{
    "generated_at": "2026-09-16T22:05:37Z",
    "source_health": {
        "healthy": 8,
        "total": 8,
        "sources": {
            "nvd": true,
            "cisa": true,
            "exploitdb": true,
            "poc_in_github": true,
            "cxsecurity": true,
            "sploitus": true,
            "cve_intel": true,
            "github": true
        }
    },
    "is_demo": false,
    "entries": [
        {
            "id": "CVE-2026-92073",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "updated_at": "2026-09-16T04:18:58.710",
            "published_at": "2026-09-15T13:17:02.153",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2062527",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:17:02.153",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92073"
                }
            ]
        },
        {
            "id": "CVE-2026-92062",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "updated_at": "2026-09-16T04:18:58.150",
            "published_at": "2026-09-15T13:17:00.777",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2054670",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:17:00.777",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92062"
                }
            ]
        },
        {
            "id": "CVE-2026-92055",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "updated_at": "2026-09-16T04:18:57.627",
            "published_at": "2026-09-15T13:16:59.370",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2063652",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:59.370",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92055"
                }
            ]
        },
        {
            "id": "CVE-2026-92054",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "updated_at": "2026-09-16T04:18:57.100",
            "published_at": "2026-09-15T13:16:58.800",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2062551",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:58.800",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92054"
                }
            ]
        },
        {
            "id": "CVE-2026-92053",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "updated_at": "2026-09-16T04:18:56.553",
            "published_at": "2026-09-15T13:16:57.053",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2061503",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:57.053",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92053"
                }
            ]
        },
        {
            "id": "CVE-2026-92052",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "updated_at": "2026-09-16T04:18:56.003",
            "published_at": "2026-09-15T13:16:56.940",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-457",
            "what_happened": "Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2061499",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:56.940",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92052"
                }
            ]
        },
        {
            "id": "CVE-2026-92047",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "updated_at": "2026-09-16T04:18:55.477",
            "published_at": "2026-09-15T13:16:56.373",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2059021",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:56.373",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92047"
                }
            ]
        },
        {
            "id": "CVE-2026-92043",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "updated_at": "2026-09-16T04:18:54.910",
            "published_at": "2026-09-15T13:16:55.750",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2050150",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:55.750",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92043"
                }
            ]
        },
        {
            "id": "CVE-2026-92033",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.",
            "updated_at": "2026-09-16T04:18:54.330",
            "published_at": "2026-09-15T13:16:54.623",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 156.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2047339",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:54.623",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92033"
                }
            ]
        },
        {
            "id": "CVE-2026-92020",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "updated_at": "2026-09-16T04:18:53.740",
            "published_at": "2026-09-15T13:16:51.990",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2066329",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-91/",
                "https://www.mozilla.org/security/advisories/mfsa2026-92/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/",
                "https://www.mozilla.org/security/advisories/mfsa2026-95/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:51.990",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92020"
                }
            ]
        },
        {
            "id": "CVE-2026-92017",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "updated_at": "2026-09-16T04:18:53.153",
            "published_at": "2026-09-15T13:16:51.403",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "Privilege escalation in the DOM: Service Workers component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2061777",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-91/",
                "https://www.mozilla.org/security/advisories/mfsa2026-92/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/",
                "https://www.mozilla.org/security/advisories/mfsa2026-95/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:51.403",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92017"
                }
            ]
        },
        {
            "id": "CVE-2026-92015",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "updated_at": "2026-09-16T04:18:52.610",
            "published_at": "2026-09-15T13:16:51.100",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "Privilege escalation in the WebExtensions component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2060235",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-91/",
                "https://www.mozilla.org/security/advisories/mfsa2026-92/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/",
                "https://www.mozilla.org/security/advisories/mfsa2026-95/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:51.100",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92015"
                }
            ]
        },
        {
            "id": "CVE-2026-92014",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 115.41, Firefox ESR 140.16, and Thunderbird 140.16.",
            "updated_at": "2026-09-16T04:18:51.990",
            "published_at": "2026-09-15T13:16:50.887",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "Privilege escalation due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox ESR 115.41, Firefox ESR 140.16, and Thunderbird 140.16.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2060000",
                "https://www.mozilla.org/security/advisories/mfsa2026-91/",
                "https://www.mozilla.org/security/advisories/mfsa2026-92/",
                "https://www.mozilla.org/security/advisories/mfsa2026-95/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:50.887",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92014"
                }
            ]
        },
        {
            "id": "CVE-2026-92013",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "updated_at": "2026-09-16T04:18:51.443",
            "published_at": "2026-09-15T13:16:49.447",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2058078",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-91/",
                "https://www.mozilla.org/security/advisories/mfsa2026-92/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/",
                "https://www.mozilla.org/security/advisories/mfsa2026-95/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:49.447",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92013"
                }
            ]
        },
        {
            "id": "CVE-2026-92012",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "updated_at": "2026-09-16T04:18:50.860",
            "published_at": "2026-09-15T13:16:49.310",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2058069",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-91/",
                "https://www.mozilla.org/security/advisories/mfsa2026-92/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/",
                "https://www.mozilla.org/security/advisories/mfsa2026-95/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:49.310",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92012"
                }
            ]
        },
        {
            "id": "CVE-2026-92011",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "updated_at": "2026-09-16T04:18:50.317",
            "published_at": "2026-09-15T13:16:49.167",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2058068",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-91/",
                "https://www.mozilla.org/security/advisories/mfsa2026-92/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/",
                "https://www.mozilla.org/security/advisories/mfsa2026-95/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:49.167",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92011"
                }
            ]
        },
        {
            "id": "CVE-2026-92010",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "updated_at": "2026-09-16T04:18:49.770",
            "published_at": "2026-09-15T13:16:48.740",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2058067",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-91/",
                "https://www.mozilla.org/security/advisories/mfsa2026-92/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/",
                "https://www.mozilla.org/security/advisories/mfsa2026-95/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:48.740",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92010"
                }
            ]
        },
        {
            "id": "CVE-2026-92009",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "updated_at": "2026-09-16T04:18:49.223",
            "published_at": "2026-09-15T13:16:48.593",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2058066",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-91/",
                "https://www.mozilla.org/security/advisories/mfsa2026-92/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/",
                "https://www.mozilla.org/security/advisories/mfsa2026-95/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:48.593",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92009"
                }
            ]
        },
        {
            "id": "CVE-2026-92008",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "updated_at": "2026-09-16T04:18:48.670",
            "published_at": "2026-09-15T13:16:48.463",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2058065",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-91/",
                "https://www.mozilla.org/security/advisories/mfsa2026-92/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/",
                "https://www.mozilla.org/security/advisories/mfsa2026-95/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:48.463",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92008"
                }
            ]
        },
        {
            "id": "CVE-2026-92007",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "updated_at": "2026-09-16T04:18:48.030",
            "published_at": "2026-09-15T13:16:48.357",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2058064",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-91/",
                "https://www.mozilla.org/security/advisories/mfsa2026-92/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/",
                "https://www.mozilla.org/security/advisories/mfsa2026-95/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:48.357",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92007"
                }
            ]
        },
        {
            "id": "CVE-2026-92006",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Firefox vulnerability",
            "summary": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "updated_at": "2026-09-16T04:18:47.283",
            "published_at": "2026-09-15T13:16:48.243",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-92006",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-92006",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-92006"
                    ],
                    "repository": "Sploitus",
                    "author": "mozilla",
                    "first_seen": "2026-09-15T14:17:48",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-92006"
                },
                {
                    "title": "Exploit for CVE-2026-92006",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-92006",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-92006"
                    ],
                    "repository": "web.nvd.nist.gov",
                    "author": "view",
                    "first_seen": "2026-09-15T14:17:48",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-92006"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=CVE-2026-92006",
                "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-92006",
                "https://bugzilla.mozilla.org/show_bug.cgi?id=2057121",
                "https://www.mozilla.org/security/advisories/mfsa2026-90/",
                "https://www.mozilla.org/security/advisories/mfsa2026-91/",
                "https://www.mozilla.org/security/advisories/mfsa2026-92/",
                "https://www.mozilla.org/security/advisories/mfsa2026-93/",
                "https://www.mozilla.org/security/advisories/mfsa2026-94/",
                "https://www.mozilla.org/security/advisories/mfsa2026-95/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T13:16:48.243",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-92006"
                }
            ],
            "enrichment_checked_at": "2026-09-15T16:05:50Z"
        },
        {
            "id": "CVE-2026-91998",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-91998 exploit",
            "summary": "Exploit for CVE-2026-91998. CVSS 9.9.",
            "updated_at": "2026-09-15T11:35:52Z",
            "published_at": "2026-09-15T11:35:52Z",
            "cvss": 9.9,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-91998",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.9,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-91998",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-91998"
                    ],
                    "repository": "Sploitus",
                    "author": "VulnCheck",
                    "first_seen": "2026-09-15T12:17:55",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-91998"
                },
                {
                    "title": "Exploit for CVE-2026-91998",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.9,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-91998",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-91998"
                    ],
                    "repository": "web.nvd.nist.gov",
                    "author": "view",
                    "first_seen": "2026-09-15T12:17:55",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-91998"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=CVE-2026-91998",
                "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-91998"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T11:35:52Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-91998"
                }
            ]
        },
        {
            "id": "CVE-2026-91995",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-91995 exploit",
            "summary": "Exploit for CVE-2026-91995. CVSS 9.3.",
            "updated_at": "2026-09-15T11:35:50Z",
            "published_at": "2026-09-15T11:35:50Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-91995",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.3,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:N/SA:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-91995",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-91995"
                    ],
                    "repository": "Sploitus",
                    "author": "VulnCheck",
                    "first_seen": "2026-09-15T12:17:54",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-91995"
                },
                {
                    "title": "Exploit for CVE-2026-91995",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.3,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:N/SA:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-91995",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-91995"
                    ],
                    "repository": "web.nvd.nist.gov",
                    "author": "view",
                    "first_seen": "2026-09-15T12:17:54",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-91995"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=CVE-2026-91995",
                "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-91995"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T11:35:50Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-91995"
                }
            ]
        },
        {
            "id": "CVE-2026-91964",
            "vendor": "FreeRDP",
            "product": "FreeRDP",
            "title": "FreeRDP vulnerability",
            "summary": "FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.",
            "updated_at": "2026-09-16T04:18:46.560",
            "published_at": "2026-09-15T16:17:52.480",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.0.0 through before 3.0.0 (semver); 3.0.0 through before 3.31.0 (semver); before 3.31.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length field that gets written to a fixed 512-byte buffer without validation, causing client crashes or potential code execution when chained with memory disclosure.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2vf2-grvj-6g8x",
                "https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-heap-buffer-overflow-via-routingtoken"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T16:17:52.480",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91964"
                }
            ]
        },
        {
            "id": "CVE-2026-91948",
            "vendor": "FreeRDP",
            "product": "FreeRDP",
            "title": "FreeRDP vulnerability",
            "summary": "FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.",
            "updated_at": "2026-09-16T04:18:46.380",
            "published_at": "2026-09-15T16:17:48.503",
            "cvss": 7.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.28.0 through before 3.31.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-191",
            "what_happened": "FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory including live pointers, potentially enabling code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/FreeRDP/FreeRDP/commit/40d9202cd95551600c07437ce6bd5ecd7d31e57b",
                "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9jcm-x588-gh26",
                "https://www.vulncheck.com/advisories/freerdp-before-3.31.0-out-of-bounds-write-via-show-protocol"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T16:17:48.503",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91948"
                }
            ]
        },
        {
            "id": "CVE-2026-91947",
            "vendor": "FreeRDP",
            "product": "FreeRDP",
            "title": "FreeRDP vulnerability",
            "summary": "FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.",
            "updated_at": "2026-09-16T04:18:46.133",
            "published_at": "2026-09-15T16:17:48.353",
            "cvss": 7.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.0.0 through before 3.31.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-6mpx-c8rj-whj5",
                "https://www.vulncheck.com/advisories/freerdp-server-before-3.31.0-use-after-free-via-drdynvc"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T16:17:48.353",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91947"
                }
            ]
        },
        {
            "id": "CVE-2026-91925",
            "vendor": "polyaxon",
            "product": "polyaxon",
            "title": "CVE-2026-91925 exploit",
            "summary": "Exploit for CVE-2026-91925. CVSS 8.8.",
            "updated_at": "2026-09-15T13:16:46.980",
            "published_at": "2026-09-15T11:17:13.220",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "0 through 2.16.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-1336",
            "what_happened": "Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code. Attackers can submit runs with Jinja2 payloads in queue, namespace, conditions, presets, or dependencies fields to execute operating system commands in the scheduler process context, exposing database credentials and service tokens.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-91925",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-91925",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-91925"
                    ],
                    "repository": "Sploitus",
                    "author": "VulnCheck",
                    "first_seen": "2026-09-15T13:16:46",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-91925"
                },
                {
                    "title": "Exploit for CVE-2026-91925",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-91925",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-91925"
                    ],
                    "repository": "web.nvd.nist.gov",
                    "author": "view",
                    "first_seen": "2026-09-15T13:16:46",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-91925"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=CVE-2026-91925",
                "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-91925",
                "https://github.com/polyaxon/cli/blob/bfea04a0bf93886f69a3195954204d9d010b55aa/cli/polyaxon/_polyaxonfile/specs/libs/engine.py",
                "https://github.com/polyaxon/cli/blob/bfea04a0bf93886f69a3195954204d9d010b55aa/cli/polyaxon/_polyaxonfile/specs/sections.py",
                "https://github.com/polyaxon/polyaxon",
                "https://github.com/polyaxon/polyaxon/issues/1540",
                "https://www.vulncheck.com/advisories/polyaxon-through-2.16.4-server-side-template-injection-via-unsandboxed-jinja2-engine"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T11:00:53Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-91925"
                },
                {
                    "at": "2026-09-15T11:17:13.220",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91925"
                }
            ],
            "enrichment_checked_at": "2026-09-16T22:05:34Z",
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
            "id": "CVE-2026-91181",
            "vendor": "Mattermost",
            "product": "Mattermost",
            "title": "Mattermost vulnerability",
            "summary": "Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data Retention Policy permission to obtain a private team's secret invite_id and email, and use it to join the team without authorization, via GET /api/v4/data_retention/policies/{policy_id}/teams.. Mattermost Advisory ID: MMSA-2026-00702",
            "updated_at": "2026-09-16T04:18:45.920",
            "published_at": "2026-09-14T22:16:59.643",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.9.0 through 11.9.0 (semver); 11.8.0 through 11.8.4 (semver); 11.7.0 through 11.7.7 (semver); 10.11.0 through 10.11.22 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data Retention Policy permission to obtain a private team's secret invite_id and email, and use it to join the team without authorization, via GET /api/v4/data_retention/policies/{policy_id}/teams.. Mattermost Advisory ID: MMSA-2026-00702",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://mattermost.com/security-updates"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T22:16:59.643",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-91181"
                }
            ]
        },
        {
            "id": "CVE-2026-90894",
            "vendor": "Parallels",
            "product": "Parallels Desktop for Mac",
            "title": "Parallels Desktop for Mac vulnerability",
            "summary": "Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group.\n\n\n\nAfter login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon unpacks with one string, tar -xf \"%1\" -C \"%2\", then Qt QProcess::splitCommand chops that string into words. A quote in the folder name closes early. The leftover text becomes extra tar flags. macOS tar --use-compress-program= runs the named program as root.",
            "updated_at": "2026-09-15T09:16:44.620",
            "published_at": "2026-09-14T10:17:06.133",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "26.4.0",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group.\n\n\n\nAfter login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon unpacks with one string, tar -xf \"%1\" -C \"%2\", then Qt QProcess::splitCommand chops that string into words. A quote in the folder name closes early. The leftover text becomes extra tar flags. macOS tar --use-compress-program= runs the named program as root.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://kb.parallels.com/en/131168",
                "https://www.parallels.com/products/desktop/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T10:17:06.133",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90894"
                }
            ]
        },
        {
            "id": "CVE-2026-90783",
            "vendor": "Moritz Bunkus",
            "product": "MKVToolNix",
            "title": "MKVToolNix vulnerability",
            "summary": "MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.",
            "updated_at": "2026-09-13T13:16:29.560",
            "published_at": "2026-09-13T13:16:29.560",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 101.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-680",
            "what_happened": "MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing a heap buffer overflow when the file is parsed with mkvmerge.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://codeberg.org/mbunkus/mkvtoolnix",
                "https://codeberg.org/mbunkus/mkvtoolnix/commit/1495126138e086080f0163bee27fafbdf956a1d0",
                "https://codeberg.org/mbunkus/mkvtoolnix/src/tag/release-101.0/lib/avilib-0.6.10/avilib.c#L2552-L2570",
                "https://www.vulncheck.com/advisories/mkvtoolnix-through-101.0-heap-buffer-overflow-via-avilib-odml-superindex-integer-wraparound"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T13:16:29.560",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90783"
                }
            ]
        },
        {
            "id": "CVE-2026-90782",
            "vendor": "Systerel",
            "product": "S2OPC",
            "title": "S2OPC vulnerability",
            "summary": "S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap allocation failures on sessions with both data-change and event notifications to cause the server process to terminate.",
            "updated_at": "2026-09-13T13:16:29.410",
            "published_at": "2026-09-13T13:16:29.410",
            "cvss": 6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "0 through 1.7.3 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 26,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap allocation failures on sessions with both data-change and event notifications to cause the server process to terminate.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-90782",
                    "summary": "NULL dereference in S2OPC 1.7.3 when DataChange alloc fails and Event alloc clobbers status.",
                    "what_happened": "NULL dereference in S2OPC 1.7.3 when DataChange alloc fails and Event alloc clobbers status.",
                    "cvss": 6,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/SC:N/VI:N/SI:N/VA:H/SA:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=B4CCFE85-C839-532A-95ED-7B18BF7D8947",
                        "https://github.com/HarshRajSinghania/CVE-2026-90782-s2opc-status-clobber"
                    ],
                    "repository": "Sploitus",
                    "author": "HarshRajSinghania",
                    "first_seen": "2026-09-14T05:42:31",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B4CCFE85-C839-532A-95ED-7B18BF7D8947"
                },
                {
                    "title": "Exploit for CVE-2026-90782",
                    "summary": "NULL dereference in S2OPC 1.7.3 when DataChange alloc fails and Event alloc clobbers status.",
                    "what_happened": "NULL dereference in S2OPC 1.7.3 when DataChange alloc fails and Event alloc clobbers status.",
                    "cvss": 6,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/SC:N/VI:N/SI:N/VA:H/SA:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=B4CCFE85-C839-532A-95ED-7B18BF7D8947",
                        "https://github.com/HarshRajSinghania/CVE-2026-90782-s2opc-status-clobber"
                    ],
                    "repository": "HarshRajSinghania/CVE-2026-90782-s2opc-status-clobber",
                    "author": "HarshRajSinghania",
                    "first_seen": "2026-09-14T05:42:31",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/HarshRajSinghania/CVE-2026-90782-s2opc-status-clobber"
                }
            ],
            "references": [
                "https://gitlab.com/systerel/S2OPC",
                "https://gitlab.com/systerel/S2OPC/-/blob/S2OPC_Toolkit_1.7.3/src/ClientServer/services/b2c/msg_subscription_publish_bs.c#L106-L147",
                "https://gitlab.com/systerel/S2OPC/-/commit/8848f051eed069b107ae7cb16a346d6f6386a8f5",
                "https://gitlab.com/systerel/S2OPC/-/issues/1815",
                "https://gitlab.com/systerel/S2OPC/-/merge_requests/1862",
                "https://www.vulncheck.com/advisories/s2opc-through-1.7.3-null-pointer-dereference-in-alloc-notification-message-items",
                "https://sploitus.com/exploit?id=B4CCFE85-C839-532A-95ED-7B18BF7D8947",
                "https://github.com/HarshRajSinghania/CVE-2026-90782-s2opc-status-clobber"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T13:16:29.410",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90782"
                }
            ]
        },
        {
            "id": "CVE-2026-90781",
            "vendor": "ALSA Project",
            "product": "alsa-lib",
            "title": "alsa-lib vulnerability",
            "summary": "alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.",
            "updated_at": "2026-09-13T13:16:29.263",
            "published_at": "2026-09-13T13:16:29.263",
            "cvss": 4.8,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.2.16.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-193",
            "what_happened": "alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/alsa-project/alsa-lib",
                "https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/control/ctlparse.c#L216-L241",
                "https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020",
                "https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/",
                "https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-off-by-one-stack-buffer-overflow-in-snd-ctl-ascii-elem-id-parse"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T13:16:29.263",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90781"
                }
            ]
        },
        {
            "id": "CVE-2026-90780",
            "vendor": "SIPp",
            "product": "sipp",
            "title": "sipp vulnerability",
            "summary": "SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to overflow the static buffer and crash the process.",
            "updated_at": "2026-09-13T12:17:17.093",
            "published_at": "2026-09-13T12:17:17.093",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.7.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to overflow the static buffer and crash the process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/SIPp/sipp",
                "https://github.com/SIPp/sipp/blob/v3.7.7/src/sip_parser.cpp#L164-L227",
                "https://github.com/SIPp/sipp/commit/8ddfb43359703e665041a955543e07f504f80232",
                "https://github.com/SIPp/sipp/pull/881",
                "https://www.vulncheck.com/advisories/sipp-through-3.7.7-buffer-overflow-via-oversized-sip-header-content"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T12:17:17.093",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90780"
                }
            ]
        },
        {
            "id": "CVE-2026-90779",
            "vendor": "SIPp",
            "product": "sipp",
            "title": "sipp vulnerability",
            "summary": "SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.",
            "updated_at": "2026-09-13T12:17:16.960",
            "published_at": "2026-09-13T12:17:16.960",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.7.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/SIPp/sipp",
                "https://github.com/SIPp/sipp/blob/v3.7.7/src/auth.cpp#L183-L192",
                "https://github.com/SIPp/sipp/commit/1d4a5622bea34d0b5cdff333e6b5734608e30af7",
                "https://github.com/SIPp/sipp/pull/880",
                "https://www.vulncheck.com/advisories/sipp-through-3.7.7-stack-buffer-overflow-via-createauthheader-algorithm-parameter"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T12:17:16.960",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90779"
                }
            ]
        },
        {
            "id": "CVE-2026-90778",
            "vendor": "SIPp",
            "product": "sipp",
            "title": "sipp vulnerability",
            "summary": "SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buffer and crash the process.",
            "updated_at": "2026-09-13T12:17:16.837",
            "published_at": "2026-09-13T12:17:16.837",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.7.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static buffer and crash the process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/SIPp/sipp",
                "https://github.com/SIPp/sipp/blob/v3.7.7/src/sip_parser.cpp#L76-L113",
                "https://github.com/SIPp/sipp/commit/ddf22d1a54e0396b2e18ebaf4cf5a3fa860e5da4",
                "https://github.com/SIPp/sipp/pull/879",
                "https://www.vulncheck.com/advisories/sipp-through-3.7.7-buffer-overflow-via-sip-to-header-tag"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T12:17:16.837",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90778"
                }
            ]
        },
        {
            "id": "CVE-2026-90777",
            "vendor": "espnet",
            "product": "espnet",
            "title": "espnet vulnerability",
            "summary": "ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deserialization when loaded through the initialization or fine-tuning path.",
            "updated_at": "2026-09-13T12:17:16.690",
            "published_at": "2026-09-13T12:17:16.690",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 202609 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deserialization when loaded through the initialization or fine-tuning path.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/espnet/espnet",
                "https://github.com/espnet/espnet/blob/v.202511/espnet2/torch_utils/load_pretrained_model.py#L99",
                "https://github.com/espnet/espnet/commit/91ca045fc179f29bc7b7fe05cd852aea65310003",
                "https://github.com/espnet/espnet/releases/tag/v.202609",
                "https://github.com/espnet/espnet/security/advisories/GHSA-64f6-3gqc-r926",
                "https://www.vulncheck.com/advisories/espnet-before-202609-remote-code-execution-via-unsafe-deserialization"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T12:17:16.690",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90777"
                }
            ]
        },
        {
            "id": "CVE-2026-90776",
            "vendor": "nodemailer",
            "product": "nodemailer",
            "title": "nodemailer vulnerability",
            "summary": "Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several seconds, causing denial of service.",
            "updated_at": "2026-09-13T12:17:16.547",
            "published_at": "2026-09-13T12:17:16.547",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.1.0 through before 10.0.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-407",
            "what_happened": "Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several seconds, causing denial of service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/nodemailer/nodemailer",
                "https://github.com/nodemailer/nodemailer/blob/v10.0.4/src/addressparser/index.ts#L251",
                "https://github.com/nodemailer/nodemailer/commit/c07f17518d25aca8ab2ad66968dcbca538c24b89",
                "https://github.com/nodemailer/nodemailer/releases/tag/v10.0.5",
                "https://github.com/nodemailer/nodemailer/security/advisories/GHSA-prgh-xp8r-p3m5",
                "https://www.vulncheck.com/advisories/nodemailer-9.1.0-through-10.0.4-denial-of-service-via-quadratic-address-parsing"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T12:17:16.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90776"
                }
            ]
        },
        {
            "id": "CVE-2026-90775",
            "vendor": "PostGIS",
            "product": "address_standardizer",
            "title": "address_standardizer vulnerability",
            "summary": "PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.",
            "updated_at": "2026-09-13T12:17:16.400",
            "published_at": "2026-09-13T12:17:16.400",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.7.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/postgis/address_standardizer",
                "https://github.com/postgis/address_standardizer/blob/e987949e0fccff6a0e7a6d3f86814d5c7a01f481/NEWS.md",
                "https://github.com/postgis/address_standardizer/blob/v3.7.0/src/analyze.c#L860",
                "https://github.com/postgis/address_standardizer/blob/v3.7.0/src/gamma.c#L301-L311",
                "https://github.com/postgis/address_standardizer/commit/a5cb4b1360a040973092f13b1af97a718e7e104a",
                "https://github.com/postgis/address_standardizer/commit/e987949e0fccff6a0e7a6d3f86814d5c7a01f481",
                "https://github.com/postgis/address_standardizer/pull/6",
                "https://www.vulncheck.com/advisories/postgis-address-standardizer-through-3.7.0-out-of-bounds-read-via-unvalidated-rule-weight"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T12:17:16.400",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90775"
                }
            ]
        },
        {
            "id": "CVE-2026-90774",
            "vendor": "orhun",
            "product": "rustypaste",
            "title": "rustypaste vulnerability",
            "summary": "rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations.",
            "updated_at": "2026-09-13T11:17:02.163",
            "published_at": "2026-09-13T11:17:02.163",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.18.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured upload directory to arbitrary locations.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/orhun/rustypaste",
                "https://github.com/orhun/rustypaste/blob/v0.18.0/src/paste.rs",
                "https://github.com/orhun/rustypaste/commit/ac05d552596af4a8429d80f30d11f67117ce02c8",
                "https://github.com/orhun/rustypaste/issues/622",
                "https://www.vulncheck.com/advisories/rustypaste-before-0.18.1-path-traversal-via-filename-header"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T11:17:02.163",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90774"
                }
            ]
        },
        {
            "id": "CVE-2026-90773",
            "vendor": "dalance",
            "product": "procs",
            "title": "procs vulnerability",
            "summary": "procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command line arguments, which are written unmodified to other users' terminals for interpretation by terminal emulators.",
            "updated_at": "2026-09-13T11:17:01.967",
            "published_at": "2026-09-13T11:17:01.967",
            "cvss": 2.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.14.12 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-150",
            "what_happened": "procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command line arguments, which are written unmodified to other users' terminals for interpretation by terminal emulators.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/dalance/procs",
                "https://github.com/dalance/procs/blob/v0.14.12/src/columns/command.rs",
                "https://github.com/dalance/procs/commit/a064cec7d59f69a636d38e247824245dcd3a9836",
                "https://github.com/dalance/procs/issues/950",
                "https://www.vulncheck.com/advisories/procs-through-0.14.12-terminal-escape-sequence-injection-via-command"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T11:17:01.967",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90773"
                }
            ]
        },
        {
            "id": "CVE-2026-90772",
            "vendor": "amundsen-io",
            "product": "amundsen-frontend",
            "title": "amundsen-frontend vulnerability",
            "summary": "Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing JavaScript in every user's browser that views search results.",
            "updated_at": "2026-09-13T11:17:01.780",
            "published_at": "2026-09-13T11:17:01.780",
            "cvss": 8.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the metadata service or Elasticsearch, executing JavaScript in every user's browser that views search results.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/amundsen-io/amundsen",
                "https://github.com/amundsen-io/amundsen/blob/frontend-4.3.0/frontend/amundsen_application/static/js/components/ResourceListItem/TableListItem/index.tsx",
                "https://github.com/amundsen-io/amundsen/issues/2362",
                "https://www.vulncheck.com/advisories/amundsen-frontend-through-4.3.0-stored-xss-via-description"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T11:17:01.780",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90772"
                }
            ]
        },
        {
            "id": "CVE-2026-90771",
            "vendor": "hapijs",
            "product": "joi",
            "title": "joi vulnerability",
            "summary": "joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.",
            "updated_at": "2026-09-13T11:17:01.613",
            "published_at": "2026-09-13T11:17:01.613",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16.0.0 through before 17.13.8 (semver); 18.0.0 through before 18.2.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-1321",
            "what_happened": "joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking downstream code relying on Object.prototype methods.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/hapijs/joi",
                "https://github.com/hapijs/joi/blob/v18.2.8/lib/messages.js",
                "https://github.com/hapijs/joi/commit/5b8333c9177e08b4ef4ed02903c2d657084e7afb",
                "https://github.com/hapijs/joi/issues/3150",
                "https://www.vulncheck.com/advisories/joi-before-17.13.8-and-18.2.9-prototype-pollution-via-messages"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T11:17:01.613",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90771"
                }
            ]
        },
        {
            "id": "CVE-2026-90770",
            "vendor": "openspug",
            "product": "spug",
            "title": "spug vulnerability",
            "summary": "Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/run_test/ endpoint to execute arbitrary commands as the Spug process user.",
            "updated_at": "2026-09-13T11:17:01.453",
            "published_at": "2026-09-13T11:17:01.453",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.4.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/run_test/ endpoint to execute arbitrary commands as the Spug process user.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openspug/spug",
                "https://github.com/openspug/spug/blob/v3.4.0/spug_api/apps/monitor/executors.py",
                "https://github.com/openspug/spug/blob/v3.4.0/spug_api/apps/monitor/views.py",
                "https://github.com/openspug/spug/commit/97aebf133e1f9cbb35ccebadab1faedfdfe93f42",
                "https://github.com/openspug/spug/issues/741",
                "https://www.vulncheck.com/advisories/spug-through-3.4.0-remote-code-execution-via-ping-check"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T11:17:01.453",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90770"
                }
            ]
        },
        {
            "id": "CVE-2026-90769",
            "vendor": "lfnovo",
            "product": "open-notebook",
            "title": "open-notebook vulnerability",
            "summary": "Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests.",
            "updated_at": "2026-09-13T11:17:01.270",
            "published_at": "2026-09-13T11:17:01.270",
            "cvss": 8.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.11.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/lfnovo/open-notebook",
                "https://github.com/lfnovo/open-notebook/blob/8889087e317177d7b6e286342ab34e0c9c01d43e/api/routers/sources.py",
                "https://github.com/lfnovo/open-notebook/commit/9045ea50196927eac7de647bb5b7009349236fb4",
                "https://github.com/lfnovo/open-notebook/issues/1284",
                "https://www.vulncheck.com/advisories/open-notebook-before-1.11.0-server-side-request-forgery-via-link-source"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T11:17:01.270",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90769"
                }
            ]
        },
        {
            "id": "CVE-2026-90768",
            "vendor": "kevoreilly",
            "product": "CAPEv2",
            "title": "CAPEv2 vulnerability",
            "summary": "CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership verification.",
            "updated_at": "2026-09-13T11:17:01.113",
            "published_at": "2026-09-13T11:17:01.113",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 471ee4bb422ec4aa0f1aa1089540a1ad0b7d84f0 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view and delete endpoints without ownership verification.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/kevoreilly/CAPEv2",
                "https://github.com/kevoreilly/CAPEv2/blob/1255b18/web/apiv2/views.py",
                "https://github.com/kevoreilly/CAPEv2/issues/3162",
                "https://www.vulncheck.com/advisories/capev2-through-commit-471ee4b-rest-api-task-endpoints-missing-ownership-check"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T11:17:01.113",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90768"
                }
            ]
        },
        {
            "id": "CVE-2026-90767",
            "vendor": "froxlor",
            "product": "Froxlor",
            "title": "Froxlor vulnerability",
            "summary": "Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthorized access that survives key deletion and SSH access revocation.",
            "updated_at": "2026-09-13T11:17:00.947",
            "published_at": "2026-09-13T11:17:00.947",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.3.12 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-93",
            "what_happened": "Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthorized access that survives key deletion and SSH access revocation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/froxlor/Froxlor",
                "https://github.com/froxlor/Froxlor/blob/2.3.10/lib/Froxlor/Api/Commands/SshKeys.php",
                "https://github.com/froxlor/Froxlor/blob/2.3.10/lib/Froxlor/Cron/System/SshKeys.php",
                "https://github.com/froxlor/Froxlor/security/advisories/GHSA-p3v3-74gc-jh5f",
                "https://www.vulncheck.com/advisories/froxlor-before-2.3.12-ssh-key-injection-via-authorized-keys"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T11:17:00.947",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90767"
                }
            ]
        },
        {
            "id": "CVE-2026-90687",
            "vendor": "n/a",
            "product": "GPAC",
            "title": "GPAC vulnerability",
            "summary": "A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is able to resolve this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is recommended.",
            "updated_at": "2026-09-14T06:16:58.677",
            "published_at": "2026-09-14T06:16:58.677",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f1219cde",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 is able to resolve this issue. Patch name: 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is recommended.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Ech06/CVE_submit/blob/main/gpac_3800.md",
                "https://github.com/gpac/gpac/",
                "https://github.com/gpac/gpac/commit/9eb40df4448b88d6a6ce3454657c06f47eff0b24",
                "https://github.com/gpac/gpac/issues/3800",
                "https://github.com/gpac/gpac/releases/tag/abi-16.23",
                "https://vuldb.com/cve/CVE-2026-90687",
                "https://vuldb.com/submit/914121",
                "https://vuldb.com/vuln/403220",
                "https://vuldb.com/vuln/403220/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T06:16:58.677",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90687"
                }
            ]
        },
        {
            "id": "CVE-2026-90686",
            "vendor": "n/a",
            "product": "GPAC",
            "title": "GPAC vulnerability",
            "summary": "A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version abi-16.23 is able to mitigate this issue. The patch is identified as afca1f1181668d85941d51ed1adf647807d5d975. It is suggested to upgrade the affected component.",
            "updated_at": "2026-09-14T06:16:58.507",
            "published_at": "2026-09-14T06:16:58.507",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f1219cde",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version abi-16.23 is able to mitigate this issue. The patch is identified as afca1f1181668d85941d51ed1adf647807d5d975. It is suggested to upgrade the affected component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Ech06/CVE_submit/blob/main/gpac_3798.md",
                "https://github.com/gpac/gpac/",
                "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
                "https://github.com/gpac/gpac/issues/3798",
                "https://github.com/gpac/gpac/releases/tag/abi-16.23",
                "https://vuldb.com/cve/CVE-2026-90686",
                "https://vuldb.com/submit/914120",
                "https://vuldb.com/vuln/403219",
                "https://vuldb.com/vuln/403219/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T06:16:58.507",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90686"
                }
            ]
        },
        {
            "id": "CVE-2026-90685",
            "vendor": "n/a",
            "product": "GPAC",
            "title": "GPAC vulnerability",
            "summary": "A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 can resolve this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. The affected component should be upgraded.",
            "updated_at": "2026-09-14T06:16:58.300",
            "published_at": "2026-09-14T06:16:58.300",
            "cvss": 0.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f1219cde",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-617",
            "what_happened": "A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 can resolve this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. The affected component should be upgraded.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/gpac/gpac/",
                "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
                "https://github.com/gpac/gpac/issues/3825",
                "https://github.com/gpac/gpac/releases/tag/abi-16.23",
                "https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln%20GPAC%20MP4Box%20Assertion%20Failure%20assert(!codec-bs).md",
                "https://vuldb.com/cve/CVE-2026-90685",
                "https://vuldb.com/submit/914027",
                "https://vuldb.com/vuln/403218",
                "https://vuldb.com/vuln/403218/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T06:16:58.300",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90685"
                }
            ]
        },
        {
            "id": "CVE-2026-90684",
            "vendor": "n/a",
            "product": "GPAC",
            "title": "GPAC vulnerability",
            "summary": "A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version abi-16.23 addresses this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.",
            "updated_at": "2026-09-14T05:16:59.067",
            "published_at": "2026-09-14T05:16:59.067",
            "cvss": 0.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f1219cde",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-617",
            "what_happened": "A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. It is possible to launch the attack on the local host. The exploit has been published and may be used. Upgrading to version abi-16.23 addresses this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/gpac/gpac/",
                "https://github.com/gpac/gpac/commit/49dee5cad329cfed310c1682703df7daa47df31a",
                "https://github.com/gpac/gpac/issues/3824",
                "https://github.com/gpac/gpac/releases/tag/abi-16.23",
                "https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln%20GPAC%20MP4Box%20Assertion%20Failure%20assert(node).md",
                "https://vuldb.com/cve/CVE-2026-90684",
                "https://vuldb.com/submit/914026",
                "https://vuldb.com/vuln/403217",
                "https://vuldb.com/vuln/403217/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:59.067",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90684"
                }
            ]
        },
        {
            "id": "CVE-2026-90683",
            "vendor": "n/a",
            "product": "GPAC",
            "title": "GPAC vulnerability",
            "summary": "A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to version abi-16.23 is able to address this issue. The patch is named 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component. This is not a duplicate of CVE-2021-46237 or CVE-2021-46234.",
            "updated_at": "2026-09-14T05:16:58.900",
            "published_at": "2026-09-14T05:16:58.900",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f1219cde",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-617",
            "what_happened": "A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locally is a requirement. The exploit is now public and may be used. Upgrading to version abi-16.23 is able to address this issue. The patch is named 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component. This is not a duplicate of CVE-2021-46237 or CVE-2021-46234.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/gpac/gpac/",
                "https://github.com/gpac/gpac/commit/49dee5cad329cfed310c1682703df7daa47df31a",
                "https://github.com/gpac/gpac/issues/3823",
                "https://github.com/gpac/gpac/releases/tag/abi-16.23",
                "https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln%20GPAC%20MP4Box%20Assertion%20Failure%20assert(num_instances).md",
                "https://vuldb.com/cve/CVE-2026-90683",
                "https://vuldb.com/submit/913780",
                "https://vuldb.com/vuln/403216",
                "https://vuldb.com/vuln/403216/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:58.900",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90683"
                }
            ]
        },
        {
            "id": "CVE-2026-90682",
            "vendor": "Matthias-Wandel",
            "product": "jhead",
            "title": "jhead vulnerability",
            "summary": "A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-14T05:16:58.730",
            "published_at": "2026-09-14T05:16:58.730",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.0; 3.1; 3.2; 3.3",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Matthias-Wandel/jhead/",
                "https://github.com/Matthias-Wandel/jhead/issues/99",
                "https://github.com/user-attachments/files/30397094/poc.zip",
                "https://vuldb.com/cve/CVE-2026-90682",
                "https://vuldb.com/submit/914948",
                "https://vuldb.com/vuln/403215",
                "https://vuldb.com/vuln/403215/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:58.730",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90682"
                }
            ]
        },
        {
            "id": "CVE-2026-90681",
            "vendor": "Matthias-Wandel",
            "product": "jhead",
            "title": "jhead vulnerability",
            "summary": "A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-14T05:16:58.537",
            "published_at": "2026-09-14T05:16:58.537",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.0; 3.1; 3.2; 3.3",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Matthias-Wandel/jhead/",
                "https://github.com/Matthias-Wandel/jhead/issues/98",
                "https://github.com/user-attachments/files/30397052/poc.zip",
                "https://vuldb.com/cve/CVE-2026-90681",
                "https://vuldb.com/submit/914946",
                "https://vuldb.com/vuln/403214",
                "https://vuldb.com/vuln/403214/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:58.537",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90681"
                }
            ]
        },
        {
            "id": "CVE-2026-90680",
            "vendor": "D-Link",
            "product": "DIR-823G",
            "title": "DIR-823G vulnerability",
            "summary": "A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.",
            "updated_at": "2026-09-14T04:16:36.353",
            "published_at": "2026-09-14T04:16:36.353",
            "cvss": 9.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.2B05_20181207",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway results in stack-based buffer overflow. The attack can be launched remotely.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Amalll-Sec/router-vulnerability-research/blob/main/advisories/d-link/dir-823g/SetStaticRouteSettings/README.md",
                "https://vuldb.com/cve/CVE-2026-90680",
                "https://vuldb.com/submit/914902",
                "https://vuldb.com/vuln/403213",
                "https://vuldb.com/vuln/403213/cti",
                "https://www.dlink.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:16:36.353",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90680"
                }
            ]
        },
        {
            "id": "CVE-2026-90668",
            "vendor": "UnrealIRCd",
            "product": "UnrealIRCd",
            "title": "UnrealIRCd vulnerability",
            "summary": "The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unlimited number of headers, if a websocket or JSON-RPC listener is enabled (disabled by default).",
            "updated_at": "2026-09-13T02:17:05.103",
            "published_at": "2026-09-13T02:17:05.103",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:X/RE:L/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.0.5 through before 6.2.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unlimited number of headers, if a websocket or JSON-RPC listener is enabled (disabled by default).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://forums.unrealircd.org/viewtopic.php?t=9483",
                "https://www.unrealircd.org/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T02:17:05.103",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90668"
                }
            ]
        },
        {
            "id": "CVE-2026-90651",
            "vendor": "Socket",
            "product": "Socket Firewall",
            "title": "Socket Firewall vulnerability",
            "summary": "Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated configuration sets SOCKET_API_SSL_VERIFY='false' and UPSTREAM_SSL_VERIFY='false', and the OpenResty/Lua HTTP client used for outbound requests accepts any certificate, including self-signed and otherwise untrusted certificates, without validating the chain. An attacker positioned to intercept traffic between Socket Firewall and the Socket API or an upstream package registry can present a crafted certificate and modify responses in transit, including substituting malicious package content or altering the allow/block decisions the firewall enforces. Setting api_ssl_verify: true and upstream_ssl_verify: true enables verification; however, in versions before 1.1.334, the generated nginx configuration did not emit lua_ssl_trusted_certificate, and thus verification could not be used successfully without manually patching the generated configuration. Version 2.0.0 changes the default for both settings to true.",
            "updated_at": "2026-09-13T00:17:07.203",
            "published_at": "2026-09-13T00:17:07.203",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.0.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the generated configuration sets SOCKET_API_SSL_VERIFY='false' and UPSTREAM_SSL_VERIFY='false', and the OpenResty/Lua HTTP client used for outbound requests accepts any certificate, including self-signed and otherwise untrusted certificates, without validating the chain. An attacker positioned to intercept traffic between Socket Firewall and the Socket API or an upstream package registry can present a crafted certificate and modify responses in transit, including substituting malicious package content or altering the allow/block decisions the firewall enforces. Setting api_ssl_verify: true and upstream_ssl_verify: true enables verification; however, in versions before 1.1.334, the generated nginx configuration did not emit lua_ssl_trusted_certificate, and thus verification could not be used successfully without manually patching the generated configuration. Version 2.0.0 changes the default for both settings to true.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.socket.dev/docs/registry-mode-configuration-reference",
                "https://github.com/SocketDev/socket-registry-firewall/releases/tag/v2.0.0"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T00:17:07.203",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90651"
                }
            ]
        },
        {
            "id": "CVE-2026-90648",
            "vendor": "WebAssembly",
            "product": "wabt",
            "title": "wabt vulnerability",
            "summary": "wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a \"table flip\" attack. It does not check the return value of calloc() in wasm_rt_allocate_funcref_table() (wasm2c/wasm-rt-impl-tableops.inc). When the funcref table allocation fails, table->data is left NULL while table->size keeps the guest-declared element count; thus, bounds checks still pass and table element accesses resolve to absolute memory addresses (i * sizeof(wasm_rt_funcref_t)). This gives arbitrary read and write of host process memory and - via table.get, table.set, and call_indirect - arbitrary code execution, defeating the isolation that wasm2c exists to provide (a full sandbox escape). wasm2c is used as an in-process sandboxing boundary by RLBox and WasmBoxC, including in Firefox, which compiles the Graphite, Hunspell, Ogg, Expat, and Woff2 libraries via wasm2c to contain untrusted font, media, and XML input. Therefore, sandboxing in these applications is potentially affected. Exploitation requires the funcref table allocation to fail, for example under an address-space limit (RLIMIT_AS), on 32-bit hosts, with vm.overcommit_memory=2, or under memory pressure. On 64-bit Linux with default overcommit the allocation succeeds and the defect is not triggered. The wasm2c memory allocator aborts on calloc failure in the same runtime; the table allocator lacks this abort behavior. This was introduced in commit ab9e0b55 (PR #813).",
            "updated_at": "2026-09-13T00:17:07.023",
            "published_at": "2026-09-13T00:17:07.023",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.0.41 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-252",
            "what_happened": "wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a \"table flip\" attack. It does not check the return value of calloc() in wasm_rt_allocate_funcref_table() (wasm2c/wasm-rt-impl-tableops.inc). When the funcref table allocation fails, table->data is left NULL while table->size keeps the guest-declared element count; thus, bounds checks still pass and table element accesses resolve to absolute memory addresses (i * sizeof(wasm_rt_funcref_t)). This gives arbitrary read and write of host process memory and - via table.get, table.set, and call_indirect - arbitrary code execution, defeating the isolation that wasm2c exists to provide (a full sandbox escape). wasm2c is used as an in-process sandboxing boundary by RLBox and WasmBoxC, including in Firefox, which compiles the Graphite, Hunspell, Ogg, Expat, and Woff2 libraries via wasm2c to contain untrusted font, media, and XML input. Therefore, sandboxing in these applications is potentially affected. Exploitation requires the funcref table allocation to fail, for example under an address-space limit (RLIMIT_AS), on 32-bit hosts, with vm.overcommit_memory=2, or under memory pressure. On 64-bit Linux with default overcommit the allocation succeeds and the defect is not triggered. The wasm2c memory allocator aborts on calloc failure in the same runtime; the table allocator lacks this abort behavior. This was introduced in commit ab9e0b55 (PR #813).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.mozilla.org/show_bug.cgi?id=1827704",
                "https://github.com/WebAssembly/wabt",
                "https://github.com/trustsig-eu/wasm2c-tableflip",
                "https://https://blog.mozilla.org/attack-and-defense/2021/12/06/webassembly-and-back-again-fine-grained-sandboxing-in-firefox-95",
                "https://rlbox.dev"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T00:17:07.023",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90648"
                }
            ]
        },
        {
            "id": "CVE-2026-90647",
            "vendor": "Kalkitech",
            "product": "ASE2000 V2 Communication Test Set",
            "title": "ASE2000 V2 Communication Test Set vulnerability",
            "summary": "ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.",
            "updated_at": "2026-09-12T23:17:01.490",
            "published_at": "2026-09-12T23:17:01.490",
            "cvss": 9.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.35 through before 2.38 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ase-systems.com/wp-content/uploads/2026/07/CYB_2026_86278_Advisory_v1.0.pdf"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T23:17:01.490",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90647"
                }
            ]
        },
        {
            "id": "CVE-2026-90623",
            "vendor": "andreashappe",
            "product": "cochise",
            "title": "cochise vulnerability",
            "summary": "A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host Key Handler. Executing a manipulation can lead to improper certificate validation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-14T04:16:36.163",
            "published_at": "2026-09-14T04:16:36.163",
            "cvss": 2.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.4.0; 0.4.1",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-287",
            "what_happened": "A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host Key Handler. Executing a manipulation can lead to improper certificate validation. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is told to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/andreashappe/cochise/",
                "https://github.com/andreashappe/cochise/issues/13",
                "https://vuldb.com/cve/CVE-2026-90623",
                "https://vuldb.com/submit/914815",
                "https://vuldb.com/vuln/403205",
                "https://vuldb.com/vuln/403205/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:16:36.163",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90623"
                }
            ]
        },
        {
            "id": "CVE-2026-90622",
            "vendor": "GNU",
            "product": "libredwg",
            "title": "libredwg vulnerability",
            "summary": "A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing a manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.14 will fix this issue. The patch is named f5b548c4c1697d66c3dabd0f6a49280a14365a3a. The affected component should be upgraded. The FIELD_HANDLE macro itself is NULL-safe (emits null_handle) - only the two raw zeroing assignments added by 27118c40 (\"encode: also disable LAYER.material\") dereferenced a NULL material handle; the fix restores the file's existing if (_obj->style) guard convention for material.",
            "updated_at": "2026-09-14T04:16:35.913",
            "published_at": "2026-09-14T04:16:35.913",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.13.4",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-404",
            "what_happened": "A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing a manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.14 will fix this issue. The patch is named f5b548c4c1697d66c3dabd0f6a49280a14365a3a. The affected component should be upgraded. The FIELD_HANDLE macro itself is NULL-safe (emits null_handle) - only the two raw zeroing assignments added by 27118c40 (\"encode: also disable LAYER.material\") dereferenced a NULL material handle; the fix restores the file's existing if (_obj->style) guard convention for material.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/LibreDWG/libredwg/commit/f5b548c4c1697d66c3dabd0f6a49280a14365a3a",
                "https://github.com/LibreDWG/libredwg/issues/1269",
                "https://github.com/LibreDWG/libredwg/releases/tag/0.14",
                "https://github.com/user-attachments/files/28549357/repro.zip",
                "https://vuldb.com/cve/CVE-2026-90622",
                "https://vuldb.com/submit/914770",
                "https://vuldb.com/vuln/403204",
                "https://vuldb.com/vuln/403204/cti",
                "https://www.gnu.org/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:16:35.913",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90622"
                }
            ]
        },
        {
            "id": "CVE-2026-90621",
            "vendor": "ipa-lab",
            "product": "HackingBuddyGPT",
            "title": "HackingBuddyGPT vulnerability",
            "summary": "A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the file src/hackingBuddyGPT/extensions/ssh_run_command.py. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-14T04:16:35.673",
            "published_at": "2026-09-14T04:16:35.673",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.1; 0.2; 0.3; 0.4; 0.5.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the file src/hackingBuddyGPT/extensions/ssh_run_command.py. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ipa-lab/hackingBuddyGPT/",
                "https://github.com/ipa-lab/hackingBuddyGPT/issues/150",
                "https://vuldb.com/cve/CVE-2026-90621",
                "https://vuldb.com/submit/914814",
                "https://vuldb.com/vuln/403203",
                "https://vuldb.com/vuln/403203/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:16:35.673",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90621"
                }
            ]
        },
        {
            "id": "CVE-2026-90620",
            "vendor": "0x4m4",
            "product": "HexStrike AI",
            "title": "HexStrike AI vulnerability",
            "summary": "A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-14T03:16:37.603",
            "published_at": "2026-09-14T03:16:37.603",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "d689933ff579d839c676c82b231f8e98326c5f04",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation causes missing authentication. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/0x4m4/hexstrike-ai/issues/223",
                "https://vuldb.com/cve/CVE-2026-90620",
                "https://vuldb.com/submit/914813",
                "https://vuldb.com/vuln/403202",
                "https://vuldb.com/vuln/403202/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T03:16:37.603",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90620"
                }
            ]
        },
        {
            "id": "CVE-2026-90619",
            "vendor": "0x4m4",
            "product": "HexStrike AI",
            "title": "HexStrike AI vulnerability",
            "summary": "A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute Endpoint. The manipulation of the argument code/script leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-14T03:16:37.427",
            "published_at": "2026-09-14T03:16:37.427",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "d689933ff579d839c676c82b231f8e98326c5f04",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknown function of the file hexstrike_server.py of the component Execute Endpoint. The manipulation of the argument code/script leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/0x4m4/hexstrike-ai/issues/222",
                "https://vuldb.com/cve/CVE-2026-90619",
                "https://vuldb.com/submit/914810",
                "https://vuldb.com/vuln/403200",
                "https://vuldb.com/vuln/403200/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T03:16:37.427",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90619"
                }
            ]
        },
        {
            "id": "CVE-2026-90618",
            "vendor": "GH05TCREW",
            "product": "PentestAgent",
            "title": "PentestAgent vulnerability",
            "summary": "A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipulation can lead to os command injection. The attack may be performed from remote. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.",
            "updated_at": "2026-09-14T03:16:37.263",
            "published_at": "2026-09-14T03:16:37.263",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "cf882dabea3ed91cef016cdd115e5426315665a2",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipulation can lead to os command injection. The attack may be performed from remote. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/GH05TCREW/pentestagent/",
                "https://github.com/GH05TCREW/pentestagent/issues/91",
                "https://github.com/GH05TCREW/pentestagent/pull/100",
                "https://vuldb.com/cve/CVE-2026-90618",
                "https://vuldb.com/submit/914809",
                "https://vuldb.com/vuln/403199",
                "https://vuldb.com/vuln/403199/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T03:16:37.263",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90618"
                }
            ]
        },
        {
            "id": "CVE-2026-90617",
            "vendor": "GH05TCREW",
            "product": "PentestAgent",
            "title": "PentestAgent vulnerability",
            "summary": "A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerability affects the function run_task of the file interface/main.py of the component MCP HTTP Server. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The pull request to fix this issue awaits acceptance.",
            "updated_at": "2026-09-14T03:16:37.083",
            "published_at": "2026-09-14T03:16:37.083",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "cf882dabea3ed91cef016cdd115e5426315665a2",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerability affects the function run_task of the file interface/main.py of the component MCP HTTP Server. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The pull request to fix this issue awaits acceptance.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/GH05TCREW/pentestagent/",
                "https://github.com/GH05TCREW/pentestagent/issues/90",
                "https://github.com/GH05TCREW/pentestagent/pull/101",
                "https://vuldb.com/cve/CVE-2026-90617",
                "https://vuldb.com/submit/914808",
                "https://vuldb.com/vuln/403198",
                "https://vuldb.com/vuln/403198/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T03:16:37.083",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90617"
                }
            ]
        },
        {
            "id": "CVE-2026-90616",
            "vendor": "Flatpak",
            "product": "Flatpak",
            "title": "Flatpak vulnerability",
            "summary": "In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app data directories (e.g., /var/cache, /var/data, /var/config, and /var/tmp) in every sandbox on every app launch where, in some cases, components of the path are attacker-controlled. Missing symlink protection can redirect the directories. Some of these directories are bind-mounted by Flatpak by passing the path (e.g., /home/user/.var/app/APP_ID/cache/tmp), which contains attacker-controlled directories (tmp) to bwrap --bind SRC DST. bwrap passes the path on to the kernel, which then follows symlinks. A malicious symlink can point to arbitrary locations on the host and it will become mounted inside the sandbox.",
            "updated_at": "2026-09-12T20:16:30.957",
            "published_at": "2026-09-12T20:16:30.957",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.18.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-61",
            "what_happened": "In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app data directories (e.g., /var/cache, /var/data, /var/config, and /var/tmp) in every sandbox on every app launch where, in some cases, components of the path are attacker-controlled. Missing symlink protection can redirect the directories. Some of these directories are bind-mounted by Flatpak by passing the path (e.g., /home/user/.var/app/APP_ID/cache/tmp), which contains attacker-controlled directories (tmp) to bwrap --bind SRC DST. bwrap passes the path on to the kernel, which then follows symlinks. A malicious symlink can point to arbitrary locations on the host and it will become mounted inside the sandbox.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj",
                "https://www.openwall.com/lists/oss-security/2026/08/11/9"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T20:16:30.957",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90616"
                }
            ]
        },
        {
            "id": "CVE-2026-90615",
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System",
            "title": "Class and Exam Timetabling System vulnerability",
            "summary": "A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.",
            "updated_at": "2026-09-14T02:17:16.030",
            "published_at": "2026-09-14T02:17:16.030",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/endingstory/e/issues/2",
                "https://vuldb.com/cve/CVE-2026-90615",
                "https://vuldb.com/submit/914719",
                "https://vuldb.com/vuln/403197",
                "https://vuldb.com/vuln/403197/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:16.030",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90615"
                }
            ]
        },
        {
            "id": "CVE-2026-90614",
            "vendor": "FedML-AI",
            "product": "FedML",
            "title": "FedML vulnerability",
            "summary": "A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-14T02:17:15.857",
            "published_at": "2026-09-14T02:17:15.857",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.9.0; 0.9.1; 0.9.2; 0.9.3; 0.9.4; 0.9.5; 0.9.6",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backend. This manipulation of the argument s3_key_str causes deserialization. Remote exploitation of the attack is possible. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/FedML-AI/FedML/",
                "https://github.com/FedML-AI/FedML/issues/2267",
                "https://vuldb.com/cve/CVE-2026-90614",
                "https://vuldb.com/submit/914219",
                "https://vuldb.com/vuln/403196",
                "https://vuldb.com/vuln/403196/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:15.857",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90614"
                }
            ]
        },
        {
            "id": "CVE-2026-90613",
            "vendor": "n/a",
            "product": "GPAC",
            "title": "GPAC vulnerability",
            "summary": "A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in reachable assertion. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. Upgrading to version abi-16.23 addresses this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component.",
            "updated_at": "2026-09-14T02:17:15.690",
            "published_at": "2026-09-14T02:17:15.690",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f1219cde",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-617",
            "what_happened": "A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in reachable assertion. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. Upgrading to version abi-16.23 addresses this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/gpac/gpac/",
                "https://github.com/gpac/gpac/commit/49dee5cad329cfed310c1682703df7daa47df31a",
                "https://github.com/gpac/gpac/issues/3822",
                "https://github.com/gpac/gpac/releases/tag/abi-16.23",
                "https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln-GPAC-MP4Box-Assertion-Failure-in-stbl-Handling.md",
                "https://vuldb.com/cve/CVE-2026-90613",
                "https://vuldb.com/submit/913520",
                "https://vuldb.com/vuln/403195",
                "https://vuldb.com/vuln/403195/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:15.690",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90613"
                }
            ]
        },
        {
            "id": "CVE-2026-90612",
            "vendor": "n/a",
            "product": "GPAC",
            "title": "GPAC vulnerability",
            "summary": "A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scene_manager/scene_dump.c of the component MP4Box. The manipulation leads to reachable assertion. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is able to address this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is advised.",
            "updated_at": "2026-09-14T02:17:15.533",
            "published_at": "2026-09-14T02:17:15.533",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f1219cde",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-617",
            "what_happened": "A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scene_manager/scene_dump.c of the component MP4Box. The manipulation leads to reachable assertion. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is able to address this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is advised.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/gpac/gpac/",
                "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
                "https://github.com/gpac/gpac/issues/3821",
                "https://github.com/gpac/gpac/releases/tag/abi-16.23",
                "https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln-GPAC-MP4Box-Assertion-Failure-in-scene-dump-(sdump-current_com_list).md",
                "https://vuldb.com/cve/CVE-2026-90612",
                "https://vuldb.com/submit/913519",
                "https://vuldb.com/vuln/403194",
                "https://vuldb.com/vuln/403194/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:15.533",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90612"
                }
            ]
        },
        {
            "id": "CVE-2026-90611",
            "vendor": "n/a",
            "product": "GPAC",
            "title": "GPAC vulnerability",
            "summary": "A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manager/loader_xmt.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 will fix this issue. This patch is called afca1f1181668d85941d51ed1adf647807d5d975. It is recommended to upgrade the affected component.",
            "updated_at": "2026-09-14T02:17:15.357",
            "published_at": "2026-09-14T02:17:15.357",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f1219cde",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-617",
            "what_happened": "A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manager/loader_xmt.c of the component MP4Box. Executing a manipulation can lead to reachable assertion. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Upgrading to version abi-16.23 will fix this issue. This patch is called afca1f1181668d85941d51ed1adf647807d5d975. It is recommended to upgrade the affected component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/gpac/gpac/",
                "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
                "https://github.com/gpac/gpac/issues/3820",
                "https://github.com/gpac/gpac/releases/tag/abi-16.23",
                "https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln-GPAC-MP4Box-Assertion-Failure-in-xmt_parse_element.md",
                "https://vuldb.com/cve/CVE-2026-90611",
                "https://vuldb.com/submit/913517",
                "https://vuldb.com/vuln/403193",
                "https://vuldb.com/vuln/403193/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:15.357",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90611"
                }
            ]
        },
        {
            "id": "CVE-2026-90610",
            "vendor": "n/a",
            "product": "GPAC",
            "title": "GPAC vulnerability",
            "summary": "A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 mitigates this issue. The patch is named afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is recommended.",
            "updated_at": "2026-09-14T02:17:15.150",
            "published_at": "2026-09-14T02:17:15.150",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f1219cde",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 mitigates this issue. The patch is named afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is recommended.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/gpac/gpac/",
                "https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975",
                "https://github.com/gpac/gpac/issues/3819",
                "https://github.com/gpac/gpac/releases/tag/abi-16.23",
                "https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln%20GPAC%20MP4Box%20Heap-Buffer-Overflow%20READ%20size%2020%20in%20gf_svg_attributes_copy.md",
                "https://vuldb.com/cve/CVE-2026-90610",
                "https://vuldb.com/submit/913516",
                "https://vuldb.com/vuln/403192",
                "https://vuldb.com/vuln/403192/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:15.150",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90610"
                }
            ]
        },
        {
            "id": "CVE-2026-90609",
            "vendor": "n/a",
            "product": "GPAC",
            "title": "GPAC vulnerability",
            "summary": "A vulnerability has been found in GPAC up to f1219cde. The impacted element is an unknown function of the file scenegraph/vrml_tools.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 is sufficient to resolve this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.",
            "updated_at": "2026-09-14T01:16:28.360",
            "published_at": "2026-09-14T01:16:28.360",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f1219cde",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-404",
            "what_happened": "A vulnerability has been found in GPAC up to f1219cde. The impacted element is an unknown function of the file scenegraph/vrml_tools.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 is sufficient to resolve this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/gpac/gpac/",
                "https://github.com/gpac/gpac/commit/49dee5cad329cfed310c1682703df7daa47df31a",
                "https://github.com/gpac/gpac/issues/3818",
                "https://github.com/gpac/gpac/releases/tag/abi-16.23",
                "https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln-GPAC-MP4Box-NULL-Pointer-Dereference-in-gf_node_set_cyclic_traverse_flag.md",
                "https://vuldb.com/cve/CVE-2026-90609",
                "https://vuldb.com/submit/913514",
                "https://vuldb.com/vuln/403191",
                "https://vuldb.com/vuln/403191/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T01:16:28.360",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90609"
                }
            ]
        },
        {
            "id": "CVE-2026-90608",
            "vendor": "Totolink",
            "product": "A3002MU",
            "title": "A3002MU vulnerability",
            "summary": "A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.",
            "updated_at": "2026-09-14T01:16:28.130",
            "published_at": "2026-09-14T01:16:28.130",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Hh-B20211125.1046",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3002MU/bof-formPortFw.md",
                "https://vuldb.com/cve/CVE-2026-90608",
                "https://vuldb.com/submit/914016",
                "https://vuldb.com/vuln/403190",
                "https://vuldb.com/vuln/403190/cti",
                "https://www.totolink.net/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T01:16:28.130",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90608"
                }
            ]
        },
        {
            "id": "CVE-2026-90607",
            "vendor": "Totolink",
            "product": "A3002MU",
            "title": "A3002MU vulnerability",
            "summary": "A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.",
            "updated_at": "2026-09-14T01:16:27.870",
            "published_at": "2026-09-14T01:16:27.870",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Hh-B20211125.1046",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3002MU/bof-formNewSchedule.md",
                "https://vuldb.com/cve/CVE-2026-90607",
                "https://vuldb.com/submit/914015",
                "https://vuldb.com/vuln/403189",
                "https://vuldb.com/vuln/403189/cti",
                "https://www.totolink.net/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T01:16:27.870",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90607"
                }
            ]
        },
        {
            "id": "CVE-2026-90606",
            "vendor": "Totolink",
            "product": "A3002MU",
            "title": "A3002MU vulnerability",
            "summary": "A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.",
            "updated_at": "2026-09-14T00:16:57.617",
            "published_at": "2026-09-14T00:16:57.617",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Hh-B20211125.1046",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3002MU/bof-formIpv6Setup.md",
                "https://vuldb.com/cve/CVE-2026-90606",
                "https://vuldb.com/submit/914010",
                "https://vuldb.com/vuln/403188",
                "https://vuldb.com/vuln/403188/cti",
                "https://www.totolink.net/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T00:16:57.617",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90606"
                }
            ]
        },
        {
            "id": "CVE-2026-90605",
            "vendor": "Totolink",
            "product": "A3002MU",
            "title": "A3002MU vulnerability",
            "summary": "A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.",
            "updated_at": "2026-09-14T00:16:57.447",
            "published_at": "2026-09-14T00:16:57.447",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Hh-B20211125.1046",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3002MU/bof-formFilter.md",
                "https://vuldb.com/cve/CVE-2026-90605",
                "https://vuldb.com/submit/914009",
                "https://vuldb.com/vuln/403187",
                "https://vuldb.com/vuln/403187/cti",
                "https://www.totolink.net/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T00:16:57.447",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90605"
                }
            ]
        },
        {
            "id": "CVE-2026-90604",
            "vendor": "Totolink",
            "product": "A3002MU",
            "title": "A3002MU vulnerability",
            "summary": "A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.",
            "updated_at": "2026-09-14T00:16:57.280",
            "published_at": "2026-09-14T00:16:57.280",
            "cvss": 2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Hh-B20211125.1046",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/ToTolink/A3002MU/XSS_A3002MU.md",
                "https://vuldb.com/cve/CVE-2026-90604",
                "https://vuldb.com/submit/914007",
                "https://vuldb.com/vuln/403186",
                "https://vuldb.com/vuln/403186/cti",
                "https://www.totolink.net/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T00:16:57.280",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90604"
                }
            ]
        },
        {
            "id": "CVE-2026-90603",
            "vendor": "Anil-matcha",
            "product": "Open-Generative-AI",
            "title": "Open-Generative-AI vulnerability",
            "summary": "A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch is advised to resolve this issue.",
            "updated_at": "2026-09-13T23:16:28.703",
            "published_at": "2026-09-13T23:16:28.703",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0; 1.0.1; 1.0.2; 1.0.3; 1.0.4; 1.0.5; 1.0.6; 1.0.7; 1.0.8; 1.0.9; 1.0.10; 1.0.11; 2.0",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch is advised to resolve this issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Anil-matcha/Open-Generative-AI/",
                "https://github.com/Anil-matcha/Open-Generative-AI/commit/f013270957f75e439eaf97eb2a93decb32a4543e",
                "https://github.com/Anil-matcha/Open-Generative-AI/issues/310",
                "https://vuldb.com/cve/CVE-2026-90603",
                "https://vuldb.com/submit/914005",
                "https://vuldb.com/vuln/403185",
                "https://vuldb.com/vuln/403185/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T23:16:28.703",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90603"
                }
            ]
        },
        {
            "id": "CVE-2026-90602",
            "vendor": "Anil-matcha",
            "product": "Open-Generative-AI",
            "title": "Open-Generative-AI vulnerability",
            "summary": "A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cross site scripting. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.",
            "updated_at": "2026-09-13T23:16:28.520",
            "published_at": "2026-09-13T23:16:28.520",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0; 1.0.1; 1.0.2; 1.0.3; 1.0.4; 1.0.5; 1.0.6; 1.0.7; 1.0.8; 1.0.9; 1.0.10; 1.0.11; 2.0",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cross site scripting. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Anil-matcha/Open-Generative-AI/",
                "https://github.com/Anil-matcha/Open-Generative-AI/issues/309",
                "https://github.com/Anil-matcha/Open-Generative-AI/pull/344",
                "https://vuldb.com/cve/CVE-2026-90602",
                "https://vuldb.com/submit/914004",
                "https://vuldb.com/vuln/403184",
                "https://vuldb.com/vuln/403184/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T23:16:28.520",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90602"
                }
            ]
        },
        {
            "id": "CVE-2026-90601",
            "vendor": "getzep",
            "product": "graphiti",
            "title": "graphiti vulnerability",
            "summary": "A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.",
            "updated_at": "2026-09-13T23:16:28.343",
            "published_at": "2026-09-13T23:16:28.343",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.30.0; 0.30.1; 0.30.2",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/getzep/graphiti/",
                "https://github.com/getzep/graphiti/issues/1716",
                "https://github.com/getzep/graphiti/pull/1739",
                "https://vuldb.com/cve/CVE-2026-90601",
                "https://vuldb.com/submit/913951",
                "https://vuldb.com/vuln/403183",
                "https://vuldb.com/vuln/403183/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T23:16:28.343",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90601"
                }
            ]
        },
        {
            "id": "CVE-2026-90600",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
            "updated_at": "2026-09-13T23:16:28.173",
            "published_at": "2026-09-13T23:16:28.173",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cheerhu/submit/issues/1",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-90600",
                "https://vuldb.com/submit/913798",
                "https://vuldb.com/vuln/403182",
                "https://vuldb.com/vuln/403182/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T23:16:28.173",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90600"
                }
            ]
        },
        {
            "id": "CVE-2026-90599",
            "vendor": "Rizwan17",
            "product": "inventory-management-system",
            "title": "inventory-management-system vulnerability",
            "summary": "A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been published and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T22:17:01.053",
            "published_at": "2026-09-13T22:17:01.053",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-352",
            "what_happened": "A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been published and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Rizwan17/inventory-management-system/",
                "https://github.com/Rizwan17/inventory-management-system/issues/17",
                "https://github.com/user-attachments/files/30648539/poc_idor_updateuser.py",
                "https://vuldb.com/cve/CVE-2026-90599",
                "https://vuldb.com/submit/913903",
                "https://vuldb.com/vuln/403181",
                "https://vuldb.com/vuln/403181/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T22:17:01.053",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90599"
                }
            ]
        },
        {
            "id": "CVE-2026-90598",
            "vendor": "jaygajera17",
            "product": "E-commerce-project-springBoot",
            "title": "E-commerce-project-springBoot vulnerability",
            "summary": "A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipulation of the argument userid results in authorization bypass. It is possible to initiate the attack remotely. The exploit is now public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The pull request to fix this issue awaits acceptance.",
            "updated_at": "2026-09-13T22:17:00.897",
            "published_at": "2026-09-13T22:17:00.897",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipulation of the argument userid results in authorization bypass. It is possible to initiate the attack remotely. The exploit is now public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The pull request to fix this issue awaits acceptance.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jaygajera17/E-commerce-project-springBoot/",
                "https://github.com/jaygajera17/E-commerce-project-springBoot/issues/172",
                "https://github.com/jaygajera17/E-commerce-project-springBoot/pull/174",
                "https://github.com/user-attachments/files/30648539/poc_idor_updateuser.py",
                "https://vuldb.com/cve/CVE-2026-90598",
                "https://vuldb.com/submit/913792",
                "https://vuldb.com/vuln/403180",
                "https://vuldb.com/vuln/403180/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T22:17:00.897",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90598"
                }
            ]
        },
        {
            "id": "CVE-2026-90597",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/sup_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.",
            "updated_at": "2026-09-13T22:17:00.737",
            "published_at": "2026-09-13T22:17:00.737",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/sup_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ltranquility/cve_submit/issues/25",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-90597",
                "https://vuldb.com/submit/913791",
                "https://vuldb.com/vuln/403179",
                "https://vuldb.com/vuln/403179/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T22:17:00.737",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90597"
                }
            ]
        },
        {
            "id": "CVE-2026-90596",
            "vendor": "n/a",
            "product": "embedded-graphics",
            "title": "embedded-graphics vulnerability",
            "summary": "A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the affected component is recommended. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T22:17:00.577",
            "published_at": "2026-09-13T22:17:00.577",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.8.0; 0.8.1; 0.8.2",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-189",
            "what_happened": "A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be carried out remotely. Upgrading the affected component is recommended. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/embedded-graphics/embedded-graphics/",
                "https://github.com/embedded-graphics/embedded-graphics/issues/820",
                "https://vuldb.com/cve/CVE-2026-90596",
                "https://vuldb.com/submit/913790",
                "https://vuldb.com/vuln/403178",
                "https://vuldb.com/vuln/403178/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T22:17:00.577",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90596"
                }
            ]
        },
        {
            "id": "CVE-2026-90595",
            "vendor": "wxiaoqi",
            "product": "Spring-Cloud-Platform",
            "title": "Spring-Cloud-Platform vulnerability",
            "summary": "A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T21:17:03.173",
            "published_at": "2026-09-13T21:17:03.173",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0; 2.2; 3.0",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/user-attachments/files/30627379/poc_vuln2_session_exposure.zip",
                "https://github.com/wxiaoqi/Spring-Cloud-Platform/",
                "https://github.com/wxiaoqi/Spring-Cloud-Platform/issues/65",
                "https://vuldb.com/cve/CVE-2026-90595",
                "https://vuldb.com/submit/913789",
                "https://vuldb.com/vuln/403177",
                "https://vuldb.com/vuln/403177/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:17:03.173",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90595"
                }
            ]
        },
        {
            "id": "CVE-2026-90594",
            "vendor": "wxiaoqi",
            "product": "Spring-Cloud-Platform",
            "title": "Spring-Cloud-Platform vulnerability",
            "summary": "A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Service. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T21:17:02.980",
            "published_at": "2026-09-13T21:17:02.980",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.0.1; 3.1.0",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Service. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/user-attachments/files/30627348/poc_vuln1_failopen_authz.zip",
                "https://github.com/wxiaoqi/Spring-Cloud-Platform/",
                "https://github.com/wxiaoqi/Spring-Cloud-Platform/issues/64",
                "https://vuldb.com/cve/CVE-2026-90594",
                "https://vuldb.com/submit/913788",
                "https://vuldb.com/vuln/403176",
                "https://vuldb.com/vuln/403176/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:17:02.980",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90594"
                }
            ]
        },
        {
            "id": "CVE-2026-90593",
            "vendor": "n/a",
            "product": "embedded-graphics",
            "title": "embedded-graphics vulnerability",
            "summary": "A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T21:17:02.787",
            "published_at": "2026-09-13T21:17:02.787",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.8.0; 0.8.1; 0.8.2",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-189",
            "what_happened": "A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/embedded-graphics/embedded-graphics/",
                "https://github.com/embedded-graphics/embedded-graphics/issues/821",
                "https://vuldb.com/cve/CVE-2026-90593",
                "https://vuldb.com/submit/913787",
                "https://vuldb.com/vuln/403175",
                "https://vuldb.com/vuln/403175/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:17:02.787",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90593"
                }
            ]
        },
        {
            "id": "CVE-2026-90584",
            "vendor": "TooTallNate",
            "product": "Java-WebSocket",
            "title": "Java-WebSocket vulnerability",
            "summary": "A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentation Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance.",
            "updated_at": "2026-09-13T21:17:02.603",
            "published_at": "2026-09-13T21:17:02.603",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.6.0; 1.6.1",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentation Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The pull request to fix this issue awaits acceptance.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/TooTallNate/Java-WebSocket/",
                "https://github.com/TooTallNate/Java-WebSocket/issues/1508",
                "https://github.com/TooTallNate/Java-WebSocket/pull/1509",
                "https://vuldb.com/cve/CVE-2026-90584",
                "https://vuldb.com/submit/913786",
                "https://vuldb.com/vuln/403169",
                "https://vuldb.com/vuln/403169/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:17:02.603",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90584"
                }
            ]
        },
        {
            "id": "CVE-2026-90583",
            "vendor": "kagisearch",
            "product": "smallweb",
            "title": "smallweb vulnerability",
            "summary": "A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulation of the argument qs results in cross site scripting. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The patch is named 00b68144e583f20a6b67e29cf01bc07f57979ffb. It is recommended to apply a patch to fix this issue. Exploitability requires a raw HTTP request carrying unencoded double-quote characters in the query string - Werkzeug's request.query_string returns the raw request-target, and ordinary browsers percent-encode \" as %22, so the payload only lands via netcat/curl-style raw sockets.",
            "updated_at": "2026-09-13T20:16:51.837",
            "published_at": "2026-09-13T20:16:51.837",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0ecb9c48edbf98dc7e934b54fbac43869e64b4cf",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulation of the argument qs results in cross site scripting. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The patch is named 00b68144e583f20a6b67e29cf01bc07f57979ffb. It is recommended to apply a patch to fix this issue. Exploitability requires a raw HTTP request carrying unencoded double-quote characters in the query string - Werkzeug's request.query_string returns the raw request-target, and ordinary browsers percent-encode \" as %22, so the payload only lands via netcat/curl-style raw sockets.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/kagisearch/smallweb/",
                "https://github.com/kagisearch/smallweb/commit/00b68144e583f20a6b67e29cf01bc07f57979ffb",
                "https://github.com/kagisearch/smallweb/issues/854",
                "https://vuldb.com/cve/CVE-2026-90583",
                "https://vuldb.com/submit/913779",
                "https://vuldb.com/vuln/403168",
                "https://vuldb.com/vuln/403168/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T20:16:51.837",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90583"
                }
            ]
        },
        {
            "id": "CVE-2026-90582",
            "vendor": "evanchiu",
            "product": "serverless-todo",
            "title": "serverless-todo vulnerability",
            "summary": "A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consumption. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T20:16:51.660",
            "published_at": "2026-09-13T20:16:51.660",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.3; 2.0.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consumption. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/evanchiu/serverless-todo/",
                "https://github.com/evanchiu/serverless-todo/issues/10",
                "https://vuldb.com/cve/CVE-2026-90582",
                "https://vuldb.com/submit/913598",
                "https://vuldb.com/vuln/403167",
                "https://vuldb.com/vuln/403167/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T20:16:51.660",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90582"
                }
            ]
        },
        {
            "id": "CVE-2026-90581",
            "vendor": "cym1102",
            "product": "nginxWebUI",
            "title": "nginxWebUI vulnerability",
            "summary": "A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.",
            "updated_at": "2026-09-13T20:16:51.487",
            "published_at": "2026-09-13T20:16:51.487",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.4.0; 4.4.1; 4.4.2",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The pull request to fix this issue awaits acceptance.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cym1102/nginxWebUI/",
                "https://github.com/cym1102/nginxWebUI/issues/213",
                "https://github.com/cym1102/nginxWebUI/pull/215",
                "https://vuldb.com/cve/CVE-2026-90581",
                "https://vuldb.com/submit/913328",
                "https://vuldb.com/vuln/403166",
                "https://vuldb.com/vuln/403166/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T20:16:51.487",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90581"
                }
            ]
        },
        {
            "id": "CVE-2026-90580",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarded-Proto results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 3.1.3 is able to resolve this issue. The patch is identified as 700137738bcaebefd4709021f6d6b0abcd7df0ac. It is recommended to upgrade the affected component. This vulnerability only affects products that are no longer supported by the maintainer.",
            "updated_at": "2026-09-13T20:16:51.317",
            "published_at": "2026-09-13T20:16:51.317",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.0.0; 3.0.1; 3.0.2",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarded-Proto results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 3.1.3 is able to resolve this issue. The patch is identified as 700137738bcaebefd4709021f6d6b0abcd7df0ac. It is recommended to upgrade the affected component. This vulnerability only affects products that are no longer supported by the maintainer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/FlowiseAI/Flowise/",
                "https://github.com/FlowiseAI/Flowise/commit/700137738bcaebefd4709021f6d6b0abcd7df0ac",
                "https://github.com/FlowiseAI/Flowise/issues/6687",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.1.3",
                "https://vuldb.com/cve/CVE-2026-90580",
                "https://vuldb.com/submit/913327",
                "https://vuldb.com/vuln/403165",
                "https://vuldb.com/vuln/403165/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T20:16:51.317",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90580"
                }
            ]
        },
        {
            "id": "CVE-2026-90579",
            "vendor": "cheshire-cat-ai",
            "product": "Cheshire Cat AI",
            "title": "Cheshire Cat AI vulnerability",
            "summary": "A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T19:16:53.517",
            "published_at": "2026-09-13T19:16:53.517",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.9.0; 1.9.1; 1.9.2",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cheshire-cat-ai/core/issues/1137",
                "https://vuldb.com/cve/CVE-2026-90579",
                "https://vuldb.com/submit/913219",
                "https://vuldb.com/vuln/403164",
                "https://vuldb.com/vuln/403164/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T19:16:53.517",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90579"
                }
            ]
        },
        {
            "id": "CVE-2026-90578",
            "vendor": "n/a",
            "product": "GPAC",
            "title": "GPAC vulnerability",
            "summary": "A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack is restricted to local execution. The exploit has been published and may be used. Upgrading to version abi-16.23 can resolve this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.",
            "updated_at": "2026-09-13T19:16:53.350",
            "published_at": "2026-09-13T19:16:53.350",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f1219cde",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack is restricted to local execution. The exploit has been published and may be used. Upgrading to version abi-16.23 can resolve this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/gpac/gpac/",
                "https://github.com/gpac/gpac/commit/49dee5cad329cfed310c1682703df7daa47df31a",
                "https://github.com/gpac/gpac/issues/3817",
                "https://github.com/gpac/gpac/releases/tag/abi-16.23",
                "https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln-GPAC-MP4Box-SEGV-in-gf_list_count-(Use-After-Free).md",
                "https://vuldb.com/cve/CVE-2026-90578",
                "https://vuldb.com/submit/913217",
                "https://vuldb.com/vuln/403163",
                "https://vuldb.com/vuln/403163/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T19:16:53.350",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90578"
                }
            ]
        },
        {
            "id": "CVE-2026-90577",
            "vendor": "n/a",
            "product": "GPAC",
            "title": "GPAC vulnerability",
            "summary": "A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version abi-16.23 addresses this issue. The patch is named 49dee5cad329cfed310c1682703df7daa47df31a. The affected component should be upgraded.",
            "updated_at": "2026-09-13T19:16:53.183",
            "published_at": "2026-09-13T19:16:53.183",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f1219cde",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffer overflow. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version abi-16.23 addresses this issue. The patch is named 49dee5cad329cfed310c1682703df7daa47df31a. The affected component should be upgraded.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/gpac/gpac/",
                "https://github.com/gpac/gpac/commit/49dee5cad329cfed310c1682703df7daa47df31a",
                "https://github.com/gpac/gpac/issues/3816",
                "https://github.com/gpac/gpac/releases/tag/abi-16.23",
                "https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln-GPAC-MP4Box-Heap-Buffer-Overflow-in-gf_node_get_field.md",
                "https://vuldb.com/cve/CVE-2026-90577",
                "https://vuldb.com/submit/913216",
                "https://vuldb.com/vuln/403162",
                "https://vuldb.com/vuln/403162/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T19:16:53.183",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90577"
                }
            ]
        },
        {
            "id": "CVE-2026-90576",
            "vendor": "n/a",
            "product": "GPAC",
            "title": "GPAC vulnerability",
            "summary": "A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. Upgrading to version abi-16.23 is able to address this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.",
            "updated_at": "2026-09-13T19:16:52.997",
            "published_at": "2026-09-13T19:16:52.997",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f1219cde",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-404",
            "what_happened": "A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. Upgrading to version abi-16.23 is able to address this issue. The name of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. You should upgrade the affected component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/gpac/gpac/",
                "https://github.com/gpac/gpac/commit/49dee5cad329cfed310c1682703df7daa47df31a",
                "https://github.com/gpac/gpac/issues/3815",
                "https://github.com/gpac/gpac/releases/tag/abi-16.23",
                "https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln-GPAC-MP4Box-gf_node_list_add_child-SEGV.md",
                "https://vuldb.com/cve/CVE-2026-90576",
                "https://vuldb.com/submit/913204",
                "https://vuldb.com/vuln/403161",
                "https://vuldb.com/vuln/403161/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T19:16:52.997",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90576"
                }
            ]
        },
        {
            "id": "CVE-2026-90575",
            "vendor": "PHPGurukul",
            "product": "Small CRM",
            "title": "Small CRM vulnerability",
            "summary": "A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks.",
            "updated_at": "2026-09-13T18:16:50.117",
            "published_at": "2026-09-13T18:16:50.117",
            "cvss": 2.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-20",
            "what_happened": "A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is said to be difficult. The exploit has been made available to the public and could be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/JdExploit/small-crm-login-unserialize",
                "https://phpgurukul.com/",
                "https://vuldb.com/cve/CVE-2026-90575",
                "https://vuldb.com/submit/913188",
                "https://vuldb.com/vuln/403160",
                "https://vuldb.com/vuln/403160/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:16:50.117",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90575"
                }
            ]
        },
        {
            "id": "CVE-2026-90574",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation of the argument firstname results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.",
            "updated_at": "2026-09-13T18:16:49.953",
            "published_at": "2026-09-13T18:16:49.953",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation of the argument firstname results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ltranquility/submit_repository/issues/13",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-90574",
                "https://vuldb.com/submit/913016",
                "https://vuldb.com/vuln/403159",
                "https://vuldb.com/vuln/403159/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:16:49.953",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90574"
                }
            ]
        },
        {
            "id": "CVE-2026-90573",
            "vendor": "n/a",
            "product": "GPAC",
            "title": "GPAC vulnerability",
            "summary": "A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. Upgrading to version abi-16.23 is sufficient to resolve this issue. The identifier of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is recommended to upgrade the affected component.",
            "updated_at": "2026-09-13T18:16:49.780",
            "published_at": "2026-09-13T18:16:49.780",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f1219cde",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-404",
            "what_happened": "A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. Upgrading to version abi-16.23 is sufficient to resolve this issue. The identifier of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is recommended to upgrade the affected component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/gpac/gpac/",
                "https://github.com/gpac/gpac/commit/49dee5cad329cfed310c1682703df7daa47df31a",
                "https://github.com/gpac/gpac/issues/3814",
                "https://github.com/gpac/gpac/releases/tag/abi-16.23",
                "https://github.com/r1ck9-2q/cve_summit/blob/main/Vuln-GPAC-MP4Box-gf_sg_mfurl_del-NULL-Pointer-Dereference.md",
                "https://vuldb.com/cve/CVE-2026-90573",
                "https://vuldb.com/submit/912814",
                "https://vuldb.com/vuln/403158",
                "https://vuldb.com/vuln/403158/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:16:49.780",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90573"
                }
            ]
        },
        {
            "id": "CVE-2026-90572",
            "vendor": "davenardella",
            "product": "snap7",
            "title": "snap7 vulnerability",
            "summary": "A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of the argument DataLen can lead to memory corruption. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T18:16:48.727",
            "published_at": "2026-09-13T18:16:48.727",
            "cvss": 2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.4.0; 1.4.1; 1.4.2; 1.4.3",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of the argument DataLen can lead to memory corruption. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/davenardella/snap7/",
                "https://github.com/davenardella/snap7/issues/30",
                "https://vuldb.com/cve/CVE-2026-90572",
                "https://vuldb.com/submit/912711",
                "https://vuldb.com/vuln/403157",
                "https://vuldb.com/vuln/403157/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:16:48.727",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90572"
                }
            ]
        },
        {
            "id": "CVE-2026-90571",
            "vendor": "Exrick",
            "product": "xmall",
            "title": "xmall vulnerability",
            "summary": "A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T17:16:58.157",
            "published_at": "2026-09-13T17:16:58.157",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "19e7917d5ed3bd2a2421a3a246ad494c133ba94c",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Exrick/xmall/",
                "https://github.com/Exrick/xmall/issues/104",
                "https://vuldb.com/cve/CVE-2026-90571",
                "https://vuldb.com/submit/912676",
                "https://vuldb.com/vuln/403156",
                "https://vuldb.com/vuln/403156/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T17:16:58.157",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90571"
                }
            ]
        },
        {
            "id": "CVE-2026-90570",
            "vendor": "linlinjava",
            "product": "litemall",
            "title": "litemall vulnerability",
            "summary": "A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Such manipulation of the argument detail leads to cross site scripting. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T17:16:57.987",
            "published_at": "2026-09-13T17:16:57.987",
            "cvss": 4.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.4.0; 1.5.0; 1.6.0; 1.7.0; 1.8.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Such manipulation of the argument detail leads to cross site scripting. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gitee.com/linlinjava/litemall/",
                "https://gitee.com/linlinjava/litemall/issues/IK5SVR",
                "https://vuldb.com/cve/CVE-2026-90570",
                "https://vuldb.com/submit/912674",
                "https://vuldb.com/vuln/403155",
                "https://vuldb.com/vuln/403155/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T17:16:57.987",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90570"
                }
            ]
        },
        {
            "id": "CVE-2026-90569",
            "vendor": "linlinjava",
            "product": "litemall",
            "title": "litemall vulnerability",
            "summary": "A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin Topic Handler. This manipulation causes cross site scripting. The attack may be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T17:16:57.820",
            "published_at": "2026-09-13T17:16:57.820",
            "cvss": 4.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.5.0; 1.6.0; 1.7.0; 1.8.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin Topic Handler. This manipulation causes cross site scripting. The attack may be initiated remotely. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gitee.com/linlinjava/litemall/",
                "https://gitee.com/linlinjava/litemall/issues/IK5SUU",
                "https://vuldb.com/cve/CVE-2026-90569",
                "https://vuldb.com/submit/912673",
                "https://vuldb.com/vuln/403154",
                "https://vuldb.com/vuln/403154/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T17:16:57.820",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90569"
                }
            ]
        },
        {
            "id": "CVE-2026-90568",
            "vendor": "moxi624",
            "product": "Mogu Blog v2",
            "title": "Mogu Blog v2 vulnerability",
            "summary": "A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of the argument sortName results in cross site scripting. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T17:16:56.773",
            "published_at": "2026-09-13T17:16:56.773",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0; 4.1; 4.2; 4.3; 4.4; 4.5; 5.0; 5.1; 5.2",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of the argument sortName results in cross site scripting. The attack can be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gitee.com/moxi159753/mogu_blog_v2/issues/IK5STW",
                "https://vuldb.com/cve/CVE-2026-90568",
                "https://vuldb.com/submit/912672",
                "https://vuldb.com/vuln/403153",
                "https://vuldb.com/vuln/403153/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T17:16:56.773",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90568"
                }
            ]
        },
        {
            "id": "CVE-2026-90567",
            "vendor": "quequnlong",
            "product": "shiyi-blog",
            "title": "shiyi-blog vulnerability",
            "summary": "A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross site scripting. The attack can be initiated remotely. The project was informed of the problem early through an issue report.",
            "updated_at": "2026-09-13T16:16:52.827",
            "published_at": "2026-09-13T16:16:52.827",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.2.0; 1.2.1",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross site scripting. The attack can be initiated remotely. The project was informed of the problem early through an issue report.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gitee.com/quequnlong/shiyi-blog/",
                "https://gitee.com/quequnlong/shiyi-blog/issues/IK5SPD",
                "https://vuldb.com/cve/CVE-2026-90567",
                "https://vuldb.com/submit/912671",
                "https://vuldb.com/vuln/403152",
                "https://vuldb.com/vuln/403152/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T16:16:52.827",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90567"
                }
            ]
        },
        {
            "id": "CVE-2026-90566",
            "vendor": "Rizwan17",
            "product": "inventory-management-system",
            "title": "inventory-management-system vulnerability",
            "summary": "A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T16:16:52.670",
            "published_at": "2026-09-13T16:16:52.670",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "bfe78a330d01bb26b9daec5dc9ecd5c77900e03f",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "http://github.com/Rizwan17/inventory-management-system/issues/16",
                "https://vuldb.com/cve/CVE-2026-90566",
                "https://vuldb.com/submit/912565",
                "https://vuldb.com/vuln/403151",
                "https://vuldb.com/vuln/403151/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T16:16:52.670",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90566"
                }
            ]
        },
        {
            "id": "CVE-2026-90565",
            "vendor": "Rizwan17",
            "product": "inventory-management-system",
            "title": "inventory-management-system vulnerability",
            "summary": "A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T16:16:52.507",
            "published_at": "2026-09-13T16:16:52.507",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "bfe78a330d01bb26b9daec5dc9ecd5c77900e03f",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Rizwan17/inventory-management-system/",
                "https://github.com/Rizwan17/inventory-management-system/issues/15",
                "https://vuldb.com/cve/CVE-2026-90565",
                "https://vuldb.com/submit/912564",
                "https://vuldb.com/vuln/403150",
                "https://vuldb.com/vuln/403150/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T16:16:52.507",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90565"
                }
            ]
        },
        {
            "id": "CVE-2026-90564",
            "vendor": "quequnlong",
            "product": "shiyi-blog",
            "title": "shiyi-blog vulnerability",
            "summary": "A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMsgList of the file blog-web/src/views/chat/index.vue of the component chat sendMsg Endpoint. Such manipulation of the argument chat_msg leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T16:16:51.673",
            "published_at": "2026-09-13T16:16:51.673",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0-1.2.1",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMsgList of the file blog-web/src/views/chat/index.vue of the component chat sendMsg Endpoint. Such manipulation of the argument chat_msg leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gitee.com/quequnlong/shiyi-blog/",
                "https://gitee.com/quequnlong/shiyi-blog/issues/IK5RVL",
                "https://vuldb.com/cve/CVE-2026-90564",
                "https://vuldb.com/submit/912553",
                "https://vuldb.com/vuln/403149",
                "https://vuldb.com/vuln/403149/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T16:16:51.673",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90564"
                }
            ]
        },
        {
            "id": "CVE-2026-90563",
            "vendor": "maliangnansheng",
            "product": "bbs-springboot",
            "title": "bbs-springboot vulnerability",
            "summary": "A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the file ArticleController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely.",
            "updated_at": "2026-09-13T15:16:28.990",
            "published_at": "2026-09-13T15:16:28.990",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.0.0",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the file ArticleController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/maliangnansheng/bbs-springboot/",
                "https://github.com/maliangnansheng/bbs-springboot/issues/38",
                "https://github.com/maliangnansheng/bbs-vue3-ui/pull/2",
                "https://vuldb.com/cve/CVE-2026-90563",
                "https://vuldb.com/submit/912549",
                "https://vuldb.com/vuln/403148",
                "https://vuldb.com/vuln/403148/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T15:16:28.990",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90563"
                }
            ]
        },
        {
            "id": "CVE-2026-90562",
            "vendor": "langbot-app",
            "product": "LangBot",
            "title": "LangBot vulnerability",
            "summary": "LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.",
            "updated_at": "2026-09-13T11:17:00.780",
            "published_at": "2026-09-13T11:17:00.780",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.8.1 through before 4.10.11 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-331",
            "what_happened": "LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the admin password and gain account access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/langbot-app/LangBot",
                "https://github.com/langbot-app/LangBot/blob/v4.10.2/src/langbot/pkg/api/http/controller/groups/user.py",
                "https://github.com/langbot-app/LangBot/blob/v4.10.2/src/langbot/pkg/core/stages/genkeys.py",
                "https://github.com/langbot-app/LangBot/commit/267232c24f93c515d6fd3f7f81c0676066ab1ab8",
                "https://github.com/langbot-app/LangBot/issues/2392",
                "https://www.vulncheck.com/advisories/langbot-before-4.10.11-authentication-bypass-via-weak-recovery-key"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T11:17:00.780",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90562"
                }
            ]
        },
        {
            "id": "CVE-2026-90561",
            "vendor": "strapi",
            "product": "strapi",
            "title": "strapi vulnerability",
            "summary": "Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields that execute in an Editor or Super Admin's session when the preview pane is expanded, enabling account takeover.",
            "updated_at": "2026-09-13T11:17:00.613",
            "published_at": "2026-09-13T11:17:00.613",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through 4.26.2 (semver); 5.0.0 through before 5.48.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields that execute in an Editor or Super Admin's session when the preview pane is expanded, enabling account takeover.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/strapi/strapi",
                "https://github.com/strapi/strapi/blob/v5.46.0/packages/core/content-manager/admin/src/pages/EditView/components/FormInputs/Wysiwyg/PreviewWysiwyg.tsx",
                "https://github.com/strapi/strapi/commit/875752612c30f951546904a29469e51e17e0ac37",
                "https://github.com/strapi/strapi/issues/26857",
                "https://www.vulncheck.com/advisories/strapi-4-x-through-4.26.2-and-5-x-before-5.48.1-stored-xss-via-wysiwyg"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T11:17:00.613",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90561"
                }
            ]
        },
        {
            "id": "CVE-2026-90560",
            "vendor": "luben",
            "product": "zstd-jni",
            "title": "zstd-jni vulnerability",
            "summary": "zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.",
            "updated_at": "2026-09-12T18:16:44.890",
            "published_at": "2026-09-12T18:16:44.890",
            "cvss": 8.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.2.0 through before 1.5.7-14 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/luben/zstd-jni",
                "https://github.com/luben/zstd-jni/blob/v1.2.0/src/main/java/com/github/luben/zstd/ZstdDictDecompress.java#L37",
                "https://github.com/luben/zstd-jni/blob/v1.5.7-13/src/main/java/com/github/luben/zstd/ZstdDictDecompress.java#L49",
                "https://github.com/luben/zstd-jni/commit/b74ab242d640c40897e62aab4c744ddfad1f915f",
                "https://github.com/luben/zstd-jni/issues/405",
                "https://github.com/luben/zstd-jni/releases/tag/v1.5.7-14",
                "https://www.vulncheck.com/advisories/zstd-jni-1.2.0-through-1.5.7-13-out-of-bounds-read-via-zstddictdecompress"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T18:16:44.890",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90560"
                }
            ]
        },
        {
            "id": "CVE-2026-90559",
            "vendor": "xerial",
            "product": "snappy-java",
            "title": "snappy-java vulnerability",
            "summary": "snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data that decompresses larger than the destination buffer, causing writes past buffer boundaries and JVM termination.",
            "updated_at": "2026-09-12T18:16:44.743",
            "published_at": "2026-09-12T18:16:44.743",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.1.10.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supply valid compressed data that decompresses larger than the destination buffer, causing writes past buffer boundaries and JVM termination.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/xerial/snappy-java",
                "https://github.com/xerial/snappy-java/blob/v1.1.10.8/src/main/java/org/xerial/snappy/Snappy.java#L561",
                "https://github.com/xerial/snappy-java/issues/728",
                "https://www.vulncheck.com/advisories/snappy-java-through-1.1.10.8-out-of-bounds-write-via-uncompress"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T18:16:44.743",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90559"
                }
            ]
        },
        {
            "id": "CVE-2026-90558",
            "vendor": "irontec",
            "product": "sngrep",
            "title": "sngrep vulnerability",
            "summary": "sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.",
            "updated_at": "2026-09-12T18:16:44.587",
            "published_at": "2026-09-12T18:16:44.587",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.8.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-ID, X-Call-ID, or other header fields to overflow stack buffers and cause crashes or execute arbitrary code during packet parsing and rendering.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/irontec/sngrep",
                "https://github.com/irontec/sngrep/blob/v1.8.4/src/sip_call.c#L260",
                "https://github.com/irontec/sngrep/blob/v1.8.4/src/sip_msg.c#L150",
                "https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b",
                "https://www.vulncheck.com/advisories/sngrep-through-1.8.4-stack-buffer-overflow-via-sip-headers"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T18:16:44.587",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90558"
                }
            ]
        },
        {
            "id": "CVE-2026-90557",
            "vendor": "freeciv",
            "product": "freeciv",
            "title": "freeciv vulnerability",
            "summary": "Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.",
            "updated_at": "2026-09-12T18:16:44.343",
            "published_at": "2026-09-12T18:16:44.343",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.1.0 through before 3.2.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file with an out-of-range activity index that bypasses bounds checking and causes a crash or limited heap memory exposure when loaded.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/freeciv/freeciv",
                "https://github.com/freeciv/freeciv/blob/R3_2_5/server/savegame/savegame2.c#L4282",
                "https://github.com/freeciv/freeciv/blob/R3_2_5/server/savegame/savegame3.c#L6108",
                "https://github.com/freeciv/freeciv/commit/ef0c76c2765fe383140eb1a70dbea1228844152e",
                "https://github.com/freeciv/freeciv/releases/tag/R3_2_6",
                "https://redmine.freeciv.org/issues/2162",
                "https://www.vulncheck.com/advisories/freeciv-3.1.0-through-3.2.5-out-of-bounds-read-via-savegame"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T18:16:44.343",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90557"
                }
            ]
        },
        {
            "id": "CVE-2026-90556",
            "vendor": "freeciv",
            "product": "freeciv",
            "title": "freeciv vulnerability",
            "summary": "Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.",
            "updated_at": "2026-09-12T18:16:44.193",
            "published_at": "2026-09-12T18:16:44.193",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.2.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/freeciv/freeciv",
                "https://github.com/freeciv/freeciv/blob/R3_2_5/server/savegame/savegame2.c#L788",
                "https://github.com/freeciv/freeciv/blob/R3_2_5/server/savegame/savegame3.c#L964",
                "https://github.com/freeciv/freeciv/commit/75ecde3e86ddf2fe775768450e9a290a4f4d4387",
                "https://github.com/freeciv/freeciv/releases/tag/R3_2_6",
                "https://redmine.freeciv.org/issues/2161",
                "https://www.vulncheck.com/advisories/freeciv-before-3.2.6-heap-buffer-overflow-via-worklist-load"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T18:16:44.193",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90556"
                }
            ]
        },
        {
            "id": "CVE-2026-90555",
            "vendor": "vllm-project",
            "product": "vLLM",
            "title": "vLLM vulnerability",
            "summary": "vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.",
            "updated_at": "2026-09-12T13:16:54.180",
            "published_at": "2026-09-12T13:16:54.180",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.28.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-409",
            "what_happened": "vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sample rates to trigger excessive memory allocation and crash the API server process affecting all tenants.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/vllm-project/vllm/security/advisories/GHSA-99f2-hwrc-gvq8",
                "https://www.vulncheck.com/advisories/vllm-before-0.28.0-denial-of-service-via-audio-header"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:54.180",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90555"
                }
            ]
        },
        {
            "id": "CVE-2026-90554",
            "vendor": "vllm-project",
            "product": "vLLM",
            "title": "vLLM vulnerability",
            "summary": "vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models. In nano_nemotron_vl.py, _extract_audio_from_videos calls load_audio_pyav(BytesIO(video_bytes)) without the max_duration_s or max_decode_bytes parameters, so neither VLLM_MAX_AUDIO_DECODE_DURATION_S nor VLLM_MAX_AUDIO_DECODE_BYTES is enforced (unlike the direct audio upload path in AudioMediaIO). When a NanoNemotronVL model is served with use_audio_in_video=True, an attacker who supplies a small, highly compressed video as multimodal input can force the server to allocate gigabytes of memory during audio decoding, resulting in a denial of service. Fixed in vLLM 0.28.0.",
            "updated_at": "2026-09-12T13:16:54.040",
            "published_at": "2026-09-12T13:16:54.040",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.10.2 through before 0.28.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models. In nano_nemotron_vl.py, _extract_audio_from_videos calls load_audio_pyav(BytesIO(video_bytes)) without the max_duration_s or max_decode_bytes parameters, so neither VLLM_MAX_AUDIO_DECODE_DURATION_S nor VLLM_MAX_AUDIO_DECODE_BYTES is enforced (unlike the direct audio upload path in AudioMediaIO). When a NanoNemotronVL model is served with use_audio_in_video=True, an attacker who supplies a small, highly compressed video as multimodal input can force the server to allocate gigabytes of memory during audio decoding, resulting in a denial of service. Fixed in vLLM 0.28.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/vllm-project/vllm/security/advisories/GHSA-936p-m5pv-vvjf",
                "https://www.vulncheck.com/advisories/vllm-before-0.28.0-denial-of-service-via-audio-extraction"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:54.040",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90554"
                }
            ]
        },
        {
            "id": "CVE-2026-90553",
            "vendor": "vllm-project",
            "product": "vLLM",
            "title": "vLLM vulnerability",
            "summary": "vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.",
            "updated_at": "2026-09-12T13:16:53.887",
            "published_at": "2026-09-12T13:16:53.887",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.28.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vLLM process authority even when trust_remote_code is set to False.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/vllm-project/vllm/security/advisories/GHSA-3c86-2m5g-59q7",
                "https://www.vulncheck.com/advisories/vllm-before-0.28.0-remote-code-execution-via-llavaonevision2-processor"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:53.887",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90553"
                }
            ]
        },
        {
            "id": "CVE-2026-90552",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to read private playlist schedule metadata. Attackers with canStream privileges or no authentication can retrieve schedule names, descriptions, timestamps, and playlist identifiers by querying these endpoints without ownership checks.",
            "updated_at": "2026-09-12T13:16:53.747",
            "published_at": "2026-09-12T13:16:53.747",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to read private playlist schedule metadata. Attackers with canStream privileges or no authentication can retrieve schedule names, descriptions, timestamps, and playlist identifiers by querying these endpoints without ownership checks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-f4q2-49rm-rxh7",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-via-playlists-schedules-list-json-php"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:53.747",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90552"
                }
            ]
        },
        {
            "id": "CVE-2026-90551",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist contents. Attackers can query the API without authentication to enumerate private playlist names, owner information, and video titles including password-protected content.",
            "updated_at": "2026-09-12T13:16:53.603",
            "published_at": "2026-09-12T13:16:53.603",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist contents. Attackers can query the API without authentication to enumerate private playlist names, owner information, and video titles including password-protected content.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-7h47-x3h5-c8xq",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-via-video-from-program-api"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:53.603",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90551"
                }
            ]
        },
        {
            "id": "CVE-2026-90550",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata. Unauthenticated attackers can request the endpoint with a video ID parameter to retrieve password-protected video titles and owner email addresses without authentication.",
            "updated_at": "2026-09-12T13:16:53.467",
            "published_at": "2026-09-12T13:16:53.467",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata. Unauthenticated attackers can request the endpoint with a video ID parameter to retrieve password-protected video titles and owner email addresses without authentication.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-g79r-wg9m-3fh3",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-via-mediasession-json-php"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:53.467",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90550"
                }
            ]
        },
        {
            "id": "CVE-2026-90549",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with sensitive owner information. Attackers can retrieve video metadata including owner email, lastLogin, filename, and hashId by sending an unauthenticated GET request to the endpoint.",
            "updated_at": "2026-09-12T13:16:53.320",
            "published_at": "2026-09-12T13:16:53.320",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with sensitive owner information. Attackers can retrieve video metadata including owner email, lastLogin, filename, and hashId by sending an unauthenticated GET request to the endpoint.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-frrh-5hwx-jggr",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-via-videosandroid-json-php-endpoint"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:53.320",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90549"
                }
            ]
        },
        {
            "id": "CVE-2026-90548",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can retrieve filenames and URLs of password-protected image galleries by directly accessing the endpoint, then fetch the exposed files without authentication.",
            "updated_at": "2026-09-12T13:16:53.187",
            "published_at": "2026-09-12T13:16:53.187",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can retrieve filenames and URLs of password-protected image galleries by directly accessing the endpoint, then fetch the exposed files without authentication.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-vr35-39vf-9qp9",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-in-imagegallery-list-json-php"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:53.187",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90548"
                }
            ]
        },
        {
            "id": "CVE-2026-90547",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to read chapter names from password-protected videos. Attackers can query the endpoint with a video ID parameter to retrieve sensitive chapter metadata without authentication or password verification.",
            "updated_at": "2026-09-12T13:16:53.050",
            "published_at": "2026-09-12T13:16:53.050",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to read chapter names from password-protected videos. Attackers can query the endpoint with a video ID parameter to retrieve sensitive chapter metadata without authentication or password verification.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-xv29-q875-59jq",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-via-getbookmarks-json-php"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:53.050",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90547"
                }
            ]
        },
        {
            "id": "CVE-2026-90546",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos. Attackers can submit like requests for videos they cannot watch to increment like counters and bypass access controls.",
            "updated_at": "2026-09-12T13:16:52.913",
            "published_at": "2026-09-12T13:16:52.913",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos. Attackers can submit like requests for videos they cannot watch to increment like counters and bypass access controls.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-5jgf-mc35-5wg5",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-via-like-json-php"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:52.913",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90546"
                }
            ]
        },
        {
            "id": "CVE-2026-90545",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers can submit POST requests with a valid session to add comments to videos they cannot watch, bypassing password and group access controls.",
            "updated_at": "2026-09-12T13:16:52.777",
            "published_at": "2026-09-12T13:16:52.777",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers can submit POST requests with a valid session to add comments to videos they cannot watch, bypassing password and group access controls.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-v3p2-4x76-7p8v",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-via-commentaddnew-json-php"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:52.777",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90545"
                }
            ]
        },
        {
            "id": "CVE-2026-90544",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can increment view counts and watch-time on videos they cannot access by submitting requests with arbitrary video IDs.",
            "updated_at": "2026-09-12T13:16:52.640",
            "published_at": "2026-09-12T13:16:52.640",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can increment view counts and watch-time on videos they cannot access by submitting requests with arbitrary video IDs.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-2fgr-549m-8g5w",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-via-videoaddviewcount-json-php"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:52.640",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90544"
                }
            ]
        },
        {
            "id": "CVE-2026-90543",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.php. The script reads the `key` and `msg` parameters from $_REQUEST, resolves the stream owner via LiveTransmition::keyExists, and verifies that the stream owner (not the caller) is an administrator; it performs no User::isLogged() check and enforces no CSRF token. As a result, an unauthenticated remote attacker who knows an administrator's Live stream key can call sendSocketSuccessMessageToUsers_id and deliver arbitrary in-app/socket notification messages to that administrator. The issue was unpatched at the time of publication.",
            "updated_at": "2026-09-12T13:16:52.497",
            "published_at": "2026-09-12T13:16:52.497",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.php. The script reads the `key` and `msg` parameters from $_REQUEST, resolves the stream owner via LiveTransmition::keyExists, and verifies that the stream owner (not the caller) is an administrator; it performs no User::isLogged() check and enforces no CSRF token. As a result, an unauthenticated remote attacker who knows an administrator's Live stream key can call sendSocketSuccessMessageToUsers_id and deliver arbitrary in-app/socket notification messages to that administrator. The issue was unpatched at the time of publication.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-wcg2-x62c-m28x",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authentication-via-socketmessageliveowner-json-php"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:52.497",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90543"
                }
            ]
        },
        {
            "id": "CVE-2026-90542",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php. Authenticated attackers can create scheduler reminders for private live schedules they cannot view and learn the private schedule title from the generated email job.",
            "updated_at": "2026-09-12T13:16:52.353",
            "published_at": "2026-09-12T13:16:52.353",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php. Authenticated attackers can create scheduler reminders for private live schedules they cannot view and learn the private schedule title from the generated email job.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-qf26-4xp7-q5h9",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-via-remindme-json-php"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:52.353",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90542"
                }
            ]
        },
        {
            "id": "CVE-2026-90541",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all menu data. Attackers can send GET requests to the endpoint to read inactive and admin-only menu names that are not displayed in the public navbar.",
            "updated_at": "2026-09-12T13:16:52.220",
            "published_at": "2026-09-12T13:16:52.220",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all menu data. Attackers can send GET requests to the endpoint to read inactive and admin-only menu names that are not displayed in the public navbar.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-9xrr-c5w3-f5p7",
                "https://www.vulncheck.com/advisories/wwbn-avideo-unauthenticated-information-disclosure-via-menus-json-php"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:52.220",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90541"
                }
            ]
        },
        {
            "id": "CVE-2026-90540",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists. Authenticated attackers can add password-protected videos they cannot watch to playlists they own by submitting the video ID and playlist ID parameters.",
            "updated_at": "2026-09-12T13:16:52.080",
            "published_at": "2026-09-12T13:16:52.080",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists. Authenticated attackers can add password-protected videos they cannot watch to playlists they own by submitting the video ID and playlist ID parameters.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-xhg9-rc5h-rp65",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-via-playlistaddvideo-json-php"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:52.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90540"
                }
            ]
        },
        {
            "id": "CVE-2026-90539",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read inactive admin menu items by submitting a POST request with a menuId parameter. Attackers can retrieve hidden menu item URLs including embedded admin-tool secret query parameters not exposed in the public navbar.",
            "updated_at": "2026-09-12T13:16:51.943",
            "published_at": "2026-09-12T13:16:51.943",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read inactive admin menu items by submitting a POST request with a menuId parameter. Attackers can retrieve hidden menu item URLs including embedded admin-tool secret query parameters not exposed in the public navbar.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-h964-rxm2-fpgj",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authentication-via-menuitems-json-php"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:51.943",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90539"
                }
            ]
        },
        {
            "id": "CVE-2026-90538",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by requesting another user's identifier. Attackers can retrieve Favorite and Watch Later playlists belonging to other users due to improper cache keying that conflates requests across different user contexts.",
            "updated_at": "2026-09-12T13:16:51.807",
            "published_at": "2026-09-12T13:16:51.807",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by requesting another user's identifier. Attackers can retrieve Favorite and Watch Later playlists belonging to other users due to improper cache keying that conflates requests across different user contexts.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-6382-hm4f-hxqg",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-via-playlistsfromuser-json-php"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:51.807",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90538"
                }
            ]
        },
        {
            "id": "CVE-2026-90537",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and trigger email sending by supplying any valid daily token obtained from Live pages.",
            "updated_at": "2026-09-12T13:16:51.667",
            "published_at": "2026-09-12T13:16:51.667",
            "cvss": 8.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and trigger email sending by supplying any valid daily token obtained from Live pages.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-qq59-3jwp-hgj9",
                "https://www.vulncheck.com/advisories/wwbn-avideo-scheduler-sendemail-missing-authorization-via-token"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:51.667",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90537"
                }
            ]
        },
        {
            "id": "CVE-2026-90536",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can call the adsInfo API with a videos_id parameter to obtain the owner's user ID and personalized ad creative URLs without authentication or permission checks.",
            "updated_at": "2026-09-12T13:16:51.523",
            "published_at": "2026-09-12T13:16:51.523",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through c3edcc274c389816d434acadac07ee78eaf330c1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can call the adsInfo API with a videos_id parameter to obtain the owner's user ID and personalized ad creative URLs without authentication or permission checks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-989c-frwf-gprj",
                "https://www.vulncheck.com/advisories/wwbn-avideo-missing-authorization-via-adsinfo-api-endpoint"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:51.523",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90536"
                }
            ]
        },
        {
            "id": "CVE-2026-90535",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known chatflow and chat identifiers, causing targeted service disruption.",
            "updated_at": "2026-09-12T13:16:51.380",
            "published_at": "2026-09-12T13:16:51.380",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.1.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known chatflow and chat identifiers, causing targeted service disruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-xhxx-56g3-mx2r",
                "https://www.vulncheck.com/advisories/flowise-before-3.1.4-denial-of-service-via-text-to-speech-abort"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:51.380",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90535"
                }
            ]
        },
        {
            "id": "CVE-2026-90534",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and invokes component loadMethods with an attacker-controlled nodeName, loadMethod, inputs, and credential value. The selected credential is resolved by raw Credential.id via getCredentialData() and decrypted without verifying Credential.workspaceId against the caller's active or shared workspace, unlike other credential read paths which are workspace-scoped. As a result, an authenticated low-privilege user (or workspace API key) in one workspace can supply a credential ID owned by another workspace and cause Flowise to act as a confused deputy, performing third-party provider calls with the victim workspace's credential and returning provider metadata to the attacker. Statically identified affected load methods include Google Drive listFiles, Google Sheets listSpreadsheets, and AWS DynamoDB KV Storage listTables. The raw credential secret itself is not returned to the attacker. This issue is fixed in version 3.1.4.",
            "updated_at": "2026-09-12T13:16:51.247",
            "published_at": "2026-09-12T13:16:51.247",
            "cvss": 6.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.1.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and invokes component loadMethods with an attacker-controlled nodeName, loadMethod, inputs, and credential value. The selected credential is resolved by raw Credential.id via getCredentialData() and decrypted without verifying Credential.workspaceId against the caller's active or shared workspace, unlike other credential read paths which are workspace-scoped. As a result, an authenticated low-privilege user (or workspace API key) in one workspace can supply a credential ID owned by another workspace and cause Flowise to act as a confused deputy, performing third-party provider calls with the victim workspace's credential and returning provider metadata to the attacker. Statically identified affected load methods include Google Drive listFiles, Google Sheets listSpreadsheets, and AWS DynamoDB KV Storage listTables. The raw credential secret itself is not returned to the attacker. This issue is fixed in version 3.1.4.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-hqvm-7539-v83j",
                "https://www.vulncheck.com/advisories/flowise-before-3.1.4-cross-workspace-credential-idor-via-node-load-method"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:51.247",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90534"
                }
            ]
        },
        {
            "id": "CVE-2026-90533",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash and temporary tokens. Attackers can query the endpoint with any user ID to obtain the owner's credential hash for offline cracking, enabling account takeover of the highest-privileged account.",
            "updated_at": "2026-09-12T13:16:51.100",
            "published_at": "2026-09-12T13:16:51.100",
            "cvss": 6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.1.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-862",
            "what_happened": "Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash and temporary tokens. Attackers can query the endpoint with any user ID to obtain the owner's credential hash for offline cracking, enabling account takeover of the highest-privileged account.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-fhxm-xxcx-g6x3",
                "https://www.vulncheck.com/advisories/flowise-before-3.1.4-broken-access-control-via-organizationuser"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:51.100",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90533"
                }
            ]
        },
        {
            "id": "CVE-2026-90529",
            "vendor": "n/a",
            "product": "DataEase",
            "title": "DataEase vulnerability",
            "summary": "A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument canvasViewInfo[*].customAttr.tooltip.backgroundColor leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T15:16:28.820",
            "published_at": "2026-09-13T15:16:28.820",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.10.0; 2.10.1; 2.10.2; 2.10.3; 2.10.4; 2.10.5; 2.10.6; 2.10.7; 2.10.8; 2.10.9; 2.10.10; 2.10.11; 2.10.12; 2.10.13; 2.10.14; 2.10.15; 2.10.16; 2.10.17; 2.10.18; 2.10.19; 2.10.20; 2.10.21; 2.10.22; 2.10.23; 2.10.24; 2.10.25; 2.10.26",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument canvasViewInfo[*].customAttr.tooltip.backgroundColor leads to cross site scripting. The attack may be performed from remote. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/dataease/dataease/",
                "https://github.com/dataease/dataease/issues/18846",
                "https://vuldb.com/cve/CVE-2026-90529",
                "https://vuldb.com/submit/912538",
                "https://vuldb.com/vuln/403119",
                "https://vuldb.com/vuln/403119/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T15:16:28.820",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90529"
                }
            ]
        },
        {
            "id": "CVE-2026-90528",
            "vendor": "TDuckApp",
            "product": "tduck-platform",
            "title": "tduck-platform vulnerability",
            "summary": "A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argument submitShowCustomPageContent causes cross site scripting. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T15:16:28.650",
            "published_at": "2026-09-13T15:16:28.650",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5.0; 5.1; 5.2; 5.3",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argument submitShowCustomPageContent causes cross site scripting. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gitee.com/TDuckApp/tduck-platform/",
                "https://gitee.com/TDuckApp/tduck-platform/issues/IK5RJD",
                "https://vuldb.com/cve/CVE-2026-90528",
                "https://vuldb.com/submit/912535",
                "https://vuldb.com/vuln/403118",
                "https://vuldb.com/vuln/403118/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T15:16:28.650",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90528"
                }
            ]
        },
        {
            "id": "CVE-2026-90527",
            "vendor": "quequnlong",
            "product": "shiyi-blog",
            "title": "shiyi-blog vulnerability",
            "summary": "A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content results in cross site scripting. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T15:16:28.487",
            "published_at": "2026-09-13T15:16:28.487",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.2.0; 1.2.1",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content results in cross site scripting. The attack can be executed remotely. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gitee.com/quequnlong/shiyi-blog/",
                "https://gitee.com/quequnlong/shiyi-blog/issues/IK5RF6",
                "https://vuldb.com/cve/CVE-2026-90527",
                "https://vuldb.com/submit/912534",
                "https://vuldb.com/vuln/403117",
                "https://vuldb.com/vuln/403117/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T15:16:28.487",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90527"
                }
            ]
        },
        {
            "id": "CVE-2026-90526",
            "vendor": "SourceCodester",
            "product": "School Registration and Fee System",
            "title": "School Registration and Fee System vulnerability",
            "summary": "A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.",
            "updated_at": "2026-09-13T14:16:50.660",
            "published_at": "2026-09-13T14:16:50.660",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pangdudu24/cve/issues/2",
                "https://vuldb.com/cve/CVE-2026-90526",
                "https://vuldb.com/submit/912528",
                "https://vuldb.com/vuln/403116",
                "https://vuldb.com/vuln/403116/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T14:16:50.660",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90526"
                }
            ]
        },
        {
            "id": "CVE-2026-90525",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.",
            "updated_at": "2026-09-13T14:16:50.500",
            "published_at": "2026-09-13T14:16:50.500",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/abigmalon/submit_cve/issues/1",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-90525",
                "https://vuldb.com/submit/912526",
                "https://vuldb.com/vuln/403115",
                "https://vuldb.com/vuln/403115/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T14:16:50.500",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90525"
                }
            ]
        },
        {
            "id": "CVE-2026-90524",
            "vendor": "jaychouchannel",
            "product": "Tourism-Management-System",
            "title": "Tourism-Management-System vulnerability",
            "summary": "A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 84d8ec384f669df3985293dab293bb7b477efa64. It is suggested to install a patch to address this issue.",
            "updated_at": "2026-09-13T14:16:50.340",
            "published_at": "2026-09-13T14:16:50.340",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "229956e20dbd4a80eeff14535e44d3099502af09",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 84d8ec384f669df3985293dab293bb7b477efa64. It is suggested to install a patch to address this issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jaychouchannel/Tourism-Management-System/",
                "https://github.com/jaychouchannel/Tourism-Management-System/commit/84d8ec384f669df3985293dab293bb7b477efa64",
                "https://github.com/jaychouchannel/Tourism-Management-System/issues/11",
                "https://vuldb.com/cve/CVE-2026-90524",
                "https://vuldb.com/submit/912245",
                "https://vuldb.com/vuln/403114",
                "https://vuldb.com/vuln/403114/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T14:16:50.340",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90524"
                }
            ]
        },
        {
            "id": "CVE-2026-90523",
            "vendor": "jaychouchannel",
            "product": "Tourism-Management-System",
            "title": "Tourism-Management-System vulnerability",
            "summary": "A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 84d8ec384f669df3985293dab293bb7b477efa64. Applying a patch is advised to resolve this issue.",
            "updated_at": "2026-09-13T14:16:49.337",
            "published_at": "2026-09-13T14:16:49.337",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "229956e20dbd4a80eeff14535e44d3099502af09",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The name of the patch is 84d8ec384f669df3985293dab293bb7b477efa64. Applying a patch is advised to resolve this issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jaychouchannel/Tourism-Management-System/",
                "https://github.com/jaychouchannel/Tourism-Management-System/commit/84d8ec384f669df3985293dab293bb7b477efa64",
                "https://github.com/jaychouchannel/Tourism-Management-System/issues/10",
                "https://vuldb.com/cve/CVE-2026-90523",
                "https://vuldb.com/submit/912244",
                "https://vuldb.com/vuln/403113",
                "https://vuldb.com/vuln/403113/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T14:16:49.337",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90523"
                }
            ]
        },
        {
            "id": "CVE-2026-90522",
            "vendor": "jaychouchannel",
            "product": "Tourism-Management-System",
            "title": "Tourism-Management-System vulnerability",
            "summary": "A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 9cb6215ac871f99a90cde763cf003e95ff282283. It is recommended to apply a patch to fix this issue.",
            "updated_at": "2026-09-13T13:16:29.090",
            "published_at": "2026-09-13T13:16:29.090",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "d984d172dceca907f8b447efbdb06dc233f7938d",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-640",
            "what_happened": "A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Patch name: 9cb6215ac871f99a90cde763cf003e95ff282283. It is recommended to apply a patch to fix this issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jaychouchannel/Tourism-Management-System/",
                "https://github.com/jaychouchannel/Tourism-Management-System/commit/9cb6215ac871f99a90cde763cf003e95ff282283",
                "https://github.com/jaychouchannel/Tourism-Management-System/issues/13",
                "https://vuldb.com/cve/CVE-2026-90522",
                "https://vuldb.com/submit/912236",
                "https://vuldb.com/vuln/403112",
                "https://vuldb.com/vuln/403112/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T13:16:29.090",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90522"
                }
            ]
        },
        {
            "id": "CVE-2026-90521",
            "vendor": "jaychouchannel",
            "product": "Tourism-Management-System",
            "title": "Tourism-Management-System vulnerability",
            "summary": "A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipulation of the argument ID results in authorization bypass. It is possible to launch the attack remotely. The exploit has been made public and could be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The patch is identified as d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. It is best practice to apply a patch to resolve this issue.",
            "updated_at": "2026-09-13T13:16:28.927",
            "published_at": "2026-09-13T13:16:28.927",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8122bf020d91199eddfff3ee02d1632a70a9a132",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipulation of the argument ID results in authorization bypass. It is possible to launch the attack remotely. The exploit has been made public and could be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The patch is identified as d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. It is best practice to apply a patch to resolve this issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jaychouchannel/Tourism-Management-System/",
                "https://github.com/jaychouchannel/Tourism-Management-System/commit/d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86",
                "https://github.com/jaychouchannel/Tourism-Management-System/issues/9",
                "https://github.com/jaychouchannel/Tourism-Management-System/pull/14",
                "https://vuldb.com/cve/CVE-2026-90521",
                "https://vuldb.com/submit/912235",
                "https://vuldb.com/vuln/403111",
                "https://vuldb.com/vuln/403111/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T13:16:28.927",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90521"
                }
            ]
        },
        {
            "id": "CVE-2026-90520",
            "vendor": "jaychouchannel",
            "product": "Tourism-Management-System",
            "title": "Tourism-Management-System vulnerability",
            "summary": "A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of the patch is d984d172dceca907f8b447efbdb06dc233f7938d. Applying a patch is the recommended action to fix this issue.",
            "updated_at": "2026-09-13T13:16:28.760",
            "published_at": "2026-09-13T13:16:28.760",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "84d8ec384f669df3985293dab293bb7b477efa64",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of the patch is d984d172dceca907f8b447efbdb06dc233f7938d. Applying a patch is the recommended action to fix this issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jaychouchannel/Tourism-Management-System/",
                "https://github.com/jaychouchannel/Tourism-Management-System/commit/d984d172dceca907f8b447efbdb06dc233f7938d",
                "https://github.com/jaychouchannel/Tourism-Management-System/issues/12",
                "https://vuldb.com/cve/CVE-2026-90520",
                "https://vuldb.com/submit/912234",
                "https://vuldb.com/vuln/403110",
                "https://vuldb.com/vuln/403110/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T13:16:28.760",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90520"
                }
            ]
        },
        {
            "id": "CVE-2026-90519",
            "vendor": "PHPGurukul",
            "product": "Bank Locker Management System",
            "title": "Bank Locker Management System vulnerability",
            "summary": "A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.",
            "updated_at": "2026-09-13T13:16:27.697",
            "published_at": "2026-09-13T13:16:27.697",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/wakakakaaaaha/vuln/issues/5",
                "https://phpgurukul.com/",
                "https://vuldb.com/cve/CVE-2026-90519",
                "https://vuldb.com/submit/912224",
                "https://vuldb.com/vuln/403106",
                "https://vuldb.com/vuln/403106/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T13:16:27.697",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90519"
                }
            ]
        },
        {
            "id": "CVE-2026-90518",
            "vendor": "PHPGurukul",
            "product": "Bank Locker Management System",
            "title": "Bank Locker Management System vulnerability",
            "summary": "A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.",
            "updated_at": "2026-09-13T12:17:16.237",
            "published_at": "2026-09-13T12:17:16.237",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/wakakakaaaaha/vuln/issues/3",
                "https://phpgurukul.com/",
                "https://vuldb.com/cve/CVE-2026-90518",
                "https://vuldb.com/submit/912176",
                "https://vuldb.com/vuln/403105",
                "https://vuldb.com/vuln/403105/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T12:17:16.237",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90518"
                }
            ]
        },
        {
            "id": "CVE-2026-90517",
            "vendor": "PHPGurukul",
            "product": "Bank Locker Management System",
            "title": "Bank Locker Management System vulnerability",
            "summary": "A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used.",
            "updated_at": "2026-09-13T12:17:16.073",
            "published_at": "2026-09-13T12:17:16.073",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/wakakakaaaaha/vuln/issues/2",
                "https://phpgurukul.com/",
                "https://vuldb.com/cve/CVE-2026-90517",
                "https://vuldb.com/submit/912139",
                "https://vuldb.com/vuln/403104",
                "https://vuldb.com/vuln/403104/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T12:17:16.073",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90517"
                }
            ]
        },
        {
            "id": "CVE-2026-90516",
            "vendor": "SourceCodester",
            "product": "School Registration and Fee System",
            "title": "School Registration and Fee System vulnerability",
            "summary": "A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.",
            "updated_at": "2026-09-13T12:17:15.893",
            "published_at": "2026-09-13T12:17:15.893",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/zuojiu567/cve/issues/3",
                "https://vuldb.com/cve/CVE-2026-90516",
                "https://vuldb.com/submit/912055",
                "https://vuldb.com/vuln/403102",
                "https://vuldb.com/vuln/403102/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T12:17:15.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90516"
                }
            ]
        },
        {
            "id": "CVE-2026-90515",
            "vendor": "SourceCodester",
            "product": "School Registration and Fee System",
            "title": "School Registration and Fee System vulnerability",
            "summary": "A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.",
            "updated_at": "2026-09-13T12:17:15.147",
            "published_at": "2026-09-13T12:17:15.147",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/zuojiu567/cve/issues/2",
                "https://vuldb.com/cve/CVE-2026-90515",
                "https://vuldb.com/submit/912054",
                "https://vuldb.com/vuln/403103",
                "https://vuldb.com/vuln/403103/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T12:17:15.147",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90515"
                }
            ]
        },
        {
            "id": "CVE-2026-90514",
            "vendor": "SourceCodester",
            "product": "School Registration and Fee System",
            "title": "School Registration and Fee System vulnerability",
            "summary": "A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
            "updated_at": "2026-09-13T11:17:00.423",
            "published_at": "2026-09-13T11:17:00.423",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/zuojiu567/cve/issues/1",
                "https://vuldb.com/cve/CVE-2026-90514",
                "https://vuldb.com/submit/912050",
                "https://vuldb.com/vuln/403101",
                "https://vuldb.com/vuln/403101/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T11:17:00.423",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90514"
                }
            ]
        },
        {
            "id": "CVE-2026-90513",
            "vendor": "simalexan",
            "product": "api-lambda-send-email-ses",
            "title": "api-lambda-send-email-ses vulnerability",
            "summary": "A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument toEmails/ccEmails/replyToEmails/subject/message causes missing authentication. It is possible to initiate the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T11:17:00.237",
            "published_at": "2026-09-13T11:17:00.237",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "bda6869aa81371d1e872242e74fe7d953edb818d",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument toEmails/ccEmails/replyToEmails/subject/message causes missing authentication. It is possible to initiate the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/simalexan/api-lambda-send-email-ses/",
                "https://github.com/simalexan/api-lambda-send-email-ses/issues/9",
                "https://vuldb.com/cve/CVE-2026-90513",
                "https://vuldb.com/submit/911886",
                "https://vuldb.com/vuln/403100",
                "https://vuldb.com/vuln/403100/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T11:17:00.237",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90513"
                }
            ]
        },
        {
            "id": "CVE-2026-90511",
            "vendor": "GongShengyue",
            "product": "OnlineBooks",
            "title": "OnlineBooks vulnerability",
            "summary": "A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.",
            "updated_at": "2026-09-13T11:17:00.050",
            "published_at": "2026-09-13T11:17:00.050",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "dfc5eacc08d3b0396c266049548618f6fb9587ea",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/hhhh333/CVE/blob/main/OnlineBooks-sql.md",
                "https://vuldb.com/cve/CVE-2026-90511",
                "https://vuldb.com/submit/911884",
                "https://vuldb.com/vuln/403099",
                "https://vuldb.com/vuln/403099/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T11:17:00.050",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90511"
                }
            ]
        },
        {
            "id": "CVE-2026-90510",
            "vendor": "dromara",
            "product": "orion-visor",
            "title": "orion-visor vulnerability",
            "summary": "A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key\r . The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T11:16:59.827",
            "published_at": "2026-09-13T11:16:59.827",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.5.0; 2.5.1; 2.5.2; 2.5.3; 2.5.4; 2.5.5; 2.5.6; 2.5.7",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-320",
            "what_happened": "A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java. The manipulation leads to use of hard-coded cryptographic key\r . The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/dromara/orion-visor/",
                "https://github.com/dromara/orion-visor/issues/171",
                "https://github.com/sumo166/CVE-apply/blob/main/dromara-orion-visor/Hardcoded%20AES%20Encryption%20Key%20Enables%20Decryption%20of%20SSH%20Private%20Keys%20and%20Host%20Passwords%20(CWE-321)_en.md",
                "https://vuldb.com/cve/CVE-2026-90510",
                "https://vuldb.com/submit/911865",
                "https://vuldb.com/vuln/403098",
                "https://vuldb.com/vuln/403098/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T11:16:59.827",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90510"
                }
            ]
        },
        {
            "id": "CVE-2026-90509",
            "vendor": "dromara",
            "product": "orion-visor",
            "title": "orion-visor vulnerability",
            "summary": "A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-13T10:16:56.117",
            "published_at": "2026-09-13T10:16:56.117",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.5.0; 2.5.1; 2.5.2; 2.5.3; 2.5.4; 2.5.5; 2.5.6; 2.5.7",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-259",
            "what_happened": "A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/dromara/orion-visor/",
                "https://github.com/dromara/orion-visor/issues/170",
                "https://github.com/sumo166/CVE-apply/blob/main/dromara-orion-visor/ExposeApi%20Hardcoded%20Default%20Token%20Authentication%20Bypass%20(CWE-798)_en.md",
                "https://vuldb.com/cve/CVE-2026-90509",
                "https://vuldb.com/submit/911864",
                "https://vuldb.com/vuln/403097",
                "https://vuldb.com/vuln/403097/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T10:16:56.117",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90509"
                }
            ]
        },
        {
            "id": "CVE-2026-90508",
            "vendor": "Chengdu Qilu Technology",
            "product": "Ludashi",
            "title": "Ludashi vulnerability",
            "summary": "A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing authorization. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.",
            "updated_at": "2026-09-13T10:16:55.900",
            "published_at": "2026-09-13T10:16:55.900",
            "cvss": 1.8,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.1026.4715.714",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing authorization. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gist.github.com/lzty/fc5f336dca4c287ab4c22168b6dc8ec2",
                "https://vuldb.com/cve/CVE-2026-90508",
                "https://vuldb.com/submit/895271",
                "https://vuldb.com/vuln/403096",
                "https://vuldb.com/vuln/403096/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T10:16:55.900",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90508"
                }
            ]
        },
        {
            "id": "CVE-2026-90507",
            "vendor": "vvbbnn00",
            "product": "WARP-Clash-API",
            "title": "WARP-Clash-API vulnerability",
            "summary": "A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to improper access controls. The attack may be launched remotely. The exploit is publicly available and might be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.",
            "updated_at": "2026-09-13T10:16:55.720",
            "published_at": "2026-09-13T10:16:55.720",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c7bf2360073959861219b422e51ae86411051b46",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such manipulation of the argument key leads to improper access controls. The attack may be launched remotely. The exploit is publicly available and might be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gist.github.com/Galaxync/26062162d9cc27550795cdc100da2dcb",
                "https://vuldb.com/cve/CVE-2026-90507",
                "https://vuldb.com/submit/895270",
                "https://vuldb.com/vuln/403095",
                "https://vuldb.com/vuln/403095/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T10:16:55.720",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90507"
                }
            ]
        },
        {
            "id": "CVE-2026-90506",
            "vendor": "vvbbnn00",
            "product": "WARP-Clash-API",
            "title": "WARP-Clash-API vulnerability",
            "summary": "A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts an unknown function of the component Save Account Job. This manipulation causes race condition. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is said to be difficult. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.",
            "updated_at": "2026-09-13T10:16:55.540",
            "published_at": "2026-09-13T10:16:55.540",
            "cvss": 1.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c7bf2360073959861219b422e51ae86411051b46",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts an unknown function of the component Save Account Job. This manipulation causes race condition. The attack may be initiated remotely. The attack's complexity is rated as high. The exploitability is said to be difficult. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gist.github.com/Galaxync/d09928879331ef9c7e2bfccd08c7288b",
                "https://vuldb.com/cve/CVE-2026-90506",
                "https://vuldb.com/submit/895265",
                "https://vuldb.com/vuln/403094",
                "https://vuldb.com/vuln/403094/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T10:16:55.540",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90506"
                }
            ]
        },
        {
            "id": "CVE-2026-90505",
            "vendor": "vvbbnn00",
            "product": "WARP-Clash-API",
            "title": "WARP-Clash-API vulnerability",
            "summary": "A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race condition. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.",
            "updated_at": "2026-09-13T10:16:55.357",
            "published_at": "2026-09-13T10:16:55.357",
            "cvss": 1.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c7bf2360073959861219b422e51ae86411051b46",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race condition. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gist.github.com/Galaxync/62748fe998dd8518691e11d765224093",
                "https://vuldb.com/cve/CVE-2026-90505",
                "https://vuldb.com/submit/895264",
                "https://vuldb.com/vuln/403093",
                "https://vuldb.com/vuln/403093/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T10:16:55.357",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90505"
                }
            ]
        },
        {
            "id": "CVE-2026-90504",
            "vendor": "vvbbnn00",
            "product": "WARP-Clash-API",
            "title": "WARP-Clash-API vulnerability",
            "summary": "A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.",
            "updated_at": "2026-09-13T10:16:54.093",
            "published_at": "2026-09-13T10:16:54.093",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c7bf2360073959861219b422e51ae86411051b46",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gist.github.com/Galaxync/b90734d80bf32e8145e46fbc326d6729",
                "https://vuldb.com/cve/CVE-2026-90504",
                "https://vuldb.com/submit/895263",
                "https://vuldb.com/vuln/403092",
                "https://vuldb.com/vuln/403092/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T10:16:54.093",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90504"
                }
            ]
        },
        {
            "id": "CVE-2026-90503",
            "vendor": "Chengdu Qilu Technology",
            "product": "Ludashi",
            "title": "Ludashi vulnerability",
            "summary": "A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information disclosure. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
            "updated_at": "2026-09-13T09:16:31.933",
            "published_at": "2026-09-13T09:16:31.933",
            "cvss": 1.8,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.1026.4715.714",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information disclosure. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://vuldb.com/cve/CVE-2026-90503",
                "https://vuldb.com/submit/895249",
                "https://vuldb.com/vuln/403091",
                "https://vuldb.com/vuln/403091/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T09:16:31.933",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90503"
                }
            ]
        },
        {
            "id": "CVE-2026-90502",
            "vendor": "stilleshan",
            "product": "ServerStatus",
            "title": "ServerStatus vulnerability",
            "summary": "A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/main.cpp of the component Stats Generation. Performing a manipulation of the argument custom results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
            "updated_at": "2026-09-13T09:16:30.827",
            "published_at": "2026-09-13T09:16:30.827",
            "cvss": 2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0; 2.0",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/main.cpp of the component Stats Generation. Performing a manipulation of the argument custom results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/BlkSword/POC/blob/main/ServerStatus%20Stored%20.pdf",
                "https://vuldb.com/cve/CVE-2026-90502",
                "https://vuldb.com/submit/895248",
                "https://vuldb.com/vuln/403090",
                "https://vuldb.com/vuln/403090/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T09:16:30.827",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90502"
                }
            ]
        },
        {
            "id": "CVE-2026-90501",
            "vendor": "lenve",
            "product": "vhr",
            "title": "vhr vulnerability",
            "summary": "A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
            "updated_at": "2026-09-13T08:16:27.017",
            "published_at": "2026-09-13T08:16:27.017",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0-SNAPSHOT",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ArrestX/vhr-advisories/blob/main/advisories/VHR-VULN-001-mass-assignment-privesc.md",
                "https://vuldb.com/cve/CVE-2026-90501",
                "https://vuldb.com/submit/892904",
                "https://vuldb.com/vuln/403089",
                "https://vuldb.com/vuln/403089/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T08:16:27.017",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90501"
                }
            ]
        },
        {
            "id": "CVE-2026-90500",
            "vendor": "lenve",
            "product": "vhr",
            "title": "vhr vulnerability",
            "summary": "A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.",
            "updated_at": "2026-09-13T08:16:25.980",
            "published_at": "2026-09-13T08:16:25.980",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0-SNAPSHOT",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ArrestX/vhr-advisories/blob/main/advisories/VHR-VULN-005-unrestricted-upload.md",
                "https://vuldb.com/cve/CVE-2026-90500",
                "https://vuldb.com/submit/892902",
                "https://vuldb.com/vuln/403088",
                "https://vuldb.com/vuln/403088/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T08:16:25.980",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90500"
                }
            ]
        },
        {
            "id": "CVE-2026-90493",
            "vendor": "Tonec",
            "product": "Internet Download Manager",
            "title": "Internet Download Manager vulnerability",
            "summary": "A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. Internet Download Manager for Windows up to and including 6.42 Build 63 installs idmwfp.sys, a Windows kernel driver that exposes the \\.\\IDMWFP device interface to authenticated local users. The device object is created with an access control descriptor equivalent to D:P(A;;GA;;;AU), granting Authenticated Users generic access to the driver. The driver's IOCTL 0x12C028 handler accepts registry-operation subcommands 0x0C through 0x0F and processes caller-controlled registry paths and values. These handlers do not authenticate the caller, do not enforce the caller's registry permissions, and do not restrict operations to IDM-owned registry namespaces. A low-privileged local authenticated user can therefore read, create, modify, and delete arbitrary registry values under HKLM and HKU through the kernel driver. This includes registry configuration consumed by privileged Windows services and drivers and enables Local Privilege Escalation, high-privilege persistence, unauthorized system configuration disclosure or modification, and compromise of system confidentiality, integrity, and availability. Exploitation requires local access, low privileges, and no user interaction. A public proof of concept is available. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
            "updated_at": "2026-09-15T02:16:48.217",
            "published_at": "2026-09-13T03:16:27.370",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.42 Build 63",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. Internet Download Manager for Windows up to and including 6.42 Build 63 installs idmwfp.sys, a Windows kernel driver that exposes the \\.\\IDMWFP device interface to authenticated local users. The device object is created with an access control descriptor equivalent to D:P(A;;GA;;;AU), granting Authenticated Users generic access to the driver. The driver's IOCTL 0x12C028 handler accepts registry-operation subcommands 0x0C through 0x0F and processes caller-controlled registry paths and values. These handlers do not authenticate the caller, do not enforce the caller's registry permissions, and do not restrict operations to IDM-owned registry namespaces. A low-privileged local authenticated user can therefore read, create, modify, and delete arbitrary registry values under HKLM and HKU through the kernel driver. This includes registry configuration consumed by privileged Windows services and drivers and enables Local Privilege Escalation, high-privilege persistence, unauthorized system configuration disclosure or modification, and compromise of system confidentiality, integrity, and availability. Exploitation requires local access, low privileges, and no user interaction. A public proof of concept is available. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/KnCRJVirX/IDM_LPE_PoC/tree/main/poc",
                "https://vuldb.com/cve/CVE-2026-90493",
                "https://vuldb.com/submit/891910",
                "https://vuldb.com/vuln/403081",
                "https://vuldb.com/vuln/403081/cti",
                "https://github.com/KnCRJVirX/IDM_LPE_PoC/blob/main/report_en.md"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T03:16:27.370",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90493"
                }
            ]
        },
        {
            "id": "CVE-2026-90492",
            "vendor": "webgjc",
            "product": "web_robot",
            "title": "web_robot vulnerability",
            "summary": "A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function controller_listen/controller_recover of the file py/web.py. The manipulation of the argument case_name leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
            "updated_at": "2026-09-13T02:17:04.930",
            "published_at": "2026-09-13T02:17:04.930",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.4.0; 2.5.0; 2.8.0",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function controller_listen/controller_recover of the file py/web.py. The manipulation of the argument case_name leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://vuldb.com/cve/CVE-2026-90492",
                "https://vuldb.com/submit/892352",
                "https://vuldb.com/vuln/403080",
                "https://vuldb.com/vuln/403080/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T02:17:04.930",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90492"
                }
            ]
        },
        {
            "id": "CVE-2026-90491",
            "vendor": "sanjevirau",
            "product": "gsubs",
            "title": "gsubs vulnerability",
            "summary": "A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file renderer/index.js of the component Electron. Executing a manipulation of the argument filename can lead to code injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.",
            "updated_at": "2026-09-13T02:17:03.097",
            "published_at": "2026-09-13T02:17:03.097",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0; 1.0.1; 1.0.2; 1.0.3",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file renderer/index.js of the component Electron. Executing a manipulation of the argument filename can lead to code injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/LeoWSY-hashblue/cve-electron-2/blob/master/gsubs/cve.md",
                "https://github.com/LeoWSY-hashblue/cve-electron-2/tree/master/gsubs/poc",
                "https://vuldb.com/cve/CVE-2026-90491",
                "https://vuldb.com/submit/891691",
                "https://vuldb.com/vuln/403079",
                "https://vuldb.com/vuln/403079/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T02:17:03.097",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90491"
                }
            ]
        },
        {
            "id": "CVE-2026-90490",
            "vendor": "lenve",
            "product": "vhr",
            "title": "vhr vulnerability",
            "summary": "A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.",
            "updated_at": "2026-09-13T01:16:37.520",
            "published_at": "2026-09-13T01:16:37.520",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0-SNAPSHOT",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ArrestX/vhr-advisories/blob/main/poc/VHR-VULN-006/YAKIT-PoC.md",
                "https://vuldb.com/cve/CVE-2026-90490",
                "https://vuldb.com/submit/888617",
                "https://vuldb.com/vuln/403078",
                "https://vuldb.com/vuln/403078/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T01:16:37.520",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90490"
                }
            ]
        },
        {
            "id": "CVE-2026-90489",
            "vendor": "Xuxueli",
            "product": "xxl-job",
            "title": "xxl-job vulnerability",
            "summary": "A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/insert. Such manipulation of the argument name/author leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.",
            "updated_at": "2026-09-13T00:17:06.853",
            "published_at": "2026-09-13T00:17:06.853",
            "cvss": 2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.0; 3.1; 3.2; 3.3; 3.4; 3.5.0",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/insert. Such manipulation of the argument name/author leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/hhhh333/CVE/blob/main/xxl-job-xss.md",
                "https://vuldb.com/cve/CVE-2026-90489",
                "https://vuldb.com/submit/892506",
                "https://vuldb.com/vuln/403077",
                "https://vuldb.com/vuln/403077/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T00:17:06.853",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90489"
                }
            ]
        },
        {
            "id": "CVE-2026-90488",
            "vendor": "Xuxueli",
            "product": "xxl-job",
            "title": "xxl-job vulnerability",
            "summary": "A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.",
            "updated_at": "2026-09-13T00:17:06.680",
            "published_at": "2026-09-13T00:17:06.680",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.4.0; 3.4.1; 3.4.2",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/zhaizejiang/xxl-job-vuln-poc/blob/main/xxl-job%20v3.4.2%20Remote%20Code%20Execution%20via%20Groovy%20Code%20Execution.md",
                "https://vuldb.com/cve/CVE-2026-90488",
                "https://vuldb.com/submit/888470",
                "https://vuldb.com/vuln/403076",
                "https://vuldb.com/vuln/403076/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T00:17:06.680",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90488"
                }
            ]
        },
        {
            "id": "CVE-2026-90487",
            "vendor": "Xuxueli",
            "product": "xxl-job",
            "title": "xxl-job vulnerability",
            "summary": "A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The manipulation results in improper privilege management. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.",
            "updated_at": "2026-09-12T23:17:01.307",
            "published_at": "2026-09-12T23:17:01.307",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.4.0; 3.4.1; 3.4.2",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The manipulation results in improper privilege management. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/zhaizejiang/xxl-job-vuln-poc/edit/main/xxl-job3.4.2_loadById%20Endpoint%20Missing%20Authentication.md",
                "https://vuldb.com/cve/CVE-2026-90487",
                "https://vuldb.com/submit/888438",
                "https://vuldb.com/vuln/403075",
                "https://vuldb.com/vuln/403075/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T23:17:01.307",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90487"
                }
            ]
        },
        {
            "id": "CVE-2026-90486",
            "vendor": "openstatusHQ",
            "product": "openstatus",
            "title": "openstatus vulnerability",
            "summary": "A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts. The manipulation leads to server-side request forgery. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is 86f370c9c20074c3c3fdec53a359874b8e670fd4. It is suggested to install a patch to address this issue. This issue got fixed with a silent patch.",
            "updated_at": "2026-09-12T23:17:01.073",
            "published_at": "2026-09-12T23:17:01.073",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f04c827112f30a11d571ebdad3892826034d6265",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts. The manipulation leads to server-side request forgery. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is 86f370c9c20074c3c3fdec53a359874b8e670fd4. It is suggested to install a patch to address this issue. This issue got fixed with a silent patch.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openstatusHQ/openstatus/",
                "https://github.com/openstatusHQ/openstatus/commit/86f370c9c20074c3c3fdec53a359874b8e670fd4",
                "https://github.com/openstatusHQ/openstatus/pull/2551",
                "https://vuldb.com/cve/CVE-2026-90486",
                "https://vuldb.com/submit/888087",
                "https://vuldb.com/vuln/403074",
                "https://vuldb.com/vuln/403074/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T23:17:01.073",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90486"
                }
            ]
        },
        {
            "id": "CVE-2026-90485",
            "vendor": "IOBit",
            "product": "Uninstaller",
            "title": "Uninstaller vulnerability",
            "summary": "A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegistryFilter.sys of the component IOCTL Dispatch Handler. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been published and may be used. Identical IURegistryFilter.sys ships across multiple IObit families. The vendor was contacted early about this disclosure but did not respond in any way.",
            "updated_at": "2026-09-12T22:16:30.783",
            "published_at": "2026-09-12T22:16:30.783",
            "cvss": 5.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "15.5.0.11",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-404",
            "what_happened": "A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegistryFilter.sys of the component IOCTL Dispatch Handler. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been published and may be used. Identical IURegistryFilter.sys ships across multiple IObit families. The vendor was contacted early about this disclosure but did not respond in any way.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://vuldb.com/cve/CVE-2026-90485",
                "https://vuldb.com/submit/887954",
                "https://vuldb.com/vuln/403064",
                "https://vuldb.com/vuln/403064/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T22:16:30.783",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90485"
                }
            ]
        },
        {
            "id": "CVE-2026-90474",
            "vendor": "samanhappy",
            "product": "mcphub",
            "title": "mcphub vulnerability",
            "summary": "MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional. Attackers who obtain an authorization code through interception can redeem it for access tokens without providing a client secret or PKCE verifier, gaining access to victim accounts and their privileges.",
            "updated_at": "2026-09-12T11:16:34.483",
            "published_at": "2026-09-12T11:16:34.483",
            "cvss": 7.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.0.32 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement is optional. Attackers who obtain an authorization code through interception can redeem it for access tokens without providing a client secret or PKCE verifier, gaining access to victim accounts and their privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/samanhappy/mcphub/blob/v1.0.31/src/services/oauthServerService.ts#L26-L38",
                "https://github.com/samanhappy/mcphub/commit/e927620cd1a80e8691213b01eb8cd6ffa1a66e9f",
                "https://github.com/samanhappy/mcphub/releases/tag/v1.0.32",
                "https://github.com/samanhappy/mcphub/security/advisories/GHSA-3m7m-37xf-xp9x",
                "https://www.vulncheck.com/advisories/mcphub-before-1.0.32-oauth-2.0-authentication-bypass"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T11:16:34.483",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90474"
                }
            ]
        },
        {
            "id": "CVE-2026-90473",
            "vendor": "msgpack",
            "product": "msgpack-java",
            "title": "msgpack-java vulnerability",
            "summary": "msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor to desynchronize and attacker-controlled data to be returned in place of later fields.",
            "updated_at": "2026-09-12T11:16:34.347",
            "published_at": "2026-09-12T11:16:34.347",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.9.12 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor to desynchronize and attacker-controlled data to be returned in place of later fields.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/msgpack/msgpack-java",
                "https://github.com/msgpack/msgpack-java/blob/v0.9.12/msgpack-core/src/main/java/org/msgpack/core/MessageUnpacker.java#L573-L581",
                "https://github.com/msgpack/msgpack-java/issues/1014",
                "https://www.vulncheck.com/advisories/msgpack-java-through-0.9.12-integer-overflow-via-map32"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T11:16:34.347",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90473"
                }
            ]
        },
        {
            "id": "CVE-2026-90472",
            "vendor": "msgpack",
            "product": "msgpack-java",
            "title": "msgpack-java vulnerability",
            "summary": "msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.",
            "updated_at": "2026-09-12T11:16:34.180",
            "published_at": "2026-09-12T11:16:34.180",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.9.12 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-674",
            "what_happened": "msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with deeply nested arrays to exhaust the deserializing thread's stack and trigger StackOverflowError, causing per-request deserialization failures.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/msgpack/msgpack-java",
                "https://github.com/msgpack/msgpack-java/blob/v0.9.12/msgpack-core/src/main/java/org/msgpack/core/MessageUnpacker.java#L646-L664",
                "https://github.com/msgpack/msgpack-java/issues/1015",
                "https://www.vulncheck.com/advisories/msgpack-java-through-0.9.12-stack-overflow-via-nested-arrays"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T11:16:34.180",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90472"
                }
            ]
        },
        {
            "id": "CVE-2026-90467",
            "vendor": "cole",
            "product": "aiosmtplib",
            "title": "aiosmtplib vulnerability",
            "summary": "aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope commands, forging authenticated identities or forcing delivery notifications to third parties.",
            "updated_at": "2026-09-12T02:16:24.770",
            "published_at": "2026-09-12T02:16:24.770",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.1.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-88",
            "what_happened": "aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope commands, forging authenticated identities or forcing delivery notifications to third parties.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cole/aiosmtplib",
                "https://github.com/cole/aiosmtplib/blob/v5.1.2/src/aiosmtplib/email.py",
                "https://github.com/cole/aiosmtplib/commit/2e1b210714974ccc9efd0d09a8f846cb9aeaaec2",
                "https://github.com/cole/aiosmtplib/releases/tag/v5.1.3",
                "https://www.vulncheck.com/advisories/aiosmtplib-before-5.1.3-esmtp-parameter-injection-via-unvalidated-addresses"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T02:16:24.770",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-90467"
                }
            ]
        },
        {
            "id": "CVE-2026-89606",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-89606 exploit",
            "summary": "Exploit for CVE-2026-89606.",
            "updated_at": "2026-09-11T19:45:08Z",
            "published_at": "2026-09-11T19:45:08Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 41,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Integer underflow in ecryptfs tag 70 packet parsing in Linux kernel via too-small body.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-89606",
                    "summary": "Integer underflow in ecryptfs tag 70 packet parsing in Linux kernel via too-small body.",
                    "what_happened": "Integer underflow in ecryptfs tag 70 packet parsing in Linux kernel via too-small body.",
                    "cvss": 0,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-89606",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-89606"
                    ],
                    "repository": "Sploitus",
                    "author": "Linux",
                    "first_seen": "2026-09-11T20:19:45",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-89606"
                },
                {
                    "title": "Exploit for CVE-2026-89606",
                    "summary": "Integer underflow in ecryptfs tag 70 packet parsing in Linux kernel via too-small body.",
                    "what_happened": "Integer underflow in ecryptfs tag 70 packet parsing in Linux kernel via too-small body.",
                    "cvss": 0,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-89606",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-89606"
                    ],
                    "repository": "web.nvd.nist.gov",
                    "author": "view",
                    "first_seen": "2026-09-11T20:19:45",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-89606"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=CVE-2026-89606",
                "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-89606"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T19:45:08Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-89606"
                }
            ]
        },
        {
            "id": "CVE-2026-89471",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: cros_usbpd-charger: bound the EC-reported port count\n\ncros_usbpd_charger_probe() reads two port counts from the EC and uses\none of them, num_charger_ports, as the loop bound when populating a\nfixed-size array:\n\n\tstruct port_data *ports[EC_USB_PD_MAX_PORTS];\t/* 8 entries */\n\t...\n\tfor (i = 0; i < charger->num_charger_ports; i++)\n\t\tcharger->ports[charger->num_registered_psy++] = port;\n\nBoth num_usbpd_ports (from EC_CMD_USB_PD_PORTS) and num_charger_ports\n(from EC_CMD_CHARGE_PORT_COUNT) are u8 values reported by the EC. The\nonly validation is a sanity check that compares the two EC-reported\nvalues against each other:\n\n\tif (num_charger_ports < num_usbpd_ports ||\n\t    num_charger_ports > num_usbpd_ports + 1)\n\t\treturn -EPROTO;\n\nIt never checks either count against EC_USB_PD_MAX_PORTS, the size of\nthe ports[] array. A malfunctioning, malicious or compromised EC that\nreports num_usbpd_ports == num_charger_ports == N for any N > 8 (for\nexample both 255) passes this check, and the loop then writes N pointers\ninto the 8-entry ports[] array embedded in the devm_kzalloc()'d\ncharger_data, overflowing it by up to 255 - 8 = 247 entries (~1976\nbytes): a slab out-of-bounds write.\n\nReject a port count larger than the ports[] array can hold.",
            "updated_at": "2026-09-13T07:17:10.390",
            "published_at": "2026-09-11T20:19:28.263",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f68b883e8fad23ed0ac4756d91594809d78678ed through before fd29d08ee487f3bf50f2575aaa74f78a74b09b21 (git); f68b883e8fad23ed0ac4756d91594809d78678ed through before 78be8b7403ff7638162438b664a07d19da76059e (git); f68b883e8fad23ed0ac4756d91594809d78678ed through before 3d1e01443b221081258ff34ea0cdd0431e4ff62e (git); f68b883e8fad23ed0ac4756d91594809d78678ed through before 48355ce49359740f52e94d3623f6fc557ce341f0 (git); 4.19",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: cros_usbpd-charger: bound the EC-reported port count\n\ncros_usbpd_charger_probe() reads two port counts from the EC and uses\none of them, num_charger_ports, as the loop bound when populating a\nfixed-size array:\n\n\tstruct port_data *ports[EC_USB_PD_MAX_PORTS];\t/* 8 entries */\n\t...\n\tfor (i = 0; i < charger->num_charger_ports; i++)\n\t\tcharger->ports[charger->num_registered_psy++] = port;\n\nBoth num_usbpd_ports (from EC_CMD_USB_PD_PORTS) and num_charger_ports\n(from EC_CMD_CHARGE_PORT_COUNT) are u8 values reported by the EC. The\nonly validation is a sanity check that compares the two EC-reported\nvalues against each other:\n\n\tif (num_charger_ports < num_usbpd_ports ||\n\t    num_charger_ports > num_usbpd_ports + 1)\n\t\treturn -EPROTO;\n\nIt never checks either count against EC_USB_PD_MAX_PORTS, the size of\nthe ports[] array. A malfunctioning, malicious or compromised EC that\nreports num_usbpd_ports == num_charger_ports == N for any N > 8 (for\nexample both 255) passes this check, and the loop then writes N pointers\ninto the 8-entry ports[] array embedded in the devm_kzalloc()'d\ncharger_data, overflowing it by up to 255 - 8 = 247 entries (~1976\nbytes): a slab out-of-bounds write.\n\nReject a port count larger than the ports[] array can hold.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/3d1e01443b221081258ff34ea0cdd0431e4ff62e",
                "https://git.kernel.org/stable/c/48355ce49359740f52e94d3623f6fc557ce341f0",
                "https://git.kernel.org/stable/c/78be8b7403ff7638162438b664a07d19da76059e",
                "https://git.kernel.org/stable/c/fd29d08ee487f3bf50f2575aaa74f78a74b09b21"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:28.263",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89471"
                }
            ]
        },
        {
            "id": "CVE-2026-89470",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS\n\nCurrently the cros_usbpd-charger driver probe iterates based on raw\ncharger port count returned by the embedded controller. The only check\nis against the number of USB PD ports which the embedded controller\nalso defines. A malicious embedded controller could return an inaccurate\nport count (up to 255) resulting in an out of bounds write and\nsubsequent memory corruption.\n\nUpdate helper functions in cros_usbpd-charger to limit port counts to\nEC_USB_PD_MAX_PORTS.",
            "updated_at": "2026-09-13T07:17:10.263",
            "published_at": "2026-09-11T20:19:28.140",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3af15cfacd1eef7f223802d49a88cae23c509183 through before fd5f289cca04ad869b34fc9ccb647670bfdb60ac (git); 3af15cfacd1eef7f223802d49a88cae23c509183 through before 4b1f2be1e1b74a50386ba718de3d62bfcf5ee701 (git); 3af15cfacd1eef7f223802d49a88cae23c509183 through before 304a29ac55ba3ee6eceaf7d83d09cd9709f3bf60 (git); 3af15cfacd1eef7f223802d49a88cae23c509183 through before 657cd3a42e937276262c0a8ae6b01a87004309de (git); 4.20",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS\n\nCurrently the cros_usbpd-charger driver probe iterates based on raw\ncharger port count returned by the embedded controller. The only check\nis against the number of USB PD ports which the embedded controller\nalso defines. A malicious embedded controller could return an inaccurate\nport count (up to 255) resulting in an out of bounds write and\nsubsequent memory corruption.\n\nUpdate helper functions in cros_usbpd-charger to limit port counts to\nEC_USB_PD_MAX_PORTS.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/304a29ac55ba3ee6eceaf7d83d09cd9709f3bf60",
                "https://git.kernel.org/stable/c/4b1f2be1e1b74a50386ba718de3d62bfcf5ee701",
                "https://git.kernel.org/stable/c/657cd3a42e937276262c0a8ae6b01a87004309de",
                "https://git.kernel.org/stable/c/fd5f289cca04ad869b34fc9ccb647670bfdb60ac"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:28.140",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89470"
                }
            ]
        },
        {
            "id": "CVE-2026-89469",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: lp8727: fix use-after-free in lp8727_release_irq()\n\nlp8727_isr_func(), the threaded IRQ handler, is the only caller that arms\npchg->work via schedule_delayed_work().  lp8727_release_irq() currently\ncancels the work before freeing the IRQ, so an IRQ delivered in between\ncan re-arm the work through the threaded handler.  After .remove returns\nthe devm layer frees pchg while lp8727_delayed_func() may still run and\ndereference it.\n\nFree the IRQ first so the threaded handler is quiesced and can no longer\nqueue work, then cancel the delayed work to drain the final generation.\n\nThis issue was found by an in-house static analysis tool.",
            "updated_at": "2026-09-13T07:17:10.137",
            "published_at": "2026-09-11T20:19:28.023",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "d71fda01610269e3aaedd451f8d3e34cdf550036 through before 80d4e40a85ba524e66c8c748aa7bb19eaf2f69df (git); d71fda01610269e3aaedd451f8d3e34cdf550036 through before ab6b1ad710bed7931540733ce145493fece8ceef (git); d71fda01610269e3aaedd451f8d3e34cdf550036 through before 6ab3128292df67295de1b2a86f21d89cf6612a7e (git); d71fda01610269e3aaedd451f8d3e34cdf550036 through before ceb6ac43b0f591722401922ceb958ce2616935e0 (git); 3.7",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: lp8727: fix use-after-free in lp8727_release_irq()\n\nlp8727_isr_func(), the threaded IRQ handler, is the only caller that arms\npchg->work via schedule_delayed_work().  lp8727_release_irq() currently\ncancels the work before freeing the IRQ, so an IRQ delivered in between\ncan re-arm the work through the threaded handler.  After .remove returns\nthe devm layer frees pchg while lp8727_delayed_func() may still run and\ndereference it.\n\nFree the IRQ first so the threaded handler is quiesced and can no longer\nqueue work, then cancel the delayed work to drain the final generation.\n\nThis issue was found by an in-house static analysis tool.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/6ab3128292df67295de1b2a86f21d89cf6612a7e",
                "https://git.kernel.org/stable/c/80d4e40a85ba524e66c8c748aa7bb19eaf2f69df",
                "https://git.kernel.org/stable/c/ab6b1ad710bed7931540733ce145493fece8ceef",
                "https://git.kernel.org/stable/c/ceb6ac43b0f591722401922ceb958ce2616935e0"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:28.023",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89469"
                }
            ]
        },
        {
            "id": "CVE-2026-89466",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: qcom_battmgr: terminate the strings from firmware\n\nThe qcom_battmgr_sc8280xp_strcpy() takes a Pascal-style string when the\nfirmware sends one. Otherwise it copies all BATTMGR_STRING_LEN bytes and\nleaves the destination without a terminator.\n\nThose destinations are model_number, serial_number and oem_info, each\nBATTMGR_STRING_LEN and declared next to each other. They go out to user\nspace as val->strval, which power_supply_format_property() prints with\n\"%s\", so a firmware string that fills the whole field makes that read run\ninto the following members.\n\nUse strscpy() so the copy always terminates, the way the SM8350 path\nalready does for the same field.",
            "updated_at": "2026-09-13T07:17:10.013",
            "published_at": "2026-09-11T20:19:27.673",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "29e8142b5623b5949587bcc4f591c4e6595c4aca through before 0e70a9b0d16acf7adebc4f386178a95da27c0027 (git); 29e8142b5623b5949587bcc4f591c4e6595c4aca through before ee053561e21ce1e1741dd64ca5ddcdb92e40edc1 (git); 29e8142b5623b5949587bcc4f591c4e6595c4aca through before 6cc6c28c9ab6e8ecf901397717a5b391b828cdaf (git); 29e8142b5623b5949587bcc4f591c4e6595c4aca through before ab1112df8f4ffa88cb024dd370c432ced80f77d8 (git); 6.3",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: qcom_battmgr: terminate the strings from firmware\n\nThe qcom_battmgr_sc8280xp_strcpy() takes a Pascal-style string when the\nfirmware sends one. Otherwise it copies all BATTMGR_STRING_LEN bytes and\nleaves the destination without a terminator.\n\nThose destinations are model_number, serial_number and oem_info, each\nBATTMGR_STRING_LEN and declared next to each other. They go out to user\nspace as val->strval, which power_supply_format_property() prints with\n\"%s\", so a firmware string that fills the whole field makes that read run\ninto the following members.\n\nUse strscpy() so the copy always terminates, the way the SM8350 path\nalready does for the same field.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0e70a9b0d16acf7adebc4f386178a95da27c0027",
                "https://git.kernel.org/stable/c/6cc6c28c9ab6e8ecf901397717a5b391b828cdaf",
                "https://git.kernel.org/stable/c/ab1112df8f4ffa88cb024dd370c432ced80f77d8",
                "https://git.kernel.org/stable/c/ee053561e21ce1e1741dd64ca5ddcdb92e40edc1"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:27.673",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89466"
                }
            ]
        },
        {
            "id": "CVE-2026-89465",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: rt9455: quiesce delayed work before teardown\n\nThe threaded IRQ handler can queue pwr_rdy_work,\nmax_charging_time_work and batt_presence_work.  pwr_rdy_work and\nbatt_presence_work can also queue max_charging_time_work, while\nbatt_presence_work can requeue itself.\n\nrt9455_remove() cancels max_charging_time_work before\nbatt_presence_work.  The latter can therefore queue\nmax_charging_time_work after it has already been cancelled:\n\n  rt9455_remove()                   workqueue\n    cancel pwr_rdy_work\n    cancel max_charging_time_work\n                                      batt_presence_work queues\n                                        max_charging_time_work\n    cancel batt_presence_work\n    return\n    devres frees rt9455_info\n                                      max_charging_time_work dereferences\n                                        rt9455_info\n\nThe IRQ also remains registered until devres cleanup and can queue more\nwork after any of the cancellation calls.  If rt9455_hw_init() fails\nafter the IRQ has been requested, probe returns without cancelling work\nthat may already have been queued.  A pending callback can then access\nrt9455_info after it has been freed.\n\nRegister rt9455_cancel_all_delayed_works() through\ndevm_add_action_or_reset() right after devm_power_supply_register().\ndevres invokes the action in reverse registration order, after the\nmanaged IRQ has been freed and before rt9455_info is released, so the\ndelayed works are drained in both rt9455_remove() and the probe error\npath.  Cancel pwr_rdy_work and batt_presence_work before\nmax_charging_time_work because both can queue the latter.\n\nThis issue was found by an in-house static analysis tool.",
            "updated_at": "2026-09-13T07:17:09.850",
            "published_at": "2026-09-11T20:19:27.533",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "e86d69dd786e94046b8f5be7df1b9a8226a40b2a through before df67c7a2fff8414aa766b8cd5ffe11ec1ca27d02 (git); e86d69dd786e94046b8f5be7df1b9a8226a40b2a through before 1b9978433c61a9b46e48832a1ebceee1cf5c9eb4 (git); e86d69dd786e94046b8f5be7df1b9a8226a40b2a through before 7323e562f6961e4b7bce3225cde4ecbc78260deb (git); e86d69dd786e94046b8f5be7df1b9a8226a40b2a through before 3e7a1ebc32fad5a558254a478efd401c17a24381 (git); 4.2",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\npower: supply: rt9455: quiesce delayed work before teardown\n\nThe threaded IRQ handler can queue pwr_rdy_work,\nmax_charging_time_work and batt_presence_work.  pwr_rdy_work and\nbatt_presence_work can also queue max_charging_time_work, while\nbatt_presence_work can requeue itself.\n\nrt9455_remove() cancels max_charging_time_work before\nbatt_presence_work.  The latter can therefore queue\nmax_charging_time_work after it has already been cancelled:\n\n  rt9455_remove()                   workqueue\n    cancel pwr_rdy_work\n    cancel max_charging_time_work\n                                      batt_presence_work queues\n                                        max_charging_time_work\n    cancel batt_presence_work\n    return\n    devres frees rt9455_info\n                                      max_charging_time_work dereferences\n                                        rt9455_info\n\nThe IRQ also remains registered until devres cleanup and can queue more\nwork after any of the cancellation calls.  If rt9455_hw_init() fails\nafter the IRQ has been requested, probe returns without cancelling work\nthat may already have been queued.  A pending callback can then access\nrt9455_info after it has been freed.\n\nRegister rt9455_cancel_all_delayed_works() through\ndevm_add_action_or_reset() right after devm_power_supply_register().\ndevres invokes the action in reverse registration order, after the\nmanaged IRQ has been freed and before rt9455_info is released, so the\ndelayed works are drained in both rt9455_remove() and the probe error\npath.  Cancel pwr_rdy_work and batt_presence_work before\nmax_charging_time_work because both can queue the latter.\n\nThis issue was found by an in-house static analysis tool.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1b9978433c61a9b46e48832a1ebceee1cf5c9eb4",
                "https://git.kernel.org/stable/c/3e7a1ebc32fad5a558254a478efd401c17a24381",
                "https://git.kernel.org/stable/c/7323e562f6961e4b7bce3225cde4ecbc78260deb",
                "https://git.kernel.org/stable/c/df67c7a2fff8414aa766b8cd5ffe11ec1ca27d02"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:27.533",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89465"
                }
            ]
        },
        {
            "id": "CVE-2026-89459",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/percpu: Fix MVIY_PERCPU() with older binutils\n\nCommit a737737cdb9c (\"s390/percpu: Infrastructure for more efficient\nthis_cpu operations\") introduced MVIY_PERCPU(), which stringifies\narguments that are already C string literals. This generates an\nassembler macro invocation with whitespace-separated quoted arguments:\n\n  GEN_MVIY \"459712\" \"%r3\"\n\nGNU as versions prior to binutils 2.39 drop the separating whitespace\nbetween quoted macro arguments during input scrubbing. They\nconsequently parse the invocation as a single argument and emit\nrepeated warnings:\n\n  Warning: missing closing `\"'\n\nThe .ifc in GEN_MVIY never matches and GNU as exits successfully\nwithout emitting the mviy instruction. As a result, the interrupted\nper-CPU sequence is not marked in lowcore and the exception return\npath cannot repair the per-CPU address register after migration.\n\nAll MVIY_PERCPU() callers pass C string literals. Use them directly\nand separate the assembler macro arguments with an explicit comma. The\nresulting invocation is:\n\n  GEN_MVIY 459712, %r3\n\nThis form is unambiguous for GNU as and LLVM's integrated assembler.\nThis behavior was fixed in GNU as from binutils 2.39, but Linux\nsupports binutils 2.30.",
            "updated_at": "2026-09-13T07:17:09.733",
            "published_at": "2026-09-11T20:19:26.780",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "a737737cdb9c94e40a9926cdc2320f874c05d709 through before 91770b08a120967077ae78600612f18bc5ee3caf (git); a737737cdb9c94e40a9926cdc2320f874c05d709 through before 101782f8945a125044347312d74d488c05741c4a (git); 7.2",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/percpu: Fix MVIY_PERCPU() with older binutils\n\nCommit a737737cdb9c (\"s390/percpu: Infrastructure for more efficient\nthis_cpu operations\") introduced MVIY_PERCPU(), which stringifies\narguments that are already C string literals. This generates an\nassembler macro invocation with whitespace-separated quoted arguments:\n\n  GEN_MVIY \"459712\" \"%r3\"\n\nGNU as versions prior to binutils 2.39 drop the separating whitespace\nbetween quoted macro arguments during input scrubbing. They\nconsequently parse the invocation as a single argument and emit\nrepeated warnings:\n\n  Warning: missing closing `\"'\n\nThe .ifc in GEN_MVIY never matches and GNU as exits successfully\nwithout emitting the mviy instruction. As a result, the interrupted\nper-CPU sequence is not marked in lowcore and the exception return\npath cannot repair the per-CPU address register after migration.\n\nAll MVIY_PERCPU() callers pass C string literals. Use them directly\nand separate the assembler macro arguments with an explicit comma. The\nresulting invocation is:\n\n  GEN_MVIY 459712, %r3\n\nThis form is unambiguous for GNU as and LLVM's integrated assembler.\nThis behavior was fixed in GNU as from binutils 2.39, but Linux\nsupports binutils 2.30.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/101782f8945a125044347312d74d488c05741c4a",
                "https://git.kernel.org/stable/c/91770b08a120967077ae78600612f18bc5ee3caf"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:26.780",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89459"
                }
            ]
        },
        {
            "id": "CVE-2026-89456",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: Propagate partial completion length across ERP recovery\n\ndasd_default_erp_postaction() copies the timing and device state from\nthe finished ERP request back to the original request but drops\nproc_bytes. A request that was partially completed, an ESE read of a\nnot-yet-allocated track returns fewer bytes than requested, and then\nrecovered through the ERP chain loses its partial-completion length.\n__dasd_cleanup_cqr() then sees proc_bytes == 0 and completes the whole\nrequest instead of requeueing the remainder, silently returning zeroed\ndata for the part that was never read.\n\nCarry proc_bytes over to the original request like the other\nper-request state.",
            "updated_at": "2026-09-13T07:17:09.600",
            "published_at": "2026-09-11T20:19:26.387",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5e6bdd37c5526ef01326df5dabb93011ee89237e through before d6b8778b1b82aa3a8dbf8612080f635b834bd16b (git); 5e6bdd37c5526ef01326df5dabb93011ee89237e through before ceafb262475ac6cb3a7d07b1102608be2b216b99 (git); 5e6bdd37c5526ef01326df5dabb93011ee89237e through before 15ec03452c18e8d288e519837d21b308300d74b2 (git); 5e6bdd37c5526ef01326df5dabb93011ee89237e through before 6fb5ba2e7e43173a3761e46f091070a8185efa14 (git); fbbacd0dcbc3ae9398c569dbea96ae4b5ad97e04 (git); 5f7c9989f11305aaa43e0f4378f4f070022a9f2b (git); 5.4.26 through before 5.5 (semver); 5.5.10 through before 5.6 (semver); 5.6",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: Propagate partial completion length across ERP recovery\n\ndasd_default_erp_postaction() copies the timing and device state from\nthe finished ERP request back to the original request but drops\nproc_bytes. A request that was partially completed, an ESE read of a\nnot-yet-allocated track returns fewer bytes than requested, and then\nrecovered through the ERP chain loses its partial-completion length.\n__dasd_cleanup_cqr() then sees proc_bytes == 0 and completes the whole\nrequest instead of requeueing the remainder, silently returning zeroed\ndata for the part that was never read.\n\nCarry proc_bytes over to the original request like the other\nper-request state.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/15ec03452c18e8d288e519837d21b308300d74b2",
                "https://git.kernel.org/stable/c/6fb5ba2e7e43173a3761e46f091070a8185efa14",
                "https://git.kernel.org/stable/c/ceafb262475ac6cb3a7d07b1102608be2b216b99",
                "https://git.kernel.org/stable/c/d6b8778b1b82aa3a8dbf8612080f635b834bd16b"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:26.387",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89456"
                }
            ]
        },
        {
            "id": "CVE-2026-89452",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/msm: Unwind probe state on registration failure\n\nmsm_iommu_probe() adds its devm-managed IOMMU object to\nqcom_iommu_devices before adding the IOMMU sysfs device and registering\nit with the IOMMU core.\n\nIf iommu_device_sysfs_add() fails, probe returns with the object still on\nqcom_iommu_devices. The driver core then releases the devm allocation,\nleaving a dangling list entry that later list walks may dereference.\n\nIf iommu_device_register() fails, the same dangling list entry remains\nand the sysfs device is left registered as well.\n\nUnwind the sysfs device and global list entry in reverse setup order on\nthe corresponding failure paths.",
            "updated_at": "2026-09-13T07:17:09.477",
            "published_at": "2026-09-11T20:19:25.843",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "42df43b36163ed7d0ab13992e411093252903273 through before f532401be9312ecd166f616bb74a65b0b4c150fa (git); 42df43b36163ed7d0ab13992e411093252903273 through before 7f7074a886c4a93e3d12076ce60a510a1ebe400c (git); 42df43b36163ed7d0ab13992e411093252903273 through before 535a200220ca2c83bc8bf54bd2cbe045d6ee70c4 (git); 4.11",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/msm: Unwind probe state on registration failure\n\nmsm_iommu_probe() adds its devm-managed IOMMU object to\nqcom_iommu_devices before adding the IOMMU sysfs device and registering\nit with the IOMMU core.\n\nIf iommu_device_sysfs_add() fails, probe returns with the object still on\nqcom_iommu_devices. The driver core then releases the devm allocation,\nleaving a dangling list entry that later list walks may dereference.\n\nIf iommu_device_register() fails, the same dangling list entry remains\nand the sysfs device is left registered as well.\n\nUnwind the sysfs device and global list entry in reverse setup order on\nthe corresponding failure paths.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/535a200220ca2c83bc8bf54bd2cbe045d6ee70c4",
                "https://git.kernel.org/stable/c/7f7074a886c4a93e3d12076ce60a510a1ebe400c",
                "https://git.kernel.org/stable/c/f532401be9312ecd166f616bb74a65b0b4c150fa"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:25.843",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89452"
                }
            ]
        },
        {
            "id": "CVE-2026-89450",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field\n\ntegra241_vintf_init_vsid() programs the guest-provided vSID into SID_MATCH,\nwhose VIRT_SID field spans bits [20:1] with bit 0 as the match-enable flag.\nThe HW therefore matches only a 20-bit Stream ID.\n\nThe bound check rejects only virt_sid > UINT_MAX, which admits a value far\nwider than the field. The write \"virt_sid << 1 | 0x1\" then drops every bit\nabove 20: a virt_sid of 0x80000000 lands as SID_MATCH = 0x1, a valid match\non vSID 0, so the entry aliases the wrong Stream ID. Because vdev->virt_id\nis guest-controlled, a VMM can trigger it.\n\nValidate virt_sid against the field width with FIELD_MAX(), and program the\nregister with FIELD_PREP() so the value and the field stay consistent.",
            "updated_at": "2026-09-13T07:17:09.350",
            "published_at": "2026-09-11T20:19:25.603",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 through before d903d99ffd22b0180bd745a43f221c21bcdd8d7c (git); 4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 through before 445204550f894ca325ac80a21e3df177ad073798 (git); 4dc0d12474f9d4833c3dd96b73d61e406d3f5dc7 through before 4379610c79bd88ddbea10e7f6c21e16d4b338c6b (git); 6.17",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/tegra241-cmdqv: Reject a vSID wider than the SID_MATCH field\n\ntegra241_vintf_init_vsid() programs the guest-provided vSID into SID_MATCH,\nwhose VIRT_SID field spans bits [20:1] with bit 0 as the match-enable flag.\nThe HW therefore matches only a 20-bit Stream ID.\n\nThe bound check rejects only virt_sid > UINT_MAX, which admits a value far\nwider than the field. The write \"virt_sid << 1 | 0x1\" then drops every bit\nabove 20: a virt_sid of 0x80000000 lands as SID_MATCH = 0x1, a valid match\non vSID 0, so the entry aliases the wrong Stream ID. Because vdev->virt_id\nis guest-controlled, a VMM can trigger it.\n\nValidate virt_sid against the field width with FIELD_MAX(), and program the\nregister with FIELD_PREP() so the value and the field stay consistent.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/4379610c79bd88ddbea10e7f6c21e16d4b338c6b",
                "https://git.kernel.org/stable/c/445204550f894ca325ac80a21e3df177ad073798",
                "https://git.kernel.org/stable/c/d903d99ffd22b0180bd745a43f221c21bcdd8d7c"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:25.603",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89450"
                }
            ]
        },
        {
            "id": "CVE-2026-89448",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Force requesting ACS when tboot is enabled\n\nCurrently the conditions of requesting ACS in detect_intel_iommu()\ndon't include tboot, leading to a possible misconfiguration with ACS\ndisabled (e.g. due to user opts) while iommu is later forced on by\ntboot_force_iommu().\n\nFix it by checking tboot in detect_intel_iommu().",
            "updated_at": "2026-09-13T07:17:09.220",
            "published_at": "2026-09-11T20:19:25.347",
            "cvss": 9.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5d990b627537e59a3a2f039ff588a4750e9c1a6a through before aaeb81241e802c86be69394f72d49fde3f861fbb (git); 5d990b627537e59a3a2f039ff588a4750e9c1a6a through before 45705a6bfdb283f7b3b509010fd617b72f942537 (git); 5d990b627537e59a3a2f039ff588a4750e9c1a6a through before 87bc611c6c98a41c00feb7b06b0c297dd141a2ae (git); 5d990b627537e59a3a2f039ff588a4750e9c1a6a through before 607432b2618b61df81134be0ef2562b8300c1216 (git); 2.6.33",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Force requesting ACS when tboot is enabled\n\nCurrently the conditions of requesting ACS in detect_intel_iommu()\ndon't include tboot, leading to a possible misconfiguration with ACS\ndisabled (e.g. due to user opts) while iommu is later forced on by\ntboot_force_iommu().\n\nFix it by checking tboot in detect_intel_iommu().",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/45705a6bfdb283f7b3b509010fd617b72f942537",
                "https://git.kernel.org/stable/c/607432b2618b61df81134be0ef2562b8300c1216",
                "https://git.kernel.org/stable/c/87bc611c6c98a41c00feb7b06b0c297dd141a2ae",
                "https://git.kernel.org/stable/c/aaeb81241e802c86be69394f72d49fde3f861fbb"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:25.347",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89448"
                }
            ]
        },
        {
            "id": "CVE-2026-89445",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Fix UAF in selftest IOPF reporting\n\nIOMMUFD selftest TRIGGER_IOPF borrows an attach handle from\ngroup->pasid_array without synchronizing against PASID detach,\nthen a concurrent iommu_report_device_fault() can dereference\nthat borrowed handle's domain pointer after the detach erases\nthe handle and frees the backing struct iommufd_attach_handle.\nTRIGGER_IOPF then dereferences the freed handle, causing a UAF.\n\nFix by adding a iopf_rwsem in mock_dev to follow the expected design\nof a real driver. Hold its read side across the whole\niommu_report_device_fault() call, and its write side around every\npath that attaches, detaches, or replaces a device domain.\nThis can block new reports and drains in-flight reports before an old\nattach handle or the IOPF fault parameter can be removed.\nAlso take the write side while registering a mock device, since\nit can invoke the mock driver's default-domain attach callback.",
            "updated_at": "2026-09-13T07:17:09.093",
            "published_at": "2026-09-11T20:19:24.990",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "ddee19971081b42615d62f4fdada21274708ed4d through before cab2895729516799384d48560e6fca105fb3f927 (git); ddee19971081b42615d62f4fdada21274708ed4d through before e27e90bde68b2ab92e63ed19caad1ef57188bea0 (git); ddee19971081b42615d62f4fdada21274708ed4d through before 8c07df7cdfcf52f1ff276c588612aabc6c6b8399 (git); 6.11",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\niommufd: Fix UAF in selftest IOPF reporting\n\nIOMMUFD selftest TRIGGER_IOPF borrows an attach handle from\ngroup->pasid_array without synchronizing against PASID detach,\nthen a concurrent iommu_report_device_fault() can dereference\nthat borrowed handle's domain pointer after the detach erases\nthe handle and frees the backing struct iommufd_attach_handle.\nTRIGGER_IOPF then dereferences the freed handle, causing a UAF.\n\nFix by adding a iopf_rwsem in mock_dev to follow the expected design\nof a real driver. Hold its read side across the whole\niommu_report_device_fault() call, and its write side around every\npath that attaches, detaches, or replaces a device domain.\nThis can block new reports and drains in-flight reports before an old\nattach handle or the IOPF fault parameter can be removed.\nAlso take the write side while registering a mock device, since\nit can invoke the mock driver's default-domain attach callback.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/8c07df7cdfcf52f1ff276c588612aabc6c6b8399",
                "https://git.kernel.org/stable/c/cab2895729516799384d48560e6fca105fb3f927",
                "https://git.kernel.org/stable/c/e27e90bde68b2ab92e63ed19caad1ef57188bea0"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:24.990",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89445"
                }
            ]
        },
        {
            "id": "CVE-2026-89443",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: ISST: Validate level in perf mask ioctls\n\nisst_if_get_perf_level_mask() and isst_if_get_base_freq_mask() use the\nuser-provided level as an index into perf_levels[] via\n_read_pp_level_info() and _read_bf_level_info(), but neither helper\nvalidates it first.\n\nThe adjacent level-info helpers reject levels above max_level before\nreading the same per-level register block. Add the same bounds checks to\nthe mask helpers, and reject disabled SST-PP levels in\nisst_if_get_perf_level_mask() to match isst_if_get_perf_level_info().\n\nThis prevents out-of-bounds reads from the per-level offset table on\ninvalid ioctl input.",
            "updated_at": "2026-09-13T07:17:08.977",
            "published_at": "2026-09-11T20:19:24.737",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "ea009e4769fa3bd05d4c111c3b6865eb3a9be829 through before 1a8bab5ceee1a42a78de12d3d69f67516a20588e (git); ea009e4769fa3bd05d4c111c3b6865eb3a9be829 through before 1889a9156553f0692acd57caf15e877baace1a01 (git); ea009e4769fa3bd05d4c111c3b6865eb3a9be829 through before d19385624bdfb577db9c94bb8879992fd5e17bcd (git); ea009e4769fa3bd05d4c111c3b6865eb3a9be829 through before 80e0d353c86a9a168ad6d213f494796294381538 (git); 6.4",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: ISST: Validate level in perf mask ioctls\n\nisst_if_get_perf_level_mask() and isst_if_get_base_freq_mask() use the\nuser-provided level as an index into perf_levels[] via\n_read_pp_level_info() and _read_bf_level_info(), but neither helper\nvalidates it first.\n\nThe adjacent level-info helpers reject levels above max_level before\nreading the same per-level register block. Add the same bounds checks to\nthe mask helpers, and reject disabled SST-PP levels in\nisst_if_get_perf_level_mask() to match isst_if_get_perf_level_info().\n\nThis prevents out-of-bounds reads from the per-level offset table on\ninvalid ioctl input.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1889a9156553f0692acd57caf15e877baace1a01",
                "https://git.kernel.org/stable/c/1a8bab5ceee1a42a78de12d3d69f67516a20588e",
                "https://git.kernel.org/stable/c/80e0d353c86a9a168ad6d213f494796294381538",
                "https://git.kernel.org/stable/c/d19385624bdfb577db9c94bb8879992fd5e17bcd"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:24.737",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89443"
                }
            ]
        },
        {
            "id": "CVE-2026-89442",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: ISST: Validate socket ID in clos_assoc ioctl\n\nisst_if_clos_assoc() validates the user-supplied socket_id with\n'socket_id > topology_max_packages()', but isst_common.sst_inst[] is\nallocated with topology_max_packages() entries, so the valid index range\nis [0, topology_max_packages()).  The '>' comparison lets\nsocket_id == topology_max_packages() pass and index one entry past the\narray.\n\nIn addition, isst_common.sst_inst[socket_id] is NULL for an in-range\npackage that has no bound TPMI SST instance, and the pointer is used\nwithout a NULL check.  Both the out-of-bounds entry and the NULL pointer\nare then dereferenced by map_partition_power_domain_id() and the\nfollowing power_domain_info access.\n\nReject socket_id >= topology_max_packages() and a NULL sst_inst, matching\nthe checks already performed by get_instance().",
            "updated_at": "2026-09-13T07:17:08.810",
            "published_at": "2026-09-11T20:19:24.613",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "12a7d2cb811dd8a884dea088a2701fcb8d00136e through before 0d90ab5f80e19cddfeb0c9fab47a1f34aa932075 (git); 12a7d2cb811dd8a884dea088a2701fcb8d00136e through before 82e707eff9e3b7ef6d96ecc23ea8876d20c7d6ca (git); 12a7d2cb811dd8a884dea088a2701fcb8d00136e through before 207b4dc6eb100141b122b2602504a1429a4b6558 (git); 12a7d2cb811dd8a884dea088a2701fcb8d00136e through before a89f07db0cb95c54dac4a8406c79a04e44a73c3c (git); 6.4",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: ISST: Validate socket ID in clos_assoc ioctl\n\nisst_if_clos_assoc() validates the user-supplied socket_id with\n'socket_id > topology_max_packages()', but isst_common.sst_inst[] is\nallocated with topology_max_packages() entries, so the valid index range\nis [0, topology_max_packages()).  The '>' comparison lets\nsocket_id == topology_max_packages() pass and index one entry past the\narray.\n\nIn addition, isst_common.sst_inst[socket_id] is NULL for an in-range\npackage that has no bound TPMI SST instance, and the pointer is used\nwithout a NULL check.  Both the out-of-bounds entry and the NULL pointer\nare then dereferenced by map_partition_power_domain_id() and the\nfollowing power_domain_info access.\n\nReject socket_id >= topology_max_packages() and a NULL sst_inst, matching\nthe checks already performed by get_instance().",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0d90ab5f80e19cddfeb0c9fab47a1f34aa932075",
                "https://git.kernel.org/stable/c/207b4dc6eb100141b122b2602504a1429a4b6558",
                "https://git.kernel.org/stable/c/82e707eff9e3b7ef6d96ecc23ea8876d20c7d6ca",
                "https://git.kernel.org/stable/c/a89f07db0cb95c54dac4a8406c79a04e44a73c3c"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:24.613",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89442"
                }
            ]
        },
        {
            "id": "CVE-2026-89441",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: via-sdmmc: cancel card-detect work on remove\n\nDisabling the device interrupt and freeing the IRQ prevents new card-detect\nwork from being queued, but carddet_work already queued by the handler can\nstill run after via_sd_remove() returns. via_sdc_card_detect() recovers the\nhost through container_of() and dereferences its MMIO base; once remove()\nreturns the host can be freed, so that work would touch freed memory.\n\nCancel carddet_work after freeing the IRQ and before cancelling\nfinish_bh_work, which the card-detect handler can also queue. carddet_work\ncan re-enable the interrupt through via_reset_pcictrl(); mask it again\nafterwards.\n\nThis issue was found by an in-house static analysis tool and confirmed by\nmanual code review.",
            "updated_at": "2026-09-13T07:17:08.650",
            "published_at": "2026-09-11T20:19:24.487",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f0bf7f61b8405224bc52fc9a3ccd167a68126e00 through before f7ff3027ef004a331ef911a4886f12bc2e996037 (git); f0bf7f61b8405224bc52fc9a3ccd167a68126e00 through before eaca730c6f5e3609df62a0469fb789235a93d276 (git); f0bf7f61b8405224bc52fc9a3ccd167a68126e00 through before 57e5d877f898d5e5c9d672a77bb6bdd24f0d9bf5 (git); 2.6.31",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: via-sdmmc: cancel card-detect work on remove\n\nDisabling the device interrupt and freeing the IRQ prevents new card-detect\nwork from being queued, but carddet_work already queued by the handler can\nstill run after via_sd_remove() returns. via_sdc_card_detect() recovers the\nhost through container_of() and dereferences its MMIO base; once remove()\nreturns the host can be freed, so that work would touch freed memory.\n\nCancel carddet_work after freeing the IRQ and before cancelling\nfinish_bh_work, which the card-detect handler can also queue. carddet_work\ncan re-enable the interrupt through via_reset_pcictrl(); mask it again\nafterwards.\n\nThis issue was found by an in-house static analysis tool and confirmed by\nmanual code review.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/57e5d877f898d5e5c9d672a77bb6bdd24f0d9bf5",
                "https://git.kernel.org/stable/c/eaca730c6f5e3609df62a0469fb789235a93d276",
                "https://git.kernel.org/stable/c/f7ff3027ef004a331ef911a4886f12bc2e996037"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:24.487",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89441"
                }
            ]
        },
        {
            "id": "CVE-2026-89440",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: via-sdmmc: stop card-detect handling on probe failure\n\nrequest_irq() registers the SD card-detect interrupt and the probe enables\nit before mmc_add_host() runs. If mmc_add_host() fails, the error path only\nunmaps the registers and returns: the interrupt stays registered, so the\nhandler keeps running against the host once it is freed. via_sdc_isr()\ndereferences sdhost and its MMIO base and schedules carddet_work, which\nvia_sdc_card_detect() also runs against freed memory through its\ncontainer_of() dereference.\n\nAdd a probe-error path that disables and frees the interrupt and cancels\ncarddet_work before unmapping. carddet_work can re-enable the device\ninterrupt via via_reset_pcictrl(), which restores PCIINTCTRL, so mask it\nagain after cancelling the work.\n\nThis issue was found by an in-house static analysis tool and confirmed by\nmanual code review.",
            "updated_at": "2026-09-13T07:17:08.490",
            "published_at": "2026-09-11T20:19:24.330",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "e4e46fb61e3bb4628170810d3f2b996b709b90d9 through before efe7f25dd27e35063477b4b0e7eed3675669fd99 (git); e4e46fb61e3bb4628170810d3f2b996b709b90d9 through before 2550f89589caad7402d618d7dffc038582c94b6b (git); e4e46fb61e3bb4628170810d3f2b996b709b90d9 through before c2b8a624911999399cc14822fec3e35032b3cee4 (git); e4e46fb61e3bb4628170810d3f2b996b709b90d9 through before 088eaa92fcebaa6b957ccf9635afdf39643a577d (git); 076bcd2c93e16b05c10564e299d6e5d26a766d00 (git); 12b8e81b77c05c658efd9cde3585bbd65ae39b59 (git); 95025a8dd0ec015872f6c16473fe04d6264e68ca (git); f59ef2a47a228e51322ad76752a55a8917c56e38 (git); 63400da6cd37a9793c19bb6aed7131b58b975a04 (git); 0959cc1685eb19774300d43ef25e318b457b156b (git); 0ec94795114edc7e24ec71849dce42bfa61dafa3 (git); ba91b413983a9235792523c6b9f7ba2586c4d75d (git); 4.9.337 through before 4.10 (semver); 4.14.303 through before 4.15 (semver); 4.19.270 through before 4.20 (semver); 5.4.229 through before 5.5 (semver); 5.10.163 through before 5.11 (semver); 5.15.86 through before 5.16 (semver); 6.0.16 through before 6.1 (semver); 6.1.2 through before 6.2 (semver); 6.2",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: via-sdmmc: stop card-detect handling on probe failure\n\nrequest_irq() registers the SD card-detect interrupt and the probe enables\nit before mmc_add_host() runs. If mmc_add_host() fails, the error path only\nunmaps the registers and returns: the interrupt stays registered, so the\nhandler keeps running against the host once it is freed. via_sdc_isr()\ndereferences sdhost and its MMIO base and schedules carddet_work, which\nvia_sdc_card_detect() also runs against freed memory through its\ncontainer_of() dereference.\n\nAdd a probe-error path that disables and frees the interrupt and cancels\ncarddet_work before unmapping. carddet_work can re-enable the device\ninterrupt via via_reset_pcictrl(), which restores PCIINTCTRL, so mask it\nagain after cancelling the work.\n\nThis issue was found by an in-house static analysis tool and confirmed by\nmanual code review.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/088eaa92fcebaa6b957ccf9635afdf39643a577d",
                "https://git.kernel.org/stable/c/2550f89589caad7402d618d7dffc038582c94b6b",
                "https://git.kernel.org/stable/c/c2b8a624911999399cc14822fec3e35032b3cee4",
                "https://git.kernel.org/stable/c/efe7f25dd27e35063477b4b0e7eed3675669fd99"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:24.330",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89440"
                }
            ]
        },
        {
            "id": "CVE-2026-89436",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[]\n\nacpi_pcc_retrieve_biosdata() rejects SINF packages only when\npcc->num_sifr is strictly less than hkey->package.count, then\nunconditionally writes a trailing sentinel at\npcc->sinf[hkey->package.count]. But pcc->sinf[] is allocated with\nexactly pcc->num_sifr elements (valid indices 0..num_sifr-1), so that\nwrite needs num_sifr strictly greater than package.count to stay in\nbounds -- num_sifr == package.count passes the existing check but\nstill overflows by one element.\n\nThis is exactly the case probe()'s existing num_sifr++ workaround\n(\"Some DSDT-s have an off-by-one bug where the SINF package count is\none higher than the SQTY reported value\") is written to accommodate:\nwhen a DSDT's SINF package count equals SQTY+1, the workaround makes\nnum_sifr equal to package.count, which is precisely the boundary that\noverflows here. Found via UBSan (array-index-out-of-bounds) on\nhardware where HKEY.SQTY returns 37 and HKEY.SINF()'s package has 38\nelements: num_sifr becomes 38 after the += 1 workaround, the loop\ncorrectly fills indices 0..37, and the sentinel write then targets\nindex 38, one past the end -- a silent 4-byte heap overflow on kernels\nwithout CONFIG_UBSAN.\n\nTightening the rejection check to num_sifr <= package.count would\navoid the overflow but breaks probe() entirely on exactly this\nhardware, since num_sifr == package.count is the case the off-by-one\nworkaround exists to support. Nothing else in the driver reads this\nsentinel value back, so simply skip the write when there is no room\nfor it instead.",
            "updated_at": "2026-09-13T07:17:08.367",
            "published_at": "2026-09-11T20:19:23.847",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "a3d0dbd18ce908292607bb6cf37c978ece8a33d4 through before a93df956ee4d903735b6d395362c839cb1dc07e3 (git); a3d0dbd18ce908292607bb6cf37c978ece8a33d4 through before 329f10d8be193bf36af124e00b9dd6644cd71724 (git); 7.2",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: panasonic-laptop: Fix sentinel write past pcc->sinf[]\n\nacpi_pcc_retrieve_biosdata() rejects SINF packages only when\npcc->num_sifr is strictly less than hkey->package.count, then\nunconditionally writes a trailing sentinel at\npcc->sinf[hkey->package.count]. But pcc->sinf[] is allocated with\nexactly pcc->num_sifr elements (valid indices 0..num_sifr-1), so that\nwrite needs num_sifr strictly greater than package.count to stay in\nbounds -- num_sifr == package.count passes the existing check but\nstill overflows by one element.\n\nThis is exactly the case probe()'s existing num_sifr++ workaround\n(\"Some DSDT-s have an off-by-one bug where the SINF package count is\none higher than the SQTY reported value\") is written to accommodate:\nwhen a DSDT's SINF package count equals SQTY+1, the workaround makes\nnum_sifr equal to package.count, which is precisely the boundary that\noverflows here. Found via UBSan (array-index-out-of-bounds) on\nhardware where HKEY.SQTY returns 37 and HKEY.SINF()'s package has 38\nelements: num_sifr becomes 38 after the += 1 workaround, the loop\ncorrectly fills indices 0..37, and the sentinel write then targets\nindex 38, one past the end -- a silent 4-byte heap overflow on kernels\nwithout CONFIG_UBSAN.\n\nTightening the rejection check to num_sifr <= package.count would\navoid the overflow but breaks probe() entirely on exactly this\nhardware, since num_sifr == package.count is the case the off-by-one\nworkaround exists to support. Nothing else in the driver reads this\nsentinel value back, so simply skip the write when there is no room\nfor it instead.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/329f10d8be193bf36af124e00b9dd6644cd71724",
                "https://git.kernel.org/stable/c/a93df956ee4d903735b6d395362c839cb1dc07e3"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:23.847",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89436"
                }
            ]
        },
        {
            "id": "CVE-2026-89308",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-89308 exploit",
            "summary": "Exploit for CVE-2026-89308. CVSS 9.3.",
            "updated_at": "2026-09-15T11:44:00Z",
            "published_at": "2026-09-15T11:44:00Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-89308",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.3,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-89308",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-89308"
                    ],
                    "repository": "Sploitus",
                    "author": "ENISA",
                    "first_seen": "2026-09-15T13:16:45",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-89308"
                },
                {
                    "title": "Exploit for CVE-2026-89308",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.3,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:H/SI:N/VA:H/SA:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-89308",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-89308"
                    ],
                    "repository": "web.nvd.nist.gov",
                    "author": "view",
                    "first_seen": "2026-09-15T13:16:45",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-89308"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=CVE-2026-89308",
                "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-89308"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T11:44:00Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-89308"
                }
            ]
        },
        {
            "id": "CVE-2026-89268",
            "vendor": "Webkul",
            "product": "QloApps",
            "title": "QloApps vulnerability",
            "summary": "QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions.",
            "updated_at": "2026-09-12T02:16:24.623",
            "published_at": "2026-09-12T02:16:24.623",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.7.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Qloapps/QloApps",
                "https://github.com/Qloapps/QloApps/blob/v1.7.0/admin/themes/default/template/helpers/list/list_header.tpl",
                "https://github.com/Qloapps/QloApps/commit/153ec1c8567798bd99155098ecc0a340e38f25bf",
                "https://github.com/Qloapps/QloApps/pull/1801",
                "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-list-filter-parameters"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T02:16:24.623",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89268"
                }
            ]
        },
        {
            "id": "CVE-2026-89267",
            "vendor": "jowilf",
            "product": "starlette-admin",
            "title": "starlette-admin vulnerability",
            "summary": "starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns.",
            "updated_at": "2026-09-12T02:16:23.580",
            "published_at": "2026-09-12T02:16:23.580",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.16.1 through 0.17.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to perform equality and comparison operations on excluded columns.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jowilf/starlette-admin",
                "https://github.com/jowilf/starlette-admin/blob/0.17.1/starlette_admin/views.py#L971-L987",
                "https://www.vulncheck.com/advisories/starlette-admin-0.16.1-through-0.17.1-searchable-fields-allowlist-bypass"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T02:16:23.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89267"
                }
            ]
        },
        {
            "id": "CVE-2026-89172",
            "vendor": "Microchip",
            "product": "AN1044",
            "title": "AN1044 vulnerability",
            "summary": "Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052.\n\nThis issue affects AN1044: through A; AN953: through A; SW300052: through 2.6.",
            "updated_at": "2026-09-12T10:16:36.317",
            "published_at": "2026-09-12T10:16:36.317",
            "cvss": 5.6,
            "cvss_vector": "CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through A (custom); 0 through 2.6 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Physical",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-1300",
            "what_happened": "Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052.\n\nThis issue affects AN1044: through A; AN953: through A; SW300052: through 2.6.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.microchip.com/en-us/application-notes/an1044",
                "https://www.microchip.com/en-us/application-notes/an953",
                "https://www.microchip.com/en-us/development-tool/sw300052",
                "https://www.microchip.com/en-us/solutions/technologies/embedded-security/how-to-report-potential-product-security-vulnerabilities/side-channel-attack-an1044-an953-sw300052-cryptographic-algorithms"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T10:16:36.317",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89172"
                }
            ]
        },
        {
            "id": "CVE-2026-89151",
            "vendor": "Forgejo",
            "product": "Forgejo",
            "title": "Forgejo vulnerability",
            "summary": "Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the \"allow maintainer edit\" feature.",
            "updated_at": "2026-09-11T03:16:24.450",
            "published_at": "2026-09-11T03:16:24.450",
            "cvss": 3.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16.0.0 through before 16.0.4 (semver); before 15.0.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-863",
            "what_happened": "Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the \"allow maintainer edit\" feature.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://codeberg.org/forgejo/forgejo/milestone/139655",
                "https://codeberg.org/forgejo/forgejo/src/branch/forgejo/release-notes-published/15.0.8.md"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T03:16:24.450",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89151"
                }
            ]
        },
        {
            "id": "CVE-2026-89145",
            "vendor": "flextype",
            "product": "flextype",
            "title": "flextype vulnerability",
            "summary": "Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can create a plugin with HTML characters in its name to execute arbitrary scripts in users' browsers when dependency validation fails.",
            "updated_at": "2026-09-11T02:18:35.617",
            "published_at": "2026-09-11T02:18:35.617",
            "cvss": 2.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.9.9 through 1.0.0-alpha.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can create a plugin with HTML characters in its name to execute arbitrary scripts in users' browsers when dependency validation fails.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/flextype/flextype",
                "https://github.com/flextype/flextype/blob/aea4ead8c449ea5517ed53b6dcbd28b0a528ad9d/src/flextype/core/Plugins.php#L345",
                "https://github.com/flextype/flextype/issues/597",
                "https://www.vulncheck.com/advisories/flextype-cms-0.9.9-through-1.0.0-alpha.3-stored-xss-via-plugin-directory"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T02:18:35.617",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89145"
                }
            ]
        },
        {
            "id": "CVE-2026-89092",
            "vendor": "The GNU C Library",
            "product": "glibc",
            "title": "glibc vulnerability",
            "summary": "The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service.",
            "updated_at": "2026-09-11T04:18:02.977",
            "published_at": "2026-09-11T02:18:35.460",
            "cvss": 4.2,
            "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.3.4 through before 2.45 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-789",
            "what_happened": "The nscd service in the GNU C Library 2.3.4 onwards may crash due to a \nstack overflow when a malicious DNS server returns too large a response \nfor a DNS query, resulting in degraded DNS resolution for the system.\n\n\n\nExploitation of this bug needs a system that has nscd enabled and using \nan untrusted DNS server for name resolution, with the compromised DNS \nserver being capable of processing records large enough to result in a \nstack overflow in an nscd thread stack.  During experimentation, bind 9 \nwas unable to handle large records, but that could change in future or \nwith a different name server.  In typical installations, nscd is \nexecuted in an isolated context as its own user without a shell, due to \nwhich any compromise of that service is isolated.\n\n\n\nThere is a remote possibility of nscd cache corruption if an attacker \nmanages to get the stack pointer into a desired point in the heap, \npotentially resulting in other caches in nscd being overwritten with \ncorrupt data through the stack overflow, until the buggy code path \neventually results in a crash.\n\n\n\nFinally, a crash in nscd may result in performance degradation when \nresolving names, but it does not result in a denial of service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sourceware.org/bugzilla/show_bug.cgi?id=34624",
                "https://sourceware.org/git/?p=glibc.git;a=blob_plain;f=advisories/GLIBC-SA-2026-0016",
                "http://www.openwall.com/lists/oss-security/2026/09/11/2"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T02:18:35.460",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89092"
                }
            ]
        },
        {
            "id": "CVE-2026-89080",
            "vendor": "Unknown",
            "product": "Really Simple Security",
            "title": "Really Simple Security vulnerability",
            "summary": "The Really Simple Security  WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.",
            "updated_at": "2026-09-13T11:16:59.650",
            "published_at": "2026-09-13T06:16:25.637",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.5.10.1 through before 9.8.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-287",
            "what_happened": "The Really Simple Security  WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypass the second factor and obtain that user's session, up to administrator.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/49546064-5663-40f8-be7c-4f3faa31fa9a/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T06:16:25.637",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89080"
                }
            ]
        },
        {
            "id": "CVE-2026-89050",
            "vendor": "Unknown",
            "product": "Quads Ads Manager for Google AdSense",
            "title": "Quads Ads Manager for Google AdSense vulnerability",
            "summary": "The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.",
            "updated_at": "2026-09-13T21:17:02.460",
            "published_at": "2026-09-13T21:17:02.460",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.0.4 through before 3.0.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling order as paid, allowing users who can place an order to obtain a paid ad placement without payment.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/da063797-1c68-4164-a94b-9e9b628bcd75/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:17:02.460",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-89050"
                }
            ]
        },
        {
            "id": "CVE-2026-89013",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-89013",
            "summary": "Dolibarr 23.0.4–24.0.0 authorization bypass via hashp=shared allows unauthenticated file read.",
            "updated_at": "2026-09-11T20:07:54Z",
            "published_at": "2026-09-11T20:07:54Z",
            "cvss": 8.7,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Dolibarr 23.0.4–24.0.0 authorization bypass via hashp=shared allows unauthenticated file read.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-89013",
                    "summary": "Dolibarr 23.0.4–24.0.0 authorization bypass via hashp=shared allows unauthenticated file read.",
                    "what_happened": "Dolibarr 23.0.4–24.0.0 authorization bypass via hashp=shared allows unauthenticated file read.",
                    "cvss": 8.7,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:N/SI:N/VA:N/SA:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=BAAF8349-AB02-5C71-B94E-0F3276B4A5E9",
                        "https://github.com/Faceless0x7/CVE-2026-89013"
                    ],
                    "repository": "Sploitus",
                    "author": "Faceless0x7",
                    "first_seen": "2026-09-11T22:07:54",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=BAAF8349-AB02-5C71-B94E-0F3276B4A5E9"
                },
                {
                    "repository": "Faceless0x7/CVE-2026-89013",
                    "author": "Faceless0x7",
                    "first_seen": "2026-09-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 4,
                    "title": "CVE-2026-89013 Exploit — Authorization bypass in Dolibarr via the hashp parameter, enabling unauthenticated access to protected documents and files.",
                    "summary": "CVE-2026-89013 Exploit — Authorization bypass in Dolibarr via the hashp parameter, enabling unauthenticated access to protected documents and files.",
                    "url": "https://github.com/Faceless0x7/CVE-2026-89013"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=BAAF8349-AB02-5C71-B94E-0F3276B4A5E9",
                "https://github.com/Faceless0x7/CVE-2026-89013"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:07:54Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=BAAF8349-AB02-5C71-B94E-0F3276B4A5E9"
                }
            ],
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:N/VI:N/SI:N/VA:N/SA:N"
        },
        {
            "id": "CVE-2026-89012",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-89012",
            "summary": "Case-sensitive denylist bypass in Dolibarr 24.0.0 universal search leaks password hashes.",
            "updated_at": "2026-09-11T20:05:28Z",
            "published_at": "2026-09-11T20:05:28Z",
            "cvss": 7.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Case-sensitive denylist bypass in Dolibarr 24.0.0 universal search leaks password hashes.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-89012",
                    "summary": "Case-sensitive denylist bypass in Dolibarr 24.0.0 universal search leaks password hashes.",
                    "what_happened": "Case-sensitive denylist bypass in Dolibarr 24.0.0 universal search leaks password hashes.",
                    "cvss": 7.1,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/SC:N/VI:N/SI:N/VA:N/SA:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=BFC7CD0E-1507-5808-A8E8-D1E81456FB9E",
                        "https://github.com/Faceless0x7/CVE-2026-89012"
                    ],
                    "repository": "Sploitus",
                    "author": "Faceless0x7",
                    "first_seen": "2026-09-11T22:05:28",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=BFC7CD0E-1507-5808-A8E8-D1E81456FB9E"
                },
                {
                    "repository": "Faceless0x7/CVE-2026-89012",
                    "author": "Faceless0x7",
                    "first_seen": "2026-09-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 5,
                    "title": "CVE-2026-89012 Exploit — SQL filter denylist bypass in Dolibarr via case-insensitive SQL column resolution and case-sensitive denylist matching.",
                    "summary": "CVE-2026-89012 Exploit — SQL filter denylist bypass in Dolibarr via case-insensitive SQL column resolution and case-sensitive denylist matching.",
                    "url": "https://github.com/Faceless0x7/CVE-2026-89012"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=BFC7CD0E-1507-5808-A8E8-D1E81456FB9E",
                "https://github.com/Faceless0x7/CVE-2026-89012"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:05:28Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=BFC7CD0E-1507-5808-A8E8-D1E81456FB9E"
                }
            ],
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/SC:N/VI:N/SI:N/VA:N/SA:N"
        },
        {
            "id": "CVE-2026-88995",
            "vendor": "Unknown",
            "product": "Bookit — Booking & Appointment Calendar",
            "title": "Bookit — Booking & Appointment Calendar vulnerability",
            "summary": "The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.",
            "updated_at": "2026-09-13T11:16:59.487",
            "published_at": "2026-09-13T06:16:25.543",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.6.0.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, including free-text booking comments and contact information.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/5a6f6d75-e7b8-44ad-a0f6-f6e4938ac3d5/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T06:16:25.543",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88995"
                }
            ]
        },
        {
            "id": "CVE-2026-88914",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.",
            "updated_at": "2026-09-11T02:18:35.300",
            "published_at": "2026-09-11T02:18:35.300",
            "cvss": 4.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/security/cve/CVE-2026-88914",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2531416",
                "https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12433",
                "https://gstreamer.freedesktop.org/security/sa-2026-0079.html"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T02:18:35.300",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88914"
                }
            ]
        },
        {
            "id": "CVE-2026-88912",
            "vendor": "Unknown",
            "product": "rtMedia for WordPress, BuddyPress and bbPress",
            "title": "rtMedia for WordPress, BuddyPress and bbPress vulnerability",
            "summary": "The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level account or above to make another user's private activity public or hide it.",
            "updated_at": "2026-09-13T11:16:59.293",
            "published_at": "2026-09-13T06:16:25.447",
            "cvss": 4.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.7.12 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-639",
            "what_happened": "The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, allowing users with a subscriber-level account or above to make another user's private activity public or hide it.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/58115528-18b6-4f2a-9f6c-d84fdcd6efb4/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T06:16:25.447",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88912"
                }
            ]
        },
        {
            "id": "CVE-2026-88802",
            "vendor": "Unknown",
            "product": "MDJM Event Management",
            "title": "MDJM Event Management vulnerability",
            "summary": "The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.",
            "updated_at": "2026-09-13T21:17:02.323",
            "published_at": "2026-09-13T21:17:02.323",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.7.8.5 (semver); 0 through 1.4.8.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to their playlist entry removal, allowing unauthenticated attackers to destroy arbitrary posts, pages and media attachments, bypassing the trash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/cac1846c-bbf4-4ad2-8dfb-d7025034a9a7/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:17:02.323",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88802"
                }
            ]
        },
        {
            "id": "CVE-2026-88793",
            "vendor": "Unknown",
            "product": "YouTube Embed",
            "title": "YouTube Embed vulnerability",
            "summary": "The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing unauthenticated attackers to store arbitrary web scripts which will execute in the session of any user viewing the affected content, including an administrator.",
            "updated_at": "2026-09-13T21:17:02.197",
            "published_at": "2026-09-13T21:17:02.197",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0 through 10.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing unauthenticated attackers to store arbitrary web scripts which will execute in the session of any user viewing the affected content, including an administrator.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/7f695b0c-5dbc-4f3e-9b3f-c3558b1729ad/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:17:02.197",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88793"
                }
            ]
        },
        {
            "id": "CVE-2026-88765",
            "vendor": "GitLab",
            "product": "GitLab",
            "title": "GitLab vulnerability",
            "summary": "GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to overflow the Unicode conversion buffer used in Advanced Search indexing.",
            "updated_at": "2026-09-16T04:18:45.750",
            "published_at": "2026-09-15T18:19:36.203",
            "cvss": 8.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "12.3 through before 19.1.8 (semver); 19.2 through before 19.2.6 (semver); 19.3 through before 19.3.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-77",
            "what_happened": "GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to overflow the Unicode conversion buffer used in Advanced Search indexing.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gitlab.com/gitlab-org/gitlab/-/work_items/627435",
                "https://hackerone.com/reports/3990469"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T18:19:36.203",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88765"
                }
            ]
        },
        {
            "id": "CVE-2026-88764",
            "vendor": "Unknown",
            "product": "Simple Membership",
            "title": "Simple Membership vulnerability",
            "summary": "The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level.",
            "updated_at": "2026-09-13T11:16:59.127",
            "published_at": "2026-09-13T06:16:25.350",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.7.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/54fdf46e-0385-40a3-b3bc-a862dc0fb03e/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T06:16:25.350",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88764"
                }
            ]
        },
        {
            "id": "CVE-2026-88260",
            "vendor": "Brainzcompany",
            "product": "Zenius EMS 8.0",
            "title": "Zenius EMS 8.0 vulnerability",
            "summary": "Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion.\n\nThis issue affects Zenius EMS 8.0: through OAM (Build 109).",
            "updated_at": "2026-09-11T03:16:24.303",
            "published_at": "2026-09-11T03:16:24.303",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through OAM (Build 109) (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-288",
            "what_happened": "Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion.\n\nThis issue affects Zenius EMS 8.0: through OAM (Build 109).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.brainz.co.kr/Features"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T03:16:24.303",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-88260"
                }
            ]
        },
        {
            "id": "CVE-2026-87919",
            "vendor": "Unknown",
            "product": "Product XML Feed Manager for WooCommerce",
            "title": "Product XML Feed Manager for WooCommerce vulnerability",
            "summary": "The Product XML Feed Manager for WooCommerce  WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the shortcode.",
            "updated_at": "2026-09-12T16:16:43.750",
            "published_at": "2026-09-12T06:16:28.537",
            "cvss": 4.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.1.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The Product XML Feed Manager for WooCommerce  WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that contains the shortcode.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/2e2f48d3-9106-4357-beec-4dbea02223dc/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:28.537",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87919"
                }
            ]
        },
        {
            "id": "CVE-2026-87918",
            "vendor": "Unknown",
            "product": "WPBot",
            "title": "WPBot vulnerability",
            "summary": "The WPBot  WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using the site's own configured API keys.",
            "updated_at": "2026-09-12T16:16:43.610",
            "published_at": "2026-09-12T06:16:28.430",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 8.5.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "The WPBot  WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI providers, allowing unauthenticated attackers to make those third-party API calls, and consume the associated cost, using the site's own configured API keys.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/d6b3745b-bda1-4734-b39c-75376477ba0a/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:28.430",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87918"
                }
            ]
        },
        {
            "id": "CVE-2026-87916",
            "vendor": "Unknown",
            "product": "WPBot",
            "title": "WPBot vulnerability",
            "summary": "The WPBot  WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range.",
            "updated_at": "2026-09-12T16:16:43.467",
            "published_at": "2026-09-12T06:16:28.317",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.4.9 through before 8.6.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The WPBot  WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated attackers to retrieve the name, email address and phone number of every chat visitor by requesting a wide date range.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/31d65e66-10b1-467a-8b20-ecf4880359e0/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:28.317",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87916"
                }
            ]
        },
        {
            "id": "CVE-2026-87894",
            "vendor": "Unknown",
            "product": "Rox Appointment Booking",
            "title": "Rox Appointment Booking vulnerability",
            "summary": "The Rox Appointment Booking  WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking details and payment status by enumerating that identifier.",
            "updated_at": "2026-09-12T16:16:43.323",
            "published_at": "2026-09-12T06:16:28.217",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.9 through before 1.2.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "The Rox Appointment Booking  WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each booking is addressed by a sequential numeric identifier, allowing unauthenticated attackers to read any customer's name, email, phone, booking details and payment status by enumerating that identifier.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/3f098db1-5406-4a77-adb1-99a66eb806a4/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:28.217",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87894"
                }
            ]
        },
        {
            "id": "CVE-2026-87892",
            "vendor": "Unknown",
            "product": "Rox Appointment Booking",
            "title": "Rox Appointment Booking vulnerability",
            "summary": "The Rox Appointment Booking  WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method restrictions.",
            "updated_at": "2026-09-12T16:16:43.180",
            "published_at": "2026-09-12T06:16:28.110",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.2.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "The Rox Appointment Booking  WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when creating a booking, allowing unauthenticated attackers to create confirmed bookings at an arbitrary price and to bypass the site's configured payment-method restrictions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/971084b9-5bf9-438a-a94d-435d1b1f01d1/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:28.110",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87892"
                }
            ]
        },
        {
            "id": "CVE-2026-87891",
            "vendor": "Unknown",
            "product": "Rox Appointment Booking",
            "title": "Rox Appointment Booking vulnerability",
            "summary": "The Rox Appointment Booking  WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner intended to keep closed.",
            "updated_at": "2026-09-12T16:16:43.040",
            "published_at": "2026-09-12T06:16:28.003",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.2.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "The Rox Appointment Booking  WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to overwrite the dates the booking system treats as unavailable, which can block legitimate bookings or open dates the site owner intended to keep closed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/e7f3b29e-2503-41bb-b15c-3c0ef71a3a00/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:28.003",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87891"
                }
            ]
        },
        {
            "id": "CVE-2026-87888",
            "vendor": "Unknown",
            "product": "YayPricing",
            "title": "YayPricing vulnerability",
            "summary": "The YayPricing  WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing  WordPress plugin before 3.5.7's settings page.",
            "updated_at": "2026-09-12T16:16:42.897",
            "published_at": "2026-09-12T06:16:27.890",
            "cvss": 8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.5.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The YayPricing  WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the subscriber role and above to store JavaScript that executes in the browser of an administrator who opens the YayPricing  WordPress plugin before 3.5.7's settings page.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/19bc425d-2aa3-4b2b-bc66-ac5ea96502e0/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:27.890",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87888"
                }
            ]
        },
        {
            "id": "CVE-2026-87886",
            "vendor": "Acronis",
            "product": "Backup",
            "title": "Acronis Backup Incorrect Default Permissions Vulnerability",
            "summary": "Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.",
            "updated_at": "2026-09-15T22:00:00Z",
            "published_at": "2026-09-15T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-87842",
            "vendor": "Unknown",
            "product": "Zonify",
            "title": "Zonify vulnerability",
            "summary": "The Zonify  WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.",
            "updated_at": "2026-09-12T16:16:42.750",
            "published_at": "2026-09-12T06:16:27.770",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.0.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The Zonify  WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/fb0cafdc-d1d5-4cad-852e-b0d569ae4469/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:27.770",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87842"
                }
            ]
        },
        {
            "id": "CVE-2026-87797",
            "vendor": "Unknown",
            "product": "Sprout Invoices",
            "title": "Sprout Invoices vulnerability",
            "summary": "The Sprout Invoices  WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users.",
            "updated_at": "2026-09-12T16:16:42.607",
            "published_at": "2026-09-12T06:16:27.660",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 20.8.16 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The Sprout Invoices  WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one of its AJAX actions, allowing any authenticated user such as a subscriber to overwrite private notes on records belonging to other users.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/ded55e47-568d-4702-b043-4707e4182a09/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:27.660",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87797"
                }
            ]
        },
        {
            "id": "CVE-2026-87759",
            "vendor": "Unknown",
            "product": "Add User Autocomplete",
            "title": "Add User Autocomplete vulnerability",
            "summary": "The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to grant themselves the administrator role on a multisite installation.",
            "updated_at": "2026-09-12T16:16:42.473",
            "published_at": "2026-09-12T06:16:27.547",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to grant themselves the administrator role on a multisite installation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/41020730-c79a-43b4-a902-3a34fdca90d6/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:27.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87759"
                }
            ]
        },
        {
            "id": "CVE-2026-87719",
            "vendor": "GitLab",
            "product": "GitLab",
            "title": "GitLab vulnerability",
            "summary": "GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.",
            "updated_at": "2026-09-15T04:18:19.173",
            "published_at": "2026-09-12T03:16:31.477",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "18.3 through before 19.1.8 (semver); 19.2 through before 19.2.6 (semver); 19.3 through before 19.3.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gitlab.com/gitlab-org/gitlab/-/work_items/628160",
                "https://hackerone.com/reports/4012289"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T03:16:31.477",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87719"
                }
            ]
        },
        {
            "id": "CVE-2026-87606",
            "vendor": "Google",
            "product": "Chrome",
            "title": "Exploit for Out-of-bounds Write in Google Chrome CVE-2026-85046 CVE-2026-87491 CVE-2026-87575 CVE-2026-87606",
            "summary": "Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
            "updated_at": "2026-09-11T13:57:30.703",
            "published_at": "2026-09-09T01:17:18.660",
            "cvss": 8.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "153.0.8010.36 through before 153.0.8010.36 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 38,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Missing authorization in SiteIsolation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Out-of-bounds Write in Google Chrome CVE-2026-85046 CVE-2026-87491 CVE-2026-87575 CVE-2026-87606",
                    "summary": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "what_happened": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B",
                        "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass."
                    ],
                    "repository": "Sploitus",
                    "author": "SneakyNachos",
                    "first_seen": "2026-09-12T17:35:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B"
                },
                {
                    "title": "Exploit for Out-of-bounds Write in Google Chrome CVE-2026-85046 CVE-2026-87491 CVE-2026-87575 CVE-2026-87606",
                    "summary": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "what_happened": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B",
                        "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass."
                    ],
                    "repository": "SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass.",
                    "author": "SneakyNachos",
                    "first_seen": "2026-09-12T17:35:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass."
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B",
                "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass.",
                "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html",
                "https://issues.chromium.org/issues/495933780"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T15:35:58Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B"
                },
                {
                    "at": "2026-09-09T01:17:18.660",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87606"
                }
            ],
            "enrichment_checked_at": "2026-09-12T22:05:27Z",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2026-87575",
            "vendor": "Google",
            "product": "Chrome",
            "title": "Exploit for Out-of-bounds Write in Google Chrome CVE-2026-85046 CVE-2026-87491 CVE-2026-87575 CVE-2026-87606",
            "summary": "Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)",
            "updated_at": "2026-09-10T14:16:10.953",
            "published_at": "2026-09-09T01:17:15.277",
            "cvss": 5.4,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "153.0.8010.36 through before 153.0.8010.36 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 38,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "Incorrect authorization in Loader in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Out-of-bounds Write in Google Chrome CVE-2026-85046 CVE-2026-87491 CVE-2026-87575 CVE-2026-87606",
                    "summary": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "what_happened": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B",
                        "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass."
                    ],
                    "repository": "Sploitus",
                    "author": "SneakyNachos",
                    "first_seen": "2026-09-12T17:35:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B"
                },
                {
                    "title": "Exploit for Out-of-bounds Write in Google Chrome CVE-2026-85046 CVE-2026-87491 CVE-2026-87575 CVE-2026-87606",
                    "summary": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "what_happened": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B",
                        "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass."
                    ],
                    "repository": "SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass.",
                    "author": "SneakyNachos",
                    "first_seen": "2026-09-12T17:35:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass."
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B",
                "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass.",
                "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html",
                "https://issues.chromium.org/issues/540013886"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T15:35:58Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B"
                },
                {
                    "at": "2026-09-09T01:17:15.277",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87575"
                }
            ],
            "enrichment_checked_at": "2026-09-12T22:05:26Z",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
        },
        {
            "id": "CVE-2026-87491",
            "vendor": "Google",
            "product": "Chromium V8",
            "title": "Google Chromium V8 Out of Bounds Write Vulnerability",
            "summary": "Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.",
            "updated_at": "2026-09-10T12:49:02.630",
            "published_at": "2026-09-09T01:17:05.887",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "153.0.8010.36 through before 153.0.8010.36 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 62,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Out-of-bounds Write in Google Chrome CVE-2026-85046 CVE-2026-87491 CVE-2026-87575 CVE-2026-87606",
                    "summary": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "what_happened": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B",
                        "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass."
                    ],
                    "repository": "Sploitus",
                    "author": "SneakyNachos",
                    "first_seen": "2026-09-12T17:35:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B"
                },
                {
                    "title": "Exploit for Out-of-bounds Write in Google Chrome CVE-2026-85046 CVE-2026-87491 CVE-2026-87575 CVE-2026-87606",
                    "summary": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "what_happened": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B",
                        "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass."
                    ],
                    "repository": "SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass.",
                    "author": "SneakyNachos",
                    "first_seen": "2026-09-12T17:35:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass."
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html",
                "https://issues.chromium.org/issues/543557673",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-87491",
                "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B",
                "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass."
            ],
            "timeline": [
                {
                    "at": "2026-09-08T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09T01:17:05.887",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87491"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "enrichment_checked_at": "2026-09-12T22:05:26Z",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-86836",
            "vendor": "Eclipse Foundation",
            "product": "Eclipse Ankaios",
            "title": "Eclipse Ankaios vulnerability",
            "summary": "In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a directory or FIFO already exists at that path when the agent (re)starts, the agent reuses it based only on an existence and/or file-type check, without validating its owner or permissions. A local, unprivileged user with write access to the same base directory (by default under `$TMPDIR/ankaios`, e.g. shared `/tmp`) can pre-create this path hierarchy, including the two Control Interface FIFOs, before the agent starts. The agent then treats the attacker-owned FIFOs as the legitimate Control Interface for the targeted workload. The attacker can complete the Control Interface handshake and issue requests using that workload's configured `controlInterfaceAccess` permissions, allowing impersonation of the workload and, depending on its configured permissions, unauthorized reading and/or modification of the cluster's desired state.",
            "updated_at": "2026-09-15T09:16:44.380",
            "published_at": "2026-09-14T18:20:20.193",
            "cvss": 8.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.1.0 through 1.0.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-276",
            "what_happened": "In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a directory or FIFO already exists at that path when the agent (re)starts, the agent reuses it based only on an existence and/or file-type check, without validating its owner or permissions. A local, unprivileged user with write access to the same base directory (by default under `$TMPDIR/ankaios`, e.g. shared `/tmp`) can pre-create this path hierarchy, including the two Control Interface FIFOs, before the agent starts. The agent then treats the attacker-owned FIFOs as the legitimate Control Interface for the targeted workload. The attacker can complete the Control Interface handshake and issue requests using that workload's configured `controlInterfaceAccess` permissions, allowing impersonation of the workload and, depending on its configured permissions, unauthorized reading and/or modification of the cluster's desired state.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/eclipse-ankaios/ankaios/pull/799",
                "https://github.com/eclipse-ankaios/ankaios/releases/tag/v1.0.3",
                "https://gitlab.eclipse.org/security/cve-assignment/-/work_items/280"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T18:20:20.193",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86836"
                }
            ]
        },
        {
            "id": "CVE-2026-86790",
            "vendor": "Unknown",
            "product": "WP Highlight Box",
            "title": "WP Highlight Box vulnerability",
            "summary": "The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.",
            "updated_at": "2026-09-12T16:16:42.327",
            "published_at": "2026-09-12T06:16:27.427",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/b48571ae-368e-4193-977a-f22fb09db4d4/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:27.427",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86790"
                }
            ]
        },
        {
            "id": "CVE-2026-86544",
            "vendor": "knowns-dev",
            "product": "knowns",
            "title": "knowns vulnerability",
            "summary": "knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.",
            "updated_at": "2026-09-07T23:16:54.303",
            "published_at": "2026-09-07T23:16:54.303",
            "cvss": 7.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.30.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/permissions/guard.go#L44-L60",
                "https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/permissions/registry.go#L99-L140",
                "https://github.com/knowns-dev/knowns/commit/a2c98fc5c313463576c9348beeec6a74ddd7333b",
                "https://github.com/knowns-dev/knowns/releases/tag/v0.30.0",
                "https://github.com/knowns-dev/knowns/security/advisories/GHSA-w323-3wpx-f7g5",
                "https://www.vulncheck.com/advisories/knowns-before-0.30.0-authorization-bypass-via-misclassified-code-actions"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:54.303",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86544"
                }
            ]
        },
        {
            "id": "CVE-2026-86543",
            "vendor": "knowns-dev",
            "product": "knowns",
            "title": "knowns vulnerability",
            "summary": "knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.",
            "updated_at": "2026-09-07T23:16:54.160",
            "published_at": "2026-09-07T23:16:54.160",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.30.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/cli/browser.go#L193-L200",
                "https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/auth.go#L80-L86",
                "https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/routes/tunnel.go#L26-L38",
                "https://github.com/knowns-dev/knowns/commit/878a02cb7cc14f0a592fdfda7a520af3cac500fb",
                "https://github.com/knowns-dev/knowns/releases/tag/v0.30.0",
                "https://github.com/knowns-dev/knowns/security/advisories/GHSA-fc85-99vc-9c75",
                "https://www.vulncheck.com/advisories/knowns-before-0.30.0-unauthenticated-management-api-exposure"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:54.160",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86543"
                }
            ]
        },
        {
            "id": "CVE-2026-86542",
            "vendor": "knowns-dev",
            "product": "knowns",
            "title": "knowns vulnerability",
            "summary": "knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files writable by the server process.",
            "updated_at": "2026-09-07T23:16:54.020",
            "published_at": "2026-09-07T23:16:54.020",
            "cvss": 8.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.30.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files writable by the server process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/routes/imports.go#L376-L420",
                "https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/routes/imports.go#L519-L551",
                "https://github.com/knowns-dev/knowns/commit/d3989829fb5095666d23d005b2f78a082832a396",
                "https://github.com/knowns-dev/knowns/releases/tag/v0.30.0",
                "https://github.com/knowns-dev/knowns/security/advisories/GHSA-wh3c-v55g-qfg8",
                "https://www.vulncheck.com/advisories/knowns-before-0.30.0-path-traversal-via-import-name"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:54.020",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86542"
                }
            ]
        },
        {
            "id": "CVE-2026-86541",
            "vendor": "knowns-dev",
            "product": "knowns",
            "title": "knowns vulnerability",
            "summary": "knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing directory traversal sequences to write malicious content to sensitive files like shell startup scripts or SSH configuration files.",
            "updated_at": "2026-09-07T23:16:53.863",
            "published_at": "2026-09-07T23:16:53.863",
            "cvss": 7.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.30.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing directory traversal sequences to write malicious content to sensitive files like shell startup scripts or SSH configuration files.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/mcp/handlers/code.go#L588-L646",
                "https://github.com/knowns-dev/knowns/commit/a2c98fc5c313463576c9348beeec6a74ddd7333b",
                "https://github.com/knowns-dev/knowns/releases/tag/v0.30.0",
                "https://github.com/knowns-dev/knowns/security/advisories/GHSA-f539-xgc6-xw7q",
                "https://www.vulncheck.com/advisories/knowns-before-0.30.0-path-traversal-via-code-replace-mcp-action"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:53.863",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86541"
                }
            ]
        },
        {
            "id": "CVE-2026-86540",
            "vendor": "knowns-dev",
            "product": "knowns",
            "title": "knowns vulnerability",
            "summary": "knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification.",
            "updated_at": "2026-09-07T23:16:53.723",
            "published_at": "2026-09-07T23:16:53.723",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.30.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. When a repository with a crafted configuration is opened, the unvalidated binary path is executed twice under the user's account without any verification.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/lsp/detect.go#L128-L157",
                "https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/models/config.go#L205-L216",
                "https://github.com/knowns-dev/knowns/commit/d3989829fb5095666d23d005b2f78a082832a396",
                "https://github.com/knowns-dev/knowns/releases/tag/v0.30.0",
                "https://github.com/knowns-dev/knowns/security/advisories/GHSA-mc52-mwq4-vfx3",
                "https://www.vulncheck.com/advisories/knowns-before-0.30.0-arbitrary-code-execution-via-lsp-binary"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:53.723",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86540"
                }
            ]
        },
        {
            "id": "CVE-2026-86539",
            "vendor": "knowns-dev",
            "product": "knowns",
            "title": "knowns vulnerability",
            "summary": "knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.",
            "updated_at": "2026-09-07T23:16:53.583",
            "published_at": "2026-09-07T23:16:53.583",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.33.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/knowns-dev/knowns/blob/v0.33.0/internal/server/routes/embedding_models.go#L64-L110",
                "https://github.com/knowns-dev/knowns/blob/v0.33.0/internal/server/routes/imports.go#L317-L330",
                "https://github.com/knowns-dev/knowns/security/advisories/GHSA-qx9v-m9gg-p5jg",
                "https://www.vulncheck.com/advisories/knowns-through-0.33.0-server-side-request-forgery-via-embedding-models-endpoint"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:53.583",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86539"
                }
            ]
        },
        {
            "id": "CVE-2026-86538",
            "vendor": "knowns-dev",
            "product": "knowns",
            "title": "knowns vulnerability",
            "summary": "knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensitive files like credentials and configuration through the JSON response.",
            "updated_at": "2026-09-07T23:16:53.443",
            "published_at": "2026-09-07T23:16:53.443",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.30.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensitive files like credentials and configuration through the JSON response.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/routes/templates.go#L299-L310",
                "https://github.com/knowns-dev/knowns/commit/09c5a96fd5817b941dc86669278c1a17db10ed4e",
                "https://github.com/knowns-dev/knowns/releases/tag/v0.30.0",
                "https://github.com/knowns-dev/knowns/security/advisories/GHSA-fpxv-c555-rhm3",
                "https://www.vulncheck.com/advisories/knowns-before-0.30.0-path-traversal-via-templatefile-parameter"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:53.443",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86538"
                }
            ]
        },
        {
            "id": "CVE-2026-86514",
            "vendor": "n/a",
            "product": "vgmstream",
            "title": "vgmstream vulnerability",
            "summary": "A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 4669d37a6af94866f6f0628678f9f90d46954e8b. To fix this issue, it is recommended to deploy a patch.",
            "updated_at": "2026-09-11T21:17:46.627",
            "published_at": "2026-09-08T03:17:19.790",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "r2117",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 4669d37a6af94866f6f0628678f9f90d46954e8b. To fix this issue, it is recommended to deploy a patch.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/vgmstream/vgmstream/",
                "https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b",
                "https://github.com/vgmstream/vgmstream/issues/1972",
                "https://github.com/vgmstream/vgmstream/pull/1956",
                "https://vuldb.com/cve/CVE-2026-86514",
                "https://vuldb.com/submit/908369",
                "https://vuldb.com/vuln/399668",
                "https://vuldb.com/vuln/399668/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T03:17:19.790",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86514"
                }
            ]
        },
        {
            "id": "CVE-2026-86509",
            "vendor": "D-Link",
            "product": "DIR-895L",
            "title": "DIR-895L vulnerability",
            "summary": "A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used.",
            "updated_at": "2026-09-11T21:17:46.010",
            "published_at": "2026-09-08T01:17:55.947",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "A1_102b07",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://tzh00203.notion.site/D-Link-DIR-895L-Stack-Overflow-in-udhcpd-TR-111-Option-125-Parsing-33cb5c52018a80dc8140e1502e4814d0",
                "https://vuldb.com/cve/CVE-2026-86509",
                "https://vuldb.com/submit/906298",
                "https://vuldb.com/vuln/399662",
                "https://vuldb.com/vuln/399662/cti",
                "https://www.dlink.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:55.947",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86509"
                }
            ]
        },
        {
            "id": "CVE-2026-86504",
            "vendor": "JetBrains",
            "product": "IntelliJ IDEA",
            "title": "IntelliJ IDEA vulnerability",
            "summary": "In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution",
            "updated_at": "2026-09-09T05:18:20.160",
            "published_at": "2026-09-07T17:17:28.903",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2026.2.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-829",
            "what_happened": "In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jetbrains.com/privacy-security/issues-fixed/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T17:17:28.903",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86504"
                }
            ]
        },
        {
            "id": "CVE-2026-86502",
            "vendor": "JetBrains",
            "product": "IntelliJ IDEA",
            "title": "IntelliJ IDEA vulnerability",
            "summary": "In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts",
            "updated_at": "2026-09-09T05:18:20.043",
            "published_at": "2026-09-07T17:17:28.670",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2026.2.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jetbrains.com/privacy-security/issues-fixed/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T17:17:28.670",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86502"
                }
            ]
        },
        {
            "id": "CVE-2026-86482",
            "vendor": "JetBrains",
            "product": "YouTrack",
            "title": "YouTrack vulnerability",
            "summary": "In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation",
            "updated_at": "2026-09-09T05:18:19.937",
            "published_at": "2026-09-07T17:17:26.383",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2026.2.18634 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jetbrains.com/privacy-security/issues-fixed/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T17:17:26.383",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86482"
                }
            ]
        },
        {
            "id": "CVE-2026-86480",
            "vendor": "JetBrains",
            "product": "Hub",
            "title": "Hub vulnerability",
            "summary": "In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges",
            "updated_at": "2026-09-09T05:18:19.830",
            "published_at": "2026-09-07T17:17:26.150",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2026.2.52442 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jetbrains.com/privacy-security/issues-fixed/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T17:17:26.150",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86480"
                }
            ]
        },
        {
            "id": "CVE-2026-86479",
            "vendor": "JetBrains",
            "product": "YouTrack",
            "title": "YouTrack vulnerability",
            "summary": "In JetBrains YouTrack before 2026.2.18788, \n2026.1.14055, \n2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR",
            "updated_at": "2026-09-09T05:18:19.723",
            "published_at": "2026-09-07T17:17:26.040",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2026.2.18788, \n2026.1.14055, \n2025.3.161254 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "In JetBrains YouTrack before 2026.2.18788, \n2026.1.14055, \n2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jetbrains.com/privacy-security/issues-fixed/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T17:17:26.040",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86479"
                }
            ]
        },
        {
            "id": "CVE-2026-86478",
            "vendor": "JetBrains",
            "product": "YouTrack",
            "title": "YouTrack vulnerability",
            "summary": "In JetBrains YouTrack before 2025.3.161254, \n2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address",
            "updated_at": "2026-09-09T05:18:19.617",
            "published_at": "2026-09-07T17:17:25.920",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2025.3.161254, \n2026.1.14042 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-290",
            "what_happened": "In JetBrains YouTrack before 2025.3.161254, \n2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jetbrains.com/privacy-security/issues-fixed/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T17:17:25.920",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86478"
                }
            ]
        },
        {
            "id": "CVE-2026-86452",
            "vendor": "MISP",
            "product": "MISP",
            "title": "MISP vulnerability",
            "summary": "Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting.\n\n\nThe users/forgot password-reset endpoint accepted an attacker-controlled email value without first imposing a reasonable length bound or validating its format. That value was then used to create an audit log entry and queue a password-reset job, causing the supplied value to be persisted more than once per request. The commit explicitly states that an unbounded unauthenticated request field was stored twice per call with no throttle.\n\nThe fix adds:\n\n - a maximum email input length of 1024 bytes;\n - email-format validation before persistent work;\n - a per-source pre-authentication request budget;\n - HTTP 429 responses when that budget is exceeded;\n - a 15-minute cooldown for API-access request emails;\n - POST-only handling and CSRF protection for the API-access request endpoint.\n\n\n\nThe new flood filter is specifically intended to limit persistent storage costs from anonymous requests such as password resets, registrations, and failed REST authentication attempts.\n\nVersion affected: ≤2.5.45",
            "updated_at": "2026-09-14T07:17:23.740",
            "published_at": "2026-09-07T14:16:56.833",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.5.45 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting.\n\n\nThe users/forgot password-reset endpoint accepted an attacker-controlled email value without first imposing a reasonable length bound or validating its format. That value was then used to create an audit log entry and queue a password-reset job, causing the supplied value to be persisted more than once per request. The commit explicitly states that an unbounded unauthenticated request field was stored twice per call with no throttle.\n\nThe fix adds:\n\n - a maximum email input length of 1024 bytes;\n - email-format validation before persistent work;\n - a per-source pre-authentication request budget;\n - HTTP 429 responses when that budget is exceeded;\n - a 15-minute cooldown for API-access request emails;\n - POST-only handling and CSRF protection for the API-access request endpoint.\n\n\n\nThe new flood filter is specifically intended to limit persistent storage costs from anonymous requests such as password resets, registrations, and failed REST authentication attempts.\n\nVersion affected: ≤2.5.45",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/MISP/MISP/commit/d75d899be"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:56.833",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86452"
                }
            ]
        },
        {
            "id": "CVE-2026-86439",
            "vendor": "knowns-dev",
            "product": "knowns",
            "title": "knowns vulnerability",
            "summary": "knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files accessible to the server process.",
            "updated_at": "2026-09-07T23:16:53.297",
            "published_at": "2026-09-07T23:16:53.297",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.30.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files accessible to the server process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/storage/doc_store.go#L124-L129",
                "https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/storage/memory_store.go#L203-L211",
                "https://github.com/knowns-dev/knowns/commit/09c5a96fd5817b941dc86669278c1a17db10ed4e",
                "https://github.com/knowns-dev/knowns/releases/tag/v0.30.0",
                "https://github.com/knowns-dev/knowns/security/advisories/GHSA-9gfj-28hw-jchp",
                "https://www.vulncheck.com/advisories/knowns-before-0.30.0-path-traversal-via-mcp-doc-and-memory-tools"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:53.297",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86439"
                }
            ]
        },
        {
            "id": "CVE-2026-86438",
            "vendor": "laradashboard",
            "product": "laradashboard",
            "title": "laradashboard vulnerability",
            "summary": "Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.",
            "updated_at": "2026-09-07T22:17:22.163",
            "published_at": "2026-09-07T22:17:22.163",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.3.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/laradashboard/laradashboard",
                "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Livewire/Marketplace/MarketplaceModuleBrowser.php#L76-L120",
                "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Policies/ModulePolicy.php#L32-L38",
                "https://github.com/laradashboard/laradashboard/commit/738cc1a219ce459323ef1d09c3789075f1b8d2f2",
                "https://github.com/laradashboard/laradashboard/releases/tag/v1.3.2",
                "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-4x9p-vg5m-vr6p",
                "https://www.vulncheck.com/advisories/lara-dashboard-before-1.3.2-missing-authorization-in-marketplace-module-install-action"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T22:17:22.163",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86438"
                }
            ]
        },
        {
            "id": "CVE-2026-86437",
            "vendor": "laradashboard",
            "product": "laradashboard",
            "title": "laradashboard vulnerability",
            "summary": "Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified application files such as routes/web.php with embedded system commands, which execute as the web server user with access to environment secrets and database credentials.",
            "updated_at": "2026-09-07T22:17:22.003",
            "published_at": "2026-09-07T22:17:22.003",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.3.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified application files such as routes/web.php with embedded system commands, which execute as the web server user with access to environment secrets and database credentials.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/laradashboard/laradashboard",
                "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Http/Requests/CoreUpgrade/UploadRequest.php#L15-L18",
                "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Policies/SettingPolicy.php#L47-L50",
                "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Services/CoreUpgradeService.php#L543-L577",
                "https://github.com/laradashboard/laradashboard/commit/738cc1a219ce459323ef1d09c3789075f1b8d2f2",
                "https://github.com/laradashboard/laradashboard/releases/tag/v1.3.2",
                "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-xv98-x5h7-4g7v",
                "https://www.vulncheck.com/advisories/lara-dashboard-before-1.3.2-incorrect-authorization-in-core-upgrade-archive-upload"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T22:17:22.003",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86437"
                }
            ]
        },
        {
            "id": "CVE-2026-86436",
            "vendor": "laradashboard",
            "product": "laradashboard",
            "title": "laradashboard vulnerability",
            "summary": "Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits execution of the uploaded file type.",
            "updated_at": "2026-09-07T22:17:21.833",
            "published_at": "2026-09-07T22:17:21.833",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.3.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files with attacker-chosen extensions to the public web root and execute code if the deployment permits execution of the uploaded file type.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/laradashboard/laradashboard",
                "https://github.com/laradashboard/laradashboard/blob/v1.3.1/app/Http/Controllers/Backend/PostController.php#L727-L741",
                "https://github.com/laradashboard/laradashboard/blob/v1.3.1/routes/web.php#L243-L244",
                "https://github.com/laradashboard/laradashboard/commit/738cc1a219ce459323ef1d09c3789075f1b8d2f2",
                "https://github.com/laradashboard/laradashboard/releases/tag/v1.3.2",
                "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-hp3f-j9w2-5rqg",
                "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j4mm-xcgj-vpvv",
                "https://www.vulncheck.com/advisories/lara-dashboard-before-1.3.2-missing-authorization-in-post-builder-media-upload-endpoints"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T22:17:21.833",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86436"
                }
            ]
        },
        {
            "id": "CVE-2026-86418",
            "vendor": "MISP",
            "product": "MISP",
            "title": "MISP vulnerability",
            "summary": "Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view.\n\nThe affected endpoint returned fields including:\n\n - organisation ID;\n\n - UUID;\n\n - name.\n\n\n\n\n\n\nWhen Security.hide_organisation_index_from_users was enabled, normal organisation enumeration was restricted, but the dashboard picker still queried all organisations. This allowed authenticated users to discover organisations that should have remained hidden from them.\n\n\nThe fix calls Organisation::createConditions($this->Auth->user()) and appends the resulting ACL conditions to the picker query. Ordinary users are thereby limited to organisations associated with events or proposals they can already see, plus their own organisation, while users with the appropriate sharing-group privilege retain broader visibility.\n\n\n\n\nVersion affected: ≤2.5.45",
            "updated_at": "2026-09-14T07:17:23.147",
            "published_at": "2026-09-07T13:20:40.527",
            "cvss": 2.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.5.45 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-organisation view.\n\nThe affected endpoint returned fields including:\n\n - organisation ID;\n\n - UUID;\n\n - name.\n\n\n\n\n\n\nWhen Security.hide_organisation_index_from_users was enabled, normal organisation enumeration was restricted, but the dashboard picker still queried all organisations. This allowed authenticated users to discover organisations that should have remained hidden from them.\n\n\nThe fix calls Organisation::createConditions($this->Auth->user()) and appends the resulting ACL conditions to the picker query. Ordinary users are thereby limited to organisations associated with events or proposals they can already see, plus their own organisation, while users with the appropriate sharing-group privilege retain broader visibility.\n\n\n\n\nVersion affected: ≤2.5.45",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/MISP/MISP/commit/8ca4486af"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T13:20:40.527",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86418"
                }
            ]
        },
        {
            "id": "CVE-2026-86407",
            "vendor": "Unknown",
            "product": "User Registration & Membership",
            "title": "User Registration & Membership vulnerability",
            "summary": "The User Registration & Membership  WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, allowing unauthenticated users to retrieve another user's email address, profile fields, role and membership order details. Exploitation requires the site owner to have added a user smart tag to that page's configurable message, which the shipped default does not contain.",
            "updated_at": "2026-09-13T11:16:58.963",
            "published_at": "2026-09-13T06:16:25.260",
            "cvss": 3.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5.0 through before 5.2.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-200",
            "what_happened": "The User Registration & Membership  WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, allowing unauthenticated users to retrieve another user's email address, profile fields, role and membership order details. Exploitation requires the site owner to have added a user smart tag to that page's configurable message, which the shipped default does not contain.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/2c9eb1fe-4e18-4fd0-9581-5672ffc4b598/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T06:16:25.260",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86407"
                }
            ]
        },
        {
            "id": "CVE-2026-86406",
            "vendor": "Unknown",
            "product": "User Registration & Membership",
            "title": "User Registration & Membership vulnerability",
            "summary": "The User Registration & Membership  WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged role, this leads to privilege escalation up to administrator.",
            "updated_at": "2026-09-13T11:16:58.793",
            "published_at": "2026-09-13T06:16:25.157",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.4.6 through before 5.2.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-269",
            "what_happened": "The User Registration & Membership  WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged role, this leads to privilege escalation up to administrator.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/0fb4ec40-3f92-4c7e-8877-8898b355d78d/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T06:16:25.157",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86406"
                }
            ]
        },
        {
            "id": "CVE-2026-86404",
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7",
            "title": "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 vulnerability",
            "summary": "EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and block-list are empty. When the allow-list is empty (size == 0), isTrustedType() returns true for ALL classes. This means all classes are deserializable by default.",
            "updated_at": "2026-09-07T14:16:56.620",
            "published_at": "2026-09-07T12:17:21.840",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and block-list are empty. When the allow-list is empty (size == 0), isTrustedType() returns true for ALL classes. This means all classes are deserializable by default.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/security/cve/CVE-2026-86404",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2477930"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T12:17:21.840",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86404"
                }
            ]
        },
        {
            "id": "CVE-2026-86342",
            "vendor": "MISP",
            "product": "MISP",
            "title": "MISP vulnerability",
            "summary": "Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's ACL, allowing restricted event correlations and associated event information to be exposed to users who could not otherwise access those events. The vulnerable queries were scoped only by attribute values and deletion status rather than MISP's event, organization, sharing-group, attribute, and object-level access controls.\n\n\nThe same preview functionality also returned cross-feed correlation information without properly restricting the feed list to feeds visible to the caller. This exposed metadata for feeds that were not marked lookup_visible; one affected response additionally included the configured feed URL even though that value was not required by the feature.\n\nThe fixes apply the caller's ACL to attribute correlation searches, remove feed URLs from correlation results, restrict cross-feed results according to feed visibility, and correct host-organization ID comparison so the authorization rules are applied consistently.\n\nVersion affected: ≤2.5.45",
            "updated_at": "2026-09-07T09:17:17.943",
            "published_at": "2026-09-07T09:17:17.943",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.5.45 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying the requesting user's ACL, allowing restricted event correlations and associated event information to be exposed to users who could not otherwise access those events. The vulnerable queries were scoped only by attribute values and deletion status rather than MISP's event, organization, sharing-group, attribute, and object-level access controls.\n\n\nThe same preview functionality also returned cross-feed correlation information without properly restricting the feed list to feeds visible to the caller. This exposed metadata for feeds that were not marked lookup_visible; one affected response additionally included the configured feed URL even though that value was not required by the feature.\n\nThe fixes apply the caller's ACL to attribute correlation searches, remove feed URLs from correlation results, restrict cross-feed results according to feed visibility, and correct host-organization ID comparison so the authorization rules are applied consistently.\n\nVersion affected: ≤2.5.45",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/MISP/MISP/commit/1fb622046",
                "https://github.com/MISP/MISP/commit/4b6916086",
                "https://github.com/MISP/MISP/commit/dc1a0f7c2",
                "https://github.com/MISP/MISP/commit/dedb4b297"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T09:17:17.943",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86342"
                }
            ]
        },
        {
            "id": "CVE-2026-86332",
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift AI (RHOAI)",
            "title": "Red Hat OpenShift AI (RHOAI) vulnerability",
            "summary": "A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the cluster NVIDIA NGC API key Secret (apiKeySecret) and the NIM image pull secret (nimPullSecret). Create and delete of the same NIM credential are admin-gated; the read path is not. This is missing authorization (CWE-862) and insufficiently protected credentials (CWE-522). It is distinct from CVE-2026-5483 (service-account token leak in the Kubernetes client response wrapper on the same route) and CVE-2026-16456 (odh-model-controller cross-namespace confused deputy).",
            "updated_at": "2026-09-07T09:17:17.807",
            "published_at": "2026-09-07T09:17:17.807",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the cluster NVIDIA NGC API key Secret (apiKeySecret) and the NIM image pull secret (nimPullSecret). Create and delete of the same NIM credential are admin-gated; the read path is not. This is missing authorization (CWE-862) and insufficiently protected credentials (CWE-522). It is distinct from CVE-2026-5483 (service-account token leak in the Kubernetes client response wrapper on the same route) and CVE-2026-16456 (odh-model-controller cross-namespace confused deputy).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/security/cve/CVE-2026-86332",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2529287"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T09:17:17.807",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86332"
                }
            ]
        },
        {
            "id": "CVE-2026-86315",
            "vendor": "Samsung Opensource",
            "product": "Escargot",
            "title": "Escargot vulnerability",
            "summary": "An out-of-bounds write caused by numeric truncation  Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definition whose instance initialization entry count exceeds UINT16_MAX.\n\n\n\nThis issue affects Escargot: 5dc93606abd42b859045add05d704a038e197359.",
            "updated_at": "2026-09-07T04:17:55.650",
            "published_at": "2026-09-07T04:17:55.650",
            "cvss": 6.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5dc93606abd42b859045add05d704a038e197359",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-197",
            "what_happened": "An out-of-bounds write caused by numeric truncation  Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definition whose instance initialization entry count exceeds UINT16_MAX.\n\n\n\nThis issue affects Escargot: 5dc93606abd42b859045add05d704a038e197359.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Samsung/escargot/pull/1660"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T04:17:55.650",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86315"
                }
            ]
        },
        {
            "id": "CVE-2026-86314",
            "vendor": "Samsung Opensource",
            "product": "Walrus",
            "title": "Walrus vulnerability",
            "summary": "Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check.\n\n\n\nThis issue affects Walrus: ff3bf5ff5c4878f8e5572c9593d303f6bc997443.",
            "updated_at": "2026-09-07T03:17:19.530",
            "published_at": "2026-09-07T03:17:19.530",
            "cvss": 6.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "ff3bf5ff5c4878f8e5572c9593d303f6bc997443",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps around and bypasses the bounds check.\n\n\n\nThis issue affects Walrus: ff3bf5ff5c4878f8e5572c9593d303f6bc997443.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Samsung/walrus/pull/482"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T03:17:19.530",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86314"
                }
            ]
        },
        {
            "id": "CVE-2026-86313",
            "vendor": "Samsung Opensource",
            "product": "Walrus",
            "title": "Walrus vulnerability",
            "summary": "Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers.\n\nThis issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.",
            "updated_at": "2026-09-07T03:17:19.407",
            "published_at": "2026-09-07T03:17:19.407",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "af80e665ea49d9003695a66502f841ed1d8397e7",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers.\n\nThis issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Samsung/walrus/pull/482"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T03:17:19.407",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86313"
                }
            ]
        },
        {
            "id": "CVE-2026-86310",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
            "updated_at": "2026-09-11T21:17:45.477",
            "published_at": "2026-09-07T14:16:56.457",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ltranquility/submit_repository/issues/7",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86310",
                "https://vuldb.com/submit/902720",
                "https://vuldb.com/vuln/399483",
                "https://vuldb.com/vuln/399483/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:56.457",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86310"
                }
            ]
        },
        {
            "id": "CVE-2026-86309",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A flaw has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.",
            "updated_at": "2026-09-07T14:16:56.290",
            "published_at": "2026-09-07T14:16:56.290",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A flaw has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/yunfan668/cve/issues/1",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86309",
                "https://vuldb.com/submit/894880",
                "https://vuldb.com/vuln/399482",
                "https://vuldb.com/vuln/399482/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:56.290",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86309"
                }
            ]
        },
        {
            "id": "CVE-2026-86308",
            "vendor": "light0011",
            "product": "cms",
            "title": "cms vulnerability",
            "summary": "A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Common/Conf/config.php of the component Debug Mode. The manipulation of the argument DB_DEBUG results in information disclosure. It is possible to launch the attack remotely. The exploit is now public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-07T14:16:56.120",
            "published_at": "2026-09-07T14:16:56.120",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c774dce31c6df0055568a8d5c53d964d99be199d; f72cf46f601efb2a0618c3814cc2f61380b38930",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unknown processing of the file App/Common/Conf/config.php of the component Debug Mode. The manipulation of the argument DB_DEBUG results in information disclosure. It is possible to launch the attack remotely. The exploit is now public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/light0011/cms/",
                "https://github.com/light0011/cms/issues/10",
                "https://github.com/light0011/cms/issues/17",
                "https://vuldb.com/cve/CVE-2026-86308",
                "https://vuldb.com/submit/894870",
                "https://vuldb.com/vuln/399481",
                "https://vuldb.com/vuln/399481/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:56.120",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86308"
                }
            ]
        },
        {
            "id": "CVE-2026-86307",
            "vendor": "light0011",
            "product": "cms",
            "title": "cms vulnerability",
            "summary": "A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-07T14:16:55.927",
            "published_at": "2026-09-07T14:16:55.927",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c774dce31c6df0055568a8d5c53d964d99be199d; f72cf46f601efb2a0618c3814cc2f61380b38930",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-352",
            "what_happened": "A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/light0011/cms/",
                "https://github.com/light0011/cms/issues/12",
                "https://vuldb.com/cve/CVE-2026-86307",
                "https://vuldb.com/submit/894818",
                "https://vuldb.com/vuln/399480",
                "https://vuldb.com/vuln/399480/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:55.927",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86307"
                }
            ]
        },
        {
            "id": "CVE-2026-86305",
            "vendor": "light0011",
            "product": "cms",
            "title": "cms vulnerability",
            "summary": "A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function Upload::upload of the file ThinkPHP/Library/Think/Upload.class.php. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-11T21:17:44.957",
            "published_at": "2026-09-07T13:20:39.753",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c774dce31c6df0055568a8d5c53d964d99be199d; f72cf46f601efb2a0618c3814cc2f61380b38930",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function Upload::upload of the file ThinkPHP/Library/Think/Upload.class.php. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/light0011/cms/",
                "https://github.com/light0011/cms/issues/9",
                "https://vuldb.com/cve/CVE-2026-86305",
                "https://vuldb.com/submit/894804",
                "https://vuldb.com/vuln/399478",
                "https://vuldb.com/vuln/399478/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T13:20:39.753",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86305"
                }
            ]
        },
        {
            "id": "CVE-2026-86304",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding:...",
            "summary": "MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor.\n\nparse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert, cert_text or anchors argument, then passes the returned XML to Net::SAML2::Protocol::Assertion->new_from_xml with the IdP signing certificate as cacert. In Net::SAML2 before 0.86 that certificate guards only encrypted assertions, so the signature on an unencrypted assertion is checked against the certificate the response itself carries.\n\nAn attacker starts a SAML login, then posts a response signed with a certificate of their own. The audience, InResponseTo and timestamp checks that follow are all satisfiable by the attacker, so the response authenticates any NameID it carries.",
            "updated_at": "2026-09-06T23:17:39.483",
            "published_at": "2026-09-06T23:17:39.483",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.006 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-347",
            "what_happened": "MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor.\n\nparse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert, cert_text or anchors argument, then passes the returned XML to Net::SAML2::Protocol::Assertion->new_from_xml with the IdP signing certificate as cacert. In Net::SAML2 before 0.86 that certificate guards only encrypted assertions, so the signature on an unencrypted assertion is checked against the certificate the response itself carries.\n\nAn attacker starts a SAML login, then posts a response signed with a certificate of their own. The audience, InResponseTo and timestamp checks that follow are all satisfiable by the attacker, so the response authenticates any NameID it carries.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://metacpan.org/release/POLETTIX/MojoX-Authentication-0.004/source/lib/MojoX/Authentication/Model/SAML2.pm#L188",
                "https://metacpan.org/release/POLETTIX/MojoX-Authentication-0.006/source/Changes",
                "https://www.cve.org/CVERecord?id=CVE-2026-18089"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T23:17:39.483",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86304"
                }
            ]
        },
        {
            "id": "CVE-2026-86299",
            "vendor": "Linksys",
            "product": "RE7000",
            "title": "RE7000 vulnerability",
            "summary": "A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched remotely. The exploit is now public and may be used.",
            "updated_at": "2026-09-11T21:17:44.440",
            "published_at": "2026-09-07T12:17:21.340",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.0.15",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched remotely. The exploit is now public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/limou89/somevul/blob/main/Linksys_RE7000_v2_PingTest_Command_Injection.md",
                "https://vuldb.com/cve/CVE-2026-86299",
                "https://vuldb.com/submit/906547",
                "https://vuldb.com/vuln/399463",
                "https://vuldb.com/vuln/399463/cti",
                "https://www.linksys.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T12:17:21.340",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86299"
                }
            ]
        },
        {
            "id": "CVE-2026-86294",
            "vendor": "SourceCodester",
            "product": "Simple Traffic Offense System",
            "title": "Simple Traffic Offense System vulnerability",
            "summary": "A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.",
            "updated_at": "2026-09-11T21:17:43.930",
            "published_at": "2026-09-07T11:17:39.180",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/tan1540684326-QAQ/cve/issues/3",
                "https://vuldb.com/cve/CVE-2026-86294",
                "https://vuldb.com/submit/906279",
                "https://vuldb.com/vuln/399456",
                "https://vuldb.com/vuln/399456/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T11:17:39.180",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86294"
                }
            ]
        },
        {
            "id": "CVE-2026-86290",
            "vendor": "SourceCodester",
            "product": "Online Voting System",
            "title": "Online Voting System vulnerability",
            "summary": "A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Category causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.",
            "updated_at": "2026-09-07T09:17:17.650",
            "published_at": "2026-09-07T09:17:17.650",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Category causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/W5M1n9/cve/issues/2",
                "https://vuldb.com/cve/CVE-2026-86290",
                "https://vuldb.com/submit/906187",
                "https://vuldb.com/vuln/399452",
                "https://vuldb.com/vuln/399452/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T09:17:17.650",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86290"
                }
            ]
        },
        {
            "id": "CVE-2026-86289",
            "vendor": "n/a",
            "product": "Ollama",
            "title": "Ollama vulnerability",
            "summary": "A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.31.2-rc1 is capable of addressing this issue. The patch is named 67b6a1c2d45321e0cb3c04a18073f9818de7724b. It is recommended to upgrade the affected component.",
            "updated_at": "2026-09-11T21:17:43.407",
            "published_at": "2026-09-07T09:17:17.470",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.31.0; 0.31.1",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-189",
            "what_happened": "A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a manipulation results in integer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.31.2-rc1 is capable of addressing this issue. The patch is named 67b6a1c2d45321e0cb3c04a18073f9818de7724b. It is recommended to upgrade the affected component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ollama/ollama/",
                "https://github.com/ollama/ollama/commit/67b6a1c2d45321e0cb3c04a18073f9818de7724b",
                "https://github.com/ollama/ollama/issues/17033",
                "https://github.com/ollama/ollama/pull/17062",
                "https://github.com/ollama/ollama/releases/tag/v0.31.2-rc1",
                "https://vuldb.com/cve/CVE-2026-86289",
                "https://vuldb.com/submit/906136",
                "https://vuldb.com/vuln/399448",
                "https://vuldb.com/vuln/399448/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T09:17:17.470",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86289"
                }
            ]
        },
        {
            "id": "CVE-2026-86288",
            "vendor": "ModelCloud",
            "product": "GPTQModel",
            "title": "GPTQModel vulnerability",
            "summary": "A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file gptqmodel/nn_modules/qlinear/tritonv2.py of the component Triton dequantization kernel. Such manipulation of the argument g_idx leads to out-of-bounds read. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.3.0 is able to resolve this issue. The name of the patch is 877c732f7d7dccd56a729844c6a5bd20f3aa8bb1. Upgrading the affected component is recommended.",
            "updated_at": "2026-09-07T09:17:17.297",
            "published_at": "2026-09-07T09:17:17.297",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.0; 7.1; 7.2.0",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file gptqmodel/nn_modules/qlinear/tritonv2.py of the component Triton dequantization kernel. Such manipulation of the argument g_idx leads to out-of-bounds read. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.3.0 is able to resolve this issue. The name of the patch is 877c732f7d7dccd56a729844c6a5bd20f3aa8bb1. Upgrading the affected component is recommended.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ModelCloud/GPTQModel/",
                "https://github.com/ModelCloud/GPTQModel/commit/877c732f7d7dccd56a729844c6a5bd20f3aa8bb1",
                "https://github.com/ModelCloud/GPTQModel/issues/2949",
                "https://github.com/ModelCloud/GPTQModel/pull/2950",
                "https://github.com/ModelCloud/GPTQModel/releases/tag/v7.3.0",
                "https://vuldb.com/cve/CVE-2026-86288",
                "https://vuldb.com/submit/906135",
                "https://vuldb.com/vuln/399447",
                "https://vuldb.com/vuln/399447/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T09:17:17.297",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86288"
                }
            ]
        },
        {
            "id": "CVE-2026-86287",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths.",
            "summary": "Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths.\n\nNon-numeric and non-ASCII prefix lengths are accepted and treated as 0. Integers over 31 bits are silently truncated.  A single malformed mask will poison the lookup table.\n\nThe result is that the lookup will silently succeed for every address. An allow-list will allow every address, and a deny-list will block every address.",
            "updated_at": "2026-09-07T21:17:31.010",
            "published_at": "2026-09-07T19:17:28.370",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.12 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-1287",
            "what_happened": "Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths.\n\nNon-numeric and non-ASCII prefix lengths are accepted and treated as 0. Integers over 31 bits are silently truncated.  A single malformed mask will poison the lookup table.\n\nThe result is that the lookup will silently succeed for every address. An allow-list will allow every address, and a deny-list will block every address.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/robrwo/perl-Net-IP-LPM/commit/814f8baa85537827db8c3b3d251e48db7aca318f.patch",
                "https://metacpan.org/release/RRWO/Net-IP-LPM-1.12/changes",
                "http://www.openwall.com/lists/oss-security/2026/09/07/1"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:17:28.370",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86287"
                }
            ]
        },
        {
            "id": "CVE-2026-86285",
            "vendor": "n/a",
            "product": "BookStack",
            "title": "BookStack vulnerability",
            "summary": "A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. The manipulation of the argument ID results in improper access controls. The attack may be launched remotely. The exploit is now public and may be used. The patch is identified as 4e406c41c4c8060a5795e74c66fb96362e54f400. It is advisable to implement a patch to correct this issue.",
            "updated_at": "2026-09-07T09:17:17.127",
            "published_at": "2026-09-07T09:17:17.127",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "26.05.0; 26.05.1; 26.05.2",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment Edit Endpoint. The manipulation of the argument ID results in improper access controls. The attack may be launched remotely. The exploit is now public and may be used. The patch is identified as 4e406c41c4c8060a5795e74c66fb96362e54f400. It is advisable to implement a patch to correct this issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://ashutosh-jena.in/blog/broken-access-control-in-bookstack-how-a-missing-permission-check-leaked-attachment-data",
                "https://codeberg.org/bookstack/bookstack/commit/4e406c41c4c8060a5795e74c66fb96362e54f400",
                "https://vuldb.com/cve/CVE-2026-86285",
                "https://vuldb.com/submit/905693",
                "https://vuldb.com/vuln/399445",
                "https://vuldb.com/vuln/399445/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T09:17:17.127",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86285"
                }
            ]
        },
        {
            "id": "CVE-2026-86284",
            "vendor": "jaychouchannel",
            "product": "Tourism-Management-System",
            "title": "Tourism-Management-System vulnerability",
            "summary": "A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected by this vulnerability is the function getOption of the file travel/src/main/java/com/controller/CommonController.java. The manipulation of the argument tableName/columnName leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. To fix this issue, it is recommended to deploy a patch.",
            "updated_at": "2026-09-07T08:17:14.820",
            "published_at": "2026-09-07T08:17:14.820",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8122bf020d91199eddfff3ee02d1632a70a9a132",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected by this vulnerability is the function getOption of the file travel/src/main/java/com/controller/CommonController.java. The manipulation of the argument tableName/columnName leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. To fix this issue, it is recommended to deploy a patch.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jaychouchannel/Tourism-Management-System/",
                "https://github.com/jaychouchannel/Tourism-Management-System/commit/d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86",
                "https://github.com/jaychouchannel/Tourism-Management-System/pull/14",
                "https://github.com/jaychouchannel/Tourism_Management_System/issues/8",
                "https://vuldb.com/cve/CVE-2026-86284",
                "https://vuldb.com/submit/905644",
                "https://vuldb.com/vuln/399444",
                "https://vuldb.com/vuln/399444/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:17:14.820",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86284"
                }
            ]
        },
        {
            "id": "CVE-2026-86283",
            "vendor": "MISP",
            "product": "MISP",
            "title": "MISP vulnerability",
            "summary": "MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs through Event::fetchSimpleEvents($user, ...), which enforces per-user event ACL. However, the view template independently re-queried the same UUIDs using only an Event.uuid IN (...) condition, omitting the createEventConditions() authorization filter. Because collection element UUIDs are stored without server-side authorization against the referenced event (CollectionElementsController::add() accepts whatever UUID the collection owner posts), an authenticated user with view access to a collection could retrieve full details of events they are not permitted to read. The exposed data included event identifiers, info, dates, timestamps, creator organization, all event tags, and galaxy clusters (the latter attached via a cluster-scoped rather than event-scoped ACL check). This constitutes an authorization bypass at the presentation layer, allowing horizontal privilege escalation across event boundaries within the MISP instance.",
            "updated_at": "2026-09-07T09:17:16.963",
            "published_at": "2026-09-06T15:17:24.813",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "0 through 2.5.45 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 23,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() action correctly resolved collection element UUIDs through Event::fetchSimpleEvents($user, ...), which enforces per-user event ACL. However, the view template independently re-queried the same UUIDs using only an Event.uuid IN (...) condition, omitting the createEventConditions() authorization filter. Because collection element UUIDs are stored without server-side authorization against the referenced event (CollectionElementsController::add() accepts whatever UUID the collection owner posts), an authenticated user with view access to a collection could retrieve full details of events they are not permitted to read. The exposed data included event identifiers, info, dates, timestamps, creator organization, all event tags, and galaxy clusters (the latter attached via a cluster-scoped rather than event-scoped ACL check). This constitutes an authorization bypass at the presentation layer, allowing horizontal privilege escalation across event boundaries within the MISP instance.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-86283",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 7.1,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/SC:N/VI:N/SI:N/VA:N/SA:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=BF41E29F-12BF-5AE5-85F2-DA882483DEC0",
                        "https://github.com/Freire007-byte/sentric-core"
                    ],
                    "repository": "Sploitus",
                    "author": "Freire007-byte",
                    "first_seen": "2026-09-13T21:40:47",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=BF41E29F-12BF-5AE5-85F2-DA882483DEC0"
                },
                {
                    "title": "Exploit for CVE-2026-86283",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 7.1,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/SC:N/VI:N/SI:N/VA:N/SA:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=BF41E29F-12BF-5AE5-85F2-DA882483DEC0",
                        "https://github.com/Freire007-byte/sentric-core"
                    ],
                    "repository": "Freire007-byte/sentric-core",
                    "author": "Freire007-byte",
                    "first_seen": "2026-09-13T21:40:47",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/Freire007-byte/sentric-core"
                }
            ],
            "references": [
                "https://github.com/MISP/MISP/commit/44573e4a8.patch",
                "https://github.com/MISP/MISP/commit/44573e4a8",
                "https://sploitus.com/exploit?id=BF41E29F-12BF-5AE5-85F2-DA882483DEC0",
                "https://github.com/Freire007-byte/sentric-core"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T15:17:24.813",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86283"
                }
            ]
        },
        {
            "id": "CVE-2026-86282",
            "vendor": "jaychouchannel",
            "product": "Tourism-Management-System",
            "title": "Tourism-Management-System vulnerability",
            "summary": "A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the component CommonDao. Executing a manipulation of the argument table/column/xColumn/yColumn can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. This patch is called d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. A patch should be applied to remediate this issue.",
            "updated_at": "2026-09-07T08:17:14.590",
            "published_at": "2026-09-07T08:17:14.590",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8122bf020d91199eddfff3ee02d1632a70a9a132",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the component CommonDao. Executing a manipulation of the argument table/column/xColumn/yColumn can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. This patch is called d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86. A patch should be applied to remediate this issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jaychouchannel/Tourism-Management-System/",
                "https://github.com/jaychouchannel/Tourism-Management-System/commit/d44ec3aa0bd2a72c8800e3befb0a9a96a6491b86",
                "https://github.com/jaychouchannel/Tourism-Management-System/pull/14",
                "https://github.com/jaychouchannel/Tourism_Management_System/issues/7",
                "https://vuldb.com/cve/CVE-2026-86282",
                "https://vuldb.com/submit/905639",
                "https://vuldb.com/vuln/399443",
                "https://vuldb.com/vuln/399443/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:17:14.590",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86282"
                }
            ]
        },
        {
            "id": "CVE-2026-86281",
            "vendor": "SourceCodester",
            "product": "Syllabus-Aligned Learning Management & Examination System",
            "title": "Syllabus-Aligned Learning Management & Examination System vulnerability",
            "summary": "A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.",
            "updated_at": "2026-09-11T21:17:42.243",
            "published_at": "2026-09-07T08:17:14.380",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-352",
            "what_happened": "A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/hackliu/Vulnerability-Reports/blob/master/Syllabus%20Aligned%20Learning%20Management%20Examination%20System/VULN-08-CSRF-Missing-Tokens.md",
                "https://vuldb.com/cve/CVE-2026-86281",
                "https://vuldb.com/submit/904882",
                "https://vuldb.com/vuln/399442",
                "https://vuldb.com/vuln/399442/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:17:14.380",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86281"
                }
            ]
        },
        {
            "id": "CVE-2026-86280",
            "vendor": "SourceCodester",
            "product": "Syllabus-Aligned Learning Management & Examination System",
            "title": "Syllabus-Aligned Learning Management & Examination System vulnerability",
            "summary": "A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack remotely. The exploit is publicly available and might be used.",
            "updated_at": "2026-09-07T08:17:13.897",
            "published_at": "2026-09-07T08:17:13.897",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-310",
            "what_happened": "A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack remotely. The exploit is publicly available and might be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/hackliu/Vulnerability-Reports/blob/master/Syllabus%20Aligned%20Learning%20Management%20Examination%20System/VULN-07-Sensitive-Information-Exposure.md",
                "https://vuldb.com/cve/CVE-2026-86280",
                "https://vuldb.com/submit/904881",
                "https://vuldb.com/vuln/399441",
                "https://vuldb.com/vuln/399441/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:17:13.897",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86280"
                }
            ]
        },
        {
            "id": "CVE-2026-86279",
            "vendor": "SourceCodester",
            "product": "Syllabus-Aligned Learning Management & Examination System",
            "title": "Syllabus-Aligned Learning Management & Examination System vulnerability",
            "summary": "A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the component Login. This manipulation causes session fixiation. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.",
            "updated_at": "2026-09-07T07:16:47.973",
            "published_at": "2026-09-07T07:16:47.973",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-384",
            "what_happened": "A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the component Login. This manipulation causes session fixiation. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/hackliu/Vulnerability-Reports/blob/master/Syllabus%20Aligned%20Learning%20Management%20Examination%20System/VULN-06-Session-Management-Flaws.md",
                "https://vuldb.com/cve/CVE-2026-86279",
                "https://vuldb.com/submit/904880",
                "https://vuldb.com/vuln/399440",
                "https://vuldb.com/vuln/399440/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T07:16:47.973",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86279"
                }
            ]
        },
        {
            "id": "CVE-2026-86278",
            "vendor": "SourceCodester",
            "product": "Syllabus-Aligned Learning Management & Examination System",
            "title": "Syllabus-Aligned Learning Management & Examination System vulnerability",
            "summary": "A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.",
            "updated_at": "2026-09-07T07:16:47.793",
            "published_at": "2026-09-07T07:16:47.793",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/hackliu/Vulnerability-Reports/blob/master/Syllabus%20Aligned%20Learning%20Management%20Examination%20System/VULN-05-XSS-Reflected-Stored.md",
                "https://vuldb.com/cve/CVE-2026-86278",
                "https://vuldb.com/submit/904879",
                "https://vuldb.com/vuln/399439",
                "https://vuldb.com/vuln/399439/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T07:16:47.793",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86278"
                }
            ]
        },
        {
            "id": "CVE-2026-86277",
            "vendor": "SourceCodester",
            "product": "Syllabus-Aligned Learning Management & Examination System",
            "title": "Syllabus-Aligned Learning Management & Examination System vulnerability",
            "summary": "A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.",
            "updated_at": "2026-09-07T07:16:47.620",
            "published_at": "2026-09-07T07:16:47.620",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/hackliu/Vulnerability-Reports/blob/master/Syllabus%20Aligned%20Learning%20Management%20Examination%20System/VULN-04-IDOR-Broken-Access-Control.md",
                "https://vuldb.com/cve/CVE-2026-86277",
                "https://vuldb.com/submit/904877",
                "https://vuldb.com/vuln/399438",
                "https://vuldb.com/vuln/399438/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T07:16:47.620",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86277"
                }
            ]
        },
        {
            "id": "CVE-2026-86276",
            "vendor": "SourceCodester",
            "product": "Syllabus-Aligned Learning Management & Examination System",
            "title": "Syllabus-Aligned Learning Management & Examination System vulnerability",
            "summary": "A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been published and may be used.",
            "updated_at": "2026-09-07T06:17:24.173",
            "published_at": "2026-09-07T06:17:24.173",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-259",
            "what_happened": "A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been published and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/hackliu/Vulnerability-Reports/blob/master/Syllabus%20Aligned%20Learning%20Management%20Examination%20System/VULN-03-SQL-Injection-Hardcoded-Credentials.md",
                "https://vuldb.com/cve/CVE-2026-86276",
                "https://vuldb.com/submit/904873",
                "https://vuldb.com/vuln/399437",
                "https://vuldb.com/vuln/399437/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T06:17:24.173",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86276"
                }
            ]
        },
        {
            "id": "CVE-2026-86275",
            "vendor": "SourceCodester",
            "product": "Syllabus-Aligned Learning Management & Examination System",
            "title": "Syllabus-Aligned Learning Management & Examination System vulnerability",
            "summary": "A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results in improper privilege management. Remote exploitation of the attack is possible. The exploit is now public and may be used.",
            "updated_at": "2026-09-07T06:17:23.993",
            "published_at": "2026-09-07T06:17:23.993",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results in improper privilege management. Remote exploitation of the attack is possible. The exploit is now public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/hackliu/Vulnerability-Reports/blob/master/Syllabus%20Aligned%20Learning%20Management%20Examination%20System/VULN-01-Unauthenticated-Privilege-Escalation.md",
                "https://vuldb.com/cve/CVE-2026-86275",
                "https://vuldb.com/submit/904872",
                "https://vuldb.com/vuln/399436",
                "https://vuldb.com/vuln/399436/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T06:17:23.993",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86275"
                }
            ]
        },
        {
            "id": "CVE-2026-86274",
            "vendor": "projeto-siga",
            "product": "siga",
            "title": "siga vulnerability",
            "summary": "A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExAutenticacaoController.java of the component Authentication Flow. Such manipulation of the argument cod/jwt leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-07T06:17:23.820",
            "published_at": "2026-09-07T06:17:23.820",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.0.2.0; 11.0.2.1; 11.0.2.2; 11.0.2.3; 11.0.2.4; 11.0.2.5; 11.0.2.6; 11.0.2.7; 11.0.2.8; 11.0.2.9; 11.0.2.10; 11.0.2.11; 11.0.2.12; 11.0.2.13; 11.1.0; 11.1.1",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExAutenticacaoController.java of the component Authentication Flow. Such manipulation of the argument cod/jwt leads to missing authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/projeto-siga/siga/",
                "https://github.com/projeto-siga/siga/issues/2493",
                "https://vuldb.com/cve/CVE-2026-86274",
                "https://vuldb.com/submit/904871",
                "https://vuldb.com/vuln/399435",
                "https://vuldb.com/vuln/399435/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T06:17:23.820",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86274"
                }
            ]
        },
        {
            "id": "CVE-2026-86273",
            "vendor": "projeto-siga",
            "product": "siga",
            "title": "siga vulnerability",
            "summary": "A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the component HTML-to-PDF Endpoint. This manipulation of the argument html causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-11T21:17:41.567",
            "published_at": "2026-09-07T06:17:23.580",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.1.0; 11.1.1",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the component HTML-to-PDF Endpoint. This manipulation of the argument html causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/projeto-siga/siga/",
                "https://github.com/projeto-siga/siga/issues/2492",
                "https://vuldb.com/cve/CVE-2026-86273",
                "https://vuldb.com/submit/904863",
                "https://vuldb.com/vuln/399434",
                "https://vuldb.com/vuln/399434/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T06:17:23.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86273"
                }
            ]
        },
        {
            "id": "CVE-2026-86272",
            "vendor": "Beijing Meite Software Technology",
            "product": "U+Smart Enjoyment WebSite",
            "title": "U+Smart Enjoyment WebSite vulnerability",
            "summary": "A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/UploadFormImg.ashx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.",
            "updated_at": "2026-09-07T05:16:55.387",
            "published_at": "2026-09-07T05:16:55.387",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "18.6001.1096.1000",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/UploadFormImg.ashx. Executing a manipulation of the argument File can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://ucn9h68n9289.feishu.cn/wiki/IYaowPR6licbC3kdw3xcJpQ7n6b?from=from_copylink",
                "https://vuldb.com/cve/CVE-2026-86272",
                "https://vuldb.com/submit/904145",
                "https://vuldb.com/vuln/399431",
                "https://vuldb.com/vuln/399431/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T05:16:55.387",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86272"
                }
            ]
        },
        {
            "id": "CVE-2026-86271",
            "vendor": "n/a",
            "product": "FluentCMS",
            "title": "FluentCMS vulnerability",
            "summary": "A vulnerability was found in FluentCMS up to 0.0.5. This affects the function GetAccessible of the file src/Backend/FluentCMS.Services/Permissions/PermissionManager.cs. Performing a manipulation results in missing authorization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-07T05:16:55.210",
            "published_at": "2026-09-07T05:16:55.210",
            "cvss": 2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.0.1; 0.0.2; 0.0.3; 0.0.4; 0.0.5",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "A vulnerability was found in FluentCMS up to 0.0.5. This affects the function GetAccessible of the file src/Backend/FluentCMS.Services/Permissions/PermissionManager.cs. Performing a manipulation results in missing authorization. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/fluentcms/FluentCMS/",
                "https://github.com/fluentcms/FluentCMS/issues/2409",
                "https://vuldb.com/cve/CVE-2026-86271",
                "https://vuldb.com/submit/904824",
                "https://vuldb.com/vuln/399430",
                "https://vuldb.com/vuln/399430/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T05:16:55.210",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86271"
                }
            ]
        },
        {
            "id": "CVE-2026-86270",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/settings_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.",
            "updated_at": "2026-09-07T05:16:55.020",
            "published_at": "2026-09-07T05:16:55.020",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/settings_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ltranquility/submit_repository/issues/10",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86270",
                "https://vuldb.com/submit/904784",
                "https://vuldb.com/vuln/399429",
                "https://vuldb.com/vuln/399429/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T05:16:55.020",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86270"
                }
            ]
        },
        {
            "id": "CVE-2026-86269",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/emp_edit1.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.",
            "updated_at": "2026-09-07T04:17:55.467",
            "published_at": "2026-09-07T04:17:55.467",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/emp_edit1.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ltranquility/submit_repository/issues/9",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86269",
                "https://vuldb.com/submit/904510",
                "https://vuldb.com/vuln/399428",
                "https://vuldb.com/vuln/399428/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T04:17:55.467",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86269"
                }
            ]
        },
        {
            "id": "CVE-2026-86268",
            "vendor": "itsourcecode",
            "product": "School Management System",
            "title": "School Management System vulnerability",
            "summary": "A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.",
            "updated_at": "2026-09-11T21:17:41.040",
            "published_at": "2026-09-07T04:17:55.277",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/anglemsg2401-bot/cve/issues/6",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86268",
                "https://vuldb.com/submit/903720",
                "https://vuldb.com/vuln/399427",
                "https://vuldb.com/vuln/399427/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T04:17:55.277",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86268"
                }
            ]
        },
        {
            "id": "CVE-2026-86267",
            "vendor": "itsourcecode",
            "product": "Information System Society Membership System",
            "title": "Information System Society Membership System vulnerability",
            "summary": "A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.",
            "updated_at": "2026-09-07T04:17:55.087",
            "published_at": "2026-09-07T04:17:55.087",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/anglemsg2401-bot/cve/issues/5",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86267",
                "https://vuldb.com/submit/903719",
                "https://vuldb.com/vuln/399426",
                "https://vuldb.com/vuln/399426/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T04:17:55.087",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86267"
                }
            ]
        },
        {
            "id": "CVE-2026-86265",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/us_transac.php. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
            "updated_at": "2026-09-07T04:17:50.427",
            "published_at": "2026-09-07T04:17:50.427",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/us_transac.php. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ltranquility/submit_repository/issues/8",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86265",
                "https://vuldb.com/submit/902721",
                "https://vuldb.com/vuln/399411",
                "https://vuldb.com/vuln/399411/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T04:17:50.427",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86265"
                }
            ]
        },
        {
            "id": "CVE-2026-86264",
            "vendor": "sfturing",
            "product": "ssm_pro",
            "title": "ssm_pro vulnerability",
            "summary": "A flaw has been found in sfturing ssm_pro up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Endpoint. This manipulation of the argument hospitalName/officesName/doctorName causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-07T03:17:19.243",
            "published_at": "2026-09-07T03:17:19.243",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "627f426331da8086ce8fff2017d65b1ddef384f8",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A flaw has been found in sfturing ssm_pro up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Endpoint. This manipulation of the argument hospitalName/officesName/doctorName causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/sfturing/hosp_order/issues/117",
                "https://vuldb.com/cve/CVE-2026-86264",
                "https://vuldb.com/submit/902243",
                "https://vuldb.com/vuln/399410",
                "https://vuldb.com/vuln/399410/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T03:17:19.243",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86264"
                }
            ]
        },
        {
            "id": "CVE-2026-86263",
            "vendor": "sfturing",
            "product": "hosp_order",
            "title": "hosp_order vulnerability",
            "summary": "A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The manipulation of the argument ID results in authorization bypass. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-07T03:17:19.070",
            "published_at": "2026-09-07T03:17:19.070",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "627f426331da8086ce8fff2017d65b1ddef384f8",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The manipulation of the argument ID results in authorization bypass. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/sfturing/hosp_order/",
                "https://github.com/sfturing/hosp_order/issues/116",
                "https://vuldb.com/cve/CVE-2026-86263",
                "https://vuldb.com/submit/902242",
                "https://vuldb.com/vuln/399409",
                "https://vuldb.com/vuln/399409/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T03:17:19.070",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86263"
                }
            ]
        },
        {
            "id": "CVE-2026-86262",
            "vendor": "sfturing",
            "product": "hosp_order",
            "title": "hosp_order vulnerability",
            "summary": "A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Handler. The manipulation of the argument userID/id leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-11T21:17:40.513",
            "published_at": "2026-09-07T03:17:18.893",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "627f426331da8086ce8fff2017d65b1ddef384f8",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Handler. The manipulation of the argument userID/id leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/sfturing/hosp_order/",
                "https://github.com/sfturing/hosp_order/issues/115",
                "https://vuldb.com/cve/CVE-2026-86262",
                "https://vuldb.com/submit/902241",
                "https://vuldb.com/vuln/399408",
                "https://vuldb.com/vuln/399408/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T03:17:18.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86262"
                }
            ]
        },
        {
            "id": "CVE-2026-86261",
            "vendor": "sfturing",
            "product": "hosp_order",
            "title": "hosp_order vulnerability",
            "summary": "A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Controller. Executing a manipulation of the argument userIdenf can lead to authorization bypass. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-07T03:17:18.723",
            "published_at": "2026-09-07T03:17:18.723",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "627f426331da8086ce8fff2017d65b1ddef384f8",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Controller. Executing a manipulation of the argument userIdenf can lead to authorization bypass. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/sfturing/hosp_order/",
                "https://github.com/sfturing/hosp_order/issues/114",
                "https://vuldb.com/cve/CVE-2026-86261",
                "https://vuldb.com/submit/902240",
                "https://vuldb.com/vuln/399407",
                "https://vuldb.com/vuln/399407/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T03:17:18.723",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86261"
                }
            ]
        },
        {
            "id": "CVE-2026-86260",
            "vendor": "sfturing",
            "product": "hosp_order",
            "title": "hosp_order vulnerability",
            "summary": "A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java of the component Password Recovery. Performing a manipulation results in unverified password change. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-07T03:17:17.647",
            "published_at": "2026-09-07T03:17:17.647",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "627f426331da8086ce8fff2017d65b1ddef384f8",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-620",
            "what_happened": "A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java of the component Password Recovery. Performing a manipulation results in unverified password change. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/sfturing/hosp_order/",
                "https://github.com/sfturing/hosp_order/issues/113",
                "https://vuldb.com/cve/CVE-2026-86260",
                "https://vuldb.com/submit/902239",
                "https://vuldb.com/vuln/399406",
                "https://vuldb.com/vuln/399406/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T03:17:17.647",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86260"
                }
            ]
        },
        {
            "id": "CVE-2026-86259",
            "vendor": "THU-MAIC",
            "product": "OpenMAIC",
            "title": "OpenMAIC vulnerability",
            "summary": "OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.",
            "updated_at": "2026-09-06T13:17:10.963",
            "published_at": "2026-09-06T13:17:10.963",
            "cvss": 9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.0.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/THU-MAIC/OpenMAIC",
                "https://github.com/THU-MAIC/OpenMAIC/blob/v1.0.0/app/api/generate/image/route.ts#L73-L78",
                "https://github.com/THU-MAIC/OpenMAIC/blob/v1.0.0/middleware.ts#L60-L63",
                "https://github.com/THU-MAIC/OpenMAIC/releases/tag/v1.0.1",
                "https://github.com/THU-MAIC/OpenMAIC/security/advisories/GHSA-9m7h-vh2h-rc3w",
                "https://www.vulncheck.com/advisories/openmaic-before-1.0.1-ssrf-via-environment-gated-url-validation"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T13:17:10.963",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86259"
                }
            ]
        },
        {
            "id": "CVE-2026-86258",
            "vendor": "jupyter",
            "product": "nbviewer",
            "title": "nbviewer vulnerability",
            "summary": "nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attackers can read files from sibling directories outside the configured root by requesting paths that share the root as a textual prefix, disclosing unintended notebooks and credentials.",
            "updated_at": "2026-09-06T13:17:10.830",
            "published_at": "2026-09-06T13:17:10.830",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.0.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attackers can read files from sibling directories outside the configured root by requesting paths that share the root as a textual prefix, disclosing unintended notebooks and credentials.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jupyter/nbviewer",
                "https://github.com/jupyter/nbviewer/blob/1.0.1/nbviewer/providers/local/handlers.py#L92-L107",
                "https://github.com/jupyter/nbviewer/commit/aad36106f72a1ca7721310c6fccc677ce4c744a5",
                "https://github.com/jupyter/nbviewer/issues/1115",
                "https://www.vulncheck.com/advisories/nbviewer-through-1.0.1-path-traversal-via-localfilehandler"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T13:17:10.830",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86258"
                }
            ]
        },
        {
            "id": "CVE-2026-86257",
            "vendor": "wger-project",
            "product": "wger",
            "title": "wger vulnerability",
            "summary": "wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or execute code when admins open the exported file in Excel or LibreOffice Calc.",
            "updated_at": "2026-09-06T12:17:16.700",
            "published_at": "2026-09-06T12:17:16.700",
            "cvss": 4.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.6 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-1236",
            "what_happened": "wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or execute code when admins open the exported file in Excel or LibreOffice Calc.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/wger-project/wger/security/advisories/GHSA-xq9m-hmp9-fw87",
                "https://www.vulncheck.com/advisories/wger-before-2.6-csv-formula-injection-via-member-export"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:16.700",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86257"
                }
            ]
        },
        {
            "id": "CVE-2026-86256",
            "vendor": "wger-project",
            "product": "wger",
            "title": "wger vulnerability",
            "summary": "wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view redirects to the user-supplied 'next' GET parameter via HttpResponseRedirect() without validating it with url_has_allowed_host_and_scheme(). An attacker who delivers a crafted link to an authenticated trainer can redirect the trainer's browser to an attacker-controlled domain, enabling phishing and leaking the wger URL structure (including the impersonated user's user_pk) via the Referer header.",
            "updated_at": "2026-09-06T12:17:16.567",
            "published_at": "2026-09-06T12:17:16.567",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.6 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-601",
            "what_happened": "wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view redirects to the user-supplied 'next' GET parameter via HttpResponseRedirect() without validating it with url_has_allowed_host_and_scheme(). An attacker who delivers a crafted link to an authenticated trainer can redirect the trainer's browser to an attacker-controlled domain, enabling phishing and leaking the wger URL structure (including the impersonated user's user_pk) via the Referer header.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/wger-project/wger/security/advisories/GHSA-vqv8-j3mj-wjxj",
                "https://www.vulncheck.com/advisories/wger-before-2.6-open-redirect-via-trainer-login-next-parameter"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:16.567",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86256"
                }
            ]
        },
        {
            "id": "CVE-2026-86255",
            "vendor": "wger-project",
            "product": "wger",
            "title": "wger vulnerability",
            "summary": "wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcing the server to iterate thousands of times per request and exhaust worker threads, denying service to legitimate users.",
            "updated_at": "2026-09-06T12:17:16.433",
            "published_at": "2026-09-06T12:17:16.433",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.5 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcing the server to iterate thousands of times per request and exhaust worker threads, denying service to legitimate users.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/wger-project/wger/security/advisories/GHSA-v25j-wqcw-fvhj",
                "https://www.vulncheck.com/advisories/wger-before-2.5-uncontrolled-resource-consumption-via-date-sequence"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:16.433",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86255"
                }
            ]
        },
        {
            "id": "CVE-2026-86254",
            "vendor": "wger-project",
            "product": "wger",
            "title": "wger vulnerability",
            "summary": "wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparison instead of the is_same_gym() helper, allowing gym staff with gym=None to delete, deactivate, or activate any other user with gym=None. Attackers with gym.manage_gym permission and gym=None affiliation can permanently delete user accounts, lock users out via deactivation, or undo defensive deactivations by exploiting the None != None comparison edge case.",
            "updated_at": "2026-09-06T12:17:16.297",
            "published_at": "2026-09-06T12:17:16.297",
            "cvss": 6.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through master (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-862",
            "what_happened": "wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparison instead of the is_same_gym() helper, allowing gym staff with gym=None to delete, deactivate, or activate any other user with gym=None. Attackers with gym.manage_gym permission and gym=None affiliation can permanently delete user accounts, lock users out via deactivation, or undo defensive deactivations by exploiting the None != None comparison edge case.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/wger-project/wger/security/advisories/GHSA-mw8f-w6p8-xrf4",
                "https://www.vulncheck.com/advisories/wger-incomplete-authorization-fix-cross-tenant-account-deletion"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:16.297",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86254"
                }
            ]
        },
        {
            "id": "CVE-2026-86253",
            "vendor": "h3js",
            "product": "h3",
            "title": "h3 vulnerability",
            "summary": "h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-encoded dot segments (%2e%2e) are passed to decodeURI() and decoded to ../ sequences without sanitization. An unauthenticated remote attacker can send crafted requests to endpoints served by serveStatic() to read arbitrary files outside the intended static directory. Fixed in 1.15.6 and 2.0.1-rc.15.",
            "updated_at": "2026-09-06T12:17:16.163",
            "published_at": "2026-09-06T12:17:16.163",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.15.6 (semver); 2.0.0-beta.0 through before 2.0.1-rc.15 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-22",
            "what_happened": "h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-encoded dot segments (%2e%2e) are passed to decodeURI() and decoded to ../ sequences without sanitization. An unauthenticated remote attacker can send crafted requests to endpoints served by serveStatic() to read arbitrary files outside the intended static directory. Fixed in 1.15.6 and 2.0.1-rc.15.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/h3js/h3/security/advisories/GHSA-wr4h-v87w-p3r7",
                "https://www.vulncheck.com/advisories/h3-before-1.15.6-path-traversal-via-percent-encoded-dot-segments"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:16.163",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86253"
                }
            ]
        },
        {
            "id": "CVE-2026-86252",
            "vendor": "h3js",
            "product": "h3",
            "title": "h3 vulnerability",
            "summary": "h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type directives, split single push calls into multiple browser-parsed events, or escape comment fields to inject data, bypassing the prior CVE fix that only addressed newline injection.",
            "updated_at": "2026-09-06T12:17:16.033",
            "published_at": "2026-09-06T12:17:16.033",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.15.9 (semver); 2.0.0-beta.0 through before 2.0.1-rc.17 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitized carriage returns. Attackers can inject event type directives, split single push calls into multiple browser-parsed events, or escape comment fields to inject data, bypassing the prior CVE fix that only addressed newline injection.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/h3js/h3/security/advisories/GHSA-4hxc-9384-m385",
                "https://www.vulncheck.com/advisories/h3-before-1.15.9-sse-event-injection-via-carriage-return"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:16.033",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86252"
                }
            ]
        },
        {
            "id": "CVE-2026-86251",
            "vendor": "h3js",
            "product": "h3",
            "title": "h3 vulnerability",
            "summary": "h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequences (e.g. %252e%252e) to be decoded to %2e%2e, which survives resolveDotSegments() because that function only checks for literal '.' characters. When the resulting asset ID is resolved by URL-based backends (CDN, S3, object storage), %2e%2e is interpreted as '..' per RFC 3986, enabling path traversal to read arbitrary files from the backend.",
            "updated_at": "2026-09-06T12:17:15.900",
            "published_at": "2026-09-06T12:17:15.900",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.15.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-22",
            "what_happened": "h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequences (e.g. %252e%252e) to be decoded to %2e%2e, which survives resolveDotSegments() because that function only checks for literal '.' characters. When the resulting asset ID is resolved by URL-based backends (CDN, S3, object storage), %2e%2e is interpreted as '..' per RFC 3986, enabling path traversal to read arbitrary files from the backend.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/h3js/h3/security/advisories/GHSA-72gr-qfp7-vwhw",
                "https://www.vulncheck.com/advisories/h3-before-1.15.9-path-traversal-via-double-decoding"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:15.900",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86251"
                }
            ]
        },
        {
            "id": "CVE-2026-86250",
            "vendor": "h3js",
            "product": "h3",
            "title": "h3 vulnerability",
            "summary": "h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk count to trigger an O(n²) cleanup loop that hangs the server process.",
            "updated_at": "2026-09-06T12:17:15.767",
            "published_at": "2026-09-06T12:17:15.767",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.0.0-beta.4 through before 2.0.1-rc.18 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted cookie header with an extremely large chunk count to trigger an O(n²) cleanup loop that hangs the server process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/h3js/h3/security/advisories/GHSA-q5pr-72pq-83v3",
                "https://www.vulncheck.com/advisories/h3-before-2.0.1-rc.18-denial-of-service-via-unbounded-chunked-cookie"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:15.767",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86250"
                }
            ]
        },
        {
            "id": "CVE-2026-86245",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_transac.php. Performing a manipulation of the argument companyname results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.",
            "updated_at": "2026-09-07T02:17:21.427",
            "published_at": "2026-09-07T02:17:21.427",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_transac.php. Performing a manipulation of the argument companyname results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/9ue33/cve/issues/1",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86245",
                "https://vuldb.com/submit/902051",
                "https://vuldb.com/vuln/399400",
                "https://vuldb.com/vuln/399400/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:21.427",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86245"
                }
            ]
        },
        {
            "id": "CVE-2026-86244",
            "vendor": "n/a",
            "product": "FastAdmin",
            "title": "FastAdmin vulnerability",
            "summary": "A security vulnerability has been detected in FastAdmin up to 1.2.0.20210401_beta. Affected is the function register/login of the file application/index/controller/User.php of the component User Controller. Such manipulation of the argument url leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 1.2.1.20210731_beta is able to address this issue. The name of the patch is b3d32e2bf3637488cfe2fc58a27a9d2475b2b51b. It is recommended to upgrade the affected component.",
            "updated_at": "2026-09-07T02:17:21.247",
            "published_at": "2026-09-07T02:17:21.247",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.2.0.20210401_beta",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A security vulnerability has been detected in FastAdmin up to 1.2.0.20210401_beta. Affected is the function register/login of the file application/index/controller/User.php of the component User Controller. Such manipulation of the argument url leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Upgrading to version 1.2.1.20210731_beta is able to address this issue. The name of the patch is b3d32e2bf3637488cfe2fc58a27a9d2475b2b51b. It is recommended to upgrade the affected component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/fastadminnet/fastadmin/commit/b3d32e2bf3637488cfe2fc58a27a9d2475b2b51b",
                "https://lhzzz08.github.io/posts/cveapplication4/",
                "https://vuldb.com/cve/CVE-2026-86244",
                "https://vuldb.com/submit/898809",
                "https://vuldb.com/vuln/399399",
                "https://vuldb.com/vuln/399399/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:21.247",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86244"
                }
            ]
        },
        {
            "id": "CVE-2026-86242",
            "vendor": "maximhq",
            "product": "Bifrost",
            "title": "Bifrost vulnerability",
            "summary": "Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-object loader treats an http-prefixed path as a download URL, writes the body to a temporary .so, and passes it to Go's plugin.Open. After a successful open, optional Init runs immediately with the supplied config as the Bifrost process user. On documented dynamically linked builds (DYNAMIC=1 / no static-link flags), which the vendor requires for custom Go plugins, plugin.Open is expected to succeed and this is unauthenticated remote code execution. On the published statically linked Docker image, plugin.Open fails with Dynamic loading not supported, so that build class is only server-side request forgery. Attack complexity is High because the attacker cannot force RCE on the default static image and a loadable plugin must match the host Go version, OS, architecture, and linkage. The 1.6.x HTTP transport line through 1.6.11 does not contain the fix.",
            "updated_at": "2026-09-06T12:17:15.583",
            "published_at": "2026-09-06T12:17:15.583",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.0.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-94",
            "what_happened": "Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-object loader treats an http-prefixed path as a download URL, writes the body to a temporary .so, and passes it to Go's plugin.Open. After a successful open, optional Init runs immediately with the supplied config as the Bifrost process user. On documented dynamically linked builds (DYNAMIC=1 / no static-link flags), which the vendor requires for custom Go plugins, plugin.Open is expected to succeed and this is unauthenticated remote code execution. On the published statically linked Docker image, plugin.Open fails with Dynamic loading not supported, so that build class is only server-side request forgery. Attack complexity is High because the attacker cannot force RCE on the default static image and a loadable plugin must match the host Go version, OS, architecture, and linkage. The 1.6.x HTTP transport line through 1.6.11 does not contain the fix.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/maximhq/bifrost",
                "https://github.com/maximhq/bifrost/commit/e0057ff355f831c251eabe9d0e44f3a3748532c6",
                "https://github.com/maximhq/bifrost/pull/5763",
                "https://github.com/maximhq/bifrost/releases/tag/transports/v2.0.0",
                "https://github.com/maximhq/bifrost/security/advisories/GHSA-2qp8-4xgm-fw6g"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:15.583",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86242"
                }
            ]
        },
        {
            "id": "CVE-2026-86241",
            "vendor": "liufee",
            "product": "FeehiCMS",
            "title": "FeehiCMS vulnerability",
            "summary": "A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie Validation. This manipulation of the argument cookieValidationKey causes use of hard-coded cryptographic key\r . The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-11T21:17:39.983",
            "published_at": "2026-09-07T02:17:21.067",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.1.0; 2.1.1",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-320",
            "what_happened": "A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie Validation. This manipulation of the argument cookieValidationKey causes use of hard-coded cryptographic key\r . The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/liufee/cms/issues/96",
                "https://github.com/yang5ynag/cve/blob/main/FEHI-003-Empty-cookieValidationKey.md",
                "https://vuldb.com/cve/CVE-2026-86241",
                "https://vuldb.com/submit/901836",
                "https://vuldb.com/vuln/399398",
                "https://vuldb.com/vuln/399398/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:21.067",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86241"
                }
            ]
        },
        {
            "id": "CVE-2026-86240",
            "vendor": "liufee",
            "product": "FeehiCMS",
            "title": "FeehiCMS vulnerability",
            "summary": "A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of the file backend/widgets/ueditor/Uploader.php of the component UEditor. The manipulation of the argument source[] results in server-side request forgery. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-07T02:17:20.890",
            "published_at": "2026-09-07T02:17:20.890",
            "cvss": 2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.1.0; 2.1.1",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of the file backend/widgets/ueditor/Uploader.php of the component UEditor. The manipulation of the argument source[] results in server-side request forgery. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/liufee/cms/issues/95",
                "https://github.com/yang5ynag/cve/blob/main/FEHI-002-UEditor-catchImage-SSRF.md",
                "https://vuldb.com/cve/CVE-2026-86240",
                "https://vuldb.com/submit/901834",
                "https://vuldb.com/vuln/399397",
                "https://vuldb.com/vuln/399397/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:20.890",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86240"
                }
            ]
        },
        {
            "id": "CVE-2026-86239",
            "vendor": "liufee",
            "product": "FeehiCMS",
            "title": "FeehiCMS vulnerability",
            "summary": "A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-07T02:17:20.710",
            "published_at": "2026-09-07T02:17:20.710",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.1.0; 2.1.1",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/liufee/cms/issues/94",
                "https://github.com/yang5ynag/cve/blob/main/FEHI-001-UEditor-Unauthorized-File-Upload.md",
                "https://vuldb.com/cve/CVE-2026-86239",
                "https://vuldb.com/submit/901833",
                "https://vuldb.com/vuln/399396",
                "https://vuldb.com/vuln/399396/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:20.710",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86239"
                }
            ]
        },
        {
            "id": "CVE-2026-86238",
            "vendor": "projectworlds",
            "product": "Online Examination System",
            "title": "Online Examination System vulnerability",
            "summary": "A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback Form. Executing a manipulation of the argument Name/Subject can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.",
            "updated_at": "2026-09-07T01:16:56.223",
            "published_at": "2026-09-07T01:16:56.223",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback Form. Executing a manipulation of the argument Name/Subject can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/CyberShailendra1/Online-Examination-System-Project",
                "https://vuldb.com/cve/CVE-2026-86238",
                "https://vuldb.com/submit/901822",
                "https://vuldb.com/vuln/399395",
                "https://vuldb.com/vuln/399395/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T01:16:56.223",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86238"
                }
            ]
        },
        {
            "id": "CVE-2026-86237",
            "vendor": "openagents-org",
            "product": "openagents",
            "title": "openagents vulnerability",
            "summary": "A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manipulation of the argument base_url results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. Endpoint and both sinks unchanged since filing; only the file moved (e277dd1a). Maintainer closed as inapplicable yet the identical unguarded code still ships in 0.9.3.post20. Sibling admin endpoints do call the shipped-but-unused-by-this-handler _require_admin().",
            "updated_at": "2026-09-07T01:16:56.040",
            "published_at": "2026-09-07T01:16:56.040",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.8.0; 0.8.1; 0.8.2; 0.8.3; 0.8.4; 0.8.5; 0.8.6; 0.8.7; 0.8.8; 0.8.9; 0.8.10; 0.8.11; 0.8.12; 0.8.13; 0.8.14; 0.8.15; 0.8.16; 0.8.17; 0.8.18; 0.8.19; 0.9.3.post20",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manipulation of the argument base_url results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used. Endpoint and both sinks unchanged since filing; only the file moved (e277dd1a). Maintainer closed as inapplicable yet the identical unguarded code still ships in 0.9.3.post20. Sibling admin endpoints do call the shipped-but-unused-by-this-handler _require_admin().",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openagents-org/openagents/",
                "https://github.com/openagents-org/openagents/issues/566",
                "https://vuldb.com/cve/CVE-2026-86237",
                "https://vuldb.com/submit/898788",
                "https://vuldb.com/submit/901667",
                "https://vuldb.com/vuln/399394",
                "https://vuldb.com/vuln/399394/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T01:16:56.040",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86237"
                }
            ]
        },
        {
            "id": "CVE-2026-86236",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. Such manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
            "updated_at": "2026-09-11T21:17:39.460",
            "published_at": "2026-09-07T01:16:55.863",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. Such manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ltranquility/submit_repository/issues/6",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86236",
                "https://vuldb.com/submit/898738",
                "https://vuldb.com/vuln/399393",
                "https://vuldb.com/vuln/399393/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T01:16:55.863",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86236"
                }
            ]
        },
        {
            "id": "CVE-2026-86235",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. This manipulation of the argument Customer causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.",
            "updated_at": "2026-09-07T00:17:47.030",
            "published_at": "2026-09-07T00:17:47.030",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. This manipulation of the argument Customer causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ltranquility/submit_repository/issues/5",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86235",
                "https://vuldb.com/submit/898638",
                "https://vuldb.com/vuln/399392",
                "https://vuldb.com/vuln/399392/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T00:17:47.030",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86235"
                }
            ]
        },
        {
            "id": "CVE-2026-86234",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument firstname results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.",
            "updated_at": "2026-09-07T00:17:46.867",
            "published_at": "2026-09-07T00:17:46.867",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument firstname results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/v89269561-web/CyberseReasearch/issues/3",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86234",
                "https://vuldb.com/submit/898594",
                "https://vuldb.com/vuln/399391",
                "https://vuldb.com/vuln/399391/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T00:17:46.867",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86234"
                }
            ]
        },
        {
            "id": "CVE-2026-86233",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.",
            "updated_at": "2026-09-07T00:17:46.683",
            "published_at": "2026-09-07T00:17:46.683",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/v89269561-web/CyberseReasearch/issues/2",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86233",
                "https://vuldb.com/submit/898593",
                "https://vuldb.com/vuln/399390",
                "https://vuldb.com/vuln/399390/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T00:17:46.683",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86233"
                }
            ]
        },
        {
            "id": "CVE-2026-86232",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?type=supplier. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.",
            "updated_at": "2026-09-06T23:17:39.323",
            "published_at": "2026-09-06T23:17:39.323",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?type=supplier. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/v89269561-web/CyberseReasearch/issues/1",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86232",
                "https://vuldb.com/submit/898592",
                "https://vuldb.com/vuln/399389",
                "https://vuldb.com/vuln/399389/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T23:17:39.323",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86232"
                }
            ]
        },
        {
            "id": "CVE-2026-86231",
            "vendor": "mwiede",
            "product": "jsch",
            "title": "jsch vulnerability",
            "summary": "A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper check for certificate revocation. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.28.6 is able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be3fd66bcafc42d23. You should upgrade the affected component.",
            "updated_at": "2026-09-11T21:17:38.907",
            "published_at": "2026-09-06T23:17:39.157",
            "cvss": 2.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.28.0; 2.28.1; 2.28.2; 2.28.3; 2.28.4; 2.28.5",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-298",
            "what_happened": "A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts results in improper check for certificate revocation. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.28.6 is able to address this issue. The patch is named 194a2f76a5c0f1c3f778565be3fd66bcafc42d23. You should upgrade the affected component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/mwiede/jsch/",
                "https://github.com/mwiede/jsch/commit/194a2f76a5c0f1c3f778565be3fd66bcafc42d23",
                "https://github.com/mwiede/jsch/issues/1091",
                "https://github.com/mwiede/jsch/pull/1098",
                "https://github.com/mwiede/jsch/releases/tag/jsch-2.28.6",
                "https://vuldb.com/cve/CVE-2026-86231",
                "https://vuldb.com/submit/898485",
                "https://vuldb.com/vuln/399388",
                "https://vuldb.com/vuln/399388/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T23:17:39.157",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86231"
                }
            ]
        },
        {
            "id": "CVE-2026-86228",
            "vendor": "n/a",
            "product": "JeecgBoot",
            "title": "JeecgBoot vulnerability",
            "summary": "A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 3.9.5 is able to resolve this issue. The name of the patch is a2be896f753936956ee6863b632b8e5a0231345c. You should upgrade the affected component.",
            "updated_at": "2026-09-06T23:17:38.990",
            "published_at": "2026-09-06T23:17:38.990",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.9.0; 3.9.1; 3.9.2; 3.9.3",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 3.9.5 is able to resolve this issue. The name of the patch is a2be896f753936956ee6863b632b8e5a0231345c. You should upgrade the affected component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jeecgboot/JeecgBoot/",
                "https://github.com/jeecgboot/JeecgBoot/commit/a2be896f753936956ee6863b632b8e5a0231345c",
                "https://github.com/jeecgboot/JeecgBoot/issues/9600",
                "https://github.com/jeecgboot/JeecgBoot/releases/tag/v3.9.5",
                "https://vuldb.com/cve/CVE-2026-86228",
                "https://vuldb.com/submit/898368",
                "https://vuldb.com/vuln/399381",
                "https://vuldb.com/vuln/399381/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T23:17:38.990",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86228"
                }
            ]
        },
        {
            "id": "CVE-2026-86227",
            "vendor": "valkey-io",
            "product": "valkey",
            "title": "valkey vulnerability",
            "summary": "A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didx causes out-of-bounds read. It is possible to initiate the attack remotely. The attack is considered to have high complexity. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks. Patch name: 4691888e7fab3df128f0bde5750c9fde2ae552fa. To fix this issue, it is recommended to deploy a patch. Exploitation requires cluster mode plus attacker-controlled dump.rdb at startup (data-dir write access, replication feed, or a stored crafted RDB) - an attacker-position DoS at boot, not network pre-auth. The issue report was closed stating it \"is worth fixing for the sake of memory safety… but I don't think it meets our bar for a security disclosure.\"",
            "updated_at": "2026-09-06T23:17:38.150",
            "published_at": "2026-09-06T23:17:38.150",
            "cvss": 1.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.0.0; 9.0.1; 9.0.2; 9.0.3; 9.0.4; 9.0.5; 9.1.0; 9.1.1",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-119",
            "what_happened": "A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didx causes out-of-bounds read. It is possible to initiate the attack remotely. The attack is considered to have high complexity. It is indicated that the exploitability is difficult. The exploit has been made available to the public and could be used for attacks. Patch name: 4691888e7fab3df128f0bde5750c9fde2ae552fa. To fix this issue, it is recommended to deploy a patch. Exploitation requires cluster mode plus attacker-controlled dump.rdb at startup (data-dir write access, replication feed, or a stored crafted RDB) - an attacker-position DoS at boot, not network pre-auth. The issue report was closed stating it \"is worth fixing for the sake of memory safety… but I don't think it meets our bar for a security disclosure.\"",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/user-attachments/files/30195539/RDB.zip",
                "https://github.com/valkey-io/valkey/",
                "https://github.com/valkey-io/valkey/commit/4691888e7fab3df128f0bde5750c9fde2ae552fa",
                "https://github.com/valkey-io/valkey/issues/4222",
                "https://github.com/valkey-io/valkey/pull/4229",
                "https://vuldb.com/cve/CVE-2026-86227",
                "https://vuldb.com/submit/897659",
                "https://vuldb.com/vuln/399380",
                "https://vuldb.com/vuln/399380/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T23:17:38.150",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86227"
                }
            ]
        },
        {
            "id": "CVE-2026-86226",
            "vendor": "Projectwolds",
            "product": "Online Attendance System",
            "title": "Online Attendance System vulnerability",
            "summary": "A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipulation of the argument email results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.",
            "updated_at": "2026-09-06T22:17:20.673",
            "published_at": "2026-09-06T22:17:20.673",
            "cvss": 2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipulation of the argument email results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/CyberShailendra1/Online-Attendance-System-Projectworlds",
                "https://vuldb.com/cve/CVE-2026-86226",
                "https://vuldb.com/submit/898328",
                "https://vuldb.com/vuln/399379",
                "https://vuldb.com/vuln/399379/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T22:17:20.673",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86226"
                }
            ]
        },
        {
            "id": "CVE-2026-86225",
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System",
            "title": "Class and Exam Timetabling System vulnerability",
            "summary": "A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.",
            "updated_at": "2026-09-06T22:17:20.507",
            "published_at": "2026-09-06T22:17:20.507",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/justconter/_CVE/issues/6",
                "https://vuldb.com/cve/CVE-2026-86225",
                "https://vuldb.com/submit/897751",
                "https://vuldb.com/vuln/399378",
                "https://vuldb.com/vuln/399378/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T22:17:20.507",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86225"
                }
            ]
        },
        {
            "id": "CVE-2026-86224",
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System",
            "title": "Class and Exam Timetabling System vulnerability",
            "summary": "A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.",
            "updated_at": "2026-09-11T21:17:38.340",
            "published_at": "2026-09-06T21:17:22.567",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/justconter/_CVE/issues/5",
                "https://vuldb.com/cve/CVE-2026-86224",
                "https://vuldb.com/submit/897750",
                "https://vuldb.com/vuln/399377",
                "https://vuldb.com/vuln/399377/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T21:17:22.567",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86224"
                }
            ]
        },
        {
            "id": "CVE-2026-86223",
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System",
            "title": "Class and Exam Timetabling System vulnerability",
            "summary": "A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.",
            "updated_at": "2026-09-06T20:17:28.280",
            "published_at": "2026-09-06T20:17:28.280",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/justconter/_CVE/issues/4",
                "https://vuldb.com/cve/CVE-2026-86223",
                "https://vuldb.com/submit/897749",
                "https://vuldb.com/vuln/399376",
                "https://vuldb.com/vuln/399376/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T20:17:28.280",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86223"
                }
            ]
        },
        {
            "id": "CVE-2026-86222",
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System",
            "title": "Class and Exam Timetabling System vulnerability",
            "summary": "A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of the argument course leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
            "updated_at": "2026-09-06T20:17:28.117",
            "published_at": "2026-09-06T20:17:28.117",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of the argument course leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/justconter/_CVE/issues/3",
                "https://vuldb.com/cve/CVE-2026-86222",
                "https://vuldb.com/submit/897748",
                "https://vuldb.com/vuln/399375",
                "https://vuldb.com/vuln/399375/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T20:17:28.117",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86222"
                }
            ]
        },
        {
            "id": "CVE-2026-86221",
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System",
            "title": "Class and Exam Timetabling System vulnerability",
            "summary": "A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This manipulation of the argument course causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.",
            "updated_at": "2026-09-06T19:17:27.943",
            "published_at": "2026-09-06T19:17:27.943",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This manipulation of the argument course causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/justconter/_CVE/issues/2",
                "https://vuldb.com/cve/CVE-2026-86221",
                "https://vuldb.com/submit/897747",
                "https://vuldb.com/vuln/399374",
                "https://vuldb.com/vuln/399374/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T19:17:27.943",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86221"
                }
            ]
        },
        {
            "id": "CVE-2026-86220",
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System",
            "title": "Class and Exam Timetabling System vulnerability",
            "summary": "A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of the argument course results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.",
            "updated_at": "2026-09-06T18:17:23.150",
            "published_at": "2026-09-06T18:17:23.150",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of the argument course results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/justconter/_CVE/issues/1",
                "https://vuldb.com/cve/CVE-2026-86220",
                "https://vuldb.com/submit/897734",
                "https://vuldb.com/vuln/399373",
                "https://vuldb.com/vuln/399373/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T18:17:23.150",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86220"
                }
            ]
        },
        {
            "id": "CVE-2026-86219",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step.",
            "summary": "Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step.\n\nserver_start generates a fresh nonce and sends it in the challenge, and nothing later compares that value against the nonce the client returns. server_step derives the expected digest from the client's own parameters, so a response verifies whenever its digest matches the nonce it carries. The count table it also checks is keyed on the client-supplied nonce and starts empty in each new server object, so a captured first response, carrying `nc=00000001`, passes that too. RFC 2831 defines the nonce in the response as the value the server sent in the preceding challenge.\n\nAn attacker who observes one successful `qop=auth` exchange can replay the captured response against a later session for the same service, host, realm and user, and authenticate as that user without knowing the password.",
            "updated_at": "2026-09-06T18:17:23.027",
            "published_at": "2026-09-06T18:17:23.027",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.2100 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-294",
            "what_happened": "Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step.\n\nserver_start generates a fresh nonce and sends it in the challenge, and nothing later compares that value against the nonce the client returns. server_step derives the expected digest from the client's own parameters, so a response verifies whenever its digest matches the nonce it carries. The count table it also checks is keyed on the client-supplied nonce and starts empty in each new server object, so a captured first response, carrying `nc=00000001`, passes that too. RFC 2831 defines the nonce in the response as the value the server sent in the preceding challenge.\n\nAn attacker who observes one successful `qop=auth` exchange can replay the captured response against a later session for the same service, host, realm and user, and authenticate as that user without knowing the password.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://datatracker.ietf.org/doc/html/rfc2831#section-2.1.2",
                "https://github.com/perl-authen-sasl/perl-authen-sasl/commit/94337367030612842924f697cead29964a96448d.patch",
                "https://metacpan.org/release/EHUELS/Authen-SASL-2.2000/source/lib/Authen/SASL/Perl/DIGEST_MD5.pm#L203-222",
                "https://metacpan.org/release/EHUELS/Authen-SASL-2.2000/source/lib/Authen/SASL/Perl/DIGEST_MD5.pm#L410-414",
                "https://metacpan.org/release/EHUELS/Authen-SASL-2.2100/changes",
                "https://www.cve.org/CVERecord?id=CVE-2025-40918"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T18:17:23.027",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86219"
                }
            ]
        },
        {
            "id": "CVE-2026-86218",
            "vendor": "N-able",
            "product": "N-central",
            "title": "N-central vulnerability",
            "summary": "N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.",
            "updated_at": "2026-09-09T05:18:19.490",
            "published_at": "2026-09-06T03:17:17.373",
            "cvss": 10,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 2026.3.1.14 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 64,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-96",
            "what_happened": "N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "title": "Exploit for Static Code Injection in N-Able N-Central CVE-2026-86218",
                    "summary": "Pre-auth RCE via static code injection in N-able N-central rated CVSS 10.0, actively exploited.",
                    "what_happened": "Pre-auth RCE via static code injection in N-able N-central rated CVSS 10.0, actively exploited.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-96",
                    "references": [
                        "https://sploitus.com/exploit?id=052122DE-9698-54C5-AF84-3E655FC24B14",
                        "https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit"
                    ],
                    "repository": "Sploitus",
                    "author": "jithinkrishnanrs",
                    "first_seen": "2026-09-12T11:01:32",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=052122DE-9698-54C5-AF84-3E655FC24B14"
                },
                {
                    "title": "Exploit for Static Code Injection in N-Able N-Central CVE-2026-86218",
                    "summary": "Pre-auth RCE via static code injection in N-able N-central rated CVSS 10.0, actively exploited.",
                    "what_happened": "Pre-auth RCE via static code injection in N-able N-central rated CVSS 10.0, actively exploited.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-96",
                    "references": [
                        "https://sploitus.com/exploit?id=052122DE-9698-54C5-AF84-3E655FC24B14",
                        "https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit"
                    ],
                    "repository": "jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit",
                    "author": "jithinkrishnanrs",
                    "first_seen": "2026-09-12T11:01:32",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit"
                }
            ],
            "references": [
                "https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86218",
                "https://sploitus.com/exploit?id=052122DE-9698-54C5-AF84-3E655FC24B14",
                "https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T03:17:17.373",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86218"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-86217",
            "vendor": "code-projects",
            "product": "Hotel and Tourism Reservation in PHP",
            "title": "Hotel and Tourism Reservation in PHP vulnerability",
            "summary": "A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.",
            "updated_at": "2026-09-11T21:17:37.720",
            "published_at": "2026-09-06T15:17:24.120",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://code-projects.org/",
                "https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Hotel%20and%20Tourism%20Reservation%20System%20%E2%80%93%20Sensitive%20Information%20Disclosure%20via%20Exposed%20SQL%20Database%20File.md",
                "https://vuldb.com/cve/CVE-2026-86217",
                "https://vuldb.com/submit/897301",
                "https://vuldb.com/vuln/399355",
                "https://vuldb.com/vuln/399355/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T15:17:24.120",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86217"
                }
            ]
        },
        {
            "id": "CVE-2026-86216",
            "vendor": "code-projects",
            "product": "Hotel and Tourism Reservation in PHP",
            "title": "Hotel and Tourism Reservation in PHP vulnerability",
            "summary": "A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.",
            "updated_at": "2026-09-06T14:17:25.760",
            "published_at": "2026-09-06T14:17:25.760",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://code-projects.org/",
                "https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Reflected%20Cross-Site%20Scripting%20(XSS)%20in%20Hotel%20and%20Tourism%20Reservation%20System%20%60room%60%20Parameter.md",
                "https://vuldb.com/cve/CVE-2026-86216",
                "https://vuldb.com/submit/897300",
                "https://vuldb.com/vuln/399354",
                "https://vuldb.com/vuln/399354/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T14:17:25.760",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86216"
                }
            ]
        },
        {
            "id": "CVE-2026-86215",
            "vendor": "Mstfakts",
            "product": "College-Management-System",
            "title": "College-Management-System vulnerability",
            "summary": "A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation of the argument log_out leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-06T14:17:24.773",
            "published_at": "2026-09-06T14:17:24.773",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "82ab01d057d96c8893c419cd9cb6870120faaea3; a37300648b6e50d43a2f10392ad741d199635daf; c81bbedea4d9e0b860ac368aa1dbb10e55ceddce",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-613",
            "what_happened": "A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation of the argument log_out leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Mstfakts/College-Management-System/",
                "https://github.com/Mstfakts/College-Management-System/issues/7",
                "https://vuldb.com/cve/CVE-2026-86215",
                "https://vuldb.com/submit/897264",
                "https://vuldb.com/vuln/399351",
                "https://vuldb.com/vuln/399351/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T14:17:24.773",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86215"
                }
            ]
        },
        {
            "id": "CVE-2026-86214",
            "vendor": "n/a",
            "product": "Mstfakts College-Management-System",
            "title": "Mstfakts College-Management-System vulnerability",
            "summary": "A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-06T13:17:10.667",
            "published_at": "2026-09-06T13:17:10.667",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "82ab01d057d96c8893c419cd9cb6870120faaea3; a37300648b6e50d43a2f10392ad741d199635daf; c81bbedea4d9e0b860ac368aa1dbb10e55ceddce",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Mstfakts/College-Management-System/issues/6",
                "https://vuldb.com/cve/CVE-2026-86214",
                "https://vuldb.com/submit/897250",
                "https://vuldb.com/vuln/399350",
                "https://vuldb.com/vuln/399350/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T13:17:10.667",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86214"
                }
            ]
        },
        {
            "id": "CVE-2026-86213",
            "vendor": "Mstfakts",
            "product": "College-Management-System",
            "title": "College-Management-System vulnerability",
            "summary": "A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of the argument book_name/book_author results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-06T13:17:10.487",
            "published_at": "2026-09-06T13:17:10.487",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "82ab01d057d96c8893c419cd9cb6870120faaea3; a37300648b6e50d43a2f10392ad741d199635daf; c81bbedea4d9e0b860ac368aa1dbb10e55ceddce",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of the argument book_name/book_author results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Mstfakts/College-Management-System/",
                "https://github.com/Mstfakts/College-Management-System/issues/5",
                "https://vuldb.com/cve/CVE-2026-86213",
                "https://vuldb.com/submit/897249",
                "https://vuldb.com/vuln/399349",
                "https://vuldb.com/vuln/399349/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T13:17:10.487",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86213"
                }
            ]
        },
        {
            "id": "CVE-2026-86212",
            "vendor": "n/a",
            "product": "Open5GS",
            "title": "Open5GS vulnerability",
            "summary": "A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9468de94caed2fc940f4a23cbf734651896d0fde. To fix this issue, it is recommended to deploy a patch.",
            "updated_at": "2026-09-11T21:17:37.160",
            "published_at": "2026-09-06T12:17:15.423",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.7.7; 2.8.0",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9468de94caed2fc940f4a23cbf734651896d0fde. To fix this issue, it is recommended to deploy a patch.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/open5gs/open5gs/",
                "https://github.com/open5gs/open5gs/commit/9468de94caed2fc940f4a23cbf734651896d0fde",
                "https://github.com/open5gs/open5gs/issues/4680",
                "https://vuldb.com/cve/CVE-2026-86212",
                "https://vuldb.com/submit/896623",
                "https://vuldb.com/vuln/399348",
                "https://vuldb.com/vuln/399348/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:15.423",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86212"
                }
            ]
        },
        {
            "id": "CVE-2026-86211",
            "vendor": "rabindralamsal",
            "product": "inventory-management-system",
            "title": "inventory-management-system vulnerability",
            "summary": "A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of the argument username/password can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.",
            "updated_at": "2026-09-06T11:18:06.427",
            "published_at": "2026-09-06T11:18:06.427",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of the argument username/password can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/yingxiujie/cve/issues/8",
                "https://vuldb.com/cve/CVE-2026-86211",
                "https://vuldb.com/submit/897074",
                "https://vuldb.com/vuln/399347",
                "https://vuldb.com/vuln/399347/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T11:18:06.427",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86211"
                }
            ]
        },
        {
            "id": "CVE-2026-86210",
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System",
            "title": "Class and Exam Timetabling System vulnerability",
            "summary": "A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_user_account.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.",
            "updated_at": "2026-09-06T10:17:15.330",
            "published_at": "2026-09-06T10:17:15.330",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_user_account.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/justconter/cve/issues/8",
                "https://vuldb.com/cve/CVE-2026-86210",
                "https://vuldb.com/submit/896590",
                "https://vuldb.com/vuln/399345",
                "https://vuldb.com/vuln/399345/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T10:17:15.330",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86210"
                }
            ]
        },
        {
            "id": "CVE-2026-86209",
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System",
            "title": "Class and Exam Timetabling System vulnerability",
            "summary": "A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.",
            "updated_at": "2026-09-06T10:17:15.163",
            "published_at": "2026-09-06T10:17:15.163",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/justconter/cve/issues/9",
                "https://vuldb.com/cve/CVE-2026-86209",
                "https://vuldb.com/submit/896589",
                "https://vuldb.com/vuln/399344",
                "https://vuldb.com/vuln/399344/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T10:17:15.163",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86209"
                }
            ]
        },
        {
            "id": "CVE-2026-86208",
            "vendor": "SourceCodester",
            "product": "Class and Exam Timetabling System",
            "title": "Class and Exam Timetabling System vulnerability",
            "summary": "A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.",
            "updated_at": "2026-09-06T10:17:14.933",
            "published_at": "2026-09-06T10:17:14.933",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/justconter/cve/issues/10",
                "https://vuldb.com/cve/CVE-2026-86208",
                "https://vuldb.com/submit/896588",
                "https://vuldb.com/vuln/399343",
                "https://vuldb.com/vuln/399343/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T10:17:14.933",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86208"
                }
            ]
        },
        {
            "id": "CVE-2026-86207",
            "vendor": "N-able",
            "product": "N-central",
            "title": "N-central vulnerability",
            "summary": "An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs",
            "updated_at": "2026-09-05T19:16:56.190",
            "published_at": "2026-09-05T19:16:56.190",
            "cvss": 7.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 2026.3.1.13 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 36,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-305",
            "what_happened": "An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "title": "Exploit for Static Code Injection in N-Able N-Central CVE-2026-86218",
                    "summary": "Pre-auth RCE via static code injection in N-able N-central rated CVSS 10.0, actively exploited.",
                    "what_happened": "Pre-auth RCE via static code injection in N-able N-central rated CVSS 10.0, actively exploited.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-96",
                    "references": [
                        "https://sploitus.com/exploit?id=052122DE-9698-54C5-AF84-3E655FC24B14",
                        "https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit"
                    ],
                    "repository": "Sploitus",
                    "author": "jithinkrishnanrs",
                    "first_seen": "2026-09-12T11:01:32",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=052122DE-9698-54C5-AF84-3E655FC24B14"
                },
                {
                    "title": "Exploit for Static Code Injection in N-Able N-Central CVE-2026-86218",
                    "summary": "Pre-auth RCE via static code injection in N-able N-central rated CVSS 10.0, actively exploited.",
                    "what_happened": "Pre-auth RCE via static code injection in N-able N-central rated CVSS 10.0, actively exploited.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-96",
                    "references": [
                        "https://sploitus.com/exploit?id=052122DE-9698-54C5-AF84-3E655FC24B14",
                        "https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit"
                    ],
                    "repository": "jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit",
                    "author": "jithinkrishnanrs",
                    "first_seen": "2026-09-12T11:01:32",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit"
                }
            ],
            "references": [
                "https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF3_Release_Notes.htm",
                "https://me.n-able.com/s/security-advisory/aArVy0000002LUzKAM/cve202686207-authentication-bypass-leads-to-unauthorised-access-to-ncentral",
                "https://sploitus.com/exploit?id=052122DE-9698-54C5-AF84-3E655FC24B14",
                "https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T19:16:56.190",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86207"
                }
            ]
        },
        {
            "id": "CVE-2026-86206",
            "vendor": "N-able",
            "product": "N-central",
            "title": "N-central vulnerability",
            "summary": "A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4",
            "updated_at": "2026-09-05T20:17:18.833",
            "published_at": "2026-09-05T20:17:18.833",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 2026.3.1.13 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 36,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-791",
            "what_happened": "A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "title": "Exploit for Static Code Injection in N-Able N-Central CVE-2026-86218",
                    "summary": "Pre-auth RCE via static code injection in N-able N-central rated CVSS 10.0, actively exploited.",
                    "what_happened": "Pre-auth RCE via static code injection in N-able N-central rated CVSS 10.0, actively exploited.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-96",
                    "references": [
                        "https://sploitus.com/exploit?id=052122DE-9698-54C5-AF84-3E655FC24B14",
                        "https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit"
                    ],
                    "repository": "Sploitus",
                    "author": "jithinkrishnanrs",
                    "first_seen": "2026-09-12T11:01:32",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=052122DE-9698-54C5-AF84-3E655FC24B14"
                },
                {
                    "title": "Exploit for Static Code Injection in N-Able N-Central CVE-2026-86218",
                    "summary": "Pre-auth RCE via static code injection in N-able N-central rated CVSS 10.0, actively exploited.",
                    "what_happened": "Pre-auth RCE via static code injection in N-able N-central rated CVSS 10.0, actively exploited.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-96",
                    "references": [
                        "https://sploitus.com/exploit?id=052122DE-9698-54C5-AF84-3E655FC24B14",
                        "https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit"
                    ],
                    "repository": "jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit",
                    "author": "jithinkrishnanrs",
                    "first_seen": "2026-09-12T11:01:32",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit"
                }
            ],
            "references": [
                "https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF3_Release_Notes.htm",
                "https://me.n-able.com/s/security-advisory/aArVy0000002LTNKA2/cve202686206-access-control-filter-bypass-allows-unauthorised-access-to-apis",
                "https://sploitus.com/exploit?id=052122DE-9698-54C5-AF84-3E655FC24B14",
                "https://github.com/jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T20:17:18.833",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86206"
                }
            ]
        },
        {
            "id": "CVE-2026-86205",
            "vendor": "h3js",
            "product": "h3",
            "title": "h3 vulnerability",
            "summary": "h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname. Attackers can craft a same-origin URL with a double-slash path segment that passes origin validation but produces a Location header interpreted by browsers as a protocol-relative redirect to an external domain.",
            "updated_at": "2026-09-06T12:17:15.277",
            "published_at": "2026-09-06T12:17:15.277",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.0.1-rc.17 through before 2.0.1-rc.18 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-601",
            "what_happened": "h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname. Attackers can craft a same-origin URL with a double-slash path segment that passes origin validation but produces a Location header interpreted by browsers as a protocol-relative redirect to an external domain.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/h3js/h3/security/advisories/GHSA-fp4x-ggrf-wmc6",
                "https://www.vulncheck.com/advisories/h3-before-2.0.1-rc.18-open-redirect-via-redirectback"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:15.277",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86205"
                }
            ]
        },
        {
            "id": "CVE-2026-86197",
            "vendor": "getgrav",
            "product": "grav",
            "title": "grav vulnerability",
            "summary": "Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\\Common\\Assets without proper output escaping. Page editors can inject arbitrary script by registering malicious assets or injecting attributes, which are rendered unescaped into document head tags and executed for all visitors including administrators.",
            "updated_at": "2026-09-05T13:18:15.110",
            "published_at": "2026-09-05T13:18:15.110",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.0.20 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\\Common\\Assets without proper output escaping. Page editors can inject arbitrary script by registering malicious assets or injecting attributes, which are rendered unescaped into document head tags and executed for all visitors including administrators.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/getgrav/grav/security/advisories/GHSA-8hgv-xc77-jmcr",
                "https://www.vulncheck.com/advisories/grav-before-2.0.20-cross-site-scripting-via-assets-sandbox"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T13:18:15.110",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86197"
                }
            ]
        },
        {
            "id": "CVE-2026-86196",
            "vendor": "getgrav",
            "product": "grav-plugin-api",
            "title": "grav-plugin-api vulnerability",
            "summary": "Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts.",
            "updated_at": "2026-09-05T13:18:14.980",
            "published_at": "2026-09-05T13:18:14.980",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.0.20 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-290",
            "what_happened": "Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any account with a malicious Host header, intercept the reset token from victim emails, and complete account takeover including super-admin accounts.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/getgrav/grav/security/advisories/GHSA-262p-56vv-7v5r",
                "https://www.vulncheck.com/advisories/grav-api-plugin-before-1.0.20-authentication-bypass-via-host-header"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T13:18:14.980",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86196"
                }
            ]
        },
        {
            "id": "CVE-2026-86195",
            "vendor": "getgrav",
            "product": "grav-plugin-api",
            "title": "grav-plugin-api vulnerability",
            "summary": "grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super. A non-super user manager with api.access and api.users.write permissions can create an invitation with a dot-keyed super flag in the access payload that bypasses the guard and persists to the new account. Attackers can accept the invitation through the public endpoint without real invitee interaction to create a super-admin account and immediately receive a valid JWT for full site control.",
            "updated_at": "2026-09-05T13:18:14.853",
            "published_at": "2026-09-05T13:18:14.853",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.0.20 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super. A non-super user manager with api.access and api.users.write permissions can create an invitation with a dot-keyed super flag in the access payload that bypasses the guard and persists to the new account. Attackers can accept the invitation through the public endpoint without real invitee interaction to create a super-admin account and immediately receive a valid JWT for full site control.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/getgrav/grav/security/advisories/GHSA-m363-3hww-gcwc",
                "https://www.vulncheck.com/advisories/grav-plugin-api-1.0.0-through-1.0.19-privilege-escalation-via-dot-keyed-super-flag"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T13:18:14.853",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86195"
                }
            ]
        },
        {
            "id": "CVE-2026-86194",
            "vendor": "getgrav",
            "product": "grav-plugin-form",
            "title": "grav-plugin-form vulnerability",
            "summary": "Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublished pages. Attackers can POST to any public page with a restricted form's name to trigger save, upload, email, or call actions without authentication.",
            "updated_at": "2026-09-05T13:18:14.727",
            "published_at": "2026-09-05T13:18:14.727",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 9.1.22 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublished pages. Attackers can POST to any public page with a restricted form's name to trigger save, upload, email, or call actions without authentication.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/getgrav/grav/security/advisories/GHSA-33m4-m988-5fvh",
                "https://www.vulncheck.com/advisories/grav-form-plugin-before-9.1.22-cross-page-form-execution"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T13:18:14.727",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86194"
                }
            ]
        },
        {
            "id": "CVE-2026-86193",
            "vendor": "getgrav",
            "product": "grav-plugin-api",
            "title": "grav-plugin-api vulnerability",
            "summary": "grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control.",
            "updated_at": "2026-09-05T13:18:14.593",
            "published_at": "2026-09-05T13:18:14.593",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.0.20 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain full administrative control.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/getgrav/grav/security/advisories/GHSA-vv8m-jqpm-38x4",
                "https://www.vulncheck.com/advisories/grav-api-plugin-authentication-bypass-via-group-inherited-super"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T13:18:14.593",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86193"
                }
            ]
        },
        {
            "id": "CVE-2026-86192",
            "vendor": "siyuan-note",
            "product": "siyuan",
            "title": "siyuan vulnerability",
            "summary": "SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.",
            "updated_at": "2026-09-05T13:18:14.443",
            "published_at": "2026-09-05T13:18:14.443",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.8.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without authorization.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-vc7j-5f5p-3x75",
                "https://www.vulncheck.com/advisories/siyuan-before-3.8.2-information-disclosure-via-attribute-view"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T13:18:14.443",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86192"
                }
            ]
        },
        {
            "id": "CVE-2026-86191",
            "vendor": "siyuan-note",
            "product": "siyuan",
            "title": "siyuan vulnerability",
            "summary": "SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visibility. Attackers can access the endpoint to retrieve complete key schemas including sensitive field names and relation definitions from hidden databases.",
            "updated_at": "2026-09-05T13:18:14.300",
            "published_at": "2026-09-05T13:18:14.300",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.8.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visibility. Attackers can access the endpoint to retrieve complete key schemas including sensitive field names and relation definitions from hidden databases.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-j4qq-w6qx-6839",
                "https://www.vulncheck.com/advisories/siyuan-before-3.8.2-private-attribute-view-key-enumeration"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T13:18:14.300",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86191"
                }
            ]
        },
        {
            "id": "CVE-2026-86190",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.",
            "updated_at": "2026-09-05T13:18:14.150",
            "published_at": "2026-09-05T13:18:14.150",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 29.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including administrator accounts, and obtain sensitive personal data for all video viewers.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-82q2-88mq-p44q",
                "https://www.vulncheck.com/advisories/wwbn-avideo-broken-access-control-via-videoviewsinfo-hash-parameter"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T13:18:14.150",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86190"
                }
            ]
        },
        {
            "id": "CVE-2026-86189",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the application root and subdirectories.",
            "updated_at": "2026-09-05T13:18:14.000",
            "published_at": "2026-09-05T13:18:14.000",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 29.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-73",
            "what_happened": "WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the application root and subdirectories.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-cprx-fggj-7vpq",
                "https://www.vulncheck.com/advisories/wwbn-avideo-unauthenticated-path-traversal-via-notify-ffmpeg-json-php"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T13:18:14.000",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86189"
                }
            ]
        },
        {
            "id": "CVE-2026-86188",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send crafted socket messages with callback names resolving to global functions like avideoConfirmHTML that accept untrusted data and assign it to innerHTML, achieving script execution in the victim's origin without authentication or user interaction.",
            "updated_at": "2026-09-05T13:18:13.843",
            "published_at": "2026-09-05T13:18:13.843",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 29.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send crafted socket messages with callback names resolving to global functions like avideoConfirmHTML that accept untrusted data and assign it to innerHTML, achieving script execution in the victim's origin without authentication or user interaction.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-xpx7-h2x7-59qq",
                "https://www.vulncheck.com/advisories/avideo-yptsocket-plugin-unauthenticated-cross-site-scripting"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T13:18:13.843",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86188"
                }
            ]
        },
        {
            "id": "CVE-2026-86187",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-force attacks due to unsalted MD5-based hashing.",
            "updated_at": "2026-09-05T13:18:13.703",
            "published_at": "2026-09-05T13:18:13.703",
            "cvss": 7.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 29.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-330",
            "what_happened": "WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-force attacks due to unsalted MD5-based hashing.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-h3ff-c2qq-pr2g",
                "https://www.vulncheck.com/advisories/wwbn-avideo-weak-prng-password-generation-via-external-login"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T13:18:13.703",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86187"
                }
            ]
        },
        {
            "id": "CVE-2026-86186",
            "vendor": "WWBN",
            "product": "AVideo",
            "title": "AVideo vulnerability",
            "summary": "AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited password guessing attempts against any account from a single IP address.",
            "updated_at": "2026-09-05T13:18:13.560",
            "published_at": "2026-09-05T13:18:13.560",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 29.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-307",
            "what_happened": "AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited password guessing attempts against any account from a single IP address.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WWBN/AVideo/security/advisories/GHSA-qmmw-hmm4-xxp7",
                "https://www.vulncheck.com/advisories/avideo-api-rate-limit-bypass-via-bot-user-agent-header"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T13:18:13.560",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86186"
                }
            ]
        },
        {
            "id": "CVE-2026-86185",
            "vendor": "Bilibili",
            "product": "Bilibili Desktop",
            "title": "Bilibili Desktop vulnerability",
            "summary": "Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.",
            "updated_at": "2026-09-05T12:16:49.240",
            "published_at": "2026-09-05T12:16:49.240",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.18.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed in the renderer with access to the privileged IPC bridge, and execute system commands or steal login credentials.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://app.bilibili.com/",
                "https://github.com/LeoWSY-hashblue/bilibili-desktop-tls-disabled-rce",
                "https://github.com/LeoWSY-hashblue/bilibili-desktop-tls-disabled-rce/blob/main/advisory.md",
                "https://www.vulncheck.com/advisories/bilibili-desktop-through-1.18.0-remote-code-execution-via-tls-verification-bypass"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:16:49.240",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86185"
                }
            ]
        },
        {
            "id": "CVE-2026-86184",
            "vendor": "laradashboard",
            "product": "laradashboard",
            "title": "laradashboard vulnerability",
            "summary": "Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to receive a fully authenticated session, enabling access to user administration, settings, database contents, and arbitrary code execution through the module installer.",
            "updated_at": "2026-09-05T12:16:49.090",
            "published_at": "2026-09-05T12:16:49.090",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint with a registered email address to receive a fully authenticated session, enabling access to user administration, settings, database contents, and arbitrary code execution through the module installer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/laradashboard/laradashboard",
                "https://github.com/laradashboard/laradashboard/blob/v1.2.2/app/Http/Controllers/Backend/Auth/ScreenshotGeneratorLoginController.php",
                "https://github.com/laradashboard/laradashboard/commit/50986e4ac58c883dd8f064cf32be3e2a87c11b24",
                "https://github.com/laradashboard/laradashboard/releases/tag/v1.3.0",
                "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-wj35-4h53-phfp",
                "https://www.vulncheck.com/advisories/lara-dashboard-before-1.3.0-missing-authentication-in-screenshot-login-route"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:16:49.090",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86184"
                }
            ]
        },
        {
            "id": "CVE-2026-86183",
            "vendor": "diem-project",
            "product": "diem",
            "title": "diem vulnerability",
            "summary": "A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the argument widget_id leads to authorization bypass. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is 116974edfb9a5b8bd69cb13586dc62bcdbb485ad. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-11T21:17:36.457",
            "published_at": "2026-09-06T09:17:16.487",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5.1.0; 5.1.1; 5.1.2; 5.1.3",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation of the argument widget_id leads to authorization bypass. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the patch is 116974edfb9a5b8bd69cb13586dc62bcdbb485ad. A patch should be applied to remediate this issue. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/diem-project/diem/",
                "https://github.com/diem-project/diem/issues/450",
                "https://vuldb.com/cve/CVE-2026-86183",
                "https://vuldb.com/submit/896155",
                "https://vuldb.com/vuln/399315",
                "https://vuldb.com/vuln/399315/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T09:17:16.487",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86183"
                }
            ]
        },
        {
            "id": "CVE-2026-86182",
            "vendor": "diem-project",
            "product": "diem",
            "title": "diem vulnerability",
            "summary": "A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmConsole. This manipulation of the argument dm_command causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-06T09:17:16.310",
            "published_at": "2026-09-06T09:17:16.310",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5.1.0; 5.1.1; 5.1.2; 5.1.3",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-352",
            "what_happened": "A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmConsole. This manipulation of the argument dm_command causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/diem-project/diem/",
                "https://github.com/diem-project/diem/issues/449",
                "https://vuldb.com/cve/CVE-2026-86182",
                "https://vuldb.com/submit/896154",
                "https://vuldb.com/vuln/399314",
                "https://vuldb.com/vuln/399314/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T09:17:16.310",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86182"
                }
            ]
        },
        {
            "id": "CVE-2026-86181",
            "vendor": "code-projects",
            "product": "Task Management System",
            "title": "Task Management System vulnerability",
            "summary": "A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Update. The manipulation of the argument lname results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used.",
            "updated_at": "2026-09-06T09:17:16.123",
            "published_at": "2026-09-06T09:17:16.123",
            "cvss": 2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Update. The manipulation of the argument lname results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://code-projects.org/",
                "https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Stored%20Cross-Site%20Scripting%20(XSS)%20in%20Task%20Management%20System%20%60lname%60%20Parameter.md",
                "https://vuldb.com/cve/CVE-2026-86181",
                "https://vuldb.com/submit/896153",
                "https://vuldb.com/submit/897266",
                "https://vuldb.com/submit/897268",
                "https://vuldb.com/vuln/399313",
                "https://vuldb.com/vuln/399313/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T09:17:16.123",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86181"
                }
            ]
        },
        {
            "id": "CVE-2026-86180",
            "vendor": "code-projects",
            "product": "Task Management System In PHP",
            "title": "Task Management System In PHP vulnerability",
            "summary": "A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
            "updated_at": "2026-09-06T08:16:41.910",
            "published_at": "2026-09-06T08:16:41.910",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://code-projects.org/",
                "https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Task%20Management%20System%20in%20PHP%20%E2%80%93%20SQL%20Injection%20in%20%60email%60%20Parameter.md",
                "https://vuldb.com/cve/CVE-2026-86180",
                "https://vuldb.com/submit/896122",
                "https://vuldb.com/vuln/399312",
                "https://vuldb.com/vuln/399312/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:16:41.910",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86180"
                }
            ]
        },
        {
            "id": "CVE-2026-86179",
            "vendor": "code-projects",
            "product": "Daily Expense Manager",
            "title": "Daily Expense Manager vulnerability",
            "summary": "A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used.",
            "updated_at": "2026-09-06T08:16:41.723",
            "published_at": "2026-09-06T08:16:41.723",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://code-projects.org/",
                "https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Daily%20Expense%20Manager%20in%20PHP%20%E2%80%93%20Sensitive%20Information%20Disclosure%20via%20Exposed%20SQL%20Database%20File.md",
                "https://vuldb.com/cve/CVE-2026-86179",
                "https://vuldb.com/submit/896102",
                "https://vuldb.com/vuln/399311",
                "https://vuldb.com/vuln/399311/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:16:41.723",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86179"
                }
            ]
        },
        {
            "id": "CVE-2026-86178",
            "vendor": "pixelfed",
            "product": "pixelfed",
            "title": "pixelfed vulnerability",
            "summary": "Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URLs and author information without following the account.",
            "updated_at": "2026-09-05T11:16:46.537",
            "published_at": "2026-09-05T11:16:46.537",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.12.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media URLs and author information without following the account.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/geo-chen/oss/blob/main/Pixelfed.md",
                "https://github.com/pixelfed/pixelfed",
                "https://github.com/pixelfed/pixelfed/blob/v0.12.9/app/Http/Controllers/StoryComposeController.php#L487-L501",
                "https://github.com/pixelfed/pixelfed/blob/v0.12.9/app/Http/Controllers/StoryComposeController.php#L566-L580",
                "https://github.com/pixelfed/pixelfed/blob/v0.12.9/routes/web-api.php#L154-L155",
                "https://www.vulncheck.com/advisories/pixelfed-through-0.12.9-unauthorized-story-access-via-api"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T11:16:46.537",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86178"
                }
            ]
        },
        {
            "id": "CVE-2026-86177",
            "vendor": "pterodactyl",
            "product": "panel",
            "title": "panel vulnerability",
            "summary": "Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.",
            "updated_at": "2026-09-05T11:16:46.397",
            "published_at": "2026-09-05T11:16:46.397",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.14.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run game-server console commands, control server power state, or create backups without proper authorization checks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/geo-chen/oss/blob/main/panel.md",
                "https://github.com/pterodactyl/panel",
                "https://github.com/pterodactyl/panel/blob/v1.14.0/app/Http/Requests/Api/Client/Servers/Schedules/StoreTaskRequest.php#L10-L25",
                "https://github.com/pterodactyl/panel/blob/v1.14.0/app/Jobs/Schedule/RunTaskJob.php#L60-L75",
                "https://github.com/pterodactyl/panel/commit/913b354aff43ff04fce95357ed68a675a1dd0fa6",
                "https://github.com/pterodactyl/panel/releases/tag/v1.14.1",
                "https://www.vulncheck.com/advisories/pterodactyl-panel-before-1.14.1-privilege-escalation-via-schedule-tasks"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T11:16:46.397",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86177"
                }
            ]
        },
        {
            "id": "CVE-2026-86176",
            "vendor": "netbox-community",
            "product": "netbox",
            "title": "netbox vulnerability",
            "summary": "NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through unscoped querysets, disclosing which users watch or bookmark which objects.",
            "updated_at": "2026-09-05T11:16:46.263",
            "published_at": "2026-09-05T11:16:46.263",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.7.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through unscoped querysets, disclosing which users watch or bookmark which objects.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/geo-chen/oss/blob/main/netbox.md#finding-1-cross-user-disclosure-of-private-notifications-subscriptions-and-bookmarks-via-rest-api-and-graphql-missing-per-user-scoping",
                "https://github.com/netbox-community/netbox",
                "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/extras/api/views.py#L153-L178",
                "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/netbox/settings.py#L667-L673",
                "https://www.vulncheck.com/advisories/netbox-through-4.7.0-information-disclosure-via-rest-and-graphql-apis"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T11:16:46.263",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86176"
                }
            ]
        },
        {
            "id": "CVE-2026-86175",
            "vendor": "netbox-community",
            "product": "netbox",
            "title": "netbox vulnerability",
            "summary": "NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and storage buckets.",
            "updated_at": "2026-09-05T11:16:46.123",
            "published_at": "2026-09-05T11:16:46.123",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.7.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-522",
            "what_happened": "NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and storage buckets.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/geo-chen/oss/blob/main/netbox.md#finding-2-netbox-data-source-backend-credentials-git-password--s3-secret-key-returned-in-plaintext-via-rest-api-and-graphql-to-users-with-only-view-permission-incomplete-fix-of-12625",
                "https://github.com/netbox-community/netbox",
                "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/core/api/serializers_/data.py#L26-L32",
                "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/core/data_backends.py#L80",
                "https://github.com/netbox-community/netbox/blob/v4.7.0/netbox/core/graphql/types.py#L30-L38",
                "https://github.com/netbox-community/netbox/issues/12625",
                "https://www.vulncheck.com/advisories/netbox-through-4.7.0-credential-disclosure-via-rest-and-graphql-apis"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T11:16:46.123",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86175"
                }
            ]
        },
        {
            "id": "CVE-2026-86174",
            "vendor": "makeplane",
            "product": "plane",
            "title": "plane vulnerability",
            "summary": "Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to the public deploy-board comment endpoint.",
            "updated_at": "2026-09-05T11:16:45.990",
            "published_at": "2026-09-05T11:16:45.990",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.4.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to the public deploy-board comment endpoint.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/makeplane/plane",
                "https://github.com/makeplane/plane/blob/v1.4.2/apps/api/plane/space/views/issue.py#L258-L275",
                "https://github.com/makeplane/plane/issues/9441",
                "https://www.vulncheck.com/advisories/plane-through-1.4.2-arbitrary-comment-write-via-public-deploy-board"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T11:16:45.990",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86174"
                }
            ]
        },
        {
            "id": "CVE-2026-86173",
            "vendor": "mindsdb",
            "product": "mindsdb",
            "title": "mindsdb vulnerability",
            "summary": "MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can bypass the allowlist control by exploiting the default empty configuration and access internal services and cloud metadata endpoints without authentication.",
            "updated_at": "2026-09-05T11:16:45.850",
            "published_at": "2026-09-05T11:16:45.850",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 26.1.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can bypass the allowlist control by exploiting the default empty configuration and access internal services and cloud metadata endpoints without authentication.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/mindsdb/mindshub",
                "https://github.com/mindsdb/mindshub/blob/v26.1.0/mindsdb/integrations/handlers/web_handler/web_handler.py#L50-L65",
                "https://github.com/mindsdb/mindshub/blob/v26.1.0/mindsdb/utilities/config.py#L273",
                "https://github.com/mindsdb/mindshub/issues/12480",
                "https://www.vulncheck.com/advisories/mindsdb-through-26.1.0-unauthenticated-ssrf-via-web-crawler"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T11:16:45.850",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86173"
                }
            ]
        },
        {
            "id": "CVE-2026-86172",
            "vendor": "DefaultFuction",
            "product": "CRM",
            "title": "CRM vulnerability",
            "summary": "A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.",
            "updated_at": "2026-09-11T21:17:35.733",
            "published_at": "2026-09-06T08:16:40.760",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/DefaultFuction/Customer-Relationship-Management-System/issues/5",
                "https://vuldb.com/cve/CVE-2026-86172",
                "https://vuldb.com/submit/895744",
                "https://vuldb.com/vuln/399310",
                "https://vuldb.com/vuln/399310/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:16:40.760",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86172"
                }
            ]
        },
        {
            "id": "CVE-2026-86171",
            "vendor": "DefaultFuction",
            "product": "CRM",
            "title": "CRM vulnerability",
            "summary": "A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.",
            "updated_at": "2026-09-06T07:16:43.633",
            "published_at": "2026-09-06T07:16:43.633",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/DefaultFuction/Customer-Relationship-Management-System/issues/4",
                "https://vuldb.com/cve/CVE-2026-86171",
                "https://vuldb.com/submit/895743",
                "https://vuldb.com/vuln/399309",
                "https://vuldb.com/vuln/399309/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T07:16:43.633",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86171"
                }
            ]
        },
        {
            "id": "CVE-2026-86170",
            "vendor": "DefaultFuction",
            "product": "CRM",
            "title": "CRM vulnerability",
            "summary": "A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.",
            "updated_at": "2026-09-06T06:16:41.403",
            "published_at": "2026-09-06T06:16:41.403",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/DefaultFuction/Customer-Relationship-Management-System/issues/3",
                "https://vuldb.com/cve/CVE-2026-86170",
                "https://vuldb.com/submit/895742",
                "https://vuldb.com/vuln/399308",
                "https://vuldb.com/vuln/399308/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T06:16:41.403",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86170"
                }
            ]
        },
        {
            "id": "CVE-2026-86169",
            "vendor": "axolotl-ai-cloud",
            "product": "axolotl",
            "title": "axolotl vulnerability",
            "summary": "Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by crafting a malicious Hugging Face model repository selected as base_model, which is loaded with hardcoded trust_remote_code=True during AutoModelForCausalLM.from_pretrained.",
            "updated_at": "2026-09-12T00:17:05.260",
            "published_at": "2026-09-05T11:16:45.703",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.19.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-829",
            "what_happened": "Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by crafting a malicious Hugging Face model repository selected as base_model, which is loaded with hardcoded trust_remote_code=True during AutoModelForCausalLM.from_pretrained.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/axolotl-ai-cloud/axolotl",
                "https://github.com/axolotl-ai-cloud/axolotl/blob/v0.18.0/src/axolotl/loaders/patch_manager.py#L794-L806",
                "https://github.com/axolotl-ai-cloud/axolotl/blob/v0.18.0/src/axolotl/monkeypatch/multipack.py#L86-L96",
                "https://github.com/axolotl-ai-cloud/axolotl/commit/b62d60b101eea7f32532ee3c0b17c2f2430a9262",
                "https://github.com/axolotl-ai-cloud/axolotl/pull/3858",
                "https://www.vulncheck.com/advisories/axolotl-through-0.18.0-remote-code-execution-via-multipack-patching",
                "https://github.com/axolotl-ai-cloud/axolotl/releases/tag/v0.19.0"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T11:16:45.703",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86169"
                }
            ]
        },
        {
            "id": "CVE-2026-86168",
            "vendor": "code-projects",
            "product": "Content Management System",
            "title": "Content Management System vulnerability",
            "summary": "A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.",
            "updated_at": "2026-09-06T05:16:50.673",
            "published_at": "2026-09-06T05:16:50.673",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://code-projects.org/",
                "https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/SQL%20Injection%20Vulnerability%20in%20Content%20Management%20System%20%60user_name%60%20Parameter.md",
                "https://vuldb.com/cve/CVE-2026-86168",
                "https://vuldb.com/submit/895608",
                "https://vuldb.com/vuln/399307",
                "https://vuldb.com/vuln/399307/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T05:16:50.673",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86168"
                }
            ]
        },
        {
            "id": "CVE-2026-86167",
            "vendor": "Tenda",
            "product": "HG10",
            "title": "HG10 vulnerability",
            "summary": "A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.",
            "updated_at": "2026-09-06T05:16:50.477",
            "published_at": "2026-09-06T05:16:50.477",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "300001138",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/HG10/command-formgponConf-fmgpon_loid.md",
                "https://vuldb.com/cve/CVE-2026-86167",
                "https://vuldb.com/submit/895596",
                "https://vuldb.com/vuln/399306",
                "https://vuldb.com/vuln/399306/cti",
                "https://www.tenda.com.cn/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T05:16:50.477",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86167"
                }
            ]
        },
        {
            "id": "CVE-2026-86166",
            "vendor": "Tenda",
            "product": "HG10",
            "title": "HG10 vulnerability",
            "summary": "A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.",
            "updated_at": "2026-09-11T21:17:35.040",
            "published_at": "2026-09-06T04:18:32.783",
            "cvss": 7.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "300001138",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/HG10/bof-formWanRedirect-if.md",
                "https://vuldb.com/cve/CVE-2026-86166",
                "https://vuldb.com/submit/895595",
                "https://vuldb.com/vuln/399305",
                "https://vuldb.com/vuln/399305/cti",
                "https://www.tenda.com.cn/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T04:18:32.783",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86166"
                }
            ]
        },
        {
            "id": "CVE-2026-86165",
            "vendor": "Tenda",
            "product": "HG10",
            "title": "HG10 vulnerability",
            "summary": "A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.",
            "updated_at": "2026-09-06T04:18:32.523",
            "published_at": "2026-09-06T04:18:32.523",
            "cvss": 8.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "300001138",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/SunnyYANGyaya/cuicuishark-sheep-fishIOT/blob/main/Tenda/HG10/bof-formURL-keywd.md",
                "https://vuldb.com/cve/CVE-2026-86165",
                "https://vuldb.com/submit/895583",
                "https://vuldb.com/submit/895594",
                "https://vuldb.com/vuln/399304",
                "https://vuldb.com/vuln/399304/cti",
                "https://www.tenda.com.cn/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T04:18:32.523",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86165"
                }
            ]
        },
        {
            "id": "CVE-2026-86164",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.",
            "updated_at": "2026-09-06T04:18:31.037",
            "published_at": "2026-09-06T04:18:31.037",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ltranquility/submit_repository/issues/4",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86164",
                "https://vuldb.com/submit/895549",
                "https://vuldb.com/vuln/399289",
                "https://vuldb.com/vuln/399289/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T04:18:31.037",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86164"
                }
            ]
        },
        {
            "id": "CVE-2026-86163",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.",
            "updated_at": "2026-09-06T04:18:30.320",
            "published_at": "2026-09-06T04:18:30.320",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/CSDVi/cve/issues/3",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-86163",
                "https://vuldb.com/submit/895531",
                "https://vuldb.com/vuln/399288",
                "https://vuldb.com/vuln/399288/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T04:18:30.320",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86163"
                }
            ]
        },
        {
            "id": "CVE-2026-86162",
            "vendor": "SourceCodester",
            "product": "Online Voting System",
            "title": "Online Voting System vulnerability",
            "summary": "A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.",
            "updated_at": "2026-09-06T03:17:17.220",
            "published_at": "2026-09-06T03:17:17.220",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Aurora-Song/cve/issues/1",
                "https://vuldb.com/cve/CVE-2026-86162",
                "https://vuldb.com/submit/895450",
                "https://vuldb.com/vuln/399287",
                "https://vuldb.com/vuln/399287/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T03:17:17.220",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86162"
                }
            ]
        },
        {
            "id": "CVE-2026-86161",
            "vendor": "SourceCodester",
            "product": "Online Voting System",
            "title": "Online Voting System vulnerability",
            "summary": "A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.",
            "updated_at": "2026-09-11T21:17:34.493",
            "published_at": "2026-09-06T03:17:17.067",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/lwcc223/CVE/issues/3",
                "https://vuldb.com/cve/CVE-2026-86161",
                "https://vuldb.com/submit/895416",
                "https://vuldb.com/vuln/399286",
                "https://vuldb.com/vuln/399286/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T03:17:17.067",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86161"
                }
            ]
        },
        {
            "id": "CVE-2026-86160",
            "vendor": "SourceCodester",
            "product": "Online Voting System",
            "title": "Online Voting System vulnerability",
            "summary": "A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
            "updated_at": "2026-09-06T03:17:16.913",
            "published_at": "2026-09-06T03:17:16.913",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/lwcc223/CVE/issues/2",
                "https://vuldb.com/cve/CVE-2026-86160",
                "https://vuldb.com/submit/895415",
                "https://vuldb.com/vuln/399285",
                "https://vuldb.com/vuln/399285/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T03:17:16.913",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86160"
                }
            ]
        },
        {
            "id": "CVE-2026-86159",
            "vendor": "SourceCodester",
            "product": "Online Voting System",
            "title": "Online Voting System vulnerability",
            "summary": "A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.",
            "updated_at": "2026-09-06T03:17:16.730",
            "published_at": "2026-09-06T03:17:16.730",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/lwcc223/CVE/issues/1",
                "https://vuldb.com/cve/CVE-2026-86159",
                "https://vuldb.com/submit/895412",
                "https://vuldb.com/vuln/399284",
                "https://vuldb.com/vuln/399284/cti",
                "https://www.sourcecodester.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T03:17:16.730",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86159"
                }
            ]
        },
        {
            "id": "CVE-2026-86153",
            "vendor": "Tenda",
            "product": "CP3",
            "title": "CP3 vulnerability",
            "summary": "A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.",
            "updated_at": "2026-09-06T02:17:19.770",
            "published_at": "2026-09-06T02:17:19.770",
            "cvss": 9.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "27.5.57.101",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://vuldb.com/cve/CVE-2026-86153",
                "https://vuldb.com/submit/895354",
                "https://vuldb.com/vuln/399276",
                "https://vuldb.com/vuln/399276/cti",
                "https://www.tenda.com.cn/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T02:17:19.770",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86153"
                }
            ]
        },
        {
            "id": "CVE-2026-86152",
            "vendor": "Tenda",
            "product": "CP3",
            "title": "CP3 vulnerability",
            "summary": "A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.",
            "updated_at": "2026-09-06T02:17:19.370",
            "published_at": "2026-09-06T02:17:19.370",
            "cvss": 10,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "27.5.57.101",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://vuldb.com/cve/CVE-2026-86152",
                "https://vuldb.com/submit/895353",
                "https://vuldb.com/vuln/399275",
                "https://vuldb.com/vuln/399275/cti",
                "https://www.tenda.com.cn/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T02:17:19.370",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86152"
                }
            ]
        },
        {
            "id": "CVE-2026-86151",
            "vendor": "Tenda",
            "product": "CP3",
            "title": "CP3 vulnerability",
            "summary": "A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.",
            "updated_at": "2026-09-11T21:17:33.980",
            "published_at": "2026-09-06T00:16:55.773",
            "cvss": 9.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "27.5.57.101",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://vuldb.com/cve/CVE-2026-86151",
                "https://vuldb.com/submit/895352",
                "https://vuldb.com/vuln/399274",
                "https://vuldb.com/vuln/399274/cti",
                "https://www.tenda.com.cn/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T00:16:55.773",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86151"
                }
            ]
        },
        {
            "id": "CVE-2026-86150",
            "vendor": "Tenda",
            "product": "CP3",
            "title": "CP3 vulnerability",
            "summary": "A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.",
            "updated_at": "2026-09-05T23:17:41.337",
            "published_at": "2026-09-05T23:17:41.337",
            "cvss": 2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "27.5.57.101",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-259",
            "what_happened": "A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://vuldb.com/cve/CVE-2026-86150",
                "https://vuldb.com/submit/895351",
                "https://vuldb.com/vuln/399273",
                "https://vuldb.com/vuln/399273/cti",
                "https://www.tenda.com.cn/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T23:17:41.337",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86150"
                }
            ]
        },
        {
            "id": "CVE-2026-86149",
            "vendor": "Tenda",
            "product": "CP3",
            "title": "CP3 vulnerability",
            "summary": "A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.",
            "updated_at": "2026-09-05T22:17:18.943",
            "published_at": "2026-09-05T22:17:18.943",
            "cvss": 9.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "27.5.57.101",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://vuldb.com/cve/CVE-2026-86149",
                "https://vuldb.com/submit/895350",
                "https://vuldb.com/vuln/399272",
                "https://vuldb.com/vuln/399272/cti",
                "https://www.tenda.com.cn/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T22:17:18.943",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86149"
                }
            ]
        },
        {
            "id": "CVE-2026-86148",
            "vendor": "Tenda",
            "product": "CP3",
            "title": "CP3 vulnerability",
            "summary": "A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.",
            "updated_at": "2026-09-05T22:17:18.743",
            "published_at": "2026-09-05T22:17:18.743",
            "cvss": 9.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "27.5.57.101",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://vuldb.com/cve/CVE-2026-86148",
                "https://vuldb.com/submit/895348",
                "https://vuldb.com/vuln/399271",
                "https://vuldb.com/vuln/399271/cti",
                "https://www.tenda.com.cn/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T22:17:18.743",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86148"
                }
            ]
        },
        {
            "id": "CVE-2026-86145",
            "vendor": "PCRE",
            "product": "PCRE2",
            "title": "PCRE2 vulnerability",
            "summary": "PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).",
            "updated_at": "2026-09-05T14:17:23.897",
            "published_at": "2026-09-05T06:17:10.370",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.32 through before 10.48 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-424",
            "what_happened": "PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an attacker-controlled regular expression, or a recursive pattern in conjunction with a small heap limit (this can be set through the API).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/PCRE2Project/pcre2/releases/tag/pcre2-10.48",
                "https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf",
                "http://www.openwall.com/lists/oss-security/2026/09/05/3"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T06:17:10.370",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86145"
                }
            ]
        },
        {
            "id": "CVE-2026-86144",
            "vendor": "xmlsoft",
            "product": "libxml2",
            "title": "libxml2 vulnerability",
            "summary": "In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).",
            "updated_at": "2026-09-15T19:20:15.060",
            "published_at": "2026-09-05T05:17:13.407",
            "cvss": 5.6,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.15.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-669",
            "what_happened": "In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/GNOME/libxml2/commit/b63cd517afecb76582dd9488c55e54ceaf50de61",
                "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T05:17:13.407",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86144"
                }
            ]
        },
        {
            "id": "CVE-2026-86143",
            "vendor": "xmlsoft",
            "product": "libxml2",
            "title": "libxml2 vulnerability",
            "summary": "In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.",
            "updated_at": "2026-09-15T19:31:15.857",
            "published_at": "2026-09-05T05:17:13.270",
            "cvss": 6.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 2.15.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-192",
            "what_happened": "In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "gitlab.gnome.org",
                    "author": "NVD reference",
                    "first_seen": "2026-09-05",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111"
                }
            ],
            "references": [
                "https://github.com/GNOME/libxml2/commit/90f293ba74d28b1d570920382e707586f68ebf35",
                "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4",
                "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T05:17:13.270",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86143"
                }
            ]
        },
        {
            "id": "CVE-2026-86142",
            "vendor": "xmlsoft",
            "product": "libxml2",
            "title": "libxml2 vulnerability",
            "summary": "In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.",
            "updated_at": "2026-09-15T19:35:48.663",
            "published_at": "2026-09-05T05:17:13.133",
            "cvss": 6.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.15.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-122",
            "what_happened": "In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/GNOME/libxml2/commit/6b3a736c0edc74ceec3d82f5252499d7911b3a58",
                "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4",
                "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T05:17:13.133",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86142"
                }
            ]
        },
        {
            "id": "CVE-2026-86141",
            "vendor": "xmlsoft",
            "product": "libxml2",
            "title": "libxml2 vulnerability",
            "summary": "xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.",
            "updated_at": "2026-09-15T19:37:41.440",
            "published_at": "2026-09-05T05:17:13.007",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.15.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-252",
            "what_happened": "xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/GNOME/libxml2/commit/e89a8aae4c9b40cdafcf66b3f9e57c62db37bb55",
                "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4",
                "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1107"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T05:17:13.007",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86141"
                }
            ]
        },
        {
            "id": "CVE-2026-86140",
            "vendor": "xmlsoft",
            "product": "libxml2",
            "title": "libxml2 vulnerability",
            "summary": "In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.",
            "updated_at": "2026-09-15T19:39:17.010",
            "published_at": "2026-09-05T05:17:12.877",
            "cvss": 8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.15.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/GNOME/libxml2/commit/d1686f91dbda141a752200419d35639fd6b38340",
                "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T05:17:12.877",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86140"
                }
            ]
        },
        {
            "id": "CVE-2026-86139",
            "vendor": "xmlsoft",
            "product": "libxml2",
            "title": "libxml2 vulnerability",
            "summary": "In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.",
            "updated_at": "2026-09-15T19:39:45.267",
            "published_at": "2026-09-05T05:17:12.730",
            "cvss": 6.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.15.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-190",
            "what_happened": "In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/GNOME/libxml2/commit/8edbbdb09f24d26a2f900141fddc2b9d014f53b0",
                "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T05:17:12.730",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86139"
                }
            ]
        },
        {
            "id": "CVE-2026-86138",
            "vendor": "xmlsoft",
            "product": "libxml2",
            "title": "libxml2 vulnerability",
            "summary": "In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.",
            "updated_at": "2026-09-15T19:40:47.560",
            "published_at": "2026-09-05T05:17:12.600",
            "cvss": 6.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.15.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-190",
            "what_happened": "In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/GNOME/libxml2/commit/a4cba4b5b5a8c42e155ed42d2d2a44955465a2e4",
                "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T05:17:12.600",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86138"
                }
            ]
        },
        {
            "id": "CVE-2026-86137",
            "vendor": "xmlsoft",
            "product": "libxml2",
            "title": "libxml2 vulnerability",
            "summary": "In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.",
            "updated_at": "2026-09-15T19:46:11.827",
            "published_at": "2026-09-05T05:17:11.490",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 2.15.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-125",
            "what_happened": "In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "gitlab.gnome.org",
                    "author": "NVD reference",
                    "first_seen": "2026-09-05",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1099"
                }
            ],
            "references": [
                "https://github.com/GNOME/libxml2/commit/76fe08d97de88bfaef2f7d5cd27f11954cc5bee2",
                "https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4",
                "https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1099"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T05:17:11.490",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86137"
                }
            ]
        },
        {
            "id": "CVE-2026-86124",
            "vendor": "HKUDS",
            "product": "AutoAgent",
            "title": "AutoAgent vulnerability",
            "summary": "AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories.",
            "updated_at": "2026-09-05T10:16:43.900",
            "published_at": "2026-09-05T10:16:43.900",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 16c12b052ef2330a198063c62a07a7f9723031e3 (git)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the container, gaining access to bind-mounted host workspace directories.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/HKUDS/AutoAgent",
                "https://github.com/HKUDS/AutoAgent/blob/16c12b052ef2330a198063c62a07a7f9723031e3/autoagent/environment/docker_env.py",
                "https://github.com/HKUDS/AutoAgent/blob/16c12b052ef2330a198063c62a07a7f9723031e3/autoagent/environment/tcp_server.py",
                "https://github.com/HKUDS/AutoAgent/issues/96",
                "https://www.vulncheck.com/advisories/autoagent-unauthenticated-remote-code-execution-via-the-sandbox-tcp-command-server"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T10:16:43.900",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86124"
                }
            ]
        },
        {
            "id": "CVE-2026-86123",
            "vendor": "sqlchat",
            "product": "sqlchat",
            "title": "sqlchat vulnerability",
            "summary": "SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into the server's network without authentication.",
            "updated_at": "2026-09-05T10:16:43.750",
            "published_at": "2026-09-05T10:16:43.750",
            "cvss": 9.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 665af875413affadfeefff81794f1d7758782bc2 (git)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-918",
            "what_happened": "SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to internal databases, execute SQL commands, enumerate schemas, and pivot into the server's network without authentication.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/sqlchat/sqlchat",
                "https://github.com/sqlchat/sqlchat/blob/665af875413affadfeefff81794f1d7758782bc2/src/pages/api/connection/execute.ts",
                "https://github.com/sqlchat/sqlchat/blob/665af875413affadfeefff81794f1d7758782bc2/src/pages/api/connection/test.ts",
                "https://github.com/sqlchat/sqlchat/issues/189",
                "https://www.vulncheck.com/advisories/sql-chat-unauthenticated-database-connection-proxy-in-the-api-connection-endpoints"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T10:16:43.750",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86123"
                }
            ]
        },
        {
            "id": "CVE-2026-86122",
            "vendor": "rowboatlabs",
            "product": "rowboat",
            "title": "rowboat vulnerability",
            "summary": "Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at internal services and cloud metadata endpoints to perform server-side request forgery and enumerate internal network topology.",
            "updated_at": "2026-09-05T10:16:43.610",
            "published_at": "2026-09-05T10:16:43.610",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.9.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs at internal services and cloud metadata endpoints to perform server-side request forgery and enumerate internal network topology.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/rowboatlabs/rowboat",
                "https://github.com/rowboatlabs/rowboat/blob/v0.9.1/apps/rowboat/src/application/lib/agents-runtime/agent-tools.ts",
                "https://github.com/rowboatlabs/rowboat/blob/v0.9.1/apps/rowboat/src/application/use-cases/projects/add-custom-mcp-server.use-case.ts",
                "https://github.com/rowboatlabs/rowboat/issues/621",
                "https://www.vulncheck.com/advisories/rowboat-through-0.9.1-server-side-request-forgery-via-custom-mcp-server"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T10:16:43.610",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86122"
                }
            ]
        },
        {
            "id": "CVE-2026-86121",
            "vendor": "trycua",
            "product": "cua-computer-server",
            "title": "cua-computer-server vulnerability",
            "summary": "Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands via the run_command endpoint, read and write arbitrary files through file operation endpoints, and access interactive PTY shells without authentication.",
            "updated_at": "2026-09-05T10:16:43.463",
            "published_at": "2026-09-05T10:16:43.463",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.3.42 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands via the run_command endpoint, read and write arbitrary files through file operation endpoints, and access interactive PTY shells without authentication.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/trycua/cua",
                "https://github.com/trycua/cua/blob/10a2e71792db/libs/python/computer-server/computer_server/cli.py",
                "https://github.com/trycua/cua/blob/10a2e71792db/libs/python/computer-server/computer_server/main.py",
                "https://github.com/trycua/cua/commit/59cf25c0ec54",
                "https://github.com/trycua/cua/issues/1892",
                "https://www.vulncheck.com/advisories/cua-computer-server-before-0.3.42-unauthenticated-rce-via-desktop-control"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T10:16:43.463",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86121"
                }
            ]
        },
        {
            "id": "CVE-2026-86120",
            "vendor": "apitable",
            "product": "apitable",
            "title": "apitable vulnerability",
            "summary": "APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid Fusion API tokens can write attachments to private datasheets they have been explicitly denied access to by exploiting the unhandled exception in the permission guard.",
            "updated_at": "2026-09-05T10:16:43.307",
            "published_at": "2026-09-05T10:16:43.307",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.13.0-beta.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-636",
            "what_happened": "APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission lookups throw exceptions. Attackers with valid Fusion API tokens can write attachments to private datasheets they have been explicitly denied access to by exploiting the unhandled exception in the permission guard.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apitable/apitable",
                "https://github.com/apitable/apitable/blob/88b24ce9f359/packages/room-server/src/fusion/middleware/guard/node.permission.guard.ts",
                "https://github.com/apitable/apitable/issues/1814",
                "https://www.vulncheck.com/advisories/apitable-through-1.13.0-beta.1-fail-open-authorization-in-the-fusion-api-node-permission-guard"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T10:16:43.307",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86120"
                }
            ]
        },
        {
            "id": "CVE-2026-86119",
            "vendor": "webstudio-is",
            "product": "webstudio",
            "title": "webstudio vulnerability",
            "summary": "Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services, and perform network reconnaissance on the instance infrastructure.",
            "updated_at": "2026-09-05T10:16:43.157",
            "published_at": "2026-09-05T10:16:43.157",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.296.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers can supply arbitrary URLs to these endpoints to read cloud instance metadata, access internal services, and perform network reconnaissance on the instance infrastructure.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/webstudio-is/webstudio",
                "https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.asset.$.ts",
                "https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.image.$.ts",
                "https://github.com/webstudio-is/webstudio/blob/55920c57c4d3e128a0fa48fceabbbc3a1d73f1ef/apps/builder/app/routes/cgi.video.$.ts",
                "https://github.com/webstudio-is/webstudio/issues/5816",
                "https://www.vulncheck.com/advisories/webstudio-through-0.296.0-ssrf-via-cgi-proxy-routes"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T10:16:43.157",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86119"
                }
            ]
        },
        {
            "id": "CVE-2026-86118",
            "vendor": "sentriz",
            "product": "gonic",
            "title": "gonic vulnerability",
            "summary": "gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly call the startScan endpoint to force CPU and I/O-intensive filesystem operations, causing denial of service on multi-user instances.",
            "updated_at": "2026-09-05T10:16:43.007",
            "published_at": "2026-09-05T10:16:43.007",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.22.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attackers can repeatedly call the startScan endpoint to force CPU and I/O-intensive filesystem operations, causing denial of service on multi-user instances.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/sentriz/gonic",
                "https://github.com/sentriz/gonic/blob/v0.21.0/server/ctrlsubsonic/ctrl.go",
                "https://github.com/sentriz/gonic/blob/v0.21.0/server/ctrlsubsonic/handlers_common.go",
                "https://github.com/sentriz/gonic/releases/tag/v0.22.0",
                "https://github.com/sentriz/gonic/security/advisories/GHSA-453r-pgfw-h3pq",
                "https://www.vulncheck.com/advisories/gonic-before-0.22.0-missing-administrator-check-on-the-subsonic-startscan-endpoint"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T10:16:43.007",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86118"
                }
            ]
        },
        {
            "id": "CVE-2026-86117",
            "vendor": "coollabsio",
            "product": "coolify",
            "title": "coolify vulnerability",
            "summary": "Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers can register a victim's email address on any enabled OAuth provider to obtain authenticated sessions as that user, bypassing password requirements and two-factor authentication.",
            "updated_at": "2026-09-05T10:16:42.860",
            "published_at": "2026-09-05T10:16:42.860",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.3.17 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-287",
            "what_happened": "Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers can register a victim's email address on any enabled OAuth provider to obtain authenticated sessions as that user, bypassing password requirements and two-factor authentication.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/coollabsio/coolify",
                "https://github.com/coollabsio/coolify/blob/v4.3.17/app/Http/Controllers/OauthController.php",
                "https://github.com/coollabsio/coolify/blob/v4.3.17/routes/web.php",
                "https://github.com/geo-chen/oss/blob/main/coolify.md",
                "https://www.vulncheck.com/advisories/coolify-through-4.3.17-oauth-account-takeover-via-unverified-email-matching"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T10:16:42.860",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86117"
                }
            ]
        },
        {
            "id": "CVE-2026-86116",
            "vendor": "metabase",
            "product": "metabase",
            "title": "metabase vulnerability",
            "summary": "Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries. Attackers can submit requests to POST, PUT, and DELETE glossary endpoints to tamper with instance-wide business glossary data without proper authorization.",
            "updated_at": "2026-09-05T10:16:42.713",
            "published_at": "2026-09-05T10:16:42.713",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.57.0 through before 0.63.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries. Attackers can submit requests to POST, PUT, and DELETE glossary endpoints to tamper with instance-wide business glossary data without proper authorization.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/geo-chen/oss/blob/main/metabase.md",
                "https://github.com/metabase/metabase",
                "https://github.com/metabase/metabase/blob/v0.62.1/src/metabase/glossary/api.clj",
                "https://github.com/metabase/metabase/commit/0a0589299cfd",
                "https://github.com/metabase/metabase/releases/tag/v0.63.1",
                "https://www.vulncheck.com/advisories/metabase-before-0.63.1-missing-function-level-authorization-on-the-glossary-management-api"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T10:16:42.713",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86116"
                }
            ]
        },
        {
            "id": "CVE-2026-86115",
            "vendor": "simstudioai",
            "product": "sim",
            "title": "sim vulnerability",
            "summary": "Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated workflow authors can bypass external URL validation by supplying paths starting with /api/ in HTTP blocks to reach internal-only endpoints like POST /api/function/execute.",
            "updated_at": "2026-09-05T10:16:42.567",
            "published_at": "2026-09-05T10:16:42.567",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.8.14 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-441",
            "what_happened": "Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authentication tokens. Authenticated workflow authors can bypass external URL validation by supplying paths starting with /api/ in HTTP blocks to reach internal-only endpoints like POST /api/function/execute.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/geo-chen/oss/blob/main/sim.md",
                "https://github.com/simstudioai/sim",
                "https://github.com/simstudioai/sim/blob/v0.8.13/apps/sim/lib/auth/hybrid.ts",
                "https://github.com/simstudioai/sim/blob/v0.8.13/apps/sim/tools/index.ts",
                "https://github.com/simstudioai/sim/pull/7179",
                "https://www.vulncheck.com/advisories/sim-before-0.8.14-confused-deputy-in-tool-url-routing-mints-an-internal-token-for-a-user-supplied-api-path"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T10:16:42.567",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86115"
                }
            ]
        },
        {
            "id": "CVE-2026-86114",
            "vendor": "getarcaneapp",
            "product": "arcane",
            "title": "arcane vulnerability",
            "summary": "Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.",
            "updated_at": "2026-09-05T10:16:42.423",
            "published_at": "2026-09-05T10:16:42.423",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.19.1 through before 2.0.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/geo-chen/oss/blob/main/arcane.md",
                "https://github.com/getarcaneapp/arcane",
                "https://github.com/getarcaneapp/arcane/blob/v1.19.5/backend/api/handlers/templates.go",
                "https://github.com/getarcaneapp/arcane/commit/1500646aa91f",
                "https://github.com/getarcaneapp/arcane/releases/tag/v2.0.0",
                "https://www.vulncheck.com/advisories/arcane-before-2.0.0-missing-administrator-authorization-on-the-compose-template-mutation-endpoints"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T10:16:42.423",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86114"
                }
            ]
        },
        {
            "id": "CVE-2026-86113",
            "vendor": "bookwyrm-social",
            "product": "bookwyrm",
            "title": "bookwyrm vulnerability",
            "summary": "BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit sequential ReadThrough IDs to overwrite arbitrary users' start dates, finish dates, progress, and progress mode, affecting reading statistics and exported data.",
            "updated_at": "2026-09-05T10:16:42.273",
            "published_at": "2026-09-05T10:16:42.273",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.9.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading records. Attackers can exploit sequential ReadThrough IDs to overwrite arbitrary users' start dates, finish dates, progress, and progress mode, affecting reading statistics and exported data.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/bookwyrm-social/bookwyrm",
                "https://github.com/bookwyrm-social/bookwyrm/blob/v0.9.1/bookwyrm/views/status.py",
                "https://github.com/geo-chen/oss/blob/main/bookwyrm.md#finding-3-authenticated-idor-in-edit-readthrough-allows-tampering-with-other-users-reading-progress",
                "https://www.vulncheck.com/advisories/bookwyrm-through-0.9.1-insecure-direct-object-reference-in-edit-readthrough-allows-tampering-with-other-users-reading-records"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T10:16:42.273",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86113"
                }
            ]
        },
        {
            "id": "CVE-2026-86112",
            "vendor": "bookwyrm-social",
            "product": "bookwyrm",
            "title": "bookwyrm vulnerability",
            "summary": "BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct statuses they cannot access. Attackers can POST to the favorite endpoint with a status ID to create unauthorized interactions, trigger ActivityPub broadcasts, and enumerate private status IDs through response differentiation.",
            "updated_at": "2026-09-05T10:16:42.130",
            "published_at": "2026-09-05T10:16:42.130",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.9.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite followers-only and direct statuses they cannot access. Attackers can POST to the favorite endpoint with a status ID to create unauthorized interactions, trigger ActivityPub broadcasts, and enumerate private status IDs through response differentiation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/bookwyrm-social/bookwyrm",
                "https://github.com/bookwyrm-social/bookwyrm/blob/v0.9.1/bookwyrm/views/interaction.py",
                "https://github.com/geo-chen/oss/blob/main/bookwyrm.md#finding-2-authenticated-idor-in-favoriteunfavorite-allows-interaction-with-private-statuses",
                "https://www.vulncheck.com/advisories/bookwyrm-through-0.9.1-missing-authorization-on-the-favorite-and-unfavorite-endpoints"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T10:16:42.130",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86112"
                }
            ]
        },
        {
            "id": "CVE-2026-86111",
            "vendor": "bookwyrm-social",
            "product": "bookwyrm",
            "title": "bookwyrm vulnerability",
            "summary": "BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types.",
            "updated_at": "2026-09-05T10:16:40.963",
            "published_at": "2026-09-05T10:16:40.963",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.9.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message reviews by enumerating sequential status IDs. Attackers can access the raw content of restricted statuses through the edit view, bypassing the privacy protections documented for these message types.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/bookwyrm-social/bookwyrm",
                "https://github.com/bookwyrm-social/bookwyrm/blob/v0.9.1/bookwyrm/templates/snippets/create_status/content_field.html",
                "https://github.com/bookwyrm-social/bookwyrm/blob/v0.9.1/bookwyrm/views/status.py",
                "https://github.com/geo-chen/oss/blob/main/bookwyrm.md#finding-1-authenticated-idor-in-editstatus-exposes-private-review-comment-and-quotation-content",
                "https://www.vulncheck.com/advisories/bookwyrm-through-0.9.1-insecure-direct-object-reference-in-editstatus-exposes-followers-only-and-direct-statuses"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T10:16:40.963",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86111"
                }
            ]
        },
        {
            "id": "CVE-2026-86093",
            "vendor": "IBM",
            "product": "Db2",
            "title": "Db2 vulnerability",
            "summary": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.",
            "updated_at": "2026-09-12T04:16:45.040",
            "published_at": "2026-09-10T22:17:04.620",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.5.0 through 11.5.9 (semver); 12.1.0 through 12.1.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-121",
            "what_happened": "IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a fixed-size stack buffer without bounds checking.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286993"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:17:04.620",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86093"
                }
            ]
        },
        {
            "id": "CVE-2026-86060",
            "vendor": "Mikrotik",
            "product": "RouterOS",
            "title": "RouterOS vulnerability",
            "summary": "RouterOS contains an argument-handling flaw in the SSH login\npath involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)",
            "updated_at": "2026-09-11T04:18:02.840",
            "published_at": "2026-09-05T20:17:18.703",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.24 through before 7.24.2 (custom); 7.0.0 through before 7.23.4 (custom); 6.0.0 through before 6.49.21 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 46,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-88",
            "what_happened": "RouterOS contains an argument-handling flaw in the SSH login\npath involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "bahirul/cve-2026-86060",
                    "author": "bahirul",
                    "first_seen": "2026-09-10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Mikrotik CVE-2026-86060 Score 9.2 Critical",
                    "summary": "Mikrotik CVE-2026-86060 Score 9.2 Critical",
                    "url": "https://github.com/bahirul/cve-2026-86060"
                }
            ],
            "references": [
                "https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve",
                "https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/",
                "https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802",
                "https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801",
                "https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800",
                "https://mikrotik.com/supportsec/september-2026-vulnerability/",
                "https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86060",
                "https://github.com/bahirul/cve-2026-86060"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T20:17:18.703",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-86060"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-85921",
            "vendor": "Microsoft",
            "product": "Windows 11 version 26H1",
            "title": "Windows 11 version 26H1 vulnerability",
            "summary": "Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-15T04:18:18.043",
            "published_at": "2026-09-14T18:20:20.047",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.28000.0 through before 10.0.28000.2956 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-415",
            "what_happened": "Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T18:20:20.047",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85921"
                }
            ]
        },
        {
            "id": "CVE-2026-85892",
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)",
            "title": "Microsoft Edge (Chromium-based) vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-15T04:18:17.510",
            "published_at": "2026-09-14T18:20:19.343",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0.0 through before 152.0.4191.66 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85892"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T18:20:19.343",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85892"
                }
            ]
        },
        {
            "id": "CVE-2026-85880",
            "vendor": "Microsoft",
            "product": "Windows",
            "title": "Microsoft Windows Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.",
            "updated_at": "2026-09-07T22:00:00Z",
            "published_at": "2026-09-07T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 30,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-85769",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized skip-block length that is not validated against the remaining size of the input buffer. This can drive an internal size counter negative, which bypasses a subsequent bounds check due to an unsafe signed-to-unsigned conversion, causing the parser to read memory outside the bounds of the heap buffer holding the state data. Successful exploitation can crash the process hosting libtpms (such as swtpm), resulting in a denial of service of the emulated TPM device and the virtual machine that depends on it. No data corruption or information disclosure was confirmed.",
            "updated_at": "2026-09-07T14:16:55.293",
            "published_at": "2026-09-04T18:18:07.153",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for example during a virtual machine's power-on or state/migration restore), a malformed state blob can supply an oversized skip-block length that is not validated against the remaining size of the input buffer. This can drive an internal size counter negative, which bypasses a subsequent bounds check due to an unsafe signed-to-unsigned conversion, causing the parser to read memory outside the bounds of the heap buffer holding the state data. Successful exploitation can crash the process hosting libtpms (such as swtpm), resulting in a denial of service of the emulated TPM device and the virtual machine that depends on it. No data corruption or information disclosure was confirmed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "isukasanuj/CVE-2026-85769",
                    "author": "isukasanuj",
                    "first_seen": "2026-09-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Heap out-of-bounds read in libtpms TPM 2.0 state deserialization — CVE-2026-85769",
                    "summary": "Heap out-of-bounds read in libtpms TPM 2.0 state deserialization — CVE-2026-85769",
                    "url": "https://github.com/isukasanuj/CVE-2026-85769"
                }
            ],
            "references": [
                "https://access.redhat.com/security/cve/CVE-2026-85769",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2528538",
                "https://github.com/stefanberger/libtpms/commit/b1462888180d896af03cae0487e8d45009cc445e",
                "https://github.com/stefanberger/libtpms/issues/614",
                "https://github.com/stefanberger/libtpms/pull/613",
                "https://github.com/isukasanuj/CVE-2026-85769"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T18:18:07.153",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85769"
                }
            ]
        },
        {
            "id": "CVE-2026-85706",
            "vendor": "GitLab",
            "product": "GitLab",
            "title": "GitLab vulnerability",
            "summary": "GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.",
            "updated_at": "2026-09-12T11:16:33.373",
            "published_at": "2026-09-12T03:16:30.473",
            "cvss": 10,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "18.7 through before 19.1.8 (semver); 19.2 through before 19.2.6 (semver); 19.3 through before 19.3.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 187,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-85706",
                    "summary": "Unauthenticated file read in GitLab CE/EE via Workhorse path-encoding bypass enabling shell access.",
                    "what_happened": "Unauthenticated file read in GitLab CE/EE via Workhorse path-encoding bypass enabling shell access.",
                    "cvss": 0,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CB41C932-3F63-547C-8278-6162A20CA9E3",
                        "https://github.com/ynsmroztas/GitLabSniper"
                    ],
                    "repository": "Sploitus",
                    "author": "ynsmroztas",
                    "first_seen": "2026-09-11T21:29:53",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=CB41C932-3F63-547C-8278-6162A20CA9E3"
                },
                {
                    "repository": "ynsmroztas/GitLabSniper",
                    "author": "ynsmroztas",
                    "first_seen": "2026-09-11",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2026-85706 Unauthenticated File Read",
                    "summary": "CVE-2026-85706 Unauthenticated File Read",
                    "url": "https://github.com/ynsmroztas/GitLabSniper"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T10:43:12+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Exploit for CVE-2026-85706",
                    "summary": "Proof-of-concept exploit for CVE-2026-85706. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=6B9784C4-97DB-5FF9-8E86-82280EFA300E"
                },
                {
                    "title": "Exploit for CVE-2026-85706",
                    "summary": "Unauthenticated arbitrary file read in GitLab CE/EE 18.7-19.3.1 via Workhorse/Puma encoding mismatch.",
                    "what_happened": "Unauthenticated arbitrary file read in GitLab CE/EE 18.7-19.3.1 via Workhorse/Puma encoding mismatch.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=F55B205B-F671-55B3-B8C3-5FDE3B715170",
                        "https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab"
                    ],
                    "repository": "Sploitus",
                    "author": "0xlyvio",
                    "first_seen": "2026-09-12T20:42:11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=F55B205B-F671-55B3-B8C3-5FDE3B715170"
                },
                {
                    "title": "Exploit for CVE-2026-85706",
                    "summary": "Unauthenticated arbitrary file read in GitLab CE/EE 18.7-19.3.1 via Workhorse/Puma encoding mismatch.",
                    "what_happened": "Unauthenticated arbitrary file read in GitLab CE/EE 18.7-19.3.1 via Workhorse/Puma encoding mismatch.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=F55B205B-F671-55B3-B8C3-5FDE3B715170",
                        "https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab"
                    ],
                    "repository": "0xlyvio/cve-2026-85706-poc-exploit-gitlab",
                    "author": "0xlyvio",
                    "first_seen": "2026-09-12T20:42:11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab"
                },
                {
                    "repository": "jithinkrishnanrs/gitlab-cve-2026-85706-ioc",
                    "author": "jithinkrishnanrs",
                    "first_seen": "2026-09-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": "CVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit. Detect and hunt for exploitation of the critical unauthenticated GitLab CE/EE path traversal vulnerability with IOC scanning, Sigma, Suricata/Snort, and SIEM detection rules.",
                    "summary": "CVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit. Detect and hunt for exploitation of the critical unauthenticated GitLab CE/EE path traversal vulnerability with IOC scanning, Sigma, Suricata/Snort, and SIEM detection rules.",
                    "url": "https://github.com/jithinkrishnanrs/gitlab-cve-2026-85706-ioc"
                },
                {
                    "repository": "solivaquaant/CVE-2026-85706",
                    "author": "solivaquaant",
                    "first_seen": "2026-09-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "PoC for CVE-2026-85706: GitLab CE/EE unauthenticated arbitrary local file read",
                    "summary": "PoC for CVE-2026-85706: GitLab CE/EE unauthenticated arbitrary local file read",
                    "url": "https://github.com/solivaquaant/CVE-2026-85706"
                },
                {
                    "repository": "mhtsec/CVE-2026-85706",
                    "author": "mhtsec",
                    "first_seen": "2026-09-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 3,
                    "title": "GitLab CE/EE unauthenticated path traversal (CVE-2026-85706) - PoC",
                    "summary": "GitLab CE/EE unauthenticated path traversal (CVE-2026-85706) - PoC",
                    "url": "https://github.com/mhtsec/CVE-2026-85706"
                },
                {
                    "repository": "guneykabel/cve-2026-85706",
                    "author": "guneykabel",
                    "first_seen": "2026-09-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 23,
                    "title": "Exploit poc for CVE-2026-85706 an unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7–19.1.7; 19.2.0–19.2.5; 19.3.0–19.3.1",
                    "summary": "Exploit poc for CVE-2026-85706 an unauthenticated arbitrary file read on Gitlab CE-EE affecting versions: 18.7–19.1.7; 19.2.0–19.2.5; 19.3.0–19.3.1",
                    "url": "https://github.com/guneykabel/cve-2026-85706"
                },
                {
                    "repository": "FlowerWitch/CVE-2026-85706_docker_exp",
                    "author": "FlowerWitch",
                    "first_seen": "2026-09-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": "CVE-2026-85706_docker_exp",
                    "summary": "CVE-2026-85706_docker_exp",
                    "url": "https://github.com/FlowerWitch/CVE-2026-85706_docker_exp"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=CB41C932-3F63-547C-8278-6162A20CA9E3",
                "https://github.com/ynsmroztas/GitLabSniper",
                "https://gitlab.com/gitlab-org/gitlab/-/work_items/627748",
                "https://hackerone.com/reports/3909881",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706",
                "https://sploitus.com/exploit?id=6B9784C4-97DB-5FF9-8E86-82280EFA300E",
                "https://sploitus.com/exploit?id=F55B205B-F671-55B3-B8C3-5FDE3B715170",
                "https://github.com/0xlyvio/cve-2026-85706-poc-exploit-gitlab",
                "https://github.com/jithinkrishnanrs/gitlab-cve-2026-85706-ioc",
                "https://github.com/solivaquaant/CVE-2026-85706",
                "https://github.com/mhtsec/CVE-2026-85706",
                "https://github.com/guneykabel/cve-2026-85706",
                "https://github.com/FlowerWitch/CVE-2026-85706_docker_exp"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T03:16:30.473",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85706"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-85703",
            "vendor": "ramon-victor",
            "product": "freegpt-webui",
            "title": "freegpt-webui vulnerability",
            "summary": "A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component Jailbreak Mode. Executing a manipulation can lead to allocation of resources. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. This vulnerability only affects products that are no longer supported by the maintainer.",
            "updated_at": "2026-09-11T21:17:32.940",
            "published_at": "2026-09-04T21:17:26.667",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "098db3dfeb41555c2ca9269df0f13e10ec1c35dc",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component Jailbreak Mode. Executing a manipulation can lead to allocation of resources. The attack can be executed remotely. The exploit has been published and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. This vulnerability only affects products that are no longer supported by the maintainer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gist.github.com/Galaxync/04d5b16498911c405580c735148a53be",
                "https://vuldb.com/cve/CVE-2026-85703",
                "https://vuldb.com/submit/895268",
                "https://vuldb.com/vuln/398807",
                "https://vuldb.com/vuln/398807/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T21:17:26.667",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85703"
                }
            ]
        },
        {
            "id": "CVE-2026-85698",
            "vendor": "tursodatabase",
            "product": "turso",
            "title": "turso vulnerability",
            "summary": "Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds validation. Attackers can craft a malicious database file with a modified cell count value to trigger an index-out-of-bounds panic when querying, causing denial of service in any application that opens untrusted database files.",
            "updated_at": "2026-09-14T20:16:59.950",
            "published_at": "2026-09-04T15:17:48.817",
            "cvss": 6.8,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.8.0-pre.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds validation. Attackers can craft a malicious database file with a modified cell count value to trigger an index-out-of-bounds panic when querying, causing denial of service in any application that opens untrusted database files.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/tursodatabase/turso",
                "https://github.com/tursodatabase/turso/blob/v0.8.0-pre.8/core/storage/pager.rs",
                "https://github.com/tursodatabase/turso/issues/7473",
                "https://www.vulncheck.com/advisories/turso-through-0.8.0-pre.8-out-of-bounds-read-denial-of-service"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T15:17:48.817",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85698"
                }
            ]
        },
        {
            "id": "CVE-2026-85693",
            "vendor": "mckaywrigley",
            "product": "chatbot-ui",
            "title": "chatbot-ui vulnerability",
            "summary": "Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by supplying arbitrary file UUIDs. The endpoint uses a service-role Supabase client that bypasses row-level security and fails to validate file ownership, enabling attackers to retrieve indexed content chunks from victim files through crafted POST requests.",
            "updated_at": "2026-09-14T20:16:59.810",
            "published_at": "2026-09-04T15:17:47.397",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 81328b61d2a4ab597a7a057be70e785cf756d9f8 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by supplying arbitrary file UUIDs. The endpoint uses a service-role Supabase client that bypasses row-level security and fails to validate file ownership, enabling attackers to retrieve indexed content chunks from victim files through crafted POST requests.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/mckaywrigley/chatbot-ui",
                "https://github.com/mckaywrigley/chatbot-ui/blob/81328b61d2a4ab597a7a057be70e785cf756d9f8/app/api/retrieval/retrieve/route.ts",
                "https://github.com/mckaywrigley/chatbot-ui/issues/2028",
                "https://www.vulncheck.com/advisories/chatbot-ui-cross-user-private-file-content-disclosure-via-retrieval-api"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T15:17:47.397",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85693"
                }
            ]
        },
        {
            "id": "CVE-2026-85688",
            "vendor": "TEN-framework",
            "product": "ten-framework",
            "title": "ten-framework vulnerability",
            "summary": "TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files.",
            "updated_at": "2026-09-14T20:16:59.663",
            "published_at": "2026-09-04T15:17:46.657",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.11.71 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths, enabling code execution through authorized_keys, cron files, or executable graph files.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/TEN-framework/ten-framework",
                "https://github.com/TEN-framework/ten-framework/blob/0.11.71/core/src/ten_manager/src/designer/file_content/mod.rs",
                "https://github.com/TEN-framework/ten-framework/issues/2187",
                "https://www.vulncheck.com/advisories/ten-framework-0.11.71-unauthenticated-file-read-write-via-tman-designer"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T15:17:46.657",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85688"
                }
            ]
        },
        {
            "id": "CVE-2026-85681",
            "vendor": "Unknown",
            "product": "WP Component",
            "title": "WP Component vulnerability",
            "summary": "The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unauthenticated attackers to overwrite any of the site's options. On a single site installation this leads to a full takeover, as registration can be enabled with a default role of administrator.",
            "updated_at": "2026-09-12T16:16:42.170",
            "published_at": "2026-09-12T06:16:27.250",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.2.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated users, and it takes both the option name and the option value from the request, allowing unauthenticated attackers to overwrite any of the site's options. On a single site installation this leads to a full takeover, as registration can be enabled with a default role of administrator.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/c602bd9e-a825-4990-a66b-1403bbeb2cee/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:27.250",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85681"
                }
            ]
        },
        {
            "id": "CVE-2026-85676",
            "vendor": "dubinc",
            "product": "dub",
            "title": "dub vulnerability",
            "summary": "Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attackers can append the redir_url parameter to any short link to redirect visitors to arbitrary external URLs through the trusted Dub domain, bypassing destination blacklists and potentially enabling phishing attacks with link cloaking enabled.",
            "updated_at": "2026-09-14T20:16:59.527",
            "published_at": "2026-09-04T15:17:45.923",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 73415cf5e6be13ce9adb7ba5e97474307db34a17 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-601",
            "what_happened": "Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attackers can append the redir_url parameter to any short link to redirect visitors to arbitrary external URLs through the trusted Dub domain, bypassing destination blacklists and potentially enabling phishing attacks with link cloaking enabled.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/dubinc/dub",
                "https://github.com/dubinc/dub/blob/73415cf5e6be13ce9adb7ba5e97474307db34a17/apps/web/lib/middleware/utils/get-final-url.ts",
                "https://github.com/dubinc/dub/issues/4337",
                "https://www.vulncheck.com/advisories/dub-open-redirect-via-unrestricted-redir-url-parameter"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T15:17:45.923",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85676"
                }
            ]
        },
        {
            "id": "CVE-2026-85671",
            "vendor": "netease-youdao",
            "product": "QAnything",
            "title": "QAnything vulnerability",
            "summary": "QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticated attackers to access any uploaded file or document. Attackers can enumerate file identifiers through unauthenticated endpoints and retrieve base64-encoded files or parsed document chunks without ownership verification to disclose cross-tenant knowledge base content.",
            "updated_at": "2026-09-14T20:16:59.390",
            "published_at": "2026-09-04T15:17:45.150",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.0.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticated attackers to access any uploaded file or document. Attackers can enumerate file identifiers through unauthenticated endpoints and retrieve base64-encoded files or parsed document chunks without ownership verification to disclose cross-tenant knowledge base content.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/netease-youdao/QAnything",
                "https://github.com/netease-youdao/QAnything/blob/v2.0.0/qanything_kernel/qanything_server/handler.py",
                "https://github.com/netease-youdao/QAnything/issues/670",
                "https://www.vulncheck.com/advisories/qanything-2.0.0-unauthenticated-cross-user-file-disclosure"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T15:17:45.150",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85671"
                }
            ]
        },
        {
            "id": "CVE-2026-85666",
            "vendor": "ogx-ai",
            "product": "ogx",
            "title": "ogx vulnerability",
            "summary": "OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery vulnerability in the OpenAI-compatible POST /v1/responses endpoint. MCP tool definitions accept a server_url parameter (along with headers and authorization values) that is fetched server-side without destination validation; the existing validate_url_not_private() guard used for other URL inputs is not applied to server_url. On the default starter configuration, which runs without authentication, a remote unauthenticated attacker can cause the server to open connections to arbitrary internal addresses (including cloud metadata endpoints such as http://169.254.169.254/) and forward attacker-supplied headers and bearer tokens to those destinations.",
            "updated_at": "2026-09-14T20:16:59.257",
            "published_at": "2026-09-04T15:17:44.397",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery vulnerability in the OpenAI-compatible POST /v1/responses endpoint. MCP tool definitions accept a server_url parameter (along with headers and authorization values) that is fetched server-side without destination validation; the existing validate_url_not_private() guard used for other URL inputs is not applied to server_url. On the default starter configuration, which runs without authentication, a remote unauthenticated attacker can cause the server to open connections to arbitrary internal addresses (including cloud metadata endpoints such as http://169.254.169.254/) and forward attacker-supplied headers and bearer tokens to those destinations.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ogx-ai/ogx",
                "https://github.com/ogx-ai/ogx/blob/v1.3.1/src/ogx/providers/utils/tools/mcp.py",
                "https://github.com/ogx-ai/ogx/issues/6287",
                "https://www.vulncheck.com/advisories/ogx-1.3.1-server-side-request-forgery-via-mcp-tool-server-url"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T15:17:44.397",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85666"
                }
            ]
        },
        {
            "id": "CVE-2026-85665",
            "vendor": "usebruno",
            "product": "bruno",
            "title": "bruno vulnerability",
            "summary": "Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a request with a body:file path containing ../ sequences that resolve outside the collection directory, causing the application to read and exfiltrate arbitrary files to attacker-controlled endpoints.",
            "updated_at": "2026-09-05T11:16:45.577",
            "published_at": "2026-09-04T15:17:44.247",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a request with a body:file path containing ../ sequences that resolve outside the collection directory, causing the application to read and exfiltrate arbitrary files to attacker-controlled endpoints.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/usebruno/bruno",
                "https://github.com/usebruno/bruno/blob/v4.1.0/packages/bruno-cli/src/runner/prepare-request.js",
                "https://github.com/usebruno/bruno/issues/8230",
                "https://www.vulncheck.com/advisories/bruno-3.4.2-arbitrary-file-read-via-unconfined-body-file-path"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T15:17:44.247",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85665"
                }
            ]
        },
        {
            "id": "CVE-2026-85661",
            "vendor": "haris-musa",
            "product": "excel-mcp-server",
            "title": "excel-mcp-server vulnerability",
            "summary": "excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.",
            "updated_at": "2026-09-14T20:16:59.127",
            "published_at": "2026-09-04T15:17:43.643",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.1.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/haris-musa/excel-mcp-server",
                "https://github.com/haris-musa/excel-mcp-server/blob/v0.1.8/src/excel_mcp/server.py",
                "https://github.com/haris-musa/excel-mcp-server/blob/v0.1.8/src/excel_mcp/validation.py",
                "https://github.com/haris-musa/excel-mcp-server/issues/149",
                "https://www.vulncheck.com/advisories/excel-mcp-server-0.1.8-arbitrary-file-read-write-via-stdio-mode"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T15:17:43.643",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85661"
                }
            ]
        },
        {
            "id": "CVE-2026-85638",
            "vendor": "jofpin",
            "product": "trape",
            "title": "trape vulnerability",
            "summary": "A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-11T21:17:31.720",
            "published_at": "2026-09-04T19:17:33.430",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "A weakness has been identified in jofpin trape 2.0. This affects an unknown part of the file core/user.py. This manipulation of the argument vId/id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jofpin/trape/",
                "https://github.com/jofpin/trape/issues/407",
                "https://vuldb.com/cve/CVE-2026-85638",
                "https://vuldb.com/submit/895139",
                "https://vuldb.com/vuln/398786",
                "https://vuldb.com/vuln/398786/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T19:17:33.430",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85638"
                }
            ]
        },
        {
            "id": "CVE-2026-85625",
            "vendor": "crcn",
            "product": "sift.js",
            "title": "sift.js vulnerability",
            "summary": "sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where. The $where operation compiles a string value into a function using new Function unless CSP_ENABLED is set (not set by default). As a result, if a prototype-pollution primitive elsewhere in the process sets Object.prototype.$where to a malicious string, even benign filter calls such as sift({}) execute arbitrary JavaScript. Additionally, passing an untrusted query object containing a string $where directly to sift results in code execution under the default configuration.",
            "updated_at": "2026-09-14T20:16:58.987",
            "published_at": "2026-09-04T15:17:42.880",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 17.1.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-1321",
            "what_happened": "sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where. The $where operation compiles a string value into a function using new Function unless CSP_ENABLED is set (not set by default). As a result, if a prototype-pollution primitive elsewhere in the process sets Object.prototype.$where to a malicious string, even benign filter calls such as sift({}) execute arbitrary JavaScript. Additionally, passing an untrusted query object containing a string $where directly to sift results in code execution under the default configuration.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/crcn/sift.js",
                "https://github.com/crcn/sift.js/blob/v17.1.3/src/core.ts",
                "https://github.com/crcn/sift.js/issues/276",
                "https://www.vulncheck.com/advisories/sift-17.1.3-prototype-pollution-remote-code-execution-via-where"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T15:17:42.880",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85625"
                }
            ]
        },
        {
            "id": "CVE-2026-85620",
            "vendor": "crystaldba",
            "product": "postgres-mcp",
            "title": "postgres-mcp vulnerability",
            "summary": "Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to read arbitrary files despite restricted-mode protections.",
            "updated_at": "2026-09-14T20:16:58.850",
            "published_at": "2026-09-04T15:17:42.150",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to read arbitrary files despite restricted-mode protections.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/crystaldba/postgres-mcp",
                "https://github.com/crystaldba/postgres-mcp/blob/v0.3.0/src/postgres_mcp/sql/safe_sql.py",
                "https://github.com/crystaldba/postgres-mcp/issues/178",
                "https://www.vulncheck.com/advisories/postgres-mcp-pro-0.3.0-restricted-mode-bypass-via-from-clause-function"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T15:17:42.150",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85620"
                }
            ]
        },
        {
            "id": "CVE-2026-85617",
            "vendor": "grokability",
            "product": "snipe-it",
            "title": "snipe-it vulnerability",
            "summary": "snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. Attackers can include unauthorized user IDs in bulk delete requests to bypass instance-level restrictions and modify or disable accounts they should not access.",
            "updated_at": "2026-09-14T20:16:58.680",
            "published_at": "2026-09-04T12:17:25.410",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 8.6.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. Attackers can include unauthorized user IDs in bulk delete requests to bypass instance-level restrictions and modify or disable accounts they should not access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/grokability/snipe-it/security/advisories/GHSA-mx3g-8v84-j6gg",
                "https://www.vulncheck.com/advisories/snipe-it-before-8.6.3-authorization-bypass-via-bulk-delete"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T12:17:25.410",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85617"
                }
            ]
        },
        {
            "id": "CVE-2026-85612",
            "vendor": "Openpanel-dev",
            "product": "openpanel",
            "title": "openpanel vulnerability",
            "summary": "OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the API to fetch arbitrary internal hosts and cloud metadata endpoints, with small responses returned verbatim enabling credential theft and internal service enumeration.",
            "updated_at": "2026-09-14T20:16:58.547",
            "published_at": "2026-09-04T12:17:24.727",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the API to fetch arbitrary internal hosts and cloud metadata endpoints, with small responses returned verbatim enabling credential theft and internal service enumeration.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Openpanel-dev/openpanel/security/advisories/GHSA-2hff-m67f-2w2w",
                "https://www.vulncheck.com/advisories/openpanel-before-2.3.0-ssrf-via-favicon-and-og-endpoints"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T12:17:24.727",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85612"
                }
            ]
        },
        {
            "id": "CVE-2026-85606",
            "vendor": "firecrawl",
            "product": "firecrawl-mcp-server",
            "title": "firecrawl-mcp-server vulnerability",
            "summary": "firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can supply absolute paths or directory traversal sequences to read sensitive files like credentials and environment variables, which are then uploaded and returned to the model context.",
            "updated_at": "2026-09-14T20:16:58.410",
            "published_at": "2026-09-04T15:17:41.393",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.24.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can supply absolute paths or directory traversal sequences to read sensitive files like credentials and environment variables, which are then uploaded and returned to the model context.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/firecrawl/firecrawl-mcp-server",
                "https://github.com/firecrawl/firecrawl-mcp-server/blob/v3.24.1/src/index.ts",
                "https://github.com/firecrawl/firecrawl-mcp-server/issues/306",
                "https://www.vulncheck.com/advisories/firecrawl-mcp-server-3.20.2-arbitrary-local-file-read-via-filepath"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T15:17:41.393",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85606"
                }
            ]
        },
        {
            "id": "CVE-2026-85604",
            "vendor": "getgrav",
            "product": "grav",
            "title": "grav vulnerability",
            "summary": "Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name inside the sandbox; the remaining denylist misses spl_autoload, which performs a PHP include. An authenticated user with only page-write rights (admin.pages or api.pages.write) can supply a crafted payload (e.g., via form frontmatter rendered by the Email plugin) that invokes spl_autoload through the sort filter, resulting in arbitrary PHP execution as the web server user.",
            "updated_at": "2026-09-05T11:16:45.460",
            "published_at": "2026-09-04T12:17:24.177",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.0.18 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name inside the sandbox; the remaining denylist misses spl_autoload, which performs a PHP include. An authenticated user with only page-write rights (admin.pages or api.pages.write) can supply a crafted payload (e.g., via form frontmatter rendered by the Email plugin) that invokes spl_autoload through the sort filter, resulting in arbitrary PHP execution as the web server user.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/getgrav/grav/security/advisories/GHSA-p6qj-p5m7-f62h",
                "https://www.vulncheck.com/advisories/grav-before-2.0.19-remote-code-execution-via-sort-filter"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T12:17:24.177",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85604"
                }
            ]
        },
        {
            "id": "CVE-2026-85603",
            "vendor": "getgrav",
            "product": "grav",
            "title": "grav vulnerability",
            "summary": "Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply directory traversal sequences in the lang POST field to write arbitrary .md files outside the pages directory with attacker-controlled content.",
            "updated_at": "2026-09-14T20:16:58.270",
            "published_at": "2026-09-04T12:17:24.040",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.10.55 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-73",
            "what_happened": "Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply directory traversal sequences in the lang POST field to write arbitrary .md files outside the pages directory with attacker-controlled content.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/getgrav/grav/security/advisories/GHSA-h9g9-73c3-23c9",
                "https://www.vulncheck.com/advisories/grav-admin-plugin-path-traversal-via-save-as-language-code"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T12:17:24.040",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85603"
                }
            ]
        },
        {
            "id": "CVE-2026-85602",
            "vendor": "getgrav",
            "product": "grav-plugin-form",
            "title": "grav-plugin-form vulnerability",
            "summary": "The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On a site configured for reCAPTCHA v3, an anonymous attacker can place their v3 token under the v2 field name (g-recaptcha-response instead of token), causing validation to use the v2 branch, which never applies the score threshold or verifies the expected action. This results in a complete bypass of reCAPTCHA v3 bot protection. The issue is fixed in version 9.1.20.",
            "updated_at": "2026-09-05T11:16:45.337",
            "published_at": "2026-09-04T12:17:23.903",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 9.1.20 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-807",
            "what_happened": "The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On a site configured for reCAPTCHA v3, an anonymous attacker can place their v3 token under the v2 field name (g-recaptcha-response instead of token), causing validation to use the v2 branch, which never applies the score threshold or verifies the expected action. This results in a complete bypass of reCAPTCHA v3 bot protection. The issue is fixed in version 9.1.20.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/getgrav/grav/security/advisories/GHSA-89j6-8h38-2cc3",
                "https://www.vulncheck.com/advisories/grav-form-plugin-before-9.1.20-recaptcha-v3-authentication-bypass"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T12:17:23.903",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85602"
                }
            ]
        },
        {
            "id": "CVE-2026-85600",
            "vendor": "getgrav",
            "product": "grav-plugin-admin2",
            "title": "grav-plugin-admin2 vulnerability",
            "summary": "Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into translation templates before parsing the result as markdown. Grav's server-side username validation (DataUser::isValidUsername) blocks filesystem-dangerous characters but not <, >, \", or ', allowing an attacker to register a username containing an HTML payload. When an administrator views a UI surface that renders the username through tHtml()—such as the two-factor force-disable confirmation prompt or the 'page is locked' editor notice—the payload executes in their authenticated session. Fixed in 2.0.21.",
            "updated_at": "2026-09-05T11:16:45.213",
            "published_at": "2026-09-04T12:17:23.630",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.0.19 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into translation templates before parsing the result as markdown. Grav's server-side username validation (DataUser::isValidUsername) blocks filesystem-dangerous characters but not <, >, \", or ', allowing an attacker to register a username containing an HTML payload. When an administrator views a UI surface that renders the username through tHtml()—such as the two-factor force-disable confirmation prompt or the 'page is locked' editor notice—the payload executes in their authenticated session. Fixed in 2.0.21.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/getgrav/grav/security/advisories/GHSA-96xm-c5hr-59rx",
                "https://www.vulncheck.com/advisories/grav-admin-before-2.0.21-stored-xss-via-username"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T12:17:23.630",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85600"
                }
            ]
        },
        {
            "id": "CVE-2026-85599",
            "vendor": "getgrav",
            "product": "grav-plugin-shortcode-core",
            "title": "grav-plugin-shortcode-core vulnerability",
            "summary": "Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitrary HTML and JavaScript that executes in the browsers of all page visitors, including administrators.",
            "updated_at": "2026-09-05T11:16:45.100",
            "published_at": "2026-09-04T12:17:23.490",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 6.2.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitrary HTML and JavaScript that executes in the browsers of all page visitors, including administrators.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/getgrav/grav/security/advisories/GHSA-hvm8-wx3f-j774",
                "https://www.vulncheck.com/advisories/grav-shortcode-core-before-6.2.5-stored-xss-via-unescaped-parameters"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T12:17:23.490",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85599"
                }
            ]
        },
        {
            "id": "CVE-2026-85598",
            "vendor": "getgrav",
            "product": "grav",
            "title": "grav vulnerability",
            "summary": "Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious Twig code that executes in visitor browsers when the parent page is rendered, including in administrator sessions.",
            "updated_at": "2026-09-14T20:16:58.137",
            "published_at": "2026-09-04T12:17:23.340",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.0.0 through 2.0.17 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with page-edit rights can create modular pages with malicious Twig code that executes in visitor browsers when the parent page is rendered, including in administrator sessions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/getgrav/grav/security/advisories/GHSA-fg8g-663r-f366",
                "https://www.vulncheck.com/advisories/grav-2.0.0-through-2.0.17-stored-xss-via-modular-pages"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T12:17:23.340",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85598"
                }
            ]
        },
        {
            "id": "CVE-2026-85597",
            "vendor": "traefik",
            "product": "traefik",
            "title": "traefik vulnerability",
            "summary": "Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts.",
            "updated_at": "2026-09-05T11:16:44.863",
            "published_at": "2026-09-04T12:17:23.210",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.11.55 (semver); 3.0.0 through 3.7.10 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/traefik/traefik/security/advisories/GHSA-g55h-rg46-x9c5",
                "https://www.vulncheck.com/advisories/traefik-before-2.11.55-mtls-bypass-via-tls-option-conflict"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T12:17:23.210",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85597"
                }
            ]
        },
        {
            "id": "CVE-2026-85596",
            "vendor": "traefik",
            "product": "traefik",
            "title": "traefik vulnerability",
            "summary": "Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the nginx.ingress.kubernetes.io/auth-tls-secret annotation was named after the Ingress namespace and name. As a result, two Ingress objects sharing the same host, the same client CA secret, and the same client-authentication mode produced two distinct TLS option names for that host. Traefik treats this as a TLS options conflict and falls back to the entry point's default TLS configuration, which does not request a client certificate, so a route configured with nginx.ingress.kubernetes.io/auth-tls-verify-client: \"on\" becomes reachable without a client certificate. Only the v3.7 line is affected; the issue is fixed in v3.7.11.",
            "updated_at": "2026-09-05T11:16:44.743",
            "published_at": "2026-09-04T12:17:23.087",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.7.0 through 3.7.10 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the nginx.ingress.kubernetes.io/auth-tls-secret annotation was named after the Ingress namespace and name. As a result, two Ingress objects sharing the same host, the same client CA secret, and the same client-authentication mode produced two distinct TLS option names for that host. Traefik treats this as a TLS options conflict and falls back to the entry point's default TLS configuration, which does not request a client certificate, so a route configured with nginx.ingress.kubernetes.io/auth-tls-verify-client: \"on\" becomes reachable without a client certificate. Only the v3.7 line is affected; the issue is fixed in v3.7.11.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/traefik/traefik/security/advisories/GHSA-j994-9gqj-9hwq",
                "https://www.vulncheck.com/advisories/traefik-3.7-authentication-bypass-via-tls-option-conflict"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T12:17:23.087",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85596"
                }
            ]
        },
        {
            "id": "CVE-2026-85595",
            "vendor": "traefik",
            "product": "traefik",
            "title": "traefik vulnerability",
            "summary": "Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.",
            "updated_at": "2026-09-05T11:16:43.577",
            "published_at": "2026-09-04T12:17:22.960",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.11.55 (semver); 3.0.0 through 3.7.10 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or password.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/traefik/traefik/security/advisories/GHSA-5w68-77r2-r64c",
                "https://www.vulncheck.com/advisories/traefik-before-2.11.55-authentication-bypass-via-digestauth"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T12:17:22.960",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85595"
                }
            ]
        },
        {
            "id": "CVE-2026-85583",
            "vendor": "siyuan-note",
            "product": "siyuan",
            "title": "siyuan vulnerability",
            "summary": "SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader role can request a logical asset under data/assets/ that is a symlink to a file outside the workspace and receive the target file bytes, bypassing workspace boundary restrictions.",
            "updated_at": "2026-09-14T20:16:58.007",
            "published_at": "2026-09-04T12:17:20.327",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.8.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-59",
            "what_happened": "SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader role can request a logical asset under data/assets/ that is a symlink to a file outside the workspace and receive the target file bytes, bypassing workspace boundary restrictions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-g7gf-v79m-jwrm",
                "https://www.vulncheck.com/advisories/siyuan-before-3.8.2-path-traversal-via-symlink-in-file-api"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T12:17:20.327",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85583"
                }
            ]
        },
        {
            "id": "CVE-2026-85546",
            "vendor": "misp",
            "product": "misp",
            "title": "misp vulnerability",
            "summary": "MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuickEdit() helper, where the HTTP method validation intended to restrict these operations to POST requests was commented out.\n\nAs a result, these state-changing actions could be invoked using GET requests. An attacker could craft a URL targeting one of the affected actions and cause an authenticated MISP user with sufficient privileges to request it, for example through a malicious link or embedded web resource.\n\nSuccessful exploitation could modify the membership of a MISP sharing group without the victim intentionally performing the operation. Depending on the action performed, an attacker could add or remove organisations or servers from a sharing group, potentially granting unintended access to information distributed through that sharing group or disrupting legitimate information sharing.\n\nThe patch restores HTTP method enforcement centrally in __initialiseSGQuickEdit() by calling allowMethod(['post']), ensuring that all four affected quick-edit operations require POST requests and are therefore subject to the application's normal protections for state-changing requests.",
            "updated_at": "2026-09-10T08:17:01.553",
            "published_at": "2026-09-04T10:17:14.287",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.4.45 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-352",
            "what_happened": "MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuickEdit() helper, where the HTTP method validation intended to restrict these operations to POST requests was commented out.\n\nAs a result, these state-changing actions could be invoked using GET requests. An attacker could craft a URL targeting one of the affected actions and cause an authenticated MISP user with sufficient privileges to request it, for example through a malicious link or embedded web resource.\n\nSuccessful exploitation could modify the membership of a MISP sharing group without the victim intentionally performing the operation. Depending on the action performed, an attacker could add or remove organisations or servers from a sharing group, potentially granting unintended access to information distributed through that sharing group or disrupting legitimate information sharing.\n\nThe patch restores HTTP method enforcement centrally in __initialiseSGQuickEdit() by calling allowMethod(['post']), ensuring that all four affected quick-edit operations require POST requests and are therefore subject to the application's normal protections for state-changing requests.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/MISP/MISP/commit/3060d93cb"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T10:17:14.287",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85546"
                }
            ]
        },
        {
            "id": "CVE-2026-85516",
            "vendor": "code-projects",
            "product": "Vehicle Management System",
            "title": "Vehicle Management System vulnerability",
            "summary": "A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.",
            "updated_at": "2026-09-11T21:17:31.057",
            "published_at": "2026-09-04T13:20:11.470",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://code-projects.org/",
                "https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/SQL%20Injection%20Vulnerability%20in%20Vehicle%20Management%20System%20%60busid%60%20Parameter.md",
                "https://vuldb.com/cve/CVE-2026-85516",
                "https://vuldb.com/submit/895112",
                "https://vuldb.com/vuln/398680",
                "https://vuldb.com/vuln/398680/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T13:20:11.470",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85516"
                }
            ]
        },
        {
            "id": "CVE-2026-85444",
            "vendor": "moos-ivp",
            "product": "moos-ivp",
            "title": "moos-ivp vulnerability",
            "summary": "MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip whitespace but index using the original string length. Attackers can send NODE_REPORT messages with leading or trailing whitespace to read past buffer bounds and access adjacent memory.",
            "updated_at": "2026-09-05T03:17:24.557",
            "published_at": "2026-09-03T23:17:24.180",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 24.8.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip whitespace but index using the original string length. Attackers can send NODE_REPORT messages with leading or trailing whitespace to read past buffer bounds and access adjacent memory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/moos-ivp/moos-ivp",
                "https://github.com/moos-ivp/moos-ivp/blob/1de9ae146cd63c209e8c3fd81611a4ed2472971b/ivp/src/lib_mbutil/MBUtils.cpp#L1710",
                "https://github.com/moos-ivp/moos-ivp/commit/faff8adfa1a69d68614461f679ebbc1d741c51aa",
                "https://github.com/moos-ivp/moos-ivp/pull/128",
                "https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-out-of-bounds-read-in-isbraced-isquoted-and-ischevroned"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T23:17:24.180",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85444"
                }
            ]
        },
        {
            "id": "CVE-2026-85439",
            "vendor": "moos-ivp",
            "product": "moos-ivp",
            "title": "moos-ivp vulnerability",
            "summary": "MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metacharacters in log file pathnames. Attackers can embed shell syntax in log file names or the --dir parameter to execute arbitrary commands with the privileges of the operator running alogsplit.",
            "updated_at": "2026-09-05T03:17:24.433",
            "published_at": "2026-09-03T23:17:23.427",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 24.8.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metacharacters in log file pathnames. Attackers can embed shell syntax in log file names or the --dir parameter to execute arbitrary commands with the privileges of the operator running alogsplit.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/moos-ivp/moos-ivp",
                "https://github.com/moos-ivp/moos-ivp/blob/1de9ae146cd63c209e8c3fd81611a4ed2472971b/ivp/src/lib_logutils/SplitHandler.cpp#L608",
                "https://github.com/moos-ivp/moos-ivp/commit/f684d77d9d6e9e96dbfce46f05988d5a643f2b60",
                "https://github.com/moos-ivp/moos-ivp/pull/127",
                "https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-alogsplit-command-injection-via-input-pathname"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T23:17:23.427",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85439"
                }
            ]
        },
        {
            "id": "CVE-2026-85434",
            "vendor": "moos-ivp",
            "product": "moos-ivp",
            "title": "moos-ivp vulnerability",
            "summary": "MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.",
            "updated_at": "2026-09-05T03:17:24.303",
            "published_at": "2026-09-03T23:17:22.643",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 24.8.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-345",
            "what_happened": "MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/moos-ivp/moos-ivp",
                "https://github.com/moos-ivp/moos-ivp/blob/1de9ae146cd63c209e8c3fd81611a4ed2472971b/ivp/src/uFldShoreBroker/ShoreBroker.cpp#L93",
                "https://github.com/moos-ivp/moos-ivp/commit/2f5224dcd68f92ce9ae10c261bb45dd7000f4d33",
                "https://github.com/moos-ivp/moos-ivp/pull/123",
                "https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-ufldshorebroker-bridge-route-injection-via-unverified-node-ping"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T23:17:22.643",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85434"
                }
            ]
        },
        {
            "id": "CVE-2026-85429",
            "vendor": "moos-ivp",
            "product": "moos-ivp",
            "title": "moos-ivp vulnerability",
            "summary": "MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation.",
            "updated_at": "2026-09-05T03:17:24.180",
            "published_at": "2026-09-03T23:17:21.910",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 24.8.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-345",
            "what_happened": "MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable notifications without validation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/moos-ivp/moos-ivp",
                "https://github.com/moos-ivp/moos-ivp/blob/1de9ae146cd63c209e8c3fd81611a4ed2472971b/ivp/src/uFldNodeComms/FldNodeComms.cpp#L114",
                "https://github.com/moos-ivp/moos-ivp/commit/3907ac07cdfd8a7255d65657dc18dc6b77b30b64",
                "https://github.com/moos-ivp/moos-ivp/pull/122",
                "https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-ufldnodecomms-node-message-source-spoofing"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T23:17:21.910",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85429"
                }
            ]
        },
        {
            "id": "CVE-2026-85424",
            "vendor": "themoos",
            "product": "core-moos",
            "title": "core-moos vulnerability",
            "summary": "MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues.",
            "updated_at": "2026-09-05T03:17:24.050",
            "published_at": "2026-09-03T23:17:21.170",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 10.4.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names to execute privileged operations including DB_CLEAR which resets all variables and clears client mail queues.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/themoos/core-moos",
                "https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/DB/MOOSDB.cpp#L1163",
                "https://github.com/themoos/core-moos/commit/5ff5cdec44242156a168cc1a545a6a21357bd3ac",
                "https://github.com/themoos/core-moos/pull/84",
                "https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-missing-authentication-for-moosdb-publish-subscribe-and-db-clear"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T23:17:21.170",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85424"
                }
            ]
        },
        {
            "id": "CVE-2026-85414",
            "vendor": "fooplugins",
            "product": "Gallery : FooGallery",
            "title": "Gallery : FooGallery vulnerability",
            "summary": "The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
            "updated_at": "2026-09-05T08:16:40.993",
            "published_at": "2026-09-05T08:16:40.993",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.3.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/foogallery/tags/3.2.6/assets/js/foogallery.4cc6f51b.js#L6599",
                "https://plugins.trac.wordpress.org/browser/foogallery/tags/3.2.6/assets/js/foogallery.4cc6f51b.js#L7367",
                "https://plugins.trac.wordpress.org/browser/foogallery/tags/3.2.6/assets/js/foogallery.4cc6f51b.js#L8048",
                "https://plugins.trac.wordpress.org/browser/foogallery/tags/3.2.6/includes/class-gallery-advanced-settings.php#L138",
                "https://plugins.trac.wordpress.org/browser/foogallery/tags/3.2.6/includes/functions.php#L301",
                "https://plugins.trac.wordpress.org/browser/foogallery/trunk/assets/js/foogallery.4cc6f51b.js#L6599",
                "https://plugins.trac.wordpress.org/browser/foogallery/trunk/assets/js/foogallery.4cc6f51b.js#L7367",
                "https://plugins.trac.wordpress.org/browser/foogallery/trunk/assets/js/foogallery.4cc6f51b.js#L8048",
                "https://plugins.trac.wordpress.org/browser/foogallery/trunk/includes/class-gallery-advanced-settings.php#L138",
                "https://plugins.trac.wordpress.org/browser/foogallery/trunk/includes/functions.php#L301",
                "https://plugins.trac.wordpress.org/changeset/3680965/foogallery",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/859e78cd-3dfe-41b9-86dd-6f9db319cad8?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:16:40.993",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85414"
                }
            ]
        },
        {
            "id": "CVE-2026-85408",
            "vendor": "Eleveo",
            "product": "Quality Management",
            "title": "Quality Management vulnerability",
            "summary": "A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. This manipulation of the argument createdBy causes dynamically-determined object attributes. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.",
            "updated_at": "2026-09-11T21:17:30.387",
            "published_at": "2026-09-04T05:17:15.743",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.7.0",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-913",
            "what_happened": "A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. This manipulation of the argument createdBy causes dynamically-determined object attributes. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://drive.google.com/file/d/1fVUqrUoO29zkq2Ib_TXFNavX9yDo-Vp6/view?usp=sharing",
                "https://vuldb.com/cve/CVE-2026-85408",
                "https://vuldb.com/submit/894906",
                "https://vuldb.com/vuln/398558",
                "https://vuldb.com/vuln/398558/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T05:17:15.743",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85408"
                }
            ]
        },
        {
            "id": "CVE-2026-85402",
            "vendor": "code-projects",
            "product": "Doctor Appointment System",
            "title": "Doctor Appointment System vulnerability",
            "summary": "A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.",
            "updated_at": "2026-09-11T21:17:29.803",
            "published_at": "2026-09-04T03:17:46.863",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://code-projects.org/",
                "https://github.com/lccc-t/CVE/issues/5",
                "https://vuldb.com/cve/CVE-2026-85402",
                "https://vuldb.com/submit/894879",
                "https://vuldb.com/vuln/398545",
                "https://vuldb.com/vuln/398545/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T03:17:46.863",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85402"
                }
            ]
        },
        {
            "id": "CVE-2026-85395",
            "vendor": "unopim",
            "product": "unopim",
            "title": "unopim vulnerability",
            "summary": "UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges can create OAuth API integrations, mint client credentials, and escalate permissions by exploiting missing authorization validation in the Bouncer middleware.",
            "updated_at": "2026-09-05T03:17:23.880",
            "published_at": "2026-09-03T19:17:31.390",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.1.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges can create OAuth API integrations, mint client credentials, and escalate permissions by exploiting missing authorization validation in the Bouncer middleware.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/geo-chen/oss/blob/main/unopim.md",
                "https://github.com/unopim/unopim",
                "https://github.com/unopim/unopim/blob/v2.1.2/packages/Webkul/User/src/Http/Middleware/Bouncer.php",
                "https://github.com/unopim/unopim/commit/acbf2e160ced78446d6e4267e89f264bf04612c4",
                "https://github.com/unopim/unopim/releases/tag/v2.1.3",
                "https://www.vulncheck.com/advisories/unopim-before-2.1.3-missing-authorization-on-integration-management-routes"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T19:17:31.390",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85395"
                }
            ]
        },
        {
            "id": "CVE-2026-85390",
            "vendor": "bluewave-labs",
            "product": "Checkmate",
            "title": "Checkmate vulnerability",
            "summary": "Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and delete monitor check history to erase incident evidence.",
            "updated_at": "2026-09-05T03:17:23.703",
            "published_at": "2026-09-03T19:17:30.690",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.11.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and delete monitor check history to erase incident evidence.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/bluewave-labs/Checkmate",
                "https://github.com/bluewave-labs/Checkmate/blob/v3.11.0/server/src/api/routes/checkRoutes.ts",
                "https://github.com/bluewave-labs/Checkmate/blob/v3.11.0/server/src/api/routes/maintenanceWindowRoutes.ts",
                "https://github.com/bluewave-labs/Checkmate/blob/v3.11.0/server/src/api/routes/notificationRoutes.ts",
                "https://github.com/bluewave-labs/Checkmate/issues/3916",
                "https://www.vulncheck.com/advisories/checkmate-through-3.11.0-missing-authorization-on-maintenance-window-notification-and-check-deletion-routes"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T19:17:30.690",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85390"
                }
            ]
        },
        {
            "id": "CVE-2026-85383",
            "vendor": "itsourcecode",
            "product": "Sales and Inventory System",
            "title": "Sales and Inventory System vulnerability",
            "summary": "A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_del.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.",
            "updated_at": "2026-09-11T21:17:29.267",
            "published_at": "2026-09-04T02:17:20.187",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_del.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ltranquility/submit_repository/issues/3",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-85383",
                "https://vuldb.com/submit/894851",
                "https://vuldb.com/vuln/398537",
                "https://vuldb.com/vuln/398537/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T02:17:20.187",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85383"
                }
            ]
        },
        {
            "id": "CVE-2026-85378",
            "vendor": "light0011",
            "product": "cms",
            "title": "cms vulnerability",
            "summary": "A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/ChapterController.class.php of the component Chapter Controller. The manipulation leads to authorization bypass. The attack can be initiated remotely. The exploit is publicly available and might be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.",
            "updated_at": "2026-09-11T21:17:28.737",
            "published_at": "2026-09-03T23:17:20.987",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c774dce31c6df0055568a8d5c53d964d99be199d; f72cf46f601efb2a0618c3814cc2f61380b38930",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/ChapterController.class.php of the component Chapter Controller. The manipulation leads to authorization bypass. The attack can be initiated remotely. The exploit is publicly available and might be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/light0011/cms/",
                "https://github.com/light0011/cms/issues/4",
                "https://vuldb.com/cve/CVE-2026-85378",
                "https://vuldb.com/submit/894787",
                "https://vuldb.com/vuln/398532",
                "https://vuldb.com/vuln/398532/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T23:17:20.987",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85378"
                }
            ]
        },
        {
            "id": "CVE-2026-85225",
            "vendor": "code-projects",
            "product": "Doctor Appointment System",
            "title": "Doctor Appointment System vulnerability",
            "summary": "A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.",
            "updated_at": "2026-09-05T03:17:18.023",
            "published_at": "2026-09-03T23:17:20.630",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://code-projects.org/",
                "https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Time-Based%20Blind%20SQL%20Injection%20in%20Doctor%20Appointment%20System%20email%20Parameter.md",
                "https://vuldb.com/cve/CVE-2026-85225",
                "https://vuldb.com/submit/894405",
                "https://vuldb.com/vuln/398424",
                "https://vuldb.com/vuln/398424/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T23:17:20.630",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85225"
                }
            ]
        },
        {
            "id": "CVE-2026-85217",
            "vendor": "Autodesk",
            "product": "Fusion",
            "title": "Fusion vulnerability",
            "summary": "A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing sensitive information with the current user.",
            "updated_at": "2026-09-11T04:18:02.610",
            "published_at": "2026-09-10T14:17:09.380",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2705.0.0 through before 2705.1.11 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-15",
            "what_happened": "A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing sensitive information with the current user.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://dl.appstreaming.autodesk.com/production/installers/Fusion%20Client%20Downloader.exe",
                "https://www.autodesk.com/trust/security-advisories/adsk-sa-2026-0016"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T14:17:09.380",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85217"
                }
            ]
        },
        {
            "id": "CVE-2026-85207",
            "vendor": "itsourcecode",
            "product": "Online Medicine Delivery System",
            "title": "Online Medicine Delivery System vulnerability",
            "summary": "A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation of the argument location leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.",
            "updated_at": "2026-09-05T03:17:16.520",
            "published_at": "2026-09-03T20:17:27.613",
            "cvss": 2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation of the argument location leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/boyslikesports/202607_vul_dir/blob/main/H-06-XSS-Reflected-OrderDetails_en.md",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-85207",
                "https://vuldb.com/submit/892997",
                "https://vuldb.com/vuln/398415",
                "https://vuldb.com/vuln/398415/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T20:17:27.613",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85207"
                }
            ]
        },
        {
            "id": "CVE-2026-85205",
            "vendor": "itsourcecode",
            "product": "Online Medicine Delivery System",
            "title": "Online Medicine Delivery System vulnerability",
            "summary": "A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. This manipulation of the argument proid causes sql injection. The attack may be initiated remotely.",
            "updated_at": "2026-09-15T19:17:44.303",
            "published_at": "2026-09-03T19:17:30.230",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. This manipulation of the argument proid causes sql injection. The attack may be initiated remotely.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/boyslikesports/202607_vul_dir/blob/main/H-02-SQLi-Wishlist-Update-Insert_en.md",
                "https://itsourcecode.com/",
                "https://vuldb.com/cve/CVE-2026-85205",
                "https://vuldb.com/submit/892993",
                "https://vuldb.com/vuln/398414",
                "https://vuldb.com/vuln/398414/cti"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T19:17:30.230",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85205"
                }
            ]
        },
        {
            "id": "CVE-2026-85200",
            "vendor": "ninjew",
            "product": "GEO my WP",
            "title": "GEO my WP vulnerability",
            "summary": "The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. In environments where PEAR is installed with register_argc_argv enabled, this file inclusion can be leveraged to write and execute arbitrary PHP code, achieving full remote code execution.",
            "updated_at": "2026-09-12T08:16:24.810",
            "published_at": "2026-09-12T08:16:24.810",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.5.5.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-98",
            "what_happened": "The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. In environments where PEAR is installed with register_argc_argv enabled, this file inclusion can be leveraged to write and execute arbitrary PHP code, achieving full remote code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Fitoussi/geo-my-wp/commit/5a768bf1c6e44ded83a65be8789f3587515665ac",
                "https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5.1/includes/gmw-functions.php#L1945",
                "https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5.1/includes/gmw-functions.php#L1987",
                "https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5.1/plugins/posts-locator/includes/gmw-posts-locator-functions.php#L964",
                "https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5.1/plugins/posts-locator/includes/gmw-posts-locator-functions.php#L975",
                "https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5.3/includes/gmw-functions.php#L1945",
                "https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5.3/includes/gmw-functions.php#L1987",
                "https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5.3/plugins/posts-locator/includes/gmw-posts-locator-functions.php#L964",
                "https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5.3/plugins/posts-locator/includes/gmw-posts-locator-functions.php#L975",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/562712a8-a42e-4b36-9985-3c71698efdda?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T08:16:24.810",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85200"
                }
            ]
        },
        {
            "id": "CVE-2026-85198",
            "vendor": "themeisle",
            "product": "MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO",
            "title": "MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO vulnerability",
            "summary": "The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and including, 4.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is only exploitable when the [mpg_spintax] shortcode is rendered in site-wide content such as a footer or template part, as the vulnerable code path is only reached when the shortcode is active on the requested page.",
            "updated_at": "2026-09-12T08:16:24.670",
            "published_at": "2026-09-12T08:16:24.670",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.2.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in all versions up to, and including, 4.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is only exploitable when the [mpg_spintax] shortcode is rendered in site-wide content such as a footer or template part, as the vulnerable code path is only reached when the shortcode is active on the requested page.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/multiple-pages-generator-by-porthas/tags/4.1.7/controllers/HookController.php#L594",
                "https://plugins.trac.wordpress.org/browser/multiple-pages-generator-by-porthas/tags/4.1.7/controllers/SpintaxController.php#L66",
                "https://plugins.trac.wordpress.org/browser/multiple-pages-generator-by-porthas/tags/4.1.7/helpers/Helper.php#L215",
                "https://plugins.trac.wordpress.org/browser/multiple-pages-generator-by-porthas/tags/4.2.0/controllers/HookController.php#L594",
                "https://plugins.trac.wordpress.org/browser/multiple-pages-generator-by-porthas/tags/4.2.0/controllers/SpintaxController.php#L66",
                "https://plugins.trac.wordpress.org/browser/multiple-pages-generator-by-porthas/tags/4.2.0/helpers/Helper.php#L215",
                "https://plugins.trac.wordpress.org/changeset?reponame=&old=3687328%40multiple-pages-generator-by-porthas&new=3687328%40multiple-pages-generator-by-porthas",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/677004db-d8ac-410c-89d9-ee841d643ef7?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T08:16:24.670",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85198"
                }
            ]
        },
        {
            "id": "CVE-2026-85184",
            "vendor": "@fastify/middie",
            "product": "@fastify/middie",
            "title": "@fastify/middie vulnerability",
            "summary": "@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request target to its path before dispatching. Because the two layers evaluate different strings, a request using an absolute-form target reaches the route handler while the path-scoped middleware, such as authentication or authorization, is skipped. An unauthenticated network attacker can use this to bypass path-based access controls in a Fastify application that relies on middie for those controls. Users should upgrade to @fastify/middie 9.3.4 or later.",
            "updated_at": "2026-09-15T20:02:28.677",
            "published_at": "2026-09-04T10:17:13.900",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.1.0 through before 9.3.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-436",
            "what_happened": "@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request target to its path before dispatching. Because the two layers evaluate different strings, a request using an absolute-form target reaches the route handler while the path-scoped middleware, such as authentication or authorization, is skipped. An unauthenticated network attacker can use this to bypass path-based access controls in a Fastify application that relies on middie for those controls. Users should upgrade to @fastify/middie 9.3.4 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/fastify/middie/security/advisories/GHSA-hx87-8wv7-pjv8"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T10:17:13.900",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85184"
                }
            ]
        },
        {
            "id": "CVE-2026-85150",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.",
            "updated_at": "2026-09-14T06:16:57.763",
            "published_at": "2026-09-03T13:06:21.910",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest authentication. Specially crafted whitespace placement around a parameter's terminator can cause an internal length calculation to underflow, leading to a crash of the process parsing the header. On an RTSP server this can be triggered by a remote, unauthenticated attacker sending a single malformed request when the server has authentication enabled; the same flaw can also be triggered against an RTSP client by a malicious or compromised RTSP server. Successful exploitation results in a denial of service (application crash) and has no confirmed impact on confidentiality or integrity.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:66460",
                "https://access.redhat.com/security/cve/CVE-2026-85150",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2527936",
                "https://gitlab.freedesktop.org/gstreamer/gstreamer-security/-/merge_requests/120",
                "https://gitlab.freedesktop.org/gstreamer/gstreamer/-/blob/main/subprojects/gst-plugins-base/gst-libs/gst/rtsp/gstrtspmessage.c#L1408",
                "https://access.redhat.com/errata/RHSA-2026:67145"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T13:06:21.910",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85150"
                }
            ]
        },
        {
            "id": "CVE-2026-85129",
            "vendor": "Unknown",
            "product": "Hoo Companion",
            "title": "Hoo Companion vulnerability",
            "summary": "The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the site, including administrators. The same request destroys the site's existing theme settings.",
            "updated_at": "2026-09-13T21:17:02.063",
            "published_at": "2026-09-13T21:17:02.063",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.2 through 1.0.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the site, including administrators. The same request destroys the site's existing theme settings.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/a50f6ec1-4297-453e-b45f-6fd889b6b0d2/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:17:02.063",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85129"
                }
            ]
        },
        {
            "id": "CVE-2026-85046",
            "vendor": "Google",
            "product": "Chrome",
            "title": "Chrome vulnerability",
            "summary": "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
            "updated_at": "2026-09-06T02:17:19.167",
            "published_at": "2026-09-03T20:17:24.210",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "152.0.7977.82 through before 152.0.7977.82 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 254,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-843",
            "what_happened": "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "atiilla/CVE-2026-85046",
                    "author": "atiilla",
                    "first_seen": "2026-09-08",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-85046 | Chrome V8 Type Confusion in Inline Array.prototype.sort (Maglev/Turbofan) | CVSS 8.8 | CWE-843 | Chrome < 152.0.7977.82",
                    "summary": "CVE-2026-85046 | Chrome V8 Type Confusion in Inline Array.prototype.sort (Maglev/Turbofan) | CVSS 8.8 | CWE-843 | Chrome < 152.0.7977.82",
                    "url": "https://github.com/atiilla/CVE-2026-85046"
                },
                {
                    "repository": "SneakyNachos/CVE-2026-85046-who-put-the-silverback-guerilla-in-the-wasm",
                    "author": "SneakyNachos",
                    "first_seen": "2026-09-08",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": "CVE-2026-85046 repository",
                    "summary": "",
                    "url": "https://github.com/SneakyNachos/CVE-2026-85046-who-put-the-silverback-guerilla-in-the-wasm"
                },
                {
                    "repository": "Eliot-code/CVE-2026-85046",
                    "author": "Eliot-code",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-85046 repository",
                    "summary": "",
                    "url": "https://github.com/Eliot-code/CVE-2026-85046"
                },
                {
                    "repository": "adriyansyah-mf/cve-2026-85046-poc",
                    "author": "adriyansyah-mf",
                    "first_seen": "2026-09-05",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 4,
                    "title": "CVE-2026-85046 repository",
                    "summary": "",
                    "url": "https://github.com/adriyansyah-mf/cve-2026-85046-poc"
                },
                {
                    "repository": "ubitquity/CVE-2026-85046-Patch-confusion-zero-day-vulnerability-in-Google-Chrome-s-V8-engine",
                    "author": "ubitquity",
                    "first_seen": "2026-09-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Conceptual C++ patch and structural analysis for CVE-2026-85046, a critical type confusion zero-day vulnerability in Google Chrome's V8 engine",
                    "summary": "Conceptual C++ patch and structural analysis for CVE-2026-85046, a critical type confusion zero-day vulnerability in Google Chrome's V8 engine",
                    "url": "https://github.com/ubitquity/CVE-2026-85046-Patch-confusion-zero-day-vulnerability-in-Google-Chrome-s-V8-engine"
                },
                {
                    "repository": "HORKimhab/CVE-2026-85046",
                    "author": "HORKimhab",
                    "first_seen": "2026-09-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": "CVE-2026-85046",
                    "summary": "CVE-2026-85046",
                    "url": "https://github.com/HORKimhab/CVE-2026-85046"
                },
                {
                    "title": "Exploit for Out-of-bounds Write in Google Chrome CVE-2026-85046 CVE-2026-87491 CVE-2026-87575 CVE-2026-87606",
                    "summary": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "what_happened": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B",
                        "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass."
                    ],
                    "repository": "Sploitus",
                    "author": "SneakyNachos",
                    "first_seen": "2026-09-12T17:35:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B"
                },
                {
                    "title": "Exploit for Out-of-bounds Write in Google Chrome CVE-2026-85046 CVE-2026-87491 CVE-2026-87575 CVE-2026-87606",
                    "summary": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "what_happened": "Out-of-bounds write exploit in Chrome escaping renderer to launch Evolution mail handler.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B",
                        "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass."
                    ],
                    "repository": "SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass.",
                    "author": "SneakyNachos",
                    "first_seen": "2026-09-12T17:35:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass."
                }
            ],
            "references": [
                "https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_01882797386.html",
                "https://issues.chromium.org/issues/542403045",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85046",
                "https://github.com/Serotav/Writeups/blob/77556c57999805fa7815a114da51d91cf24fbea9/v8/When_Sorting_Leads_To_Confusion.md",
                "https://github.com/v8/v8/commit/e0562d87ad9c17042b581582c99237d798572e67",
                "https://news.ycombinator.com/item?id=49570669",
                "https://serotav.github.io/Writeups/v8/when-sorting-leads-to-confusion/",
                "https://github.com/atiilla/CVE-2026-85046",
                "https://github.com/SneakyNachos/CVE-2026-85046-who-put-the-silverback-guerilla-in-the-wasm",
                "https://github.com/Eliot-code/CVE-2026-85046",
                "https://github.com/adriyansyah-mf/cve-2026-85046-poc",
                "https://github.com/ubitquity/CVE-2026-85046-Patch-confusion-zero-day-vulnerability-in-Google-Chrome-s-V8-engine",
                "https://github.com/HORKimhab/CVE-2026-85046",
                "https://sploitus.com/exploit?id=14859BF6-CABE-54BE-AF18-C2152F60F38B",
                "https://github.com/SneakyNachos/CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass."
            ],
            "timeline": [
                {
                    "at": "2026-09-03T20:17:24.210",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85046"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-85038",
            "vendor": "Unknown",
            "product": "B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More",
            "title": "B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More vulnerability",
            "summary": "The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration.",
            "updated_at": "2026-09-06T11:18:06.253",
            "published_at": "2026-09-06T07:16:43.530",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.2.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during registration is one actually offered on the registration form, allowing unauthenticated users to assign themselves to restricted B2B customer groups and to skip the manual account-approval workflow during self-registration.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/a397aeaf-7629-45dd-a2ee-3e904cc19550/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T07:16:43.530",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85038"
                }
            ]
        },
        {
            "id": "CVE-2026-85025",
            "vendor": "IBM",
            "product": "Langflow OSS",
            "title": "Langflow OSS vulnerability",
            "summary": "IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.",
            "updated_at": "2026-09-12T04:16:44.783",
            "published_at": "2026-09-10T21:17:51.990",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through 1.11.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286666"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T21:17:51.990",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85025"
                }
            ]
        },
        {
            "id": "CVE-2026-85014",
            "vendor": "undici",
            "product": "undici",
            "title": "undici vulnerability",
            "summary": "undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an unclean close the internal socket-close handler calls abort on the writable stream unconditionally and discards the returned promise, but per the WHATWG Streams standard aborting a locked writable returns a promise that rejects with a TypeError. Because the application holds a writer on that writable, which is the only way to write, the rejection is never observed and Node's default unhandled-rejection behavior terminates the process. An untrusted server can therefore crash a client with a single abrupt disconnect, with no authentication and no application mistake. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.",
            "updated_at": "2026-09-15T14:09:06.380",
            "published_at": "2026-09-04T17:17:02.470",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.0.0 through before 7.29.1 (semver); 8.0.0 through before 8.10.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-248",
            "what_happened": "undici's experimental WebSocketStream client crashes the whole Node.js process when a remote peer closes the TCP connection without a WebSocket close handshake. On an unclean close the internal socket-close handler calls abort on the writable stream unconditionally and discards the returned promise, but per the WHATWG Streams standard aborting a locked writable returns a promise that rejects with a TypeError. Because the application holds a writer on that writable, which is the only way to write, the rejection is never observed and Node's default unhandled-rejection behavior terminates the process. An untrusted server can therefore crash a client with a single abrupt disconnect, with no authentication and no application mistake. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T17:17:02.470",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85014"
                }
            ]
        },
        {
            "id": "CVE-2026-85008",
            "vendor": "undici",
            "product": "undici",
            "title": "undici vulnerability",
            "summary": "undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is never placed in the skip list and instead falls through to the full cache-read path. The response-storage gate also lacked a method check, so a response to an unsafe request that is heuristically cacheable or carries an explicit Cache-Control directive is stored and later replayed from cache. Because response headers from a remote origin are untrusted, an origin can answer once with a cacheable status and then have the client's own subsequent state-changing requests to that path served from the stale cache entry without ever reaching the origin, an integrity failure that occurs under the interceptor's default configuration. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.",
            "updated_at": "2026-09-15T14:20:11.717",
            "published_at": "2026-09-04T17:17:02.347",
            "cvss": 3.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.0.0 through before 7.29.1 (semver); 8.0.0 through before 8.10.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-345",
            "what_happened": "undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from the set of safe methods, so an unsafe method such as POST, PUT, or DELETE is never placed in the skip list and instead falls through to the full cache-read path. The response-storage gate also lacked a method check, so a response to an unsafe request that is heuristically cacheable or carries an explicit Cache-Control directive is stored and later replayed from cache. Because response headers from a remote origin are untrusted, an origin can answer once with a cacheable status and then have the client's own subsequent state-changing requests to that path served from the stale cache entry without ever reaching the origin, an integrity failure that occurs under the interceptor's default configuration. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T17:17:02.347",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85008"
                }
            ]
        },
        {
            "id": "CVE-2026-84961",
            "vendor": "undici",
            "product": "undici",
            "title": "undici vulnerability",
            "summary": "undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2.",
            "updated_at": "2026-09-15T14:29:35.253",
            "published_at": "2026-09-04T17:17:02.227",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.24.1 through before 7.29.1 (semver); 8.0.0 through before 8.10.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T17:17:02.227",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84961"
                }
            ]
        },
        {
            "id": "CVE-2026-84947",
            "vendor": "undici",
            "product": "undici",
            "title": "undici vulnerability",
            "summary": "undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the interceptor aborts cleanly, but when a response has no Content-Length and is chunked, the interceptor instead signals completion early once the accumulated size reaches the maximum, without pausing or aborting the request. Because the underlying parser keeps delivering body bytes, a second completion signal fires and trips an internal assertion, which aborts the request and tears down the connection. The application is left observing a misleading successful status with an empty or truncated body while the connection has actually been disconnected. This affects undici versions from 7.1.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.",
            "updated_at": "2026-09-15T14:30:53.617",
            "published_at": "2026-09-04T17:17:02.103",
            "cvss": 3.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.1.0 through before 7.29.1 (semver); 8.0.0 through before 8.10.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-20",
            "what_happened": "undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, the interceptor aborts cleanly, but when a response has no Content-Length and is chunked, the interceptor instead signals completion early once the accumulated size reaches the maximum, without pausing or aborting the request. Because the underlying parser keeps delivering body bytes, a second completion signal fires and trips an internal assertion, which aborts the request and tears down the connection. The application is left observing a misleading successful status with an empty or truncated body while the connection has actually been disconnected. This affects undici versions from 7.1.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T17:17:02.103",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84947"
                }
            ]
        },
        {
            "id": "CVE-2026-84937",
            "vendor": "Unknown",
            "product": "Video Player for YouTube",
            "title": "Video Player for YouTube vulnerability",
            "summary": "The Video Player for YouTube  WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks and read arbitrary data from the database.",
            "updated_at": "2026-09-06T11:18:06.110",
            "published_at": "2026-09-05T07:17:14.963",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "The Video Player for YouTube  WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks and read arbitrary data from the database.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/5f81c233-8544-4a7b-a1c6-e447dc889a8d/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:14.963",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84937"
                }
            ]
        },
        {
            "id": "CVE-2026-84936",
            "vendor": "Unknown",
            "product": "EmbedPress",
            "title": "EmbedPress vulnerability",
            "summary": "The EmbedPress  WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows in the database.",
            "updated_at": "2026-09-06T11:18:05.970",
            "published_at": "2026-09-05T07:17:14.873",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.6.0 through before 4.6.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "The EmbedPress  WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows in the database.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/bd708c98-1657-423b-aa2b-14aa18307c03/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:14.873",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84936"
                }
            ]
        },
        {
            "id": "CVE-2026-84935",
            "vendor": "Unknown",
            "product": "HT Menu",
            "title": "HT Menu vulnerability",
            "summary": "The HT Menu  WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permissions such as Subscribers to store JavaScript that executes in the browser of any visitor, administrators included, who views the affected menu.",
            "updated_at": "2026-09-06T11:18:05.827",
            "published_at": "2026-09-05T07:17:14.783",
            "cvss": 8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.2.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The HT Menu  WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those stored settings when the menu is rendered, allowing users with minimal permissions such as Subscribers to store JavaScript that executes in the browser of any visitor, administrators included, who views the affected menu.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/10aeb456-764d-4f4d-a2c9-e357474d59c7/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:14.783",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84935"
                }
            ]
        },
        {
            "id": "CVE-2026-84934",
            "vendor": "Unknown",
            "product": "JCH Optimize",
            "title": "JCH Optimize vulnerability",
            "summary": "The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the site.",
            "updated_at": "2026-09-06T11:18:05.680",
            "published_at": "2026-09-05T07:17:14.690",
            "cvss": 8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 6.0.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal action runs, allowing any authenticated users such as Subscribers to import arbitrary JCH Optimize WordPress plugin before 6.0.1 settings and store a script that executes in the browser of any visitor or administrator viewing the site.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/d808ad17-d20e-4ee5-94f3-935c10cde772/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:14.690",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84934"
                }
            ]
        },
        {
            "id": "CVE-2026-84933",
            "vendor": "undici",
            "product": "undici",
            "title": "undici vulnerability",
            "summary": "undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example one marked with a public and max-age directive, is stored and then re-served to a later caller that matches the same cache key. As a result one caller's cookie is disclosed to a different caller, and an untrusted server can inject cookies into cached responses served to all subsequent callers. This violates the requirement that a shared cache must not store cookies. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.",
            "updated_at": "2026-09-15T14:38:55.600",
            "published_at": "2026-09-04T17:17:01.973",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.0.0 through before 7.29.1 (semver); 8.0.0 through before 8.10.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-200",
            "what_happened": "undici's cache interceptor does not handle the Set-Cookie response header anywhere in its cache path, so it neither refuses to store nor strips that header. In shared cache mode, which is the default, an otherwise cacheable response that carries a Set-Cookie header, for example one marked with a public and max-age directive, is stored and then re-served to a later caller that matches the same cache key. As a result one caller's cookie is disclosed to a different caller, and an untrusted server can inject cookies into cached responses served to all subsequent callers. This violates the requirement that a shared cache must not store cookies. This affects undici versions from 7.0.0 up to 7.29.1 and from 8.0.0 up to 8.10.2. Users should upgrade to undici 7.29.1 or 8.10.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T17:17:01.973",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84933"
                }
            ]
        },
        {
            "id": "CVE-2026-84931",
            "vendor": "Unknown",
            "product": "Joli Table Of Contents",
            "title": "Joli Table Of Contents vulnerability",
            "summary": "The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute in the browser of any user who views the post, including higher-privileged users such as administrators. This crosses a privilege boundary even on multisite, where such users are not permitted to post unfiltered HTML.",
            "updated_at": "2026-09-06T11:18:05.537",
            "published_at": "2026-09-05T07:17:14.600",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.0.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, allowing users with the Author role and above to inject arbitrary HTML attributes and JavaScript that execute in the browser of any user who views the post, including higher-privileged users such as administrators. This crosses a privilege boundary even on multisite, where such users are not permitted to post unfiltered HTML.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/0dc8747c-14c2-4bb2-9b99-7978ff5128f5/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:14.600",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84931"
                }
            ]
        },
        {
            "id": "CVE-2026-84930",
            "vendor": "Unknown",
            "product": "CatFolders Document Gallery & PDF Library",
            "title": "CatFolders Document Gallery & PDF Library vulnerability",
            "summary": "The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected post.",
            "updated_at": "2026-09-06T11:18:05.397",
            "published_at": "2026-09-05T07:17:14.503",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.0.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery output, allowing users with the Author role and above to inject arbitrary web scripts that execute in the browser of anyone who views the affected post.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/c38b69f2-60cb-46b3-aa81-451ac062f5c7/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:14.503",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84930"
                }
            ]
        },
        {
            "id": "CVE-2026-84927",
            "vendor": "Unknown",
            "product": "EmbedPress",
            "title": "EmbedPress vulnerability",
            "summary": "The EmbedPress  WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site.",
            "updated_at": "2026-09-06T11:18:05.253",
            "published_at": "2026-09-05T07:17:14.410",
            "cvss": 2.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.6.0 through before 4.6.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The EmbedPress  WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/12984501-5d93-4941-9e12-6bb8049bd23d/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:14.410",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84927"
                }
            ]
        },
        {
            "id": "CVE-2026-84926",
            "vendor": "Unknown",
            "product": "EmbedPress",
            "title": "EmbedPress vulnerability",
            "summary": "The EmbedPress  WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role.",
            "updated_at": "2026-09-06T11:18:05.110",
            "published_at": "2026-09-05T07:17:14.317",
            "cvss": 2.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.6.0 through before 4.6.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The EmbedPress  WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/5f1bc0f2-1112-4f75-b2b6-27498e43cd4b/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:14.317",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84926"
                }
            ]
        },
        {
            "id": "CVE-2026-84901",
            "vendor": "Unknown",
            "product": "Eventin",
            "title": "Eventin vulnerability",
            "summary": "The Eventin  WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.",
            "updated_at": "2026-09-06T11:18:04.970",
            "published_at": "2026-09-05T07:17:14.227",
            "cvss": 4.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.1.22 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The Eventin  WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level access and above to change the site's front-page setting to an event they do not own and to create, edit and delete global event and speaker taxonomy terms they should not be able to manage.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/b1906fd4-82ab-435f-bb07-e8f2db402029/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:14.227",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84901"
                }
            ]
        },
        {
            "id": "CVE-2026-84899",
            "vendor": "Unknown",
            "product": "VikWidgetsLoader",
            "title": "VikWidgetsLoader vulnerability",
            "summary": "The VikWidgetsLoader  WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who reviews the pending submission.",
            "updated_at": "2026-09-06T11:18:04.830",
            "published_at": "2026-09-05T07:17:14.127",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.11.0 through before 1.12.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The VikWidgetsLoader  WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Contributor role to store arbitrary JavaScript that executes in the browser of any user viewing the affected post, including the administrator who reviews the pending submission.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/4e0beb72-d73b-4802-894d-141aadbd8d4f/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:14.127",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84899"
                }
            ]
        },
        {
            "id": "CVE-2026-84898",
            "vendor": "Unknown",
            "product": "Eventin",
            "title": "Eventin vulnerability",
            "summary": "The Eventin  WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files.",
            "updated_at": "2026-09-06T11:18:04.683",
            "published_at": "2026-09-05T07:17:14.033",
            "cvss": 6.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.1.21 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-22",
            "what_happened": "The Eventin  WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level access and above to include and execute arbitrary local PHP files.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/d8dea263-5676-4e3c-9ea4-36904e1ac4d3/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:14.033",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84898"
                }
            ]
        },
        {
            "id": "CVE-2026-84896",
            "vendor": "Unknown",
            "product": "King Addons for Elementor",
            "title": "King Addons for Elementor vulnerability",
            "summary": "The King Addons for Elementor  WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators.",
            "updated_at": "2026-09-06T11:18:04.537",
            "published_at": "2026-09-05T07:17:13.940",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 51.1.77 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The King Addons for Elementor  WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with Contributor-level access and above to store JavaScript that executes in the browser of any visitor to the affected page, including logged-in administrators.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/fe9ac024-53dc-48a3-99c8-1ec97c84c959/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:13.940",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84896"
                }
            ]
        },
        {
            "id": "CVE-2026-84889",
            "vendor": "IBM",
            "product": "Langflow OSS",
            "title": "Langflow OSS vulnerability",
            "summary": "IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.",
            "updated_at": "2026-09-12T16:16:42.053",
            "published_at": "2026-09-10T22:17:04.347",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through 1.10.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286656"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:17:04.347",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84889"
                }
            ]
        },
        {
            "id": "CVE-2026-84869",
            "vendor": "ConnectWise",
            "product": "ScreenConnect",
            "title": "ScreenConnect vulnerability",
            "summary": "A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.",
            "updated_at": "2026-09-12T04:16:42.757",
            "published_at": "2026-09-08T20:18:51.147",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "All versions prior to 26.6.5",
            "fixed": "See vendor advisory",
            "source_count": 23,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ConnectWise-Advisories/Disclosures/tree/main/CVE-2026-84869",
                "https://www.connectwise.com/company/trust/advisories",
                "https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-84869",
                "https://www.huntress.com/blog/rogue-screenconnect-installations"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T20:18:51.147",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84869"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-84745",
            "vendor": "Unknown",
            "product": "The Events Calendar",
            "title": "The Events Calendar vulnerability",
            "summary": "The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full contents of every unpublished record on the site, including other users'.",
            "updated_at": "2026-09-06T11:18:04.383",
            "published_at": "2026-09-05T07:17:13.850",
            "cvss": 2.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 6.17.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read it on its public REST archives, allowing users with a low-privilege role such as contributor to read the full contents of every unpublished record on the site, including other users'.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/cf23ee00-322c-4443-a50d-a91f90d179aa/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:13.850",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84745"
                }
            ]
        },
        {
            "id": "CVE-2026-84732",
            "vendor": "OpenVPN",
            "product": "OpenVPN",
            "title": "OpenVPN vulnerability",
            "summary": "Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow",
            "updated_at": "2026-09-07T09:17:16.840",
            "published_at": "2026-09-07T09:17:16.840",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.6.22 (semver); 0 through 2.7.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://community.openvpn.net/Security%20Announcements/CVE-2026-84732"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T09:17:16.840",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84732"
                }
            ]
        },
        {
            "id": "CVE-2026-84657",
            "vendor": "Jenkins Project",
            "product": "Jenkins",
            "title": "Jenkins vulnerability",
            "summary": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users.",
            "updated_at": "2026-09-15T18:05:47.627",
            "published_at": "2026-09-02T16:17:30.373",
            "cvss": 4.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "up to 2.568.2; up to 2.579",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-862",
            "what_happened": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allowing attackers with Item/Build permission to cancel builds started by other users.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-4015"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T16:17:30.373",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84657"
                }
            ]
        },
        {
            "id": "CVE-2026-84656",
            "vendor": "Jenkins Project",
            "product": "Jenkins",
            "title": "Jenkins vulnerability",
            "summary": "A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to.",
            "updated_at": "2026-09-15T18:06:43.853",
            "published_at": "2026-09-02T16:17:30.273",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "up to 2.568.2; up to 2.579",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they have no access to.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-4006"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T16:17:30.273",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84656"
                }
            ]
        },
        {
            "id": "CVE-2026-84655",
            "vendor": "Jenkins Project",
            "product": "Jenkins",
            "title": "Jenkins vulnerability",
            "summary": "Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.",
            "updated_at": "2026-09-15T18:07:05.090",
            "published_at": "2026-09-02T16:17:30.177",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "up to 2.568.2; up to 2.579",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-116",
            "what_happened": "Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to inject arbitrary fields into JSON and Python API responses.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-3879"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T16:17:30.177",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84655"
                }
            ]
        },
        {
            "id": "CVE-2026-84653",
            "vendor": "Jenkins Project",
            "product": "Jenkins",
            "title": "Jenkins vulnerability",
            "summary": "Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.",
            "updated_at": "2026-09-15T18:15:37.527",
            "published_at": "2026-09-02T16:17:29.983",
            "cvss": 3.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.421 through 2.579; 2.426.1 through 2.568.2",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-3981"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T16:17:29.983",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84653"
                }
            ]
        },
        {
            "id": "CVE-2026-84652",
            "vendor": "Jenkins Project",
            "product": "Jenkins",
            "title": "Jenkins vulnerability",
            "summary": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the \"remember me\" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the \"remember me\" cookie, grants the attacker access to Jenkins as that user.",
            "updated_at": "2026-09-11T21:09:18.967",
            "published_at": "2026-09-02T16:17:29.893",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.568.3; before 2.580",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-384",
            "what_happened": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the \"remember me\" cookie, allowing attackers able to serve content on the same site as Jenkins to set a known session cookie in the victim's browser, which after the victim authenticates via the \"remember me\" cookie, grants the attacker access to Jenkins as that user.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-4016"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T16:17:29.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84652"
                }
            ]
        },
        {
            "id": "CVE-2026-84651",
            "vendor": "Jenkins Project",
            "product": "Jenkins",
            "title": "Jenkins vulnerability",
            "summary": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers with Agent/Configure permission on one agent to take over a different agent, gaining control of its configuration and obtaining access to its inbound agent secret and environment variables.",
            "updated_at": "2026-09-11T21:16:20.667",
            "published_at": "2026-09-02T16:17:29.803",
            "cvss": 6.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.568.3; before 2.580",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by specifying that agent's name in the submitted XML document, allowing attackers with Agent/Configure permission on one agent to take over a different agent, gaining control of its configuration and obtaining access to its inbound agent secret and environment variables.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-4025"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T16:17:29.803",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84651"
                }
            ]
        },
        {
            "id": "CVE-2026-84650",
            "vendor": "Jenkins Project",
            "product": "Jenkins",
            "title": "Jenkins vulnerability",
            "summary": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.",
            "updated_at": "2026-09-11T21:16:02.740",
            "published_at": "2026-09-02T16:17:29.713",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.568.3; before 2.580",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-4032"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T16:17:29.713",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84650"
                }
            ]
        },
        {
            "id": "CVE-2026-84648",
            "vendor": "Jenkins Project",
            "product": "Jenkins",
            "title": "Jenkins vulnerability",
            "summary": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.",
            "updated_at": "2026-09-11T21:14:57.963",
            "published_at": "2026-09-02T16:17:29.527",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.568.3; before 2.580",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-3967"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T16:17:29.527",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84648"
                }
            ]
        },
        {
            "id": "CVE-2026-84646",
            "vendor": "Jenkins Project",
            "product": "Jenkins",
            "title": "Jenkins vulnerability",
            "summary": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.",
            "updated_at": "2026-09-11T21:15:45.160",
            "published_at": "2026-09-02T16:17:29.313",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.568.3; before 2.580",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user objects by submitting crafted XML.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-3908"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T16:17:29.313",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84646"
                }
            ]
        },
        {
            "id": "CVE-2026-84645",
            "vendor": "Jenkins Project",
            "product": "Jenkins",
            "title": "Jenkins vulnerability",
            "summary": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution.",
            "updated_at": "2026-09-11T21:15:29.510",
            "published_at": "2026-09-02T16:17:29.193",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.568.3; before 2.580",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jenkins.io/security/advisory/2026-09-02/#SECURITY-3972"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T16:17:29.193",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84645"
                }
            ]
        },
        {
            "id": "CVE-2026-84632",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.",
            "updated_at": "2026-09-16T04:18:45.510",
            "published_at": "2026-09-14T21:17:38.153",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.7 (custom); before 27 (custom); before 15.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/149034",
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038",
                "https://support.apple.com/en-us/149041",
                "https://support.apple.com/en-us/149042",
                "https://support.apple.com/en-us/149043"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:38.153",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84632"
                }
            ]
        },
        {
            "id": "CVE-2026-84611",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.",
            "updated_at": "2026-09-16T04:18:43.913",
            "published_at": "2026-09-14T21:17:36.240",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.7 (custom); before 27 (custom); before 15.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a maliciously crafted 3D model may lead to memory corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/149034",
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038",
                "https://support.apple.com/en-us/149041",
                "https://support.apple.com/en-us/149042",
                "https://support.apple.com/en-us/149043"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:36.240",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84611"
                }
            ]
        },
        {
            "id": "CVE-2026-84607",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "A race condition was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A sandboxed app may be able to execute arbitrary code with kernel privileges.",
            "updated_at": "2026-09-16T04:18:43.600",
            "published_at": "2026-09-14T21:17:36.033",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.7 (custom); before 27 (custom); before 15.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "A race condition was addressed with improved state management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. A sandboxed app may be able to execute arbitrary code with kernel privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/149034",
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038",
                "https://support.apple.com/en-us/149041",
                "https://support.apple.com/en-us/149042",
                "https://support.apple.com/en-us/149043"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:36.033",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84607"
                }
            ]
        },
        {
            "id": "CVE-2026-84515",
            "vendor": "Apple",
            "product": "macOS",
            "title": "macOS vulnerability",
            "summary": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to kernel memory corruption.",
            "updated_at": "2026-09-16T04:18:43.280",
            "published_at": "2026-09-14T21:17:28.043",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 15.8 (custom); before 26.7 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious SMB server may lead to kernel memory corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149042",
                "https://support.apple.com/en-us/149043"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:28.043",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84515"
                }
            ]
        },
        {
            "id": "CVE-2026-84506",
            "vendor": "Apple",
            "product": "macOS",
            "title": "macOS vulnerability",
            "summary": "A use after free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to execute arbitrary code with kernel privileges.",
            "updated_at": "2026-09-16T04:18:42.980",
            "published_at": "2026-09-14T21:17:27.180",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 15.8 (custom); before 26.7 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A use after free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to execute arbitrary code with kernel privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149042",
                "https://support.apple.com/en-us/149043"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:27.180",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84506"
                }
            ]
        },
        {
            "id": "CVE-2026-84504",
            "vendor": "fastify",
            "product": "fastify",
            "title": "fastify vulnerability",
            "summary": "fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the root, fastify replaces the entire request body with that property's value before the handler runs, so the handler receives a different object than the one that satisfied the schema. An authenticated low-privilege caller can use this to make nested data replace the validated body and trigger an operation the route schema did not authorize, leading to unauthorized state changes and data disclosure. Users should upgrade to fastify 5.12.2 or later.",
            "updated_at": "2026-09-15T20:05:15.050",
            "published_at": "2026-09-04T10:17:13.790",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.12.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If a request that passes its route schema contains a property named value at the root, fastify replaces the entire request body with that property's value before the handler runs, so the handler receives a different object than the one that satisfied the schema. An authenticated low-privilege caller can use this to make nested data replace the validated body and trigger an operation the route schema did not authorize, leading to unauthorized state changes and data disclosure. Users should upgrade to fastify 5.12.2 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/fastify/fastify/security/advisories/GHSA-667r-xxjv-c9mm"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T10:17:13.790",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84504"
                }
            ]
        },
        {
            "id": "CVE-2026-84469",
            "vendor": "fastify",
            "product": "fastify",
            "title": "fastify vulnerability",
            "summary": "fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance. When an application assigns false to a route's body, querystring, params, or headers schema to deny all input, fastify treats it as a missing schema, compiles no validator, and runs the route handler on any request. An unauthenticated remote client can therefore reach a handler that a valid deny-all schema was intended to make unreachable, a complete validation bypass that can lead to unauthorized state changes or execution of disabled operations. Users should upgrade to fastify 5.12.2 or later.",
            "updated_at": "2026-09-15T20:06:50.543",
            "published_at": "2026-09-04T10:17:13.677",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.12.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as a valid schema that rejects every instance. When an application assigns false to a route's body, querystring, params, or headers schema to deny all input, fastify treats it as a missing schema, compiles no validator, and runs the route handler on any request. An unauthenticated remote client can therefore reach a handler that a valid deny-all schema was intended to make unreachable, a complete validation bypass that can lead to unauthorized state changes or execution of disabled operations. Users should upgrade to fastify 5.12.2 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/fastify/fastify/security/advisories/GHSA-hwr6-493r-vm6h"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T10:17:13.677",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84469"
                }
            ]
        },
        {
            "id": "CVE-2026-84428",
            "vendor": "fastify",
            "product": "fastify",
            "title": "fastify vulnerability",
            "summary": "fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and the root-level required array, and does not lowercase the trigger and dependent names inside the JSON Schema Draft 7 dependencies keyword. Because Node stores request header names in lowercase, a canonical-case dependency such as requiring an authentication header whenever a privileged-mode header is present never matches, and the presence assertion is silently skipped. An unauthenticated remote client can therefore send the header that activates a privileged branch while omitting the header the dependency was meant to require, bypassing the conditional check. Users should upgrade to fastify 5.12.2 or later.",
            "updated_at": "2026-09-15T19:54:32.420",
            "published_at": "2026-09-04T11:17:19.317",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.12.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-178",
            "what_happened": "fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the transformation is incomplete: it lowercases the properties keys and the root-level required array, and does not lowercase the trigger and dependent names inside the JSON Schema Draft 7 dependencies keyword. Because Node stores request header names in lowercase, a canonical-case dependency such as requiring an authentication header whenever a privileged-mode header is present never matches, and the presence assertion is silently skipped. An unauthenticated remote client can therefore send the header that activates a privileged branch while omitting the header the dependency was meant to require, bypassing the conditional check. Users should upgrade to fastify 5.12.2 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/fastify/fastify/security/advisories/GHSA-9q9j-q6p8-xq58"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T11:17:19.317",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84428"
                }
            ]
        },
        {
            "id": "CVE-2026-84393",
            "vendor": "Fortinet",
            "product": "FortiOS",
            "title": "FortiOS vulnerability",
            "summary": "A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>",
            "updated_at": "2026-09-10T04:18:18.120",
            "published_at": "2026-09-08T17:18:37.883",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.6.1 through 7.6.6 (semver); 7.6.2 through 7.6.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-297",
            "what_happened": "A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via <insert attack vector here>",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://fortiguard.fortinet.com/psirt/FG-IR-26-174"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T17:18:37.883",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84393"
                }
            ]
        },
        {
            "id": "CVE-2026-84389",
            "vendor": "Fortinet",
            "product": "FortiSIEM",
            "title": "FortiSIEM vulnerability",
            "summary": "A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here>",
            "updated_at": "2026-09-10T04:18:17.983",
            "published_at": "2026-09-08T17:18:37.410",
            "cvss": 3.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.5.0 through 7.5.1 (semver); 7.4.1 through 7.4.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-601",
            "what_happened": "A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here>",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://fortiguard.fortinet.com/psirt/FG-IR-26-169"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T17:18:37.410",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84389"
                }
            ]
        },
        {
            "id": "CVE-2026-84385",
            "vendor": "Fortinet",
            "product": "FortiSOAR on-premise",
            "title": "FortiSOAR on-premise vulnerability",
            "summary": "A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to escalation of privilege via <insert attack vector here>",
            "updated_at": "2026-09-10T04:18:17.837",
            "published_at": "2026-09-08T17:18:37.030",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.6.0 through 7.6.6 (semver); 7.5.0 through 7.5.3 (semver); 7.4.0 through 7.4.5 (semver); 7.3.0 through 7.3.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.6, FortiSOAR on-premise 7.5.0 through 7.5.3, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to escalation of privilege via <insert attack vector here>",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://fortiguard.fortinet.com/psirt/FG-IR-26-164"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T17:18:37.030",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84385"
                }
            ]
        },
        {
            "id": "CVE-2026-84256",
            "vendor": "OpenVPN",
            "product": "OpenVPN",
            "title": "OpenVPN vulnerability",
            "summary": "An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject",
            "updated_at": "2026-09-07T08:17:13.777",
            "published_at": "2026-09-07T08:17:13.777",
            "cvss": 7.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.1_rc10 through 2.6.22 (semver); 2.7_alpha1 through 2.7.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://community.openvpn.net/Security%20Announcements/CVE-2026-84256"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:17:13.777",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84256"
                }
            ]
        },
        {
            "id": "CVE-2026-84226",
            "vendor": "OpenVPN",
            "product": "OpenVPN",
            "title": "OpenVPN vulnerability",
            "summary": "OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps",
            "updated_at": "2026-09-07T08:17:13.653",
            "published_at": "2026-09-07T08:17:13.653",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.5.0 through 2.6.22 (semver); 2.7_alpha1 through 2.7.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-426",
            "what_happened": "OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://community.openvpn.net/Security%20Announcements/CVE-2026-84226"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:17:13.653",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84226"
                }
            ]
        },
        {
            "id": "CVE-2026-84225",
            "vendor": "Unknown",
            "product": "Kirki",
            "title": "Kirki vulnerability",
            "summary": "The Kirki  WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.",
            "updated_at": "2026-09-06T11:18:04.237",
            "published_at": "2026-09-05T07:17:13.760",
            "cvss": 2.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.0.0 through before 6.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-639",
            "what_happened": "The Kirki  WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before changing its state, allowing users whom an administrator has granted content-level access to the page builder to modify comments left by other users, including on pages they cannot themselves open.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/9f83f0a2-7d77-49a2-a23a-03f787e2e356/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:13.760",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84225"
                }
            ]
        },
        {
            "id": "CVE-2026-84221",
            "vendor": "Unknown",
            "product": "Kirki",
            "title": "Kirki vulnerability",
            "summary": "The Kirki  WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.",
            "updated_at": "2026-09-06T11:18:04.093",
            "published_at": "2026-09-05T07:17:13.667",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.0.0 through before 6.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "The Kirki  WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to append arbitrary SQL and read the contents of the database, including user credentials.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/6c34da62-46fb-4dd4-a433-bd3df4d9fcfd/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:13.667",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84221"
                }
            ]
        },
        {
            "id": "CVE-2026-84219",
            "vendor": "Unknown",
            "product": "Kirki",
            "title": "Kirki vulnerability",
            "summary": "The Kirki  WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments.",
            "updated_at": "2026-09-06T11:18:03.950",
            "published_at": "2026-09-06T07:16:43.427",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.2.1 through before 6.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-79",
            "what_happened": "The Kirki  WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a comment which then runs in the session of anyone viewing a page that displays it, including an administrator, and on every page of the site when its header or footer is built to show comments.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/e95bd1e3-6f61-423f-add6-519e1ca7bf66/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T07:16:43.427",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84219"
                }
            ]
        },
        {
            "id": "CVE-2026-84186",
            "vendor": "PrestaShop",
            "product": "PrestaShop",
            "title": "PrestaShop vulnerability",
            "summary": "Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse proxy, load balancer or CDN. The application incorrectly processes the IP address string and uses the address controlled by the visitor rather than the one provided by the trusted infrastructure, allowing an unauthenticated remote attacker to cause the application to interpret their connection as originating from an arbitrary IP address. This condition allows IP-based controls, such as the maintenance mode allowlist, to be bypassed, as well as enabling the forgery of security and audit logs and the evasion of third-party mechanisms that rely on the IP address, such as geolocation checks, fraud detection or request throttling.",
            "updated_at": "2026-09-07T09:17:16.693",
            "published_at": "2026-09-07T09:17:16.693",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 9.1.5 (custom); before 8.2.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-290",
            "what_happened": "Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when the application is running behind a reverse proxy, load balancer or CDN. The application incorrectly processes the IP address string and uses the address controlled by the visitor rather than the one provided by the trusted infrastructure, allowing an unauthenticated remote attacker to cause the application to interpret their connection as originating from an arbitrary IP address. This condition allows IP-based controls, such as the maintenance mode allowlist, to be bypassed, as well as enabling the forgery of security and audit logs and the evasion of third-party mechanisms that rely on the IP address, such as geolocation checks, fraud detection or request throttling.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.incibe.es/en/incibe-cert/notices/aviso/incorrect-access-control-prestashop"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T09:17:16.693",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84186"
                }
            ]
        },
        {
            "id": "CVE-2026-84171",
            "vendor": "Unknown",
            "product": "WP images upload on piclect",
            "title": "WP images upload on piclect vulnerability",
            "summary": "The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.",
            "updated_at": "2026-09-12T16:16:41.897",
            "published_at": "2026-09-12T06:16:27.137",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a publicly accessible directory, allowing unauthenticated attackers to upload arbitrary files and execute arbitrary code on the server.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/e5b9fd87-92a7-4fc6-b8b2-896b87d97c40/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:27.137",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84171"
                }
            ]
        },
        {
            "id": "CVE-2026-84099",
            "vendor": "Unknown",
            "product": "wpstorecart",
            "title": "wpstorecart vulnerability",
            "summary": "The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.",
            "updated_at": "2026-09-12T16:16:41.670",
            "published_at": "2026-09-12T06:16:27.020",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 5.0.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-502",
            "what_happened": "The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, allowing unauthenticated attackers to inject arbitrary PHP objects, which may be escalated further when a suitable gadget chain is present on the site.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/11d36ab2-ac8d-42cf-91c0-dea55d7edc9a/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:27.020",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84099"
                }
            ]
        },
        {
            "id": "CVE-2026-84047",
            "vendor": "Unknown",
            "product": "Album Cover Finder",
            "title": "Album Cover Finder vulnerability",
            "summary": "The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.",
            "updated_at": "2026-09-12T16:16:41.527",
            "published_at": "2026-09-12T06:16:26.910",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.7.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/eebacbae-4b25-45b5-96d9-f5ba28dfd825/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:26.910",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84047"
                }
            ]
        },
        {
            "id": "CVE-2026-84028",
            "vendor": "Unknown",
            "product": "Bold Page Builder",
            "title": "Bold Page Builder vulnerability",
            "summary": "The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.",
            "updated_at": "2026-09-06T11:18:03.790",
            "published_at": "2026-09-06T07:16:43.320",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.9.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/6abd5d49-af3a-4515-ba33-57b56a9fba4e/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T07:16:43.320",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84028"
                }
            ]
        },
        {
            "id": "CVE-2026-84025",
            "vendor": "Unknown",
            "product": "BEAR",
            "title": "BEAR vulnerability",
            "summary": "The BEAR  WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadable file URLs and private product metadata.",
            "updated_at": "2026-09-12T16:16:41.390",
            "published_at": "2026-09-12T06:16:26.700",
            "cvss": 2.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.2.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-639",
            "what_happened": "The BEAR  WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who are restricted to their own products to read other owners' product information, including protected downloadable file URLs and private product metadata.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/468a9f1a-1a16-410f-97a0-8a87a974df21/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:26.700",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84025"
                }
            ]
        },
        {
            "id": "CVE-2026-84024",
            "vendor": "Unknown",
            "product": "BEAR",
            "title": "BEAR vulnerability",
            "summary": "The BEAR  WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.",
            "updated_at": "2026-09-12T16:16:41.250",
            "published_at": "2026-09-12T06:16:26.573",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.2.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-352",
            "what_happened": "The BEAR  WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration by tricking a logged-in administrator into visiting a crafted page.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/8ea75cb0-e6f0-4ea4-a70f-f9c4e2e16681/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:26.573",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84024"
                }
            ]
        },
        {
            "id": "CVE-2026-84023",
            "vendor": "Unknown",
            "product": "BEAR",
            "title": "BEAR vulnerability",
            "summary": "The BEAR  WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafted page.",
            "updated_at": "2026-09-12T16:16:41.113",
            "published_at": "2026-09-12T06:16:26.467",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.2.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-352",
            "what_happened": "The BEAR  WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify arbitrary terms by tricking a logged-in privileged user into visiting a crafted page.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/7adbb52f-94e2-425e-9930-2ab856961b63/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:26.467",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84023"
                }
            ]
        },
        {
            "id": "CVE-2026-84022",
            "vendor": "Unknown",
            "product": "Bold Page Builder",
            "title": "Bold Page Builder vulnerability",
            "summary": "The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.",
            "updated_at": "2026-09-06T11:18:03.613",
            "published_at": "2026-09-05T07:17:13.573",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.9.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user views the affected page.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/53bbe80c-caea-4893-82a6-03e5173390de/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:13.573",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84022"
                }
            ]
        },
        {
            "id": "CVE-2026-84021",
            "vendor": "Unknown",
            "product": "Bold Page Builder",
            "title": "Bold Page Builder vulnerability",
            "summary": "The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user clicks the affected link.",
            "updated_at": "2026-09-06T11:18:03.473",
            "published_at": "2026-09-05T07:17:13.470",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.9.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when a user clicks the affected link.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/ca226eab-59a2-42d5-96f6-84dacf7c6c5a/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:13.470",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84021"
                }
            ]
        },
        {
            "id": "CVE-2026-83991",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809",
            "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
            "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
            "updated_at": "2026-09-09T20:14:54.747",
            "published_at": "2026-09-08T18:21:09.823",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 89,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                },
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-54121-Certighost",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost",
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83991"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:10:10Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                },
                {
                    "at": "2026-09-08T18:21:09.823",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83991"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
            "enrichment_checked_at": "2026-09-12T10:05:19Z"
        },
        {
            "id": "CVE-2026-83987",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:42.333",
            "published_at": "2026-09-08T18:21:09.180",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83987"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:21:09.180",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83987"
                }
            ]
        },
        {
            "id": "CVE-2026-83985",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:41.767",
            "published_at": "2026-09-08T18:21:08.840",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83985"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:21:08.840",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83985"
                }
            ]
        },
        {
            "id": "CVE-2026-83983",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:41.540",
            "published_at": "2026-09-08T18:21:08.660",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83983"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:21:08.660",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83983"
                }
            ]
        },
        {
            "id": "CVE-2026-83982",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:41.330",
            "published_at": "2026-09-08T18:21:08.490",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83982"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:21:08.490",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83982"
                }
            ]
        },
        {
            "id": "CVE-2026-83981",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:41.143",
            "published_at": "2026-09-08T18:21:08.323",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83981"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:21:08.323",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83981"
                }
            ]
        },
        {
            "id": "CVE-2026-83980",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:40.970",
            "published_at": "2026-09-08T18:21:08.163",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83980"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:21:08.163",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83980"
                }
            ]
        },
        {
            "id": "CVE-2026-83978",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:40.780",
            "published_at": "2026-09-08T18:21:07.833",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83978"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:21:07.833",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83978"
                }
            ]
        },
        {
            "id": "CVE-2026-83977",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:40.603",
            "published_at": "2026-09-08T18:21:07.667",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83977"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:21:07.667",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83977"
                }
            ]
        },
        {
            "id": "CVE-2026-83973",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:40.420",
            "published_at": "2026-09-08T18:21:06.997",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83973"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:21:06.997",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83973"
                }
            ]
        },
        {
            "id": "CVE-2026-83972",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:40.243",
            "published_at": "2026-09-08T18:21:06.833",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83972"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:21:06.833",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83972"
                }
            ]
        },
        {
            "id": "CVE-2026-83971",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:40.060",
            "published_at": "2026-09-08T18:21:06.670",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83971"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:21:06.670",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83971"
                }
            ]
        },
        {
            "id": "CVE-2026-83970",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:39.877",
            "published_at": "2026-09-08T18:21:06.480",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83970"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:21:06.480",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83970"
                }
            ]
        },
        {
            "id": "CVE-2026-83967",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:39.700",
            "published_at": "2026-09-08T18:21:05.983",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83967"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:21:05.983",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83967"
                }
            ]
        },
        {
            "id": "CVE-2026-83954",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:39.507",
            "published_at": "2026-09-08T18:21:05.660",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83954"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:21:05.660",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83954"
                }
            ]
        },
        {
            "id": "CVE-2026-83711",
            "vendor": "Microsoft",
            "product": "Entra",
            "title": "Entra vulnerability",
            "summary": "Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-05T04:18:05.063",
            "published_at": "2026-09-03T23:17:20.500",
            "cvss": 10,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "-",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83711"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T23:17:20.500",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83711"
                }
            ]
        },
        {
            "id": "CVE-2026-83628",
            "vendor": "jfarthing84",
            "product": "Theme My Login",
            "title": "Theme My Login vulnerability",
            "summary": "The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the `tml_ms_signup_handler()` function's `gimmeanotherblog` branch failing to enforce the network's `active_signup` registration policy, checking only `is_user_logged_in()` while sibling branches such as `validate-blog-signup` apply the full policy gate. This makes it possible for authenticated attackers, with Subscriber-level access and above, to directly POST `stage=gimmeanotherblog` to Theme My Login's signup route, bypassing the configured registration policy entirely — even when it is set to `none` or `user` — which causes `wpmu_create_blog()` to execute with the attacker's user ID, after which WordPress core assigns the Administrator role on the newly created subsite via `add_user_to_blog()`. The privilege gain is scoped to the newly created subsite only; the attacker's account retains Subscriber-level access on the main site and does not obtain Super Admin or network-level capabilities such as `manage_network` or `manage_sites`.",
            "updated_at": "2026-09-05T06:17:10.230",
            "published_at": "2026-09-05T06:17:10.230",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 7.1.15 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the `tml_ms_signup_handler()` function's `gimmeanotherblog` branch failing to enforce the network's `active_signup` registration policy, checking only `is_user_logged_in()` while sibling branches such as `validate-blog-signup` apply the full policy gate. This makes it possible for authenticated attackers, with Subscriber-level access and above, to directly POST `stage=gimmeanotherblog` to Theme My Login's signup route, bypassing the configured registration policy entirely — even when it is set to `none` or `user` — which causes `wpmu_create_blog()` to execute with the attacker's user ID, after which WordPress core assigns the Administrator role on the newly created subsite via `add_user_to_blog()`. The privilege gain is scoped to the newly created subsite only; the attacker's account retains Subscriber-level access on the main site and does not obtain Super Admin or network-level capabilities such as `manage_network` or `manage_sites`.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/theme-my-login/tags/7.1.15/includes/ms-functions.php#L580",
                "https://plugins.trac.wordpress.org/browser/theme-my-login/tags/7.1.15/includes/ms-functions.php#L661",
                "https://plugins.trac.wordpress.org/browser/theme-my-login/tags/7.1.15/includes/ms-functions.php#L708",
                "https://plugins.trac.wordpress.org/changeset/3669721/theme-my-login/trunk/includes/ms-functions.php",
                "https://plugins.trac.wordpress.org/changeset?old_path=%2Ftheme-my-login/tags/7.1.15&new_path=%2Ftheme-my-login/tags/7.2.0",
                "https://plugins.trac.wordpress.org/changeset?reponame=&new=3669722%40theme-my-login%2Ftags%2F7.2.0&old=3643898%40theme-my-login%2Ftags%2F7.1.15",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/72585c12-baa9-4c63-8584-906a1d3b332f?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T06:17:10.230",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83628"
                }
            ]
        },
        {
            "id": "CVE-2026-83627",
            "vendor": "wpmudev",
            "product": "Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN",
            "title": "Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN vulnerability",
            "summary": "The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written to wp-content/wphb-logs/page-caching-log.php, a directly web-accessible PHP file that is supposed to be protected by a leading '<?php die(); ?>' header. That header is guarded by class_exists( 'Filesystem' ), which can never match because class_exists() resolves string arguments in the global namespace while the class is Hummingbird\\Core\\Filesystem; when the log is created during a front-end request the header is therefore omitted entirely. get_cookies() then writes the raw name of any cookie matching the wphb_cache_ prefix into that file without sanitization. This makes it possible for unauthenticated attackers to write arbitrary PHP into the log file with a single anonymous request and execute it by requesting the file directly, resulting in full remote code execution. Exploitation requires the site administrator to have enabled Page Caching with the Debug Log option (non-default), and the log file to be created during a front-end request — a state reached by the plugin's own 'Clear logs' action, any cache flush, or unattended via the plugin's daily log-rotation cron, which can strip the protective header from an existing log file.",
            "updated_at": "2026-09-05T06:17:10.080",
            "published_at": "2026-09-05T06:17:10.080",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.21.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written to wp-content/wphb-logs/page-caching-log.php, a directly web-accessible PHP file that is supposed to be protected by a leading '<?php die(); ?>' header. That header is guarded by class_exists( 'Filesystem' ), which can never match because class_exists() resolves string arguments in the global namespace while the class is Hummingbird\\Core\\Filesystem; when the log is created during a front-end request the header is therefore omitted entirely. get_cookies() then writes the raw name of any cookie matching the wphb_cache_ prefix into that file without sanitization. This makes it possible for unauthenticated attackers to write arbitrary PHP into the log file with a single anonymous request and execute it by requesting the file directly, resulting in full remote code execution. Exploitation requires the site administrator to have enabled Page Caching with the Debug Log option (non-default), and the log file to be created during a front-end request — a state reached by the plugin's own 'Clear logs' action, any cache flush, or unattended via the plugin's daily log-rotation cron, which can strip the protective header from an existing log file.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/hummingbird-performance/trunk/core/modules/class-page-cache.php#L1973",
                "https://plugins.trac.wordpress.org/browser/hummingbird-performance/trunk/core/modules/class-page-cache.php#L1982",
                "https://plugins.trac.wordpress.org/browser/hummingbird-performance/trunk/core/modules/class-page-cache.php#L749",
                "https://plugins.trac.wordpress.org/browser/hummingbird-performance/trunk/core/modules/class-page-cache.php#L752",
                "https://plugins.trac.wordpress.org/changeset/3675836/hummingbird-performance/trunk/core/modules/class-page-cache.php",
                "https://plugins.trac.wordpress.org/changeset?old_path=%2Fhummingbird-performance/tags/3.20.0&new_path=%2Fhummingbird-performance/tags/3.21.2",
                "https://plugins.trac.wordpress.org/changeset?reponame=&new=3675836%40hummingbird-performance%2Ftags%2F3.21.2&old=3614991%40hummingbird-performance%2Ftags%2F3.20.0",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/65c3ca36-79e6-47f8-9524-27e7631f4caf?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T06:17:10.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83627"
                }
            ]
        },
        {
            "id": "CVE-2026-83625",
            "vendor": "supsysticcom",
            "product": "Contact Form by Supsystic",
            "title": "Contact Form by Supsystic vulnerability",
            "summary": "The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An unauthenticated attacker can first call the 'updateNonce' action — which is accessible without authentication due to its absence from the plugin's permission list — to obtain a valid nonce, then submit a contact form with a malicious payload in a spoofed IP header such as X-Forwarded-For.",
            "updated_at": "2026-09-05T08:16:40.857",
            "published_at": "2026-09-05T08:16:40.857",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.10.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, 1.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An unauthenticated attacker can first call the 'updateNonce' action — which is accessible without authentication due to its absence from the plugin's permission list — to obtain a valid nonce, then submit a contact form with a malicious payload in a spoofed IP header such as X-Forwarded-For.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.10.2/classes/utils.php#L77",
                "https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.10.2/modules/forms/controller.php#L390",
                "https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.10.2/modules/forms/controller.php#L411",
                "https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.10.2/modules/forms/js/admin.forms.contacts.list.js#L204",
                "https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.10.2/modules/forms/models/forms.php#L103",
                "https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.8.1/classes/utils.php#L77",
                "https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.8.1/modules/forms/controller.php#L390",
                "https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.8.1/modules/forms/controller.php#L411",
                "https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.8.1/modules/forms/js/admin.forms.contacts.list.js#L204",
                "https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.8.1/modules/forms/models/forms.php#L103",
                "https://plugins.trac.wordpress.org/changeset?reponame=&old=3679442%40contact-form-by-supsystic&new=3679442%40contact-form-by-supsystic",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/aa65bced-a449-4ba5-accf-40a824ee464d?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:16:40.857",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83625"
                }
            ]
        },
        {
            "id": "CVE-2026-83549",
            "vendor": "SonicWall",
            "product": "SMA1000 Appliances",
            "title": "SonicWall SMA1000 Appliances OS Command Injection Vulnerability",
            "summary": "SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 89,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "xcoy0te/CVE-2026-83548-checker",
                    "author": "xcoy0te",
                    "first_seen": "2026-09-04",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 0,
                    "title": "Non-intrusive detector for SonicWall SMA 1000 exposure to CVE-2026-83548/-83549 (version/patch-state check; no exploitation)",
                    "summary": "Non-intrusive detector for SonicWall SMA 1000 exposure to CVE-2026-83548/-83549 (version/patch-state check; no exploitation)",
                    "url": "https://github.com/xcoy0te/CVE-2026-83548-checker"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/xcoy0te/CVE-2026-83548-checker"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-83548",
            "vendor": "SonicWall",
            "product": "SMA1000 Appliances",
            "title": "SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
            "summary": "SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 128,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "xcoy0te/CVE-2026-83548-checker",
                    "author": "xcoy0te",
                    "first_seen": "2026-09-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Non-intrusive detector for SonicWall SMA 1000 exposure to CVE-2026-83548/-83549 (version/patch-state check; no exploitation)",
                    "summary": "Non-intrusive detector for SonicWall SMA 1000 exposure to CVE-2026-83548/-83549 (version/patch-state check; no exploitation)",
                    "url": "https://github.com/xcoy0te/CVE-2026-83548-checker"
                },
                {
                    "repository": "xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis",
                    "author": "xoessie",
                    "first_seen": "2026-09-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Vulnerability Analysis of CVE-2026-83548 affecting SonicWall SMA1000 security systems.",
                    "summary": "Vulnerability Analysis of CVE-2026-83548 affecting SonicWall SMA1000 security systems.",
                    "url": "https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/xcoy0te/CVE-2026-83548-checker",
                "https://github.com/xoessie/CVE-2026-83548-SonicWall-SMA1000-Analysis"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-83544",
            "vendor": "Unknown",
            "product": "Greenshift",
            "title": "Greenshift vulnerability",
            "summary": "The Greenshift  WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.",
            "updated_at": "2026-09-06T11:18:03.323",
            "published_at": "2026-09-05T07:17:13.373",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 13.2.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Greenshift  WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/f2bd202b-43fc-4ca7-9bab-649ed87e7cbd/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:13.373",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83544"
                }
            ]
        },
        {
            "id": "CVE-2026-83543",
            "vendor": "Unknown",
            "product": "Greenshift",
            "title": "Greenshift vulnerability",
            "summary": "The Greenshift  WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response.",
            "updated_at": "2026-09-06T11:18:03.180",
            "published_at": "2026-09-05T07:17:13.280",
            "cvss": 4.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 13.2.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "The Greenshift  WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above to make the server issue requests to arbitrary hosts and read the response.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/902e46ad-e577-4a3e-be19-a3bcc75ece77/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:13.280",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83543"
                }
            ]
        },
        {
            "id": "CVE-2026-83534",
            "vendor": "DALIBO",
            "product": "PostgreSQL Anonymizer",
            "title": "PostgreSQL Anonymizer vulnerability",
            "summary": "PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions",
            "updated_at": "2026-09-09T05:18:19.027",
            "published_at": "2026-09-06T16:16:50.753",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1 through before 3.2.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-250",
            "what_happened": "PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymizer 3.2.0 and later versions",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/666"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T16:16:50.753",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83534"
                }
            ]
        },
        {
            "id": "CVE-2026-83532",
            "vendor": "Unknown",
            "product": "Custom Menu Wizard Widget",
            "title": "Custom Menu Wizard Widget vulnerability",
            "summary": "The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.",
            "updated_at": "2026-09-12T16:16:40.973",
            "published_at": "2026-09-12T06:16:26.353",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/164f3fdd-00a6-482f-b3a2-78b50508011d/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:26.353",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83532"
                }
            ]
        },
        {
            "id": "CVE-2026-83527",
            "vendor": "Ivanti",
            "product": "Sentry",
            "title": "Sentry vulnerability",
            "summary": "An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.",
            "updated_at": "2026-09-09T05:18:18.923",
            "published_at": "2026-09-08T15:18:51.130",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-288",
            "what_happened": "An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-83527"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T15:18:51.130",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-83527"
                }
            ]
        },
        {
            "id": "CVE-2026-82918",
            "vendor": "Keyence Corporation",
            "product": "XG-X VisionTerminal",
            "title": "XG-X VisionTerminal vulnerability",
            "summary": "XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is installed may be disclosed.",
            "updated_at": "2026-09-15T12:17:53.467",
            "published_at": "2026-09-03T13:06:15.910",
            "cvss": 6.7,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through Ver.3.6.0000 (semver); 0 through Ver.5.5.0010 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-611",
            "what_happened": "XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is installed may be disclosed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jvn.jp/en/vu/JVNVU98062224/index.html",
                "https://www.keyence.com/mi26082104"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T13:06:15.910",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82918"
                }
            ]
        },
        {
            "id": "CVE-2026-82851",
            "vendor": "Unknown",
            "product": "Masteriyo LMS",
            "title": "Masteriyo LMS vulnerability",
            "summary": "The Masteriyo LMS  WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' private and draft courses.",
            "updated_at": "2026-09-12T16:16:40.830",
            "published_at": "2026-09-12T06:16:26.253",
            "cvss": 2.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.14.0 through before 3.4.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "The Masteriyo LMS  WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing users with the instructor role to retrieve the full content and metadata of arbitrary posts, including other instructors' private and draft courses.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/07664081-72c3-4f7e-9324-e0047b6e6d22/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:26.253",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82851"
                }
            ]
        },
        {
            "id": "CVE-2026-82847",
            "vendor": "Unknown",
            "product": "Masteriyo LMS",
            "title": "Masteriyo LMS vulnerability",
            "summary": "The Masteriyo LMS  WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.",
            "updated_at": "2026-09-12T16:16:40.697",
            "published_at": "2026-09-12T06:16:26.147",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.4.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Masteriyo LMS  WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, allowing users with the instructor role to perform Stored Cross-Site Scripting attacks against higher privileged users such as administrators.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/9cc4f7a7-e5b9-48fe-962b-f5d0753e6158/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:26.147",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82847"
                }
            ]
        },
        {
            "id": "CVE-2026-82846",
            "vendor": "Unknown",
            "product": "Masteriyo LMS",
            "title": "Masteriyo LMS vulnerability",
            "summary": "The Masteriyo LMS  WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator.",
            "updated_at": "2026-09-06T11:18:03.030",
            "published_at": "2026-09-05T07:17:13.187",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.18.0 through before 3.4.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Masteriyo LMS  WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing users with a course-author role to perform Stored Cross-Site Scripting attacks that run in the session of anyone viewing the course, including a logged-in administrator.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/0ee2052c-90a8-4b98-947a-adc55feb1de7/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:13.187",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82846"
                }
            ]
        },
        {
            "id": "CVE-2026-82845",
            "vendor": "Unknown",
            "product": "Masteriyo LMS",
            "title": "Masteriyo LMS vulnerability",
            "summary": "The Masteriyo LMS  WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS  WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rather than code execution.",
            "updated_at": "2026-09-12T16:16:40.557",
            "published_at": "2026-09-12T06:16:26.043",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.4.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "The Masteriyo LMS  WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users with a minimal account to inject arbitrary PHP objects and, by way of a class shipped in a library bundled with the Masteriyo LMS  WordPress plugin before 3.4.1, write and execute arbitrary code on the server. A weaker form of the same issue is reachable without an account and yields an arbitrary file write rather than code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/5ced30ea-8b78-495f-b10c-42b3f10adcb3/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:26.043",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82845"
                }
            ]
        },
        {
            "id": "CVE-2026-82758",
            "vendor": "ash-project",
            "product": "ash_authentication_oauth2_server",
            "title": "ash_authentication_oauth2_server vulnerability",
            "summary": "Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token.\n\nresolve_secret/3 in AshAuthentication.Oauth2Server (reached through __resolve_secret__!) treated any return other than {:ok, _} or :error from a configured {module, function, args} or 2-arity-function secret provider as a valid secret, wrapping nil, false, or \"\" as {:ok, value}. When the initial_access_token resolves to such an empty value, POST /oauth/register compares the presented bearer token against it and the comparison passes with no token supplied, so registration is open although it was configured closed. The same fail-open affected other resolved secrets such as signing_secret.\n\nThis issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.",
            "updated_at": "2026-09-07T23:16:53.123",
            "published_at": "2026-09-07T23:16:53.123",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.1.0 through before 0.3.1 (semver); 855b578037c5ded18e8a6e60f42e56bde4905fae through before 30a87101871775d27d79f9ad6f29eafa4779e118 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "Improper Authentication vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to register OAuth clients even when Dynamic Client Registration is gated by an initial access token.\n\nresolve_secret/3 in AshAuthentication.Oauth2Server (reached through __resolve_secret__!) treated any return other than {:ok, _} or :error from a configured {module, function, args} or 2-arity-function secret provider as a valid secret, wrapping nil, false, or \"\" as {:ok, value}. When the initial_access_token resolves to such an empty value, POST /oauth/register compares the presented bearer token against it and the comparison passes with no token supplied, so registration is open although it was configured closed. The same fail-open affected other resolved secrets such as signing_secret.\n\nThis issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-82758.html",
                "https://github.com/ash-project/ash_authentication_oauth2_server/commit/30a87101871775d27d79f9ad6f29eafa4779e118",
                "https://github.com/ash-project/ash_authentication_oauth2_server/security/advisories/GHSA-fxc6-vp68-87pw",
                "https://osv.dev/vulnerability/EEF-CVE-2026-82758"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:53.123",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82758"
                }
            ]
        },
        {
            "id": "CVE-2026-82757",
            "vendor": "ash-project",
            "product": "ash_authentication_oauth2_server",
            "title": "ash_authentication_oauth2_server vulnerability",
            "summary": "Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses.\n\npublic_ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy for CIMD metadata fetches. It classified several address forms as publicly routable that are not: IPv4-compatible ::/96 (for example ::127.0.0.1), SIIT IPv4-translated ::ffff:0:0:0/96, and deprecated site-local fec0::/10. A returned AAAA record in one of these ranges passed the policy, so a fetch pinned to that address reached space the policy was meant to block.\n\nThis issue affects ash_authentication_oauth2_server: from 0.3.0 before 0.3.1.",
            "updated_at": "2026-09-07T23:16:52.957",
            "published_at": "2026-09-07T23:16:52.957",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.3.0 through before 0.3.1 (semver); e713a9ba816761140c226e2ca55b75c0b93f5984 through before 268b591261a3473ab9b87272963e4dd2fd99d972 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "Server-Side Request Forgery (SSRF) vulnerability in ash-project ash_authentication_oauth2_server allows an attacker who controls a client metadata URL and its DNS to make the server connect to internal or loopback addresses.\n\npublic_ip?/1 in AshAuthentication.Oauth2Server.CIMD.ReqFetcher enforces the outbound policy for CIMD metadata fetches. It classified several address forms as publicly routable that are not: IPv4-compatible ::/96 (for example ::127.0.0.1), SIIT IPv4-translated ::ffff:0:0:0/96, and deprecated site-local fec0::/10. A returned AAAA record in one of these ranges passed the policy, so a fetch pinned to that address reached space the policy was meant to block.\n\nThis issue affects ash_authentication_oauth2_server: from 0.3.0 before 0.3.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-82757.html",
                "https://github.com/ash-project/ash_authentication_oauth2_server/commit/268b591261a3473ab9b87272963e4dd2fd99d972",
                "https://github.com/ash-project/ash_authentication_oauth2_server/security/advisories/GHSA-wprp-8gvj-p6cv",
                "https://osv.dev/vulnerability/EEF-CVE-2026-82757"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:52.957",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82757"
                }
            ]
        },
        {
            "id": "CVE-2026-82756",
            "vendor": "ash-project",
            "product": "ash_authentication_oauth2_server",
            "title": "ash_authentication_oauth2_server vulnerability",
            "summary": "Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header.\n\nBearerPlug and RequireScopePlug built the Bearer resource_metadata=\"...\" challenge by interpolating a resource_metadata URL derived from the request tenant directly into the quoted value. In a multi-tenant application that sets the Ash tenant from request-controlled data (a subdomain, the Host, a path segment, or a header), a tenant containing a \" closes the quoted value and appends attacker-chosen auth-params, including a second resource_metadata URL pointing at an attacker-controlled authorization server that spec-following clients follow. Carriage returns and line feeds are rejected by Plug, so this is parameter injection within one header, not response splitting.\n\nThis issue affects ash_authentication_oauth2_server: from 0.1.3 before 0.3.1.",
            "updated_at": "2026-09-07T23:16:52.770",
            "published_at": "2026-09-07T23:16:52.770",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.1.3 through before 0.3.1 (semver); 99de0a1cacb5ef667c4533278b7c81ca98c00231 through before 09f97476715da031b136eaec7b2cda2363ad8149 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-116",
            "what_happened": "Improper Encoding or Escaping of Output vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to inject arbitrary authentication parameters into the WWW-Authenticate challenge header.\n\nBearerPlug and RequireScopePlug built the Bearer resource_metadata=\"...\" challenge by interpolating a resource_metadata URL derived from the request tenant directly into the quoted value. In a multi-tenant application that sets the Ash tenant from request-controlled data (a subdomain, the Host, a path segment, or a header), a tenant containing a \" closes the quoted value and appends attacker-chosen auth-params, including a second resource_metadata URL pointing at an attacker-controlled authorization server that spec-following clients follow. Carriage returns and line feeds are rejected by Plug, so this is parameter injection within one header, not response splitting.\n\nThis issue affects ash_authentication_oauth2_server: from 0.1.3 before 0.3.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-82756.html",
                "https://github.com/ash-project/ash_authentication_oauth2_server/commit/09f97476715da031b136eaec7b2cda2363ad8149",
                "https://github.com/ash-project/ash_authentication_oauth2_server/security/advisories/GHSA-2h3v-83jg-2qmm",
                "https://osv.dev/vulnerability/EEF-CVE-2026-82756"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:52.770",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82756"
                }
            ]
        },
        {
            "id": "CVE-2026-82755",
            "vendor": "ash-project",
            "product": "ash_authentication_oauth2_server",
            "title": "ash_authentication_oauth2_server vulnerability",
            "summary": "Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery metadata to another tenant's clients.\n\nThe RFC 8414 and RFC 9728 metadata endpoints in AshAuthentication.Phoenix.Oauth2Server.ProtocolRouter return tenant-specific values (issuer, authorization_endpoint, token_endpoint, jwks_uri) when a tenant is set, but sent them with Cache-Control: public, max-age=3600 and no Vary. When the tenant is derived from something other than the URL (a header or the Host) and a shared cache sits in front, the cache key is the URL alone, so a stored response for one tenant is served to another for up to an hour. Affected clients may then send authorization codes and secrets to the wrong tenant's token endpoint and validate tokens against the wrong keys.\n\nThis issue affects ash_authentication_oauth2_server: from 0.1.3 before 0.3.1.",
            "updated_at": "2026-09-07T23:16:52.580",
            "published_at": "2026-09-07T23:16:52.580",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.1.3 through before 0.3.1 (semver); 99de0a1cacb5ef667c4533278b7c81ca98c00231 through before 768d87f70e4e97ae1d2bf1606b5bf3f4d03f24a1 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-524",
            "what_happened": "Use of Cache Containing Sensitive Information vulnerability in ash-project ash_authentication_oauth2_server allows a shared HTTP cache to serve one tenant's OAuth discovery metadata to another tenant's clients.\n\nThe RFC 8414 and RFC 9728 metadata endpoints in AshAuthentication.Phoenix.Oauth2Server.ProtocolRouter return tenant-specific values (issuer, authorization_endpoint, token_endpoint, jwks_uri) when a tenant is set, but sent them with Cache-Control: public, max-age=3600 and no Vary. When the tenant is derived from something other than the URL (a header or the Host) and a shared cache sits in front, the cache key is the URL alone, so a stored response for one tenant is served to another for up to an hour. Affected clients may then send authorization codes and secrets to the wrong tenant's token endpoint and validate tokens against the wrong keys.\n\nThis issue affects ash_authentication_oauth2_server: from 0.1.3 before 0.3.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-82755.html",
                "https://github.com/ash-project/ash_authentication_oauth2_server/commit/768d87f70e4e97ae1d2bf1606b5bf3f4d03f24a1",
                "https://github.com/ash-project/ash_authentication_oauth2_server/security/advisories/GHSA-crqf-7m54-4hgc",
                "https://osv.dev/vulnerability/EEF-CVE-2026-82755"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:52.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82755"
                }
            ]
        },
        {
            "id": "CVE-2026-82754",
            "vendor": "ash-project",
            "product": "ash_authentication_oauth2_server",
            "title": "ash_authentication_oauth2_server vulnerability",
            "summary": "Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix.\n\noauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwards the same ProtocolRouter at both the /oauth prefix and the /.well-known prefix. Phoenix forward strips the matched prefix before dispatch, so the full route table answers under both mounts, and POST /register, POST /token, and POST /revoke are reachable as /.well-known/register, /.well-known/token, and /.well-known/revoke. Edge controls such as WAF rules, rate limits, or authentication exemptions written against the /oauth paths, or that allow-list /.well-known as unauthenticated, do not apply to the alias.\n\nThis issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.",
            "updated_at": "2026-09-07T23:16:52.403",
            "published_at": "2026-09-07T23:16:52.403",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.1.0 through before 0.3.1 (semver); 855b578037c5ded18e8a6e60f42e56bde4905fae through before a72972d7ed3eb74c05dfa0653a258ef14454459a (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-424",
            "what_happened": "Improper Protection of Alternate Path vulnerability in ash-project ash_authentication_oauth2_server exposes the state-changing OAuth endpoints under an unintended URL prefix, bypassing controls scoped to the canonical prefix.\n\noauth2_server_protocol_routes/1 in AshAuthentication.Phoenix.Oauth2Server.Router forwards the same ProtocolRouter at both the /oauth prefix and the /.well-known prefix. Phoenix forward strips the matched prefix before dispatch, so the full route table answers under both mounts, and POST /register, POST /token, and POST /revoke are reachable as /.well-known/register, /.well-known/token, and /.well-known/revoke. Edge controls such as WAF rules, rate limits, or authentication exemptions written against the /oauth paths, or that allow-list /.well-known as unauthenticated, do not apply to the alias.\n\nThis issue affects ash_authentication_oauth2_server: from 0.1.0 before 0.3.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-82754.html",
                "https://github.com/ash-project/ash_authentication_oauth2_server/commit/a72972d7ed3eb74c05dfa0653a258ef14454459a",
                "https://github.com/ash-project/ash_authentication_oauth2_server/security/advisories/GHSA-wwxg-h779-3wf4",
                "https://osv.dev/vulnerability/EEF-CVE-2026-82754"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:52.403",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82754"
                }
            ]
        },
        {
            "id": "CVE-2026-82753",
            "vendor": "ash-project",
            "product": "ash_authentication_oauth2_server",
            "title": "ash_authentication_oauth2_server vulnerability",
            "summary": "Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database storage and memory.\n\nThe /authorize endpoint is unauthenticated by design. With Client ID Metadata Documents enabled, resolve_client/3 in AshAuthentication.Oauth2Server.CIMD fetches the document for each new URL-shaped client_id and upserts a client row, with no cap on the number of rows, no expiry or garbage collection, and no length bound on the fetched fields; the document was also placed in CIMD.Cache before validation, so even rejected documents held cache memory until their TTL. An attacker serving valid documents at many distinct URLs creates one permanent client row per URL, each able to carry multi-megabyte strings, growing storage and memory without bound.\n\nThis issue affects ash_authentication_oauth2_server: from 0.3.0 before 0.3.1.",
            "updated_at": "2026-09-07T23:16:52.227",
            "published_at": "2026-09-07T23:16:52.227",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.3.0 through before 0.3.1 (semver); e713a9ba816761140c226e2ca55b75c0b93f5984 through before 45e24f69e0f95d67413e2508acc2264156acb5ac (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_authentication_oauth2_server allows an unauthenticated attacker to exhaust database storage and memory.\n\nThe /authorize endpoint is unauthenticated by design. With Client ID Metadata Documents enabled, resolve_client/3 in AshAuthentication.Oauth2Server.CIMD fetches the document for each new URL-shaped client_id and upserts a client row, with no cap on the number of rows, no expiry or garbage collection, and no length bound on the fetched fields; the document was also placed in CIMD.Cache before validation, so even rejected documents held cache memory until their TTL. An attacker serving valid documents at many distinct URLs creates one permanent client row per URL, each able to carry multi-megabyte strings, growing storage and memory without bound.\n\nThis issue affects ash_authentication_oauth2_server: from 0.3.0 before 0.3.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-82753.html",
                "https://github.com/ash-project/ash_authentication_oauth2_server/commit/45e24f69e0f95d67413e2508acc2264156acb5ac",
                "https://github.com/ash-project/ash_authentication_oauth2_server/security/advisories/GHSA-9pv3-wxjm-f846",
                "https://osv.dev/vulnerability/EEF-CVE-2026-82753"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:52.227",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82753"
                }
            ]
        },
        {
            "id": "CVE-2026-82752",
            "vendor": "ash-project",
            "product": "ash",
            "title": "ash vulnerability",
            "summary": "Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose length constraint should bound it.\n\nAsh measures string length with Elixir's String.length/1, which counts Unicode graphemes, in the max_length and min_length constraints of Ash.Type.String (apply_constraints/2 in lib/ash/type/string.ex), in Ash.Resource.Validation.StringLength, and in the string_length expression function. A grapheme carries an unbounded number of combining marks, so a base character followed by a million combining acute accents is one grapheme and megabytes of data, and satisfies max_length: 2. Where the data layer imposes no independent limit (ETS, Mnesia, or a Postgres text column) the whole value is persisted, so an attacker can write an entire request body into an attribute declared with a small maximum and grow storage without bound.\n\nThe counting unit also disagrees with the storage layer, which counts codepoints rather than graphemes, so a value accepted by the constraint can still be rejected or truncated by the column. A Postgres varchar(n) column bounds the value itself and is not exposed.\n\nThis issue affects ash: from 0.10.0 before 3.33.0.",
            "updated_at": "2026-09-05T18:17:29.170",
            "published_at": "2026-09-05T18:17:29.170",
            "cvss": 5.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.10.0 through before 3.33.0 (semver); 05848d5f4affe60fddd812222a18ada080c0813b through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1284",
            "what_happened": "Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose length constraint should bound it.\n\nAsh measures string length with Elixir's String.length/1, which counts Unicode graphemes, in the max_length and min_length constraints of Ash.Type.String (apply_constraints/2 in lib/ash/type/string.ex), in Ash.Resource.Validation.StringLength, and in the string_length expression function. A grapheme carries an unbounded number of combining marks, so a base character followed by a million combining acute accents is one grapheme and megabytes of data, and satisfies max_length: 2. Where the data layer imposes no independent limit (ETS, Mnesia, or a Postgres text column) the whole value is persisted, so an attacker can write an entire request body into an attribute declared with a small maximum and grow storage without bound.\n\nThe counting unit also disagrees with the storage layer, which counts codepoints rather than graphemes, so a value accepted by the constraint can still be rejected or truncated by the column. A Postgres varchar(n) column bounds the value itself and is not exposed.\n\nThis issue affects ash: from 0.10.0 before 3.33.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-82752.html",
                "https://github.com/ash-project/ash/commit/a64cab49b8886503e6b7c7b211d83c475aac48ca",
                "https://github.com/ash-project/ash/commit/cdbf4c4da6bda5f6f139078f01a64320b595216d",
                "https://github.com/ash-project/ash/security/advisories/GHSA-cwjv-574p-59f6",
                "https://osv.dev/vulnerability/EEF-CVE-2026-82752"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T18:17:29.170",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82752"
                }
            ]
        },
        {
            "id": "CVE-2026-82751",
            "vendor": "ZenHive",
            "product": "mpp",
            "title": "mpp vulnerability",
            "summary": "Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account.\n\nWhen the server sponsors Tempo payments, MPP.Methods.Tempo.FeePayerPolicy.measure/3 in lib/mpp/methods/tempo/fee_payer_policy.ex bounds the gas fields, the fee budget, the validity window and the access list of the client-signed 0x76 envelope, but does not check whether the envelope carries the optional key_authorization field. A client can attach a fully signed key authorization, provisioning a new access key with token spending limits on its own account, alongside the normal payment call. The key and each limit entry are persistent storage writes billed as intrinsic gas to the sponsor, bounded only by the gas_limit ceiling. At the reporter's default of one key with three token limits the sponsored cost rises from about 46,587 gas to about 1,808,700 gas, and the client keeps a valid access key it paid nothing for.\n\nThis issue affects mpp: from 0.2.0 before 0.16.1.",
            "updated_at": "2026-09-06T17:17:56.070",
            "published_at": "2026-09-06T17:17:56.070",
            "cvss": 8.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.2.0 through before 0.16.1 (semver); d29d54e507918db00a5b65d90136b73166c017d7 through before 0482572b47e1ffe1537ab80ab613d47b92833c2d (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1284",
            "what_happened": "Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for provisioning an access key on the client's own account.\n\nWhen the server sponsors Tempo payments, MPP.Methods.Tempo.FeePayerPolicy.measure/3 in lib/mpp/methods/tempo/fee_payer_policy.ex bounds the gas fields, the fee budget, the validity window and the access list of the client-signed 0x76 envelope, but does not check whether the envelope carries the optional key_authorization field. A client can attach a fully signed key authorization, provisioning a new access key with token spending limits on its own account, alongside the normal payment call. The key and each limit entry are persistent storage writes billed as intrinsic gas to the sponsor, bounded only by the gas_limit ceiling. At the reporter's default of one key with three token limits the sponsored cost rises from about 46,587 gas to about 1,808,700 gas, and the client keeps a valid access key it paid nothing for.\n\nThis issue affects mpp: from 0.2.0 before 0.16.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-82751.html",
                "https://github.com/ZenHive/mpp/commit/0482572b47e1ffe1537ab80ab613d47b92833c2d",
                "https://github.com/ZenHive/mpp/security/advisories/GHSA-rpwj-vrf7-4x36",
                "https://osv.dev/vulnerability/EEF-CVE-2026-82751"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T17:17:56.070",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82751"
                }
            ]
        },
        {
            "id": "CVE-2026-82750",
            "vendor": "ZenHive",
            "product": "mpp",
            "title": "mpp vulnerability",
            "summary": "Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the client's choosing.\n\nWhen the server sponsors Tempo payments, MPP.Methods.Tempo.FeePayerPolicy.measure/3 in lib/mpp/methods/tempo/fee_payer_policy.ex bounds the gas fields, the fee budget, the validity window and the access list of the client-signed 0x76 envelope, but never reads its aa_authorization_list field. Every signed delegation in that list is charged as intrinsic gas before the payment call runs, so a client attaching delegations from throwaway authority keys makes the sponsor pay for them within the default gas_limit ceiling. At the reporter's default of seven entries the sponsored cost rises from about 46,575 gas to about 1,884,087 gas. Because each entry is applied as a persistent set-code delegation, a client can also upgrade its own accounts to delegated code at the sponsor's expense.\n\nThis issue affects mpp: from 0.2.0 before 0.16.1.",
            "updated_at": "2026-09-06T17:17:55.867",
            "published_at": "2026-09-06T17:17:55.867",
            "cvss": 8.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.2.0 through before 0.16.1 (semver); d29d54e507918db00a5b65d90136b73166c017d7 through before 0482572b47e1ffe1537ab80ab613d47b92833c2d (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1284",
            "what_happened": "Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multiplier and to have the sponsor pay for EIP-7702 account delegations of the client's choosing.\n\nWhen the server sponsors Tempo payments, MPP.Methods.Tempo.FeePayerPolicy.measure/3 in lib/mpp/methods/tempo/fee_payer_policy.ex bounds the gas fields, the fee budget, the validity window and the access list of the client-signed 0x76 envelope, but never reads its aa_authorization_list field. Every signed delegation in that list is charged as intrinsic gas before the payment call runs, so a client attaching delegations from throwaway authority keys makes the sponsor pay for them within the default gas_limit ceiling. At the reporter's default of seven entries the sponsored cost rises from about 46,575 gas to about 1,884,087 gas. Because each entry is applied as a persistent set-code delegation, a client can also upgrade its own accounts to delegated code at the sponsor's expense.\n\nThis issue affects mpp: from 0.2.0 before 0.16.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-82750.html",
                "https://github.com/ZenHive/mpp/commit/0482572b47e1ffe1537ab80ab613d47b92833c2d",
                "https://github.com/ZenHive/mpp/security/advisories/GHSA-5qrp-r24c-w6jr",
                "https://osv.dev/vulnerability/EEF-CVE-2026-82750"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T17:17:55.867",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82750"
                }
            ]
        },
        {
            "id": "CVE-2026-82586",
            "vendor": "ash-project",
            "product": "ash_lua",
            "title": "ash_lua vulnerability",
            "summary": "Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list.\n\nAshLua exposes Ash resources to Lua scripts, gated by a manifest declaring which fields are exposed. The read action's operation aggregate path in AshLua.Runtime took the field name straight from the Lua call and resolved it with only String.to_existing_atom and Ash.Query.Aggregate.new!, neither of which consults the exposed-field allow-list the normal fields path enforces. A script can therefore read the value of any attribute of any record the actor may read, including private sensitive?: true columns, via resource.read({ operation = {\"list\", \"hashed_password\"} }); min and max give a value oracle. Anyone able to submit or influence a Lua script can reach this.\n\nThis issue affects ash_lua: from 0.1.0 before 0.2.1.",
            "updated_at": "2026-09-07T23:16:52.093",
            "published_at": "2026-09-07T23:16:52.093",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.1.0 through before 0.2.1 (semver); 8675e47cca81f36594083a7e63379bac9e123e72 through before c0dfcd9494766d548178c37df0bd01cff378e1c7 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-424",
            "what_happened": "Improper Protection of Alternate Path vulnerability in ash-project ash_lua allows a user-supplied Lua script to read attributes that are not on the exposed-field allow-list.\n\nAshLua exposes Ash resources to Lua scripts, gated by a manifest declaring which fields are exposed. The read action's operation aggregate path in AshLua.Runtime took the field name straight from the Lua call and resolved it with only String.to_existing_atom and Ash.Query.Aggregate.new!, neither of which consults the exposed-field allow-list the normal fields path enforces. A script can therefore read the value of any attribute of any record the actor may read, including private sensitive?: true columns, via resource.read({ operation = {\"list\", \"hashed_password\"} }); min and max give a value oracle. Anyone able to submit or influence a Lua script can reach this.\n\nThis issue affects ash_lua: from 0.1.0 before 0.2.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-82586.html",
                "https://github.com/ash-project/ash_lua/commit/c0dfcd9494766d548178c37df0bd01cff378e1c7",
                "https://github.com/ash-project/ash_lua/security/advisories/GHSA-37jv-wc37-fhcw",
                "https://osv.dev/vulnerability/EEF-CVE-2026-82586"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:52.093",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82586"
                }
            ]
        },
        {
            "id": "CVE-2026-82584",
            "vendor": "ash-project",
            "product": "igniter",
            "title": "igniter vulnerability",
            "summary": "Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install confirmation prompt.\n\nmix igniter.install prints a confirmation panel (an anti-typosquatting safeguard) listing a package's hex metadata before adding it. The panel builder in Igniter.Project.Deps wrote publisher-controlled fields (meta.description, owner usernames, requirement names, version) to the terminal with only newlines stripped. A malicious or typosquatted package can embed ANSI terminal escape sequences (cursor movement, line erase, carriage returns) in its metadata to overwrite the panel, forging trusted author names and download counts while concealing the real ones, so a developer relying on the panel to vet the package is deceived into approving a malicious dependency.\n\nThis issue affects igniter: from 0.8.1 before 0.8.4.",
            "updated_at": "2026-09-07T23:16:51.933",
            "published_at": "2026-09-07T23:16:51.933",
            "cvss": 2.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.8.1 through before 0.8.4 (semver); d26d9b3a8348661813617606076315075d32663b through before d492b1aa33f8fb0dacc0afa41b703fb922d42816 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-150",
            "what_happened": "Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project igniter allows a malicious package publisher to forge the mix igniter.install confirmation prompt.\n\nmix igniter.install prints a confirmation panel (an anti-typosquatting safeguard) listing a package's hex metadata before adding it. The panel builder in Igniter.Project.Deps wrote publisher-controlled fields (meta.description, owner usernames, requirement names, version) to the terminal with only newlines stripped. A malicious or typosquatted package can embed ANSI terminal escape sequences (cursor movement, line erase, carriage returns) in its metadata to overwrite the panel, forging trusted author names and download counts while concealing the real ones, so a developer relying on the panel to vet the package is deceived into approving a malicious dependency.\n\nThis issue affects igniter: from 0.8.1 before 0.8.4.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-82584.html",
                "https://github.com/ash-project/igniter/commit/d492b1aa33f8fb0dacc0afa41b703fb922d42816",
                "https://github.com/ash-project/igniter/security/advisories/GHSA-cj7w-j579-gc42",
                "https://osv.dev/vulnerability/EEF-CVE-2026-82584"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:51.933",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82584"
                }
            ]
        },
        {
            "id": "CVE-2026-82538",
            "vendor": "ILIAS-eLearning e.V.",
            "product": "ILIAS",
            "title": "ILIAS vulnerability",
            "summary": "ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and because multi-statement execution is enabled in the database layer, stacked queries enable full database read and write access as well as administrator account takeover.",
            "updated_at": "2026-09-14T20:16:57.190",
            "published_at": "2026-09-04T18:18:01.357",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.0 through before 9.22 (custom); 10.0 through before 10.10 (custom); 11.0 through before 11.3 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation against declared sortable columns. Authenticated users with write permission on any container can inject arbitrary SQL through the sort parameter, and because multi-statement execution is enabled in the database layer, stacked queries enable full database read and write access as well as administrator account takeover.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&obj_id=225630&ref_id=35",
                "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&obj_id=225631&ref_id=35",
                "https://docu.ilias.de/ilias.php?baseClass=illmpresentationgui&obj_id=225632&ref_id=35",
                "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=wy:ll:6t&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=15821&blpg=934",
                "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=wy:ll:6t&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=15821&blpg=935",
                "https://docu.ilias.de/ilias.php?baseClass=ilrepositorygui&cmdNode=wy:ll:6t&cmdClass=ilBlogPostingGUI&cmd=previewFullscreen&ref_id=15821&blpg=936",
                "https://www.vulncheck.com/advisories/ilias-arbitrary-file-read-via-soap-addfile",
                "https://www.vulncheck.com/advisories/ilias-arbitrary-sql-injection-via-repository-trash-table-sort-parameter"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T18:18:01.357",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82538"
                }
            ]
        },
        {
            "id": "CVE-2026-82329",
            "vendor": "JFrog",
            "product": "Artifactory",
            "title": "JFrog Artifactory Improper Authentication Vulnerability",
            "summary": "JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.",
            "updated_at": "2026-09-03T13:06:15.630",
            "published_at": "2026-08-28T20:20:21.293",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 7.111.21 (custom); 7.117.0 through before 7.117.28 (custom); 7.125.0 through before 7.125.20 (custom); 7.133.0 through before 7.133.29 (custom); 7.146.0 through before 7.146.38 (custom); 7.161.0 through before 7.161.20 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 118,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Improper Authentication in Jfrog Artifactory CVE-2026-82329",
                    "summary": "Auth bypass in JFrog Artifactory via JWT forged with blank HMAC secret for admin access.",
                    "what_happened": "Auth bypass in JFrog Artifactory via JWT forged with blank HMAC secret for admin access.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=49FCCCD6-2B66-5481-836E-ED29704FF510",
                        "https://github.com/0xTerror/CVE-2026-82329-JFrog-Artifactory-"
                    ],
                    "repository": "Sploitus",
                    "author": "0xTerror",
                    "first_seen": "2026-09-07T12:58:29",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=49FCCCD6-2B66-5481-836E-ED29704FF510"
                },
                {
                    "title": "Exploit for Improper Authentication in Jfrog Artifactory CVE-2026-82329",
                    "summary": "Auth bypass in JFrog Artifactory via JWT forged with blank HMAC secret for admin access.",
                    "what_happened": "Auth bypass in JFrog Artifactory via JWT forged with blank HMAC secret for admin access.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=49FCCCD6-2B66-5481-836E-ED29704FF510",
                        "https://github.com/0xTerror/CVE-2026-82329-JFrog-Artifactory-"
                    ],
                    "repository": "0xTerror/CVE-2026-82329-JFrog-Artifactory-",
                    "author": "0xTerror",
                    "first_seen": "2026-09-07T12:58:29",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/0xTerror/CVE-2026-82329-JFrog-Artifactory-"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
                "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82329",
                "https://sploitus.com/exploit?id=49FCCCD6-2B66-5481-836E-ED29704FF510",
                "https://github.com/0xTerror/CVE-2026-82329-JFrog-Artifactory-"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-28T20:20:21.293",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82329"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "enrichment_checked_at": "2026-09-07T16:05:33Z",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-82312",
            "vendor": "OpenVPN",
            "product": "OpenVPN",
            "title": "OpenVPN vulnerability",
            "summary": "OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects",
            "updated_at": "2026-09-07T08:17:13.527",
            "published_at": "2026-09-07T08:17:13.527",
            "cvss": 1.8,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.0.0 through 2.6.22 (semver); 2.7_alpha1 through 2.7.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-412",
            "what_happened": "OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://community.openvpn.net/Security%20Announcements/CVE-2026-82312"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:17:13.527",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82312"
                }
            ]
        },
        {
            "id": "CVE-2026-82304",
            "vendor": "Unknown",
            "product": "Music Store",
            "title": "Music Store vulnerability",
            "summary": "The Music Store  WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.",
            "updated_at": "2026-09-06T11:18:02.880",
            "published_at": "2026-09-05T07:17:13.090",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.245 through before 1.4.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "The Music Store  WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/0a4d2ffc-a437-430e-a760-d8d7fb388f0c/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:13.090",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82304"
                }
            ]
        },
        {
            "id": "CVE-2026-82209",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`).",
            "updated_at": "2026-09-15T07:16:31.233",
            "published_at": "2026-09-06T18:17:22.847",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.46.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 8.21.0 through before 8.22.0 (semver); e77b5b7453c1e8ccd7ec0816890d98e2f392e465 through before 95c1e8915dce64606bd753fd47fc0bd236e31cd6 (git); 8.21.0; 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-201",
            "what_happened": "When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-09-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3972385"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-82209.html",
                "https://curl.se/docs/CVE-2026-82209.json",
                "https://hackerone.com/reports/3972385"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T18:17:22.847",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82209"
                }
            ]
        },
        {
            "id": "CVE-2026-82208",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "With the wolfSSL backend, when CA caching is enabled and an\n`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can\nsilently reinstall the cached store after the callback returns. A certificate\ntrusted by the cached store but rejected by the callback-selected store is\nthen incorrectly accepted.",
            "updated_at": "2026-09-15T07:16:31.050",
            "published_at": "2026-09-06T18:17:22.733",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.9.1 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 8.21.0 through before 8.22.0 (semver); 0f2876b2c33f6784a27b6f7345bd8cd95b46352a through before ed0338befd1d865a8ea1fbaa90013a096dedd07a (git); 8.21.0; 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "With the wolfSSL backend, when CA caching is enabled and an\n`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can\nsilently reinstall the cached store after the callback returns. A certificate\ntrusted by the cached store but rejected by the callback-selected store is\nthen incorrectly accepted.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-09-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3973090"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-82208.html",
                "https://curl.se/docs/CVE-2026-82208.json",
                "https://hackerone.com/reports/3973090"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T18:17:22.733",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82208"
                }
            ]
        },
        {
            "id": "CVE-2026-82079",
            "vendor": "Nintendo",
            "product": "Nintendo Switch",
            "title": "Nintendo Switch vulnerability",
            "summary": "A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic.\nThis issue affects Nintendo Switch: before 23.0.0.",
            "updated_at": "2026-09-11T04:17:59.633",
            "published_at": "2026-09-10T06:17:06.330",
            "cvss": 7,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 23.0.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted network traffic.\nThis issue affects Nintendo Switch: before 23.0.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.nintendo.com/security-advisories/en/index.html"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T06:17:06.330",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82079"
                }
            ]
        },
        {
            "id": "CVE-2026-82078",
            "vendor": "PaperCut",
            "product": "PaperCut MF/NG",
            "title": "PaperCut MF/NG vulnerability",
            "summary": "An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.",
            "updated_at": "2026-09-14T00:16:56.777",
            "published_at": "2026-08-28T16:18:31.240",
            "cvss": 9.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "before 24.1.10 (semver); 25.0.0 through before 25.0.13 (semver); 26.0.0 through before 26.0.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-470",
            "what_happened": "An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/",
                "https://github.com/rapid7/metasploit-framework/pull/21842",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-82078"
            ],
            "timeline": [
                {
                    "at": "2026-08-28T16:18:31.240",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82078"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-82053",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity rather than the expected one. This can result in incorrect role assignments based on the LDAP directory's access control configuration, potentially allowing an authenticated user to acquire elevated privileges that were not intended by the deployment's authorization policy.",
            "updated_at": "2026-09-10T04:18:17.623",
            "published_at": "2026-09-08T17:18:33.143",
            "cvss": 7.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.9 (semver); 8.0.0 through before 8.0.30 (semver); 7.0.0 through before 7.0.41 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity rather than the expected one. This can result in incorrect role assignments based on the LDAP directory's access control configuration, potentially allowing an authenticated user to acquire elevated privileges that were not intended by the deployment's authorization policy.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-130785"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T17:18:33.143",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82053"
                }
            ]
        },
        {
            "id": "CVE-2026-82049",
            "vendor": "Python Software Foundation",
            "product": "CPython",
            "title": "CPython vulnerability",
            "summary": "In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.",
            "updated_at": "2026-09-16T04:18:42.637",
            "published_at": "2026-09-14T19:17:50.927",
            "cvss": 8.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.14.0b1 (python)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-59",
            "what_happened": "In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca",
                "https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3",
                "https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d",
                "https://github.com/python/cpython/issues/157190",
                "https://github.com/python/cpython/pull/157191",
                "https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/",
                "http://www.openwall.com/lists/oss-security/2026/09/14/27"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T19:17:50.927",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-82049"
                }
            ]
        },
        {
            "id": "CVE-2026-81963",
            "vendor": "Microsoft",
            "product": "Windows",
            "title": "Microsoft Windows Link Following Vulnerability",
            "summary": "Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.",
            "updated_at": "2026-09-07T22:00:00Z",
            "published_at": "2026-09-07T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 30,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-81941",
            "vendor": "IBM",
            "product": "Langflow OSS",
            "title": "Langflow OSS vulnerability",
            "summary": "IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls intended to prevent exactly this class of access. Successful exploitation could lead to arbitrary command execution, sensitive data exposure (including credentials from the process environment), file system modification, and lateral movement to services reachable from the server.",
            "updated_at": "2026-09-12T04:16:39.370",
            "published_at": "2026-09-10T22:17:03.220",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through 1.11.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER_COMPONENTS server-side controls intended to prevent exactly this class of access. Successful exploitation could lead to arbitrary command execution, sensitive data exposure (including credentials from the process environment), file system modification, and lateral movement to services reachable from the server.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286666"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:17:03.220",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81941"
                }
            ]
        },
        {
            "id": "CVE-2026-81940",
            "vendor": "IBM",
            "product": "Langflow OSS",
            "title": "Langflow OSS vulnerability",
            "summary": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.",
            "updated_at": "2026-09-12T04:16:39.240",
            "published_at": "2026-09-10T22:17:03.083",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through 1.11.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286666"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:17:03.083",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81940"
                }
            ]
        },
        {
            "id": "CVE-2026-81861",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-81861",
            "summary": "SCADAPack Secure Lock CVE-2026-81861 POC verifies vendor DTM fixtures decode with common keys.",
            "updated_at": "2026-09-11T00:22:33Z",
            "published_at": "2026-09-11T00:22:33Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 53,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "SCADAPack Secure Lock CVE-2026-81861 POC verifies vendor DTM fixtures decode with common keys.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-81861",
                    "summary": "SCADAPack Secure Lock CVE-2026-81861 POC verifies vendor DTM fixtures decode with common keys.",
                    "what_happened": "SCADAPack Secure Lock CVE-2026-81861 POC verifies vendor DTM fixtures decode with common keys.",
                    "cvss": 0,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=8330C8D8-76F2-5681-B9DB-1FEE71931C2C",
                        "https://github.com/abhinavagarwal07/scadapack-secure-lock-poc"
                    ],
                    "repository": "Sploitus",
                    "author": "abhinavagarwal07",
                    "first_seen": "2026-09-11T02:22:33",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=8330C8D8-76F2-5681-B9DB-1FEE71931C2C"
                },
                {
                    "title": "Exploit for CVE-2026-81861",
                    "summary": "SCADAPack Secure Lock CVE-2026-81861 POC verifies vendor DTM fixtures decode with common keys.",
                    "what_happened": "SCADAPack Secure Lock CVE-2026-81861 POC verifies vendor DTM fixtures decode with common keys.",
                    "cvss": 0,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=8330C8D8-76F2-5681-B9DB-1FEE71931C2C",
                        "https://github.com/abhinavagarwal07/scadapack-secure-lock-poc"
                    ],
                    "repository": "abhinavagarwal07/scadapack-secure-lock-poc",
                    "author": "abhinavagarwal07",
                    "first_seen": "2026-09-11T02:22:33",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://github.com/abhinavagarwal07/scadapack-secure-lock-poc"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=8330C8D8-76F2-5681-B9DB-1FEE71931C2C",
                "https://github.com/abhinavagarwal07/scadapack-secure-lock-poc"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T00:22:33Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=8330C8D8-76F2-5681-B9DB-1FEE71931C2C"
                }
            ],
            "enrichment_checked_at": "2026-09-11T04:05:32Z"
        },
        {
            "id": "CVE-2026-81830",
            "vendor": "OpenVPN",
            "product": "OpenVPN",
            "title": "OpenVPN vulnerability",
            "summary": "The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation",
            "updated_at": "2026-09-07T08:17:13.410",
            "published_at": "2026-09-07T08:17:13.410",
            "cvss": 5.6,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.4.0 through 2.6.22 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-73",
            "what_happened": "The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://community.openvpn.net/Security%20Announcements/CVE-2026-81830"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:17:13.410",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81830"
                }
            ]
        },
        {
            "id": "CVE-2026-81780",
            "vendor": "hashthemes",
            "product": "Hash Form",
            "title": "Exploit for CVE-2026-81780",
            "summary": "Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.",
            "updated_at": "2026-09-01T20:48:22.513",
            "published_at": "2026-08-31T21:17:52.027",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a through 1.4.2 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 71,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-81780",
                    "summary": "Remote code execution exploit in Hash Form identified as CVE-2026-81780.",
                    "what_happened": "Remote code execution exploit in Hash Form identified as CVE-2026-81780.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=6E596533-FD58-554D-9A3F-CDD5B2DD1740",
                        "https://github.com/0xTerror/CVE-2026-81780-Hash-Form"
                    ],
                    "repository": "Sploitus",
                    "author": "0xTerror",
                    "first_seen": "2026-09-07T13:07:45",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=6E596533-FD58-554D-9A3F-CDD5B2DD1740"
                },
                {
                    "title": "Exploit for CVE-2026-81780",
                    "summary": "Remote code execution exploit in Hash Form identified as CVE-2026-81780.",
                    "what_happened": "Remote code execution exploit in Hash Form identified as CVE-2026-81780.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=6E596533-FD58-554D-9A3F-CDD5B2DD1740",
                        "https://github.com/0xTerror/CVE-2026-81780-Hash-Form"
                    ],
                    "repository": "0xTerror/CVE-2026-81780-Hash-Form",
                    "author": "0xTerror",
                    "first_seen": "2026-09-07T13:07:45",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/0xTerror/CVE-2026-81780-Hash-Form"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=6E596533-FD58-554D-9A3F-CDD5B2DD1740",
                "https://github.com/0xTerror/CVE-2026-81780-Hash-Form",
                "https://patchstack.com/database/wordpress/plugin/hash-form/vulnerability/wordpress-hash-form-plugin-1-4-2-arbitrary-file-upload-vulnerability?_s_id=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T11:07:45Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=6E596533-FD58-554D-9A3F-CDD5B2DD1740"
                },
                {
                    "at": "2026-08-31T21:17:52.027",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81780"
                }
            ],
            "enrichment_checked_at": "2026-09-07T16:05:32Z",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-81742",
            "vendor": "Unknown",
            "product": "BE REST Endpoints",
            "title": "BE REST Endpoints vulnerability",
            "summary": "The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.",
            "updated_at": "2026-09-12T16:16:40.417",
            "published_at": "2026-09-12T06:16:25.937",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.0.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any user visiting the site.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/ea7c371a-3d0b-4e09-9c76-145345ad316b/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:25.937",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81742"
                }
            ]
        },
        {
            "id": "CVE-2026-81738",
            "vendor": "OpenVPN",
            "product": "OpenVPN",
            "title": "OpenVPN vulnerability",
            "summary": "OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries",
            "updated_at": "2026-09-07T08:17:13.270",
            "published_at": "2026-09-07T08:17:13.270",
            "cvss": 2.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.5.0 through 2.7.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-121",
            "what_happened": "OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://community.openvpn.net/Security%20Announcements/CVE-2026-81738"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:17:13.270",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81738"
                }
            ]
        },
        {
            "id": "CVE-2026-81648",
            "vendor": "Unknown",
            "product": "CryptoPayment Gateway",
            "title": "CryptoPayment Gateway vulnerability",
            "summary": "The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.",
            "updated_at": "2026-09-13T21:17:01.930",
            "published_at": "2026-09-13T21:17:01.930",
            "cvss": 10,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.2.1 through 1.2.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment gateway configuration and recovering stored wallet credentials in cleartext.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/9b1490a0-1381-4d22-8086-f75aade4e898/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:17:01.930",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81648"
                }
            ]
        },
        {
            "id": "CVE-2026-81638",
            "vendor": "ash-project",
            "product": "ash_double_entry",
            "title": "ash_double_entry vulnerability",
            "summary": "Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.\n\nAshDoubleEntry.ULID renders a 128-bit ULID as 26 Crockford base-32 characters, but the first character encodes only 3 bits, so canonical values are 0 to 7. decode/1 in lib/ulid.ex masks the first character to its low 3 bits and valid?/1 accepts all 32 characters in that position, so 0..., 8..., G... and R... decode to the identical 16-byte value and resolve to the same row. When the type is exposed as a public ID over an HTTP or API boundary, an attacker-supplied ID can be spelled differently from the record it actually reads or writes, desynchronizing or bypassing string-level checks such as idempotency and deduplication keys, deny-lists, audit correlation, or signatures computed over the submitted ID.\n\nThis issue affects ash_double_entry: from 0.1.0 before 1.0.19.",
            "updated_at": "2026-09-07T23:16:51.757",
            "published_at": "2026-09-07T23:16:51.757",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.1.0 through before 1.0.19 (semver); 1e5f7ce8ff25f519c904731a29eb1258324e561a through before d3e688d300a581ae214b3ca7d95ef4de63fbb050 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-173",
            "what_happened": "Improper Handling of Alternate Encoding vulnerability in ash-project ash_double_entry allows an attacker to submit several distinct string spellings of the same identifier.\n\nAshDoubleEntry.ULID renders a 128-bit ULID as 26 Crockford base-32 characters, but the first character encodes only 3 bits, so canonical values are 0 to 7. decode/1 in lib/ulid.ex masks the first character to its low 3 bits and valid?/1 accepts all 32 characters in that position, so 0..., 8..., G... and R... decode to the identical 16-byte value and resolve to the same row. When the type is exposed as a public ID over an HTTP or API boundary, an attacker-supplied ID can be spelled differently from the record it actually reads or writes, desynchronizing or bypassing string-level checks such as idempotency and deduplication keys, deny-lists, audit correlation, or signatures computed over the submitted ID.\n\nThis issue affects ash_double_entry: from 0.1.0 before 1.0.19.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-81638.html",
                "https://github.com/ash-project/ash_double_entry/commit/d3e688d300a581ae214b3ca7d95ef4de63fbb050",
                "https://github.com/ash-project/ash_double_entry/security/advisories/GHSA-qxp2-vgp9-268q",
                "https://osv.dev/vulnerability/EEF-CVE-2026-81638"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T23:16:51.757",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81638"
                }
            ]
        },
        {
            "id": "CVE-2026-81624",
            "vendor": "Red Hat",
            "product": "Red Hat build of Apache Camel for Spring Boot 4",
            "title": "Red Hat build of Apache Camel for Spring Boot 4 vulnerability",
            "summary": "Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send large amounts of data or maintain connections indefinitely, potentially crashing the server by exhausting its memory or other resources.",
            "updated_at": "2026-09-10T08:16:59.283",
            "published_at": "2026-08-31T09:17:03.453",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "Undertow is a flexible performant web server used in JBoss EAP and WildFly. A flaw was found in how Undertow handles WebSocket connections. Specifically, certain configuration limits like message buffer sizes and session timeouts cannot be adjusted and default to being unlimited. This allows a remote attacker to send large amounts of data or maintain connections indefinitely, potentially crashing the server by exhausting its memory or other resources.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/security/cve/CVE-2026-81624",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2524868"
            ],
            "timeline": [
                {
                    "at": "2026-08-31T09:17:03.453",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81624"
                }
            ]
        },
        {
            "id": "CVE-2026-81578",
            "vendor": "PaperCut",
            "product": "PaperCut MF/NG",
            "title": "PaperCut MF/NG vulnerability",
            "summary": "An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the  completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.",
            "updated_at": "2026-09-14T00:16:56.207",
            "published_at": "2026-08-28T16:18:29.600",
            "cvss": 8.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "before 24.1.10 (semver); 25.0.0 through before 25.0.13 (semver); 26.0.0 through before 26.0.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-305",
            "what_happened": "An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the  completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/",
                "https://github.com/rapid7/metasploit-framework/pull/21842",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81578"
            ],
            "timeline": [
                {
                    "at": "2026-08-28T16:18:29.600",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81578"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-31",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-81543",
            "vendor": "Tyche Softwares",
            "product": "Abandoned Cart Pro for WooCommerce",
            "title": "Abandoned Cart Pro for WooCommerce vulnerability",
            "summary": "The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_change_manual_email_data. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify SMTP connector settings to route administrator recovery emails through an attacker-controlled server and intercept auto-login links to gain full administrative access. The plugin's auto-login feature must be enabled, which is the default configuration.",
            "updated_at": "2026-09-05T08:16:40.730",
            "published_at": "2026-09-05T08:16:40.730",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 10.7.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_change_manual_email_data. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify SMTP connector settings to route administrator recovery emails through an attacker-controlled server and intercept auto-login links to gain full administrative access. The plugin's auto-login feature must be enabled, which is the default configuration.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://woocommerce.com/products/abandoned-cart-pro/",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/b8d8aa73-2e68-4353-a603-6fb61ab3406b?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:16:40.730",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81543"
                }
            ]
        },
        {
            "id": "CVE-2026-81468",
            "vendor": "Dell",
            "product": "ThinOS 10",
            "title": "ThinOS 10 vulnerability",
            "summary": "Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.",
            "updated_at": "2026-09-11T04:17:58.087",
            "published_at": "2026-09-10T16:17:58.157",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2605_10.2616 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T16:17:58.157",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81468"
                }
            ]
        },
        {
            "id": "CVE-2026-81467",
            "vendor": "Dell",
            "product": "ThinOS 10",
            "title": "ThinOS 10 vulnerability",
            "summary": "Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.",
            "updated_at": "2026-09-11T04:17:57.980",
            "published_at": "2026-09-10T16:17:58.040",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2605_10.2616 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T16:17:58.040",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81467"
                }
            ]
        },
        {
            "id": "CVE-2026-81429",
            "vendor": "Unknown",
            "product": "Export & Import WPBakery Page Builder",
            "title": "Export & Import WPBakery Page Builder vulnerability",
            "summary": "The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that results in Stored Cross-Site Scripting executed in the administrator's session.",
            "updated_at": "2026-09-12T16:16:40.280",
            "published_at": "2026-09-12T06:16:25.833",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.0.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data before storing it and echoing it back, allowing attackers to make a logged-in administrator import a crafted template via a forged request that results in Stored Cross-Site Scripting executed in the administrator's session.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/48f67510-9fb3-4f74-a38e-31635617ba60/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:25.833",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81429"
                }
            ]
        },
        {
            "id": "CVE-2026-81424",
            "vendor": "Unknown",
            "product": "Accept Stripe Payments",
            "title": "Accept Stripe Payments vulnerability",
            "summary": "The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for.",
            "updated_at": "2026-09-06T11:18:02.733",
            "published_at": "2026-09-05T07:17:12.997",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.1.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "The Accept Stripe Payments WordPress plugin before 2.1.4 does not verify that the product fulfilled when a checkout is completed matches the product the authoritative payment was actually made for, checking only that the amount paid is at least the referenced product's price, allowing unauthenticated attackers who complete a genuine payment to obtain fulfilment for a different, equal- or lower-priced product than the one they paid for.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/64c20ce4-d94d-4f09-8d95-9ba232066f62/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:12.997",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81424"
                }
            ]
        },
        {
            "id": "CVE-2026-81423",
            "vendor": "Unknown",
            "product": "Accept Stripe Payments",
            "title": "Accept Stripe Payments vulnerability",
            "summary": "The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged for phishing.",
            "updated_at": "2026-09-06T11:18:02.580",
            "published_at": "2026-09-05T07:17:12.900",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.1.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-601",
            "what_happened": "The Accept Stripe Payments WordPress plugin before 2.1.4 does not validate a user-supplied URL before using it in a redirect, allowing unauthenticated attackers to redirect visitors to an arbitrary external website, which can be leveraged for phishing.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/0e4bbbde-b93e-4b58-8baf-301073e9a0c5/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:12.900",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81423"
                }
            ]
        },
        {
            "id": "CVE-2026-81404",
            "vendor": "Unknown",
            "product": "IPGP Visitors Origin",
            "title": "IPGP Visitors Origin vulnerability",
            "summary": "The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request.",
            "updated_at": "2026-09-06T11:18:02.430",
            "published_at": "2026-09-05T07:17:12.810",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.3 through before 1.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users who are tricked into submitting a crafted request.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/8fbfb296-78d8-4f3b-ab21-7a5a4e0ea421/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:12.810",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81404"
                }
            ]
        },
        {
            "id": "CVE-2026-81402",
            "vendor": "Unknown",
            "product": "DS Ad Rotator",
            "title": "DS Ad Rotator vulnerability",
            "summary": "The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution.",
            "updated_at": "2026-09-12T16:16:40.140",
            "published_at": "2026-09-12T06:16:25.730",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthenticated attackers to upload arbitrary files, including PHP, to a web-accessible directory, which can lead to remote code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/60e82611-ddf1-4275-8c68-14694d863fca/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:25.730",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81402"
                }
            ]
        },
        {
            "id": "CVE-2026-81353",
            "vendor": "Microsoft",
            "product": "HEIF Image Extension",
            "title": "HEIF Image Extension vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.",
            "updated_at": "2026-09-11T04:17:57.577",
            "published_at": "2026-09-08T18:20:53.070",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0.0 through before 1.2.48.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81353"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:53.070",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81353"
                }
            ]
        },
        {
            "id": "CVE-2026-81348",
            "vendor": "Unknown",
            "product": "My Private Site",
            "title": "My Private Site vulnerability",
            "summary": "The My Private Site  WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login.",
            "updated_at": "2026-09-06T11:18:02.277",
            "published_at": "2026-09-05T07:17:12.710",
            "cvss": 3.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.2.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-200",
            "what_happened": "The My Private Site  WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthenticated front-end read surfaces, allowing unauthenticated users to view post content, comments and post URLs from a site the administrator placed behind mandatory login.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/54228ea4-eec6-4752-a16e-85209d4445b0/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:12.710",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81348"
                }
            ]
        },
        {
            "id": "CVE-2026-81302",
            "vendor": "JAL Digital Co.,Ltd.",
            "product": "PALLET CONTROL",
            "title": "PALLET CONTROL vulnerability",
            "summary": "PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.",
            "updated_at": "2026-09-07T06:17:20.180",
            "published_at": "2026-09-04T09:17:11.230",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-276",
            "what_happened": "PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jvn.jp/en/jp/JVN84094853/",
                "https://www.jaldx.co.jp/solution/palletcontrol/2026/08/31/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T09:17:11.230",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81302"
                }
            ]
        },
        {
            "id": "CVE-2026-81268",
            "vendor": "IBM",
            "product": "Langflow OSS",
            "title": "Langflow OSS vulnerability",
            "summary": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.",
            "updated_at": "2026-09-12T04:16:39.107",
            "published_at": "2026-09-10T22:17:02.390",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through 1.11.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-613",
            "what_happened": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286662"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:17:02.390",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81268"
                }
            ]
        },
        {
            "id": "CVE-2026-81240",
            "vendor": "Dell",
            "product": "Wyse Management Suite",
            "title": "Wyse Management Suite vulnerability",
            "summary": "Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
            "updated_at": "2026-09-16T04:18:42.457",
            "published_at": "2026-09-15T18:19:24.630",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before WMS 2605.0.3.683 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000502744/dsa-2026-387-security-update-for-dell-wyse-management-suite-wms-for-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T18:19:24.630",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81240"
                }
            ]
        },
        {
            "id": "CVE-2026-81239",
            "vendor": "Dell",
            "product": "Wyse Management Suite",
            "title": "Wyse Management Suite vulnerability",
            "summary": "Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
            "updated_at": "2026-09-16T04:18:42.240",
            "published_at": "2026-09-15T18:19:24.513",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before WMS 2605.0.3.683 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000502744/dsa-2026-387-security-update-for-dell-wyse-management-suite-wms-for-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T18:19:24.513",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81239"
                }
            ]
        },
        {
            "id": "CVE-2026-81236",
            "vendor": "Dell",
            "product": "Wyse Management Suite",
            "title": "Wyse Management Suite vulnerability",
            "summary": "Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
            "updated_at": "2026-09-16T04:18:42.057",
            "published_at": "2026-09-15T18:19:24.147",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before WMS 2605.0.3.683 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000502744/dsa-2026-387-security-update-for-dell-wyse-management-suite-wms-for-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T18:19:24.147",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81236"
                }
            ]
        },
        {
            "id": "CVE-2026-81235",
            "vendor": "Dell",
            "product": "Wyse Management Suite",
            "title": "Wyse Management Suite vulnerability",
            "summary": "Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.",
            "updated_at": "2026-09-16T04:18:41.777",
            "published_at": "2026-09-15T18:19:24.023",
            "cvss": 8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before WMS 2605.0.3.683 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-325",
            "what_happened": "Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000502744/dsa-2026-387-security-update-for-dell-wyse-management-suite-wms-for-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T18:19:24.023",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81235"
                }
            ]
        },
        {
            "id": "CVE-2026-81211",
            "vendor": "IBM",
            "product": "Langflow OSS",
            "title": "Langflow OSS vulnerability",
            "summary": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.",
            "updated_at": "2026-09-12T04:16:38.973",
            "published_at": "2026-09-10T22:17:01.977",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through 1.11.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286666"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:17:01.977",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81211"
                }
            ]
        },
        {
            "id": "CVE-2026-81204",
            "vendor": "IBM",
            "product": "Langflow OSS",
            "title": "Langflow OSS vulnerability",
            "summary": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.",
            "updated_at": "2026-09-12T04:16:38.837",
            "published_at": "2026-09-10T22:17:01.580",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through 1.11.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286666"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:17:01.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81204"
                }
            ]
        },
        {
            "id": "CVE-2026-81090",
            "vendor": "Unknown",
            "product": "Gpx2Graphics",
            "title": "Gpx2Graphics vulnerability",
            "summary": "The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.",
            "updated_at": "2026-09-12T16:16:40.007",
            "published_at": "2026-09-12T06:16:25.620",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-352",
            "what_happened": "The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/92e50025-cfa4-4727-bd02-8f45196021ae/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:25.620",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81090"
                }
            ]
        },
        {
            "id": "CVE-2026-81049",
            "vendor": "Dell",
            "product": "ThinOS 10",
            "title": "ThinOS 10 vulnerability",
            "summary": "Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.",
            "updated_at": "2026-09-11T04:17:57.467",
            "published_at": "2026-09-10T16:17:57.670",
            "cvss": 4.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2605_10.2616 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-353",
            "what_happened": "Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T16:17:57.670",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81049"
                }
            ]
        },
        {
            "id": "CVE-2026-81048",
            "vendor": "Dell",
            "product": "ThinOS 10",
            "title": "ThinOS 10 vulnerability",
            "summary": "Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution",
            "updated_at": "2026-09-11T04:17:57.060",
            "published_at": "2026-09-10T16:17:57.543",
            "cvss": 9.6,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2605_10.2616 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T16:17:57.543",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81048"
                }
            ]
        },
        {
            "id": "CVE-2026-81046",
            "vendor": "Dell",
            "product": "ThinOS 10",
            "title": "ThinOS 10 vulnerability",
            "summary": "Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.",
            "updated_at": "2026-09-11T04:17:56.037",
            "published_at": "2026-09-10T16:17:57.417",
            "cvss": 9.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2605_10.2616 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000502746/dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T16:17:57.417",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81046"
                }
            ]
        },
        {
            "id": "CVE-2026-81017",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/chrome: sensorhub: Bound the EC-reported sensor number\n\nEach EC FIFO event carries an 8-bit sensor number (in->sensor_num).\ncros_ec_sensorhub_ring_handler() validates the FIFO event count, the\nper-read count and the ring bound, but not the sensor number, which\ncros_ec_sensor_ring_process_event() then uses unchecked to index\nsensorhub->batch_state[] - allocated with only sensorhub->sensor_num\nentries. A sensor number of sensor_num or larger is an out-of-bounds\nread and write of batch_state[].\n\nValidate the sensor number in the ring handler, where each event is read\nfrom the EC, and drop a malformed event before it is used.",
            "updated_at": "2026-09-13T07:17:08.230",
            "published_at": "2026-09-11T20:19:10.680",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "145d59baff5944b71551ac518d7fd7d377a9c820 through before 3d2636dce0a8fe9eecad29010699847be425dc80 (git); 145d59baff5944b71551ac518d7fd7d377a9c820 through before 5eaf7faa99578ae090030d1e2e6ea3b37a615496 (git); 145d59baff5944b71551ac518d7fd7d377a9c820 through before 4d9bf63ed74f859c6698bc01d8fb216ef9253867 (git); 145d59baff5944b71551ac518d7fd7d377a9c820 through before 833740a2333c2e4db4e02e3d0ffba04e8718a5f3 (git); 5.7",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/chrome: sensorhub: Bound the EC-reported sensor number\n\nEach EC FIFO event carries an 8-bit sensor number (in->sensor_num).\ncros_ec_sensorhub_ring_handler() validates the FIFO event count, the\nper-read count and the ring bound, but not the sensor number, which\ncros_ec_sensor_ring_process_event() then uses unchecked to index\nsensorhub->batch_state[] - allocated with only sensorhub->sensor_num\nentries. A sensor number of sensor_num or larger is an out-of-bounds\nread and write of batch_state[].\n\nValidate the sensor number in the ring handler, where each event is read\nfrom the EC, and drop a malformed event before it is used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/3d2636dce0a8fe9eecad29010699847be425dc80",
                "https://git.kernel.org/stable/c/4d9bf63ed74f859c6698bc01d8fb216ef9253867",
                "https://git.kernel.org/stable/c/5eaf7faa99578ae090030d1e2e6ea3b37a615496",
                "https://git.kernel.org/stable/c/833740a2333c2e4db4e02e3d0ffba04e8718a5f3"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:10.680",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81017"
                }
            ]
        },
        {
            "id": "CVE-2026-81016",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86/amd/pmc: Propagate SMU errors and validate S2D address\n\namd_stb_s2d_init() discards the return value of several S2D SMU commands.\nWhen the SMU refuses a command (e.g. \"SMU cmd failed. err: 0xff\") the\nfailure is only noticed indirectly - if at all - and reported as -EIO,\nmasking the real error.\n\nMore seriously, the S2D_PHYS_ADDR_LOW/HIGH return values are ignored, so\non failure phys_addr_low/hi are left uninitialised and the assembled\naddress is passed straight to devm_ioremap().  When the SMU leaves them at\nzero this maps physical address 0 and trips the ioremap-on-RAM warning:\n\n  amd_pmc AMDI000B:00: SMU cmd failed. err: 0xff\n  ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff\n  WARNING: CPU: 13 PID: 4592 at arch/x86/mm/ioremap.c:...\n\nCheck the return value of each SMU command and propagate it, and reject a\nzero physical address before calling devm_ioremap().",
            "updated_at": "2026-09-13T07:17:08.107",
            "published_at": "2026-09-11T20:19:10.560",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d through before 8178f59d76570b152d836bde07f5997f15861f04 (git); 3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d through before 775d4cde1f9737796ce7d8393521e9e8c5b49891 (git); 3d7d407dfb05b257e15cb0c6b056428a4a8c2e5d through before 0225c1d637687b03726f00ac65b6def843d2c464 (git); 5.18",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86/amd/pmc: Propagate SMU errors and validate S2D address\n\namd_stb_s2d_init() discards the return value of several S2D SMU commands.\nWhen the SMU refuses a command (e.g. \"SMU cmd failed. err: 0xff\") the\nfailure is only noticed indirectly - if at all - and reported as -EIO,\nmasking the real error.\n\nMore seriously, the S2D_PHYS_ADDR_LOW/HIGH return values are ignored, so\non failure phys_addr_low/hi are left uninitialised and the assembled\naddress is passed straight to devm_ioremap().  When the SMU leaves them at\nzero this maps physical address 0 and trips the ioremap-on-RAM warning:\n\n  amd_pmc AMDI000B:00: SMU cmd failed. err: 0xff\n  ioremap on RAM at 0x0000000000000000 - 0x0000000000ffffff\n  WARNING: CPU: 13 PID: 4592 at arch/x86/mm/ioremap.c:...\n\nCheck the return value of each SMU command and propagate it, and reject a\nzero physical address before calling devm_ioremap().",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0225c1d637687b03726f00ac65b6def843d2c464",
                "https://git.kernel.org/stable/c/775d4cde1f9737796ce7d8393521e9e8c5b49891",
                "https://git.kernel.org/stable/c/8178f59d76570b152d836bde07f5997f15861f04"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:10.560",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81016"
                }
            ]
        },
        {
            "id": "CVE-2026-81015",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails\n\namd_pmc_probe() registers the LPS0 s2idle handler with\nacpi_register_lps0_dev() and creates the driver's debugfs directory before\ncalling amd_stb_s2d_init(), which is the last step in probe that can fail.\n\nWhen amd_stb_s2d_init() fails (for example the S2D telemetry region cannot\nbe ioremapped on a long-running system, or the SMU rejects the S2D setup)\nthe error path only calls pci_dev_put() and returns.  This leaves\namd_pmc_s2idle_dev_ops on the global lps0_s2idle_devops_head list and leaks\nthe debugfs directory, while the devm-managed resources backing the handler\nare torn down.\n\nReloading the module then walks the corrupted list in\nacpi_register_lps0_dev() and hits:\n\n  list_add corruption. next->prev should be prev, but was NULL.\n  kernel BUG at lib/list_debug.c:29!\n   acpi_register_lps0_dev+0x44/0x80\n   amd_pmc_probe+0x224/0x380 [amd_pmc]\n   platform_probe+0x67/0x90\n\nEven without a reload, the stale registration means the next s2idle\ntransition calls into torn-down driver state.\n\nUnwind the debugfs directory and the LPS0 registration on the\namd_stb_s2d_init() error path.  acpi_unregister_lps0_dev() is safe to call\nunconditionally here: it is guarded on the same conditions as\nacpi_register_lps0_dev(), which is exactly what amd_pmc_remove() already\nrelies on.",
            "updated_at": "2026-09-13T07:17:07.983",
            "published_at": "2026-09-11T20:19:10.437",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "83ad6974dd3bf34c080b3c08d36d02ebc3bd6da8 through before bc9aa5fe21c3966c80647ed6574b94b863f23c62 (git); 83ad6974dd3bf34c080b3c08d36d02ebc3bd6da8 through before 30e5f4d0cd0be655c800f10ae3e530391aa6c1b5 (git); 83ad6974dd3bf34c080b3c08d36d02ebc3bd6da8 through before 76f650a76d6a36a4bee79d94db90a0e935a95477 (git); 6.14",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86/amd/pmc: Fix LPS0 and debugfs leaks when STB init fails\n\namd_pmc_probe() registers the LPS0 s2idle handler with\nacpi_register_lps0_dev() and creates the driver's debugfs directory before\ncalling amd_stb_s2d_init(), which is the last step in probe that can fail.\n\nWhen amd_stb_s2d_init() fails (for example the S2D telemetry region cannot\nbe ioremapped on a long-running system, or the SMU rejects the S2D setup)\nthe error path only calls pci_dev_put() and returns.  This leaves\namd_pmc_s2idle_dev_ops on the global lps0_s2idle_devops_head list and leaks\nthe debugfs directory, while the devm-managed resources backing the handler\nare torn down.\n\nReloading the module then walks the corrupted list in\nacpi_register_lps0_dev() and hits:\n\n  list_add corruption. next->prev should be prev, but was NULL.\n  kernel BUG at lib/list_debug.c:29!\n   acpi_register_lps0_dev+0x44/0x80\n   amd_pmc_probe+0x224/0x380 [amd_pmc]\n   platform_probe+0x67/0x90\n\nEven without a reload, the stale registration means the next s2idle\ntransition calls into torn-down driver state.\n\nUnwind the debugfs directory and the LPS0 registration on the\namd_stb_s2d_init() error path.  acpi_unregister_lps0_dev() is safe to call\nunconditionally here: it is guarded on the same conditions as\nacpi_register_lps0_dev(), which is exactly what amd_pmc_remove() already\nrelies on.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/30e5f4d0cd0be655c800f10ae3e530391aa6c1b5",
                "https://git.kernel.org/stable/c/76f650a76d6a36a4bee79d94db90a0e935a95477",
                "https://git.kernel.org/stable/c/bc9aa5fe21c3966c80647ed6574b94b863f23c62"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:10.437",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81015"
                }
            ]
        },
        {
            "id": "CVE-2026-81012",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()\n\nhp_get_string_from_buffer() clamps the converted string length against\nthe destination buffer size with \"size > dst_size\", so when the\nconverted length is exactly equal to dst_size, conv_dst_size is left\nat dst_size and the unconditional NUL terminator write\n\n\tdst[conv_dst_size] = 0;\n\nlands one byte past the destination buffer. This is the same shape of\nbug as the previously fixed off-by-one in hp_convert_hexstr_to_str():\nthe buffer is sized correctly for the content, but the terminator\nwrite is never checked against that size.\n\nFix by changing the comparison to \">=\" so conv_dst_size is always left\nwith room for the terminator.\n\nAll fixed-size destinations that reach this function (path[512],\ncurrent_value[512], current_password/current_value[64], and the\nper-entry buffers in encodings[][512] and prerequisites[][512]) are\naffected.",
            "updated_at": "2026-09-13T07:17:07.880",
            "published_at": "2026-09-11T20:19:10.050",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "a34fc329b1895fc8a6eb12099adc47009421ba6a through before 3cc772d0154799961f032e5a992d4a50523e291a (git); a34fc329b1895fc8a6eb12099adc47009421ba6a through before b15b334fbc3c0c46440f8a892ebf62164fca23d6 (git); a34fc329b1895fc8a6eb12099adc47009421ba6a through before ddf98cf33529714b3ba1a158afb1db5b0f759a1a (git); a34fc329b1895fc8a6eb12099adc47009421ba6a through before dc03f05e419f3460342fb7564884f244622634b6 (git); 6.6",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer()\n\nhp_get_string_from_buffer() clamps the converted string length against\nthe destination buffer size with \"size > dst_size\", so when the\nconverted length is exactly equal to dst_size, conv_dst_size is left\nat dst_size and the unconditional NUL terminator write\n\n\tdst[conv_dst_size] = 0;\n\nlands one byte past the destination buffer. This is the same shape of\nbug as the previously fixed off-by-one in hp_convert_hexstr_to_str():\nthe buffer is sized correctly for the content, but the terminator\nwrite is never checked against that size.\n\nFix by changing the comparison to \">=\" so conv_dst_size is always left\nwith room for the terminator.\n\nAll fixed-size destinations that reach this function (path[512],\ncurrent_value[512], current_password/current_value[64], and the\nper-entry buffers in encodings[][512] and prerequisites[][512]) are\naffected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/3cc772d0154799961f032e5a992d4a50523e291a",
                "https://git.kernel.org/stable/c/b15b334fbc3c0c46440f8a892ebf62164fca23d6",
                "https://git.kernel.org/stable/c/dc03f05e419f3460342fb7564884f244622634b6",
                "https://git.kernel.org/stable/c/ddf98cf33529714b3ba1a158afb1db5b0f759a1a"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:10.050",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81012"
                }
            ]
        },
        {
            "id": "CVE-2026-81011",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: hp-bioscfg: pass validated element count to package parsers\n\nThe per-type package parsers are handed the wrong element count.\n\nhp_init_bios_package_attribute() validates obj->package.count and then\ncalls one of the five hp_populate_*_package_data() wrappers (string,\ninteger, enumeration, ordered list, password). Each wrapper forwards a\ncount to its hp_populate_*_elements_from_package() parser, but instead\nof forwarding the validated obj->package.count it derives the count\nfrom elements[0]. elements[0] is the NAME field and is always an\nACPI_TYPE_STRING, so reading ->package.count from it in fact reads\n->string.length through the union acpi_object. The parsers thus bound\nthemselves against the length of the name string rather than against\nthe real number of elements in the package.\n\nThis is safe today because hp_init_bios_package_attribute() refuses any\npackage that has fewer than the type's element count, so a parser only\never runs on a full package and never reads past it regardless of the\nbogus bound.\n\nAn upcoming change relaxes that check to accept shorter packages. Once\na parser can receive fewer elements than its per-type count, a bound\ntaken from the name length no longer reflects the array size, and the\n\"elem < count\" loop conditions and \"elem + n >= count\" sub-loop guards\nread past the end of elements[] - an out-of-bounds heap read.\n\nForward the validated obj->package.count to every *_package_data()\nwrapper so the parsers bound themselves against the real package size.\nThis does not change behaviour for the packages that enumerate\ncorrectly today and is a prerequisite for accepting shorter packages\nsafely.",
            "updated_at": "2026-09-13T07:17:07.770",
            "published_at": "2026-09-11T20:19:09.927",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "a34fc329b1895fc8a6eb12099adc47009421ba6a through before 436017808c7cbcdb5e49b2142090d4391e3de9a6 (git); a34fc329b1895fc8a6eb12099adc47009421ba6a through before a38127df99ae8b1851560b35b837c9952416143a (git); a34fc329b1895fc8a6eb12099adc47009421ba6a through before 400cbc3ccc88a5ad37cd85056224635ce9eba018 (git); a34fc329b1895fc8a6eb12099adc47009421ba6a through before e0ddfd77c0c320b7d12b6c9169303b140b798775 (git); 6.6",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: hp-bioscfg: pass validated element count to package parsers\n\nThe per-type package parsers are handed the wrong element count.\n\nhp_init_bios_package_attribute() validates obj->package.count and then\ncalls one of the five hp_populate_*_package_data() wrappers (string,\ninteger, enumeration, ordered list, password). Each wrapper forwards a\ncount to its hp_populate_*_elements_from_package() parser, but instead\nof forwarding the validated obj->package.count it derives the count\nfrom elements[0]. elements[0] is the NAME field and is always an\nACPI_TYPE_STRING, so reading ->package.count from it in fact reads\n->string.length through the union acpi_object. The parsers thus bound\nthemselves against the length of the name string rather than against\nthe real number of elements in the package.\n\nThis is safe today because hp_init_bios_package_attribute() refuses any\npackage that has fewer than the type's element count, so a parser only\never runs on a full package and never reads past it regardless of the\nbogus bound.\n\nAn upcoming change relaxes that check to accept shorter packages. Once\na parser can receive fewer elements than its per-type count, a bound\ntaken from the name length no longer reflects the array size, and the\n\"elem < count\" loop conditions and \"elem + n >= count\" sub-loop guards\nread past the end of elements[] - an out-of-bounds heap read.\n\nForward the validated obj->package.count to every *_package_data()\nwrapper so the parsers bound themselves against the real package size.\nThis does not change behaviour for the packages that enumerate\ncorrectly today and is a prerequisite for accepting shorter packages\nsafely.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/400cbc3ccc88a5ad37cd85056224635ce9eba018",
                "https://git.kernel.org/stable/c/436017808c7cbcdb5e49b2142090d4391e3de9a6",
                "https://git.kernel.org/stable/c/a38127df99ae8b1851560b35b837c9952416143a",
                "https://git.kernel.org/stable/c/e0ddfd77c0c320b7d12b6c9169303b140b798775"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:09.927",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81011"
                }
            ]
        },
        {
            "id": "CVE-2026-81010",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/waitid: honor task_work cancellation\n\nio_waitid_cb() may run through the fallback task_work path when\ntask_work_add() can no longer queue work to the originating task. The\nfallback runs from a kworker and io_uring marks such task work as\ncanceled through tw.cancel.\n\nio_waitid_cb() currently ignores tw.cancel and calls __do_wait().\nwaitid is task-context dependent: __do_wait() performs child lookup\nrelative to current, and the retry path also uses\ncurrent->signal->wait_chldexit. If the callback runs from the fallback\nkworker, current is therefore not the task that submitted the request.\n\nHonor tw.cancel before entering __do_wait(). Complete the request with\n-ECANCELED and skip the siginfo copy, since canceled task work may run\nwithout the submitting task's userspace execution context.\n\nKeep the existing siginfo handling for normal waitid completion and\nexplicit cancellation.",
            "updated_at": "2026-09-13T07:17:07.653",
            "published_at": "2026-09-11T20:19:09.813",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f31ecf671ddc498f20219453395794ff2383e06b through before 7bc98e2de8c58a2bfaf0f540eb096a386ecfc96c (git); f31ecf671ddc498f20219453395794ff2383e06b through before 14572de82e5022899e5856008bc9cac97004a88c (git); 6.7",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/waitid: honor task_work cancellation\n\nio_waitid_cb() may run through the fallback task_work path when\ntask_work_add() can no longer queue work to the originating task. The\nfallback runs from a kworker and io_uring marks such task work as\ncanceled through tw.cancel.\n\nio_waitid_cb() currently ignores tw.cancel and calls __do_wait().\nwaitid is task-context dependent: __do_wait() performs child lookup\nrelative to current, and the retry path also uses\ncurrent->signal->wait_chldexit. If the callback runs from the fallback\nkworker, current is therefore not the task that submitted the request.\n\nHonor tw.cancel before entering __do_wait(). Complete the request with\n-ECANCELED and skip the siginfo copy, since canceled task work may run\nwithout the submitting task's userspace execution context.\n\nKeep the existing siginfo handling for normal waitid completion and\nexplicit cancellation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/14572de82e5022899e5856008bc9cac97004a88c",
                "https://git.kernel.org/stable/c/7bc98e2de8c58a2bfaf0f540eb096a386ecfc96c"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:09.813",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81010"
                }
            ]
        },
        {
            "id": "CVE-2026-81008",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ninterconnect: Fix use after free in icc_get() and of_icc_get_by_index()\n\nIn of_icc_get_by_index() and icc_get(), if the dynamic allocation for\npath->name fails via kasprintf(), the error handling path directly\ncalls kfree(path) to free the path object and returns an error.\n\nHowever, prior to this point, path_find() calls path_init(), which\nalready links the path's requests into the req_list of the respective\ninterconnect nodes via hlist_add_head(). Directly invoking kfree(path)\nleaves dangling pointers in the hlist. A subsequent call to icc_get()\nor icc_set_bw() will traverse or modify these corrupted lists, triggering\na slab use afterfree.\n\nKASAN report showing the vulnerability when reproducing via debugfs:\n\n  BUG: KASAN: slab-use-after-free in path_find+0x6f8/0xcfc\n  Write of size 8 at addr fff000000d43f748 by task sh/1\n  ...\n  Call trace:\n   kasan_report+0xac/0xfc\n   path_find+0x6f8/0xcfc\n   icc_get+0x148/0x380\n   icc_get_set+0xf8/0x2d0\n  ...\n  Freed by task 1:\n   kfree+0x1a0/0x4a4\n   icc_get+0x2cc/0x380\n   icc_get_set+0xf8/0x2d0\n\nFix this by replacing kfree(path) with the proper teardown function,\nicc_put(path), which safely removes the requests from the req_list using\nhlist_del() and drops the provider usage references before freeing the\nmemory.\n\nAdditionally, in icc_get(), ensure that the icc_lock mutex is released\nprior to calling icc_put(path) to avoid a deadlock, as icc_put()\ninternally acquires the same lock.",
            "updated_at": "2026-09-13T07:17:07.517",
            "published_at": "2026-09-11T20:19:09.560",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3791163602f7140011a8dc1691cfe6ec0cb1ef07 through before a4e9aa7907ade87d1d96853d14e05dcf682f8363 (git); 3791163602f7140011a8dc1691cfe6ec0cb1ef07 through before db8147c5d5ad2cfa21c2be566f95981b41b05de6 (git); 3791163602f7140011a8dc1691cfe6ec0cb1ef07 through before d715d19cfcfe99f361adb05cefc143a95d400b87 (git); 3791163602f7140011a8dc1691cfe6ec0cb1ef07 through before 25c7e242aca084fdc1098248194032317dca625d (git); 5.6",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ninterconnect: Fix use after free in icc_get() and of_icc_get_by_index()\n\nIn of_icc_get_by_index() and icc_get(), if the dynamic allocation for\npath->name fails via kasprintf(), the error handling path directly\ncalls kfree(path) to free the path object and returns an error.\n\nHowever, prior to this point, path_find() calls path_init(), which\nalready links the path's requests into the req_list of the respective\ninterconnect nodes via hlist_add_head(). Directly invoking kfree(path)\nleaves dangling pointers in the hlist. A subsequent call to icc_get()\nor icc_set_bw() will traverse or modify these corrupted lists, triggering\na slab use afterfree.\n\nKASAN report showing the vulnerability when reproducing via debugfs:\n\n  BUG: KASAN: slab-use-after-free in path_find+0x6f8/0xcfc\n  Write of size 8 at addr fff000000d43f748 by task sh/1\n  ...\n  Call trace:\n   kasan_report+0xac/0xfc\n   path_find+0x6f8/0xcfc\n   icc_get+0x148/0x380\n   icc_get_set+0xf8/0x2d0\n  ...\n  Freed by task 1:\n   kfree+0x1a0/0x4a4\n   icc_get+0x2cc/0x380\n   icc_get_set+0xf8/0x2d0\n\nFix this by replacing kfree(path) with the proper teardown function,\nicc_put(path), which safely removes the requests from the req_list using\nhlist_del() and drops the provider usage references before freeing the\nmemory.\n\nAdditionally, in icc_get(), ensure that the icc_lock mutex is released\nprior to calling icc_put(path) to avoid a deadlock, as icc_put()\ninternally acquires the same lock.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/25c7e242aca084fdc1098248194032317dca625d",
                "https://git.kernel.org/stable/c/a4e9aa7907ade87d1d96853d14e05dcf682f8363",
                "https://git.kernel.org/stable/c/d715d19cfcfe99f361adb05cefc143a95d400b87",
                "https://git.kernel.org/stable/c/db8147c5d5ad2cfa21c2be566f95981b41b05de6"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:09.560",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81008"
                }
            ]
        },
        {
            "id": "CVE-2026-81007",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: ipmb: validate write message length\n\nipmb_write() read message fields before validating the length byte.\n\nA zero or short write can read uninitialized stack bytes.\n\nA length smaller than the SMBus header underflows the block write length.\n\nRequire a non-empty buffer and the minimum IPMB request length.\n\nAlso require the length byte plus payload before parsing the message.",
            "updated_at": "2026-09-13T07:17:07.393",
            "published_at": "2026-09-11T20:19:09.443",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "51bd6f291583684f495ea498984dfc22049d7fd2 through before 60939bcda6f3f104ef456fdbf3cc5733c0720fb1 (git); 51bd6f291583684f495ea498984dfc22049d7fd2 through before 5719431ca2b5fa26560bb38f6202f8b97fa3bbb0 (git); 51bd6f291583684f495ea498984dfc22049d7fd2 through before a84c6e3d188f2c6e674910929eb790634299d6d5 (git); 51bd6f291583684f495ea498984dfc22049d7fd2 through before 53637506884dbd5c91a89b1a3547d99d80f8ed2c (git); 5.3",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: ipmb: validate write message length\n\nipmb_write() read message fields before validating the length byte.\n\nA zero or short write can read uninitialized stack bytes.\n\nA length smaller than the SMBus header underflows the block write length.\n\nRequire a non-empty buffer and the minimum IPMB request length.\n\nAlso require the length byte plus payload before parsing the message.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/53637506884dbd5c91a89b1a3547d99d80f8ed2c",
                "https://git.kernel.org/stable/c/5719431ca2b5fa26560bb38f6202f8b97fa3bbb0",
                "https://git.kernel.org/stable/c/60939bcda6f3f104ef456fdbf3cc5733c0720fb1",
                "https://git.kernel.org/stable/c/a84c6e3d188f2c6e674910929eb790634299d6d5"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:09.443",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81007"
                }
            ]
        },
        {
            "id": "CVE-2026-81006",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: Remove all sysfs files on registration failure\n\nipmi_add_smi() creates the nr_users and nr_msgs files before trying to\ncreate the maintenance_mode file. If that last creation fails, the error\npath removes only nr_users before dropping the final reference to the\ninterface.\n\nRemove nr_msgs as well so no sysfs attribute embedded in the freed\ninterface remains registered.",
            "updated_at": "2026-09-13T07:17:07.273",
            "published_at": "2026-09-11T20:19:09.313",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "627118470fccc61d7763aa667fcab0a9476843f6 through before d46c97eddcbc53ca885e8bb359930c58884616ff (git); 627118470fccc61d7763aa667fcab0a9476843f6 through before b115b7d06f26b3f000d2afda88acb54c7a7cb2c9 (git); 627118470fccc61d7763aa667fcab0a9476843f6 through before b6c46ab0bdee90c238e96ea4a74972118c97900d (git); 6.18",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: Remove all sysfs files on registration failure\n\nipmi_add_smi() creates the nr_users and nr_msgs files before trying to\ncreate the maintenance_mode file. If that last creation fails, the error\npath removes only nr_users before dropping the final reference to the\ninterface.\n\nRemove nr_msgs as well so no sysfs attribute embedded in the freed\ninterface remains registered.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/b115b7d06f26b3f000d2afda88acb54c7a7cb2c9",
                "https://git.kernel.org/stable/c/b6c46ab0bdee90c238e96ea4a74972118c97900d",
                "https://git.kernel.org/stable/c/d46c97eddcbc53ca885e8bb359930c58884616ff"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:09.313",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81006"
                }
            ]
        },
        {
            "id": "CVE-2026-81004",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nipmi:msghandler: Cancel work cleanly on an error\n\nIf an error occurs during startup of an IPMI interface, it may have\nscheduled work to run.  The work needs to be canceled before the\ninterface can be freed.",
            "updated_at": "2026-09-13T07:17:07.157",
            "published_at": "2026-09-11T20:19:09.057",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "edb6c2118293c1fba9cd11ca80ed043d2411a7e5 through before 99692252b348c11377fd0cdd66b6b18f3b22758e (git); 62cd145453d577113f993efd025f258dd86aa183 through before a496c51dd3257ed7e00873af2ad9bb22c3ddc4cf (git); 62cd145453d577113f993efd025f258dd86aa183 through before ae84a2536577057e97f23f75a202e26d0e86cf01 (git); 5199fc5dc9c519115457406009fcefd50721c995 (git); 6.18.20 through before 6.18.50 (semver); 6.19.10 through before 6.20 (semver); 7.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nipmi:msghandler: Cancel work cleanly on an error\n\nIf an error occurs during startup of an IPMI interface, it may have\nscheduled work to run.  The work needs to be canceled before the\ninterface can be freed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/99692252b348c11377fd0cdd66b6b18f3b22758e",
                "https://git.kernel.org/stable/c/a496c51dd3257ed7e00873af2ad9bb22c3ddc4cf",
                "https://git.kernel.org/stable/c/ae84a2536577057e97f23f75a202e26d0e86cf01"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:09.057",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81004"
                }
            ]
        },
        {
            "id": "CVE-2026-81003",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/iucv: filter frames in afiucv_hs_rcv() by ingress device\n\nafiucv_hs_rcv() selects a socket from iucv_sk_list by matching four 8-byte\nname fields in the transport header alone. No check is made against the\nnet_device the frame arrived on.\n\nThis can cause a frame arriving on any netdev to be delivered to an AF_IUCV\nsocket. Three problems follow.\n\nFirst, a frame arriving over HiperSockets can be delivered to a socket\nbound to the classic z/VM IUCV transport, which has iucv->hs_dev == NULL.\niucv_sock_bind() takes the classic path whenever the requested userid\nmatches iucv_userid, even on a guest that also has a HiperSockets device\ncarrying the same identifier. The child socket created by\nafiucv_hs_callback_syn() for such a match inherits hs_dev = NULL and\ntransport = AF_IUCV_TRANS_HIPER, so the first send() on it returns -ENODEV.\nThe socket delivered to accept() is unusable.\n\nSecond, a frame arriving on one netdev can be delivered to a socket bound\nto a different IQD device. Which can lead to\n- Accept-queue exhaustion (DoS)\n- Attacker-controlled peer identity in the child socket\n- Data injection into existing sockets\n- Fabric noise on the IQD fabric, where bogus replies are sent\n- killing established connections\n\nThird, all AF_IUCV sockets live in init_net, as iucv_sock_alloc() calls\nsk_alloc(&init_net, ...). But even frames arriving on netdev devices in a\nnamespace can be delivered to an IUCV socket. So a process in an\nunprivileged user and network namespace holding only the CAP_NET_RAW\ncapability valid within that namespace can send a raw ETH_P_AF_IUCV frame\non its own lo device and have it matched against init_net sockets.\n\nFix all three by skipping any socket whose hs_dev does not match the\ningress device. A classic z/VM IUCV socket has hs_dev == NULL; the ingress\ndev is never NULL, so classic sockets are skipped automatically. An unbound\nHIPER socket also has hs_dev == NULL and is skipped. A bound HIPER socket\nis only reachable from the exact IQD device it was bound to. Because hs_dev\nis always a device in init_net (iucv_sock_bind() scans\nfor_each_netdev_rcu(&init_net, ...) exclusively), a frame whose ingress\ndevice belongs to another namespace never matches any socket.\n\nNote that AF_IUCV over HiperSockets provides no per-connection\nauthentication: no sequence numbers, no TLS, no nonce. The four name fields\nidentifying a connection are exchanged in plaintext on the shared\nHiperSockets segment (VCHID). Any host on the same HiperSockets segment\ncould spoof any frame type against an existing connection. That is a\nprotocol-level property unchanged by this patch. The fix reduces the attack\nsurface to peers present on the same HiperSockets segment.",
            "updated_at": "2026-09-13T07:17:07.013",
            "published_at": "2026-09-11T20:19:08.863",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3881ac441f642d56503818123446f7298442236b through before dfac2936b83be00035ae176f8252e1c1e1de9207 (git); 3881ac441f642d56503818123446f7298442236b through before 8e3763f1ccac3fc395f9af2b87114c023ced8a3f (git); 3881ac441f642d56503818123446f7298442236b through before a7f0130a091724e69827ab58e74777a88747e892 (git); 3881ac441f642d56503818123446f7298442236b through before 80230a18c164a4b5bbc048fe2768b219ac17bc5a (git); 3.2",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/iucv: filter frames in afiucv_hs_rcv() by ingress device\n\nafiucv_hs_rcv() selects a socket from iucv_sk_list by matching four 8-byte\nname fields in the transport header alone. No check is made against the\nnet_device the frame arrived on.\n\nThis can cause a frame arriving on any netdev to be delivered to an AF_IUCV\nsocket. Three problems follow.\n\nFirst, a frame arriving over HiperSockets can be delivered to a socket\nbound to the classic z/VM IUCV transport, which has iucv->hs_dev == NULL.\niucv_sock_bind() takes the classic path whenever the requested userid\nmatches iucv_userid, even on a guest that also has a HiperSockets device\ncarrying the same identifier. The child socket created by\nafiucv_hs_callback_syn() for such a match inherits hs_dev = NULL and\ntransport = AF_IUCV_TRANS_HIPER, so the first send() on it returns -ENODEV.\nThe socket delivered to accept() is unusable.\n\nSecond, a frame arriving on one netdev can be delivered to a socket bound\nto a different IQD device. Which can lead to\n- Accept-queue exhaustion (DoS)\n- Attacker-controlled peer identity in the child socket\n- Data injection into existing sockets\n- Fabric noise on the IQD fabric, where bogus replies are sent\n- killing established connections\n\nThird, all AF_IUCV sockets live in init_net, as iucv_sock_alloc() calls\nsk_alloc(&init_net, ...). But even frames arriving on netdev devices in a\nnamespace can be delivered to an IUCV socket. So a process in an\nunprivileged user and network namespace holding only the CAP_NET_RAW\ncapability valid within that namespace can send a raw ETH_P_AF_IUCV frame\non its own lo device and have it matched against init_net sockets.\n\nFix all three by skipping any socket whose hs_dev does not match the\ningress device. A classic z/VM IUCV socket has hs_dev == NULL; the ingress\ndev is never NULL, so classic sockets are skipped automatically. An unbound\nHIPER socket also has hs_dev == NULL and is skipped. A bound HIPER socket\nis only reachable from the exact IQD device it was bound to. Because hs_dev\nis always a device in init_net (iucv_sock_bind() scans\nfor_each_netdev_rcu(&init_net, ...) exclusively), a frame whose ingress\ndevice belongs to another namespace never matches any socket.\n\nNote that AF_IUCV over HiperSockets provides no per-connection\nauthentication: no sequence numbers, no TLS, no nonce. The four name fields\nidentifying a connection are exchanged in plaintext on the shared\nHiperSockets segment (VCHID). Any host on the same HiperSockets segment\ncould spoof any frame type against an existing connection. That is a\nprotocol-level property unchanged by this patch. The fix reduces the attack\nsurface to peers present on the same HiperSockets segment.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/80230a18c164a4b5bbc048fe2768b219ac17bc5a",
                "https://git.kernel.org/stable/c/8e3763f1ccac3fc395f9af2b87114c023ced8a3f",
                "https://git.kernel.org/stable/c/a7f0130a091724e69827ab58e74777a88747e892",
                "https://git.kernel.org/stable/c/dfac2936b83be00035ae176f8252e1c1e1de9207"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:08.863",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81003"
                }
            ]
        },
        {
            "id": "CVE-2026-81002",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nxdp: fix zero-copy frame layout\n\nxdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page\nand advertises PAGE_SIZE as its frame size.  It allows the copied frame\nto occupy the page tail needed by skb_shared_info and records zero\nheadroom even when metadata separates the frame header from packet data.\nAn AF_XDP zero-copy packet redirected through cpumap can therefore make\nthe skb overlap skb_shared_info or place it beyond the allocated page.\n\nLimit the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and include the\nmetadata length in frame headroom.  Redirect callers already handle a\nNULL conversion result.\n\nBUG: KASAN: slab-out-of-bounds in skb_gro_receive\nWrite of size 4 at addr ffff88800cf37004 by task cpumap/1/map:1/146\nCall Trace:\n skb_gro_receive (net/core/gro.c:174)\n udp_gro_receive (net/ipv4/udp_offload.c:812)\n inet_gro_receive (net/ipv4/af_inet.c:1539)\n dev_gro_receive (net/core/gro.c:515)\n gro_receive_skb (net/core/gro.c:633)\n cpu_map_kthread_run (kernel/bpf/cpumap.c:395)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:164)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:255)\nKernel panic - not syncing: KASAN: panic_on_warn set ...",
            "updated_at": "2026-09-13T07:17:06.883",
            "published_at": "2026-09-11T20:19:08.483",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "b0d1beeff2a97a0cf1965ea8f1d13b8973f22582 through before 444216dacdbebd3e52d5e704facafbb230da09e9 (git); b0d1beeff2a97a0cf1965ea8f1d13b8973f22582 through before 15d1f3c0dbe7a740f779337deb39f23cd8d002c8 (git); b0d1beeff2a97a0cf1965ea8f1d13b8973f22582 through before 68d7cc5512238693670fc19c7a615df631e10edf (git); b0d1beeff2a97a0cf1965ea8f1d13b8973f22582 through before 71283aaa6c65b3cec84caf1dc78560985737641f (git); 4.20",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nxdp: fix zero-copy frame layout\n\nxdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page\nand advertises PAGE_SIZE as its frame size.  It allows the copied frame\nto occupy the page tail needed by skb_shared_info and records zero\nheadroom even when metadata separates the frame header from packet data.\nAn AF_XDP zero-copy packet redirected through cpumap can therefore make\nthe skb overlap skb_shared_info or place it beyond the allocated page.\n\nLimit the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and include the\nmetadata length in frame headroom.  Redirect callers already handle a\nNULL conversion result.\n\nBUG: KASAN: slab-out-of-bounds in skb_gro_receive\nWrite of size 4 at addr ffff88800cf37004 by task cpumap/1/map:1/146\nCall Trace:\n skb_gro_receive (net/core/gro.c:174)\n udp_gro_receive (net/ipv4/udp_offload.c:812)\n inet_gro_receive (net/ipv4/af_inet.c:1539)\n dev_gro_receive (net/core/gro.c:515)\n gro_receive_skb (net/core/gro.c:633)\n cpu_map_kthread_run (kernel/bpf/cpumap.c:395)\n kthread (kernel/kthread.c:436)\n ret_from_fork (arch/x86/kernel/process.c:164)\n ret_from_fork_asm (arch/x86/entry/entry_64.S:255)\nKernel panic - not syncing: KASAN: panic_on_warn set ...",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/15d1f3c0dbe7a740f779337deb39f23cd8d002c8",
                "https://git.kernel.org/stable/c/444216dacdbebd3e52d5e704facafbb230da09e9",
                "https://git.kernel.org/stable/c/68d7cc5512238693670fc19c7a615df631e10edf",
                "https://git.kernel.org/stable/c/71283aaa6c65b3cec84caf1dc78560985737641f"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:08.483",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81002"
                }
            ]
        },
        {
            "id": "CVE-2026-81001",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nslip: fix use-after-free in sl_sync()\n\nslip_devs[] stores bare net_device pointers and takes no reference on\nthem.  sl_sync() and sl_alloc() walk that table from slip_open() under\nrtnl_lock(), while an entry is dropped by sl_free_netdev(), which\nsl_setup() installs as dev->priv_destructor.\n\npriv_destructor is called from netdev_run_todo(), which deliberately\nruns with the RTNL semaphore released so that it can sleep while waiting\nfor the device refcount to drop:\n\n\t/* Snapshot list, allow later requests */\n\tlist_replace_init(&net_todo_list, &list);\n\n\t__rtnl_unlock();\n\t...\n\t\tif (dev->priv_destructor)\n\t\t\tdev->priv_destructor(dev);\t/* slip_devs[i] = NULL */\n\t\tif (dev->needs_free_netdev)\n\t\t\tfree_netdev(dev);\n\t\t...\n\t\t/* Free network device */\n\t\tkobject_put(&dev->dev.kobj);\n\nSo rtnl_lock() does not serialise slip_open() against the teardown at\nall.  sl_sync() can load slip_devs[i] while the entry is still published\nand dereference it after netdev_run_todo() has run the destructor and\nreleased the device:\n\n  CPU0 (slip_open)                 CPU1 (slip_close)\n                                   unregister_netdev()\n                                     rtnl_unlock()\n                                       netdev_run_todo()\n                                         __rtnl_unlock()\n  rtnl_lock()\n  sl_sync()\n    dev = slip_devs[i]\n                                         priv_destructor(dev)\n                                           slip_devs[i] = NULL\n                                         kobject_put(&dev->dev.kobj)\n                                           /* dev is freed */\n    sl = netdev_priv(dev)\n    if (sl->tty || sl->leased)     /* use-after-free */\n\n  BUG: KASAN: use-after-free in sl_sync drivers/net/slip/slip.c:730 [inline]\n  BUG: KASAN: use-after-free in slip_open+0xef4/0x1210 drivers/net/slip/slip.c:806\n  Read of size 1 at addr ffff8880712dac71 by task syz-executor.2/6506\n\n  CPU: 2 PID: 6506 Comm: syz-executor.2 Not tainted 6.1.134-syzkaller-00260-g0c8fc3469765 #0\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014\n  Call Trace:\n   sl_sync drivers/net/slip/slip.c:730 [inline]\n   slip_open+0xef4/0x1210 drivers/net/slip/slip.c:806\n   tty_ldisc_open+0xa2/0x120 drivers/tty/tty_ldisc.c:433\n   tty_set_ldisc+0x324/0x720 drivers/tty/tty_ldisc.c:564\n   tiocsetd drivers/tty/tty_io.c:2428 [inline]\n   tty_ioctl+0x5f0/0x1530 drivers/tty/tty_io.c:2712\n\n  Allocated by task 6502:\n   alloc_netdev_mqs+0x98/0xfe0 net/core/dev.c:10719\n   sl_alloc drivers/net/slip/slip.c:756 [inline]\n   slip_open+0x36d/0x1210 drivers/net/slip/slip.c:817\n   tty_ldisc_open+0xa2/0x120 drivers/tty/tty_ldisc.c:433\n   tty_set_ldisc+0x324/0x720 drivers/tty/tty_ldisc.c:564\n\n  Freed by task 6497:\n   device_release+0xa2/0x240 drivers/base/core.c:2507\n   kobject_put+0x179/0x280 lib/kobject.c:729\n   netdev_run_todo+0x6c8/0xef0 net/core/dev.c:10509\n   slip_close+0x166/0x1c0 drivers/net/slip/slip.c:906\n   tty_ldisc_close+0x113/0x1a0 drivers/tty/tty_ldisc.c:456\n   tty_ldisc_kill+0x94/0x160 drivers/tty/tty_ldisc.c:614\n   tty_ldisc_release+0xe3/0x2b0 drivers/tty/tty_ldisc.c:782\n   tty_release+0xbcc/0xe70 drivers/tty/tty_io.c:1860\n\nCommit e58c19124189 (\"slip: Fix use-after-free Read in slip_open\") fixed\na different source of stale entries - a device left in slip_devs[] after\nslip_open() freed it on the registration error path - and does not\naddress this race, which is why the report survives it.\n\nDrop the entry from ndo_uninit instead.  unregister_netdevice() calls\nndo_uninit under RTNL, before the device is queued to netdev_run_todo(),\nso an entry that sl_sync() can still see while holding RTNL belongs to a\ndevice that cannot be freed until RTNL is dropped.  sl_free_netdev()\nstays only for the slip_open() error path, where register_netdevice()\nmay have failed before ndo_init and ndo_uninit is then not called\neither.  Both running for the same device is harmless: the\n---truncated---",
            "updated_at": "2026-09-13T07:17:06.723",
            "published_at": "2026-09-11T20:19:08.160",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5342b77c4123ba39f911d92a813295fb3bb21f69 through before a235b20972bbd98ca1fb127d6269434edc607f19 (git); 5342b77c4123ba39f911d92a813295fb3bb21f69 through before 486577db807891d0f964fdf13c1640c7f54b0ad1 (git); 5342b77c4123ba39f911d92a813295fb3bb21f69 through before d6f25e5bd777b05880da8673daf74a8419480545 (git); 5342b77c4123ba39f911d92a813295fb3bb21f69 through before 2c4e7c42d77e78ad595dbb9e4b5886b58b45d89d (git); 2.6.32",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nslip: fix use-after-free in sl_sync()\n\nslip_devs[] stores bare net_device pointers and takes no reference on\nthem.  sl_sync() and sl_alloc() walk that table from slip_open() under\nrtnl_lock(), while an entry is dropped by sl_free_netdev(), which\nsl_setup() installs as dev->priv_destructor.\n\npriv_destructor is called from netdev_run_todo(), which deliberately\nruns with the RTNL semaphore released so that it can sleep while waiting\nfor the device refcount to drop:\n\n\t/* Snapshot list, allow later requests */\n\tlist_replace_init(&net_todo_list, &list);\n\n\t__rtnl_unlock();\n\t...\n\t\tif (dev->priv_destructor)\n\t\t\tdev->priv_destructor(dev);\t/* slip_devs[i] = NULL */\n\t\tif (dev->needs_free_netdev)\n\t\t\tfree_netdev(dev);\n\t\t...\n\t\t/* Free network device */\n\t\tkobject_put(&dev->dev.kobj);\n\nSo rtnl_lock() does not serialise slip_open() against the teardown at\nall.  sl_sync() can load slip_devs[i] while the entry is still published\nand dereference it after netdev_run_todo() has run the destructor and\nreleased the device:\n\n  CPU0 (slip_open)                 CPU1 (slip_close)\n                                   unregister_netdev()\n                                     rtnl_unlock()\n                                       netdev_run_todo()\n                                         __rtnl_unlock()\n  rtnl_lock()\n  sl_sync()\n    dev = slip_devs[i]\n                                         priv_destructor(dev)\n                                           slip_devs[i] = NULL\n                                         kobject_put(&dev->dev.kobj)\n                                           /* dev is freed */\n    sl = netdev_priv(dev)\n    if (sl->tty || sl->leased)     /* use-after-free */\n\n  BUG: KASAN: use-after-free in sl_sync drivers/net/slip/slip.c:730 [inline]\n  BUG: KASAN: use-after-free in slip_open+0xef4/0x1210 drivers/net/slip/slip.c:806\n  Read of size 1 at addr ffff8880712dac71 by task syz-executor.2/6506\n\n  CPU: 2 PID: 6506 Comm: syz-executor.2 Not tainted 6.1.134-syzkaller-00260-g0c8fc3469765 #0\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014\n  Call Trace:\n   sl_sync drivers/net/slip/slip.c:730 [inline]\n   slip_open+0xef4/0x1210 drivers/net/slip/slip.c:806\n   tty_ldisc_open+0xa2/0x120 drivers/tty/tty_ldisc.c:433\n   tty_set_ldisc+0x324/0x720 drivers/tty/tty_ldisc.c:564\n   tiocsetd drivers/tty/tty_io.c:2428 [inline]\n   tty_ioctl+0x5f0/0x1530 drivers/tty/tty_io.c:2712\n\n  Allocated by task 6502:\n   alloc_netdev_mqs+0x98/0xfe0 net/core/dev.c:10719\n   sl_alloc drivers/net/slip/slip.c:756 [inline]\n   slip_open+0x36d/0x1210 drivers/net/slip/slip.c:817\n   tty_ldisc_open+0xa2/0x120 drivers/tty/tty_ldisc.c:433\n   tty_set_ldisc+0x324/0x720 drivers/tty/tty_ldisc.c:564\n\n  Freed by task 6497:\n   device_release+0xa2/0x240 drivers/base/core.c:2507\n   kobject_put+0x179/0x280 lib/kobject.c:729\n   netdev_run_todo+0x6c8/0xef0 net/core/dev.c:10509\n   slip_close+0x166/0x1c0 drivers/net/slip/slip.c:906\n   tty_ldisc_close+0x113/0x1a0 drivers/tty/tty_ldisc.c:456\n   tty_ldisc_kill+0x94/0x160 drivers/tty/tty_ldisc.c:614\n   tty_ldisc_release+0xe3/0x2b0 drivers/tty/tty_ldisc.c:782\n   tty_release+0xbcc/0xe70 drivers/tty/tty_io.c:1860\n\nCommit e58c19124189 (\"slip: Fix use-after-free Read in slip_open\") fixed\na different source of stale entries - a device left in slip_devs[] after\nslip_open() freed it on the registration error path - and does not\naddress this race, which is why the report survives it.\n\nDrop the entry from ndo_uninit instead.  unregister_netdevice() calls\nndo_uninit under RTNL, before the device is queued to netdev_run_todo(),\nso an entry that sl_sync() can still see while holding RTNL belongs to a\ndevice that cannot be freed until RTNL is dropped.  sl_free_netdev()\nstays only for the slip_open() error path, where register_netdevice()\nmay have failed before ndo_init and ndo_uninit is then not called\neither.  Both running for the same device is harmless: the\n---truncated---",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2c4e7c42d77e78ad595dbb9e4b5886b58b45d89d",
                "https://git.kernel.org/stable/c/486577db807891d0f964fdf13c1640c7f54b0ad1",
                "https://git.kernel.org/stable/c/a235b20972bbd98ca1fb127d6269434edc607f19",
                "https://git.kernel.org/stable/c/d6f25e5bd777b05880da8673daf74a8419480545"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:08.160",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81001"
                }
            ]
        },
        {
            "id": "CVE-2026-81000",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tun: bound receive headroom\n\ntun_get_user() uses tun->align both as skb headroom and when choosing how\nmuch packet data to keep linear. OVS can propagate an oversized headroom\nrequest from another port to TUN or TAP.\n\nWhen align is larger than the usable space in a one-page skb head,\nSKB_MAX_HEAD(align) underflows and the result becomes negative when stored\nin good_linear. That value later wraps when assigned to the size_t linear\nvariable, and tun_alloc_skb() can place skb->data outside the allocated\nhead.\n\nBound the headroom stored by TUN to the one-page skb-head budget and the\nlargest non-sentinel 16-bit skb header offset. Leave one linear byte for\nraw TUN and a complete Ethernet header for TAP, including NET_IP_ALIGN.\n\nAlso pull the raw-TUN protocol byte and the TAP Ethernet header before\naccessing them, so these checks remain safe for nonlinear skbs supplied by\nother allocation paths.",
            "updated_at": "2026-09-13T07:17:06.600",
            "published_at": "2026-09-11T20:19:07.710",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "eaea34b23c46bf17b4a5638be69ab3561854f34b through before 379d85c7f25f3e05a428225e6b8a65613c6e9b9d (git); eaea34b23c46bf17b4a5638be69ab3561854f34b through before e098d9cc8859614a7f7baebc96e32a5a16b18ed2 (git); eaea34b23c46bf17b4a5638be69ab3561854f34b through before 0ada54ea63e48b9c1608e917ccb7dfadbe86db28 (git); eaea34b23c46bf17b4a5638be69ab3561854f34b through before 447c9303942c439a117d9b76ce6d6e2116b38ee7 (git); 4.6",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tun: bound receive headroom\n\ntun_get_user() uses tun->align both as skb headroom and when choosing how\nmuch packet data to keep linear. OVS can propagate an oversized headroom\nrequest from another port to TUN or TAP.\n\nWhen align is larger than the usable space in a one-page skb head,\nSKB_MAX_HEAD(align) underflows and the result becomes negative when stored\nin good_linear. That value later wraps when assigned to the size_t linear\nvariable, and tun_alloc_skb() can place skb->data outside the allocated\nhead.\n\nBound the headroom stored by TUN to the one-page skb-head budget and the\nlargest non-sentinel 16-bit skb header offset. Leave one linear byte for\nraw TUN and a complete Ethernet header for TAP, including NET_IP_ALIGN.\n\nAlso pull the raw-TUN protocol byte and the TAP Ethernet header before\naccessing them, so these checks remain safe for nonlinear skbs supplied by\nother allocation paths.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0ada54ea63e48b9c1608e917ccb7dfadbe86db28",
                "https://git.kernel.org/stable/c/379d85c7f25f3e05a428225e6b8a65613c6e9b9d",
                "https://git.kernel.org/stable/c/447c9303942c439a117d9b76ce6d6e2116b38ee7",
                "https://git.kernel.org/stable/c/e098d9cc8859614a7f7baebc96e32a5a16b18ed2"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:07.710",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-81000"
                }
            ]
        },
        {
            "id": "CVE-2026-80998",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bnxt: ring the doorbell when SW USO exits early\n\nWhen a burst of packets is handed down to the driver, the driver defers\nthe doorbell to the end by setting txr->kick_pending = 1. The normal TX\npath handles this, but the SW USO path can miss it if it returns\nearly.\n\nIf bnxt_sw_udp_gso_xmit runs but returns early with NETDEV_TX_BUSY and\ntxr->kick_pending was previously set to 1, then the TX queue can\nstall because the driver wrote some BDs but never wrote the doorbell.\nThe device won't know to do the TX which would generate the completion\nthat would wake the queue back up.\n\nSimplify bnxt_sw_udp_gso_xmit to set txr->kick_pending in its success\ncase and check the flag on return. The added check after\nbnxt_sw_udp_gso_xmit returns ensures that any pending doorbells are\nwritten handling both successful USO and any early returns, which\nprevents the TX queue stall mentioned above.\n\nThis TX queue stall was observed on a production system with a netdev TX\nwatchdog informing about the queue stall.",
            "updated_at": "2026-09-13T07:17:06.483",
            "published_at": "2026-09-11T20:19:06.873",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "cc5d90667db81474ed7a92a1b2fa3daec5559307 through before 48d1c9665db6e3d4aeca62eb669377162ebc6fdf (git); cc5d90667db81474ed7a92a1b2fa3daec5559307 through before 4e15e89faac9f308baeb01f46c13a051814d2449 (git); 7.1",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bnxt: ring the doorbell when SW USO exits early\n\nWhen a burst of packets is handed down to the driver, the driver defers\nthe doorbell to the end by setting txr->kick_pending = 1. The normal TX\npath handles this, but the SW USO path can miss it if it returns\nearly.\n\nIf bnxt_sw_udp_gso_xmit runs but returns early with NETDEV_TX_BUSY and\ntxr->kick_pending was previously set to 1, then the TX queue can\nstall because the driver wrote some BDs but never wrote the doorbell.\nThe device won't know to do the TX which would generate the completion\nthat would wake the queue back up.\n\nSimplify bnxt_sw_udp_gso_xmit to set txr->kick_pending in its success\ncase and check the flag on return. The added check after\nbnxt_sw_udp_gso_xmit returns ensures that any pending doorbells are\nwritten handling both successful USO and any early returns, which\nprevents the TX queue stall mentioned above.\n\nThis TX queue stall was observed on a production system with a netdev TX\nwatchdog informing about the queue stall.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/48d1c9665db6e3d4aeca62eb669377162ebc6fdf",
                "https://git.kernel.org/stable/c/4e15e89faac9f308baeb01f46c13a051814d2449"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:06.873",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80998"
                }
            ]
        },
        {
            "id": "CVE-2026-80997",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipa: fix stalled modem TX queue after runtime resume\n\nipa_start_xmit() unconditionally stops the TX queue before calling\npm_runtime_get(), relying on the wake scheduled by runtime resume\n(ipa_modem_wake_queue_work()) to restart it once power is ACTIVE.\nBut that work is queued from within the runtime resume callback,\nbefore the device's power state reaches RPM_ACTIVE, so it can run\nwhile the device is still RPM_RESUMING.  The wake is then consumed\ntoo early: the transmit it restarts stops the queue again,\npm_runtime_get() returns -EINPROGRESS without arranging any future\nwake (deferred_resume exists only for RPM_SUSPENDING), and after the\nresume completes nothing is left to wake the queue.  Transmit stalls\npermanently: packets pile up in the qdisc behind the stopped queue,\nthe device runtime-suspends, and since the netdev registers no\nndo_tx_timeout the watchdog never fires.  Observed on SM7635\n(Fairphone 6) as the cellular data path going permanently deaf\nwithin hours, RX included, since nothing resumes the suspended\nendpoints.\n\nClose the window by making the wake work wait for the resume to\ncomplete (pm_runtime_get_sync()) before waking the queue.  Every\nqueue stop is then guaranteed a later wake that happens while power\nis ACTIVE; a transmit racing a new suspend/resume cycle re-schedules\nthe work.  If the device could not be resumed, wake the queue anyway\nso pending packets are dropped by the transmit path rather than\nstranded.\n\nThe STARTED power flag used to narrow this window: a wake running\nbefore the transmit path's stop suppressed that stop, but only once,\nas the flag was cleared by the first stop it absorbed.  Removing the\nflag made a single transmit during an in-flight resume sufficient to\nstrand the queue, which is the form observed.\n\nWith an accelerated reproducer (autosuspend delay shortened to 5 ms,\n~20 packets/s of TX), an unpatched kernel stalled three times in\n230 s / 4380 packets; with this patch the same test ran 3601 s /\n70298 packets without a stall.",
            "updated_at": "2026-09-13T07:17:06.347",
            "published_at": "2026-09-11T20:19:06.740",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "688de12f080f10dff8f3ddc80103e432ad8deb0b through before 30d5226bac52073c91ce85c2dcff93b866baefdb (git); 688de12f080f10dff8f3ddc80103e432ad8deb0b through before 62da38b4b3a0dd74a3e0eecf4992d40385924205 (git); 688de12f080f10dff8f3ddc80103e432ad8deb0b through before 30cef9c1229a36a9c80edb29296459849a2fbaa3 (git); 688de12f080f10dff8f3ddc80103e432ad8deb0b through before 3cbfd627ee720f3d2460d2cbe2fe9e4130240db6 (git); 6.9",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ipa: fix stalled modem TX queue after runtime resume\n\nipa_start_xmit() unconditionally stops the TX queue before calling\npm_runtime_get(), relying on the wake scheduled by runtime resume\n(ipa_modem_wake_queue_work()) to restart it once power is ACTIVE.\nBut that work is queued from within the runtime resume callback,\nbefore the device's power state reaches RPM_ACTIVE, so it can run\nwhile the device is still RPM_RESUMING.  The wake is then consumed\ntoo early: the transmit it restarts stops the queue again,\npm_runtime_get() returns -EINPROGRESS without arranging any future\nwake (deferred_resume exists only for RPM_SUSPENDING), and after the\nresume completes nothing is left to wake the queue.  Transmit stalls\npermanently: packets pile up in the qdisc behind the stopped queue,\nthe device runtime-suspends, and since the netdev registers no\nndo_tx_timeout the watchdog never fires.  Observed on SM7635\n(Fairphone 6) as the cellular data path going permanently deaf\nwithin hours, RX included, since nothing resumes the suspended\nendpoints.\n\nClose the window by making the wake work wait for the resume to\ncomplete (pm_runtime_get_sync()) before waking the queue.  Every\nqueue stop is then guaranteed a later wake that happens while power\nis ACTIVE; a transmit racing a new suspend/resume cycle re-schedules\nthe work.  If the device could not be resumed, wake the queue anyway\nso pending packets are dropped by the transmit path rather than\nstranded.\n\nThe STARTED power flag used to narrow this window: a wake running\nbefore the transmit path's stop suppressed that stop, but only once,\nas the flag was cleared by the first stop it absorbed.  Removing the\nflag made a single transmit during an in-flight resume sufficient to\nstrand the queue, which is the form observed.\n\nWith an accelerated reproducer (autosuspend delay shortened to 5 ms,\n~20 packets/s of TX), an unpatched kernel stalled three times in\n230 s / 4380 packets; with this patch the same test ran 3601 s /\n70298 packets without a stall.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/30cef9c1229a36a9c80edb29296459849a2fbaa3",
                "https://git.kernel.org/stable/c/30d5226bac52073c91ce85c2dcff93b866baefdb",
                "https://git.kernel.org/stable/c/3cbfd627ee720f3d2460d2cbe2fe9e4130240db6",
                "https://git.kernel.org/stable/c/62da38b4b3a0dd74a3e0eecf4992d40385924205"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:06.740",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80997"
                }
            ]
        },
        {
            "id": "CVE-2026-80995",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mctp: hold a reference to the route device in mctp_route_lookup()\n\nmctp_route_lookup() uses rt->dev without holding a reference on it.\nmctp_route_lookup_single() returns the route under RCU only, so the\nroute's device can be torn down concurrently: mctp_dev_put() drops the\nlast reference and synchronously kfree()s mdev->addrs.  mctp_dev_saddr()\nthen reads rt->dev->addrs[0], giving a use-after-free reachable by an\nunprivileged local AF_MCTP user on the receive/forwarding path (no\nCAP_NET_RAW required):\n\n  BUG: KASAN: slab-use-after-free in mctp_route_lookup\n  Read of size 1 at addr ... by task mctp_uaf/...\n   mctp_route_lookup\n   mctp_pkttype_receive\n  Freed by task ...:\n   kfree\n   mctp_dev_put\n   mctp_dev_notify\n\nIn the same window mctp_dst_from_route() -> mctp_dev_hold() also\nincrements a refcount that has already reached zero\n(\"refcount_t: addition on 0 ... mctp_dev_hold\").\n\nThis reintroduces the use-after-free class of CVE-2023-3439: the source\naddress lookup was moved ahead of the point where the destination takes\nits device reference.\n\nTake a reference with refcount_inc_not_zero() before touching rt->dev,\nskip a device that is already dead, and drop the reference once the\ndestination has taken its own.",
            "updated_at": "2026-09-13T07:17:06.230",
            "published_at": "2026-09-11T20:19:06.497",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "22cb45afd221b9e4f2a1dcc74a8ff645b7293aa1 through before cc561f8af25586300c2f9d285babb163b866b293 (git); 22cb45afd221b9e4f2a1dcc74a8ff645b7293aa1 through before 408da1df18116c971c3392e21e50586688cd3fbf (git); 7.1",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mctp: hold a reference to the route device in mctp_route_lookup()\n\nmctp_route_lookup() uses rt->dev without holding a reference on it.\nmctp_route_lookup_single() returns the route under RCU only, so the\nroute's device can be torn down concurrently: mctp_dev_put() drops the\nlast reference and synchronously kfree()s mdev->addrs.  mctp_dev_saddr()\nthen reads rt->dev->addrs[0], giving a use-after-free reachable by an\nunprivileged local AF_MCTP user on the receive/forwarding path (no\nCAP_NET_RAW required):\n\n  BUG: KASAN: slab-use-after-free in mctp_route_lookup\n  Read of size 1 at addr ... by task mctp_uaf/...\n   mctp_route_lookup\n   mctp_pkttype_receive\n  Freed by task ...:\n   kfree\n   mctp_dev_put\n   mctp_dev_notify\n\nIn the same window mctp_dst_from_route() -> mctp_dev_hold() also\nincrements a refcount that has already reached zero\n(\"refcount_t: addition on 0 ... mctp_dev_hold\").\n\nThis reintroduces the use-after-free class of CVE-2023-3439: the source\naddress lookup was moved ahead of the point where the destination takes\nits device reference.\n\nTake a reference with refcount_inc_not_zero() before touching rt->dev,\nskip a device that is already dead, and drop the reference once the\ndestination has taken its own.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/408da1df18116c971c3392e21e50586688cd3fbf",
                "https://git.kernel.org/stable/c/cc561f8af25586300c2f9d285babb163b866b293"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:06.497",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80995"
                }
            ]
        },
        {
            "id": "CVE-2026-80994",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix flow mask use-after-free on flow deletion\n\nThe commit in the Fixes tag below made so flow->mask free is scheduled\nvia RCU right after it is removed from the flow table.  The pointer\nstays in the flow structure and it can be accessible while in the same\nRCU critical section.  This is done to avoid requiring ovs_mutex for\nthe ovs_flow_free().\n\nHowever, while removing the flow during processing of CMD_DEL, we do\nnot take RCU read lock before the removal, and ovs_flow_cmd_fill_info()\nuses the flow->mask pointer afterwards.  The RCU read lock is taken,\nbut it's already late at that point.  The comment on that line\nacknowledges that the lock is cosmetic and doesn't serve a real purpose.\n\nThis leads to use-after-free if the RCU grace period passes between\nremoval and the filling.  It is a short race window, but it is there\nand can lead to a real crash in case memory allocation for the info\ntakes a bit longer:\n\n BUG: KASAN: slab-use-after-free in __ovs_nla_put_key\n             net/openvswitch/flow_netlink.c:1996\n BUG: KASAN: slab-use-after-free in ovs_nla_put_key+0x2463/0x2e30\n             net/openvswitch/flow_netlink.c:2250\n Read of size 4 at addr ffff88801ee89970 by task ovs_flow_del_ec/9487\n\n Call Trace:\n  <TASK>\n  __ovs_nla_put_key net/openvswitch/flow_netlink.c:1996\n  ovs_nla_put_key+0x2463/0x2e30 net/openvswitch/flow_netlink.c:2250\n  ovs_flow_cmd_fill_info+0x420/0x9c0 net/openvswitch/datapath.c:930\n  ovs_flow_cmd_del+0x53a/0x970 net/openvswitch/datapath.c:1467\n  ...\n  netlink_rcv_skb+0x156/0x420 net/netlink/af_netlink.c:2556\n  </TASK>\n\n Allocated by task 9487:\n  mask_alloc net/openvswitch/flow_table.c:967\n  flow_mask_insert net/openvswitch/flow_table.c:1012\n  ovs_flow_tbl_insert+0xea2/0x1a90 net/openvswitch/flow_table.c:1084\n  ovs_flow_cmd_new+0x7e3/0xd90 net/openvswitch/datapath.c:1086\n  ...\n  netlink_rcv_skb+0x156/0x420 net/netlink/af_netlink.c:2556\n\n Freed by task 9485:\n  rcu_free_sheaf+0x1e/0x100 mm/slub.c:5978\n  rcu_do_batch kernel/rcu/tree.c:2645\n  rcu_core+0x59c/0x10c0 kernel/rcu/tree.c:2897\n  handle_softirqs+0x1e4/0x9a0 kernel/softirq.c:622\n  ...\n  instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062\n\novs_flow_tbl_remove() must be called after the ovs_flow_cmd_fill_info()\nto avoid this race.  This also helps with cleaning up the forced cast\nand the cosmetic RCU read lock.  Before the commit in the Fixes tag the\norder did not matter as long as the flow object itself was not freed.\n\nA wider RCU critical section could be another option, but we have a\nGFP_KERNEL allocation in the way.\n\nReported by Trend Micro's Zero Day Initiative as ZDI-CAN-32042.",
            "updated_at": "2026-09-13T07:17:06.087",
            "published_at": "2026-09-11T20:19:06.357",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "56c19868e115fcf8d62d843e1b9616bb9837d0db through before 0ba5cbc2f049af94ec94ff6f64958545efc5eaa2 (git); 56c19868e115fcf8d62d843e1b9616bb9837d0db through before ac73e3af571da06c1d1cfe3f0f00dc978b851700 (git); 56c19868e115fcf8d62d843e1b9616bb9837d0db through before 7f072b84afd05a77963eb1872f7174e280661dce (git); 56c19868e115fcf8d62d843e1b9616bb9837d0db through before 4e30317ff67a2eb12b4d890d39f72fd7e7117d48 (git); 3.16",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix flow mask use-after-free on flow deletion\n\nThe commit in the Fixes tag below made so flow->mask free is scheduled\nvia RCU right after it is removed from the flow table.  The pointer\nstays in the flow structure and it can be accessible while in the same\nRCU critical section.  This is done to avoid requiring ovs_mutex for\nthe ovs_flow_free().\n\nHowever, while removing the flow during processing of CMD_DEL, we do\nnot take RCU read lock before the removal, and ovs_flow_cmd_fill_info()\nuses the flow->mask pointer afterwards.  The RCU read lock is taken,\nbut it's already late at that point.  The comment on that line\nacknowledges that the lock is cosmetic and doesn't serve a real purpose.\n\nThis leads to use-after-free if the RCU grace period passes between\nremoval and the filling.  It is a short race window, but it is there\nand can lead to a real crash in case memory allocation for the info\ntakes a bit longer:\n\n BUG: KASAN: slab-use-after-free in __ovs_nla_put_key\n             net/openvswitch/flow_netlink.c:1996\n BUG: KASAN: slab-use-after-free in ovs_nla_put_key+0x2463/0x2e30\n             net/openvswitch/flow_netlink.c:2250\n Read of size 4 at addr ffff88801ee89970 by task ovs_flow_del_ec/9487\n\n Call Trace:\n  <TASK>\n  __ovs_nla_put_key net/openvswitch/flow_netlink.c:1996\n  ovs_nla_put_key+0x2463/0x2e30 net/openvswitch/flow_netlink.c:2250\n  ovs_flow_cmd_fill_info+0x420/0x9c0 net/openvswitch/datapath.c:930\n  ovs_flow_cmd_del+0x53a/0x970 net/openvswitch/datapath.c:1467\n  ...\n  netlink_rcv_skb+0x156/0x420 net/netlink/af_netlink.c:2556\n  </TASK>\n\n Allocated by task 9487:\n  mask_alloc net/openvswitch/flow_table.c:967\n  flow_mask_insert net/openvswitch/flow_table.c:1012\n  ovs_flow_tbl_insert+0xea2/0x1a90 net/openvswitch/flow_table.c:1084\n  ovs_flow_cmd_new+0x7e3/0xd90 net/openvswitch/datapath.c:1086\n  ...\n  netlink_rcv_skb+0x156/0x420 net/netlink/af_netlink.c:2556\n\n Freed by task 9485:\n  rcu_free_sheaf+0x1e/0x100 mm/slub.c:5978\n  rcu_do_batch kernel/rcu/tree.c:2645\n  rcu_core+0x59c/0x10c0 kernel/rcu/tree.c:2897\n  handle_softirqs+0x1e4/0x9a0 kernel/softirq.c:622\n  ...\n  instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1062\n\novs_flow_tbl_remove() must be called after the ovs_flow_cmd_fill_info()\nto avoid this race.  This also helps with cleaning up the forced cast\nand the cosmetic RCU read lock.  Before the commit in the Fixes tag the\norder did not matter as long as the flow object itself was not freed.\n\nA wider RCU critical section could be another option, but we have a\nGFP_KERNEL allocation in the way.\n\nReported by Trend Micro's Zero Day Initiative as ZDI-CAN-32042.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0ba5cbc2f049af94ec94ff6f64958545efc5eaa2",
                "https://git.kernel.org/stable/c/4e30317ff67a2eb12b4d890d39f72fd7e7117d48",
                "https://git.kernel.org/stable/c/7f072b84afd05a77963eb1872f7174e280661dce",
                "https://git.kernel.org/stable/c/ac73e3af571da06c1d1cfe3f0f00dc978b851700"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:06.357",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80994"
                }
            ]
        },
        {
            "id": "CVE-2026-80992",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ravb: avoid dereferencing an invalid PTP clock\n\nThe PTP clock is unavailable before the first open, so querying its\nindex can dereference a NULL pointer. Registration failures can also\nleave an error pointer in priv->ptp.clock.\n\nCache the PHC index separately and report -1 while no clock is\nregistered. Normalize registration errors to NULL and preserve the\nstatic timestamping capabilities.",
            "updated_at": "2026-09-13T07:17:05.953",
            "published_at": "2026-09-11T20:19:06.110",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "a0d2f20650e81407d8e51ad2cbdc492861c74e9c through before fc710f89a644e030a7ca15343176ca862fd61b9d (git); a0d2f20650e81407d8e51ad2cbdc492861c74e9c through before 8d4d06d6e2b501cb8e30ed3b1924c470358e8052 (git); a0d2f20650e81407d8e51ad2cbdc492861c74e9c through before 0aaa53936419cf0c19c670387fc6d431e042a1b6 (git); a0d2f20650e81407d8e51ad2cbdc492861c74e9c through before 1f77af0aaf277413ff32f6ff8c2c4282bd64c897 (git); 4.2",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ravb: avoid dereferencing an invalid PTP clock\n\nThe PTP clock is unavailable before the first open, so querying its\nindex can dereference a NULL pointer. Registration failures can also\nleave an error pointer in priv->ptp.clock.\n\nCache the PHC index separately and report -1 while no clock is\nregistered. Normalize registration errors to NULL and preserve the\nstatic timestamping capabilities.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0aaa53936419cf0c19c670387fc6d431e042a1b6",
                "https://git.kernel.org/stable/c/1f77af0aaf277413ff32f6ff8c2c4282bd64c897",
                "https://git.kernel.org/stable/c/8d4d06d6e2b501cb8e30ed3b1924c470358e8052",
                "https://git.kernel.org/stable/c/fc710f89a644e030a7ca15343176ca862fd61b9d"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:06.110",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80992"
                }
            ]
        },
        {
            "id": "CVE-2026-80991",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ravb: serialize PTP clock teardown\n\nravb_ptp_interrupt() can race with ravb_ptp_stop() and pass the clock to\nptp_clock_event() while ptp_clock_unregister() is freeing it. This can\nlead to a use-after-free.\n\nUse READ_ONCE() and WRITE_ONCE() for lockless access to the clock pointer.\nAtomically detach it with xchg() before disabling PTP interrupts, then\nsynchronize all IRQs which can invoke ravb_ptp_interrupt() before\nunregistering the detached clock.\n\nA handler which read the old pointer completes before the clock is\nunregistered, while later handlers read NULL and skip the event.",
            "updated_at": "2026-09-13T07:17:05.830",
            "published_at": "2026-09-11T20:19:05.993",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "a0d2f20650e81407d8e51ad2cbdc492861c74e9c through before 695acb5534a9e366efb47b40c7487fc56488b09b (git); a0d2f20650e81407d8e51ad2cbdc492861c74e9c through before 67a82e6f886beed0de8f8da08bb767e68fba952d (git); a0d2f20650e81407d8e51ad2cbdc492861c74e9c through before 66b50c31419e7946e9aa325a468ad9b64c961a25 (git); a0d2f20650e81407d8e51ad2cbdc492861c74e9c through before 1cb9663789c5b7a12fcd419fcca6d6254c398252 (git); 4.2",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ravb: serialize PTP clock teardown\n\nravb_ptp_interrupt() can race with ravb_ptp_stop() and pass the clock to\nptp_clock_event() while ptp_clock_unregister() is freeing it. This can\nlead to a use-after-free.\n\nUse READ_ONCE() and WRITE_ONCE() for lockless access to the clock pointer.\nAtomically detach it with xchg() before disabling PTP interrupts, then\nsynchronize all IRQs which can invoke ravb_ptp_interrupt() before\nunregistering the detached clock.\n\nA handler which read the old pointer completes before the clock is\nunregistered, while later handlers read NULL and skip the event.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1cb9663789c5b7a12fcd419fcca6d6254c398252",
                "https://git.kernel.org/stable/c/66b50c31419e7946e9aa325a468ad9b64c961a25",
                "https://git.kernel.org/stable/c/67a82e6f886beed0de8f8da08bb767e68fba952d",
                "https://git.kernel.org/stable/c/695acb5534a9e366efb47b40c7487fc56488b09b"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:05.993",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80991"
                }
            ]
        },
        {
            "id": "CVE-2026-80989",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: thunderbolt: Mark the connection down when bringing it up fails\n\nEvery failure path in tbnet_connected_work() undoes its own work and\nreturns without clearing login_sent, so the connection still looks\nestablished. The next tbnet_tear_down() therefore takes its main branch\nand repeats a teardown that already happened: it stops rings that are\nalready stopped, which is a dev_WARN() and fatal under panic_on_warn,\nand it releases net->remote_transmit_path even on the HopID mismatch\npath, where this connection never owned that id, silently freeing one\nthat someone else is still using.\n\nClear login_sent on those paths. That is enough for tbnet_tear_down() to\nleave the unwound state alone, and login_received has to stay set: it\nrecords that the peer has logged in and carries the transmit path it gave\nus, which nothing on this side can make the peer send again. Two things\nchange beyond keeping the teardown out of the way: the logout request in\nthat block is no longer sent, and the peer's next login request now\nre-queues our login work rather than connected_work, giving the\nconnection a fresh login instead of a retry on stale state.",
            "updated_at": "2026-09-13T07:17:05.693",
            "published_at": "2026-09-11T20:19:05.730",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e through before ed1d6e3d735e7b03f43a02f4306c89eb7663da14 (git); e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e through before f01e6a35c440b62f060e21f36b385e574a7f308c (git); e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e through before d6c0af293129345a17dc31c9b4179dc7f3d6af7a (git); e69b6c02b4c3b8d03be7136f90dd9551ad5a5a5e through before 3c8b26ebf525ba5960510f48c6e9936a79ebe76f (git); 4.15",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: thunderbolt: Mark the connection down when bringing it up fails\n\nEvery failure path in tbnet_connected_work() undoes its own work and\nreturns without clearing login_sent, so the connection still looks\nestablished. The next tbnet_tear_down() therefore takes its main branch\nand repeats a teardown that already happened: it stops rings that are\nalready stopped, which is a dev_WARN() and fatal under panic_on_warn,\nand it releases net->remote_transmit_path even on the HopID mismatch\npath, where this connection never owned that id, silently freeing one\nthat someone else is still using.\n\nClear login_sent on those paths. That is enough for tbnet_tear_down() to\nleave the unwound state alone, and login_received has to stay set: it\nrecords that the peer has logged in and carries the transmit path it gave\nus, which nothing on this side can make the peer send again. Two things\nchange beyond keeping the teardown out of the way: the logout request in\nthat block is no longer sent, and the peer's next login request now\nre-queues our login work rather than connected_work, giving the\nconnection a fresh login instead of a retry on stale state.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/3c8b26ebf525ba5960510f48c6e9936a79ebe76f",
                "https://git.kernel.org/stable/c/d6c0af293129345a17dc31c9b4179dc7f3d6af7a",
                "https://git.kernel.org/stable/c/ed1d6e3d735e7b03f43a02f4306c89eb7663da14",
                "https://git.kernel.org/stable/c/f01e6a35c440b62f060e21f36b385e574a7f308c"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:05.730",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80989"
                }
            ]
        },
        {
            "id": "CVE-2026-80987",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: ntb_transport: Reject oversized TX buffers\n\nntb_process_tx() handles an oversized buffer by calling tx_handler()\nwith a NULL data pointer and returning success. ntb_netdev therefore\nneither frees the skb in its completion callback nor takes its enqueue\nerror path, leaking it.\n\nReject oversized buffers in ntb_transport_tx_enqueue() before acquiring\na queue entry and return -EMSGSIZE. The caller retains ownership of the\nbuffer, and the preceding netdev patch frees the skb when enqueue\nreturns this permanent error.",
            "updated_at": "2026-09-13T07:17:05.567",
            "published_at": "2026-09-11T20:19:05.353",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "fce8a7bb5b4bfb8a27324703fd5b002ee9247e90 through before a7f22105a7df8c7fd74d0af27ace6fa94fe03d87 (git); fce8a7bb5b4bfb8a27324703fd5b002ee9247e90 through before 6b6bbc6c878d64eacc60877df49fce7b1b6a08d0 (git); fce8a7bb5b4bfb8a27324703fd5b002ee9247e90 through before 75a604e9f1cfdebda421062fdf42225ca32154cd (git); fce8a7bb5b4bfb8a27324703fd5b002ee9247e90 through before a4f2387db6f1cc2f03abba7f3a6807ad61e26ff7 (git); 3.9",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: ntb_transport: Reject oversized TX buffers\n\nntb_process_tx() handles an oversized buffer by calling tx_handler()\nwith a NULL data pointer and returning success. ntb_netdev therefore\nneither frees the skb in its completion callback nor takes its enqueue\nerror path, leaking it.\n\nReject oversized buffers in ntb_transport_tx_enqueue() before acquiring\na queue entry and return -EMSGSIZE. The caller retains ownership of the\nbuffer, and the preceding netdev patch frees the skb when enqueue\nreturns this permanent error.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/6b6bbc6c878d64eacc60877df49fce7b1b6a08d0",
                "https://git.kernel.org/stable/c/75a604e9f1cfdebda421062fdf42225ca32154cd",
                "https://git.kernel.org/stable/c/a4f2387db6f1cc2f03abba7f3a6807ad61e26ff7",
                "https://git.kernel.org/stable/c/a7f22105a7df8c7fd74d0af27ace6fa94fe03d87"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:05.353",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80987"
                }
            ]
        },
        {
            "id": "CVE-2026-80986",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: bound the peer rkey counts in SMC-Rv2 LLC messages\n\nOn a link whose device has max_recv_sge == 1 there is no shared v2 receive\nbuffer, and smc_llc_save_add_link_rkeys() takes the v2 extension from 44\nbytes past the start of the queue entry's inline message:\n\n  ext = (struct smc_llc_msg_add_link_v2_ext *)(llc_msg + SMC_WR_TX_SIZE);\n\nThe entry is a 72-byte allocation and the extension starts at offset 68, so\next->num_rkeys at offset 94 is already past it. This happens on every\nSMC-Rv2 link addition, whatever the peer sends:\n\n  [    2.490065] BUG: KASAN: slab-out-of-bounds in smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.490431] Read of size 2 at addr ffff8880056406de by task smctest/106\n  [    2.490709]\n  [    2.490792] CPU: 0 UID: 0 PID: 106 Comm: smctest Not tainted 7.2.0-rc5-p1-g77a5d9d9c99f #32 PREEMPT(lazy)\n  [    2.490795] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n  [    2.490798] Call Trace:\n  [    2.490803]  <TASK>\n  [    2.490805]  dump_stack_lvl+0x53/0x70\n  [    2.490810]  print_report+0xd0/0x630\n  [    2.490828]  ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n  [    2.490832]  ? smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.490834]  kasan_report+0xce/0x100\n  [    2.490836]  ? smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.490837]  smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.490839]  ? smcr_buf_map_lgr+0x1bf/0x2b0\n  [    2.490844]  smc_llc_cli_add_link+0xca7/0x1e80\n  [    2.490848]  ? smc_llc_wait+0x355/0x810\n  [    2.490850]  ? __pfx_smc_llc_wait+0x10/0x10\n  [    2.490851]  ? __pfx_smc_llc_cli_add_link+0x10/0x10\n  [    2.490853]  ? __pfx_autoremove_wake_function+0x10/0x10\n  [    2.490863]  __smc_connect+0x3f5c/0x4980\n  [    2.490873]  ? __pfx_kernel_connect+0x10/0x10\n  [    2.490888]  ? __pfx___smc_connect+0x10/0x10\n  [    2.490891]  ? release_sock+0x148/0x1d0\n  [    2.490894]  smc_connect+0x42c/0x580\n  [    2.490896]  __sys_connect+0xfc/0x130\n  [    2.490898]  ? __pfx___sys_connect+0x10/0x10\n  [    2.490900]  ? handle_mm_fault+0x1a1/0x430\n  [    2.490908]  __x64_sys_connect+0x6d/0xb0\n  [    2.490909]  ? fpregs_assert_state_consistent+0x56/0xe0\n  [    2.490917]  do_syscall_64+0xf9/0x540\n  [    2.490921]  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n  [    2.490924] RIP: 0033:0x421bb4\n  [    2.490927] Code: ff f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 80 3d ad 34 09 00 00 74 13 b8 2a 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 4c c3 0f 1f 00 55 48 89 e5 48 83 ec 10 89 55\n  [    2.490929] RSP: 002b:00007ffd473b01a8 EFLAGS: 00000202 ORIG_RAX: 000000000000002a\n  [    2.490935] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000421bb4\n  [    2.490936] RDX: 0000000000000010 RSI: 00007ffd473b01d0 RDI: 0000000000000003\n  [    2.490937] RBP: 0000000000003930 R08: 0000000000000004 R09: 0000000000000000\n  [    2.490938] R10: 00007ffd473b0f98 R11: 0000000000000202 R12: 0000000000000006\n  [    2.490939] R13: 00007ffd473b0f87 R14: 0000000000000003 R15: 00007ffd473b0f90\n  [    2.490940]  </TASK>\n  [    2.490941]\n  [    2.499545] Allocated by task 44:\n  [    2.499693]  kasan_save_stack+0x33/0x60\n  [    2.499860]  kasan_save_track+0x14/0x30\n  [    2.500026]  __kasan_kmalloc+0x8f/0xa0\n  [    2.500190]  __kmalloc_cache_noprof+0x158/0x370\n  [    2.500393]  smc_llc_enqueue+0x72/0x560\n  [    2.500559]  smc_wr_rx_tasklet_fn+0x474/0xa80\n  [    2.500747]  tasklet_action_common+0x20f/0x8a0\n  [    2.500945]  handle_softirqs+0x18e/0x590\n  [    2.501115]  do_softirq+0x3b/0x60\n  [    2.501266]  __local_bh_enable_ip+0x61/0x70\n  [    2.501446]  __alloc_skb+0x732/0x890\n  [    2.501604]  rxe_init_packet+0x16b/0x4f0\n  [    2.501783]  prepare_ack_packet+0xb8/0x830\n  [    2.501962]  rxe_receiver+0x495/0x96e0\n  [    2.502125]  do_work+0x144/0x470\n  [    2.502269]  process_one_work+0x633/0x1030\n  [    2.502450]  worker_thread+0x45b/0xd10\n  [    2.50261\n---truncated---",
            "updated_at": "2026-09-13T07:17:05.417",
            "published_at": "2026-09-11T20:19:05.180",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "27ef6a9981fe74191849966a6d5e0400a4008ab8 through before 486c699a8cde82c1d9b4f443eeab4ddf86358cb0 (git); 27ef6a9981fe74191849966a6d5e0400a4008ab8 through before 5e5d9e6df677d30a2203d257b5fd8b99814fa607 (git); 27ef6a9981fe74191849966a6d5e0400a4008ab8 through before 2d1e7c5aaa3326e95e2058457f172ca99a9a4577 (git); 6.14",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: bound the peer rkey counts in SMC-Rv2 LLC messages\n\nOn a link whose device has max_recv_sge == 1 there is no shared v2 receive\nbuffer, and smc_llc_save_add_link_rkeys() takes the v2 extension from 44\nbytes past the start of the queue entry's inline message:\n\n  ext = (struct smc_llc_msg_add_link_v2_ext *)(llc_msg + SMC_WR_TX_SIZE);\n\nThe entry is a 72-byte allocation and the extension starts at offset 68, so\next->num_rkeys at offset 94 is already past it. This happens on every\nSMC-Rv2 link addition, whatever the peer sends:\n\n  [    2.490065] BUG: KASAN: slab-out-of-bounds in smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.490431] Read of size 2 at addr ffff8880056406de by task smctest/106\n  [    2.490709]\n  [    2.490792] CPU: 0 UID: 0 PID: 106 Comm: smctest Not tainted 7.2.0-rc5-p1-g77a5d9d9c99f #32 PREEMPT(lazy)\n  [    2.490795] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n  [    2.490798] Call Trace:\n  [    2.490803]  <TASK>\n  [    2.490805]  dump_stack_lvl+0x53/0x70\n  [    2.490810]  print_report+0xd0/0x630\n  [    2.490828]  ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n  [    2.490832]  ? smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.490834]  kasan_report+0xce/0x100\n  [    2.490836]  ? smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.490837]  smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.490839]  ? smcr_buf_map_lgr+0x1bf/0x2b0\n  [    2.490844]  smc_llc_cli_add_link+0xca7/0x1e80\n  [    2.490848]  ? smc_llc_wait+0x355/0x810\n  [    2.490850]  ? __pfx_smc_llc_wait+0x10/0x10\n  [    2.490851]  ? __pfx_smc_llc_cli_add_link+0x10/0x10\n  [    2.490853]  ? __pfx_autoremove_wake_function+0x10/0x10\n  [    2.490863]  __smc_connect+0x3f5c/0x4980\n  [    2.490873]  ? __pfx_kernel_connect+0x10/0x10\n  [    2.490888]  ? __pfx___smc_connect+0x10/0x10\n  [    2.490891]  ? release_sock+0x148/0x1d0\n  [    2.490894]  smc_connect+0x42c/0x580\n  [    2.490896]  __sys_connect+0xfc/0x130\n  [    2.490898]  ? __pfx___sys_connect+0x10/0x10\n  [    2.490900]  ? handle_mm_fault+0x1a1/0x430\n  [    2.490908]  __x64_sys_connect+0x6d/0xb0\n  [    2.490909]  ? fpregs_assert_state_consistent+0x56/0xe0\n  [    2.490917]  do_syscall_64+0xf9/0x540\n  [    2.490921]  entry_SYSCALL_64_after_hwframe+0x77/0x7f\n  [    2.490924] RIP: 0033:0x421bb4\n  [    2.490927] Code: ff f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 80 3d ad 34 09 00 00 74 13 b8 2a 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 4c c3 0f 1f 00 55 48 89 e5 48 83 ec 10 89 55\n  [    2.490929] RSP: 002b:00007ffd473b01a8 EFLAGS: 00000202 ORIG_RAX: 000000000000002a\n  [    2.490935] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 0000000000421bb4\n  [    2.490936] RDX: 0000000000000010 RSI: 00007ffd473b01d0 RDI: 0000000000000003\n  [    2.490937] RBP: 0000000000003930 R08: 0000000000000004 R09: 0000000000000000\n  [    2.490938] R10: 00007ffd473b0f98 R11: 0000000000000202 R12: 0000000000000006\n  [    2.490939] R13: 00007ffd473b0f87 R14: 0000000000000003 R15: 00007ffd473b0f90\n  [    2.490940]  </TASK>\n  [    2.490941]\n  [    2.499545] Allocated by task 44:\n  [    2.499693]  kasan_save_stack+0x33/0x60\n  [    2.499860]  kasan_save_track+0x14/0x30\n  [    2.500026]  __kasan_kmalloc+0x8f/0xa0\n  [    2.500190]  __kmalloc_cache_noprof+0x158/0x370\n  [    2.500393]  smc_llc_enqueue+0x72/0x560\n  [    2.500559]  smc_wr_rx_tasklet_fn+0x474/0xa80\n  [    2.500747]  tasklet_action_common+0x20f/0x8a0\n  [    2.500945]  handle_softirqs+0x18e/0x590\n  [    2.501115]  do_softirq+0x3b/0x60\n  [    2.501266]  __local_bh_enable_ip+0x61/0x70\n  [    2.501446]  __alloc_skb+0x732/0x890\n  [    2.501604]  rxe_init_packet+0x16b/0x4f0\n  [    2.501783]  prepare_ack_packet+0xb8/0x830\n  [    2.501962]  rxe_receiver+0x495/0x96e0\n  [    2.502125]  do_work+0x144/0x470\n  [    2.502269]  process_one_work+0x633/0x1030\n  [    2.502450]  worker_thread+0x45b/0xd10\n  [    2.50261\n---truncated---",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2d1e7c5aaa3326e95e2058457f172ca99a9a4577",
                "https://git.kernel.org/stable/c/486c699a8cde82c1d9b4f443eeab4ddf86358cb0",
                "https://git.kernel.org/stable/c/5e5d9e6df677d30a2203d257b5fd8b99814fa607"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:05.180",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80986"
                }
            ]
        },
        {
            "id": "CVE-2026-80985",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: carry oversized SMC-Rv2 LLC messages in the queue entry\n\nsmc_llc_rmt_delete_rkey() and smc_llc_save_add_link_rkeys() read the part\nof a v2 message that does not fit into the 44-byte union smc_llc_msg, and\nboth bound themselves by the size of the buffer it landed in, not by what\narrived. On a link with a shared v2 receive buffer a 44-byte\nDELETE_RKEY_V2 declaring 255 rkeys reaches rkey[9..254] in whatever an\nearlier message left in lgr->wr_rx_buf_v2, and passes each of them to\nsmc_rtoken_delete(). One of those 255 matched a registered rtoken and\ndeleted it. An ADD_LINK on such a link installs up to 255 rtokens from\nthe same bytes.\n\nCopy the tail into the queue entry, so its length is the length of the\nmessage that arrived, and declare the rkeys that fit inline as a member of\nthe union instead of reaching them through a cast. The same\nDELETE_RKEY_V2 now processes the 9 rkeys it carries. The copy is limited\nto the longest tail the two functions can read, so the peer does not pick\nthe size of the entry.\n\nThe bound the previous patch placed on links without a shared v2 receive\nbuffer is no longer needed.",
            "updated_at": "2026-09-13T07:17:05.290",
            "published_at": "2026-09-11T20:19:05.050",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "27ef6a9981fe74191849966a6d5e0400a4008ab8 through before edf30d65e3ac52f886f7d87b1a7449742e79157d (git); 27ef6a9981fe74191849966a6d5e0400a4008ab8 through before 0d6f80be8ac5886842640d6526abf3f9a215be75 (git); 27ef6a9981fe74191849966a6d5e0400a4008ab8 through before 8d3c1ab82c11d4fadebf817a825fd221b3e197ea (git); 6.14",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: carry oversized SMC-Rv2 LLC messages in the queue entry\n\nsmc_llc_rmt_delete_rkey() and smc_llc_save_add_link_rkeys() read the part\nof a v2 message that does not fit into the 44-byte union smc_llc_msg, and\nboth bound themselves by the size of the buffer it landed in, not by what\narrived. On a link with a shared v2 receive buffer a 44-byte\nDELETE_RKEY_V2 declaring 255 rkeys reaches rkey[9..254] in whatever an\nearlier message left in lgr->wr_rx_buf_v2, and passes each of them to\nsmc_rtoken_delete(). One of those 255 matched a registered rtoken and\ndeleted it. An ADD_LINK on such a link installs up to 255 rtokens from\nthe same bytes.\n\nCopy the tail into the queue entry, so its length is the length of the\nmessage that arrived, and declare the rkeys that fit inline as a member of\nthe union instead of reaching them through a cast. The same\nDELETE_RKEY_V2 now processes the 9 rkeys it carries. The copy is limited\nto the longest tail the two functions can read, so the peer does not pick\nthe size of the entry.\n\nThe bound the previous patch placed on links without a shared v2 receive\nbuffer is no longer needed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0d6f80be8ac5886842640d6526abf3f9a215be75",
                "https://git.kernel.org/stable/c/8d3c1ab82c11d4fadebf817a825fd221b3e197ea",
                "https://git.kernel.org/stable/c/edf30d65e3ac52f886f7d87b1a7449742e79157d"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:05.050",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80985"
                }
            ]
        },
        {
            "id": "CVE-2026-80982",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix use-after-free in smc_rx_pipe_buf_release()\n\nsmc_rx_splice() hands RMB pages to a pipe and takes a socket reference\nper entry so the smc_sock stays alive until the reader finishes. The\nconnection does not: a concurrent close runs smc_conn_free(), which\nreleases the receive buffer back to the link group pool.\n\nsmc_rx_pipe_buf_release() tests sk_state before taking the socket lock.\nThe state can change between the test and the lock, and\nsmc_rx_update_cons() then dereferences conn->rmb_desc and walks\nconn->lgr, which smc_conn_free() has already released. On the\nis_reg_err path smcr_buf_unuse() frees the descriptor outright, so\nthis is a use-after-free.\n\nTake the socket lock first and test conn->freed instead.\nsmc_conn_free() sets that flag before releasing anything, and every\ncaller holds the socket lock. The two paths exclude each other: either\nthe pipe release runs first with everything valid, or it sees the flag\nand skips the update.",
            "updated_at": "2026-09-13T07:17:05.160",
            "published_at": "2026-09-11T20:19:04.667",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9014db202cb764b8e14c53e7bacc81f9a1a2ba7f through before 6a644a7340df978785f3109d1e0726a982ce2c6f (git); 9014db202cb764b8e14c53e7bacc81f9a1a2ba7f through before 0761e49aa78c2f1362511054c6e9670653858837 (git); 9014db202cb764b8e14c53e7bacc81f9a1a2ba7f through before 0926f59ca0f94120895b92180c636a48d0ed3a6d (git); 9014db202cb764b8e14c53e7bacc81f9a1a2ba7f through before c924884743e948e25625b7fbf3ee2a9325a204a7 (git); 4.18",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix use-after-free in smc_rx_pipe_buf_release()\n\nsmc_rx_splice() hands RMB pages to a pipe and takes a socket reference\nper entry so the smc_sock stays alive until the reader finishes. The\nconnection does not: a concurrent close runs smc_conn_free(), which\nreleases the receive buffer back to the link group pool.\n\nsmc_rx_pipe_buf_release() tests sk_state before taking the socket lock.\nThe state can change between the test and the lock, and\nsmc_rx_update_cons() then dereferences conn->rmb_desc and walks\nconn->lgr, which smc_conn_free() has already released. On the\nis_reg_err path smcr_buf_unuse() frees the descriptor outright, so\nthis is a use-after-free.\n\nTake the socket lock first and test conn->freed instead.\nsmc_conn_free() sets that flag before releasing anything, and every\ncaller holds the socket lock. The two paths exclude each other: either\nthe pipe release runs first with everything valid, or it sees the flag\nand skips the update.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0761e49aa78c2f1362511054c6e9670653858837",
                "https://git.kernel.org/stable/c/0926f59ca0f94120895b92180c636a48d0ed3a6d",
                "https://git.kernel.org/stable/c/6a644a7340df978785f3109d1e0726a982ce2c6f",
                "https://git.kernel.org/stable/c/c924884743e948e25625b7fbf3ee2a9325a204a7"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:04.667",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80982"
                }
            ]
        },
        {
            "id": "CVE-2026-80981",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link()\n\nsmc_llc_srv_add_link() keeps add_llc pointing into the queue entry:\n\n  add_llc = &qentry->msg.add_link;\t\t\tsmc_llc.c:1482\n  ...\n  smc_llc_save_add_link_info(link_new, add_llc);\tsmc_llc.c:1494\n  smc_llc_flow_qentry_del(&lgr->llc_flow_lcl);\t\tsmc_llc.c:1495\n  ...\n  u8 *llc_msg = smc_link_shared_v2_rxbuf(link) ?\n\t(u8 *)lgr->wr_rx_buf_v2 : (u8 *)add_llc;\tsmc_llc.c:1504\n  smc_llc_save_add_link_rkeys(link, link_new, llc_msg);\tsmc_llc.c:1506\n\nsmc_llc_flow_qentry_del() kfree()s the entry, so on a link without a shared\nv2 receive buffer the pointer handed to smc_llc_save_add_link_rkeys() is\nalready freed. Before the Fixes: commit that branch always used\nlgr->wr_rx_buf_v2 and add_llc was not used after the free.\n\nReproduced on an unpatched tree over rxe, with KASAN, kasan_multi_shot\nand a link forced to max_recv_sge == 1: the entry is freed and read by\nthe same call, and the freeing frame is smc_llc_srv_add_link() itself.\n\n  [    2.523161] BUG: KASAN: slab-use-after-free in smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.523499] Read of size 2 at addr ffff8880052194de by task kworker/0:1/11\n  [    2.523789]\n  [    2.523862] CPU: 0 UID: 0 PID: 11 Comm: kworker/0:1 Not tainted 7.2.0-rc5-p0-g2c9dd296545d #35 PREEMPT(lazy)\n  [    2.523865] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n  [    2.523866] Workqueue: smc_hs_wq smc_listen_work\n  [    2.523869] Call Trace:\n  [    2.523870]  <TASK>\n  [    2.523871]  dump_stack_lvl+0x53/0x70\n  [    2.523872]  print_report+0xd0/0x630\n  [    2.523874]  ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n  [    2.523876]  ? smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.523878]  kasan_report+0xce/0x100\n  [    2.523879]  ? smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.523881]  smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.523883]  ? smcr_buf_reg_lgr+0x2a4/0x660\n  [    2.523885]  smc_llc_srv_add_link+0xaa2/0x1e50\n  [    2.523888]  ? _printk+0xba/0xf0\n  [    2.523897]  ? __pfx_smc_llc_srv_add_link+0x10/0x10\n  [    2.523899]  ? down_write+0xb0/0x130\n  [    2.523903]  ? __pfx_down_write+0x10/0x10\n  [    2.523905]  smc_listen_work+0x489e/0x4d00\n  [    2.523907]  ? kmem_cache_free+0x1c6/0x3a0\n  [    2.523911]  ? __pfx_smc_listen_work+0x10/0x10\n  [    2.523913]  ? release_sock+0x148/0x1d0\n  [    2.523915]  ? smc_tcp_listen_work+0xb4f/0xfc0\n  [    2.523917]  ? _raw_spin_lock_irq+0x80/0xe0\n  [    2.523918]  ? __pfx__raw_spin_lock_irq+0x10/0x10\n  [    2.523920]  process_one_work+0x633/0x1030\n  [    2.523922]  ? assign_work+0x11d/0x370\n  [    2.523924]  worker_thread+0x45b/0xd10\n  [    2.523926]  ? __pfx_worker_thread+0x10/0x10\n  [    2.523928]  ? __pfx_worker_thread+0x10/0x10\n  [    2.523929]  kthread+0x2c6/0x3b0\n  [    2.523931]  ? recalc_sigpending+0x15c/0x1e0\n  [    2.523934]  ? __pfx_kthread+0x10/0x10\n  [    2.523935]  ret_from_fork+0x36e/0x5a0\n  [    2.523937]  ? __pfx_ret_from_fork+0x10/0x10\n  [    2.523938]  ? __switch_to+0x572/0xdd0\n  [    2.523943]  ? __pfx_kthread+0x10/0x10\n  [    2.523944]  ret_from_fork_asm+0x1a/0x30\n  [    2.523947]  </TASK>\n  [    2.523948]\n  [    2.531253] Allocated by task 48:\n  [    2.531399]  kasan_save_stack+0x33/0x60\n  [    2.531570]  kasan_save_track+0x14/0x30\n  [    2.531737]  __kasan_kmalloc+0x8f/0xa0\n  [    2.531905]  __kmalloc_cache_noprof+0x158/0x370\n  [    2.532100]  smc_llc_enqueue+0x72/0x560\n  [    2.532268]  smc_wr_rx_tasklet_fn+0x474/0xa80\n  [    2.532491]  tasklet_action_common+0x20f/0x8a0\n  [    2.532714]  handle_softirqs+0x18e/0x590\n  [    2.532886]  do_softirq+0x3b/0x60\n  [    2.533036]  __local_bh_enable_ip+0x61/0x70\n  [    2.533221]  __alloc_skb+0x732/0x890\n  [    2.533384]  rxe_init_packet+0x16b/0x4f0\n  [    2.533567]  prepare_ack_packet+0xb8/0x830\n  [    2.533760]  rxe_receiver+0x495/0x96e0\n  [    2.533933]  do_work+0x144/0x470\n  [    2\n---truncated---",
            "updated_at": "2026-09-13T07:17:05.000",
            "published_at": "2026-09-11T20:19:04.520",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "27ef6a9981fe74191849966a6d5e0400a4008ab8 through before c52a998a223e7e84333306996edec096178d1e95 (git); 27ef6a9981fe74191849966a6d5e0400a4008ab8 through before adef84cc85d449ac28d2b4b4c49cf19619c56e27 (git); 27ef6a9981fe74191849966a6d5e0400a4008ab8 through before a42a459ef0e54cb0c4b3e43e21cb0e658e664f64 (git); 6.14",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix use-after-free of the LLC qentry in smc_llc_srv_add_link()\n\nsmc_llc_srv_add_link() keeps add_llc pointing into the queue entry:\n\n  add_llc = &qentry->msg.add_link;\t\t\tsmc_llc.c:1482\n  ...\n  smc_llc_save_add_link_info(link_new, add_llc);\tsmc_llc.c:1494\n  smc_llc_flow_qentry_del(&lgr->llc_flow_lcl);\t\tsmc_llc.c:1495\n  ...\n  u8 *llc_msg = smc_link_shared_v2_rxbuf(link) ?\n\t(u8 *)lgr->wr_rx_buf_v2 : (u8 *)add_llc;\tsmc_llc.c:1504\n  smc_llc_save_add_link_rkeys(link, link_new, llc_msg);\tsmc_llc.c:1506\n\nsmc_llc_flow_qentry_del() kfree()s the entry, so on a link without a shared\nv2 receive buffer the pointer handed to smc_llc_save_add_link_rkeys() is\nalready freed. Before the Fixes: commit that branch always used\nlgr->wr_rx_buf_v2 and add_llc was not used after the free.\n\nReproduced on an unpatched tree over rxe, with KASAN, kasan_multi_shot\nand a link forced to max_recv_sge == 1: the entry is freed and read by\nthe same call, and the freeing frame is smc_llc_srv_add_link() itself.\n\n  [    2.523161] BUG: KASAN: slab-use-after-free in smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.523499] Read of size 2 at addr ffff8880052194de by task kworker/0:1/11\n  [    2.523789]\n  [    2.523862] CPU: 0 UID: 0 PID: 11 Comm: kworker/0:1 Not tainted 7.2.0-rc5-p0-g2c9dd296545d #35 PREEMPT(lazy)\n  [    2.523865] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n  [    2.523866] Workqueue: smc_hs_wq smc_listen_work\n  [    2.523869] Call Trace:\n  [    2.523870]  <TASK>\n  [    2.523871]  dump_stack_lvl+0x53/0x70\n  [    2.523872]  print_report+0xd0/0x630\n  [    2.523874]  ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n  [    2.523876]  ? smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.523878]  kasan_report+0xce/0x100\n  [    2.523879]  ? smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.523881]  smc_llc_save_add_link_rkeys+0x333/0x350\n  [    2.523883]  ? smcr_buf_reg_lgr+0x2a4/0x660\n  [    2.523885]  smc_llc_srv_add_link+0xaa2/0x1e50\n  [    2.523888]  ? _printk+0xba/0xf0\n  [    2.523897]  ? __pfx_smc_llc_srv_add_link+0x10/0x10\n  [    2.523899]  ? down_write+0xb0/0x130\n  [    2.523903]  ? __pfx_down_write+0x10/0x10\n  [    2.523905]  smc_listen_work+0x489e/0x4d00\n  [    2.523907]  ? kmem_cache_free+0x1c6/0x3a0\n  [    2.523911]  ? __pfx_smc_listen_work+0x10/0x10\n  [    2.523913]  ? release_sock+0x148/0x1d0\n  [    2.523915]  ? smc_tcp_listen_work+0xb4f/0xfc0\n  [    2.523917]  ? _raw_spin_lock_irq+0x80/0xe0\n  [    2.523918]  ? __pfx__raw_spin_lock_irq+0x10/0x10\n  [    2.523920]  process_one_work+0x633/0x1030\n  [    2.523922]  ? assign_work+0x11d/0x370\n  [    2.523924]  worker_thread+0x45b/0xd10\n  [    2.523926]  ? __pfx_worker_thread+0x10/0x10\n  [    2.523928]  ? __pfx_worker_thread+0x10/0x10\n  [    2.523929]  kthread+0x2c6/0x3b0\n  [    2.523931]  ? recalc_sigpending+0x15c/0x1e0\n  [    2.523934]  ? __pfx_kthread+0x10/0x10\n  [    2.523935]  ret_from_fork+0x36e/0x5a0\n  [    2.523937]  ? __pfx_ret_from_fork+0x10/0x10\n  [    2.523938]  ? __switch_to+0x572/0xdd0\n  [    2.523943]  ? __pfx_kthread+0x10/0x10\n  [    2.523944]  ret_from_fork_asm+0x1a/0x30\n  [    2.523947]  </TASK>\n  [    2.523948]\n  [    2.531253] Allocated by task 48:\n  [    2.531399]  kasan_save_stack+0x33/0x60\n  [    2.531570]  kasan_save_track+0x14/0x30\n  [    2.531737]  __kasan_kmalloc+0x8f/0xa0\n  [    2.531905]  __kmalloc_cache_noprof+0x158/0x370\n  [    2.532100]  smc_llc_enqueue+0x72/0x560\n  [    2.532268]  smc_wr_rx_tasklet_fn+0x474/0xa80\n  [    2.532491]  tasklet_action_common+0x20f/0x8a0\n  [    2.532714]  handle_softirqs+0x18e/0x590\n  [    2.532886]  do_softirq+0x3b/0x60\n  [    2.533036]  __local_bh_enable_ip+0x61/0x70\n  [    2.533221]  __alloc_skb+0x732/0x890\n  [    2.533384]  rxe_init_packet+0x16b/0x4f0\n  [    2.533567]  prepare_ack_packet+0xb8/0x830\n  [    2.533760]  rxe_receiver+0x495/0x96e0\n  [    2.533933]  do_work+0x144/0x470\n  [    2\n---truncated---",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/a42a459ef0e54cb0c4b3e43e21cb0e658e664f64",
                "https://git.kernel.org/stable/c/adef84cc85d449ac28d2b4b4c49cf19619c56e27",
                "https://git.kernel.org/stable/c/c52a998a223e7e84333306996edec096178d1e95"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:04.520",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80981"
                }
            ]
        },
        {
            "id": "CVE-2026-80980",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: stop killed, freed and out_of_sync sharing a byte\n\nThe three connection state flags are single-bit bitfields, so they occupy\none byte of struct smc_connection and every store to one is a\nread-modify-write of the other two:\n\n    u8  killed : 1;\n    u8  freed : 1;\n    u8  out_of_sync : 1;\n\nThey are not written under a common lock. smc_cdc_msg_validate() sets\nout_of_sync from the receive tasklet, while smc_conn_kill() sets killed\nfrom process context under lock_sock(), and the receive path does not defer\nto the backlog when the socket is owned -- smc_cdc_msg_recv() takes only\nbh_lock_sock().\n\nGive each flag its own byte so a store no longer touches its neighbours.\nAll readers test them as booleans and are unchanged. struct smc_connection\ngrows by two bytes.",
            "updated_at": "2026-09-13T07:17:04.887",
            "published_at": "2026-09-11T20:19:04.407",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "b286a0651e4404ab96cdfdcdad8a839a26b3751e through before 313f79149eb337411c64e2c247234b62ef9a3cb9 (git); b286a0651e4404ab96cdfdcdad8a839a26b3751e through before 2cb7a8d64b7e8ccdc69bbe48fe9c4eaa79c33aec (git); b286a0651e4404ab96cdfdcdad8a839a26b3751e through before db51a8658c11a82432b64999519a269c3aabb447 (git); 5.8",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: stop killed, freed and out_of_sync sharing a byte\n\nThe three connection state flags are single-bit bitfields, so they occupy\none byte of struct smc_connection and every store to one is a\nread-modify-write of the other two:\n\n    u8  killed : 1;\n    u8  freed : 1;\n    u8  out_of_sync : 1;\n\nThey are not written under a common lock. smc_cdc_msg_validate() sets\nout_of_sync from the receive tasklet, while smc_conn_kill() sets killed\nfrom process context under lock_sock(), and the receive path does not defer\nto the backlog when the socket is owned -- smc_cdc_msg_recv() takes only\nbh_lock_sock().\n\nGive each flag its own byte so a store no longer touches its neighbours.\nAll readers test them as booleans and are unchanged. struct smc_connection\ngrows by two bytes.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2cb7a8d64b7e8ccdc69bbe48fe9c4eaa79c33aec",
                "https://git.kernel.org/stable/c/313f79149eb337411c64e2c247234b62ef9a3cb9",
                "https://git.kernel.org/stable/c/db51a8658c11a82432b64999519a269c3aabb447"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:04.407",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80980"
                }
            ]
        },
        {
            "id": "CVE-2026-80979",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: unregister the connection before draining the rx tasklet\n\nsmc_conn_free() calls smc_ism_unset_conn() only while the link group is\nstill on its device list, and never sets conn->killed.\nsmc_lgr_terminate_sched() unlinks the group immediately and defers killing\nits connections to a work item, so a connection freed in that window keeps\nits smcd->conn[] slot with both gates in smcd_handle_irq() open, and the\ndevice can re-arm the receive tasklet after tasklet_kill() has returned. On\nthe DMB-nocopy path the ghost send buffer is freed right after that drain,\nso the re-armed tasklet dereferences it.\n\nUnregister unconditionally and drain before the detach at both teardown\nsites, mirroring rmb_desc, which smc_buf_unuse() releases after the drain.\nClear conn->sndbuf_desc before freeing it as well, so a reader that samples\nthe pointer cannot get one that is already freed.",
            "updated_at": "2026-09-13T07:17:04.733",
            "published_at": "2026-09-11T20:19:04.277",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "ae2be35cbed2c8385e890147ea321a3fcc3ca5fa through before b4d540ac95cd35c6ebab6afb7eae2bcac7b277a5 (git); ae2be35cbed2c8385e890147ea321a3fcc3ca5fa through before 5bd8b764a610b6b6bc0c4d3d01652747f6e0b5c3 (git); ae2be35cbed2c8385e890147ea321a3fcc3ca5fa through before b74d313567dfc1b7e56629ddbad04e728686f235 (git); ae2be35cbed2c8385e890147ea321a3fcc3ca5fa through before 36cdf5d48ca191dcd71c28cadbe0981b1d25318d (git); 21f6f41e82e59740e26e06e77bdf58dc7f6f08dd (git); 6.6.66 through before 6.7 (semver); 6.10",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: unregister the connection before draining the rx tasklet\n\nsmc_conn_free() calls smc_ism_unset_conn() only while the link group is\nstill on its device list, and never sets conn->killed.\nsmc_lgr_terminate_sched() unlinks the group immediately and defers killing\nits connections to a work item, so a connection freed in that window keeps\nits smcd->conn[] slot with both gates in smcd_handle_irq() open, and the\ndevice can re-arm the receive tasklet after tasklet_kill() has returned. On\nthe DMB-nocopy path the ghost send buffer is freed right after that drain,\nso the re-armed tasklet dereferences it.\n\nUnregister unconditionally and drain before the detach at both teardown\nsites, mirroring rmb_desc, which smc_buf_unuse() releases after the drain.\nClear conn->sndbuf_desc before freeing it as well, so a reader that samples\nthe pointer cannot get one that is already freed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/36cdf5d48ca191dcd71c28cadbe0981b1d25318d",
                "https://git.kernel.org/stable/c/5bd8b764a610b6b6bc0c4d3d01652747f6e0b5c3",
                "https://git.kernel.org/stable/c/b4d540ac95cd35c6ebab6afb7eae2bcac7b277a5",
                "https://git.kernel.org/stable/c/b74d313567dfc1b7e56629ddbad04e728686f235"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:04.277",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80979"
                }
            ]
        },
        {
            "id": "CVE-2026-80978",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: cap advertised IP tunnel headroom\n\nIP tunnel devices derive their advertised needed_headroom from lower\noutput devices. A stack of user-created devices can make the derived\nvalue larger than the 16-bit skb header offsets can represent. Once IP\noutput reserves it, skb head expansion can wrap those offsets.\n\nThe runtime transmit path already caps a growing needed_headroom at 512.\nApply the same cap when tunnel configuration publishes needed_headroom\nderived from a lower output device.\n\nCapping the advertised value is safe: IP tunnel transmit still expands\nthe skb when a packet needs more headroom. A nonsensical stacked\nconfiguration can therefore incur an extra reallocation, but it cannot\npublish an unbounded reservation to upper layers.",
            "updated_at": "2026-09-13T07:17:04.597",
            "published_at": "2026-09-11T20:19:04.143",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1a37e412a0225fcba5587f24c0dfc7636efc8b69 through before bc4e05ae66c9797a0972ac44326e69c5305e0020 (git); 1a37e412a0225fcba5587f24c0dfc7636efc8b69 through before af0ee8f04bea22cdb331fa3509e17f81b48938ad (git); 1a37e412a0225fcba5587f24c0dfc7636efc8b69 through before 9144f2c53a04465a6878172b523f640313c5559e (git); 1a37e412a0225fcba5587f24c0dfc7636efc8b69 through before 6b222adeb9340306e2ff97127c76117abb9b3df8 (git); 3.11",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: cap advertised IP tunnel headroom\n\nIP tunnel devices derive their advertised needed_headroom from lower\noutput devices. A stack of user-created devices can make the derived\nvalue larger than the 16-bit skb header offsets can represent. Once IP\noutput reserves it, skb head expansion can wrap those offsets.\n\nThe runtime transmit path already caps a growing needed_headroom at 512.\nApply the same cap when tunnel configuration publishes needed_headroom\nderived from a lower output device.\n\nCapping the advertised value is safe: IP tunnel transmit still expands\nthe skb when a packet needs more headroom. A nonsensical stacked\nconfiguration can therefore incur an extra reallocation, but it cannot\npublish an unbounded reservation to upper layers.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/6b222adeb9340306e2ff97127c76117abb9b3df8",
                "https://git.kernel.org/stable/c/9144f2c53a04465a6878172b523f640313c5559e",
                "https://git.kernel.org/stable/c/af0ee8f04bea22cdb331fa3509e17f81b48938ad",
                "https://git.kernel.org/stable/c/bc4e05ae66c9797a0972ac44326e69c5305e0020"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:04.143",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80978"
                }
            ]
        },
        {
            "id": "CVE-2026-80977",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: don't touch shared zerocopy state in skb_tx_error()\n\nskb_tx_error() completes the zerocopy uarg and clears\nSKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears\nSKBFL_MANAGED_FRAG_REFS. Both live in skb_shinfo(), which every clone\nshares, while the caller only owns the reference it is about to drop.\nThrough a clone it tells the producer its pages are free and drops\nSKBFL_SHARED_FRAG for an skb that is still in flight.\n\nOpen vSwitch reaches this with a non-last OVS_ACTION_ATTR_RECIRC:\nclone_execute() sends a skb_clone() into ovs_dp_process_packet() while\ndo_execute_actions() keeps forwarding the original, and skb_clone()\ndoes not privatise the frags here -- skb_orphan_frags() returns early\non SKBFL_DONT_ORPHAN. A flow miss on the clone then strips the marker\nfrom the packet still being forwarded, and a later local ESP delivery\ndecrypts in place over frags it does not own privately.\n\nSkip it for a cloned skb. Nothing is lost: skb_release_data() clears\nthe zerocopy state once the last reference to the shared data goes.",
            "updated_at": "2026-09-13T07:17:04.467",
            "published_at": "2026-09-11T20:19:04.013",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "25121173f7b1e4ac3fc692df6e7b8c52ec36abba through before 15aa81b390d401abf4b8211042470e9e92e3b7fb (git); 25121173f7b1e4ac3fc692df6e7b8c52ec36abba through before 288f9970670841044ab030104fa6b6ed159949d0 (git); 25121173f7b1e4ac3fc692df6e7b8c52ec36abba through before 0370da114a9bc044e248b85c6809d1b5e0c1f7f9 (git); 25121173f7b1e4ac3fc692df6e7b8c52ec36abba through before f66bdb1cc0fcd227a062378f8be0b5873aa5600a (git); 3.8",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: don't touch shared zerocopy state in skb_tx_error()\n\nskb_tx_error() completes the zerocopy uarg and clears\nSKBFL_ALL_ZEROCOPY, and skb_zcopy_downgrade_managed() clears\nSKBFL_MANAGED_FRAG_REFS. Both live in skb_shinfo(), which every clone\nshares, while the caller only owns the reference it is about to drop.\nThrough a clone it tells the producer its pages are free and drops\nSKBFL_SHARED_FRAG for an skb that is still in flight.\n\nOpen vSwitch reaches this with a non-last OVS_ACTION_ATTR_RECIRC:\nclone_execute() sends a skb_clone() into ovs_dp_process_packet() while\ndo_execute_actions() keeps forwarding the original, and skb_clone()\ndoes not privatise the frags here -- skb_orphan_frags() returns early\non SKBFL_DONT_ORPHAN. A flow miss on the clone then strips the marker\nfrom the packet still being forwarded, and a later local ESP delivery\ndecrypts in place over frags it does not own privately.\n\nSkip it for a cloned skb. Nothing is lost: skb_release_data() clears\nthe zerocopy state once the last reference to the shared data goes.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0370da114a9bc044e248b85c6809d1b5e0c1f7f9",
                "https://git.kernel.org/stable/c/15aa81b390d401abf4b8211042470e9e92e3b7fb",
                "https://git.kernel.org/stable/c/288f9970670841044ab030104fa6b6ed159949d0",
                "https://git.kernel.org/stable/c/f66bdb1cc0fcd227a062378f8be0b5873aa5600a"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:04.013",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80977"
                }
            ]
        },
        {
            "id": "CVE-2026-80976",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nseg6: reset IP6CB after IPv6 decapsulation\n\ndecap_and_validate() pulls the outer SRv6 headers and makes the inner\npacket the skb network header. The IPv6 control block still contains\nvalues collected while parsing the outer packet, including nhoff and\nextension-header flags.\n\nEnd.DX6 and End.DT6 route the inner IPv6 packet directly to the IPv6\ninput path. An unprivileged user can reach End.DT6 from a user and net\nnamespace by installing a local SID and injecting an outer packet with\nHop-by-Hop and Destination Options headers followed by an SRH and a\nminimal inner IPv6 packet.\n\nThe outer extension headers leave a large nhoff in IP6CB. After\ndecapsulation, ip6_protocol_deliver_rcu() uses that stale offset on the\ninner packet and reads beyond the skb head. KASAN reports:\n\n  BUG: KASAN: slab-out-of-bounds in ip6_protocol_deliver_rcu\n  ip6_protocol_deliver_rcu+0x1118/0x1450\n  ip6_input_finish+0x11b/0x240\n  seg6_local_input_core+0xed/0x2e0\n  lwtunnel_input+0x1e9/0x4e0\n  ipv6_rthdr_rcv+0x525f/0x6c50\n  ip6_protocol_deliver_rcu+0xcb7/0x1450\n\nBefore clearing IP6CB for an inner IPv6 packet, save its incoming\ninterface index and L3 slave state. Restore both after the clear and set\nnhoff to the inner IPv6 base-header nexthdr field.\n\nUse IP6CB(skb)->iif rather than skb->skb_iif because VRF processing can\nreplace skb_iif with the L3 master while IP6CB keeps the receiving\ninterface. Preserve IP6SKB_L3SLAVE for the same reason.",
            "updated_at": "2026-09-13T07:17:04.323",
            "published_at": "2026-09-11T20:19:03.887",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "d7a669dd2f8ba07a17423f4ad586dfc0379882f7 through before 2b154e96fcb3f01fd42765c64e0a56820fbc16eb (git); d7a669dd2f8ba07a17423f4ad586dfc0379882f7 through before cfa186a0857a0f831dfca67b16bbc40ecfdf3280 (git); d7a669dd2f8ba07a17423f4ad586dfc0379882f7 through before c73fb911e02b9a766c950bc9707f3e3a96ffd702 (git); d7a669dd2f8ba07a17423f4ad586dfc0379882f7 through before f967455fb2a5a2079b9eb5823e9ccf359174bf9f (git); 4.14",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nseg6: reset IP6CB after IPv6 decapsulation\n\ndecap_and_validate() pulls the outer SRv6 headers and makes the inner\npacket the skb network header. The IPv6 control block still contains\nvalues collected while parsing the outer packet, including nhoff and\nextension-header flags.\n\nEnd.DX6 and End.DT6 route the inner IPv6 packet directly to the IPv6\ninput path. An unprivileged user can reach End.DT6 from a user and net\nnamespace by installing a local SID and injecting an outer packet with\nHop-by-Hop and Destination Options headers followed by an SRH and a\nminimal inner IPv6 packet.\n\nThe outer extension headers leave a large nhoff in IP6CB. After\ndecapsulation, ip6_protocol_deliver_rcu() uses that stale offset on the\ninner packet and reads beyond the skb head. KASAN reports:\n\n  BUG: KASAN: slab-out-of-bounds in ip6_protocol_deliver_rcu\n  ip6_protocol_deliver_rcu+0x1118/0x1450\n  ip6_input_finish+0x11b/0x240\n  seg6_local_input_core+0xed/0x2e0\n  lwtunnel_input+0x1e9/0x4e0\n  ipv6_rthdr_rcv+0x525f/0x6c50\n  ip6_protocol_deliver_rcu+0xcb7/0x1450\n\nBefore clearing IP6CB for an inner IPv6 packet, save its incoming\ninterface index and L3 slave state. Restore both after the clear and set\nnhoff to the inner IPv6 base-header nexthdr field.\n\nUse IP6CB(skb)->iif rather than skb->skb_iif because VRF processing can\nreplace skb_iif with the L3 master while IP6CB keeps the receiving\ninterface. Preserve IP6SKB_L3SLAVE for the same reason.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2b154e96fcb3f01fd42765c64e0a56820fbc16eb",
                "https://git.kernel.org/stable/c/c73fb911e02b9a766c950bc9707f3e3a96ffd702",
                "https://git.kernel.org/stable/c/cfa186a0857a0f831dfca67b16bbc40ecfdf3280",
                "https://git.kernel.org/stable/c/f967455fb2a5a2079b9eb5823e9ccf359174bf9f"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:03.887",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80976"
                }
            ]
        },
        {
            "id": "CVE-2026-80975",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmfd: qnap-mcu: keep the reply buffer alive past a command timeout\n\nqnap_mcu_exec() publishes an on-stack buffer to the receive path:\n\n\tunsigned char rx[QNAP_MCU_RX_BUFFER_SIZE];\n\t...\n\treply->data = rx;\n\treply->length = length;\n\nand qnap_mcu_receive_buf() writes into it from the serdev receive path,\nwhich runs out of flush_to_ldisc() and is not serialized against\nqnap_mcu_exec() at all. bus_lock cannot cover it, because qnap_mcu_exec()\nholds that mutex across wait_for_completion_timeout().\n\nOn a timeout qnap_mcu_exec() returns with reply->data still pointing at\nits own frame. A reply that arrives late, or an unsolicited message from\nthe MCU, is then written into a stack frame that has been left, corrupting\nwhatever runs next on that stack. The same applies when qnap_mcu_write()\nfails, since that path returns without touching the reply state either.\n\nMove the receive buffer into struct qnap_mcu. It is 37 bytes and the\nstructure is devm_kzalloc()ed, so it lives as long as the driver, and a\nlate write lands in memory that is still valid and is reinitialized by the\nnext command. bus_lock keeps commands from sharing it.\n\nThis deliberately does not clear reply->data or reply->length on the\ntimeout path. Doing so races with qnap_mcu_receive_buf(), which reads both\nafter its\n\n\tif (!reply->length)\n\t\treturn size;\n\ncheck: clearing reply->data gives a NULL dereference, and clearing\nreply->length alone removes the reply->received == reply->length exit\ncondition, so the copy loop runs until the uart chunk is consumed and\noverruns the buffer. Leaving both set keeps the write bounded by\nreply->length, which qnap_mcu_exec() has already checked against\nsizeof(mcu->rx).",
            "updated_at": "2026-09-13T07:17:04.190",
            "published_at": "2026-09-11T20:19:03.763",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "998f70d1806bb718a7565f350283e4a79c8cbb4b through before 0b6680e306397097a97767447368221fac753809 (git); 998f70d1806bb718a7565f350283e4a79c8cbb4b through before 8391ee06d08845a0a165b5fe679ba326915166b2 (git); 998f70d1806bb718a7565f350283e4a79c8cbb4b through before 47504742cea7878ebd1bf1491bbed923df6b90b1 (git); 6.14",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nmfd: qnap-mcu: keep the reply buffer alive past a command timeout\n\nqnap_mcu_exec() publishes an on-stack buffer to the receive path:\n\n\tunsigned char rx[QNAP_MCU_RX_BUFFER_SIZE];\n\t...\n\treply->data = rx;\n\treply->length = length;\n\nand qnap_mcu_receive_buf() writes into it from the serdev receive path,\nwhich runs out of flush_to_ldisc() and is not serialized against\nqnap_mcu_exec() at all. bus_lock cannot cover it, because qnap_mcu_exec()\nholds that mutex across wait_for_completion_timeout().\n\nOn a timeout qnap_mcu_exec() returns with reply->data still pointing at\nits own frame. A reply that arrives late, or an unsolicited message from\nthe MCU, is then written into a stack frame that has been left, corrupting\nwhatever runs next on that stack. The same applies when qnap_mcu_write()\nfails, since that path returns without touching the reply state either.\n\nMove the receive buffer into struct qnap_mcu. It is 37 bytes and the\nstructure is devm_kzalloc()ed, so it lives as long as the driver, and a\nlate write lands in memory that is still valid and is reinitialized by the\nnext command. bus_lock keeps commands from sharing it.\n\nThis deliberately does not clear reply->data or reply->length on the\ntimeout path. Doing so races with qnap_mcu_receive_buf(), which reads both\nafter its\n\n\tif (!reply->length)\n\t\treturn size;\n\ncheck: clearing reply->data gives a NULL dereference, and clearing\nreply->length alone removes the reply->received == reply->length exit\ncondition, so the copy loop runs until the uart chunk is consumed and\noverruns the buffer. Leaving both set keeps the write bounded by\nreply->length, which qnap_mcu_exec() has already checked against\nsizeof(mcu->rx).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0b6680e306397097a97767447368221fac753809",
                "https://git.kernel.org/stable/c/47504742cea7878ebd1bf1491bbed923df6b90b1",
                "https://git.kernel.org/stable/c/8391ee06d08845a0a165b5fe679ba326915166b2"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:03.763",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80975"
                }
            ]
        },
        {
            "id": "CVE-2026-80972",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: aloop: Check card index validity at probe\n\naloop driver blindly trusts that the given devptr->id value is within\nthe proper card index range at probe.  It's OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.",
            "updated_at": "2026-09-13T07:17:04.093",
            "published_at": "2026-09-11T20:19:03.367",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "597603d615d2b19a9e451d8cfac24372856a522d through before c589aeaadfde1cfedb5c6f0a3c782807282126d9 (git); 597603d615d2b19a9e451d8cfac24372856a522d through before 7b3f9855849363e402bf2141df2b428581cbf31b (git); 597603d615d2b19a9e451d8cfac24372856a522d through before efbc2e9e43a1b5c6d75ae47439c06896bb142ae6 (git); 597603d615d2b19a9e451d8cfac24372856a522d through before 819b106a9fd2ef3fd8abf898b9a8e4524eca8f48 (git); 2.6.37",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: aloop: Check card index validity at probe\n\naloop driver blindly trusts that the given devptr->id value is within\nthe proper card index range at probe.  It's OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/7b3f9855849363e402bf2141df2b428581cbf31b",
                "https://git.kernel.org/stable/c/819b106a9fd2ef3fd8abf898b9a8e4524eca8f48",
                "https://git.kernel.org/stable/c/c589aeaadfde1cfedb5c6f0a3c782807282126d9",
                "https://git.kernel.org/stable/c/efbc2e9e43a1b5c6d75ae47439c06896bb142ae6"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:03.367",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80972"
                }
            ]
        },
        {
            "id": "CVE-2026-80971",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: bcd2000: clear the URB pointers on disconnect\n\nbcd2000_free_usb_related_resources() frees both URBs and leaves the\npointers behind:\n\n\tusb_kill_urb(bcd2k->midi_out_urb);\n\tusb_kill_urb(bcd2k->midi_in_urb);\n\n\tusb_free_urb(bcd2k->midi_out_urb);\n\tusb_free_urb(bcd2k->midi_in_urb);\n\nThe rawmidi device outlives that call.  A substream that is still open\nwhen the device is unplugged reaches bcd2000_midi_send() from the\ntrigger path on close.  That function writes to the freed URB and then\nhands it to the USB core:\n\n\tbcd2k->midi_out_urb->transfer_buffer_length = BUFSIZE;\n\t...\n\tret = usb_submit_urb(bcd2k->midi_out_urb, GFP_ATOMIC);\n\nusb_kill_urb() does not stop a later submission either, so a submit that\nraces the disconnect can requeue the URB after it has been reaped.\nmidi_in_urb is exposed the same way: bcd2000_input_complete() resubmits\nit from the completion handler.\n\nKASAN on 7.2.0-rc5 (arm64):\n\n  BUG: KASAN: slab-use-after-free in bcd2000_midi_send [snd_bcd2000]\n  Write of size 4 at addr ffff00001827d388 by task bpoc/168\n   __asan_store4\n   bcd2000_midi_send [snd_bcd2000]\n   bcd2000_midi_output_trigger [snd_bcd2000]\n   snd_rawmidi_kernel_write1\n   close_substream.part.0\n  Freed by task 168:\n   usb_free_urb\n   bcd2000_disconnect [snd_bcd2000]\n\n  BUG: KASAN: slab-use-after-free in usb_submit_urb\n  Read of size 8 at addr ffff00001827d3b8 by task bpoc/168\n\nClear both pointers after freeing and test them on the paths that can\nstill run.  Poison the URBs before freeing them: usb_poison_urb() waits\nfor a running completion handler and rejects any later submission, so\nafter it returns the input path is quiesced and only the rawmidi trigger\npath can still reach bcd2000_midi_send().  No unpoison is needed; the\nURBs are freed on the next line.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>",
            "updated_at": "2026-09-13T07:17:03.953",
            "published_at": "2026-09-11T20:19:03.233",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "b47a22290d581277be70e8a597824a4985d39e83 through before eb482a06791d6168beb8c78cc904ac5a5ed96a55 (git); b47a22290d581277be70e8a597824a4985d39e83 through before 7df3194bdb7479cad9199889655a566a2c0c1d1b (git); b47a22290d581277be70e8a597824a4985d39e83 through before b06ebc7fe25a6af4a9f6e4a3d4236a4178ad4b01 (git); b47a22290d581277be70e8a597824a4985d39e83 through before 459d3a64766f5ca2f1886daeaf24582831a5f5ab (git); 3.16",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: bcd2000: clear the URB pointers on disconnect\n\nbcd2000_free_usb_related_resources() frees both URBs and leaves the\npointers behind:\n\n\tusb_kill_urb(bcd2k->midi_out_urb);\n\tusb_kill_urb(bcd2k->midi_in_urb);\n\n\tusb_free_urb(bcd2k->midi_out_urb);\n\tusb_free_urb(bcd2k->midi_in_urb);\n\nThe rawmidi device outlives that call.  A substream that is still open\nwhen the device is unplugged reaches bcd2000_midi_send() from the\ntrigger path on close.  That function writes to the freed URB and then\nhands it to the USB core:\n\n\tbcd2k->midi_out_urb->transfer_buffer_length = BUFSIZE;\n\t...\n\tret = usb_submit_urb(bcd2k->midi_out_urb, GFP_ATOMIC);\n\nusb_kill_urb() does not stop a later submission either, so a submit that\nraces the disconnect can requeue the URB after it has been reaped.\nmidi_in_urb is exposed the same way: bcd2000_input_complete() resubmits\nit from the completion handler.\n\nKASAN on 7.2.0-rc5 (arm64):\n\n  BUG: KASAN: slab-use-after-free in bcd2000_midi_send [snd_bcd2000]\n  Write of size 4 at addr ffff00001827d388 by task bpoc/168\n   __asan_store4\n   bcd2000_midi_send [snd_bcd2000]\n   bcd2000_midi_output_trigger [snd_bcd2000]\n   snd_rawmidi_kernel_write1\n   close_substream.part.0\n  Freed by task 168:\n   usb_free_urb\n   bcd2000_disconnect [snd_bcd2000]\n\n  BUG: KASAN: slab-use-after-free in usb_submit_urb\n  Read of size 8 at addr ffff00001827d3b8 by task bpoc/168\n\nClear both pointers after freeing and test them on the paths that can\nstill run.  Poison the URBs before freeing them: usb_poison_urb() waits\nfor a running completion handler and rejects any later submission, so\nafter it returns the input path is quiesced and only the rawmidi trigger\npath can still reach bcd2000_midi_send().  No unpoison is needed; the\nURBs are freed on the next line.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/459d3a64766f5ca2f1886daeaf24582831a5f5ab",
                "https://git.kernel.org/stable/c/7df3194bdb7479cad9199889655a566a2c0c1d1b",
                "https://git.kernel.org/stable/c/b06ebc7fe25a6af4a9f6e4a3d4236a4178ad4b01",
                "https://git.kernel.org/stable/c/eb482a06791d6168beb8c78cc904ac5a5ed96a55"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:03.233",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80971"
                }
            ]
        },
        {
            "id": "CVE-2026-80969",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: mpu401: Check card index validity at probe\n\nmpu401 driver blindly trusts that the given devptr->id value is within\nthe proper card index range at probe.  It's OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.",
            "updated_at": "2026-09-13T07:17:03.853",
            "published_at": "2026-09-11T20:19:02.967",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "b3fe95123f0db79dd0345d249c312823178c11f5 through before 76b6bc38d0f310c0ae1b2a2ebabe2947d92c601a (git); b3fe95123f0db79dd0345d249c312823178c11f5 through before cc4215cc2a4b2a9cf8b1952bbe8d5bf925acb3ea (git); b3fe95123f0db79dd0345d249c312823178c11f5 through before 8adda66edf795d4648f8e26f312e4414c535d25a (git); b3fe95123f0db79dd0345d249c312823178c11f5 through before f7dcecb92ed192ff5fcf842918fb1aaea84b5bdd (git); 2.6.16",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: mpu401: Check card index validity at probe\n\nmpu401 driver blindly trusts that the given devptr->id value is within\nthe proper card index range at probe.  It's OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/76b6bc38d0f310c0ae1b2a2ebabe2947d92c601a",
                "https://git.kernel.org/stable/c/8adda66edf795d4648f8e26f312e4414c535d25a",
                "https://git.kernel.org/stable/c/cc4215cc2a4b2a9cf8b1952bbe8d5bf925acb3ea",
                "https://git.kernel.org/stable/c/f7dcecb92ed192ff5fcf842918fb1aaea84b5bdd"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:02.967",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80969"
                }
            ]
        },
        {
            "id": "CVE-2026-80968",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: mts64: Check card index validity at probe\n\nAlthough mts64 driver has a check of the given devptr->id value, it\ndoesn't check for a negative id, which is often given as \"none\" or\nsuch value when bound via sysfs.  This may lead to OOB access for\nindex[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.",
            "updated_at": "2026-09-13T07:17:03.753",
            "published_at": "2026-09-11T20:19:02.843",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad through before 036e7aa793375ab16ea0f64b8de6673220416cc1 (git); 68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad through before a4e774eeb61aec64da5b03d3becffde26f7fe4de (git); 68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad through before cf3af453a48c8d905512dfc44a5a59439b70f4f0 (git); 68ab801e32bbe2caac8b8c6e6e94f41fe7d687ad through before d18a260720f86a5f8b5fcfefc4ba2e9dd01c10f8 (git); 2.6.19",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: mts64: Check card index validity at probe\n\nAlthough mts64 driver has a check of the given devptr->id value, it\ndoesn't check for a negative id, which is often given as \"none\" or\nsuch value when bound via sysfs.  This may lead to OOB access for\nindex[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/036e7aa793375ab16ea0f64b8de6673220416cc1",
                "https://git.kernel.org/stable/c/a4e774eeb61aec64da5b03d3becffde26f7fe4de",
                "https://git.kernel.org/stable/c/cf3af453a48c8d905512dfc44a5a59439b70f4f0",
                "https://git.kernel.org/stable/c/d18a260720f86a5f8b5fcfefc4ba2e9dd01c10f8"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:02.843",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80968"
                }
            ]
        },
        {
            "id": "CVE-2026-80967",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcxhr: initialize mutexes before requesting threaded IRQ\n\npcxhr_probe() requests pcxhr_threaded_irq() before initializing\nmgr->lock, even though the threaded handler takes that mutex.\n\nInitialize the manager locks before request_threaded_irq() so an\nearly interrupt cannot run against uninitialized mutex state during\nprobe.",
            "updated_at": "2026-09-13T07:17:03.630",
            "published_at": "2026-09-11T20:19:02.720",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9bef72bdb26e291d6dffb04768741a0e49582666 through before c069b3cfd753d6688ea0271c43553631ab38ce10 (git); 9bef72bdb26e291d6dffb04768741a0e49582666 through before 7ef9ad82d95dd3c74570d80a689a0570fbc7539e (git); 9bef72bdb26e291d6dffb04768741a0e49582666 through before 7cf280fbef5db6310e1b32074c8c34d1ba459796 (git); 9bef72bdb26e291d6dffb04768741a0e49582666 through before 6c97817e20598e5473094e0e38d1f51f1cf4dfff (git); 3.18",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcxhr: initialize mutexes before requesting threaded IRQ\n\npcxhr_probe() requests pcxhr_threaded_irq() before initializing\nmgr->lock, even though the threaded handler takes that mutex.\n\nInitialize the manager locks before request_threaded_irq() so an\nearly interrupt cannot run against uninitialized mutex state during\nprobe.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/6c97817e20598e5473094e0e38d1f51f1cf4dfff",
                "https://git.kernel.org/stable/c/7cf280fbef5db6310e1b32074c8c34d1ba459796",
                "https://git.kernel.org/stable/c/7ef9ad82d95dd3c74570d80a689a0570fbc7539e",
                "https://git.kernel.org/stable/c/c069b3cfd753d6688ea0271c43553631ab38ce10"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:02.720",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80967"
                }
            ]
        },
        {
            "id": "CVE-2026-80966",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: portman2x4: Check card index validity at probe\n\nAlthough portman2x4 driver has a check of the given devptr->id value,\nit doesn't check for a negative id, which is often given as \"none\" or\nsuch value when bound via sysfs.  This may lead to OOB access for\nindex[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.",
            "updated_at": "2026-09-13T07:17:03.527",
            "published_at": "2026-09-11T20:19:02.600",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "757e119bf52b014b3181eed97b01f87a245b8ff9 through before 0ce391090809d610647f424b9b1dc24aa2c546fd (git); 757e119bf52b014b3181eed97b01f87a245b8ff9 through before d7ef7890e3e35b4ba09e76fc6b72047a1599a5e8 (git); 757e119bf52b014b3181eed97b01f87a245b8ff9 through before e1ce8ad1009b1736b3044b3324350dcfdd516f42 (git); 757e119bf52b014b3181eed97b01f87a245b8ff9 through before 3690ef20469d5959378260e2752f2314a2572913 (git); 2.6.21",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: portman2x4: Check card index validity at probe\n\nAlthough portman2x4 driver has a check of the given devptr->id value,\nit doesn't check for a negative id, which is often given as \"none\" or\nsuch value when bound via sysfs.  This may lead to OOB access for\nindex[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0ce391090809d610647f424b9b1dc24aa2c546fd",
                "https://git.kernel.org/stable/c/3690ef20469d5959378260e2752f2314a2572913",
                "https://git.kernel.org/stable/c/d7ef7890e3e35b4ba09e76fc6b72047a1599a5e8",
                "https://git.kernel.org/stable/c/e1ce8ad1009b1736b3044b3324350dcfdd516f42"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:02.600",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80966"
                }
            ]
        },
        {
            "id": "CVE-2026-80965",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: serial-u16550: Check card index validity at probe\n\nserial-u16550 driver blindly trusts that the given devptr->id value is\nwithin the proper card index range at probe.  It's OK for the devices\nthe driver itself creates at the module probe time, but if the device\nis bound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.",
            "updated_at": "2026-09-13T07:17:03.427",
            "published_at": "2026-09-11T20:19:02.477",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9caf6b5908e1e3b10478e9201ca1be809145253f through before fbf3fb097e66fc1874e54ecc46d600d9325480d6 (git); 9caf6b5908e1e3b10478e9201ca1be809145253f through before 7555e83d7738e65dc83921e3c85bbdc081f08f2f (git); 9caf6b5908e1e3b10478e9201ca1be809145253f through before 6d6fdb24fe2eaf6174fc502284c6e1dc5f7242ba (git); 9caf6b5908e1e3b10478e9201ca1be809145253f through before e0fb960b227fcdebe22e4f26c9486d60943c0424 (git); 2.6.16",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: serial-u16550: Check card index validity at probe\n\nserial-u16550 driver blindly trusts that the given devptr->id value is\nwithin the proper card index range at probe.  It's OK for the devices\nthe driver itself creates at the module probe time, but if the device\nis bound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/6d6fdb24fe2eaf6174fc502284c6e1dc5f7242ba",
                "https://git.kernel.org/stable/c/7555e83d7738e65dc83921e3c85bbdc081f08f2f",
                "https://git.kernel.org/stable/c/e0fb960b227fcdebe22e4f26c9486d60943c0424",
                "https://git.kernel.org/stable/c/fbf3fb097e66fc1874e54ecc46d600d9325480d6"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:02.477",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80965"
                }
            ]
        },
        {
            "id": "CVE-2026-80964",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: virmidi: Check card index validity at probe\n\nvirmidi driver blindly trusts that the given devptr->id value is\nwithin the proper card index range at probe.  It's OK for the devices\nthe driver itself creates at the module probe time, but if the device\nis bound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.",
            "updated_at": "2026-09-13T07:17:03.327",
            "published_at": "2026-09-11T20:19:02.347",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3564fbb880f9a62ddbb81b7440c32e0e6619c52d through before 43f161c53279adac0517cf1c443e531e738b54ce (git); 3564fbb880f9a62ddbb81b7440c32e0e6619c52d through before 40ee4224e2fe24c05b92e4d37476adb6e83f10e9 (git); 3564fbb880f9a62ddbb81b7440c32e0e6619c52d through before f48c5f3b03afdb795e5f448a1d53d912d5b09f2e (git); 3564fbb880f9a62ddbb81b7440c32e0e6619c52d through before b65d5182ecd6b7a24a83d980a0d06e809ef876c5 (git); 2.6.16",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: virmidi: Check card index validity at probe\n\nvirmidi driver blindly trusts that the given devptr->id value is\nwithin the proper card index range at probe.  It's OK for the devices\nthe driver itself creates at the module probe time, but if the device\nis bound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/40ee4224e2fe24c05b92e4d37476adb6e83f10e9",
                "https://git.kernel.org/stable/c/43f161c53279adac0517cf1c443e531e738b54ce",
                "https://git.kernel.org/stable/c/b65d5182ecd6b7a24a83d980a0d06e809ef876c5",
                "https://git.kernel.org/stable/c/f48c5f3b03afdb795e5f448a1d53d912d5b09f2e"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:02.347",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80964"
                }
            ]
        },
        {
            "id": "CVE-2026-80962",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-pcache: validate geometry fields from on-disk cache_info\n\ncache_segs_init() iterates cache_info->n_segs times indexing\ncache->segments[], which is sized to the cache device geometry, and\nget_seg_id() takes each segment id from the on-media cache_info and the\nper-segment next_seg link. Both come from cache device metadata that is\nonly CRC-protected with a fixed public seed, so whoever supplies the\ncache device on a table load (CAP_SYS_ADMIN) controls them: an oversized\nn_segs or an out-of-range id drives an out-of-bounds access of\ncache->segments[] and a wild CACHE_DEV_SEGMENT() pointer into the device\nmapping -- an out-of-bounds read and write from on-disk data.\n\nReject an n_segs that exceeds the device segment count and a segment id\nthat is out of range before either is used. Valid metadata is unaffected.",
            "updated_at": "2026-09-13T07:17:03.200",
            "published_at": "2026-09-11T20:19:02.100",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before ab5dcde6fa96bc115b85f3621c60e39c66229a90 (git); 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before 3e19172089ec81132a8a48e802b1034a744209f4 (git); 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before 32d1809da31094ef76fd98dc1f1a8b55ca1295dd (git); 6.18",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-pcache: validate geometry fields from on-disk cache_info\n\ncache_segs_init() iterates cache_info->n_segs times indexing\ncache->segments[], which is sized to the cache device geometry, and\nget_seg_id() takes each segment id from the on-media cache_info and the\nper-segment next_seg link. Both come from cache device metadata that is\nonly CRC-protected with a fixed public seed, so whoever supplies the\ncache device on a table load (CAP_SYS_ADMIN) controls them: an oversized\nn_segs or an out-of-range id drives an out-of-bounds access of\ncache->segments[] and a wild CACHE_DEV_SEGMENT() pointer into the device\nmapping -- an out-of-bounds read and write from on-disk data.\n\nReject an n_segs that exceeds the device segment count and a segment id\nthat is out of range before either is used. Valid metadata is unaffected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/32d1809da31094ef76fd98dc1f1a8b55ca1295dd",
                "https://git.kernel.org/stable/c/3e19172089ec81132a8a48e802b1034a744209f4",
                "https://git.kernel.org/stable/c/ab5dcde6fa96bc115b85f3621c60e39c66229a90"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:02.100",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80962"
                }
            ]
        },
        {
            "id": "CVE-2026-80961",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-pcache: validate kset key_num and intra-segment bounds\n\nTwo more fields decoded from the cache device go unbounded. The kset\nkey_num drives cache_kset_crc() and the replay loop in cache_replay(),\nthe writeback worker and the GC worker, but only the magic and a\nfixed-seed CRC are checked first, so a non-last kset whose key_num exceeds\nthe PCACHE_KSET_KEYS_MAX buffer reads past its end before the CRC compare.\nA key's intra-segment offset and length in cache_key_decode() are taken\nverbatim, so a key running past its segment is replayed into the cache\ntree and the data CRC check and every later read hit then copy adjacent\npersistent memory into the caller's bio -- an out-of-bounds read that\nleaks to user space. Both fields are controlled by whoever supplies the\ncache device (CAP_SYS_ADMIN); the CRC seed is public.\n\nAdd kset_onmedia_valid() to bound key_num before any kset read, and\nreject a key whose offset plus length, computed in 64 bits, exceeds the\nsegment data_size. Valid metadata is unaffected.",
            "updated_at": "2026-09-13T07:17:03.070",
            "published_at": "2026-09-11T20:19:01.980",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before d8caf96040a06096276ab72f5e1e8547c014c564 (git); 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before 5ac38f4b4862fad6e7270fde5c3356a822ce74ca (git); 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before f11deb032fd84081e7831cffcba895d893054a22 (git); 6.18",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-pcache: validate kset key_num and intra-segment bounds\n\nTwo more fields decoded from the cache device go unbounded. The kset\nkey_num drives cache_kset_crc() and the replay loop in cache_replay(),\nthe writeback worker and the GC worker, but only the magic and a\nfixed-seed CRC are checked first, so a non-last kset whose key_num exceeds\nthe PCACHE_KSET_KEYS_MAX buffer reads past its end before the CRC compare.\nA key's intra-segment offset and length in cache_key_decode() are taken\nverbatim, so a key running past its segment is replayed into the cache\ntree and the data CRC check and every later read hit then copy adjacent\npersistent memory into the caller's bio -- an out-of-bounds read that\nleaks to user space. Both fields are controlled by whoever supplies the\ncache device (CAP_SYS_ADMIN); the CRC seed is public.\n\nAdd kset_onmedia_valid() to bound key_num before any kset read, and\nreject a key whose offset plus length, computed in 64 bits, exceeds the\nsegment data_size. Valid metadata is unaffected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/5ac38f4b4862fad6e7270fde5c3356a822ce74ca",
                "https://git.kernel.org/stable/c/d8caf96040a06096276ab72f5e1e8547c014c564",
                "https://git.kernel.org/stable/c/f11deb032fd84081e7831cffcba895d893054a22"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:01.980",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80961"
                }
            ]
        },
        {
            "id": "CVE-2026-80959",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-pcache: bound the persisted tail-position offset\n\ncache_pos_decode() takes the persisted key_tail and dirty_tail seg_off from\nthe cache device and addresses within the segment with it. A seg_off at or\npast the segment data_size, controllable by whoever supplies the device\n(CAP_SYS_ADMIN), reads past the segment data.\n\nReject a decoded seg_off that is not below the segment data_size.",
            "updated_at": "2026-09-13T07:17:02.943",
            "published_at": "2026-09-11T20:19:01.750",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before ffd9a214a94f9928e54856f42b1cc3e33fb10e36 (git); 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before 8bf7a06ca3c1611809725f58cfd573f2ffbda75f (git); 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before d1898576090a10d2ac2715218a652e78fb65a6b0 (git); 6.18",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-pcache: bound the persisted tail-position offset\n\ncache_pos_decode() takes the persisted key_tail and dirty_tail seg_off from\nthe cache device and addresses within the segment with it. A seg_off at or\npast the segment data_size, controllable by whoever supplies the device\n(CAP_SYS_ADMIN), reads past the segment data.\n\nReject a decoded seg_off that is not below the segment data_size.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/8bf7a06ca3c1611809725f58cfd573f2ffbda75f",
                "https://git.kernel.org/stable/c/d1898576090a10d2ac2715218a652e78fb65a6b0",
                "https://git.kernel.org/stable/c/ffd9a214a94f9928e54856f42b1cc3e33fb10e36"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:01.750",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80959"
                }
            ]
        },
        {
            "id": "CVE-2026-80958",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-pcache: clamp the tail kset read to the segment data region\n\nThe tail-kset read in cache_replay(), the writeback worker and the GC\nworker bounds its length by PCACHE_SEG_SIZE - seg_off, the raw segment\nsize rather than the data region. A tail near the segment end reads past\nthe segment data into the following control area.\n\nClamp the read to cache_seg_remain(), the data region.",
            "updated_at": "2026-09-13T07:17:02.823",
            "published_at": "2026-09-11T20:19:01.637",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before 2cd9776fe3f2d88ec22c36d3c8ba09fbf9d5500c (git); 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before 1ab55354368d071ebaee4d8c82313955eab65a04 (git); 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before becf07e2b0053027495ecd671b1f82fb2e615f68 (git); 6.18",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-pcache: clamp the tail kset read to the segment data region\n\nThe tail-kset read in cache_replay(), the writeback worker and the GC\nworker bounds its length by PCACHE_SEG_SIZE - seg_off, the raw segment\nsize rather than the data region. A tail near the segment end reads past\nthe segment data into the following control area.\n\nClamp the read to cache_seg_remain(), the data region.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1ab55354368d071ebaee4d8c82313955eab65a04",
                "https://git.kernel.org/stable/c/2cd9776fe3f2d88ec22c36d3c8ba09fbf9d5500c",
                "https://git.kernel.org/stable/c/becf07e2b0053027495ecd671b1f82fb2e615f68"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:01.637",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80958"
                }
            ]
        },
        {
            "id": "CVE-2026-80955",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-pcache: fix use-after-free and invalid seg operations in kset_replay()\n\nIn kset_replay, when key->seg_gen is stale (key->seg_gen <\nkey->cache_pos.cache_seg->gen), cache_key_put(key) is called but then\nkey->cache_pos.cache_seg is accessed as the argument to cache_seg_get().\nThis is a use-after-free on the freed key memory. Although mempool\nrecycled memory is not immediately reclaimed or overwritten in practice,\nthis is still a potential UAF bug.\n\nAdditionally, for expired invalid keys, setting the cache->seg_map bit\nand calling cache_seg_get() is unreasonable since the corresponding\nsegment data is no longer valid.\n\nFix both issues by moving cache_seg_get() and __set_bit() after the\ngen check, so they only execute for valid keys, and using continue to\nskip invalid keys.",
            "updated_at": "2026-09-13T07:17:02.700",
            "published_at": "2026-09-11T20:19:01.287",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before 1894fc7a3bab90143dcd26ef8ee27040ef4a7501 (git); 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before f39a3e9cc5946473e16d6f5071b2ee0216c56d06 (git); 1d57628ff95b32d5cfa8d8f50e07690c161e9cf0 through before c2e894eac398b258f12fdec73ed6ba081047f7b3 (git); 6.18",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-pcache: fix use-after-free and invalid seg operations in kset_replay()\n\nIn kset_replay, when key->seg_gen is stale (key->seg_gen <\nkey->cache_pos.cache_seg->gen), cache_key_put(key) is called but then\nkey->cache_pos.cache_seg is accessed as the argument to cache_seg_get().\nThis is a use-after-free on the freed key memory. Although mempool\nrecycled memory is not immediately reclaimed or overwritten in practice,\nthis is still a potential UAF bug.\n\nAdditionally, for expired invalid keys, setting the cache->seg_map bit\nand calling cache_seg_get() is unreasonable since the corresponding\nsegment data is no longer valid.\n\nFix both issues by moving cache_seg_get() and __set_bit() after the\ngen check, so they only execute for valid keys, and using continue to\nskip invalid keys.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1894fc7a3bab90143dcd26ef8ee27040ef4a7501",
                "https://git.kernel.org/stable/c/c2e894eac398b258f12fdec73ed6ba081047f7b3",
                "https://git.kernel.org/stable/c/f39a3e9cc5946473e16d6f5071b2ee0216c56d06"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:01.287",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80955"
                }
            ]
        },
        {
            "id": "CVE-2026-80954",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode()\n\ni3c_device_get_supported_xfer_mode() uses dev->desc to obtain the\nmaster controller.  However, dev->desc must not be dereferenced unless\nbus->lock is held, and this function does not take that lock.\n\nThe function only needs access to the master controller associated with\nthe device's bus.  Use dev->bus instead, which is always valid for the\nlifetime of the device and does not require dereferencing dev->desc.",
            "updated_at": "2026-09-13T07:17:02.590",
            "published_at": "2026-09-11T20:19:01.167",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "256a21743d911f94ce92fe28f793cd586f3860b2 through before 251db58324ea4792c3f9f692ab09be148e051969 (git); 256a21743d911f94ce92fe28f793cd586f3860b2 through before 8bed7f4fa710914b7f05fd59998316bfb4d43385 (git); 6.19",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode()\n\ni3c_device_get_supported_xfer_mode() uses dev->desc to obtain the\nmaster controller.  However, dev->desc must not be dereferenced unless\nbus->lock is held, and this function does not take that lock.\n\nThe function only needs access to the master controller associated with\nthe device's bus.  Use dev->bus instead, which is always valid for the\nlifetime of the device and does not require dereferencing dev->desc.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/251db58324ea4792c3f9f692ab09be148e051969",
                "https://git.kernel.org/stable/c/8bed7f4fa710914b7f05fd59998316bfb4d43385"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:01.167",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80954"
                }
            ]
        },
        {
            "id": "CVE-2026-80953",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: master: adi: initialize the lock before enabling interrupts\n\nadi_i3c_master_probe() requests the IRQ and unmasks REG_IRQ_PENDING_CMDR\nbefore the controller's IBI state, transfer queue list and transfer\nqueue lock are initialized.  A pending CMDR interrupt can therefore run\nadi_i3c_master_irq() and take master->xferqueue.lock before the dynamic\nlock has been initialized.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the probe ordering and the IRQ path\nadi_i3c_master_probe() -> adi_i3c_master_irq() -> xferqueue.lock, with a\npending CMDR interrupt arriving after REG_IRQ_PENDING_CMDR is unmasked.\nLockdep reported:\n\n  INFO: trying to register non-static key.\n  you didn't initialize this object before use?\n  lock_acquire+0xbb/0x290\n  _raw_spin_lock_irqsave+0x36/0x60\n  adi_i3c_master_irq+0x32/0x56 [vuln_msv]\n  adi_i3c_master_probe+0x5a/0xf47 [vuln_msv]\n\nInitialize the transfer queue and IBI state before requesting and\nunmasking the IRQ.",
            "updated_at": "2026-09-13T07:17:02.463",
            "published_at": "2026-09-11T20:19:01.040",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "a79ac2cdc91d6be3010f2e9a3b2a2ccfc26e2086 through before a15a1b95de980362c14f32f519b293b0d12ce86f (git); a79ac2cdc91d6be3010f2e9a3b2a2ccfc26e2086 through before de8c32b0a246bbb4b44ec29e12769496a0bf66f7 (git); a79ac2cdc91d6be3010f2e9a3b2a2ccfc26e2086 through before 8a53f9102a0d3eeb8784999f925028acf339c276 (git); 6.18",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: master: adi: initialize the lock before enabling interrupts\n\nadi_i3c_master_probe() requests the IRQ and unmasks REG_IRQ_PENDING_CMDR\nbefore the controller's IBI state, transfer queue list and transfer\nqueue lock are initialized.  A pending CMDR interrupt can therefore run\nadi_i3c_master_irq() and take master->xferqueue.lock before the dynamic\nlock has been initialized.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the probe ordering and the IRQ path\nadi_i3c_master_probe() -> adi_i3c_master_irq() -> xferqueue.lock, with a\npending CMDR interrupt arriving after REG_IRQ_PENDING_CMDR is unmasked.\nLockdep reported:\n\n  INFO: trying to register non-static key.\n  you didn't initialize this object before use?\n  lock_acquire+0xbb/0x290\n  _raw_spin_lock_irqsave+0x36/0x60\n  adi_i3c_master_irq+0x32/0x56 [vuln_msv]\n  adi_i3c_master_probe+0x5a/0xf47 [vuln_msv]\n\nInitialize the transfer queue and IBI state before requesting and\nunmasking the IRQ.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/8a53f9102a0d3eeb8784999f925028acf339c276",
                "https://git.kernel.org/stable/c/a15a1b95de980362c14f32f519b293b0d12ce86f",
                "https://git.kernel.org/stable/c/de8c32b0a246bbb4b44ec29e12769496a0bf66f7"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:01.040",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80953"
                }
            ]
        },
        {
            "id": "CVE-2026-80952",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: master: Fix info leak and UAF in device unregister path\n\ni3c_master_unregister_i3c_devs() clears i3cdev->dev->desc before\ncalling device_unregister().  During device_unregister(),\ndevice_del() emits a KOBJ_REMOVE uevent and unbinds the driver while\nthe device descriptor is still expected to be valid.  As a result,\ni3c_device_uevent() and a racing modalias_show() can observe a NULL\ndesc and fall back to an uninitialized stack struct i3c_device_info,\nleaking kernel stack contents in the generated modalias.  Driver\n.remove() callbacks may also encounter an unexpected NULL desc during\nunbind.\n\nKeep desc valid until device_unregister() has completed.  Since\ndevice_unregister() drops the device reference and may free the device,\ntake an extra reference with get_device() before unregistering.  Clear\ndesc afterwards and release the extra reference with put_device().\nThis preserves the release-time invariant that desc must be NULL while\navoiding both the information leak and a potential use-after-free from\nwriting desc after the device has been released.",
            "updated_at": "2026-09-13T07:17:02.330",
            "published_at": "2026-09-11T20:19:00.927",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 through before c16b6f25e0cc2dd1055dde1256cbf5a9e888cf49 (git); 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 through before 94fb9786d67a8f8b899e77381620f86bad94fdf7 (git); 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 through before 4837be0f9ac2efe5e83b35a696b6242c473d280c (git); 3a379bbcea0af6280e1ca0d1edfcf4e68cde6ee0 through before d2c743efd2d1ee64e94324664808f623dd865872 (git); 5.0",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: master: Fix info leak and UAF in device unregister path\n\ni3c_master_unregister_i3c_devs() clears i3cdev->dev->desc before\ncalling device_unregister().  During device_unregister(),\ndevice_del() emits a KOBJ_REMOVE uevent and unbinds the driver while\nthe device descriptor is still expected to be valid.  As a result,\ni3c_device_uevent() and a racing modalias_show() can observe a NULL\ndesc and fall back to an uninitialized stack struct i3c_device_info,\nleaking kernel stack contents in the generated modalias.  Driver\n.remove() callbacks may also encounter an unexpected NULL desc during\nunbind.\n\nKeep desc valid until device_unregister() has completed.  Since\ndevice_unregister() drops the device reference and may free the device,\ntake an extra reference with get_device() before unregistering.  Clear\ndesc afterwards and release the extra reference with put_device().\nThis preserves the release-time invariant that desc must be NULL while\navoiding both the information leak and a potential use-after-free from\nwriting desc after the device has been released.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/4837be0f9ac2efe5e83b35a696b6242c473d280c",
                "https://git.kernel.org/stable/c/94fb9786d67a8f8b899e77381620f86bad94fdf7",
                "https://git.kernel.org/stable/c/c16b6f25e0cc2dd1055dde1256cbf5a9e888cf49",
                "https://git.kernel.org/stable/c/d2c743efd2d1ee64e94324664808f623dd865872"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:00.927",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80952"
                }
            ]
        },
        {
            "id": "CVE-2026-80950",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: renesas: Check that the transfer is valid before accessing it\n\nThe Renesas I3C driver uses an asynchronous model to transfer data. It\nprepares a struct renesas_i3c_xfer, enqueues it, and waits for completion.\nThe interrupt handler dequeues the transfer, updates/uses it, and signals\nthe waiting thread.\n\nIf the completion times out, the waiting thread dequeues the transfer and\nfree it. If an interrupt fires after that, the handler may access freed\nmemory, leading to crashes.\n\nCheck that the transfer is still valid before accessing it in the\ninterrupt handler. With it clear any status flags and disable all\nthe interrupts to avoid triggering the same interrupts again.",
            "updated_at": "2026-09-13T07:17:02.210",
            "published_at": "2026-09-11T20:19:00.683",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "d028219a9f1485914492bf373406f6a0e665ace2 through before 0093f9fc102ba8b98561fdd2f8559553ef56be59 (git); d028219a9f1485914492bf373406f6a0e665ace2 through before ec631aff93261c6d031f953549802322032f2aba (git); d028219a9f1485914492bf373406f6a0e665ace2 through before 5f1a76ecfe90544a28d657306c9b3caa66ba0e63 (git); 6.17",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: renesas: Check that the transfer is valid before accessing it\n\nThe Renesas I3C driver uses an asynchronous model to transfer data. It\nprepares a struct renesas_i3c_xfer, enqueues it, and waits for completion.\nThe interrupt handler dequeues the transfer, updates/uses it, and signals\nthe waiting thread.\n\nIf the completion times out, the waiting thread dequeues the transfer and\nfree it. If an interrupt fires after that, the handler may access freed\nmemory, leading to crashes.\n\nCheck that the transfer is still valid before accessing it in the\ninterrupt handler. With it clear any status flags and disable all\nthe interrupts to avoid triggering the same interrupts again.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0093f9fc102ba8b98561fdd2f8559553ef56be59",
                "https://git.kernel.org/stable/c/5f1a76ecfe90544a28d657306c9b3caa66ba0e63",
                "https://git.kernel.org/stable/c/ec631aff93261c6d031f953549802322032f2aba"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:00.683",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80950"
                }
            ]
        },
        {
            "id": "CVE-2026-80948",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()\n\nIn iwl_op_mode_dvm_start(), jumping to out_free_eeprom currently bypasses\nthe out_free_eeprom_blob label. Consequently, error paths triggered after\nsuccessfully parsing the EEPROM free priv->nvm_data but leak\npriv->eeprom_blob.\n\nFix this memory leak by reordering the error handling labels so\nthat out_free_eeprom falls through to out_free_eeprom_blob.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1-rc6.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have\nsupported Intel DVM wireless hardware and firmware to test with, no\nruntime testing was able to be performed.",
            "updated_at": "2026-09-13T07:17:02.110",
            "published_at": "2026-09-11T20:19:00.443",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "26a7ca9a71a3f7e1826de96b1a1e907123e11b07 through before 84ba017a1e1ea7896ed1e3258c947bdbfc5299c5 (git); 26a7ca9a71a3f7e1826de96b1a1e907123e11b07 through before ad2a9fdca4a7100472be82ee6048c616fc589720 (git); 26a7ca9a71a3f7e1826de96b1a1e907123e11b07 through before 67105abd6195a685a84dcb8a5daf54a1f4bfdb60 (git); 3.6",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: dvm: fix memory leak in iwl_op_mode_dvm_start()\n\nIn iwl_op_mode_dvm_start(), jumping to out_free_eeprom currently bypasses\nthe out_free_eeprom_blob label. Consequently, error paths triggered after\nsuccessfully parsing the EEPROM free priv->nvm_data but leak\npriv->eeprom_blob.\n\nFix this memory leak by reordering the error handling labels so\nthat out_free_eeprom falls through to out_free_eeprom_blob.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1-rc6.\n\nAn x86_64 allyesconfig build showed no new warnings. As we do not have\nsupported Intel DVM wireless hardware and firmware to test with, no\nruntime testing was able to be performed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/67105abd6195a685a84dcb8a5daf54a1f4bfdb60",
                "https://git.kernel.org/stable/c/84ba017a1e1ea7896ed1e3258c947bdbfc5299c5",
                "https://git.kernel.org/stable/c/ad2a9fdca4a7100472be82ee6048c616fc589720"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:00.443",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80948"
                }
            ]
        },
        {
            "id": "CVE-2026-80947",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop\n\nrtl8xxxu arms rx_urb_wq from the RX completion path:\nrtl8xxxu_rx_complete() hands the URB to rtl8xxxu_queue_rx_urb(), which\nqueues it on rx_urb_pending_list and, once the list grows past\nRTL8XXXU_RX_URB_PENDING_WATER, schedules rx_urb_wq.  The worker\nrtl8xxxu_rx_urb_work() drains rx_urb_pending_list, recovers priv through\ncontainer_of, and resubmits each URB through rtl8xxxu_submit_rx_urb(),\nwhich anchors it on rx_anchor and dereferences priv->udev.\n\nrtl8xxxu_stop() cancels the sibling work items (c2hcmd_work, ra_watchdog,\nupdate_beacon_work) but never cancels rx_urb_wq, so a worker armed during\nthe last burst of RX traffic can run rtl8xxxu_rx_urb_work() after\nrtl8xxxu_disconnect() has called ieee80211_free_hw(), which frees priv,\nproducing a use-after-free.  The window opens under active RX traffic\n(pending count above the watermark) followed by a disconnect.\n\nThere are two teardown races to close:\n\n  * rtl8xxxu_queue_rx_urb() decided whether to enqueue under rx_urb_lock\n    but called schedule_work() after dropping the lock.  A completion\n    that observed shutdown == false and released the lock could then call\n    schedule_work() after rtl8xxxu_stop() had set shutdown and\n    cancel_work_sync() had already returned, arming the worker to run\n    after the teardown.  Move schedule_work() under the same !shutdown\n    branch so the arming decision is atomic with the shutdown check.\n\n  * rtl8xxxu_rx_urb_work() anchors every URB it drained back onto\n    rx_anchor through rtl8xxxu_submit_rx_urb().  A worker still running\n    when usb_kill_anchored_urbs(&priv->rx_anchor) returned would submit a\n    URB that escaped the kill.  In rtl8xxxu_stop(), call\n    cancel_work_sync(&priv->rx_urb_wq) before the kill so the worker is\n    drained first.\n\nAfter priv->shutdown is set under rx_urb_lock, completions can no longer\nqueue rx_urb_wq. cancel_work_sync() then drains the last queued or running\nworker, and the following usb_kill_anchored_urbs() kills the URBs it may\nhave submitted.\n\nrtl8xxxu_disconnect() is covered because ieee80211_unregister_hw()\nguarantees .stop() runs for a live interface before ieee80211_free_hw()\nfrees priv.  The probe error path needs no cancel: rx_urb_wq is\nINIT_WORK()'d there but cannot have been scheduled, since no URB is\nsubmitted before ieee80211_register_hw() succeeds.\n\nThis bug was found by static analysis.",
            "updated_at": "2026-09-13T07:17:01.960",
            "published_at": "2026-09-11T20:19:00.303",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "26f1fad29ad973b0fb26a9ca3dcb2a73dde781aa through before 800d2b490a9af1e7132a3564c2ad5a81292e5b40 (git); 26f1fad29ad973b0fb26a9ca3dcb2a73dde781aa through before 620acb1e8037b73a457dc8ef20fc23fc7adcb405 (git); 26f1fad29ad973b0fb26a9ca3dcb2a73dde781aa through before 972ab8b9c08f3eb3fa535082de2950dd93604dfd (git); 26f1fad29ad973b0fb26a9ca3dcb2a73dde781aa through before 6c080026ecc17eecb103f8927c64ea73a74bb818 (git); 4.4",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop\n\nrtl8xxxu arms rx_urb_wq from the RX completion path:\nrtl8xxxu_rx_complete() hands the URB to rtl8xxxu_queue_rx_urb(), which\nqueues it on rx_urb_pending_list and, once the list grows past\nRTL8XXXU_RX_URB_PENDING_WATER, schedules rx_urb_wq.  The worker\nrtl8xxxu_rx_urb_work() drains rx_urb_pending_list, recovers priv through\ncontainer_of, and resubmits each URB through rtl8xxxu_submit_rx_urb(),\nwhich anchors it on rx_anchor and dereferences priv->udev.\n\nrtl8xxxu_stop() cancels the sibling work items (c2hcmd_work, ra_watchdog,\nupdate_beacon_work) but never cancels rx_urb_wq, so a worker armed during\nthe last burst of RX traffic can run rtl8xxxu_rx_urb_work() after\nrtl8xxxu_disconnect() has called ieee80211_free_hw(), which frees priv,\nproducing a use-after-free.  The window opens under active RX traffic\n(pending count above the watermark) followed by a disconnect.\n\nThere are two teardown races to close:\n\n  * rtl8xxxu_queue_rx_urb() decided whether to enqueue under rx_urb_lock\n    but called schedule_work() after dropping the lock.  A completion\n    that observed shutdown == false and released the lock could then call\n    schedule_work() after rtl8xxxu_stop() had set shutdown and\n    cancel_work_sync() had already returned, arming the worker to run\n    after the teardown.  Move schedule_work() under the same !shutdown\n    branch so the arming decision is atomic with the shutdown check.\n\n  * rtl8xxxu_rx_urb_work() anchors every URB it drained back onto\n    rx_anchor through rtl8xxxu_submit_rx_urb().  A worker still running\n    when usb_kill_anchored_urbs(&priv->rx_anchor) returned would submit a\n    URB that escaped the kill.  In rtl8xxxu_stop(), call\n    cancel_work_sync(&priv->rx_urb_wq) before the kill so the worker is\n    drained first.\n\nAfter priv->shutdown is set under rx_urb_lock, completions can no longer\nqueue rx_urb_wq. cancel_work_sync() then drains the last queued or running\nworker, and the following usb_kill_anchored_urbs() kills the URBs it may\nhave submitted.\n\nrtl8xxxu_disconnect() is covered because ieee80211_unregister_hw()\nguarantees .stop() runs for a live interface before ieee80211_free_hw()\nfrees priv.  The probe error path needs no cancel: rx_urb_wq is\nINIT_WORK()'d there but cannot have been scheduled, since no URB is\nsubmitted before ieee80211_register_hw() succeeds.\n\nThis bug was found by static analysis.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/620acb1e8037b73a457dc8ef20fc23fc7adcb405",
                "https://git.kernel.org/stable/c/6c080026ecc17eecb103f8927c64ea73a74bb818",
                "https://git.kernel.org/stable/c/800d2b490a9af1e7132a3564c2ad5a81292e5b40",
                "https://git.kernel.org/stable/c/972ab8b9c08f3eb3fa535082de2950dd93604dfd"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:00.303",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80947"
                }
            ]
        },
        {
            "id": "CVE-2026-80945",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: iaa - unmap dst before software fallback on decompress\n\nOn a hardware analytics error, decompress retries through the software\nfallback, which writes req->dst with the CPU while it is still mapped\nDMA_FROM_DEVICE. With SWIOTLB active the later dma_unmap_sg() copies the\nstale bounce buffer over req->dst, corrupting the result.\n\nUnmap before the fallback runs. The async path unmaps inline; the sync\npath signals the retry with -EAGAIN so iaa_comp_adecompress() runs the\nfallback after unmapping.",
            "updated_at": "2026-09-13T07:17:01.827",
            "published_at": "2026-09-11T20:19:00.057",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2ec6761df889fdf896fde761abd447596dd8f8c2 through before fc933a4a419ba8a75da28666a018602c44846953 (git); 2ec6761df889fdf896fde761abd447596dd8f8c2 through before fcd86180ef78b0e41763faef7c6d2de7dfb50c1a (git); 2ec6761df889fdf896fde761abd447596dd8f8c2 through before 94a25930477113730372e0fa2985da4c5ac95c9a (git); 6.8",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: iaa - unmap dst before software fallback on decompress\n\nOn a hardware analytics error, decompress retries through the software\nfallback, which writes req->dst with the CPU while it is still mapped\nDMA_FROM_DEVICE. With SWIOTLB active the later dma_unmap_sg() copies the\nstale bounce buffer over req->dst, corrupting the result.\n\nUnmap before the fallback runs. The async path unmaps inline; the sync\npath signals the retry with -EAGAIN so iaa_comp_adecompress() runs the\nfallback after unmapping.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/94a25930477113730372e0fa2985da4c5ac95c9a",
                "https://git.kernel.org/stable/c/fc933a4a419ba8a75da28666a018602c44846953",
                "https://git.kernel.org/stable/c/fcd86180ef78b0e41763faef7c6d2de7dfb50c1a"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:19:00.057",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80945"
                }
            ]
        },
        {
            "id": "CVE-2026-80944",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: Detach sync cmd buffer on interrupted wait\n\nmwifiex synchronous commands keep the caller-provided data buffer in\ncmd_node->data_buf. Several callers pass stack-allocated objects there.\n\nIf wait_event_interruptible_timeout() is interrupted, the caller can\nreturn and release that stack object while the firmware command is still\nthe current command. A late firmware response then reaches the normal\nresponse handler, which can copy data through cmd_node->data_buf into the\nstale stack address.\n\nThis fixes a stack corruption observed during repeated association and\ndisassociation cycles. The panic trace showed the command wait being\ninterrupted immediately before a bad pointer dereference:\n\n  cmd_wait_q terminated: -512\n  Unable to handle kernel paging request at virtual address 002c583837384662\n  Kernel panic - not syncing: stack-protector: Kernel stack is corrupted\n  ...\n  Tainted: [M]=MACHINE_CHECK\n\nThe fault address decodes as little-endian ASCII:\n\n  0x002c583837384662 -> \"bF878X,\\0\"\n\nwhich is a fragment of the VERSION_EXT firmware string exposed as\ndebugfs \"verext\":\n\n  w8997o-V4, RF878X, FP92, 16.92.21.p153.7\n\nThe same runs also showed corrupted control data containing:\n\n  0x2400372e333531 -> \"153.7\\0$\"\n\nwhich is the tail of the same VERSION_EXT string. This points at a late\nVERSION_EXT response writing through a stale stack-backed data_buf after\nthe interrupted wait returned.\n\nAfter cancelling pending commands on an interrupted or timed-out wait,\ndetach the caller-owned data buffer from the still-current command. This\npreserves the existing command cancellation behaviour while preventing a\nlate response from writing through a pointer whose lifetime ended with the\nwaiting caller.\n\nTested on an i.MX8MP board using an 88W8997.",
            "updated_at": "2026-09-13T07:17:01.680",
            "published_at": "2026-09-11T20:18:59.923",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3d026d09b28dda24777129a931634949c75a9181 through before 20ee9c03f261bf6ac59331e2ca7b46b23646412a (git); 3d026d09b28dda24777129a931634949c75a9181 through before b1bbeb8970eeb6c6bf3cd5314138103f7b69446d (git); 3d026d09b28dda24777129a931634949c75a9181 through before d29a165588b6a0cf7a38db5cbd602aef7ef8c658 (git); 3d026d09b28dda24777129a931634949c75a9181 through before ef06882c7d8a7400b67d0d003b1008093dd589ed (git); 3.15",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: Detach sync cmd buffer on interrupted wait\n\nmwifiex synchronous commands keep the caller-provided data buffer in\ncmd_node->data_buf. Several callers pass stack-allocated objects there.\n\nIf wait_event_interruptible_timeout() is interrupted, the caller can\nreturn and release that stack object while the firmware command is still\nthe current command. A late firmware response then reaches the normal\nresponse handler, which can copy data through cmd_node->data_buf into the\nstale stack address.\n\nThis fixes a stack corruption observed during repeated association and\ndisassociation cycles. The panic trace showed the command wait being\ninterrupted immediately before a bad pointer dereference:\n\n  cmd_wait_q terminated: -512\n  Unable to handle kernel paging request at virtual address 002c583837384662\n  Kernel panic - not syncing: stack-protector: Kernel stack is corrupted\n  ...\n  Tainted: [M]=MACHINE_CHECK\n\nThe fault address decodes as little-endian ASCII:\n\n  0x002c583837384662 -> \"bF878X,\\0\"\n\nwhich is a fragment of the VERSION_EXT firmware string exposed as\ndebugfs \"verext\":\n\n  w8997o-V4, RF878X, FP92, 16.92.21.p153.7\n\nThe same runs also showed corrupted control data containing:\n\n  0x2400372e333531 -> \"153.7\\0$\"\n\nwhich is the tail of the same VERSION_EXT string. This points at a late\nVERSION_EXT response writing through a stale stack-backed data_buf after\nthe interrupted wait returned.\n\nAfter cancelling pending commands on an interrupted or timed-out wait,\ndetach the caller-owned data buffer from the still-current command. This\npreserves the existing command cancellation behaviour while preventing a\nlate response from writing through a pointer whose lifetime ended with the\nwaiting caller.\n\nTested on an i.MX8MP board using an 88W8997.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/20ee9c03f261bf6ac59331e2ca7b46b23646412a",
                "https://git.kernel.org/stable/c/b1bbeb8970eeb6c6bf3cd5314138103f7b69446d",
                "https://git.kernel.org/stable/c/d29a165588b6a0cf7a38db5cbd602aef7ef8c658",
                "https://git.kernel.org/stable/c/ef06882c7d8a7400b67d0d003b1008093dd589ed"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:18:59.923",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80944"
                }
            ]
        },
        {
            "id": "CVE-2026-80943",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtlwifi: rtl8192du: check QoS TID before indexing tids\n\nrtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID\nfrom the 802.11 header and then uses it as an index into\nsta_entry->tids[]. ieee80211_get_tid() returns the low 4-bit QoS TID\nvalue, so the result can be in the range 0..15.\n\nrtlwifi only allocates MAX_TID_COUNT entries for sta_entry->tids[], and\nMAX_TID_COUNT is 9. A QoS TID greater than 8 therefore indexes past the\naggregation state array. Keep the default RTL_AGG_STOP state for\nout-of-range TIDs, matching rtl92cu_tx_fill_desc().\n\nThis issue was detected by our static analysis tool and confirmed by\nmanual audit. UBSAN validation for the same bug pattern reports an\narray-index-out-of-bounds access with index 10 for type\n'rtl_tid_data [9]'.",
            "updated_at": "2026-09-13T07:17:01.543",
            "published_at": "2026-09-11T20:18:59.807",
            "cvss": 7.6,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8321424134a400a5e3eb39f9acca6bc6946ff447 through before 6e327f14e1c43e175bf530f9165b2cadff308553 (git); 8321424134a400a5e3eb39f9acca6bc6946ff447 through before 0c0b374e12d52af23ca741728db31091677cf9dc (git); 8321424134a400a5e3eb39f9acca6bc6946ff447 through before 42785f7e8d31540e6172bbcf08a7cc3cae1086f8 (git); 8321424134a400a5e3eb39f9acca6bc6946ff447 through before ed4f05d9f2f42fd866f55108db8123eefcc5fb33 (git); 6.11",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtlwifi: rtl8192du: check QoS TID before indexing tids\n\nrtl92du_tx_fill_desc() uses ieee80211_get_tid() to read the QoS TID\nfrom the 802.11 header and then uses it as an index into\nsta_entry->tids[]. ieee80211_get_tid() returns the low 4-bit QoS TID\nvalue, so the result can be in the range 0..15.\n\nrtlwifi only allocates MAX_TID_COUNT entries for sta_entry->tids[], and\nMAX_TID_COUNT is 9. A QoS TID greater than 8 therefore indexes past the\naggregation state array. Keep the default RTL_AGG_STOP state for\nout-of-range TIDs, matching rtl92cu_tx_fill_desc().\n\nThis issue was detected by our static analysis tool and confirmed by\nmanual audit. UBSAN validation for the same bug pattern reports an\narray-index-out-of-bounds access with index 10 for type\n'rtl_tid_data [9]'.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0c0b374e12d52af23ca741728db31091677cf9dc",
                "https://git.kernel.org/stable/c/42785f7e8d31540e6172bbcf08a7cc3cae1086f8",
                "https://git.kernel.org/stable/c/6e327f14e1c43e175bf530f9165b2cadff308553",
                "https://git.kernel.org/stable/c/ed4f05d9f2f42fd866f55108db8123eefcc5fb33"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:18:59.807",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80943"
                }
            ]
        },
        {
            "id": "CVE-2026-80937",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy\n\nmt7915_mcu_get_eeprom() copies a fixed EFUSE block into the driver's\ndev->mt76.eeprom.data buffer at the offset reported by the MCU response\n(res->addr, a device-controlled __le32) without checking it against the\nbuffer size. A malicious or malfunctioning device can report an arbitrary\naddress and drive a 16-byte out-of-bounds write past eeprom.data.\n\nReject a response whose address would place the copy outside eeprom.data\nbefore deriving the destination pointer. Devices that echo the requested\nin-bounds offset are unaffected.",
            "updated_at": "2026-09-13T07:17:01.423",
            "published_at": "2026-09-11T20:18:57.627",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "e57b7901469fc0b021930b83a8094baaf3d81b09 through before 5fdaf7016d7684ef756a229fd5d96b4a140eeb40 (git); e57b7901469fc0b021930b83a8094baaf3d81b09 through before 5f48b0d752a76590e2c613aae5345c2474627d1b (git); e57b7901469fc0b021930b83a8094baaf3d81b09 through before 44b5adfe49499f53002737f5fe81d608c08122fc (git); 5.8",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: bound the device EEPROM address before the EFUSE copy\n\nmt7915_mcu_get_eeprom() copies a fixed EFUSE block into the driver's\ndev->mt76.eeprom.data buffer at the offset reported by the MCU response\n(res->addr, a device-controlled __le32) without checking it against the\nbuffer size. A malicious or malfunctioning device can report an arbitrary\naddress and drive a 16-byte out-of-bounds write past eeprom.data.\n\nReject a response whose address would place the copy outside eeprom.data\nbefore deriving the destination pointer. Devices that echo the requested\nin-bounds offset are unaffected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/44b5adfe49499f53002737f5fe81d608c08122fc",
                "https://git.kernel.org/stable/c/5f48b0d752a76590e2c613aae5345c2474627d1b",
                "https://git.kernel.org/stable/c/5fdaf7016d7684ef756a229fd5d96b4a140eeb40"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:18:57.627",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80937"
                }
            ]
        },
        {
            "id": "CVE-2026-80936",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7925: cancel mlo_pm_work on stop\n\nmt7925 queues mlo_pm_work with a 5 second delay during multi-link\npower-save setup and never cancels it on the stop path. If the device is\ntorn down inside that window, the work outlives the teardown and its timer\nfires afterwards, trying to queue onto the workqueue that is already gone:\n\n  workqueue: cannot queue mt7925_mlo_pm_work [mt7925_common] on wq phy0\n  WARNING: kernel/workqueue.c:2283 at __queue_work+0x59/0xa0, CPU#1: swapper/1/0\n   call_timer_fn+0x2a/0x140\n   __run_timers+0x203/0x330\n   run_timer_softirq+0x86/0xf0\n\nmt7921 already has its own stop callback, so add one for mt7925 that\ncancels the work before calling mt792x_stop(). mt7925_ops backs both the\nPCIe and USB drivers, so this covers both.",
            "updated_at": "2026-09-13T07:17:01.293",
            "published_at": "2026-09-11T20:18:57.513",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "276a568832577c81ec90b62dc506bbdc3781ca46 through before 304470333b7f525b23699ea7a7aed3b40ca37ca9 (git); 276a568832577c81ec90b62dc506bbdc3781ca46 through before 9e20da749ad229a1aa649ece528721b9652f15e1 (git); 276a568832577c81ec90b62dc506bbdc3781ca46 through before 81faf578320df2dfc682a96baa6e85851dd68b6f (git); 74eb79258bfd5f2ffe6d26a09c898992b2afa1ce (git); 6.14.3 through before 6.15 (semver); 6.15",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7925: cancel mlo_pm_work on stop\n\nmt7925 queues mlo_pm_work with a 5 second delay during multi-link\npower-save setup and never cancels it on the stop path. If the device is\ntorn down inside that window, the work outlives the teardown and its timer\nfires afterwards, trying to queue onto the workqueue that is already gone:\n\n  workqueue: cannot queue mt7925_mlo_pm_work [mt7925_common] on wq phy0\n  WARNING: kernel/workqueue.c:2283 at __queue_work+0x59/0xa0, CPU#1: swapper/1/0\n   call_timer_fn+0x2a/0x140\n   __run_timers+0x203/0x330\n   run_timer_softirq+0x86/0xf0\n\nmt7921 already has its own stop callback, so add one for mt7925 that\ncancels the work before calling mt792x_stop(). mt7925_ops backs both the\nPCIe and USB drivers, so this covers both.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/304470333b7f525b23699ea7a7aed3b40ca37ca9",
                "https://git.kernel.org/stable/c/81faf578320df2dfc682a96baa6e85851dd68b6f",
                "https://git.kernel.org/stable/c/9e20da749ad229a1aa649ece528721b9652f15e1"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:18:57.513",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80936"
                }
            ]
        },
        {
            "id": "CVE-2026-80935",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy\n\nmt7996_mcu_get_eeprom() derives the destination of the EFUSE/EXT block\ncopy from the address reported by the MCU response (event->addr, a\ndevice-controlled __le32) and clamps only the copy length, never the\ndestination offset into dev->mt76.eeprom.data. A malicious or\nmalfunctioning device can report an arbitrary address and drive an\nout-of-bounds write of up to MT7996_EXT_EEPROM_BLOCK_SIZE bytes past\neeprom.data.\n\nReject a response whose address would place the copy outside eeprom.data\nbefore deriving the destination pointer. Devices that echo the requested\nin-bounds offset are unaffected.",
            "updated_at": "2026-09-13T07:17:01.180",
            "published_at": "2026-09-11T20:18:57.403",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "98686cd21624c75a043e96812beadddf4f6f48e5 through before 6be59da2063d5b3522bfde8aae0487ec095eb384 (git); 98686cd21624c75a043e96812beadddf4f6f48e5 through before 13b3c29a782033ce4a230be9e5618032813dbcd4 (git); 6.2",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: bound the device EEPROM address before the EFUSE copy\n\nmt7996_mcu_get_eeprom() derives the destination of the EFUSE/EXT block\ncopy from the address reported by the MCU response (event->addr, a\ndevice-controlled __le32) and clamps only the copy length, never the\ndestination offset into dev->mt76.eeprom.data. A malicious or\nmalfunctioning device can report an arbitrary address and drive an\nout-of-bounds write of up to MT7996_EXT_EEPROM_BLOCK_SIZE bytes past\neeprom.data.\n\nReject a response whose address would place the copy outside eeprom.data\nbefore deriving the destination pointer. Devices that echo the requested\nin-bounds offset are unaffected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/13b3c29a782033ce4a230be9e5618032813dbcd4",
                "https://git.kernel.org/stable/c/6be59da2063d5b3522bfde8aae0487ec095eb384"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:18:57.403",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80935"
                }
            ]
        },
        {
            "id": "CVE-2026-80933",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: validate default EEPROM firmware size\n\nThe default EEPROM firmware is parsed and copied as a full EEPROM\nwithout checking its length. A truncated file can make the driver\nread beyond the firmware buffer during variant validation or the\nfallback copy.\n\nReject files shorter than MT7996_EEPROM_SIZE before parsing or\ncopying the firmware.",
            "updated_at": "2026-09-13T07:17:01.053",
            "published_at": "2026-09-11T20:18:57.160",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "98686cd21624c75a043e96812beadddf4f6f48e5 through before 03b81f015dbb29807ce1ec6d45537d658abdac69 (git); 98686cd21624c75a043e96812beadddf4f6f48e5 through before 7074ec3769820302f1ccf8794a40a6582153b820 (git); 98686cd21624c75a043e96812beadddf4f6f48e5 through before 653c6e289b13cc6942f3e8f8e3c568e70fa42d1f (git); 6.2",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7996: validate default EEPROM firmware size\n\nThe default EEPROM firmware is parsed and copied as a full EEPROM\nwithout checking its length. A truncated file can make the driver\nread beyond the firmware buffer during variant validation or the\nfallback copy.\n\nReject files shorter than MT7996_EEPROM_SIZE before parsing or\ncopying the firmware.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/03b81f015dbb29807ce1ec6d45537d658abdac69",
                "https://git.kernel.org/stable/c/653c6e289b13cc6942f3e8f8e3c568e70fa42d1f",
                "https://git.kernel.org/stable/c/7074ec3769820302f1ccf8794a40a6582153b820"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:18:57.160",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80933"
                }
            ]
        },
        {
            "id": "CVE-2026-80932",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: flush works in dependency order\n\nvirtio_vsock_remove() stops the virtqueues and then flushes each work\nitem before freeing the enclosing virtio_vsock.  The current order does\nnot account for dependencies between those items: tx_work may queue\nsend_pkt_work, and send_pkt_work may queue rx_work.\n\nIn particular, send_pkt_work can set restart_rx and release tx_lock.\nThe remove path can then stop the queues and flush rx_work before\nsend_pkt_work queues it.  Although the later send_pkt_work flush waits\nfor that producer to finish, nothing waits for the newly queued rx_work,\nso kfree(vsock) can race with it.\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in\n  virtio_transport_rx_work+0x487/0x4b0\n  Read of size 8 at addr ffff888114c2b008 by task kworker/1:1/47\n  Workqueue: virtio_vsock virtio_transport_rx_work\n  Call Trace:\n   virtio_transport_rx_work+0x487/0x4b0\n   process_one_work+0x688/0x1120\n   worker_thread+0x45b/0xd10\n  Allocated by task 1:\n   virtio_vsock_probe+0xef/0x6b0\n  Freed by task 84:\n   kfree+0x131/0x3c0\n   virtio_vsock_remove+0xd1/0x100\n\nFlush the works in producer-to-consumer order.  virtio_vsock_vqs_del()\nhas already disabled the queue callbacks and cleared the run flags, so\nafter tx_work and send_pkt_work are drained, no source remains that can\nqueue rx_work after its flush.",
            "updated_at": "2026-09-13T07:17:00.920",
            "published_at": "2026-09-11T20:18:57.023",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 through before 2187a56f2fd1715d54daed6392809223c60544f3 (git); 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 through before 165a330a68b5f299d8735f0194c314cb2e571269 (git); 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 through before da5e9f08714c19ba04e6863aca69d40f042f2e04 (git); 0ea9e1d3a9e3ef7d2a1462d3de6b95131dc7d872 through before 728836ebca239810f164262b10211ef59182f811 (git); 4.8",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: flush works in dependency order\n\nvirtio_vsock_remove() stops the virtqueues and then flushes each work\nitem before freeing the enclosing virtio_vsock.  The current order does\nnot account for dependencies between those items: tx_work may queue\nsend_pkt_work, and send_pkt_work may queue rx_work.\n\nIn particular, send_pkt_work can set restart_rx and release tx_lock.\nThe remove path can then stop the queues and flush rx_work before\nsend_pkt_work queues it.  Although the later send_pkt_work flush waits\nfor that producer to finish, nothing waits for the newly queued rx_work,\nso kfree(vsock) can race with it.\n\nKASAN reported:\n\n  BUG: KASAN: slab-use-after-free in\n  virtio_transport_rx_work+0x487/0x4b0\n  Read of size 8 at addr ffff888114c2b008 by task kworker/1:1/47\n  Workqueue: virtio_vsock virtio_transport_rx_work\n  Call Trace:\n   virtio_transport_rx_work+0x487/0x4b0\n   process_one_work+0x688/0x1120\n   worker_thread+0x45b/0xd10\n  Allocated by task 1:\n   virtio_vsock_probe+0xef/0x6b0\n  Freed by task 84:\n   kfree+0x131/0x3c0\n   virtio_vsock_remove+0xd1/0x100\n\nFlush the works in producer-to-consumer order.  virtio_vsock_vqs_del()\nhas already disabled the queue callbacks and cleared the run flags, so\nafter tx_work and send_pkt_work are drained, no source remains that can\nqueue rx_work after its flush.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/165a330a68b5f299d8735f0194c314cb2e571269",
                "https://git.kernel.org/stable/c/2187a56f2fd1715d54daed6392809223c60544f3",
                "https://git.kernel.org/stable/c/728836ebca239810f164262b10211ef59182f811",
                "https://git.kernel.org/stable/c/da5e9f08714c19ba04e6863aca69d40f042f2e04"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:18:57.023",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80932"
                }
            ]
        },
        {
            "id": "CVE-2026-80931",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nw1: ds28e17: reject an oversize length on an I2C block read\n\nw1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire\nto I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the\ndevice. The downstream slave puts a length byte in buf[0]. The driver\nthen reads that many bytes into buf[1] with w1_f19_i2c_read().\n\nbuf[0] is controlled by the device and can be 0 to 255.\nw1_f19_i2c_read() only rejects a zero count. The caller buffer is\nI2C_SMBUS_BLOCK_MAX + 2, so 34 bytes. A length above 32 makes the read\nrun past it, up to about 222 bytes out of bounds.\n\nThe SMBus core does check buf[0] against I2C_SMBUS_BLOCK_MAX. That\ncheck runs after master_xfer returns. By then the write is already\ndone. i2c-algo-bit rejects an oversize length before it copies, and\nreturns -EPROTO.\n\nReject a length above I2C_SMBUS_BLOCK_MAX at both RECV_LEN sites, the\nsame way i2c-algo-bit does.",
            "updated_at": "2026-09-13T07:17:00.787",
            "published_at": "2026-09-11T20:18:56.893",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "ebc4768ac4971eab4b570e733e47ac9dfd0e4175 through before cb55c5da9828f77db2a2701316949d4de1e9b773 (git); ebc4768ac4971eab4b570e733e47ac9dfd0e4175 through before ae0c79a8527044e54d81fd5a3b49ce6177633758 (git); ebc4768ac4971eab4b570e733e47ac9dfd0e4175 through before 6df05f630c84a109736642362e452089886f9974 (git); ebc4768ac4971eab4b570e733e47ac9dfd0e4175 through before 169ae5e65e5aaf213b6a578f6478a9fd2e523606 (git); 4.15",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nw1: ds28e17: reject an oversize length on an I2C block read\n\nw1_f19_i2c_master_transfer() is the master_xfer for the DS28E17 1-Wire\nto I2C bridge. On an I2C_M_RECV_LEN read, it takes the length from the\ndevice. The downstream slave puts a length byte in buf[0]. The driver\nthen reads that many bytes into buf[1] with w1_f19_i2c_read().\n\nbuf[0] is controlled by the device and can be 0 to 255.\nw1_f19_i2c_read() only rejects a zero count. The caller buffer is\nI2C_SMBUS_BLOCK_MAX + 2, so 34 bytes. A length above 32 makes the read\nrun past it, up to about 222 bytes out of bounds.\n\nThe SMBus core does check buf[0] against I2C_SMBUS_BLOCK_MAX. That\ncheck runs after master_xfer returns. By then the write is already\ndone. i2c-algo-bit rejects an oversize length before it copies, and\nreturns -EPROTO.\n\nReject a length above I2C_SMBUS_BLOCK_MAX at both RECV_LEN sites, the\nsame way i2c-algo-bit does.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/169ae5e65e5aaf213b6a578f6478a9fd2e523606",
                "https://git.kernel.org/stable/c/6df05f630c84a109736642362e452089886f9974",
                "https://git.kernel.org/stable/c/ae0c79a8527044e54d81fd5a3b49ce6177633758",
                "https://git.kernel.org/stable/c/cb55c5da9828f77db2a2701316949d4de1e9b773"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:18:56.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80931"
                }
            ]
        },
        {
            "id": "CVE-2026-80929",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsysctl: move the \"cad_pid\" entry from pid_table[] to kern_reboot_table[]\n\ncad_pid is global, and kill_cad_pid() is only used in the root namespace.\n\nHowever, due to pid_table_root_permissions(), a non-root user can unshare\npid/user namespaces and modify it from the child namespace. This makes no\nsense and is simply wrong.\n\nMove it to kern_reboot_table[] where it logically belongs; this ensures\nthat only GLOBAL_ROOT_UID can read/modify this sysctl.\n\nNote that this patch doesn't preserve \"#ifdef CONFIG_PROC_SYSCTL\" around\nthe \"cad_pid\"; CONFIG_PROC_SYSCTL selects CONFIG_SYSCTL, so it is always\nset when kern_reboot_table[] is compiled.",
            "updated_at": "2026-09-13T07:17:00.663",
            "published_at": "2026-09-11T20:18:56.647",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "e054bcbe7e7af2baad3752f1a4916a7fffc0457e through before e8527de7fea191fda704792a56081f9009aeec37 (git); e054bcbe7e7af2baad3752f1a4916a7fffc0457e through before a09bc4eaa67e1a72df3b6d0beb3afeef1e1fdfcd (git); e054bcbe7e7af2baad3752f1a4916a7fffc0457e through before 7170ca01623b399c97f2ae9d3e228badc1f25ea3 (git); 6.17",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nsysctl: move the \"cad_pid\" entry from pid_table[] to kern_reboot_table[]\n\ncad_pid is global, and kill_cad_pid() is only used in the root namespace.\n\nHowever, due to pid_table_root_permissions(), a non-root user can unshare\npid/user namespaces and modify it from the child namespace. This makes no\nsense and is simply wrong.\n\nMove it to kern_reboot_table[] where it logically belongs; this ensures\nthat only GLOBAL_ROOT_UID can read/modify this sysctl.\n\nNote that this patch doesn't preserve \"#ifdef CONFIG_PROC_SYSCTL\" around\nthe \"cad_pid\"; CONFIG_PROC_SYSCTL selects CONFIG_SYSCTL, so it is always\nset when kern_reboot_table[] is compiled.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/7170ca01623b399c97f2ae9d3e228badc1f25ea3",
                "https://git.kernel.org/stable/c/a09bc4eaa67e1a72df3b6d0beb3afeef1e1fdfcd",
                "https://git.kernel.org/stable/c/e8527de7fea191fda704792a56081f9009aeec37"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:18:56.647",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80929"
                }
            ]
        },
        {
            "id": "CVE-2026-80928",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmack: fix cred UAF in smack_file_send_sigiotask()\n\nWhen inspecting the credentials of another task, objective credentials\n(->real_cred, accessed with __task_cred()) must always be used.\n\nAccessing ->cred on a non-current task is forbidden unless that task is\nbeing created or destroyed; a task is allowed to change its own ->cred\npointer with no synchronization, and changing ->cred should only affect the\ncurrent syscall.\n\nsmack_file_send_sigiotask() was accessing both sets of credentials: First\ntsk->cred, then __task_cred(tsk).\n\nFix it, always access the objective credentials here.\n\nI have tested that this bug can lead to a KASAN-reported UAF of struct cred\nin smack_file_send_sigiotask(), and that this fix prevents the race.",
            "updated_at": "2026-09-13T07:17:00.527",
            "published_at": "2026-09-11T20:18:56.513",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3b11a1decef07c19443d24ae926982bc8ec9f4c0 through before b5bcf3adfa27279da4401ab8f1e1a706601a92be (git); 3b11a1decef07c19443d24ae926982bc8ec9f4c0 through before ed64aa505875a3b4defd504ee8e59e1949246a62 (git); 3b11a1decef07c19443d24ae926982bc8ec9f4c0 through before b791401bf389a1546a830d2b381ca60fe94c7870 (git); 3b11a1decef07c19443d24ae926982bc8ec9f4c0 through before fedc88e38ce979a720cd2de042578cb5df3dc8de (git); 2.6.29",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmack: fix cred UAF in smack_file_send_sigiotask()\n\nWhen inspecting the credentials of another task, objective credentials\n(->real_cred, accessed with __task_cred()) must always be used.\n\nAccessing ->cred on a non-current task is forbidden unless that task is\nbeing created or destroyed; a task is allowed to change its own ->cred\npointer with no synchronization, and changing ->cred should only affect the\ncurrent syscall.\n\nsmack_file_send_sigiotask() was accessing both sets of credentials: First\ntsk->cred, then __task_cred(tsk).\n\nFix it, always access the objective credentials here.\n\nI have tested that this bug can lead to a KASAN-reported UAF of struct cred\nin smack_file_send_sigiotask(), and that this fix prevents the race.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/b5bcf3adfa27279da4401ab8f1e1a706601a92be",
                "https://git.kernel.org/stable/c/b791401bf389a1546a830d2b381ca60fe94c7870",
                "https://git.kernel.org/stable/c/ed64aa505875a3b4defd504ee8e59e1949246a62",
                "https://git.kernel.org/stable/c/fedc88e38ce979a720cd2de042578cb5df3dc8de"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:18:56.513",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80928"
                }
            ]
        },
        {
            "id": "CVE-2026-80926",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in oplock break notification\n\nsmb2_oplock_break_noti() reads opinfo->conn without any lock and\ndereferences it after two allocations which may sleep.  When the\ndurable handle owning the oplock is disconnected, session_fd_check()\nclears opinfo->conn and drops its conn reference under ci->m_lock, and\nthe last ksmbd_conn_put() frees the connection.  A break triggered by\nanother connection that races with the teardown can then resurrect the\nfreed connection: ksmbd_conn_get() is a plain atomic_inc, and the\nqueued break work later dereferences the stale conn via\nksmbd_conn_write(), a use-after-free reachable by any authenticated\nclient holding a durable batch oplock.\n\nThread the caller's inode into the notification path instead of taking\na new reference on it.  Every caller of oplock_break() already holds a\nlive ksmbd_file (or an explicit ksmbd_inode_lookup_lock() reference,\nin the parent lease break paths) on the inode that owns the break\ntarget's oplock list, so ci cannot be freed during the call, and its\nlock can be taken without dereferencing opinfo->o_fp, which a\nconcurrent close may free.  Select and pin the connection under\nci->m_lock, the same lock session_fd_check() and\nksmbd_reopen_durable_fd() use to update opinfo->conn, so a concurrent\ndetach either loses the race to the clear or keeps the connection\nalive until the notification work releases it.  Transfer the reference\nto the work item and release it on allocation failures.",
            "updated_at": "2026-09-13T07:16:59.460",
            "published_at": "2026-09-11T20:18:56.257",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "e735dbd489e3ea02be78dba991056fe1138be51e through before c8279ae8df68cce9cd3b785e85f7a86c80a46e78 (git); b003086d76968298f22e7cf62239833b5a3a06b1 through before 8cc98db4fc590e6c7d9db6529320982ee16c5d1d (git); b003086d76968298f22e7cf62239833b5a3a06b1 through before 0e753899627b5e28a9fea8bca98262a6f65a2452 (git); 945a86b21b40fb17183f5b27461baa6f03e2467f (git); 1ff58dcfcab434ebb51649da33774fbb8e1f7b67 (git); 75e33deda658c1ab3a9336cbdb1436536f9b3660 (git); 6.18.36 through before 6.18.51 (semver); 6.6.143 through before 6.7 (semver); 6.12.94 through before 6.13 (semver); 7.0.13 through before 7.1 (semver); 7.1",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in oplock break notification\n\nsmb2_oplock_break_noti() reads opinfo->conn without any lock and\ndereferences it after two allocations which may sleep.  When the\ndurable handle owning the oplock is disconnected, session_fd_check()\nclears opinfo->conn and drops its conn reference under ci->m_lock, and\nthe last ksmbd_conn_put() frees the connection.  A break triggered by\nanother connection that races with the teardown can then resurrect the\nfreed connection: ksmbd_conn_get() is a plain atomic_inc, and the\nqueued break work later dereferences the stale conn via\nksmbd_conn_write(), a use-after-free reachable by any authenticated\nclient holding a durable batch oplock.\n\nThread the caller's inode into the notification path instead of taking\na new reference on it.  Every caller of oplock_break() already holds a\nlive ksmbd_file (or an explicit ksmbd_inode_lookup_lock() reference,\nin the parent lease break paths) on the inode that owns the break\ntarget's oplock list, so ci cannot be freed during the call, and its\nlock can be taken without dereferencing opinfo->o_fp, which a\nconcurrent close may free.  Select and pin the connection under\nci->m_lock, the same lock session_fd_check() and\nksmbd_reopen_durable_fd() use to update opinfo->conn, so a concurrent\ndetach either loses the race to the clear or keeps the connection\nalive until the notification work releases it.  Transfer the reference\nto the work item and release it on allocation failures.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0e753899627b5e28a9fea8bca98262a6f65a2452",
                "https://git.kernel.org/stable/c/8cc98db4fc590e6c7d9db6529320982ee16c5d1d",
                "https://git.kernel.org/stable/c/c8279ae8df68cce9cd3b785e85f7a86c80a46e78"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:18:56.257",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80926"
                }
            ]
        },
        {
            "id": "CVE-2026-80909",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Reject UVD message with invalid number of h265 refs\n\nSame change as for h264, avoids overflow later when calculating\nmin dpb size.\n\n(cherry picked from commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5)",
            "updated_at": "2026-09-07T15:17:33.720",
            "published_at": "2026-09-04T18:18:00.640",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 through before 1facad2a78c1a8aeecc36eb4d560c7f1e10ce198 (git); 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 through before 499907e5d46e575e96967c0230a0a6af980a17ab (git); 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 through before cbf1c84bf5cac2b3742ea3d2085fa713424465cc (git); 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 through before a930c54cb67200de8bc0de87480d09ece7dcd85d (git); 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 through before 2abcdc5f738574e7fcdd9417575dffb877fdc26f (git); 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 through before e304c3e0d9ce251887be1f274aa0ed52219d5fd7 (git); 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 through before 0acdf1a575f59bd46717d5c487d84575af5bee8f (git); 86fa0bdc6fd7b2debc07ce86f1bcd5fb254822e3 through before 9fca434208f1f9ab977feac62df8ebb1cc7ce893 (git); 4.2",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Reject UVD message with invalid number of h265 refs\n\nSame change as for h264, avoids overflow later when calculating\nmin dpb size.\n\n(cherry picked from commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0acdf1a575f59bd46717d5c487d84575af5bee8f",
                "https://git.kernel.org/stable/c/1facad2a78c1a8aeecc36eb4d560c7f1e10ce198",
                "https://git.kernel.org/stable/c/2abcdc5f738574e7fcdd9417575dffb877fdc26f",
                "https://git.kernel.org/stable/c/499907e5d46e575e96967c0230a0a6af980a17ab",
                "https://git.kernel.org/stable/c/9fca434208f1f9ab977feac62df8ebb1cc7ce893",
                "https://git.kernel.org/stable/c/a930c54cb67200de8bc0de87480d09ece7dcd85d",
                "https://git.kernel.org/stable/c/cbf1c84bf5cac2b3742ea3d2085fa713424465cc",
                "https://git.kernel.org/stable/c/e304c3e0d9ce251887be1f274aa0ed52219d5fd7"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T18:18:00.640",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80909"
                }
            ]
        },
        {
            "id": "CVE-2026-80908",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Reject UVD message with dimensions above 4096\n\nFixes potential overflow in DPB size calculations.\n\n(cherry picked from commit 05e1387d151f71569fbe122d2c89f9db0c21dc10)",
            "updated_at": "2026-09-07T15:17:33.603",
            "published_at": "2026-09-04T18:18:00.507",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21 through before 8bae80eaed00e7ae28412a3cdf590f4beca72294 (git); d38ceaf99ed015f2a0b9af3499791bd3a3daae21 through before 9adc5e25f31d7ee7dfc18814499b6e3a6d402904 (git); d38ceaf99ed015f2a0b9af3499791bd3a3daae21 through before 382bef781ff441ce8055bdada57b8c291dc0fd30 (git); d38ceaf99ed015f2a0b9af3499791bd3a3daae21 through before 8435d41afcf2bc31ecee213ef651c12bd1a16d38 (git); d38ceaf99ed015f2a0b9af3499791bd3a3daae21 through before f7af372d3b892b95dd3cd1c6acf29daa39ba076d (git); d38ceaf99ed015f2a0b9af3499791bd3a3daae21 through before 339deb76ee4859ea973e435c9a9a4a4fefc29338 (git); d38ceaf99ed015f2a0b9af3499791bd3a3daae21 through before 17fbb996c05f2190e0fa20927ca0b9804d481b02 (git); d38ceaf99ed015f2a0b9af3499791bd3a3daae21 through before 8c9aebcdd9f46f7a14b98d6ab18574b7a48fbb08 (git); 4.2",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Reject UVD message with dimensions above 4096\n\nFixes potential overflow in DPB size calculations.\n\n(cherry picked from commit 05e1387d151f71569fbe122d2c89f9db0c21dc10)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/17fbb996c05f2190e0fa20927ca0b9804d481b02",
                "https://git.kernel.org/stable/c/339deb76ee4859ea973e435c9a9a4a4fefc29338",
                "https://git.kernel.org/stable/c/382bef781ff441ce8055bdada57b8c291dc0fd30",
                "https://git.kernel.org/stable/c/8435d41afcf2bc31ecee213ef651c12bd1a16d38",
                "https://git.kernel.org/stable/c/8bae80eaed00e7ae28412a3cdf590f4beca72294",
                "https://git.kernel.org/stable/c/8c9aebcdd9f46f7a14b98d6ab18574b7a48fbb08",
                "https://git.kernel.org/stable/c/9adc5e25f31d7ee7dfc18814499b6e3a6d402904",
                "https://git.kernel.org/stable/c/f7af372d3b892b95dd3cd1c6acf29daa39ba076d"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T18:18:00.507",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80908"
                }
            ]
        },
        {
            "id": "CVE-2026-80907",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix UVD dpb min size calculation for H264\n\nThis should use actual number of references from the decode\nmessage, instead of maximum derived from level.\n\n(cherry picked from commit 64b525edb7e7bdfcdc77883c5e413804e2396856)",
            "updated_at": "2026-09-07T15:17:33.510",
            "published_at": "2026-09-04T18:18:00.393",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "d38ceaf99ed015f2a0b9af3499791bd3a3daae21 through before fa96c24485942e277483cc70d9551d9e0111d7c5 (git); d38ceaf99ed015f2a0b9af3499791bd3a3daae21 through before 33f4ef585368fe93523dca1e5440e006f6e5146e (git); d38ceaf99ed015f2a0b9af3499791bd3a3daae21 through before 38914cb2c6afb5fe00241ea3438e655822196378 (git); d38ceaf99ed015f2a0b9af3499791bd3a3daae21 through before ff4361816b6ba4bd29b548b17d993056a1ae2502 (git); d38ceaf99ed015f2a0b9af3499791bd3a3daae21 through before 21a8084cd76223a13493237e04d45f5226d7cee6 (git); 4.2",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix UVD dpb min size calculation for H264\n\nThis should use actual number of references from the decode\nmessage, instead of maximum derived from level.\n\n(cherry picked from commit 64b525edb7e7bdfcdc77883c5e413804e2396856)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/21a8084cd76223a13493237e04d45f5226d7cee6",
                "https://git.kernel.org/stable/c/33f4ef585368fe93523dca1e5440e006f6e5146e",
                "https://git.kernel.org/stable/c/38914cb2c6afb5fe00241ea3438e655822196378",
                "https://git.kernel.org/stable/c/fa96c24485942e277483cc70d9551d9e0111d7c5",
                "https://git.kernel.org/stable/c/ff4361816b6ba4bd29b548b17d993056a1ae2502"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T18:18:00.393",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80907"
                }
            ]
        },
        {
            "id": "CVE-2026-80899",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: remove fscache backend entirely\n\nEROFS over fscache was introduced to provide image lazy pulling\nfunctionality. After the feature landed, the fscache subsystem made\nnetfs a new hard dependency, which is unexpected for a local filesystem\nand has an kernel-defined caching hierarchy which could be inflexible\ncompared to the fanotify pre-content hooks. Therefore, this feature has\nbeen deprecated for almost two years.\n\nAs EROFS file-backed mounts and fanotify pre-content hooks both upstream\nfor a while and already providing equivalent functionality (erofs-utils\nhas supported fanotify pre-content hooks), let's remove the fscache\nbackend now.\n\nThe main application of this feature is Nydus [1], and they plan to move\nto use fanotify pre-content hooks in the near future too.\n\nI hope this patch can be merged into Linux 7.2, which is also motivated\nby newly found implementation issues [2][3] that are not worth\ninvestigating given the deprecation and limited development resources.\nThe associated fscache/cachefiles cleanup patch will follow separately\nthrough the vfs tree (netfs) later: it seems fine since the codebase is\nisolated by CONFIG_CACHEFILES_ONDEMAND.\n\n[1] https://github.com/dragonflyoss/nydus/blob/v2.1.0/docs/nydus-fscache.md\n[2] https://github.com/dragonflyoss/nydus/pull/1824\n[3] https://lore.kernel.org/r/20260619135800.1594811-1-michael.bommarito@gmail.com",
            "updated_at": "2026-09-07T15:17:33.410",
            "published_at": "2026-09-04T18:17:58.170",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "a1bafc3109d713ed83f73d61ba5cb1e6fd80fdbc through before f6145794f17a27d25f8a84edb80731fb0e07c196 (git); a1bafc3109d713ed83f73d61ba5cb1e6fd80fdbc through before c37460cd9b2fcb61ec66b7eb4fde737e65ec2a56 (git); 6.9",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: remove fscache backend entirely\n\nEROFS over fscache was introduced to provide image lazy pulling\nfunctionality. After the feature landed, the fscache subsystem made\nnetfs a new hard dependency, which is unexpected for a local filesystem\nand has an kernel-defined caching hierarchy which could be inflexible\ncompared to the fanotify pre-content hooks. Therefore, this feature has\nbeen deprecated for almost two years.\n\nAs EROFS file-backed mounts and fanotify pre-content hooks both upstream\nfor a while and already providing equivalent functionality (erofs-utils\nhas supported fanotify pre-content hooks), let's remove the fscache\nbackend now.\n\nThe main application of this feature is Nydus [1], and they plan to move\nto use fanotify pre-content hooks in the near future too.\n\nI hope this patch can be merged into Linux 7.2, which is also motivated\nby newly found implementation issues [2][3] that are not worth\ninvestigating given the deprecation and limited development resources.\nThe associated fscache/cachefiles cleanup patch will follow separately\nthrough the vfs tree (netfs) later: it seems fine since the codebase is\nisolated by CONFIG_CACHEFILES_ONDEMAND.\n\n[1] https://github.com/dragonflyoss/nydus/blob/v2.1.0/docs/nydus-fscache.md\n[2] https://github.com/dragonflyoss/nydus/pull/1824\n[3] https://lore.kernel.org/r/20260619135800.1594811-1-michael.bommarito@gmail.com",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/c37460cd9b2fcb61ec66b7eb4fde737e65ec2a56",
                "https://git.kernel.org/stable/c/f6145794f17a27d25f8a84edb80731fb0e07c196"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T18:17:58.170",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80899"
                }
            ]
        },
        {
            "id": "CVE-2026-80883",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered\n\nThe host1x_client_register() function is called just prior to register map\ninitialization loop, making the device available to userspace. This may\nresult in userspace attempting to submits a job before the register map is\ninitialized. Address this by moving register initialization before host1x\nclient registration.",
            "updated_at": "2026-09-07T15:17:33.310",
            "published_at": "2026-09-04T17:17:00.983",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "d43f81cbaf43531a977e8b4c4427f19acf8a5061 through before 6e22d5ad61cfa38aa53fab86a530113aff6a3619 (git); d43f81cbaf43531a977e8b4c4427f19acf8a5061 through before 5db37fd7710e74bc4df48bddab8f571d0bfc6769 (git); d43f81cbaf43531a977e8b4c4427f19acf8a5061 through before 40a2a91da02c434938f0ba53877984820800b5f0 (git); d43f81cbaf43531a977e8b4c4427f19acf8a5061 through before 3055292b8eed69553b389a609197a241df47e68e (git); d43f81cbaf43531a977e8b4c4427f19acf8a5061 through before c4ef5ba1131346159e31f4ef858525cf377380a6 (git); 3.10",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered\n\nThe host1x_client_register() function is called just prior to register map\ninitialization loop, making the device available to userspace. This may\nresult in userspace attempting to submits a job before the register map is\ninitialized. Address this by moving register initialization before host1x\nclient registration.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/3055292b8eed69553b389a609197a241df47e68e",
                "https://git.kernel.org/stable/c/40a2a91da02c434938f0ba53877984820800b5f0",
                "https://git.kernel.org/stable/c/5db37fd7710e74bc4df48bddab8f571d0bfc6769",
                "https://git.kernel.org/stable/c/6e22d5ad61cfa38aa53fab86a530113aff6a3619",
                "https://git.kernel.org/stable/c/c4ef5ba1131346159e31f4ef858525cf377380a6"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T17:17:00.983",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80883"
                }
            ]
        },
        {
            "id": "CVE-2026-80857",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free\n\nThe abort_on_kill path in request_wait_answer() calls fuse_abort_conn()\nand returns without waiting for FR_FINISHED.  If fuse_dev_do_write() is\nconcurrently processing the same request (FR_LOCKED set), the caller\nfrees req->args while it is still being accessed, causing a\nuse-after-free.\n\nFix this by jumping to the existing wait_event(FR_FINISHED) instead of\nreturning early.  The wait will not hang because fuse_abort_conn()\nensures all requests are ended.",
            "updated_at": "2026-09-07T16:17:30.437",
            "published_at": "2026-09-04T16:18:14.810",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0c7fca880a40a209a9c92be14143996d14b93ff6 through before a8bbb2a60513bf322170903c21462f0bf4f62be2 (git); 204aa22a686bfee48daca7db620c1e017615f2ff through before 715cb86e33cda43f5224cdc3fd5610c0b6a46f7a (git); 204aa22a686bfee48daca7db620c1e017615f2ff through before 64b0b5cacbd2fea88001464cb712c9dfc795b26e (git); 300e812b882a174dca675d8028684001ad5826bc (git); 6.18.25 through before 6.18.50 (semver); 7.0.2 through before 7.1 (semver); 7.1",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free\n\nThe abort_on_kill path in request_wait_answer() calls fuse_abort_conn()\nand returns without waiting for FR_FINISHED.  If fuse_dev_do_write() is\nconcurrently processing the same request (FR_LOCKED set), the caller\nfrees req->args while it is still being accessed, causing a\nuse-after-free.\n\nFix this by jumping to the existing wait_event(FR_FINISHED) instead of\nreturning early.  The wait will not hang because fuse_abort_conn()\nensures all requests are ended.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/64b0b5cacbd2fea88001464cb712c9dfc795b26e",
                "https://git.kernel.org/stable/c/715cb86e33cda43f5224cdc3fd5610c0b6a46f7a",
                "https://git.kernel.org/stable/c/a8bbb2a60513bf322170903c21462f0bf4f62be2"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:18:14.810",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80857"
                }
            ]
        },
        {
            "id": "CVE-2026-80834",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: sun8i-ce - Remove crypto_rng interface\n\nSince the crypto_rng interface for hardware PRNGs is unused and is\nredundant with hwrng and the actual Linux RNG, it's being phased out.\nMost drivers for it were already removed.  Go ahead and remove the\nsun8i-ce support which is one of the only remaining ones.\n\nNote that the sun8i-ce support for hwrng remains in place.  That is the\ninterface that actually matters.\n\nAs usual for crypto_rng, this driver was also buggy: its ->generate()\nfunction had a use-after-free vulnerability due to using\nwait_for_completion_interruptible_timeout() without handling shutting\ndown the DMA operation if a signal is sent.  There's no point in fixing\nthis separately only to remove the code anyway, so this commit is marked\nwith Fixes and Cc stable.",
            "updated_at": "2026-09-07T16:17:30.333",
            "published_at": "2026-09-04T16:18:11.683",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5eb7e946888493959b1c393144934afcbcd0cfc1 through before 7bb9e6060710eb7b59491d9826169190297adace (git); 5eb7e946888493959b1c393144934afcbcd0cfc1 through before 8e4f9110aba3127024646ef7a8999dcfcc03f516 (git); 5eb7e946888493959b1c393144934afcbcd0cfc1 through before 1017f987c5f0841f00408a78f947990c9d84b346 (git); 5eb7e946888493959b1c393144934afcbcd0cfc1 through before 011556f71d094da61379ae3672692cae2795304e (git); 5.10",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: sun8i-ce - Remove crypto_rng interface\n\nSince the crypto_rng interface for hardware PRNGs is unused and is\nredundant with hwrng and the actual Linux RNG, it's being phased out.\nMost drivers for it were already removed.  Go ahead and remove the\nsun8i-ce support which is one of the only remaining ones.\n\nNote that the sun8i-ce support for hwrng remains in place.  That is the\ninterface that actually matters.\n\nAs usual for crypto_rng, this driver was also buggy: its ->generate()\nfunction had a use-after-free vulnerability due to using\nwait_for_completion_interruptible_timeout() without handling shutting\ndown the DMA operation if a signal is sent.  There's no point in fixing\nthis separately only to remove the code anyway, so this commit is marked\nwith Fixes and Cc stable.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/011556f71d094da61379ae3672692cae2795304e",
                "https://git.kernel.org/stable/c/1017f987c5f0841f00408a78f947990c9d84b346",
                "https://git.kernel.org/stable/c/7bb9e6060710eb7b59491d9826169190297adace",
                "https://git.kernel.org/stable/c/8e4f9110aba3127024646ef7a8999dcfcc03f516"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:18:11.683",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80834"
                }
            ]
        },
        {
            "id": "CVE-2026-80833",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: sun8i-ss - Remove crypto_rng interface\n\nSince the crypto_rng interface for hardware PRNGs is unused and is\nredundant with hwrng and the actual Linux RNG, it's being phased out.\nMost drivers for it were already removed.  Go ahead and remove the\nsun8i-ss support which is one of the only remaining ones.\n\nAs usual for crypto_rng, this driver was also buggy: its ->generate()\nfunction had a use-after-free vulnerability due to using\nwait_for_completion_interruptible_timeout() without handling shutting\ndown the DMA operation if a signal is sent.  Also, it had a buffer\noverread bug in the line 'memcpy(ctx->seed, d + dlen, ctx->slen);'.\nThere's no point in fixing these bugs separately only to remove the code\nanyway, so this commit is marked with Fixes and Cc stable.",
            "updated_at": "2026-09-07T16:17:30.227",
            "published_at": "2026-09-04T16:18:11.577",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "ac2614d721dea2ff273af19c6c5d508d58a2bb3e through before d29ccf9eeb67d775221e49a079caa1af83427afa (git); ac2614d721dea2ff273af19c6c5d508d58a2bb3e through before 7c257a295e05ceb8f78aa3efecc4e9ce19c3313f (git); ac2614d721dea2ff273af19c6c5d508d58a2bb3e through before 8ab58786b4c63b8f1b6c522f33bb67a3c8c2791f (git); ac2614d721dea2ff273af19c6c5d508d58a2bb3e through before a78446ee6fae86ac8733f120e3ffce2e5d9384f5 (git); 5.10",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: sun8i-ss - Remove crypto_rng interface\n\nSince the crypto_rng interface for hardware PRNGs is unused and is\nredundant with hwrng and the actual Linux RNG, it's being phased out.\nMost drivers for it were already removed.  Go ahead and remove the\nsun8i-ss support which is one of the only remaining ones.\n\nAs usual for crypto_rng, this driver was also buggy: its ->generate()\nfunction had a use-after-free vulnerability due to using\nwait_for_completion_interruptible_timeout() without handling shutting\ndown the DMA operation if a signal is sent.  Also, it had a buffer\noverread bug in the line 'memcpy(ctx->seed, d + dlen, ctx->slen);'.\nThere's no point in fixing these bugs separately only to remove the code\nanyway, so this commit is marked with Fixes and Cc stable.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/7c257a295e05ceb8f78aa3efecc4e9ce19c3313f",
                "https://git.kernel.org/stable/c/8ab58786b4c63b8f1b6c522f33bb67a3c8c2791f",
                "https://git.kernel.org/stable/c/a78446ee6fae86ac8733f120e3ffce2e5d9384f5",
                "https://git.kernel.org/stable/c/d29ccf9eeb67d775221e49a079caa1af83427afa"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:18:11.577",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80833"
                }
            ]
        },
        {
            "id": "CVE-2026-80830",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: core: Add lock to usb_wakeup_notification()\n\nAdd a spin lock to usb_wakeup notification to prevent a race condition\nwith dereferencing freed memory. This could be hit by the xHCI driver as\nit calls this function from an IRQ and could race with the\nhub_disconnect() function, which properly grabs this lock to protect the\nstate of the device.",
            "updated_at": "2026-09-07T15:17:33.187",
            "published_at": "2026-09-04T16:18:11.143",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4ee823b83bc9851743fab756c76b27d6a1e2472b through before a7a16167991c88016acef720927400404039d850 (git); 4ee823b83bc9851743fab756c76b27d6a1e2472b through before 975ef630393c07fcbebf94f4d97043161b77a6ce (git); 4ee823b83bc9851743fab756c76b27d6a1e2472b through before 71cfda2fdf78041a01e9d94143baa79feabbdbf6 (git); 4ee823b83bc9851743fab756c76b27d6a1e2472b through before 04ab260407972e631c86f2bc576cd8e64d65b325 (git); 4ee823b83bc9851743fab756c76b27d6a1e2472b through before bf2288583b4e072bdff17a233963619e4bc7a8b5 (git); 4ee823b83bc9851743fab756c76b27d6a1e2472b through before d80b946804674069db7ce6657319a71cf8eeaa5a (git); 4ee823b83bc9851743fab756c76b27d6a1e2472b through before 960ca456faf61824b178f47967340300b24183db (git); 4ee823b83bc9851743fab756c76b27d6a1e2472b through before 7c48aa0c1e79116b8af4b988d16ee29b427d6491 (git); 4ee823b83bc9851743fab756c76b27d6a1e2472b through before e263e18a9e7b1ff3e7301f0801c6ff87c31adfb6 (git); 3.4",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: core: Add lock to usb_wakeup_notification()\n\nAdd a spin lock to usb_wakeup notification to prevent a race condition\nwith dereferencing freed memory. This could be hit by the xHCI driver as\nit calls this function from an IRQ and could race with the\nhub_disconnect() function, which properly grabs this lock to protect the\nstate of the device.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/04ab260407972e631c86f2bc576cd8e64d65b325",
                "https://git.kernel.org/stable/c/71cfda2fdf78041a01e9d94143baa79feabbdbf6",
                "https://git.kernel.org/stable/c/7c48aa0c1e79116b8af4b988d16ee29b427d6491",
                "https://git.kernel.org/stable/c/960ca456faf61824b178f47967340300b24183db",
                "https://git.kernel.org/stable/c/975ef630393c07fcbebf94f4d97043161b77a6ce",
                "https://git.kernel.org/stable/c/a7a16167991c88016acef720927400404039d850",
                "https://git.kernel.org/stable/c/bf2288583b4e072bdff17a233963619e4bc7a8b5",
                "https://git.kernel.org/stable/c/d80b946804674069db7ce6657319a71cf8eeaa5a",
                "https://git.kernel.org/stable/c/e263e18a9e7b1ff3e7301f0801c6ff87c31adfb6"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:18:11.143",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80830"
                }
            ]
        },
        {
            "id": "CVE-2026-80822",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()\n\nAdd a check to see if devm_kasprintf() is not NULL in\nmchp_ipc_get_cluster_aggr_irq(), returning -ENOMEM if the function\nfailed.",
            "updated_at": "2026-09-07T15:17:33.090",
            "published_at": "2026-09-04T16:18:09.970",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "e4b1d67e71419c4af581890ecea84b04920d4116 through before 364edaedf4125825781a12c84c77699780d52a16 (git); e4b1d67e71419c4af581890ecea84b04920d4116 through before df5c9816986b2f4d754ef3aa65a92382e9b39c4a (git); e4b1d67e71419c4af581890ecea84b04920d4116 through before b233e7836d98d1790e71f5f3734a86409664f341 (git); e4b1d67e71419c4af581890ecea84b04920d4116 through before b37c4d0a2fd90c0c31223acd37f763eb8953ed1a (git); 6.14",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: mchp-ipc-sbi: Add null check for devm_kasprintf()\n\nAdd a check to see if devm_kasprintf() is not NULL in\nmchp_ipc_get_cluster_aggr_irq(), returning -ENOMEM if the function\nfailed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/364edaedf4125825781a12c84c77699780d52a16",
                "https://git.kernel.org/stable/c/b233e7836d98d1790e71f5f3734a86409664f341",
                "https://git.kernel.org/stable/c/b37c4d0a2fd90c0c31223acd37f763eb8953ed1a",
                "https://git.kernel.org/stable/c/df5c9816986b2f4d754ef3aa65a92382e9b39c4a"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:18:09.970",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80822"
                }
            ]
        },
        {
            "id": "CVE-2026-80814",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nrndis_host: add overflow check in rndis_rx_fixup()\n\nAdd an overflow check to ensure that data_offset + data_len + 8 does not\nwrap, which would enable an OOB read of the USB data buffer.",
            "updated_at": "2026-09-07T15:17:32.967",
            "published_at": "2026-09-04T16:18:08.913",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "64e049102d3de3e61409cb6019403a9e689dfda6 through before 2140db1232af04b92faa6c4a2a40df6371ea89ff (git); 64e049102d3de3e61409cb6019403a9e689dfda6 through before 8ca3bd404d076495ed0b274b65971c57b6fd5ac0 (git); 64e049102d3de3e61409cb6019403a9e689dfda6 through before f8e6fde5db87f855e99b200e392467274f0eb9d7 (git); 64e049102d3de3e61409cb6019403a9e689dfda6 through before 10a6b99079697c5027b25352e882bdf54fef702a (git); 64e049102d3de3e61409cb6019403a9e689dfda6 through before c5398ce6db7647b7004d73a3102ccc25fb4bb596 (git); 64e049102d3de3e61409cb6019403a9e689dfda6 through before e971d956353d382ee2185d71c47b538501a43f76 (git); 64e049102d3de3e61409cb6019403a9e689dfda6 through before be7dc3650f799a253df4edd4fe230fc9ea4be063 (git); 64e049102d3de3e61409cb6019403a9e689dfda6 through before 2ded89ca77fae1da6886fe94831acfe4d6aa80b1 (git); 64e049102d3de3e61409cb6019403a9e689dfda6 through before 965a251f23ff69cfb4486974d4532e9bb551c7fc (git); 2.6.14",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nrndis_host: add overflow check in rndis_rx_fixup()\n\nAdd an overflow check to ensure that data_offset + data_len + 8 does not\nwrap, which would enable an OOB read of the USB data buffer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/10a6b99079697c5027b25352e882bdf54fef702a",
                "https://git.kernel.org/stable/c/2140db1232af04b92faa6c4a2a40df6371ea89ff",
                "https://git.kernel.org/stable/c/2ded89ca77fae1da6886fe94831acfe4d6aa80b1",
                "https://git.kernel.org/stable/c/8ca3bd404d076495ed0b274b65971c57b6fd5ac0",
                "https://git.kernel.org/stable/c/965a251f23ff69cfb4486974d4532e9bb551c7fc",
                "https://git.kernel.org/stable/c/be7dc3650f799a253df4edd4fe230fc9ea4be063",
                "https://git.kernel.org/stable/c/c5398ce6db7647b7004d73a3102ccc25fb4bb596",
                "https://git.kernel.org/stable/c/e971d956353d382ee2185d71c47b538501a43f76",
                "https://git.kernel.org/stable/c/f8e6fde5db87f855e99b200e392467274f0eb9d7"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:18:08.913",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80814"
                }
            ]
        },
        {
            "id": "CVE-2026-80812",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: dummy: Check card index validity at probe\n\nsnd_dummy_probe() blindly trusts that the given devptr->id value is\nwithin the proper card index range.  It's OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.",
            "updated_at": "2026-09-07T15:17:32.840",
            "published_at": "2026-09-04T16:18:08.633",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6e65c1cc4458b2784224759b6137a50d4f65e610 through before b7579e86afcec932e169d10e2d603abed8dd2fdf (git); 6e65c1cc4458b2784224759b6137a50d4f65e610 through before 4d0892a90b57f0e89b274c3f3c51c2fa17937c88 (git); 6e65c1cc4458b2784224759b6137a50d4f65e610 through before b20eb7ecbdaa3e649023fe41b177d90983ffb487 (git); 6e65c1cc4458b2784224759b6137a50d4f65e610 through before c9f10a001c243d1f069ebb0e2f4999ad4043a254 (git); 6e65c1cc4458b2784224759b6137a50d4f65e610 through before f20c2c32ec1c5c3526f29a03b487c55a5890996c (git); 6e65c1cc4458b2784224759b6137a50d4f65e610 through before 3dba0e92e18980cb5a4d70a9a263539ae4f0c7ec (git); 6e65c1cc4458b2784224759b6137a50d4f65e610 through before 690b721b9595f9a43395fd4047a832c42b5b6078 (git); 6e65c1cc4458b2784224759b6137a50d4f65e610 through before 02442d5fe8ee365a084b055d4fa81a0c1abfc3fd (git); 2.6.16",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: dummy: Check card index validity at probe\n\nsnd_dummy_probe() blindly trusts that the given devptr->id value is\nwithin the proper card index range.  It's OK for the devices the\ndriver itself creates at the module probe time, but if the device is\nbound manually via sysfs interface, this could be -1 as \"none\", and\nthis leads to OOB access for index[] and other parameters.\n\nAdd a sanity check for the card index and warn/correct it if it's a\nvalue out of the range.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/02442d5fe8ee365a084b055d4fa81a0c1abfc3fd",
                "https://git.kernel.org/stable/c/3dba0e92e18980cb5a4d70a9a263539ae4f0c7ec",
                "https://git.kernel.org/stable/c/4d0892a90b57f0e89b274c3f3c51c2fa17937c88",
                "https://git.kernel.org/stable/c/690b721b9595f9a43395fd4047a832c42b5b6078",
                "https://git.kernel.org/stable/c/b20eb7ecbdaa3e649023fe41b177d90983ffb487",
                "https://git.kernel.org/stable/c/b7579e86afcec932e169d10e2d603abed8dd2fdf",
                "https://git.kernel.org/stable/c/c9f10a001c243d1f069ebb0e2f4999ad4043a254",
                "https://git.kernel.org/stable/c/f20c2c32ec1c5c3526f29a03b487c55a5890996c"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:18:08.633",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80812"
                }
            ]
        },
        {
            "id": "CVE-2026-80788",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations\n\nWhen fuzzing the nvme target code, I tripped a kernel warning in\nnvmet_tcp_map_data() because the length passed into the allocator is\ncontrolled by the remote initiator.\n\nA remote initiator that sends a command with an SGL claiming a huge\nnumber, can create a scatterlist and iovec allocation of over 1 million\nentries, which causes the backing kmalloc call to exceed MAX_PAGE_ORDER\nand then the page allocator will trip on a WARN_ON_ONCE_GFP() message:\n\n  WARNING: mm/page_alloc.c:5280 __alloc_frozen_pages_noprof\n  Workqueue: nvmet_tcp_wq nvmet_tcp_io_work\n  ...\n  sgl_alloc_order\n  nvmet_tcp_map_data\n  nvmet_tcp_try_recv_pdu\n\nAs it's never good to trip a kernel warning remotely due to many systems\nhaving panic-on-warn enabled, let's silence it by just add GFP_NOWARN to\nthe allocation flags.",
            "updated_at": "2026-09-07T15:17:32.710",
            "published_at": "2026-09-04T16:18:04.857",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "872d26a391da92ed8f0c0f5cb5fef428067b7f30 through before 8d01f0d0e96485e39ad89b859ef85e1dc3020465 (git); 872d26a391da92ed8f0c0f5cb5fef428067b7f30 through before 7b6a54d4e7b0da423c2b53ed293fd36b16c0b19e (git); 872d26a391da92ed8f0c0f5cb5fef428067b7f30 through before e7077e6c45423dd2bb7de7b5fc4b018a8e6c4741 (git); 872d26a391da92ed8f0c0f5cb5fef428067b7f30 through before 86cc450022473c4a29b43a09f3ec22a9ef566dac (git); 872d26a391da92ed8f0c0f5cb5fef428067b7f30 through before c509f20be1cabda3087810bb2d658d66b3f31f35 (git); 872d26a391da92ed8f0c0f5cb5fef428067b7f30 through before 9c95f7e66c62ee6c6abedcf1c04311f430ff5833 (git); 872d26a391da92ed8f0c0f5cb5fef428067b7f30 through before 7fd6da0f28932442b51658bac4ff55565ca9b377 (git); 872d26a391da92ed8f0c0f5cb5fef428067b7f30 through before 9b770e40bc00381e5ebf53653de5776773415be3 (git); 872d26a391da92ed8f0c0f5cb5fef428067b7f30 through before 737a3b535247226f6e1a7988fd9d6e63e7d6fc71 (git); 5.0",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations\n\nWhen fuzzing the nvme target code, I tripped a kernel warning in\nnvmet_tcp_map_data() because the length passed into the allocator is\ncontrolled by the remote initiator.\n\nA remote initiator that sends a command with an SGL claiming a huge\nnumber, can create a scatterlist and iovec allocation of over 1 million\nentries, which causes the backing kmalloc call to exceed MAX_PAGE_ORDER\nand then the page allocator will trip on a WARN_ON_ONCE_GFP() message:\n\n  WARNING: mm/page_alloc.c:5280 __alloc_frozen_pages_noprof\n  Workqueue: nvmet_tcp_wq nvmet_tcp_io_work\n  ...\n  sgl_alloc_order\n  nvmet_tcp_map_data\n  nvmet_tcp_try_recv_pdu\n\nAs it's never good to trip a kernel warning remotely due to many systems\nhaving panic-on-warn enabled, let's silence it by just add GFP_NOWARN to\nthe allocation flags.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/737a3b535247226f6e1a7988fd9d6e63e7d6fc71",
                "https://git.kernel.org/stable/c/7b6a54d4e7b0da423c2b53ed293fd36b16c0b19e",
                "https://git.kernel.org/stable/c/7fd6da0f28932442b51658bac4ff55565ca9b377",
                "https://git.kernel.org/stable/c/86cc450022473c4a29b43a09f3ec22a9ef566dac",
                "https://git.kernel.org/stable/c/8d01f0d0e96485e39ad89b859ef85e1dc3020465",
                "https://git.kernel.org/stable/c/9b770e40bc00381e5ebf53653de5776773415be3",
                "https://git.kernel.org/stable/c/9c95f7e66c62ee6c6abedcf1c04311f430ff5833",
                "https://git.kernel.org/stable/c/c509f20be1cabda3087810bb2d658d66b3f31f35",
                "https://git.kernel.org/stable/c/e7077e6c45423dd2bb7de7b5fc4b018a8e6c4741"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:18:04.857",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80788"
                }
            ]
        },
        {
            "id": "CVE-2026-80786",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: Wrap user-invoked calls to fb_set_var() in helper\n\nHandle fbcon during display updates in fb_set_var_from_user(). Check\nwith fbcon if the mode change is possible, update hardware state and\nfinally update fbcon. Update all callers.\n\nOnly the FBIOPUT_VSCREENINFO ioctl currently does all steps. Other\nmode-changes callers in sysfs and driver code are missing fbcon-related\nsteps.\n\nWith the new helper, ps3fb and sh_mobile_lcdcfb no longer maintain\nfbcon state themselves.",
            "updated_at": "2026-09-07T15:17:32.617",
            "published_at": "2026-09-04T16:18:04.580",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 07f7e46833f71472e30da54a50dacdf48521bdd3 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 6f611e5e5f3327cf2e2daabe6ee5acac58cc784e (git); 2.6.12",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: Wrap user-invoked calls to fb_set_var() in helper\n\nHandle fbcon during display updates in fb_set_var_from_user(). Check\nwith fbcon if the mode change is possible, update hardware state and\nfinally update fbcon. Update all callers.\n\nOnly the FBIOPUT_VSCREENINFO ioctl currently does all steps. Other\nmode-changes callers in sysfs and driver code are missing fbcon-related\nsteps.\n\nWith the new helper, ps3fb and sh_mobile_lcdcfb no longer maintain\nfbcon state themselves.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/07f7e46833f71472e30da54a50dacdf48521bdd3",
                "https://git.kernel.org/stable/c/6f611e5e5f3327cf2e2daabe6ee5acac58cc784e"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:18:04.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80786"
                }
            ]
        },
        {
            "id": "CVE-2026-80785",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: serialize mode sysfs access with lock_fb_info()\n\nshow_mode(), show_modes(), and store_mode() access fb_info->modelist\nand fb_info->mode without holding lock_fb_info(). store_modes() takes\nlock_fb_info() while replacing the modelist and freeing the old one.\n\nA concurrent reader or writer can load a pointer to an old modelist\nentry before store_modes() frees it, then dereference freed memory or\nstore a stale freed pointer in fb_info->mode.\n\nTake lock_fb_info() in show_mode(), show_modes(), and store_mode() to\nserialize with store_modes(). In show_mode(), copy the mode to the\nstack and format after dropping the lock. In store_mode(), split\nactivate() into a _locked variant to avoid double-locking, and hold\nthe locks for the modelist walk, mode conversion, activation, and\nfb_info->mode assignment together.",
            "updated_at": "2026-09-07T15:17:32.513",
            "published_at": "2026-09-04T16:18:04.470",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 26135631ed8e487bc6aef70cc41934e258d09bbe (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 061db6b7a910b8378f3b2df64f8c0a3ddc6e85f2 (git); 2.6.12",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: serialize mode sysfs access with lock_fb_info()\n\nshow_mode(), show_modes(), and store_mode() access fb_info->modelist\nand fb_info->mode without holding lock_fb_info(). store_modes() takes\nlock_fb_info() while replacing the modelist and freeing the old one.\n\nA concurrent reader or writer can load a pointer to an old modelist\nentry before store_modes() frees it, then dereference freed memory or\nstore a stale freed pointer in fb_info->mode.\n\nTake lock_fb_info() in show_mode(), show_modes(), and store_mode() to\nserialize with store_modes(). In show_mode(), copy the mode to the\nstack and format after dropping the lock. In store_mode(), split\nactivate() into a _locked variant to avoid double-locking, and hold\nthe locks for the modelist walk, mode conversion, activation, and\nfb_info->mode assignment together.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/061db6b7a910b8378f3b2df64f8c0a3ddc6e85f2",
                "https://git.kernel.org/stable/c/26135631ed8e487bc6aef70cc41934e258d09bbe"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:18:04.470",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80785"
                }
            ]
        },
        {
            "id": "CVE-2026-80753",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\novpn: run deferred work on a module-owned workqueue\n\novpn queues several work items whose callbacks execute module text.\nThese works currently run on the global system workqueues, so module\nexit has no driver-owned drain point that guarantees the callbacks have\nfully returned before the module text can be freed.\n\nObject references protect the objects used by the callbacks, but they do\nnot prove that a workqueue function has returned. In particular, a\nworker can drop the final reference that unblocks device teardown while\nit is still executing ovpn code.\n\nAdd a module-owned workqueue and queue all ovpn work items on it. During\nmodule exit, unregister rtnl and netlink first, flush the workqueue so\nordinary ovpn workers finish, run the final RCU barrier, and destroy the\nworkqueue last. This keeps the workqueue available for cleanup work\nqueued from RCU callbacks, while ensuring no ovpn work item can outlive\nthe module text.\n\nThe per-device delayed keepalive work remains explicitly disabled during\nnetdev teardown (disable_delayed_work_sync in ndo_uninit), since\nflush_workqueue does not flush delayed work that is still only pending\non its timer.",
            "updated_at": "2026-09-07T16:17:30.097",
            "published_at": "2026-09-03T13:06:15.010",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11851cbd60ea1e5abbd97619d69845ead99303d6 through before b5fe67111e63a8a81ec31056c4475509076fd266 (git); 11851cbd60ea1e5abbd97619d69845ead99303d6 through before bbe81f40582d451ac849b20707784220f33a23bd (git); 11851cbd60ea1e5abbd97619d69845ead99303d6 through before e9714db8041763f59dde152c812b96b3de05c6d9 (git); 6.16",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\novpn: run deferred work on a module-owned workqueue\n\novpn queues several work items whose callbacks execute module text.\nThese works currently run on the global system workqueues, so module\nexit has no driver-owned drain point that guarantees the callbacks have\nfully returned before the module text can be freed.\n\nObject references protect the objects used by the callbacks, but they do\nnot prove that a workqueue function has returned. In particular, a\nworker can drop the final reference that unblocks device teardown while\nit is still executing ovpn code.\n\nAdd a module-owned workqueue and queue all ovpn work items on it. During\nmodule exit, unregister rtnl and netlink first, flush the workqueue so\nordinary ovpn workers finish, run the final RCU barrier, and destroy the\nworkqueue last. This keeps the workqueue available for cleanup work\nqueued from RCU callbacks, while ensuring no ovpn work item can outlive\nthe module text.\n\nThe per-device delayed keepalive work remains explicitly disabled during\nnetdev teardown (disable_delayed_work_sync in ndo_uninit), since\nflush_workqueue does not flush delayed work that is still only pending\non its timer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/b5fe67111e63a8a81ec31056c4475509076fd266",
                "https://git.kernel.org/stable/c/bbe81f40582d451ac849b20707784220f33a23bd",
                "https://git.kernel.org/stable/c/e9714db8041763f59dde152c812b96b3de05c6d9"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T13:06:15.010",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80753"
                }
            ]
        },
        {
            "id": "CVE-2026-80724",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nptp: vmclock: prevent read-only mappings from becoming writable\n\nvmclock_miscdev_mmap() rejects writable mappings of the shared vmclock\nABI page with -EROFS, but leaves VM_MAYWRITE set.  Userspace can map the\npage read-only and then upgrade it to writable with mprotect(), after\nwhich the guest can corrupt the host-written timekeeping data (sequence\ncounter, UTC time, TSC offset) that the vmclock ABI defines as read-only.\n\nClear VM_MAYWRITE on the read-only path so the mapping cannot be\nupgraded, as i915 does for its read-only objects and as fixed in drm/vc4\n(CVE-2026-68445) and drm/panthor (CVE-2024-53071).",
            "updated_at": "2026-09-07T16:17:29.930",
            "published_at": "2026-08-28T08:16:58.210",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "20503272422693d793b84f88bf23fe4e955d3a33 through before 5b4f2bec7bea6c04084d720d731bedee7caf878d (git); 20503272422693d793b84f88bf23fe4e955d3a33 through before 3f5677d2f817355147337f0453174c7bb0f3b66a (git); 20503272422693d793b84f88bf23fe4e955d3a33 through before 2496e141827102d6af512950057d402a2cfb2bfc (git); 20503272422693d793b84f88bf23fe4e955d3a33 through before 2e596e7814ba38cdc129991058b6c254ed37cb11 (git); 20503272422693d793b84f88bf23fe4e955d3a33 through before 0ce59c4148ecd1520c5592a63bb3c8991ee2d326 (git); 20503272422693d793b84f88bf23fe4e955d3a33 through before a5edadbae57e2298a56cf7a4e774a027905a331f (git); 6.13",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nptp: vmclock: prevent read-only mappings from becoming writable\n\nvmclock_miscdev_mmap() rejects writable mappings of the shared vmclock\nABI page with -EROFS, but leaves VM_MAYWRITE set.  Userspace can map the\npage read-only and then upgrade it to writable with mprotect(), after\nwhich the guest can corrupt the host-written timekeeping data (sequence\ncounter, UTC time, TSC offset) that the vmclock ABI defines as read-only.\n\nClear VM_MAYWRITE on the read-only path so the mapping cannot be\nupgraded, as i915 does for its read-only objects and as fixed in drm/vc4\n(CVE-2026-68445) and drm/panthor (CVE-2024-53071).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0ce59c4148ecd1520c5592a63bb3c8991ee2d326",
                "https://git.kernel.org/stable/c/2496e141827102d6af512950057d402a2cfb2bfc",
                "https://git.kernel.org/stable/c/2e596e7814ba38cdc129991058b6c254ed37cb11",
                "https://git.kernel.org/stable/c/3f5677d2f817355147337f0453174c7bb0f3b66a",
                "https://git.kernel.org/stable/c/5b4f2bec7bea6c04084d720d731bedee7caf878d",
                "https://git.kernel.org/stable/c/a5edadbae57e2298a56cf7a4e774a027905a331f"
            ],
            "timeline": [
                {
                    "at": "2026-08-28T08:16:58.210",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80724"
                }
            ]
        },
        {
            "id": "CVE-2026-80494",
            "vendor": "Unknown",
            "product": "Yogeta WP Cloud",
            "title": "Yogeta WP Cloud vulnerability",
            "summary": "The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.",
            "updated_at": "2026-09-12T16:16:39.867",
            "published_at": "2026-09-12T06:16:25.510",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-552",
            "what_happened": "The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authorization check, allowing unauthenticated attackers to download arbitrary files from the server, including files containing sensitive credentials.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/fdc0fefb-c090-4972-9867-d1090353e40c/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:25.510",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80494"
                }
            ]
        },
        {
            "id": "CVE-2026-80491",
            "vendor": "Unknown",
            "product": "SAMO Forms",
            "title": "SAMO Forms vulnerability",
            "summary": "The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.",
            "updated_at": "2026-09-12T16:16:39.737",
            "published_at": "2026-09-12T06:16:25.403",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.0.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/765e7131-2eb4-41df-a1e0-05c8a89cb88c/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:25.403",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80491"
                }
            ]
        },
        {
            "id": "CVE-2026-80439",
            "vendor": "Unknown",
            "product": "Redirection for Contact Form 7",
            "title": "Redirection for Contact Form 7 vulnerability",
            "summary": "The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode registered on the site and read its output.",
            "updated_at": "2026-09-06T11:18:02.163",
            "published_at": "2026-09-06T10:17:14.810",
            "cvss": 4.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.2.7 through before 3.2.11 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-74",
            "what_happened": "The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those values into an action's settings and then processes those settings for shortcodes, allowing unauthenticated users to run any shortcode registered on the site and read its output.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/96562897-f18c-45d3-9f31-0e40e8df1383/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T10:17:14.810",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80439"
                }
            ]
        },
        {
            "id": "CVE-2026-80437",
            "vendor": "Unknown",
            "product": "Ninja Forms",
            "title": "Ninja Forms vulnerability",
            "summary": "The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.",
            "updated_at": "2026-09-06T11:18:02.057",
            "published_at": "2026-09-06T10:17:14.693",
            "cvss": 4.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.14.10 through before 3.15.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-74",
            "what_happened": "The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/473a3321-7dc6-454a-82f4-89b6a393d09a/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T10:17:14.693",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80437"
                }
            ]
        },
        {
            "id": "CVE-2026-80428",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22_ 10.0 < 10.10_ 11.0 < 11.3 - RCE",
            "summary": "CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22_ 10.0 < 10.10_ 11.0 < 11.3 - RCE",
            "updated_at": "2026-09-10T22:00:00Z",
            "published_at": "2026-09-10T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 38,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52682",
                    "author": "DigiProSec",
                    "first_seen": "2026-09-11",
                    "confidence": "High",
                    "title": "CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22_ 10.0 < 10.10_ 11.0 < 11.3 - RCE",
                    "summary": "CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22_ 10.0 < 10.10_ 11.0 < 11.3 - RCE",
                    "url": "https://www.exploit-db.com/exploits/52682",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52682"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52682"
                }
            ]
        },
        {
            "id": "CVE-2026-80255",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host.",
            "updated_at": "2026-09-15T07:16:30.770",
            "published_at": "2026-09-06T18:17:22.623",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.13.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 8.21.0 through before 8.22.0 (semver); 1aea05a6c2699e80c75936d58569851555acd603 through before 4f6aa41a0145e930e766775dbe860883d350aa0a (git); 8.21.0; 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-201",
            "what_happened": "A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-09-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3972395"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-80255.html",
                "https://curl.se/docs/CVE-2026-80255.json",
                "https://hackerone.com/reports/3972395"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T18:17:22.623",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80255"
                }
            ]
        },
        {
            "id": "CVE-2026-80238",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This vulnerability is considered critical because a low-privileged operator with SSH access to the SCG host can gain root-level access to the host without requiring a password by leveraging the exposed Docker socket. Additionally, an attacker who compromises a service running within the orchestrator container can access the same socket and escape the container boundary to obtain host-level control. Dell recommends that customers upgrade at the earliest opportunity.",
            "updated_at": "2026-09-11T21:23:22.180",
            "published_at": "2026-09-07T13:20:39.293",
            "cvss": 9.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-250",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This vulnerability is considered critical because a low-privileged operator with SSH access to the SCG host can gain root-level access to the host without requiring a password by leveraging the exposed Docker socket. Additionally, an attacker who compromises a service running within the orchestrator container can access the same socket and escape the container boundary to obtain host-level control. Dell recommends that customers upgrade at the earliest opportunity.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T13:20:39.293",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80238"
                }
            ]
        },
        {
            "id": "CVE-2026-80231",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup\nfor a given hostname even when using a different Native CA Store setting\n(`CURLSSLOPT_NATIVE_CA`) than when the connection was created.",
            "updated_at": "2026-09-15T07:16:30.570",
            "published_at": "2026-09-06T18:17:22.500",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.71.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 8.21.0 through before 8.22.0 (semver); 148534db57dda611cf8516e92e4d6e35fc1e5074 through before 7be1e70cb6bcd83e130ecfe8cb91b6a7dcdeff42 (git); 8.21.0; 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-488",
            "what_happened": "A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup\nfor a given hostname even when using a different Native CA Store setting\n(`CURLSSLOPT_NATIVE_CA`) than when the connection was created.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-09-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3969368"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-80231.html",
                "https://curl.se/docs/CVE-2026-80231.json",
                "https://hackerone.com/reports/3969368"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T18:17:22.500",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80231"
                }
            ]
        },
        {
            "id": "CVE-2026-80230",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected.",
            "updated_at": "2026-09-15T07:16:30.337",
            "published_at": "2026-09-06T18:17:22.327",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.45.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 8.21.0 through before 8.22.0 (semver); 8363656cb4e0c60a11d8531ead0ec43120b50591 through before 5267ed859d545534d0c21675a2b70af5a3b6e3ef (git); 8.21.0; 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable\nstandard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and\n`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning on\nconnections established without a presented server certificate. Bypassing the\npinning check under these disabled-verification conditions allows\nunauthenticated connections to succeed when they should be rejected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-09-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3969300"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-80230.html",
                "https://curl.se/docs/CVE-2026-80230.json",
                "https://hackerone.com/reports/3969300"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T18:17:22.327",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80230"
                }
            ]
        },
        {
            "id": "CVE-2026-80229",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations.",
            "updated_at": "2026-09-15T07:16:30.157",
            "published_at": "2026-09-06T18:17:22.217",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.14.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 8.21.0 through before 8.22.0 (semver); f2ce6c46b9dcc46ced0ce43fa95176ea7599a854 through before 7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb (git); 8.21.0; 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-09-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3969255"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-80229.html",
                "https://curl.se/docs/CVE-2026-80229.json",
                "https://hackerone.com/reports/3969255"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T18:17:22.217",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80229"
                }
            ]
        },
        {
            "id": "CVE-2026-80178",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.",
            "updated_at": "2026-09-11T21:23:49.013",
            "published_at": "2026-09-07T13:20:39.170",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T13:20:39.170",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80178"
                }
            ]
        },
        {
            "id": "CVE-2026-80172",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthenticated attacker with remote access could exploit this, leading to unauthorized access. This vulnerability is considered critical as an unauthenticated attacker can repeatedly reuse a captured request to generate ADMIN access and refresh tokens. Since there is no nonce validation or time limit on requests, the attack can be performed indefinitely. Dell recommends customers to upgrade at the earliest opportunity",
            "updated_at": "2026-09-11T04:17:55.830",
            "published_at": "2026-09-09T12:17:15.057",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-345",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthenticated attacker with remote access could exploit this, leading to unauthorized access. This vulnerability is considered critical as an unauthenticated attacker can repeatedly reuse a captured request to generate ADMIN access and refresh tokens. Since there is no nonce validation or time limit on requests, the attack can be performed indefinitely. Dell recommends customers to upgrade at the earliest opportunity",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T12:17:15.057",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80172"
                }
            ]
        },
        {
            "id": "CVE-2026-80170",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.",
            "updated_at": "2026-09-11T21:23:12.640",
            "published_at": "2026-09-07T14:16:55.173",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-798",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:55.173",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80170"
                }
            ]
        },
        {
            "id": "CVE-2026-80166",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.",
            "updated_at": "2026-09-09T05:18:14.767",
            "published_at": "2026-09-07T17:17:25.570",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T17:17:25.570",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80166"
                }
            ]
        },
        {
            "id": "CVE-2026-80164",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "updated_at": "2026-09-07T14:16:55.060",
            "published_at": "2026-09-07T14:16:55.060",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:55.060",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80164"
                }
            ]
        },
        {
            "id": "CVE-2026-80135",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Check or Handling of Exceptional Conditions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.",
            "updated_at": "2026-09-11T21:24:27.980",
            "published_at": "2026-09-07T13:20:39.047",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-703",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Check or Handling of Exceptional Conditions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T13:20:39.047",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80135"
                }
            ]
        },
        {
            "id": "CVE-2026-80134",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "updated_at": "2026-09-11T21:25:15.237",
            "published_at": "2026-09-07T13:20:38.923",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-798",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T13:20:38.923",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80134"
                }
            ]
        },
        {
            "id": "CVE-2026-80133",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.",
            "updated_at": "2026-09-11T21:25:32.910",
            "published_at": "2026-09-07T13:20:38.800",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-23",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T13:20:38.800",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80133"
                }
            ]
        },
        {
            "id": "CVE-2026-80132",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "updated_at": "2026-09-11T21:25:41.970",
            "published_at": "2026-09-07T13:20:38.670",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-306",
            "what_happened": "ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T13:20:38.670",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80132"
                }
            ]
        },
        {
            "id": "CVE-2026-80131",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.",
            "updated_at": "2026-09-07T14:16:54.933",
            "published_at": "2026-09-07T14:16:54.933",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-22",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:54.933",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80131"
                }
            ]
        },
        {
            "id": "CVE-2026-80130",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to remote execution.",
            "updated_at": "2026-09-07T14:16:54.813",
            "published_at": "2026-09-07T14:16:54.813",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-23",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to remote execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:54.813",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80130"
                }
            ]
        },
        {
            "id": "CVE-2026-80129",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.",
            "updated_at": "2026-09-07T14:16:54.697",
            "published_at": "2026-09-07T14:16:54.697",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-22",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:54.697",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80129"
                }
            ]
        },
        {
            "id": "CVE-2026-80128",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.",
            "updated_at": "2026-09-07T14:16:54.580",
            "published_at": "2026-09-07T14:16:54.580",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before Secure Connect Gateway 5.0 - Appliance (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-287",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:54.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80128"
                }
            ]
        },
        {
            "id": "CVE-2026-80099",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-80099",
            "summary": "Proof-of-concept exploit for CVE-2026-80099. CVSS 8.8.",
            "updated_at": "2026-09-12T09:42:06Z",
            "published_at": "2026-09-12T09:42:06Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 35,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-80099",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=C7F9250E-AA39-59AC-BF9E-916E50F105AC",
                        "https://github.com/Wayang1337/CVE-2026-80099"
                    ],
                    "repository": "Sploitus",
                    "author": "Wayang1337",
                    "first_seen": "2026-09-12T09:42:45",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=C7F9250E-AA39-59AC-BF9E-916E50F105AC"
                },
                {
                    "title": "Exploit for CVE-2026-80099",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=C7F9250E-AA39-59AC-BF9E-916E50F105AC",
                        "https://github.com/Wayang1337/CVE-2026-80099"
                    ],
                    "repository": "Wayang1337/CVE-2026-80099",
                    "author": "Wayang1337",
                    "first_seen": "2026-09-12T09:42:45",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/Wayang1337/CVE-2026-80099"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=C7F9250E-AA39-59AC-BF9E-916E50F105AC",
                "https://github.com/Wayang1337/CVE-2026-80099"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T09:42:06Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=C7F9250E-AA39-59AC-BF9E-916E50F105AC"
                }
            ]
        },
        {
            "id": "CVE-2026-80098",
            "vendor": "Microsoft",
            "product": "Microsoft Copilot Studio",
            "title": "Microsoft Copilot Studio vulnerability",
            "summary": "Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-05T04:18:04.943",
            "published_at": "2026-09-03T23:17:20.350",
            "cvss": 9.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "-",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-347",
            "what_happened": "Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-80098"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T23:17:20.350",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80098"
                }
            ]
        },
        {
            "id": "CVE-2026-80072",
            "vendor": "Unknown",
            "product": "User Registration & Membership",
            "title": "User Registration & Membership vulnerability",
            "summary": "The User Registration & Membership  WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which can be abused for phishing.",
            "updated_at": "2026-09-13T11:16:58.623",
            "published_at": "2026-09-13T06:16:25.060",
            "cvss": 4.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.2.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-601",
            "what_happened": "The User Registration & Membership  WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which can be abused for phishing.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/0af2c06d-87a0-4be7-a409-ffb7ad958aad/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T06:16:25.060",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80072"
                }
            ]
        },
        {
            "id": "CVE-2026-80071",
            "vendor": "Unknown",
            "product": "User Registration & Membership",
            "title": "User Registration & Membership vulnerability",
            "summary": "The User Registration & Membership  WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.",
            "updated_at": "2026-09-13T11:16:58.460",
            "published_at": "2026-09-13T06:16:24.947",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.2.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "The User Registration & Membership  WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/a4fbdeea-0d3b-466b-b4b6-4c4db277cd1d/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T06:16:24.947",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80071"
                }
            ]
        },
        {
            "id": "CVE-2026-80057",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.",
            "updated_at": "2026-09-11T21:21:54.297",
            "published_at": "2026-09-07T15:17:32.397",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-321",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T15:17:32.397",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80057"
                }
            ]
        },
        {
            "id": "CVE-2026-80056",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.",
            "updated_at": "2026-09-11T21:22:05.523",
            "published_at": "2026-09-07T15:17:32.277",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-532",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T15:17:32.277",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-80056"
                }
            ]
        },
        {
            "id": "CVE-2026-79987",
            "vendor": "craftcms",
            "product": "cms",
            "title": "cms vulnerability",
            "summary": "A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.",
            "updated_at": "2026-09-11T04:17:55.070",
            "published_at": "2026-09-10T16:17:56.543",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5.8.0 through before 5.10.13 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-470",
            "what_happened": "A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/craftcms/cms",
                "https://github.com/craftcms/cms/releases/tag/5.10.13",
                "https://github.com/craftcms/cms/security/advisories/GHSA-9c4j-cjw3-r3xx",
                "https://www.hckrt.com/hacktivity/HCKRT-9TSYY2"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T16:17:56.543",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79987"
                }
            ]
        },
        {
            "id": "CVE-2026-79974",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "updated_at": "2026-09-11T04:17:53.847",
            "published_at": "2026-09-09T09:17:11.590",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-287",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T09:17:11.590",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79974"
                }
            ]
        },
        {
            "id": "CVE-2026-79972",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "updated_at": "2026-09-11T04:17:53.730",
            "published_at": "2026-09-09T12:17:14.760",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T12:17:14.760",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79972"
                }
            ]
        },
        {
            "id": "CVE-2026-79963",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution.",
            "updated_at": "2026-09-11T04:17:53.613",
            "published_at": "2026-09-09T12:17:14.507",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-494",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T12:17:14.507",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79963"
                }
            ]
        },
        {
            "id": "CVE-2026-79945",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.",
            "updated_at": "2026-09-11T04:17:53.503",
            "published_at": "2026-09-09T16:17:08.527",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T16:17:08.527",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79945"
                }
            ]
        },
        {
            "id": "CVE-2026-79941",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.",
            "updated_at": "2026-09-11T04:17:53.393",
            "published_at": "2026-09-09T15:17:10.363",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T15:17:10.363",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79941"
                }
            ]
        },
        {
            "id": "CVE-2026-79742",
            "vendor": "IBM",
            "product": "Langflow OSS",
            "title": "Langflow OSS vulnerability",
            "summary": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.",
            "updated_at": "2026-09-12T04:16:38.707",
            "published_at": "2026-09-10T22:17:00.780",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through 1.11.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286666"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:17:00.780",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79742"
                }
            ]
        },
        {
            "id": "CVE-2026-79741",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.",
            "updated_at": "2026-09-11T04:17:53.287",
            "published_at": "2026-09-09T16:17:08.147",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T16:17:08.147",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79741"
                }
            ]
        },
        {
            "id": "CVE-2026-79734",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.",
            "updated_at": "2026-09-07T14:16:54.460",
            "published_at": "2026-09-07T14:16:54.460",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:54.460",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79734"
                }
            ]
        },
        {
            "id": "CVE-2026-79724",
            "vendor": "IBM",
            "product": "Langflow OSS",
            "title": "Langflow OSS vulnerability",
            "summary": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.",
            "updated_at": "2026-09-12T16:16:39.620",
            "published_at": "2026-09-10T22:17:00.530",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through 1.11.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286666"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:17:00.530",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79724"
                }
            ]
        },
        {
            "id": "CVE-2026-79698",
            "vendor": "Advantech",
            "product": "WISE-6610-NB",
            "title": "WISE-6610-NB vulnerability",
            "summary": "A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.",
            "updated_at": "2026-09-11T21:17:17.030",
            "published_at": "2026-09-07T07:16:47.420",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.2.1_20251110",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://uvxbywu62qm.feishu.cn/wiki/RgziwoXf2iD9zKkI4MJcfWcNn7c?from=from_copylink",
                "https://vuldb.com/cve/CVE-2026-79698",
                "https://vuldb.com/submit/879219",
                "https://vuldb.com/vuln/399513",
                "https://vuldb.com/vuln/399513/cti",
                "https://www.advantech.com/",
                "https://www.advantech.com/en-us/support/details/firmware?id=1-2K7AXRI",
                "https://www.advantech.com/zh-tw/security-advisory"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T07:16:47.420",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79698"
                }
            ]
        },
        {
            "id": "CVE-2026-79697",
            "vendor": "Advantech",
            "product": "WISE-6610-NB",
            "title": "WISE-6610-NB vulnerability",
            "summary": "A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.",
            "updated_at": "2026-09-07T07:16:45.903",
            "published_at": "2026-09-07T07:16:45.903",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.2.1_20251110",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://uvxbywu62qm.feishu.cn/wiki/EzwXwS0vKiroHmk9rqzcjP0EnMe?from=from_copylink",
                "https://vuldb.com/cve/CVE-2026-79697",
                "https://vuldb.com/submit/879208",
                "https://vuldb.com/vuln/399512",
                "https://vuldb.com/vuln/399512/cti",
                "https://www.advantech.com/",
                "https://www.advantech.com/en-us/support/details/firmware?id=1-2K7AXRI",
                "https://www.advantech.com/zh-tw/security-advisory"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T07:16:45.903",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79697"
                }
            ]
        },
        {
            "id": "CVE-2026-79689",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.",
            "updated_at": "2026-09-11T04:17:53.167",
            "published_at": "2026-09-09T16:17:07.197",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T16:17:07.197",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79689"
                }
            ]
        },
        {
            "id": "CVE-2026-79645",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "updated_at": "2026-09-11T21:22:13.653",
            "published_at": "2026-09-07T15:17:32.033",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T15:17:32.033",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79645"
                }
            ]
        },
        {
            "id": "CVE-2026-79644",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "updated_at": "2026-09-11T21:22:45.097",
            "published_at": "2026-09-07T15:17:31.913",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T15:17:31.913",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79644"
                }
            ]
        },
        {
            "id": "CVE-2026-79641",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.",
            "updated_at": "2026-09-11T04:17:52.993",
            "published_at": "2026-09-09T11:17:15.500",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-78",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T11:17:15.500",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79641"
                }
            ]
        },
        {
            "id": "CVE-2026-79637",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "updated_at": "2026-09-11T04:17:52.833",
            "published_at": "2026-09-09T12:17:13.977",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T12:17:13.977",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79637"
                }
            ]
        },
        {
            "id": "CVE-2026-79418",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions.",
            "updated_at": "2026-09-15T19:17:40.233",
            "published_at": "2026-09-04T16:18:00.103",
            "cvss": 8.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://drive.google.com/file/d/1mp-uS-tAthH9FAObfx1D3lOM7IIjRsmE/view?usp=sharing",
                "https://emxtecnologia.com.br/gestao-x-business-suite/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:18:00.103",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79418"
                }
            ]
        },
        {
            "id": "CVE-2026-79300",
            "vendor": "SEP",
            "product": "sesam",
            "title": "sesam vulnerability",
            "summary": "SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalization differently, which may allow multiple SEP sesam user accounts to be created for the same Active Directory (AD) account. Active Directory treats usernames as case-insensitive, while SEP sesam distinguishes between different letter casing. As a result, the same AD user can be represented by multiple SEP sesam user accounts that differ only in username capitalization. When Active Directory authentication is configured and multi-factor authentication (MFA) is enforced, this behavior may allow an additional OTP Authenticator to be registered for the same AD account, reducing the effectiveness of MFA protection.",
            "updated_at": "2026-09-12T23:17:00.893",
            "published_at": "2026-09-12T23:17:00.893",
            "cvss": 3.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0 through before 5.2.0.24 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-180",
            "what_happened": "SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalization differently, which may allow multiple SEP sesam user accounts to be created for the same Active Directory (AD) account. Active Directory treats usernames as case-insensitive, while SEP sesam distinguishes between different letter casing. As a result, the same AD user can be represented by multiple SEP sesam user accounts that differ only in username capitalization. When Active Directory authentication is configured and multi-factor authentication (MFA) is enforced, this behavior may allow an additional OTP Authenticator to be registered for the same AD account, reducing the effectiveness of MFA protection.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wiki.sep.de/wiki/index.php/Release_Notes_5.2.0_Artemis#fixed"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T23:17:00.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79300"
                }
            ]
        },
        {
            "id": "CVE-2026-78804",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-78804",
            "summary": "Authenticated SQLi in Dolibarr product stock management via seuil_stock_alerte parameter.",
            "updated_at": "2026-09-10T12:10:44Z",
            "published_at": "2026-09-10T12:10:44Z",
            "cvss": 6,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 61,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Authenticated SQLi in Dolibarr product stock management via seuil_stock_alerte parameter.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-78804",
                    "summary": "Authenticated SQLi in Dolibarr product stock management via seuil_stock_alerte parameter.",
                    "what_happened": "Authenticated SQLi in Dolibarr product stock management via seuil_stock_alerte parameter.",
                    "cvss": 6,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=1FC3DC67-B4B6-5FC1-B780-A2A7619D8D7C",
                        "https://github.com/repo4Chu/CVE-2026-78804_Dolibarr_authenticated_SQL_injection"
                    ],
                    "repository": "Sploitus",
                    "author": "repo4Chu",
                    "first_seen": "2026-09-10T14:10:44",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=1FC3DC67-B4B6-5FC1-B780-A2A7619D8D7C"
                },
                {
                    "title": "Exploit for CVE-2026-78804",
                    "summary": "Authenticated SQLi in Dolibarr product stock management via seuil_stock_alerte parameter.",
                    "what_happened": "Authenticated SQLi in Dolibarr product stock management via seuil_stock_alerte parameter.",
                    "cvss": 6,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=1FC3DC67-B4B6-5FC1-B780-A2A7619D8D7C",
                        "https://github.com/repo4Chu/CVE-2026-78804_Dolibarr_authenticated_SQL_injection"
                    ],
                    "repository": "repo4Chu/CVE-2026-78804_Dolibarr_authenticated_SQL_injection",
                    "author": "repo4Chu",
                    "first_seen": "2026-09-10T14:10:44",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/repo4Chu/CVE-2026-78804_Dolibarr_authenticated_SQL_injection"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=1FC3DC67-B4B6-5FC1-B780-A2A7619D8D7C",
                "https://github.com/repo4Chu/CVE-2026-78804_Dolibarr_authenticated_SQL_injection"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T12:10:44Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=1FC3DC67-B4B6-5FC1-B780-A2A7619D8D7C"
                }
            ],
            "enrichment_checked_at": "2026-09-10T16:05:46Z",
            "cvss_vector": "NONE"
        },
        {
            "id": "CVE-2026-78684",
            "vendor": "vllm-project",
            "product": "vllm",
            "title": "vllm vulnerability",
            "summary": "vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.",
            "updated_at": "2026-09-14T21:08:51.177",
            "published_at": "2026-08-25T12:16:27.387",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.27.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video that bypasses resource controls, causing partial denial of service for concurrent requests.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/vllm-project/vllm/commit/e23b19309b8705b21c3b3ff4129c9974ba15a419",
                "https://github.com/vllm-project/vllm/security/advisories/GHSA-cqm8-jxg6-fqfq",
                "https://www.vulncheck.com/advisories/vllm-before-denial-of-service-via-deepstream-backend"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T12:16:27.387",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78684"
                }
            ]
        },
        {
            "id": "CVE-2026-78575",
            "vendor": "IBM",
            "product": "Langflow OSS",
            "title": "Langflow OSS vulnerability",
            "summary": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.",
            "updated_at": "2026-09-12T04:16:38.447",
            "published_at": "2026-09-10T22:17:00.130",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through 1.11.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286666"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:17:00.130",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78575"
                }
            ]
        },
        {
            "id": "CVE-2026-78571",
            "vendor": "IBM",
            "product": "Langflow OSS",
            "title": "Langflow OSS vulnerability",
            "summary": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.",
            "updated_at": "2026-09-12T04:16:38.313",
            "published_at": "2026-09-10T22:16:59.853",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through 1.11.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286666"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:16:59.853",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78571"
                }
            ]
        },
        {
            "id": "CVE-2026-78569",
            "vendor": "IBM",
            "product": "Langflow OSS",
            "title": "Langflow OSS vulnerability",
            "summary": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.",
            "updated_at": "2026-09-12T16:16:39.500",
            "published_at": "2026-09-10T22:16:59.723",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through 1.11.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286666"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:16:59.723",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78569"
                }
            ]
        },
        {
            "id": "CVE-2026-78494",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "updated_at": "2026-09-11T04:17:52.557",
            "published_at": "2026-09-09T09:17:10.990",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T09:17:10.990",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78494"
                }
            ]
        },
        {
            "id": "CVE-2026-78493",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.",
            "updated_at": "2026-09-11T04:17:52.440",
            "published_at": "2026-09-09T16:17:06.640",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T16:17:06.640",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78493"
                }
            ]
        },
        {
            "id": "CVE-2026-78492",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "updated_at": "2026-09-11T04:17:51.853",
            "published_at": "2026-09-09T12:17:13.850",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T12:17:13.850",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78492"
                }
            ]
        },
        {
            "id": "CVE-2026-78488",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution.",
            "updated_at": "2026-09-11T21:22:54.260",
            "published_at": "2026-09-07T15:17:31.790",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T15:17:31.790",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78488"
                }
            ]
        },
        {
            "id": "CVE-2026-78487",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.",
            "updated_at": "2026-09-07T14:16:54.340",
            "published_at": "2026-09-07T14:16:54.340",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-321",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:54.340",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78487"
                }
            ]
        },
        {
            "id": "CVE-2026-78484",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.",
            "updated_at": "2026-09-11T04:17:51.527",
            "published_at": "2026-09-09T16:17:06.517",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T16:17:06.517",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78484"
                }
            ]
        },
        {
            "id": "CVE-2026-78480",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "updated_at": "2026-09-11T21:23:03.420",
            "published_at": "2026-09-07T15:17:31.670",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T15:17:31.670",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78480"
                }
            ]
        },
        {
            "id": "CVE-2026-78456",
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2022 (CU 26)",
            "title": "Microsoft SQL Server 2022 (CU 26) vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.",
            "updated_at": "2026-09-15T14:55:45.910",
            "published_at": "2026-09-08T18:20:44.280",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16.0.0.0 through before 16.0.4275.2 (custom); 16.0.0 through before 16.0.1200.5 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78456"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:44.280",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78456"
                }
            ]
        },
        {
            "id": "CVE-2026-78448",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:37.980",
            "published_at": "2026-09-08T18:20:42.800",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-78448"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:42.800",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78448"
                }
            ]
        },
        {
            "id": "CVE-2026-78438",
            "vendor": "boldgrid",
            "product": "W3 Total Cache",
            "title": "W3 Total Cache vulnerability",
            "summary": "The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the \"Lazy Load Images\" feature with \"Process background images\" to be enabled, and the malicious comment to be approved by a moderator before execution is triggered.",
            "updated_at": "2026-09-05T07:17:12.580",
            "published_at": "2026-09-05T07:17:12.580",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.10.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the \"Lazy Load Images\" feature with \"Process background images\" to be enabled, and the malicious comment to be approved by a moderator before execution is triggered.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Mutator.php#L255",
                "https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Mutator.php#L293",
                "https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Mutator.php#L91",
                "https://plugins.trac.wordpress.org/browser/w3-total-cache/tags/2.10.5/UserExperience_LazyLoad_Plugin.php#L87",
                "https://plugins.trac.wordpress.org/changeset/3680101/w3-total-cache/tags/2.10.6/UserExperience_LazyLoad_Mutator.php",
                "https://plugins.trac.wordpress.org/changeset?old_path=%2Fw3-total-cache/tags/2.10.5&new_path=%2Fw3-total-cache/tags/2.10.6",
                "https://plugins.trac.wordpress.org/changeset?reponame=&new=3680101%40w3-total-cache%2Ftags%2F2.10.6&old=3653442%40w3-total-cache%2Ftags%2F2.10.5",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/5580ad05-af50-4899-9cbf-39ad8000eb6a?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:12.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78438"
                }
            ]
        },
        {
            "id": "CVE-2026-78408",
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images",
            "title": "Red Hat Hardened Images vulnerability",
            "summary": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.",
            "updated_at": "2026-09-05T14:17:23.727",
            "published_at": "2026-09-02T16:17:23.687",
            "cvss": 7.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-775",
            "what_happened": "The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:63162",
                "https://access.redhat.com/security/cve/CVE-2026-78408",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2522497",
                "https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj",
                "http://www.openwall.com/lists/oss-security/2026/09/05/2"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T16:17:23.687",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78408"
                }
            ]
        },
        {
            "id": "CVE-2026-78362",
            "vendor": "Unknown",
            "product": "SEO Flow by LupsOnline",
            "title": "SEO Flow by LupsOnline vulnerability",
            "summary": "The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state.",
            "updated_at": "2026-09-06T11:18:01.910",
            "published_at": "2026-09-05T07:17:12.487",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.0.0 through before 3.0.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the SEO Flow by LupsOnline WordPress plugin before 3.0.3 to have been configured, which is its normal operating state.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/0833424b-1231-4a48-be90-13fe4edc60c9/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:12.487",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78362"
                }
            ]
        },
        {
            "id": "CVE-2026-78254",
            "vendor": "Apache Software Foundation",
            "product": "Apache Ant",
            "title": "Apache Ant vulnerability",
            "summary": "The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18. \n\n\n\n\nIn order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-in-the-middle attack. Additionally in the case of scp or the ftp task using ftps the server must pass the server identity checks performed by the tasks.\n\n\n\n\nFor ftp tasks not using ftps a malicious server could act as a machine-in-the-middle to provide malicious files.\n\n\n\n\nStarting with Ant 1.10.18 both tasks will prevent writing outside of the destination directory by default. An option is available to disable this behavior in the unlikely case that the  old behavior is required by existing build files.\n\n\n\n\nMitigations:\n\n\n\n\nUsers of scp and ftp (when using ftps) in any version of Ant should not bypass server identity checks. Users of ftp not using ftps should switch to ftps where possible.\n\n\n\n\nAll users are recommended to upgrade to Apache Ant 1.10.18, which fixes this issue.",
            "updated_at": "2026-09-07T09:17:16.583",
            "published_at": "2026-09-07T08:17:12.943",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.2 through before 1.10.18 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-23",
            "what_happened": "The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18. \n\n\n\n\nIn order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-in-the-middle attack. Additionally in the case of scp or the ftp task using ftps the server must pass the server identity checks performed by the tasks.\n\n\n\n\nFor ftp tasks not using ftps a malicious server could act as a machine-in-the-middle to provide malicious files.\n\n\n\n\nStarting with Ant 1.10.18 both tasks will prevent writing outside of the destination directory by default. An option is available to disable this behavior in the unlikely case that the  old behavior is required by existing build files.\n\n\n\n\nMitigations:\n\n\n\n\nUsers of scp and ftp (when using ftps) in any version of Ant should not bypass server identity checks. Users of ftp not using ftps should switch to ftps where possible.\n\n\n\n\nAll users are recommended to upgrade to Apache Ant 1.10.18, which fixes this issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://lists.apache.org/thread/05s46qrlbhd06c6rsgvxh8zo0l4p9scz",
                "http://www.openwall.com/lists/oss-security/2026/09/06/2"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:17:12.943",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78254"
                }
            ]
        },
        {
            "id": "CVE-2026-78221",
            "vendor": "OpenVPN",
            "product": "OpenVPN",
            "title": "OpenVPN vulnerability",
            "summary": "An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.",
            "updated_at": "2026-09-07T08:17:12.813",
            "published_at": "2026-09-07T08:17:12.813",
            "cvss": 5.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.7_alpha1 through 2.7.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-131",
            "what_happened": "An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://community.openvpn.net/Security%20Announcements/CVE-2026-78221"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:17:12.813",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78221"
                }
            ]
        },
        {
            "id": "CVE-2026-78175",
            "vendor": "themeum",
            "product": "Tutor LMS – eLearning and online course solution",
            "title": "Tutor LMS – eLearning and online course solution vulnerability",
            "summary": "The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler lacking any capability or role check, relying solely on a nonce, while also passing attacker-supplied values through `esc_sql()`, which replaces every `%` character with a 66-byte HMAC placeholder token before the data is serialized and stored via `update_user_meta()`; when the meta is later retrieved, the placeholder is collapsed back to a single `%`, leaving serialized string length declarations 65 bytes greater than the actual content, and because array keys originate from entirely unescaped POST field names, `unserialize()` over-reads into attacker-controlled bytes, allowing injection of an arbitrary serialized object stream. This makes it possible for authenticated attackers, with subscriber-level access and above, to achieve remote code execution on the server by triggering the `GuzzleHttp\\Cookie\\FileCookieJar` POP chain, reachable via the `spl_autoload_register` loader in `TUTOR\\RestAPI` which loads the plugin's own bundled PayPal Composer autoloader, writing attacker-controlled content to an attacker-specified filename. This has an unauthenticated pathway when user registration is enabled, which is common for students and teachers to register, and it requires the monetization feature to be enabled.",
            "updated_at": "2026-09-12T08:16:24.507",
            "published_at": "2026-09-12T08:16:24.507",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.0.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.0.7 via the `withdraw_method_field` parameter of the `tutor_save_withdraw_account` AJAX handler. This is due to the handler lacking any capability or role check, relying solely on a nonce, while also passing attacker-supplied values through `esc_sql()`, which replaces every `%` character with a 66-byte HMAC placeholder token before the data is serialized and stored via `update_user_meta()`; when the meta is later retrieved, the placeholder is collapsed back to a single `%`, leaving serialized string length declarations 65 bytes greater than the actual content, and because array keys originate from entirely unescaped POST field names, `unserialize()` over-reads into attacker-controlled bytes, allowing injection of an arbitrary serialized object stream. This makes it possible for authenticated attackers, with subscriber-level access and above, to achieve remote code execution on the server by triggering the `GuzzleHttp\\Cookie\\FileCookieJar` POP chain, reachable via the `spl_autoload_register` loader in `TUTOR\\RestAPI` which loads the plugin's own bundled PayPal Composer autoloader, writing attacker-controlled content to an attacker-specified filename. This has an unauthenticated pathway when user registration is enabled, which is common for students and teachers to register, and it requires the monetization feature to be enabled.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/tutor/tags/4.0.7/classes/RestAPI.php#L190",
                "https://plugins.trac.wordpress.org/browser/tutor/tags/4.0.7/classes/Withdraw.php#L204",
                "https://plugins.trac.wordpress.org/browser/tutor/tags/4.0.7/classes/Withdraw.php#L213",
                "https://plugins.trac.wordpress.org/browser/tutor/tags/4.0.7/classes/Withdraw.php#L217",
                "https://plugins.trac.wordpress.org/browser/tutor/tags/4.0.7/classes/Withdraw.php#L44",
                "https://plugins.trac.wordpress.org/changeset?reponame=&old=3690454%40tutor&new=3690454%40tutor",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/d0077d56-11e7-4e74-abe0-63e81db67be3?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T08:16:24.507",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78175"
                }
            ]
        },
        {
            "id": "CVE-2026-78159",
            "vendor": "stellarwp",
            "product": "The Events Calendar",
            "title": "The Events Calendar vulnerability",
            "summary": "The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area.",
            "updated_at": "2026-09-12T08:16:24.377",
            "published_at": "2026-09-12T08:16:24.377",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 6.17.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/common/src/Tribe/Utils/Element_Classes.php#L211",
                "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Template_Bootstrap.php#L214",
                "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Widgets/Service_Provider.php#L279",
                "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/views/v2/components/messages.php#L30",
                "https://plugins.trac.wordpress.org/changeset?reponame=&old=3667866%40the-events-calendar&new=3667866%40the-events-calendar",
                "https://plugins.trac.wordpress.org/changeset?reponame=&old=3667867%40the-events-calendar&new=3667867%40the-events-calendar",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/cc2ccfeb-6df6-4fee-96a5-94f8dd131f7c?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T08:16:24.377",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78159"
                }
            ]
        },
        {
            "id": "CVE-2026-78152",
            "vendor": "Unknown",
            "product": "SureRank SEO",
            "title": "SureRank SEO vulnerability",
            "summary": "The SureRank SEO  WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.",
            "updated_at": "2026-09-12T16:16:39.357",
            "published_at": "2026-09-12T06:16:25.290",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.6.2 through before 1.10.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The SureRank SEO  WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/f16d3d06-6db0-4c6a-9eee-80b87d886a47/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:25.290",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78152"
                }
            ]
        },
        {
            "id": "CVE-2026-78150",
            "vendor": "Unknown",
            "product": "Smart Post",
            "title": "Smart Post vulnerability",
            "summary": "The Smart Post  WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draft of their own and read its content and metadata.",
            "updated_at": "2026-09-06T11:18:01.763",
            "published_at": "2026-09-05T07:17:12.393",
            "cvss": 2.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.0.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "The Smart Post  WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to duplicate, allowing users with contributor privileges and above to copy any private or password protected post into a draft of their own and read its content and metadata.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/e6c8a115-88a2-4fdf-9b97-8ae8a8c7f0aa/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:12.393",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78150"
                }
            ]
        },
        {
            "id": "CVE-2026-78149",
            "vendor": "Unknown",
            "product": "Smart Post",
            "title": "Smart Post vulnerability",
            "summary": "The Smart Post  WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protected post content and the password that guards it.",
            "updated_at": "2026-09-06T11:18:01.617",
            "published_at": "2026-09-05T07:17:12.300",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.0.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The Smart Post  WordPress plugin before 4.0.8 does not check whether a post is password protected before returning its content and its stored password through an unauthenticated AJAX action, allowing unauthenticated users to read protected post content and the password that guards it.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/8140528f-27d4-485c-ad63-4dcaa3932af2/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:12.300",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78149"
                }
            ]
        },
        {
            "id": "CVE-2026-78135",
            "vendor": "strongSwan",
            "product": "strongSwan",
            "title": "strongSwan vulnerability",
            "summary": "libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.",
            "updated_at": "2026-09-11T03:16:23.160",
            "published_at": "2026-09-11T03:16:23.160",
            "cvss": 5.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5.9.7 through before 6.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-841",
            "what_happened": "libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/strongswan/strongswan/releases/tag/6.1.0",
                "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78135).html"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T03:16:23.160",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78135"
                }
            ]
        },
        {
            "id": "CVE-2026-78134",
            "vendor": "strongSwan",
            "product": "strongSwan",
            "title": "strongSwan vulnerability",
            "summary": "strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.",
            "updated_at": "2026-09-11T02:18:34.910",
            "published_at": "2026-09-11T02:18:34.910",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.5.0 through before 6.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-863",
            "what_happened": "strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/strongswan/strongswan/releases/tag/6.1.0",
                "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78134).html"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T02:18:34.910",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78134"
                }
            ]
        },
        {
            "id": "CVE-2026-78133",
            "vendor": "strongSwan",
            "product": "strongSwan",
            "title": "strongSwan vulnerability",
            "summary": "libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.",
            "updated_at": "2026-09-11T02:18:34.757",
            "published_at": "2026-09-11T02:18:34.757",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.0.0 through before 6.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/strongswan/strongswan/releases/tag/6.1.0",
                "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78133).html"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T02:18:34.757",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78133"
                }
            ]
        },
        {
            "id": "CVE-2026-78132",
            "vendor": "strongSwan",
            "product": "strongSwan",
            "title": "strongSwan vulnerability",
            "summary": "strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.",
            "updated_at": "2026-09-11T02:18:34.613",
            "published_at": "2026-09-11T02:18:34.613",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5.1.3 through before 6.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-835",
            "what_happened": "strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/strongswan/strongswan/releases/tag/6.1.0",
                "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78132).html"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T02:18:34.613",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78132"
                }
            ]
        },
        {
            "id": "CVE-2026-78131",
            "vendor": "strongSwan",
            "product": "strongSwan",
            "title": "strongSwan vulnerability",
            "summary": "strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.",
            "updated_at": "2026-09-11T02:18:34.490",
            "published_at": "2026-09-11T02:18:34.490",
            "cvss": 3.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.2.0 through before 6.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-401",
            "what_happened": "strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/strongswan/strongswan/releases/tag/6.1.0",
                "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78131).html"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T02:18:34.490",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78131"
                }
            ]
        },
        {
            "id": "CVE-2026-78130",
            "vendor": "strongSwan",
            "product": "strongSwan",
            "title": "strongSwan vulnerability",
            "summary": "strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.",
            "updated_at": "2026-09-11T02:18:34.353",
            "published_at": "2026-09-11T02:18:34.353",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.2.0 through before 6.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/strongswan/strongswan/releases/tag/6.1.0",
                "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78130).html"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T02:18:34.353",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78130"
                }
            ]
        },
        {
            "id": "CVE-2026-78129",
            "vendor": "strongSwan",
            "product": "strongSwan",
            "title": "strongSwan vulnerability",
            "summary": "strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.",
            "updated_at": "2026-09-11T02:18:34.207",
            "published_at": "2026-09-11T02:18:34.207",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.6.2 through before 6.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-835",
            "what_happened": "strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/strongswan/strongswan/releases/tag/6.1.0",
                "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78129).html"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T02:18:34.207",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78129"
                }
            ]
        },
        {
            "id": "CVE-2026-78127",
            "vendor": "strongSwan",
            "product": "strongSwan",
            "title": "strongSwan vulnerability",
            "summary": "libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.",
            "updated_at": "2026-09-11T02:18:34.063",
            "published_at": "2026-09-11T02:18:34.063",
            "cvss": 3.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.1.2 through before 6.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-401",
            "what_happened": "libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/strongswan/strongswan/releases/tag/6.1.0",
                "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78127).html"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T02:18:34.063",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78127"
                }
            ]
        },
        {
            "id": "CVE-2026-78126",
            "vendor": "strongSwan",
            "product": "strongSwan",
            "title": "strongSwan vulnerability",
            "summary": "strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.",
            "updated_at": "2026-09-11T02:18:33.920",
            "published_at": "2026-09-11T02:18:33.920",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.1.10 through before 6.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-476",
            "what_happened": "strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/strongswan/strongswan/releases/tag/6.1.0",
                "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78126).html"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T02:18:33.920",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78126"
                }
            ]
        },
        {
            "id": "CVE-2026-78124",
            "vendor": "strongSwan",
            "product": "strongSwan",
            "title": "strongSwan vulnerability",
            "summary": "strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.",
            "updated_at": "2026-09-11T02:18:33.770",
            "published_at": "2026-09-11T02:18:33.770",
            "cvss": 3.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5.0.2 through before 6.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-401",
            "what_happened": "strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/strongswan/strongswan/releases/tag/6.1.0",
                "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78124).html"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T02:18:33.770",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78124"
                }
            ]
        },
        {
            "id": "CVE-2026-78123",
            "vendor": "strongSwan",
            "product": "strongSwan",
            "title": "strongSwan vulnerability",
            "summary": "strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.",
            "updated_at": "2026-09-11T02:18:33.413",
            "published_at": "2026-09-11T02:18:33.413",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5.0.2 through before 6.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-825",
            "what_happened": "strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/strongswan/strongswan/releases/tag/6.1.0",
                "https://www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78123).html"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T02:18:33.413",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78123"
                }
            ]
        },
        {
            "id": "CVE-2026-78043",
            "vendor": "OpenVPN",
            "product": "OpenVPN",
            "title": "OpenVPN vulnerability",
            "summary": "The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths",
            "updated_at": "2026-09-07T08:17:12.637",
            "published_at": "2026-09-07T08:17:12.637",
            "cvss": 5.6,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.7_alpha1 through 2.7.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://community.openvpn.net/Security%20Announcements/CVE-2026-78043"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:17:12.637",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78043"
                }
            ]
        },
        {
            "id": "CVE-2026-78006",
            "vendor": "stellarwp",
            "product": "The Events Calendar",
            "title": "The Events Calendar vulnerability",
            "summary": "The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. This makes it possible for unauthenticated attackers to execute code on the server. This is exploitable without authentication or approval because the plugin's V2 single-event template runs do_blocks() over buffered comment HTML, and WordPress returns a moderation-hash URL that allows an unauthenticated commenter to immediately view their own pending comment, delivering the injected block markup to the vulnerable code path before any moderation occurs. This does require comments to be enabled and visible on events.",
            "updated_at": "2026-09-12T08:16:24.240",
            "published_at": "2026-09-12T08:16:24.240",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "0 through 6.17.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 58,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. This makes it possible for unauthenticated attackers to execute code on the server. This is exploitable without authentication or approval because the plugin's V2 single-event template runs do_blocks() over buffered comment HTML, and WordPress returns a moderation-hash URL that allows an unauthenticated commenter to immediately view their own pending comment, delivering the injected block markup to the vulnerable code path before any moderation occurs. This does require comments to be enabled and visible on events.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-78006",
                    "summary": "Unauthenticated PHP Object Injection to RCE in The Events Calendar <= 6.17.4 via event comment.",
                    "what_happened": "Unauthenticated PHP Object Injection to RCE in The Events Calendar <= 6.17.4 via event comment.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=C6D57857-780F-507B-BE68-A4C3C17A833E",
                        "https://github.com/DeadExpl0it/CVE-2026-78006-POC"
                    ],
                    "repository": "Sploitus",
                    "author": "DeadExpl0it",
                    "first_seen": "2026-09-12T11:42:16",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=C6D57857-780F-507B-BE68-A4C3C17A833E"
                },
                {
                    "title": "Exploit for CVE-2026-78006",
                    "summary": "Unauthenticated PHP Object Injection to RCE in The Events Calendar <= 6.17.4 via event comment.",
                    "what_happened": "Unauthenticated PHP Object Injection to RCE in The Events Calendar <= 6.17.4 via event comment.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=C6D57857-780F-507B-BE68-A4C3C17A833E",
                        "https://github.com/DeadExpl0it/CVE-2026-78006-POC"
                    ],
                    "repository": "DeadExpl0it/CVE-2026-78006-POC",
                    "author": "DeadExpl0it",
                    "first_seen": "2026-09-12T11:42:16",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/DeadExpl0it/CVE-2026-78006-POC"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T15:06:42+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2026-78006-POC exploit",
                    "summary": "Exploit for CVE-2026-78006. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DEADEXPL0IT-CVE-2026-78006-POC"
                }
            ],
            "references": [
                "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/common/src/Tribe/Utils/Collection_Trait.php#L247",
                "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Collections/Lazy_Post_Collection.php#L82",
                "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Template_Bootstrap.php#L213",
                "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Widgets/Service_Provider.php#L255",
                "https://plugins.trac.wordpress.org/browser/the-events-calendar/tags/6.17.3/src/Tribe/Views/V2/Widgets/Service_Provider.php#L295",
                "https://plugins.trac.wordpress.org/changeset?reponame=&old=3690576%40the-events-calendar&new=3690576%40the-events-calendar",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/a0c67346-534a-4b67-a904-fa148703707a?source=cve",
                "https://sploitus.com/exploit?id=C6D57857-780F-507B-BE68-A4C3C17A833E",
                "https://github.com/DeadExpl0it/CVE-2026-78006-POC",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DEADEXPL0IT-CVE-2026-78006-POC"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T08:16:24.240",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-78006"
                }
            ]
        },
        {
            "id": "CVE-2026-77830",
            "vendor": "cleantalk",
            "product": "Spam protection, Honeypot, Anti-Spam by CleanTalk",
            "title": "Spam protection, Honeypot, Anti-Spam by CleanTalk vulnerability",
            "summary": "The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up to, and including, 6.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is deliverable via unauthenticated comment submission and executes exclusively for non-logged-in visitors; if comment moderation is enabled, an approving moderator must first publish the comment before the script reaches other users.",
            "updated_at": "2026-09-05T07:17:12.163",
            "published_at": "2026-09-05T07:17:12.163",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 6.86 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up to, and including, 6.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is deliverable via unauthenticated comment submission and executes exclusively for non-logged-in visitors; if comment moderation is enabled, an approving moderator must first publish the comment before the script reaches other users.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/cleantalk.php#L234",
                "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/lib/Cleantalk/ApbctWP/ContactsEncoder/ContactsEncoder.php#L114",
                "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L914",
                "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.84/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L933",
                "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/cleantalk.php#L234",
                "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/lib/Cleantalk/ApbctWP/ContactsEncoder/ContactsEncoder.php#L114",
                "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L914",
                "https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/tags/6.85/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php#L933",
                "https://plugins.trac.wordpress.org/changeset/3677388/cleantalk-spam-protect/trunk/lib/Cleantalk/Common/ContactsEncoder/ContactsEncoder.php",
                "https://plugins.trac.wordpress.org/changeset?old_path=%2Fcleantalk-spam-protect/tags/6.86&new_path=%2Fcleantalk-spam-protect/tags/6.87",
                "https://plugins.trac.wordpress.org/changeset?reponame=&new=3677388%40cleantalk-spam-protect%2Ftags%2F6.87&old=3654120%40cleantalk-spam-protect%2Ftags%2F6.86",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/10e7000b-597a-4165-8604-cb6b29714abb?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:12.163",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77830"
                }
            ]
        },
        {
            "id": "CVE-2026-77826",
            "vendor": "Unknown",
            "product": "RegistrationMagic",
            "title": "RegistrationMagic vulnerability",
            "summary": "The RegistrationMagic  WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled.",
            "updated_at": "2026-09-06T11:18:01.470",
            "published_at": "2026-09-05T07:17:12.063",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5.0.1.8 through before 6.0.9.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "The RegistrationMagic  WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/b79a83e8-d7b0-4aa8-b2ba-37a7eecd437b/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:12.063",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77826"
                }
            ]
        },
        {
            "id": "CVE-2026-77822",
            "vendor": "IBM",
            "product": "ContextForge MCP Gateway",
            "title": "ContextForge MCP Gateway vulnerability",
            "summary": "IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.",
            "updated_at": "2026-09-15T15:16:27.183",
            "published_at": "2026-09-04T16:17:59.550",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "<= v1.0.8",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-918",
            "what_happened": "IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286055"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:17:59.550",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77822"
                }
            ]
        },
        {
            "id": "CVE-2026-77773",
            "vendor": "Unknown",
            "product": "Contact Form to Chat Apps | Click to Chat to Order",
            "title": "Contact Form to Chat Apps | Click to Chat to Order vulnerability",
            "summary": "The Contact Form to Chat Apps | Click to Chat to Order  WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entries of any form created with a supported third-party form Contact Form to Chat Apps | Click to Chat to Order  WordPress plugin before 2.15.8.",
            "updated_at": "2026-09-13T11:16:57.173",
            "published_at": "2026-09-13T06:16:24.680",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.15.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The Contact Form to Chat Apps | Click to Chat to Order  WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entries of any form created with a supported third-party form Contact Form to Chat Apps | Click to Chat to Order  WordPress plugin before 2.15.8.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/c4c15701-2149-43b4-b794-38871c0dc734/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T06:16:24.680",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77773"
                }
            ]
        },
        {
            "id": "CVE-2026-77771",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-77771",
            "summary": "Proof-of-concept exploit for CVE-2026-77771. CVSS 7.5.",
            "updated_at": "2026-09-12T09:28:56Z",
            "published_at": "2026-09-12T09:28:56Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 35,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-287",
            "what_happened": "2FA bypass in miniOrange Two-Factor Authentication for WordPress via unlimited OTP brute-force.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-77771",
                    "summary": "2FA bypass in miniOrange Two-Factor Authentication for WordPress via unlimited OTP brute-force.",
                    "what_happened": "2FA bypass in miniOrange Two-Factor Authentication for WordPress via unlimited OTP brute-force.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "High",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=85C533D5-C017-5130-B139-CE37FBD19E1E",
                        "https://github.com/pervinzahidli/CVE-2026-77771"
                    ],
                    "repository": "Sploitus",
                    "author": "pervinzahidli",
                    "first_seen": "2026-09-12T09:31:38",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=85C533D5-C017-5130-B139-CE37FBD19E1E"
                },
                {
                    "title": "Exploit for CVE-2026-77771",
                    "summary": "2FA bypass in miniOrange Two-Factor Authentication for WordPress via unlimited OTP brute-force.",
                    "what_happened": "2FA bypass in miniOrange Two-Factor Authentication for WordPress via unlimited OTP brute-force.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "High",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=85C533D5-C017-5130-B139-CE37FBD19E1E",
                        "https://github.com/pervinzahidli/CVE-2026-77771"
                    ],
                    "repository": "pervinzahidli/CVE-2026-77771",
                    "author": "pervinzahidli",
                    "first_seen": "2026-09-12T09:31:38",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://github.com/pervinzahidli/CVE-2026-77771"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=85C533D5-C017-5130-B139-CE37FBD19E1E",
                "https://github.com/pervinzahidli/CVE-2026-77771"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T09:28:56Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=85C533D5-C017-5130-B139-CE37FBD19E1E"
                }
            ]
        },
        {
            "id": "CVE-2026-77753",
            "vendor": "Unknown",
            "product": "Temporary Login Without Password",
            "title": "Temporary Login Without Password vulnerability",
            "summary": "The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC after the administrator believes it has been withdrawn. The retained access carries whatever role was granted, which for the Temporary Login Without Password WordPress plugin before 1.9.9's main use case is Administrator.",
            "updated_at": "2026-09-12T16:16:39.220",
            "published_at": "2026-09-12T06:16:25.183",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.9.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the temporary access expires or is disabled, allowing the recipient of a temporary login to retain working access to the site over REST and XML-RPC after the administrator believes it has been withdrawn. The retained access carries whatever role was granted, which for the Temporary Login Without Password WordPress plugin before 1.9.9's main use case is Administrator.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/9424fd42-5c77-41a9-a1fb-db568126515e/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:25.183",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77753"
                }
            ]
        },
        {
            "id": "CVE-2026-77752",
            "vendor": "Unknown",
            "product": "Temporary Login Without Password",
            "title": "Temporary Login Without Password vulnerability",
            "summary": "The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.",
            "updated_at": "2026-09-12T16:16:39.080",
            "published_at": "2026-09-12T06:16:25.070",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.5 through before 1.9.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the new account those rights, allowing an administrator of a single site on a multisite network to take over the whole network. The same missing check also allows an existing account, including the attacker's own, to be promoted.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/09308b99-3142-44f0-b2e1-9f4680325d2d/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:25.070",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77752"
                }
            ]
        },
        {
            "id": "CVE-2026-77705",
            "vendor": "Unknown",
            "product": "Booking for Appointments and Events Calendar",
            "title": "Booking for Appointments and Events Calendar vulnerability",
            "summary": "The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.",
            "updated_at": "2026-09-12T16:16:38.943",
            "published_at": "2026-09-12T06:16:24.967",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.4.10 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "The Booking for Appointments and Events Calendar  WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordPress account linked to it, allowing users holding Amelia's customer or employee management permissions to set the password and email address of other users' WordPress accounts and take them over.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/bfd0ce74-f91e-41fe-8288-7b1d34dd16fe/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:24.967",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77705"
                }
            ]
        },
        {
            "id": "CVE-2026-77689",
            "vendor": "Unknown",
            "product": "Booking for Appointments and Events Calendar",
            "title": "Booking for Appointments and Events Calendar vulnerability",
            "summary": "The Booking for Appointments and Events Calendar  WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an unauthenticated attacker obtain confirmed, fully paid appointments and events without any payment being collected.",
            "updated_at": "2026-09-12T16:16:38.807",
            "published_at": "2026-09-12T06:16:24.860",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.0 through before 9.8.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "The Booking for Appointments and Events Calendar  WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the payment gateway named in a public, unauthenticated booking request even when the site has never configured that gateway. This lets an unauthenticated attacker obtain confirmed, fully paid appointments and events without any payment being collected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/ac597716-193d-419f-b55c-802ee979385e/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:24.860",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77689"
                }
            ]
        },
        {
            "id": "CVE-2026-77505",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "updated_at": "2026-09-10T04:18:16.817",
            "published_at": "2026-09-08T18:20:37.920",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77505"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:37.920",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77505"
                }
            ]
        },
        {
            "id": "CVE-2026-77488",
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (CU 31)",
            "title": "Microsoft SQL Server 2017 (CU 31) vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.",
            "updated_at": "2026-09-15T14:57:29.537",
            "published_at": "2026-09-08T18:20:34.527",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0 through before 14.0.3550.4 (custom); 14.0.0 through before 14.0.2130.4 (custom); 15.0.0.0 through before 15.0.4490.9 (custom); 15.0.0 through before 15.0.2190.7 (custom); 16.0.0.0 through before 16.0.4275.2 (custom); 16.0.0 through before 16.0.1200.5 (custom); 17.0.0.0 through before 17.0.4085.5 (custom); 17.0.1050.2 through before 17.0.1135.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-191",
            "what_happened": "Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77488"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:34.527",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77488"
                }
            ]
        },
        {
            "id": "CVE-2026-77487",
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (CU 31)",
            "title": "Microsoft SQL Server 2017 (CU 31) vulnerability",
            "summary": "Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-15T15:43:50.457",
            "published_at": "2026-09-08T18:20:34.397",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0 through before 14.0.3550.4 (custom); 14.0.0 through before 14.0.2130.4 (custom); 15.0.0.0 through before 15.0.4490.9 (custom); 15.0.0 through before 15.0.2190.7 (custom); 16.0.0.0 through before 16.0.4275.2 (custom); 16.0.0 through before 16.0.1200.5 (custom); 17.0.0.0 through before 17.0.4085.5 (custom); 17.0.1050.2 through before 17.0.1135.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77487"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:34.397",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77487"
                }
            ]
        },
        {
            "id": "CVE-2026-77486",
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (CU 31)",
            "title": "Microsoft SQL Server 2017 (CU 31) vulnerability",
            "summary": "Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.",
            "updated_at": "2026-09-15T15:44:38.337",
            "published_at": "2026-09-08T18:20:34.277",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0 through before 14.0.3550.4 (custom); 14.0.0 through before 14.0.2130.4 (custom); 15.0.0.0 through before 15.0.4490.9 (custom); 15.0.0 through before 15.0.2190.7 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77486"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:34.277",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77486"
                }
            ]
        },
        {
            "id": "CVE-2026-77481",
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (CU 31)",
            "title": "Microsoft SQL Server 2017 (CU 31) vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.",
            "updated_at": "2026-09-15T14:55:03.260",
            "published_at": "2026-09-08T18:20:33.633",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0 through before 14.0.3550.4 (custom); 14.0.0 through before 14.0.2130.4 (custom); 15.0.0.0 through before 15.0.4490.9 (custom); 15.0.0 through before 15.0.2190.7 (custom); 16.0.0.0 through before 16.0.4275.2 (custom); 16.0.0 through before 16.0.1200.5 (custom); 17.0.0.0 through before 17.0.4085.5 (custom); 17.0.1050.2 through before 17.0.1135.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77481"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:33.633",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77481"
                }
            ]
        },
        {
            "id": "CVE-2026-77263",
            "vendor": "iubenda",
            "product": "iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more",
            "title": "iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more vulnerability",
            "summary": "The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.13.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit works by embedding KSES-allowed markup such as abbr title attributes and HTML comments in a submitted comment so that the global strtr() substitution strips substrings from an inert tag, mutating it into an executable element such as an img onerror handler that runs in the WordPress origin for any visitor, including logged-in administrators.",
            "updated_at": "2026-09-05T06:17:09.950",
            "published_at": "2026-09-05T06:17:09.950",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.13.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.13.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit works by embedding KSES-allowed markup such as abbr title attributes and HTML comments in a submitted comment so that the global strtr() substitution strips substrings from an inert tag, mutating it into an executable element such as an img onerror handler that runs in the WordPress origin for any visitor, including logged-in administrators.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php#L381",
                "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php#L941",
                "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda_cookie_solution.php#L834",
                "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/trunk/iubenda_cookie_solution.php#L857",
                "https://plugins.trac.wordpress.org/changeset/3675630/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php",
                "https://plugins.trac.wordpress.org/changeset?old_path=%2Fiubenda-cookie-law-solution/tags/3.13.4&new_path=%2Fiubenda-cookie-law-solution/tags/3.13.5",
                "https://plugins.trac.wordpress.org/changeset?reponame=&new=3675630%40iubenda-cookie-law-solution%2Ftags%2F3.13.5&old=3663183%40iubenda-cookie-law-solution%2Ftags%2F3.13.4",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/f8d18aaa-c8f4-4688-841d-2a77b71b60b0?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T06:17:09.950",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77263"
                }
            ]
        },
        {
            "id": "CVE-2026-77233",
            "vendor": "iubenda",
            "product": "iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more",
            "title": "iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more vulnerability",
            "summary": "The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite in all versions up to, and including, 3.13.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability only manifests when the 'Secondary' parser engine is active (parser_engine=default); it does not exist under the default 'new' DOM-based parser engine.",
            "updated_at": "2026-09-05T06:17:09.780",
            "published_at": "2026-09-05T06:17:09.780",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.13.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite in all versions up to, and including, 3.13.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability only manifests when the 'Secondary' parser engine is active (parser_engine=default); it does not exist under the default 'new' DOM-based parser engine.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.2/iubenda-cookie-class/iubenda.class.php#L557",
                "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.2/iubenda-cookie-class/iubenda.class.php#L570",
                "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.2/iubenda_cookie_solution.php#L986",
                "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.3/iubenda-cookie-class/iubenda.class.php#L557",
                "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.3/iubenda-cookie-class/iubenda.class.php#L570",
                "https://plugins.trac.wordpress.org/browser/iubenda-cookie-law-solution/tags/3.13.3/iubenda_cookie_solution.php#L986",
                "https://plugins.trac.wordpress.org/changeset/3675630/iubenda-cookie-law-solution/trunk/iubenda-cookie-class/iubenda.class.php",
                "https://plugins.trac.wordpress.org/changeset?old_path=%2Fiubenda-cookie-law-solution/tags/3.13.4&new_path=%2Fiubenda-cookie-law-solution/tags/3.13.5",
                "https://plugins.trac.wordpress.org/changeset?reponame=&new=3675630%40iubenda-cookie-law-solution%2Ftags%2F3.13.5&old=3663183%40iubenda-cookie-law-solution%2Ftags%2F3.13.4",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/af459f28-a058-42d3-8818-43603c6a14eb?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T06:17:09.780",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77233"
                }
            ]
        },
        {
            "id": "CVE-2026-77161",
            "vendor": "egoi",
            "product": "Smart Marketing SMS and Newsletters Forms",
            "title": "Smart Marketing SMS and Newsletters Forms vulnerability",
            "summary": "The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the plugin's sync feature to be enabled (options['enabled']) and get_option('egoi_mapping') to be truthy, both of which reflect ordinary configured states for the plugin's core contact mapping functionality.",
            "updated_at": "2026-09-12T08:16:24.103",
            "published_at": "2026-09-12T08:16:24.103",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 5.1.24 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the plugin's sync feature to be enabled (options['enabled']) and get_option('egoi_mapping') to be truthy, both of which reflect ordinary configured states for the plugin's core contact mapping functionality.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/smart-marketing-for-wp/trunk/admin/class-egoi-for-wp-listener.php#L132",
                "https://plugins.trac.wordpress.org/browser/smart-marketing-for-wp/trunk/admin/class-egoi-for-wp-listener.php#L183",
                "https://plugins.trac.wordpress.org/browser/smart-marketing-for-wp/trunk/includes/class-egoi-for-wp.php#L841",
                "https://plugins.trac.wordpress.org/browser/smart-marketing-for-wp/trunk/includes/class-egoi-for-wp.php#L908",
                "https://plugins.trac.wordpress.org/changeset?reponame=&old=3663923%40smart-marketing-for-wp&new=3663923%40smart-marketing-for-wp",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/f14e3f20-b022-49f8-89b0-acca9b950cb8?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T08:16:24.103",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77161"
                }
            ]
        },
        {
            "id": "CVE-2026-77150",
            "vendor": "unitecms",
            "product": "Unlimited Elements For Elementor",
            "title": "Unlimited Elements For Elementor vulnerability",
            "summary": "The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The show_preview AJAX action is registered for unauthenticated users and is gated only by a nonce, which an unauthenticated attacker can retrieve by loading any publicly accessible page that emits it.",
            "updated_at": "2026-09-11T04:17:49.493",
            "published_at": "2026-09-11T04:17:49.493",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.0.16 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The show_preview AJAX action is registered for unauthenticated users and is gated only by a nonce, which an unauthenticated attacker can retrieve by loading any publicly accessible page that emits it.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/framework/functions.php#L53",
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_actions.class.php#L379",
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_actions.class.php#L42",
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_addon.class.php#L272",
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_addons.class.php#L1437",
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_operations.class.php#L212",
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/provider/provider_admin.class.php#L305",
                "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3661670%40unlimited-elements-for-elementor%2Ftrunk&old=3628543%40unlimited-elements-for-elementor%2Ftrunk&sfp_email=&sfph_mail=",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/3deeb8f5-d9a7-43cb-9068-a921ed6db2bc?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T04:17:49.493",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77150"
                }
            ]
        },
        {
            "id": "CVE-2026-77106",
            "vendor": "Commvault",
            "product": "Commvault Cloud",
            "title": "Commvault Cloud vulnerability",
            "summary": "Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.",
            "updated_at": "2026-09-09T05:18:09.460",
            "published_at": "2026-09-08T13:17:26.517",
            "cvss": 7.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.46.0 through 11.46.19 (custom); 11.44.0 through 11.44.19 (custom); 11.40.0 through 11.40.71 (custom); 11.36.0 through 11.36.122 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-862",
            "what_happened": "Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://documentation.commvault.com/securityadvisories/CV_2026_08_8.html"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T13:17:26.517",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77106"
                }
            ]
        },
        {
            "id": "CVE-2026-77105",
            "vendor": "Commvault",
            "product": "Commvault Cloud",
            "title": "Commvault Cloud vulnerability",
            "summary": "CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.",
            "updated_at": "2026-09-09T05:18:09.293",
            "published_at": "2026-09-08T13:17:26.393",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.46.0 through 11.46.19 (custom); 11.44.0 through 11.44.19 (custom); 11.40.0 through 11.40.71 (custom); 11.36.0 through 11.36.122 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-347",
            "what_happened": "CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://documentation.commvault.com/securityadvisories/CV_2026_08_7.html"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T13:17:26.393",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77105"
                }
            ]
        },
        {
            "id": "CVE-2026-77089",
            "vendor": "Commvault",
            "product": "Commvault Cloud",
            "title": "Commvault Cloud vulnerability",
            "summary": "Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.",
            "updated_at": "2026-09-09T05:18:09.163",
            "published_at": "2026-09-08T13:17:25.227",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.46.0 through 11.46.19 (custom); 11.44.0 through 11.44.19 (custom); 11.40.0 through 11.40.71 (custom); 11.36.0 through 11.36.122 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://documentation.commvault.com/securityadvisories/CV_2026_07_1.html"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T13:17:25.227",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77089"
                }
            ]
        },
        {
            "id": "CVE-2026-77006",
            "vendor": "Unknown",
            "product": "WebTotem Backups",
            "title": "WebTotem Backups vulnerability",
            "summary": "The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.",
            "updated_at": "2026-09-12T16:16:38.670",
            "published_at": "2026-09-12T06:16:24.733",
            "cvss": 9.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.0.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-73",
            "what_happened": "The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/71bc08cb-681c-44bd-b6a0-bb5c58e31653/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:24.733",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77006"
                }
            ]
        },
        {
            "id": "CVE-2026-77005",
            "vendor": "Unknown",
            "product": "CODE MONKEYS PROPOSALS",
            "title": "CODE MONKEYS PROPOSALS vulnerability",
            "summary": "The CODE MONKEYS PROPOSALS  WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.",
            "updated_at": "2026-09-12T16:16:38.523",
            "published_at": "2026-09-12T06:16:24.623",
            "cvss": 9.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.0.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-73",
            "what_happened": "The CODE MONKEYS PROPOSALS  WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on the server, which can lead to a site takeover.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/b9340774-84c2-41ec-a770-0123dd5608c2/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:24.623",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77005"
                }
            ]
        },
        {
            "id": "CVE-2026-76968",
            "vendor": "SAP_SE",
            "product": "SAP Web Dispatcher, Internet Communication Manager and SAP Content Server",
            "title": "SAP Web Dispatcher, Internet Communication Manager and SAP Content Server vulnerability",
            "summary": "SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.",
            "updated_at": "2026-09-08T01:17:55.283",
            "published_at": "2026-09-08T01:17:55.283",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "KRNL64NUC 7.22; 7.22EXT; KRNL64UC 7.22; 7.53; WEBDISP 7.22_EXT; 7.54; 7.77; 7.93; 9.16; CONTSERV 7.53; KERNEL 7.22; 9.18; 9.19; 9.20",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-497",
            "what_happened": "SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used to facilitate further attacks. This vulnerability has a high impact on the confidentiality of the application, with no impact on integrity or availability.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3750721",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:55.283",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76968"
                }
            ]
        },
        {
            "id": "CVE-2026-76967",
            "vendor": "SAP_SE",
            "product": "SAP NetWeaver Business Client",
            "title": "SAP NetWeaver Business Client vulnerability",
            "summary": "SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This results in a high impact on confidentiality, integrity and availability of the application.",
            "updated_at": "2026-09-09T05:18:09.043",
            "published_at": "2026-09-08T01:17:55.170",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "BC-WD-CLT-BUS 8.00; 8.10",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This results in a high impact on confidentiality, integrity and availability of the application.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3784138",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:55.170",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76967"
                }
            ]
        },
        {
            "id": "CVE-2026-76963",
            "vendor": "SAP_SE",
            "product": "SAP NetWeaver and ABAP Platform",
            "title": "SAP NetWeaver and ABAP Platform vulnerability",
            "summary": "Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details, resulting in low impact on confidentiality while integrity and availability remain unaffected.",
            "updated_at": "2026-09-08T01:17:55.040",
            "published_at": "2026-09-08T01:17:55.040",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "SAP_BASIS 700; SAP_BASIS 701; SAP_BASIS 702; SAP_BASIS 731; SAP_BASIS 740; SAP_BASIS 750; SAP_BASIS 751; SAP_BASIS 752; SAP_BASIS 753; SAP_BASIS 754; SAP_BASIS 755; SAP_BASIS 756; SAP_BASIS 757; SAP_BASIS 758",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details, resulting in low impact on confidentiality while integrity and availability remain unaffected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3772838",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:55.040",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76963"
                }
            ]
        },
        {
            "id": "CVE-2026-76962",
            "vendor": "SAP_SE",
            "product": "SAP S/4HANA (Manage Bank Chains app)",
            "title": "SAP S/4HANA (Manage Bank Chains app) vulnerability",
            "summary": "SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.",
            "updated_at": "2026-09-08T01:17:54.917",
            "published_at": "2026-09-08T01:17:54.917",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "S4CORE 107; 108; 109",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3657599",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:54.917",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76962"
                }
            ]
        },
        {
            "id": "CVE-2026-76961",
            "vendor": "SAP_SE",
            "product": "SAP S/4HANA (Finance for Advanced Payment Management)",
            "title": "SAP S/4HANA (Finance for Advanced Payment Management) vulnerability",
            "summary": "SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.",
            "updated_at": "2026-09-08T01:17:54.793",
            "published_at": "2026-09-08T01:17:54.793",
            "cvss": 3.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "S4CORE 108",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-352",
            "what_happened": "SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3371336",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:54.793",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76961"
                }
            ]
        },
        {
            "id": "CVE-2026-76960",
            "vendor": "SAP_SE",
            "product": "SAP S/4HANA (Finance for Advanced Payment Management)",
            "title": "SAP S/4HANA (Finance for Advanced Payment Management) vulnerability",
            "summary": "SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.",
            "updated_at": "2026-09-08T01:17:54.680",
            "published_at": "2026-09-08T01:17:54.680",
            "cvss": 3.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "S4CORE 105; 106; 107",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-352",
            "what_happened": "SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3365276",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:54.680",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76960"
                }
            ]
        },
        {
            "id": "CVE-2026-76959",
            "vendor": "SAP_SE",
            "product": "SAP S/4HANA (Finance for Advanced Payment Management)",
            "title": "SAP S/4HANA (Finance for Advanced Payment Management) vulnerability",
            "summary": "SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.",
            "updated_at": "2026-09-08T01:17:54.560",
            "published_at": "2026-09-08T01:17:54.560",
            "cvss": 4.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "UIAPFI70 800; 900; 901; 902",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-352",
            "what_happened": "SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malicious link or page. If an authenticated victim interacts with it, unintended actions could be triggered on the web server on their behalf. This results in a low impact on confidentiality and integrity. There is no impact on availability.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3365311",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:54.560",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76959"
                }
            ]
        },
        {
            "id": "CVE-2026-76958",
            "vendor": "SAP_SE",
            "product": "SAP Integration Suite",
            "title": "SAP Integration Suite vulnerability",
            "summary": "SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging output, resulting in a high impact on confidentiality. It could also lead to resource exhaustion, causing a low impact on availability. There is no impact on integrity.",
            "updated_at": "2026-09-08T01:17:54.430",
            "published_at": "2026-09-08T01:17:54.430",
            "cvss": 8.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "CloudIntegrationTradingPartnerManagementV2 2.9.2; B2BIntegrationFactoryCloudIntegrationTradingPartnerManagement 1.10.0",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-611",
            "what_happened": "SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging output, resulting in a high impact on confidentiality. It could also lead to resource exhaustion, causing a low impact on availability. There is no impact on integrity.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3792978",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:54.430",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76958"
                }
            ]
        },
        {
            "id": "CVE-2026-76904",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "PostGIS SQL Injection GeoTools",
            "summary": "PostGIS SQL Injection GeoTools",
            "updated_at": "2026-08-26T10:47:23Z",
            "published_at": "2026-08-26T10:47:23Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 191,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · bickZero93/CVE-2026-76904",
                    "author": "bickZero93",
                    "first_seen": "2026-08-26",
                    "last_seen": "2026-08-26T10:47:23Z",
                    "pushed_at": "2026-08-26T10:47:14Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Injection",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "PostGIS SQL Injection GeoTools",
                    "repository_description": "PostGIS SQL Injection GeoTools",
                    "summary": "PostGIS SQL Injection GeoTools",
                    "source": "CVE-Intel",
                    "url": "https://github.com/bickZero93/CVE-2026-76904"
                },
                {
                    "repository": "CVE-Intel · YonLiud/CVE-2026-76904",
                    "author": "YonLiud",
                    "first_seen": "2026-08-16",
                    "last_seen": "2026-08-26T08:47:17Z",
                    "pushed_at": "2026-08-22T20:10:52Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 3,
                    "forks": 1,
                    "topics": [
                        "exploit",
                        "geoserver",
                        "poc",
                        "rce",
                        "zero-day"
                    ],
                    "title": "One-Day POC | GeoServer Unauthenticated SQL injection to complete RCE",
                    "repository_description": "One-Day POC | GeoServer Unauthenticated SQL injection to complete RCE",
                    "summary": "One-Day POC | GeoServer Unauthenticated SQL injection to complete RCE",
                    "source": "CVE-Intel",
                    "url": "https://github.com/YonLiud/CVE-2026-76904"
                }
            ],
            "references": [
                "https://github.com/bickZero93/CVE-2026-76904",
                "https://github.com/YonLiud/CVE-2026-76904"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T10:47:23Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/bickZero93/CVE-2026-76904"
                }
            ]
        },
        {
            "id": "CVE-2026-76827",
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Management for Kubernetes 2.11",
            "title": "Red Hat Advanced Cluster Management for Kubernetes 2.11 vulnerability",
            "summary": "A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.",
            "updated_at": "2026-09-05T18:17:29.027",
            "published_at": "2026-08-19T21:17:39.227",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-693",
            "what_happened": "A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster's indexed search data. This is possible because the delta-sync write paths in search-indexer do not properly restrict UPDATE/DELETE operations to data owned by the calling cluster. An attacker could exploit this by crafting specific user identifiers (UIDs) with a different cluster's prefix.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/errata/RHSA-2026:60387",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/errata/RHSA-2026:60389",
                "https://access.redhat.com/errata/RHSA-2026:60390",
                "https://access.redhat.com/errata/RHSA-2026:60391",
                "https://access.redhat.com/security/cve/CVE-2026-76827",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2519896"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T21:17:39.227",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76827"
                }
            ]
        },
        {
            "id": "CVE-2026-76578",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Exploit for CVE-2026-76578 CVE-2026-76560 CVE-2026-76578",
            "summary": "A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.",
            "updated_at": "2026-09-08T19:08:15.590",
            "published_at": "2026-09-07T13:20:36.850",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 58,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-76578 CVE-2026-76560 CVE-2026-76578",
                    "summary": "Unauthenticated OTP ADD ACI flaw in FreeIPA grants anonymous domain admin rights (CVE-2026-76578).",
                    "what_happened": "Unauthenticated OTP ADD ACI flaw in FreeIPA grants anonymous domain admin rights (CVE-2026-76578).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=EDA76119-7B8C-53D2-A4B1-38396AB1D337",
                        "https://github.com/BrainBob/CVE-2026-76578"
                    ],
                    "repository": "Sploitus",
                    "author": "BrainBob",
                    "first_seen": "2026-09-09T20:26:27",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=EDA76119-7B8C-53D2-A4B1-38396AB1D337"
                },
                {
                    "title": "Exploit for CVE-2026-76578 CVE-2026-76560 CVE-2026-76578",
                    "summary": "Unauthenticated OTP ADD ACI flaw in FreeIPA grants anonymous domain admin rights (CVE-2026-76578).",
                    "what_happened": "Unauthenticated OTP ADD ACI flaw in FreeIPA grants anonymous domain admin rights (CVE-2026-76578).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=EDA76119-7B8C-53D2-A4B1-38396AB1D337",
                        "https://github.com/BrainBob/CVE-2026-76578"
                    ],
                    "repository": "BrainBob/CVE-2026-76578",
                    "author": "BrainBob",
                    "first_seen": "2026-09-09T20:26:27",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/BrainBob/CVE-2026-76578"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=EDA76119-7B8C-53D2-A4B1-38396AB1D337",
                "https://github.com/BrainBob/CVE-2026-76578",
                "https://access.redhat.com/security/cve/CVE-2026-76578",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2519522"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T18:26:27Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=EDA76119-7B8C-53D2-A4B1-38396AB1D337"
                },
                {
                    "at": "2026-09-07T13:20:36.850",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76578"
                }
            ],
            "enrichment_checked_at": "2026-09-09T22:05:34Z",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-76573",
            "vendor": "sc0ttkclark",
            "product": "Pods – Custom Content Types and Fields",
            "title": "Pods – Custom Content Types and Fields vulnerability",
            "summary": "The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'not_found' Shortcode Attribute in all versions up to, and including, 3.3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
            "updated_at": "2026-09-05T09:16:50.010",
            "published_at": "2026-09-05T09:16:50.010",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.3.9.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'not_found' Shortcode Attribute in all versions up to, and including, 3.3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/pods/tags/3.3.9.1/classes/PodsInit.php#L514",
                "https://plugins.trac.wordpress.org/browser/pods/tags/3.3.9.1/includes/general.php#L1399",
                "https://plugins.trac.wordpress.org/browser/pods/tags/3.3.9.1/includes/general.php#L2535",
                "https://plugins.trac.wordpress.org/browser/pods/tags/3.3.9.1/includes/general.php#L2539",
                "https://plugins.trac.wordpress.org/changeset?reponame=&old=3674726%40pods&new=3674726%40pods",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/82ca2dfc-a820-49d7-bb73-38dbb8406841?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T09:16:50.010",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76573"
                }
            ]
        },
        {
            "id": "CVE-2026-76560",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
            "title": "Red Hat Enterprise Linux 7 Extended Lifecycle Support vulnerability",
            "summary": "A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.",
            "updated_at": "2026-09-08T03:17:19.137",
            "published_at": "2026-09-07T14:16:54.197",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 57,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-76578 CVE-2026-76560 CVE-2026-76578",
                    "summary": "Unauthenticated OTP ADD ACI flaw in FreeIPA grants anonymous domain admin rights (CVE-2026-76578).",
                    "what_happened": "Unauthenticated OTP ADD ACI flaw in FreeIPA grants anonymous domain admin rights (CVE-2026-76578).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=EDA76119-7B8C-53D2-A4B1-38396AB1D337",
                        "https://github.com/BrainBob/CVE-2026-76578"
                    ],
                    "repository": "Sploitus",
                    "author": "BrainBob",
                    "first_seen": "2026-09-09T20:26:27",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=EDA76119-7B8C-53D2-A4B1-38396AB1D337"
                },
                {
                    "title": "Exploit for CVE-2026-76578 CVE-2026-76560 CVE-2026-76578",
                    "summary": "Unauthenticated OTP ADD ACI flaw in FreeIPA grants anonymous domain admin rights (CVE-2026-76578).",
                    "what_happened": "Unauthenticated OTP ADD ACI flaw in FreeIPA grants anonymous domain admin rights (CVE-2026-76578).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=EDA76119-7B8C-53D2-A4B1-38396AB1D337",
                        "https://github.com/BrainBob/CVE-2026-76578"
                    ],
                    "repository": "BrainBob/CVE-2026-76578",
                    "author": "BrainBob",
                    "first_seen": "2026-09-09T20:26:27",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/BrainBob/CVE-2026-76578"
                }
            ],
            "references": [
                "https://access.redhat.com/security/cve/CVE-2026-76560",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2519521",
                "https://access.redhat.com/errata/RHSA-2026:64771",
                "https://sploitus.com/exploit?id=EDA76119-7B8C-53D2-A4B1-38396AB1D337",
                "https://github.com/BrainBob/CVE-2026-76578"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:54.197",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76560"
                }
            ]
        },
        {
            "id": "CVE-2026-76461",
            "vendor": "Cisco",
            "product": "Cisco Secure Email",
            "title": "Cisco Secure Email vulnerability",
            "summary": "A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.\r\n\r\nThis vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.",
            "updated_at": "2026-09-15T04:18:15.100",
            "published_at": "2026-09-14T17:17:51.113",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "14.0.0-698; 13.5.1-277; 13.0.0-392; 14.2.0-620; 13.0.5-007; 13.5.4-038; 14.2.1-020; 14.3.0-032; 15.0.0-104; 15.0.1-030; 15.5.0-048; 15.5.1-055; 15.5.2-018; 16.0.0-050; 15.0.3-002; 16.0.0-054; 15.5.3-022; 16.0.1-017; 15.5.4-012; 16.0.4-016; 15.0.5-016; 16.0.2-112; 16.0.3-044",
            "fixed": "See vendor advisory",
            "source_count": 18,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.\r\n\r\nThis vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "title": "Exploit for SQL Injection in Cisco Asyncos CVE-2026-76461",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-89",
                    "references": [
                        "https://sploitus.com/exploit?id=03C95DC1-6684-5667-B855-F38C831D669E",
                        "https://github.com/fevar54/CVE-2026-76461-Detection-Kit-"
                    ],
                    "repository": "Sploitus",
                    "author": "fevar54",
                    "first_seen": "2026-09-15T14:45:53",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=03C95DC1-6684-5667-B855-F38C831D669E"
                },
                {
                    "title": "Exploit for SQL Injection in Cisco Asyncos CVE-2026-76461",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-89",
                    "references": [
                        "https://sploitus.com/exploit?id=03C95DC1-6684-5667-B855-F38C831D669E",
                        "https://github.com/fevar54/CVE-2026-76461-Detection-Kit-"
                    ],
                    "repository": "fevar54/CVE-2026-76461-Detection-Kit-",
                    "author": "fevar54",
                    "first_seen": "2026-09-15T14:45:53",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/fevar54/CVE-2026-76461-Detection-Kit-"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76461",
                "https://sploitus.com/exploit?id=03C95DC1-6684-5667-B855-F38C831D669E",
                "https://github.com/fevar54/CVE-2026-76461-Detection-Kit-"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T17:17:51.113",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76461"
                },
                {
                    "at": "2026-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-76460",
            "vendor": "Cisco",
            "product": "Identity Services Engine",
            "title": "Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability",
            "summary": "Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.",
            "updated_at": "2026-09-15T22:00:00Z",
            "published_at": "2026-09-15T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-76443",
            "vendor": "Cisco",
            "product": "Cisco Secure Email",
            "title": "Cisco Secure Email vulnerability",
            "summary": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76443 are related to issues with improper neutralization that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.",
            "updated_at": "2026-09-15T04:18:14.493",
            "published_at": "2026-09-14T17:17:50.970",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0-698; 13.5.1-277; 13.0.0-392; 14.2.0-620; 13.0.5-007; 13.5.4-038; 14.2.1-020; 14.3.0-032; 15.0.0-104; 15.0.1-030; 15.5.0-048; 15.5.1-055; 15.5.2-018; 16.0.0-050; 15.0.3-002; 16.0.0-054; 15.5.3-022; 16.0.1-017; 15.5.4-012; 16.0.4-016; 15.0.5-016; 16.0.2-112; 16.0.3-044; 13.6.2-023; 13.6.2-078; 13.0.0-249; 13.0.0-277; 13.8.1-052; 13.8.1-068; 13.8.1-074; 14.0.0-404; 12.8.1-002; 14.1.0-227; 13.6.1-201; 14.2.0-203; 14.2.0-212; 12.8.1-021; 13.8.1-108; 14.2.0-224; 14.3.0-120; 15.0.0-334; 15.5.1-024; 15.5.1-029; 15.5.2-005; 16.0.0-195; 15.5.3-017; 16.0.1-010; 15.0.1-035; 16.0.2-088; 15.5.4-007; 15.0.2-007; 16.0.4-010; 16.0.3-016",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-707",
            "what_happened": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76443 are related to issues with improper neutralization that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T17:17:50.970",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76443"
                }
            ]
        },
        {
            "id": "CVE-2026-76442",
            "vendor": "Cisco",
            "product": "Cisco Secure Email",
            "title": "Cisco Secure Email vulnerability",
            "summary": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76442 are related to issues with improper validation of specified quantity in input that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-1284.",
            "updated_at": "2026-09-16T04:18:41.067",
            "published_at": "2026-09-14T17:17:50.810",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0-698; 13.5.1-277; 13.0.0-392; 14.2.0-620; 13.0.5-007; 13.5.4-038; 14.2.1-020; 14.3.0-032; 15.0.0-104; 15.0.1-030; 15.5.0-048; 15.5.1-055; 15.5.2-018; 16.0.0-050; 15.0.3-002; 16.0.0-054; 15.5.3-022; 16.0.1-017; 15.5.4-012; 16.0.4-016; 15.0.5-016; 16.0.2-112; 16.0.3-044; 16.5.0-780; 13.6.2-023; 13.6.2-078; 13.0.0-249; 13.0.0-277; 13.8.1-052; 13.8.1-068; 13.8.1-074; 14.0.0-404; 12.8.1-002; 14.1.0-227; 13.6.1-201; 14.2.0-203; 14.2.0-212; 12.8.1-021; 13.8.1-108; 14.2.0-224; 14.3.0-120; 15.0.0-334; 15.5.1-024; 15.5.1-029; 15.5.2-005; 16.0.0-195; 15.5.3-017; 16.0.1-010; 15.0.1-035; 16.0.2-088; 15.5.4-007; 15.0.2-007; 16.0.4-010; 16.0.3-016; 16.5.0-429",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1284",
            "what_happened": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76442 are related to issues with improper validation of specified quantity in input that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-1284.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm",
                "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T17:17:50.810",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76442"
                }
            ]
        },
        {
            "id": "CVE-2026-76441",
            "vendor": "Cisco",
            "product": "Cisco Secure Email and Web Manager",
            "title": "Cisco Secure Email and Web Manager vulnerability",
            "summary": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76441 are related to issues with improper access control that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.",
            "updated_at": "2026-09-15T04:18:13.277",
            "published_at": "2026-09-14T17:17:50.673",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "13.6.2-023; 13.6.2-078; 13.0.0-249; 13.0.0-277; 13.8.1-052; 13.8.1-068; 13.8.1-074; 14.0.0-404; 12.8.1-002; 14.1.0-227; 13.6.1-201; 14.2.0-203; 14.2.0-212; 12.8.1-021; 13.8.1-108; 14.2.0-224; 14.3.0-120; 15.0.0-334; 15.5.1-024; 15.5.1-029; 15.5.2-005; 16.0.0-195; 15.5.3-017; 16.0.1-010; 15.0.1-035; 16.0.2-088; 15.5.4-007; 15.0.2-007; 16.0.4-010; 16.0.3-016",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76441 are related to issues with improper access control that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T17:17:50.673",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76441"
                }
            ]
        },
        {
            "id": "CVE-2026-76440",
            "vendor": "Cisco",
            "product": "Cisco Secure Email",
            "title": "Cisco Secure Email vulnerability",
            "summary": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76440 are related to path traversal issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-23.",
            "updated_at": "2026-09-15T04:18:12.660",
            "published_at": "2026-09-14T17:17:50.520",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0-698; 13.5.1-277; 13.0.0-392; 14.2.0-620; 13.0.5-007; 13.5.4-038; 14.2.1-020; 14.3.0-032; 15.0.0-104; 15.0.1-030; 15.5.0-048; 15.5.1-055; 15.5.2-018; 16.0.0-050; 15.0.3-002; 16.0.0-054; 15.5.3-022; 16.0.1-017; 15.5.4-012; 16.0.4-016; 15.0.5-016; 16.0.2-112; 16.0.3-044; 15.5.5-014; 13.6.2-023; 13.6.2-078; 13.0.0-249; 13.0.0-277; 13.8.1-052; 13.8.1-068; 13.8.1-074; 14.0.0-404; 12.8.1-002; 14.1.0-227; 13.6.1-201; 14.2.0-203; 14.2.0-212; 12.8.1-021; 13.8.1-108; 14.2.0-224; 14.3.0-120; 15.0.0-334; 15.5.1-024; 15.5.1-029; 15.5.2-005; 16.0.0-195; 15.5.3-017; 16.0.1-010; 15.0.1-035; 16.0.2-088; 15.5.4-007; 15.0.2-007; 16.0.4-010; 16.0.3-016; 16.5.0-429; 15.5.5-006",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-23",
            "what_happened": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-76440 are related to path traversal issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-23.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T17:17:50.520",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76440"
                }
            ]
        },
        {
            "id": "CVE-2026-76245",
            "vendor": "eidetic-labs",
            "product": "stigmem",
            "title": "stigmem vulnerability",
            "summary": "stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired. This affects the availability and reliability of authenticated federation flows on nodes using federation peer authentication paths. The issue is fixed in 0.9.0a2, which uses the canonical millisecond-based validation path.",
            "updated_at": "2026-09-11T18:28:15.520",
            "published_at": "2026-08-19T14:17:56.957",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.9.0a2 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-345",
            "what_happened": "stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired. This affects the availability and reliability of authenticated federation flows on nodes using federation peer authentication paths. The issue is fixed in 0.9.0a2, which uses the canonical millisecond-based validation path.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/eidetic-labs/stigmem/security/advisories/GHSA-xh5j-xjfq-qvvx",
                "https://www.vulncheck.com/advisories/stigmem-federation-peer-token-timestamp-validation-bypass"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T14:17:56.957",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76245"
                }
            ]
        },
        {
            "id": "CVE-2026-76244",
            "vendor": "eidetic-labs",
            "product": "stigmem",
            "title": "stigmem vulnerability",
            "summary": "stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while binding federation to non-loopback addresses expose federation traffic to cleartext interception and man-in-the-middle attacks.",
            "updated_at": "2026-09-11T18:28:15.520",
            "published_at": "2026-08-19T14:17:56.827",
            "cvss": 9.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.9.0a2 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-319",
            "what_happened": "stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while binding federation to non-loopback addresses expose federation traffic to cleartext interception and man-in-the-middle attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/eidetic-labs/stigmem/security/advisories/GHSA-jmfc-hfjq-pxcp",
                "https://www.vulncheck.com/advisories/stigmem-node-insecure-federation-transport-configuration"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T14:17:56.827",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76244"
                }
            ]
        },
        {
            "id": "CVE-2026-76242",
            "vendor": "eidetic-labs",
            "product": "stigmem",
            "title": "stigmem vulnerability",
            "summary": "stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network where initial registration can be intercepted or misdirected, an attacker can register a malicious peer and gain access to or tamper with federation traffic. Fixed in 0.9.0a2, which introduces a pending approval flow requiring administrator fingerprint verification before peer tokens are accepted.",
            "updated_at": "2026-09-11T18:28:15.520",
            "published_at": "2026-08-19T14:17:56.567",
            "cvss": 9.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.9.0a2 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network where initial registration can be intercepted or misdirected, an attacker can register a malicious peer and gain access to or tamper with federation traffic. Fixed in 0.9.0a2, which introduces a pending approval flow requiring administrator fingerprint verification before peer tokens are accepted.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/eidetic-labs/stigmem/security/advisories/GHSA-9vp8-3hmv-8fgh",
                "https://www.vulncheck.com/advisories/stigmem-federation-peer-registration-authentication-bypass"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T14:17:56.567",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76242"
                }
            ]
        },
        {
            "id": "CVE-2026-76241",
            "vendor": "eidetic-labs",
            "product": "stigmem",
            "title": "stigmem vulnerability",
            "summary": "stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into an environment where plugin directories are writable by less-trusted users, unsigned (potentially malicious) plugin code could be loaded and executed, resulting in arbitrary code execution. Fixed in 0.9.0a2, which requires a second explicit acknowledgment to disable signature enforcement.",
            "updated_at": "2026-09-11T18:28:15.520",
            "published_at": "2026-08-19T14:17:56.430",
            "cvss": 7.3,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.9.0a2 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-494",
            "what_happened": "stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into an environment where plugin directories are writable by less-trusted users, unsigned (potentially malicious) plugin code could be loaded and executed, resulting in arbitrary code execution. Fixed in 0.9.0a2, which requires a second explicit acknowledgment to disable signature enforcement.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/eidetic-labs/stigmem/security/advisories/GHSA-w7pm-9g55-mxfm",
                "https://www.vulncheck.com/advisories/stigmem-plugin-signature-enforcement-bypass-via-configuration"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T14:17:56.430",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76241"
                }
            ]
        },
        {
            "id": "CVE-2026-76240",
            "vendor": "eidetic-labs",
            "product": "stigmem",
            "title": "stigmem vulnerability",
            "summary": "stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a schema name were derived from tenant, request, or user input. Fixed in 0.9.0a2, which adds identifier quoting and validation. As a workaround, only configure schema names from trusted deployment configuration.",
            "updated_at": "2026-09-11T18:28:15.520",
            "published_at": "2026-08-19T14:17:56.300",
            "cvss": 7.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.9.0a2 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a schema name were derived from tenant, request, or user input. Fixed in 0.9.0a2, which adds identifier quoting and validation. As a workaround, only configure schema names from trusted deployment configuration.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/eidetic-labs/stigmem/security/advisories/GHSA-9pc9-4crj-mhpj",
                "https://www.vulncheck.com/advisories/stigmem-postgres-sql-injection-via-schema-identifier"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T14:17:56.300",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76240"
                }
            ]
        },
        {
            "id": "CVE-2026-76236",
            "vendor": "eidetic-labs",
            "product": "stigmem-node",
            "title": "stigmem-node vulnerability",
            "summary": "stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to \"default\" instead of the caller's tenant, allowing deletion records to be written to the wrong tenant, and the read-suppression path (_get_tombstone_filter and the tombstone scope cache) lacked a tenant_id predicate, so tombstone suppression was applied tenant-blind across fact queries and provenance reads. As a result, a tenant's deletion could be attributed to the wrong tenant and tombstone suppression could either hide facts belonging to other tenants or fail to hide facts within the correct tenant, undermining data isolation and RTBF guarantees. The issue is exploitable only on multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant; single-tenant deployments are unaffected. Fixed in 0.9.0a12.",
            "updated_at": "2026-09-11T18:28:15.520",
            "published_at": "2026-08-19T14:17:54.810",
            "cvss": 7.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.9.0a12 (python)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to \"default\" instead of the caller's tenant, allowing deletion records to be written to the wrong tenant, and the read-suppression path (_get_tombstone_filter and the tombstone scope cache) lacked a tenant_id predicate, so tombstone suppression was applied tenant-blind across fact queries and provenance reads. As a result, a tenant's deletion could be attributed to the wrong tenant and tombstone suppression could either hide facts belonging to other tenants or fail to hide facts within the correct tenant, undermining data isolation and RTBF guarantees. The issue is exploitable only on multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant; single-tenant deployments are unaffected. Fixed in 0.9.0a12.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/eidetic-labs/stigmem/security/advisories/GHSA-x26h-xmv8-gxf7",
                "https://www.vulncheck.com/advisories/stigmem-before-0a12-cross-tenant-bola-via-tombstones"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T14:17:54.810",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76236"
                }
            ]
        },
        {
            "id": "CVE-2026-76191",
            "vendor": "Adobe",
            "product": "Adobe Animate 2023",
            "title": "Adobe Animate 2023 vulnerability",
            "summary": "Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.",
            "updated_at": "2026-09-15T13:44:36.537",
            "published_at": "2026-09-08T18:20:33.240",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 23.0.16 (semver); 0 through 24.0.14 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://helpx.adobe.com/security/products/animate/apsb26-132.html"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:33.240",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76191"
                }
            ]
        },
        {
            "id": "CVE-2026-76169",
            "vendor": "fastify",
            "product": "fastify",
            "title": "fastify vulnerability",
            "summary": "fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated handlers dispatches malformed paths through a single shared handler pointer before URL decoding, ignoring the prefix and skipping the selected handler's normal lifecycle. An unauthenticated attacker can therefore reach an authentication-protected private fallback through an unrelated public prefix and read its full response, bypassing the authentication hook and breaking prefix encapsulation. Users should upgrade to fastify 5.12.2 or later.",
            "updated_at": "2026-09-15T20:07:46.700",
            "published_at": "2026-09-04T10:17:12.020",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 5.12.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-288",
            "what_happened": "fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different sibling plugin, and invoke it without the preHandler hook declared for that handler. The internal not-found router for encapsulated handlers dispatches malformed paths through a single shared handler pointer before URL decoding, ignoring the prefix and skipping the selected handler's normal lifecycle. An unauthenticated attacker can therefore reach an authentication-protected private fallback through an unrelated public prefix and read its full response, bypassing the authentication hook and breaking prefix encapsulation. Users should upgrade to fastify 5.12.2 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/fastify/fastify/security/advisories/GHSA-p68q-wchp-6fh7"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T10:17:12.020",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76169"
                }
            ]
        },
        {
            "id": "CVE-2026-76161",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "summary": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "updated_at": "2026-09-05T23:17:41.270",
            "published_at": "2026-09-05T23:17:41.270",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [],
            "timeline": [
                {
                    "at": "2026-09-05T23:17:41.270",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76161"
                }
            ]
        },
        {
            "id": "CVE-2026-76160",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "summary": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "updated_at": "2026-09-05T23:17:41.177",
            "published_at": "2026-09-05T23:17:41.177",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [],
            "timeline": [
                {
                    "at": "2026-09-05T23:17:41.177",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76160"
                }
            ]
        },
        {
            "id": "CVE-2026-76139",
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Management for Kubernetes 2.11",
            "title": "Red Hat Advanced Cluster Management for Kubernetes 2.11 vulnerability",
            "summary": "A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to unauthorized access to build resources and potential compromise of the resulting operator bundle.",
            "updated_at": "2026-09-05T15:17:31.240",
            "published_at": "2026-08-19T21:17:38.070",
            "cvss": 8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-829",
            "what_happened": "A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to unauthorized access to build resources and potential compromise of the resulting operator bundle.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:60399",
                "https://access.redhat.com/errata/RHSA-2026:60400",
                "https://access.redhat.com/errata/RHSA-2026:60401",
                "https://access.redhat.com/errata/RHSA-2026:60402",
                "https://access.redhat.com/errata/RHSA-2026:60403",
                "https://access.redhat.com/errata/RHSA-2026:60404",
                "https://access.redhat.com/security/cve/CVE-2026-76139",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2519852"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T21:17:38.070",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76139"
                }
            ]
        },
        {
            "id": "CVE-2026-76059",
            "vendor": "IBM",
            "product": "Langflow OSS",
            "title": "Langflow OSS vulnerability",
            "summary": "IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias tracking; the resolved value was never checked against the dangerous callable blocklist due to the logic error. If the crafted component reached the runtime execution path, the attacker could cause arbitrary operating system commands to execute on the server in-process, with the privileges of the running service.",
            "updated_at": "2026-09-12T04:16:37.820",
            "published_at": "2026-09-10T22:16:59.590",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through 1.11.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-693",
            "what_happened": "IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias tracking; the resolved value was never checked against the dangerous callable blocklist due to the logic error. If the crafted component reached the runtime execution path, the attacker could cause arbitrary operating system commands to execute on the server in-process, with the privileges of the running service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286666"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:16:59.590",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-76059"
                }
            ]
        },
        {
            "id": "CVE-2026-75816",
            "vendor": "shabti",
            "product": "Frontend Admin by DynamiApps",
            "title": "Frontend Admin by DynamiApps vulnerability",
            "summary": "The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its current_user_can('edit_post') authorization gate whenever the post ID is non-numeric — such as the string user_1 — allowing unauthenticated form submissions to be routed to arbitrary user records without restriction. This makes it possible for unauthenticated attackers to overwrite any user's registered email address, including an administrator's, and then leverage WordPress's native password-reset flow to fully take over the targeted account.",
            "updated_at": "2026-09-06T03:17:16.607",
            "published_at": "2026-09-06T03:17:16.607",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.29.12 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its current_user_can('edit_post') authorization gate whenever the post ID is non-numeric — such as the string user_1 — allowing unauthenticated form submissions to be routed to arbitrary user records without restriction. This makes it possible for unauthenticated attackers to overwrite any user's registered email address, including an administrator's, and then leverage WordPress's native password-reset flow to fully take over the targeted account.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/fields/user/class-user-email.php#L127",
                "https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/actions/post.php#L1001",
                "https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/actions/post.php#L1224",
                "https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/classes/display.php#L26",
                "https://plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/classes/submit.php#L125",
                "https://plugins.trac.wordpress.org/changeset/3664865/acf-frontend-form-element",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/f1637a3b-7b0f-485d-9d19-4f711f8c671b?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T03:17:16.607",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75816"
                }
            ]
        },
        {
            "id": "CVE-2026-75803",
            "vendor": "OpenSSL",
            "product": "OpenSSL",
            "title": "OpenSSL vulnerability",
            "summary": "Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module.",
            "updated_at": "2026-09-11T21:17:17.823",
            "published_at": "2026-08-25T13:19:29.570",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.0.2 (semver); 3.6.0 through before 3.6.4 (semver); 3.5.0 through before 3.5.8 (semver); 3.4.0 through before 3.4.7 (semver); 3.0.0 through before 3.0.22 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-354",
            "what_happened": "Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\n\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext and\nexpecting the call to check the AEAD tag may accept forged messages.\n\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\n\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after the\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\n\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42",
                "https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b",
                "https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a",
                "https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34",
                "https://github.com/openssl/openssl/commit/bf95f5f772e9362f87b25cfa2f8cb15d984865b9",
                "https://openssl-library.org/news/secadv/20260825.txt"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T13:19:29.570",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75803"
                }
            ]
        },
        {
            "id": "CVE-2026-75800",
            "vendor": "Unknown",
            "product": "Frontegg SAML SSO",
            "title": "Frontegg SAML SSO vulnerability",
            "summary": "The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.",
            "updated_at": "2026-09-12T16:16:38.363",
            "published_at": "2026-09-12T06:16:23.340",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.0.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/be658aa5-8f7f-4938-bf13-b2e6ed3dcf89/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:16:23.340",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75800"
                }
            ]
        },
        {
            "id": "CVE-2026-75793",
            "vendor": "Unknown",
            "product": "SureCart",
            "title": "SureCart vulnerability",
            "summary": "The SureCart  WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.",
            "updated_at": "2026-09-06T11:18:01.323",
            "published_at": "2026-09-06T07:16:43.220",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.7.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "The SureCart  WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account and receive a logged-in session even when registration is disabled.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/d1c2ea43-2643-4cdf-8dfe-e11109266f51/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T07:16:43.220",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75793"
                }
            ]
        },
        {
            "id": "CVE-2026-75650",
            "vendor": "Adobe",
            "product": "Adobe Commerce",
            "title": "Adobe Commerce vulnerability",
            "summary": "Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.",
            "updated_at": "2026-09-09T05:18:07.237",
            "published_at": "2026-09-07T21:17:30.863",
            "cvss": 10,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "0 through 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug (custom); 0 through 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug (custom); 0 through 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug (custom)",
            "fixed": "See vendor advisory",
            "source_count": 30,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1336",
            "what_happened": "Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://helpx.adobe.com/security/products/magento/apsb26-146.html",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-75650"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T21:17:30.863",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75650"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-75624",
            "vendor": "IBM",
            "product": "App Connect Enterprise",
            "title": "App Connect Enterprise vulnerability",
            "summary": "IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.",
            "updated_at": "2026-09-15T04:18:11.977",
            "published_at": "2026-09-10T22:16:59.313",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "13.0.1.0 through 13.0.8.1 (semver); 12.0.1.0 through 12.0.12.27 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286532"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:16:59.313",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75624"
                }
            ]
        },
        {
            "id": "CVE-2026-75604",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-75604 Next.js Windows RCE poc",
            "summary": "CVE-2026-75604 Next.js Windows RCE poc",
            "updated_at": "2026-08-26T12:23:33Z",
            "published_at": "2026-08-26T12:23:33Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 191,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · rafabd1/CVE-2026-75604-poc",
                    "author": "rafabd1",
                    "first_seen": "2026-08-25",
                    "last_seen": "2026-08-26T12:23:33Z",
                    "pushed_at": "2026-08-26T02:23:42Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 13,
                    "forks": 13,
                    "topics": [],
                    "title": "CVE-2026-75604 Next.js Windows RCE poc",
                    "repository_description": "CVE-2026-75604 Next.js Windows RCE poc",
                    "summary": "CVE-2026-75604 Next.js Windows RCE poc",
                    "source": "CVE-Intel",
                    "url": "https://github.com/rafabd1/CVE-2026-75604-poc"
                },
                {
                    "repository": "CVE-Intel · HackSpeak/CVE-2026-75604",
                    "author": "HackSpeak",
                    "first_seen": "2026-08-26",
                    "last_seen": "2026-08-26T11:54:40Z",
                    "pushed_at": "2026-08-26T11:54:05Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 1,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing",
                    "repository_description": "CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing",
                    "summary": "CVE-2026-75604 (Next.js Windows RCE) PoC - unauthenticated RCE via cache path traversal + forged Server Action; for authorized security testing",
                    "source": "CVE-Intel",
                    "url": "https://github.com/HackSpeak/CVE-2026-75604"
                }
            ],
            "references": [
                "https://github.com/rafabd1/CVE-2026-75604-poc",
                "https://github.com/HackSpeak/CVE-2026-75604"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T12:23:33Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/rafabd1/CVE-2026-75604-poc"
                }
            ]
        },
        {
            "id": "CVE-2026-75586",
            "vendor": "unitecms",
            "product": "Unlimited Elements For Elementor",
            "title": "Unlimited Elements For Elementor vulnerability",
            "summary": "The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' Parameter in all versions up to, and including, 2.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The front-end AJAX handler is registered on the public 'wp' action with no nonce, capability, or referer check, and the raw attacker-controlled id value is interpolated verbatim into an exception message that is echoed back without escaping; when the response is served as text/html rather than application/json, the browser parses the injected markup.",
            "updated_at": "2026-09-05T08:16:40.600",
            "published_at": "2026-09-05T08:16:40.600",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.0.17 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' Parameter in all versions up to, and including, 2.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The front-end AJAX handler is registered on the public 'wp' action with no nonce, capability, or referer check, and the raw attacker-controlled id value is interpolated verbatim into an exception message that is echoed back without escaping; when the response is served as text/html rather than application/json, the browser parses the injected markup.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/framework/helper_base.class.php#L44",
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_filters_process.class.php#L4083",
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_form.class.php#L1159",
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_form.class.php#L179",
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/provider/core/unlimited_elements/helper_provider_core.class.php#L746",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/522bdd65-8077-4cd4-800a-e6ef9a982d33?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:16:40.600",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75586"
                }
            ]
        },
        {
            "id": "CVE-2026-75569",
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1",
            "title": "multicluster engine for Kubernetes 2.1 vulnerability",
            "summary": "A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to the distribution of malicious software.",
            "updated_at": "2026-09-07T19:17:28.130",
            "published_at": "2026-08-19T21:17:37.287",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-1357",
            "what_happened": "A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to the distribution of malicious software.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:59634",
                "https://access.redhat.com/errata/RHSA-2026:59636",
                "https://access.redhat.com/errata/RHSA-2026:59637",
                "https://access.redhat.com/errata/RHSA-2026:59638",
                "https://access.redhat.com/errata/RHSA-2026:59642",
                "https://access.redhat.com/errata/RHSA-2026:59643",
                "https://access.redhat.com/security/cve/CVE-2026-75569",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2519849"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T21:17:37.287",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75569"
                }
            ]
        },
        {
            "id": "CVE-2026-75538",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond up to about 2 GB.\n\nThis would easily trash the allocated block's allocator metadata footer, and the next block, if any, and most likely cause the BEAM VM to crash. Utilizing this with precision enough to achieve Remote Code Execution would be extremely unfeasible.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to erts from 6.0 before 15.2.7.13, from 16.0 before 16.4.0.6, and from 17.0 before 17.0.6. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown.",
            "updated_at": "2026-09-08T02:17:27.870",
            "published_at": "2026-09-01T15:17:26.853",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 6.0 through before 15.2.7.13 (otp); 16.0 through before 16.4.0.6 (otp); 17.0 through before 17.0.6 (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before 08e8efdba8500d2d6f54c6b1de1492b228017c9b (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond up to about 2 GB.\n\nThis would easily trash the allocated block's allocator metadata footer, and the next block, if any, and most likely cause the BEAM VM to crash. Utilizing this with precision enough to achieve Remote Code Execution would be extremely unfeasible.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to erts from 6.0 before 15.2.7.13, from 16.0 before 16.4.0.6, and from 17.0 before 17.0.6. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-75538.html",
                "https://github.com/erlang/otp/commit/08e8efdba8500d2d6f54c6b1de1492b228017c9b",
                "https://github.com/erlang/otp/security/advisories/GHSA-8m6r-2pj2-25pm",
                "https://osv.dev/vulnerability/EEF-CVE-2026-75538"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:26.853",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75538"
                }
            ]
        },
        {
            "id": "CVE-2026-75501",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Rejected reason: Vendor could not replicate the vul, and reporter is unavailable to comment.",
            "summary": "Rejected reason: Vendor could not replicate the vul, and reporter is unavailable to comment.",
            "updated_at": "2026-09-15T20:17:47.897",
            "published_at": "2026-08-21T15:16:47.070",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Rejected reason: Vendor could not replicate the vul, and reporter is unavailable to comment.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [],
            "timeline": [
                {
                    "at": "2026-08-21T15:16:47.070",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75501"
                }
            ]
        },
        {
            "id": "CVE-2026-75485",
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Management for Kubernetes 2.11",
            "title": "Red Hat Advanced Cluster Management for Kubernetes 2.11 vulnerability",
            "summary": "A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially disclosing sensitive authentication information to anyone with access to the archive.",
            "updated_at": "2026-09-05T18:17:28.897",
            "published_at": "2026-08-18T16:18:20.743",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-532",
            "what_happened": "A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially disclosing sensitive authentication information to anyone with access to the archive.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/errata/RHSA-2026:60387",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/errata/RHSA-2026:60389",
                "https://access.redhat.com/errata/RHSA-2026:60390",
                "https://access.redhat.com/errata/RHSA-2026:60391",
                "https://access.redhat.com/security/cve/CVE-2026-75485",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2517905"
            ],
            "timeline": [
                {
                    "at": "2026-08-18T16:18:20.743",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75485"
                }
            ]
        },
        {
            "id": "CVE-2026-75134",
            "vendor": "SEOWriting",
            "product": "SEOWriting",
            "title": "SEOWriting vulnerability",
            "summary": "SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. Attackers can store crafted JavaScript payloads in post content that execute when the affected post is viewed or previewed by higher-privileged users, potentially leading to privilege escalation or account compromise.",
            "updated_at": "2026-09-14T21:07:11.883",
            "published_at": "2026-09-02T20:17:36.577",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.12.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist that explicitly permits the onload event handler on iframe elements. Attackers can store crafted JavaScript payloads in post content that execute when the affected post is viewed or previewed by higher-privileged users, potentially leading to privilege escalation or account compromise.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Elymaro/CVE/blob/main/WordPress/CVE-2026-75134.md",
                "https://wordpress.org/plugins/seowriting/",
                "https://www.vulncheck.com/advisories/seowriting-wordpress-plugin-stored-xss-via-iframe-onload"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T20:17:36.577",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75134"
                }
            ]
        },
        {
            "id": "CVE-2026-75051",
            "vendor": "JetBrains",
            "product": "YouTrack",
            "title": "YouTrack vulnerability",
            "summary": "In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible",
            "updated_at": "2026-09-15T16:14:58.900",
            "published_at": "2026-08-17T16:17:52.213",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2026.2.17917 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jetbrains.com/privacy-security/issues-fixed/"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T16:17:52.213",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75051"
                }
            ]
        },
        {
            "id": "CVE-2026-75050",
            "vendor": "JetBrains",
            "product": "YouTrack",
            "title": "YouTrack vulnerability",
            "summary": "In JetBrains YouTrack before 2026.1.13901, \n2026.2.17950 doS attack was possible via crafted type parameters",
            "updated_at": "2026-09-15T17:45:36.590",
            "published_at": "2026-08-17T16:17:52.097",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2026.1.13901, \n2026.2.17950 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "In JetBrains YouTrack before 2026.1.13901, \n2026.2.17950 doS attack was possible via crafted type parameters",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jetbrains.com/privacy-security/issues-fixed/"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T16:17:52.097",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75050"
                }
            ]
        },
        {
            "id": "CVE-2026-75049",
            "vendor": "JetBrains",
            "product": "YouTrack",
            "title": "YouTrack vulnerability",
            "summary": "In JetBrains YouTrack before 2026.1.13903, \n2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint",
            "updated_at": "2026-09-15T17:49:19.917",
            "published_at": "2026-08-17T16:17:51.987",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2026.1.13903, \n2026.2.17950 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "In JetBrains YouTrack before 2026.1.13903, \n2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jetbrains.com/privacy-security/issues-fixed/"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T16:17:51.987",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75049"
                }
            ]
        },
        {
            "id": "CVE-2026-75048",
            "vendor": "JetBrains",
            "product": "YouTrack",
            "title": "YouTrack vulnerability",
            "summary": "In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible",
            "updated_at": "2026-09-15T17:48:37.563",
            "published_at": "2026-08-17T16:17:51.870",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2026.2.18068 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jetbrains.com/privacy-security/issues-fixed/"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T16:17:51.870",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75048"
                }
            ]
        },
        {
            "id": "CVE-2026-75047",
            "vendor": "JetBrains",
            "product": "YouTrack",
            "title": "YouTrack vulnerability",
            "summary": "In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint",
            "updated_at": "2026-09-15T17:47:56.213",
            "published_at": "2026-08-17T16:17:51.757",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2026.2.18177 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-409",
            "what_happened": "In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jetbrains.com/privacy-security/issues-fixed/"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T16:17:51.757",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75047"
                }
            ]
        },
        {
            "id": "CVE-2026-75046",
            "vendor": "JetBrains",
            "product": "YouTrack",
            "title": "YouTrack vulnerability",
            "summary": "In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint",
            "updated_at": "2026-09-15T17:47:29.567",
            "published_at": "2026-08-17T16:17:51.647",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2026.2.18112 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jetbrains.com/privacy-security/issues-fixed/"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T16:17:51.647",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75046"
                }
            ]
        },
        {
            "id": "CVE-2026-75045",
            "vendor": "JetBrains",
            "product": "YouTrack",
            "title": "YouTrack vulnerability",
            "summary": "In JetBrains YouTrack before 2025.3.156085, \n2026.1.13913, \n2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature",
            "updated_at": "2026-09-15T17:46:16.590",
            "published_at": "2026-08-17T16:17:51.530",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2025.3.156085, \n2026.1.13913, \n2026.2.18112 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-288",
            "what_happened": "In JetBrains YouTrack before 2025.3.156085, \n2026.1.13913, \n2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jetbrains.com/privacy-security/issues-fixed/"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T16:17:51.530",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75045"
                }
            ]
        },
        {
            "id": "CVE-2026-75044",
            "vendor": "JetBrains",
            "product": "YouTrack",
            "title": "YouTrack vulnerability",
            "summary": "In JetBrains YouTrack before 2025.3.156085, \n2026.1.13914, \n2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint",
            "updated_at": "2026-09-15T17:46:57.947",
            "published_at": "2026-08-17T16:17:51.410",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2025.3.156085, \n2026.1.13914, \n2026.2.18095 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "In JetBrains YouTrack before 2025.3.156085, \n2026.1.13914, \n2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.jetbrains.com/privacy-security/issues-fixed/"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T16:17:51.410",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75044"
                }
            ]
        },
        {
            "id": "CVE-2026-75018",
            "vendor": "outlawgt",
            "product": "Custom Contact Forms",
            "title": "Custom Contact Forms vulnerability",
            "summary": "The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently force-delete arbitrary posts of any post type (including pages, administrator-authored posts, and WooCommerce products) and write arbitrary ccf_field_* post meta onto any post regardless of ownership or post type. The top-level form ID is checked via edit_post/publish_posts, but the nested fields[].ID and choices[].ID paths processed by _create_and_map_fields() and _create_and_map_choices() carry no equivalent capability or post-type guard, leaving those sinks fully exposed while delete_item() and delete_submission() contain explicit post-type restriction fixes demonstrating the developer's awareness of scoping requirements.",
            "updated_at": "2026-09-05T08:16:40.397",
            "published_at": "2026-09-05T08:16:40.397",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 7.16 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently force-delete arbitrary posts of any post type (including pages, administrator-authored posts, and WooCommerce products) and write arbitrary ccf_field_* post meta onto any post regardless of ownership or post type. The top-level form ID is checked via edit_post/publish_posts, but the nested fields[].ID and choices[].ID paths processed by _create_and_map_fields() and _create_and_map_choices() carry no equivalent capability or post-type guard, leaving those sinks fully exposed while delete_item() and delete_submission() contain explicit post-type restriction fixes demonstrating the developer's awareness of scoping requirements.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.0/classes/class-ccf-api-form-controller.php#L1026",
                "https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.0/classes/class-ccf-api-form-controller.php#L291",
                "https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.0/classes/class-ccf-api-form-controller.php#L336",
                "https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.0/classes/class-ccf-api-form-controller.php#L360",
                "https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.0/classes/class-ccf-api-form-controller.php#L977",
                "https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.0/classes/class-ccf-api-form-controller.php#L993",
                "https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.2/classes/class-ccf-api-form-controller.php#L1026",
                "https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.2/classes/class-ccf-api-form-controller.php#L291",
                "https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.2/classes/class-ccf-api-form-controller.php#L336",
                "https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.2/classes/class-ccf-api-form-controller.php#L360",
                "https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.2/classes/class-ccf-api-form-controller.php#L977",
                "https://plugins.trac.wordpress.org/browser/custom-contact-forms/tags/7.15.2/classes/class-ccf-api-form-controller.php#L993",
                "https://plugins.trac.wordpress.org/changeset?reponame=&old=3669565%40custom-contact-forms&new=3669565%40custom-contact-forms",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/9a34ec54-7629-4c14-b5e0-d47f5d3a72ce?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:16:40.397",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75018"
                }
            ]
        },
        {
            "id": "CVE-2026-74994",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "updated_at": "2026-09-08T02:17:27.360",
            "published_at": "2026-09-01T15:17:25.927",
            "cvss": 6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 5.10 through before 9.3.2.7 (otp); 9.4 through before 9.6.2.3 (otp); 9.7 through before 9.7.2 (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-74994.html",
                "https://github.com/erlang/otp/commit/6101cb74ff2870718c622ba7af0c100f7f2524e3",
                "https://github.com/erlang/otp/commit/6982e381137ede21a4e1faf5fa2dd82321691176",
                "https://github.com/erlang/otp/commit/c5ccec8ed25c70ec6557fd81277e4b2f52285c19",
                "https://github.com/erlang/otp/security/advisories/GHSA-c3cq-q8x6-547g",
                "https://osv.dev/vulnerability/EEF-CVE-2026-74994"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:25.927",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74994"
                }
            ]
        },
        {
            "id": "CVE-2026-74933",
            "vendor": "Unknown",
            "product": "GenieWords",
            "title": "GenieWords vulnerability",
            "summary": "The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.",
            "updated_at": "2026-09-13T21:17:01.800",
            "published_at": "2026-09-13T21:17:01.800",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.5.27 through 1.5.34 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that execute on every front-end page.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/23dc45bb-e7b6-4cae-81ce-2c6394afb454/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:17:01.800",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74933"
                }
            ]
        },
        {
            "id": "CVE-2026-74835",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "updated_at": "2026-09-08T01:17:54.277",
            "published_at": "2026-09-01T15:17:25.730",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 5.10 through before 9.3.2.7 (otp); 9.4 through before 9.6.2.3 (otp); 9.7 through before 9.7.2 (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-74835.html",
                "https://github.com/erlang/otp/commit/0bceff0c2987cae83d9d4a77c5ecacd6d01b8b86",
                "https://github.com/erlang/otp/commit/7f9c460d1818c2afb78fbd01f8d8b81343bbb011",
                "https://github.com/erlang/otp/commit/8e1ca42b64df6c41306affbe8dc129bdbd4042c7",
                "https://github.com/erlang/otp/security/advisories/GHSA-8qrh-x566-5xv5",
                "https://osv.dev/vulnerability/EEF-CVE-2026-74835"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:25.730",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74835"
                }
            ]
        },
        {
            "id": "CVE-2026-73834",
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Management for Kubernetes 2.11",
            "title": "Red Hat Advanced Cluster Management for Kubernetes 2.11 vulnerability",
            "summary": "A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive, potentially exposing sensitive information to anyone with access to the archive.",
            "updated_at": "2026-09-05T18:17:28.770",
            "published_at": "2026-08-18T16:18:17.493",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-312",
            "what_happened": "A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in cleartext in the resulting archive, potentially exposing sensitive information to anyone with access to the archive.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/errata/RHSA-2026:60387",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/errata/RHSA-2026:60389",
                "https://access.redhat.com/errata/RHSA-2026:60390",
                "https://access.redhat.com/errata/RHSA-2026:60391",
                "https://access.redhat.com/security/cve/CVE-2026-73834",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2517904"
            ],
            "timeline": [
                {
                    "at": "2026-08-18T16:18:17.493",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73834"
                }
            ]
        },
        {
            "id": "CVE-2026-73812",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and silently discards Content-Length. A CL-preferring front-end paired with chunked-preferring inets creates a classic CL.TE front-end/back-end desync.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "updated_at": "2026-09-08T01:17:54.130",
            "published_at": "2026-09-01T15:17:25.540",
            "cvss": 8.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 5.10 through before 9.3.2.7 (otp); 9.4 through before 9.6.2.3 (otp); 9.7 through before 9.7.2 (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before 591dc00dc99dc2a426167a3b5257c0c94bd45e91 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-444",
            "what_happened": "httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 identifies as a probable smuggling attempt. handle_body/3 frames by chunked and silently discards Content-Length. A CL-preferring front-end paired with chunked-preferring inets creates a classic CL.TE front-end/back-end desync.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-73812.html",
                "https://github.com/erlang/otp/commit/591dc00dc99dc2a426167a3b5257c0c94bd45e91",
                "https://github.com/erlang/otp/security/advisories/GHSA-7j6m-4ffg-hg46",
                "https://osv.dev/vulnerability/EEF-CVE-2026-73812"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:25.540",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73812"
                }
            ]
        },
        {
            "id": "CVE-2026-73787",
            "vendor": "Hewlett Packard Enterprise (HPE)",
            "product": "ClearPass Policy Manager (CPPM)",
            "title": "ClearPass Policy Manager (CPPM) vulnerability",
            "summary": "A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.",
            "updated_at": "2026-09-11T04:17:49.390",
            "published_at": "2026-09-09T20:20:33.607",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.11.0 through 6.11.14 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05130en_us&docLocale=en_US"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T20:20:33.607",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73787"
                }
            ]
        },
        {
            "id": "CVE-2026-73769",
            "vendor": "Hewlett Packard Enterprise (HPE)",
            "product": "ClearPass Policy Manager (CPPM)",
            "title": "ClearPass Policy Manager (CPPM) vulnerability",
            "summary": "A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.",
            "updated_at": "2026-09-11T04:17:49.273",
            "published_at": "2026-09-09T20:20:33.360",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.12.0 through 6.12.8 (semver); 6.11.0 through 6.11.14 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05130en_us&docLocale=en_US"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T20:20:33.360",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73769"
                }
            ]
        },
        {
            "id": "CVE-2026-73751",
            "vendor": "Hewlett Packard Enterprise (HPE)",
            "product": "AOS-CX",
            "title": "AOS-CX vulnerability",
            "summary": "An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.",
            "updated_at": "2026-09-15T18:58:52.170",
            "published_at": "2026-09-01T21:18:41.647",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.18.0000 through 10.18.0001 (semver); 10.17.0000 through 10.17.1021 (semver); 10.16.0000 through 10.16.1051 (semver); 10.13.0000 through 10.13.1180 (semver); 10.10.0000 through 10.10.1180 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "An authenticated user with low-privileged access could submit crafted input through the web-based management interface to execute arbitrary commands on the underlying operating system.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T21:18:41.647",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73751"
                }
            ]
        },
        {
            "id": "CVE-2026-73750",
            "vendor": "Hewlett Packard Enterprise (HPE)",
            "product": "AOS-CX",
            "title": "AOS-CX vulnerability",
            "summary": "Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a Denial-of-Service or potential remote code execution with elevated privileges.",
            "updated_at": "2026-09-15T19:01:07.707",
            "published_at": "2026-09-01T21:18:41.540",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.18.0000 through 10.18.0001 (semver); 10.17.0000 through 10.17.1021 (semver); 10.16.0000 through 10.16.1051 (semver); 10.13.0000 through 10.13.1180 (semver); 10.10.0000 through 10.10.1180 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "Vulnerabilities exist in the authentication module that may improperly process malformed or truncated input. An authenticated remote attacker could exploit these vulnerabilities by providing specially crafted input from a compromised or hostile authentication server. Successful exploitation could result in a Denial-of-Service or potential remote code execution with elevated privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05134en_us&docLocale=en_US"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T21:18:41.540",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73750"
                }
            ]
        },
        {
            "id": "CVE-2026-73683",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Laravel Socialite < 5.29.0 - Facebook OIDC Nonce Replay Authentication Bypass",
            "summary": "Laravel Socialite < 5.29.0 - Facebook OIDC Nonce Replay Authentication Bypass",
            "updated_at": "2026-08-20T22:00:00Z",
            "published_at": "2026-08-20T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 94,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Laravel Socialite < 5.29.0 - Facebook OIDC Nonce Replay Authentication Bypass",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CXSecurity WLB-2026080013",
                    "author": "Mohammed Idrees Banyamer",
                    "first_seen": "2026-08-21",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Laravel Socialite < 5.29.0 - Facebook OIDC Nonce Replay Authentication Bypass",
                    "summary": "Laravel Socialite < 5.29.0 - Facebook OIDC Nonce Replay Authentication Bypass",
                    "what_happened": "Laravel Socialite < 5.29.0 - Facebook OIDC Nonce Replay Authentication Bypass",
                    "cvss": 0,
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "url": "https://cxsecurity.com/issue/WLB-2026080013",
                    "cwe": "Unknown"
                }
            ],
            "references": [
                "https://cxsecurity.com/issue/WLB-2026080013"
            ],
            "timeline": [
                {
                    "at": "2026-08-20T22:00:00Z",
                    "label": "Discovered through CXSecurity",
                    "url": "https://cxsecurity.com/issue/WLB-2026080013"
                }
            ]
        },
        {
            "id": "CVE-2026-73570",
            "vendor": "Synacor",
            "product": "Zimbra Collaboration Suite (ZCS)",
            "title": "Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability",
            "summary": "Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.",
            "updated_at": "2026-08-26T09:01:39Z",
            "published_at": "2026-08-26T09:01:39Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 538,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · gabrielunknown/CVE-2026-73570",
                    "author": "gabrielunknown",
                    "first_seen": "2026-08-26",
                    "last_seen": "2026-08-26T09:01:39Z",
                    "pushed_at": "2026-08-26T04:14:30Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Perl",
                    "stars": 1,
                    "forks": 0,
                    "topics": [],
                    "title": "Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)",
                    "repository_description": "Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)",
                    "summary": "Zimbra SNMP Notification OS Command Injection — Unauthenticated RCE via SMTP exploit (Poc)",
                    "source": "CVE-Intel",
                    "url": "https://github.com/gabrielunknown/CVE-2026-73570"
                },
                {
                    "repository": "CVE-Intel · BiuTrap/CVE-2026-73570",
                    "author": "BiuTrap",
                    "first_seen": "2026-08-24",
                    "last_seen": "2026-08-25T23:48:31Z",
                    "pushed_at": "2026-08-25T23:48:28Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "PoC",
                    "language": "",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-73570 PoC",
                    "repository_description": "CVE-2026-73570 PoC",
                    "summary": "CVE-2026-73570 PoC",
                    "source": "CVE-Intel",
                    "url": "https://github.com/BiuTrap/CVE-2026-73570"
                },
                {
                    "repository": "CVE-Intel · HORKimhab/CVE-2026-73570",
                    "author": "HORKimhab",
                    "first_seen": "2026-08-21",
                    "last_seen": "2026-08-25T19:43:29Z",
                    "pushed_at": "2026-08-25T19:39:33Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 5,
                    "forks": 1,
                    "topics": [],
                    "title": "CVE-2026-73570",
                    "repository_description": "CVE-2026-73570",
                    "summary": "CVE-2026-73570",
                    "source": "CVE-Intel",
                    "url": "https://github.com/HORKimhab/CVE-2026-73570"
                },
                {
                    "repository": "CVE-Intel · jishino567/CVE-2026-73570",
                    "author": "jishino567",
                    "first_seen": "2026-08-25",
                    "last_seen": "2026-08-25T16:04:11Z",
                    "pushed_at": "2026-08-25T10:36:17Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Injection",
                    "language": "Python",
                    "stars": 1,
                    "forks": 0,
                    "topics": [
                        "cve-2026-73570",
                        "exploit",
                        "zimbra",
                        "zimbra-exploit"
                    ],
                    "title": "PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)",
                    "repository_description": "PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)",
                    "summary": "PoC for CVE-2026-73570 (Zimbra SMTP Command Injection)",
                    "source": "CVE-Intel",
                    "url": "https://github.com/jishino567/CVE-2026-73570"
                },
                {
                    "repository": "juanpoch/CVE-2026-73570",
                    "author": "juanpoch",
                    "first_seen": "2026-09-05",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)",
                    "summary": "Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)",
                    "url": "https://github.com/juanpoch/CVE-2026-73570"
                },
                {
                    "repository": "dahnutz/zimbra-cve-2026-73570-ir",
                    "author": "dahnutz",
                    "first_seen": "2026-09-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-73570 repository",
                    "summary": "",
                    "url": "https://github.com/dahnutz/zimbra-cve-2026-73570-ir"
                },
                {
                    "repository": "INFOKOM-KI/Zimbra-CVE-2026-73570-Rules",
                    "author": "INFOKOM-KI",
                    "first_seen": "2026-08-28",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Wazuh Rules for Detection Zimbra (CVE-2026-73570).",
                    "summary": "Wazuh Rules for Detection Zimbra (CVE-2026-73570).",
                    "url": "https://github.com/INFOKOM-KI/Zimbra-CVE-2026-73570-Rules"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/gabrielunknown/CVE-2026-73570",
                "https://github.com/BiuTrap/CVE-2026-73570",
                "https://github.com/HORKimhab/CVE-2026-73570",
                "https://github.com/jishino567/CVE-2026-73570",
                "https://github.com/juanpoch/CVE-2026-73570",
                "https://github.com/dahnutz/zimbra-cve-2026-73570-ir",
                "https://github.com/INFOKOM-KI/Zimbra-CVE-2026-73570-Rules"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T09:01:39Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-73476",
            "vendor": "Drupal",
            "product": "External Authentication",
            "title": "External Authentication vulnerability",
            "summary": "Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.",
            "updated_at": "2026-09-15T12:28:25.280",
            "published_at": "2026-09-02T13:18:08.413",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.0.0 through before 2.0.13 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-178",
            "what_happened": "Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This issue affects External Authentication versions: from 0.0.0 to 2.0.13.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.drupal.org/sa-contrib-2026-098"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T13:18:08.413",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73476"
                }
            ]
        },
        {
            "id": "CVE-2026-73392",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "summary": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-12965.",
            "updated_at": "2026-09-11T08:16:48.133",
            "published_at": "2026-08-18T15:17:06.543",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-12965.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [],
            "timeline": [
                {
                    "at": "2026-08-18T15:17:06.543",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73392"
                }
            ]
        },
        {
            "id": "CVE-2026-73276",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities.\n\nThis issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 7.1.2 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.",
            "updated_at": "2026-09-08T01:17:53.980",
            "published_at": "2026-09-01T15:17:25.367",
            "cvss": 8.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "22.2 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 7.1.2 through before 9.3.2.7 (otp); 9.4 through before 9.6.2.3 (otp); 9.7 through before 9.7.2 (otp); c06db0bedf49a9b40725745e73fa82e562612815 through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-444",
            "what_happened": "Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities.\n\nThis issue affects OTP from OTP 22.2 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 7.1.2 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-73276.html",
                "https://github.com/erlang/otp/commit/60add5a19e2154560fdff3fe92dba14a68bbd683",
                "https://github.com/erlang/otp/commit/6cd995e34d3bb3d36dd278dded2d62c25e71820c",
                "https://github.com/erlang/otp/commit/c285240c6e4b93960c5dc4f17ba04e6fdfb27a0f",
                "https://github.com/erlang/otp/security/advisories/GHSA-6v7q-jwgh-cx8p",
                "https://osv.dev/vulnerability/EEF-CVE-2026-73276"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:25.367",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73276"
                }
            ]
        },
        {
            "id": "CVE-2026-73270",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting them with different casing, on deployments whose filesystem is case-insensitive.\n\nmod_auth:secret_path/3 decides whether a resolved filesystem path lies inside a protected directory block by running the configured directory path through re:run/3 without the caseless option. A request for /secret/file against a directory configured as /Secret therefore does not match, so the request is treated as unprotected and no authentication challenge is issued, while the filesystem resolves the differently cased path to the same file and mod_get serves it. Deployments on case-sensitive filesystems are unaffected, because there the filesystem itself rejects the mismatched casing.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "updated_at": "2026-09-08T01:17:53.753",
            "published_at": "2026-09-01T15:17:25.103",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 5.10 through before 9.3.2.7 (otp); 9.4 through before 9.6.2.3 (otp); 9.7 through before 9.7.2 (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-178",
            "what_happened": "Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by requesting them with different casing, on deployments whose filesystem is case-insensitive.\n\nmod_auth:secret_path/3 decides whether a resolved filesystem path lies inside a protected directory block by running the configured directory path through re:run/3 without the caseless option. A request for /secret/file against a directory configured as /Secret therefore does not match, so the request is treated as unprotected and no authentication challenge is issued, while the filesystem resolves the differently cased path to the same file and mod_get serves it. Deployments on case-sensitive filesystems are unaffected, because there the filesystem itself rejects the mismatched casing.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-73270.html",
                "https://github.com/erlang/otp/commit/9641944a2efbf55bea760f8ff7ba777fe3a0961c",
                "https://github.com/erlang/otp/commit/bac19eb3dbd96cc49b6d8cabc1c04248bf8c79f6",
                "https://github.com/erlang/otp/commit/d8878dec0ececc2eab18e47bb18b472f224ca633",
                "https://github.com/erlang/otp/security/advisories/GHSA-mh78-93cr-jx8f",
                "https://osv.dev/vulnerability/EEF-CVE-2026-73270",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:25.103",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73270"
                }
            ]
        },
        {
            "id": "CVE-2026-73269",
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1",
            "title": "multicluster engine for Kubernetes 2.1 vulnerability",
            "summary": "A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.",
            "updated_at": "2026-09-07T19:17:27.977",
            "published_at": "2026-08-12T20:17:53.793",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from namespace-local access to cluster-wide control. This privilege escalation grants broad permissions, including the ability to access and manipulate secrets, manage cluster actions, and delete hosted clusters or node pools.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:59556",
                "https://access.redhat.com/errata/RHSA-2026:59557",
                "https://access.redhat.com/errata/RHSA-2026:59558",
                "https://access.redhat.com/errata/RHSA-2026:59559",
                "https://access.redhat.com/errata/RHSA-2026:59579",
                "https://access.redhat.com/errata/RHSA-2026:59593",
                "https://access.redhat.com/security/cve/CVE-2026-73269",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2514220"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T20:17:53.793",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73269"
                }
            ]
        },
        {
            "id": "CVE-2026-73268",
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1",
            "title": "multicluster engine for Kubernetes 2.1 vulnerability",
            "summary": "A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading to arbitrary code execution and privilege escalation, potentially accessing cluster-wide secrets.",
            "updated_at": "2026-09-07T19:17:27.823",
            "published_at": "2026-08-12T20:17:53.650",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate user-controlled input when unmarshaling the spec.install.overrideJob raw extension. Successful exploitation allows the injected Job to run with the controller's elevated privileges, leading to arbitrary code execution and privilege escalation, potentially accessing cluster-wide secrets.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:59556",
                "https://access.redhat.com/errata/RHSA-2026:59557",
                "https://access.redhat.com/errata/RHSA-2026:59558",
                "https://access.redhat.com/errata/RHSA-2026:59559",
                "https://access.redhat.com/errata/RHSA-2026:59579",
                "https://access.redhat.com/errata/RHSA-2026:59593",
                "https://access.redhat.com/security/cve/CVE-2026-73268",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2514219"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T20:17:53.650",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73268"
                }
            ]
        },
        {
            "id": "CVE-2026-73267",
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1",
            "title": "multicluster engine for Kubernetes 2.1 vulnerability",
            "summary": "A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any ManagedCluster, including the hub's local-cluster or other tenants' clusters, due to a missing ownership check. This vulnerability can lead to a denial of service by enabling unauthorized deletion of ManagedClusters.",
            "updated_at": "2026-09-07T19:17:27.670",
            "published_at": "2026-08-21T03:16:39.080",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-602",
            "what_happened": "A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any ManagedCluster, including the hub's local-cluster or other tenants' clusters, due to a missing ownership check. This vulnerability can lead to a denial of service by enabling unauthorized deletion of ManagedClusters.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:59556",
                "https://access.redhat.com/errata/RHSA-2026:59557",
                "https://access.redhat.com/errata/RHSA-2026:59558",
                "https://access.redhat.com/errata/RHSA-2026:59559",
                "https://access.redhat.com/errata/RHSA-2026:59579",
                "https://access.redhat.com/errata/RHSA-2026:59593",
                "https://access.redhat.com/security/cve/CVE-2026-73267",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2514218"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T03:16:39.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73267"
                }
            ]
        },
        {
            "id": "CVE-2026-73266",
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1",
            "title": "multicluster engine for Kubernetes 2.1 vulnerability",
            "summary": "A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.",
            "updated_at": "2026-09-07T19:17:27.517",
            "published_at": "2026-08-13T17:17:35.713",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-441",
            "what_happened": "A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable the injection of policies and workloads into other tenants' clusters.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:59556",
                "https://access.redhat.com/errata/RHSA-2026:59557",
                "https://access.redhat.com/errata/RHSA-2026:59558",
                "https://access.redhat.com/errata/RHSA-2026:59559",
                "https://access.redhat.com/errata/RHSA-2026:59579",
                "https://access.redhat.com/errata/RHSA-2026:59593",
                "https://access.redhat.com/security/cve/CVE-2026-73266",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2514217"
            ],
            "timeline": [
                {
                    "at": "2026-08-13T17:17:35.713",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73266"
                }
            ]
        },
        {
            "id": "CVE-2026-73229",
            "vendor": "encode",
            "product": "django-rest-framework",
            "title": "django-rest-framework vulnerability",
            "summary": "Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.get() without view.check_permissions() while rendering an invalid write request, allowing a 400 Bad Request HTML response to disclose data from a GET representation that the requester is not permitted to access. This issue is fixed in version 3.17.2.",
            "updated_at": "2026-09-11T18:24:59.400",
            "published_at": "2026-08-11T20:18:48.113",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.17.2",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's rest_framework/renderers.py AdminRenderer.render() uses override_method() to simulate GET and directly invokes view.get() without view.check_permissions() while rendering an invalid write request, allowing a 400 Bad Request HTML response to disclose data from a GET representation that the requester is not permitted to access. This issue is fixed in version 3.17.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/encode/django-rest-framework/commit/71f81946906e52f9dc8e5d22a0f3d2afa50c455e",
                "https://github.com/encode/django-rest-framework/commit/9e82afc98acfe6fc28c9bf78147f0c5b3f222cb5",
                "https://github.com/encode/django-rest-framework/pull/10012",
                "https://github.com/encode/django-rest-framework/releases/tag/3.17.2",
                "https://github.com/encode/django-rest-framework/security/advisories/GHSA-g47c-3xmw-q6m2"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T20:18:48.113",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73229"
                }
            ]
        },
        {
            "id": "CVE-2026-73228",
            "vendor": "encode",
            "product": "django-rest-framework",
            "title": "django-rest-framework vulnerability",
            "summary": "Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-form-urlencoded bodies, bypassing Django's DATA_UPLOAD_MAX_MEMORY_SIZE protection and allowing oversized request bodies to consume additional memory and CPU. This issue is fixed in version 3.17.2.",
            "updated_at": "2026-09-11T18:24:59.400",
            "published_at": "2026-08-11T19:18:52.603",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.17.2",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser and FormParser for application/json and application/x-www-form-urlencoded bodies, bypassing Django's DATA_UPLOAD_MAX_MEMORY_SIZE protection and allowing oversized request bodies to consume additional memory and CPU. This issue is fixed in version 3.17.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/encode/django-rest-framework/commit/2912dc98042f78e27636551fc22eeaf10f725fdd",
                "https://github.com/encode/django-rest-framework/commit/82ef7b7e4e0a73ba5c489b465fae7e76d948da4e",
                "https://github.com/encode/django-rest-framework/pull/10013",
                "https://github.com/encode/django-rest-framework/security/advisories/GHSA-2m8g-3cmr-wg3w"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:18:52.603",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73228"
                }
            ]
        },
        {
            "id": "CVE-2026-73033",
            "vendor": "Sucuri",
            "product": "sucuri-wordpress-plugin",
            "title": "sucuri-wordpress-plugin vulnerability",
            "summary": "Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integrity.lib.php that allows authenticated administrators to delete arbitrary files by supplying directory traversal sequences in the sucuriscan_integrity parameter. Attackers can manipulate the unsanitized file path concatenated with ABSPATH to traverse outside the WordPress installation directory and invoke unlink() on sensitive files such as wp-config.php and .htaccess, causing site outage or enabling malicious reinstallation.",
            "updated_at": "2026-09-10T20:44:57.447",
            "published_at": "2026-08-10T21:17:26.610",
            "cvss": 7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.7.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmission() method in src/integrity.lib.php that allows authenticated administrators to delete arbitrary files by supplying directory traversal sequences in the sucuriscan_integrity parameter. Attackers can manipulate the unsanitized file path concatenated with ABSPATH to traverse outside the WordPress installation directory and invoke unlink() on sensitive files such as wp-config.php and .htaccess, causing site outage or enabling malicious reinstallation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Sucuri/sucuri-wordpress-plugin/issues/217",
                "https://www.vulncheck.com/advisories/sucuri-wordpress-plugin-path-traversal-via-integrity-lib-php"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T21:17:26.610",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73033"
                }
            ]
        },
        {
            "id": "CVE-2026-73007",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:37.637",
            "published_at": "2026-09-08T18:20:29.487",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73007"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:29.487",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73007"
                }
            ]
        },
        {
            "id": "CVE-2026-73002",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:37.457",
            "published_at": "2026-09-08T18:20:28.713",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "Integer overflow or wraparound in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-73002"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:28.713",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-73002"
                }
            ]
        },
        {
            "id": "CVE-2026-72996",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-12T04:16:37.237",
            "published_at": "2026-09-08T18:20:27.907",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72996"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:27.907",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72996"
                }
            ]
        },
        {
            "id": "CVE-2026-72987",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "updated_at": "2026-09-10T04:18:16.120",
            "published_at": "2026-09-08T18:20:25.697",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72987"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:25.697",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72987"
                }
            ]
        },
        {
            "id": "CVE-2026-72963",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-10T04:18:15.860",
            "published_at": "2026-09-08T18:20:22.223",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72963"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:22.223",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72963"
                }
            ]
        },
        {
            "id": "CVE-2026-72928",
            "vendor": "Microsoft",
            "product": "Windows Server 2025",
            "title": "Windows Server 2025 vulnerability",
            "summary": "Use after free in Windows DNS allows an authorized attacker to execute code over a network.",
            "updated_at": "2026-09-10T04:18:15.737",
            "published_at": "2026-09-08T18:20:17.103",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows DNS allows an authorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72928"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:17.103",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72928"
                }
            ]
        },
        {
            "id": "CVE-2026-72898",
            "vendor": "Metabase",
            "product": "Metabase",
            "title": "Metabase SQL Injection Vulnerability",
            "summary": "Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.",
            "updated_at": "2026-08-10T22:00:00Z",
            "published_at": "2026-08-10T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-72710",
            "vendor": "SPIP",
            "product": "SPIP",
            "title": "SPIP vulnerability",
            "summary": "SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlled arg parameter resolving to internal database tables. Attackers can insert a malicious row into the spip_jobs queue with a controlled PHP function and arguments, which is then dynamically executed when the cron processes the queue, resulting in remote code execution.",
            "updated_at": "2026-09-15T03:17:05.947",
            "published_at": "2026-09-11T17:18:58.907",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.4.18 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-915",
            "what_happened": "SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlled arg parameter resolving to internal database tables. Attackers can insert a malicious row into the spip_jobs queue with a controlled PHP function and arguments, which is then dynamically executed when the cron processes the queue, resulting in remote code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://blog.lexfo.fr/casse-spip-sqli-to-rce.html",
                "https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html",
                "https://www.vulncheck.com/advisories/spip-remote-code-execution-via-editer-objet-php-job-queue-injection"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T17:18:58.907",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72710"
                }
            ]
        },
        {
            "id": "CVE-2026-72709",
            "vendor": "SPIP",
            "product": "SPIP",
            "title": "SPIP vulnerability",
            "summary": "SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission check. Attackers can bypass template-level authorization guards through direct HTTP requests to invoke actions such as editer_auteur, enabling arbitrary account password rewrites including administrator accounts and resulting in full account takeover.",
            "updated_at": "2026-09-15T03:17:05.813",
            "published_at": "2026-09-11T17:18:58.760",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.4.18 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission check. Attackers can bypass template-level authorization guards through direct HTTP requests to invoke actions such as editer_auteur, enabling arbitrary account password rewrites including administrator accounts and resulting in full account takeover.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://blog.lexfo.fr/casse-spip-sqli-to-rce.html",
                "https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html",
                "https://www.vulncheck.com/advisories/spip-missing-authorization-via-ecrire-action-editer-auteur"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T17:18:58.760",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72709"
                }
            ]
        },
        {
            "id": "CVE-2026-72708",
            "vendor": "SPIP",
            "product": "SPIP",
            "title": "SPIP vulnerability",
            "summary": "SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word character followed by an open parenthesis, which bypasses escaping for date-type columns across MySQL, SQLite, and PostgreSQL backends. Attackers can exploit the always-present sitemap.xml.html template's annee criterion to embed unescaped time-based or boolean payloads into database queries, enabling extraction of arbitrary database content including the alea_ephemere secret used to sign SPIP action nonces.",
            "updated_at": "2026-09-15T03:17:05.660",
            "published_at": "2026-09-11T17:18:57.197",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.4.18 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word character followed by an open parenthesis, which bypasses escaping for date-type columns across MySQL, SQLite, and PostgreSQL backends. Attackers can exploit the always-present sitemap.xml.html template's annee criterion to embed unescaped time-based or boolean payloads into database queries, enabling extraction of arbitrary database content including the alea_ephemere secret used to sign SPIP action nonces.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://blog.lexfo.fr/casse-spip-sqli-to-rce.html",
                "https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-4-18.html",
                "https://www.vulncheck.com/advisories/spip-unauthenticated-sql-injection-via-sitemap-annee-parameter"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T17:18:57.197",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72708"
                }
            ]
        },
        {
            "id": "CVE-2026-72693",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat(\"/proc/<pid>/fd/0\")`. `stat()` on `/proc/<pid>/fd/0` follows the symlink to the underlying TTY device node. As a result, `buf.st_uid` reflects the owner of the TTY node rather than the owner of the process holding the file descriptor. If the TTY owner returns to `root` or the getty owner after logout while an unprivileged process still has `fd 0` attached to that TTY, the check can incorrectly treat that process as belonging to the privileged console owner. Once that check succeeds, the `-u` path executes a passwordless login as the selected user. In the documented `kbrequest`/init deployment using `openvt -us`, this can result in passwordless `login -f root` on the spawned VT. This report establishes that privilege escalation path for that documented deployment; it does not claim equivalent reachability for deployments that do not use `openvt -u` from a privileged `kbrequest`/init path.",
            "updated_at": "2026-09-15T12:17:53.320",
            "published_at": "2026-08-11T09:17:14.340",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat(\"/proc/<pid>/fd/0\")`. `stat()` on `/proc/<pid>/fd/0` follows the symlink to the underlying TTY device node. As a result, `buf.st_uid` reflects the owner of the TTY node rather than the owner of the process holding the file descriptor. If the TTY owner returns to `root` or the getty owner after logout while an unprivileged process still has `fd 0` attached to that TTY, the check can incorrectly treat that process as belonging to the privileged console owner. Once that check succeeds, the `-u` path executes a passwordless login as the selected user. In the documented `kbrequest`/init deployment using `openvt -us`, this can result in passwordless `login -f root` on the spawned VT. This report establishes that privilege escalation path for that documented deployment; it does not claim equivalent reachability for deployments that do not use `openvt -u` from a privileged `kbrequest`/init path.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:41136",
                "https://access.redhat.com/errata/RHSA-2026:57597",
                "https://access.redhat.com/errata/RHSA-2026:57610",
                "https://access.redhat.com/errata/RHSA-2026:60440",
                "https://access.redhat.com/errata/RHSA-2026:66357",
                "https://access.redhat.com/security/cve/CVE-2026-72693",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2462115"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T09:17:14.340",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72693"
                }
            ]
        },
        {
            "id": "CVE-2026-72530",
            "vendor": "TrueConf",
            "product": "Server",
            "title": "TrueConf Server Code Injection Vulnerability",
            "summary": "TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.",
            "updated_at": "2026-08-19T22:00:00Z",
            "published_at": "2026-08-19T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 86,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "fevar54/CVE-2026-72530-TrueConf-Sandbox-Escape-",
                    "author": "fevar54",
                    "first_seen": "2026-08-25",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server.",
                    "summary": "Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code Injection y Sandbox Escape** en TrueConf Server.",
                    "url": "https://github.com/fevar54/CVE-2026-72530-TrueConf-Sandbox-Escape-"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/fevar54/CVE-2026-72530-TrueConf-Sandbox-Escape-"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-72529",
            "vendor": "TrueConf",
            "product": "Server",
            "title": "TrueConf Server Missing Authentication for Critical Function Vulnerability",
            "summary": "TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.",
            "updated_at": "2026-08-19T22:00:00Z",
            "published_at": "2026-08-19T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 48,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-71852",
            "vendor": "py-pdf",
            "product": "pypdf",
            "title": "pypdf vulnerability",
            "summary": "pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font /W width ranges or excessive width entries during text extraction. This issue is fixed in 6.15.0.",
            "updated_at": "2026-09-10T20:30:11.423",
            "published_at": "2026-08-07T19:18:54.547",
            "cvss": 4.8,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 6.15.0",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-834",
            "what_happened": "pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font /W width ranges or excessive width entries during text extraction. This issue is fixed in 6.15.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/py-pdf/pypdf/commit/51cb6acf9e8a35b77e90b4d87d28fe3e1416d7d7",
                "https://github.com/py-pdf/pypdf/pull/3946",
                "https://github.com/py-pdf/pypdf/releases/tag/6.15.0",
                "https://github.com/py-pdf/pypdf/security/advisories/GHSA-fwg2-594c-jp42"
            ],
            "timeline": [
                {
                    "at": "2026-08-07T19:18:54.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71852"
                }
            ]
        },
        {
            "id": "CVE-2026-71846",
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Management for Kubernetes 2.11",
            "title": "Red Hat Advanced Cluster Management for Kubernetes 2.11 vulnerability",
            "summary": "A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the insights-client pod or ServiceAccount token would grant an attacker read access to all Secrets across the hub cluster, including managed-cluster kubeconfigs and other sensitive credentials.",
            "updated_at": "2026-09-05T18:17:28.630",
            "published_at": "2026-08-12T22:17:16.143",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-250",
            "what_happened": "A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the insights-client pod or ServiceAccount token would grant an attacker read access to all Secrets across the hub cluster, including managed-cluster kubeconfigs and other sensitive credentials.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/errata/RHSA-2026:60387",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/errata/RHSA-2026:60389",
                "https://access.redhat.com/errata/RHSA-2026:60390",
                "https://access.redhat.com/errata/RHSA-2026:60391",
                "https://access.redhat.com/security/cve/CVE-2026-71846",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2512569"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T22:17:16.143",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71846"
                }
            ]
        },
        {
            "id": "CVE-2026-71845",
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Management for Kubernetes 2.11",
            "title": "Red Hat Advanced Cluster Management for Kubernetes 2.11 vulnerability",
            "summary": "A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every startup. An attacker with access to pod logs or centralized logging could obtain the credential, leading to unauthorized access to the CCX API.",
            "updated_at": "2026-09-05T18:17:28.487",
            "published_at": "2026-08-11T20:18:45.800",
            "cvss": 6.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-532",
            "what_happened": "A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every startup. An attacker with access to pod logs or centralized logging could obtain the credential, leading to unauthorized access to the CCX API.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/errata/RHSA-2026:60387",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/errata/RHSA-2026:60389",
                "https://access.redhat.com/errata/RHSA-2026:60390",
                "https://access.redhat.com/errata/RHSA-2026:60391",
                "https://access.redhat.com/security/cve/CVE-2026-71845",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2512568"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T20:18:45.800",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71845"
                }
            ]
        },
        {
            "id": "CVE-2026-71562",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a malicious or compromised HTTP server to degrade availability by returning a numeric header whose value is a very long run of digits.\n\nhttpc_handler.erl converts the server-supplied Content-Length with list_to_integer/1 before comparing it against max_body_size, so the size check cannot protect the conversion, and the option defaults to nolimit in any case. The same unbounded conversion appears in httpc_response:format_response/1 for Content-Length and in httpc_response:get_ms_from_retry_after/1 for Retry-After, which is guarded only by a check that the first character is a digit. A value of up to roughly 1.26 million digits converts successfully and costs the requesting process hundreds of milliseconds of arbitrary-precision arithmetic per response. The conversion function is documented to accept integers of any size, so bounding the input is the caller's responsibility.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "updated_at": "2026-09-08T01:17:53.543",
            "published_at": "2026-09-01T15:17:24.883",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 5.10 through before 9.3.2.7 (otp); 9.4 through before 9.6.2.3 (otp); 9.7 through before 9.7.2 (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1284",
            "what_happened": "Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP inets httpc allows a malicious or compromised HTTP server to degrade availability by returning a numeric header whose value is a very long run of digits.\n\nhttpc_handler.erl converts the server-supplied Content-Length with list_to_integer/1 before comparing it against max_body_size, so the size check cannot protect the conversion, and the option defaults to nolimit in any case. The same unbounded conversion appears in httpc_response:format_response/1 for Content-Length and in httpc_response:get_ms_from_retry_after/1 for Retry-After, which is guarded only by a check that the first character is a digit. A value of up to roughly 1.26 million digits converts successfully and costs the requesting process hundreds of milliseconds of arbitrary-precision arithmetic per response. The conversion function is documented to accept integers of any size, so bounding the input is the caller's responsibility.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-71562.html",
                "https://github.com/erlang/otp/commit/aba0fe8c2d700bf4ac94607cf7f00e53bbe4042d",
                "https://github.com/erlang/otp/commit/e3be1cfe9f6cedd0cd20d9905e05601dfb31c8aa",
                "https://github.com/erlang/otp/security/advisories/GHSA-cqx9-9hq6-m8wf",
                "https://osv.dev/vulnerability/EEF-CVE-2026-71562",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:24.883",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71562"
                }
            ]
        },
        {
            "id": "CVE-2026-71557",
            "vendor": "go-git",
            "product": "go-git",
            "title": "go-git vulnerability",
            "summary": "go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue.",
            "updated_at": "2026-09-10T20:41:33.140",
            "published_at": "2026-08-07T17:17:10.833",
            "cvss": 6.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 5.19.2; >= 6.0.0-alpha.1, < 6.0.0-alpha.5",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example containing directory-traversal sequences) can cause go-git to write files outside the intended reference storage directory. Versions 5.19.2 and 6.0.0-alpha.5 fix the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/go-git/go-git/commit/4a0e66d555de5f9a30c31e2df64f445f42bd01e7",
                "https://github.com/go-git/go-git/commit/da9f7d8a0e98b475600177348d6ece384a370f36",
                "https://github.com/go-git/go-git/pull/2247",
                "https://github.com/go-git/go-git/pull/2254",
                "https://github.com/go-git/go-git/releases/tag/v5.19.2",
                "https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5",
                "https://github.com/go-git/go-git/security/advisories/GHSA-qgq7-7hm3-q39j"
            ],
            "timeline": [
                {
                    "at": "2026-08-07T17:17:10.833",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71557"
                }
            ]
        },
        {
            "id": "CVE-2026-71556",
            "vendor": "go-git",
            "product": "go-git",
            "title": "go-git vulnerability",
            "summary": "go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.",
            "updated_at": "2026-09-10T20:41:33.140",
            "published_at": "2026-08-07T17:17:10.150",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 5.19.2; >= 6.0.0-alpha.1, < 6.0.0-alpha.5",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-59",
            "what_happened": "go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a maliciously crafted repository containing a symlink can cause go-git to read from or write to files outside the intended working directory when the repository is cloned and its worktree operations are used. Versions 5.19.2 and 6.0.0-alpha.5.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/go-git/go-git/commit/008a78f2dd86f52544ddff8b8e8ddeecdf3f7aab",
                "https://github.com/go-git/go-git/commit/661d1c7f101d34e002a3cfcf8dbea5b7421d07ac",
                "https://github.com/go-git/go-git/releases/tag/v5.19.2",
                "https://github.com/go-git/go-git/releases/tag/v6.0.0-alpha.5",
                "https://github.com/go-git/go-git/security/advisories/GHSA-hc8v-wwc9-vgxm"
            ],
            "timeline": [
                {
                    "at": "2026-08-07T17:17:10.150",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71556"
                }
            ]
        },
        {
            "id": "CVE-2026-71555",
            "vendor": "THM-Health",
            "product": "PILOS",
            "title": "PILOS vulnerability",
            "summary": "PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages opened by PILOS via a link that opens a new browsing context (e.g., target=\"_blank\") retain a window.opener reference back to the originating PILOS tab. A malicious destination page reached this way can use window.opener to navigate or manipulate the original PILOS tab, a technique known as reverse tabnabbing, potentially redirecting an authenticated user to a phishing page that mimics PILOS. This issue is fixed in version 4.14.1.",
            "updated_at": "2026-09-10T20:42:39.707",
            "published_at": "2026-08-06T22:18:32.553",
            "cvss": 4.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 2.1.0, < 4.14.1",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-1022",
            "what_happened": "PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages opened by PILOS via a link that opens a new browsing context (e.g., target=\"_blank\") retain a window.opener reference back to the originating PILOS tab. A malicious destination page reached this way can use window.opener to navigate or manipulate the original PILOS tab, a technique known as reverse tabnabbing, potentially redirecting an authenticated user to a phishing page that mimics PILOS. This issue is fixed in version 4.14.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/THM-Health/PILOS/commit/b50f2bd07c4f4a7d6a9981578238ae3579275d81",
                "https://github.com/THM-Health/PILOS/releases/tag/v4.14.1",
                "https://github.com/THM-Health/PILOS/security/advisories/GHSA-j4wr-p8gh-xrw5"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:32.553",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71555"
                }
            ]
        },
        {
            "id": "CVE-2026-71510",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-89012",
            "summary": "Case-sensitive denylist bypass in Dolibarr 24.0.0 universal search leaks password hashes.",
            "updated_at": "2026-09-11T20:05:28Z",
            "published_at": "2026-09-11T20:05:28Z",
            "cvss": 7.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 43,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Case-sensitive denylist bypass in Dolibarr 24.0.0 universal search leaks password hashes.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-89012",
                    "summary": "Case-sensitive denylist bypass in Dolibarr 24.0.0 universal search leaks password hashes.",
                    "what_happened": "Case-sensitive denylist bypass in Dolibarr 24.0.0 universal search leaks password hashes.",
                    "cvss": 7.1,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/SC:N/VI:N/SI:N/VA:N/SA:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=BFC7CD0E-1507-5808-A8E8-D1E81456FB9E",
                        "https://github.com/Faceless0x7/CVE-2026-89012"
                    ],
                    "repository": "Sploitus",
                    "author": "Faceless0x7",
                    "first_seen": "2026-09-11T22:05:28",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=BFC7CD0E-1507-5808-A8E8-D1E81456FB9E"
                },
                {
                    "title": "Exploit for CVE-2026-89012",
                    "summary": "Case-sensitive denylist bypass in Dolibarr 24.0.0 universal search leaks password hashes.",
                    "what_happened": "Case-sensitive denylist bypass in Dolibarr 24.0.0 universal search leaks password hashes.",
                    "cvss": 7.1,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/SC:N/VI:N/SI:N/VA:N/SA:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=BFC7CD0E-1507-5808-A8E8-D1E81456FB9E",
                        "https://github.com/Faceless0x7/CVE-2026-89012"
                    ],
                    "repository": "Faceless0x7/CVE-2026-89012",
                    "author": "Faceless0x7",
                    "first_seen": "2026-09-11T22:05:28",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/Faceless0x7/CVE-2026-89012"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=BFC7CD0E-1507-5808-A8E8-D1E81456FB9E",
                "https://github.com/Faceless0x7/CVE-2026-89012"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T20:05:28Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=BFC7CD0E-1507-5808-A8E8-D1E81456FB9E"
                }
            ],
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/SC:N/VI:N/SI:N/VA:N/SA:N"
        },
        {
            "id": "CVE-2026-71498",
            "vendor": "uhop",
            "product": "node-re2",
            "title": "node-re2 vulnerability",
            "summary": "node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end of the allocated buffer while attempting to decode the final, incomplete code point. This could result in an out-of-bounds read and potential disclosure of adjacent memory contents. This issue is fixed in version 1.26.1.",
            "updated_at": "2026-09-10T20:30:11.423",
            "published_at": "2026-08-06T22:18:32.207",
            "cvss": 5.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.26.1",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the native binding to read past the end of the allocated buffer while attempting to decode the final, incomplete code point. This could result in an out-of-bounds read and potential disclosure of adjacent memory contents. This issue is fixed in version 1.26.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/uhop/node-re2/commit/9d72042a6a0da5bc523908b04808ea0e23867cc4",
                "https://github.com/uhop/node-re2/issues/272",
                "https://github.com/uhop/node-re2/security/advisories/GHSA-j4r3-hg7j-8chg"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:32.207",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71498"
                }
            ]
        },
        {
            "id": "CVE-2026-71497",
            "vendor": "jhy",
            "product": "jsoup",
            "title": "jsoup vulnerability",
            "summary": "jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a different element. When a custom Safelist permits certain raw-text elements, this misparsing can cause content that should remain inert text to be emitted as active markup after serialization, potentially resulting in cross-site scripting. jsoup's built-in Safelists are not affected. This issue is fixed in version 1.23.1.",
            "updated_at": "2026-09-10T20:41:33.140",
            "published_at": "2026-08-06T22:18:32.043",
            "cvss": 4.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 1.14.3, < 1.23.1",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-79",
            "what_happened": "jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to acquire the parsing behavior of a different element. When a custom Safelist permits certain raw-text elements, this misparsing can cause content that should remain inert text to be emitted as active markup after serialization, potentially resulting in cross-site scripting. jsoup's built-in Safelists are not affected. This issue is fixed in version 1.23.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70",
                "https://github.com/jhy/jsoup/issues/2538",
                "https://github.com/jhy/jsoup/releases/tag/jsoup-1.23.1",
                "https://github.com/jhy/jsoup/security/advisories/GHSA-pmhh-3w7g-xqp8"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:32.043",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71497"
                }
            ]
        },
        {
            "id": "CVE-2026-71488",
            "vendor": "thephpleague",
            "product": "commonmark",
            "title": "commonmark vulnerability",
            "summary": "league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character positions and byte positions, and the Autolink extension can also copy and validate the remaining line at every URL-like prefix, allowing an attacker who can submit Markdown for conversion to consume disproportionate CPU time with a comparatively small request. This issue is fixed in 2.9.0.",
            "updated_at": "2026-09-10T20:41:33.140",
            "published_at": "2026-08-06T22:18:31.893",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 0.6.0, < 2.9.0",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-407",
            "what_happened": "league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character positions and byte positions, and the Autolink extension can also copy and validate the remaining line at every URL-like prefix, allowing an attacker who can submit Markdown for conversion to consume disproportionate CPU time with a comparatively small request. This issue is fixed in 2.9.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/thephpleague/commonmark/commit/a6ef6cdc308dfa39a34239c35818e75892a0e6a8",
                "https://github.com/thephpleague/commonmark/commit/a70979ea0d7d3377bd7127536748454a922bf5eb",
                "https://github.com/thephpleague/commonmark/commit/c97b02e5e652b992033b93ba5d6182f706343fc6",
                "https://github.com/thephpleague/commonmark/releases/tag/2.9.0",
                "https://github.com/thephpleague/commonmark/security/advisories/GHSA-2q4p-g7hv-5rgv"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:31.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71488"
                }
            ]
        },
        {
            "id": "CVE-2026-71478",
            "vendor": "thephpleague",
            "product": "commonmark",
            "title": "commonmark vulnerability",
            "summary": "league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed, or leading C0 control character, in a javascript: URL that browsers discard before parsing the scheme, causing the browser to still execute the script even when the unsafe-link filter is enabled. This issue is fixed in 2.9.0.",
            "updated_at": "2026-09-10T20:41:33.140",
            "published_at": "2026-08-06T22:18:31.750",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 1.5.0, <= 2.8.3",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed, or leading C0 control character, in a javascript: URL that browsers discard before parsing the scheme, causing the browser to still execute the script even when the unsafe-link filter is enabled. This issue is fixed in 2.9.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/thephpleague/commonmark/commit/493a5aa7d65754b73846006eaff9c2c4431a8e2c",
                "https://github.com/thephpleague/commonmark/releases/tag/2.9.0",
                "https://github.com/thephpleague/commonmark/security/advisories/GHSA-29pj-957v-52mc"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:31.750",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71478"
                }
            ]
        },
        {
            "id": "CVE-2026-71475",
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Management for Kubernetes 2.13",
            "title": "Red Hat Advanced Cluster Management for Kubernetes 2.13 vulnerability",
            "summary": "A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validation or URL encoding. This vulnerability allows a malicious spoke to redirect authenticated requests to unintended API endpoints, potentially leading to information disclosure or unauthorized access.",
            "updated_at": "2026-09-05T18:17:28.350",
            "published_at": "2026-08-11T20:18:45.673",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validation or URL encoding. This vulnerability allows a malicious spoke to redirect authenticated requests to unintended API endpoints, potentially leading to information disclosure or unauthorized access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/errata/RHSA-2026:60389",
                "https://access.redhat.com/errata/RHSA-2026:60390",
                "https://access.redhat.com/errata/RHSA-2026:60391",
                "https://access.redhat.com/security/cve/CVE-2026-71475",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2512154"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T20:18:45.673",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71475"
                }
            ]
        },
        {
            "id": "CVE-2026-71474",
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Management for Kubernetes 2.11",
            "title": "Red Hat Advanced Cluster Management for Kubernetes 2.11 vulnerability",
            "summary": "A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized access to Red Hat cloud services.",
            "updated_at": "2026-09-05T18:17:28.207",
            "published_at": "2026-08-11T20:18:45.547",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-532",
            "what_happened": "A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized access to Red Hat cloud services.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/errata/RHSA-2026:60387",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/errata/RHSA-2026:60389",
                "https://access.redhat.com/errata/RHSA-2026:60390",
                "https://access.redhat.com/errata/RHSA-2026:60391",
                "https://access.redhat.com/security/cve/CVE-2026-71474",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2512153"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T20:18:45.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71474"
                }
            ]
        },
        {
            "id": "CVE-2026-71468",
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Management for Kubernetes 2.11",
            "title": "Red Hat Advanced Cluster Management for Kubernetes 2.11 vulnerability",
            "summary": "A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.",
            "updated_at": "2026-09-05T18:17:28.070",
            "published_at": "2026-08-11T20:18:45.410",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-266",
            "what_happened": "A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/errata/RHSA-2026:60387",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/errata/RHSA-2026:60389",
                "https://access.redhat.com/errata/RHSA-2026:60390",
                "https://access.redhat.com/errata/RHSA-2026:60391",
                "https://access.redhat.com/security/cve/CVE-2026-71468",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2512147"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T20:18:45.410",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71468"
                }
            ]
        },
        {
            "id": "CVE-2026-71433",
            "vendor": "langchain-ai",
            "product": "langgraph",
            "title": "langgraph vulnerability",
            "summary": "LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarchical namespaces as a dot joined string and scoped reads by matching that string as a simple prefix pattern, so a read scoped to one namespace could also match a sibling namespace whose flattened form shares the same leading characters, or a namespace label containing unescaped pattern metacharacters, allowing an authenticated caller to retrieve stored items belonging to another tenant or user through an ordinary scoped search or list namespaces call, with no crafted input required. This issue is fixed in versions 3.1.1 of langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite.",
            "updated_at": "2026-09-10T20:41:33.140",
            "published_at": "2026-08-06T22:18:30.107",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.1.1",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-200",
            "what_happened": "LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarchical namespaces as a dot joined string and scoped reads by matching that string as a simple prefix pattern, so a read scoped to one namespace could also match a sibling namespace whose flattened form shares the same leading characters, or a namespace label containing unescaped pattern metacharacters, allowing an authenticated caller to retrieve stored items belonging to another tenant or user through an ordinary scoped search or list namespaces call, with no crafted input required. This issue is fixed in versions 3.1.1 of langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/langchain-ai/langgraph/commit/66ebe1a0da921e73f0f9f879ba105d314c079f7c",
                "https://github.com/langchain-ai/langgraph/pull/8478",
                "https://github.com/langchain-ai/langgraph/releases/tag/checkpointpostgres%3D%3D3.1.1",
                "https://github.com/langchain-ai/langgraph/releases/tag/checkpointsqlite%3D%3D3.1.1",
                "https://github.com/langchain-ai/langgraph/security/advisories/GHSA-47pj-3jcm-6whg"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:30.107",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71433"
                }
            ]
        },
        {
            "id": "CVE-2026-71430",
            "vendor": "uhop",
            "product": "node-re2",
            "title": "node-re2 vulnerability",
            "summary": "node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that V8 returns when the resulting string or buffer exceeds V8's maximum string length. When a global replace uses an output amplifying replacement template, the result can grow quadratically with the input size, and once the result exceeds V8's maximum string length, the unchecked ToLocalChecked call causes a fatal, uncatchable process abort instead of a catchable exception. This issue is fixed in version 1.25.1.",
            "updated_at": "2026-09-10T20:30:11.423",
            "published_at": "2026-08-06T22:18:29.963",
            "cvss": 6.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.25.1",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-617",
            "what_happened": "node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that V8 returns when the resulting string or buffer exceeds V8's maximum string length. When a global replace uses an output amplifying replacement template, the result can grow quadratically with the input size, and once the result exceeds V8's maximum string length, the unchecked ToLocalChecked call causes a fatal, uncatchable process abort instead of a catchable exception. This issue is fixed in version 1.25.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/uhop/node-re2/security/advisories/GHSA-8hcv-x26h-mcgp"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:29.963",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71430"
                }
            ]
        },
        {
            "id": "CVE-2026-71399",
            "vendor": "Adobe",
            "product": "Adobe XD",
            "title": "Adobe XD vulnerability",
            "summary": "Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "updated_at": "2026-09-15T15:01:17.123",
            "published_at": "2026-08-25T18:18:00.903",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 60 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "Adobe XD is affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://helpx.adobe.com/security/products/xd/apsb26-125.html"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T18:18:00.903",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71399"
                }
            ]
        },
        {
            "id": "CVE-2026-71380",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid request headers with a large Content-Length and then stalling before the body is complete.\n\nhttpd_request_handler:handle_info/2 cancels the request timeout as soon as a parse step succeeds, which includes the headers, and the clause that handles a decoder asking for more data re-arms the socket with {active, once} without setting any further timer. httpd_request:whole_body/2 returns such a continuation whenever the bytes received are fewer than the announced Content-Length, so a well-formed request that stops mid-body leaves the worker waiting indefinitely. The periodic byte-rate check that would reclaim it is armed only when minimum_bytes_per_second is configured, which it is not by default. Repeating this across connections occupies every worker permitted by max_clients and denies service to legitimate clients at negligible bandwidth cost.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "updated_at": "2026-09-08T01:17:53.310",
            "published_at": "2026-09-01T15:17:24.637",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 5.10 through before 9.3.2.7 (otp); 9.4 through before 9.6.2.3 (otp); 9.7 through before 9.7.2 (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before 81b453aac5a006bb8d26405f2bc3cf24e9d7733c (git)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-772",
            "what_happened": "Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending valid request headers with a large Content-Length and then stalling before the body is complete.\n\nhttpd_request_handler:handle_info/2 cancels the request timeout as soon as a parse step succeeds, which includes the headers, and the clause that handles a decoder asking for more data re-arms the socket with {active, once} without setting any further timer. httpd_request:whole_body/2 returns such a continuation whenever the bytes received are fewer than the announced Content-Length, so a well-formed request that stops mid-body leaves the worker waiting indefinitely. The periodic byte-rate check that would reclaim it is armed only when minimum_bytes_per_second is configured, which it is not by default. Repeating this across connections occupies every worker permitted by max_clients and denies service to legitimate clients at negligible bandwidth cost.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-71380.html",
                "https://github.com/erlang/otp/commit/81b453aac5a006bb8d26405f2bc3cf24e9d7733c",
                "https://github.com/erlang/otp/security/advisories/GHSA-5vp4-58hc-h8cc",
                "https://osv.dev/vulnerability/EEF-CVE-2026-71380",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:24.637",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71380"
                }
            ]
        },
        {
            "id": "CVE-2026-71362",
            "vendor": "Adobe",
            "product": "Adobe Commerce",
            "title": "Adobe Commerce vulnerability",
            "summary": "Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.",
            "updated_at": "2026-09-15T14:33:10.020",
            "published_at": "2026-08-11T18:18:21.610",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug (custom); 0 through 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul (custom); 0 through 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://helpx.adobe.com/security/products/magento/apsb26-92.html"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T18:18:21.610",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71362"
                }
            ]
        },
        {
            "id": "CVE-2026-71348",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.",
            "updated_at": "2026-09-15T13:00:26.280",
            "published_at": "2026-09-08T18:20:14.780",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Physical",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Spaceport.sys allows an unauthorized attacker to execute code with a physical attack.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71348"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:14.780",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71348"
                }
            ]
        },
        {
            "id": "CVE-2026-71343",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.",
            "updated_at": "2026-09-15T13:01:19.020",
            "published_at": "2026-09-08T18:20:14.397",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71343"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:14.397",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71343"
                }
            ]
        },
        {
            "id": "CVE-2026-71342",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-15T13:02:36.573",
            "published_at": "2026-09-08T18:20:14.230",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71342"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:14.230",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71342"
                }
            ]
        },
        {
            "id": "CVE-2026-71341",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.",
            "updated_at": "2026-09-15T13:03:53.213",
            "published_at": "2026-09-08T18:20:14.057",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "Out-of-bounds read in Windows Partition Management Driver allows an authorized attacker to disclose information locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71341"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:14.057",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71341"
                }
            ]
        },
        {
            "id": "CVE-2026-71340",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-15T13:05:08.690",
            "published_at": "2026-09-08T18:20:13.897",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71340"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:13.897",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71340"
                }
            ]
        },
        {
            "id": "CVE-2026-71339",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-15T13:07:08.877",
            "published_at": "2026-09-08T18:20:13.720",
            "cvss": 6.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71339"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:13.720",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71339"
                }
            ]
        },
        {
            "id": "CVE-2026-71338",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-15T13:07:56.120",
            "published_at": "2026-09-08T18:20:13.573",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-415",
            "what_happened": "Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71338"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:13.573",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71338"
                }
            ]
        },
        {
            "id": "CVE-2026-71337",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2",
            "title": "Windows 10 Version 21H2 vulnerability",
            "summary": "Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-15T13:08:44.657",
            "published_at": "2026-09-08T18:20:13.430",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "Stack-based buffer overflow in Windows Storage Management Provider allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71337"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:13.430",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71337"
                }
            ]
        },
        {
            "id": "CVE-2026-71329",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.",
            "updated_at": "2026-09-15T13:09:49.930",
            "published_at": "2026-09-08T18:20:12.307",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Physical",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code with a physical attack.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71329"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:12.307",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71329"
                }
            ]
        },
        {
            "id": "CVE-2026-71269",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "summary": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "updated_at": "2026-09-16T06:16:31.323",
            "published_at": "2026-08-05T13:24:51.207",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [],
            "timeline": [
                {
                    "at": "2026-08-05T13:24:51.207",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71269"
                }
            ]
        },
        {
            "id": "CVE-2026-70922",
            "vendor": "Oracle Corporation",
            "product": "Oracle Financial Services Enterprise Case Management",
            "title": "Oracle Financial Services Enterprise Case Management vulnerability",
            "summary": "Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI).  Supported versions that are affected are 8.0.8.2 and  8.1.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Enterprise Case Management.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Enterprise Case Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
            "updated_at": "2026-09-11T20:17:35.350",
            "published_at": "2026-08-18T21:17:50.043",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.0.8.2 (semver); 8.1.2.11 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI).  Supported versions that are affected are 8.0.8.2 and  8.1.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Enterprise Case Management.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Enterprise Case Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.oracle.com/security-alerts/cspuaug2026.html"
            ],
            "timeline": [
                {
                    "at": "2026-08-18T21:17:50.043",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70922"
                }
            ]
        },
        {
            "id": "CVE-2026-70910",
            "vendor": "Oracle Corporation",
            "product": "Siebel CRM Integration",
            "title": "Siebel CRM Integration vulnerability",
            "summary": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST).  Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
            "updated_at": "2026-09-11T20:17:09.263",
            "published_at": "2026-08-18T21:17:48.870",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through 26.6 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST).  Supported versions that are affected are 17.0-26.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.oracle.com/security-alerts/cspuaug2026.html"
            ],
            "timeline": [
                {
                    "at": "2026-08-18T21:17:48.870",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70910"
                }
            ]
        },
        {
            "id": "CVE-2026-70852",
            "vendor": "Oracle Corporation",
            "product": "Oracle Demand Planning",
            "title": "Oracle Demand Planning vulnerability",
            "summary": "Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations).  Supported versions that are affected are 12.1 and  12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Demand Planning.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Demand Planning accessible data as well as  unauthorized update, insert or delete access to some of Oracle Demand Planning accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
            "updated_at": "2026-09-11T20:15:12.970",
            "published_at": "2026-08-18T21:17:41.210",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "12.1 (semver); 12.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations).  Supported versions that are affected are 12.1 and  12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Demand Planning.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Demand Planning accessible data as well as  unauthorized update, insert or delete access to some of Oracle Demand Planning accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.oracle.com/security-alerts/cspuaug2026.html"
            ],
            "timeline": [
                {
                    "at": "2026-08-18T21:17:41.210",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70852"
                }
            ]
        },
        {
            "id": "CVE-2026-70846",
            "vendor": "Oracle Corporation",
            "product": "Oracle Demand Planning",
            "title": "Oracle Demand Planning vulnerability",
            "summary": "Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations).  Supported versions that are affected are 12.1 and  12.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Planning.  While the vulnerability is in Oracle Demand Planning, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Demand Planning accessible data as well as  unauthorized access to critical data or complete access to all Oracle Demand Planning accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
            "updated_at": "2026-09-11T20:15:00.937",
            "published_at": "2026-08-18T21:17:40.430",
            "cvss": 9.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "12.1 (semver); 12.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations).  Supported versions that are affected are 12.1 and  12.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Planning.  While the vulnerability is in Oracle Demand Planning, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Demand Planning accessible data as well as  unauthorized access to critical data or complete access to all Oracle Demand Planning accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.oracle.com/security-alerts/cspuaug2026.html"
            ],
            "timeline": [
                {
                    "at": "2026-08-18T21:17:40.430",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70846"
                }
            ]
        },
        {
            "id": "CVE-2026-70737",
            "vendor": "Oracle Corporation",
            "product": "Oracle Enterprise Manager for Systems Infrastructure",
            "title": "Oracle Enterprise Manager for Systems Infrastructure vulnerability",
            "summary": "Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Storage Server Management).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Systems Infrastructure.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Systems Infrastructure. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
            "updated_at": "2026-09-11T20:14:41.213",
            "published_at": "2026-08-18T21:17:26.440",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "13.5 (semver); 24.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "Vulnerability in the Oracle Enterprise Manager for Systems Infrastructure product of Oracle Enterprise Manager (component: Storage Server Management).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Systems Infrastructure.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Systems Infrastructure. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.oracle.com/security-alerts/cspuaug2026.html"
            ],
            "timeline": [
                {
                    "at": "2026-08-18T21:17:26.440",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70737"
                }
            ]
        },
        {
            "id": "CVE-2026-70636",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST request to the oauth2-credential refresh route with a trailing credential identifier to bypass all authentication and authorization checks, triggering unauthorized OAuth token rotation against credentials belonging to any workspace and potentially disrupting dependent OAuth integrations. This is a bypass of CVE-2026-41273.",
            "updated_at": "2026-09-15T16:02:22.903",
            "published_at": "2026-08-06T22:18:28.150",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "0 through 3.1.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST request to the oauth2-credential refresh route with a trailing credential identifier to bypass all authentication and authorization checks, triggering unauthorized OAuth token rotation against credentials belonging to any workspace and potentially disrupting dependent OAuth integrations. This is a bypass of CVE-2026-41273.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-70636.md"
                }
            ],
            "references": [
                "https://flowiseai.com/sunset",
                "https://github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-70636.md",
                "https://www.vulncheck.com/advisories/flowise-authentication-bypass-via-oauth2-credential-refresh-endpoint"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:28.150",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70636"
                }
            ]
        },
        {
            "id": "CVE-2026-70618",
            "vendor": "Spacebar Server",
            "product": "Spacebar Server",
            "title": "Spacebar Server vulnerability",
            "summary": "Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids endpoint without guild membership verification. Attackers can exploit the unprotected route handler in the roles member-ids endpoint, which lacks permission checks present in sibling endpoints, to retrieve the full list of member user IDs for any guild on the instance using only a valid bearer token and a known guild ID.",
            "updated_at": "2026-09-16T20:34:39.840",
            "published_at": "2026-08-05T20:17:17.940",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 51da17cf19d476483ee44e5f832d1ebdcd844f88 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user to enumerate complete guild membership by querying the GET /guilds/{guild_id}/roles/{role_id}/member-ids endpoint without guild membership verification. Attackers can exploit the unprotected route handler in the roles member-ids endpoint, which lacks permission checks present in sibling endpoints, to retrieve the full list of member user IDs for any guild on the instance using only a valid bearer token and a known guild ID.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/spacebarchat/server/commit/51da17cf19d476483ee44e5f832d1ebdcd844f88",
                "https://github.com/spacebarchat/server/security/advisories/GHSA-p5cf-7hg9-gf65",
                "https://www.vulncheck.com/advisories/spacebar-server-missing-authorization-via-member-ids-endpoint"
            ],
            "timeline": [
                {
                    "at": "2026-08-05T20:17:17.940",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70618"
                }
            ]
        },
        {
            "id": "CVE-2026-70617",
            "vendor": "Spacebar Server",
            "product": "Spacebar Server",
            "title": "Spacebar Server vulnerability",
            "summary": "Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can exploit the unguarded PUT /channels/{channel_id}/recipients/{user_id} handler to join private group DMs, read complete message history, post messages as a participant, and force-add third-party users without their consent.",
            "updated_at": "2026-09-16T20:34:51.637",
            "published_at": "2026-08-05T20:17:17.770",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through dcfd91035e3da42abf5f32d8d86a35219225b3d4 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can exploit the unguarded PUT /channels/{channel_id}/recipients/{user_id} handler to join private group DMs, read complete message history, post messages as a participant, and force-add third-party users without their consent.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/spacebarchat/server/commit/dcfd91035e3da42abf5f32d8d86a35219225b3d4",
                "https://github.com/spacebarchat/server/security/advisories/GHSA-g38j-78fh-jm74",
                "https://www.vulncheck.com/advisories/spacebar-server-missing-authorization-via-group-dm-recipient-endpoint"
            ],
            "timeline": [
                {
                    "at": "2026-08-05T20:17:17.770",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70617"
                }
            ]
        },
        {
            "id": "CVE-2026-70587",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.",
            "updated_at": "2026-09-15T13:11:00.830",
            "published_at": "2026-09-08T18:20:11.980",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-170",
            "what_happened": "Improper null termination in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70587"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:11.980",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70587"
                }
            ]
        },
        {
            "id": "CVE-2026-70547",
            "vendor": "jfrog",
            "product": "artifactory",
            "title": "artifactory vulnerability",
            "summary": "An authenticated user without repository read permission may access package metadata under specific conditions.",
            "updated_at": "2026-09-11T18:43:59.277",
            "published_at": "2026-08-12T16:17:21.440",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.161.0 through before 7.161.16 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "An authenticated user without repository read permission may access package metadata under specific conditions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
                "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:21.440",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70547"
                }
            ]
        },
        {
            "id": "CVE-2026-70478",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The endpoint decrypts the stored credential, sends a refresh request to the configured OAuth provider with the client secret and refresh token, and returns the refreshed access_token in the response body. An attacker with a credential ID can use the token to access the victim's connected service and can also exhaust refresh-token quota. This issue is fixed in 3.1.3.",
            "updated_at": "2026-09-11T21:14:26.357",
            "published_at": "2026-08-04T20:16:54.610",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.1.2",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The endpoint decrypts the stored credential, sends a refresh request to the configured OAuth provider with the client secret and refresh token, and returns the refreshed access_token in the response body. An attacker with a credential ID can use the token to access the victim's connected service and can also exhaust refresh-token quota. This issue is fixed in 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-qgvm-j2hm-6m38"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T20:16:54.610",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70478"
                }
            ]
        },
        {
            "id": "CVE-2026-70477",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific flaw exists within the run method of the CSV_Agents class, where untrusted data is used to construct an LLM prompt and the resulting pythonCode is validated by validatePythonCodeForDataFrame before execution. An attacker can leverage this to execute arbitrary code in the context of the service account. This issue is fixed in 3.1.3.",
            "updated_at": "2026-09-11T21:09:26.917",
            "published_at": "2026-08-04T20:16:54.473",
            "cvss": 9.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.1.2",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-94",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in an unsandboxed Pyodide environment. The specific flaw exists within the run method of the CSV_Agents class, where untrusted data is used to construct an LLM prompt and the resulting pythonCode is validated by validatePythonCodeForDataFrame before execution. An attacker can leverage this to execute arbitrary code in the context of the service account. This issue is fixed in 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/f4e2794f6a576b94578f2fdafbf49c2fb304626c",
                "https://github.com/FlowiseAI/Flowise/pull/6499",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-5xvg-pmgg-3mxr"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T20:16:54.473",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70477"
                }
            ]
        },
        {
            "id": "CVE-2026-70476",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts accept attacker-controlled Stripe subscriptionId values without verifying that the identifier belongs to the authenticated user's organization. An authenticated attacker can perform unauthorized Stripe subscription operations on other tenants, including changing subscription plans or modifying seat quantities, resulting in financial impact and service disruption. This issue is fixed in 3.1.3.",
            "updated_at": "2026-09-11T21:09:17.230",
            "published_at": "2026-08-04T20:16:54.330",
            "cvss": 8.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.2",
            "fixed": "See vendor advisory",
            "source_count": 24,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterprise/controllers/organization.controller.ts accept attacker-controlled Stripe subscriptionId values without verifying that the identifier belongs to the authenticated user's organization. An authenticated attacker can perform unauthorized Stripe subscription operations on other tenants, including changing subscription plans or modifying seat quantities, resulting in financial impact and service disruption. This issue is fixed in 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-gmmw-qg98-6j6p"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/4d7899d02ca370a5510406be5c91483085a412f9",
                "https://github.com/FlowiseAI/Flowise/pull/6321",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-gmmw-qg98-6j6p"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T20:16:54.330",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70476"
                }
            ]
        },
        {
            "id": "CVE-2026-70475",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware that protects other execution endpoints. Any authenticated user, regardless of assigned permissions, can modify execution state, data, and metadata of any execution in their workspace, enabling privilege escalation and manipulation of workflow execution results. This issue is fixed in 3.1.3.",
            "updated_at": "2026-09-11T21:08:48.403",
            "published_at": "2026-08-04T20:16:54.170",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.1.2",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware that protects other execution endpoints. Any authenticated user, regardless of assigned permissions, can modify execution state, data, and metadata of any execution in their workspace, enabling privilege escalation and manipulation of workflow execution results. This issue is fixed in 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/96a9b23b5a103b362a0ee1368d04636755be1bed",
                "https://github.com/FlowiseAI/Flowise/pull/6409",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-fm2f-4339-4p2f"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T20:16:54.170",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70475"
                }
            ]
        },
        {
            "id": "CVE-2026-70474",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback, and refresh handlers query the Credential table by id only; callback and refresh are whitelisted from authentication. This allows any authenticated user to initiate OAuth2 flows against credentials belonging to other workspaces, allows an unauthenticated attacker to forge OAuth2 callbacks to overwrite tokens in any credential, and allows an unauthenticated attacker to refresh tokens for any credential. The affected routes include /api/v1/oauth2-credential/authorize/<VICTIM_CREDENTIAL_UUID>, /api/v1/oauth2-credential/callback?code=ATTACKER_AUTH_CODE&state=<VICTIM_CREDENTIAL_UUID>, and /api/v1/oauth2-credential/refresh/<VICTIM_CREDENTIAL_UUID>. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-11T21:07:42.970",
            "published_at": "2026-08-04T19:16:54.977",
            "cvss": 7.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback, and refresh handlers query the Credential table by id only; callback and refresh are whitelisted from authentication. This allows any authenticated user to initiate OAuth2 flows against credentials belonging to other workspaces, allows an unauthenticated attacker to forge OAuth2 callbacks to overwrite tokens in any credential, and allows an unauthenticated attacker to refresh tokens for any credential. The affected routes include /api/v1/oauth2-credential/authorize/<VICTIM_CREDENTIAL_UUID>, /api/v1/oauth2-credential/callback?code=ATTACKER_AUTH_CODE&state=<VICTIM_CREDENTIAL_UUID>, and /api/v1/oauth2-credential/refresh/<VICTIM_CREDENTIAL_UUID>. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wch5-xp77-fxg4"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wch5-xp77-fxg4"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T19:16:54.977",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70474"
                }
            ]
        },
        {
            "id": "CVE-2026-70473",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response can exceed 100MB and includes sensitive configuration data, including Vector Store settings such as Qdrant Server URL and collection name. The observed behavior indicates missing or insufficient authorization checks, workspace/project/tenant isolation, and pagination or limits, exposing integration parameters and infrastructure details that may enable further targeted attacks. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-11T21:05:40.573",
            "published_at": "2026-08-04T19:16:54.830",
            "cvss": 8.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 24,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response can exceed 100MB and includes sensitive configuration data, including Vector Store settings such as Qdrant Server URL and collection name. The observed behavior indicates missing or insufficient authorization checks, workspace/project/tenant isolation, and pagination or limits, exposing integration parameters and infrastructure details that may enable further targeted attacks. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-fr6g-7cq8-fg82"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/d81483b70c997ddf981acc9c49fbd9a02fa345cd",
                "https://github.com/FlowiseAI/Flowise/pull/6170",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-fr6g-7cq8-fg82"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T19:16:54.830",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70473"
                }
            ]
        },
        {
            "id": "CVE-2026-70472",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without checking whether that credential belongs to the caller workspace. Route permissions assistants:* only check feature access. The controller passes req.query.credential straight to the service, and the service uses findOneBy({ id: credentialId }), decrypts the credential, and calls OpenAI APIs without a workspaceId check. If an attacker knows another workspace credentialId, the attacker can use that workspace OpenAI key, read, modify, or delete victim vector stores and files, cause billing impact on the victim OpenAI account, and violate multi-tenant boundaries. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T19:01:45.947",
            "published_at": "2026-08-04T19:16:54.680",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without checking whether that credential belongs to the caller workspace. Route permissions assistants:* only check feature access. The controller passes req.query.credential straight to the service, and the service uses findOneBy({ id: credentialId }), decrypts the credential, and calls OpenAI APIs without a workspaceId check. If an attacker knows another workspace credentialId, the attacker can use that workspace OpenAI key, read, modify, or delete victim vector stores and files, cause billing impact on the victim OpenAI account, and violate multi-tenant boundaries. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/d81483b70c997ddf981acc9c49fbd9a02fa345cd",
                "https://github.com/FlowiseAI/Flowise/pull/6170",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-chm3-vqcf-52rx"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T19:16:54.680",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70472"
                }
            ]
        },
        {
            "id": "CVE-2026-70471",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protected Variables API. Variables for the active workspace are fetched at packages/components/src/utils.ts and runtime variables are resolved from server environment variables, while the official variables route enforces variables:view. A user or API key that is denied variables:view can call /api/v1/node-custom-function and receive $vars pre-populated with all variables for the workspace, including Variable.name to Variable.value static variables and Variable.name to process.env[Variable.name] runtime variables. This can expose secrets such as database passwords, JWT secrets, SMTP passwords, and cloud keys, depending on the workspace Variables configuration. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T19:09:15.917",
            "published_at": "2026-08-04T19:16:54.540",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protected Variables API. Variables for the active workspace are fetched at packages/components/src/utils.ts and runtime variables are resolved from server environment variables, while the official variables route enforces variables:view. A user or API key that is denied variables:view can call /api/v1/node-custom-function and receive $vars pre-populated with all variables for the workspace, including Variable.name to Variable.value static variables and Variable.name to process.env[Variable.name] runtime variables. This can expose secrets such as database passwords, JWT secrets, SMTP passwords, and cloud keys, depending on the workspace Variables configuration. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-8r8h-6vcc-xhrv"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T19:16:54.540",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70471"
                }
            ]
        },
        {
            "id": "CVE-2026-70470",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbitrary Python execution inside Pyodide and full OS command execution on the Flowise host via Pyodide js module interop. The validator gates pyodide.runPythonAsync in packages/components/nodes/agents/CSVAgent/CSVAgent.ts and packages/components/nodes/agents/AirtableAgent/AirtableAgent.ts with an ASCII word-boundary blacklist. JavaScript regex word boundaries are ASCII-only, while Python 3 NFKC-normalizes identifiers at parse time, so homoglyph forms such as __cl𝐚ss__, __subcl𝐚sses__, __b𝐚se__, and __b𝐮iltins__ bypass the blacklist and are parsed as their ASCII equivalents. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T19:19:38.873",
            "published_at": "2026-08-04T18:16:57.930",
            "cvss": 9.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-184",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbitrary Python execution inside Pyodide and full OS command execution on the Flowise host via Pyodide js module interop. The validator gates pyodide.runPythonAsync in packages/components/nodes/agents/CSVAgent/CSVAgent.ts and packages/components/nodes/agents/AirtableAgent/AirtableAgent.ts with an ASCII word-boundary blacklist. JavaScript regex word boundaries are ASCII-only, while Python 3 NFKC-normalizes identifiers at parse time, so homoglyph forms such as __cl𝐚ss__, __subcl𝐚sses__, __b𝐚se__, and __b𝐮iltins__ bypass the blacklist and are parsed as their ASCII equivalents. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-52fh-8v99-63c2"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/f4e2794f6a576b94578f2fdafbf49c2fb304626c",
                "https://github.com/FlowiseAI/Flowise/pull/6499",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-52fh-8v99-63c2"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T18:16:57.930",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70470"
                }
            ]
        },
        {
            "id": "CVE-2026-70425",
            "vendor": "Dell",
            "product": "PowerScale OneFS",
            "title": "PowerScale OneFS vulnerability",
            "summary": "Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability. An admin privileged local attacker could potentially exploit this vulnerability, leading to elevation of privileges to root, impacting confidentiality, integrity, and availability.",
            "updated_at": "2026-09-11T04:17:48.910",
            "published_at": "2026-09-09T17:17:32.920",
            "cvss": 6.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 9.13.1.1 or later (semver); before 9.15.0.0 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability. An admin privileged local attacker could potentially exploit this vulnerability, leading to elevation of privileges to root, impacting confidentiality, integrity, and availability.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000505684/dsa-2026-360-security-update-for-dell-powerscale-onefs-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T17:17:32.920",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70425"
                }
            ]
        },
        {
            "id": "CVE-2026-70409",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of digits.\n\neldap:parse_port/2 passes the port substring straight to list_to_integer/1 with no length bound. The surrounding try ... catch only rejects a value that fails to parse, so a syntactically valid port of up to roughly 1.26 million digits converts successfully and costs the caller hundreds of milliseconds of arbitrary-precision arithmetic per referral. The conversion function itself is documented to accept integers of any size, so bounding the input is the caller's responsibility. Reaching the flaw requires the application to pass a server-supplied referral to eldap:parse_ldap_url/1, which eldap never calls itself: referral strings are returned to the caller unparsed.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to eldap from 1.0.3 before 1.2.14.2, from 1.2.15 before 1.2.16.1, and from 1.3 before 1.3.1.",
            "updated_at": "2026-09-08T01:17:53.137",
            "published_at": "2026-09-01T15:17:24.427",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 1.0.3 through before 1.2.14.2 (otp); 1.2.15 through before 1.2.16.1 (otp); 1.3 through before 1.3.1 (otp); d8dbf15de4fa1a08b9a05e7d8e08fdb025fe1dc3 through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1284",
            "what_happened": "Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP server to degrade availability by returning a referral URL whose port component is a very long run of digits.\n\neldap:parse_port/2 passes the port substring straight to list_to_integer/1 with no length bound. The surrounding try ... catch only rejects a value that fails to parse, so a syntactically valid port of up to roughly 1.26 million digits converts successfully and costs the caller hundreds of milliseconds of arbitrary-precision arithmetic per referral. The conversion function itself is documented to accept integers of any size, so bounding the input is the caller's responsibility. Reaching the flaw requires the application to pass a server-supplied referral to eldap:parse_ldap_url/1, which eldap never calls itself: referral strings are returned to the caller unparsed.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to eldap from 1.0.3 before 1.2.14.2, from 1.2.15 before 1.2.16.1, and from 1.3 before 1.3.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-70409.html",
                "https://github.com/erlang/otp/commit/aba0fe8c2d700bf4ac94607cf7f00e53bbe4042d",
                "https://github.com/erlang/otp/commit/e3be1cfe9f6cedd0cd20d9905e05601dfb31c8aa",
                "https://github.com/erlang/otp/security/advisories/GHSA-9vgh-c8cm-m9p4",
                "https://osv.dev/vulnerability/EEF-CVE-2026-70409",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:24.427",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70409"
                }
            ]
        },
        {
            "id": "CVE-2026-70405",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a BER INTEGER whose length field is arbitrarily large.\n\nsnmp_pdus:dec_integer_notag/1 defaults its size limit to infinity, and do_dec_integer_notag/2 then accumulates the value across every declared byte with a recursive shift and bitwise or. Work grows superlinearly in the declared length because each operation acts on a progressively larger bignum. The size-limited variant dec_integer_notag/2 exists but is reached from only one call site, dec_snmp_version/1, which bounds the version field to ten bytes; the request identifier, error status and index, generic and specific trap fields, engine boots and time, and every varbind value decoded by dec_value/1 all use the unbounded form. The decode runs before the PDU is processed, so no valid request is required beyond what the deployment demands to accept the message at all.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to snmp from 4.25.1 before 5.18.2.1, from 5.19 before 5.20.2.2, and from 5.20.3 before 5.20.5. Whether OTP before OTP 17.0, corresponding to snmp before 4.25.1, is affected is unknown.",
            "updated_at": "2026-09-08T01:17:52.940",
            "published_at": "2026-09-01T15:17:24.193",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 4.25.1 through before 5.18.2.1 (otp); 5.19 through before 5.20.2.2 (otp); 5.20.3 through before 5.20.5 (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1284",
            "what_happened": "Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP snmp allows a remote attacker to degrade availability by sending an SNMP message containing a BER INTEGER whose length field is arbitrarily large.\n\nsnmp_pdus:dec_integer_notag/1 defaults its size limit to infinity, and do_dec_integer_notag/2 then accumulates the value across every declared byte with a recursive shift and bitwise or. Work grows superlinearly in the declared length because each operation acts on a progressively larger bignum. The size-limited variant dec_integer_notag/2 exists but is reached from only one call site, dec_snmp_version/1, which bounds the version field to ten bytes; the request identifier, error status and index, generic and specific trap fields, engine boots and time, and every varbind value decoded by dec_value/1 all use the unbounded form. The decode runs before the PDU is processed, so no valid request is required beyond what the deployment demands to accept the message at all.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to snmp from 4.25.1 before 5.18.2.1, from 5.19 before 5.20.2.2, and from 5.20.3 before 5.20.5. Whether OTP before OTP 17.0, corresponding to snmp before 4.25.1, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-70405.html",
                "https://github.com/erlang/otp/commit/aba0fe8c2d700bf4ac94607cf7f00e53bbe4042d",
                "https://github.com/erlang/otp/commit/e3be1cfe9f6cedd0cd20d9905e05601dfb31c8aa",
                "https://github.com/erlang/otp/security/advisories/GHSA-q7cq-pfgf-5hr7",
                "https://osv.dev/vulnerability/EEF-CVE-2026-70405",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:24.193",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70405"
                }
            ]
        },
        {
            "id": "CVE-2026-70399",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections. The max_clients option is documented to default to 150, and the inets hardening guide presents that limit as the first layer of denial-of-service defence, but a server that does not set it explicitly accepts an unlimited number of simultaneous connections. Establishing the connections is sufficient; no valid request and no authentication are required.\n\nThe accept gate in httpd_manager:handle_new_connection/4 reads the option with httpd_util:lookup/2, which returns undefined when the key is absent, rather than the three-argument form carrying the 150 default that the neighbouring get_ustate/2 uses. Erlang term ordering places every integer before every atom, so the Count =< Max guard holds for any connection count and the server never returns {reject, busy}. Each accepted connection occupies a worker process and a socket for as long as it is held, driving the node towards process, memory and file descriptor exhaustion. Servers that set max_clients explicitly are unaffected, because a configured value is applied as intended.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.",
            "updated_at": "2026-09-08T01:17:52.707",
            "published_at": "2026-09-01T15:17:23.947",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 5.10 through before 9.3.2.7 (otp); 9.4 through before 9.6.2.3 (otp); 9.7 through before 9.7.2 (otp); d9674f32811cd5bb02b0d6656053b5ee226bc74c through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections. The max_clients option is documented to default to 150, and the inets hardening guide presents that limit as the first layer of denial-of-service defence, but a server that does not set it explicitly accepts an unlimited number of simultaneous connections. Establishing the connections is sufficient; no valid request and no authentication are required.\n\nThe accept gate in httpd_manager:handle_new_connection/4 reads the option with httpd_util:lookup/2, which returns undefined when the key is absent, rather than the three-argument form carrying the 150 default that the neighbouring get_ustate/2 uses. Erlang term ordering places every integer before every atom, so the Count =< Max guard holds for any connection count and the server never returns {reject, busy}. Each accepted connection occupies a worker process and a socket for as long as it is held, driving the node towards process, memory and file descriptor exhaustion. Servers that set max_clients explicitly are unaffected, because a configured value is applied as intended.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-70399.html",
                "https://github.com/erlang/otp/commit/6746dc4e1df5257ad8ac91cbbd167cb8b0274ce7",
                "https://github.com/erlang/otp/commit/d94a94c96eb4cccbd6f7d7da5975f0c035b69612",
                "https://github.com/erlang/otp/commit/e0050fc00c500a4fa9ba1f594603c787ff6d20b2",
                "https://github.com/erlang/otp/security/advisories/GHSA-pwvh-c689-f8q5",
                "https://osv.dev/vulnerability/EEF-CVE-2026-70399",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:23.947",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70399"
                }
            ]
        },
        {
            "id": "CVE-2026-70352",
            "vendor": "Microsoft",
            "product": "Azure AI Language Authoring",
            "title": "Azure AI Language Authoring vulnerability",
            "summary": "Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-05T04:18:04.830",
            "published_at": "2026-09-03T23:17:20.213",
            "cvss": 10,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "-",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70352"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T23:17:20.213",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70352"
                }
            ]
        },
        {
            "id": "CVE-2026-70341",
            "vendor": "Microsoft",
            "product": "Microsoft Edge (Chromium-based)",
            "title": "Microsoft Edge (Chromium-based) vulnerability",
            "summary": "Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.",
            "updated_at": "2026-09-12T16:16:37.597",
            "published_at": "2026-09-11T16:17:46.080",
            "cvss": 8.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0.0 through before 152.0.4191.52 (custom); 1.0.0 through before 152.0.4191.52 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70341"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T16:17:46.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70341"
                }
            ]
        },
        {
            "id": "CVE-2026-70290",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.",
            "updated_at": "2026-09-15T12:44:03.730",
            "published_at": "2026-09-08T18:20:04.720",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-908",
            "what_happened": "Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70290"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:04.720",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70290"
                }
            ]
        },
        {
            "id": "CVE-2026-70289",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-15T12:42:52.957",
            "published_at": "2026-09-08T18:20:04.520",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70289"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:04.520",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70289"
                }
            ]
        },
        {
            "id": "CVE-2026-70178",
            "vendor": "Microsoft",
            "product": "Microsoft Fabric",
            "title": "Microsoft Fabric vulnerability",
            "summary": "Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-05T04:18:04.710",
            "published_at": "2026-09-03T23:17:20.083",
            "cvss": 8.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "-",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-862",
            "what_happened": "Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70178"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T23:17:20.083",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70178"
                }
            ]
        },
        {
            "id": "CVE-2026-69911",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-11T04:17:48.603",
            "published_at": "2026-09-08T18:20:02.413",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69911"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:02.413",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69911"
                }
            ]
        },
        {
            "id": "CVE-2026-69907",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-10T04:18:15.560",
            "published_at": "2026-09-08T18:20:01.067",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-280",
            "what_happened": "Improper handling of insufficient permissions or privileges in Windows Enterprise App Management allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69907"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:01.067",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69907"
                }
            ]
        },
        {
            "id": "CVE-2026-69906",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-15T12:30:24.650",
            "published_at": "2026-09-08T18:20:00.887",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69906"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:20:00.887",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69906"
                }
            ]
        },
        {
            "id": "CVE-2026-69875",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809",
            "title": "Windows 10 Version 1809 vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-15T12:31:27.100",
            "published_at": "2026-09-08T18:19:58.350",
            "cvss": 8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69875"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:58.350",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69875"
                }
            ]
        },
        {
            "id": "CVE-2026-69858",
            "vendor": "Microsoft",
            "product": "Windows Server 2022",
            "title": "Windows Server 2022 vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "updated_at": "2026-09-10T04:18:15.430",
            "published_at": "2026-09-08T18:19:57.143",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69858"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:57.143",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69858"
                }
            ]
        },
        {
            "id": "CVE-2026-69846",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-15T12:32:53.343",
            "published_at": "2026-09-08T18:19:56.153",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69846"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:56.153",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69846"
                }
            ]
        },
        {
            "id": "CVE-2026-69841",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-10T04:18:15.230",
            "published_at": "2026-09-08T18:19:55.650",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69841"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:55.650",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69841"
                }
            ]
        },
        {
            "id": "CVE-2026-69813",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "updated_at": "2026-09-10T04:18:15.070",
            "published_at": "2026-09-08T18:19:52.823",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69813"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:52.823",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69813"
                }
            ]
        },
        {
            "id": "CVE-2026-69775",
            "vendor": "Microsoft",
            "product": "Windows 11 version 23H2",
            "title": "Windows 11 version 23H2 vulnerability",
            "summary": "Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-10T04:18:14.937",
            "published_at": "2026-09-08T18:19:48.980",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69775"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:48.980",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69775"
                }
            ]
        },
        {
            "id": "CVE-2026-69730",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "updated_at": "2026-09-10T04:18:14.773",
            "published_at": "2026-09-08T18:19:45.140",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69730"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:45.140",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69730"
                }
            ]
        },
        {
            "id": "CVE-2026-69723",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a network.",
            "updated_at": "2026-09-15T12:34:10.603",
            "published_at": "2026-09-08T18:19:44.413",
            "cvss": 5.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-497",
            "what_happened": "Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69723"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:44.413",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69723"
                }
            ]
        },
        {
            "id": "CVE-2026-69709",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "updated_at": "2026-09-15T12:35:47.023",
            "published_at": "2026-09-08T18:19:42.550",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69709"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:42.550",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69709"
                }
            ]
        },
        {
            "id": "CVE-2026-69688",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-10T04:18:14.583",
            "published_at": "2026-09-08T18:19:40.870",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Encrypting File System (EFS) allows an authorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69688"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:40.870",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69688"
                }
            ]
        },
        {
            "id": "CVE-2026-69680",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network.",
            "updated_at": "2026-09-10T04:18:14.423",
            "published_at": "2026-09-08T18:19:39.613",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-346",
            "what_happened": "Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69680"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:39.613",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69680"
                }
            ]
        },
        {
            "id": "CVE-2026-69669",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to execute code over a network.",
            "updated_at": "2026-09-15T12:36:59.080",
            "published_at": "2026-09-08T18:19:38.537",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69669"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:38.537",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69669"
                }
            ]
        },
        {
            "id": "CVE-2026-69664",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hexadecimal number. The worker serving the connection is never released and no timeout reclaims it, so repeating the request across connections occupies every available worker and denies service to legitimate clients. No authentication is required and the default configuration is affected.\n\nThe chunk-size line must arrive in a write separate from the headers. When the body accompanies the headers, httpd_request_handler:handle_body/3 calls http_chunk:decode/3 inside a try ... catch throw:Error, so the {error, {chunk_size, _}} thrown by http_chunk:decode_size/4 is answered with 400 Bad Request. When the chunk size arrives later, the decoder is resumed through a bare catch in httpd_request_handler:handle_info/2, which converts the throw into a return value rather than raising it; the resulting error tuple is then treated as the next decoder continuation, the socket is re-armed, and the worker waits for data that never comes. The request timeout has already been cancelled at the point the headers were accepted, and the periodic byte-rate check is only armed when minimum_bytes_per_second is configured, which it is not by default.\n\nThis issue affects OTP from OTP 18.1.4 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 6.0.3 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.",
            "updated_at": "2026-09-08T01:17:52.473",
            "published_at": "2026-09-01T15:17:23.677",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "18.1.4 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 6.0.3 through before 9.3.2.7 (otp); 9.4 through before 9.6.2.3 (otp); 9.7 through before 9.7.2 (otp); 77acb473d8f056f6f534395f131c6e45693797f0 through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-772",
            "what_happened": "Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by sending a request with a chunked body whose chunk-size line is not a hexadecimal number. The worker serving the connection is never released and no timeout reclaims it, so repeating the request across connections occupies every available worker and denies service to legitimate clients. No authentication is required and the default configuration is affected.\n\nThe chunk-size line must arrive in a write separate from the headers. When the body accompanies the headers, httpd_request_handler:handle_body/3 calls http_chunk:decode/3 inside a try ... catch throw:Error, so the {error, {chunk_size, _}} thrown by http_chunk:decode_size/4 is answered with 400 Bad Request. When the chunk size arrives later, the decoder is resumed through a bare catch in httpd_request_handler:handle_info/2, which converts the throw into a return value rather than raising it; the resulting error tuple is then treated as the next decoder continuation, the socket is re-armed, and the worker waits for data that never comes. The request timeout has already been cancelled at the point the headers were accepted, and the periodic byte-rate check is only armed when minimum_bytes_per_second is configured, which it is not by default.\n\nThis issue affects OTP from OTP 18.1.4 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 6.0.3 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-69664.html",
                "https://github.com/erlang/otp/commit/a3adf63078438c86527d704e23282b7721d8ca12",
                "https://github.com/erlang/otp/commit/bd4e74348c6be8a49f060da6fd48d43f3a960292",
                "https://github.com/erlang/otp/commit/df1a9ca4666e2fdfc44886bfaae76de086d803f6",
                "https://github.com/erlang/otp/security/advisories/GHSA-mr35-8h7w-w3gq",
                "https://osv.dev/vulnerability/EEF-CVE-2026-69664",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:23.677",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69664"
                }
            ]
        },
        {
            "id": "CVE-2026-69645",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-10T04:18:14.237",
            "published_at": "2026-09-08T18:19:36.620",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69645"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:36.620",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69645"
                }
            ]
        },
        {
            "id": "CVE-2026-69638",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "updated_at": "2026-09-15T12:38:23.640",
            "published_at": "2026-09-08T18:19:36.133",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69638"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:36.133",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69638"
                }
            ]
        },
        {
            "id": "CVE-2026-69627",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally.",
            "updated_at": "2026-09-15T12:39:31.520",
            "published_at": "2026-09-08T18:19:34.933",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "Out-of-bounds read in Windows Remote Desktop Licensing Service allows an authorized attacker to disclose information locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69627"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:34.933",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69627"
                }
            ]
        },
        {
            "id": "CVE-2026-69616",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally.",
            "updated_at": "2026-09-15T12:41:03.720",
            "published_at": "2026-09-08T18:19:33.297",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to disclose information locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69616"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:33.297",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69616"
                }
            ]
        },
        {
            "id": "CVE-2026-69600",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-11T04:17:48.083",
            "published_at": "2026-09-08T18:19:30.663",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69600"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:30.663",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69600"
                }
            ]
        },
        {
            "id": "CVE-2026-69579",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.",
            "updated_at": "2026-09-10T04:18:14.027",
            "published_at": "2026-09-08T18:19:27.440",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69579"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:27.440",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69579"
                }
            ]
        },
        {
            "id": "CVE-2026-69575",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-10T04:18:13.843",
            "published_at": "2026-09-08T18:19:26.910",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69575"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:26.910",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69575"
                }
            ]
        },
        {
            "id": "CVE-2026-69551",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Windows DNS allows an authorized attacker to execute code over a network.",
            "updated_at": "2026-09-10T04:18:13.680",
            "published_at": "2026-09-08T18:19:23.677",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows DNS allows an authorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69551"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:23.677",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69551"
                }
            ]
        },
        {
            "id": "CVE-2026-69482",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally.",
            "updated_at": "2026-09-10T04:18:13.493",
            "published_at": "2026-09-08T18:19:14.313",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-379",
            "what_happened": "Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69482"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:14.313",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69482"
                }
            ]
        },
        {
            "id": "CVE-2026-69481",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-10T04:18:13.290",
            "published_at": "2026-09-08T18:19:14.137",
            "cvss": 8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69481"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:19:14.137",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69481"
                }
            ]
        },
        {
            "id": "CVE-2026-69310",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-10T04:18:13.093",
            "published_at": "2026-09-08T18:18:47.500",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69310"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:18:47.500",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69310"
                }
            ]
        },
        {
            "id": "CVE-2026-69290",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-10T04:18:12.873",
            "published_at": "2026-09-08T18:18:44.070",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "Stack-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69290"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:18:44.070",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69290"
                }
            ]
        },
        {
            "id": "CVE-2026-69264",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to globalThis, which on Node.js exposes eval and dynamic import, the attacker can break out of the Python string literal, hand a JavaScript string to js.eval, dynamically import Node built-in modules such as fs and child_process, and execute arbitrary file I/O or OS commands as the Flowise process. The two validator paths around this code, validatePythonCodeForDataFrame and validateCustomReadCSVFunction, are never applied to the bootstrap template. A workspace user with chatflows:create or agentflows/chatflows update permission can plant a CSV Agent node with a crafted csvFile; once the chatflow is exposed via POST /api/v1/prediction/:id, any unauthenticated request triggers host remote code execution. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T19:20:36.803",
            "published_at": "2026-08-04T18:16:57.027",
            "cvss": 9.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to globalThis, which on Node.js exposes eval and dynamic import, the attacker can break out of the Python string literal, hand a JavaScript string to js.eval, dynamically import Node built-in modules such as fs and child_process, and execute arbitrary file I/O or OS commands as the Flowise process. The two validator paths around this code, validatePythonCodeForDataFrame and validateCustomReadCSVFunction, are never applied to the bootstrap template. A workspace user with chatflows:create or agentflows/chatflows update permission can plant a CSV Agent node with a crafted csvFile; once the chatflow is exposed via POST /api/v1/prediction/:id, any unauthenticated request triggers host remote code execution. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-4j8x-x6v7-w9rq"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/f4e2794f6a576b94578f2fdafbf49c2fb304626c",
                "https://github.com/FlowiseAI/Flowise/pull/6499",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-4j8x-x6v7-w9rq"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T18:16:57.027",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69264"
                }
            ]
        },
        {
            "id": "CVE-2026-69263",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_PATH, DYLD_LIBRARY_PATH, and NODE_OPTIONS by exact environment-variable name. Because npm reads configuration from npm_config_* variables, setting npm_config_yes=true reproduced --yes behavior without using a blocked flag, causing npx to auto-install and execute the named package when a Custom MCP server launched. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T19:24:10.777",
            "published_at": "2026-08-04T17:17:01.683",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-184",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_PATH, DYLD_LIBRARY_PATH, and NODE_OPTIONS by exact environment-variable name. Because npm reads configuration from npm_config_* variables, setting npm_config_yes=true reproduced --yes behavior without using a blocked flag, causing npx to auto-install and execute the named package when a Custom MCP server launched. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-xc48-889x-5qmw"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/a4c4e4988cded15edf725e762560575b889ae351",
                "https://github.com/FlowiseAI/Flowise/pull/6471",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-xc48-889x-5qmw"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T17:17:01.683",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69263"
                }
            ]
        },
        {
            "id": "CVE-2026-69262",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was sufficient to reach the delete path. The delete logic then resolved the target record only by id and workspaceId and did not validate the target resource type, allowing a caller with only agentflows:delete to delete a CHATFLOW and a caller with only chatflows:delete to delete an AGENTFLOW in the same workspace. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T19:41:55.683",
            "published_at": "2026-08-04T17:17:01.547",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was sufficient to reach the delete path. The delete logic then resolved the target record only by id and workspaceId and did not validate the target resource type, allowing a caller with only agentflows:delete to delete a CHATFLOW and a caller with only chatflows:delete to delete an AGENTFLOW in the same workspace. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-p5w8-m249-4r4v"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/2f528ceced74afaa95fc7a282965e7788796448b",
                "https://github.com/FlowiseAI/Flowise/pull/6445",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-p5w8-m249-4r4v"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T17:17:01.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69262"
                }
            ]
        },
        {
            "id": "CVE-2026-69259",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it after the intended database setting, allowing additionalConfig.database to overwrite the SQLite database path. An authenticated attacker using the published Docker image, which ran as root, could write a SQLite database to paths such as /etc/chromium/exploit.conf; by controlling the table name and namespace value, the attacker could place shell syntax into the database file and trigger execution when Puppeteer launched Chromium and sourced /etc/chromium/*.conf. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T19:47:08.963",
            "published_at": "2026-08-04T17:17:01.413",
            "cvss": 9.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it after the intended database setting, allowing additionalConfig.database to overwrite the SQLite database path. An authenticated attacker using the published Docker image, which ran as root, could write a SQLite database to paths such as /etc/chromium/exploit.conf; by controlling the table name and namespace value, the attacker could place shell syntax into the database file and trigger execution when Puppeteer launched Chromium and sourced /etc/chromium/*.conf. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x3hf-7cj6-3r4m"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/d07186844263bad057008863037466aff7c3390f",
                "https://github.com/FlowiseAI/Flowise/pull/6464",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x3hf-7cj6-3r4m"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T17:17:01.413",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69259"
                }
            ]
        },
        {
            "id": "CVE-2026-69258",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in packages/server/src/utils/buildChatflow.ts and packages/server/src/utils/index.ts without checking apiOverrideStatus. This allowed unauthenticated attackers to inject arbitrary properties into the flow execution context of any public chatflow, overwrite values such as chatId, sessionId, and chatHistory, and control values resolved through $flow.* template variables consumed by flow nodes. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T19:47:46.573",
            "published_at": "2026-08-04T17:17:01.280",
            "cvss": 8.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in packages/server/src/utils/buildChatflow.ts and packages/server/src/utils/index.ts without checking apiOverrideStatus. This allowed unauthenticated attackers to inject arbitrary properties into the flow execution context of any public chatflow, overwrite values such as chatId, sessionId, and chatHistory, and control values resolved through $flow.* template variables consumed by flow nodes. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-6vh2-wg4h-4vwj"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/23b997ee5ef9e269b628bad0f56f1ecb86bd2fca",
                "https://github.com/FlowiseAI/Flowise/pull/6279",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-6vh2-wg4h-4vwj"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T17:17:01.280",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69258"
                }
            ]
        },
        {
            "id": "CVE-2026-69257",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against the deny list. Because ipaddr.js reports these addresses as ipv6 while IPv4 CIDR deny-list entries are ipv4, isDeniedIP() skipped the IPv4 CIDR checks. An attacker who controls DNS resolution for a hostname used by the HTTP Node, API Chain, Document Loader, MCP tool, or other paths using secureAxiosRequest(), secureFetch(), or checkDenyList() could return a AAAA record for an IPv4-mapped target and cause requests to reach localhost, internal services, or cloud metadata endpoints. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T19:52:01.927",
            "published_at": "2026-08-04T17:17:00.840",
            "cvss": 7.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against the deny list. Because ipaddr.js reports these addresses as ipv6 while IPv4 CIDR deny-list entries are ipv4, isDeniedIP() skipped the IPv4 CIDR checks. An attacker who controls DNS resolution for a hostname used by the HTTP Node, API Chain, Document Loader, MCP tool, or other paths using secureAxiosRequest(), secureFetch(), or checkDenyList() could return a AAAA record for an IPv4-mapped target and cause requests to reach localhost, internal services, or cloud metadata endpoints. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-c6xh-wv4j-ppv5"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/0fc769208395641c1411ccdb9c81416e54802155",
                "https://github.com/FlowiseAI/Flowise/pull/6431",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-c6xh-wv4j-ppv5"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T17:17:00.840",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69257"
                }
            ]
        },
        {
            "id": "CVE-2026-69256",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could deserialize a pickled payload and achieve code execution without matching the denied words. The affected file is flowise-components/nodes/agents/CSVAgent/CSVAgent.ts, where user-supplied customReadCSVFunc is evaluated as pd.${customReadCSVFunc}. An authenticated user who can create or modify a chatflow can add a CSV Agent, place a malicious read_pickle payload in the Additional Parameters, save the chatflow, and trigger /api/v1/prediction/<UUID> to execute commands. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T19:53:48.650",
            "published_at": "2026-08-04T17:17:00.707",
            "cvss": 9.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could deserialize a pickled payload and achieve code execution without matching the denied words. The affected file is flowise-components/nodes/agents/CSVAgent/CSVAgent.ts, where user-supplied customReadCSVFunc is evaluated as pd.${customReadCSVFunc}. An authenticated user who can create or modify a chatflow can add a CSV Agent, place a malicious read_pickle payload in the Additional Parameters, save the chatflow, and trigger /api/v1/prediction/<UUID> to execute commands. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x6vm-w76m-8j7g"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/c79fe56a6c249850e96bce9b4859f7a0083e4507",
                "https://github.com/FlowiseAI/Flowise/pull/6257",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-x6vm-w76m-8j7g"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T17:17:00.707",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69256"
                }
            ]
        },
        {
            "id": "CVE-2026-69255",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into executable Python as base64_string = \"${base64String}\" before calling Pyodide. The validatePythonCodeForDataFrame() denylist only checked later LLM-generated code and did not validate this initial code block. An authenticated attacker could inject a closing quote followed by Python code, use Pyodide's js bridge to load Node.js child_process, and execute arbitrary operating system commands as root in the Flowise container. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T19:58:41.640",
            "published_at": "2026-08-04T17:17:00.570",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into executable Python as base64_string = \"${base64String}\" before calling Pyodide. The validatePythonCodeForDataFrame() denylist only checked later LLM-generated code and did not validate this initial code block. An authenticated attacker could inject a closing quote followed by Python code, use Pyodide's js bridge to load Node.js child_process, and execute arbitrary operating system commands as root in the Flowise container. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-vmv7-4m6c-3cg5"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/f4e2794f6a576b94578f2fdafbf49c2fb304626c",
                "https://github.com/FlowiseAI/Flowise/pull/6499",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise%403.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-vmv7-4m6c-3cg5"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T17:17:00.570",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69255"
                }
            ]
        },
        {
            "id": "CVE-2026-69254",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the default NodeVM security settings in packages/components/src/utils.ts. An authenticated attacker reaching packages/server/src/routes/node-custom-functions/index.ts could run a custom function that imported flowise-components/dist/src/utils.js, called executeJavaScriptCode() again with nodeVMOptions.require.builtin set to allow all built-in modules, and then required child_process to execute arbitrary system commands as root on the Flowise server. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T19:59:27.650",
            "published_at": "2026-08-04T16:16:29.243",
            "cvss": 9.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the default NodeVM security settings in packages/components/src/utils.ts. An authenticated attacker reaching packages/server/src/routes/node-custom-functions/index.ts could run a custom function that imported flowise-components/dist/src/utils.js, called executeJavaScriptCode() again with nodeVMOptions.require.builtin set to allow all built-in modules, and then required child_process to execute arbitrary system commands as root on the Flowise server. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-3769-jgqc-cxm7"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/3086cb7e323bb96c5a581d3232ef975b0d92183d",
                "https://github.com/FlowiseAI/Flowise/pull/6306",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-3769-jgqc-cxm7"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T16:16:29.243",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69254"
                }
            ]
        },
        {
            "id": "CVE-2026-69253",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process  vm2  sandbox. To build that code, they inserted a user-controlled  baseURL  value straight into the JavaScript source, for example  const url = \"${baseURL}/...\"; . The only check on  baseURL  was  isValidURL , but a valid-looking URL can still contain characters that break out of a code string. An authenticated user could craft a  baseURL  that passed this check, closed the surrounding string, and injected their own JavaScript into the sandboxed script (code injection, CWE-94). The  vm2  sandbox runs in the same Node.js process as Flowise and exposes risky dependencies. As a result, the injected code could escape the sandbox and run arbitrary code on the Flowise server as the Flowise process user. Exploitation only requires an authenticated session. The issue is fixed in version 3.1.3, which passes the URL to the sandbox as data instead of inserting it into code and adds stricter URL validation.",
            "updated_at": "2026-09-14T19:59:58.067",
            "published_at": "2026-08-04T16:16:29.100",
            "cvss": 9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-95",
            "what_happened": "Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process  vm2  sandbox. To build that code, they inserted a user-controlled  baseURL  value straight into the JavaScript source, for example  const url = \"${baseURL}/...\"; . The only check on  baseURL  was  isValidURL , but a valid-looking URL can still contain characters that break out of a code string. An authenticated user could craft a  baseURL  that passed this check, closed the surrounding string, and injected their own JavaScript into the sandboxed script (code injection, CWE-94). The  vm2  sandbox runs in the same Node.js process as Flowise and exposes risky dependencies. As a result, the injected code could escape the sandbox and run arbitrary code on the Flowise server as the Flowise process user. Exploitation only requires an authenticated session. The issue is fixed in version 3.1.3, which passes the URL to the sandbox as data instead of inserting it into code and adds stricter URL validation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wg86-r78f-74mp"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/3f257bdc8196082a178da7134a075824401b13b9",
                "https://github.com/FlowiseAI/Flowise/pull/6417",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wg86-r78f-74mp"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T16:16:29.100",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69253"
                }
            ]
        },
        {
            "id": "CVE-2026-69252",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files feature gate and did not enforce checkPermission on GET or DELETE. A low-privileged authenticated API key with unrelated permissions could call GET /api/v1/files to list files under the organization storage root and DELETE /api/v1/files?path=... to delete files belonging to other workspaces in the same organization because getAllFiles and deleteFile used activeOrganizationId and a user-controlled path without restricting access by permissions or activeWorkspaceId. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T20:01:38.190",
            "published_at": "2026-08-04T16:16:28.960",
            "cvss": 7.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files feature gate and did not enforce checkPermission on GET or DELETE. A low-privileged authenticated API key with unrelated permissions could call GET /api/v1/files to list files under the organization storage root and DELETE /api/v1/files?path=... to delete files belonging to other workspaces in the same organization because getAllFiles and deleteFile used activeOrganizationId and a user-controlled path without restricting access by permissions or activeWorkspaceId. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wp74-f5hh-5f3r"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/bc22bf8baec95b6a3d6e1b3563b4f03491cd6fbb",
                "https://github.com/FlowiseAI/Flowise/pull/6435",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-wp74-f5hh-5f3r"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T16:16:28.960",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69252"
                }
            ]
        },
        {
            "id": "CVE-2026-69251",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig input in packages/components/nodes/recordmanager/MySQLRecordManager/MySQLrecordManager.ts, packages/components/nodes/recordmanager/PostgresRecordManager/PostgresRecordManager.ts, packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts, packages/components/nodes/memory/AgentMemory/MySQLAgentMemory/MySQLAgentMemory.ts, and packages/components/nodes/memory/AgentMemory/AgentMemory.ts. TypeORM DataSource options such as entities, subscribers, and migrations can load local JavaScript files, allowing an authenticated user to execute arbitrary code on the server by uploading a JavaScript payload and referencing it from additionalConfig.entities. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T20:09:25.623",
            "published_at": "2026-08-04T15:16:44.430",
            "cvss": 9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig input in packages/components/nodes/recordmanager/MySQLRecordManager/MySQLrecordManager.ts, packages/components/nodes/recordmanager/PostgresRecordManager/PostgresRecordManager.ts, packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts, packages/components/nodes/memory/AgentMemory/MySQLAgentMemory/MySQLAgentMemory.ts, and packages/components/nodes/memory/AgentMemory/AgentMemory.ts. TypeORM DataSource options such as entities, subscribers, and migrations can load local JavaScript files, allowing an authenticated user to execute arbitrary code on the server by uploading a JavaScript payload and referencing it from additionalConfig.entities. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-g32j-mmxr-gfq5"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-g32j-mmxr-gfq5"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T15:16:44.430",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69251"
                }
            ]
        },
        {
            "id": "CVE-2026-69250",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unauthenticated by design and performs a server-side HTTP request to the credential-controlled accessTokenUrl without SSRF protections. Runtime validation confirmed that the endpoint was reachable without authentication, triggered outbound POST requests to an attacker-controlled server, reflected the full remote response body to the caller through tokenInfo, and sent client_id, client_secret, grant_type=refresh_token, and refresh_token in the request body. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-14T20:03:30.460",
            "published_at": "2026-08-04T15:16:44.277",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST /api/v1/oauth2-credential/refresh/:credentialId is unauthenticated by design and performs a server-side HTTP request to the credential-controlled accessTokenUrl without SSRF protections. Runtime validation confirmed that the endpoint was reachable without authentication, triggered outbound POST requests to an attacker-controlled server, reflected the full remote response body to the caller through tokenInfo, and sent client_id, client_secret, grant_type=refresh_token, and refresh_token in the request body. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-r745-8hwv-h473"
                }
            ],
            "references": [
                "https://github.com/FlowiseAI/Flowise/commit/da8b251a9a4c59484ceaf6f71df7406aede7bef2",
                "https://github.com/FlowiseAI/Flowise/releases/tag/flowise@3.1.3",
                "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-r745-8hwv-h473"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T15:16:44.277",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69250"
                }
            ]
        },
        {
            "id": "CVE-2026-69249",
            "vendor": "pyca",
            "product": "cryptography",
            "title": "cryptography vulnerability",
            "summary": "python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0.",
            "updated_at": "2026-09-10T20:36:14.340",
            "published_at": "2026-08-03T22:16:52.720",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 42.0.0, < 49.0.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pyca/cryptography/commit/3763aa79b",
                "https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582",
                "https://github.com/pyca/cryptography/pull/14960",
                "https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww",
                "https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2026-3553.yaml"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T22:16:52.720",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69249"
                }
            ]
        },
        {
            "id": "CVE-2026-69248",
            "vendor": "pyca",
            "product": "cryptography",
            "title": "cryptography vulnerability",
            "summary": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0.",
            "updated_at": "2026-09-10T20:36:14.340",
            "published_at": "2026-08-03T22:16:52.550",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 49.0.0",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 45.0.0 through 48.0.0, if an intermediate constrained CA permits the DNS name foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of *.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names. The core issue is in DNSConstraint::matches, where a wildcard pattern was treated as matching a more-specific permitted constraint even though *.example.com can expand to sibling names such as bar.example.com outside foo.example.com. This allows acceptance of an invalid certificate chain. This issue is fixed in 49.0.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2",
                "https://github.com/pyca/cryptography/pull/14888",
                "https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T22:16:52.550",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69248"
                }
            ]
        },
        {
            "id": "CVE-2026-69247",
            "vendor": "pyca",
            "product": "cryptography",
            "title": "cryptography vulnerability",
            "summary": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.",
            "updated_at": "2026-09-10T20:36:14.340",
            "published_at": "2026-08-03T22:16:52.380",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 44.0.0, < 50.0.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-208",
            "what_happened": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguishable ways, one of which disclosed the exact length recovered from the RSA operation. The same distinction was also observable by timing. An application that decrypts attacker-supplied EnvelopedData and reflects the outcome gives the attacker a Bleichenbacher oracle against the content-encryption key. Decryption ran as RSA PKCS#1 v1.5 decrypt of encryptedKey, build an AES cipher from the result, then AES-CBC decrypt and PKCS#7 unpad. Invalid RSA padding, a valid padding with a bad key length, a correct length with a wrong key, and the real key each failed or succeeded differently. Case 1 is reachable only where the linked library lacks implicit rejection: OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. Exploitation requires a service that auto-decrypts untrusted EnvelopedData matching the victim certificate and answers adaptively at high volume, such as an S/MIME gateway or mail filter. This issue is fixed in 50.0.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f",
                "https://github.com/pyca/cryptography/pull/15369",
                "https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T22:16:52.380",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69247"
                }
            ]
        },
        {
            "id": "CVE-2026-69244",
            "vendor": "aio-libs",
            "product": "aiohttp",
            "title": "aiohttp vulnerability",
            "summary": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental response, could trigger a DoS in the client. The vulnerable path was error message construction in aiohttp/_http_parser.pyx, where an llhttp error-position pointer was used to build a snippet for malformed chunked responses and malformed request or response bytes at the buffer end. This issue is fixed in version 3.14.3.",
            "updated_at": "2026-09-10T20:36:14.340",
            "published_at": "2026-08-03T21:16:42.273",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.14.3",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental response, could trigger a DoS in the client. The vulnerable path was error message construction in aiohttp/_http_parser.pyx, where an llhttp error-position pointer was used to build a snippet for malformed chunked responses and malformed request or response bytes at the buffer end. This issue is fixed in version 3.14.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d",
                "https://github.com/aio-libs/aiohttp/pull/13223",
                "https://github.com/aio-libs/aiohttp/releases/tag/v3.14.3",
                "https://github.com/aio-libs/aiohttp/security/advisories/GHSA-cq5v-8q36-5273"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:42.273",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69244"
                }
            ]
        },
        {
            "id": "CVE-2026-69243",
            "vendor": "aio-libs",
            "product": "aiohttp",
            "title": "aiohttp vulnerability",
            "summary": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attacker may be able to execute a request smuggling vulnerability using an edge case in the WebSocket upgrade procedure. A WebSocket upgrade request with a body could cause the parser to switch protocols before the complete request body was received, leaving trailing bytes to be handled as upgraded-protocol or pipelined data rather than normal HTTP body data. This issue is fixed in version 3.14.2.",
            "updated_at": "2026-09-10T20:36:14.340",
            "published_at": "2026-08-03T21:16:42.113",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.14.2",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-444",
            "what_happened": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades. If using the server-side component, an attacker may be able to execute a request smuggling vulnerability using an edge case in the WebSocket upgrade procedure. A WebSocket upgrade request with a body could cause the parser to switch protocols before the complete request body was received, leaving trailing bytes to be handled as upgraded-protocol or pipelined data rather than normal HTTP body data. This issue is fixed in version 3.14.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98",
                "https://github.com/aio-libs/aiohttp/pull/13017",
                "https://github.com/aio-libs/aiohttp/releases/tag/v3.14.2",
                "https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22v"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:42.113",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69243"
                }
            ]
        },
        {
            "id": "CVE-2026-69240",
            "vendor": "sequelize",
            "product": "sequelize",
            "title": "sequelize vulnerability",
            "summary": "Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a string and starts with TO_TIMESTAMP or TO_DATE, escape returns val directly instead of replacing single quotes. An attacker can inject arbitrary SQL expressions through an application value that reaches this escape path. This issue is fixed in version 6.37.4.",
            "updated_at": "2026-09-10T20:36:14.340",
            "published_at": "2026-08-03T21:16:41.970",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 6.37.4",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a string and starts with TO_TIMESTAMP or TO_DATE, escape returns val directly instead of replacing single quotes. An attacker can inject arbitrary SQL expressions through an application value that reaches this escape path. This issue is fixed in version 6.37.4.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/sequelize/sequelize/commit/5deadd2410ae9136a21fb652db206d27bb715f26",
                "https://github.com/sequelize/sequelize/releases/tag/v6.37.4",
                "https://github.com/sequelize/sequelize/security/advisories/GHSA-v8fg-2rw7-q452"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:41.970",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69240"
                }
            ]
        },
        {
            "id": "CVE-2026-69238",
            "vendor": "Esri",
            "product": "Portal for ArcGIS",
            "title": "Portal for ArcGIS vulnerability",
            "summary": "There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "updated_at": "2026-09-11T20:17:12.827",
            "published_at": "2026-08-21T21:17:04.617",
            "cvss": 3.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.1 through 11.5 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T21:17:04.617",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69238"
                }
            ]
        },
        {
            "id": "CVE-2026-69237",
            "vendor": "Esri",
            "product": "Portal for ArcGIS",
            "title": "Portal for ArcGIS vulnerability",
            "summary": "There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary HTML into an administrative API. Users working with ArcGIS Enterprise 11.1, and 11.3 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "updated_at": "2026-09-11T20:18:01.287",
            "published_at": "2026-08-21T21:17:04.503",
            "cvss": 3.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.1 through 11.3 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert arbitrary HTML into an administrative API. Users working with ArcGIS Enterprise 11.1, and 11.3 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T21:17:04.503",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69237"
                }
            ]
        },
        {
            "id": "CVE-2026-69236",
            "vendor": "Esri",
            "product": "Portal for ArcGIS",
            "title": "Portal for ArcGIS vulnerability",
            "summary": "There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, 12.0 or 12.1 are encouraged to patch. All users are advised to upgrade to the latest long-term support release and apply the patch.",
            "updated_at": "2026-09-11T16:26:18.400",
            "published_at": "2026-08-21T21:17:04.380",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.1 through 12.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, 12.0 or 12.1 are encouraged to patch. All users are advised to upgrade to the latest long-term support release and apply the patch.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T21:17:04.380",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69236"
                }
            ]
        },
        {
            "id": "CVE-2026-69235",
            "vendor": "Esri",
            "product": "Portal for ArcGIS",
            "title": "Portal for ArcGIS vulnerability",
            "summary": "There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "updated_at": "2026-09-11T16:50:00.660",
            "published_at": "2026-08-21T21:17:04.260",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.1 through 11.5 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T21:17:04.260",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69235"
                }
            ]
        },
        {
            "id": "CVE-2026-69234",
            "vendor": "Esri",
            "product": "Portal for ArcGIS",
            "title": "Portal for ArcGIS vulnerability",
            "summary": "There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release. Users working with ArcGIS Web App Builder developer edition are advised to migrate to ArcGIS Experience Builder, as ArcGIS Web App Builder developer edition is unsupported when this CVE is assigned.",
            "updated_at": "2026-09-11T17:02:00.790",
            "published_at": "2026-08-21T21:17:04.140",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.1 through 11.5 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release. Users working with ArcGIS Web App Builder developer edition are advised to migrate to ArcGIS Experience Builder, as ArcGIS Web App Builder developer edition is unsupported when this CVE is assigned.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T21:17:04.140",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69234"
                }
            ]
        },
        {
            "id": "CVE-2026-69233",
            "vendor": "Esri",
            "product": "Portal for ArcGIS",
            "title": "Portal for ArcGIS vulnerability",
            "summary": "There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "updated_at": "2026-09-11T17:03:45.760",
            "published_at": "2026-08-21T21:17:04.023",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.1 through 11.5 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T21:17:04.023",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69233"
                }
            ]
        },
        {
            "id": "CVE-2026-69232",
            "vendor": "Esri",
            "product": "Portal for ArcGIS",
            "title": "Portal for ArcGIS vulnerability",
            "summary": "There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "updated_at": "2026-09-11T17:05:31.307",
            "published_at": "2026-08-21T21:17:03.907",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.1 through 11.5 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T21:17:03.907",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69232"
                }
            ]
        },
        {
            "id": "CVE-2026-69231",
            "vendor": "Esri",
            "product": "Portal for ArcGIS",
            "title": "Portal for ArcGIS vulnerability",
            "summary": "There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "updated_at": "2026-09-11T17:06:39.347",
            "published_at": "2026-08-21T21:17:03.787",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.1 through 11.5 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject malicious code that could potentially execute arbitrary JavaScript in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T21:17:03.787",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69231"
                }
            ]
        },
        {
            "id": "CVE-2026-69230",
            "vendor": "Esri",
            "product": "Portal for ArcGIS",
            "title": "Portal for ArcGIS vulnerability",
            "summary": "There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "updated_at": "2026-09-11T17:48:52.230",
            "published_at": "2026-08-21T21:17:03.670",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.1 through 11.5 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker to inject malicious code that could potentially execute arbitrary in a victim’s browser. Users working with ArcGIS Enterprise 11.1, 11.3, and 11.5 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T21:17:03.670",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69230"
                }
            ]
        },
        {
            "id": "CVE-2026-69229",
            "vendor": "Esri",
            "product": "Portal for ArcGIS",
            "title": "Portal for ArcGIS vulnerability",
            "summary": "There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 and 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "updated_at": "2026-09-11T17:50:09.237",
            "published_at": "2026-08-21T21:17:03.547",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.1 through 12.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML into the Portal for ArcGIS Home application. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5 and 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T21:17:03.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69229"
                }
            ]
        },
        {
            "id": "CVE-2026-69228",
            "vendor": "Esri",
            "product": "Portal for ArcGIS",
            "title": "Portal for ArcGIS vulnerability",
            "summary": "There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenticated users. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, or 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "updated_at": "2026-09-11T17:51:42.023",
            "published_at": "2026-08-21T21:17:03.423",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.1 through 12.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a specific resource (not user content) that should only be accessible by authenticated users. Users working with ArcGIS Enterprise 11.1, 11.3, 11.5, or 12.0 are encouraged to patch. All users are advised to upgrade to the latest long-term support release.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T21:17:03.423",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69228"
                }
            ]
        },
        {
            "id": "CVE-2026-69225",
            "vendor": "Esri",
            "product": "Portal for ArcGIS",
            "title": "Portal for ArcGIS vulnerability",
            "summary": "There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.",
            "updated_at": "2026-09-11T17:58:14.710",
            "published_at": "2026-08-21T21:17:03.300",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.5 through 12.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-200",
            "what_happened": "There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T21:17:03.300",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69225"
                }
            ]
        },
        {
            "id": "CVE-2026-69224",
            "vendor": "Esri",
            "product": "Portal for ArcGIS",
            "title": "Portal for ArcGIS vulnerability",
            "summary": "There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.",
            "updated_at": "2026-09-11T17:59:56.997",
            "published_at": "2026-08-21T21:17:03.150",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.1 through 12.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-200",
            "what_happened": "There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, unauthenticated attacker to reflect sensitive information in a http response body.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/august-2026-arcgis-security-bulletin"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T21:17:03.150",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69224"
                }
            ]
        },
        {
            "id": "CVE-2026-69198",
            "vendor": "beaugunderson",
            "product": "ip-address",
            "title": "ip-address vulnerability",
            "summary": "ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own subnet mask is shorter than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable, while correctForm() and address still return the real internal target. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed address independently of subnetMask; the defect is solely that the containment guard sits in the classification path. This issue is fixed in version 10.2.2.",
            "updated_at": "2026-09-10T20:30:11.423",
            "published_at": "2026-08-03T20:17:30.107",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 10.1.1, < 10.2.2",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own subnet mask is shorter than the reference range's mask. That mask comes verbatim from the CIDR suffix on the parsed input, so appending a suffix such as /0 suppresses classification entirely: isLoopback(), isPrivate(), isLinkLocal(), isCGNAT(), isMulticast(), isUnspecified(), isBroadcast(), isULA(), and getType() all report an internal address as unremarkable, while correctForm() and address still return the real internal target. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, may therefore treat an internal target as external and allow the request. The underlying bit comparison is correct, and mask(n) already returns the first n bits of the full parsed address independently of subnetMask; the defect is solely that the containment guard sits in the classification path. This issue is fixed in version 10.2.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/beaugunderson/ip-address/commit/488fe9bc7c35363b4b090494fc38c266d217740d",
                "https://github.com/beaugunderson/ip-address/releases/tag/v10.2.2",
                "https://github.com/beaugunderson/ip-address/security/advisories/GHSA-4xrf-jv44-h6hh"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T20:17:30.107",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69198"
                }
            ]
        },
        {
            "id": "CVE-2026-69192",
            "vendor": "beaugunderson",
            "product": "ip-address",
            "title": "ip-address vulnerability",
            "summary": "ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This issue is fixed in version 10.3.1.",
            "updated_at": "2026-09-10T20:30:11.423",
            "published_at": "2026-08-03T20:17:29.960",
            "cvss": 7.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 10.3.1",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as octal. The library and the network stack therefore disagree about which host a string names. new Address4('012.0.0.1') reports correctForm() of 12.0.0.1 and isPrivate() of false, but fetch('http://012.0.0.1/') connects to 10.0.0.1. An application that builds a network trust-boundary decision on these checks, for example a filter intended to block Server-Side Request Forgery, or SSRF, will classify an internal target as external and allow the request. The defect is in the parse gate rather than in any one classifier, so every consumer of Address4 inherits it: isPrivate(), isLoopback(), isLinkLocal(), isCGNAT(), isInSubnet(), isHostInSubnet(), and correctForm() are all computed from the mis-decoded octets. This issue is fixed in version 10.3.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e",
                "https://github.com/beaugunderson/ip-address/releases/tag/v10.3.1",
                "https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T20:17:29.960",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69192"
                }
            ]
        },
        {
            "id": "CVE-2026-69185",
            "vendor": "socketio",
            "product": "socket.io",
            "title": "socket.io vulnerability",
            "summary": "Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.",
            "updated_at": "2026-09-10T20:30:11.423",
            "published_at": "2026-08-03T20:17:29.797",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.3.6; >= 3.4.0, < 3.4.5; >= 4.0.0, < 4.2.7",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server run out of memory. This vulnerability is fixed in 4.2.7, 3.4.5, and 3.3.6.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/socketio/socket.io/commit/7c6ef571a00656718e9e05e3b948fd1758b2a7b4",
                "https://github.com/socketio/socket.io/commit/9c6323e5cde41bd75df3379b5fc9293664a5f240",
                "https://github.com/socketio/socket.io/commit/ced94ffa3ac020a8f3c14eb98a3bf34acb14d291",
                "https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T20:17:29.797",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69185"
                }
            ]
        },
        {
            "id": "CVE-2026-69127",
            "vendor": "getkirby",
            "product": "kirby",
            "title": "kirby vulnerability",
            "summary": "Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability affects all Kirby sites that have not disabled the REST API with the 'api' => false option. This issue is fixed in versions 4.9.5 and 5.5.2.",
            "updated_at": "2026-09-16T13:42:42.113",
            "published_at": "2026-08-07T19:18:53.107",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 4.9.5; >= 5.0.0, < 5.5.2",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-497",
            "what_happened": "Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability affects all Kirby sites that have not disabled the REST API with the 'api' => false option. This issue is fixed in versions 4.9.5 and 5.5.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/getkirby/kirby/commit/469c5a1a2973811591d996bc967eead3565df1f0",
                "https://github.com/getkirby/kirby/commit/58f819988436b31969078bc4655452dd48546451",
                "https://github.com/getkirby/kirby/security/advisories/GHSA-rf2p-vh74-7vvh"
            ],
            "timeline": [
                {
                    "at": "2026-08-07T19:18:53.107",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69127"
                }
            ]
        },
        {
            "id": "CVE-2026-69110",
            "vendor": "Microck",
            "product": "opencode-studio",
            "title": "opencode-studio vulnerability",
            "summary": "OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionally delete any video by ID through the unauthenticated DELETE /api/short-video/:videoId endpoint.",
            "updated_at": "2026-09-16T20:34:19.230",
            "published_at": "2026-08-04T16:16:28.483",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.4.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionally delete any video by ID through the unauthenticated DELETE /api/short-video/:videoId endpoint.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Microck/opencode-studio/commit/1f4d7a7f52beb43105d345b26fd0c0ffc2bf0004",
                "https://github.com/Microck/opencode-studio/issues/54",
                "https://github.com/Microck/opencode-studio/pull/55",
                "https://github.com/Microck/opencode-studio/releases/tag/v2.4.4",
                "https://www.vulncheck.com/advisories/opencode-studio-unauthenticated-file-read-via-api-tmp-and-api-music"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T16:16:28.483",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69110"
                }
            ]
        },
        {
            "id": "CVE-2026-69107",
            "vendor": "jfrog",
            "product": "artifactory",
            "title": "artifactory vulnerability",
            "summary": "An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.",
            "updated_at": "2026-09-11T18:45:52.793",
            "published_at": "2026-08-12T16:17:20.220",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 7.104.16 (custom); 7.111.0 through before 7.111.14 (custom); 7.117.0 through before 7.117.21 (custom); 7.125.0 through before 7.125.14 (custom); 7.133.0 through before 7.133.21 (custom); 7.146.0 through before 7.146.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-862",
            "what_happened": "An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
                "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:20.220",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69107"
                }
            ]
        },
        {
            "id": "CVE-2026-69106",
            "vendor": "jfrog",
            "product": "artifactory",
            "title": "artifactory vulnerability",
            "summary": "A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.",
            "updated_at": "2026-09-11T15:36:31.117",
            "published_at": "2026-08-12T18:18:11.273",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 7.146.28 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
                "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T18:18:11.273",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69106"
                }
            ]
        },
        {
            "id": "CVE-2026-69105",
            "vendor": "jfrog",
            "product": "artifactory",
            "title": "artifactory vulnerability",
            "summary": "An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.",
            "updated_at": "2026-09-11T18:49:47.130",
            "published_at": "2026-08-12T16:17:20.093",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.161.0 through before 7.161.16 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-345",
            "what_happened": "An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
                "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:20.093",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69105"
                }
            ]
        },
        {
            "id": "CVE-2026-69100",
            "vendor": "dromara",
            "product": "lamp-cloud",
            "title": "lamp-cloud vulnerability",
            "summary": "LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend server.",
            "updated_at": "2026-09-16T20:32:21.400",
            "published_at": "2026-08-04T16:16:28.340",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 5.6.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend server.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/dromara/lamp-cloud/commit/84b0c27d3693e468c2c690d9fbc8ea9c22cd34e3",
                "https://github.com/dromara/lamp-cloud/issues/408",
                "https://www.vulncheck.com/advisories/lamp-gluefactory-unsandboxed-groovy-script-remote-code-execution"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T16:16:28.340",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69100"
                }
            ]
        },
        {
            "id": "CVE-2026-69097",
            "vendor": "gitpython-developers",
            "product": "GitPython",
            "title": "GitPython vulnerability",
            "summary": "GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.",
            "updated_at": "2026-09-16T20:45:54.883",
            "published_at": "2026-08-03T14:16:30.677",
            "cvss": 7.3,
            "cvss_vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "before 3.1.53 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-74",
            "what_happened": "GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names. Attackers can inject core.sshCommand or other dangerous config keys into the victim's .git/config via create_submodule or clone_from operations, achieving remote code execution when git performs ssh operations.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2"
                }
            ],
            "references": [
                "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2",
                "https://www.vulncheck.com/advisories/gitpython-before-config-injection-via-submodule-names"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T14:16:30.677",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69097"
                }
            ]
        },
        {
            "id": "CVE-2026-69096",
            "vendor": "openwrt",
            "product": "luci",
            "title": "luci vulnerability",
            "summary": "OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the docker.container.ttyd_start method even though it performs mutating operations. The run_ttyd handler builds a shell command from the request-controlled id, cmd, and uid fields and passes it to system() without quoting or argv-style execution in the rpcd root context. An authenticated attacker holding only the luci-app-dockerman read ACL can inject shell metacharacters (e.g., in id) to execute arbitrary commands as root via an HTTP POST to /ubus. openwrt-24.10 and openwrt-23.05 do not contain this backend and are not affected; no patched version was known as of the advisory.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-08-03T14:16:30.500",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "26.162.29621~507ab5e (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the docker.container.ttyd_start method even though it performs mutating operations. The run_ttyd handler builds a shell command from the request-controlled id, cmd, and uid fields and passes it to system() without quoting or argv-style execution in the rpcd root context. An authenticated attacker holding only the luci-app-dockerman read ACL can inject shell metacharacters (e.g., in id) to execute arbitrary commands as root via an HTTP POST to /ubus. openwrt-24.10 and openwrt-23.05 do not contain this backend and are not affected; no patched version was known as of the advisory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openwrt/luci/commit/44618b5b53d9bdad5cd489e82e29688b4d0862c1",
                "https://github.com/openwrt/luci/commit/f4d0a44950e42bcbb8eacf715a3493b276a4f3ac",
                "https://github.com/openwrt/luci/security/advisories/GHSA-cq4h-h8jr-3xqv",
                "https://www.vulncheck.com/advisories/openwrt-luci-app-dockerman-read-acl-remote-code-execution"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T14:16:30.500",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69096"
                }
            ]
        },
        {
            "id": "CVE-2026-69095",
            "vendor": "openwrt",
            "product": "luci",
            "title": "luci vulnerability",
            "summary": "OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal sequences in the query string to escape the intended directory and read sensitive files accessible to the CGI process.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-08-03T14:16:30.343",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5890760a454dad2cb00389dba2cdc5e779e0ffdd (git)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal sequences in the query string to escape the intended directory and read sensitive files accessible to the CGI process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openwrt/luci/security/advisories/GHSA-8qcq-jgrj-gvmj",
                "https://www.vulncheck.com/advisories/openwrt-luci-app-bmx7-path-traversal-via-bmx7-info"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T14:16:30.343",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69095"
                }
            ]
        },
        {
            "id": "CVE-2026-69094",
            "vendor": "Admidio",
            "product": "admidio",
            "title": "admidio vulnerability",
            "summary": "Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers can enumerate global list UUIDs and overwrite admin-curated global lists or other users' private lists by supplying a list_uuid parameter, transferring ownership and demoting global lists to personal configurations.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-08-03T14:16:30.203",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.0.11 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers can enumerate global list UUIDs and overwrite admin-curated global lists or other users' private lists by supplying a list_uuid parameter, transferring ownership and demoting global lists to personal configurations.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Admidio/admidio/security/advisories/GHSA-rw2j-8c57-x6h2",
                "https://www.vulncheck.com/advisories/admidio-before-idor-via-save-temporary-mylist-function-php"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T14:16:30.203",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69094"
                }
            ]
        },
        {
            "id": "CVE-2026-69093",
            "vendor": "Admidio",
            "product": "admidio",
            "title": "admidio vulnerability",
            "summary": "Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy). An attacker can trick an authenticated administrator into visiting a crafted URL to delete or duplicate Category Report configurations, affecting the integrity and availability of that module's configuration.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-08-03T14:16:30.057",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.0.11 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-352",
            "what_happened": "Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy). An attacker can trick an authenticated administrator into visiting a crafted URL to delete or duplicate Category Report configurations, affecting the integrity and availability of that module's configuration.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Admidio/admidio/commit/e1fe6fd2fcafb6a65a550760f79447abdef31461",
                "https://github.com/Admidio/admidio/security/advisories/GHSA-mvx3-m6p6-7r9w",
                "https://www.vulncheck.com/advisories/admidio-before-csrf-via-category-report-preferences"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T14:16:30.057",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69093"
                }
            ]
        },
        {
            "id": "CVE-2026-69092",
            "vendor": "Admidio",
            "product": "admidio",
            "title": "admidio vulnerability",
            "summary": "Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response. Unauthenticated attackers can inject arbitrary JavaScript through SAML Issuer elements or LightSaml library parameters to execute code in users' browsers and hijack sessions.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-08-03T14:16:29.887",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.0.11 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response. Unauthenticated attackers can inject arbitrary JavaScript through SAML Issuer elements or LightSaml library parameters to execute code in users' browsers and hijack sessions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Admidio/admidio/security/advisories/GHSA-7jxv-38f3-6xgf",
                "https://www.vulncheck.com/advisories/admidio-before-reflected-xss-via-sso-saml-endpoint"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T14:16:29.887",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69092"
                }
            ]
        },
        {
            "id": "CVE-2026-69091",
            "vendor": "Admidio",
            "product": "admidio",
            "title": "admidio vulnerability",
            "summary": "Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to validate the login-only configuration state, allowing unauthenticated attackers to read forum topics and posts by directly accessing the module with read-only parameters.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-08-03T14:16:29.730",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.0.11 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logic in modules/forum.php fails to validate the login-only configuration state, allowing unauthenticated attackers to read forum topics and posts by directly accessing the module with read-only parameters.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Admidio/admidio/security/advisories/GHSA-cf48-6jrq-gjcm",
                "https://www.vulncheck.com/advisories/admidio-before-authentication-bypass-via-forum-php"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T14:16:29.730",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69091"
                }
            ]
        },
        {
            "id": "CVE-2026-69090",
            "vendor": "Admidio",
            "product": "admidio",
            "title": "admidio vulnerability",
            "summary": "Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from another organization to groups_roles.php handlers to modify that organization's roles without authorization.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-08-03T14:16:29.580",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.0.11 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to other organizations. Attackers can supply a role UUID from another organization to groups_roles.php handlers to modify that organization's roles without authorization.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Admidio/admidio/security/advisories/GHSA-fcq9-w4hp-xchg",
                "https://www.vulncheck.com/advisories/admidio-before-cross-organization-role-modification"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T14:16:29.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-69090"
                }
            ]
        },
        {
            "id": "CVE-2026-68971",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manager distinguishes a team-scoped Dag from a global one by that field -- the Keycloak auth manager, for example, checks the `DAG` resource instead of `DAG:<team>` -- so the team-scoped permission that should gate the request was never consulted. In a deployment running multi-team mode with a team-aware auth manager, an authenticated user in one team could trigger Dag runs belonging to another team, supplying their own `dag_run_id` and `conf`, and could read another team's XCom values. Deployments using the FAB auth manager are unaffected, as it has no multi-team support. Users are advised to upgrade to apache-airflow 3.3.1 or later, which resolves the Dag's team at both sites.",
            "updated_at": "2026-09-16T15:17:42.407",
            "published_at": "2026-08-12T16:17:19.970",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manager distinguishes a team-scoped Dag from a global one by that field -- the Keycloak auth manager, for example, checks the `DAG` resource instead of `DAG:<team>` -- so the team-scoped permission that should gate the request was never consulted. In a deployment running multi-team mode with a team-aware auth manager, an authenticated user in one team could trigger Dag runs belonging to another team, supplying their own `dag_run_id` and `conf`, and could read another team's XCom values. Deployments using the FAB auth manager are unaffected, as it has no multi-team support. Users are advised to upgrade to apache-airflow 3.3.1 or later, which resolves the Dag's team at both sites.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/70893",
                "https://lists.apache.org/thread/kfxqqwgojdjdnt6bxg3ord4y41y334fo",
                "http://www.openwall.com/lists/oss-security/2026/08/12/15"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:19.970",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68971"
                }
            ]
        },
        {
            "id": "CVE-2026-68970",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was returned unmasked. Any authenticated user able to read the logs or rendered templates of a task that references such a Variable could recover the values, with no special configuration required. This is the list-shaped counterpart of CVE-2026-59244, whose fix covered the dict case only, so deployments that upgraded in response to that advisory remain affected and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later.",
            "updated_at": "2026-09-16T15:17:42.253",
            "published_at": "2026-08-12T16:17:19.853",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-312",
            "what_happened": "Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was returned unmasked. Any authenticated user able to read the logs or rendered templates of a task that references such a Variable could recover the values, with no special configuration required. This is the list-shaped counterpart of CVE-2026-59244, whose fix covered the dict case only, so deployments that upgraded in response to that advisory remain affected and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/70891",
                "https://lists.apache.org/thread/kkrlnbsk47oght4h38mcd3h2kcb8dt28",
                "https://www.cve.org/CVERecord?id=CVE-2026-59244"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:19.853",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68970"
                }
            ]
        },
        {
            "id": "CVE-2026-68969",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and a bulk request nests its entities two levels below, so no masking was applied to them. Any authenticated user with audit-log read access -- who need not hold Variables or Connections read at all -- could recover those secrets verbatim, and the Connection `extra` copy is stored unencrypted in the log while the connection table encrypts it. The Airflow UI's *Import Variables* action posts to this endpoint, so an ordinary operator import wrote every secret in the file to the log. This is a different code path from CVE-2026-50204: that fix shipped in 3.3.0 and covers the single-entity endpoints only, so deployments that upgraded in response to that advisory remain affected and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later.",
            "updated_at": "2026-09-16T15:17:42.090",
            "published_at": "2026-08-12T16:17:19.730",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-532",
            "what_happened": "Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and a bulk request nests its entities two levels below, so no masking was applied to them. Any authenticated user with audit-log read access -- who need not hold Variables or Connections read at all -- could recover those secrets verbatim, and the Connection `extra` copy is stored unencrypted in the log while the connection table encrypts it. The Airflow UI's *Import Variables* action posts to this endpoint, so an ordinary operator import wrote every secret in the file to the log. This is a different code path from CVE-2026-50204: that fix shipped in 3.3.0 and covers the single-entity endpoints only, so deployments that upgraded in response to that advisory remain affected and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/70890",
                "https://lists.apache.org/thread/p3jr90jgp2brto4vwcrx680f3x11y70c",
                "https://www.cve.org/CVERecord?id=CVE-2026-50204"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:19.730",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68969"
                }
            ]
        },
        {
            "id": "CVE-2026-68968",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts values `int()` rejects (`1.0` coerces to `1`); FastAPI resolves dependencies before endpoint validation, so the two acted on different Dags. An authenticated user holding edit permission on any single Dag could therefore read, pause and cancel backfills belonging to any other Dag, including moving another Dag's queued runs to `failed`. No non-default configuration is required and backfill ids are sequential, so finding a target is trivial. Users are advised to upgrade to apache-airflow 3.3.1 or later, which parses the backfill id with the same type the routes declare.",
            "updated_at": "2026-09-16T15:17:41.923",
            "published_at": "2026-08-12T16:17:19.607",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-436",
            "what_happened": "Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts values `int()` rejects (`1.0` coerces to `1`); FastAPI resolves dependencies before endpoint validation, so the two acted on different Dags. An authenticated user holding edit permission on any single Dag could therefore read, pause and cancel backfills belonging to any other Dag, including moving another Dag's queued runs to `failed`. No non-default configuration is required and backfill ids are sequential, so finding a target is trivial. Users are advised to upgrade to apache-airflow 3.3.1 or later, which parses the backfill id with the same type the routes declare.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/70889",
                "https://lists.apache.org/thread/f9zmw6xs5b4syhwzbl6fsxm4kf2632ol",
                "http://www.openwall.com/lists/oss-security/2026/08/12/12"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:19.607",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68968"
                }
            ]
        },
        {
            "id": "CVE-2026-68930",
            "vendor": "Eugeny",
            "product": "russh",
            "title": "russh vulnerability",
            "summary": "Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, and the exec_request callback. Version 0.62.5 fixes the issue.",
            "updated_at": "2026-09-09T21:02:22.660",
            "published_at": "2026-08-03T17:16:44.843",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 0.62.5",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-666",
            "what_happened": "Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened or confirmed in russh/src/server/encrypted.rs, server_read_authenticated, and the exec_request callback. Version 0.62.5 fixes the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Eugeny/russh/commit/7c5659f8cf6f6f2f9989d12dba0ebf49dc50a171",
                "https://github.com/Eugeny/russh/releases/tag/v0.62.5",
                "https://github.com/Eugeny/russh/security/advisories/GHSA-m65r-rprj-r5rg"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T17:16:44.843",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68930"
                }
            ]
        },
        {
            "id": "CVE-2026-68877",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.",
            "updated_at": "2026-09-10T04:18:11.777",
            "published_at": "2026-09-08T18:18:34.910",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68877"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:18:34.910",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68877"
                }
            ]
        },
        {
            "id": "CVE-2026-68872",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow Amazon provider",
            "title": "Apache Airflow Amazon provider vulnerability",
            "summary": "The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.",
            "updated_at": "2026-09-16T15:17:41.750",
            "published_at": "2026-08-10T19:17:30.587",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 9.34.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/70878",
                "https://lists.apache.org/thread/9nd31g40rd2zpgwwymskvjpfq1xnmllg",
                "http://www.openwall.com/lists/oss-security/2026/08/10/6"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T19:17:30.587",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68872"
                }
            ]
        },
        {
            "id": "CVE-2026-68871",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow Yandex provider",
            "title": "Apache Airflow Yandex provider vulnerability",
            "summary": "The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-yandex 4.5.1 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.",
            "updated_at": "2026-09-16T15:17:41.590",
            "published_at": "2026-08-10T19:17:30.463",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.5.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-yandex 4.5.1 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/70877",
                "https://lists.apache.org/thread/jlj9tv085txk4t0j029mvh43mz89o63c",
                "http://www.openwall.com/lists/oss-security/2026/08/10/5"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T19:17:30.463",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68871"
                }
            ]
        },
        {
            "id": "CVE-2026-68870",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow Microsoft Azure provider",
            "title": "Apache Airflow Microsoft Azure provider vulnerability",
            "summary": "The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-microsoft-azure 14.1.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.",
            "updated_at": "2026-09-16T15:17:41.427",
            "published_at": "2026-08-10T19:17:30.337",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 14.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-639",
            "what_happened": "The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-microsoft-azure 14.1.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/70876",
                "https://github.com/apache/airflow/pull/70899",
                "https://lists.apache.org/thread/dtkk6vtfoj1y4zjyd6s3mzg0v5g9yg0p",
                "http://www.openwall.com/lists/oss-security/2026/08/10/4"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T19:17:30.337",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68870"
                }
            ]
        },
        {
            "id": "CVE-2026-68868",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow Google provider",
            "title": "Apache Airflow Google provider vulnerability",
            "summary": "The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team's Connection or Variable, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-google 22.3.0 or later, which builds and applies the team-scoped secret name.",
            "updated_at": "2026-09-16T15:17:41.263",
            "published_at": "2026-08-12T11:17:10.063",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 22.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-1220",
            "what_happened": "The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team's Connection or Variable, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-google 22.3.0 or later, which builds and applies the team-scoped secret name.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/70869",
                "https://lists.apache.org/thread/03h5y0fmqlh0yf055zlocxh591ozx69x",
                "http://www.openwall.com/lists/oss-security/2026/08/12/3"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T11:17:10.063",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68868"
                }
            ]
        },
        {
            "id": "CVE-2026-68844",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.",
            "updated_at": "2026-09-10T04:18:04.790",
            "published_at": "2026-09-08T18:18:32.467",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Windows Storage Spaces Controller allows an authorized attacker to execute code locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68844"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:18:32.467",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68844"
                }
            ]
        },
        {
            "id": "CVE-2026-68820",
            "vendor": "Microsoft",
            "product": "Windows Ancillary Function Driver for WinSock",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-08-10T22:00:00Z",
            "published_at": "2026-08-10T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-68771",
            "vendor": "Comfy-Org",
            "product": "ComfyUI",
            "title": "ComfyUI vulnerability",
            "summary": "ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt referencing the uploaded file, causing torch.load to deserialize the attacker-controlled pickle payload using __reduce__ and execute arbitrary commands as the ComfyUI process user.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-07-31T22:17:03.630",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 0.23.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt referencing the uploaded file, causing torch.load to deserialize the attacker-controlled pickle payload using __reduce__ and execute arbitrary commands as the ComfyUI process user.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Comfy-Org/ComfyUI",
                "https://github.com/Comfy-Org/ComfyUI/commit/94ee49b1612824366a8631ea069b2a1fa5c73720",
                "https://github.com/Comfy-Org/ComfyUI/pull/14543",
                "https://www.vulncheck.com/advisories/comfyui-unauthenticated-rce-via-loadtrainingdataset-pickle-deserialization"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T22:17:03.630",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68771"
                }
            ]
        },
        {
            "id": "CVE-2026-68770",
            "vendor": "Hugging Face",
            "product": "sentence-transformers",
            "title": "sentence-transformers vulnerability",
            "summary": "sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guard condition includes an 'or os.path.exists(model_name_or_path)' clause that satisfies the trust gate whenever the supplied path exists on the local filesystem, regardless of the trust_remote_code=False argument. Attackers who can control or influence the contents of a model directory on disk can place malicious Python files such as modeling_*.py referenced via modules.json, causing the code to execute at import time when an application loads the model with SentenceTransformer(path, trust_remote_code=False), bypassing the documented security contract and achieving code execution within the loading process.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-07-31T21:17:32.440",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 5.5.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guard condition includes an 'or os.path.exists(model_name_or_path)' clause that satisfies the trust gate whenever the supplied path exists on the local filesystem, regardless of the trust_remote_code=False argument. Attackers who can control or influence the contents of a model directory on disk can place malicious Python files such as modeling_*.py referenced via modules.json, causing the code to execute at import time when an application loads the model with SentenceTransformer(path, trust_remote_code=False), bypassing the documented security contract and achieving code execution within the loading process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/huggingface/sentence-transformers",
                "https://github.com/huggingface/sentence-transformers/commit/ae1acc3fb2aa2004577b297eb4a915ce7a03316a",
                "https://github.com/huggingface/sentence-transformers/issues/3801",
                "https://github.com/huggingface/sentence-transformers/pull/3807",
                "https://www.vulncheck.com/advisories/sentence-transformers-arbitrary-code-execution-on-local-model-load-despite-trust-remote-code-false"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T21:17:32.440",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68770"
                }
            ]
        },
        {
            "id": "CVE-2026-68583",
            "vendor": "openwrt",
            "product": "luci",
            "title": "luci vulnerability",
            "summary": "luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administrator's browser under the LuCI origin.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-08-02T13:16:54.377",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.2.4-4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administrator's browser under the LuCI origin.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openwrt/luci/security/advisories/GHSA-q335-4c83-c88h",
                "https://www.vulncheck.com/advisories/luci-app-adblock-fast-before-4-stored-xss-via-file-url-name"
            ],
            "timeline": [
                {
                    "at": "2026-08-02T13:16:54.377",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68583"
                }
            ]
        },
        {
            "id": "CVE-2026-68503",
            "vendor": "grisuno",
            "product": "LazyOwn",
            "title": "LazyOwn vulnerability",
            "summary": "LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP Basic authentication, allowing any network-reachable attacker who knows the defaults to authenticate to the C2 dashboard with operator-level access. This issue is fixed in 0.2.154.",
            "updated_at": "2026-09-10T20:12:43.783",
            "published_at": "2026-07-30T21:18:13.460",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 0.2.154",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1392",
            "what_happened": "LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP Basic authentication, allowing any network-reachable attacker who knows the defaults to authenticate to the C2 dashboard with operator-level access. This issue is fixed in 0.2.154.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/grisuno/LazyOwn/commit/2e1e3a7b5da8149ae28a970b5883aefa42921652",
                "https://github.com/grisuno/LazyOwn/releases/tag/release/0.2.154",
                "https://github.com/grisuno/LazyOwn/security/advisories/GHSA-38jf-j9x7-jf6f"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T21:18:13.460",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68503"
                }
            ]
        },
        {
            "id": "CVE-2026-68502",
            "vendor": "grisuno",
            "product": "LazyOwn",
            "title": "LazyOwn vulnerability",
            "summary": "LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reaching LazyOwnShell.do_cmd and subprocess.call(command, shell=True), allowing unauthenticated remote code execution in the C2 process. This issue is fixed in 0.2.154.",
            "updated_at": "2026-09-10T20:12:43.783",
            "published_at": "2026-07-30T21:18:13.317",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 0.2.154",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reaching LazyOwnShell.do_cmd and subprocess.call(command, shell=True), allowing unauthenticated remote code execution in the C2 process. This issue is fixed in 0.2.154.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/grisuno/LazyOwn/commit/2e1e3a7b5da8149ae28a970b5883aefa42921652",
                "https://github.com/grisuno/LazyOwn/releases/tag/release/0.2.154",
                "https://github.com/grisuno/LazyOwn/security/advisories/GHSA-fr84-8cfg-59w4"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T21:18:13.317",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68502"
                }
            ]
        },
        {
            "id": "CVE-2026-68501",
            "vendor": "Sylius",
            "product": "MolliePlugin",
            "title": "MolliePlugin vulnerability",
            "summary": "Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAction::fetchQrCodeFromOrder endpoints look up sequential orderId values without ownership or session checks, exposing order tokenValue values that can be used with GET /{_locale}/register-after-checkout/{tokenValue} to view customer first name, last name, and email. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1.",
            "updated_at": "2026-09-10T20:12:43.783",
            "published_at": "2026-07-30T21:18:13.180",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.2.8; >= 3.0.0, < 3.2.4; >= 3.3.0, < 3.3.1",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAction::fetchQrCodeFromOrder endpoints look up sequential orderId values without ownership or session checks, exposing order tokenValue values that can be used with GET /{_locale}/register-after-checkout/{tokenValue} to view customer first name, last name, and email. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Sylius/MolliePlugin/commit/01316b3ad3cf82e3c5ad160115d0a2cf89174e49",
                "https://github.com/Sylius/MolliePlugin/commit/153c754486b1bc597b67a90ac07ef71cd7958267",
                "https://github.com/Sylius/MolliePlugin/commit/d1f7753e92106e8bf3bedcfc61b02ea7b8e1c38a",
                "https://github.com/Sylius/MolliePlugin/pull/351",
                "https://github.com/Sylius/MolliePlugin/pull/352",
                "https://github.com/Sylius/MolliePlugin/pull/354",
                "https://github.com/Sylius/MolliePlugin/releases/tag/v2.2.8",
                "https://github.com/Sylius/MolliePlugin/releases/tag/v3.2.4",
                "https://github.com/Sylius/MolliePlugin/releases/tag/v3.3.1",
                "https://github.com/Sylius/MolliePlugin/security/advisories/GHSA-x83g-979r-f5fh"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T21:18:13.180",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68501"
                }
            ]
        },
        {
            "id": "CVE-2026-68500",
            "vendor": "Sylius",
            "product": "MolliePlugin",
            "title": "MolliePlugin vulnerability",
            "summary": "Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie payment belongs to the referenced Sylius order, allowing an unauthenticated attacker with any valid paid Mollie payment ID to mark a victim order as paid without transferring funds for that order. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1.",
            "updated_at": "2026-09-10T20:12:43.783",
            "published_at": "2026-07-30T21:18:13.007",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.2.8; >= 3.0.0, < 3.2.4; >= 3.3.0, < 3.3.1",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie payment belongs to the referenced Sylius order, allowing an unauthenticated attacker with any valid paid Mollie payment ID to mark a victim order as paid without transferring funds for that order. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Sylius/MolliePlugin/commit/01316b3ad3cf82e3c5ad160115d0a2cf89174e49",
                "https://github.com/Sylius/MolliePlugin/commit/153c754486b1bc597b67a90ac07ef71cd7958267",
                "https://github.com/Sylius/MolliePlugin/commit/d1f7753e92106e8bf3bedcfc61b02ea7b8e1c38a",
                "https://github.com/Sylius/MolliePlugin/pull/351",
                "https://github.com/Sylius/MolliePlugin/pull/352",
                "https://github.com/Sylius/MolliePlugin/pull/354",
                "https://github.com/Sylius/MolliePlugin/releases/tag/v2.2.8",
                "https://github.com/Sylius/MolliePlugin/releases/tag/v3.2.4",
                "https://github.com/Sylius/MolliePlugin/releases/tag/v3.3.1",
                "https://github.com/Sylius/MolliePlugin/security/advisories/GHSA-rc52-c4hv-w89p"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T21:18:13.007",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68500"
                }
            ]
        },
        {
            "id": "CVE-2026-68499",
            "vendor": "uhop",
            "product": "node-re2",
            "title": "node-re2 vulnerability",
            "summary": "re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native memory growth that blocks the event loop and can exhaust host memory. This issue is fixed in 1.25.2.",
            "updated_at": "2026-09-10T20:30:11.423",
            "published_at": "2026-07-30T21:18:12.870",
            "cvss": 6.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.25.2",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-835",
            "what_happened": "re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop and unbounded native memory growth that blocks the event loop and can exhaust host memory. This issue is fixed in 1.25.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/uhop/node-re2/commit/56293de4fc0914d7bc35f92e98de25b0d9bb417d",
                "https://github.com/uhop/node-re2/releases/tag/1.25.2",
                "https://github.com/uhop/node-re2/security/advisories/GHSA-6hxr-mr5r-9836"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T21:18:12.870",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-68499"
                }
            ]
        },
        {
            "id": "CVE-2026-68138",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-68138 Linux qdisc rate-table race local privilege escalation PoC",
            "summary": "CVE-2026-68138 Linux qdisc rate-table race local privilege escalation PoC",
            "updated_at": "2026-08-26T13:14:48Z",
            "published_at": "2026-08-26T13:14:48Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 286,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · aramosf/CVE-2026-68138",
                    "author": "aramosf",
                    "first_seen": "2026-08-11",
                    "last_seen": "2026-08-26T13:14:48Z",
                    "pushed_at": "2026-08-12T15:31:34Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "LPE",
                    "language": "C",
                    "stars": 32,
                    "forks": 6,
                    "topics": [],
                    "title": "CVE-2026-68138 Linux qdisc rate-table race local privilege escalation PoC",
                    "repository_description": "CVE-2026-68138 Linux qdisc rate-table race local privilege escalation PoC",
                    "summary": "CVE-2026-68138 Linux qdisc rate-table race local privilege escalation PoC",
                    "source": "CVE-Intel",
                    "url": "https://github.com/aramosf/CVE-2026-68138"
                },
                {
                    "repository": "CVE-Intel · suominen/CVE-2026-68138",
                    "author": "suominen",
                    "first_seen": "2026-08-17",
                    "last_seen": "2026-08-26T05:55:14Z",
                    "pushed_at": "2026-08-26T05:54:22Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Shell",
                    "stars": 0,
                    "forks": 0,
                    "topics": [
                        "cve",
                        "linux",
                        "security"
                    ],
                    "title": "Tracking CVE-2026-68138, the Linux kernel net/sched qdisc rate-table use-after-free",
                    "repository_description": "Tracking CVE-2026-68138, the Linux kernel net/sched qdisc rate-table use-after-free",
                    "summary": "Tracking CVE-2026-68138, the Linux kernel net/sched qdisc rate-table use-after-free",
                    "source": "CVE-Intel",
                    "url": "https://github.com/suominen/CVE-2026-68138"
                },
                {
                    "repository": "CVE-Intel · jangkrikkbozz/CVE-2026-68138",
                    "author": "jangkrikkbozz",
                    "first_seen": "2026-08-17",
                    "last_seen": "2026-08-17T08:24:13Z",
                    "pushed_at": "2026-08-17T08:23:09Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "LPE",
                    "language": "",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-68138 Linux Local Privilege Escalation Exploit",
                    "repository_description": "CVE-2026-68138 Linux Local Privilege Escalation Exploit",
                    "summary": "CVE-2026-68138 Linux Local Privilege Escalation Exploit",
                    "source": "CVE-Intel",
                    "url": "https://github.com/jangkrikkbozz/CVE-2026-68138"
                }
            ],
            "references": [
                "https://github.com/aramosf/CVE-2026-68138",
                "https://github.com/suominen/CVE-2026-68138",
                "https://github.com/jangkrikkbozz/CVE-2026-68138"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T13:14:48Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/aramosf/CVE-2026-68138"
                }
            ]
        },
        {
            "id": "CVE-2026-67977",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
            "updated_at": "2026-09-09T16:04:24.933",
            "published_at": "2026-08-03T22:16:51.740",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/freedomfoxvare/cve/issues/1",
                "https://github.com/nasa/fprime"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T22:16:51.740",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67977"
                }
            ]
        },
        {
            "id": "CVE-2026-67673",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is triggered when processing the edl fw_flash command, where the <filename> argument is copied to a 64-byte stack buffer via memcpy without proper length validation. An attacker with physical access to the UART3 serial interface can exploit this vulnerability by sending a maliciously crafted command with an oversized filename parameter,",
            "updated_at": "2026-09-09T16:04:24.933",
            "published_at": "2026-08-03T23:16:47.080",
            "cvss": 4.6,
            "cvss_vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Physical",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is triggered when processing the edl fw_flash command, where the <filename> argument is copied to a 64-byte stack buffer via memcpy without proper length validation. An attacker with physical access to the UART3 serial interface can exploit this vulnerability by sending a maliciously crafted command with an oversized filename parameter,",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/dazuo233/cve/issues/2"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T23:16:47.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67673"
                }
            ]
        },
        {
            "id": "CVE-2026-67622",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector store listings, and upload files into victim workspaces by exploiting the missing workspace-scoped authorization check in the credential lookup logic.",
            "updated_at": "2026-09-15T16:07:38.673",
            "published_at": "2026-08-06T22:18:22.873",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "0 through 3.1.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification. Attackers can enumerate cross-workspace assistant metadata, retrieve file and vector store listings, and upload files into victim workspaces by exploiting the missing workspace-scoped authorization check in the credential lookup logic.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-67622.md"
                }
            ],
            "references": [
                "https://flowiseai.com/sunset",
                "https://github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-67622.md",
                "https://www.vulncheck.com/advisories/flowise-idor-in-openai-assistants-integration"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:22.873",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67622"
                }
            ]
        },
        {
            "id": "CVE-2026-67621",
            "vendor": "FlowiseAI",
            "product": "Flowise",
            "title": "Flowise vulnerability",
            "summary": "Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, consume embedding API credits, and modify knowledge bases used by downstream chatflows.",
            "updated_at": "2026-09-15T16:08:16.127",
            "published_at": "2026-08-06T22:18:22.717",
            "cvss": 7.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "0 through 3.1.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document store routes to trigger document ingestion, refresh vector database contents, consume embedding API credits, and modify knowledge bases used by downstream chatflows.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-67621.md"
                }
            ],
            "references": [
                "https://flowiseai.com/sunset",
                "https://github.com/Caycon/cve-advisories/blob/main/2026/Flowise/CVE-2026-67621.md",
                "https://www.vulncheck.com/advisories/flowise-missing-authorization-on-document-store-mutation-endpoints"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:22.717",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67621"
                }
            ]
        },
        {
            "id": "CVE-2026-67618",
            "vendor": "marimo-team",
            "product": "marimo",
            "title": "marimo vulnerability",
            "summary": "marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata, which is merged into session configuration with higher precedence than the operator's own settings due to insufficient sanitization in sanitize_pyproject_dict. When an operator opens the crafted notebook and makes an AI request, marimo resolves the attacker-controlled base_url from the notebook config while falling back to the operator's OPENAI_API_KEY environment variable for authentication, transmitting the API key to the attacker-controlled endpoint without requiring any cell execution.",
            "updated_at": "2026-09-16T13:42:43.283",
            "published_at": "2026-08-04T15:16:41.293",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.23.15 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-345",
            "what_happened": "marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata, which is merged into session configuration with higher precedence than the operator's own settings due to insufficient sanitization in sanitize_pyproject_dict. When an operator opens the crafted notebook and makes an AI request, marimo resolves the attacker-controlled base_url from the notebook config while falling back to the operator's OPENAI_API_KEY environment variable for authentication, transmitting the API key to the attacker-controlled endpoint without requiring any cell execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/marimo-team/marimo/commit/1a21bd71e258438d2511136b5edacc94c08855f4",
                "https://github.com/marimo-team/marimo/pull/10281",
                "https://github.com/marimo-team/marimo/releases/tag/0.23.15",
                "https://www.vulncheck.com/advisories/marimo-api-key-exfiltration-via-malicious-notebook-pep-723-metadata"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T15:16:41.293",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67618"
                }
            ]
        },
        {
            "id": "CVE-2026-67617",
            "vendor": "microweber",
            "product": "microweber",
            "title": "microweber vulnerability",
            "summary": "Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET /api/save_content_admin endpoint, bypassing three independent sanitization controls including XSS middleware that ignores GET requests, a strip_unsafe() function that only matches double-quoted onerror attributes, and a titlecase normalizer that passes HTML decimal entity-encoded payloads through unchanged. Attackers can store malicious scripts that execute without user interaction for every visitor to the public blog page and within the admin post editor, enabling session riding through same-origin fetch requests using the CSRF token embedded in the page.",
            "updated_at": "2026-09-10T20:44:57.447",
            "published_at": "2026-08-03T22:16:50.963",
            "cvss": 4.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.0.20 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting malicious payloads via the tag_names parameter of the GET /api/save_content_admin endpoint, bypassing three independent sanitization controls including XSS middleware that ignores GET requests, a strip_unsafe() function that only matches double-quoted onerror attributes, and a titlecase normalizer that passes HTML decimal entity-encoded payloads through unchanged. Attackers can store malicious scripts that execute without user interaction for every visitor to the public blog page and within the admin post editor, enabling session riding through same-origin fetch requests using the CSRF token embedded in the page.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/theopaid/Stored-XSS-via-Content-Tag-Names-Microweber-",
                "https://www.vulncheck.com/advisories/microweber-cms-stored-xss-via-tag-names-parameter"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T22:16:50.963",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67617"
                }
            ]
        },
        {
            "id": "CVE-2026-67612",
            "vendor": "openemr",
            "product": "openemr",
            "title": "openemr vulnerability",
            "summary": "OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that allows authenticated administrators to inject arbitrary HTML and JavaScript by storing malicious payloads through the template save mode, which only filters literal PHP open tags. Attackers can exploit the lack of output encoding at the template retrieval endpoint combined with missing HttpOnly cookie attributes to exfiltrate session tokens via document.cookie access, enabling full session hijacking of any admin, clinician, or portal patient who views a poisoned template.",
            "updated_at": "2026-09-09T20:40:01.933",
            "published_at": "2026-08-03T17:16:44.037",
            "cvss": 4.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 8.2.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that allows authenticated administrators to inject arbitrary HTML and JavaScript by storing malicious payloads through the template save mode, which only filters literal PHP open tags. Attackers can exploit the lack of output encoding at the template retrieval endpoint combined with missing HttpOnly cookie attributes to exfiltrate session tokens via document.cookie access, enabling full session hijacking of any admin, clinician, or portal patient who views a poisoned template.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jivasecurity.com/writeups/openemr-portal-template-stored-xss",
                "https://www.vulncheck.com/advisories/openemr-stored-xss-via-import-template-php-template-management"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T17:16:44.037",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67612"
                }
            ]
        },
        {
            "id": "CVE-2026-67610",
            "vendor": "openemr",
            "product": "openemr",
            "title": "openemr vulnerability",
            "summary": "OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks field. Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens granting read access to all FHIR resources across all patients in the system.",
            "updated_at": "2026-09-09T20:40:01.933",
            "published_at": "2026-08-03T17:16:43.703",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 8.2.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks field. Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens granting read access to all FHIR resources across all patients in the system.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jivasecurity.com/writeups/openemr-unauth-oauth2-client-registration",
                "https://www.vulncheck.com/advisories/openemr-oauth2-dynamic-client-registration-unauthorized-fhir-access"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T17:16:43.703",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67610"
                }
            ]
        },
        {
            "id": "CVE-2026-67609",
            "vendor": "Telenia Software",
            "product": "TVox",
            "title": "TVox vulnerability",
            "summary": "Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows attackers with access to the apache account to execute arbitrary commands as root by exploiting an insecure sudoers configuration in /etc/sudoers.d/telenia. The configuration grants the apache user NOPASSWD execution of /bin/nice, which can be leveraged to invoke arbitrary commands, enabling full root-level command execution without supplying a password.",
            "updated_at": "2026-09-09T20:40:01.933",
            "published_at": "2026-08-03T15:16:20.980",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "26.0.0 through 26.5.3 (semver); 24.0.0 through 24.9.21 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-250",
            "what_happened": "Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows attackers with access to the apache account to execute arbitrary commands as root by exploiting an insecure sudoers configuration in /etc/sudoers.d/telenia. The configuration grants the apache user NOPASSWD execution of /bin/nice, which can be leveraged to invoke arbitrary commands, enabling full root-level command execution without supplying a password.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://karmainsecurity.com/KIS-2026-16",
                "https://www.teleniasoftware.com/",
                "https://www.vulncheck.com/advisories/telenia-tvox-privilege-escalation-via-insecure-sudoers-configuration"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T15:16:20.980",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67609"
                }
            ]
        },
        {
            "id": "CVE-2026-67608",
            "vendor": "Telenia Software",
            "product": "TVox",
            "title": "TVox vulnerability",
            "summary": "Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an unsanitized pid parameter into an exec() call when the action parameter is set to checkProcess. Attackers can inject malicious OS commands through the pid request parameter to execute arbitrary commands with the privileges of the apache user.",
            "updated_at": "2026-09-09T20:40:01.933",
            "published_at": "2026-08-03T14:16:27.793",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "26.0.0 through 26.5.3 (semver); 24.0.0 through 24.9.21 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an unsanitized pid parameter into an exec() call when the action parameter is set to checkProcess. Attackers can inject malicious OS commands through the pid request parameter to execute arbitrary commands with the privileges of the apache user.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://karmainsecurity.com/KIS-2026-15",
                "https://www.teleniasoftware.com/",
                "https://www.vulncheck.com/advisories/telenia-tvox-os-command-injection-via-action-audio-php"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T14:16:27.793",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67608"
                }
            ]
        },
        {
            "id": "CVE-2026-67607",
            "vendor": "hfiref0x",
            "product": "LightFTP",
            "title": "LightFTP vulnerability",
            "summary": "LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attackers to destabilize or crash the daemon by triggering unsynchronized access to shared per-connection state without holding the required mutex lock. Attackers can send a data-transfer command such as LIST followed immediately by ABOR to exploit the missing synchronization on shared context and detached thread id reuse, resulting in daemon destabilization or crash which can lead to a denial of service. The 2.3.1 patch only narrowed the timing window (an extra re-check and reordered cleanup), it never added the missing lock, so the underlying race remains.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-07-31T16:17:11.913",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-367",
            "what_happened": "LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attackers to destabilize or crash the daemon by triggering unsynchronized access to shared per-connection state without holding the required mutex lock. Attackers can send a data-transfer command such as LIST followed immediately by ABOR to exploit the missing synchronization on shared context and detached thread id reuse, resulting in daemon destabilization or crash which can lead to a denial of service. The 2.3.1 patch only narrowed the timing window (an extra re-check and reordered cleanup), it never added the missing lock, so the underlying race remains.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/zeroscience/tuktam#real-world-case-study-lightftp-cve-2024-11144",
                "https://www.vulncheck.com/advisories/lightftp-race-condition-dos-via-worker-thread-cleanup"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T16:17:11.913",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67607"
                }
            ]
        },
        {
            "id": "CVE-2026-67598",
            "vendor": "emlog",
            "product": "emlog",
            "title": "emlog vulnerability",
            "summary": "Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST are unconditionally disabled across sendStream(), sendImageRequest(), send(), and fetchSearchHtml() with no option to re-enable verification. Attackers can perform man-in-the-middle interception to extract Authorization Bearer API keys from every AI request and inject crafted AI responses that may be acted upon by the tool-call execution pipeline, including the query_database and update_config tool handlers.",
            "updated_at": "2026-09-09T20:40:01.933",
            "published_at": "2026-08-03T20:17:27.960",
            "cvss": 9.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.6.23 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST are unconditionally disabled across sendStream(), sendImageRequest(), send(), and fetchSearchHtml() with no option to re-enable verification. Attackers can perform man-in-the-middle interception to extract Authorization Bearer API keys from every AI request and inject crafted AI responses that may be acted upon by the tool-call execution pipeline, including the query_database and update_config tool handlers.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/emlog/emlog/security/advisories/GHSA-hf85-99vj-m4c5",
                "https://www.vulncheck.com/advisories/emlog-pro-tls-certificate-validation-disabled-in-ai-php"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T20:17:27.960",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67598"
                }
            ]
        },
        {
            "id": "CVE-2026-67587",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not help. A Dag author — who controls a task instance's `next_kwargs` through the task execution API — can therefore cause an arbitrary module to be imported inside the scheduler process, when the scheduler's `awaiting_input` timeout sweep deserializes that value. No non-default configuration is required; the sweep runs unconditionally. Versions before 3.3.0 are not affected: the class existed, but the scheduler sweep that reaches it did not. This is a separate code path from CVE-2026-58076 and CVE-2026-67260, which cover different gadgets reaching deserialization — applying either of those fixes does not address this one. Users are advised to upgrade to apache-airflow 3.3.1 or later.",
            "updated_at": "2026-09-16T15:17:41.107",
            "published_at": "2026-08-12T16:17:15.090",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.3.0 through before 3.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes` allow-list, so tightening that setting does not help. A Dag author — who controls a task instance's `next_kwargs` through the task execution API — can therefore cause an arbitrary module to be imported inside the scheduler process, when the scheduler's `awaiting_input` timeout sweep deserializes that value. No non-default configuration is required; the sweep runs unconditionally. Versions before 3.3.0 are not affected: the class existed, but the scheduler sweep that reaches it did not. This is a separate code path from CVE-2026-58076 and CVE-2026-67260, which cover different gadgets reaching deserialization — applying either of those fixes does not address this one. Users are advised to upgrade to apache-airflow 3.3.1 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/70704",
                "https://lists.apache.org/thread/o00ww4n69qojvsckb464dtwd2nhzy6t0",
                "https://www.cve.org/CVERecord?id=CVE-2026-58076",
                "https://www.cve.org/CVERecord?id=CVE-2026-67260"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:15.090",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67587"
                }
            ]
        },
        {
            "id": "CVE-2026-67550",
            "vendor": "uhop",
            "product": "node-re2",
            "title": "node-re2 vulnerability",
            "summary": "re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII subject to trigger an out-of-bounds heap read and an uncatchable process crash, with limited heap information disclosure in some cases. This issue is fixed in 1.25.2.",
            "updated_at": "2026-09-10T20:30:11.423",
            "published_at": "2026-07-30T20:18:15.030",
            "cvss": 5.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.25.2",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-125",
            "what_happened": "re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII subject to trigger an out-of-bounds heap read and an uncatchable process crash, with limited heap information disclosure in some cases. This issue is fixed in 1.25.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/uhop/node-re2/commit/56293de4fc0914d7bc35f92e98de25b0d9bb417d",
                "https://github.com/uhop/node-re2/releases/tag/1.25.2",
                "https://github.com/uhop/node-re2/security/advisories/GHSA-ff84-5f28-78qj"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T20:18:15.030",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67550"
                }
            ]
        },
        {
            "id": "CVE-2026-67531",
            "vendor": "agentfront",
            "product": "frontmcp",
            "title": "frontmcp vulnerability",
            "summary": "FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own property, the ECMAScript Proxy invariants force the security membrane to hand back the raw host object, letting a script reach _zod.constr.constructor (the host Function constructor) and execute arbitrary code in the server process. A single tools/call is sufficient to escape the sandbox and achieve remote code execution as the server user, exposing everything the process holds such as OAuth client secrets, JWT_SECRET, session keys, database credentials, and cloud instance metadata. Because the framework's DEFAULT_AUTH_OPTIONS is public mode, an unconfigured server serves this to unauthenticated callers, and on authenticated servers an indirect prompt injection in tool output or fetched content can trigger it without a human attackerThis issue is fixed in version 1.5.7.",
            "updated_at": "2026-09-10T20:37:00.427",
            "published_at": "2026-08-06T00:16:53.733",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.5.7",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own property, the ECMAScript Proxy invariants force the security membrane to hand back the raw host object, letting a script reach _zod.constr.constructor (the host Function constructor) and execute arbitrary code in the server process. A single tools/call is sufficient to escape the sandbox and achieve remote code execution as the server user, exposing everything the process holds such as OAuth client secrets, JWT_SECRET, session keys, database credentials, and cloud instance metadata. Because the framework's DEFAULT_AUTH_OPTIONS is public mode, an unconfigured server serves this to unauthenticated callers, and on authenticated servers an indirect prompt injection in tool output or fetched content can trigger it without a human attackerThis issue is fixed in version 1.5.7.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/agentfront/frontmcp/commit/209cddd19a8d4db0777f725b527818da7df6f67f",
                "https://github.com/agentfront/frontmcp/security/advisories/GHSA-mp29-fxh8-92px"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T00:16:53.733",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67531"
                }
            ]
        },
        {
            "id": "CVE-2026-67434",
            "vendor": "PHPCSStandards",
            "product": "PHP_CodeSniffer",
            "title": "PHP_CodeSniffer vulnerability",
            "summary": "PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgblame, and Svnblame report formats. As a result, running PHP_CodeSniffer over untrusted files, for example in a continuous integration pipeline that scans pull requests, or on a developer machine reviewing third party code, could result in attacker controlled shell commands being executed when the Gitblame, Hgblame, or Svnblame report processes a file whose name contains shell metacharacters. Users using the default Full report, or any of the other non-blame reports, are not affected. Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as \" and ;, are not affected. This issue is fixed in versions 3.13.6 and 4.0.2.",
            "updated_at": "2026-09-10T20:41:33.140",
            "published_at": "2026-08-06T22:18:21.750",
            "cvss": 7.3,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.13.6; >= 4.0.0, < 4.0.2",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgblame, and Svnblame report formats. As a result, running PHP_CodeSniffer over untrusted files, for example in a continuous integration pipeline that scans pull requests, or on a developer machine reviewing third party code, could result in attacker controlled shell commands being executed when the Gitblame, Hgblame, or Svnblame report processes a file whose name contains shell metacharacters. Users using the default Full report, or any of the other non-blame reports, are not affected. Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as \" and ;, are not affected. This issue is fixed in versions 3.13.6 and 4.0.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/PHPCSStandards/PHP_CodeSniffer/commit/7a3a6bbf153a03fa3a9413afc60bded6b764e76b",
                "https://github.com/PHPCSStandards/PHP_CodeSniffer/commit/f0e1ebb0563f0e5d7f190497a787bcaf8474f3fe",
                "https://github.com/PHPCSStandards/PHP_CodeSniffer/pull/1473",
                "https://github.com/PHPCSStandards/PHP_CodeSniffer/releases/tag/3.13.6",
                "https://github.com/PHPCSStandards/PHP_CodeSniffer/releases/tag/4.0.2",
                "https://github.com/PHPCSStandards/PHP_CodeSniffer/security/advisories/GHSA-hmqg-cxww-wqhq"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:21.750",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67434"
                }
            ]
        },
        {
            "id": "CVE-2026-67422",
            "vendor": "facelessuser",
            "product": "pymdown-extensions",
            "title": "pymdown-extensions vulnerability",
            "summary": "pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run of delimiter characters in exponentially many ways, causing catastrophic backtracking. As a result, a single untrusted Markdown line under 50 bytes rendered with markdown.markdown() in each extension's default configuration drives the rendering thread into unbounded CPU usage that grows exponentially with input length, enabling an unauthenticated remote attacker who can submit Markdown to cause denial of service. The exposure is concrete for web applications that render user-supplied Markdown (comments, wikis, issue bodies, live preview), including any app using pymdownx.extra which bundles the vulnerable betterem default, as well as hosted docs/CI systems that build untrusted Markdown. The issue has been fixed in version 11.0.1.",
            "updated_at": "2026-09-10T20:41:33.140",
            "published_at": "2026-08-06T22:18:21.600",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 11.0.1",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1333",
            "what_happened": "pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run of delimiter characters in exponentially many ways, causing catastrophic backtracking. As a result, a single untrusted Markdown line under 50 bytes rendered with markdown.markdown() in each extension's default configuration drives the rendering thread into unbounded CPU usage that grows exponentially with input length, enabling an unauthenticated remote attacker who can submit Markdown to cause denial of service. The exposure is concrete for web applications that render user-supplied Markdown (comments, wikis, issue bodies, live preview), including any app using pymdownx.extra which bundles the vulnerable betterem default, as well as hosted docs/CI systems that build untrusted Markdown. The issue has been fixed in version 11.0.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/facelessuser/pymdown-extensions/commit/c68498598d7b13011bb4571350b6e3612a4ce44b",
                "https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-gm37-52c6-37mw"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:21.600",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67422"
                }
            ]
        },
        {
            "id": "CVE-2026-67398",
            "vendor": "WebPros",
            "product": "WHMCS",
            "title": "WHMCS vulnerability",
            "summary": "Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.",
            "updated_at": "2026-09-14T21:17:25.283",
            "published_at": "2026-09-04T00:17:13.563",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.5.0 through before 8.12.2 (semver); 8.13.0 through before 8.13.7 (semver); 9.0.0 through before 9.0.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.7, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://help.whmcs.com/m/125386/l/2116695-cve-2026-67398-whmcs-security-update-2026-09-03"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T00:17:13.563",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67398"
                }
            ]
        },
        {
            "id": "CVE-2026-67373",
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2025 (CU8)",
            "title": "Microsoft SQL Server 2025 (CU8) vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.",
            "updated_at": "2026-09-09T05:17:28.693",
            "published_at": "2026-09-08T18:18:20.950",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0.0.0 through before 17.0.4085.5 (custom); 17.0.1050.2 through before 17.0.1135.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67373"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:18:20.950",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67373"
                }
            ]
        },
        {
            "id": "CVE-2026-67370",
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (CU 31)",
            "title": "Microsoft SQL Server 2017 (CU 31) vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-09T05:17:28.550",
            "published_at": "2026-09-08T18:18:20.817",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0 through before 14.0.3550.4 (custom); 14.0.0 through before 14.0.2130.4 (custom); 15.0.0.0 through before 15.0.4490.9 (custom); 15.0.0 through before 15.0.2190.7 (custom); 16.0.0.0 through before 16.0.4275.2 (custom); 16.0.0 through before 16.0.1200.5 (custom); 17.0.0.0 through before 17.0.4085.5 (custom); 17.0.1050.2 through before 17.0.1135.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67370"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:18:20.817",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67370"
                }
            ]
        },
        {
            "id": "CVE-2026-67368",
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (CU 31)",
            "title": "Microsoft SQL Server 2017 (CU 31) vulnerability",
            "summary": "Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-09T04:18:05.113",
            "published_at": "2026-09-08T18:18:20.550",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0 through before 14.0.3550.4 (custom); 14.0.0 through before 14.0.2130.4 (custom); 15.0.0.0 through before 15.0.4490.9 (custom); 15.0.0 through before 15.0.2190.7 (custom); 16.0.0.0 through before 16.0.4275.2 (custom); 16.0.0 through before 16.0.1200.5 (custom); 17.0.0.0 through before 17.0.4085.5 (custom); 17.0.1050.2 through before 17.0.1135.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-59",
            "what_happened": "Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-67368"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:18:20.550",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67368"
                }
            ]
        },
        {
            "id": "CVE-2026-67350",
            "vendor": "s9y",
            "product": "Serendipity",
            "title": "Serendipity vulnerability",
            "summary": "Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits plugin is configured with commentredirection set to s9y. Attackers can craft trusted-looking URLs leveraging the legitimate blog domain to conduct phishing, deliver malware, or bypass URL reputation filters.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-07-31T15:18:01.103",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.6.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-601",
            "what_happened": "Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits plugin is configured with commentredirection set to s9y. Attackers can craft trusted-looking URLs leveraging the legitimate blog domain to conduct phishing, deliver malware, or bypass URL reputation filters.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/s9y/Serendipity/security/advisories/GHSA-77rw-27c5-4hxm",
                "https://www.vulncheck.com/advisories/serendipity-open-redirect-via-exit-php"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T15:18:01.103",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67350"
                }
            ]
        },
        {
            "id": "CVE-2026-67338",
            "vendor": "jupyterlab",
            "product": "jupyterlab",
            "title": "jupyterlab vulnerability",
            "summary": "JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.",
            "updated_at": "2026-09-09T20:36:38.867",
            "published_at": "2026-08-01T13:17:04.843",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.5.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-84",
            "what_happened": "JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6",
                "https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12",
                "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4",
                "https://www.vulncheck.com/advisories/jupyterlab-before-stored-xss-via-extension-manager"
            ],
            "timeline": [
                {
                    "at": "2026-08-01T13:17:04.843",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67338"
                }
            ]
        },
        {
            "id": "CVE-2026-67326",
            "vendor": "gitpython-developers",
            "product": "GitPython",
            "title": "GitPython vulnerability",
            "summary": "GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.",
            "updated_at": "2026-09-16T20:45:28.520",
            "published_at": "2026-08-01T13:17:03.063",
            "cvss": 7.3,
            "cvss_vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "before 3.1.50 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-20",
            "what_happened": "GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary section headers into .git/config. Attackers can inject newlines to create a forged [core] section with hooksPath pointing to attacker-controlled directories, achieving remote code execution when git hooks are triggered.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-mv93-w799-cj2w"
                }
            ],
            "references": [
                "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-mv93-w799-cj2w",
                "https://www.vulncheck.com/advisories/gitpython-before-newline-injection-via-config-writer-section"
            ],
            "timeline": [
                {
                    "at": "2026-08-01T13:17:03.063",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67326"
                }
            ]
        },
        {
            "id": "CVE-2026-67310",
            "vendor": "openremote",
            "product": "openremote",
            "title": "openremote vulnerability",
            "summary": "OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm access check validates only a single realm obtained via realms.stream().findFirst() on a HashSet of realms from the request, rather than all realms. Because HashSet iteration order is non-deterministic, an authenticated attacker who includes alarm-asset links from both their own realm and a victim realm can, with roughly 50% probability per request (retryable), persist cross-tenant links and disclose victim asset names (returned via @Formula fields) through GET requests on the attacker's own alarm. Fixed in 1.27.0.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-08-01T13:17:00.850",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.27.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of AlarmResourceImpl. The realm access check validates only a single realm obtained via realms.stream().findFirst() on a HashSet of realms from the request, rather than all realms. Because HashSet iteration order is non-deterministic, an authenticated attacker who includes alarm-asset links from both their own realm and a victim realm can, with roughly 50% probability per request (retryable), persist cross-tenant links and disclose victim asset names (returned via @Formula fields) through GET requests on the attacker's own alarm. Fixed in 1.27.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openremote/openremote/security/advisories/GHSA-q2gm-frx3-2qjr",
                "https://www.vulncheck.com/advisories/openremote-before-cross-tenant-idor-via-setassetlinks"
            ],
            "timeline": [
                {
                    "at": "2026-08-01T13:17:00.850",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67310"
                }
            ]
        },
        {
            "id": "CVE-2026-67309",
            "vendor": "traefik",
            "product": "traefik",
            "title": "traefik vulnerability",
            "summary": "Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (generated from the nginx.ingress.kubernetes.io/rewrite-target annotation). When an Ingress path uses a regex that captures attacker-controlled text without requiring a path separator (e.g., path /api(.*) with rewrite target /$1), a crafted request such as /api../admin matches the public router, is rewritten to a dot-segment traversal path (/../admin), and is forwarded without post-replacement normalization validation. A backend that normalizes dot segments resolves the path to a protected endpoint (e.g., /admin) reachable only through a separate router secured with BasicAuth, DigestAuth, or ForwardAuth, resulting in route-level authentication bypass. The issue is fixed in v3.7.8.",
            "updated_at": "2026-09-16T20:45:02.070",
            "published_at": "2026-08-01T13:17:00.703",
            "cvss": 7.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "3.7.0 through before 3.7.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (generated from the nginx.ingress.kubernetes.io/rewrite-target annotation). When an Ingress path uses a regex that captures attacker-controlled text without requiring a path separator (e.g., path /api(.*) with rewrite target /$1), a crafted request such as /api../admin matches the public router, is rewritten to a dot-segment traversal path (/../admin), and is forwarded without post-replacement normalization validation. A backend that normalizes dot segments resolves the path to a protected endpoint (e.g., /admin) reachable only through a separate router secured with BasicAuth, DigestAuth, or ForwardAuth, resulting in route-level authentication bypass. The issue is fixed in v3.7.8.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/traefik/traefik/security/advisories/GHSA-8rxv-jg7p-wvg3"
                }
            ],
            "references": [
                "https://github.com/traefik/traefik/commit/69259c3acc9d4bdc065cb2e3b83336f7de3e7038",
                "https://github.com/traefik/traefik/commit/b93f02cd07b79490fb8c8f02e301a7a1ec553195",
                "https://github.com/traefik/traefik/security/advisories/GHSA-8rxv-jg7p-wvg3",
                "https://www.vulncheck.com/advisories/traefik-path-traversal-via-rewritetarget-authentication-bypass"
            ],
            "timeline": [
                {
                    "at": "2026-08-01T13:17:00.703",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67309"
                }
            ]
        },
        {
            "id": "CVE-2026-67308",
            "vendor": "wazuh",
            "product": "wazuh",
            "title": "wazuh vulnerability",
            "summary": "Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are directly interpolated into run steps, enabling command execution and exfiltration of secrets including GITHUB_TOKEN and AWS credentials on self-hosted runners.",
            "updated_at": "2026-09-09T20:26:18.573",
            "published_at": "2026-08-01T13:17:00.553",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 44bf114d2f4901aa82ecbb9e5b0780f7c3ca5263 (git)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are directly interpolated into run steps, enabling command execution and exfiltration of secrets including GITHUB_TOKEN and AWS credentials on self-hosted runners.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/wazuh/wazuh/security/advisories/GHSA-95w2-gpvr-q4jh",
                "https://www.vulncheck.com/advisories/wazuh-github-actions-shell-injection-via-fork-pull-request"
            ],
            "timeline": [
                {
                    "at": "2026-08-01T13:17:00.553",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67308"
                }
            ]
        },
        {
            "id": "CVE-2026-67297",
            "vendor": "FreeRDP",
            "product": "FreeRDP",
            "title": "FreeRDP vulnerability",
            "summary": "FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.",
            "updated_at": "2026-09-11T21:04:27.790",
            "published_at": "2026-08-01T13:16:58.967",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 3.29.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2c6r-4pr4-9x8m"
                }
            ],
            "references": [
                "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2c6r-4pr4-9x8m",
                "https://www.vulncheck.com/advisories/freerdp-before-resource-exhaustion-via-chunked-http-response"
            ],
            "timeline": [
                {
                    "at": "2026-08-01T13:16:58.967",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67297"
                }
            ]
        },
        {
            "id": "CVE-2026-67296",
            "vendor": "FreeRDP",
            "product": "FreeRDP",
            "title": "FreeRDP vulnerability",
            "summary": "FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.",
            "updated_at": "2026-09-11T21:03:57.027",
            "published_at": "2026-08-01T13:16:58.830",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 3.29.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jm8r-22j6-4m4v"
                }
            ],
            "references": [
                "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jm8r-22j6-4m4v",
                "https://www.vulncheck.com/advisories/freerdp-before-denial-of-service-via-rdpei-pdu"
            ],
            "timeline": [
                {
                    "at": "2026-08-01T13:16:58.830",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67296"
                }
            ]
        },
        {
            "id": "CVE-2026-67294",
            "vendor": "FreeRDP",
            "product": "FreeRDP",
            "title": "FreeRDP vulnerability",
            "summary": "FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. In x509_utils_verify(), when server-purpose (X509_PURPOSE_SSL_SERVER) verification fails, the code falls back to client-purpose and any-purpose verification, so a trusted, hostname-matching certificate valid only for clientAuth can be accepted as the RDP server certificate. In environments relying on EKU separation between client and server certificates, this allows a clientAuth-only certificate issued by a trusted CA to bypass server certificate purpose validation.",
            "updated_at": "2026-09-11T21:03:16.017",
            "published_at": "2026-08-01T13:16:58.523",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 3.29.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 23,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication. In x509_utils_verify(), when server-purpose (X509_PURPOSE_SSL_SERVER) verification fails, the code falls back to client-purpose and any-purpose verification, so a trusted, hostname-matching certificate valid only for clientAuth can be accepted as the RDP server certificate. In environments relying on EKU separation between client and server certificates, this allows a clientAuth-only certificate issued by a trusted CA to bypass server certificate purpose validation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-89c6-jjrw-96h4"
                }
            ],
            "references": [
                "https://github.com/FreeRDP/FreeRDP/commit/f3b4347105114fe7453828736bea069999af319f",
                "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-89c6-jjrw-96h4",
                "https://www.vulncheck.com/advisories/freerdp-before-tls-certificate-eku-bypass"
            ],
            "timeline": [
                {
                    "at": "2026-08-01T13:16:58.523",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67294"
                }
            ]
        },
        {
            "id": "CVE-2026-67292",
            "vendor": "FreeRDP",
            "product": "FreeRDP",
            "title": "FreeRDP vulnerability",
            "summary": "FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to the actual received Ping payload, so a malicious gateway/WebSocket peer sending a non-empty Ping control frame causes the client to reply with an overlong Pong that discloses bytes beyond the received payload (the peer receives the masking key and can unmask the reply). A zero-length Ping reaches an assertion and terminates the client (denial of service).",
            "updated_at": "2026-09-11T21:02:51.287",
            "published_at": "2026-08-01T13:16:58.240",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 3.29.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 23,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-130",
            "what_happened": "FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to the actual received Ping payload, so a malicious gateway/WebSocket peer sending a non-empty Ping control frame causes the client to reply with an overlong Pong that discloses bytes beyond the received payload (the peer receives the masking key and can unmask the reply). A zero-length Ping reaches an assertion and terminates the client (denial of service).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8v6m-2cmc-chx9"
                }
            ],
            "references": [
                "https://github.com/FreeRDP/FreeRDP/commit/f3b4347105114fe7453828736bea069999af319f",
                "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8v6m-2cmc-chx9",
                "https://www.vulncheck.com/advisories/freerdp-before-websocket-ping-buffer-over-disclosure"
            ],
            "timeline": [
                {
                    "at": "2026-08-01T13:16:58.240",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67292"
                }
            ]
        },
        {
            "id": "CVE-2026-67281",
            "vendor": "Mikrotik",
            "product": "RouterOS",
            "title": "RouterOS vulnerability",
            "summary": "RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)",
            "updated_at": "2026-09-07T14:16:54.077",
            "published_at": "2026-09-05T20:17:18.547",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.24 through before 7.24.2 (custom); 7.20 through before 7.23.4 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve",
                "https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/",
                "https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802",
                "https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801",
                "https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800",
                "https://mikrotik.com/supportsec/september-2026-vulnerability/",
                "https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T20:17:18.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67281"
                }
            ]
        },
        {
            "id": "CVE-2026-67279",
            "vendor": "Mikrotik",
            "product": "RouterOS",
            "title": "RouterOS vulnerability",
            "summary": "RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)",
            "updated_at": "2026-09-05T21:16:50.613",
            "published_at": "2026-09-05T20:17:18.390",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.24 through before 7.24.2 (custom); 7.0.0 through before 7.23.4 (custom); 6.0.0 through before 6.49.21 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-841",
            "what_happened": "RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve",
                "https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/",
                "https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802",
                "https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801",
                "https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800",
                "https://mikrotik.com/supportsec/september-2026-vulnerability/",
                "https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T20:17:18.390",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67279"
                }
            ]
        },
        {
            "id": "CVE-2026-67278",
            "vendor": "Mikrotik",
            "product": "RouterOS",
            "title": "RouterOS vulnerability",
            "summary": "MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation.\n\nThis issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)",
            "updated_at": "2026-09-07T14:16:53.963",
            "published_at": "2026-09-05T20:17:18.257",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.24 through before 7.24.2 (custom); 7.0.0 through before 7.23.4 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-347",
            "what_happened": "MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation.\n\nThis issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve",
                "https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/",
                "https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802",
                "https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801",
                "https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800",
                "https://mikrotik.com/supportsec/september-2026-vulnerability/",
                "https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T20:17:18.257",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67278"
                }
            ]
        },
        {
            "id": "CVE-2026-67277",
            "vendor": "Mikrotik",
            "product": "RouterOS",
            "title": "RouterOS vulnerability",
            "summary": "RouterOS accepts a \"related\" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With \"random-data=false\", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.\n\n\n\nThis issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)",
            "updated_at": "2026-09-11T04:17:44.900",
            "published_at": "2026-09-05T20:17:18.120",
            "cvss": 8.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "7.24 through before 7.24.2 (custom); 7.0.0 through before 7.23.4 (custom); 6.0.0 through before 6.49.21 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 30,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "RouterOS accepts a \"related\" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With \"random-data=false\", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.\n\n\n\nThis issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve",
                "https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/",
                "https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802",
                "https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801",
                "https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800",
                "https://mikrotik.com/supportsec/september-2026-vulnerability/",
                "https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-67277"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T20:17:18.120",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67277"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-67276",
            "vendor": "Mikrotik",
            "product": "RouterOS",
            "title": "RouterOS vulnerability",
            "summary": "RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)",
            "updated_at": "2026-09-09T05:17:28.130",
            "published_at": "2026-09-05T20:17:17.977",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.24 through before 7.24.2 (custom); 7.9 through before 7.23.4 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-347",
            "what_happened": "RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve",
                "https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/",
                "https://forum.mikrotik.com/t/6-49-21-long-term-is-released/272802",
                "https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801",
                "https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800",
                "https://mikrotik.com/supportsec/september-2026-vulnerability/",
                "https://npratley.net/reversing-mikrotiks-silent-patch-the-routeros-7-23-4-fix-they-wouldnt-explain/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T20:17:17.977",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67276"
                }
            ]
        },
        {
            "id": "CVE-2026-67260",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module import and object instantiation inside the scheduler process, or terminate the scheduler job. No non-default configuration is required: the sweep runs unconditionally every 15 seconds, and the default `allowed_deserialization_classes` setting does not cover this code path. Versions before 3.3.0 are not affected, because human-in-the-loop tasks deferred onto the triggerer instead. This is a different code path from CVE-2026-58076, which covers the same unguarded exception-node deserialization reached elsewhere — deployments that applied that fix must upgrade for this issue as well. Users are advised to upgrade to apache-airflow 3.3.1 or later.",
            "updated_at": "2026-09-16T15:17:40.903",
            "published_at": "2026-08-12T16:17:14.813",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.3.0 through before 3.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task execution API — can cause an arbitrary module import and object instantiation inside the scheduler process, or terminate the scheduler job. No non-default configuration is required: the sweep runs unconditionally every 15 seconds, and the default `allowed_deserialization_classes` setting does not cover this code path. Versions before 3.3.0 are not affected, because human-in-the-loop tasks deferred onto the triggerer instead. This is a different code path from CVE-2026-58076, which covers the same unguarded exception-node deserialization reached elsewhere — deployments that applied that fix must upgrade for this issue as well. Users are advised to upgrade to apache-airflow 3.3.1 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/70685",
                "https://lists.apache.org/thread/vygr0fh82cjzjp5k4vtfmboxryvm3lyn",
                "https://www.cve.org/CVERecord?id=CVE-2026-58076"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:14.813",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-67260"
                }
            ]
        },
        {
            "id": "CVE-2026-67206",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Wolf CMS 0.8.3.1 - RCE v",
            "summary": "Wolf CMS 0.8.3.1 - RCE v",
            "updated_at": "2026-08-31T22:00:00Z",
            "published_at": "2026-08-31T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 96,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52672",
                    "author": "Balachandar Gowrisankar",
                    "first_seen": "2026-09-01",
                    "confidence": "High",
                    "title": "Wolf CMS 0.8.3.1 - RCE v",
                    "summary": "Wolf CMS 0.8.3.1 - RCE v",
                    "url": "https://www.exploit-db.com/exploits/52672",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52672"
            ],
            "timeline": [
                {
                    "at": "2026-08-31T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52672"
                }
            ]
        },
        {
            "id": "CVE-2026-66898",
            "vendor": "Canonical",
            "product": "LXD",
            "title": "LXD vulnerability",
            "summary": "A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.",
            "updated_at": "2026-09-11T15:30:05.387",
            "published_at": "2026-08-12T21:17:39.700",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "4.0.0 through before 4.0.12 (semver); 5.0.0 through before 5.0.4 (semver); 5.21.0 through before 5.21.2 (semver); 6.0 through before 6.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An attacker can exploit this flaw by supplying a crafted backup archive with malicious instance or volume names containing path traversal sequences, potentially allowing file access or overwriting outside the designated restore directory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/canonical/lxd/security/advisories/GHSA-m857-c7gc-c984"
                }
            ],
            "references": [
                "https://github.com/canonical/lxd/security/advisories/GHSA-m857-c7gc-c984"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T21:17:39.700",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66898"
                }
            ]
        },
        {
            "id": "CVE-2026-66897",
            "vendor": "Canonical",
            "product": "LXD",
            "title": "LXD vulnerability",
            "summary": "A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution.",
            "updated_at": "2026-09-11T15:28:53.323",
            "published_at": "2026-08-24T10:16:39.767",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "4.0.0 through before 4.0.13 (semver); 5.0.0 through before 5.0.9 (semver); 5.21.0 through before 5.21.7 (semver); 6.0 through before 6.10 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target template paths specified in metadata.yaml, LXD validates the path against a confined os.Root directory handle but subsequently opens and creates the file using os.Create with an unconfined string path. This discrepancy between path resolution checks and file creation allows an attacker to escape directory confinement, overwrite root-owned host files, and achieve host root code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-24",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/canonical/lxd/security/advisories/GHSA-q39m-8fx9-42fv"
                }
            ],
            "references": [
                "https://github.com/canonical/lxd/security/advisories/GHSA-q39m-8fx9-42fv"
            ],
            "timeline": [
                {
                    "at": "2026-08-24T10:16:39.767",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66897"
                }
            ]
        },
        {
            "id": "CVE-2026-66835",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash.\n\nhttpd_request:validate_uri/1 normalises the request URI with uri_string:normalize/1, which performs RFC 3986 dot-segment removal but does not collapse empty path segments, so a doubled slash survives. mod_alias:real_name/3 concatenates the document root with that URI, and mod_auth:secret_path/3 then decides whether the result lies inside a protected directory block by running the configured directory path as an unanchored regular expression against it. The doubled slash breaks the contiguous substring the regex needs, so the request is treated as unprotected and no authentication challenge is issued, while mod_get opens the same path and the operating system collapses the doubled slash and returns the protected file. The same path mismatch also evades the per-path accounting in mod_security.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "updated_at": "2026-09-08T01:17:52.243",
            "published_at": "2026-09-01T15:17:23.433",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 5.10 through before 9.3.2.7 (otp); 9.4 through before 9.6.2.3 (otp); 9.7 through before 9.7.2 (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-50",
            "what_happened": "Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory by prefixing the request path with an extra slash.\n\nhttpd_request:validate_uri/1 normalises the request URI with uri_string:normalize/1, which performs RFC 3986 dot-segment removal but does not collapse empty path segments, so a doubled slash survives. mod_alias:real_name/3 concatenates the document root with that URI, and mod_auth:secret_path/3 then decides whether the result lies inside a protected directory block by running the configured directory path as an unanchored regular expression against it. The doubled slash breaks the contiguous substring the regex needs, so the request is treated as unprotected and no authentication challenge is issued, while mod_get opens the same path and the operating system collapses the doubled slash and returns the protected file. The same path mismatch also evades the per-path accounting in mod_security.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-66835.html",
                "https://github.com/erlang/otp/commit/9641944a2efbf55bea760f8ff7ba777fe3a0961c",
                "https://github.com/erlang/otp/commit/bac19eb3dbd96cc49b6d8cabc1c04248bf8c79f6",
                "https://github.com/erlang/otp/commit/d8878dec0ececc2eab18e47bb18b472f224ca633",
                "https://github.com/erlang/otp/security/advisories/GHSA-r4vv-vc2c-2fw6",
                "https://osv.dev/vulnerability/EEF-CVE-2026-66835",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:23.433",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66835"
                }
            ]
        },
        {
            "id": "CVE-2026-66820",
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (CU 31)",
            "title": "Microsoft SQL Server 2017 (CU 31) vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-09T05:17:27.977",
            "published_at": "2026-09-08T18:18:20.420",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0 through before 14.0.3550.4 (custom); 14.0.0 through before 14.0.2130.4 (custom); 15.0.0.0 through before 15.0.4490.9 (custom); 15.0.0 through before 15.0.2190.7 (custom); 16.0.0.0 through before 16.0.4275.2 (custom); 16.0.0 through before 16.0.1200.5 (custom); 17.0.0.0 through before 17.0.4085.5 (custom); 17.0.1050.2 through before 17.0.1135.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66820"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:18:20.420",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66820"
                }
            ]
        },
        {
            "id": "CVE-2026-66819",
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (CU 31)",
            "title": "Microsoft SQL Server 2017 (CU 31) vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-09T04:18:04.607",
            "published_at": "2026-09-08T18:18:20.273",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0 through before 14.0.3550.4 (custom); 14.0.0 through before 14.0.2130.4 (custom); 15.0.0.0 through before 15.0.4490.9 (custom); 15.0.0 through before 15.0.2190.7 (custom); 16.0.0.0 through before 16.0.4275.2 (custom); 16.0.0 through before 16.0.1200.5 (custom); 17.0.0.0 through before 17.0.4085.5 (custom); 17.0.1050.2 through before 17.0.1135.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66819"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:18:20.273",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66819"
                }
            ]
        },
        {
            "id": "CVE-2026-66818",
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (CU 31)",
            "title": "Microsoft SQL Server 2017 (CU 31) vulnerability",
            "summary": "Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-09T04:18:04.143",
            "published_at": "2026-09-08T18:18:20.143",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0 through before 14.0.3550.4 (custom); 14.0.0 through before 14.0.2130.4 (custom); 15.0.0.0 through before 15.0.4490.9 (custom); 15.0.0 through before 15.0.2190.7 (custom); 16.0.0.0 through before 16.0.4275.2 (custom); 16.0.0 through before 16.0.1200.5 (custom); 17.0.0.0 through before 17.0.4085.5 (custom); 17.0.1050.2 through before 17.0.1135.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66818"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:18:20.143",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66818"
                }
            ]
        },
        {
            "id": "CVE-2026-66814",
            "vendor": "Microsoft",
            "product": "Microsoft SQL Server 2017 (CU 31)",
            "title": "Microsoft SQL Server 2017 (CU 31) vulnerability",
            "summary": "Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-09T05:17:27.643",
            "published_at": "2026-09-08T18:18:19.880",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0 through before 14.0.3550.4 (custom); 14.0.0 through before 14.0.2130.4 (custom); 15.0.0.0 through before 15.0.4490.9 (custom); 15.0.0 through before 15.0.2190.7 (custom); 16.0.0.0 through before 16.0.4275.2 (custom); 16.0.0 through before 16.0.1200.5 (custom); 17.0.0.0 through before 17.0.4085.5 (custom); 17.0.1050.2 through before 17.0.1135.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-1220",
            "what_happened": "Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66814"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:18:19.880",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66814"
                }
            ]
        },
        {
            "id": "CVE-2026-66795",
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1",
            "title": "multicluster engine for Kubernetes 2.1 vulnerability",
            "summary": "A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster.",
            "updated_at": "2026-09-07T19:17:27.280",
            "published_at": "2026-08-17T21:16:47.163",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to submit a malicious CSR. Successful exploitation can lead to privilege escalation, enabling the attacker to obtain administrative credentials on the hub cluster.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:59556",
                "https://access.redhat.com/errata/RHSA-2026:59557",
                "https://access.redhat.com/errata/RHSA-2026:59558",
                "https://access.redhat.com/errata/RHSA-2026:59559",
                "https://access.redhat.com/errata/RHSA-2026:59579",
                "https://access.redhat.com/errata/RHSA-2026:59593",
                "https://access.redhat.com/security/cve/CVE-2026-66795",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2507540"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T21:16:47.163",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66795"
                }
            ]
        },
        {
            "id": "CVE-2026-66794",
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1",
            "title": "multicluster engine for Kubernetes 2.1 vulnerability",
            "summary": "A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary services across any managed cluster. This enables unauthorized access to internal services that would otherwise be protected, potentially leading to information disclosure or further compromise of the cluster environment.",
            "updated_at": "2026-09-07T19:17:27.137",
            "published_at": "2026-08-19T18:17:16.547",
            "cvss": 9.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary services across any managed cluster. This enables unauthorized access to internal services that would otherwise be protected, potentially leading to information disclosure or further compromise of the cluster environment.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:59556",
                "https://access.redhat.com/errata/RHSA-2026:59557",
                "https://access.redhat.com/errata/RHSA-2026:59558",
                "https://access.redhat.com/errata/RHSA-2026:59559",
                "https://access.redhat.com/errata/RHSA-2026:59579",
                "https://access.redhat.com/errata/RHSA-2026:59593",
                "https://access.redhat.com/security/cve/CVE-2026-66794",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2507539"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T18:17:16.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66794"
                }
            ]
        },
        {
            "id": "CVE-2026-66768",
            "vendor": "SAP_SE",
            "product": "SAP NetWeaver (SAP GUI for Java)",
            "title": "SAP NetWeaver (SAP GUI for Java) vulnerability",
            "summary": "SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.",
            "updated_at": "2026-09-09T05:17:27.537",
            "published_at": "2026-09-08T01:17:52.113",
            "cvss": 9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "BC-FES-JAV 8.10",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-807",
            "what_happened": "SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3781729",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:52.113",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66768"
                }
            ]
        },
        {
            "id": "CVE-2026-66767",
            "vendor": "SAP_SE",
            "product": "SAP NetWeaver Application Server for ABAP and ABAP Platform",
            "title": "SAP NetWeaver Application Server for ABAP and ABAP Platform vulnerability",
            "summary": "SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.",
            "updated_at": "2026-09-09T05:17:27.420",
            "published_at": "2026-09-08T01:17:51.987",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "KRNL64NUC 7.22; 7.22EXT; KRNL64UC 7.22; 7.53; 8.04; KERNEL 7.22; 7.54; 7.77; 7.93; 9.16; 9.18; 9.19; 9.20",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-191",
            "what_happened": "SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3757002",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:51.987",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66767"
                }
            ]
        },
        {
            "id": "CVE-2026-66627",
            "vendor": "EDGE22 Studios Ltd.",
            "product": "GP Premium",
            "title": "GP Premium vulnerability",
            "summary": "Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion.\n\nThis issue affects GP Premium: from n/a through 2.5.5.",
            "updated_at": "2026-09-08T00:16:52.683",
            "published_at": "2026-08-18T15:16:57.563",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a through 2.5.5 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion.\n\nThis issue affects GP Premium: from n/a through 2.5.5.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://patchstack.com/database/wordpress/plugin/gp-premium/vulnerability/wordpress-gp-premium-plugin-2-5-5-arbitrary-file-upload-vulnerability?_s_id=cve"
            ],
            "timeline": [
                {
                    "at": "2026-08-18T15:16:57.563",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66627"
                }
            ]
        },
        {
            "id": "CVE-2026-66420",
            "vendor": "Ylianst",
            "product": "MeshCentral",
            "title": "MeshCentral vulnerability",
            "summary": "MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of the twelve WebSocket endpoints, send crafted action commands to exfiltrate the server sessionKey used to sign session cookies, forge session tokens as arbitrary users, and gain full remote control of all managed devices governed by the MeshCentral instance.",
            "updated_at": "2026-09-09T20:26:18.573",
            "published_at": "2026-07-30T23:16:53.527",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.1.21 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-346",
            "what_happened": "MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed certificates are in use. Attackers can open cross-origin WebSocket connections to any of the twelve WebSocket endpoints, send crafted action commands to exfiltrate the server sessionKey used to sign session cookies, forge session tokens as arbitrary users, and gain full remote control of all managed devices governed by the MeshCentral instance.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Ylianst/MeshCentral",
                "https://github.com/Ylianst/MeshCentral/commit/f04c9f4",
                "https://github.com/Ylianst/MeshCentral/pull/7882",
                "https://www.vulncheck.com/advisories/meshcentral-cross-site-websocket-hijacking-via-origin-validation-bypass-on-self-signed-certificate-deployments"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T23:16:53.527",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66420"
                }
            ]
        },
        {
            "id": "CVE-2026-66384",
            "vendor": "JFrog",
            "product": "Artifactory",
            "title": "JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability",
            "summary": "JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.",
            "updated_at": "2026-08-26T22:00:00Z",
            "published_at": "2026-08-26T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 49,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-66373",
            "vendor": "Redis",
            "product": "Redis",
            "title": "Redis vulnerability",
            "summary": "Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.",
            "updated_at": "2026-09-09T16:03:33.283",
            "published_at": "2026-07-25T01:16:26.277",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 8.8.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-415",
            "what_happened": "Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/berabuddies/redis-poc",
                "https://github.com/redis/redis/compare/8.6.4...8.8.0",
                "https://github.com/redis/redis/pull/15081",
                "https://news.ycombinator.com/item?id=49024938",
                "https://x.com/Fried_rice/status/2080059356322918777",
                "https://lists.debian.org/debian-lts-announce/2026/08/msg00012.html"
            ],
            "timeline": [
                {
                    "at": "2026-07-25T01:16:26.277",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66373"
                }
            ]
        },
        {
            "id": "CVE-2026-66357",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a new header. This missing feature became a security concern as the understanding of HTTP request smuggling attacks evolved.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "updated_at": "2026-09-08T01:17:51.840",
            "published_at": "2026-09-01T15:17:23.047",
            "cvss": 8.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 5.10 through before 9.3.2.7 (otp); 9.4 through before 9.6.2.3 (otp); 9.7 through before 9.7.2 (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-444",
            "what_happened": "httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet unconditionally starts a new header. This missing feature became a security concern as the understanding of HTTP request smuggling attacks evolved.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-66357.html",
                "https://github.com/erlang/otp/commit/220d618d2479a7180b4a06d0c5aacfaa4af4a85b",
                "https://github.com/erlang/otp/commit/273d8958de38ff2a7fe0c5dcc5b6bfe6f65717f3",
                "https://github.com/erlang/otp/commit/e640d599287d2eba919e6f13b91f042d7dbe6ff4",
                "https://github.com/erlang/otp/security/advisories/GHSA-qh2f-33hj-37qf",
                "https://osv.dev/vulnerability/EEF-CVE-2026-66357"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:23.047",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66357"
                }
            ]
        },
        {
            "id": "CVE-2026-66066",
            "vendor": "rails",
            "product": "rails",
            "title": "rails vulnerability",
            "summary": "Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.",
            "updated_at": "2026-09-10T20:36:14.340",
            "published_at": "2026-07-30T19:18:35.843",
            "cvss": 9.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 7.2.3.2; >= 8.0.0.beta1, < 8.0.5.1; >= 8.1.0.beta1, < 8.1.3.1",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1188",
            "what_happened": "Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/rails/rails/commit/1c01bb587206ee6eb0e1179c2cef96a6a47acb1e",
                "https://github.com/rails/rails/commit/349e7a5d5b4b715af1e416db824f3c078a7d59e5",
                "https://github.com/rails/rails/commit/d79b7f4aa17dec8ce4960fef05733c8c0c7ef49a",
                "https://github.com/rails/rails/releases/tag/v7.2.3.2",
                "https://github.com/rails/rails/releases/tag/v8.0.5.1",
                "https://github.com/rails/rails/releases/tag/v8.1.3.1",
                "https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm",
                "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2026-66066.yml",
                "https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html",
                "http://www.openwall.com/lists/oss-security/2026/07/29/9",
                "http://www.openwall.com/lists/oss-security/2026/08/01/6",
                "https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066",
                "https://github.com/rails/rails-forensics-CVE-2026-66066"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T19:18:35.843",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66066"
                }
            ]
        },
        {
            "id": "CVE-2026-66065",
            "vendor": "Q00",
            "product": "ouroboros",
            "title": "ouroboros vulnerability",
            "summary": "Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary command execution by shipping a .env (auto-loaded at import, with no review step). The CVE-2026-47211 fix added _UNTRUSTED_ENV_DENYLIST to stop an untrusted project-directory .env from redirecting execution, but it did not account for all keys. The backend config-home and MCP/plugin roots bypass the approval gate by pointing the nested agent, MCP servers, and plugin roster at attacker config. Other variables re-enable blocked local transports, replace sub-agent prompts, switch backends, and lower tool approval classes, further weakening the approval gate. This issue has been fixed in version 0.42.1.",
            "updated_at": "2026-09-10T20:31:16.483",
            "published_at": "2026-08-03T21:16:41.193",
            "cvss": 8.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 0.42.1",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-15",
            "what_happened": "Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary command execution by shipping a .env (auto-loaded at import, with no review step). The CVE-2026-47211 fix added _UNTRUSTED_ENV_DENYLIST to stop an untrusted project-directory .env from redirecting execution, but it did not account for all keys. The backend config-home and MCP/plugin roots bypass the approval gate by pointing the nested agent, MCP servers, and plugin roster at attacker config. Other variables re-enable blocked local transports, replace sub-agent prompts, switch backends, and lower tool approval classes, further weakening the approval gate. This issue has been fixed in version 0.42.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Q00/ouroboros/releases/tag/v0.42.1",
                "https://github.com/Q00/ouroboros/security/advisories/GHSA-jv2h-4p9v-wf5w"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:41.193",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66065"
                }
            ]
        },
        {
            "id": "CVE-2026-66016",
            "vendor": "jfrog",
            "product": "artifactory",
            "title": "artifactory vulnerability",
            "summary": "Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.",
            "updated_at": "2026-09-11T18:50:25.797",
            "published_at": "2026-08-12T16:17:14.383",
            "cvss": 6.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 7.146.35 (custom); 7.161.0 through before 7.161.16 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-312",
            "what_happened": "Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged local users.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
                "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:14.383",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66016"
                }
            ]
        },
        {
            "id": "CVE-2026-66014",
            "vendor": "jfrog",
            "product": "artifactory",
            "title": "artifactory vulnerability",
            "summary": "JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.",
            "updated_at": "2026-09-15T18:30:26.147",
            "published_at": "2026-07-27T20:16:41.790",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 7.111.18 (custom); 7.117.0 through before 7.117.25 (custom); 7.125.0 through before 7.125.18 (custom); 7.133.0 through before 7.133.27 (custom); 7.146.0 through before 7.146.34 (custom); 7.161.0 through before 7.161.15 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
                "https://docs.jfrog.com/releases/docs/jfrog-security-advisories"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T20:16:41.790",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66014"
                }
            ]
        },
        {
            "id": "CVE-2026-65981",
            "vendor": "coturn",
            "product": "coturn",
            "title": "coturn vulnerability",
            "summary": "Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an authenticated attacker who obtains a victim MOBILITY-TICKET to receive and inject relayed traffic and consume the victim's quota. In the handle_turn_refresh resume branch, the victim allocation (orig_ss) is located solely by the attacker-controlled mobile id, and credentials are only adopted (via copy_auth_parameters) when the resuming session is unauthenticated. Because the attacker's session already has hmackey_set set to 1 from its own prior authentication (which is never reset for long-term-credential sessions), the credential copy is skipped and check_stun_auth validates the REFRESH against the attacker's own identity rather than the allocation owner's. This issue is fixed in version 4.15.0.",
            "updated_at": "2026-09-09T20:55:04.493",
            "published_at": "2026-07-31T21:17:31.857",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 4.15.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-639",
            "what_happened": "Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an authenticated attacker who obtains a victim MOBILITY-TICKET to receive and inject relayed traffic and consume the victim's quota. In the handle_turn_refresh resume branch, the victim allocation (orig_ss) is located solely by the attacker-controlled mobile id, and credentials are only adopted (via copy_auth_parameters) when the resuming session is unauthenticated. Because the attacker's session already has hmackey_set set to 1 from its own prior authentication (which is never reset for long-term-credential sessions), the credential copy is skipped and check_stun_auth validates the REFRESH against the attacker's own identity rather than the allocation owner's. This issue is fixed in version 4.15.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/coturn/coturn/commit/37df0513168f830a7c9ce0a411db0300fa182f05",
                "https://github.com/coturn/coturn/security/advisories/GHSA-69wx-x7x6-pjj8"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T21:17:31.857",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65981"
                }
            ]
        },
        {
            "id": "CVE-2026-65919",
            "vendor": "meshery",
            "product": "meshery",
            "title": "meshery vulnerability",
            "summary": "Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. Attackers can supply absolute paths or traversal sequences in the file parameter to read arbitrary files from the host filesystem without authentication.",
            "updated_at": "2026-09-14T19:17:38.640",
            "published_at": "2026-07-23T18:17:02.290",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.0.57 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. Attackers can supply absolute paths or traversal sequences in the file parameter to read arbitrary files from the host filesystem without authentication.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/meshery/meshery/commit/ea83a26cb090b13be36c07cf24a99f8c637cc765",
                "https://github.com/meshery/meshery/issues/18375",
                "https://github.com/meshery/meshery/issues/20076",
                "https://github.com/meshery/meshery/pull/20133",
                "https://github.com/meshery/meshery/releases/tag/v1.0.57",
                "https://www.vulncheck.com/advisories/meshery-unauthenticated-arbitrary-file-read-via-fileview-and-filedownload"
            ],
            "timeline": [
                {
                    "at": "2026-07-23T18:17:02.290",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65919"
                }
            ]
        },
        {
            "id": "CVE-2026-65841",
            "vendor": "xdan",
            "product": "jodit",
            "title": "jodit vulnerability",
            "summary": "Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and execute when content is loaded. This issue is fixed in version 4.13.6.",
            "updated_at": "2026-09-09T20:55:04.493",
            "published_at": "2026-07-31T20:16:53.967",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 4.13.6",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-80",
            "what_happened": "Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.13.6, Jodit's clean-html denyTags filter does not normalize foreign SVG or MathML script node names, allowing a script element nested directly in SVG or MathML to remain in editor.value and execute when content is loaded. This issue is fixed in version 4.13.6.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/xdan/jodit/commit/49a31f451f6b686f5610022a1d4406ee85138dc5",
                "https://github.com/xdan/jodit/releases/tag/4.13.6",
                "https://github.com/xdan/jodit/security/advisories/GHSA-45qg-252v-3f7p"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T20:16:53.967",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65841"
                }
            ]
        },
        {
            "id": "CVE-2026-65818",
            "vendor": "Microsoft",
            "product": "Microsoft Power Platform",
            "title": "Microsoft Power Platform vulnerability",
            "summary": "Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-05T04:18:04.580",
            "published_at": "2026-09-03T23:17:19.817",
            "cvss": 8.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "-",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-918",
            "what_happened": "Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65818"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T23:17:19.817",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65818"
                }
            ]
        },
        {
            "id": "CVE-2026-65669",
            "vendor": "Microsoft",
            "product": "SQL Server Management Studio 22",
            "title": "SQL Server Management Studio 22 vulnerability",
            "summary": "Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-09T04:18:03.657",
            "published_at": "2026-09-08T18:18:14.893",
            "cvss": 9.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "22.0 through before 22.8.2 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65669"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:18:14.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65669"
                }
            ]
        },
        {
            "id": "CVE-2026-65400",
            "vendor": "Apple",
            "product": "macOS",
            "title": "macOS vulnerability",
            "summary": "An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.",
            "updated_at": "2026-09-15T12:47:12.333",
            "published_at": "2026-08-06T22:18:14.533",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "review",
            "affected": "before 14.8.9 (custom); before 15.7.9 (custom); before 26.6.1 (custom); before 26.7 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 44,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · HORKimhab/CVE-2026-65400",
                    "author": "HORKimhab",
                    "first_seen": "2026-08-18",
                    "last_seen": "2026-08-26T09:28:45Z",
                    "pushed_at": "2026-08-18T01:51:36Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 3,
                    "forks": 1,
                    "topics": [],
                    "title": "CVE-2026-65400",
                    "repository_description": "CVE-2026-65400",
                    "summary": "CVE-2026-65400",
                    "source": "CVE-Intel",
                    "url": "https://github.com/HORKimhab/CVE-2026-65400"
                },
                {
                    "repository": "CVE-Intel · panchocosil/CVE-2026-65400-poc",
                    "author": "panchocosil",
                    "first_seen": "2026-08-21",
                    "last_seen": "2026-08-25T03:42:35Z",
                    "pushed_at": "2026-08-22T17:57:51Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Bypass",
                    "language": "Python",
                    "stars": 3,
                    "forks": 0,
                    "topics": [
                        "apple",
                        "cve-2026-65400",
                        "exploit",
                        "macos",
                        "poc",
                        "screen-sharing",
                        "security-research",
                        "vulnerability-research"
                    ],
                    "title": "Read-only PoC for CVE-2026-65400 — macOS Screen Sharing (screensharingd) pre-auth SRP bypass giving root file read. Patched in macOS 26.6.1 / 15.7.9 / 14.8.9.",
                    "repository_description": "Read-only PoC for CVE-2026-65400 — macOS Screen Sharing (screensharingd) pre-auth SRP bypass giving root file read. Patched in macOS 26.6.1 / 15.7.9 / 14.8.9.",
                    "summary": "Read-only PoC for CVE-2026-65400 — macOS Screen Sharing (screensharingd) pre-auth SRP bypass giving root file read. Patched in macOS 26.6.1 / 15.7.9 / 14.8.9.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/panchocosil/CVE-2026-65400-poc"
                },
                {
                    "repository": "CVE-Intel · acheong08/CVE-2026-65400",
                    "author": "acheong08",
                    "first_seen": "2026-08-22",
                    "last_seen": "2026-08-22T15:30:42Z",
                    "pushed_at": "2026-08-22T09:27:55Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 2,
                    "forks": 1,
                    "topics": [],
                    "title": "Apple MacOS Screen Sharing Arbitrary File read/write -> RCE",
                    "repository_description": "Apple MacOS Screen Sharing Arbitrary File read/write -> RCE",
                    "summary": "Apple MacOS Screen Sharing Arbitrary File read/write -> RCE",
                    "source": "CVE-Intel",
                    "url": "https://github.com/acheong08/CVE-2026-65400"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/HORKimhab/CVE-2026-65400",
                "https://github.com/panchocosil/CVE-2026-65400-poc",
                "https://github.com/acheong08/CVE-2026-65400",
                "https://support.apple.com/en-us/148170",
                "https://support.apple.com/en-us/148171",
                "https://support.apple.com/en-us/148172",
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149042",
                "http://seclists.org/fulldisclosure/2026/Aug/36",
                "http://seclists.org/fulldisclosure/2026/Aug/37",
                "https://advisories.ncsc.nl/2026/ncsc-2026-0280.html",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65400"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:14.533",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65400"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-65391",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.",
            "updated_at": "2026-09-16T04:18:39.640",
            "published_at": "2026-09-14T21:17:22.877",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:22.877",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65391"
                }
            ]
        },
        {
            "id": "CVE-2026-65390",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.",
            "updated_at": "2026-09-16T04:18:39.080",
            "published_at": "2026-09-14T21:17:22.767",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "An integer overflow was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:22.767",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65390"
                }
            ]
        },
        {
            "id": "CVE-2026-65374",
            "vendor": "Apple",
            "product": "macOS",
            "title": "macOS vulnerability",
            "summary": "A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious WebDAV server may result in code execution.",
            "updated_at": "2026-09-16T04:18:38.750",
            "published_at": "2026-09-14T21:17:21.810",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 15.8 (custom); before 26.7 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious WebDAV server may result in code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149042",
                "https://support.apple.com/en-us/149043"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:21.810",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65374"
                }
            ]
        },
        {
            "id": "CVE-2026-65351",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:20.147",
            "published_at": "2026-08-17T22:17:25.580",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-703",
            "what_happened": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "e4zyy/Project-CVE-2026-65351",
                    "author": "e4zyy",
                    "first_seen": "2026-08-27",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "For educational purposes",
                    "summary": "For educational purposes",
                    "url": "https://github.com/e4zyy/Project-CVE-2026-65351"
                }
            ],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038",
                "https://github.com/e4zyy/Project-CVE-2026-65351"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:25.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65351"
                }
            ]
        },
        {
            "id": "CVE-2026-65349",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or read kernel memory.",
            "updated_at": "2026-09-14T21:17:19.967",
            "published_at": "2026-08-17T22:17:25.483",
            "cvss": 6.6,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 26.6.1 (custom); before 15.8 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or read kernel memory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "ByteV0rtex/CVE-2026-65349",
                    "author": "ByteV0rtex",
                    "first_seen": "2026-09-02",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 2,
                    "title": "CVE-2026-65349 PoC — getattrlist OOB write in vfs_attr_pack_internal (iOS 26.6 / 23G71)",
                    "summary": "CVE-2026-65349 PoC — getattrlist OOB write in vfs_attr_pack_internal (iOS 26.6 / 23G71)",
                    "url": "https://github.com/ByteV0rtex/CVE-2026-65349"
                }
            ],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038",
                "https://support.apple.com/en-us/149043",
                "https://github.com/ByteV0rtex/CVE-2026-65349"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:25.483",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65349"
                }
            ]
        },
        {
            "id": "CVE-2026-65347",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service.",
            "updated_at": "2026-09-14T21:17:19.703",
            "published_at": "2026-08-17T22:17:25.390",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to a denial-of-service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:25.390",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65347"
                }
            ]
        },
        {
            "id": "CVE-2026-65346",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to arbitrary code execution.",
            "updated_at": "2026-09-14T21:17:19.537",
            "published_at": "2026-08-17T22:17:25.293",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 15.8 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing an image may lead to arbitrary code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038",
                "https://support.apple.com/en-us/149043"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:25.293",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65346"
                }
            ]
        },
        {
            "id": "CVE-2026-65343",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected system termination.",
            "updated_at": "2026-09-14T21:17:19.163",
            "published_at": "2026-08-17T22:17:25.200",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 26.6.1 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 19,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. A remote attacker may be able to cause unexpected system termination.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "ByteV0rtex/CVE-2026-65343",
                    "author": "ByteV0rtex",
                    "first_seen": "2026-09-02",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 73,
                    "title": "CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)",
                    "summary": "CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)",
                    "url": "https://github.com/ByteV0rtex/CVE-2026-65343"
                },
                {
                    "repository": "AmorCool/iOS26.6-CVE-2026-65343",
                    "author": "AmorCool",
                    "first_seen": "2026-09-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)",
                    "summary": "CVE-2026-65343 PoC — AppleKeyStore OOB read → KASLR defeat (iOS 26.6 / 23G71)",
                    "url": "https://github.com/AmorCool/iOS26.6-CVE-2026-65343"
                }
            ],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038",
                "https://github.com/ByteV0rtex/CVE-2026-65343",
                "https://github.com/AmorCool/iOS26.6-CVE-2026-65343"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:25.200",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65343"
                }
            ]
        },
        {
            "id": "CVE-2026-65341",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.",
            "updated_at": "2026-09-14T21:17:18.880",
            "published_at": "2026-08-17T22:17:25.103",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:25.103",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65341"
                }
            ]
        },
        {
            "id": "CVE-2026-65340",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:18.703",
            "published_at": "2026-08-17T22:17:24.973",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:24.973",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65340"
                }
            ]
        },
        {
            "id": "CVE-2026-65339",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive user information.",
            "updated_at": "2026-09-14T21:17:18.540",
            "published_at": "2026-08-17T22:17:24.850",
            "cvss": 5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 15.8 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-693",
            "what_happened": "A logic issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive user information.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038",
                "https://support.apple.com/en-us/149043"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:24.850",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65339"
                }
            ]
        },
        {
            "id": "CVE-2026-65338",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:18.370",
            "published_at": "2026-08-17T22:17:24.747",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:24.747",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65338"
                }
            ]
        },
        {
            "id": "CVE-2026-65337",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:18.200",
            "published_at": "2026-08-17T22:17:24.650",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:24.650",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65337"
                }
            ]
        },
        {
            "id": "CVE-2026-65336",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:18.027",
            "published_at": "2026-08-17T22:17:24.547",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:24.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65336"
                }
            ]
        },
        {
            "id": "CVE-2026-65335",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:17.860",
            "published_at": "2026-08-17T22:17:24.430",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:24.430",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65335"
                }
            ]
        },
        {
            "id": "CVE-2026-65334",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:17.693",
            "published_at": "2026-08-17T22:17:24.330",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:24.330",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65334"
                }
            ]
        },
        {
            "id": "CVE-2026-65333",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:17.530",
            "published_at": "2026-08-17T22:17:24.233",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:24.233",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65333"
                }
            ]
        },
        {
            "id": "CVE-2026-65332",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:17.363",
            "published_at": "2026-08-17T22:17:24.130",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-703",
            "what_happened": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:24.130",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65332"
                }
            ]
        },
        {
            "id": "CVE-2026-65331",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:17.190",
            "published_at": "2026-08-17T22:17:24.040",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-703",
            "what_happened": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:24.040",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65331"
                }
            ]
        },
        {
            "id": "CVE-2026-65330",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.",
            "updated_at": "2026-09-14T21:17:17.003",
            "published_at": "2026-08-17T22:17:23.933",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 15.8 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Sequoia 15.8, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. An app may be able to cause unexpected system termination or corrupt kernel memory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038",
                "https://support.apple.com/en-us/149043"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:23.933",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65330"
                }
            ]
        },
        {
            "id": "CVE-2026-65329",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, iOS 27 and iPadOS 27. An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic.",
            "updated_at": "2026-09-14T21:17:16.833",
            "published_at": "2026-08-17T22:17:23.830",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-287",
            "what_happened": "An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, iOS 27 and iPadOS 27. An attacker in a privileged network position may be able to bypass IPSec authentication and intercept network traffic.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/149034"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:23.830",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65329"
                }
            ]
        },
        {
            "id": "CVE-2026-65017",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with no prior access to the secret — could read a team-scoped Celery broker URL, including its embedded credentials, in cleartext, while the equivalent global option was correctly masked. The secrets masker matched only base section and option names and did not normalize team-prefixed sections before the sensitivity check (CWE-200). This is a distinct masker bypass from CVE-2026-48828 and CVE-2026-48892: deployments that upgraded to apache-airflow 3.3.0 to address those issues remain affected by this team-scoped variant. Users are advised to upgrade to apache-airflow 3.3.1 or later, which normalizes team-scoped sections before masking.",
            "updated_at": "2026-09-16T15:17:40.443",
            "published_at": "2026-08-12T16:17:12.577",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.3.0 through before 3.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled multi-team mode and exposed the Config API, an authenticated Viewer holding only configuration-read access — with no prior access to the secret — could read a team-scoped Celery broker URL, including its embedded credentials, in cleartext, while the equivalent global option was correctly masked. The secrets masker matched only base section and option names and did not normalize team-prefixed sections before the sensitivity check (CWE-200). This is a distinct masker bypass from CVE-2026-48828 and CVE-2026-48892: deployments that upgraded to apache-airflow 3.3.0 to address those issues remain affected by this team-scoped variant. Users are advised to upgrade to apache-airflow 3.3.1 or later, which normalizes team-scoped sections before masking.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/70755",
                "https://lists.apache.org/thread/kykn94kjf0tntx4wywtvjowh5bzdgf38",
                "https://www.cve.org/CVERecord?id=CVE-2026-48828",
                "https://www.cve.org/CVERecord?id=CVE-2026-48892"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:12.577",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-65017"
                }
            ]
        },
        {
            "id": "CVE-2026-65008",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Grav CMS 2.0.7 - RCE",
            "summary": "Grav CMS 2.0.7 - RCE",
            "updated_at": "2026-08-31T22:00:00Z",
            "published_at": "2026-08-31T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 147,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52669",
                    "author": "zer0dayf",
                    "first_seen": "2026-09-01",
                    "confidence": "High",
                    "title": "Grav CMS 2.0.7 - RCE",
                    "summary": "Grav CMS 2.0.7 - RCE",
                    "url": "https://www.exploit-db.com/exploits/52669",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "zer0dayf/CVE-2026-65008",
                    "author": "zer0dayf",
                    "first_seen": "2026-07-27",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": " CVE-2026-65008",
                    "summary": " CVE-2026-65008",
                    "url": "https://github.com/zer0dayf/CVE-2026-65008"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52669",
                "https://github.com/zer0dayf/CVE-2026-65008"
            ],
            "timeline": [
                {
                    "at": "2026-08-31T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52669"
                }
            ]
        },
        {
            "id": "CVE-2026-64927",
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Management for Kubernetes 2.11",
            "title": "Red Hat Advanced Cluster Management for Kubernetes 2.11 vulnerability",
            "summary": "A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in unauthorized areas. This could lead to unauthorized access to information or elevated privileges within the system.",
            "updated_at": "2026-09-05T18:17:27.930",
            "published_at": "2026-08-12T02:16:37.780",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in unauthorized areas. This could lead to unauthorized access to information or elevated privileges within the system.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/errata/RHSA-2026:60387",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/errata/RHSA-2026:60389",
                "https://access.redhat.com/errata/RHSA-2026:60390",
                "https://access.redhat.com/errata/RHSA-2026:60391",
                "https://access.redhat.com/security/cve/CVE-2026-64927",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2514229"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T02:16:37.780",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64927"
                }
            ]
        },
        {
            "id": "CVE-2026-64849",
            "vendor": "MLflow",
            "product": "MLflow",
            "title": "MLflow Server-Side Request Forgery Vulnerability",
            "summary": "MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.",
            "updated_at": "2026-08-18T22:00:00Z",
            "published_at": "2026-08-18T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 48,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-18T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-64827",
            "vendor": "Telenia Software",
            "product": "TVox",
            "title": "TVox vulnerability",
            "summary": "Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.",
            "updated_at": "2026-09-09T20:40:01.933",
            "published_at": "2026-08-03T14:16:27.630",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "26.0.0 through 26.5.3 (semver); 24.0.0 through 24.9.21 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-807",
            "what_happened": "Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.php where the redirectToLoginAdminIRequestHaveAccessToken() function derives the current page name from PHP_SELF and skips authentication when the value matches 'login_admin.php'. Attackers can append '/login_admin.php' to the path of any target PHP script to cause the authentication check to pass and gain unauthenticated access to all PHP scripts under the manager HTML directory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://karmainsecurity.com/KIS-2026-14",
                "https://www.teleniasoftware.com/",
                "https://www.vulncheck.com/advisories/telenia-tvox-authentication-bypass-via-set-env-php",
                "http://seclists.org/fulldisclosure/2026/Aug/30"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T14:16:27.630",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64827"
                }
            ]
        },
        {
            "id": "CVE-2026-64816",
            "vendor": "CyberTimon",
            "product": "RapidRAW",
            "title": "RapidRAW vulnerability",
            "summary": "RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking the victim's NTLMv2 credentials. The vulnerable code path is reachable through two vectors: community presets fetched automatically from the remote preset repository when the victim opens the Community tab, and individual preset files imported directly by the victim via the preset import feature (handle_import_presets_from_file in file_management.rs). The second vector does not require control of the community preset repository and is triggered when a user imports a preset file shared through Discord, forums, or similar channels.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-07-30T22:16:55.920",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.6.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-73",
            "what_happened": "RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking the victim's NTLMv2 credentials. The vulnerable code path is reachable through two vectors: community presets fetched automatically from the remote preset repository when the victim opens the Community tab, and individual preset files imported directly by the victim via the preset import feature (handle_import_presets_from_file in file_management.rs). The second vector does not require control of the community preset repository and is triggered when a user imports a preset file shared through Discord, forums, or similar channels.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/CyberTimon/RapidRAW/commit/83852f36ba4a260be",
                "https://github.com/CyberTimon/RapidRAW/releases/tag/v1.6.0",
                "https://www.vulncheck.com/advisories/rapidraw-ntlmv2-credential-leak-via-unc-path-in-lutpath"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T22:16:55.920",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64816"
                }
            ]
        },
        {
            "id": "CVE-2026-64788",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.",
            "updated_at": "2026-09-14T21:17:16.557",
            "published_at": "2026-08-17T22:17:23.480",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:23.480",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64788"
                }
            ]
        },
        {
            "id": "CVE-2026-64787",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process termination.",
            "updated_at": "2026-09-14T21:17:16.393",
            "published_at": "2026-08-17T22:17:23.377",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process termination.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:23.377",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64787"
                }
            ]
        },
        {
            "id": "CVE-2026-64784",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:16.223",
            "published_at": "2026-08-17T22:17:23.273",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:23.273",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64784"
                }
            ]
        },
        {
            "id": "CVE-2026-64782",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:16.050",
            "published_at": "2026-08-17T22:17:23.180",
            "cvss": 3.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:23.180",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64782"
                }
            ]
        },
        {
            "id": "CVE-2026-64781",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "The issue was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:15.877",
            "published_at": "2026-08-17T22:17:23.073",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "The issue was addressed with improved input validation. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:23.073",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64781"
                }
            ]
        },
        {
            "id": "CVE-2026-64780",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:15.707",
            "published_at": "2026-08-17T22:17:22.977",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:22.977",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64780"
                }
            ]
        },
        {
            "id": "CVE-2026-64779",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:15.533",
            "published_at": "2026-08-17T22:17:22.873",
            "cvss": 3.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:22.873",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64779"
                }
            ]
        },
        {
            "id": "CVE-2026-64778",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Visiting a maliciously crafted website may leak sensitive data.",
            "updated_at": "2026-09-14T21:17:15.367",
            "published_at": "2026-08-17T22:17:22.777",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Visiting a maliciously crafted website may leak sensitive data.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:22.777",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64778"
                }
            ]
        },
        {
            "id": "CVE-2026-64760",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive kernel state.",
            "updated_at": "2026-09-14T21:17:15.097",
            "published_at": "2026-08-17T22:17:20.937",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 18.7.10 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may be able to leak sensitive kernel state.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149034",
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:20.937",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64760"
                }
            ]
        },
        {
            "id": "CVE-2026-64752",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Processing a maliciously crafted image may lead to arbitrary code execution.",
            "updated_at": "2026-09-16T04:18:38.373",
            "published_at": "2026-09-14T21:17:14.770",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. Processing a maliciously crafted image may lead to arbitrary code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/149034",
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:14.770",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64752"
                }
            ]
        },
        {
            "id": "CVE-2026-64718",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, Safari 27, iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, visionOS 27, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:14.467",
            "published_at": "2026-07-27T21:17:10.753",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6 (custom); before 27 (custom); before 26.7 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, Safari 27, iOS 26.6 and iPadOS 26.6, iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, visionOS 27, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/128066",
                "https://support.apple.com/en-us/128067",
                "https://support.apple.com/en-us/128068",
                "https://support.apple.com/en-us/128069",
                "https://support.apple.com/en-us/128070",
                "https://support.apple.com/en-us/128073",
                "https://support.apple.com/en-us/149034",
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149038",
                "https://support.apple.com/en-us/149039",
                "https://support.apple.com/en-us/149041"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T21:17:10.753",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64718"
                }
            ]
        },
        {
            "id": "CVE-2026-64715",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process crash.",
            "updated_at": "2026-09-14T21:17:14.173",
            "published_at": "2026-08-17T22:17:17.343",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to an unexpected process crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:17.343",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64715"
                }
            ]
        },
        {
            "id": "CVE-2026-64705",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.",
            "updated_at": "2026-09-14T21:17:13.680",
            "published_at": "2026-08-25T20:17:00.333",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6 (custom); before 14.8.7 (custom); before 15.7.7 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/127116",
                "https://support.apple.com/en-us/127117",
                "https://support.apple.com/en-us/128066",
                "https://support.apple.com/en-us/128067"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T20:17:00.333",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64705"
                }
            ]
        },
        {
            "id": "CVE-2026-64677",
            "vendor": "ankitects",
            "product": "anki",
            "title": "anki vulnerability",
            "summary": "Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or malicious websites combined with an origin-check bypass, to read local files through directory traversal. This issue is fixed in version 25.09.3.",
            "updated_at": "2026-09-16T13:42:43.213",
            "published_at": "2026-08-06T22:18:14.250",
            "cvss": 5.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 25.09.3",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requested media and built-in data paths, allowing scripts served from shared decks, or malicious websites combined with an origin-check bypass, to read local files through directory traversal. This issue is fixed in version 25.09.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ankitects/anki/commit/f4692e54a4fafc89528afab1983f0b98d593023f",
                "https://github.com/ankitects/anki/security/advisories/GHSA-78wr-2gg2-4hqg"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:14.250",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64677"
                }
            ]
        },
        {
            "id": "CVE-2026-64655",
            "vendor": "cli",
            "product": "cli",
            "title": "cli vulnerability",
            "summary": "GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify  builds the certificate Subject Alternative Name matcher from the --signer-repo and --signer-workflow  flag values without escaping regex metacharacters, so a user-supplied repository or workflow name is treated as a regular expression rather than a literal string. Because GitHub permits characters such as  `.`  in organization, repository, and workflow path names and  `.`  is a regex wildcard, an attacker can register a lookalike name (for example github/artifact.attestations-workflows) that satisfies a matcher intended for a different trusted signer (github/artifact-attestations-workflows), bypassing the intended Sigstore attestation verification. Exploitation requires the attacker to create a plausible lookalike repository and produce valid attestations from it, which could undermine supply chain verification for CI/CD pipelines or policy gates that pin trust to a specific signing workflow. This issue is fixed in version 2.97.0.",
            "updated_at": "2026-09-10T20:36:14.340",
            "published_at": "2026-08-06T22:18:13.527",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.97.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-185",
            "what_happened": "GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify  builds the certificate Subject Alternative Name matcher from the --signer-repo and --signer-workflow  flag values without escaping regex metacharacters, so a user-supplied repository or workflow name is treated as a regular expression rather than a literal string. Because GitHub permits characters such as  `.`  in organization, repository, and workflow path names and  `.`  is a regex wildcard, an attacker can register a lookalike name (for example github/artifact.attestations-workflows) that satisfies a matcher intended for a different trusted signer (github/artifact-attestations-workflows), bypassing the intended Sigstore attestation verification. Exploitation requires the attacker to create a plausible lookalike repository and produce valid attestations from it, which could undermine supply chain verification for CI/CD pipelines or policy gates that pin trust to a specific signing workflow. This issue is fixed in version 2.97.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cli/cli/commit/55dbb4dc6b7edb10b48e3d7fc5bccd32318d1b55",
                "https://github.com/cli/cli/releases/tag/v2.97.0",
                "https://github.com/cli/cli/security/advisories/GHSA-mm27-mwq9-fr5g"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:13.527",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64655"
                }
            ]
        },
        {
            "id": "CVE-2026-64654",
            "vendor": "cli",
            "product": "cli",
            "title": "cli vulnerability",
            "summary": "GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content without neutralizing terminal escape sequences. An attacker who can influence that content can embed escape sequences that are interpreted by the terminal of a user who runs an affected command, with impact ranging from cosmetic manipulation of the title or on-screen content to, on some terminal emulators, command execution. This extends the same class of issue as CVE-2026-45803—which addressed only gh run view --log—to the other affected command paths. This issue is fixed in version 2.97.0.",
            "updated_at": "2026-09-10T20:36:14.340",
            "published_at": "2026-08-06T22:18:13.380",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.97.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-150",
            "what_happened": "GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API, pull request, release, codespace, skill, or agent-task content without neutralizing terminal escape sequences. An attacker who can influence that content can embed escape sequences that are interpreted by the terminal of a user who runs an affected command, with impact ranging from cosmetic manipulation of the title or on-screen content to, on some terminal emulators, command execution. This extends the same class of issue as CVE-2026-45803—which addressed only gh run view --log—to the other affected command paths. This issue is fixed in version 2.97.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cli/cli/commit/2a1409fe88d416cc85fc96fb5bc473f83ed5a054",
                "https://github.com/cli/cli/releases/tag/v2.97.0",
                "https://github.com/cli/cli/security/advisories/GHSA-3m3g-3wcr-px46"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:13.380",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64654"
                }
            ]
        },
        {
            "id": "CVE-2026-64653",
            "vendor": "cli",
            "product": "cli",
            "title": "cli vulnerability",
            "summary": "GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent encoding, allowing URL path metacharacters in attacker-controlled repository or resource values to make gh address a different API endpoint or resource than the user intended. This issue is fixed in version 2.97.0.",
            "updated_at": "2026-09-10T20:36:14.340",
            "published_at": "2026-08-06T22:18:13.237",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.97.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent encoding, allowing URL path metacharacters in attacker-controlled repository or resource values to make gh address a different API endpoint or resource than the user intended. This issue is fixed in version 2.97.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cli/cli/commit/0c2eea6338a2323cfff000160b9b5a56a38d2a06",
                "https://github.com/cli/cli/releases/tag/v2.97.0",
                "https://github.com/cli/cli/security/advisories/GHSA-4fjg-2h4q-fwg3"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:13.237",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64653"
                }
            ]
        },
        {
            "id": "CVE-2026-64652",
            "vendor": "cli",
            "product": "cli",
            "title": "cli vulnerability",
            "summary": "GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As a result, part of an affected token could appear in terminal or CI output that is captured or shared. Authenticated users are affected if they ran gh auth status (without the --show-token flag) with a token type whose format contains an underscore after the prefix. This includes fine-grained personal access tokens (github_pat_*) and GitHub App installation and user access tokens (ghs_*, ghu_*; for example, ghs_<APPID>_<JWT>), as well as the Actions GITHUB_TOKEN. Classic tokens such as gho_* and ghp_* have an underscore-free body and are not affected. This issue is fixed in version 2.97.0.",
            "updated_at": "2026-09-10T20:36:14.340",
            "published_at": "2026-08-06T22:18:13.087",
            "cvss": 3.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.97.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-201",
            "what_happened": "GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characters after the last underscore in certain fine-grained personal access tokens and GitHub App tokens. As a result, part of an affected token could appear in terminal or CI output that is captured or shared. Authenticated users are affected if they ran gh auth status (without the --show-token flag) with a token type whose format contains an underscore after the prefix. This includes fine-grained personal access tokens (github_pat_*) and GitHub App installation and user access tokens (ghs_*, ghu_*; for example, ghs_<APPID>_<JWT>), as well as the Actions GITHUB_TOKEN. Classic tokens such as gho_* and ghp_* have an underscore-free body and are not affected. This issue is fixed in version 2.97.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cli/cli/commit/3f6a16a9f8c7fe9676aa8d8f47b399310dd231c3",
                "https://github.com/cli/cli/releases/tag/v2.97.0",
                "https://github.com/cli/cli/security/advisories/GHSA-cg6r-mpgc-h9mm"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:13.087",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64652"
                }
            ]
        },
        {
            "id": "CVE-2026-64638",
            "vendor": "WordPress",
            "product": "WordPress",
            "title": "Exploit for XSS2Shell-CVE-2026-64638",
            "summary": "Pre-auth XSS in WordPress wp-login.php enables RCE via DOM clobbering and app password theft.",
            "updated_at": "2026-09-03T17:02:54.670",
            "published_at": "2026-08-07T18:17:20.340",
            "cvss": 8.9,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 94,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-79",
            "what_happened": "Pre-auth XSS in WordPress wp-login.php enables RCE via DOM clobbering and app password theft.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for XSS2Shell-CVE-2026-64638",
                    "summary": "Pre-auth XSS in WordPress wp-login.php enables RCE via DOM clobbering and app password theft.",
                    "what_happened": "Pre-auth XSS in WordPress wp-login.php enables RCE via DOM clobbering and app password theft.",
                    "cvss": 8.9,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JENDMAOUL-XSS2SHELL-CVE-2026-64638",
                        "https://kitploit.com/ja/tools/github/jendmaoul/xss2shell-cve-2026-64638/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-30T12:37:04",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JENDMAOUL-XSS2SHELL-CVE-2026-64638"
                },
                {
                    "title": "Exploit for XSS2Shell-CVE-2026-64638",
                    "summary": "Pre-auth XSS in WordPress wp-login.php enables RCE via DOM clobbering and app password theft.",
                    "what_happened": "Pre-auth XSS in WordPress wp-login.php enables RCE via DOM clobbering and app password theft.",
                    "cvss": 8.9,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JENDMAOUL-XSS2SHELL-CVE-2026-64638",
                        "https://kitploit.com/ja/tools/github/jendmaoul/xss2shell-cve-2026-64638/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-08-30T12:37:04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/jendmaoul/xss2shell-cve-2026-64638/"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-14T18:33:14+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "XSS2Shell exploit",
                    "summary": "Exploit for CVE-2026-64638. CVSS 8.9.",
                    "cvss": 8.9,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WORDSEC-XSS2SHELL"
                },
                {
                    "title": "Exploit for XSS2Shell CVE-2026-64638",
                    "summary": "Pre-auth XSS to RCE in WordPress (CVE-2026-64638) via Application Password and plugin upload.",
                    "what_happened": "Pre-auth XSS to RCE in WordPress (CVE-2026-64638) via Application Password and plugin upload.",
                    "cvss": 8.9,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WORDSEC-XSS2SHELL",
                        "https://kitploit.com/ja/tools/github/wordsec/xss2shell/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-12T10:18:11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/wordsec/xss2shell/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JENDMAOUL-XSS2SHELL-CVE-2026-64638",
                "https://kitploit.com/ja/tools/github/jendmaoul/xss2shell-cve-2026-64638/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WORDSEC-XSS2SHELL",
                "https://kitploit.com/ja/tools/github/wordsec/xss2shell/",
                "https://hackerone.com/reports/3877102",
                "https://wordpress.org/news/2026/08/wordpress-7-0-3-release/"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T10:37:04Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JENDMAOUL-XSS2SHELL-CVE-2026-64638"
                },
                {
                    "at": "2026-08-07T18:17:20.340",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64638"
                }
            ],
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/SC:H/VI:H/SI:H/VA:H/SA:H",
            "enrichment_checked_at": "2026-09-15T04:05:43Z"
        },
        {
            "id": "CVE-2026-64380",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: harden POSIX SID length parsing\n\nposix_info_sid_size() reads sid[1] to obtain the subauthority count,\nbut its existing boundary check still accepts buffers with only one\nremaining byte. Require two bytes before reading sid[1] so all client\npaths that reuse the helper reject truncated POSIX SIDs safely.",
            "updated_at": "2026-09-08T14:06:05.950",
            "published_at": "2026-07-25T10:17:21.220",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "349e13ad30b45998bb9937cfe0b32be6f951976d through before 171605aed68380c2fa75dff9b3a1ed427c50065b (git); 349e13ad30b45998bb9937cfe0b32be6f951976d through before 4213c1208978483021d7d125c131de3985d38f61 (git); 349e13ad30b45998bb9937cfe0b32be6f951976d through before 96e889bc1e759c83f25093e8c2f3da31b4973f30 (git); 349e13ad30b45998bb9937cfe0b32be6f951976d through before 0de5b8e76847f5de26f364a82c6602c4881c30da (git); 349e13ad30b45998bb9937cfe0b32be6f951976d through before 427eb7eb46425fec845a43e861f3d6e2899cae59 (git); 349e13ad30b45998bb9937cfe0b32be6f951976d through before 86c5d470f5d42e61123b2f4b4f0b91f4eee5b980 (git); 349e13ad30b45998bb9937cfe0b32be6f951976d through before 46a84715a015cb48e1b9c219dc88c03d8a541ea4 (git); 349e13ad30b45998bb9937cfe0b32be6f951976d through before 7ad2bcf2441430bb2e918fb3ef9a90d775a6e422 (git); 5.7",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: harden POSIX SID length parsing\n\nposix_info_sid_size() reads sid[1] to obtain the subauthority count,\nbut its existing boundary check still accepts buffers with only one\nremaining byte. Require two bytes before reading sid[1] so all client\npaths that reuse the helper reject truncated POSIX SIDs safely.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0de5b8e76847f5de26f364a82c6602c4881c30da",
                "https://git.kernel.org/stable/c/171605aed68380c2fa75dff9b3a1ed427c50065b",
                "https://git.kernel.org/stable/c/4213c1208978483021d7d125c131de3985d38f61",
                "https://git.kernel.org/stable/c/427eb7eb46425fec845a43e861f3d6e2899cae59",
                "https://git.kernel.org/stable/c/46a84715a015cb48e1b9c219dc88c03d8a541ea4",
                "https://git.kernel.org/stable/c/7ad2bcf2441430bb2e918fb3ef9a90d775a6e422",
                "https://git.kernel.org/stable/c/86c5d470f5d42e61123b2f4b4f0b91f4eee5b980",
                "https://git.kernel.org/stable/c/96e889bc1e759c83f25093e8c2f3da31b4973f30"
            ],
            "timeline": [
                {
                    "at": "2026-07-25T10:17:21.220",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64380"
                }
            ]
        },
        {
            "id": "CVE-2026-64379",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: mask server-provided mode to 07777 in modefromsid\n\nWhen modefromsid is active, parse_dacl() applies the server-provided\nsub_auth[2] value from the NFS mode SID to cf_mode without masking to\n07777. Apply the correct masking, same as in the read path.",
            "updated_at": "2026-09-08T14:08:51.350",
            "published_at": "2026-07-25T10:17:21.090",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "e2f8fbfb8d09c06decde162090fac3ee220aa280 through before 5f6f2241034f189c69d4d0b5f8fe24a0c25b0c14 (git); e2f8fbfb8d09c06decde162090fac3ee220aa280 through before ee2216dbdf0c677e89bb43e03247dba590ed00ef (git); e2f8fbfb8d09c06decde162090fac3ee220aa280 through before f511807feee7cb29b61bdfa86472c7e9e2e5df94 (git); e2f8fbfb8d09c06decde162090fac3ee220aa280 through before 08c600b7e1818539ba5efee4cdb06215c245ca78 (git); e2f8fbfb8d09c06decde162090fac3ee220aa280 through before b84e002e0df26bbc6cbd3ca01b8212601fe0ae7d (git); e2f8fbfb8d09c06decde162090fac3ee220aa280 through before c6c484a7d5bff6b929a86d7ed5130f29834c6a0d (git); e2f8fbfb8d09c06decde162090fac3ee220aa280 through before f80add1bfb3425100a325b14f19648e75669a954 (git); e2f8fbfb8d09c06decde162090fac3ee220aa280 through before e3d9c7160d483fc8f9e225aafad8ecbbc43f3151 (git); 5.4",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: mask server-provided mode to 07777 in modefromsid\n\nWhen modefromsid is active, parse_dacl() applies the server-provided\nsub_auth[2] value from the NFS mode SID to cf_mode without masking to\n07777. Apply the correct masking, same as in the read path.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/08c600b7e1818539ba5efee4cdb06215c245ca78",
                "https://git.kernel.org/stable/c/5f6f2241034f189c69d4d0b5f8fe24a0c25b0c14",
                "https://git.kernel.org/stable/c/b84e002e0df26bbc6cbd3ca01b8212601fe0ae7d",
                "https://git.kernel.org/stable/c/c6c484a7d5bff6b929a86d7ed5130f29834c6a0d",
                "https://git.kernel.org/stable/c/e3d9c7160d483fc8f9e225aafad8ecbbc43f3151",
                "https://git.kernel.org/stable/c/ee2216dbdf0c677e89bb43e03247dba590ed00ef",
                "https://git.kernel.org/stable/c/f511807feee7cb29b61bdfa86472c7e9e2e5df94",
                "https://git.kernel.org/stable/c/f80add1bfb3425100a325b14f19648e75669a954"
            ],
            "timeline": [
                {
                    "at": "2026-07-25T10:17:21.090",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64379"
                }
            ]
        },
        {
            "id": "CVE-2026-64378",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwriteback: fix race between cgroup_writeback_umount() and inode_switch_wbs()\n\nWhen a container exits, the following BUG_ON() is occasionally triggered:\n\n==================================================================\n VFS: Busy inodes after unmount of sdb (ext4)\n ------------[ cut here ]------------\n kernel BUG at fs/super.c:695!\n CPU: 3 PID: 6 Comm: containerd-shim Tainted: G OE K 6.6 #1\n pstate: 63400009 (nZCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n pc : generic_shutdown_super+0xf0/0x100\n lr : generic_shutdown_super+0xf0/0x100\n Call trace:\n  generic_shutdown_super+0xf0/0x100\n  kill_block_super+0x20/0x48\n  ext4_kill_sb+0x28/0x60\n  deactivate_locked_super+0x54/0x130\n  deactivate_super+0x84/0xa0\n  cleanup_mnt+0xa4/0x140\n  __cleanup_mnt+0x18/0x28\n  task_work_run+0x78/0xe0\n  do_notify_resume+0x204/0x240\n==================================================================\n\nThe root cause is a race between cgroup_writeback_umount() and\ninode_switch_wbs()/cleanup_offline_cgwb(). There is a window between\ninode_prepare_wbs_switch() returning true and the subsequent\nwb_queue_isw() call. Following is the process that triggers the issue:\n\n      CPU A (umount)           |          CPU B (writeback)\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n                                 inode_switch_wbs/cleanup_offline_cgwb\n                                  atomic_inc(&isw_nr_in_flight)\n                                  inode_prepare_wbs_switch\n                                   -> passes SB_ACTIVE check\n                                   __iget(inode)\n generic_shutdown_super\n  sb->s_flags &= ~SB_ACTIVE\n  cgroup_writeback_umount(sb)\n   smp_mb()\n   atomic_read(&isw_nr_in_flight)\n   rcu_barrier()\n    -> no pending RCU callbacks\n   flush_workqueue(isw_wq)\n    -> nothing queued, returns\n  evict_inodes(sb)\n   -> Inode skipped as isw still holds a ref.\n  sop->put_super(sb)\n   /* destroys percpu counters */\n  -> VFS: Busy inodes after unmount!\n                                  wb_queue_isw()\n                                   queue_work(isw_wq, ...)\n                                  /* later in work function */\n                                  inode_switch_wbs_work_fn\n                                   process_inode_switch_wbs\n                                    iput() -> evict\n                                     percpu_counter_dec() // UAF!\n\nFix this by extending the RCU read-side critical section in\ninode_switch_wbs() and cleanup_offline_cgwb() to cover from\ninode_prepare_wbs_switch() through wb_queue_isw().  Since there is\nno sleep in this window, rcu_read_lock() can be used.  Then add a\nsynchronize_rcu() in cgroup_writeback_umount() before the existing\nrcu_barrier(), so that all in-flight switchers that have passed the\nSB_ACTIVE check have completed queue_work() before flush_workqueue()\nis called.\n\nThe existing rcu_barrier() is intentionally retained so this fix can\nbe backported unchanged to stable kernels (5.10.y, 6.6.y, ...) that\nstill queue switches via queue_rcu_work(). It is a no-op on current\nmainline (since commit e1b849cfa6b6 (\"writeback: Avoid contention on\nwb->list_lock when switching inodes\")) and is removed in a follow-up\npatch.",
            "updated_at": "2026-09-08T15:23:22.650",
            "published_at": "2026-07-25T10:17:20.940",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "a1a0e23e49037c23ea84bc8cc146a03584d13577 through before 087d5b8b501c570f84bf655164e6698c3ce146e0 (git); a1a0e23e49037c23ea84bc8cc146a03584d13577 through before 3c9c9648f77e4d14e50676bc51c2174ba9c8d361 (git); a1a0e23e49037c23ea84bc8cc146a03584d13577 through before 5c3265f3252b2ee50707adaaa3f9bd0df3df72de (git); a1a0e23e49037c23ea84bc8cc146a03584d13577 through before c923cc3cb5cd8945ceaf08252754110643446593 (git); a1a0e23e49037c23ea84bc8cc146a03584d13577 through before 685fc15a410885b6d4dee64de0dce721b9428b12 (git); a1a0e23e49037c23ea84bc8cc146a03584d13577 through before 53eeaf4d63068dbc7708b0c7adb20151c812feca (git); a1a0e23e49037c23ea84bc8cc146a03584d13577 through before cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d (git); c5cbbec54fe71c4de2d34f8c0ec8fbfdd7f17339 (git); 4.4.5 through before 4.5 (semver); 4.5",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-362",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwriteback: fix race between cgroup_writeback_umount() and inode_switch_wbs()\n\nWhen a container exits, the following BUG_ON() is occasionally triggered:\n\n==================================================================\n VFS: Busy inodes after unmount of sdb (ext4)\n ------------[ cut here ]------------\n kernel BUG at fs/super.c:695!\n CPU: 3 PID: 6 Comm: containerd-shim Tainted: G OE K 6.6 #1\n pstate: 63400009 (nZCv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\n pc : generic_shutdown_super+0xf0/0x100\n lr : generic_shutdown_super+0xf0/0x100\n Call trace:\n  generic_shutdown_super+0xf0/0x100\n  kill_block_super+0x20/0x48\n  ext4_kill_sb+0x28/0x60\n  deactivate_locked_super+0x54/0x130\n  deactivate_super+0x84/0xa0\n  cleanup_mnt+0xa4/0x140\n  __cleanup_mnt+0x18/0x28\n  task_work_run+0x78/0xe0\n  do_notify_resume+0x204/0x240\n==================================================================\n\nThe root cause is a race between cgroup_writeback_umount() and\ninode_switch_wbs()/cleanup_offline_cgwb(). There is a window between\ninode_prepare_wbs_switch() returning true and the subsequent\nwb_queue_isw() call. Following is the process that triggers the issue:\n\n      CPU A (umount)           |          CPU B (writeback)\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\n                                 inode_switch_wbs/cleanup_offline_cgwb\n                                  atomic_inc(&isw_nr_in_flight)\n                                  inode_prepare_wbs_switch\n                                   -> passes SB_ACTIVE check\n                                   __iget(inode)\n generic_shutdown_super\n  sb->s_flags &= ~SB_ACTIVE\n  cgroup_writeback_umount(sb)\n   smp_mb()\n   atomic_read(&isw_nr_in_flight)\n   rcu_barrier()\n    -> no pending RCU callbacks\n   flush_workqueue(isw_wq)\n    -> nothing queued, returns\n  evict_inodes(sb)\n   -> Inode skipped as isw still holds a ref.\n  sop->put_super(sb)\n   /* destroys percpu counters */\n  -> VFS: Busy inodes after unmount!\n                                  wb_queue_isw()\n                                   queue_work(isw_wq, ...)\n                                  /* later in work function */\n                                  inode_switch_wbs_work_fn\n                                   process_inode_switch_wbs\n                                    iput() -> evict\n                                     percpu_counter_dec() // UAF!\n\nFix this by extending the RCU read-side critical section in\ninode_switch_wbs() and cleanup_offline_cgwb() to cover from\ninode_prepare_wbs_switch() through wb_queue_isw().  Since there is\nno sleep in this window, rcu_read_lock() can be used.  Then add a\nsynchronize_rcu() in cgroup_writeback_umount() before the existing\nrcu_barrier(), so that all in-flight switchers that have passed the\nSB_ACTIVE check have completed queue_work() before flush_workqueue()\nis called.\n\nThe existing rcu_barrier() is intentionally retained so this fix can\nbe backported unchanged to stable kernels (5.10.y, 6.6.y, ...) that\nstill queue switches via queue_rcu_work(). It is a no-op on current\nmainline (since commit e1b849cfa6b6 (\"writeback: Avoid contention on\nwb->list_lock when switching inodes\")) and is removed in a follow-up\npatch.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/087d5b8b501c570f84bf655164e6698c3ce146e0",
                "https://git.kernel.org/stable/c/3c9c9648f77e4d14e50676bc51c2174ba9c8d361",
                "https://git.kernel.org/stable/c/53eeaf4d63068dbc7708b0c7adb20151c812feca",
                "https://git.kernel.org/stable/c/5c3265f3252b2ee50707adaaa3f9bd0df3df72de",
                "https://git.kernel.org/stable/c/685fc15a410885b6d4dee64de0dce721b9428b12",
                "https://git.kernel.org/stable/c/c923cc3cb5cd8945ceaf08252754110643446593",
                "https://git.kernel.org/stable/c/cba38ec4cbd3a7b8b942a8d52531a05be8a9ff0d"
            ],
            "timeline": [
                {
                    "at": "2026-07-25T10:17:20.940",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64378"
                }
            ]
        },
        {
            "id": "CVE-2026-64377",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: qcom-cpufreq-hw: Fix possible double free\n\nqcom_cpufreq.data is allocated with devm_kzalloc() in probe() as an\narray of per-domain data. qcom_cpufreq_hw_cpu_init() stores a pointer to\none element of this array in policy->driver_data.\n\nqcom_cpufreq_hw_cpu_exit() currently calls kfree() on policy->driver_data.\nThis is not valid because the memory is devm-managed. For the first\ndomain, this can free the devm-managed allocation while the devres entry\nis still active, leading to a possible double free when the platform\ndevice is later detached. For other domains, the pointer may refer to an\nelement inside the array rather than the allocation base.\n\nRemove the kfree(data) call and let devres release qcom_cpufreq.data.\n\nThis issue was found by a static analysis tool I am developing.",
            "updated_at": "2026-09-08T14:20:18.577",
            "published_at": "2026-07-25T10:17:20.837",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "054a3ef683a176a509cc9b37f762029aae942495 through before 28a03a3f6e6cda0b0da3b43761d175dec5d14d13 (git); 054a3ef683a176a509cc9b37f762029aae942495 through before e904961332801c87355f5d11c65bb433e717c489 (git); 054a3ef683a176a509cc9b37f762029aae942495 through before 9de568ef6cdfc7912d5ea8db02843c0e4ef0c75d (git); 054a3ef683a176a509cc9b37f762029aae942495 through before bcb8889c4981fdde42d4fd2c29a77d510fe21da2 (git); 6.2",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-415",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: qcom-cpufreq-hw: Fix possible double free\n\nqcom_cpufreq.data is allocated with devm_kzalloc() in probe() as an\narray of per-domain data. qcom_cpufreq_hw_cpu_init() stores a pointer to\none element of this array in policy->driver_data.\n\nqcom_cpufreq_hw_cpu_exit() currently calls kfree() on policy->driver_data.\nThis is not valid because the memory is devm-managed. For the first\ndomain, this can free the devm-managed allocation while the devres entry\nis still active, leading to a possible double free when the platform\ndevice is later detached. For other domains, the pointer may refer to an\nelement inside the array rather than the allocation base.\n\nRemove the kfree(data) call and let devres release qcom_cpufreq.data.\n\nThis issue was found by a static analysis tool I am developing.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/28a03a3f6e6cda0b0da3b43761d175dec5d14d13",
                "https://git.kernel.org/stable/c/9de568ef6cdfc7912d5ea8db02843c0e4ef0c75d",
                "https://git.kernel.org/stable/c/bcb8889c4981fdde42d4fd2c29a77d510fe21da2",
                "https://git.kernel.org/stable/c/e904961332801c87355f5d11c65bb433e717c489"
            ],
            "timeline": [
                {
                    "at": "2026-07-25T10:17:20.837",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64377"
                }
            ]
        },
        {
            "id": "CVE-2026-64376",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware_loader: fix device reference leak in firmware_upload_register()\n\nfirmware_upload_register()\n  -> fw_create_instance()\n     -> device_initialize()\n\nAfter fw_create_instance() succeeds, the lifetime of the embedded struct\ndevice is expected to be managed through the device core reference\ncounting, since fw_create_instance() has already called\ndevice_initialize().\n\nIn firmware_upload_register(), if alloc_lookup_fw_priv() fails after\nfw_create_instance() succeeds, the code reaches free_fw_sysfs and frees\nfw_sysfs directly instead of releasing the device reference with\nput_device(). This may leave the reference count of the embedded struct\ndevice unbalanced, resulting in a refcount leak.\n\nThe issue was identified by a static analysis tool I developed and\nconfirmed by manual review. Fix this by using put_device(fw_dev) in the\nfailure path and letting fw_dev_release() handle the final cleanup,\ninstead of freeing the instance directly from the error path.",
            "updated_at": "2026-09-08T14:21:55.037",
            "published_at": "2026-07-25T10:17:20.717",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "97730bbb242cde22b7140acd202ffd88823886c9 through before 517676ec7dfca064e08f94007a4abd21969de0a0 (git); 97730bbb242cde22b7140acd202ffd88823886c9 through before 46d403da376a8b7c1187193294953816e1a8d7fe (git); 97730bbb242cde22b7140acd202ffd88823886c9 through before 2619b47a0c8114eef980a56ade7e3ef4b58eb384 (git); 97730bbb242cde22b7140acd202ffd88823886c9 through before 92f41769e5fd16bcd9ba97500d0517332e0a5b45 (git); 97730bbb242cde22b7140acd202ffd88823886c9 through before 15432f19562fdb9199cce6d9fc24db12c71ed574 (git); 97730bbb242cde22b7140acd202ffd88823886c9 through before 896df22ee57648b0c505bd76ddbc6b2341834696 (git); 5.19",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware_loader: fix device reference leak in firmware_upload_register()\n\nfirmware_upload_register()\n  -> fw_create_instance()\n     -> device_initialize()\n\nAfter fw_create_instance() succeeds, the lifetime of the embedded struct\ndevice is expected to be managed through the device core reference\ncounting, since fw_create_instance() has already called\ndevice_initialize().\n\nIn firmware_upload_register(), if alloc_lookup_fw_priv() fails after\nfw_create_instance() succeeds, the code reaches free_fw_sysfs and frees\nfw_sysfs directly instead of releasing the device reference with\nput_device(). This may leave the reference count of the embedded struct\ndevice unbalanced, resulting in a refcount leak.\n\nThe issue was identified by a static analysis tool I developed and\nconfirmed by manual review. Fix this by using put_device(fw_dev) in the\nfailure path and letting fw_dev_release() handle the final cleanup,\ninstead of freeing the instance directly from the error path.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/15432f19562fdb9199cce6d9fc24db12c71ed574",
                "https://git.kernel.org/stable/c/2619b47a0c8114eef980a56ade7e3ef4b58eb384",
                "https://git.kernel.org/stable/c/46d403da376a8b7c1187193294953816e1a8d7fe",
                "https://git.kernel.org/stable/c/517676ec7dfca064e08f94007a4abd21969de0a0",
                "https://git.kernel.org/stable/c/896df22ee57648b0c505bd76ddbc6b2341834696",
                "https://git.kernel.org/stable/c/92f41769e5fd16bcd9ba97500d0517332e0a5b45"
            ],
            "timeline": [
                {
                    "at": "2026-07-25T10:17:20.717",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64376"
                }
            ]
        },
        {
            "id": "CVE-2026-64375",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nproc: protect ptrace_may_access() with exec_update_lock (FD links)\n\nproc_pid_get_link() and proc_pid_readlink() currently look up the task from\nthe pid once, then do the ptrace access check on that task, then look up\nthe task from the pid a second time to do the actual access.\nThat's racy in several ways.\n\nTo fix it, pass the task to the ->proc_get_link() handler, and instead of\nproc_fd_access_allowed(), introduce a new helper call_proc_get_link() that\nlooks up and locks the task, does the access check, and calls\n->proc_get_link().",
            "updated_at": "2026-09-08T14:31:06.567",
            "published_at": "2026-07-25T10:17:20.593",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "778c1144771f0064b6f51bee865cceb0d996f2f9 through before 6253dfee5afba536bb54fc6fe6c091c3758fafe1 (git); 778c1144771f0064b6f51bee865cceb0d996f2f9 through before 65bf0d2b6e914f1448d6a2fde193dcf60936a651 (git); 778c1144771f0064b6f51bee865cceb0d996f2f9 through before de497d7aa2fae453a7e7c8f7d3e8682e565e3aaf (git); 778c1144771f0064b6f51bee865cceb0d996f2f9 through before 138c692d2b2d63d26f2eb957d0e4fcc5d61f9ff2 (git); 778c1144771f0064b6f51bee865cceb0d996f2f9 through before 83b17872e3166c295c599279fc9562ac3840c638 (git); 778c1144771f0064b6f51bee865cceb0d996f2f9 through before 497c6bae5167428596575f20af6613ff5671f383 (git); 778c1144771f0064b6f51bee865cceb0d996f2f9 through before dfd1894cb64cbd8758b461ed713800fe73db4f82 (git); 778c1144771f0064b6f51bee865cceb0d996f2f9 through before 6255da28d4bb5349fe18e84cb043ccd394eba75d (git); 2.6.18; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nproc: protect ptrace_may_access() with exec_update_lock (FD links)\n\nproc_pid_get_link() and proc_pid_readlink() currently look up the task from\nthe pid once, then do the ptrace access check on that task, then look up\nthe task from the pid a second time to do the actual access.\nThat's racy in several ways.\n\nTo fix it, pass the task to the ->proc_get_link() handler, and instead of\nproc_fd_access_allowed(), introduce a new helper call_proc_get_link() that\nlooks up and locks the task, does the access check, and calls\n->proc_get_link().",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/138c692d2b2d63d26f2eb957d0e4fcc5d61f9ff2",
                "https://git.kernel.org/stable/c/497c6bae5167428596575f20af6613ff5671f383",
                "https://git.kernel.org/stable/c/6253dfee5afba536bb54fc6fe6c091c3758fafe1",
                "https://git.kernel.org/stable/c/6255da28d4bb5349fe18e84cb043ccd394eba75d",
                "https://git.kernel.org/stable/c/65bf0d2b6e914f1448d6a2fde193dcf60936a651",
                "https://git.kernel.org/stable/c/83b17872e3166c295c599279fc9562ac3840c638",
                "https://git.kernel.org/stable/c/de497d7aa2fae453a7e7c8f7d3e8682e565e3aaf",
                "https://git.kernel.org/stable/c/dfd1894cb64cbd8758b461ed713800fe73db4f82",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-07-25T10:17:20.593",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64375"
                }
            ]
        },
        {
            "id": "CVE-2026-64374",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT\n\nRT migration is done aggressively. When a CPU schedules out a high\npriority RT task for a lower priority task, it will look to see if there's\nany RT tasks that are waiting to run on another CPU that is of higher\npriority than the task this CPU is about to run. If it finds one, it will\npull that task over to the CPU and allow it to run there instead.\n\nNormally, this pulling is done by looking at the RT overloaded mask (rto)\nwhich contains all the CPUs in the scheduler domain with RT tasks that are\nwaiting to run due to a higher priority RT task currently running on their\nCPU. The CPU that is about to schedule a lower priority task will grab the\nrq lock of the overloaded CPU and move the RT task from that CPU's runqueue\nto the local one and schedule the higher priority RT task.\n\nThis caused issues when a lot of CPUs would schedule a lower priority task\nat the same time. They would all try to grab the same runqueue lock of\nthe CPU with the overloaded RT tasks. Only the first CPU that got in will\nget that task. All the others would wait until they got the runqueue lock\nand see there's nothing to pull and do nothing. On systems with lots of\nCPUs, this caused a large latency (up to 500us) which is beyond what\nPREEMPT_RT is to allow.\n\nThe solution to that was to create an RT_PUSH_IPI logic. When any CPU\nwanted to pull a task, instead of grabbing the runqueue lock of the\noverloaded CPU, it would start by sending an IPI to the overloaded CPU,\nand that IPI handler would have the CPU with the waiting RT task do a push\ninstead. Then that handler would send an IPI to the next CPU with\noverloaded RT tasks, and so on. Note, after the first CPU starts this\nprocess, if another CPU wanted to do a pull, it would see that the process\nhas already begun and would only increment a counter to have the IPIs\ncontinue again.\n\nThe RT_PUSH_IPI solved the latency problem with PREEMPT_RT but could cause\na new issue with non PREEMPT_RT. Namely, softirqs run in a threaded\ncontext on PREEMPT_RT but they can run in an interrupt context in non-RT.\n\nIf an IPI lands on a CPU that has just woken up multiple RT tasks and the\ncurrent CPU is running a non RT or a low priority RT task, instead of\ndoing a push, it would simply do a schedule on that CPU. But if a softirq\nwas also executing on this CPU, the schedule would need to wait until the\nsoftirq finished. Until then, the CPU would still be considered overloaded\nas there are RT tasks still waiting to run on it.\n\nA live lock occurred on a workload that was doing heavy networking traffic\non a large machine where the softirqs would run 500us out of 750us. And it\nwould also be waking up RT tasks, causing the RT pull logic to be\nconstantly executed.\n\nWhen a softirq triggered on a CPU with RT tasks queued but not running\nyet, and the other CPUs would see this CPU as being overloaded, they would\nsend an IPI over to it. The CPU would notice that the waiting RT tasks are\nof higher priority than the currently running task and simply schedule\nthat CPU instead. But because the softirq was executing, before it could\nschedule, it would receive another IPI to do the same. The amount of IPIs\nwould slow down the currently running softirq so much that before it could\nreturn back to task context, it would execute another softirq never\nallowing the CPU to schedule. This live locked that CPU.\n\nAs RT_PUSH_IPI was created to help PREEMPT_RT, make it default off if\nPREEMPT_RT is not enabled.",
            "updated_at": "2026-09-08T14:35:16.073",
            "published_at": "2026-07-25T10:17:20.433",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "b6366f048e0caff28af5335b7af2031266e1b06b through before b99f04ae3d200d2f8844aa29145bd18eccbeecde (git); b6366f048e0caff28af5335b7af2031266e1b06b through before d8312a56d9a162e3ec76476aa487e7d20bc602e9 (git); b6366f048e0caff28af5335b7af2031266e1b06b through before 44aae426dbfd51286f7eb601cfa14bc32164812a (git); b6366f048e0caff28af5335b7af2031266e1b06b through before 860aaff72c8446fed5e576249e19952883a18885 (git); b6366f048e0caff28af5335b7af2031266e1b06b through before 89237c8fc15d8016a194076e648ccb57d75e65ae (git); b6366f048e0caff28af5335b7af2031266e1b06b through before 4bd0da48fbc1dbef6774175129107fbbdd353e26 (git); b6366f048e0caff28af5335b7af2031266e1b06b through before a18f80bf5359238c4f067d691b96af00286fdd89 (git); b6366f048e0caff28af5335b7af2031266e1b06b through before dd29c017aed628076e915fe4cdfb5392fd4c5cab (git); 4.1",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-667",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT\n\nRT migration is done aggressively. When a CPU schedules out a high\npriority RT task for a lower priority task, it will look to see if there's\nany RT tasks that are waiting to run on another CPU that is of higher\npriority than the task this CPU is about to run. If it finds one, it will\npull that task over to the CPU and allow it to run there instead.\n\nNormally, this pulling is done by looking at the RT overloaded mask (rto)\nwhich contains all the CPUs in the scheduler domain with RT tasks that are\nwaiting to run due to a higher priority RT task currently running on their\nCPU. The CPU that is about to schedule a lower priority task will grab the\nrq lock of the overloaded CPU and move the RT task from that CPU's runqueue\nto the local one and schedule the higher priority RT task.\n\nThis caused issues when a lot of CPUs would schedule a lower priority task\nat the same time. They would all try to grab the same runqueue lock of\nthe CPU with the overloaded RT tasks. Only the first CPU that got in will\nget that task. All the others would wait until they got the runqueue lock\nand see there's nothing to pull and do nothing. On systems with lots of\nCPUs, this caused a large latency (up to 500us) which is beyond what\nPREEMPT_RT is to allow.\n\nThe solution to that was to create an RT_PUSH_IPI logic. When any CPU\nwanted to pull a task, instead of grabbing the runqueue lock of the\noverloaded CPU, it would start by sending an IPI to the overloaded CPU,\nand that IPI handler would have the CPU with the waiting RT task do a push\ninstead. Then that handler would send an IPI to the next CPU with\noverloaded RT tasks, and so on. Note, after the first CPU starts this\nprocess, if another CPU wanted to do a pull, it would see that the process\nhas already begun and would only increment a counter to have the IPIs\ncontinue again.\n\nThe RT_PUSH_IPI solved the latency problem with PREEMPT_RT but could cause\na new issue with non PREEMPT_RT. Namely, softirqs run in a threaded\ncontext on PREEMPT_RT but they can run in an interrupt context in non-RT.\n\nIf an IPI lands on a CPU that has just woken up multiple RT tasks and the\ncurrent CPU is running a non RT or a low priority RT task, instead of\ndoing a push, it would simply do a schedule on that CPU. But if a softirq\nwas also executing on this CPU, the schedule would need to wait until the\nsoftirq finished. Until then, the CPU would still be considered overloaded\nas there are RT tasks still waiting to run on it.\n\nA live lock occurred on a workload that was doing heavy networking traffic\non a large machine where the softirqs would run 500us out of 750us. And it\nwould also be waking up RT tasks, causing the RT pull logic to be\nconstantly executed.\n\nWhen a softirq triggered on a CPU with RT tasks queued but not running\nyet, and the other CPUs would see this CPU as being overloaded, they would\nsend an IPI over to it. The CPU would notice that the waiting RT tasks are\nof higher priority than the currently running task and simply schedule\nthat CPU instead. But because the softirq was executing, before it could\nschedule, it would receive another IPI to do the same. The amount of IPIs\nwould slow down the currently running softirq so much that before it could\nreturn back to task context, it would execute another softirq never\nallowing the CPU to schedule. This live locked that CPU.\n\nAs RT_PUSH_IPI was created to help PREEMPT_RT, make it default off if\nPREEMPT_RT is not enabled.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/44aae426dbfd51286f7eb601cfa14bc32164812a",
                "https://git.kernel.org/stable/c/4bd0da48fbc1dbef6774175129107fbbdd353e26",
                "https://git.kernel.org/stable/c/860aaff72c8446fed5e576249e19952883a18885",
                "https://git.kernel.org/stable/c/89237c8fc15d8016a194076e648ccb57d75e65ae",
                "https://git.kernel.org/stable/c/a18f80bf5359238c4f067d691b96af00286fdd89",
                "https://git.kernel.org/stable/c/b99f04ae3d200d2f8844aa29145bd18eccbeecde",
                "https://git.kernel.org/stable/c/d8312a56d9a162e3ec76476aa487e7d20bc602e9",
                "https://git.kernel.org/stable/c/dd29c017aed628076e915fe4cdfb5392fd4c5cab"
            ],
            "timeline": [
                {
                    "at": "2026-07-25T10:17:20.433",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64374"
                }
            ]
        },
        {
            "id": "CVE-2026-64373",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: Fix hotplug-suspend race during reboot\n\nDuring system reboot, cpufreq_suspend() is called via the\nkernel_restart() -> device_shutdown() path. Unlike the normal system\nsuspend path, the reboot path does not call freeze_processes(), so\nuserspace processes and kernel threads remain active.\n\nThis allows CPU hotplug operations to run concurrently with\ncpufreq_suspend(). The original code has no synchronization with CPU\nhotplug, leading to a race condition where governor_data can be freed\nby the hotplug path while cpufreq_suspend() is still accessing it,\nresulting in a null pointer dereference:\n\n  Unable to handle kernel NULL pointer dereference\n  Call Trace:\n   do_kernel_fault+0x28/0x3c\n   cpufreq_suspend+0xdc/0x160\n   device_shutdown+0x18/0x200\n   kernel_restart+0x40/0x80\n   arm64_sys_reboot+0x1b0/0x200\n\nFix this by adding cpus_read_lock()/cpus_read_unlock() to\ncpufreq_suspend() to block CPU hotplug operations while suspend is in\nprogress.\n\n[ rjw: Changelog edits ]",
            "updated_at": "2026-09-08T15:23:15.967",
            "published_at": "2026-07-25T10:17:20.283",
            "cvss": 4.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 through before 6d5dd354c37abaf4d60400c55c71f23ba2b33639 (git); 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 through before 9103078c7b3091a2fbb52af176f95982ee7dd7f8 (git); 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 through before cd4524ff6567fa4458a5bec4b017105e671d393e (git); 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 through before 73255d702c7560185fd5951aadcf7eb057c2f453 (git); 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 through before a0ef2fc89d28ca62923376c4b8ffaa57136a36be (git); 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 through before 6e175c00c62dca3d91b987015808b5d52e8db2b4 (git); 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 through before a0106b41f9a724868d390b8b3b4ea5ca0e04ea53 (git); 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 through before a9029dd55696c651ee46912afa2a166fa456bb3e (git); 8bfa06ea6e81bf08d2132d7e70c2b5313b34caf8 (git); 7ccf3b8b7a12dc9da158c2e699c36d04b2496944 (git); 5f466713989250938624afa79dc33bae20920700 (git); 89ab39da1452d272007acc5912d4008047b86706 (git); cb4b4601f910c78d2b49f637a12ef98b41cb76a9 (git); 4.4.198 through before 4.5 (semver); 4.9.198 through before 4.10 (semver); 4.14.151 through before 4.15 (semver); 4.19.81 through before 4.20 (semver); 5.3.8 through before 5.4 (semver); 5.4",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: Fix hotplug-suspend race during reboot\n\nDuring system reboot, cpufreq_suspend() is called via the\nkernel_restart() -> device_shutdown() path. Unlike the normal system\nsuspend path, the reboot path does not call freeze_processes(), so\nuserspace processes and kernel threads remain active.\n\nThis allows CPU hotplug operations to run concurrently with\ncpufreq_suspend(). The original code has no synchronization with CPU\nhotplug, leading to a race condition where governor_data can be freed\nby the hotplug path while cpufreq_suspend() is still accessing it,\nresulting in a null pointer dereference:\n\n  Unable to handle kernel NULL pointer dereference\n  Call Trace:\n   do_kernel_fault+0x28/0x3c\n   cpufreq_suspend+0xdc/0x160\n   device_shutdown+0x18/0x200\n   kernel_restart+0x40/0x80\n   arm64_sys_reboot+0x1b0/0x200\n\nFix this by adding cpus_read_lock()/cpus_read_unlock() to\ncpufreq_suspend() to block CPU hotplug operations while suspend is in\nprogress.\n\n[ rjw: Changelog edits ]",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/6d5dd354c37abaf4d60400c55c71f23ba2b33639",
                "https://git.kernel.org/stable/c/6e175c00c62dca3d91b987015808b5d52e8db2b4",
                "https://git.kernel.org/stable/c/73255d702c7560185fd5951aadcf7eb057c2f453",
                "https://git.kernel.org/stable/c/9103078c7b3091a2fbb52af176f95982ee7dd7f8",
                "https://git.kernel.org/stable/c/a0106b41f9a724868d390b8b3b4ea5ca0e04ea53",
                "https://git.kernel.org/stable/c/a0ef2fc89d28ca62923376c4b8ffaa57136a36be",
                "https://git.kernel.org/stable/c/a9029dd55696c651ee46912afa2a166fa456bb3e",
                "https://git.kernel.org/stable/c/cd4524ff6567fa4458a5bec4b017105e671d393e"
            ],
            "timeline": [
                {
                    "at": "2026-07-25T10:17:20.283",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64373"
                }
            ]
        },
        {
            "id": "CVE-2026-64372",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: pcc: fix use-after-free and double free in _OSC evaluation\n\npcc_cpufreq_do_osc() calls acpi_evaluate_object() twice for the\ntwo-phase _OSC negotiation. Between the two calls it freed\noutput.pointer but left output.length unchanged. Since\nacpi_evaluate_object() treats a non-zero length with a non-NULL\npointer as an existing buffer to write into, the second call wrote\ninto freed memory (use-after-free). The subsequent kfree(output.pointer)\nat out_free then freed the same pointer a second time (double free).\n\nReset output.pointer to NULL and output.length to ACPI_ALLOCATE_BUFFER\nafter freeing the first result, so ACPICA allocates a fresh buffer for\neach phase independently.",
            "updated_at": "2026-09-08T15:03:00.187",
            "published_at": "2026-07-25T10:17:20.147",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0f1d683fb35d6c6f49ef696c95757f3970682a0e through before 8e454e9d0bc03446d610ee49abec9dfd424f6541 (git); 0f1d683fb35d6c6f49ef696c95757f3970682a0e through before 632666a63116d8061c62a988d1ca39dcd6d27c9b (git); 0f1d683fb35d6c6f49ef696c95757f3970682a0e through before 5cdb25f144b101083d8bf3fd023ad87fbe6850d7 (git); 0f1d683fb35d6c6f49ef696c95757f3970682a0e through before 982c9f92d57bda2b769851ff6d90d43dcf5f3734 (git); 0f1d683fb35d6c6f49ef696c95757f3970682a0e through before a36ca93a8ba57464e521d70a337d37f069064111 (git); 0f1d683fb35d6c6f49ef696c95757f3970682a0e through before 6ba6f6783be2ffeb2cbcdc9321c4b9f708f796f7 (git); 0f1d683fb35d6c6f49ef696c95757f3970682a0e through before 0e3c739a2f6fc1de5b19a8839ab80696b9cb2a29 (git); 0f1d683fb35d6c6f49ef696c95757f3970682a0e through before 266d3dd8b757b48a576e90f018b51f7b7563cc32 (git); 2.6.34",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: pcc: fix use-after-free and double free in _OSC evaluation\n\npcc_cpufreq_do_osc() calls acpi_evaluate_object() twice for the\ntwo-phase _OSC negotiation. Between the two calls it freed\noutput.pointer but left output.length unchanged. Since\nacpi_evaluate_object() treats a non-zero length with a non-NULL\npointer as an existing buffer to write into, the second call wrote\ninto freed memory (use-after-free). The subsequent kfree(output.pointer)\nat out_free then freed the same pointer a second time (double free).\n\nReset output.pointer to NULL and output.length to ACPI_ALLOCATE_BUFFER\nafter freeing the first result, so ACPICA allocates a fresh buffer for\neach phase independently.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0e3c739a2f6fc1de5b19a8839ab80696b9cb2a29",
                "https://git.kernel.org/stable/c/266d3dd8b757b48a576e90f018b51f7b7563cc32",
                "https://git.kernel.org/stable/c/5cdb25f144b101083d8bf3fd023ad87fbe6850d7",
                "https://git.kernel.org/stable/c/632666a63116d8061c62a988d1ca39dcd6d27c9b",
                "https://git.kernel.org/stable/c/6ba6f6783be2ffeb2cbcdc9321c4b9f708f796f7",
                "https://git.kernel.org/stable/c/8e454e9d0bc03446d610ee49abec9dfd424f6541",
                "https://git.kernel.org/stable/c/982c9f92d57bda2b769851ff6d90d43dcf5f3734",
                "https://git.kernel.org/stable/c/a36ca93a8ba57464e521d70a337d37f069064111"
            ],
            "timeline": [
                {
                    "at": "2026-07-25T10:17:20.147",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64372"
                }
            ]
        },
        {
            "id": "CVE-2026-64371",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nproc: protect ptrace_may_access() with exec_update_lock (part 1)\n\nFix the easy cases where procfs currently calls ptrace_may_access() without\nexec_update_lock protection, where the fix is to simply add the extra lock\nor use mm_access():\n\n - do_task_stat(): grab exec_update_lock\n - proc_pid_wchan(): grab exec_update_lock\n - proc_map_files_lookup(): use mm_access() instead of get_task_mm()\n - proc_map_files_readdir(): use mm_access() instead of get_task_mm()\n - proc_ns_get_link(): grab exec_update_lock\n - proc_ns_readlink(): grab exec_update_lock",
            "updated_at": "2026-09-08T15:23:41.413",
            "published_at": "2026-07-25T10:17:20.010",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f83ce3e6b02d5e48b3a43b001390e2b58820389d through before ae1e630bcaac739f625822078edbaea98366930d (git); f83ce3e6b02d5e48b3a43b001390e2b58820389d through before d54f14655fd7d7b293698a8b6918563c4c0465e7 (git); f83ce3e6b02d5e48b3a43b001390e2b58820389d through before bb43679356f1f2a4c6b1c88aec4f021e5b5c74e9 (git); f83ce3e6b02d5e48b3a43b001390e2b58820389d through before 7456ae990a9738962b33146916fabca62ae3d4e0 (git); f83ce3e6b02d5e48b3a43b001390e2b58820389d through before 4bfe8c481846cee52473a2f7d7b30ee8e6749fc4 (git); f83ce3e6b02d5e48b3a43b001390e2b58820389d through before f9b4b03ccc9c69bf7f7298d4559906ebea7143b3 (git); f83ce3e6b02d5e48b3a43b001390e2b58820389d through before c1cfd63326f5d09999134e9052c353faf738286e (git); f83ce3e6b02d5e48b3a43b001390e2b58820389d through before 6650527444dadc63d84aa939d14ecba4fadb2f69 (git); 6b06d6282100dd5aacf7d45443d651a1995bd9c4 (git); 334ed22054b2ec8477e4409e214fc139cf937ef6 (git); 2.6.27.23 through before 2.6.28 (semver); 2.6.29.3 through before 2.6.30 (semver); 2.6.30; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nproc: protect ptrace_may_access() with exec_update_lock (part 1)\n\nFix the easy cases where procfs currently calls ptrace_may_access() without\nexec_update_lock protection, where the fix is to simply add the extra lock\nor use mm_access():\n\n - do_task_stat(): grab exec_update_lock\n - proc_pid_wchan(): grab exec_update_lock\n - proc_map_files_lookup(): use mm_access() instead of get_task_mm()\n - proc_map_files_readdir(): use mm_access() instead of get_task_mm()\n - proc_ns_get_link(): grab exec_update_lock\n - proc_ns_readlink(): grab exec_update_lock",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/4bfe8c481846cee52473a2f7d7b30ee8e6749fc4",
                "https://git.kernel.org/stable/c/6650527444dadc63d84aa939d14ecba4fadb2f69",
                "https://git.kernel.org/stable/c/7456ae990a9738962b33146916fabca62ae3d4e0",
                "https://git.kernel.org/stable/c/ae1e630bcaac739f625822078edbaea98366930d",
                "https://git.kernel.org/stable/c/bb43679356f1f2a4c6b1c88aec4f021e5b5c74e9",
                "https://git.kernel.org/stable/c/c1cfd63326f5d09999134e9052c353faf738286e",
                "https://git.kernel.org/stable/c/d54f14655fd7d7b293698a8b6918563c4c0465e7",
                "https://git.kernel.org/stable/c/f9b4b03ccc9c69bf7f7298d4559906ebea7143b3",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-07-25T10:17:20.010",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64371"
                }
            ]
        },
        {
            "id": "CVE-2026-64370",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nposix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path\n\nIn do_cpu_nanosleep(), posix_cpu_timer_create() takes a pid reference\nvia get_pid() and stores it in timer.it.cpu.pid. If the subsequent\nposix_cpu_timer_set() call fails, the function returns immediately\nwithout calling posix_cpu_timer_del() to release the pid reference,\ncausing a leak.\n\nFix it by calling posix_cpu_timer_del() before the unlock-and-return\non the error path, consistent with the other exit paths in the same\nfunction.",
            "updated_at": "2026-09-08T15:23:56.573",
            "published_at": "2026-07-25T10:17:19.880",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before afed3cdc1cca133f804fcf57ff228974f424b23a (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 8a270b1258797f61b61da44f8bfd41a581b5c85b (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before d605d00085adc3fddf67de01dc2a44aebf1a3fb5 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before e5ffc638faf5dc7d9dc85c9a95e10bf97442e0c0 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before eb4cec29a78334d09bcfb41c0660cdd62ba05843 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 7776f9226e99eb49d97492b0b445027cfcb189da (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 8f06363446c5d043c9a7c008b250040e9de98cf9 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 87bd2ad568e15b90d5f7d4bcd70342d05dad649c (git); 2.6.12; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nposix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path\n\nIn do_cpu_nanosleep(), posix_cpu_timer_create() takes a pid reference\nvia get_pid() and stores it in timer.it.cpu.pid. If the subsequent\nposix_cpu_timer_set() call fails, the function returns immediately\nwithout calling posix_cpu_timer_del() to release the pid reference,\ncausing a leak.\n\nFix it by calling posix_cpu_timer_del() before the unlock-and-return\non the error path, consistent with the other exit paths in the same\nfunction.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/7776f9226e99eb49d97492b0b445027cfcb189da",
                "https://git.kernel.org/stable/c/87bd2ad568e15b90d5f7d4bcd70342d05dad649c",
                "https://git.kernel.org/stable/c/8a270b1258797f61b61da44f8bfd41a581b5c85b",
                "https://git.kernel.org/stable/c/8f06363446c5d043c9a7c008b250040e9de98cf9",
                "https://git.kernel.org/stable/c/afed3cdc1cca133f804fcf57ff228974f424b23a",
                "https://git.kernel.org/stable/c/d605d00085adc3fddf67de01dc2a44aebf1a3fb5",
                "https://git.kernel.org/stable/c/e5ffc638faf5dc7d9dc85c9a95e10bf97442e0c0",
                "https://git.kernel.org/stable/c/eb4cec29a78334d09bcfb41c0660cdd62ba05843",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-07-25T10:17:19.880",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64370"
                }
            ]
        },
        {
            "id": "CVE-2026-64369",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390: Revert support for DCACHE_WORD_ACCESS\n\nload_unaligned_zeropad() reads eight bytes from unaligned addresses and may\ncross page boundaries. It handles exceptions which may happen if reading\nfrom the second page results in an exception.\n\nFor pages which are donated to the Ultravisor for secure execution purposes\nthe do_secure_storage_access() exception handler however does not handle\nsuch exceptions correctly. Such an exception may result in an endless\nexception loop which will never be resolved.\n\nAn attempt to fix this [1] turned out to be not sufficient. For now revert\nload_unaligned_zeropad() until this problem has been resolved in a proper\nway.\n\nNote that the implementation of load_unaligned_zeropad() itself is\ncorrect. The revert is just a temporary workaround until there is complete\nfix for secure storage access exceptions.\n\n[1] commit b00be77302d7 (\"s390/mm: Add missing secure storage access fixups for donated memory\")",
            "updated_at": "2026-09-08T15:05:19.630",
            "published_at": "2026-07-25T10:17:19.743",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "802ba53eefc592a6a82231f74e19bafe3256f172 through before c9e0f1517631ac08987f8385817119bccf2f1f12 (git); 802ba53eefc592a6a82231f74e19bafe3256f172 through before be79d285bea70d0edd5015bd487311bfa8cbebc9 (git); 802ba53eefc592a6a82231f74e19bafe3256f172 through before c94806905e02cc8e17a69c822d93c41743b7ffc5 (git); 802ba53eefc592a6a82231f74e19bafe3256f172 through before 37540b8c287fc817bdbd0c62bb75ad6eab0e5d03 (git); 6.7",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-835",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390: Revert support for DCACHE_WORD_ACCESS\n\nload_unaligned_zeropad() reads eight bytes from unaligned addresses and may\ncross page boundaries. It handles exceptions which may happen if reading\nfrom the second page results in an exception.\n\nFor pages which are donated to the Ultravisor for secure execution purposes\nthe do_secure_storage_access() exception handler however does not handle\nsuch exceptions correctly. Such an exception may result in an endless\nexception loop which will never be resolved.\n\nAn attempt to fix this [1] turned out to be not sufficient. For now revert\nload_unaligned_zeropad() until this problem has been resolved in a proper\nway.\n\nNote that the implementation of load_unaligned_zeropad() itself is\ncorrect. The revert is just a temporary workaround until there is complete\nfix for secure storage access exceptions.\n\n[1] commit b00be77302d7 (\"s390/mm: Add missing secure storage access fixups for donated memory\")",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/37540b8c287fc817bdbd0c62bb75ad6eab0e5d03",
                "https://git.kernel.org/stable/c/be79d285bea70d0edd5015bd487311bfa8cbebc9",
                "https://git.kernel.org/stable/c/c94806905e02cc8e17a69c822d93c41743b7ffc5",
                "https://git.kernel.org/stable/c/c9e0f1517631ac08987f8385817119bccf2f1f12"
            ],
            "timeline": [
                {
                    "at": "2026-07-25T10:17:19.743",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64369"
                }
            ]
        },
        {
            "id": "CVE-2026-64364",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: fix out-of-bounds bit access on mt_io_flags\n\nmt_io_flags is a single unsigned long, but mt_process_slot(),\nmt_release_pending_palms() and mt_release_contacts() use it as a\nper-slot bitmap indexed by the slot number. That slot number is only\nbounded by td->maxcontacts, which is taken from the device's\nContactCountMaximum feature report and can be up to 255, not by\nBITS_PER_LONG.\n\nAs a result, a multitouch device that advertises a large contact count\nmakes set_bit()/clear_bit() operate past the mt_io_flags word and\ncorrupt the adjacent members of struct mt_device. The sticky-fingers\nrelease timer is the easiest way to reach this. mt_release_contacts()\nruns\n\n\tfor (i = 0; i < mt->num_slots; i++)\n\t\tclear_bit(i, &td->mt_io_flags);\n\nwith num_slots == maxcontacts. For maxcontacts around 250 the loop\nclears the bits that overlap td->applications.next, zeroing that list\nhead, and the list_for_each_entry() that immediately follows then\ndereferences NULL. The kernel panics from timer (softirq) context. On a\nKASAN build this shows up as a general protection fault in\nmt_release_contacts() with a null-ptr-deref at offset 0x58, which is\noffsetof(struct mt_application, num_received).\n\nThe state is reachable from an untrusted USB or Bluetooth HID\nmultitouch device; no local privileges are required.\n\nStore the per-slot active state in a separately allocated bitmap sized\nfor maxcontacts, the same pattern already used for pending_palm_slots,\nand keep only MT_IO_FLAGS_RUNNING in mt_io_flags. The two\n\"mt_io_flags & MT_IO_SLOTS_MASK\" arming checks become\nbitmap_empty(td->active_slots, td->maxcontacts).\n\nMove MT_IO_FLAGS_RUNNING back to bit 0. It was bumped to bit 32 by the\nsame commit to leave the low byte for the slot bits; with the slot bits\ngone it fits in bit 0 again, which also keeps it within the unsigned\nlong on 32-bit.",
            "updated_at": "2026-09-10T21:35:45.760",
            "published_at": "2026-07-25T10:17:19.110",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "fc488f675344931ffab6a51c43691065ec006567 through before 12e90656e330ff8bbaf2f29c535fdb8a11cc6f55 (git); 77711d850bed75ae7142c3d1f22c1a8b4d049c33 through before 152983d87387f6a8ae72b73474cfa55fbcf1ec75 (git); 6acfe25968913788d30ec0eedd80178c4ea3f1d0 through before b5c037d6b807017e74a115288f81bc9cd5a5aab8 (git); d280c138e66be87d1fccfed42593f02fdb893905 through before a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d (git); f32fea4c0234c971c12e46d76612cdc2dd4bb046 through before e24918ee67c4dc3d20d4670750e46e9b160365f4 (git); 46f781e0d151844589dc2125c8cce3300546f92a through before 37daa8c96bd563d03150e23f094cb60703594a6d (git); 46f781e0d151844589dc2125c8cce3300546f92a through before 6493ebf9489efef0105078377b973ab33d51af22 (git); 46f781e0d151844589dc2125c8cce3300546f92a through before 8813b0612275cc61fe9e6603d0ee019247ade6be (git); 59bd04163e6451b9c7275277882ed9f4abfa2051 (git); 5.10.246 through before 5.10.261 (semver); 5.15.196 through before 5.15.212 (semver); 6.1.158 through before 6.1.178 (semver); 6.6.114 through before 6.6.145 (semver); 6.12.55 through before 6.12.97 (semver); 6.17.5 through before 6.18 (semver); 6.18",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: fix out-of-bounds bit access on mt_io_flags\n\nmt_io_flags is a single unsigned long, but mt_process_slot(),\nmt_release_pending_palms() and mt_release_contacts() use it as a\nper-slot bitmap indexed by the slot number. That slot number is only\nbounded by td->maxcontacts, which is taken from the device's\nContactCountMaximum feature report and can be up to 255, not by\nBITS_PER_LONG.\n\nAs a result, a multitouch device that advertises a large contact count\nmakes set_bit()/clear_bit() operate past the mt_io_flags word and\ncorrupt the adjacent members of struct mt_device. The sticky-fingers\nrelease timer is the easiest way to reach this. mt_release_contacts()\nruns\n\n\tfor (i = 0; i < mt->num_slots; i++)\n\t\tclear_bit(i, &td->mt_io_flags);\n\nwith num_slots == maxcontacts. For maxcontacts around 250 the loop\nclears the bits that overlap td->applications.next, zeroing that list\nhead, and the list_for_each_entry() that immediately follows then\ndereferences NULL. The kernel panics from timer (softirq) context. On a\nKASAN build this shows up as a general protection fault in\nmt_release_contacts() with a null-ptr-deref at offset 0x58, which is\noffsetof(struct mt_application, num_received).\n\nThe state is reachable from an untrusted USB or Bluetooth HID\nmultitouch device; no local privileges are required.\n\nStore the per-slot active state in a separately allocated bitmap sized\nfor maxcontacts, the same pattern already used for pending_palm_slots,\nand keep only MT_IO_FLAGS_RUNNING in mt_io_flags. The two\n\"mt_io_flags & MT_IO_SLOTS_MASK\" arming checks become\nbitmap_empty(td->active_slots, td->maxcontacts).\n\nMove MT_IO_FLAGS_RUNNING back to bit 0. It was bumped to bit 32 by the\nsame commit to leave the low byte for the slot bits; with the slot bits\ngone it fits in bit 0 again, which also keeps it within the unsigned\nlong on 32-bit.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/12e90656e330ff8bbaf2f29c535fdb8a11cc6f55",
                "https://git.kernel.org/stable/c/152983d87387f6a8ae72b73474cfa55fbcf1ec75",
                "https://git.kernel.org/stable/c/37daa8c96bd563d03150e23f094cb60703594a6d",
                "https://git.kernel.org/stable/c/6493ebf9489efef0105078377b973ab33d51af22",
                "https://git.kernel.org/stable/c/8813b0612275cc61fe9e6603d0ee019247ade6be",
                "https://git.kernel.org/stable/c/a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d",
                "https://git.kernel.org/stable/c/b5c037d6b807017e74a115288f81bc9cd5a5aab8",
                "https://git.kernel.org/stable/c/e24918ee67c4dc3d20d4670750e46e9b160365f4"
            ],
            "timeline": [
                {
                    "at": "2026-07-25T10:17:19.110",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64364"
                }
            ]
        },
        {
            "id": "CVE-2026-64068",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix missing locking around retry adding new subreqs\n\nFix netfs_retry_read_subrequests() and netfs_retry_write_stream() to take\nthe appropriate lock when adding extra subrequests into\nstream->subrequests.",
            "updated_at": "2026-09-07T16:17:29.043",
            "published_at": "2026-07-19T16:17:47.390",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "288ace2f57c9d06dd2e42bd80d03747d879a4068 through before d5c9d19b0ff2f7153532ac238a5e96fed2df315c (git); 288ace2f57c9d06dd2e42bd80d03747d879a4068 through before 393f3f0d7353a94b1e0bc4ca89c683fe983e5fd2 (git); 288ace2f57c9d06dd2e42bd80d03747d879a4068 through before cce18c263e9623872327ba3c956012f73c1179cc (git); 6.10",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-667",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix missing locking around retry adding new subreqs\n\nFix netfs_retry_read_subrequests() and netfs_retry_write_stream() to take\nthe appropriate lock when adding extra subrequests into\nstream->subrequests.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/393f3f0d7353a94b1e0bc4ca89c683fe983e5fd2",
                "https://git.kernel.org/stable/c/cce18c263e9623872327ba3c956012f73c1179cc",
                "https://git.kernel.org/stable/c/d5c9d19b0ff2f7153532ac238a5e96fed2df315c"
            ],
            "timeline": [
                {
                    "at": "2026-07-19T16:17:47.390",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-64068"
                }
            ]
        },
        {
            "id": "CVE-2026-63839",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int()\n\nlwmi_dev_evaluate_int() leaks output.pointer when retval == NULL (found\nby sashiko.dev [1]).\n\nFix it by moving `ret_obj = output.pointer' outside of the `if (retval)'\nblock so that it is always freed by the __free cleanup callback.\n\nNo functional change intended.",
            "updated_at": "2026-09-07T16:17:28.937",
            "published_at": "2026-07-19T15:16:50.693",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "e521d16e76cd9ea99c585e064f4e7daf657b1451 through before ce493f9261cd3f4bffe2f72481d8c3ee01c559a3 (git); e521d16e76cd9ea99c585e064f4e7daf657b1451 through before 40a984dd0602e238ad893b167751620e751d1199 (git); e521d16e76cd9ea99c585e064f4e7daf657b1451 through before 0c3887a134f191723b53e2a47e501b534c8723ee (git); 6.17",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int()\n\nlwmi_dev_evaluate_int() leaks output.pointer when retval == NULL (found\nby sashiko.dev [1]).\n\nFix it by moving `ret_obj = output.pointer' outside of the `if (retval)'\nblock so that it is always freed by the __free cleanup callback.\n\nNo functional change intended.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0c3887a134f191723b53e2a47e501b534c8723ee",
                "https://git.kernel.org/stable/c/40a984dd0602e238ad893b167751620e751d1199",
                "https://git.kernel.org/stable/c/ce493f9261cd3f4bffe2f72481d8c3ee01c559a3"
            ],
            "timeline": [
                {
                    "at": "2026-07-19T15:16:50.693",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63839"
                }
            ]
        },
        {
            "id": "CVE-2026-63769",
            "vendor": "huginn",
            "product": "huginn",
            "title": "huginn vulnerability",
            "summary": "Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via error signatures, and access cloud metadata endpoints to retrieve sensitive credentials.",
            "updated_at": "2026-09-14T20:16:48.943",
            "published_at": "2026-07-20T19:17:29.633",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2026.09.09 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via error signatures, and access cloud metadata endpoints to retrieve sensitive credentials.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/huginn/huginn/issues/3679",
                "https://github.com/huginn/huginn/pull/3684",
                "https://github.com/huginn/huginn/releases/tag/v2026.09.09",
                "https://github.com/huginn/huginn/security/advisories/GHSA-f7cq-gj98-cfjp",
                "https://www.vulncheck.com/advisories/huginn-ssrf-via-scenarioimport-fetch-url-method"
            ],
            "timeline": [
                {
                    "at": "2026-07-20T19:17:29.633",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63769"
                }
            ]
        },
        {
            "id": "CVE-2026-63696",
            "vendor": "Dell",
            "product": "SmartFabric OS10 Software",
            "title": "SmartFabric OS10 Software vulnerability",
            "summary": "Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.",
            "updated_at": "2026-09-16T04:18:38.170",
            "published_at": "2026-09-15T15:17:20.527",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 10.6.1.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-494",
            "what_happened": "Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000507473/dsa-2026-343-security-update-for-dell-networking-os10-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T15:17:20.527",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63696"
                }
            ]
        },
        {
            "id": "CVE-2026-63695",
            "vendor": "Dell",
            "product": "SmartFabric OS10 Software",
            "title": "SmartFabric OS10 Software vulnerability",
            "summary": "Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.",
            "updated_at": "2026-09-16T04:18:37.990",
            "published_at": "2026-09-15T15:17:20.390",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 10.6.1.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000507473/dsa-2026-343-security-update-for-dell-networking-os10-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T15:17:20.390",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63695"
                }
            ]
        },
        {
            "id": "CVE-2026-63643",
            "vendor": "MagicMirrorOrg",
            "product": "MagicMirror",
            "title": "Exploit for CVE-2026-63642 CVE-2026-63642 CVE-2026-63643",
            "summary": "MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through the unauthenticated Socket.IO namespace /calendar. The handler passes these fields to CalendarFetcher, causing a server-side request without SSRF validation and optionally disabling TLS verification. When the response is valid iCal, CALENDAR_EVENTS returns parsed event data to the attacker, allowing internal-service response data to be exfiltrated; other responses still provide a blind request and timing primitive. This issue is fixed in version 2.37.0.",
            "updated_at": "2026-09-08T21:02:26.047",
            "published_at": "2026-08-18T18:19:12.260",
            "cvss": 6.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "< 2.37.0",
            "fixed": "See vendor advisory",
            "source_count": 54,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-441",
            "what_happened": "MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through the unauthenticated Socket.IO namespace /calendar. The handler passes these fields to CalendarFetcher, causing a server-side request without SSRF validation and optionally disabling TLS verification. When the response is valid iCal, CALENDAR_EVENTS returns parsed event data to the attacker, allowing internal-service response data to be exfiltrated; other responses still provide a blind request and timing primitive. This issue is fixed in version 2.37.0.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-63642 CVE-2026-63642 CVE-2026-63643",
                    "summary": "Unauthenticated SSRF in MagicMirror² Calendar module ≤ 2.36.0 via ADD_CALENDAR URL parameter.",
                    "what_happened": "Unauthenticated SSRF in MagicMirror² Calendar module ≤ 2.36.0 via ADD_CALENDAR URL parameter.",
                    "cvss": 6.3,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:L/VI:N/SI:N/VA:N/SA:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-918",
                    "references": [
                        "https://sploitus.com/exploit?id=AB52C65C-61B5-5467-9449-496A92020833",
                        "https://github.com/hakaioffsec/CVE-2026-63642"
                    ],
                    "repository": "Sploitus",
                    "author": "hakaioffsec",
                    "first_seen": "2026-09-10T18:20:22",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=AB52C65C-61B5-5467-9449-496A92020833"
                },
                {
                    "title": "Exploit for CVE-2026-63642 CVE-2026-63642 CVE-2026-63643",
                    "summary": "Unauthenticated SSRF in MagicMirror² Calendar module ≤ 2.36.0 via ADD_CALENDAR URL parameter.",
                    "what_happened": "Unauthenticated SSRF in MagicMirror² Calendar module ≤ 2.36.0 via ADD_CALENDAR URL parameter.",
                    "cvss": 6.3,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:L/VI:N/SI:N/VA:N/SA:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-918",
                    "references": [
                        "https://sploitus.com/exploit?id=AB52C65C-61B5-5467-9449-496A92020833",
                        "https://github.com/hakaioffsec/CVE-2026-63642"
                    ],
                    "repository": "hakaioffsec/CVE-2026-63642",
                    "author": "hakaioffsec",
                    "first_seen": "2026-09-10T18:20:22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://github.com/hakaioffsec/CVE-2026-63642"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=AB52C65C-61B5-5467-9449-496A92020833",
                "https://github.com/hakaioffsec/CVE-2026-63642",
                "https://github.com/MagicMirrorOrg/MagicMirror/commit/58c2a5e675a7d367b64d72e1d35680d202ff5c9f",
                "https://github.com/MagicMirrorOrg/MagicMirror/pull/4169",
                "https://github.com/MagicMirrorOrg/MagicMirror/releases/tag/v2.37.0",
                "https://github.com/MagicMirrorOrg/MagicMirror/security/advisories/GHSA-w6x9-28jw-hq7j"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T16:20:22Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=AB52C65C-61B5-5467-9449-496A92020833"
                },
                {
                    "at": "2026-08-18T18:19:12.260",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63643"
                }
            ],
            "enrichment_checked_at": "2026-09-10T22:05:31Z",
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
            "id": "CVE-2026-63642",
            "vendor": "MagicMirrorOrg",
            "product": "MagicMirror",
            "title": "Exploit for CVE-2026-63642 CVE-2026-63642 CVE-2026-63643",
            "summary": "MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfeed/node_helper.js accepts the CHECK_ARTICLE_URL notification through the unauthenticated Socket.IO namespace /newsfeed and performs fetch(url, { method: \"HEAD\" }) without validating the attacker-controlled URL. The helper returns ARTICLE_URL_STATUS containing the URL and framing result, providing a response and timing oracle that can identify internal hosts and ports and trigger side effects on services that react to HEAD requests. This issue is fixed in version 2.37.0.",
            "updated_at": "2026-09-08T21:02:26.047",
            "published_at": "2026-08-18T18:19:12.117",
            "cvss": 6.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "< 2.37.0",
            "fixed": "See vendor advisory",
            "source_count": 54,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfeed/node_helper.js accepts the CHECK_ARTICLE_URL notification through the unauthenticated Socket.IO namespace /newsfeed and performs fetch(url, { method: \"HEAD\" }) without validating the attacker-controlled URL. The helper returns ARTICLE_URL_STATUS containing the URL and framing result, providing a response and timing oracle that can identify internal hosts and ports and trigger side effects on services that react to HEAD requests. This issue is fixed in version 2.37.0.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-63642 CVE-2026-63642 CVE-2026-63643",
                    "summary": "Unauthenticated SSRF in MagicMirror² Calendar module ≤ 2.36.0 via ADD_CALENDAR URL parameter.",
                    "what_happened": "Unauthenticated SSRF in MagicMirror² Calendar module ≤ 2.36.0 via ADD_CALENDAR URL parameter.",
                    "cvss": 6.3,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:L/VI:N/SI:N/VA:N/SA:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-918",
                    "references": [
                        "https://sploitus.com/exploit?id=AB52C65C-61B5-5467-9449-496A92020833",
                        "https://github.com/hakaioffsec/CVE-2026-63642"
                    ],
                    "repository": "Sploitus",
                    "author": "hakaioffsec",
                    "first_seen": "2026-09-10T18:20:22",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=AB52C65C-61B5-5467-9449-496A92020833"
                },
                {
                    "title": "Exploit for CVE-2026-63642 CVE-2026-63642 CVE-2026-63643",
                    "summary": "Unauthenticated SSRF in MagicMirror² Calendar module ≤ 2.36.0 via ADD_CALENDAR URL parameter.",
                    "what_happened": "Unauthenticated SSRF in MagicMirror² Calendar module ≤ 2.36.0 via ADD_CALENDAR URL parameter.",
                    "cvss": 6.3,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/SC:L/VI:N/SI:N/VA:N/SA:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-918",
                    "references": [
                        "https://sploitus.com/exploit?id=AB52C65C-61B5-5467-9449-496A92020833",
                        "https://github.com/hakaioffsec/CVE-2026-63642"
                    ],
                    "repository": "hakaioffsec/CVE-2026-63642",
                    "author": "hakaioffsec",
                    "first_seen": "2026-09-10T18:20:22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://github.com/hakaioffsec/CVE-2026-63642"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=AB52C65C-61B5-5467-9449-496A92020833",
                "https://github.com/hakaioffsec/CVE-2026-63642",
                "https://github.com/MagicMirrorOrg/MagicMirror/commit/58c2a5e675a7d367b64d72e1d35680d202ff5c9f",
                "https://github.com/MagicMirrorOrg/MagicMirror/pull/4169",
                "https://github.com/MagicMirrorOrg/MagicMirror/releases/tag/v2.37.0",
                "https://github.com/MagicMirrorOrg/MagicMirror/security/advisories/GHSA-998g-7v5w-cr7g"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T16:20:22Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=AB52C65C-61B5-5467-9449-496A92020833"
                },
                {
                    "at": "2026-08-18T18:19:12.117",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63642"
                }
            ],
            "enrichment_checked_at": "2026-09-10T22:05:31Z",
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
            "id": "CVE-2026-63637",
            "vendor": "dgraph-io",
            "product": "dgraph",
            "title": "dgraph vulnerability",
            "summary": "Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted GraphQL query or mutation filters to inject DQL operators, disclose unintended nodes, or expand modification and deletion targets. This issue is fixed in version 25.3.8.",
            "updated_at": "2026-09-10T20:41:33.140",
            "published_at": "2026-08-06T22:18:12.330",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 25.3.8",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-943",
            "what_happened": "Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strings into generated DQL without quoting or validating the /pattern/flags form, allowing crafted GraphQL query or mutation filters to inject DQL operators, disclose unintended nodes, or expand modification and deletion targets. This issue is fixed in version 25.3.8.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/dgraph-io/dgraph/commit/aaff09ab9608f87d88e9d601e71d271306083392",
                "https://github.com/dgraph-io/dgraph/security/advisories/GHSA-33p8-wc97-5qcj"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:12.330",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63637"
                }
            ]
        },
        {
            "id": "CVE-2026-63622",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10.0 Extended Update Support",
            "title": "Red Hat Enterprise Linux 10.0 Extended Update Support vulnerability",
            "summary": "A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for privilege escalation from the `swtpm` sandbox to root-level file ownership control.",
            "updated_at": "2026-09-09T07:16:56.637",
            "published_at": "2026-08-10T21:17:23.550",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-59",
            "what_happened": "A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnerability in the `virFileChownFiles()` function. By planting a symbolic link within the `swtpm` state directory, the attacker could trick the root-level libvirt daemon into changing the ownership of an arbitrary file to the `swtpm` user. This allows for privilege escalation from the `swtpm` sandbox to root-level file ownership control.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:64773",
                "https://access.redhat.com/errata/RHSA-2026:65515",
                "https://access.redhat.com/errata/RHSA-2026:65516",
                "https://access.redhat.com/errata/RHSA-2026:65803",
                "https://access.redhat.com/security/cve/CVE-2026-63622",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2513065"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T21:17:23.550",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63622"
                }
            ]
        },
        {
            "id": "CVE-2026-63505",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Probo 0.222.2 -  IDOR",
            "summary": "Probo 0.222.2 -  IDOR",
            "updated_at": "2026-08-16T22:00:00Z",
            "published_at": "2026-08-16T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52650",
                    "author": "Jorge González Milla",
                    "first_seen": "2026-08-17",
                    "confidence": "High",
                    "title": "Probo 0.222.2 -  IDOR",
                    "summary": "Probo 0.222.2 -  IDOR",
                    "url": "https://www.exploit-db.com/exploits/52650",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52650"
            ],
            "timeline": [
                {
                    "at": "2026-08-16T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52650"
                }
            ]
        },
        {
            "id": "CVE-2026-63427",
            "vendor": "Lenovo",
            "product": "Software Fix",
            "title": "Software Fix vulnerability",
            "summary": "An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.",
            "updated_at": "2026-09-15T04:18:09.087",
            "published_at": "2026-09-10T21:17:28.347",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 7.6.2.10 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-290",
            "what_happened": "An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.lenovo.com/us/en/downloads/ds101291-rescue-and-smart-assistant-lmsa",
                "https://support.lenovo.com/us/en/product_security/LEN-217409"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T21:17:28.347",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63427"
                }
            ]
        },
        {
            "id": "CVE-2026-63376",
            "vendor": "BinaryMuse",
            "product": "toml-node",
            "title": "toml-node vulnerability",
            "summary": "toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Object.prototype. The currentPath tracking value uses both arrays and strings, so valueAssignments records a comma-joined path such as a,b.y while deepRef checks the dot-joined path a.b.y, allowing the duplicate-key guard to miss and attacker-controlled keys to be written to Object.prototype. A table-array prefix-clearing path in addTableArray can also erase guard state before the same __proto__ traversal. Injected properties become visible throughout the Node.js process and can cause denial of service, logic or authorization bypass, or code execution when an application contains a suitable gadget. This issue is fixed in version 4.1.2.",
            "updated_at": "2026-09-05T03:17:16.343",
            "published_at": "2026-09-03T21:17:21.513",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 4.1.2",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1321",
            "what_happened": "toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Object.prototype. The currentPath tracking value uses both arrays and strings, so valueAssignments records a comma-joined path such as a,b.y while deepRef checks the dot-joined path a.b.y, allowing the duplicate-key guard to miss and attacker-controlled keys to be written to Object.prototype. A table-array prefix-clearing path in addTableArray can also erase guard state before the same __proto__ traversal. Injected properties become visible throughout the Node.js process and can cause denial of service, logic or authorization bypass, or code execution when an application contains a suitable gadget. This issue is fixed in version 4.1.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/BinaryMuse/toml-node/commit/def6ab5ea99038c0dd482cd6af1745a6af8b4c44",
                "https://github.com/BinaryMuse/toml-node/commit/dfaff662276adc38a2e03df3139f7119b0185463",
                "https://github.com/BinaryMuse/toml-node/security/advisories/GHSA-v5mp-jgw5-2x6j"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T21:17:21.513",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63376"
                }
            ]
        },
        {
            "id": "CVE-2026-63310",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "summary": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "updated_at": "2026-09-15T00:16:57.827",
            "published_at": "2026-08-22T15:16:19.100",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [],
            "timeline": [
                {
                    "at": "2026-08-22T15:16:19.100",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63310"
                }
            ]
        },
        {
            "id": "CVE-2026-63300",
            "vendor": "Canonical",
            "product": "LXD",
            "title": "LXD vulnerability",
            "summary": "An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the instance's configuration against the target project's enforced restrictions (such as restricted.containers.lowlevel, restricted.devices.*, and restricted.networks.access). An attacker can exploit this by creating a disallowed or high-privilege instance in an unrestricted project and subsequently moving it into the restricted project.",
            "updated_at": "2026-09-11T15:21:14.557",
            "published_at": "2026-08-12T20:17:47.953",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "5.0.0 through before 5.0.8 (semver); 5.21.0 through before 5.21.6 (semver); 6.0 through before 6.10 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 43,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance between projects, LXD fails to validate the instance's configuration against the target project's enforced restrictions (such as restricted.containers.lowlevel, restricted.devices.*, and restricted.networks.access). An attacker can exploit this by creating a disallowed or high-privilege instance in an unrestricted project and subsequently moving it into the restricted project.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/canonical/lxd/pull/18605"
                },
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/canonical/lxd/security/advisories/GHSA-5g5r-wh97-qcq2"
                }
            ],
            "references": [
                "https://github.com/canonical/lxd/pull/18605",
                "https://github.com/canonical/lxd/pull/18651",
                "https://github.com/canonical/lxd/security/advisories/GHSA-5g5r-wh97-qcq2"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T20:17:47.953",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63300"
                }
            ]
        },
        {
            "id": "CVE-2026-63299",
            "vendor": "Canonical",
            "product": "LXD",
            "title": "LXD vulnerability",
            "summary": "An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot restore operations skip the AllowVolumeUpdate check when the configuration is nil (Config == nil). An attacker can exploit these flaws to allocate storage resources that exceed the administrative limits configured for a project.",
            "updated_at": "2026-09-11T15:26:06.753",
            "published_at": "2026-08-12T20:17:47.830",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "5.0.0 through before 5.0.8 (semver); 5.21.0 through before 5.21.6 (semver); 6.0 through before 6.10 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the limits.AllowVolumeCreation check before moving a volume across projects, and volume snapshot restore operations skip the AllowVolumeUpdate check when the configuration is nil (Config == nil). An attacker can exploit these flaws to allocate storage resources that exceed the administrative limits configured for a project.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/canonical/lxd/security/advisories/GHSA-5h78-p252-989h"
                }
            ],
            "references": [
                "https://github.com/canonical/lxd/security/advisories/GHSA-5h78-p252-989h"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T20:17:47.830",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63299"
                }
            ]
        },
        {
            "id": "CVE-2026-63298",
            "vendor": "Canonical",
            "product": "LXD",
            "title": "LXD vulnerability",
            "summary": "An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon.",
            "updated_at": "2026-09-11T15:20:11.603",
            "published_at": "2026-08-12T20:17:47.713",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "5.0.0 through before 5.0.8 (semver); 5.21.0 through before 5.21.6 (semver); 4.0.0 through before 4.0.12 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or 'nvidia.require.*' configuration values, an attacker can manipulate the generated lxc.conf file. This flaw enables the attacker to execute arbitrary code on the host system with the privileges of the LXD daemon.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/canonical/lxd/security/advisories/GHSA-vfh7-q59q-54v2"
                }
            ],
            "references": [
                "https://github.com/canonical/lxd/security/advisories/GHSA-vfh7-q59q-54v2"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T20:17:47.713",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63298"
                }
            ]
        },
        {
            "id": "CVE-2026-63297",
            "vendor": "Canonical",
            "product": "LXD",
            "title": "LXD vulnerability",
            "summary": "An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.",
            "updated_at": "2026-09-11T15:18:18.907",
            "published_at": "2026-08-12T20:17:47.583",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "5.0.0 through before 5.0.8 (semver); 5.21.0 through before 5.21.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-367",
            "what_happened": "An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction checks before configuration merging is complete, creating a time-of-check to time-of-use (TOCTOU) condition. An attacker can exploit this flaw to copy instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/canonical/lxd/security/advisories/GHSA-v989-qw7w-xvg4"
                }
            ],
            "references": [
                "https://github.com/canonical/lxd/security/advisories/GHSA-v989-qw7w-xvg4"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T20:17:47.583",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63297"
                }
            ]
        },
        {
            "id": "CVE-2026-63296",
            "vendor": "Canonical",
            "product": "LXD",
            "title": "LXD vulnerability",
            "summary": "An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.",
            "updated_at": "2026-09-11T15:15:30.017",
            "published_at": "2026-08-12T20:17:47.437",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "5.0.0 through before 5.0.8 (semver); 5.21.0 through before 5.21.6 (semver); 6.0 through before 6.10 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the target project's enforced restrictions. An attacker can exploit this flaw to move instances with disallowed high-privilege configurations into restricted projects, bypassing security controls.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625"
                }
            ],
            "references": [
                "https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T20:17:47.437",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63296"
                }
            ]
        },
        {
            "id": "CVE-2026-63295",
            "vendor": "Canonical",
            "product": "LXD",
            "title": "LXD vulnerability",
            "summary": "An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the security.idmap.isolated key. An attacker can exploit this flaw by creating or updating an instance without explicitly setting security.idmap.isolated, bypassing the target project's security constraints.",
            "updated_at": "2026-09-11T15:13:26.143",
            "published_at": "2026-08-12T20:17:47.303",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "4.0.0 through before 4.0.12 (semver); 5.0.0 through before 5.0.8 (semver); 5.21.0 through before 5.21.6 (semver); 6.0 through before 6.10 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing restricted.containers.privilege=isolated), LXD fails to enforce the requirement if an instance configuration omits the security.idmap.isolated key. An attacker can exploit this flaw by creating or updating an instance without explicitly setting security.idmap.isolated, bypassing the target project's security constraints.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/canonical/lxd/security/advisories/GHSA-7vp9-3vmp-c5jm"
                }
            ],
            "references": [
                "https://github.com/canonical/lxd/security/advisories/GHSA-7vp9-3vmp-c5jm"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T20:17:47.303",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63295"
                }
            ]
        },
        {
            "id": "CVE-2026-63294",
            "vendor": "Canonical",
            "product": "LXD",
            "title": "LXD vulnerability",
            "summary": "A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges.",
            "updated_at": "2026-09-11T15:11:30.647",
            "published_at": "2026-08-12T20:17:47.187",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "4.0.0 through before 4.0.12 (semver); 5.0.0 through before 5.0.8 (semver); 5.21.0 through before 5.21.6 (semver); 6.0 through before 6.10 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-59",
            "what_happened": "A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to process unconfined configuration metadata and execute arbitrary commands with root privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/canonical/lxd/security/advisories/GHSA-fv82-v4fj-mm4m"
                }
            ],
            "references": [
                "https://github.com/canonical/lxd/security/advisories/GHSA-fv82-v4fj-mm4m"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T20:17:47.187",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63294"
                }
            ]
        },
        {
            "id": "CVE-2026-63077",
            "vendor": "JetBrains",
            "product": "TeamCity",
            "title": "JetBrains TeamCity Deserialization of Untrusted Data Vulnerability",
            "summary": "JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.",
            "updated_at": "2026-08-04T22:00:00Z",
            "published_at": "2026-08-04T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-63076",
            "vendor": "OpenSSL",
            "product": "OpenSSL",
            "title": "OpenSSL vulnerability",
            "summary": "Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE.",
            "updated_at": "2026-09-11T21:17:12.460",
            "published_at": "2026-08-25T13:19:26.543",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.0.2 (semver); 3.6.0 through before 3.6.4 (semver); 3.5.0 through before 3.5.8 (semver); 3.4.0 through before 3.4.7 (semver); 3.0.0 through before 3.0.22 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "Issue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\n\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\n\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openssl/openssl/commit/37882aa2e0256e1072442a8f62f7db45b995c45b",
                "https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e",
                "https://github.com/openssl/openssl/commit/a1f348ccb328c3afbd4ba6883f9b7c813c043259",
                "https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226",
                "https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c",
                "https://openssl-library.org/news/secadv/20260825.txt"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T13:19:26.543",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63076"
                }
            ]
        },
        {
            "id": "CVE-2026-63075",
            "vendor": "OpenSSL",
            "product": "OpenSSL",
            "title": "OpenSSL vulnerability",
            "summary": "Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary.",
            "updated_at": "2026-09-11T21:17:05.403",
            "published_at": "2026-08-25T13:19:26.413",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.0.2 (semver); 3.6.0 through before 3.6.4 (semver); 3.5.0 through before 3.5.8 (semver); 3.4.0 through before 3.4.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\n\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many concurrent\nQUIC connections.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a connection, and\nthen drives the connection such that ACK-only packets are forced from the \nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\n\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually storing\nthe ACK-only packet metadata itself.\n\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc",
                "https://github.com/openssl/openssl/commit/7c98d79738549df92868e7dd9be4bbf061eed709",
                "https://github.com/openssl/openssl/commit/bf84721c2548351176e367e6de505792f0118dc6",
                "https://github.com/openssl/openssl/commit/c902e5f16d6a9e130e96d3ca6d8f64d71652e393",
                "https://openssl-library.org/news/secadv/20260825.txt"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T13:19:26.413",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63075"
                }
            ]
        },
        {
            "id": "CVE-2026-63074",
            "vendor": "OpenSSL",
            "product": "OpenSSL",
            "title": "OpenSSL vulnerability",
            "summary": "Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.",
            "updated_at": "2026-09-11T21:16:58.127",
            "published_at": "2026-08-25T13:19:26.283",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.0.2 (semver); 3.6.0 through before 3.6.4 (semver); 3.5.0 through before 3.5.8 (semver); 3.4.0 through before 3.4.7 (semver); 3.0.0 through before 3.0.22 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-770",
            "what_happened": "Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never expunges\nthem (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\n\nImpact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in the\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\n\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\n\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message remains\nin the server contexts untrusted certificate stack.  This exposes servers with\nlong lived ctx objects to Denial of Service attacks in which an attacker sends\nmessages intending to be rejected with a large list of additional certificates\nrepeatedly, forcing the server to store them indefinitely.\n   \nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\n\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7",
                "https://github.com/openssl/openssl/commit/21a5d9658b0c66daace60e10ea18ff32a448de9f",
                "https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46",
                "https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af",
                "https://github.com/openssl/openssl/commit/f636f9ca0fa1bae5b42f9e787f025c96fb09c43a",
                "https://openssl-library.org/news/secadv/20260825.txt"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T13:19:26.283",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63074"
                }
            ]
        },
        {
            "id": "CVE-2026-63073",
            "vendor": "OpenSSL",
            "product": "OpenSSL",
            "title": "OpenSSL vulnerability",
            "summary": "Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary.",
            "updated_at": "2026-09-11T21:16:45.633",
            "published_at": "2026-08-25T13:19:26.147",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.0.2 (semver); 3.6.0 through before 3.6.4 (semver); 3.5.0 through before 3.5.8 (semver); 3.4.0 through before 3.4.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-134",
            "what_happened": "Issue summary: OpenSSL CMP response validation passed an unexpected response\nsender distinguished name directly as the format string to `ERR_raise_data()`.\n\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP client\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\n\nCWE: CWE-134 (Use of Externally-Controlled Format String)\n\nDescription: When validating a received CMP message, ossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with X509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching variadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for a\nCMP client validating server responses.\n\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through unrelated\nstack contents and crash the client. The reliable consequence is a denial of\nservice, when the response comes from a malicious or intercepted CMP endpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable path\nto remote code execution.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openssl/openssl/commit/0cc20b322639919aa423e90799d9a57c3b4b76ca",
                "https://github.com/openssl/openssl/commit/6a0acc072b4d37a7cac1252a29c1ce1f00c5ec29",
                "https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21",
                "https://github.com/openssl/openssl/commit/a7e5a6eea8fd3ccca6b6fbba031a5fbf8a3d93b4",
                "https://openssl-library.org/news/secadv/20260825.txt"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T13:19:26.147",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63073"
                }
            ]
        },
        {
            "id": "CVE-2026-63072",
            "vendor": "OpenSSL",
            "product": "OpenSSL",
            "title": "OpenSSL vulnerability",
            "summary": "Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.",
            "updated_at": "2026-09-11T21:16:34.287",
            "published_at": "2026-08-25T13:19:26.010",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "review",
            "affected": "4.0.0 through before 4.0.2 (semver); 3.6.0 through before 3.6.4 (semver); 3.5.0 through before 3.5.8 (semver); 3.4.0 through before 3.4.7 (semver); 3.0.0 through before 3.0.22 (semver); 1.1.1 through before 1.1.1zi (custom)",
            "fixed": "See vendor advisory",
            "source_count": 44,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\n\nImpact summary: An attacker who supplies a crafted CMS message can trigger a\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\n\nCWE: CWE-787: Out-of-bounds Write\n\nDescription: The key-wrap OID is potentially attacker-controlled on the wire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\n\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\n\nFIPS impact: no\n\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · 0xBlackash/CVE-2026-63072",
                    "author": "0xBlackash",
                    "first_seen": "2026-08-26",
                    "last_seen": "2026-08-26T11:01:36Z",
                    "pushed_at": "2026-08-26T10:57:52Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Shell",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-63072",
                    "repository_description": "CVE-2026-63072",
                    "summary": "CVE-2026-63072",
                    "source": "CVE-Intel",
                    "url": "https://github.com/0xBlackash/CVE-2026-63072"
                }
            ],
            "references": [
                "https://github.com/0xBlackash/CVE-2026-63072",
                "https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756",
                "https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42",
                "https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335",
                "https://github.com/openssl/openssl/commit/9ec2f6d2ae2bcad907cf7ee38584855bafe4979a",
                "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382",
                "https://openssl-library.org/news/secadv/20260825.txt"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T13:19:26.010",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63072"
                }
            ]
        },
        {
            "id": "CVE-2026-63033",
            "vendor": "MZ Automation",
            "product": "lib60870",
            "title": "lib60870 vulnerability",
            "summary": "A crafted IEC 60870-5-104 I-frame with a declared object count exceeding\n what fits in the ASDU body causes InformationObject_ParseObjectAddress \nto read one byte past the end of the heap-allocated message buffer.",
            "updated_at": "2026-09-08T19:30:43.093",
            "published_at": "2026-07-30T23:16:51.917",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.4.0",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "A crafted IEC 60870-5-104 I-frame with a declared object count exceeding\n what fits in the ASDU body causes InformationObject_ParseObjectAddress \nto read one byte past the end of the heap-allocated message buffer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-11.json",
                "https://github.com/mz-automation/lib60870/security/advisories/GHSA-7v97-jmwv-w5j7",
                "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T23:16:51.917",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63033"
                }
            ]
        },
        {
            "id": "CVE-2026-63030",
            "vendor": "WordPress",
            "product": "Core",
            "title": "WordPress Core Interpretation Conflict Vulnerability",
            "summary": "WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.",
            "updated_at": "2026-08-26T12:50:28Z",
            "published_at": "2026-08-26T12:50:28Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 809,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · Icex0/wp2shell-poc",
                    "author": "Icex0",
                    "first_seen": "2026-07-17",
                    "last_seen": "2026-08-26T12:50:28Z",
                    "pushed_at": "2026-08-11T13:41:27Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 757,
                    "forks": 172,
                    "topics": [
                        "cve-2026-63030",
                        "wp2shell",
                        "wp2shell-poc"
                    ],
                    "title": "wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain",
                    "repository_description": "wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain",
                    "summary": "wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Icex0/wp2shell-poc"
                },
                {
                    "repository": "CVE-Intel · attackercan/wp2shell-poc2",
                    "author": "attackercan",
                    "first_seen": "2026-07-17",
                    "last_seen": "2026-08-25T20:05:25Z",
                    "pushed_at": "2026-07-17T22:50:06Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "Exploit",
                    "language": "",
                    "stars": 7,
                    "forks": 4,
                    "topics": [],
                    "title": "CVE-2026-63030",
                    "repository_description": "CVE-2026-63030",
                    "summary": "CVE-2026-63030",
                    "source": "CVE-Intel",
                    "url": "https://github.com/attackercan/wp2shell-poc2"
                },
                {
                    "repository": "CVE-Intel · 4minx/CVE-2026-63030",
                    "author": "4minx",
                    "first_seen": "2026-07-18",
                    "last_seen": "2026-08-25T14:16:07Z",
                    "pushed_at": "2026-07-18T13:40:45Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "Python",
                    "stars": 10,
                    "forks": 2,
                    "topics": [],
                    "title": "CVE-2026-63030 (wp2shell) POC.",
                    "repository_description": "CVE-2026-63030 (wp2shell) POC.",
                    "summary": "CVE-2026-63030 (wp2shell) POC.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/4minx/CVE-2026-63030"
                },
                {
                    "repository": "CVE-Intel · sowarma/wp2shell-PoC",
                    "author": "sowarma",
                    "first_seen": "2026-08-05",
                    "last_seen": "2026-08-25T10:09:59Z",
                    "pushed_at": "2026-08-20T10:15:52Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 914,
                    "forks": 215,
                    "topics": [
                        "cve",
                        "cve-2026-60137",
                        "cve-2026-63030",
                        "data-analysis",
                        "wp2shell",
                        "wp2shell-poc"
                    ],
                    "title": "CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept",
                    "repository_description": "CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept",
                    "summary": "CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept",
                    "source": "CVE-Intel",
                    "url": "https://github.com/sowarma/wp2shell-PoC"
                },
                {
                    "repository": "CVE-Intel · dinosn/wp2shell-lab",
                    "author": "dinosn",
                    "first_seen": "2026-07-18",
                    "last_seen": "2026-08-25T02:44:44Z",
                    "pushed_at": "2026-07-22T11:36:51Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Injection",
                    "language": "Python",
                    "stars": 59,
                    "forks": 21,
                    "topics": [
                        "cve-2026-60137",
                        "cve-2026-63030",
                        "security",
                        "sql-injection",
                        "vulnerability-lab",
                        "wordpress",
                        "wp2shell"
                    ],
                    "title": "Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1",
                    "repository_description": "Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1",
                    "summary": "Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1",
                    "source": "CVE-Intel",
                    "url": "https://github.com/dinosn/wp2shell-lab"
                },
                {
                    "repository": "CVE-Intel · Lutfifakee-Project/wp2shell",
                    "author": "Lutfifakee-Project",
                    "first_seen": "2026-07-18",
                    "last_seen": "2026-08-24T21:57:15Z",
                    "pushed_at": "2026-07-18T06:44:40Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 7,
                    "forks": 3,
                    "topics": [
                        "cve-2026-63030",
                        "exploit",
                        "python",
                        "rce",
                        "security-tools",
                        "sql-injection",
                        "unauthenticated",
                        "unauthenticated-rce"
                    ],
                    "title": "wp2shell - WordPress CVE-2026-63030 Exploit & Scanner",
                    "repository_description": "wp2shell - WordPress CVE-2026-63030 Exploit & Scanner",
                    "summary": "wp2shell - WordPress CVE-2026-63030 Exploit & Scanner",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Lutfifakee-Project/wp2shell"
                },
                {
                    "repository": "CVE-Intel · ZephrFish/wp2shell-scanner",
                    "author": "ZephrFish",
                    "first_seen": "2026-07-17",
                    "last_seen": "2026-08-23T13:14:52Z",
                    "pushed_at": "2026-07-18T22:07:34Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 55,
                    "forks": 11,
                    "topics": [],
                    "title": "CVE-2026-63030, CVE-2026-60137, wp2shell scanner",
                    "repository_description": "CVE-2026-63030, CVE-2026-60137, wp2shell scanner",
                    "summary": "CVE-2026-63030, CVE-2026-60137, wp2shell scanner",
                    "source": "CVE-Intel",
                    "url": "https://github.com/ZephrFish/wp2shell-scanner"
                },
                {
                    "repository": "CVE-Intel · InstaWP/wp2shell-scan",
                    "author": "InstaWP",
                    "first_seen": "2026-07-19",
                    "last_seen": "2026-08-22T11:56:04Z",
                    "pushed_at": "2026-07-21T08:22:34Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Shell",
                    "stars": 5,
                    "forks": 0,
                    "topics": [],
                    "title": "Detect & clean up wp2shell (CVE-2026-63030) WordPress compromise — bulk-runnable, read-only by default",
                    "repository_description": "Detect & clean up wp2shell (CVE-2026-63030) WordPress compromise — bulk-runnable, read-only by default",
                    "summary": "Detect & clean up wp2shell (CVE-2026-63030) WordPress compromise — bulk-runnable, read-only by default",
                    "source": "CVE-Intel",
                    "url": "https://github.com/InstaWP/wp2shell-scan"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/Icex0/wp2shell-poc",
                "https://github.com/attackercan/wp2shell-poc2",
                "https://github.com/4minx/CVE-2026-63030",
                "https://github.com/sowarma/wp2shell-PoC",
                "https://github.com/dinosn/wp2shell-lab",
                "https://github.com/Lutfifakee-Project/wp2shell",
                "https://github.com/ZephrFish/wp2shell-scanner",
                "https://github.com/InstaWP/wp2shell-scan"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T12:50:28Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-63020",
            "vendor": "F5",
            "product": "BIG-IP",
            "title": "BIG-IP vulnerability",
            "summary": "A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages \n\n\n\n\n\nImpact:\n\n\nAn attacker may trick authenticated BIG-IP users \ninto accessing malicious links and reflect a spoofed error message in \nthe victim's BIG-IP Configuration utility web browser session. This is a\n control plane issue; there is no data plane exposure.\n\n\n\n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
            "updated_at": "2026-09-15T18:19:18.243",
            "published_at": "2026-09-02T16:17:18.400",
            "cvss": 2.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "21.1.0 through before 21.1.0.1 (custom); 21.0.0 through before 21.0.0.3 (custom); 17.5.0 through before 17.5.1.8 (custom); 17.1.0 through before 17.1.3.4 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-451",
            "what_happened": "A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages \n\n\n\n\n\nImpact:\n\n\nAn attacker may trick authenticated BIG-IP users \ninto accessing malicious links and reflect a spoofed error message in \nthe victim's BIG-IP Configuration utility web browser session. This is a\n control plane issue; there is no data plane exposure.\n\n\n\n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://my.f5.com/manage/s/article/K000161728"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T16:17:18.400",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-63020"
                }
            ]
        },
        {
            "id": "CVE-2026-62999",
            "vendor": "copier-org",
            "product": "copier",
            "title": "copier vulnerability",
            "summary": "Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP server or Git transport decodes the path, allowing unsafe template features from a repository outside the trusted prefix to run after user interaction. This issue is fixed in version 9.17.0.",
            "updated_at": "2026-09-09T20:55:04.493",
            "published_at": "2026-07-31T20:16:53.523",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 9.5.0, <= 9.16.0",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-22",
            "what_happened": "Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP server or Git transport decodes the path, allowing unsafe template features from a repository outside the trusted prefix to run after user interaction. This issue is fixed in version 9.17.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/copier-org/copier/commit/7408f0d6287a7bf452715fd9f25dc54eaba3c295",
                "https://github.com/copier-org/copier/releases/tag/v9.17.0",
                "https://github.com/copier-org/copier/security/advisories/GHSA-34mv-rjq9-5mch"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T20:16:53.523",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62999"
                }
            ]
        },
        {
            "id": "CVE-2026-62959",
            "vendor": "coturn",
            "product": "coturn",
            "title": "coturn vulnerability",
            "summary": "Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when Coturn is started with --acme-redirect <URL> and exposes a plaintext-TCP listener, an unauthenticated remote client can send a single ordinary HTTP GET request and receive a 301 response whose Location header contains up to ~870 bytes of adjacent process heap memory. The leaked region is a recycled network receive buffer that is reused without being zeroed, so on a busy server it can contain data from other clients' requests (TURN credentials, OAuth tokens, relayed payloads). Root cause is a signed→unsigned conversion. This issue is fixed in version 4.15.0.",
            "updated_at": "2026-09-09T20:55:04.493",
            "published_at": "2026-07-31T20:16:53.357",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 4.5.2, < 4.15.0",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "Coturn is a free open source implementation of TURN and STUN Server. From 4.5.2 through 4.14.0, when Coturn is started with --acme-redirect <URL> and exposes a plaintext-TCP listener, an unauthenticated remote client can send a single ordinary HTTP GET request and receive a 301 response whose Location header contains up to ~870 bytes of adjacent process heap memory. The leaked region is a recycled network receive buffer that is reused without being zeroed, so on a busy server it can contain data from other clients' requests (TURN credentials, OAuth tokens, relayed payloads). Root cause is a signed→unsigned conversion. This issue is fixed in version 4.15.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/coturn/coturn/commit/960835886692fa04cf63ddd970c3f330740c87f4",
                "https://github.com/coturn/coturn/pull/1965",
                "https://github.com/coturn/coturn/releases/tag/4.15.0",
                "https://github.com/coturn/coturn/security/advisories/GHSA-m23x-5qf5-988g"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T20:16:53.357",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62959"
                }
            ]
        },
        {
            "id": "CVE-2026-62916",
            "vendor": "Microsoft",
            "product": "Microsoft Entra",
            "title": "Microsoft Entra vulnerability",
            "summary": "Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.",
            "updated_at": "2026-09-05T04:18:04.033",
            "published_at": "2026-09-03T23:17:19.693",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "-",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-288",
            "what_happened": "Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62916"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T23:17:19.693",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62916"
                }
            ]
        },
        {
            "id": "CVE-2026-62911",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "POC pre-auth RCE on Exchange",
            "summary": "POC pre-auth RCE on Exchange",
            "updated_at": "2026-08-26T12:03:50Z",
            "published_at": "2026-08-26T12:03:50Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 96,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · hypnguyen1209/CVE-2026-62911",
                    "author": "hypnguyen1209",
                    "first_seen": "2026-08-22",
                    "last_seen": "2026-08-26T12:03:50Z",
                    "pushed_at": "2026-08-22T04:49:54Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 24,
                    "forks": 3,
                    "topics": [
                        "cve-2026-62911"
                    ],
                    "title": "POC pre-auth RCE on Exchange",
                    "repository_description": "POC pre-auth RCE on Exchange",
                    "summary": "POC pre-auth RCE on Exchange",
                    "source": "CVE-Intel",
                    "url": "https://github.com/hypnguyen1209/CVE-2026-62911"
                }
            ],
            "references": [
                "https://github.com/hypnguyen1209/CVE-2026-62911"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T12:03:50Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/hypnguyen1209/CVE-2026-62911"
                }
            ]
        },
        {
            "id": "CVE-2026-62845",
            "vendor": "clastix",
            "product": "kamaji",
            "title": "kamaji vulnerability",
            "summary": "Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers. These fields have no format validation, so a value containing a quote character breaks out of the quoted identifier — SQL injection executed over Kamaji's root connection to the shared datastore. etcd driver is not affected.This issue is fixed in version 26.7.4-edge.",
            "updated_at": "2026-09-08T20:51:43.490",
            "published_at": "2026-07-30T22:16:55.457",
            "cvss": 4.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 26.6.4-edge",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers. These fields have no format validation, so a value containing a quote character breaks out of the quoted identifier — SQL injection executed over Kamaji's root connection to the shared datastore. etcd driver is not affected.This issue is fixed in version 26.7.4-edge.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/clastix/kamaji/commit/6a9f3e10ae408e7948e2aca2db694791a299e79c",
                "https://github.com/clastix/kamaji/releases/tag/26.7.4-edge",
                "https://github.com/clastix/kamaji/security/advisories/GHSA-r47v-ppwp-fh4r"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T22:16:55.457",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62845"
                }
            ]
        },
        {
            "id": "CVE-2026-62813",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.",
            "updated_at": "2026-09-09T05:17:27.053",
            "published_at": "2026-09-08T18:18:03.667",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62813"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:18:03.667",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62813"
                }
            ]
        },
        {
            "id": "CVE-2026-62810",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-09T04:18:03.090",
            "published_at": "2026-09-08T18:18:03.337",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62810"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:18:03.337",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62810"
                }
            ]
        },
        {
            "id": "CVE-2026-62759",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.",
            "updated_at": "2026-09-09T04:18:02.480",
            "published_at": "2026-09-08T18:17:58.917",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-290",
            "what_happened": "Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62759"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:17:58.917",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62759"
                }
            ]
        },
        {
            "id": "CVE-2026-62721",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-14T18:18:08.877",
            "published_at": "2026-08-11T17:18:22.870",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9418 (custom); 10.0.17763.0 through before 10.0.17763.9121 (custom); 10.0.19044.0 through before 10.0.19044.7663 (custom); 10.0.19045.0 through before 10.0.19045.7663 (custom); 10.0.22631.0 through before 10.0.22631.7517 (custom); 10.0.26100.0 through before 10.0.26100.9457 (custom); 10.0.26200.0 through before 10.0.26200.9457 (custom); 10.0.28000.0 through before 10.0.28000.2956 (custom); 6.2.9200.0 through before 6.2.9200.26280 (custom); 6.3.9600.0 through before 6.3.9600.23338 (custom); 10.0.20348.0 through before 10.0.20348.5499 (custom); 10.0.26100.0 through before 10.0.26100.33296 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-1220",
            "what_happened": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62721"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T17:18:22.870",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62721"
                }
            ]
        },
        {
            "id": "CVE-2026-62697",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 21H2",
            "title": "Windows 10 Version 21H2 vulnerability",
            "summary": "Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-09T04:18:01.897",
            "published_at": "2026-09-08T18:17:52.523",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62697"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:17:52.523",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62697"
                }
            ]
        },
        {
            "id": "CVE-2026-62694",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-09T05:17:26.543",
            "published_at": "2026-09-08T18:17:52.170",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62694"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:17:52.170",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62694"
                }
            ]
        },
        {
            "id": "CVE-2026-62420",
            "vendor": "Canonical",
            "product": "LXD",
            "title": "LXD vulnerability",
            "summary": "An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project.",
            "updated_at": "2026-09-11T14:32:59.620",
            "published_at": "2026-08-12T20:17:46.897",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "5.0.0 through before 5.0.8 (semver); 5.21.0 through before 5.21.6 (semver); 6.0 through before 6.10 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 24,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with migration: true, project: <target>, and target: <member>, the destination node skips all project restriction checks because the request arrives as an internal cluster notification. An attacker can exploit this to introduce disallowed instance configurations into a restricted project.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/canonical/lxd/security/advisories/GHSA-v9wr-9r7q-fh4g"
                }
            ],
            "references": [
                "https://github.com/canonical/lxd/pull/18605",
                "https://github.com/canonical/lxd/pull/18651",
                "https://github.com/canonical/lxd/security/advisories/GHSA-v9wr-9r7q-fh4g"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T20:17:46.897",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62420"
                }
            ]
        },
        {
            "id": "CVE-2026-62324",
            "vendor": "xdan",
            "product": "jodit",
            "title": "jodit vulnerability",
            "summary": "Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values before checking the scheme, allowing case variants, control-byte prefixes, and embedded tabs or newlines to bypass filtering and execute attacker-controlled script when a victim clicks a stored link rendered by an application. This issue is fixed in version 4.12.31.",
            "updated_at": "2026-09-09T20:55:04.493",
            "published_at": "2026-07-31T20:16:53.197",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 4.12.31",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElement method fails to use isDangerousUrl to normalize javascript: href values before checking the scheme, allowing case variants, control-byte prefixes, and embedded tabs or newlines to bypass filtering and execute attacker-controlled script when a victim clicks a stored link rendered by an application. This issue is fixed in version 4.12.31.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/xdan/jodit/commit/5fba6ef2381d151d7cb8e3c5ad0b9996af0f97b0",
                "https://github.com/xdan/jodit/releases/tag/4.12.31",
                "https://github.com/xdan/jodit/security/advisories/GHSA-j839-gqq4-gf9j"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T20:16:53.197",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62324"
                }
            ]
        },
        {
            "id": "CVE-2026-62246",
            "vendor": "clastix",
            "product": "kamaji",
            "title": "kamaji vulnerability",
            "summary": "Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with colliding normalized identifiers to share control-plane state and read, modify, or destroy another tenant's Kubernetes data. This issue is fixed in version 26.7.4-edge.",
            "updated_at": "2026-09-08T20:51:43.490",
            "published_at": "2026-07-30T22:16:55.300",
            "cvss": 8.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 26.7.4-edge",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-284",
            "what_happened": "Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and GetDefaultDatastoreUsername(), allowing distinct tenants with colliding normalized identifiers to share control-plane state and read, modify, or destroy another tenant's Kubernetes data. This issue is fixed in version 26.7.4-edge.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/clastix/kamaji/commit/4232a9df7ccd08075c26191f59566202042543a9",
                "https://github.com/clastix/kamaji/security/advisories/GHSA-4f3f-65vx-r34f"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T22:16:55.300",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62246"
                }
            ]
        },
        {
            "id": "CVE-2026-62196",
            "vendor": "OpenClaw",
            "product": "OpenClaw",
            "title": "OpenClaw vulnerability",
            "summary": "OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in the affected feature.",
            "updated_at": "2026-09-05T04:17:56.397",
            "published_at": "2026-07-13T22:16:51.243",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2026.3.22 through before 2026.6.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in the affected feature.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openclaw/openclaw/security/advisories/GHSA-fh38-965w-f6c3",
                "https://www.vulncheck.com/advisories/openclaw-authorization-bypass-via-whatsapp-group-ids"
            ],
            "timeline": [
                {
                    "at": "2026-07-13T22:16:51.243",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62196"
                }
            ]
        },
        {
            "id": "CVE-2026-61893",
            "vendor": "MZ Automation",
            "product": "lib60870",
            "title": "lib60870 vulnerability",
            "summary": "A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an \ninflated object count causes TestCommand_getFromBuffer to read one byte \npast the end of the heap-allocated message buffer.",
            "updated_at": "2026-09-08T19:30:43.093",
            "published_at": "2026-07-30T23:16:51.760",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.4.0",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an \ninflated object count causes TestCommand_getFromBuffer to read one byte \npast the end of the heap-allocated message buffer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-11.json",
                "https://github.com/mz-automation/lib60870/security/advisories/GHSA-g3w7-x5rx-83xm",
                "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-11"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T23:16:51.760",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61893"
                }
            ]
        },
        {
            "id": "CVE-2026-61876",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "LuCI DHCPv6 -  Lease Hostname Stored Cross-Site Scripting",
            "summary": "LuCI DHCPv6 -  Lease Hostname Stored Cross-Site Scripting",
            "updated_at": "2026-08-10T22:00:00Z",
            "published_at": "2026-08-10T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52637",
                    "author": "banyamer",
                    "first_seen": "2026-08-11",
                    "confidence": "High",
                    "title": "LuCI DHCPv6 -  Lease Hostname Stored Cross-Site Scripting",
                    "summary": "LuCI DHCPv6 -  Lease Hostname Stored Cross-Site Scripting",
                    "url": "https://www.exploit-db.com/exploits/52637",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52637"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52637"
                }
            ]
        },
        {
            "id": "CVE-2026-61802",
            "vendor": "wazuh",
            "product": "wazuh",
            "title": "wazuh vulnerability",
            "summary": "Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, a low-privilege API user can read the cleartext cluster key from a configuration endpoint that fails to redact it. The REST API provides a masking control, mask_sensitive_config, that redacts sensitive fields such as authd.pass and cluster.key from configuration responses for users who lack update-config permission, and every config-read endpoint carries this decorator except GET /cluster/local/config. That endpoint, backed by read_config_wrapper, is gated only by cluster:read and returns the local node's cluster configuration including the cleartext key, whereas its siblings return the same value masked. As a result, any account with the default readonly or cluster_readonly role, which is explicitly denied update-config precisely so it cannot view secrets, receives the real cluster key. Because the cluster key authenticates and encrypts traffic between cluster nodes, disclosing it to an unprivileged account provides the authentication precondition for the cluster-peer remote code execution chains established by prior advisories. This issue is fixed in version 4.14.",
            "updated_at": "2026-09-15T19:10:57.060",
            "published_at": "2026-08-28T02:16:21.907",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.14.0, < 4.14.7",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, a low-privilege API user can read the cleartext cluster key from a configuration endpoint that fails to redact it. The REST API provides a masking control, mask_sensitive_config, that redacts sensitive fields such as authd.pass and cluster.key from configuration responses for users who lack update-config permission, and every config-read endpoint carries this decorator except GET /cluster/local/config. That endpoint, backed by read_config_wrapper, is gated only by cluster:read and returns the local node's cluster configuration including the cleartext key, whereas its siblings return the same value masked. As a result, any account with the default readonly or cluster_readonly role, which is explicitly denied update-config precisely so it cannot view secrets, receives the real cluster key. Because the cluster key authenticates and encrypts traffic between cluster nodes, disclosing it to an unprivileged account provides the authentication precondition for the cluster-peer remote code execution chains established by prior advisories. This issue is fixed in version 4.14.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-28",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-chmg-89pf-2q82"
                }
            ],
            "references": [
                "https://github.com/wazuh/wazuh/commit/1c55af25ebb160bddbde591efc19bb77b01282e7",
                "https://github.com/wazuh/wazuh/security/advisories/GHSA-chmg-89pf-2q82"
            ],
            "timeline": [
                {
                    "at": "2026-08-28T02:16:21.907",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61802"
                }
            ]
        },
        {
            "id": "CVE-2026-61800",
            "vendor": "wazuh",
            "product": "wazuh",
            "title": "wazuh vulnerability",
            "summary": "Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to remote code execution as root. During cluster file synchronization, the non-merged branch of update_master_files_in_worker() moves each staged file to a destination derived only from safe_join(), which confines the path to /var/ossec but never verifies that the file lands in the directory declared by its cluster_item_key. Because the destination check present on the primary node and on the worker's merged branch was not applied, a peer can place files at attacker-chosen locations under /var/ossec, including paths that are executed as root, and the delete branch has the same gap. This is an incomplete fix for CVE-2026-30893, which addressed traversal outside /var/ossec but left this path able to redirect files anywhere within it. This issue is fixed in version 4.14.7.",
            "updated_at": "2026-09-15T19:12:34.260",
            "published_at": "2026-08-28T02:16:21.767",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.4.0, < 4.14.7",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to remote code execution as root. During cluster file synchronization, the non-merged branch of update_master_files_in_worker() moves each staged file to a destination derived only from safe_join(), which confines the path to /var/ossec but never verifies that the file lands in the directory declared by its cluster_item_key. Because the destination check present on the primary node and on the worker's merged branch was not applied, a peer can place files at attacker-chosen locations under /var/ossec, including paths that are executed as root, and the delete branch has the same gap. This is an incomplete fix for CVE-2026-30893, which addressed traversal outside /var/ossec but left this path able to redirect files anywhere within it. This issue is fixed in version 4.14.7.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-28",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-3jff-488g-335f"
                }
            ],
            "references": [
                "https://github.com/wazuh/wazuh/commit/f7f7c4d2d9e683c5d42e997fe7028a3fb2578853",
                "https://github.com/wazuh/wazuh/security/advisories/GHSA-3jff-488g-335f"
            ],
            "timeline": [
                {
                    "at": "2026-08-28T02:16:21.767",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61800"
                }
            ]
        },
        {
            "id": "CVE-2026-61797",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-61797",
            "summary": "Authenticated time-based blind SQL injection in GLPI PDF Plugin 4.1.2 enables data extraction.",
            "updated_at": "2026-09-14T17:11:41Z",
            "published_at": "2026-09-14T17:11:41Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 19,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Authenticated time-based blind SQL injection in GLPI PDF Plugin 4.1.2 enables data extraction.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-61797",
                    "summary": "Authenticated time-based blind SQL injection in GLPI PDF Plugin 4.1.2 enables data extraction.",
                    "what_happened": "Authenticated time-based blind SQL injection in GLPI PDF Plugin 4.1.2 enables data extraction.",
                    "cvss": 0,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=01F5352E-B308-56D5-BD2F-D2F155D0541B",
                        "https://github.com/itres-labs/CVE-2026-61797"
                    ],
                    "repository": "Sploitus",
                    "author": "itres-labs",
                    "first_seen": "2026-09-14T19:11:41",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=01F5352E-B308-56D5-BD2F-D2F155D0541B"
                },
                {
                    "title": "Exploit for CVE-2026-61797",
                    "summary": "Authenticated time-based blind SQL injection in GLPI PDF Plugin 4.1.2 enables data extraction.",
                    "what_happened": "Authenticated time-based blind SQL injection in GLPI PDF Plugin 4.1.2 enables data extraction.",
                    "cvss": 0,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=01F5352E-B308-56D5-BD2F-D2F155D0541B",
                        "https://github.com/itres-labs/CVE-2026-61797"
                    ],
                    "repository": "itres-labs/CVE-2026-61797",
                    "author": "itres-labs",
                    "first_seen": "2026-09-14T19:11:41",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/itres-labs/CVE-2026-61797"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=01F5352E-B308-56D5-BD2F-D2F155D0541B",
                "https://github.com/itres-labs/CVE-2026-61797"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T17:11:41Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=01F5352E-B308-56D5-BD2F-D2F155D0541B"
                }
            ],
            "enrichment_checked_at": "2026-09-14T22:05:30Z"
        },
        {
            "id": "CVE-2026-61783",
            "vendor": "wazuh",
            "product": "wazuh",
            "title": "wazuh vulnerability",
            "summary": "Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, an authenticated low-privilege user can read the cluster secret from the manager configuration because the logic that masks sensitive values is disabled by any update-config RBAC rule, including an explicit deny. The mask_sensitive_config() decorator applies masking only when _has_update_permissions() returns false, but that gate treats a user as able to update the config whenever a  manager:update_config  or  cluster:update_config  rule exists, without ever checking whether the rule's effect is allow or deny. Because a deny rule is stored as a real entry, a read-only account that is hardened by explicitly denying config edits is counted as having update permission, which turns masking off. A single authenticated GET request to the configuration endpoint with  raw=true  then returns the verbatim ossec.conf XML with  cluster.key  in clear, whereas an otherwise identical account without the deny rule sees the value masked. This issue is fixed in version 4.14.7.",
            "updated_at": "2026-09-15T19:13:26.400",
            "published_at": "2026-08-28T00:18:07.997",
            "cvss": 7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.14.0, < 4.14.7",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, an authenticated low-privilege user can read the cluster secret from the manager configuration because the logic that masks sensitive values is disabled by any update-config RBAC rule, including an explicit deny. The mask_sensitive_config() decorator applies masking only when _has_update_permissions() returns false, but that gate treats a user as able to update the config whenever a  manager:update_config  or  cluster:update_config  rule exists, without ever checking whether the rule's effect is allow or deny. Because a deny rule is stored as a real entry, a read-only account that is hardened by explicitly denying config edits is counted as having update permission, which turns masking off. A single authenticated GET request to the configuration endpoint with  raw=true  then returns the verbatim ossec.conf XML with  cluster.key  in clear, whereas an otherwise identical account without the deny rule sees the value masked. This issue is fixed in version 4.14.7.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-28",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-vjcq-cf36-f5gx"
                }
            ],
            "references": [
                "https://github.com/wazuh/wazuh/commit/939f2e52afff8fbeb7b0894f3f1417eb6c395db3",
                "https://github.com/wazuh/wazuh/security/advisories/GHSA-vjcq-cf36-f5gx"
            ],
            "timeline": [
                {
                    "at": "2026-08-28T00:18:07.997",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61783"
                }
            ]
        },
        {
            "id": "CVE-2026-61632",
            "vendor": "facelessuser",
            "product": "pymdown-extensions",
            "title": "pymdown-extensions vulnerability",
            "summary": "PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images referenced by <img src=\"...\"> by joining the src onto the configured base_path with os.path.normpath and opening the result directly, without verifying that the resolved path stays inside base_path. As a result, an src containing ../ sequences or an absolute path reads a file outside base_path as long as it has an allowed image extension (.png, .jpg, .jpeg, .gif, .svg), and the file's contents are then base64-encoded into the rendered output, disclosing them. An application that renders untrusted Markdown with pymdownx.b64 enabled can therefore leak the contents of image-extension files readable by the process to whoever controls the Markdown or views the output, a targeted file-read bounded by the extension check. This issue has been fixed in version 11.0.",
            "updated_at": "2026-09-10T20:41:33.140",
            "published_at": "2026-08-06T22:18:11.410",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 11.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vulnerable to a path traversal that discloses arbitrary files: it inlines images referenced by <img src=\"...\"> by joining the src onto the configured base_path with os.path.normpath and opening the result directly, without verifying that the resolved path stays inside base_path. As a result, an src containing ../ sequences or an absolute path reads a file outside base_path as long as it has an allowed image extension (.png, .jpg, .jpeg, .gif, .svg), and the file's contents are then base64-encoded into the rendered output, disclosing them. An application that renders untrusted Markdown with pymdownx.b64 enabled can therefore leak the contents of image-extension files readable by the process to whoever controls the Markdown or views the output, a targeted file-read bounded by the extension check. This issue has been fixed in version 11.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/facelessuser/pymdown-extensions/releases/tag/11.0",
                "https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-9xwg-3r6f-jcx2"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:11.410",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61632"
                }
            ]
        },
        {
            "id": "CVE-2026-61549",
            "vendor": "woodpecker-ci",
            "product": "woodpecker",
            "title": "woodpecker vulnerability",
            "summary": "Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pipeline-step value directly into the pod specification without administrator authorization. Any user with Push permission on a connected repository can therefore run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace and inherit that account's RBAC permissions. When a privileged ServiceAccount is reachable, the attacker can exfiltrate secrets such as database credentials, API keys, and TLS certificates and may take over the cluster. This issue is fixed in version 3.16.0.",
            "updated_at": "2026-09-16T04:18:37.707",
            "published_at": "2026-09-15T15:17:20.110",
            "cvss": 9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 1.0.0, < 3.16.0",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pipeline-step value directly into the pod specification without administrator authorization. Any user with Push permission on a connected repository can therefore run pipeline pods under an arbitrary ServiceAccount in the pipeline namespace and inherit that account's RBAC permissions. When a privileged ServiceAccount is reachable, the attacker can exfiltrate secrets such as database credentials, API keys, and TLS certificates and may take over the cluster. This issue is fixed in version 3.16.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/woodpecker-ci/woodpecker/commit/5df9d52260626c074c6caafb2dc83d3bc6b53be1",
                "https://github.com/woodpecker-ci/woodpecker/commit/609ba481b5e912f59aaae8ca7bc22b44523c5e37",
                "https://github.com/woodpecker-ci/woodpecker/pull/6792",
                "https://github.com/woodpecker-ci/woodpecker/releases/tag/v3.16.0",
                "https://github.com/woodpecker-ci/woodpecker/security/advisories/GHSA-qf34-295c-26v8"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T15:17:20.110",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61549"
                }
            ]
        },
        {
            "id": "CVE-2026-61526",
            "vendor": "adonisjs",
            "product": "http-server",
            "title": "http-server vulnerability",
            "summary": "AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.2, the  error.message is interpolated into the default HTML exception response without escaping, allowing a crafted missing-route URL to execute attacker-controlled JavaScript when a victim opens it and no custom status page or JSON response handles the error. When debug mode is disabled and no custom status page handles the error, the default HTML renderer interpolates error.message directly into an HTML response. This issue is fixed in versions 8.2.1 and 9.1.0.",
            "updated_at": "2026-09-10T20:31:16.483",
            "published_at": "2026-07-30T21:18:12.030",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 8.0.0-next.0, < 8.2.1; >= 9.0.0, < 9.1.0",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.2, the  error.message is interpolated into the default HTML exception response without escaping, allowing a crafted missing-route URL to execute attacker-controlled JavaScript when a victim opens it and no custom status page or JSON response handles the error. When debug mode is disabled and no custom status page handles the error, the default HTML renderer interpolates error.message directly into an HTML response. This issue is fixed in versions 8.2.1 and 9.1.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/adonisjs/http-server/commit/5d7465d599753b1fce8a36da18955f2c273e4f87",
                "https://github.com/adonisjs/http-server/commit/71a0a8e375c375e3588ba44ef68b0ef5a993c3d3",
                "https://github.com/adonisjs/http-server/releases/tag/v8.2.1",
                "https://github.com/adonisjs/http-server/releases/tag/v9.1.0",
                "https://github.com/adonisjs/http-server/security/advisories/GHSA-cwm9-gfhc-46f6"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T21:18:12.030",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61526"
                }
            ]
        },
        {
            "id": "CVE-2026-61524",
            "vendor": "WebsiteBaker Org e.V.",
            "product": "WebsiteBaker CMS",
            "title": "WebsiteBaker CMS vulnerability",
            "summary": "WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by uploading a crafted ZIP archive containing a PHP webshell alongside a valid info.php metadata file. Attackers can place the malicious archive through the module installation interface, causing the application to extract the webshell into a web-accessible modules/ subdirectory where it becomes immediately executable by any unauthenticated user via direct HTTP request.",
            "updated_at": "2026-09-09T20:40:01.933",
            "published_at": "2026-08-03T18:16:40.210",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.13.10 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by uploading a crafted ZIP archive containing a PHP webshell alongside a valid info.php metadata file. Attackers can place the malicious archive through the module installation interface, causing the application to extract the webshell into a web-accessible modules/ subdirectory where it becomes immediately executable by any unauthenticated user via direct HTTP request.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://addon.websitebaker.org/en/browse-add-ons/?type=5&cid=997",
                "https://medium.com/@benjaminasareagyapong2006/two-rce-vulnerabilities-i-found-on-my-birthday-evening-4563006a615a",
                "https://www.vulncheck.com/advisories/websitebaker-cms-file-upload-rce-via-module-installation"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T18:16:40.210",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61524"
                }
            ]
        },
        {
            "id": "CVE-2026-61523",
            "vendor": "WebsiteBaker Org e.V.",
            "product": "WebsiteBaker CMS",
            "title": "WebsiteBaker CMS vulnerability",
            "summary": "WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content through the droplet Code field, which is written verbatim to a publicly accessible PHP file with no content sanitization. Attackers can save a PHP webshell via the save_droplet handler to a predictable path inside the modules directory, enabling unauthenticated users to achieve remote code execution by making direct HTTP requests to the written file.",
            "updated_at": "2026-09-09T20:40:01.933",
            "published_at": "2026-08-03T18:16:40.053",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.13.10 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content through the droplet Code field, which is written verbatim to a publicly accessible PHP file with no content sanitization. Attackers can save a PHP webshell via the save_droplet handler to a predictable path inside the modules directory, enabling unauthenticated users to achieve remote code execution by making direct HTTP requests to the written file.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://addon.websitebaker.org/en/browse-add-ons/?type=5&cid=997",
                "https://medium.com/@benjaminasareagyapong2006/two-rce-vulnerabilities-i-found-on-my-birthday-evening-4563006a615a",
                "https://www.vulncheck.com/advisories/websitebaker-cms-code-injection-via-droplets-editor"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T18:16:40.053",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61523"
                }
            ]
        },
        {
            "id": "CVE-2026-61459",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "mcp-server-kubernetes 3.8.x - Argument Injection",
            "summary": "mcp-server-kubernetes 3.8.x - Argument Injection",
            "updated_at": "2026-08-10T22:00:00Z",
            "published_at": "2026-08-10T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52638",
                    "author": "banyamer",
                    "first_seen": "2026-08-11",
                    "confidence": "High",
                    "title": "mcp-server-kubernetes 3.8.x - Argument Injection",
                    "summary": "mcp-server-kubernetes 3.8.x - Argument Injection",
                    "url": "https://www.exploit-db.com/exploits/52638",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52638"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52638"
                }
            ]
        },
        {
            "id": "CVE-2026-61447",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "PraisonAI praisonaiagents  1.6.77 - Remote Code Execution",
            "summary": "PraisonAI praisonaiagents  1.6.77 - Remote Code Execution",
            "updated_at": "2026-08-10T22:00:00Z",
            "published_at": "2026-08-10T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52639",
                    "author": "banyamer",
                    "first_seen": "2026-08-11",
                    "confidence": "High",
                    "title": "PraisonAI praisonaiagents  1.6.77 - Remote Code Execution",
                    "summary": "PraisonAI praisonaiagents  1.6.77 - Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/52639",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52639"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52639"
                }
            ]
        },
        {
            "id": "CVE-2026-61410",
            "vendor": "Dell",
            "product": "Secure Connect Gateway 5.0 - Application",
            "title": "Secure Connect Gateway 5.0 - Application vulnerability",
            "summary": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. This vulnerability is considered critical because it allows an attacker to execute commands remotely on a target system by sending a specially crafted request to the application, bypassing intended restrictions on code execution.Dell recommends customers to upgrade at the earliest opportunity.",
            "updated_at": "2026-09-11T21:25:55.570",
            "published_at": "2026-09-07T13:20:33.853",
            "cvss": 9.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.36.00.00 or later (semver); before 5.36.00.16 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. This vulnerability is considered critical because it allows an attacker to execute commands remotely on a target system by sending a specially crafted request to the application, bypassing intended restrictions on code execution.Dell recommends customers to upgrade at the earliest opportunity.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T13:20:33.853",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-61410"
                }
            ]
        },
        {
            "id": "CVE-2026-60163",
            "vendor": "Oracle Corporation",
            "product": "MySQL Server",
            "title": "MySQL Server vulnerability",
            "summary": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
            "updated_at": "2026-09-15T04:18:08.553",
            "published_at": "2026-07-21T22:17:17.003",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.4.0-8.4.10; 9.7.0-9.7.1; 8.0.0-8.0.47",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and  9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.oracle.com/security-alerts/cpujul2026.html",
                "http://www.openwall.com/lists/oss-security/2026/09/15/1"
            ],
            "timeline": [
                {
                    "at": "2026-07-21T22:17:17.003",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-60163"
                }
            ]
        },
        {
            "id": "CVE-2026-60137",
            "vendor": "WordPress",
            "product": "Core",
            "title": "WordPress Core SQL Injection Vulnerability",
            "summary": "WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.",
            "updated_at": "2026-08-26T12:50:28Z",
            "published_at": "2026-08-26T12:50:28Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 809,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · Icex0/wp2shell-poc",
                    "author": "Icex0",
                    "first_seen": "2026-07-17",
                    "last_seen": "2026-08-26T12:50:28Z",
                    "pushed_at": "2026-08-11T13:41:27Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 757,
                    "forks": 172,
                    "topics": [
                        "cve-2026-63030",
                        "wp2shell",
                        "wp2shell-poc"
                    ],
                    "title": "wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain",
                    "repository_description": "wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain",
                    "summary": "wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Icex0/wp2shell-poc"
                },
                {
                    "repository": "CVE-Intel · sowarma/wp2shell-PoC",
                    "author": "sowarma",
                    "first_seen": "2026-08-05",
                    "last_seen": "2026-08-25T10:09:59Z",
                    "pushed_at": "2026-08-20T10:15:52Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 914,
                    "forks": 215,
                    "topics": [
                        "cve",
                        "cve-2026-60137",
                        "cve-2026-63030",
                        "data-analysis",
                        "wp2shell",
                        "wp2shell-poc"
                    ],
                    "title": "CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept",
                    "repository_description": "CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept",
                    "summary": "CVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept",
                    "source": "CVE-Intel",
                    "url": "https://github.com/sowarma/wp2shell-PoC"
                },
                {
                    "repository": "CVE-Intel · dinosn/wp2shell-lab",
                    "author": "dinosn",
                    "first_seen": "2026-07-18",
                    "last_seen": "2026-08-25T02:44:44Z",
                    "pushed_at": "2026-07-22T11:36:51Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Injection",
                    "language": "Python",
                    "stars": 59,
                    "forks": 21,
                    "topics": [
                        "cve-2026-60137",
                        "cve-2026-63030",
                        "security",
                        "sql-injection",
                        "vulnerability-lab",
                        "wordpress",
                        "wp2shell"
                    ],
                    "title": "Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1",
                    "repository_description": "Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1",
                    "summary": "Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1",
                    "source": "CVE-Intel",
                    "url": "https://github.com/dinosn/wp2shell-lab"
                },
                {
                    "repository": "CVE-Intel · ZephrFish/wp2shell-scanner",
                    "author": "ZephrFish",
                    "first_seen": "2026-07-17",
                    "last_seen": "2026-08-23T13:14:52Z",
                    "pushed_at": "2026-07-18T22:07:34Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 55,
                    "forks": 11,
                    "topics": [],
                    "title": "CVE-2026-63030, CVE-2026-60137, wp2shell scanner",
                    "repository_description": "CVE-2026-63030, CVE-2026-60137, wp2shell scanner",
                    "summary": "CVE-2026-63030, CVE-2026-60137, wp2shell scanner",
                    "source": "CVE-Intel",
                    "url": "https://github.com/ZephrFish/wp2shell-scanner"
                },
                {
                    "repository": "CVE-Intel · DeadExpl0it/wp2shell-poc",
                    "author": "DeadExpl0it",
                    "first_seen": "2026-08-21",
                    "last_seen": "2026-08-21T04:42:00Z",
                    "pushed_at": "2026-08-21T04:38:42Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "wp2shell — WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137",
                    "repository_description": "wp2shell — WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137",
                    "summary": "wp2shell — WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137",
                    "source": "CVE-Intel",
                    "url": "https://github.com/DeadExpl0it/wp2shell-poc"
                },
                {
                    "repository": "CVE-Intel · mhassani97/cve-2026-63030-lab",
                    "author": "mhassani97",
                    "first_seen": "2026-08-20",
                    "last_seen": "2026-08-20T12:27:20Z",
                    "pushed_at": "2026-08-20T12:26:35Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Dockerfile",
                    "stars": 0,
                    "forks": 1,
                    "topics": [],
                    "title": "wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain",
                    "repository_description": "wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain",
                    "summary": "wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain",
                    "source": "CVE-Intel",
                    "url": "https://github.com/mhassani97/cve-2026-63030-lab"
                },
                {
                    "repository": "CVE-Intel · TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-",
                    "author": "TranDongA3",
                    "first_seen": "2026-08-19",
                    "last_seen": "2026-08-19T08:42:32Z",
                    "pushed_at": "2026-08-19T08:41:57Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "PoC",
                    "language": "",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "POC-CVE-2026-63030-CVE-2026-60137-",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-"
                },
                {
                    "repository": "CVE-Intel · 0xsha/wp2shell",
                    "author": "0xsha",
                    "first_seen": "2026-07-18",
                    "last_seen": "2026-08-18T19:12:56Z",
                    "pushed_at": "2026-07-18T19:05:43Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 102,
                    "forks": 29,
                    "topics": [],
                    "title": "CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core",
                    "repository_description": "CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core",
                    "summary": "CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core",
                    "source": "CVE-Intel",
                    "url": "https://github.com/0xsha/wp2shell"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/Icex0/wp2shell-poc",
                "https://github.com/sowarma/wp2shell-PoC",
                "https://github.com/dinosn/wp2shell-lab",
                "https://github.com/ZephrFish/wp2shell-scanner",
                "https://github.com/DeadExpl0it/wp2shell-poc",
                "https://github.com/mhassani97/cve-2026-63030-lab",
                "https://github.com/TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-",
                "https://github.com/0xsha/wp2shell"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T12:50:28Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-60004",
            "vendor": "Gitea",
            "product": "Gitea",
            "title": "Gitea Code Injection Vulnerability",
            "summary": "Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.",
            "updated_at": "2026-08-26T12:17:30Z",
            "published_at": "2026-08-26T12:17:30Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 809,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · EQSTLab/CVE-2026-60004",
                    "author": "EQSTLab",
                    "first_seen": "2026-07-30",
                    "last_seen": "2026-08-26T12:17:30Z",
                    "pushed_at": "2026-08-19T07:07:11Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 1,
                    "forks": 0,
                    "topics": [],
                    "title": "Gitea diffpatch RCE",
                    "repository_description": "Gitea diffpatch RCE",
                    "summary": "Gitea diffpatch RCE",
                    "source": "CVE-Intel",
                    "url": "https://github.com/EQSTLab/CVE-2026-60004"
                },
                {
                    "repository": "CVE-Intel · fevar54/cve-2026-60004",
                    "author": "fevar54",
                    "first_seen": "2026-08-25",
                    "last_seen": "2026-08-25T22:18:31Z",
                    "pushed_at": "2026-08-25T18:15:36Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [
                        "cve-pocs"
                    ],
                    "title": "CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.",
                    "repository_description": "CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.",
                    "summary": "CVE-2026-60004 es una vulnerabilidad crítica (CVSS 9.8) en Gitea que permite ejecución remota de código sin autenticación mediante el endpoint `/api/v1/repos/{owner}/{repo}/diffpatch`.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/fevar54/cve-2026-60004"
                },
                {
                    "repository": "CVE-Intel · imbas007/CVE-2026-60004-POC",
                    "author": "imbas007",
                    "first_seen": "2026-08-03",
                    "last_seen": "2026-08-21T10:55:39Z",
                    "pushed_at": "2026-08-03T08:31:38Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 15,
                    "forks": 6,
                    "topics": [
                        "1day",
                        "cve",
                        "cve-2026-60004",
                        "exploit",
                        "gitea",
                        "nuclei",
                        "nuclei-template",
                        "poc"
                    ],
                    "title": "CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)",
                    "repository_description": "CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)",
                    "summary": "CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)",
                    "source": "CVE-Intel",
                    "url": "https://github.com/imbas007/CVE-2026-60004-POC"
                },
                {
                    "repository": "CVE-Intel · gagaltotal/CVE-2026-60004-poc-gitea",
                    "author": "gagaltotal",
                    "first_seen": "2026-08-08",
                    "last_seen": "2026-08-11T14:33:28Z",
                    "pushed_at": "2026-08-08T16:41:43Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Go",
                    "stars": 2,
                    "forks": 0,
                    "topics": [
                        "auth",
                        "gitea",
                        "gitea-api",
                        "go",
                        "golang",
                        "golang-cli",
                        "rce",
                        "rce-exploit"
                    ],
                    "title": "CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection",
                    "repository_description": "CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection",
                    "summary": "CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection",
                    "source": "CVE-Intel",
                    "url": "https://github.com/gagaltotal/CVE-2026-60004-poc-gitea"
                },
                {
                    "repository": "CVE-Intel · Sachinart/CVE-2026-60004-gitea-0day",
                    "author": "Sachinart",
                    "first_seen": "2026-08-04",
                    "last_seen": "2026-08-04T22:54:53Z",
                    "pushed_at": "2026-08-04T22:54:40Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE",
                    "repository_description": "CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE",
                    "summary": "CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Sachinart/CVE-2026-60004-gitea-0day"
                },
                {
                    "repository": "CVE-Intel · HackSpeak/CVE-2026-60004",
                    "author": "HackSpeak",
                    "first_seen": "2026-08-04",
                    "last_seen": "2026-08-04T12:32:10Z",
                    "pushed_at": "2026-08-04T12:31:49Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 1,
                    "forks": 0,
                    "topics": [],
                    "title": "Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account",
                    "repository_description": "Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account",
                    "summary": "Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account",
                    "source": "CVE-Intel",
                    "url": "https://github.com/HackSpeak/CVE-2026-60004"
                },
                {
                    "repository": "CVE-Intel · shinthink/CVE-2026-60004",
                    "author": "shinthink",
                    "first_seen": "2026-08-03",
                    "last_seen": "2026-08-03T12:49:46Z",
                    "pushed_at": "2026-08-03T12:47:22Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [
                        "code-injection",
                        "cve",
                        "cve-2026-60004",
                        "exploit",
                        "forgejo",
                        "git",
                        "gitea",
                        "hook"
                    ],
                    "title": "CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1",
                    "repository_description": "CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1",
                    "summary": "CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1",
                    "source": "CVE-Intel",
                    "url": "https://github.com/shinthink/CVE-2026-60004"
                },
                {
                    "repository": "CVE-Intel · HORKimhab/CVE-2026-60004",
                    "author": "HORKimhab",
                    "first_seen": "2026-07-29",
                    "last_seen": "2026-07-31T17:19:06Z",
                    "pushed_at": "2026-07-29T08:45:51Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 4,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-60004",
                    "repository_description": "CVE-2026-60004",
                    "summary": "CVE-2026-60004",
                    "source": "CVE-Intel",
                    "url": "https://github.com/HORKimhab/CVE-2026-60004"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/EQSTLab/CVE-2026-60004",
                "https://github.com/fevar54/cve-2026-60004",
                "https://github.com/imbas007/CVE-2026-60004-POC",
                "https://github.com/gagaltotal/CVE-2026-60004-poc-gitea",
                "https://github.com/Sachinart/CVE-2026-60004-gitea-0day",
                "https://github.com/HackSpeak/CVE-2026-60004",
                "https://github.com/shinthink/CVE-2026-60004",
                "https://github.com/HORKimhab/CVE-2026-60004"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T12:17:30Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-59827",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Metabase 0.61.0  - Authenticated Remote Code Execution",
            "summary": "Metabase 0.61.0  - Authenticated Remote Code Execution",
            "updated_at": "2026-09-02T22:00:00Z",
            "published_at": "2026-09-02T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 98,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52680",
                    "author": "Gutierre0x80",
                    "first_seen": "2026-09-03",
                    "confidence": "High",
                    "title": "Metabase 0.61.0  - Authenticated Remote Code Execution",
                    "summary": "Metabase 0.61.0  - Authenticated Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/52680",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52680"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52680"
                }
            ]
        },
        {
            "id": "CVE-2026-59822",
            "vendor": "BerriAI",
            "product": "LiteLLM",
            "title": "BerriAI LiteLLM Improper Authentication Vulnerability",
            "summary": "BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 50,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-59696",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade availability by supplying a URI whose port component is a very long run of digits.\n\nuri_string:get_port/1 passes the port substring to binary_to_integer/1 with no length bound, catching only error:badarg, so a syntactically valid port of up to roughly 1.26 million digits converts successfully and costs the calling process hundreds of milliseconds of arbitrary-precision arithmetic. The conversion is reached from every authority-parsing path in uri_string:parse/1, including the host, registered-name, and IPv4 and IPv6 forms. parse/1 is the documented interface for parsing URIs, so any application that parses an attacker-supplied URI is exposed without further configuration. The conversion function is documented to accept integers of any size, so bounding the input is the caller's responsibility.\n\nThis issue affects OTP from OTP 21.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to stdlib from 3.5 before 6.2.2.5, from 7.0 before 7.3.0.2, and from 8.0 before 8.0.4.",
            "updated_at": "2026-09-08T01:17:51.663",
            "published_at": "2026-09-01T15:17:22.250",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "21.0 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 3.5 through before 6.2.2.5 (otp); 7.0 through before 7.3.0.2 (otp); 8.0 through before 8.0.4 (otp); 29a9dd0e17a97a3e6e46f0d08c6ba8f31db33f5e through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1284",
            "what_happened": "Improper Validation of Specified Quantity in Input vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade availability by supplying a URI whose port component is a very long run of digits.\n\nuri_string:get_port/1 passes the port substring to binary_to_integer/1 with no length bound, catching only error:badarg, so a syntactically valid port of up to roughly 1.26 million digits converts successfully and costs the calling process hundreds of milliseconds of arbitrary-precision arithmetic. The conversion is reached from every authority-parsing path in uri_string:parse/1, including the host, registered-name, and IPv4 and IPv6 forms. parse/1 is the documented interface for parsing URIs, so any application that parses an attacker-supplied URI is exposed without further configuration. The conversion function is documented to accept integers of any size, so bounding the input is the caller's responsibility.\n\nThis issue affects OTP from OTP 21.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to stdlib from 3.5 before 6.2.2.5, from 7.0 before 7.3.0.2, and from 8.0 before 8.0.4.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-59696.html",
                "https://github.com/erlang/otp/commit/aba0fe8c2d700bf4ac94607cf7f00e53bbe4042d",
                "https://github.com/erlang/otp/commit/e3be1cfe9f6cedd0cd20d9905e05601dfb31c8aa",
                "https://github.com/erlang/otp/security/advisories/GHSA-8qw4-2chm-mvj2",
                "https://osv.dev/vulnerability/EEF-CVE-2026-59696",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:22.250",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59696"
                }
            ]
        },
        {
            "id": "CVE-2026-59643",
            "vendor": "Legion of the Bouncy Castle Inc.",
            "product": "BC-JAVA",
            "title": "BC-JAVA vulnerability",
            "summary": "In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.",
            "updated_at": "2026-09-10T19:02:52.073",
            "published_at": "2026-08-03T01:16:44.333",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.81 through before 1.85 (maven); 2.0.12 through before 2.0.13 (maven)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-347",
            "what_happened": "In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 2.0.13.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/bcgit/bc-java/commit/d3f8cc408b4a36d28e5a410c93436fe3d0fe726b",
                "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059643"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T01:16:44.333",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59643"
                }
            ]
        },
        {
            "id": "CVE-2026-59569",
            "vendor": "Zscaler",
            "product": "Client Connector",
            "title": "Client Connector vulnerability",
            "summary": "An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.",
            "updated_at": "2026-09-15T04:18:07.997",
            "published_at": "2026-09-14T15:17:06.603",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before Android: 4.2.0.152 (custom); before ChromeOS: 4.2.0.152 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T15:17:06.603",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59569"
                }
            ]
        },
        {
            "id": "CVE-2026-59346",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-59346",
            "summary": "Proof-of-concept exploit for CVE-2026-59346.",
            "updated_at": "2026-09-15T11:11:39Z",
            "published_at": "2026-09-15T11:11:39Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-59346",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 0,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=0F791A8F-6EAD-5EAB-8510-775EC1066789",
                        "https://github.com/0xCyberstan/CVE-2026-59346-POC"
                    ],
                    "repository": "Sploitus",
                    "author": "0xCyberstan",
                    "first_seen": "2026-09-15T11:13:48",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=0F791A8F-6EAD-5EAB-8510-775EC1066789"
                },
                {
                    "title": "Exploit for CVE-2026-59346",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 0,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=0F791A8F-6EAD-5EAB-8510-775EC1066789",
                        "https://github.com/0xCyberstan/CVE-2026-59346-POC"
                    ],
                    "repository": "0xCyberstan/CVE-2026-59346-POC",
                    "author": "0xCyberstan",
                    "first_seen": "2026-09-15T11:13:48",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/0xCyberstan/CVE-2026-59346-POC"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=0F791A8F-6EAD-5EAB-8510-775EC1066789",
                "https://github.com/0xCyberstan/CVE-2026-59346-POC"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T11:11:39Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=0F791A8F-6EAD-5EAB-8510-775EC1066789"
                }
            ]
        },
        {
            "id": "CVE-2026-59326",
            "vendor": "Spring",
            "product": "Spring Tools for Eclipse",
            "title": "Spring Tools for Eclipse vulnerability",
            "summary": "The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form http://user:pass@proxy:8080, and the language server writes this value to its log file without any redaction. Since language server log files are often attached to bug reports or are readable by other local users/processes, this can result in disclosure of proxy credentials.\nAffected Spring Products and Versions:\nSpring Tools for Eclipse: 5.2.0 and earlier\nSpring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier",
            "updated_at": "2026-09-08T20:06:39.910",
            "published_at": "2026-07-30T06:25:55.677",
            "cvss": 3.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 5.2.0 (custom); 0 through 2.2.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-532",
            "what_happened": "The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form http://user:pass@proxy:8080, and the language server writes this value to its log file without any redaction. Since language server log files are often attached to bug reports or are readable by other local users/processes, this can result in disclosure of proxy credentials.\nAffected Spring Products and Versions:\nSpring Tools for Eclipse: 5.2.0 and earlier\nSpring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://spring.io/security/cve-2026-59326"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T06:25:55.677",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59326"
                }
            ]
        },
        {
            "id": "CVE-2026-59310",
            "vendor": "Broadcom",
            "product": "VMware vCenter",
            "title": "Broadcom VMware vCenter Path Traversal Vulnerability",
            "summary": "Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.",
            "updated_at": "2026-08-17T22:00:00Z",
            "published_at": "2026-08-17T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-59250",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a single text-encoded H.248/Megaco message containing an oversized property parm name.\n\nWhen tokenizing a Local/Remote descriptor, mfs_load_property_groups extracts the attacker-controlled property name (bounded only by the message length) and, when no value follows, formats it into a fixed 512-byte error_msg field of the MfsErlDrvData struct using an unchecked sprintf call. Names longer than roughly 452 bytes overflow into the immediately following struct fields (text_buf, text_ptr, term_spec, term_spec_size, term_spec_index), overwriting live pointers and counters with attacker-chosen bytes. Subsequent scanner code writes and frees through the corrupted pointers, producing arbitrary write and arbitrary free primitives inside the BEAM VM process, which can be leveraged for remote code execution. On builds compiled with _FORTIFY_SOURCE the overflow is detected at runtime and terminates the process with SIGABRT, resulting in denial of service.\n\nThe overflow occurs in the flex scanner before any grammar or Megaco-level authentication processing, so exploitation requires only network reachability to the megaco transport port on a node configured with {scanner, flex}.\n\nThis vulnerability is associated with program files lib/megaco/src/flex/megaco_flex_scanner_drv.flex.src and program routines mfs_load_property_groups.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.15, from OTP 28.0 before OTP 28.5.0.4, and from OTP 29.0 before OTP 29.0.4, corresponding to megaco from 3.17.1 before 4.7.2.2, from 4.8 before 4.8.3.1, and from 4.9 before 4.9.1. Whether OTP before OTP 17.0, corresponding to megaco before 3.17.1, is affected is unknown.",
            "updated_at": "2026-09-08T01:17:51.410",
            "published_at": "2026-07-27T16:18:03.330",
            "cvss": 8.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.15 (otp); 28.0 through before 28.5.0.4 (otp); 29.0 through before 29.0.4 (otp); 3.17.1 through before 4.7.2.2 (otp); 4.8 through before 4.8.3.1 (otp); 4.9 through before 4.9.1 (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before 8704c8f550a11ed5f825e3c011ecb03565b79c4f (git)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a single text-encoded H.248/Megaco message containing an oversized property parm name.\n\nWhen tokenizing a Local/Remote descriptor, mfs_load_property_groups extracts the attacker-controlled property name (bounded only by the message length) and, when no value follows, formats it into a fixed 512-byte error_msg field of the MfsErlDrvData struct using an unchecked sprintf call. Names longer than roughly 452 bytes overflow into the immediately following struct fields (text_buf, text_ptr, term_spec, term_spec_size, term_spec_index), overwriting live pointers and counters with attacker-chosen bytes. Subsequent scanner code writes and frees through the corrupted pointers, producing arbitrary write and arbitrary free primitives inside the BEAM VM process, which can be leveraged for remote code execution. On builds compiled with _FORTIFY_SOURCE the overflow is detected at runtime and terminates the process with SIGABRT, resulting in denial of service.\n\nThe overflow occurs in the flex scanner before any grammar or Megaco-level authentication processing, so exploitation requires only network reachability to the megaco transport port on a node configured with {scanner, flex}.\n\nThis vulnerability is associated with program files lib/megaco/src/flex/megaco_flex_scanner_drv.flex.src and program routines mfs_load_property_groups.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.15, from OTP 28.0 before OTP 28.5.0.4, and from OTP 29.0 before OTP 29.0.4, corresponding to megaco from 3.17.1 before 4.7.2.2, from 4.8 before 4.8.3.1, and from 4.9 before 4.9.1. Whether OTP before OTP 17.0, corresponding to megaco before 3.17.1, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-59250.html",
                "https://github.com/erlang/otp/commit/8704c8f550a11ed5f825e3c011ecb03565b79c4f",
                "https://github.com/erlang/otp/security/advisories/GHSA-7xgh-gmgf-q2g7",
                "https://osv.dev/vulnerability/EEF-CVE-2026-59250",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T16:18:03.330",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59250"
                }
            ]
        },
        {
            "id": "CVE-2026-59247",
            "vendor": "gleam-lang",
            "product": "gleam",
            "title": "gleam vulnerability",
            "summary": "Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute forged Hex package contents during dependency resolution.\n\nDuring dependency resolution Gleam fetches package metadata from the signature-verified Hex repository, which covers each release's dependency requirements and SHA-256 outer_checksum. After resolving versions, gleam_cli::dependencies::lookup_package makes a second request to the unsigned Hex API through gleam_core::hex::get_package_release and records the outer_checksum and dependency names from that JSON response into manifest.toml, instead of the values from the verified repository metadata. The Hex repository signature does not cover the API response.\n\nAn adversary in the middle who can intercept TLS with a certificate trusted by the Gleam process (for example a TLS-inspecting proxy using a CA in the operating system trust store or added through GLEAM_CACERTS_PATH), and who can modify both the API release response and the corresponding repository tarball, can supply a package archive with a matching forged checksum without the Hex repository signing key. Gleam verifies the forged tarball against the forged checksum, accepts it, and extracts it as a dependency source, resulting in loss of integrity of the downloaded package contents.\n\nOnly projects that resolve or update Hex dependencies are affected, which happens when the manifest is missing, a dependency is added or updated, or dependency requirements change. Builds that reuse an unchanged, known-good manifest.toml continue to verify tarballs against its pinned checksum. This issue affects gleam: from 0.18.0 before 1.18.0.",
            "updated_at": "2026-09-08T01:17:51.207",
            "published_at": "2026-07-29T15:16:26.780",
            "cvss": 7.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.18.0 through before 1.18.0 (semver); 8447b78cc844ff4aec44eea23dbd68d1fea11f11 through before c9c0d48c123c8abae6db8dd61b25ccb427ed3d35 (git); v0.18.0-elixir through before v1.18.0-elixir (other); v0.18.0-elixir-slim through before v1.18.0-elixir-slim (other); v0.18.0-elixir-alpine through before v1.18.0-elixir-alpine (other); v0.18.0-erlang through before v1.18.0-erlang (other); v0.18.0-erlang-slim through before v1.18.0-erlang-slim (other); v0.18.0-erlang-alpine through before v1.18.0-erlang-alpine (other); v0.18.0-node through before v1.18.0-node (other); v0.18.0-node-slim through before v1.18.0-node-slim (other); v0.18.0-node-alpine through before v1.18.0-node-alpine (other); v1.6.0-scratch through before v1.18.0-scratch (other)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-345",
            "what_happened": "Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute forged Hex package contents during dependency resolution.\n\nDuring dependency resolution Gleam fetches package metadata from the signature-verified Hex repository, which covers each release's dependency requirements and SHA-256 outer_checksum. After resolving versions, gleam_cli::dependencies::lookup_package makes a second request to the unsigned Hex API through gleam_core::hex::get_package_release and records the outer_checksum and dependency names from that JSON response into manifest.toml, instead of the values from the verified repository metadata. The Hex repository signature does not cover the API response.\n\nAn adversary in the middle who can intercept TLS with a certificate trusted by the Gleam process (for example a TLS-inspecting proxy using a CA in the operating system trust store or added through GLEAM_CACERTS_PATH), and who can modify both the API release response and the corresponding repository tarball, can supply a package archive with a matching forged checksum without the Hex repository signing key. Gleam verifies the forged tarball against the forged checksum, accepts it, and extracts it as a dependency source, resulting in loss of integrity of the downloaded package contents.\n\nOnly projects that resolve or update Hex dependencies are affected, which happens when the manifest is missing, a dependency is added or updated, or dependency requirements change. Builds that reuse an unchanged, known-good manifest.toml continue to verify tarballs against its pinned checksum. This issue affects gleam: from 0.18.0 before 1.18.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-59247.html",
                "https://github.com/gleam-lang/gleam/commit/c9c0d48c123c8abae6db8dd61b25ccb427ed3d35",
                "https://github.com/gleam-lang/gleam/security/advisories/GHSA-4vvc-458m-r82g",
                "https://github.com/hexpm/specifications/blob/main/registry-v2.md",
                "https://osv.dev/vulnerability/EEF-CVE-2026-59247"
            ],
            "timeline": [
                {
                    "at": "2026-07-29T15:16:26.780",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59247"
                }
            ]
        },
        {
            "id": "CVE-2026-59245",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow FAB provider",
            "title": "Apache Airflow FAB provider vulnerability",
            "summary": "In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named `DAGs` exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.2 or later, which disambiguates the resource-name collision.",
            "updated_at": "2026-09-16T15:17:39.437",
            "published_at": "2026-07-13T16:16:41.880",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.7.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named `DAGs` exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.2 or later, which disambiguates the resource-name collision.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/69106",
                "https://lists.apache.org/thread/70f37q3mwov1vm3zolrfxlzds278c78h",
                "http://www.openwall.com/lists/oss-security/2026/07/13/4"
            ],
            "timeline": [
                {
                    "at": "2026-07-13T16:16:41.880",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59245"
                }
            ]
        },
        {
            "id": "CVE-2026-59244",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.",
            "updated_at": "2026-09-16T15:17:39.273",
            "published_at": "2026-08-12T16:17:09.197",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-312",
            "what_happened": "Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an `isinstance(str)` guard — so a secret stored as a JSON Variable and referenced in a template via `var.json` was displayed in cleartext to any user with access to that task's Rendered Templates view. Users are advised to upgrade to apache-airflow 3.3.1 or later, which masks nested Variable values regardless of type.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/68975",
                "https://lists.apache.org/thread/fncod6vttfo5fvmfs3h9r8s2kmm9j1n6",
                "http://www.openwall.com/lists/oss-security/2026/08/12/7"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:09.197",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59244"
                }
            ]
        },
        {
            "id": "CVE-2026-59243",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow FAB provider",
            "title": "Apache Airflow FAB provider vulnerability",
            "summary": "The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True`. This issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.3, which defaults `verify_signature=True`.",
            "updated_at": "2026-09-16T15:17:39.093",
            "published_at": "2026-07-29T10:16:44.390",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.7.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-347",
            "what_happened": "The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one holding the Admin role (CWE-347). Deployments running the FAB auth manager with the Azure AD OAuth login path under its default configuration are affected; the Authentik path already defaulted to `True`. This issue affects `apache-airflow-providers-fab` before 3.7.3. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.3, which defaults `verify_signature=True`.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/69374",
                "https://lists.apache.org/thread/x4784l7z00tl3gw4tv2dmvoon77rxgpl",
                "http://www.openwall.com/lists/oss-security/2026/07/28/10"
            ],
            "timeline": [
                {
                    "at": "2026-07-29T10:16:44.390",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59243"
                }
            ]
        },
        {
            "id": "CVE-2026-59242",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access to instantiate arbitrary `airflow.*` classes on the API server (CWE-502). An authenticated user who can write an XCom value and then read it back with `deserialize=true` triggers the unsafe instantiation. Users are advised to upgrade to apache-airflow 3.3.1 or later, which rejects reserved XCom serialization keys submitted as JSON string literals.",
            "updated_at": "2026-09-16T15:17:38.930",
            "published_at": "2026-08-12T16:17:09.067",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_value` without the `_check_forbidden_xcom_keys` guard, allowing an authenticated API user with XCom write-and-read access to instantiate arbitrary `airflow.*` classes on the API server (CWE-502). An authenticated user who can write an XCom value and then read it back with `deserialize=true` triggers the unsafe instantiation. Users are advised to upgrade to apache-airflow 3.3.1 or later, which rejects reserved XCom serialization keys submitted as JSON string literals.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/69378",
                "https://lists.apache.org/thread/dm0520yhh4mn7qknyoh45r2w6c5qg2mg",
                "http://www.openwall.com/lists/oss-security/2026/08/12/6"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:09.067",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59242"
                }
            ]
        },
        {
            "id": "CVE-2026-58704",
            "vendor": "Google",
            "product": "Pixel",
            "title": "Google Pixel Improper Authorization Vulnerability",
            "summary": "Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.",
            "updated_at": "2026-09-15T22:00:00Z",
            "published_at": "2026-09-15T22:00:00Z",
            "cvss": 0,
            "confidence": 85,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-58644",
            "vendor": "Microsoft",
            "product": "SharePoint",
            "title": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
            "summary": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.",
            "updated_at": "2026-07-15T22:00:00Z",
            "published_at": "2026-07-15T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-07-15T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-58592",
            "vendor": "LadybirdBrowser",
            "product": "Ladybird",
            "title": "Ladybird vulnerability",
            "summary": "Ladybird before commit 2f9dc7e contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via the ESM path, WebAssemblyModule.cpp passes a stack-local Wasm::FunctionType by reference to create_host_function, whose host callback captures and later reads that reference; once the ESM link-loop iteration ends the FunctionType is destroyed, leaving the callback with a dangling reference (the normal instantiate path uses a long-lived reference and is not affected). Stale result-type data lets the host callback return an empty result vector for a statically non-empty result, so the destination register retains an attacker-influenced value that is then consumed by the WASM-GC array.set handler, which bit-casts the reference low bits to an ArrayInstance pointer after only a null check, yielding an arbitrary write. A web page can chain this into code execution in the WebContent process. Verified reachable from HTML content without any instrumentation or source modification.",
            "updated_at": "2026-09-11T15:17:02.437",
            "published_at": "2026-07-01T20:17:11.600",
            "cvss": 8.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2f9dc7e9f35eed67dde3f9e8567d390dc4f0c665 (git)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-787",
            "what_happened": "Ladybird before commit 2f9dc7e contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via the ESM path, WebAssemblyModule.cpp passes a stack-local Wasm::FunctionType by reference to create_host_function, whose host callback captures and later reads that reference; once the ESM link-loop iteration ends the FunctionType is destroyed, leaving the callback with a dangling reference (the normal instantiate path uses a long-lived reference and is not affected). Stale result-type data lets the host callback return an empty result vector for a statically non-empty result, so the destination register retains an attacker-influenced value that is then consumed by the WASM-GC array.set handler, which bit-casts the reference low bits to an ArrayInstance pointer after only a null check, yielding an arbitrary write. A web page can chain this into code execution in the WebContent process. Verified reachable from HTML content without any instrumentation or source modification.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/LadybirdBrowser/ladybird/commit/2f9dc7e9f35eed67dde3f9e8567d390dc4f0c665",
                "https://github.com/LadybirdBrowser/ladybird/issues/11569",
                "https://github.com/LadybirdBrowser/ladybird/pull/11606",
                "https://github.com/bikini/exploitarium/tree/main/ladybird-wasm-esm-host-function-rce-poc",
                "https://www.vulncheck.com/advisories/ladybird-web-reachable-code-execution-via-dangling-functiontype-reference-in-webassembly-esm-integration"
            ],
            "timeline": [
                {
                    "at": "2026-07-01T20:17:11.600",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58592"
                }
            ]
        },
        {
            "id": "CVE-2026-58480",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Blocksy Companion  2.1.46 - RCE",
            "summary": "Blocksy Companion  2.1.46 - RCE",
            "updated_at": "2026-08-10T22:00:00Z",
            "published_at": "2026-08-10T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52640",
                    "author": "banyamer",
                    "first_seen": "2026-08-11",
                    "confidence": "High",
                    "title": "Blocksy Companion  2.1.46 - RCE",
                    "summary": "Blocksy Companion  2.1.46 - RCE",
                    "url": "https://www.exploit-db.com/exploits/52640",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52640"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52640"
                }
            ]
        },
        {
            "id": "CVE-2026-58289",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Microsoft Edge 150.0.4078.48 - RCE",
            "summary": "Microsoft Edge 150.0.4078.48 - RCE",
            "updated_at": "2026-08-09T22:00:00Z",
            "published_at": "2026-08-09T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52632",
                    "author": "banyamer",
                    "first_seen": "2026-08-10",
                    "confidence": "High",
                    "title": "Microsoft Edge 150.0.4078.48 - RCE",
                    "summary": "Microsoft Edge 150.0.4078.48 - RCE",
                    "url": "https://www.exploit-db.com/exploits/52632",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52632"
            ],
            "timeline": [
                {
                    "at": "2026-08-09T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52632"
                }
            ]
        },
        {
            "id": "CVE-2026-58240",
            "vendor": "SAP_SE",
            "product": "SAP NetWeaver (Message Server)",
            "title": "SAP NetWeaver (Message Server) vulnerability",
            "summary": "SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.",
            "updated_at": "2026-09-09T05:17:26.417",
            "published_at": "2026-09-08T01:17:51.080",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "KERNEL 9.16; 9.18; 9.19; 9.20",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-308",
            "what_happened": "SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3759472",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:51.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58240"
                }
            ]
        },
        {
            "id": "CVE-2026-58234",
            "vendor": "SAP_SE",
            "product": "SAP Process Integration (SOAP Adapter)",
            "title": "SAP Process Integration (SOAP Adapter) vulnerability",
            "summary": "SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with no impact on confidentiality and integrity.",
            "updated_at": "2026-09-08T01:17:50.953",
            "published_at": "2026-09-08T01:17:50.953",
            "cvss": 2.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MESSAGING 7.50; SAP_XIAF 7.50",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-776",
            "what_happened": "SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increase processor load and degrade system responsiveness. Successful exploitation results in low impact on availability with no impact on confidentiality and integrity.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3736494",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:50.953",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58234"
                }
            ]
        },
        {
            "id": "CVE-2026-58139",
            "vendor": "duckdb",
            "product": "duckdb-aws",
            "title": "duckdb-aws vulnerability",
            "summary": "The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to extract plaintext AWS credentials by calling the load_aws_credentials function with the redact_secret parameter set to false, circumventing the database-wide allow_unredacted_secrets=false policy. Attackers can invoke this single function to retrieve the underlying AWS credential chain including access_key_id, secret_access_key, session_token, and region in plaintext, which are immediately valid against AWS APIs and particularly impactful in managed environments where pg_duckdb is preloaded and an AWS credential chain such as IMDSv2, IRSA, ECS task role, or EC2 instance role is reachable.",
            "updated_at": "2026-09-09T20:40:01.933",
            "published_at": "2026-08-03T20:17:25.220",
            "cvss": 6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 7d04119ee8d3f8836e278f0e8cbf21827ff5338b (git)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to extract plaintext AWS credentials by calling the load_aws_credentials function with the redact_secret parameter set to false, circumventing the database-wide allow_unredacted_secrets=false policy. Attackers can invoke this single function to retrieve the underlying AWS credential chain including access_key_id, secret_access_key, session_token, and region in plaintext, which are immediately valid against AWS APIs and particularly impactful in managed environments where pg_duckdb is preloaded and an AWS credential chain such as IMDSv2, IRSA, ECS task role, or EC2 instance role is reachable.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/duckdb/duckdb-aws/commit/7d04119ee8d3f8836e278f0e8cbf21827ff5338b",
                "https://github.com/duckdb/duckdb-aws/pull/156",
                "https://www.vulncheck.com/advisories/duckdb-aws-extension-security-policy-bypass-via-load-aws-credentials-procedure"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T20:17:25.220",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58139"
                }
            ]
        },
        {
            "id": "CVE-2026-58138",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution",
            "summary": "OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution",
            "updated_at": "2026-08-09T22:00:00Z",
            "published_at": "2026-08-09T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52633",
                    "author": "banyamer",
                    "first_seen": "2026-08-10",
                    "confidence": "High",
                    "title": "OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution",
                    "summary": "OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/52633",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52633"
            ],
            "timeline": [
                {
                    "at": "2026-08-09T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52633"
                }
            ]
        },
        {
            "id": "CVE-2026-58076",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author could place a value there that causes an arbitrary callable to be imported and invoked -- for example `subprocess.check_output`, or `builtins.eval` on the `builtins`-prefixed variant. The code runs in the **Scheduler**, which reconstructs serialized Dags in its normal loop with no request involved, and in the **API server**, on any authenticated read of the Dag such as `GET /api/v2/dags/{dag_id}/details`. Both are components the Airflow security model states must never execute Dag-author code, and both hold the metadata database credentials and the JWT signing secret. No non-default configuration is required. This is a **different sink from CVE-2026-33264**, which covered only the trigger branch of the same deserializer: deployments that upgraded in response to that advisory are still affected through the exception branch and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later, which restricts the imported class to a subclass of `BaseException`.",
            "updated_at": "2026-09-16T15:17:38.613",
            "published_at": "2026-08-12T16:17:08.317",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.0.0 through before 3.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config` reaches that branch, so a Dag author could place a value there that causes an arbitrary callable to be imported and invoked -- for example `subprocess.check_output`, or `builtins.eval` on the `builtins`-prefixed variant. The code runs in the **Scheduler**, which reconstructs serialized Dags in its normal loop with no request involved, and in the **API server**, on any authenticated read of the Dag such as `GET /api/v2/dags/{dag_id}/details`. Both are components the Airflow security model states must never execute Dag-author code, and both hold the metadata database credentials and the JWT signing secret. No non-default configuration is required. This is a **different sink from CVE-2026-33264**, which covered only the trigger branch of the same deserializer: deployments that upgraded in response to that advisory are still affected through the exception branch and must upgrade again. Users are advised to upgrade to apache-airflow 3.3.1 or later, which restricts the imported class to a subclass of `BaseException`.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/68511",
                "https://lists.apache.org/thread/t81p688t15jozxsng8521o60nh2kfsos",
                "https://www.cve.org/CVERecord?id=CVE-2026-33264"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:08.317",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58076"
                }
            ]
        },
        {
            "id": "CVE-2026-58065",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow Git provider",
            "title": "Apache Airflow Git provider vulnerability",
            "summary": "The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or injecting malicious repository content. Deployments that use the Git DAG bundle or Git provider to clone over SSH with a deploy key are affected. The fix changes the default to verify host keys; upgrade to apache-airflow-providers-git `0.4.1` or later and configure a `known_hosts` file.",
            "updated_at": "2026-09-16T16:17:13.310",
            "published_at": "2026-07-13T16:16:41.757",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.4.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-322",
            "what_happened": "The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or injecting malicious repository content. Deployments that use the Git DAG bundle or Git provider to clone over SSH with a deploy key are affected. The fix changes the default to verify host keys; upgrade to apache-airflow-providers-git `0.4.1` or later and configure a `known_hosts` file.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/69103",
                "https://lists.apache.org/thread/fjmclngfksz2kp7llpcjxzdz568h0zhc",
                "http://www.openwall.com/lists/oss-security/2026/07/13/3"
            ],
            "timeline": [
                {
                    "at": "2026-07-13T16:16:41.757",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58065"
                }
            ]
        },
        {
            "id": "CVE-2026-58058",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Nmap  7.99  - Extension Header Integer Underflow",
            "summary": "Nmap  7.99  - Extension Header Integer Underflow",
            "updated_at": "2026-08-16T22:00:00Z",
            "published_at": "2026-08-16T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52647",
                    "author": "banyamer",
                    "first_seen": "2026-08-17",
                    "confidence": "High",
                    "title": "Nmap  7.99  - Extension Header Integer Underflow",
                    "summary": "Nmap  7.99  - Extension Header Integer Underflow",
                    "url": "https://www.exploit-db.com/exploits/52647",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52647"
            ],
            "timeline": [
                {
                    "at": "2026-08-16T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52647"
                }
            ]
        },
        {
            "id": "CVE-2026-58037",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-58025",
            "summary": "PHP deserialization RCE in MediaWiki via WikiImporter log entry parameters.",
            "updated_at": "2026-09-06T05:50:09Z",
            "published_at": "2026-09-06T05:50:09Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 73,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "PHP deserialization RCE in MediaWiki via WikiImporter log entry parameters.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-58025",
                    "summary": "PHP deserialization RCE in MediaWiki via WikiImporter log entry parameters.",
                    "what_happened": "PHP deserialization RCE in MediaWiki via WikiImporter log entry parameters.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-502",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHINTHINK-CVE-2026-58025",
                        "https://kitploit.com/ja/tools/github/shinthink/cve-2026-58025/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T07:50:09",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHINTHINK-CVE-2026-58025"
                },
                {
                    "title": "Exploit for CVE-2026-58025",
                    "summary": "PHP deserialization RCE in MediaWiki via WikiImporter log entry parameters.",
                    "what_happened": "PHP deserialization RCE in MediaWiki via WikiImporter log entry parameters.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-502",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHINTHINK-CVE-2026-58025",
                        "https://kitploit.com/ja/tools/github/shinthink/cve-2026-58025/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-06T07:50:09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/shinthink/cve-2026-58025/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHINTHINK-CVE-2026-58025",
                "https://kitploit.com/ja/tools/github/shinthink/cve-2026-58025/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T05:50:09Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHINTHINK-CVE-2026-58025"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-58015",
            "vendor": "GNOME",
            "product": "GLib",
            "title": "GLib vulnerability",
            "summary": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
            "updated_at": "2026-09-15T12:17:51.643",
            "published_at": "2026-06-30T13:19:17.707",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 2.88.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 27,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-22",
            "what_happened": "A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "gitlab.gnome.org",
                    "author": "NVD reference",
                    "first_seen": "2026-06-30",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3931"
                }
            ],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:49512",
                "https://access.redhat.com/errata/RHSA-2026:55440",
                "https://access.redhat.com/errata/RHSA-2026:57015",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/errata/RHSA-2026:61766",
                "https://access.redhat.com/errata/RHSA-2026:61783",
                "https://access.redhat.com/errata/RHSA-2026:63135",
                "https://access.redhat.com/errata/RHSA-2026:63138",
                "https://access.redhat.com/errata/RHSA-2026:63140",
                "https://access.redhat.com/errata/RHSA-2026:65762",
                "https://access.redhat.com/errata/RHSA-2026:65763",
                "https://access.redhat.com/errata/RHSA-2026:65767",
                "https://access.redhat.com/errata/RHSA-2026:65768",
                "https://access.redhat.com/errata/RHSA-2026:65769",
                "https://access.redhat.com/errata/RHSA-2026:65770",
                "https://access.redhat.com/errata/RHSA-2026:65771",
                "https://access.redhat.com/errata/RHSA-2026:65773",
                "https://access.redhat.com/security/cve/CVE-2026-58015",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492256",
                "https://gitlab.gnome.org/GNOME/glib/-/issues/3931",
                "https://access.redhat.com/errata/RHSA-2026:66018",
                "https://access.redhat.com/errata/RHSA-2026:66357"
            ],
            "timeline": [
                {
                    "at": "2026-06-30T13:19:17.707",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58015"
                }
            ]
        },
        {
            "id": "CVE-2026-58014",
            "vendor": "GNOME",
            "product": "GLib",
            "title": "GLib vulnerability",
            "summary": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.",
            "updated_at": "2026-09-15T12:17:51.327",
            "published_at": "2026-06-30T13:19:17.580",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 2.88.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 28,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-193",
            "what_happened": "A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "gitlab.gnome.org",
                    "author": "NVD reference",
                    "first_seen": "2026-06-30",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3930"
                }
            ],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:49512",
                "https://access.redhat.com/errata/RHSA-2026:55440",
                "https://access.redhat.com/errata/RHSA-2026:57015",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/errata/RHSA-2026:61766",
                "https://access.redhat.com/errata/RHSA-2026:61783",
                "https://access.redhat.com/errata/RHSA-2026:63135",
                "https://access.redhat.com/errata/RHSA-2026:63138",
                "https://access.redhat.com/errata/RHSA-2026:63140",
                "https://access.redhat.com/errata/RHSA-2026:65762",
                "https://access.redhat.com/errata/RHSA-2026:65763",
                "https://access.redhat.com/errata/RHSA-2026:65767",
                "https://access.redhat.com/errata/RHSA-2026:65768",
                "https://access.redhat.com/errata/RHSA-2026:65769",
                "https://access.redhat.com/errata/RHSA-2026:65770",
                "https://access.redhat.com/errata/RHSA-2026:65771",
                "https://access.redhat.com/errata/RHSA-2026:65773",
                "https://access.redhat.com/security/cve/CVE-2026-58014",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492255",
                "https://gitlab.gnome.org/GNOME/glib/-/issues/3930",
                "https://access.redhat.com/errata/RHSA-2026:66018",
                "https://access.redhat.com/errata/RHSA-2026:66357"
            ],
            "timeline": [
                {
                    "at": "2026-06-30T13:19:17.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58014"
                }
            ]
        },
        {
            "id": "CVE-2026-58013",
            "vendor": "GNOME",
            "product": "GLib",
            "title": "GLib vulnerability",
            "summary": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.",
            "updated_at": "2026-09-10T18:18:03.590",
            "published_at": "2026-06-30T13:19:17.457",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 2.88.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-126",
            "what_happened": "A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "gitlab.gnome.org",
                    "author": "NVD reference",
                    "first_seen": "2026-06-30",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3925"
                }
            ],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:49512",
                "https://access.redhat.com/errata/RHSA-2026:55440",
                "https://access.redhat.com/errata/RHSA-2026:57015",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/errata/RHSA-2026:61766",
                "https://access.redhat.com/errata/RHSA-2026:61783",
                "https://access.redhat.com/errata/RHSA-2026:63135",
                "https://access.redhat.com/errata/RHSA-2026:63138",
                "https://access.redhat.com/errata/RHSA-2026:63140",
                "https://access.redhat.com/errata/RHSA-2026:65762",
                "https://access.redhat.com/errata/RHSA-2026:65763",
                "https://access.redhat.com/errata/RHSA-2026:65767",
                "https://access.redhat.com/errata/RHSA-2026:65768",
                "https://access.redhat.com/errata/RHSA-2026:65769",
                "https://access.redhat.com/errata/RHSA-2026:65770",
                "https://access.redhat.com/errata/RHSA-2026:65771",
                "https://access.redhat.com/errata/RHSA-2026:65773",
                "https://access.redhat.com/security/cve/CVE-2026-58013",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492248",
                "https://gitlab.gnome.org/GNOME/glib/-/issues/3925",
                "https://access.redhat.com/errata/RHSA-2026:66018"
            ],
            "timeline": [
                {
                    "at": "2026-06-30T13:19:17.457",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58013"
                }
            ]
        },
        {
            "id": "CVE-2026-58012",
            "vendor": "GNOME",
            "product": "GLib",
            "title": "GLib vulnerability",
            "summary": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.",
            "updated_at": "2026-09-10T18:18:03.290",
            "published_at": "2026-06-30T13:19:17.330",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 2.86.5 (semver); before 2.88.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-126",
            "what_happened": "A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "gitlab.gnome.org",
                    "author": "NVD reference",
                    "first_seen": "2026-06-30",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3918"
                }
            ],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:49512",
                "https://access.redhat.com/errata/RHSA-2026:55440",
                "https://access.redhat.com/errata/RHSA-2026:57015",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/errata/RHSA-2026:61766",
                "https://access.redhat.com/errata/RHSA-2026:61783",
                "https://access.redhat.com/errata/RHSA-2026:63135",
                "https://access.redhat.com/errata/RHSA-2026:63138",
                "https://access.redhat.com/errata/RHSA-2026:63140",
                "https://access.redhat.com/errata/RHSA-2026:65762",
                "https://access.redhat.com/errata/RHSA-2026:65763",
                "https://access.redhat.com/errata/RHSA-2026:65767",
                "https://access.redhat.com/errata/RHSA-2026:65768",
                "https://access.redhat.com/errata/RHSA-2026:65769",
                "https://access.redhat.com/errata/RHSA-2026:65770",
                "https://access.redhat.com/errata/RHSA-2026:65771",
                "https://access.redhat.com/errata/RHSA-2026:65773",
                "https://access.redhat.com/security/cve/CVE-2026-58012",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492247",
                "https://gitlab.gnome.org/GNOME/glib/-/issues/3918",
                "https://access.redhat.com/errata/RHSA-2026:66018"
            ],
            "timeline": [
                {
                    "at": "2026-06-30T13:19:17.330",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58012"
                }
            ]
        },
        {
            "id": "CVE-2026-58011",
            "vendor": "GNOME",
            "product": "GLib",
            "title": "GLib vulnerability",
            "summary": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.",
            "updated_at": "2026-09-10T18:18:03.000",
            "published_at": "2026-06-30T13:19:17.200",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 2.86.5 (semver); before 2.88.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 70,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "gitlab.gnome.org",
                    "author": "NVD reference",
                    "first_seen": "2026-06-30",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3917"
                },
                {
                    "repository": "gitlab.gnome.org",
                    "author": "NVD reference",
                    "first_seen": "2026-06-30",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gitlab.gnome.org/GNOME/glib/-/work_items/3917"
                }
            ],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:49512",
                "https://access.redhat.com/errata/RHSA-2026:55440",
                "https://access.redhat.com/errata/RHSA-2026:57015",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/errata/RHSA-2026:61766",
                "https://access.redhat.com/errata/RHSA-2026:61783",
                "https://access.redhat.com/errata/RHSA-2026:63135",
                "https://access.redhat.com/errata/RHSA-2026:63138",
                "https://access.redhat.com/errata/RHSA-2026:63140",
                "https://access.redhat.com/errata/RHSA-2026:65762",
                "https://access.redhat.com/errata/RHSA-2026:65763",
                "https://access.redhat.com/errata/RHSA-2026:65767",
                "https://access.redhat.com/errata/RHSA-2026:65768",
                "https://access.redhat.com/errata/RHSA-2026:65769",
                "https://access.redhat.com/errata/RHSA-2026:65770",
                "https://access.redhat.com/errata/RHSA-2026:65771",
                "https://access.redhat.com/errata/RHSA-2026:65773",
                "https://access.redhat.com/security/cve/CVE-2026-58011",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492245",
                "https://gitlab.gnome.org/GNOME/glib/-/issues/3917",
                "https://gitlab.gnome.org/GNOME/glib/-/work_items/3917",
                "https://access.redhat.com/errata/RHSA-2026:66018"
            ],
            "timeline": [
                {
                    "at": "2026-06-30T13:19:17.200",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58011"
                }
            ]
        },
        {
            "id": "CVE-2026-58010",
            "vendor": "GNOME",
            "product": "GLib",
            "title": "GLib vulnerability",
            "summary": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.",
            "updated_at": "2026-09-10T18:18:02.700",
            "published_at": "2026-06-30T13:19:17.067",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 2.86.5 (semver); before 2.88.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-126",
            "what_happened": "A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "gitlab.gnome.org",
                    "author": "NVD reference",
                    "first_seen": "2026-06-30",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gitlab.gnome.org/GNOME/glib/-/issues/3915"
                }
            ],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:49512",
                "https://access.redhat.com/errata/RHSA-2026:55440",
                "https://access.redhat.com/errata/RHSA-2026:57015",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/errata/RHSA-2026:61766",
                "https://access.redhat.com/errata/RHSA-2026:61783",
                "https://access.redhat.com/errata/RHSA-2026:63135",
                "https://access.redhat.com/errata/RHSA-2026:63138",
                "https://access.redhat.com/errata/RHSA-2026:63140",
                "https://access.redhat.com/errata/RHSA-2026:65762",
                "https://access.redhat.com/errata/RHSA-2026:65763",
                "https://access.redhat.com/errata/RHSA-2026:65767",
                "https://access.redhat.com/errata/RHSA-2026:65768",
                "https://access.redhat.com/errata/RHSA-2026:65769",
                "https://access.redhat.com/errata/RHSA-2026:65770",
                "https://access.redhat.com/errata/RHSA-2026:65771",
                "https://access.redhat.com/errata/RHSA-2026:65773",
                "https://access.redhat.com/security/cve/CVE-2026-58010",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492243",
                "https://gitlab.gnome.org/GNOME/glib/-/issues/3915",
                "https://access.redhat.com/errata/RHSA-2026:66018"
            ],
            "timeline": [
                {
                    "at": "2026-06-30T13:19:17.067",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58010"
                }
            ]
        },
        {
            "id": "CVE-2026-57588",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Tenable Nessus 10.12.1 - SQL Injection",
            "summary": "Tenable Nessus 10.12.1 - SQL Injection",
            "updated_at": "2026-09-05T22:00:00Z",
            "published_at": "2026-09-05T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 147,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Tenable Nessus 10.12.1 SQL Injection",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52620",
                    "author": "banyamer",
                    "first_seen": "2026-07-07",
                    "confidence": "High",
                    "title": "Tenable Nessus 10.12.1 - SQL Injection",
                    "summary": "Tenable Nessus 10.12.1 - SQL Injection",
                    "url": "https://www.exploit-db.com/exploits/52620",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "CXSecurity WLB-2026090005",
                    "author": "Mohammed Idrees Banyamer",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Tenable Nessus 10.12.1 SQL Injection",
                    "summary": "Tenable Nessus 10.12.1 SQL Injection",
                    "what_happened": "Tenable Nessus 10.12.1 SQL Injection",
                    "cvss": 0,
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "url": "https://cxsecurity.com/issue/WLB-2026090005",
                    "cwe": "Unknown"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52620",
                "https://cxsecurity.com/issue/WLB-2026090005"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52620"
                }
            ]
        },
        {
            "id": "CVE-2026-56845",
            "vendor": "Rocket.Chat",
            "product": "Rocket.Chat",
            "title": "Rocket.Chat vulnerability",
            "summary": "An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.",
            "updated_at": "2026-09-09T15:41:24.427",
            "published_at": "2026-08-04T01:16:19.660",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 8.2.0 (semver); before 8.1.1 (semver); before 8.0.2 (semver); before 7.13.4 (semver); before 7.12.5 (semver); before 7.11.5 (semver); before 7.10.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an attacker can read arbitrary files outside the base directory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://hackerone.com/reports/3514640"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T01:16:19.660",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56845"
                }
            ]
        },
        {
            "id": "CVE-2026-56818",
            "vendor": "netty",
            "product": "netty",
            "title": "netty vulnerability",
            "summary": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does not clear the same state when the sibling maxElements limit is exceeded. A peer can start a valid RESP array, send a bulk string child, then send a nested array header longer than the configured maxElements. Netty throws a decoder exception in decodeRedisArrayHeader, but the existing partial aggregate remains retained in the handler. If the application leaves the channel alive after the exception, later messages are still consumed into the pre-error aggregate, allowing an unauthenticated peer to keep attacker-controlled aggregate state alive across a security-limit exception and pin retained pooled buffers. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
            "updated_at": "2026-09-10T20:43:19.260",
            "published_at": "2026-08-07T18:17:19.100",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 4.1.136.Final; >= 4.2.0-Final, < 4.2.16.Final",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-401",
            "what_happened": "Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does not clear the same state when the sibling maxElements limit is exceeded. A peer can start a valid RESP array, send a bulk string child, then send a nested array header longer than the configured maxElements. Netty throws a decoder exception in decodeRedisArrayHeader, but the existing partial aggregate remains retained in the handler. If the application leaves the channel alive after the exception, later messages are still consumed into the pre-error aggregate, allowing an unauthenticated peer to keep attacker-controlled aggregate state alive across a security-limit exception and pin retained pooled buffers. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b",
                "https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6",
                "https://github.com/netty/netty/pull/17065",
                "https://github.com/netty/netty/security/advisories/GHSA-p9jm-q85p-7mcp"
            ],
            "timeline": [
                {
                    "at": "2026-08-07T18:17:19.100",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56818"
                }
            ]
        },
        {
            "id": "CVE-2026-56758",
            "vendor": "MZ Automation GmbH",
            "product": "libiec61850",
            "title": "libiec61850 vulnerability",
            "summary": "The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS\n connection establishment. When parsing certain fields within the \ncalling AP title, an attacker controlled length value of zero or one may\n cause the parser to read past the end of a heap buffer.",
            "updated_at": "2026-09-08T19:30:43.093",
            "published_at": "2026-07-30T23:16:51.517",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.6.2 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS\n connection establishment. When parsing certain fields within the \ncalling AP title, an attacker controlled length value of zero or one may\n cause the parser to read past the end of a heap buffer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-10.json",
                "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-10"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T23:16:51.517",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56758"
                }
            ]
        },
        {
            "id": "CVE-2026-56177",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Use after free in Windows Server allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-09T04:18:00.987",
            "published_at": "2026-09-08T18:17:42.563",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "Use after free in Windows Server allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56177"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:17:42.563",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56177"
                }
            ]
        },
        {
            "id": "CVE-2026-56155",
            "vendor": "Microsoft",
            "product": "Active Directory Federation Services",
            "title": "Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability",
            "summary": "Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-07-13T22:00:00Z",
            "published_at": "2026-07-13T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-07-13T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-56015",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Net::IP::LPM versions before 1.11 for Perl allow a heap out-of-bounds read via an unbounded prefix length.",
            "summary": "Net::IP::LPM versions before 1.11 for Perl allow a heap out-of-bounds read via an unbounded prefix length.\n\nadd() passes the prefix string to the trie builder addPrefixToTrie() without checking it against the address width.\n\naddPrefixToTrie() then walks the prefix buffer by prefix_length bits, reading prefix[byte] for byte up to prefix_len/8, where prefix is the 4-byte (IPv4) or 16-byte (IPv6) packed address. A prefix length greater than 32 for IPv4 or 128 for IPv6, for example add(\"1.2.3.4/255\", $v) or add(\"2001:db8::/255\", $v), reads past the end of the packed address.\n\nThe out-of-bounds read happens during trie construction and is bounded: the prefix length is stored as an unsigned char, so the bit walk reads at most 32 bytes from the start of the packed address, a short distance past the end of the 4-byte or 16-byte buffer. It is detectable under AddressSanitizer, valgrind, or a hardened allocator, where it can abort the process. Lookups and dump() format only the valid address width, so the out-of-bounds bytes are not exposed through the module's API.",
            "updated_at": "2026-09-07T19:17:26.970",
            "published_at": "2026-07-03T13:17:30.130",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.11 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "Net::IP::LPM versions before 1.11 for Perl allow a heap out-of-bounds read via an unbounded prefix length.\n\nadd() passes the prefix string to the trie builder addPrefixToTrie() without checking it against the address width.\n\naddPrefixToTrie() then walks the prefix buffer by prefix_length bits, reading prefix[byte] for byte up to prefix_len/8, where prefix is the 4-byte (IPv4) or 16-byte (IPv6) packed address. A prefix length greater than 32 for IPv4 or 128 for IPv6, for example add(\"1.2.3.4/255\", $v) or add(\"2001:db8::/255\", $v), reads past the end of the packed address.\n\nThe out-of-bounds read happens during trie construction and is bounded: the prefix length is stored as an unsigned char, so the bit walk reads at most 32 bytes from the start of the packed address, a short distance past the end of the 4-byte or 16-byte buffer. It is detectable under AddressSanitizer, valgrind, or a hardened allocator, where it can abort the process. Lookups and dump() format only the valid address width, so the out-of-bounds bytes are not exposed through the module's API.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://metacpan.org/release/RRWO/Net-IP-LPM-1.11/changes",
                "https://rt.cpan.org/Ticket/Display.html?id=179856",
                "https://security.metacpan.org/patches/N/Net-IP-LPM/1.10/CVE-2026-56015-r2.patch",
                "http://www.openwall.com/lists/oss-security/2026/07/03/4"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T13:17:30.130",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-56015"
                }
            ]
        },
        {
            "id": "CVE-2026-55953",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The client-side tls_handshake:hello/5 handler validates the negotiated protocol version and the downgrade sentinel but hands the server-chosen suite directly to ssl_handshake:handle_server_hello_extensions/9, which installs it without a membership check. The TLS 1.3 client path performs this check (per RFC 8446), so it is not affected.\n\nAn on-path attacker between the client and the intended server can respond with a ServerHello selecting an anonymous key exchange suite such as TLS_DH_anon_* or TLS_ECDH_anon_* that the client never offered. Anonymous suites do not require the server to present a certificate, so the entire verify_peer and cacerts configuration is bypassed: the attacker completes the handshake with its own ephemeral parameters, no certificate is validated, no hostname is checked, and ssl:connect returns {ok, Socket}. All subsequent application traffic is readable and modifiable by the attacker.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.15, from OTP 28.0 before OTP 28.5.0.4, and from OTP 29.0 before OTP 29.0.4, corresponding to ssl from 5.3.4 before 11.2.12.11, from 11.3 before 11.6.0.4, and from 11.7 before 11.7.4. Whether OTP before OTP 17.0, corresponding to ssl before 5.3.4, is affected is unknown.",
            "updated_at": "2026-09-08T01:17:50.707",
            "published_at": "2026-07-27T16:17:49.500",
            "cvss": 9.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.15 (otp); 28.0 through before 28.5.0.4 (otp); 29.0 through before 29.0.4 (otp); 5.3.4 through before 11.2.12.11 (otp); 11.3 through before 11.6.0.4 (otp); 11.7 through before 11.7.4 (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-757",
            "what_happened": "The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The client-side tls_handshake:hello/5 handler validates the negotiated protocol version and the downgrade sentinel but hands the server-chosen suite directly to ssl_handshake:handle_server_hello_extensions/9, which installs it without a membership check. The TLS 1.3 client path performs this check (per RFC 8446), so it is not affected.\n\nAn on-path attacker between the client and the intended server can respond with a ServerHello selecting an anonymous key exchange suite such as TLS_DH_anon_* or TLS_ECDH_anon_* that the client never offered. Anonymous suites do not require the server to present a certificate, so the entire verify_peer and cacerts configuration is bypassed: the attacker completes the handshake with its own ephemeral parameters, no certificate is validated, no hostname is checked, and ssl:connect returns {ok, Socket}. All subsequent application traffic is readable and modifiable by the attacker.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.15, from OTP 28.0 before OTP 28.5.0.4, and from OTP 29.0 before OTP 29.0.4, corresponding to ssl from 5.3.4 before 11.2.12.11, from 11.3 before 11.6.0.4, and from 11.7 before 11.7.4. Whether OTP before OTP 17.0, corresponding to ssl before 5.3.4, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-55953.html",
                "https://github.com/erlang/otp/commit/064e236414614f9085cbbbd6eacf0e43c02d1b4b",
                "https://github.com/erlang/otp/commit/0a82596d425abe43dc2e0b3d74aa1557ef74051c",
                "https://github.com/erlang/otp/commit/e6ff938116b2872bccc478af7fefb56627285b77",
                "https://github.com/erlang/otp/security/advisories/GHSA-c6cw-pr89-w882",
                "https://osv.dev/vulnerability/EEF-CVE-2026-55953",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T16:17:49.500",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55953"
                }
            ]
        },
        {
            "id": "CVE-2026-55951",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates every header into a list before the length check runs (which only fires after the terminating CRLF CRLF is received).\n\nA malicious or compromised HTTP server can send an arbitrarily large number of headers, or headers with very large values, causing the client process to allocate unbounded memory until the system runs out of memory or the BEAM VM crashes. A proof-of-concept server sending 100,000 headers of roughly 4000 bytes each caused the client VM to allocate over 13 GB of memory in under 30 seconds.\n\nAny application using httpc:request/4,5 to connect to untrusted servers is affected. No authentication is required: any server the client connects to (including via a redirect or man-in-the-middle) can trigger the exhaustion.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "updated_at": "2026-09-08T01:17:50.477",
            "published_at": "2026-09-01T15:17:20.780",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.17 (otp); 28.0 through before 28.5.0.6 (otp); 29.0 through before 29.0.6 (otp); 5.10 through before 9.3.2.7 (otp); 9.4 through before 9.6.2.3 (otp); 9.7 through before 9.7.2 (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option defaults to nolimit, and httpc_response:parse_headers/6 accumulates every header into a list before the length check runs (which only fires after the terminating CRLF CRLF is received).\n\nA malicious or compromised HTTP server can send an arbitrarily large number of headers, or headers with very large values, causing the client process to allocate unbounded memory until the system runs out of memory or the BEAM VM crashes. A proof-of-concept server sending 100,000 headers of roughly 4000 bytes each caused the client VM to allocate over 13 GB of memory in under 30 seconds.\n\nAny application using httpc:request/4,5 to connect to untrusted servers is affected. No authentication is required: any server the client connects to (including via a redirect or man-in-the-middle) can trigger the exhaustion.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-55951.html",
                "https://github.com/erlang/otp/commit/aba0fe8c2d700bf4ac94607cf7f00e53bbe4042d",
                "https://github.com/erlang/otp/commit/e3be1cfe9f6cedd0cd20d9905e05601dfb31c8aa",
                "https://github.com/erlang/otp/security/advisories/GHSA-f9fw-mg7q-4g3x",
                "https://osv.dev/vulnerability/EEF-CVE-2026-55951",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T15:17:20.780",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55951"
                }
            ]
        },
        {
            "id": "CVE-2026-55780",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "NanaZip 6.5  -  DoS",
            "summary": "NanaZip 6.5  -  DoS",
            "updated_at": "2026-08-16T22:00:00Z",
            "published_at": "2026-08-16T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52652",
                    "author": "Jorge González Milla",
                    "first_seen": "2026-08-17",
                    "confidence": "High",
                    "title": "NanaZip 6.5  -  DoS",
                    "summary": "NanaZip 6.5  -  DoS",
                    "url": "https://www.exploit-db.com/exploits/52652",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52652"
            ],
            "timeline": [
                {
                    "at": "2026-08-16T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52652"
                }
            ]
        },
        {
            "id": "CVE-2026-55777",
            "vendor": "allinurl",
            "product": "goaccess",
            "title": "goaccess vulnerability",
            "summary": "GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the source offset and copy length for memmove, allowing a crafted User-Agent in a processed access log to read up to approximately 4 KB beyond the heap allocation and conditionally crash GoAccess. This issue is fixed in version 1.11.",
            "updated_at": "2026-09-08T20:51:43.490",
            "published_at": "2026-07-30T21:17:57.360",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.11",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the source offset and copy length for memmove, allowing a crafted User-Agent in a processed access log to read up to approximately 4 KB beyond the heap allocation and conditionally crash GoAccess. This issue is fixed in version 1.11.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/allinurl/goaccess/commit/ba813ed97d998dbdcb8d87e178799a4bb2da9e81",
                "https://github.com/allinurl/goaccess/security/advisories/GHSA-5phr-qpgf-hgrg"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T21:17:57.360",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55777"
                }
            ]
        },
        {
            "id": "CVE-2026-55770",
            "vendor": "openbao",
            "product": "openbao",
            "title": "openbao vulnerability",
            "summary": "OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/ldaputil/client.go GetUserDN. With the LDAP authentication backend configured for an Active Directory UPNDomain path or UserDN and UserAttr binding, an attacker-controlled username containing filter metacharacters could alter the search predicate and select a different directory entry because EscapeLDAPValue does not neutralize the characters handled by ldap.EscapeFilter. A resulting token could be associated with another LDAP identity and gain access to secrets, policies, or modification capabilities assigned to that identity. This issue is fixed in version 2.5.5.",
            "updated_at": "2026-09-16T04:18:25.170",
            "published_at": "2026-09-15T16:17:15.763",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.5.5",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-90",
            "what_happened": "OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/ldaputil/client.go GetUserDN. With the LDAP authentication backend configured for an Active Directory UPNDomain path or UserDN and UserAttr binding, an attacker-controlled username containing filter metacharacters could alter the search predicate and select a different directory entry because EscapeLDAPValue does not neutralize the characters handled by ldap.EscapeFilter. A resulting token could be associated with another LDAP identity and gain access to secrets, policies, or modification capabilities assigned to that identity. This issue is fixed in version 2.5.5.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openbao/openbao/commit/10b7825c714c1ef25b6c3c1c2cd6ecd8747c0659",
                "https://github.com/openbao/openbao/commit/8077f96bdc02137b0a072146b6f9ca11c96c549c",
                "https://github.com/openbao/openbao/pull/3306",
                "https://github.com/openbao/openbao/pull/3313",
                "https://github.com/openbao/openbao/releases/tag/v2.5.5",
                "https://github.com/openbao/openbao/releases/tag/v2.6.0",
                "https://github.com/openbao/openbao/security/advisories/GHSA-6mwx-4547-5vc9"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T16:17:15.763",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55770"
                }
            ]
        },
        {
            "id": "CVE-2026-55768",
            "vendor": "allinurl",
            "product": "goaccess",
            "title": "goaccess vulnerability",
            "summary": "GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-bit WSFrame.payloadlen field before enforcing the maximum frame size, allowing an unauthenticated remote client to bypass the guard and force an approximately 18-exabyte allocation request that terminates the process. This issue is fixed in version 1.11.",
            "updated_at": "2026-09-08T20:51:43.490",
            "published_at": "2026-07-30T21:17:57.193",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.11",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-681",
            "what_happened": "GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-bit WSFrame.payloadlen field before enforcing the maximum frame size, allowing an unauthenticated remote client to bypass the guard and force an approximately 18-exabyte allocation request that terminates the process. This issue is fixed in version 1.11.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/allinurl/goaccess/commit/ea74b87254d0adc675c087ff49bddd2d60dc01d5",
                "https://github.com/allinurl/goaccess/security/advisories/GHSA-5gm5-pvh2-wg46"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T21:17:57.193",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55768"
                }
            ]
        },
        {
            "id": "CVE-2026-55584",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "phpSysInfo 3.4.5 - IP Allowlist Bypass",
            "summary": "phpSysInfo 3.4.5 - IP Allowlist Bypass",
            "updated_at": "2026-08-16T22:00:00Z",
            "published_at": "2026-08-16T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52648",
                    "author": "Muhammed Mirac Kayikci",
                    "first_seen": "2026-08-17",
                    "confidence": "High",
                    "title": "phpSysInfo 3.4.5 - IP Allowlist Bypass",
                    "summary": "phpSysInfo 3.4.5 - IP Allowlist Bypass",
                    "url": "https://www.exploit-db.com/exploits/52648",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52648"
            ],
            "timeline": [
                {
                    "at": "2026-08-16T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52648"
                }
            ]
        },
        {
            "id": "CVE-2026-55343",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.",
            "updated_at": "2026-09-16T04:18:24.470",
            "published_at": "2026-09-15T19:17:21.600",
            "cvss": 8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:21.600",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55343"
                }
            ]
        },
        {
            "id": "CVE-2026-55332",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T04:18:24.193",
            "published_at": "2026-09-15T19:17:21.507",
            "cvss": 6.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "In multiple locations, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:21.507",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55332"
                }
            ]
        },
        {
            "id": "CVE-2026-55331",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T04:18:23.977",
            "published_at": "2026-09-15T19:17:21.413",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:21.413",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55331"
                }
            ]
        },
        {
            "id": "CVE-2026-55323",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T04:18:23.770",
            "published_at": "2026-09-15T19:17:21.317",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:21.317",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55323"
                }
            ]
        },
        {
            "id": "CVE-2026-55318",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T04:18:23.477",
            "published_at": "2026-09-15T19:17:21.217",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-362",
            "what_happened": "In multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:21.217",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55318"
                }
            ]
        },
        {
            "id": "CVE-2026-55317",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In printf of printf.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T04:18:23.227",
            "published_at": "2026-09-15T19:17:21.113",
            "cvss": 6.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "In printf of printf.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:21.113",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55317"
                }
            ]
        },
        {
            "id": "CVE-2026-55100",
            "vendor": "kyndryl-open-source",
            "product": "hashi-vault-js",
            "title": "hashi-vault-js vulnerability",
            "summary": "hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query strings instead of using encodeURIComponent() and URLSearchParams, allowing path traversal and query parameter injection. This issue is fixed in version 0.5.2.",
            "updated_at": "2026-09-10T20:30:11.423",
            "published_at": "2026-07-31T18:17:17.480",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 0.5.2",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-23",
            "what_happened": "hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query strings instead of using encodeURIComponent() and URLSearchParams, allowing path traversal and query parameter injection. This issue is fixed in version 0.5.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/kyndryl-open-source/hashi-vault-js/commit/ea2f76052d366a08f35f62ef4c12b6a334c91ec2",
                "https://github.com/kyndryl-open-source/hashi-vault-js/pull/66",
                "https://github.com/kyndryl-open-source/hashi-vault-js/releases/tag/v0.5.2",
                "https://github.com/kyndryl-open-source/hashi-vault-js/security/advisories/GHSA-g956-2f74-rmv7"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T18:17:17.480",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55100"
                }
            ]
        },
        {
            "id": "CVE-2026-55040",
            "vendor": "Microsoft",
            "product": "SharePoint",
            "title": "Microsoft SharePoint Weak Authentication Vulnerability",
            "summary": "Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.",
            "updated_at": "2026-08-26T08:15:13Z",
            "published_at": "2026-08-26T08:15:13Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 404,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · zenzue/CVE-2026-55040",
                    "author": "zenzue",
                    "first_seen": "2026-08-26",
                    "last_seen": "2026-08-26T08:15:13Z",
                    "pushed_at": "2026-08-26T08:09:52Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-55040",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/zenzue/CVE-2026-55040"
                },
                {
                    "repository": "CVE-Intel · sfewer-r7/CVE-2026-55040",
                    "author": "sfewer-r7",
                    "first_seen": "2026-08-06",
                    "last_seen": "2026-08-22T12:02:56Z",
                    "pushed_at": "2026-08-10T15:35:23Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Bypass",
                    "language": "Python",
                    "stars": 56,
                    "forks": 13,
                    "topics": [],
                    "title": "Microsoft SharePoint JWT Authentication Bypass (CVE-2026-55040)",
                    "repository_description": "Microsoft SharePoint JWT Authentication Bypass (CVE-2026-55040)",
                    "summary": "Microsoft SharePoint JWT Authentication Bypass (CVE-2026-55040)",
                    "source": "CVE-Intel",
                    "url": "https://github.com/sfewer-r7/CVE-2026-55040"
                },
                {
                    "repository": "CVE-Intel · l0ggg/CVE-2026-55040",
                    "author": "l0ggg",
                    "first_seen": "2026-07-28",
                    "last_seen": "2026-08-20T14:49:00Z",
                    "pushed_at": "2026-07-28T09:04:14Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 3,
                    "forks": 1,
                    "topics": [],
                    "title": "Exploit code for CVE-2026-55040, it can create auth header for any validate account.",
                    "repository_description": "Exploit code for CVE-2026-55040, it can create auth header for any validate account.",
                    "summary": "Exploit code for CVE-2026-55040, it can create auth header for any validate account.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/l0ggg/CVE-2026-55040"
                },
                {
                    "repository": "virologi-info/mssharepoint-scanner",
                    "author": "virologi-info",
                    "first_seen": "2026-08-27",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 0,
                    "title": "A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.",
                    "summary": "A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.",
                    "url": "https://github.com/virologi-info/mssharepoint-scanner"
                },
                {
                    "repository": "maxprog-svg/CVE-2026-55040-Mass-Exploit",
                    "author": "maxprog-svg",
                    "first_seen": "2026-08-27",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-55040",
                    "summary": "CVE-2026-55040",
                    "url": "https://github.com/maxprog-svg/CVE-2026-55040-Mass-Exploit"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/zenzue/CVE-2026-55040",
                "https://github.com/sfewer-r7/CVE-2026-55040",
                "https://github.com/l0ggg/CVE-2026-55040",
                "https://github.com/virologi-info/mssharepoint-scanner",
                "https://github.com/maxprog-svg/CVE-2026-55040-Mass-Exploit"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T08:15:13Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-55007",
            "vendor": "Microsoft",
            "product": "Microsoft Exchange Server 2019 Cumulative Update 14",
            "title": "Microsoft Exchange Server 2019 Cumulative Update 14 vulnerability",
            "summary": "Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.",
            "updated_at": "2026-09-09T04:18:00.117",
            "published_at": "2026-09-08T18:17:41.820",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "15.02.0.0 through before 15.02.1544.046 (custom); 15.02.0.0 through before 15.02.1748.051 (custom); 15.02.0.0 through before 15.02.2562.049 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-415",
            "what_happened": "Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55007"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:17:41.820",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55007"
                }
            ]
        },
        {
            "id": "CVE-2026-54909",
            "vendor": "pion",
            "product": "stun",
            "title": "stun vulnerability",
            "summary": "pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response parsing paths, allowing remote denial of service. This issue is fixed in version 3.1.3.",
            "updated_at": "2026-09-10T20:30:11.423",
            "published_at": "2026-07-31T23:17:25.433",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.1.3",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed short XOR-MAPPED-ADDRESS attribute in STUN or ICE Binding-response parsing paths, allowing remote denial of service. This issue is fixed in version 3.1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pion/stun/commit/fa9f074a33a8059c76c960b1fbee39f308002423",
                "https://github.com/pion/stun/pull/278",
                "https://github.com/pion/stun/releases/tag/v3.1.3",
                "https://github.com/pion/stun/security/advisories/GHSA-34rh-wp3j-6cxc"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T23:17:25.433",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54909"
                }
            ]
        },
        {
            "id": "CVE-2026-54891",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl (tls_gen_connection module) allows a network-positioned attacker to inject unauthenticated plaintext that the TLS client application later treats as authenticated server data.\n\nThe function tls_gen_connection:handle_protocol_record/3 rejects APPLICATION_DATA records that arrive in pre-handshake states when the TLS endpoint acts as a server, but does not apply the same check when the endpoint acts as a client. A network-positioned attacker can send plaintext APPLICATION_DATA records to the client during the handshake. The records are buffered and, once the handshake completes successfully, delivered to the application as if they were authenticated post-handshake data. The attacker cannot observe the client's response or steer the connection, so the impact is limited to blind injection of unauthenticated bytes. The injection window is wider for TLS versions prior to TLS 1.3 than for TLS 1.3.\n\nThis vulnerability is associated with program file lib/ssl/src/tls_gen_connection.erl.\n\nTLS 1.3 is affected starting with OTP 22.0, when TLS 1.3 support was added.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.14, from OTP 28.0 before OTP 28.5.0.3, and from OTP 29.0 before OTP 29.0.3, corresponding to ssl from 5.3.4 before 11.2.12.10, from 11.3 before 11.6.0.3, and from 11.7 before 11.7.3. Whether OTP before OTP 17.0, corresponding to ssl before 5.3.4, is affected is unknown.",
            "updated_at": "2026-09-08T01:17:31.370",
            "published_at": "2026-07-02T17:17:02.747",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before 27.3.4.14 (otp); 28.0 through before 28.5.0.3 (otp); 29.0 through before 29.0.3 (otp); 5.3.4 through before 11.2.12.10 (otp); 11.3 through before 11.6.0.3 (otp); 11.7 through before 11.7.3 (otp); 84adefa331c4159d432d22840663c38f155cd4c1 through before 07d2d0e93f6aaf7652a81e8df075fc1728da5e96 (git)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-924",
            "what_happened": "Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl (tls_gen_connection module) allows a network-positioned attacker to inject unauthenticated plaintext that the TLS client application later treats as authenticated server data.\n\nThe function tls_gen_connection:handle_protocol_record/3 rejects APPLICATION_DATA records that arrive in pre-handshake states when the TLS endpoint acts as a server, but does not apply the same check when the endpoint acts as a client. A network-positioned attacker can send plaintext APPLICATION_DATA records to the client during the handshake. The records are buffered and, once the handshake completes successfully, delivered to the application as if they were authenticated post-handshake data. The attacker cannot observe the client's response or steer the connection, so the impact is limited to blind injection of unauthenticated bytes. The injection window is wider for TLS versions prior to TLS 1.3 than for TLS 1.3.\n\nThis vulnerability is associated with program file lib/ssl/src/tls_gen_connection.erl.\n\nTLS 1.3 is affected starting with OTP 22.0, when TLS 1.3 support was added.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.14, from OTP 28.0 before OTP 28.5.0.3, and from OTP 29.0 before OTP 29.0.3, corresponding to ssl from 5.3.4 before 11.2.12.10, from 11.3 before 11.6.0.3, and from 11.7 before 11.7.3. Whether OTP before OTP 17.0, corresponding to ssl before 5.3.4, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-54891.html",
                "https://github.com/erlang/otp/commit/07d2d0e93f6aaf7652a81e8df075fc1728da5e96",
                "https://github.com/erlang/otp/security/advisories/GHSA-gf6r-99xw-6qg6",
                "https://osv.dev/vulnerability/EEF-CVE-2026-54891",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions"
            ],
            "timeline": [
                {
                    "at": "2026-07-02T17:17:02.747",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54891"
                }
            ]
        },
        {
            "id": "CVE-2026-54874",
            "vendor": "OpenSSL",
            "product": "OpenSSL",
            "title": "OpenSSL vulnerability",
            "summary": "Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell",
            "updated_at": "2026-09-11T21:16:28.067",
            "published_at": "2026-08-25T13:19:24.033",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.0.2 (semver); 3.6.0 through before 3.6.4 (semver); 3.5.0 through before 3.5.8 (semver); 3.4.0 through before 3.4.7 (semver); 3.0.0 through before 3.0.22 (semver); 1.1.1 through before 1.1.1zi (custom); 1.0.2 through before 1.0.2zr (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-405",
            "what_happened": "Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23",
                "https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40",
                "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382",
                "https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107",
                "https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c",
                "https://openssl-library.org/news/secadv/20260825.txt"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T13:19:24.033",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54874"
                }
            ]
        },
        {
            "id": "CVE-2026-54787",
            "vendor": "sigstore",
            "product": "sigstore-go",
            "title": "sigstore-go vulnerability",
            "summary": "sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.",
            "updated_at": "2026-09-10T20:30:11.423",
            "published_at": "2026-07-31T23:17:25.287",
            "cvss": 3.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.2.1",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-324",
            "what_happened": "sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window of an ExpiringKey wrapping a self-managed long-lived signing key without a certificate, which can allow an attacker holding expired key material to sign accepted bundles. This issue is fixed in version 1.2.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/sigstore/sigstore-go/commit/4594ab4c779d08be1f4419803a8249188f35ed5f",
                "https://github.com/sigstore/sigstore-go/pull/642",
                "https://github.com/sigstore/sigstore-go/releases/tag/v1.2.1",
                "https://github.com/sigstore/sigstore-go/security/advisories/GHSA-wqqc-jjcq-vfxm"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T23:17:25.287",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54787"
                }
            ]
        },
        {
            "id": "CVE-2026-54785",
            "vendor": "eLyiN",
            "product": "gemini-bridge",
            "title": "gemini-bridge vulnerability",
            "summary": "gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining it to the working directory, then forwarded the contents to the Gemini CLI. Because the caller also controls query, the file contents are echoed back through the Gemini round-trip (and sent to Google), making this an arbitrary local file read. This issue is fixed in version 1.3.1.",
            "updated_at": "2026-09-10T20:31:16.483",
            "published_at": "2026-07-31T23:17:25.133",
            "cvss": 6.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 1.0.0, < 1.3.1",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "gemini-bridge is a lightweight MCP server bridging AI agents to Google's Gemini AI via the official CLI. From 1.0.0 until 1.3.1, consult_gemini_with_files in inline mode read any file path supplied in the files argument without confining it to the working directory, then forwarded the contents to the Gemini CLI. Because the caller also controls query, the file contents are echoed back through the Gemini round-trip (and sent to Google), making this an arbitrary local file read. This issue is fixed in version 1.3.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/eLyiN/gemini-bridge/commit/8f3b85afd02b692c4bc974b5176e12fb277ea801",
                "https://github.com/eLyiN/gemini-bridge/pull/9",
                "https://github.com/eLyiN/gemini-bridge/releases/tag/v1.3.1",
                "https://github.com/eLyiN/gemini-bridge/security/advisories/GHSA-c5px-58j2-7fqp"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T23:17:25.133",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54785"
                }
            ]
        },
        {
            "id": "CVE-2026-54768",
            "vendor": "wp-graphql",
            "product": "wp-graphql",
            "title": "wp-graphql vulnerability",
            "summary": "WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in version 2.15.1.",
            "updated_at": "2026-09-10T20:30:11.423",
            "published_at": "2026-07-31T23:17:24.973",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.15.1",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-204",
            "what_happened": "WPGraphQL provides a GraphQL API for WordPress sites. From 2.0.0 until 2.15.1, the deprecated user field on SendPasswordResetEmailPayload lets an unauthenticated caller distinguish existing author-class accounts through the sendPasswordResetEmail mutation and obtain public profile fields. This issue is fixed in version 2.15.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/wp-graphql/wp-graphql/releases/tag/wp-graphql/v2.15.1",
                "https://github.com/wp-graphql/wp-graphql/security/advisories/GHSA-jhh7-832h-f8hv"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T23:17:24.973",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54768"
                }
            ]
        },
        {
            "id": "CVE-2026-54737",
            "vendor": "phun-ky",
            "product": "defaults-deep",
            "title": "defaults-deep vulnerability",
            "summary": "@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, allowing properties to be written to Object.prototype. This issue is fixed in version 2.0.5.",
            "updated_at": "2026-09-10T20:12:43.783",
            "published_at": "2026-07-31T18:17:17.330",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.0.5",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1321",
            "what_happened": "@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, allowing properties to be written to Object.prototype. This issue is fixed in version 2.0.5.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/phun-ky/defaults-deep/commit/807dba930f8718f9126cad59d949b8fd3539b059",
                "https://github.com/phun-ky/defaults-deep/pull/49",
                "https://github.com/phun-ky/defaults-deep/releases/tag/2.0.5",
                "https://github.com/phun-ky/defaults-deep/security/advisories/GHSA-mj3g-7xcc-x4vh"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T18:17:17.330",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54737"
                }
            ]
        },
        {
            "id": "CVE-2026-54729",
            "vendor": "HackingRepo",
            "product": "dssrf-js",
            "title": "dssrf-js vulnerability",
            "summary": "DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no address and no dns.lookup fallback occurs, allowing server-side request forgery. This issue is fixed in version 1.0.5.",
            "updated_at": "2026-09-10T20:12:43.783",
            "published_at": "2026-07-31T18:17:17.173",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.0.5",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no address and no dns.lookup fallback occurs, allowing server-side request forgery. This issue is fixed in version 1.0.5.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/HackingRepo/dssrf-js/commit/668c21792cd1252baf779a176aa652e2b4c0067d",
                "https://github.com/HackingRepo/dssrf-js/pull/102",
                "https://github.com/HackingRepo/dssrf-js/security/advisories/GHSA-5846-7qm3-r52j"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T18:17:17.173",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54729"
                }
            ]
        },
        {
            "id": "CVE-2026-54725",
            "vendor": "bank-vaults",
            "product": "vault-secrets-webhook",
            "title": "vault-secrets-webhook vulnerability",
            "summary": "vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and vault.security.banzaicloud.io/vault-serviceaccount can cause a ServiceAccount JWT to be sent to an attacker-controlled Vault address. This issue is fixed in version 1.23.1.",
            "updated_at": "2026-09-10T20:12:43.783",
            "published_at": "2026-07-31T18:17:17.013",
            "cvss": 9.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.23.1",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and vault.security.banzaicloud.io/vault-serviceaccount can cause a ServiceAccount JWT to be sent to an attacker-controlled Vault address. This issue is fixed in version 1.23.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/bank-vaults/vault-secrets-webhook/commit/76db45976fee0f54cafd94dffa425e6b542f65a0",
                "https://github.com/bank-vaults/vault-secrets-webhook/releases/tag/v1.23.1",
                "https://github.com/bank-vaults/vault-secrets-webhook/security/advisories/GHSA-r2v3-8gwf-7ghm"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T18:17:17.013",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54725"
                }
            ]
        },
        {
            "id": "CVE-2026-54722",
            "vendor": "HackingRepo",
            "product": "dssrf-js",
            "title": "dssrf-js vulnerability",
            "summary": "DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the @ userinfo delimiter with remove_at_symbol_in_string before new URL parses the URL, allowing an attacker-controlled URL to bypass internal-IP validation and cause a client using the original URL to reach an internal service. This issue is fixed in version 1.0.4.",
            "updated_at": "2026-09-10T20:12:43.783",
            "published_at": "2026-07-30T17:16:33.180",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.0.4",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-76",
            "what_happened": "DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the @ userinfo delimiter with remove_at_symbol_in_string before new URL parses the URL, allowing an attacker-controlled URL to bypass internal-IP validation and cause a client using the original URL to reach an internal service. This issue is fixed in version 1.0.4.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/HackingRepo/dssrf-js/commit/9211f91bf532433a1a1b27d946571546a63664b3",
                "https://github.com/HackingRepo/dssrf-js/issues/97",
                "https://github.com/HackingRepo/dssrf-js/pull/98",
                "https://github.com/HackingRepo/dssrf-js/security/advisories/GHSA-cg4g-m8jx-vjv2"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T17:16:33.180",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54722"
                }
            ]
        },
        {
            "id": "CVE-2026-54715",
            "vendor": "allinurl",
            "product": "goaccess",
            "title": "goaccess vulnerability",
            "summary": "GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five, allowing a crafted User-Agent in a processed access log to write one to four attacker-influenced bytes beyond the heap allocation and corrupt or crash GoAccess. This issue is fixed in version 1.11.",
            "updated_at": "2026-09-08T20:51:43.490",
            "published_at": "2026-07-30T21:17:49.323",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 1.10.2, < 1.11",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five, allowing a crafted User-Agent in a processed access log to write one to four attacker-influenced bytes beyond the heap allocation and corrupt or crash GoAccess. This issue is fixed in version 1.11.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/allinurl/goaccess/commit/81f90d9dafd6956c188dea9f944d24946d3d3351",
                "https://github.com/allinurl/goaccess/security/advisories/GHSA-qcx5-vh2x-35fr"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T21:17:49.323",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54715"
                }
            ]
        },
        {
            "id": "CVE-2026-54707",
            "vendor": "onionshare",
            "product": "onionshare",
            "title": "onionshare vulnerability",
            "summary": "OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionshare_cli/web/receive_mode.py, where ReceiveModeRequest._get_file_stream() writes multipart file[] data to disk despite the text-only setting. This issue is fixed in version 2.6.4.",
            "updated_at": "2026-09-10T20:12:43.783",
            "published_at": "2026-07-31T17:16:33.870",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.6.4",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionshare_cli/web/receive_mode.py, where ReceiveModeRequest._get_file_stream() writes multipart file[] data to disk despite the text-only setting. This issue is fixed in version 2.6.4.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/onionshare/onionshare/commit/a090e97193efc91fbeac9dace7793ea568b83cf5",
                "https://github.com/onionshare/onionshare/releases/tag/v2.6.4",
                "https://github.com/onionshare/onionshare/security/advisories/GHSA-v833-3823-cmhp"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T17:16:33.870",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54707"
                }
            ]
        },
        {
            "id": "CVE-2026-54706",
            "vendor": "onionshare",
            "product": "onionshare",
            "title": "onionshare vulnerability",
            "summary": "OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.",
            "updated_at": "2026-09-10T20:12:43.783",
            "published_at": "2026-07-31T17:16:33.723",
            "cvss": 4.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.6.4",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-59",
            "what_happened": "OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/onionshare/onionshare/commit/48f31cfac077fcc9c04c67c2a6dbf87d956f5eec",
                "https://github.com/onionshare/onionshare/releases/tag/v2.6.4",
                "https://github.com/onionshare/onionshare/security/advisories/GHSA-22p9-r2f5-22mf"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T17:16:33.723",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54706"
                }
            ]
        },
        {
            "id": "CVE-2026-54680",
            "vendor": "kube-logging",
            "product": "logging-operator",
            "title": "logging-operator vulnerability",
            "summary": "Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without escaping, allowing a user who can create Flow resources to inject a Fluentd <match **> block using @type exec and execute arbitrary commands inside the Fluentd aggregator. This issue is fixed in version 6.6.0.",
            "updated_at": "2026-09-10T20:12:43.783",
            "published_at": "2026-07-29T17:16:52.900",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 6.6.0",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without escaping, allowing a user who can create Flow resources to inject a Fluentd <match **> block using @type exec and execute arbitrary commands inside the Fluentd aggregator. This issue is fixed in version 6.6.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/kube-logging/logging-operator/commit/cf437d7f1e056c78740bf5716ac8bdebcf002425",
                "https://github.com/kube-logging/logging-operator/releases/tag/6.6.0",
                "https://github.com/kube-logging/logging-operator/security/advisories/GHSA-mjqf-28ph-426h"
            ],
            "timeline": [
                {
                    "at": "2026-07-29T17:16:52.900",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54680"
                }
            ]
        },
        {
            "id": "CVE-2026-54650",
            "vendor": "bablilayoub",
            "product": "openhole",
            "title": "openhole vulnerability",
            "summary": "openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent encoded dot segments %2e and separators %2f to reach tunneled local services as ../ and / for path traversal. This issue is fixed in version 0.1.2.",
            "updated_at": "2026-09-10T20:05:05.293",
            "published_at": "2026-07-28T23:17:08.763",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 0.1.2",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent encoded dot segments %2e and separators %2f to reach tunneled local services as ../ and / for path traversal. This issue is fixed in version 0.1.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/bablilayoub/openhole/commit/a28c27adde2a7ed0c347b730c8707208c0f78ed3",
                "https://github.com/bablilayoub/openhole/releases/tag/v0.1.2",
                "https://github.com/bablilayoub/openhole/security/advisories/GHSA-fh2f-xfxc-q9cc"
            ],
            "timeline": [
                {
                    "at": "2026-07-28T23:17:08.763",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54650"
                }
            ]
        },
        {
            "id": "CVE-2026-54647",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CubeCart 6.7.4 - SQL injection",
            "summary": "CubeCart 6.7.4 - SQL injection",
            "updated_at": "2026-08-30T22:00:00Z",
            "published_at": "2026-08-30T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 96,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52664",
                    "author": "Mikail KOCADAĞ",
                    "first_seen": "2026-08-31",
                    "confidence": "High",
                    "title": "CubeCart 6.7.4 - SQL injection",
                    "summary": "CubeCart 6.7.4 - SQL injection",
                    "url": "https://www.exploit-db.com/exploits/52664",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52664"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52664"
                }
            ]
        },
        {
            "id": "CVE-2026-54646",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CubeCart 6.7.4 - SQL",
            "summary": "CubeCart 6.7.4 - SQL",
            "updated_at": "2026-08-30T22:00:00Z",
            "published_at": "2026-08-30T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 96,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52663",
                    "author": "Mikail KOCADAĞ",
                    "first_seen": "2026-08-31",
                    "confidence": "High",
                    "title": "CubeCart 6.7.4 - SQL",
                    "summary": "CubeCart 6.7.4 - SQL",
                    "url": "https://www.exploit-db.com/exploits/52663",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52663"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52663"
                }
            ]
        },
        {
            "id": "CVE-2026-54645",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CubeCart 6.7.4 - Stored XSS",
            "summary": "CubeCart 6.7.4 - Stored XSS",
            "updated_at": "2026-08-30T22:00:00Z",
            "published_at": "2026-08-30T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 96,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52662",
                    "author": "Mikail KOCADAĞ",
                    "first_seen": "2026-08-31",
                    "confidence": "High",
                    "title": "CubeCart 6.7.4 - Stored XSS",
                    "summary": "CubeCart 6.7.4 - Stored XSS",
                    "url": "https://www.exploit-db.com/exploits/52662",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52662"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52662"
                }
            ]
        },
        {
            "id": "CVE-2026-54644",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CubeCart 6.7.4 - Cross-Site Scripting",
            "summary": "CubeCart 6.7.4 - Cross-Site Scripting",
            "updated_at": "2026-08-30T22:00:00Z",
            "published_at": "2026-08-30T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 96,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52661",
                    "author": "Mikail KOCADAĞ",
                    "first_seen": "2026-08-31",
                    "confidence": "High",
                    "title": "CubeCart 6.7.4 - Cross-Site Scripting",
                    "summary": "CubeCart 6.7.4 - Cross-Site Scripting",
                    "url": "https://www.exploit-db.com/exploits/52661",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52661"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52661"
                }
            ]
        },
        {
            "id": "CVE-2026-54638",
            "vendor": "gotd",
            "product": "td",
            "title": "td vulnerability",
            "summary": "gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, dataLen) before checking the remaining buffer, allowing remote unauthenticated denial of service through excessive memory allocation and CPU or garbage collection pressure. This issue is fixed in version 0.145.1.",
            "updated_at": "2026-09-10T20:05:05.293",
            "published_at": "2026-07-28T23:17:08.617",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 0.145.1",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, dataLen) before checking the remaining buffer, allowing remote unauthenticated denial of service through excessive memory allocation and CPU or garbage collection pressure. This issue is fixed in version 0.145.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/gotd/td/commit/9d5d1f31ea5022d9798d84ccce15de2e91ba6baa",
                "https://github.com/gotd/td/issues/1711",
                "https://github.com/gotd/td/releases/tag/v0.145.1",
                "https://github.com/gotd/td/security/advisories/GHSA-whmm-qj9r-wvr2"
            ],
            "timeline": [
                {
                    "at": "2026-07-28T23:17:08.617",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54638"
                }
            ]
        },
        {
            "id": "CVE-2026-54605",
            "vendor": "ruby-oauth",
            "product": "oauth",
            "title": "oauth vulnerability",
            "summary": "OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer's configuration and expose signed OAuth request metadata, including the Authorization header, to a cross-origin host. This issue is fixed in version 1.1.6.",
            "updated_at": "2026-09-09T20:50:00.950",
            "published_at": "2026-07-28T17:16:52.367",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 0.5.5, < 1.1.6",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parses the raw Location header of a 300 to 399 redirect returned by the OAuth server and follows the redirect recursively, which can mutate the consumer's configuration and expose signed OAuth request metadata, including the Authorization header, to a cross-origin host. This issue is fixed in version 1.1.6.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ruby-oauth/oauth/commit/d069dc8c4c9631947451215f07460d6cdf0caf3f",
                "https://github.com/ruby-oauth/oauth/releases/tag/v1.1.6",
                "https://github.com/ruby-oauth/oauth/security/advisories/GHSA-prq8-7wvh-44qh"
            ],
            "timeline": [
                {
                    "at": "2026-07-28T17:16:52.367",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54605"
                }
            ]
        },
        {
            "id": "CVE-2026-54603",
            "vendor": "ruby-oauth",
            "product": "oauth2",
            "title": "oauth2 vulnerability",
            "summary": "OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host, leaking the credential. This issue is fixed in version 2.0.22.",
            "updated_at": "2026-09-09T20:50:00.950",
            "published_at": "2026-07-28T17:16:52.227",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 0.4.0, < 2.0.22",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relative redirect Location returned to OAuth2::Client#request overrides the request authority, so the bearer Authorization header is sent to an attacker-controlled host, leaking the credential. This issue is fixed in version 2.0.22.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ruby-oauth/oauth2/commit/0f0a474f1b38453e119e660c2daca742d4378ce9",
                "https://github.com/ruby-oauth/oauth2/releases/tag/v2.0.22",
                "https://github.com/ruby-oauth/oauth2/security/advisories/GHSA-pp92-crg2-gfv9"
            ],
            "timeline": [
                {
                    "at": "2026-07-28T17:16:52.227",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54603"
                }
            ]
        },
        {
            "id": "CVE-2026-54513",
            "vendor": "FasterXML",
            "product": "jackson-databind",
            "title": "jackson-databind vulnerability",
            "summary": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
            "updated_at": "2026-09-11T13:18:15.873",
            "published_at": "2026-06-23T21:17:02.333",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 2.10.0, < 2.18.8; >= 2.19.0, < 2.21.4; >= 3.0.0, < 3.1.4",
            "fixed": "See vendor advisory",
            "source_count": 32,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-184",
            "what_happened": "jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/FasterXML/jackson-databind/commit/01d1692c8d0ed03e51a0e3c4f8a9e6908e4931e5",
                "https://github.com/FasterXML/jackson-databind/commit/24529da29fdf46ff94ca38de9ebf31cd188f5e8e",
                "https://github.com/FasterXML/jackson-databind/issues/5981",
                "https://github.com/FasterXML/jackson-databind/issues/5983",
                "https://github.com/FasterXML/jackson-databind/pull/5984",
                "https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rmj7-2vxq-3g9f",
                "https://access.redhat.com/errata/RHSA-2026:36839",
                "https://access.redhat.com/errata/RHSA-2026:40895",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:43218",
                "https://access.redhat.com/errata/RHSA-2026:43400",
                "https://access.redhat.com/errata/RHSA-2026:44061",
                "https://access.redhat.com/errata/RHSA-2026:44062",
                "https://access.redhat.com/errata/RHSA-2026:44063",
                "https://access.redhat.com/errata/RHSA-2026:44064",
                "https://access.redhat.com/errata/RHSA-2026:44065",
                "https://access.redhat.com/errata/RHSA-2026:44066",
                "https://access.redhat.com/errata/RHSA-2026:44271",
                "https://access.redhat.com/errata/RHSA-2026:48095",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:50846",
                "https://access.redhat.com/errata/RHSA-2026:50847",
                "https://access.redhat.com/errata/RHSA-2026:50848",
                "https://access.redhat.com/errata/RHSA-2026:50849",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:54622",
                "https://access.redhat.com/errata/RHSA-2026:62260",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-54513",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492010",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54513.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-23T21:17:02.333",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54513"
                }
            ]
        },
        {
            "id": "CVE-2026-54457",
            "vendor": "tensorzero",
            "product": "tensorzero",
            "title": "tensorzero vulnerability",
            "summary": "TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON storage_path parameter that dynamically overrides the [object_storage] configuration. Selecting the filesystem storage type allows arbitrary files on the gateway filesystem to be read, including credential files. Selecting the s3_compatible storage type causes outbound object-storage requests to attacker-chosen internal or cloud-metadata endpoints. Exploitation requires access to the gateway, which can be authenticated or unauthenticated depending on deployment configuration. This issue is fixed in version 2026.6.0.",
            "updated_at": "2026-09-11T18:24:59.400",
            "published_at": "2026-08-21T21:17:00.267",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2026.6.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-552",
            "what_happened": "TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero Gateway /internal/object_storage endpoint accepts a caller-supplied JSON storage_path parameter that dynamically overrides the [object_storage] configuration. Selecting the filesystem storage type allows arbitrary files on the gateway filesystem to be read, including credential files. Selecting the s3_compatible storage type causes outbound object-storage requests to attacker-chosen internal or cloud-metadata endpoints. Exploitation requires access to the gateway, which can be authenticated or unauthenticated depending on deployment configuration. This issue is fixed in version 2026.6.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/tensorzero/tensorzero/commit/0abbc838bae3394fe7491dad7009670d4e3b6cf8",
                "https://github.com/tensorzero/tensorzero/releases/tag/2026.6.0",
                "https://github.com/tensorzero/tensorzero/security/advisories/GHSA-824w-x939-6cmc"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T21:17:00.267",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54457"
                }
            ]
        },
        {
            "id": "CVE-2026-54422",
            "vendor": "OpenStack",
            "product": "Ironic Python Agent",
            "title": "Ironic Python Agent vulnerability",
            "summary": "In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.",
            "updated_at": "2026-09-09T16:03:22.897",
            "published_at": "2026-07-24T05:16:45.460",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.2.0 through before 10.2.3 (semver); 11.0.0 through before 11.2.1 (semver); 11.3.0 through before 11.5.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-522",
            "what_happened": "In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugs.launchpad.net/ironic-python-agent/+bug/2155826",
                "https://security.openstack.org/ossa/OSSA-2026-028.html",
                "https://www.openwall.com/lists/oss-security/2026/07/23/4",
                "http://www.openwall.com/lists/oss-security/2026/07/23/4"
            ],
            "timeline": [
                {
                    "at": "2026-07-24T05:16:45.460",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54422"
                }
            ]
        },
        {
            "id": "CVE-2026-54371",
            "vendor": "attr project",
            "product": "attr",
            "title": "attr vulnerability",
            "summary": "attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.",
            "updated_at": "2026-09-11T13:18:15.587",
            "published_at": "2026-06-29T14:16:57.823",
            "cvss": 8.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.6.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-59",
            "what_happened": "attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f",
                "https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b",
                "https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr",
                "https://access.redhat.com/errata/RHSA-2026:34889",
                "https://access.redhat.com/errata/RHSA-2026:56133",
                "https://access.redhat.com/errata/RHSA-2026:59380",
                "https://access.redhat.com/errata/RHSA-2026:60226",
                "https://access.redhat.com/errata/RHSA-2026:61783",
                "https://access.redhat.com/errata/RHSA-2026:63135",
                "https://access.redhat.com/errata/RHSA-2026:63138",
                "https://access.redhat.com/errata/RHSA-2026:66018",
                "https://access.redhat.com/security/cve/CVE-2026-54371",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2490283",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-29T14:16:57.823",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54371"
                }
            ]
        },
        {
            "id": "CVE-2026-54280",
            "vendor": "aio-libs",
            "product": "aiohttp",
            "title": "aiohttp vulnerability",
            "summary": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation temporarily until garbage collection or similar closes the file. This vulnerability is fixed in 3.14.1.",
            "updated_at": "2026-09-16T20:15:00.917",
            "published_at": "2026-06-22T18:16:46.670",
            "cvss": 1.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.14.1",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-404",
            "what_happened": "AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation temporarily until garbage collection or similar closes the file. This vulnerability is fixed in 3.14.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/aio-libs/aiohttp/commit/a762eda5242f6490d6ba667533193f8b473ad587",
                "https://github.com/aio-libs/aiohttp/security/advisories/GHSA-9x8q-7h8h-wcw9"
            ],
            "timeline": [
                {
                    "at": "2026-06-22T18:16:46.670",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54280"
                }
            ]
        },
        {
            "id": "CVE-2026-54272",
            "vendor": "beaugunderson",
            "product": "ip-address",
            "title": "ip-address vulnerability",
            "summary": "ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifies an address by matching it against a table of known IPv6 special-use prefixes, returning Global unicast when nothing matches. That table had no entry for the IPv4-mapped range (::ffff:0:0/96), so every mapped address fell through to Global unicast; NAT64 addresses matched their own NAT64 … labels. The boolean checks isLoopback, isUnspecified, and isMulticast compared getType() against a fixed label and so returned false, while isLinkLocal and isULA checked only the native IPv6 ranges. The library already exposed isMapped4() and to4(), but did not apply them inside these checks, so a mapped or NAT64 address was never normalized to its embedded IPv4 address before classification. For IPv4-mapped addresses the host OS routes to the IPv4 stack, so the misclassification is reachable on any dual-stack host. For NAT64, the classification bypass is unconditional but end-to-end reachability additionally requires a NAT64/DNS64 gateway in the deployment network.This issue has been fixed in version 10.2.1.",
            "updated_at": "2026-09-09T20:50:00.950",
            "published_at": "2026-07-27T18:16:56.410",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 10.1.1, < 10.2.1",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifies an address by matching it against a table of known IPv6 special-use prefixes, returning Global unicast when nothing matches. That table had no entry for the IPv4-mapped range (::ffff:0:0/96), so every mapped address fell through to Global unicast; NAT64 addresses matched their own NAT64 … labels. The boolean checks isLoopback, isUnspecified, and isMulticast compared getType() against a fixed label and so returned false, while isLinkLocal and isULA checked only the native IPv6 ranges. The library already exposed isMapped4() and to4(), but did not apply them inside these checks, so a mapped or NAT64 address was never normalized to its embedded IPv4 address before classification. For IPv4-mapped addresses the host OS routes to the IPv4 stack, so the misclassification is reachable on any dual-stack host. For NAT64, the classification bypass is unconditional but end-to-end reachability additionally requires a NAT64/DNS64 gateway in the deployment network.This issue has been fixed in version 10.2.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/beaugunderson/ip-address/security/advisories/GHSA-22jq-vg5j-6vgg"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T18:16:56.410",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54272"
                }
            ]
        },
        {
            "id": "CVE-2026-54218",
            "vendor": "Tobit Laboratories AG",
            "product": "TeamDavid",
            "title": "TeamDavid vulnerability",
            "summary": "Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various \nfiles using only obfuscation. Any user with access to the server’s file \nsystem, or who can otherwise extract files from the server (see \nvulnerability “Random File Read”), can potentially obtain affected \nusers’ passwords. This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.",
            "updated_at": "2026-09-07T14:16:53.357",
            "published_at": "2026-08-07T10:16:59.153",
            "cvss": 8.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before Rollout 528 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-321",
            "what_happened": "Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various \nfiles using only obfuscation. Any user with access to the server’s file \nsystem, or who can otherwise extract files from the server (see \nvulnerability “Random File Read”), can potentially obtain affected \nusers’ passwords. This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://chayns.net/77892-10814/tapp/763210?postId=11454",
                "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            ],
            "timeline": [
                {
                    "at": "2026-08-07T10:16:59.153",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54218"
                }
            ]
        },
        {
            "id": "CVE-2026-54217",
            "vendor": "Tobit Laboratories AG",
            "product": "TeamDavid",
            "title": "TeamDavid vulnerability",
            "summary": "Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An \nattacker can send an email containing malicious JavaScript code. When a \nuser accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.",
            "updated_at": "2026-09-07T14:16:52.947",
            "published_at": "2026-08-07T10:16:59.027",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before Rollout 528 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An \nattacker can send an email containing malicious JavaScript code. When a \nuser accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://chayns.net/77892-10814/tapp/763210?postId=11454",
                "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            ],
            "timeline": [
                {
                    "at": "2026-08-07T10:16:59.027",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54217"
                }
            ]
        },
        {
            "id": "CVE-2026-54216",
            "vendor": "Tobit Laboratories AG",
            "product": "TeamDavid",
            "title": "TeamDavid vulnerability",
            "summary": "Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) \nvulnerability. By sending a specially crafted link including an \narbitrary path, an XSS payload or the parameter “EntryInfo”, and the \nparameter “!templateName=entryMail”, an attacker can cause the payload \nto execute in the victim’s browser when they click the link. This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.",
            "updated_at": "2026-09-07T14:16:52.533",
            "published_at": "2026-08-07T10:16:58.893",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before Rollout 528 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) \nvulnerability. By sending a specially crafted link including an \narbitrary path, an XSS payload or the parameter “EntryInfo”, and the \nparameter “!templateName=entryMail”, an attacker can cause the payload \nto execute in the victim’s browser when they click the link. This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://chayns.net/77892-10814/tapp/763210?postId=11454",
                "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            ],
            "timeline": [
                {
                    "at": "2026-08-07T10:16:58.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54216"
                }
            ]
        },
        {
            "id": "CVE-2026-54215",
            "vendor": "Tobit Laboratories AG",
            "product": "TeamDavid",
            "title": "TeamDavid vulnerability",
            "summary": "Tobit Laboratories AG TeamDavid's Webbox  contains an open redirect vulnerability via the \n“replyUrl” parameter. An attacker can exploit this vulnerability to \ncraft a URL within the application that, when visited, redirects the \nuser’s browser to an arbitrary third-party site. This can be abused for \nphishing attacks, where users receive a trusted domain link but are \nredirected to a phishing website. This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.",
            "updated_at": "2026-09-07T14:16:52.097",
            "published_at": "2026-08-07T10:16:58.763",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before Rollout 528 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-601",
            "what_happened": "Tobit Laboratories AG TeamDavid's Webbox  contains an open redirect vulnerability via the \n“replyUrl” parameter. An attacker can exploit this vulnerability to \ncraft a URL within the application that, when visited, redirects the \nuser’s browser to an arbitrary third-party site. This can be abused for \nphishing attacks, where users receive a trusted domain link but are \nredirected to a phishing website. This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://chayns.net/77892-10814/tapp/763210?postId=11454",
                "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            ],
            "timeline": [
                {
                    "at": "2026-08-07T10:16:58.763",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54215"
                }
            ]
        },
        {
            "id": "CVE-2026-54196",
            "vendor": "Jetmonsters",
            "product": "JetFormBuilder",
            "title": "JetFormBuilder vulnerability",
            "summary": "Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation.\n\nThis issue affects JetFormBuilder: from n/a through 3.6.1.",
            "updated_at": "2026-09-16T12:17:04.600",
            "published_at": "2026-06-17T13:20:50.960",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a through 3.6.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-266",
            "what_happened": "Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation.\n\nThis issue affects JetFormBuilder: from n/a through 3.6.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://patchstack.com/database/wordpress/plugin/jetformbuilder/vulnerability/wordpress-jetformbuilder-plugin-3-6-1-privilege-escalation-vulnerability?_s_id=cve"
            ],
            "timeline": [
                {
                    "at": "2026-06-17T13:20:50.960",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54196"
                }
            ]
        },
        {
            "id": "CVE-2026-54183",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a deeply-nested value was shown unmasked in the Variables UI. The exposure is limited to the UI: any authenticated user who can see the Variable in the UI can already read its full value through the Variables REST API, so this does not disclose data the user could not otherwise obtain — the masking is a shoulder-surfing defense for the UI, not an access-control boundary.\n\nThis is an incomplete-fix follow-up to CVE-2026-42358, whose fix made only the dictionary walk unbounded; lists, tuples, and sets beyond the depth limit remained unmasked in the UI. Deployments that applied the CVE-2026-42358 fix should also upgrade to address this residual case. Upgrade to apache-airflow 3.3.1 or later.",
            "updated_at": "2026-09-16T15:17:37.610",
            "published_at": "2026-08-12T16:17:04.640",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.3.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The masker's recursion-depth limit did not descend into values nested inside a list, tuple, or set beyond that limit, so an Airflow Variable holding such a deeply-nested value was shown unmasked in the Variables UI. The exposure is limited to the UI: any authenticated user who can see the Variable in the UI can already read its full value through the Variables REST API, so this does not disclose data the user could not otherwise obtain — the masking is a shoulder-surfing defense for the UI, not an access-control boundary.\n\nThis is an incomplete-fix follow-up to CVE-2026-42358, whose fix made only the dictionary walk unbounded; lists, tuples, and sets beyond the depth limit remained unmasked in the UI. Deployments that applied the CVE-2026-42358 fix should also upgrade to address this residual case. Upgrade to apache-airflow 3.3.1 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/68422",
                "https://lists.apache.org/thread/z5mrdq6c60f2wyx4cc64cj8nv0dxd9lo",
                "https://www.cve.org/CVERecord?id=CVE-2026-42358"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T16:17:04.640",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54183"
                }
            ]
        },
        {
            "id": "CVE-2026-54121",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
            "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
            "updated_at": "2026-09-11T22:10:10Z",
            "published_at": "2026-09-11T22:10:10Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 69,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                },
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-54121-Certighost",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:10:10Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2026-54100",
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift for Windows Containers 10.21",
            "title": "Red Hat OpenShift for Windows Containers 10.21 vulnerability",
            "summary": "A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet bootstrap credentials transferred during node configuration, enabling compromise of Windows node identities in the cluster.",
            "updated_at": "2026-09-06T20:17:27.890",
            "published_at": "2026-06-22T14:17:40.950",
            "cvss": 8.3,
            "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0 through 4.22.1",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet bootstrap credentials transferred during node configuration, enabling compromise of Windows node identities in the cluster.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:47173",
                "https://access.redhat.com/errata/RHSA-2026:61780",
                "https://access.redhat.com/security/cve/CVE-2026-54100",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2487953",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54100.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-22T14:17:40.950",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54100"
                }
            ]
        },
        {
            "id": "CVE-2026-54099",
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift for Windows Containers 10.21",
            "title": "Red Hat OpenShift for Windows Containers 10.21 vulnerability",
            "summary": "A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.",
            "updated_at": "2026-09-06T20:17:27.663",
            "published_at": "2026-06-22T14:17:40.820",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0 through before 4.22.1",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:47173",
                "https://access.redhat.com/errata/RHSA-2026:61780",
                "https://access.redhat.com/security/cve/CVE-2026-54099",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2487950",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54099.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-22T14:17:40.820",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54099"
                }
            ]
        },
        {
            "id": "CVE-2026-54085",
            "vendor": "wazuh",
            "product": "wazuh",
            "title": "wazuh vulnerability",
            "summary": "Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response scripts pass attacker-influenced alert fields to privileged system commands without validating their format, allowing argument injection into tools that run as root. Five of the eight scripts that handle the srcip field, route-null.c, netsh.c, pf.c, npf.c, and ipfw.c, omit the get_ip_version() check that rejects non-IP input, and disable-account.c passes the dstuser field to passwd/chuser with only a comparison against \"root\". An attacker who can inject crafted log events, for example via syslog, can supply srcip or dstuser values that, when an active response rule triggers, are passed unvalidated to firewall and account-management commands such as pfctl, npfctl, ipfw, route, netsh, and passwd. This enables injecting additional command arguments, and on Windows the unquoted CreateProcess command-line concatenation in wpopenv() lets a srcip containing spaces add further arguments, while disable-account.c can be abused to lock arbitrary system accounts. This issue is fixed in version 4.14.7.",
            "updated_at": "2026-09-15T19:14:47.517",
            "published_at": "2026-08-28T00:18:07.520",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 4.2.0, < 4.14.7",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-88",
            "what_happened": "Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response scripts pass attacker-influenced alert fields to privileged system commands without validating their format, allowing argument injection into tools that run as root. Five of the eight scripts that handle the srcip field, route-null.c, netsh.c, pf.c, npf.c, and ipfw.c, omit the get_ip_version() check that rejects non-IP input, and disable-account.c passes the dstuser field to passwd/chuser with only a comparison against \"root\". An attacker who can inject crafted log events, for example via syslog, can supply srcip or dstuser values that, when an active response rule triggers, are passed unvalidated to firewall and account-management commands such as pfctl, npfctl, ipfw, route, netsh, and passwd. This enables injecting additional command arguments, and on Windows the unquoted CreateProcess command-line concatenation in wpopenv() lets a srcip containing spaces add further arguments, while disable-account.c can be abused to lock arbitrary system accounts. This issue is fixed in version 4.14.7.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/wazuh/wazuh/commit/b7f3a5e59000e4cdef75f397f1107ae3e1c186a9",
                "https://github.com/wazuh/wazuh/security/advisories/GHSA-mvh4-g699-984j"
            ],
            "timeline": [
                {
                    "at": "2026-08-28T00:18:07.520",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54085"
                }
            ]
        },
        {
            "id": "CVE-2026-54084",
            "vendor": "wazuh",
            "product": "wazuh",
            "title": "wazuh vulnerability",
            "summary": "Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.0.0 through 4.14.6, a malicious or man-in-the-middle enrollment manager can crash a Wazuh agent during enrollment by returning a malformed key response with fewer than four fields, causing a NULL pointer dereference. The  w_enrollment_process_agent_key()  routine splits the manager-provided key into four space-separated fields but does not verify that all fields are present before passing them to validators. Because OS_StrBreak() leaves missing trailing entries as NULL and OS_IsValidName() calls strlen() on its argument without a NULL check, a response such as  OSSEC K:'1'  reaches OS_IsValidName(NULL) and terminates the agent process. Since Wazuh permits enrollment against an unverified manager when no CA certificate is configured, an attacker operating a rogue manager or intercepting the enrollment flow can deterministically crash agents, resulting in denial of service. This issue is fixed in version 4.14.7.",
            "updated_at": "2026-09-15T19:16:22.553",
            "published_at": "2026-08-28T00:18:07.370",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.0.0, < 4.14.7",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-476",
            "what_happened": "Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.0.0 through 4.14.6, a malicious or man-in-the-middle enrollment manager can crash a Wazuh agent during enrollment by returning a malformed key response with fewer than four fields, causing a NULL pointer dereference. The  w_enrollment_process_agent_key()  routine splits the manager-provided key into four space-separated fields but does not verify that all fields are present before passing them to validators. Because OS_StrBreak() leaves missing trailing entries as NULL and OS_IsValidName() calls strlen() on its argument without a NULL check, a response such as  OSSEC K:'1'  reaches OS_IsValidName(NULL) and terminates the agent process. Since Wazuh permits enrollment against an unverified manager when no CA certificate is configured, an attacker operating a rogue manager or intercepting the enrollment flow can deterministically crash agents, resulting in denial of service. This issue is fixed in version 4.14.7.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-28",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-ppc7-hj9v-vx39"
                }
            ],
            "references": [
                "https://github.com/wazuh/wazuh/commit/7dfbb4a292bc6ae8e3bb4c1982f687f35216a748",
                "https://github.com/wazuh/wazuh/security/advisories/GHSA-ppc7-hj9v-vx39"
            ],
            "timeline": [
                {
                    "at": "2026-08-28T00:18:07.370",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54084"
                }
            ]
        },
        {
            "id": "CVE-2026-54083",
            "vendor": "wazuh",
            "product": "wazuh",
            "title": "wazuh vulnerability",
            "summary": "Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The  ip-customblock  active response script contains a path traversal vulnerability that lets an attacker create or delete arbitrary files on the filesystem as root. The script builds a file path by concatenating the  srcip  field taken from alert JSON directly onto the fixed  /ipblock/  base directory, without validating that the value is a well-formed IP address. Because the extraction routine returns the raw string unchecked, an attacker who can trigger alert-matching log events with a crafted  srcip  containing  ../  sequences can escape the base directory. The block action opens the resulting path in append mode, creating an empty file at an arbitrary location, while the unblock action passes it to remove(), deleting an arbitrary file; since the active response daemon runs as root, this includes sensitive files such as system credentials and Wazuh configuration. Unlike the sibling scripts host-deny.c, default-firewall-drop.c, and firewalld-drop.c, which reject non-IP input via get_ip_version(), ip-customblock.c omits this validation. This issue is fixed in version 4.14.7.",
            "updated_at": "2026-09-15T19:19:39.370",
            "published_at": "2026-08-28T00:18:07.233",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.2.0, < 4.14.7; >= 5.0.0-alpha0, < 5.0.0-beta3",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The  ip-customblock  active response script contains a path traversal vulnerability that lets an attacker create or delete arbitrary files on the filesystem as root. The script builds a file path by concatenating the  srcip  field taken from alert JSON directly onto the fixed  /ipblock/  base directory, without validating that the value is a well-formed IP address. Because the extraction routine returns the raw string unchecked, an attacker who can trigger alert-matching log events with a crafted  srcip  containing  ../  sequences can escape the base directory. The block action opens the resulting path in append mode, creating an empty file at an arbitrary location, while the unblock action passes it to remove(), deleting an arbitrary file; since the active response daemon runs as root, this includes sensitive files such as system credentials and Wazuh configuration. Unlike the sibling scripts host-deny.c, default-firewall-drop.c, and firewalld-drop.c, which reject non-IP input via get_ip_version(), ip-customblock.c omits this validation. This issue is fixed in version 4.14.7.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-28",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-m4mf-qmhf-8vj6"
                }
            ],
            "references": [
                "https://github.com/wazuh/wazuh/commit/e6ef99025b2ca4ba8003efb591c51545006bc2d4",
                "https://github.com/wazuh/wazuh/security/advisories/GHSA-m4mf-qmhf-8vj6"
            ],
            "timeline": [
                {
                    "at": "2026-08-28T00:18:07.233",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54083"
                }
            ]
        },
        {
            "id": "CVE-2026-53977",
            "vendor": "Bohdan Triapitsyn",
            "product": "OpenChamber",
            "title": "OpenChamber vulnerability",
            "summary": "OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authentication middleware in the Express route handler chain. Attackers can exploit the route registration order in bootstrap-runtime.js to reach the shutdown handler before auth middleware executes, causing denial of service to all active AI coding sessions and locking out legitimate remote users regardless of whether UI_PASSWORD is configured.",
            "updated_at": "2026-09-16T20:18:30.540",
            "published_at": "2026-08-06T16:16:43.483",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.11.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authentication middleware in the Express route handler chain. Attackers can exploit the route registration order in bootstrap-runtime.js to reach the shutdown handler before auth middleware executes, causing denial of service to all active AI coding sessions and locking out legitimate remote users regardless of whether UI_PASSWORD is configured.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openchamber/openchamber",
                "https://github.com/openchamber/openchamber/commit/f1b9506132faf6c564a2694c7f33b94421a49b4a",
                "https://www.vulncheck.com/advisories/openchamber-unauthenticated-dos-via-api-system-shutdown"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T16:16:43.483",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53977"
                }
            ]
        },
        {
            "id": "CVE-2026-53976",
            "vendor": "Bohdan Triapitsyn",
            "product": "OpenChamber",
            "title": "OpenChamber vulnerability",
            "summary": "OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments.",
            "updated_at": "2026-09-16T20:18:30.540",
            "published_at": "2026-08-06T15:16:55.983",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.11.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openchamber/openchamber",
                "https://github.com/openchamber/openchamber/commit/f1b9506132faf6c564a2694c7f33b94421a49b4a",
                "https://www.vulncheck.com/advisories/openchamber-path-traversal-file-read-via-allowoutsideworkspace-parameter"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T15:16:55.983",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53976"
                }
            ]
        },
        {
            "id": "CVE-2026-53975",
            "vendor": "Bohdan Triapitsyn",
            "product": "OpenChamber",
            "title": "OpenChamber vulnerability",
            "summary": "OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.",
            "updated_at": "2026-09-16T20:18:30.540",
            "published_at": "2026-08-06T15:16:55.827",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.11.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openchamber/openchamber",
                "https://github.com/openchamber/openchamber/commit/f1b9506132faf6c564a2694c7f33b94421a49b4a",
                "https://www.vulncheck.com/advisories/openchamber-unauthenticated-rce-via-api-fs-exec"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T15:16:55.827",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53975"
                }
            ]
        },
        {
            "id": "CVE-2026-53683",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.",
            "updated_at": "2026-09-14T08:16:35.127",
            "published_at": "2026-09-02T09:16:38.247",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-601",
            "what_happened": "reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/security/cve/CVE-2026-53683",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2487512"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T09:16:38.247",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53683"
                }
            ]
        },
        {
            "id": "CVE-2026-53613",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-53613-poc",
            "summary": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "updated_at": "2026-08-26T09:53:41Z",
            "published_at": "2026-08-26T09:53:41Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 97,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · mohamedjawady/CVE-2026-53613-poc",
                    "author": "mohamedjawady",
                    "first_seen": "2026-08-26",
                    "last_seen": "2026-08-26T09:53:41Z",
                    "pushed_at": "2026-08-26T09:48:46Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "Shell",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-53613-poc",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/mohamedjawady/CVE-2026-53613-poc"
                }
            ],
            "references": [
                "https://github.com/mohamedjawady/CVE-2026-53613-poc"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T09:53:41Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/mohamedjawady/CVE-2026-53613-poc"
                }
            ]
        },
        {
            "id": "CVE-2026-53599",
            "vendor": "redaxo",
            "product": "core",
            "title": "core vulnerability",
            "summary": "REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polyglot named shell.php.any.jpg, which web servers with multi-extension PHP handlers can execute as the web-server user. This issue is fixed in version 5.21.1.",
            "updated_at": "2026-09-09T20:55:04.493",
            "published_at": "2026-07-31T20:16:51.847",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 5.18.2, < 5.21.1",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-434",
            "what_happened": "REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polyglot named shell.php.any.jpg, which web servers with multi-extension PHP handlers can execute as the web-server user. This issue is fixed in version 5.21.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/redaxo/core/commit/462e36896bb65d292ba22d711044c23c9cfb0340",
                "https://github.com/redaxo/core/pull/6538",
                "https://github.com/redaxo/core/releases/tag/5.21.1",
                "https://github.com/redaxo/core/security/advisories/GHSA-98pp-vccm-qm25"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T20:16:51.847",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53599"
                }
            ]
        },
        {
            "id": "CVE-2026-53573",
            "vendor": "geonetwork",
            "product": "core-geonetwork",
            "title": "core-geonetwork vulnerability",
            "summary": "GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.",
            "updated_at": "2026-09-10T20:30:11.423",
            "published_at": "2026-07-31T23:17:24.667",
            "cvss": 4.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 3.12.0, <= 3.12.12; >= 4.0.0-alpha.1, <= 4.0.6; >= 4.2.0, < 4.2.16; >= 4.4.0, < 4.4.11",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-601",
            "what_happened": "GeoNetwork is a catalog application to manage spatially referenced resources. From 3.12.0 until 4.2.16 and 4.4.11, unsafe redirect validation in GeonetworkOAuth2LoginAuthenticationFilter and KeycloakAuthenticationProcessingFilter permits an attacker-controlled external redirect after login. This issue is fixed in versions 4.2.16 and 4.4.11.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/geonetwork/core-geonetwork/commit/0d74f673dfc926bde935819ed34636d789b2fecd",
                "https://github.com/geonetwork/core-geonetwork/commit/cde9b6481a29e2473b7b74479b4e3fd6843bac4e",
                "https://github.com/geonetwork/core-geonetwork/pull/9307",
                "https://github.com/geonetwork/core-geonetwork/pull/9309",
                "https://github.com/geonetwork/core-geonetwork/releases/tag/4.2.16",
                "https://github.com/geonetwork/core-geonetwork/releases/tag/4.4.11",
                "https://github.com/geonetwork/core-geonetwork/security/advisories/GHSA-pjp7-q6wp-97qx"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T23:17:24.667",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53573"
                }
            ]
        },
        {
            "id": "CVE-2026-53510",
            "vendor": "savonrb",
            "product": "savon",
            "title": "savon vulnerability",
            "summary": "Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is fixed in version 2.17.2.",
            "updated_at": "2026-09-09T20:55:04.493",
            "published_at": "2026-07-31T20:16:51.530",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 0.9.8, < 2.17.2",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-94",
            "what_happened": "Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is fixed in version 2.17.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/savonrb/savon/commit/8f22eb543e7436f6247172c9be47e22792d375e9",
                "https://github.com/savonrb/savon/releases/tag/v2.17.2",
                "https://github.com/savonrb/savon/security/advisories/GHSA-mx5j-mp4f-g8jg"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T20:16:51.530",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53510"
                }
            ]
        },
        {
            "id": "CVE-2026-53400",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: core: fix adapter registration race\n\nAdapters can be looked up based on their id using i2c_get_adapter()\nwhich takes a reference to the embedded struct device.\n\nMake sure that the adapter (including its struct device) has been\ninitialised before adding it to the IDR to avoid accessing uninitialised\ndata which could, for example, lead to NULL-pointer dereferences or\nuse-after-free.\n\nNote that the i2c-dev chardev, which is registered from a bus notifier,\ncurrently uses i2c_get_adapter() so the adapter needs to be added to the\nIDR before registration.",
            "updated_at": "2026-09-08T09:18:16.267",
            "published_at": "2026-07-19T12:16:51.177",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6e13e641841833cc2aa5baefe89bb04bc388801b through before 2e57c788e71f1763445f812eba4e0b4a2fbd0646 (git); 6e13e641841833cc2aa5baefe89bb04bc388801b through before a4365bc41baaf67f3a5aa8556d23544e6ec7480a (git); 6e13e641841833cc2aa5baefe89bb04bc388801b through before 1febb174815bcae56d73587e99e8f87e02f0784d (git); 6e13e641841833cc2aa5baefe89bb04bc388801b through before da9d8d9711f78deebc202d0cffcf577e45ee8621 (git); 6e13e641841833cc2aa5baefe89bb04bc388801b through before 78793c75dc6d0ff2e4d50ad617349b328a99054e (git); 6e13e641841833cc2aa5baefe89bb04bc388801b through before 6a946038f2a5a8c29048c6af369d4e391448a5c5 (git); 6e13e641841833cc2aa5baefe89bb04bc388801b through before a4c8094bbf4c6fa68b17e3b16f6a0a1b7a14f3e0 (git); 6e13e641841833cc2aa5baefe89bb04bc388801b through before ba14d7cf2fe7284610a29854bdff22b2537d3ce6 (git); 2.6.22; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-362",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: core: fix adapter registration race\n\nAdapters can be looked up based on their id using i2c_get_adapter()\nwhich takes a reference to the embedded struct device.\n\nMake sure that the adapter (including its struct device) has been\ninitialised before adding it to the IDR to avoid accessing uninitialised\ndata which could, for example, lead to NULL-pointer dereferences or\nuse-after-free.\n\nNote that the i2c-dev chardev, which is registered from a bus notifier,\ncurrently uses i2c_get_adapter() so the adapter needs to be added to the\nIDR before registration.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1febb174815bcae56d73587e99e8f87e02f0784d",
                "https://git.kernel.org/stable/c/2e57c788e71f1763445f812eba4e0b4a2fbd0646",
                "https://git.kernel.org/stable/c/6a946038f2a5a8c29048c6af369d4e391448a5c5",
                "https://git.kernel.org/stable/c/78793c75dc6d0ff2e4d50ad617349b328a99054e",
                "https://git.kernel.org/stable/c/a4365bc41baaf67f3a5aa8556d23544e6ec7480a",
                "https://git.kernel.org/stable/c/a4c8094bbf4c6fa68b17e3b16f6a0a1b7a14f3e0",
                "https://git.kernel.org/stable/c/ba14d7cf2fe7284610a29854bdff22b2537d3ce6",
                "https://git.kernel.org/stable/c/da9d8d9711f78deebc202d0cffcf577e45ee8621",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-07-19T12:16:51.177",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53400"
                }
            ]
        },
        {
            "id": "CVE-2026-53362",
            "vendor": "Linux",
            "product": "Kernel",
            "title": "Linux Kernel Unspecified Vulnerability",
            "summary": "Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.",
            "updated_at": "2026-08-26T22:00:00Z",
            "published_at": "2026-08-26T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 96,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "suominen/ipv6_frag_escape",
                    "author": "suominen",
                    "first_seen": "2026-07-03",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 0,
                    "title": "Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape",
                    "summary": "Tracking IPV6_FRAG_ESCAPE (CVE-2026-53362, CVE-2026-53366), the IPv6 fragmentation container escape",
                    "url": "https://github.com/suominen/ipv6_frag_escape"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/suominen/ipv6_frag_escape"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-53359",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Januscape CVE-2026-53359",
            "summary": "Use-after-free in KVM/x86 shadow MMU enabling guest-to-host escape on Intel and AMD.",
            "updated_at": "2026-09-05T05:10:12Z",
            "published_at": "2026-09-05T05:10:12Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 43,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Use-after-free in KVM/x86 shadow MMU enabling guest-to-host escape on Intel and AMD.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Januscape CVE-2026-53359",
                    "summary": "Use-after-free in KVM/x86 shadow MMU enabling guest-to-host escape on Intel and AMD.",
                    "what_happened": "Use-after-free in KVM/x86 shadow MMU enabling guest-to-host escape on Intel and AMD.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-V4BEL-JANUSCAPE",
                        "https://kitploit.com/ru/tools/github/v4bel/januscape/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T07:10:12",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-V4BEL-JANUSCAPE"
                },
                {
                    "title": "Exploit for Januscape CVE-2026-53359",
                    "summary": "Use-after-free in KVM/x86 shadow MMU enabling guest-to-host escape on Intel and AMD.",
                    "what_happened": "Use-after-free in KVM/x86 shadow MMU enabling guest-to-host escape on Intel and AMD.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-V4BEL-JANUSCAPE",
                        "https://kitploit.com/ru/tools/github/v4bel/januscape/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T07:10:12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/v4bel/januscape/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-V4BEL-JANUSCAPE",
                "https://kitploit.com/ru/tools/github/v4bel/januscape/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T05:10:12Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-V4BEL-JANUSCAPE"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-53352",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsignal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()\n\nWhen a multi-threaded process receives a stop signal (e.g., SIGSTOP),\ndo_signal_stop() sets JOBCTL_STOP_PENDING and JOBCTL_STOP_CONSUME on all\nthreads and sets signal->group_stop_count to the number of threads. If\none of the threads concurrently calls execve(), de_thread() invokes\nzap_other_threads() to kill all other threads. zap_other_threads()\naborts the pending group stop by resetting signal->group_stop_count to 0\nand clears the JOBCTL_PENDING_MASK for all other threads. However, it\nfails to clear the job control flags for the calling thread.\n\nWhen execve() completes, the calling thread returns to user mode and\nchecks for pending signals. Seeing the stale JOBCTL_STOP_PENDING flag,\nit calls do_signal_stop(), which invokes task_participate_group_stop().\nSince JOBCTL_STOP_CONSUME is still set, it attempts to decrement the\nalready-zero signal->group_stop_count, triggering a warning:\n\nsig->group_stop_count == 0\nWARNING: CPU: 1 PID: 6475 at kernel/signal.c:373\ntask_participate_group_stop+0x215/0x2d0\nCall Trace:\n <TASK>\n do_signal_stop+0x3be/0x5c0 kernel/signal.c:2619\n get_signal+0xa8c/0x1330 kernel/signal.c:2884\n arch_do_signal_or_restart+0xbc/0x840 arch/x86/kernel/signal.c:337\n exit_to_user_mode_loop+0x8c/0x4d0 kernel/entry/common.c:98\n do_syscall_64+0x33e/0xf80 arch/x86/entry/syscall_64.c:100\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n </TASK>\n\nFix this race condition by clearing the JOBCTL_PENDING_MASK for the\ncalling thread in zap_other_threads(), ensuring it does not retain any\nstale job control state after the thread group is destroyed. This aligns\nwith other functions that tear down a thread group and abort group\nstops, such as zap_process() and complete_signal(), which correctly\nclear these flags for all threads including the current one.",
            "updated_at": "2026-09-08T09:18:16.093",
            "published_at": "2026-07-01T14:16:43.347",
            "cvss": 4.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "39efa3ef3a376a4e53de2f82fc91182459d34200 through before 2b32b2fb241435145ea199efac024540759d2495 (git); 39efa3ef3a376a4e53de2f82fc91182459d34200 through before 391ebe74456a0f1d60b3ba4a8a64d9f44c1728fe (git); 39efa3ef3a376a4e53de2f82fc91182459d34200 through before f8d720bc2e35d568c18be0644e92a468de428370 (git); 39efa3ef3a376a4e53de2f82fc91182459d34200 through before f4aae11abb449dc536269705d0419ec69480faa9 (git); 39efa3ef3a376a4e53de2f82fc91182459d34200 through before 76aebd9ef20078719dfd6282d3b06c27e900a65a (git); 39efa3ef3a376a4e53de2f82fc91182459d34200 through before 8c046f36222c6ce1e0daef2c45c891c72602f8a1 (git); 39efa3ef3a376a4e53de2f82fc91182459d34200 through before dfcd0ba14769d94d76ac9d9814b85e7fcacd4e29 (git); 39efa3ef3a376a4e53de2f82fc91182459d34200 through before 90918794a4e2c3b440f8fcf3847765a8b1d81b25 (git); 3.0; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nsignal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()\n\nWhen a multi-threaded process receives a stop signal (e.g., SIGSTOP),\ndo_signal_stop() sets JOBCTL_STOP_PENDING and JOBCTL_STOP_CONSUME on all\nthreads and sets signal->group_stop_count to the number of threads. If\none of the threads concurrently calls execve(), de_thread() invokes\nzap_other_threads() to kill all other threads. zap_other_threads()\naborts the pending group stop by resetting signal->group_stop_count to 0\nand clears the JOBCTL_PENDING_MASK for all other threads. However, it\nfails to clear the job control flags for the calling thread.\n\nWhen execve() completes, the calling thread returns to user mode and\nchecks for pending signals. Seeing the stale JOBCTL_STOP_PENDING flag,\nit calls do_signal_stop(), which invokes task_participate_group_stop().\nSince JOBCTL_STOP_CONSUME is still set, it attempts to decrement the\nalready-zero signal->group_stop_count, triggering a warning:\n\nsig->group_stop_count == 0\nWARNING: CPU: 1 PID: 6475 at kernel/signal.c:373\ntask_participate_group_stop+0x215/0x2d0\nCall Trace:\n <TASK>\n do_signal_stop+0x3be/0x5c0 kernel/signal.c:2619\n get_signal+0xa8c/0x1330 kernel/signal.c:2884\n arch_do_signal_or_restart+0xbc/0x840 arch/x86/kernel/signal.c:337\n exit_to_user_mode_loop+0x8c/0x4d0 kernel/entry/common.c:98\n do_syscall_64+0x33e/0xf80 arch/x86/entry/syscall_64.c:100\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n </TASK>\n\nFix this race condition by clearing the JOBCTL_PENDING_MASK for the\ncalling thread in zap_other_threads(), ensuring it does not retain any\nstale job control state after the thread group is destroyed. This aligns\nwith other functions that tear down a thread group and abort group\nstops, such as zap_process() and complete_signal(), which correctly\nclear these flags for all threads including the current one.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2b32b2fb241435145ea199efac024540759d2495",
                "https://git.kernel.org/stable/c/391ebe74456a0f1d60b3ba4a8a64d9f44c1728fe",
                "https://git.kernel.org/stable/c/76aebd9ef20078719dfd6282d3b06c27e900a65a",
                "https://git.kernel.org/stable/c/8c046f36222c6ce1e0daef2c45c891c72602f8a1",
                "https://git.kernel.org/stable/c/90918794a4e2c3b440f8fcf3847765a8b1d81b25",
                "https://git.kernel.org/stable/c/dfcd0ba14769d94d76ac9d9814b85e7fcacd4e29",
                "https://git.kernel.org/stable/c/f4aae11abb449dc536269705d0419ec69480faa9",
                "https://git.kernel.org/stable/c/f8d720bc2e35d568c18be0644e92a468de428370",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-07-01T14:16:43.347",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53352"
                }
            ]
        },
        {
            "id": "CVE-2026-53313",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths\n\nIn dc_dmub_srv_log_diagnostic_data() and\ndc_dmub_srv_enable_dpia_trace().\n\nBoth functions check:\n\n  if (!dc_dmub_srv || !dc_dmub_srv->dmub)\n\nand then call DC_LOG_ERROR() inside that block.\n\nDC_LOG_ERROR() uses dc_dmub_srv->ctx internally. So if\ndc_dmub_srv is NULL, the logging itself can dereference a\nNULL pointer and cause a crash.\n\nFix this by splitting the checks.\n\nFirst check if dc_dmub_srv is NULL and return immediately.\nThen check dc_dmub_srv->dmub and log the error only when\ndc_dmub_srv is valid.\n\nFixes the below:\n../display/dc/dc_dmub_srv.c:962 dc_dmub_srv_log_diagnostic_data() error: we previously assumed 'dc_dmub_srv' could be null (see line 961)\n../display/dc/dc_dmub_srv.c:1167 dc_dmub_srv_enable_dpia_trace() error: we previously assumed 'dc_dmub_srv' could be null (see line 1166)",
            "updated_at": "2026-09-07T16:17:28.797",
            "published_at": "2026-06-26T20:17:24.613",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2631ac1ac328189031d1aefbbd4929050f72fb23 through before a71fdbd6e8289e2725d33a9873833459f3b1824f (git); 2631ac1ac328189031d1aefbbd4929050f72fb23 through before 2ab18de5ebb11c76bfc8087c5a09fbcccd0dea8a (git); 2631ac1ac328189031d1aefbbd4929050f72fb23 through before b37a978e6d8c33fbfa4abc5dcca4c7cfc6d01f22 (git); 2631ac1ac328189031d1aefbbd4929050f72fb23 through before 4ae3e16f4b3bf64140f773629b765d605ee079a9 (git); 5.14",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths\n\nIn dc_dmub_srv_log_diagnostic_data() and\ndc_dmub_srv_enable_dpia_trace().\n\nBoth functions check:\n\n  if (!dc_dmub_srv || !dc_dmub_srv->dmub)\n\nand then call DC_LOG_ERROR() inside that block.\n\nDC_LOG_ERROR() uses dc_dmub_srv->ctx internally. So if\ndc_dmub_srv is NULL, the logging itself can dereference a\nNULL pointer and cause a crash.\n\nFix this by splitting the checks.\n\nFirst check if dc_dmub_srv is NULL and return immediately.\nThen check dc_dmub_srv->dmub and log the error only when\ndc_dmub_srv is valid.\n\nFixes the below:\n../display/dc/dc_dmub_srv.c:962 dc_dmub_srv_log_diagnostic_data() error: we previously assumed 'dc_dmub_srv' could be null (see line 961)\n../display/dc/dc_dmub_srv.c:1167 dc_dmub_srv_enable_dpia_trace() error: we previously assumed 'dc_dmub_srv' could be null (see line 1166)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2ab18de5ebb11c76bfc8087c5a09fbcccd0dea8a",
                "https://git.kernel.org/stable/c/4ae3e16f4b3bf64140f773629b765d605ee079a9",
                "https://git.kernel.org/stable/c/a71fdbd6e8289e2725d33a9873833459f3b1824f",
                "https://git.kernel.org/stable/c/b37a978e6d8c33fbfa4abc5dcca4c7cfc6d01f22"
            ],
            "timeline": [
                {
                    "at": "2026-06-26T20:17:24.613",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53313"
                }
            ]
        },
        {
            "id": "CVE-2026-53295",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: add sanity check for channel array\n\nFail gracefully if there is no channel array attached to the mailbox\ncontroller. Otherwise the later dereference will cause an OOPS which\nmight not be seen because mailbox controllers might instantiate very\nearly. Remove the comment explaining the obvious while here.",
            "updated_at": "2026-09-08T09:18:15.920",
            "published_at": "2026-06-26T20:17:22.427",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2b6d83e2b8b7de82331a6a1dcd64b51020a6031c through before 5cc3300fab262b26c28bc2fc06df693410c3840b (git); 2b6d83e2b8b7de82331a6a1dcd64b51020a6031c through before 0f11444271110d9b5bc6316a153c6431abda899c (git); 2b6d83e2b8b7de82331a6a1dcd64b51020a6031c through before d44872a569b8fbacde457ff2587a775e5004bb79 (git); 2b6d83e2b8b7de82331a6a1dcd64b51020a6031c through before 14aed0d4e58389cc6a88acf8610b12d3e476272b (git); 2b6d83e2b8b7de82331a6a1dcd64b51020a6031c through before 6362c4a7d7e21e68cd9aa04df7cde16befba3a4b (git); 2b6d83e2b8b7de82331a6a1dcd64b51020a6031c through before 9dd7489943324298bb0f385495795a82f1dd6507 (git); 2b6d83e2b8b7de82331a6a1dcd64b51020a6031c through before 37792091ab28ba030fd8d61184c47d4d51294170 (git); 2b6d83e2b8b7de82331a6a1dcd64b51020a6031c through before c1aad75595fb67edc7fda8af249d3b886efa1be9 (git); 3.18; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: add sanity check for channel array\n\nFail gracefully if there is no channel array attached to the mailbox\ncontroller. Otherwise the later dereference will cause an OOPS which\nmight not be seen because mailbox controllers might instantiate very\nearly. Remove the comment explaining the obvious while here.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0f11444271110d9b5bc6316a153c6431abda899c",
                "https://git.kernel.org/stable/c/14aed0d4e58389cc6a88acf8610b12d3e476272b",
                "https://git.kernel.org/stable/c/37792091ab28ba030fd8d61184c47d4d51294170",
                "https://git.kernel.org/stable/c/5cc3300fab262b26c28bc2fc06df693410c3840b",
                "https://git.kernel.org/stable/c/6362c4a7d7e21e68cd9aa04df7cde16befba3a4b",
                "https://git.kernel.org/stable/c/9dd7489943324298bb0f385495795a82f1dd6507",
                "https://git.kernel.org/stable/c/c1aad75595fb67edc7fda8af249d3b886efa1be9",
                "https://git.kernel.org/stable/c/d44872a569b8fbacde457ff2587a775e5004bb79",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-26T20:17:22.427",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53295"
                }
            ]
        },
        {
            "id": "CVE-2026-53275",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: Fix use-after-free when processing MLD queries\n\nWhen processing an MLD query, a pointer to the multicast group address\nis retrieved when initially parsing the packet. This pointer is later\ndereferenced without being reloaded despite the fact that the skb header\nmight have been reallocated following the pskb_may_pull() calls, leading\nto a use-after-free [1].\n\nFix by copying the multicast group address when the packet is initially\nparsed.\n\n[1]\nBUG: KASAN: slab-use-after-free in __mld_query_work (net/ipv6/mcast.c:1512)\nRead of size 8 at addr ffff8881154b8e90 by task kworker/4:1/118\n\nWorkqueue: mld mld_query_work\nCall Trace:\n<TASK>\ndump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)\nprint_address_description.constprop.0 (mm/kasan/report.c:378)\nprint_report (mm/kasan/report.c:482)\nkasan_report (mm/kasan/report.c:595)\n__mld_query_work (net/ipv6/mcast.c:1512)\nmld_query_work (net/ipv6/mcast.c:1563)\nprocess_one_work (kernel/workqueue.c:3314)\nworker_thread (kernel/workqueue.c:3397 kernel/workqueue.c:3478)\nkthread (kernel/kthread.c:436)\nret_from_fork (arch/x86/kernel/process.c:158)\nret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n</TASK>\n\n[...]\n\nFreed by task 118:\nkasan_save_stack (mm/kasan/common.c:57)\nkasan_save_track (mm/kasan/common.c:78)\nkasan_save_free_info (mm/kasan/generic.c:584)\n__kasan_slab_free (mm/kasan/common.c:253 mm/kasan/common.c:285)\nkfree (./include/linux/kasan.h:235 mm/slub.c:2689 mm/slub.c:6251 mm/slub.c:6566)\npskb_expand_head (net/core/skbuff.c:2335)\n__pskb_pull_tail (net/core/skbuff.c:2878 (discriminator 4))\n__mld_query_work (net/ipv6/mcast.c:1495 (discriminator 1))\nmld_query_work (net/ipv6/mcast.c:1563)\nprocess_one_work (kernel/workqueue.c:3314)\nworker_thread (kernel/workqueue.c:3397 kernel/workqueue.c:3478)\nkthread (kernel/kthread.c:436)\nret_from_fork (arch/x86/kernel/process.c:158)\nret_from_fork_asm (arch/x86/entry/entry_64.S:245)",
            "updated_at": "2026-09-08T09:18:15.730",
            "published_at": "2026-06-25T09:16:45.687",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "97300b5fdfe28c6edae926926f9467a27cf5889c through before dfaf1f5e7eb81be87582bd6a57d34e61a57d5dea (git); 97300b5fdfe28c6edae926926f9467a27cf5889c through before 1354271c89d0e5fbf8b3d94097ff0216695209c7 (git); 97300b5fdfe28c6edae926926f9467a27cf5889c through before 53baa63a4183291574483f89583dbef13677a2c4 (git); 97300b5fdfe28c6edae926926f9467a27cf5889c through before 2a613bf497029d555a7428406aa8cdb84a503cea (git); 97300b5fdfe28c6edae926926f9467a27cf5889c through before b2eb8886200b907fc71806869620609f0f4cacb0 (git); 97300b5fdfe28c6edae926926f9467a27cf5889c through before 4203806f700bb44ea0b05d484d9d40044b47fb04 (git); 97300b5fdfe28c6edae926926f9467a27cf5889c through before 087dbacf897c020f438f780f0a4a8aa73b6d7c5a (git); 97300b5fdfe28c6edae926926f9467a27cf5889c through before 791c91dc7a9dfb2457d5e29b8216a6484b9c4b40 (git); 2.6.15; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: Fix use-after-free when processing MLD queries\n\nWhen processing an MLD query, a pointer to the multicast group address\nis retrieved when initially parsing the packet. This pointer is later\ndereferenced without being reloaded despite the fact that the skb header\nmight have been reallocated following the pskb_may_pull() calls, leading\nto a use-after-free [1].\n\nFix by copying the multicast group address when the packet is initially\nparsed.\n\n[1]\nBUG: KASAN: slab-use-after-free in __mld_query_work (net/ipv6/mcast.c:1512)\nRead of size 8 at addr ffff8881154b8e90 by task kworker/4:1/118\n\nWorkqueue: mld mld_query_work\nCall Trace:\n<TASK>\ndump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)\nprint_address_description.constprop.0 (mm/kasan/report.c:378)\nprint_report (mm/kasan/report.c:482)\nkasan_report (mm/kasan/report.c:595)\n__mld_query_work (net/ipv6/mcast.c:1512)\nmld_query_work (net/ipv6/mcast.c:1563)\nprocess_one_work (kernel/workqueue.c:3314)\nworker_thread (kernel/workqueue.c:3397 kernel/workqueue.c:3478)\nkthread (kernel/kthread.c:436)\nret_from_fork (arch/x86/kernel/process.c:158)\nret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n</TASK>\n\n[...]\n\nFreed by task 118:\nkasan_save_stack (mm/kasan/common.c:57)\nkasan_save_track (mm/kasan/common.c:78)\nkasan_save_free_info (mm/kasan/generic.c:584)\n__kasan_slab_free (mm/kasan/common.c:253 mm/kasan/common.c:285)\nkfree (./include/linux/kasan.h:235 mm/slub.c:2689 mm/slub.c:6251 mm/slub.c:6566)\npskb_expand_head (net/core/skbuff.c:2335)\n__pskb_pull_tail (net/core/skbuff.c:2878 (discriminator 4))\n__mld_query_work (net/ipv6/mcast.c:1495 (discriminator 1))\nmld_query_work (net/ipv6/mcast.c:1563)\nprocess_one_work (kernel/workqueue.c:3314)\nworker_thread (kernel/workqueue.c:3397 kernel/workqueue.c:3478)\nkthread (kernel/kthread.c:436)\nret_from_fork (arch/x86/kernel/process.c:158)\nret_from_fork_asm (arch/x86/entry/entry_64.S:245)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/087dbacf897c020f438f780f0a4a8aa73b6d7c5a",
                "https://git.kernel.org/stable/c/1354271c89d0e5fbf8b3d94097ff0216695209c7",
                "https://git.kernel.org/stable/c/2a613bf497029d555a7428406aa8cdb84a503cea",
                "https://git.kernel.org/stable/c/4203806f700bb44ea0b05d484d9d40044b47fb04",
                "https://git.kernel.org/stable/c/53baa63a4183291574483f89583dbef13677a2c4",
                "https://git.kernel.org/stable/c/791c91dc7a9dfb2457d5e29b8216a6484b9c4b40",
                "https://git.kernel.org/stable/c/b2eb8886200b907fc71806869620609f0f4cacb0",
                "https://git.kernel.org/stable/c/dfaf1f5e7eb81be87582bd6a57d34e61a57d5dea",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-25T09:16:45.687",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53275"
                }
            ]
        },
        {
            "id": "CVE-2026-53269",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: synproxy: add mutex to guard hook reference counting\n\nAs the synproxy infrastructure register netfilter hooks on-demand when a\nuser adds the first iptables target or nftables expression, if done\nconcurrently they can race each other.\n\nIntroduce a mutex to serialize the refcount control blocks access from\nboth frontends. While a per namespace mutex might be more efficient, it\nis not needed for target/expression like SYNPROXY.",
            "updated_at": "2026-09-08T09:18:15.570",
            "published_at": "2026-06-25T09:16:45.007",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "ad49d86e07a497e834cb06f2b151dccd75f8e148 through before 0ec9ddc1bda261a2c57636c74c8b4e53000102c9 (git); ad49d86e07a497e834cb06f2b151dccd75f8e148 through before 56ffbe3a08c01dcdb0d6adee9ce1e535bfb3b389 (git); ad49d86e07a497e834cb06f2b151dccd75f8e148 through before debc57b83d5b323df74bf010c8d50fe26ad2ed6b (git); ad49d86e07a497e834cb06f2b151dccd75f8e148 through before 0f8ba5e4c53d2e4a536aa68140beda9fe59b2f88 (git); ad49d86e07a497e834cb06f2b151dccd75f8e148 through before 640441348258220e78daed40528b85b8afcedab6 (git); ad49d86e07a497e834cb06f2b151dccd75f8e148 through before aaf80701dc2f7a48fe543961e21f8ca3924d587c (git); ad49d86e07a497e834cb06f2b151dccd75f8e148 through before fbf0591275f50eae5733c3d7a8cd6c1e79933ffa (git); ad49d86e07a497e834cb06f2b151dccd75f8e148 through before 2fcba19caaeb2a33017459d3430f057967bb91b6 (git); 5.3; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: synproxy: add mutex to guard hook reference counting\n\nAs the synproxy infrastructure register netfilter hooks on-demand when a\nuser adds the first iptables target or nftables expression, if done\nconcurrently they can race each other.\n\nIntroduce a mutex to serialize the refcount control blocks access from\nboth frontends. While a per namespace mutex might be more efficient, it\nis not needed for target/expression like SYNPROXY.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0ec9ddc1bda261a2c57636c74c8b4e53000102c9",
                "https://git.kernel.org/stable/c/0f8ba5e4c53d2e4a536aa68140beda9fe59b2f88",
                "https://git.kernel.org/stable/c/2fcba19caaeb2a33017459d3430f057967bb91b6",
                "https://git.kernel.org/stable/c/56ffbe3a08c01dcdb0d6adee9ce1e535bfb3b389",
                "https://git.kernel.org/stable/c/640441348258220e78daed40528b85b8afcedab6",
                "https://git.kernel.org/stable/c/aaf80701dc2f7a48fe543961e21f8ca3924d587c",
                "https://git.kernel.org/stable/c/debc57b83d5b323df74bf010c8d50fe26ad2ed6b",
                "https://git.kernel.org/stable/c/fbf0591275f50eae5733c3d7a8cd6c1e79933ffa",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-25T09:16:45.007",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53269"
                }
            ]
        },
        {
            "id": "CVE-2026-53268",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack_irc: fix possible out-of-bounds read\n\nWhen parsing fails after we've matched the command string we\nshould bail out instead of trying to match a different command.\n\nThis helper should be deprecated, given prevalence of TLS I doubt it has\nany relevance in 2026.",
            "updated_at": "2026-09-08T09:18:15.393",
            "published_at": "2026-06-25T09:16:44.883",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "869f37d8e48f3911eb70f38a994feaa8f8380008 through before 4cdda7f868f48e2f81579371584fdbdce37df2c8 (git); 869f37d8e48f3911eb70f38a994feaa8f8380008 through before 8a1d6e40dedfe1068aee094d851bd69e289c9fd6 (git); 869f37d8e48f3911eb70f38a994feaa8f8380008 through before 0afc802160af0df61ed374fdb97fb34cfe5cdf2f (git); 869f37d8e48f3911eb70f38a994feaa8f8380008 through before 7c34f91305292083253df6a9f6c8ede02d4ccaea (git); 869f37d8e48f3911eb70f38a994feaa8f8380008 through before ddddd8271359961e403d11c90c9ba9fc38914f7e (git); 869f37d8e48f3911eb70f38a994feaa8f8380008 through before 9e5da2379f968a3ea5a6e38921ab6201576466dc (git); 869f37d8e48f3911eb70f38a994feaa8f8380008 through before 573810f61bcd6b6815e2ff53bbdd2b9c9d747176 (git); 869f37d8e48f3911eb70f38a994feaa8f8380008 through before 66eba0ffce3b7e11449946b4cbbef8ea36112f56 (git); 2.6.20; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack_irc: fix possible out-of-bounds read\n\nWhen parsing fails after we've matched the command string we\nshould bail out instead of trying to match a different command.\n\nThis helper should be deprecated, given prevalence of TLS I doubt it has\nany relevance in 2026.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0afc802160af0df61ed374fdb97fb34cfe5cdf2f",
                "https://git.kernel.org/stable/c/4cdda7f868f48e2f81579371584fdbdce37df2c8",
                "https://git.kernel.org/stable/c/573810f61bcd6b6815e2ff53bbdd2b9c9d747176",
                "https://git.kernel.org/stable/c/66eba0ffce3b7e11449946b4cbbef8ea36112f56",
                "https://git.kernel.org/stable/c/7c34f91305292083253df6a9f6c8ede02d4ccaea",
                "https://git.kernel.org/stable/c/8a1d6e40dedfe1068aee094d851bd69e289c9fd6",
                "https://git.kernel.org/stable/c/9e5da2379f968a3ea5a6e38921ab6201576466dc",
                "https://git.kernel.org/stable/c/ddddd8271359961e403d11c90c9ba9fc38914f7e",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-25T09:16:44.883",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53268"
                }
            ]
        },
        {
            "id": "CVE-2026-53249",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: restrict IPOPT_SSRR and IPOPT_LSRR options\n\nThis patch restricts setting Loose Source and Record Route (LSRR)\nand Strict Source and Record Route (SSRR) IP options to users\nwith CAP_NET_RAW capability.\n\nThis prevents unprivileged applications from forcing packets to route\nthrough attacker-controlled nodes to leak TCP ISN and possibly other\nprotocol information.\n\nWhile LSRR and SSRR are commonly filtered in many network environments,\nthey may still be supported and forwarded along some network paths.\n\nRFC 7126 (Recommendations on Filtering of IPv4 Packets Containing\nIPv4 Options) recommend to drop these options in 4.3 and 4.4.",
            "updated_at": "2026-09-08T09:18:15.233",
            "published_at": "2026-06-25T09:16:42.847",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 4cd6e9ed49347d3a2fdaaf07e32fb524756dddc2 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 2a87c3e8f03ce655ed0ef500d64d5fd924ec3691 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 89343ff12b3178fc236fe531a3603e7c97c68278 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 8ff85dbabbbfb05e86e6cde31d91ac5782179d4d (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 00e8845fe3428c69e980dce5071cb3da1d8f7578 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before a4f3fd6516920988c47ba8d19714985c40c816a1 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 28f5ad1b4055405eb1616e603fe511ba5e3725e7 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before d3915a1f5a4bc0ac911032903c3c6ab8df9fcc7c (git); 2.6.12; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: restrict IPOPT_SSRR and IPOPT_LSRR options\n\nThis patch restricts setting Loose Source and Record Route (LSRR)\nand Strict Source and Record Route (SSRR) IP options to users\nwith CAP_NET_RAW capability.\n\nThis prevents unprivileged applications from forcing packets to route\nthrough attacker-controlled nodes to leak TCP ISN and possibly other\nprotocol information.\n\nWhile LSRR and SSRR are commonly filtered in many network environments,\nthey may still be supported and forwarded along some network paths.\n\nRFC 7126 (Recommendations on Filtering of IPv4 Packets Containing\nIPv4 Options) recommend to drop these options in 4.3 and 4.4.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/00e8845fe3428c69e980dce5071cb3da1d8f7578",
                "https://git.kernel.org/stable/c/28f5ad1b4055405eb1616e603fe511ba5e3725e7",
                "https://git.kernel.org/stable/c/2a87c3e8f03ce655ed0ef500d64d5fd924ec3691",
                "https://git.kernel.org/stable/c/4cd6e9ed49347d3a2fdaaf07e32fb524756dddc2",
                "https://git.kernel.org/stable/c/89343ff12b3178fc236fe531a3603e7c97c68278",
                "https://git.kernel.org/stable/c/8ff85dbabbbfb05e86e6cde31d91ac5782179d4d",
                "https://git.kernel.org/stable/c/a4f3fd6516920988c47ba8d19714985c40c816a1",
                "https://git.kernel.org/stable/c/d3915a1f5a4bc0ac911032903c3c6ab8df9fcc7c",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-25T09:16:42.847",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53249"
                }
            ]
        },
        {
            "id": "CVE-2026-53239",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()\n\nFix the race by pruning the bin while still holding xfrm_policy_lock,\nbefore dropping it. Use __xfrm_policy_inexact_prune_bin() directly since\nthe lock is already held. The wrapper xfrm_policy_inexact_prune_bin()\nbecomes unused and is removed.\n\nRace:\n\n  CPU0 (XFRM_MSG_DELPOLICY)           CPU1 (XFRM_MSG_NEWSPDINFO)\n  ==========================          ==========================\n  xfrm_policy_bysel_ctx():\n    spin_lock_bh(xfrm_policy_lock)\n    bin = xfrm_policy_inexact_lookup()\n    __xfrm_policy_unlink(pol)\n    spin_unlock_bh(xfrm_policy_lock)\n    xfrm_policy_kill(ret)\n    // wide window, lock not held\n                                       xfrm_hash_rebuild():\n                                         spin_lock_bh(xfrm_policy_lock)\n                                         __xfrm_policy_inexact_flush():\n                                           kfree_rcu(bin)  // bin freed\n                                         spin_unlock_bh(xfrm_policy_lock)\n    xfrm_policy_inexact_prune_bin(bin)\n    // UAF: bin is freed",
            "updated_at": "2026-09-08T09:18:15.057",
            "published_at": "2026-06-25T09:16:41.840",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6be3b0db6db82cf056a72cc18042048edd27f8ee through before 8fc536e9f6856230f19c7d13e71af064b6a77b22 (git); 6be3b0db6db82cf056a72cc18042048edd27f8ee through before c4c1ea36d83bf3c4569468ca5b8b614fda1bf821 (git); 6be3b0db6db82cf056a72cc18042048edd27f8ee through before 25c8c7fb3b0b9668c7d05e209f58c158d2b020c7 (git); 6be3b0db6db82cf056a72cc18042048edd27f8ee through before 42827d03f8009a6a218bacab153e21f39d6a121c (git); 6be3b0db6db82cf056a72cc18042048edd27f8ee through before 88697cf980222d5906a37bf47662dac0732e2a0f (git); 6be3b0db6db82cf056a72cc18042048edd27f8ee through before b5316e2b8614a87d8736941972441cb47bfd4491 (git); 6be3b0db6db82cf056a72cc18042048edd27f8ee through before ec82ea4eb220164d854f8734ca5a35e23e577b94 (git); 6be3b0db6db82cf056a72cc18042048edd27f8ee through before 7f2d76c9c03257c0782afef9d95321fa04096f60 (git); 5.0; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()\n\nFix the race by pruning the bin while still holding xfrm_policy_lock,\nbefore dropping it. Use __xfrm_policy_inexact_prune_bin() directly since\nthe lock is already held. The wrapper xfrm_policy_inexact_prune_bin()\nbecomes unused and is removed.\n\nRace:\n\n  CPU0 (XFRM_MSG_DELPOLICY)           CPU1 (XFRM_MSG_NEWSPDINFO)\n  ==========================          ==========================\n  xfrm_policy_bysel_ctx():\n    spin_lock_bh(xfrm_policy_lock)\n    bin = xfrm_policy_inexact_lookup()\n    __xfrm_policy_unlink(pol)\n    spin_unlock_bh(xfrm_policy_lock)\n    xfrm_policy_kill(ret)\n    // wide window, lock not held\n                                       xfrm_hash_rebuild():\n                                         spin_lock_bh(xfrm_policy_lock)\n                                         __xfrm_policy_inexact_flush():\n                                           kfree_rcu(bin)  // bin freed\n                                         spin_unlock_bh(xfrm_policy_lock)\n    xfrm_policy_inexact_prune_bin(bin)\n    // UAF: bin is freed",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/25c8c7fb3b0b9668c7d05e209f58c158d2b020c7",
                "https://git.kernel.org/stable/c/42827d03f8009a6a218bacab153e21f39d6a121c",
                "https://git.kernel.org/stable/c/7f2d76c9c03257c0782afef9d95321fa04096f60",
                "https://git.kernel.org/stable/c/88697cf980222d5906a37bf47662dac0732e2a0f",
                "https://git.kernel.org/stable/c/8fc536e9f6856230f19c7d13e71af064b6a77b22",
                "https://git.kernel.org/stable/c/b5316e2b8614a87d8736941972441cb47bfd4491",
                "https://git.kernel.org/stable/c/c4c1ea36d83bf3c4569468ca5b8b614fda1bf821",
                "https://git.kernel.org/stable/c/ec82ea4eb220164d854f8734ca5a35e23e577b94",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-25T09:16:41.840",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53239"
                }
            ]
        },
        {
            "id": "CVE-2026-53236",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: restrict SO_ATTACH_FILTER to priv users\n\nThis patch restricts the use of SO_ATTACH_FILTER (cBPF) on TCP sockets\nto users with CAP_NET_ADMIN capability.\n\nThis blocks potential side-channel attack where an unprivileged application\nattaches a filter to leak TCP sequence/acknowledgment numbers.",
            "updated_at": "2026-09-08T09:18:14.913",
            "published_at": "2026-06-25T09:16:41.493",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 3747de241a66ef2c7032d2cc2b826a47c5fa0f6a (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before ecfe9171b26ae3eed0cd8bab7a943e9e2c9e51ba (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 82b3e7ce10c53fc12aab8904745603efc74f8c07 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before ede69b8f6670600e534591664584f810d7c385f9 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before c68517a3e18e20997808821c5559d0cba4d776c1 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 5d39580f68e6ddeedd15e587282207489dfb3da2 (git); 2.6.12; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: restrict SO_ATTACH_FILTER to priv users\n\nThis patch restricts the use of SO_ATTACH_FILTER (cBPF) on TCP sockets\nto users with CAP_NET_ADMIN capability.\n\nThis blocks potential side-channel attack where an unprivileged application\nattaches a filter to leak TCP sequence/acknowledgment numbers.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/3747de241a66ef2c7032d2cc2b826a47c5fa0f6a",
                "https://git.kernel.org/stable/c/5d39580f68e6ddeedd15e587282207489dfb3da2",
                "https://git.kernel.org/stable/c/82b3e7ce10c53fc12aab8904745603efc74f8c07",
                "https://git.kernel.org/stable/c/c68517a3e18e20997808821c5559d0cba4d776c1",
                "https://git.kernel.org/stable/c/ecfe9171b26ae3eed0cd8bab7a943e9e2c9e51ba",
                "https://git.kernel.org/stable/c/ede69b8f6670600e534591664584f810d7c385f9",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-25T09:16:41.493",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53236"
                }
            ]
        },
        {
            "id": "CVE-2026-53223",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: guard timestamp cmsgs to real error queue skbs\n\nskb_is_err_queue() treats PACKET_OUTGOING as the sole marker for an skb\nfrom sk_error_queue. That assumption is not true for AF_PACKET sockets:\noutgoing packet taps are also delivered to packet sockets with\nskb->pkt_type == PACKET_OUTGOING, but their skb->cb is owned by AF_PACKET\ninstead of struct sock_exterr_skb.\n\nIf such an skb is received with timestamping enabled, the generic\ntimestamp cmsg path can read AF_PACKET control-buffer state as\nsock_exterr_skb::opt_stats. With SO_RXQ_OVFL enabled, the packet drop\ncounter overlaps opt_stats. An odd drop count makes the path emit\nSCM_TIMESTAMPING_OPT_STATS with skb->len and skb->data. For non-linear\nskbs this copies past the linear head and can trigger hardened usercopy or\ndisclose adjacent heap contents.\n\nKeep skb_is_err_queue() local to net/socket.c, but make it verify that\nthe PACKET_OUTGOING marker is paired with the sock_rmem_free destructor\ninstalled by sock_queue_err_skb(). AF_PACKET receive skbs use normal\nreceive ownership and no longer pass as error-queue skbs, while legitimate\nsk_error_queue entries keep the PACKET_OUTGOING marker and sock_rmem_free\nownership.",
            "updated_at": "2026-09-08T09:18:14.723",
            "published_at": "2026-06-25T09:16:40.073",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8605330aac5a5785630aec8f64378a54891937cc through before 24a0d548d3a765cd4558224e4f8e06e14cba26e3 (git); 8605330aac5a5785630aec8f64378a54891937cc through before 71ff5cdd5da61d0438e902aa0fd68c28bc901abe (git); 8605330aac5a5785630aec8f64378a54891937cc through before ad9a0374ee6d11048e1f74cd5180bad58b9848b4 (git); 8605330aac5a5785630aec8f64378a54891937cc through before b903e9b5629ec8dd6db92174070045bf81ad7060 (git); 8605330aac5a5785630aec8f64378a54891937cc through before e0665b2a8e90bb08bd205062c75662b502d31797 (git); 8605330aac5a5785630aec8f64378a54891937cc through before 3dde4fb941fa5649ab809f6cd3e20e0c424a4e31 (git); 8605330aac5a5785630aec8f64378a54891937cc through before eb51a9ad3ceb01bc6c0fb608dbc856e03ee6f24a (git); 8605330aac5a5785630aec8f64378a54891937cc through before 1ee90b77b727df903033db873c75caac5c27ec98 (git); cdaf15b43bd31003220cb080bcbbd57787a2fca9 (git); 4.10.14 through before 4.11 (semver); 4.11; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: guard timestamp cmsgs to real error queue skbs\n\nskb_is_err_queue() treats PACKET_OUTGOING as the sole marker for an skb\nfrom sk_error_queue. That assumption is not true for AF_PACKET sockets:\noutgoing packet taps are also delivered to packet sockets with\nskb->pkt_type == PACKET_OUTGOING, but their skb->cb is owned by AF_PACKET\ninstead of struct sock_exterr_skb.\n\nIf such an skb is received with timestamping enabled, the generic\ntimestamp cmsg path can read AF_PACKET control-buffer state as\nsock_exterr_skb::opt_stats. With SO_RXQ_OVFL enabled, the packet drop\ncounter overlaps opt_stats. An odd drop count makes the path emit\nSCM_TIMESTAMPING_OPT_STATS with skb->len and skb->data. For non-linear\nskbs this copies past the linear head and can trigger hardened usercopy or\ndisclose adjacent heap contents.\n\nKeep skb_is_err_queue() local to net/socket.c, but make it verify that\nthe PACKET_OUTGOING marker is paired with the sock_rmem_free destructor\ninstalled by sock_queue_err_skb(). AF_PACKET receive skbs use normal\nreceive ownership and no longer pass as error-queue skbs, while legitimate\nsk_error_queue entries keep the PACKET_OUTGOING marker and sock_rmem_free\nownership.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1ee90b77b727df903033db873c75caac5c27ec98",
                "https://git.kernel.org/stable/c/24a0d548d3a765cd4558224e4f8e06e14cba26e3",
                "https://git.kernel.org/stable/c/3dde4fb941fa5649ab809f6cd3e20e0c424a4e31",
                "https://git.kernel.org/stable/c/71ff5cdd5da61d0438e902aa0fd68c28bc901abe",
                "https://git.kernel.org/stable/c/ad9a0374ee6d11048e1f74cd5180bad58b9848b4",
                "https://git.kernel.org/stable/c/b903e9b5629ec8dd6db92174070045bf81ad7060",
                "https://git.kernel.org/stable/c/e0665b2a8e90bb08bd205062c75662b502d31797",
                "https://git.kernel.org/stable/c/eb51a9ad3ceb01bc6c0fb608dbc856e03ee6f24a",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-25T09:16:40.073",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53223"
                }
            ]
        },
        {
            "id": "CVE-2026-53219",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: x_tables: avoid leaking percpu counter pointers\n\nThe native and compat get-entries paths copy the fixed rule entry header\nfrom the kernelized rule blob to userspace before overwriting the entry's\ncounter fields with a sanitized counter snapshot.\n\nOn SMP kernels, entry->counters.pcnt contains the percpu allocation\naddress used by x_tables rule counters. A caller can provide a userspace\nbuffer that faults during the initial fixed-header copy after pcnt has\nbeen copied but before the later sanitized counter copy runs. The syscall\nthen returns -EFAULT while leaving the raw percpu pointer in userspace.\n\nCopy only the fixed entry prefix before counters from the kernelized rule\nblob, then copy the sanitized counter snapshot into the counter field.\nApply this ordering to the IPv4, IPv6, and ARP native and compat\nget-entries implementations so a fault cannot expose the internal percpu\ncounter pointer.",
            "updated_at": "2026-09-08T09:18:14.567",
            "published_at": "2026-06-25T09:16:39.613",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "71ae0dff02d756e4d2ca710b79f2ff5390029a5f through before b74ba3343eb44b2cbf7e9665918c287df1d52ebb (git); 71ae0dff02d756e4d2ca710b79f2ff5390029a5f through before 0b35dc8527ccc16b7dc34e8a3164313e68cd4e45 (git); 71ae0dff02d756e4d2ca710b79f2ff5390029a5f through before b28e2fcad3db7e8687b15bc20bced26b5b7c920e (git); 71ae0dff02d756e4d2ca710b79f2ff5390029a5f through before a0d16941adf3a501956d74aefd8d6e217906e79c (git); 71ae0dff02d756e4d2ca710b79f2ff5390029a5f through before 8d67e42ad3b1a95a152541015a07110e06992d6c (git); 71ae0dff02d756e4d2ca710b79f2ff5390029a5f through before 08a3e218064db11f154ad9ad5541751ea7f34ebe (git); 71ae0dff02d756e4d2ca710b79f2ff5390029a5f through before fb0521aff1e10e300d89725cc439d3ea74c828c5 (git); 71ae0dff02d756e4d2ca710b79f2ff5390029a5f through before f7f2fbb0e893a0238dc464f8d8c0f5609bec584f (git); 4.2; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: x_tables: avoid leaking percpu counter pointers\n\nThe native and compat get-entries paths copy the fixed rule entry header\nfrom the kernelized rule blob to userspace before overwriting the entry's\ncounter fields with a sanitized counter snapshot.\n\nOn SMP kernels, entry->counters.pcnt contains the percpu allocation\naddress used by x_tables rule counters. A caller can provide a userspace\nbuffer that faults during the initial fixed-header copy after pcnt has\nbeen copied but before the later sanitized counter copy runs. The syscall\nthen returns -EFAULT while leaving the raw percpu pointer in userspace.\n\nCopy only the fixed entry prefix before counters from the kernelized rule\nblob, then copy the sanitized counter snapshot into the counter field.\nApply this ordering to the IPv4, IPv6, and ARP native and compat\nget-entries implementations so a fault cannot expose the internal percpu\ncounter pointer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/08a3e218064db11f154ad9ad5541751ea7f34ebe",
                "https://git.kernel.org/stable/c/0b35dc8527ccc16b7dc34e8a3164313e68cd4e45",
                "https://git.kernel.org/stable/c/8d67e42ad3b1a95a152541015a07110e06992d6c",
                "https://git.kernel.org/stable/c/a0d16941adf3a501956d74aefd8d6e217906e79c",
                "https://git.kernel.org/stable/c/b28e2fcad3db7e8687b15bc20bced26b5b7c920e",
                "https://git.kernel.org/stable/c/b74ba3343eb44b2cbf7e9665918c287df1d52ebb",
                "https://git.kernel.org/stable/c/f7f2fbb0e893a0238dc464f8d8c0f5609bec584f",
                "https://git.kernel.org/stable/c/fb0521aff1e10e300d89725cc439d3ea74c828c5",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-25T09:16:39.613",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53219"
                }
            ]
        },
        {
            "id": "CVE-2026-53218",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_exthdr: fix register tracking for F_PRESENT flag\n\nnft_exthdr_init() passes user-controlled priv->len to\nnft_parse_register_store(), which marks that many bytes in the\nregister bitmap as initialized.  However, when NFT_EXTHDR_F_PRESENT\nis set, the eval paths write only 1 byte (nft_reg_store8) or\n4 bytes (*dest = 0 on TCP/DCCP error path).  When len > 4,\nregisters beyond the first are never written, retaining\nuninitialized stack data from nft_regs.\n\nBail out if userspace requests too much data when F_PRESENT is set.",
            "updated_at": "2026-09-08T09:18:14.403",
            "published_at": "2026-06-25T09:16:39.500",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c078ca3b0c5bf82c2b31906c446d6e2ad8ea0783 through before 8738b1b6d0e639ca1fc0f61516afd3557ac4ecc6 (git); c078ca3b0c5bf82c2b31906c446d6e2ad8ea0783 through before 19748967d59c31d24d21d40b728570788310b237 (git); c078ca3b0c5bf82c2b31906c446d6e2ad8ea0783 through before 46fc15a044e9938e7ea77786fb37edd2cd74f031 (git); c078ca3b0c5bf82c2b31906c446d6e2ad8ea0783 through before cd513e43b4b2bd1de39e2367bc4261c699a8652f (git); c078ca3b0c5bf82c2b31906c446d6e2ad8ea0783 through before 67b27434c43b68a97becda98c9f0c8cf6cba2134 (git); c078ca3b0c5bf82c2b31906c446d6e2ad8ea0783 through before 78069a6d8bc86c9e036eb82c2af4a19cc1871a53 (git); c078ca3b0c5bf82c2b31906c446d6e2ad8ea0783 through before f08fb3d42fd3aad0b7a263da3ac3ebaf0845e265 (git); c078ca3b0c5bf82c2b31906c446d6e2ad8ea0783 through before 772cecf198da732faebb5dcfc46d66a505be8495 (git); 4.11; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-908",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_exthdr: fix register tracking for F_PRESENT flag\n\nnft_exthdr_init() passes user-controlled priv->len to\nnft_parse_register_store(), which marks that many bytes in the\nregister bitmap as initialized.  However, when NFT_EXTHDR_F_PRESENT\nis set, the eval paths write only 1 byte (nft_reg_store8) or\n4 bytes (*dest = 0 on TCP/DCCP error path).  When len > 4,\nregisters beyond the first are never written, retaining\nuninitialized stack data from nft_regs.\n\nBail out if userspace requests too much data when F_PRESENT is set.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/19748967d59c31d24d21d40b728570788310b237",
                "https://git.kernel.org/stable/c/46fc15a044e9938e7ea77786fb37edd2cd74f031",
                "https://git.kernel.org/stable/c/67b27434c43b68a97becda98c9f0c8cf6cba2134",
                "https://git.kernel.org/stable/c/772cecf198da732faebb5dcfc46d66a505be8495",
                "https://git.kernel.org/stable/c/78069a6d8bc86c9e036eb82c2af4a19cc1871a53",
                "https://git.kernel.org/stable/c/8738b1b6d0e639ca1fc0f61516afd3557ac4ecc6",
                "https://git.kernel.org/stable/c/cd513e43b4b2bd1de39e2367bc4261c699a8652f",
                "https://git.kernel.org/stable/c/f08fb3d42fd3aad0b7a263da3ac3ebaf0845e265",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-25T09:16:39.500",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53218"
                }
            ]
        },
        {
            "id": "CVE-2026-53196",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: io_ti: fix heap overflow in get_manuf_info()\n\nget_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the\ndevice I2C EEPROM into a buffer allocated with kmalloc_obj(), which\nis sizeof(struct edge_ti_manuf_descriptor) = 10 bytes.\n\nThe Size field comes from the device and is only validated (in\ncheck_i2c_image()) to make sure the descriptor fits within\nTI_MAX_I2C_SIZE (16384 bytes), not against the destination buffer size.\nA malicious USB device can therefore set Size to any value up to 16377,\ncausing a heap overflow of up to 16367 bytes when plugged into a host\nrunning this driver.\n\nvalid_csum() is called after read_rom() and also iterates\nbuffer[0..Size-1], compounding the out-of-bounds access.\n\nFix by rejecting descriptors with unexpected length before calling\nread_rom().\n\n[ johan: amend commit message; also check for short descriptors ]",
            "updated_at": "2026-09-16T13:18:02.680",
            "published_at": "2026-06-25T09:16:37.107",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before e168db91442b94e64fa82a7dd297983d48ea5cc0 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 561edb021486e6723d841926aa4b48097da06190 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before cfd634f6dfd40c49a84f9bddc2867a80e2e2623a (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before d92f17af7097d10bdeddf26f66f34b354104b277 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before b849f30d1a9e66aae6b715aaef66e427390cb081 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before f96cf7bf9fbf15d7fcf0c91fec47ba8a010369ea (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before d214d2341d4f9f447e36a7d012cdf6a6631a55f1 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 183c1076eca43bbb3e7bdf597456f91d81c73e74 (git); 2.6.12",
            "fixed": "See vendor advisory",
            "source_count": 20,
            "kev": false,
            "attack_vector": "Physical",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: io_ti: fix heap overflow in get_manuf_info()\n\nget_manuf_info() reads le16_to_cpu(rom_desc->Size) bytes from the\ndevice I2C EEPROM into a buffer allocated with kmalloc_obj(), which\nis sizeof(struct edge_ti_manuf_descriptor) = 10 bytes.\n\nThe Size field comes from the device and is only validated (in\ncheck_i2c_image()) to make sure the descriptor fits within\nTI_MAX_I2C_SIZE (16384 bytes), not against the destination buffer size.\nA malicious USB device can therefore set Size to any value up to 16377,\ncausing a heap overflow of up to 16367 bytes when plugged into a host\nrunning this driver.\n\nvalid_csum() is called after read_rom() and also iterates\nbuffer[0..Size-1], compounding the out-of-bounds access.\n\nFix by rejecting descriptors with unexpected length before calling\nread_rom().\n\n[ johan: amend commit message; also check for short descriptors ]",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/183c1076eca43bbb3e7bdf597456f91d81c73e74",
                "https://git.kernel.org/stable/c/561edb021486e6723d841926aa4b48097da06190",
                "https://git.kernel.org/stable/c/b849f30d1a9e66aae6b715aaef66e427390cb081",
                "https://git.kernel.org/stable/c/cfd634f6dfd40c49a84f9bddc2867a80e2e2623a",
                "https://git.kernel.org/stable/c/d214d2341d4f9f447e36a7d012cdf6a6631a55f1",
                "https://git.kernel.org/stable/c/d92f17af7097d10bdeddf26f66f34b354104b277",
                "https://git.kernel.org/stable/c/e168db91442b94e64fa82a7dd297983d48ea5cc0",
                "https://git.kernel.org/stable/c/f96cf7bf9fbf15d7fcf0c91fec47ba8a010369ea",
                "https://access.redhat.com/errata/RHSA-2026:61887",
                "https://access.redhat.com/errata/RHSA-2026:65708",
                "https://access.redhat.com/errata/RHSA-2026:65709",
                "https://access.redhat.com/errata/RHSA-2026:65710",
                "https://access.redhat.com/errata/RHSA-2026:65711",
                "https://access.redhat.com/errata/RHSA-2026:65712",
                "https://access.redhat.com/errata/RHSA-2026:67114",
                "https://access.redhat.com/errata/RHSA-2026:67721",
                "https://access.redhat.com/errata/RHSA-2026:67723",
                "https://access.redhat.com/security/cve/CVE-2026-53196",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492750",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53196.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-25T09:16:37.107",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53196"
                }
            ]
        },
        {
            "id": "CVE-2026-53134",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_fib: fix stale stack leak via the OIFNAME register\n\nFor NFT_FIB_RESULT_OIFNAME the destination register is declared with\nlen = IFNAMSIZ (four 32-bit registers), but on the lookup-fail,\nRTN_LOCAL and oif-mismatch paths nft_fib{4,6}_eval() only writes one\nregister via \"*dest = 0\". The remaining three registers are left as\nwhatever was on the stack in nft_do_chain()'s struct nft_regs, and a\ndownstream expression that loads the register span can leak that\nuninitialised kernel stack to userspace.\n\nThe NFTA_FIB_F_PRESENT existence check has the same shape: it is only\nmeaningful for NFT_FIB_RESULT_OIF, yet it was accepted for any result type\nwhile the eval stores a single byte via nft_reg_store8(), leaving the rest\nof the declared span stale.\n\nFix both:\n\n - replace the bare \"*dest = 0\" in the eval with nft_fib_store_result(),\n   which strscpy_pad()s the whole IFNAMSIZ for OIFNAME (and is already\n   used on the other early-return path), and\n\n - restrict NFTA_FIB_F_PRESENT to NFT_FIB_RESULT_OIF and declare its\n   destination as a single u8, so the marked span matches the one byte\n   the eval writes.",
            "updated_at": "2026-09-08T09:18:14.237",
            "published_at": "2026-06-25T09:16:30.657",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 through before 6744e49fe51bfba26522acc2d0e9703cb41d8e50 (git); f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 through before eca18feed38b3377a2ec5d1f22af1170c55d0171 (git); f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 through before d19ddef8c327a4773ff81f8e51027d1e0b4cf069 (git); f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 through before eb8a8124484dbc3c2b543e207da39bbccb703d31 (git); f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 through before 8c84885e9790823828bb8084736ea15769b1ac16 (git); f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 through before 84d8f58cf28a0415413f43ba7148f7bacd4c1b6e (git); f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 through before 3544210609f6d1db282bbdeca639104ef624c393 (git); f6d0cbcf09c506b9b022df8f9d7693a7cec3c732 through before ab185e0c4fb82dfba6fb86f8271e06f931d9c64c (git); 4.10; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-401",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_fib: fix stale stack leak via the OIFNAME register\n\nFor NFT_FIB_RESULT_OIFNAME the destination register is declared with\nlen = IFNAMSIZ (four 32-bit registers), but on the lookup-fail,\nRTN_LOCAL and oif-mismatch paths nft_fib{4,6}_eval() only writes one\nregister via \"*dest = 0\". The remaining three registers are left as\nwhatever was on the stack in nft_do_chain()'s struct nft_regs, and a\ndownstream expression that loads the register span can leak that\nuninitialised kernel stack to userspace.\n\nThe NFTA_FIB_F_PRESENT existence check has the same shape: it is only\nmeaningful for NFT_FIB_RESULT_OIF, yet it was accepted for any result type\nwhile the eval stores a single byte via nft_reg_store8(), leaving the rest\nof the declared span stale.\n\nFix both:\n\n - replace the bare \"*dest = 0\" in the eval with nft_fib_store_result(),\n   which strscpy_pad()s the whole IFNAMSIZ for OIFNAME (and is already\n   used on the other early-return path), and\n\n - restrict NFTA_FIB_F_PRESENT to NFT_FIB_RESULT_OIF and declare its\n   destination as a single u8, so the marked span matches the one byte\n   the eval writes.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/3544210609f6d1db282bbdeca639104ef624c393",
                "https://git.kernel.org/stable/c/6744e49fe51bfba26522acc2d0e9703cb41d8e50",
                "https://git.kernel.org/stable/c/84d8f58cf28a0415413f43ba7148f7bacd4c1b6e",
                "https://git.kernel.org/stable/c/8c84885e9790823828bb8084736ea15769b1ac16",
                "https://git.kernel.org/stable/c/ab185e0c4fb82dfba6fb86f8271e06f931d9c64c",
                "https://git.kernel.org/stable/c/d19ddef8c327a4773ff81f8e51027d1e0b4cf069",
                "https://git.kernel.org/stable/c/eb8a8124484dbc3c2b543e207da39bbccb703d31",
                "https://git.kernel.org/stable/c/eca18feed38b3377a2ec5d1f22af1170c55d0171",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-25T09:16:30.657",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53134"
                }
            ]
        },
        {
            "id": "CVE-2026-53113",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix memory leaks in beacon template setup\n\nThe functions ath11k_mac_setup_bcn_tmpl_ema() and\nath11k_mac_setup_bcn_tmpl_mbssid() allocate memory for beacon templates\nbut fail to free it when parameter setup returns an error.\n\nSince beacon templates must be released during normal execution, they\nmust also be released in the error handling paths to prevent memory\nleaks.\n\nFix this by using unified exit paths with proper cleanup in the respective\nerror paths.\n\nCompile tested only. Issue found using a prototype static analysis tool\nand code review.",
            "updated_at": "2026-09-07T16:17:28.680",
            "published_at": "2026-06-24T17:17:25.700",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "335a92765d308dfe22826f5562cd4b4389b45e71 through before 9478aa5b39e986d45fafe279c24d3546783c22b1 (git); 335a92765d308dfe22826f5562cd4b4389b45e71 through before 5fc3d921512d31839227a2d22a2990de02acefeb (git); 335a92765d308dfe22826f5562cd4b4389b45e71 through before 5d63aa38d5ca85206d9699ffdd616b58780dba07 (git); 335a92765d308dfe22826f5562cd4b4389b45e71 through before ff49eba595df500e4ddccc593088c8a4ab5f2c27 (git); 6.5",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-401",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix memory leaks in beacon template setup\n\nThe functions ath11k_mac_setup_bcn_tmpl_ema() and\nath11k_mac_setup_bcn_tmpl_mbssid() allocate memory for beacon templates\nbut fail to free it when parameter setup returns an error.\n\nSince beacon templates must be released during normal execution, they\nmust also be released in the error handling paths to prevent memory\nleaks.\n\nFix this by using unified exit paths with proper cleanup in the respective\nerror paths.\n\nCompile tested only. Issue found using a prototype static analysis tool\nand code review.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/5d63aa38d5ca85206d9699ffdd616b58780dba07",
                "https://git.kernel.org/stable/c/5fc3d921512d31839227a2d22a2990de02acefeb",
                "https://git.kernel.org/stable/c/9478aa5b39e986d45fafe279c24d3546783c22b1",
                "https://git.kernel.org/stable/c/ff49eba595df500e4ddccc593088c8a4ab5f2c27"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:25.700",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53113"
                }
            ]
        },
        {
            "id": "CVE-2026-53102",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()\n\nmt76_connac_mcu_alloc_sta_req() allocates an skb which is expected to\nbe freed eventually by mt76_mcu_skb_send_msg(). However, currently if\nan intermediate function fails before sending, the allocated skb is\nleaked.\n\nSpecifically, mt76_connac_mcu_sta_wed_update() and\nmt76_connac_mcu_sta_key_tlv() may fail, leading to an immediate memory\nleak in the error path.\n\nFix this by explicitly freeing the skb in these error paths.\nCommit 7c0f63fe37a5 (\"wifi: mt76: mt7996: fix memory leak on\nmt7996_mcu_sta_key_tlv error\") made a similar change.\n\nCompile tested only. Issue found using a prototype static analysis tool\nand code review.",
            "updated_at": "2026-09-07T16:17:28.540",
            "published_at": "2026-06-24T17:17:24.473",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6683d988089ce0e80bd859a9493333b6b272420e through before 7de35b99503012e57bec027e98ed53f881518b5b (git); 6683d988089ce0e80bd859a9493333b6b272420e through before 8527ac1bce87aaabde6755e8e6eb2a9f439d1292 (git); 6683d988089ce0e80bd859a9493333b6b272420e through before eb466406d2094deefadc2cd6ddb4f6eeb086d1b4 (git); 6683d988089ce0e80bd859a9493333b6b272420e through before c41075ce8cf05ed8c0e7b7efef000dce548ffc42 (git); 5.18",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-401",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()\n\nmt76_connac_mcu_alloc_sta_req() allocates an skb which is expected to\nbe freed eventually by mt76_mcu_skb_send_msg(). However, currently if\nan intermediate function fails before sending, the allocated skb is\nleaked.\n\nSpecifically, mt76_connac_mcu_sta_wed_update() and\nmt76_connac_mcu_sta_key_tlv() may fail, leading to an immediate memory\nleak in the error path.\n\nFix this by explicitly freeing the skb in these error paths.\nCommit 7c0f63fe37a5 (\"wifi: mt76: mt7996: fix memory leak on\nmt7996_mcu_sta_key_tlv error\") made a similar change.\n\nCompile tested only. Issue found using a prototype static analysis tool\nand code review.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/7de35b99503012e57bec027e98ed53f881518b5b",
                "https://git.kernel.org/stable/c/8527ac1bce87aaabde6755e8e6eb2a9f439d1292",
                "https://git.kernel.org/stable/c/c41075ce8cf05ed8c0e7b7efef000dce548ffc42",
                "https://git.kernel.org/stable/c/eb466406d2094deefadc2cd6ddb4f6eeb086d1b4"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:24.473",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53102"
                }
            ]
        },
        {
            "id": "CVE-2026-53071",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp\n\nl2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding\nl2cap_chan_lock(). Every other l2cap_chan_del() caller in the file\nacquires the lock first. A remote BLE device can send a crafted\nL2CAP ECRED reconfiguration response to corrupt the channel list\nwhile another thread is iterating it.\n\nAdd l2cap_chan_hold() and l2cap_chan_lock() before l2cap_chan_del(),\nand l2cap_chan_unlock() and l2cap_chan_put() after, matching the\npattern used in l2cap_ecred_conn_rsp() and l2cap_conn_del().",
            "updated_at": "2026-09-16T13:18:02.357",
            "published_at": "2026-06-24T17:17:20.843",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "15f02b91056253e8cdc592888f431da0731337b8 through before 96dca51715d86559ed6ed8028e5445cecb80f3ae (git); 15f02b91056253e8cdc592888f431da0731337b8 through before 330b20ec97916961ee0e6c29c06bc0fa7c96e64c (git); 15f02b91056253e8cdc592888f431da0731337b8 through before 0ccd75c51f620374086f359e906917676e699a1c (git); 15f02b91056253e8cdc592888f431da0731337b8 through before 77a853aec710b2fdf41fa298ea3cbc9a4358f917 (git); 15f02b91056253e8cdc592888f431da0731337b8 through before fe1188abdae9b7a8199dcdfcf9244d5e5d61eb14 (git); 15f02b91056253e8cdc592888f431da0731337b8 through before dc89961b76f12aff47124c1df4bdb32a080f4d0c (git); 15f02b91056253e8cdc592888f431da0731337b8 through before 5501d055a1ce3c747141e3955ba8cf034d193f3e (git); 15f02b91056253e8cdc592888f431da0731337b8 through before 42776497cdbc9a665b384a6dcb85f0d4bd927eab (git); 5.7",
            "fixed": "See vendor advisory",
            "source_count": 19,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-667",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp\n\nl2cap_ecred_reconf_rsp() calls l2cap_chan_del() without holding\nl2cap_chan_lock(). Every other l2cap_chan_del() caller in the file\nacquires the lock first. A remote BLE device can send a crafted\nL2CAP ECRED reconfiguration response to corrupt the channel list\nwhile another thread is iterating it.\n\nAdd l2cap_chan_hold() and l2cap_chan_lock() before l2cap_chan_del(),\nand l2cap_chan_unlock() and l2cap_chan_put() after, matching the\npattern used in l2cap_ecred_conn_rsp() and l2cap_conn_del().",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0ccd75c51f620374086f359e906917676e699a1c",
                "https://git.kernel.org/stable/c/330b20ec97916961ee0e6c29c06bc0fa7c96e64c",
                "https://git.kernel.org/stable/c/42776497cdbc9a665b384a6dcb85f0d4bd927eab",
                "https://git.kernel.org/stable/c/5501d055a1ce3c747141e3955ba8cf034d193f3e",
                "https://git.kernel.org/stable/c/77a853aec710b2fdf41fa298ea3cbc9a4358f917",
                "https://git.kernel.org/stable/c/96dca51715d86559ed6ed8028e5445cecb80f3ae",
                "https://git.kernel.org/stable/c/dc89961b76f12aff47124c1df4bdb32a080f4d0c",
                "https://git.kernel.org/stable/c/fe1188abdae9b7a8199dcdfcf9244d5e5d61eb14",
                "https://access.redhat.com/errata/RHSA-2026:42550",
                "https://access.redhat.com/errata/RHSA-2026:42552",
                "https://access.redhat.com/errata/RHSA-2026:42919",
                "https://access.redhat.com/errata/RHSA-2026:43307",
                "https://access.redhat.com/errata/RHSA-2026:65710",
                "https://access.redhat.com/errata/RHSA-2026:65711",
                "https://access.redhat.com/errata/RHSA-2026:67721",
                "https://access.redhat.com/errata/RHSA-2026:67723",
                "https://access.redhat.com/security/cve/CVE-2026-53071",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492458",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53071.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:20.843",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53071"
                }
            ]
        },
        {
            "id": "CVE-2026-53050",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nquota: Fix race of dquot_scan_active() with quota deactivation\n\ndquot_scan_active() can race with quota deactivation in\nquota_release_workfn() like:\n\n  CPU0 (quota_release_workfn)         CPU1 (dquot_scan_active)\n  ==============================      ==============================\n  spin_lock(&dq_list_lock);\n  list_replace_init(\n    &releasing_dquots, &rls_head);\n    /* dquot X on rls_head,\n       dq_count == 0,\n       DQ_ACTIVE_B still set */\n  spin_unlock(&dq_list_lock);\n  synchronize_srcu(&dquot_srcu);\n                                      spin_lock(&dq_list_lock);\n                                      list_for_each_entry(dquot,\n                                          &inuse_list, dq_inuse) {\n                                        /* finds dquot X */\n                                        dquot_active(X) -> true\n                                        atomic_inc(&X->dq_count);\n                                      }\n                                      spin_unlock(&dq_list_lock);\n  spin_lock(&dq_list_lock);\n  dquot = list_first_entry(&rls_head);\n  WARN_ON_ONCE(atomic_read(&dquot->dq_count));\n\nThe problem is not only a cosmetic one as under memory pressure the\ncaller of dquot_scan_active() can end up working on freed dquot.\n\nFix the problem by making sure the dquot is removed from releasing list\nwhen we acquire a reference to it.",
            "updated_at": "2026-09-08T09:18:14.037",
            "published_at": "2026-06-24T17:17:16.887",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "22c06bf1f99ec3ec16b1a81342becba4c59a1f16 through before 2bdc80f4619411e5bd4a3ef23f51e14021ed457c (git); 56e96b38d2f7cd95b3c30eb70decac7233915e0a through before f9438cb8c8ec3adc84b2b450a3aab0123d074c3b (git); 12a820a9923c11e8e898da9f82c8aded70cdcd16 through before ac8a2e0d287ebf35e5d7e51e260b4e146648ba4a (git); 869b6ea1609f655a43251bf41757aa44e5350a8f through before 6678dde265708003c2b42551af4a2e3cb05decd5 (git); 869b6ea1609f655a43251bf41757aa44e5350a8f through before 61e25f664dc2a08299e07d84c85776abc2350f75 (git); 869b6ea1609f655a43251bf41757aa44e5350a8f through before fdd424d7c35633ac577fd87d1b043d1b8a6cd350 (git); 869b6ea1609f655a43251bf41757aa44e5350a8f through before 82cbdb4c1ebb5ea7d7bd45c18d3483b5bd32ebc1 (git); 869b6ea1609f655a43251bf41757aa44e5350a8f through before e93ab401da4b2e2c1b8ef2424de2f238d51c8b2d (git); bb7e3a019b52d829949d02b64ebab37838148fbf (git); 061a18239ced5eb086967a2b4451cb1cc5ce0702 (git); 2a1ddddba6541143c8f73962f3021f1789114284 (git); 5.10.199 through before 5.10.258 (semver); 5.15.136 through before 5.15.209 (semver); 6.1.59 through before 6.1.175 (semver); 4.19.297 through before 4.20 (semver); 5.4.259 through before 5.5 (semver); 6.5.8 through before 6.6 (semver); 6.6; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-362",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nquota: Fix race of dquot_scan_active() with quota deactivation\n\ndquot_scan_active() can race with quota deactivation in\nquota_release_workfn() like:\n\n  CPU0 (quota_release_workfn)         CPU1 (dquot_scan_active)\n  ==============================      ==============================\n  spin_lock(&dq_list_lock);\n  list_replace_init(\n    &releasing_dquots, &rls_head);\n    /* dquot X on rls_head,\n       dq_count == 0,\n       DQ_ACTIVE_B still set */\n  spin_unlock(&dq_list_lock);\n  synchronize_srcu(&dquot_srcu);\n                                      spin_lock(&dq_list_lock);\n                                      list_for_each_entry(dquot,\n                                          &inuse_list, dq_inuse) {\n                                        /* finds dquot X */\n                                        dquot_active(X) -> true\n                                        atomic_inc(&X->dq_count);\n                                      }\n                                      spin_unlock(&dq_list_lock);\n  spin_lock(&dq_list_lock);\n  dquot = list_first_entry(&rls_head);\n  WARN_ON_ONCE(atomic_read(&dquot->dq_count));\n\nThe problem is not only a cosmetic one as under memory pressure the\ncaller of dquot_scan_active() can end up working on freed dquot.\n\nFix the problem by making sure the dquot is removed from releasing list\nwhen we acquire a reference to it.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2bdc80f4619411e5bd4a3ef23f51e14021ed457c",
                "https://git.kernel.org/stable/c/61e25f664dc2a08299e07d84c85776abc2350f75",
                "https://git.kernel.org/stable/c/6678dde265708003c2b42551af4a2e3cb05decd5",
                "https://git.kernel.org/stable/c/82cbdb4c1ebb5ea7d7bd45c18d3483b5bd32ebc1",
                "https://git.kernel.org/stable/c/ac8a2e0d287ebf35e5d7e51e260b4e146648ba4a",
                "https://git.kernel.org/stable/c/e93ab401da4b2e2c1b8ef2424de2f238d51c8b2d",
                "https://git.kernel.org/stable/c/f9438cb8c8ec3adc84b2b450a3aab0123d074c3b",
                "https://git.kernel.org/stable/c/fdd424d7c35633ac577fd87d1b043d1b8a6cd350",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:16.887",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53050"
                }
            ]
        },
        {
            "id": "CVE-2026-53016",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - copy IV using skcipher ivsize\n\nAF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver.\n\nccp_aes_complete() restores AES_BLOCK_SIZE bytes into the caller's IV\nbuffer while RFC3686 skciphers expose an 8-byte IV, so the restore\noverruns the provided buffer.\n\nUse crypto_skcipher_ivsize() to copy only the algorithm's IV length.",
            "updated_at": "2026-09-16T13:18:01.940",
            "published_at": "2026-06-24T17:17:12.893",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2b789435d7f36ed918d92db647f3a2f3fec9bb1f through before 939061b2d0f7f15114e34b4ce878ef50ff4089c3 (git); 2b789435d7f36ed918d92db647f3a2f3fec9bb1f through before 798d409a8949f3f495f238549b86de2886b129bd (git); 2b789435d7f36ed918d92db647f3a2f3fec9bb1f through before dfb2cf434829819268fe50f41542aad318ad62b2 (git); 2b789435d7f36ed918d92db647f3a2f3fec9bb1f through before eecee15e263ccb8cd77170a56ab6c969cb54dd6a (git); 2b789435d7f36ed918d92db647f3a2f3fec9bb1f through before bb01d8f1f385bc9034ca114d3508c7fdea24fc9a (git); 2b789435d7f36ed918d92db647f3a2f3fec9bb1f through before df9784bb5b637ac80f4a2768a58ca9a50bef28a9 (git); 2b789435d7f36ed918d92db647f3a2f3fec9bb1f through before 227c1e1d9e2aa4cfc65ba446d5690da1f546cda4 (git); 2b789435d7f36ed918d92db647f3a2f3fec9bb1f through before a7a1f3cdd64d8a165d9b8c9e9ad7fb46ac19dfc4 (git); 3.14",
            "fixed": "See vendor advisory",
            "source_count": 23,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - copy IV using skcipher ivsize\n\nAF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver.\n\nccp_aes_complete() restores AES_BLOCK_SIZE bytes into the caller's IV\nbuffer while RFC3686 skciphers expose an 8-byte IV, so the restore\noverruns the provided buffer.\n\nUse crypto_skcipher_ivsize() to copy only the algorithm's IV length.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/227c1e1d9e2aa4cfc65ba446d5690da1f546cda4",
                "https://git.kernel.org/stable/c/798d409a8949f3f495f238549b86de2886b129bd",
                "https://git.kernel.org/stable/c/939061b2d0f7f15114e34b4ce878ef50ff4089c3",
                "https://git.kernel.org/stable/c/a7a1f3cdd64d8a165d9b8c9e9ad7fb46ac19dfc4",
                "https://git.kernel.org/stable/c/bb01d8f1f385bc9034ca114d3508c7fdea24fc9a",
                "https://git.kernel.org/stable/c/df9784bb5b637ac80f4a2768a58ca9a50bef28a9",
                "https://git.kernel.org/stable/c/dfb2cf434829819268fe50f41542aad318ad62b2",
                "https://git.kernel.org/stable/c/eecee15e263ccb8cd77170a56ab6c969cb54dd6a",
                "https://access.redhat.com/errata/RHSA-2026:38491",
                "https://access.redhat.com/errata/RHSA-2026:39494",
                "https://access.redhat.com/errata/RHSA-2026:55764",
                "https://access.redhat.com/errata/RHSA-2026:55765",
                "https://access.redhat.com/errata/RHSA-2026:56574",
                "https://access.redhat.com/errata/RHSA-2026:59473",
                "https://access.redhat.com/errata/RHSA-2026:59544",
                "https://access.redhat.com/errata/RHSA-2026:61256",
                "https://access.redhat.com/errata/RHSA-2026:64767",
                "https://access.redhat.com/errata/RHSA-2026:65710",
                "https://access.redhat.com/errata/RHSA-2026:67721",
                "https://access.redhat.com/errata/RHSA-2026:67723",
                "https://access.redhat.com/security/cve/CVE-2026-53016",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492269",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53016.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:12.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53016"
                }
            ]
        },
        {
            "id": "CVE-2026-53012",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: fix IPv6 route referencing IPv4 nexthop\n\nsyzbot reported a panic [1] [2].\n\nWhen an IPv6 nexthop is replaced with an IPv4 nexthop, the has_v4 flag\nof all groups containing this nexthop is not updated. This is because\nnh_group_v4_update is only called when replacing AF_INET to AF_INET6,\nbut the reverse direction (AF_INET6 to AF_INET) is missed.\n\nThis allows a stale has_v4=false to bypass fib6_check_nexthop, causing\nIPv6 routes to be attached to groups that effectively contain only AF_INET\nmembers. Subsequent route lookups then call nexthop_fib6_nh() which\nreturns NULL for the AF_INET member, leading to a NULL pointer\ndereference.\n\nFix by calling nh_group_v4_update whenever the family changes, not just\nAF_INET to AF_INET6.\n\nReproducer:\n\t# AF_INET6 blackhole\n\tip -6 nexthop add id 1 blackhole\n\t# group with has_v4=false\n\tip nexthop add id 100 group 1\n\t# replace with AF_INET (no -6), has_v4 stays false\n\tip nexthop replace id 1 blackhole\n\t# pass stale has_v4 check\n\tip -6 route add 2001:db8::/64 nhid 100\n\t# panic\n\tping -6 2001:db8::1\n\n[1] https://syzkaller.appspot.com/bug?id=e17283eb2f8dcf3dd9b47fe6f67a95f71faadad0\n[2] https://syzkaller.appspot.com/bug?id=8699b6ae54c9f35837d925686208402949e12ef3",
            "updated_at": "2026-09-08T09:18:13.880",
            "published_at": "2026-06-24T17:17:12.433",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7bf4796dd09984ad1612877a82d0d139c70ae27f through before ceffe81a0be92afc0cd1340bc8ca46559cce9bb4 (git); 7bf4796dd09984ad1612877a82d0d139c70ae27f through before 9c2d6770a5f4545a307eb66979bef7656a34d621 (git); 7bf4796dd09984ad1612877a82d0d139c70ae27f through before 6275796f22bb382f3e9aa58ed0b4ef7bdad78cb8 (git); 7bf4796dd09984ad1612877a82d0d139c70ae27f through before aaac3bed034239e1d75732211d9b05f30b0b4f35 (git); 7bf4796dd09984ad1612877a82d0d139c70ae27f through before ad85961004fd4bd2f31209ac4b07612c6cefb9e7 (git); 7bf4796dd09984ad1612877a82d0d139c70ae27f through before 613c8f4a501421dd258b07ea614205d4e16ec845 (git); 7bf4796dd09984ad1612877a82d0d139c70ae27f through before b3b7e850e1541f0520c4a12ec884255c30427ff6 (git); 7bf4796dd09984ad1612877a82d0d139c70ae27f through before 29c95185ba32b621fbc3800fb86e7dc3edf5c2be (git); 5.3; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnexthop: fix IPv6 route referencing IPv4 nexthop\n\nsyzbot reported a panic [1] [2].\n\nWhen an IPv6 nexthop is replaced with an IPv4 nexthop, the has_v4 flag\nof all groups containing this nexthop is not updated. This is because\nnh_group_v4_update is only called when replacing AF_INET to AF_INET6,\nbut the reverse direction (AF_INET6 to AF_INET) is missed.\n\nThis allows a stale has_v4=false to bypass fib6_check_nexthop, causing\nIPv6 routes to be attached to groups that effectively contain only AF_INET\nmembers. Subsequent route lookups then call nexthop_fib6_nh() which\nreturns NULL for the AF_INET member, leading to a NULL pointer\ndereference.\n\nFix by calling nh_group_v4_update whenever the family changes, not just\nAF_INET to AF_INET6.\n\nReproducer:\n\t# AF_INET6 blackhole\n\tip -6 nexthop add id 1 blackhole\n\t# group with has_v4=false\n\tip nexthop add id 100 group 1\n\t# replace with AF_INET (no -6), has_v4 stays false\n\tip nexthop replace id 1 blackhole\n\t# pass stale has_v4 check\n\tip -6 route add 2001:db8::/64 nhid 100\n\t# panic\n\tping -6 2001:db8::1\n\n[1] https://syzkaller.appspot.com/bug?id=e17283eb2f8dcf3dd9b47fe6f67a95f71faadad0\n[2] https://syzkaller.appspot.com/bug?id=8699b6ae54c9f35837d925686208402949e12ef3",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/29c95185ba32b621fbc3800fb86e7dc3edf5c2be",
                "https://git.kernel.org/stable/c/613c8f4a501421dd258b07ea614205d4e16ec845",
                "https://git.kernel.org/stable/c/6275796f22bb382f3e9aa58ed0b4ef7bdad78cb8",
                "https://git.kernel.org/stable/c/9c2d6770a5f4545a307eb66979bef7656a34d621",
                "https://git.kernel.org/stable/c/aaac3bed034239e1d75732211d9b05f30b0b4f35",
                "https://git.kernel.org/stable/c/ad85961004fd4bd2f31209ac4b07612c6cefb9e7",
                "https://git.kernel.org/stable/c/b3b7e850e1541f0520c4a12ec884255c30427ff6",
                "https://git.kernel.org/stable/c/ceffe81a0be92afc0cd1340bc8ca46559cce9bb4",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:12.433",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53012"
                }
            ]
        },
        {
            "id": "CVE-2026-53006",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix possible UAF in icmpv6_rcv()\n\nCaching saddr and daddr before pskb_pull() is problematic\nsince skb->head can change.\n\nRemove these temporary variables:\n\n- We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr\n  when net_dbg_ratelimited() is called in the slow path.\n\n- Avoid potential future misuse after pskb_pull() call.",
            "updated_at": "2026-09-16T13:18:01.563",
            "published_at": "2026-06-24T17:17:11.750",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4b3418fba0fe819197e3359d5ddbef84ba2c59de through before 7bff2c8fe5c35ae58bf73104f53db3676e6e5d94 (git); 4b3418fba0fe819197e3359d5ddbef84ba2c59de through before aff0f28f5be803de2452ce702631c021fcd9ce8a (git); 4b3418fba0fe819197e3359d5ddbef84ba2c59de through before 38bdbc897c0d83a3e2b925a51b69420f1feba29a (git); 4b3418fba0fe819197e3359d5ddbef84ba2c59de through before 0069813e6ca9309eca78022bcb3aeb1e9ef90a12 (git); 4b3418fba0fe819197e3359d5ddbef84ba2c59de through before 1e1f0f89ee4692a64be3f3707ff8ac1ae57b03e7 (git); 4b3418fba0fe819197e3359d5ddbef84ba2c59de through before 7c66b368c6ff453f99cb39d84af93e908e51eef2 (git); 4b3418fba0fe819197e3359d5ddbef84ba2c59de through before 085e31a811ef234ef8c3e219c4636dfebfe7e10f (git); 4b3418fba0fe819197e3359d5ddbef84ba2c59de through before f996edd7615e686ada141b7f3395025729ff8ccb (git); 4.4; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 24,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix possible UAF in icmpv6_rcv()\n\nCaching saddr and daddr before pskb_pull() is problematic\nsince skb->head can change.\n\nRemove these temporary variables:\n\n- We only access &ipv6_hdr(skb)->saddr and &ipv6_hdr(skb)->daddr\n  when net_dbg_ratelimited() is called in the slow path.\n\n- Avoid potential future misuse after pskb_pull() call.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0069813e6ca9309eca78022bcb3aeb1e9ef90a12",
                "https://git.kernel.org/stable/c/085e31a811ef234ef8c3e219c4636dfebfe7e10f",
                "https://git.kernel.org/stable/c/1e1f0f89ee4692a64be3f3707ff8ac1ae57b03e7",
                "https://git.kernel.org/stable/c/38bdbc897c0d83a3e2b925a51b69420f1feba29a",
                "https://git.kernel.org/stable/c/7bff2c8fe5c35ae58bf73104f53db3676e6e5d94",
                "https://git.kernel.org/stable/c/7c66b368c6ff453f99cb39d84af93e908e51eef2",
                "https://git.kernel.org/stable/c/aff0f28f5be803de2452ce702631c021fcd9ce8a",
                "https://git.kernel.org/stable/c/f996edd7615e686ada141b7f3395025729ff8ccb",
                "https://access.redhat.com/errata/RHSA-2026:45192",
                "https://access.redhat.com/errata/RHSA-2026:47010",
                "https://access.redhat.com/errata/RHSA-2026:47011",
                "https://access.redhat.com/errata/RHSA-2026:47017",
                "https://access.redhat.com/errata/RHSA-2026:61932",
                "https://access.redhat.com/errata/RHSA-2026:62568",
                "https://access.redhat.com/security/cve/CVE-2026-53006",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492363",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53006.json",
                "https://access.redhat.com/errata/RHSA-2026:64767",
                "https://access.redhat.com/errata/RHSA-2026:65710",
                "https://access.redhat.com/errata/RHSA-2026:65711",
                "https://access.redhat.com/errata/RHSA-2026:65712",
                "https://access.redhat.com/errata/RHSA-2026:67721",
                "https://access.redhat.com/errata/RHSA-2026:67723"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:11.750",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53006"
                }
            ]
        },
        {
            "id": "CVE-2026-53002",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack: remove sprintf usage\n\nReplace it with scnprintf, the buffer sizes are expected to be large enough\nto hold the result, no need for snprintf+overflow check.\n\nIncrease buffer size in mangle_content_len() while at it.\n\nBUG: KASAN: stack-out-of-bounds in vsnprintf+0xea5/0x1270\nWrite of size 1 at addr [..]\n vsnprintf+0xea5/0x1270\n sprintf+0xb1/0xe0\n mangle_content_len+0x1ac/0x280\n nf_nat_sdp_session+0x1cc/0x240\n process_sdp+0x8f8/0xb80\n process_invite_request+0x108/0x2b0\n process_sip_msg+0x5da/0xf50\n sip_help_tcp+0x45e/0x780\n nf_confirm+0x34d/0x990\n [..]",
            "updated_at": "2026-09-08T09:18:13.327",
            "published_at": "2026-06-24T17:17:11.263",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9fafcd7b203229c3f3893a475741afc27e276306 through before 2f793ba78470a99f40389b7dc60a81d9f5ad3956 (git); 9fafcd7b203229c3f3893a475741afc27e276306 through before 6bbf829b4c1b44c941c47dd0d710f1393258f3d5 (git); 9fafcd7b203229c3f3893a475741afc27e276306 through before ab64e61c9323fa6de21bd20da1ddb29a0fb65d34 (git); 9fafcd7b203229c3f3893a475741afc27e276306 through before 1c9fb8aeed06790d42cdcd00f6c3ce0b9e926c1e (git); 9fafcd7b203229c3f3893a475741afc27e276306 through before a8e0a32a23d3f34862af3b4da792ecb3a891a9a3 (git); 9fafcd7b203229c3f3893a475741afc27e276306 through before 8e3be0d12615a173fe260cd42753ca7a001acbf2 (git); 9fafcd7b203229c3f3893a475741afc27e276306 through before c08ff52e44945e6ef4ce0790f49ea761b060c45b (git); 9fafcd7b203229c3f3893a475741afc27e276306 through before 6e7066bdb481a87fe88c4fa563e348c03b2d373d (git); 2.6.20; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack: remove sprintf usage\n\nReplace it with scnprintf, the buffer sizes are expected to be large enough\nto hold the result, no need for snprintf+overflow check.\n\nIncrease buffer size in mangle_content_len() while at it.\n\nBUG: KASAN: stack-out-of-bounds in vsnprintf+0xea5/0x1270\nWrite of size 1 at addr [..]\n vsnprintf+0xea5/0x1270\n sprintf+0xb1/0xe0\n mangle_content_len+0x1ac/0x280\n nf_nat_sdp_session+0x1cc/0x240\n process_sdp+0x8f8/0xb80\n process_invite_request+0x108/0x2b0\n process_sip_msg+0x5da/0xf50\n sip_help_tcp+0x45e/0x780\n nf_confirm+0x34d/0x990\n [..]",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1c9fb8aeed06790d42cdcd00f6c3ce0b9e926c1e",
                "https://git.kernel.org/stable/c/2f793ba78470a99f40389b7dc60a81d9f5ad3956",
                "https://git.kernel.org/stable/c/6bbf829b4c1b44c941c47dd0d710f1393258f3d5",
                "https://git.kernel.org/stable/c/6e7066bdb481a87fe88c4fa563e348c03b2d373d",
                "https://git.kernel.org/stable/c/8e3be0d12615a173fe260cd42753ca7a001acbf2",
                "https://git.kernel.org/stable/c/a8e0a32a23d3f34862af3b4da792ecb3a891a9a3",
                "https://git.kernel.org/stable/c/ab64e61c9323fa6de21bd20da1ddb29a0fb65d34",
                "https://git.kernel.org/stable/c/c08ff52e44945e6ef4ce0790f49ea761b060c45b",
                "https://access.redhat.com/security/cve/CVE-2026-53002",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492329",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53002.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:11.263",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53002"
                }
            ]
        },
        {
            "id": "CVE-2026-53001",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xtables: restrict several matches to inet family\n\nThis is a partial revert of:\n\n  commit ab4f21e6fb1c (\"netfilter: xtables: use NFPROTO_UNSPEC in more extensions\")\n\nto allow ipv4 and ipv6 only.\n\n- xt_mac\n- xt_owner\n- xt_physdev\n\nThese extensions are not used by ebtables in userspace.\n\nMoreover, xt_realm is only for ipv4, since dst->tclassid is ipv4\nspecific.",
            "updated_at": "2026-09-08T09:18:13.177",
            "published_at": "2026-06-24T17:17:11.143",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "ab4f21e6fb1c09b13c4c3cb8357babe8223471bd through before 14203f9edf944b3fb63faadd62f38452421ecdfc (git); ab4f21e6fb1c09b13c4c3cb8357babe8223471bd through before 7eaf9c740f33230cb224dc265f3c69f8531ff57b (git); ab4f21e6fb1c09b13c4c3cb8357babe8223471bd through before 9a109751b297b0f2135495749ef5a18ba31ec7d4 (git); ab4f21e6fb1c09b13c4c3cb8357babe8223471bd through before cbeb259f31382de70a70a59ffd0e66f5e80d9818 (git); ab4f21e6fb1c09b13c4c3cb8357babe8223471bd through before 689a91ff18d6448d94c1ab7c076fecdb2b668bef (git); ab4f21e6fb1c09b13c4c3cb8357babe8223471bd through before 76160e04440c9698b989dbd9492a7ec4f520c9ee (git); ab4f21e6fb1c09b13c4c3cb8357babe8223471bd through before fa88161ef56e29bdaa05cc89dbc4ee221e94bfe9 (git); ab4f21e6fb1c09b13c4c3cb8357babe8223471bd through before b6fe26f86a1649f84e057f3f15605b08eda15497 (git); 2.6.28; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xtables: restrict several matches to inet family\n\nThis is a partial revert of:\n\n  commit ab4f21e6fb1c (\"netfilter: xtables: use NFPROTO_UNSPEC in more extensions\")\n\nto allow ipv4 and ipv6 only.\n\n- xt_mac\n- xt_owner\n- xt_physdev\n\nThese extensions are not used by ebtables in userspace.\n\nMoreover, xt_realm is only for ipv4, since dst->tclassid is ipv4\nspecific.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/14203f9edf944b3fb63faadd62f38452421ecdfc",
                "https://git.kernel.org/stable/c/689a91ff18d6448d94c1ab7c076fecdb2b668bef",
                "https://git.kernel.org/stable/c/76160e04440c9698b989dbd9492a7ec4f520c9ee",
                "https://git.kernel.org/stable/c/7eaf9c740f33230cb224dc265f3c69f8531ff57b",
                "https://git.kernel.org/stable/c/9a109751b297b0f2135495749ef5a18ba31ec7d4",
                "https://git.kernel.org/stable/c/b6fe26f86a1649f84e057f3f15605b08eda15497",
                "https://git.kernel.org/stable/c/cbeb259f31382de70a70a59ffd0e66f5e80d9818",
                "https://git.kernel.org/stable/c/fa88161ef56e29bdaa05cc89dbc4ee221e94bfe9",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:11.143",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53001"
                }
            ]
        },
        {
            "id": "CVE-2026-53000",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nat: use kfree_rcu to release ops\n\nFlorian Westphal says:\n\n\"Historically this is not an issue, even for normal base hooks: the data\npath doesn't use the original nf_hook_ops that are used to register the\ncallbacks.\n\nHowever, in v5.14 I added the ability to dump the active netfilter\nhooks from userspace.\n\nThis code will peek back into the nf_hook_ops that are available\nat the tail of the pointer-array blob used by the datapath.\n\nThe nat hooks are special, because they are called indirectly from\nthe central nat dispatcher hook. They are currently invisible to\nthe nfnl hook dump subsystem though.\n\nBut once that changes the nat ops structures have to be deferred too.\"\n\nUpdate nf_nat_register_fn() to deal with partial exposition of the hooks\nfrom error path which can be also an issue for nfnetlink_hook.",
            "updated_at": "2026-09-16T13:18:01.290",
            "published_at": "2026-06-24T17:17:11.047",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "e2cf17d3774c323ef6dab6e9f7c0cfc5e742afd9 through before 32fdd2e38e7435a368d88f5977a7d6585ebc8b0e (git); e2cf17d3774c323ef6dab6e9f7c0cfc5e742afd9 through before 3c7511f38ab511b791196b13ae48bf4973bf7dfd (git); e2cf17d3774c323ef6dab6e9f7c0cfc5e742afd9 through before 6eda0d771f94267f73f57c94630aa47e90957915 (git); 5.14",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-763",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nat: use kfree_rcu to release ops\n\nFlorian Westphal says:\n\n\"Historically this is not an issue, even for normal base hooks: the data\npath doesn't use the original nf_hook_ops that are used to register the\ncallbacks.\n\nHowever, in v5.14 I added the ability to dump the active netfilter\nhooks from userspace.\n\nThis code will peek back into the nf_hook_ops that are available\nat the tail of the pointer-array blob used by the datapath.\n\nThe nat hooks are special, because they are called indirectly from\nthe central nat dispatcher hook. They are currently invisible to\nthe nfnl hook dump subsystem though.\n\nBut once that changes the nat ops structures have to be deferred too.\"\n\nUpdate nf_nat_register_fn() to deal with partial exposition of the hooks\nfrom error path which can be also an issue for nfnetlink_hook.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/32fdd2e38e7435a368d88f5977a7d6585ebc8b0e",
                "https://git.kernel.org/stable/c/3c7511f38ab511b791196b13ae48bf4973bf7dfd",
                "https://git.kernel.org/stable/c/6eda0d771f94267f73f57c94630aa47e90957915",
                "https://access.redhat.com/errata/RHSA-2026:55445",
                "https://access.redhat.com/errata/RHSA-2026:64808",
                "https://access.redhat.com/errata/RHSA-2026:67720",
                "https://access.redhat.com/security/cve/CVE-2026-53000",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492273",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53000.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:11.047",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53000"
                }
            ]
        },
        {
            "id": "CVE-2026-52999",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_osf: fix out-of-bounds read on option matching\n\nIn nf_osf_match(), the nf_osf_hdr_ctx structure is initialized once\nand passed by reference to nf_osf_match_one() for each fingerprint\nchecked. During TCP option parsing, nf_osf_match_one() advances the\nshared ctx->optp pointer.\n\nIf a fingerprint perfectly matches, the function returns early without\nrestoring ctx->optp to its initial state. If the user has configured\nNF_OSF_LOGLEVEL_ALL, the loop continues to the next fingerprint.\nHowever, because ctx->optp was not restored, the next call to\nnf_osf_match_one() starts parsing from the end of the options buffer.\nThis causes subsequent matches to read garbage data and fail\nimmediately, making it impossible to log more than one match or logging\nincorrect matches.\n\nInstead of using a shared ctx->optp pointer, pass the context as a\nconstant pointer and use a local pointer (optp) for TCP option\ntraversal. This makes nf_osf_match_one() strictly stateless from the\ncaller's perspective, ensuring every fingerprint check starts at the\ncorrect option offset.",
            "updated_at": "2026-09-08T09:18:12.990",
            "published_at": "2026-06-24T17:17:10.913",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1a6a0951fc009f6d9fe8ebea2d2417d80d54097b through before 0145548346c4a30981a870a8ca00eac46ba27e85 (git); 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b through before 1c136f2c44a5913646bac85303612fd0825197a0 (git); 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b through before 1e19a07291bb8682c14c39a64725a3ae54ab8ccc (git); 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b through before 32e50f92c7cf3f4eba29622179a5fcdc2aebab41 (git); 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b through before 70a3f31d25cf2ec9d4ddfa408120171ead955623 (git); 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b through before 21883587593d7c8bb519a79460a0b5bc5ffbdabd (git); 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b through before edb78a142d2e5948e63647c0646aa7e7886935f0 (git); 1a6a0951fc009f6d9fe8ebea2d2417d80d54097b through before f5ca450087c3baf3651055e7a6de92600f827af3 (git); 0c1054e0e5fdef2369fb089e94def978bd209e1f (git); 8316b60582facd4068fb0916c4db2418c21b7174 (git); 4.19.26 through before 4.20 (semver); 4.20.13 through before 4.21 (semver); 5.0; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_osf: fix out-of-bounds read on option matching\n\nIn nf_osf_match(), the nf_osf_hdr_ctx structure is initialized once\nand passed by reference to nf_osf_match_one() for each fingerprint\nchecked. During TCP option parsing, nf_osf_match_one() advances the\nshared ctx->optp pointer.\n\nIf a fingerprint perfectly matches, the function returns early without\nrestoring ctx->optp to its initial state. If the user has configured\nNF_OSF_LOGLEVEL_ALL, the loop continues to the next fingerprint.\nHowever, because ctx->optp was not restored, the next call to\nnf_osf_match_one() starts parsing from the end of the options buffer.\nThis causes subsequent matches to read garbage data and fail\nimmediately, making it impossible to log more than one match or logging\nincorrect matches.\n\nInstead of using a shared ctx->optp pointer, pass the context as a\nconstant pointer and use a local pointer (optp) for TCP option\ntraversal. This makes nf_osf_match_one() strictly stateless from the\ncaller's perspective, ensuring every fingerprint check starts at the\ncorrect option offset.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0145548346c4a30981a870a8ca00eac46ba27e85",
                "https://git.kernel.org/stable/c/1c136f2c44a5913646bac85303612fd0825197a0",
                "https://git.kernel.org/stable/c/1e19a07291bb8682c14c39a64725a3ae54ab8ccc",
                "https://git.kernel.org/stable/c/21883587593d7c8bb519a79460a0b5bc5ffbdabd",
                "https://git.kernel.org/stable/c/32e50f92c7cf3f4eba29622179a5fcdc2aebab41",
                "https://git.kernel.org/stable/c/70a3f31d25cf2ec9d4ddfa408120171ead955623",
                "https://git.kernel.org/stable/c/edb78a142d2e5948e63647c0646aa7e7886935f0",
                "https://git.kernel.org/stable/c/f5ca450087c3baf3651055e7a6de92600f827af3",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:10.913",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52999"
                }
            ]
        },
        {
            "id": "CVE-2026-52998",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_osf: fix potential NULL dereference in ttl check\n\nThe nf_osf_ttl() function accessed skb->dev to perform a local interface\naddress lookup without verifying that the device pointer was valid.\n\nAdditionally, the implementation utilized an in_dev_for_each_ifa_rcu\nloop to match the packet source address against local interface\naddresses. It assumed that packets from the same subnet should not see a\ndecrement on the initial TTL. A packet might appear it is from the same\nsubnet but it actually isn't especially in modern environments with\ncontainers and virtual switching.\n\nRemove the device dereference and interface loop. Replace the logic with\na switch statement that evaluates the TTL according to the ttl_check.",
            "updated_at": "2026-09-08T09:18:12.810",
            "published_at": "2026-06-24T17:17:10.777",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before f4de0777e4554a7de19c920accde6319dd530782 (git); 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before c996a90f3071cf43683e5423da31aadbe002b8b4 (git); 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before edc806f9122961f0d3819f7c69c14cccde31f277 (git); 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before 5d05de2f0928d81309a815ecc76d1a3ad72cbc16 (git); 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before 95be653a76793856ff8b2d8bd82c2943c23f5ca8 (git); 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before 79b90a96688e521771fa6ed3dc7864b76b8df293 (git); 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before 83fc5dd63455a779ea2dd0f7ffee3c920919d80b (git); 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before 711987ba281fd806322a7cd244e98e2a81903114 (git); 2.6.31; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_osf: fix potential NULL dereference in ttl check\n\nThe nf_osf_ttl() function accessed skb->dev to perform a local interface\naddress lookup without verifying that the device pointer was valid.\n\nAdditionally, the implementation utilized an in_dev_for_each_ifa_rcu\nloop to match the packet source address against local interface\naddresses. It assumed that packets from the same subnet should not see a\ndecrement on the initial TTL. A packet might appear it is from the same\nsubnet but it actually isn't especially in modern environments with\ncontainers and virtual switching.\n\nRemove the device dereference and interface loop. Replace the logic with\na switch statement that evaluates the TTL according to the ttl_check.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/5d05de2f0928d81309a815ecc76d1a3ad72cbc16",
                "https://git.kernel.org/stable/c/711987ba281fd806322a7cd244e98e2a81903114",
                "https://git.kernel.org/stable/c/79b90a96688e521771fa6ed3dc7864b76b8df293",
                "https://git.kernel.org/stable/c/83fc5dd63455a779ea2dd0f7ffee3c920919d80b",
                "https://git.kernel.org/stable/c/95be653a76793856ff8b2d8bd82c2943c23f5ca8",
                "https://git.kernel.org/stable/c/c996a90f3071cf43683e5423da31aadbe002b8b4",
                "https://git.kernel.org/stable/c/edc806f9122961f0d3819f7c69c14cccde31f277",
                "https://git.kernel.org/stable/c/f4de0777e4554a7de19c920accde6319dd530782",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:10.777",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52998"
                }
            ]
        },
        {
            "id": "CVE-2026-52986",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_sip: don't use simple_strtoul\n\nReplace unsafe port parsing in epaddr_len(), ct_sip_parse_header_uri(),\nand ct_sip_parse_request() with a new sip_parse_port() helper that\nvalidates each digit against the buffer limit, eliminating the use of\nsimple_strtoul() which assumes NUL-terminated strings.\n\nThe previous code dereferenced pointers without bounds checks after\nsip_parse_addr() and relied on simple_strtoul() on non-NUL-terminated\nskb data. A port that reaches the buffer limit without a trailing\ncharacter is also rejected as malformed.\n\nAlso get rid of all simple_strtoul() usage in conntrack, prefer a\nstricter version instead.  There are intentional changes:\n\n- Bail out if number is > UINT_MAX and indicate a failure, same for\n  too long sequences.\n  While we do accept 05535 as port 5535, we will not accept e.g.\n  'sip:10.0.0.1:005060'.  While its syntactically valid under RFC 3261,\n  we should restrict this to not waste cycles when presented with\n  malformed packets with 64k '0' characters.\n\n- Force base 10 in ct_sip_parse_numerical_param(). This is used to fetch\n  'expire=' and 'rports='; both are expected to use base-10.\n\n- In nf_nat_sip.c, only accept the parsed value if its within the 1k-64k\n  range.\n\n- epaddr_len now returns 0 if the port is invalid, as it already does\n  for invalid ip addresses.  This is intentional. nf_conntrack_sip\n  performs lots of guesswork to find the right parts of the message\n  to parse.  Being stricter could break existing setups.\n  Connection tracking helpers are designed to allow traffic to\n  pass, not to block it.\n\nBased on an earlier patch from Jenny Guanni Qu <qguanni@gmail.com>.",
            "updated_at": "2026-09-08T09:18:12.620",
            "published_at": "2026-06-24T17:17:09.383",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "05e3ced297fe755093140e7487e292fb7603316e through before 8cd0358379570003659186706e077929d6930c40 (git); 05e3ced297fe755093140e7487e292fb7603316e through before 9c6afcb1c3cbb2c0da65b8515ac14d7273872f84 (git); 05e3ced297fe755093140e7487e292fb7603316e through before b3264c977e79d8a25778d4fd11520f00fea1329c (git); 05e3ced297fe755093140e7487e292fb7603316e through before ea2ecd29b8f4433e52607192ca91084f95787ca0 (git); 05e3ced297fe755093140e7487e292fb7603316e through before 9f69c323ae0ab517e595c2cc74e0ae0d9d085611 (git); 05e3ced297fe755093140e7487e292fb7603316e through before 7df9863bf538a626e8a684e59cb2c43eac0ef3c8 (git); 05e3ced297fe755093140e7487e292fb7603316e through before 523762e3b6933fff81f01dfa3c60c0774044cdab (git); 05e3ced297fe755093140e7487e292fb7603316e through before 8cf6809cddcbe301aedfc6b51bcd4944d45795f6 (git); 2.6.26; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack_sip: don't use simple_strtoul\n\nReplace unsafe port parsing in epaddr_len(), ct_sip_parse_header_uri(),\nand ct_sip_parse_request() with a new sip_parse_port() helper that\nvalidates each digit against the buffer limit, eliminating the use of\nsimple_strtoul() which assumes NUL-terminated strings.\n\nThe previous code dereferenced pointers without bounds checks after\nsip_parse_addr() and relied on simple_strtoul() on non-NUL-terminated\nskb data. A port that reaches the buffer limit without a trailing\ncharacter is also rejected as malformed.\n\nAlso get rid of all simple_strtoul() usage in conntrack, prefer a\nstricter version instead.  There are intentional changes:\n\n- Bail out if number is > UINT_MAX and indicate a failure, same for\n  too long sequences.\n  While we do accept 05535 as port 5535, we will not accept e.g.\n  'sip:10.0.0.1:005060'.  While its syntactically valid under RFC 3261,\n  we should restrict this to not waste cycles when presented with\n  malformed packets with 64k '0' characters.\n\n- Force base 10 in ct_sip_parse_numerical_param(). This is used to fetch\n  'expire=' and 'rports='; both are expected to use base-10.\n\n- In nf_nat_sip.c, only accept the parsed value if its within the 1k-64k\n  range.\n\n- epaddr_len now returns 0 if the port is invalid, as it already does\n  for invalid ip addresses.  This is intentional. nf_conntrack_sip\n  performs lots of guesswork to find the right parts of the message\n  to parse.  Being stricter could break existing setups.\n  Connection tracking helpers are designed to allow traffic to\n  pass, not to block it.\n\nBased on an earlier patch from Jenny Guanni Qu <qguanni@gmail.com>.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/523762e3b6933fff81f01dfa3c60c0774044cdab",
                "https://git.kernel.org/stable/c/7df9863bf538a626e8a684e59cb2c43eac0ef3c8",
                "https://git.kernel.org/stable/c/8cd0358379570003659186706e077929d6930c40",
                "https://git.kernel.org/stable/c/8cf6809cddcbe301aedfc6b51bcd4944d45795f6",
                "https://git.kernel.org/stable/c/9c6afcb1c3cbb2c0da65b8515ac14d7273872f84",
                "https://git.kernel.org/stable/c/9f69c323ae0ab517e595c2cc74e0ae0d9d085611",
                "https://git.kernel.org/stable/c/b3264c977e79d8a25778d4fd11520f00fea1329c",
                "https://git.kernel.org/stable/c/ea2ecd29b8f4433e52607192ca91084f95787ca0",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:09.383",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52986"
                }
            ]
        },
        {
            "id": "CVE-2026-52970",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_ct: fix missing expect put in obj eval\n\nnft_ct_expect_obj_eval() allocates an expectation and may call\nnf_ct_expect_related(), but never drops its local reference.\n\nAdd nf_ct_expect_put(exp) before return to balance allocation.",
            "updated_at": "2026-09-08T09:18:12.460",
            "published_at": "2026-06-24T17:17:07.500",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "857b46027d6f91150797295752581b7155b9d0e1 through before cdb9a25dd3416d427e8b2753210f8baf44207577 (git); 857b46027d6f91150797295752581b7155b9d0e1 through before 26ab32ec73941871c97562ee1f39587950dc3b68 (git); 857b46027d6f91150797295752581b7155b9d0e1 through before 7b96242ceedfe249f158419f3254bcee04173ffe (git); 857b46027d6f91150797295752581b7155b9d0e1 through before ecca618e1e339494911090474ed87742c0f73976 (git); 857b46027d6f91150797295752581b7155b9d0e1 through before 2aef1b13d5c0285f340512c6c07eb858fd018fd8 (git); 857b46027d6f91150797295752581b7155b9d0e1 through before 1dced0725e2fae3ac3416274db20a7ff5a46931d (git); 857b46027d6f91150797295752581b7155b9d0e1 through before 84c422cea5a45fe56be839f25880f21fd33940cd (git); 857b46027d6f91150797295752581b7155b9d0e1 through before 19f94b6fee75b3ef7fbc06f3745b9a771a8a19a4 (git); 5.3; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_ct: fix missing expect put in obj eval\n\nnft_ct_expect_obj_eval() allocates an expectation and may call\nnf_ct_expect_related(), but never drops its local reference.\n\nAdd nf_ct_expect_put(exp) before return to balance allocation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/19f94b6fee75b3ef7fbc06f3745b9a771a8a19a4",
                "https://git.kernel.org/stable/c/1dced0725e2fae3ac3416274db20a7ff5a46931d",
                "https://git.kernel.org/stable/c/26ab32ec73941871c97562ee1f39587950dc3b68",
                "https://git.kernel.org/stable/c/2aef1b13d5c0285f340512c6c07eb858fd018fd8",
                "https://git.kernel.org/stable/c/7b96242ceedfe249f158419f3254bcee04173ffe",
                "https://git.kernel.org/stable/c/84c422cea5a45fe56be839f25880f21fd33940cd",
                "https://git.kernel.org/stable/c/cdb9a25dd3416d427e8b2753210f8baf44207577",
                "https://git.kernel.org/stable/c/ecca618e1e339494911090474ed87742c0f73976",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:07.500",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52970"
                }
            ]
        },
        {
            "id": "CVE-2026-52946",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling\n\nA SOFTIRQ-safe to SOFTIRQ-unsafe lock order deadlock can occur in\nsend_sigio() and send_sigurg() when a process group receives a signal.\n\nWhen FASYNC is configured for a process group (PIDTYPE_PGID), both\nfunctions use read_lock(&tasklist_lock) to traverse the task list.\nHowever, they are frequently called from softirq context:\n- send_sigio() via input_inject_event -> kill_fasync\n- send_sigurg() via tcp_check_urg -> sk_send_sigurg (NET_RX_SOFTIRQ)\n\nThe deadlock is caused by the rwlock writer fairness mechanism:\n1. CPU 0 (process context) holds read_lock(&tasklist_lock) in do_wait().\n2. CPU 1 (process context) attempts write_lock(&tasklist_lock) in\n   fork() or exit() and spins, which blocks all new readers.\n3. CPU 0 is interrupted by a softirq (e.g., TCP URG packet reception).\n4. The softirq calls send_sigurg() and attempts to acquire\n   read_lock(&tasklist_lock), deadlocking because CPU 1 is waiting.\n\nSince PID hashing and do_each_pid_task() traversals are already\nRCU-protected, the read_lock on tasklist_lock is no longer strictly\nrequired for safe traversal. Fix this by replacing tasklist_lock with\nrcu_read_lock(), aligning the process group signaling path with the\nsingle-PID path. This also mitigates a potential remote denial of\nservice vector via TCP URG packets.\n\nLockdep splat:\n=====================================================\nWARNING: SOFTIRQ-safe -> SOFTIRQ-unsafe lock order detected\n[...]\nChain exists of:\n  &dev->event_lock --> &f_owner->lock --> tasklist_lock\n\nPossible interrupt unsafe locking scenario:\n       CPU0                    CPU1\n       ----                    ----\n  lock(tasklist_lock);\n                           local_irq_disable();\n                           lock(&dev->event_lock);\n                           lock(&f_owner->lock);\n  <Interrupt>\n    lock(&dev->event_lock);\n\n*** DEADLOCK ***",
            "updated_at": "2026-09-08T09:18:12.257",
            "published_at": "2026-06-24T17:17:04.610",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 54626335ea4174ab2d9a183b511d825f6765e47b (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 897d6a7247739fb1528f98c575df4f2e5de7f994 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 32dbd5ce4be3a3ed7e00f8af18795cc84fc50a33 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before b5fa9e32fb6718f70c986ee14dd5d01b4846f331 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 1bee417678f1135e35b25a37734db46aa94258d2 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 20a93e397abe850c49b6fa0e8cc827b5f634a8f5 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before bfcc8e8d8a495bb34cae9e620adfb75fb13a3954 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 36c1b57b2ecf3c61ac93f5f07bd29b6f21e226ed (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 00633c4683828acd5256fa8d5163f440d74bbe71 (git); 2.6.12; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-667",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling\n\nA SOFTIRQ-safe to SOFTIRQ-unsafe lock order deadlock can occur in\nsend_sigio() and send_sigurg() when a process group receives a signal.\n\nWhen FASYNC is configured for a process group (PIDTYPE_PGID), both\nfunctions use read_lock(&tasklist_lock) to traverse the task list.\nHowever, they are frequently called from softirq context:\n- send_sigio() via input_inject_event -> kill_fasync\n- send_sigurg() via tcp_check_urg -> sk_send_sigurg (NET_RX_SOFTIRQ)\n\nThe deadlock is caused by the rwlock writer fairness mechanism:\n1. CPU 0 (process context) holds read_lock(&tasklist_lock) in do_wait().\n2. CPU 1 (process context) attempts write_lock(&tasklist_lock) in\n   fork() or exit() and spins, which blocks all new readers.\n3. CPU 0 is interrupted by a softirq (e.g., TCP URG packet reception).\n4. The softirq calls send_sigurg() and attempts to acquire\n   read_lock(&tasklist_lock), deadlocking because CPU 1 is waiting.\n\nSince PID hashing and do_each_pid_task() traversals are already\nRCU-protected, the read_lock on tasklist_lock is no longer strictly\nrequired for safe traversal. Fix this by replacing tasklist_lock with\nrcu_read_lock(), aligning the process group signaling path with the\nsingle-PID path. This also mitigates a potential remote denial of\nservice vector via TCP URG packets.\n\nLockdep splat:\n=====================================================\nWARNING: SOFTIRQ-safe -> SOFTIRQ-unsafe lock order detected\n[...]\nChain exists of:\n  &dev->event_lock --> &f_owner->lock --> tasklist_lock\n\nPossible interrupt unsafe locking scenario:\n       CPU0                    CPU1\n       ----                    ----\n  lock(tasklist_lock);\n                           local_irq_disable();\n                           lock(&dev->event_lock);\n                           lock(&f_owner->lock);\n  <Interrupt>\n    lock(&dev->event_lock);\n\n*** DEADLOCK ***",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/00633c4683828acd5256fa8d5163f440d74bbe71",
                "https://git.kernel.org/stable/c/1bee417678f1135e35b25a37734db46aa94258d2",
                "https://git.kernel.org/stable/c/20a93e397abe850c49b6fa0e8cc827b5f634a8f5",
                "https://git.kernel.org/stable/c/32dbd5ce4be3a3ed7e00f8af18795cc84fc50a33",
                "https://git.kernel.org/stable/c/36c1b57b2ecf3c61ac93f5f07bd29b6f21e226ed",
                "https://git.kernel.org/stable/c/54626335ea4174ab2d9a183b511d825f6765e47b",
                "https://git.kernel.org/stable/c/897d6a7247739fb1528f98c575df4f2e5de7f994",
                "https://git.kernel.org/stable/c/b5fa9e32fb6718f70c986ee14dd5d01b4846f331",
                "https://git.kernel.org/stable/c/bfcc8e8d8a495bb34cae9e620adfb75fb13a3954",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T17:17:04.610",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52946"
                }
            ]
        },
        {
            "id": "CVE-2026-52943",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: fix missing zerocopy reference in pskb_carve helpers\n\npskb_carve_inside_header() and pskb_carve_inside_nonlinear() both copy\nthe old skb_shared_info header into a new buffer via memcpy(), which\nincludes the destructor_arg pointer (uarg) for MSG_ZEROCOPY skbs.\nNeither function calls net_zcopy_get() for the new shinfo, creating an\nunaccounted holder: every skb_shared_info with destructor_arg set will\ncall skb_zcopy_clear() once when freed, but the corresponding\nnet_zcopy_get() was never called for the new copy. Repeated calls\ndrive uarg->refcnt to zero prematurely, freeing ubuf_info_msgzc while\nTX skbs still hold live destructor_arg pointers.\n\nKASAN reports use-after-free on a freed ubuf_info_msgzc:\n\n  BUG: KASAN: slab-use-after-free in skb_release_data+0x77b/0x810\n  Read of size 8 at addr ffff88801574d3e8 by task poc/220\n\n  Call Trace:\n   skb_release_data+0x77b/0x810\n   kfree_skb_list_reason+0x13e/0x610\n   skb_release_data+0x4cd/0x810\n   sk_skb_reason_drop+0xf3/0x340\n   skb_queue_purge_reason+0x282/0x440\n   rds_tcp_inc_free+0x1e/0x30\n   rds_recvmsg+0x354/0x1780\n   __sys_recvmsg+0xdf/0x180\n\n  Allocated by task 219:\n   msg_zerocopy_realloc+0x157/0x7b0\n   tcp_sendmsg_locked+0x2892/0x3ba0\n\n  Freed by task 219:\n   ip_recv_error+0x74a/0xb10\n   tcp_recvmsg+0x475/0x530\n\nThe skb consuming the late access still referenced the same uarg via\nshinfo->destructor_arg copied by pskb_carve_inside_nonlinear() without\na refcount bump. This has been verified to be reliably exploitable: a\nworking proof-of-concept achieves full root privilege escalation from\nan unprivileged local user on a default kernel configuration.\n\nThe fix follows the pattern of pskb_expand_head() which has the same\nmemcpy/cloned structure. For pskb_carve_inside_header(), net_zcopy_get()\nis placed after skb_orphan_frags() succeeds, so the orphan error path\nneeds no cleanup. For pskb_carve_inside_nonlinear(), net_zcopy_get() is\nplaced after all failure points and just before skb_release_data(), so\nno error path needs cleanup at all -- matching pskb_expand_head() more\nclosely and avoiding the need for a balancing net_zcopy_put().",
            "updated_at": "2026-09-08T09:18:11.903",
            "published_at": "2026-06-24T10:17:19.293",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6fa01ccd883021105e9f8af7d04b9f156fa3494a through before 8dbed691e43a50903658130bde0fcb5abc425b37 (git); 6fa01ccd883021105e9f8af7d04b9f156fa3494a through before 9b40bdc2a3298225dffab8158208a0d8c6300578 (git); 6fa01ccd883021105e9f8af7d04b9f156fa3494a through before fd470f0a97b8e9a125f520265d2f3b088ffb5b8a (git); 6fa01ccd883021105e9f8af7d04b9f156fa3494a through before ceafb893b12f23331dcc5ff9587e643c3a40ee9f (git); 6fa01ccd883021105e9f8af7d04b9f156fa3494a through before 2e0e74c59b2761a414d9f48d7bee1e45220b2427 (git); 6fa01ccd883021105e9f8af7d04b9f156fa3494a through before 96a4713ae041cc85e712bac682cd2e644004d6c6 (git); 6fa01ccd883021105e9f8af7d04b9f156fa3494a through before 474d6c771d798bca84f0a140b611e36743511e18 (git); 6fa01ccd883021105e9f8af7d04b9f156fa3494a through before 98d0912e9f841e5529a5b89a972805f34cb1c69d (git); 4.7; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: fix missing zerocopy reference in pskb_carve helpers\n\npskb_carve_inside_header() and pskb_carve_inside_nonlinear() both copy\nthe old skb_shared_info header into a new buffer via memcpy(), which\nincludes the destructor_arg pointer (uarg) for MSG_ZEROCOPY skbs.\nNeither function calls net_zcopy_get() for the new shinfo, creating an\nunaccounted holder: every skb_shared_info with destructor_arg set will\ncall skb_zcopy_clear() once when freed, but the corresponding\nnet_zcopy_get() was never called for the new copy. Repeated calls\ndrive uarg->refcnt to zero prematurely, freeing ubuf_info_msgzc while\nTX skbs still hold live destructor_arg pointers.\n\nKASAN reports use-after-free on a freed ubuf_info_msgzc:\n\n  BUG: KASAN: slab-use-after-free in skb_release_data+0x77b/0x810\n  Read of size 8 at addr ffff88801574d3e8 by task poc/220\n\n  Call Trace:\n   skb_release_data+0x77b/0x810\n   kfree_skb_list_reason+0x13e/0x610\n   skb_release_data+0x4cd/0x810\n   sk_skb_reason_drop+0xf3/0x340\n   skb_queue_purge_reason+0x282/0x440\n   rds_tcp_inc_free+0x1e/0x30\n   rds_recvmsg+0x354/0x1780\n   __sys_recvmsg+0xdf/0x180\n\n  Allocated by task 219:\n   msg_zerocopy_realloc+0x157/0x7b0\n   tcp_sendmsg_locked+0x2892/0x3ba0\n\n  Freed by task 219:\n   ip_recv_error+0x74a/0xb10\n   tcp_recvmsg+0x475/0x530\n\nThe skb consuming the late access still referenced the same uarg via\nshinfo->destructor_arg copied by pskb_carve_inside_nonlinear() without\na refcount bump. This has been verified to be reliably exploitable: a\nworking proof-of-concept achieves full root privilege escalation from\nan unprivileged local user on a default kernel configuration.\n\nThe fix follows the pattern of pskb_expand_head() which has the same\nmemcpy/cloned structure. For pskb_carve_inside_header(), net_zcopy_get()\nis placed after skb_orphan_frags() succeeds, so the orphan error path\nneeds no cleanup. For pskb_carve_inside_nonlinear(), net_zcopy_get() is\nplaced after all failure points and just before skb_release_data(), so\nno error path needs cleanup at all -- matching pskb_expand_head() more\nclosely and avoiding the need for a balancing net_zcopy_put().",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2e0e74c59b2761a414d9f48d7bee1e45220b2427",
                "https://git.kernel.org/stable/c/474d6c771d798bca84f0a140b611e36743511e18",
                "https://git.kernel.org/stable/c/8dbed691e43a50903658130bde0fcb5abc425b37",
                "https://git.kernel.org/stable/c/96a4713ae041cc85e712bac682cd2e644004d6c6",
                "https://git.kernel.org/stable/c/98d0912e9f841e5529a5b89a972805f34cb1c69d",
                "https://git.kernel.org/stable/c/9b40bdc2a3298225dffab8158208a0d8c6300578",
                "https://git.kernel.org/stable/c/ceafb893b12f23331dcc5ff9587e643c3a40ee9f",
                "https://git.kernel.org/stable/c/fd470f0a97b8e9a125f520265d2f3b088ffb5b8a",
                "https://access.redhat.com/security/cve/CVE-2026-52943",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492137",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52943.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T10:17:19.293",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52943"
                }
            ]
        },
        {
            "id": "CVE-2026-52942",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_log: validate MAC header was set before dumping it\n\nThe fallback path of dump_mac_header() guards the MAC header access\nonly with \"skb->mac_header != skb->network_header\", without checking\nskb_mac_header_was_set(). When the MAC header is unset, mac_header is\n0xffff, so the test passes and skb_mac_header(skb) returns\nskb->head + 0xffff, ~64 KiB past the buffer; the loop then reads\ndev->hard_header_len bytes out of bounds into the kernel log.\n\nThis is reachable via the netdev logger: nf_log_unknown_packet() calls\ndump_mac_header() unconditionally, and an skb sent through AF_PACKET\nwith PACKET_QDISC_BYPASS reaches the egress hook with mac_header still\nunset (__dev_queue_xmit(), which would reset it, is bypassed).\n\nAdd the skb_mac_header_was_set() check the ARPHRD_ETHER path already\nuses, and replace the open-coded MAC header length test with\nskb_mac_header_len(). Only skbs with an unset MAC header are affected;\nvalid ones are dumped as before.\n\n BUG: KASAN: slab-out-of-bounds in dump_mac_header (net/netfilter/nf_log_syslog.c:831)\n Read of size 1 at addr ffff88800ea49d3f by task exploit/148\n Call Trace:\n  kasan_report (mm/kasan/report.c:595)\n  dump_mac_header (net/netfilter/nf_log_syslog.c:831)\n  nf_log_netdev_packet (net/netfilter/nf_log_syslog.c:938 net/netfilter/nf_log_syslog.c:963)\n  nf_log_packet (net/netfilter/nf_log.c:260)\n  nft_log_eval (net/netfilter/nft_log.c:60)\n  nft_do_chain (net/netfilter/nf_tables_core.c:285)\n  nft_do_chain_netdev (net/netfilter/nft_chain_filter.c:307)\n  nf_hook_slow (net/netfilter/core.c:619)\n  nf_hook_direct_egress (net/packet/af_packet.c:257)\n  packet_xmit (net/packet/af_packet.c:280)\n  packet_sendmsg (net/packet/af_packet.c:3114)\n  __sys_sendto (net/socket.c:2265)",
            "updated_at": "2026-09-08T09:18:11.710",
            "published_at": "2026-06-24T08:16:24.490",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7eb9282cd0efac08b8377cbd5037ba297c77e3f7 through before 2e96e1bc9b4d5450e6c33f078e19a9bc1dda6c0b (git); 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 through before d704ee9c7bc68a161684c51a7ac05b446dcf38d4 (git); 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 through before befb8968a2abdfa948d5600ea7f7a509a292a590 (git); 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 through before 8a81e336da685423f5b64aac4d571e63d674c52a (git); 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 through before c38d41134085193efd5b237cf513ad5b3421a60d (git); 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 through before af1b7699466f6556b351fa25d3dc870abfb5d310 (git); 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 through before 65ef7397eb9a296e91839f5fd10be96f23d332e7 (git); 7eb9282cd0efac08b8377cbd5037ba297c77e3f7 through before a84b6fedbc97078788be78dbdd7517d143ad1a77 (git); 2.6.36; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_log: validate MAC header was set before dumping it\n\nThe fallback path of dump_mac_header() guards the MAC header access\nonly with \"skb->mac_header != skb->network_header\", without checking\nskb_mac_header_was_set(). When the MAC header is unset, mac_header is\n0xffff, so the test passes and skb_mac_header(skb) returns\nskb->head + 0xffff, ~64 KiB past the buffer; the loop then reads\ndev->hard_header_len bytes out of bounds into the kernel log.\n\nThis is reachable via the netdev logger: nf_log_unknown_packet() calls\ndump_mac_header() unconditionally, and an skb sent through AF_PACKET\nwith PACKET_QDISC_BYPASS reaches the egress hook with mac_header still\nunset (__dev_queue_xmit(), which would reset it, is bypassed).\n\nAdd the skb_mac_header_was_set() check the ARPHRD_ETHER path already\nuses, and replace the open-coded MAC header length test with\nskb_mac_header_len(). Only skbs with an unset MAC header are affected;\nvalid ones are dumped as before.\n\n BUG: KASAN: slab-out-of-bounds in dump_mac_header (net/netfilter/nf_log_syslog.c:831)\n Read of size 1 at addr ffff88800ea49d3f by task exploit/148\n Call Trace:\n  kasan_report (mm/kasan/report.c:595)\n  dump_mac_header (net/netfilter/nf_log_syslog.c:831)\n  nf_log_netdev_packet (net/netfilter/nf_log_syslog.c:938 net/netfilter/nf_log_syslog.c:963)\n  nf_log_packet (net/netfilter/nf_log.c:260)\n  nft_log_eval (net/netfilter/nft_log.c:60)\n  nft_do_chain (net/netfilter/nf_tables_core.c:285)\n  nft_do_chain_netdev (net/netfilter/nft_chain_filter.c:307)\n  nf_hook_slow (net/netfilter/core.c:619)\n  nf_hook_direct_egress (net/packet/af_packet.c:257)\n  packet_xmit (net/packet/af_packet.c:280)\n  packet_sendmsg (net/packet/af_packet.c:3114)\n  __sys_sendto (net/socket.c:2265)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2e96e1bc9b4d5450e6c33f078e19a9bc1dda6c0b",
                "https://git.kernel.org/stable/c/65ef7397eb9a296e91839f5fd10be96f23d332e7",
                "https://git.kernel.org/stable/c/8a81e336da685423f5b64aac4d571e63d674c52a",
                "https://git.kernel.org/stable/c/a84b6fedbc97078788be78dbdd7517d143ad1a77",
                "https://git.kernel.org/stable/c/af1b7699466f6556b351fa25d3dc870abfb5d310",
                "https://git.kernel.org/stable/c/befb8968a2abdfa948d5600ea7f7a509a292a590",
                "https://git.kernel.org/stable/c/c38d41134085193efd5b237cf513ad5b3421a60d",
                "https://git.kernel.org/stable/c/d704ee9c7bc68a161684c51a7ac05b446dcf38d4",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T08:16:24.490",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52942"
                }
            ]
        },
        {
            "id": "CVE-2026-52933",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/poll: fix signed comparison in io_poll_get_ownership()\n\nio_poll_get_ownership() uses a signed comparison to check whether\npoll_refs has reached the threshold for the slowpath:\n\n    if (unlikely(atomic_read(&req->poll_refs) >= IO_POLL_REF_BIAS))\n\natomic_read() returns int (signed). When IO_POLL_CANCEL_FLAG\n(BIT(31)) is set in poll_refs, the value becomes negative in\nsigned arithmetic, so the >= 128 comparison always evaluates to\nfalse and the slowpath is never taken.\n\nFix this by casting the atomic_read() result to unsigned int\nbefore the comparison, so that the cancel flag is treated as a\nlarge positive value and correctly triggers the slowpath.",
            "updated_at": "2026-09-08T09:18:11.540",
            "published_at": "2026-06-24T08:16:23.480",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "a26a35e9019fd70bf3cf647dcfdae87abc7bacea through before 81bf96b0abbfa4cd47ea32e12596aed3855fb2f3 (git); a26a35e9019fd70bf3cf647dcfdae87abc7bacea through before cf522703d4f194991615763697ae25a3f9539763 (git); a26a35e9019fd70bf3cf647dcfdae87abc7bacea through before fc47043f3d9af3efa407665b47f8378ec691ba18 (git); a26a35e9019fd70bf3cf647dcfdae87abc7bacea through before ea0697129807d718037f618221037aa0660ee3c5 (git); a26a35e9019fd70bf3cf647dcfdae87abc7bacea through before c6d191164dc81838d8dbf452a6000f68c558d1ae (git); a26a35e9019fd70bf3cf647dcfdae87abc7bacea through before 326941b22806cbf2df1fbfe902b7908b368cce42 (git); 4b702b7d11ce1b9d26fc6d7c5a7ef4ac1d455048 (git); bc4e6ee16778149811333a969a7a893d4cc110c5 (git); 5.15.82 through before 5.16 (semver); 6.0.11 through before 6.1 (semver); 6.1; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-835",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/poll: fix signed comparison in io_poll_get_ownership()\n\nio_poll_get_ownership() uses a signed comparison to check whether\npoll_refs has reached the threshold for the slowpath:\n\n    if (unlikely(atomic_read(&req->poll_refs) >= IO_POLL_REF_BIAS))\n\natomic_read() returns int (signed). When IO_POLL_CANCEL_FLAG\n(BIT(31)) is set in poll_refs, the value becomes negative in\nsigned arithmetic, so the >= 128 comparison always evaluates to\nfalse and the slowpath is never taken.\n\nFix this by casting the atomic_read() result to unsigned int\nbefore the comparison, so that the cancel flag is treated as a\nlarge positive value and correctly triggers the slowpath.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/326941b22806cbf2df1fbfe902b7908b368cce42",
                "https://git.kernel.org/stable/c/81bf96b0abbfa4cd47ea32e12596aed3855fb2f3",
                "https://git.kernel.org/stable/c/c6d191164dc81838d8dbf452a6000f68c558d1ae",
                "https://git.kernel.org/stable/c/cf522703d4f194991615763697ae25a3f9539763",
                "https://git.kernel.org/stable/c/ea0697129807d718037f618221037aa0660ee3c5",
                "https://git.kernel.org/stable/c/fc47043f3d9af3efa407665b47f8378ec691ba18",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T08:16:23.480",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52933"
                }
            ]
        },
        {
            "id": "CVE-2026-52930",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nipc/shm: serialize orphan cleanup with shm_nattch updates\n\nshm_destroy_orphaned() walks the shm idr under shm_ids(ns).rwsem, but that\ndoes not serialize all fields tested by shm_may_destroy().  In particular,\nshm_nattch is updated while holding shm_perm.lock, and attach paths can do\nthat without holding the rwsem.\n\nDo not decide that an orphaned segment is unused before taking the object\nlock.  Move the shm_may_destroy() check under shm_perm.lock, matching the\nother destroy paths, and unlock the segment when it no longer qualifies\nfor removal.",
            "updated_at": "2026-09-08T09:18:11.377",
            "published_at": "2026-06-24T08:16:23.157",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4c677e2eefdba9c5bfc4474e2e91b26ae8458a1d through before b1e9aef48e4d8a0c1b54fb913077b0824ed7d650 (git); 4c677e2eefdba9c5bfc4474e2e91b26ae8458a1d through before 92cda2593cf2ed25b0e9d78e5e6d8303bba1a064 (git); 4c677e2eefdba9c5bfc4474e2e91b26ae8458a1d through before 1f0d01e35dbb228084d5187212e32c91a30dcbeb (git); 4c677e2eefdba9c5bfc4474e2e91b26ae8458a1d through before 6560be3f6a5bb84f006f184f0c966747bb58e1a3 (git); 4c677e2eefdba9c5bfc4474e2e91b26ae8458a1d through before b5107b4ce3ad45fcf369ee2058c8910620f4b5a8 (git); 4c677e2eefdba9c5bfc4474e2e91b26ae8458a1d through before db752ebfdaf2c7f27cd9690ef48b616af068319c (git); 4c677e2eefdba9c5bfc4474e2e91b26ae8458a1d through before 030bbc857bd51d4b25a90d931d3f8775ef22823a (git); 4c677e2eefdba9c5bfc4474e2e91b26ae8458a1d through before 2e5c6f4fd4001562781e99bbfc7f1f0127187542 (git); 3.1; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nipc/shm: serialize orphan cleanup with shm_nattch updates\n\nshm_destroy_orphaned() walks the shm idr under shm_ids(ns).rwsem, but that\ndoes not serialize all fields tested by shm_may_destroy().  In particular,\nshm_nattch is updated while holding shm_perm.lock, and attach paths can do\nthat without holding the rwsem.\n\nDo not decide that an orphaned segment is unused before taking the object\nlock.  Move the shm_may_destroy() check under shm_perm.lock, matching the\nother destroy paths, and unlock the segment when it no longer qualifies\nfor removal.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/030bbc857bd51d4b25a90d931d3f8775ef22823a",
                "https://git.kernel.org/stable/c/1f0d01e35dbb228084d5187212e32c91a30dcbeb",
                "https://git.kernel.org/stable/c/2e5c6f4fd4001562781e99bbfc7f1f0127187542",
                "https://git.kernel.org/stable/c/6560be3f6a5bb84f006f184f0c966747bb58e1a3",
                "https://git.kernel.org/stable/c/92cda2593cf2ed25b0e9d78e5e6d8303bba1a064",
                "https://git.kernel.org/stable/c/b1e9aef48e4d8a0c1b54fb913077b0824ed7d650",
                "https://git.kernel.org/stable/c/b5107b4ce3ad45fcf369ee2058c8910620f4b5a8",
                "https://git.kernel.org/stable/c/db752ebfdaf2c7f27cd9690ef48b616af068319c",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T08:16:23.157",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52930"
                }
            ]
        },
        {
            "id": "CVE-2026-52924",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: purge outqueue on stale COOKIE-ECHO handling\n\nsctp_stream_update() is only invoked when the association is moved into\nCOOKIE_WAIT during association setup/reconfiguration. In this path, the\noutbound stream scheduler state (stream->out_curr) is expected to be\nclean, since no user data should have been transmitted yet unless the\nstate machine has already partially progressed.\n\nHowever, a corner case exists in sctp_sf_do_5_2_6_stale(): when a\nStale Cookie ERROR is received, the association is rolled back from\nCOOKIE_ECHOED to COOKIE_WAIT. In this scenario, user data may already\nhave been queued and even bundled with the COOKIE-ECHO chunk.\n\nDuring the rollback, sctp_stream_update() frees the old stream table\nand installs a new one, but it does not invalidate stream->out_curr.\nAs a result, out_curr may still point to a freed sctp_stream_out\nentry from the previous stream state.\n\nLater, SCTP scheduler dequeue paths (FCFS, RR, PRIO, etc.) rely on\nstream->out_curr->ext, which can lead to use-after-free once the old\nstream state has been released via sctp_stream_free().\n\nThis results in crashes such as (reported by Yuqi):\n\n  BUG: KASAN: slab-use-after-free in sctp_sched_fcfs_dequeue+0x13a/0x140\n  Read of size 8 at addr ff1100004d4d3208 by task mini_poc/9312\n  CPU: 1 UID: 1001 PID: 9312 Comm: mini_poc Not tainted\n     7.1.0-rc1-00305-gbd3a4795d574 #5 PREEMPT(full)\n   sctp_sched_fcfs_dequeue+0x13a/0x140\n   sctp_outq_flush+0x1603/0x33e0\n   sctp_do_sm+0x31c9/0x5d30\n   sctp_assoc_bh_rcv+0x392/0x6f0\n   sctp_inq_push+0x1db/0x270\n   sctp_rcv+0x138d/0x3c10\n\nFix this by fully purging the association outqueue when handling the\nStale Cookie case. This ensures all pending transmit and retransmit\nstate is dropped, and any scheduler cached pointers are invalidated,\nmaking it safe to rebuild stream state during COOKIE_WAIT restart.\n\nUpdating only stream->out_curr would be insufficient, since queued\nand retransmittable data would still reference the old stream state and\ntrigger later use-after-free in dequeue paths.",
            "updated_at": "2026-09-15T12:17:51.013",
            "published_at": "2026-06-24T08:16:22.430",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5bbbbe32a43199c2b9ea5ea66fab6241c64beb51 through before 84b7a319105db2f917ccdcf502bdc866082b1285 (git); 5bbbbe32a43199c2b9ea5ea66fab6241c64beb51 through before f46e1d1a758878f0d22c4fbbd1bf42bb7165d1e8 (git); 5bbbbe32a43199c2b9ea5ea66fab6241c64beb51 through before 3c0741a441a7df7099d7ca6a64a6a0de09c677c8 (git); 5bbbbe32a43199c2b9ea5ea66fab6241c64beb51 through before 2afc9e684dc7fecf73db1edc937ebbc47b4b68dc (git); 5bbbbe32a43199c2b9ea5ea66fab6241c64beb51 through before 1d4652f677906a64487c13f9ace54b0eb263b5d0 (git); 5bbbbe32a43199c2b9ea5ea66fab6241c64beb51 through before a6207349e703cfc04756a4d16dec9176135813a5 (git); 5bbbbe32a43199c2b9ea5ea66fab6241c64beb51 through before 83ade59e5da365f4bf8bce72c5a38774202b442f (git); 5bbbbe32a43199c2b9ea5ea66fab6241c64beb51 through before e374b22e9b07b72a25909621464ff74096151bfb (git); 4.15",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: purge outqueue on stale COOKIE-ECHO handling\n\nsctp_stream_update() is only invoked when the association is moved into\nCOOKIE_WAIT during association setup/reconfiguration. In this path, the\noutbound stream scheduler state (stream->out_curr) is expected to be\nclean, since no user data should have been transmitted yet unless the\nstate machine has already partially progressed.\n\nHowever, a corner case exists in sctp_sf_do_5_2_6_stale(): when a\nStale Cookie ERROR is received, the association is rolled back from\nCOOKIE_ECHOED to COOKIE_WAIT. In this scenario, user data may already\nhave been queued and even bundled with the COOKIE-ECHO chunk.\n\nDuring the rollback, sctp_stream_update() frees the old stream table\nand installs a new one, but it does not invalidate stream->out_curr.\nAs a result, out_curr may still point to a freed sctp_stream_out\nentry from the previous stream state.\n\nLater, SCTP scheduler dequeue paths (FCFS, RR, PRIO, etc.) rely on\nstream->out_curr->ext, which can lead to use-after-free once the old\nstream state has been released via sctp_stream_free().\n\nThis results in crashes such as (reported by Yuqi):\n\n  BUG: KASAN: slab-use-after-free in sctp_sched_fcfs_dequeue+0x13a/0x140\n  Read of size 8 at addr ff1100004d4d3208 by task mini_poc/9312\n  CPU: 1 UID: 1001 PID: 9312 Comm: mini_poc Not tainted\n     7.1.0-rc1-00305-gbd3a4795d574 #5 PREEMPT(full)\n   sctp_sched_fcfs_dequeue+0x13a/0x140\n   sctp_outq_flush+0x1603/0x33e0\n   sctp_do_sm+0x31c9/0x5d30\n   sctp_assoc_bh_rcv+0x392/0x6f0\n   sctp_inq_push+0x1db/0x270\n   sctp_rcv+0x138d/0x3c10\n\nFix this by fully purging the association outqueue when handling the\nStale Cookie case. This ensures all pending transmit and retransmit\nstate is dropped, and any scheduler cached pointers are invalidated,\nmaking it safe to rebuild stream state during COOKIE_WAIT restart.\n\nUpdating only stream->out_curr would be insufficient, since queued\nand retransmittable data would still reference the old stream state and\ntrigger later use-after-free in dequeue paths.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1d4652f677906a64487c13f9ace54b0eb263b5d0",
                "https://git.kernel.org/stable/c/2afc9e684dc7fecf73db1edc937ebbc47b4b68dc",
                "https://git.kernel.org/stable/c/3c0741a441a7df7099d7ca6a64a6a0de09c677c8",
                "https://git.kernel.org/stable/c/83ade59e5da365f4bf8bce72c5a38774202b442f",
                "https://git.kernel.org/stable/c/84b7a319105db2f917ccdcf502bdc866082b1285",
                "https://git.kernel.org/stable/c/a6207349e703cfc04756a4d16dec9176135813a5",
                "https://git.kernel.org/stable/c/e374b22e9b07b72a25909621464ff74096151bfb",
                "https://git.kernel.org/stable/c/f46e1d1a758878f0d22c4fbbd1bf42bb7165d1e8",
                "https://access.redhat.com/errata/RHSA-2026:59723",
                "https://access.redhat.com/errata/RHSA-2026:59737",
                "https://access.redhat.com/errata/RHSA-2026:59821",
                "https://access.redhat.com/errata/RHSA-2026:67471",
                "https://access.redhat.com/security/cve/CVE-2026-52924",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492095",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52924.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T08:16:22.430",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52924"
                }
            ]
        },
        {
            "id": "CVE-2026-52912",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_queue: hold bridge skb->dev while queued\n\nbr_pass_frame_up() rewrites skb->dev from the ingress port to the bridge\nmaster before queueing bridge LOCAL_IN packets. NFQUEUE only holds\nreferences on state.in/out and bridge physdevs, so a queued bridge\npacket can retain a freed bridge master in skb->dev until reinjection.\n\nWhen the verdict is reinjected later, br_netif_receive_skb() re-enters\nthe receive path with skb->dev still pointing at the freed bridge master,\ntriggering a use-after-free.\n\nStore skb->dev in the queue entry, hold a reference on it for the queue\nlifetime, and use the saved device when dropping queued packets during\nNETDEV_DOWN handling.",
            "updated_at": "2026-09-08T09:18:11.190",
            "published_at": "2026-06-24T08:16:20.640",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "ac28634456867b23b95faccba7997a62ec430603 through before 950d809f154dca04e5fbe5d3c8b9c5e44769cd57 (git); ac28634456867b23b95faccba7997a62ec430603 through before a698ac8ab2561cf575d2d9f34095032651dd952e (git); ac28634456867b23b95faccba7997a62ec430603 through before 19924bdd8a45ebc72a7b84c57fd63057d1dc75ac (git); ac28634456867b23b95faccba7997a62ec430603 through before 1e5e20031c5eee8d2e490a90ff4d6a2feecfc3be (git); ac28634456867b23b95faccba7997a62ec430603 through before 3823c27099cfe2482299065814adbaa771be9644 (git); ac28634456867b23b95faccba7997a62ec430603 through before 15d464265120ab9818bd673af301deee09bedab2 (git); ac28634456867b23b95faccba7997a62ec430603 through before 3fb0f5c0f64162a8c3f25616a4f1e340b921737f (git); ac28634456867b23b95faccba7997a62ec430603 through before e196115ec330a18de415bdb9f5071aa9f08e53ce (git); 4.7; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_queue: hold bridge skb->dev while queued\n\nbr_pass_frame_up() rewrites skb->dev from the ingress port to the bridge\nmaster before queueing bridge LOCAL_IN packets. NFQUEUE only holds\nreferences on state.in/out and bridge physdevs, so a queued bridge\npacket can retain a freed bridge master in skb->dev until reinjection.\n\nWhen the verdict is reinjected later, br_netif_receive_skb() re-enters\nthe receive path with skb->dev still pointing at the freed bridge master,\ntriggering a use-after-free.\n\nStore skb->dev in the queue entry, hold a reference on it for the queue\nlifetime, and use the saved device when dropping queued packets during\nNETDEV_DOWN handling.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/15d464265120ab9818bd673af301deee09bedab2",
                "https://git.kernel.org/stable/c/19924bdd8a45ebc72a7b84c57fd63057d1dc75ac",
                "https://git.kernel.org/stable/c/1e5e20031c5eee8d2e490a90ff4d6a2feecfc3be",
                "https://git.kernel.org/stable/c/3823c27099cfe2482299065814adbaa771be9644",
                "https://git.kernel.org/stable/c/3fb0f5c0f64162a8c3f25616a4f1e340b921737f",
                "https://git.kernel.org/stable/c/950d809f154dca04e5fbe5d3c8b9c5e44769cd57",
                "https://git.kernel.org/stable/c/a698ac8ab2561cf575d2d9f34095032651dd952e",
                "https://git.kernel.org/stable/c/e196115ec330a18de415bdb9f5071aa9f08e53ce",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T08:16:20.640",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52912"
                }
            ]
        },
        {
            "id": "CVE-2026-52910",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Free reuseport cBPF prog after RCU grace period.\n\nEulgyu Kim reported the splat below with a repro. [0]\n\nThe repro sets up a UDP reuseport group with a cBPF prog and\nreplaces it with a new one while another thread is sending\na UDP packet to the group.\n\nThe reuseport prog is freed by sk_reuseport_prog_free().\nbpf_prog_put() is called for \"e\"BPF prog to destruct through\nmultiple stages while cBPF prog is freed immediately by\nbpf_release_orig_filter() and bpf_prog_free().\n\nIf a reuseport prog is detached from the setsockopt() path\n(reuseport_attach_prog() or reuseport_detach_prog()),\nsk_reuseport_prog_free() is called without waiting for RCU\nreaders to complete, resulting in various bugs.\n\nLet's defer freeing the reuseport cBPF prog after one RCU\ngrace period.\n\nNote \"e\"BPF prog is safe as is unless the fast path starts\nto touch fields destroyed in bpf_prog_put_deferred() and\n__bpf_prog_put_noref().\n\n[0]:\nBUG: KASAN: vmalloc-out-of-bounds in reuseport_select_sock+0xedc/0x1220 net/core/sock_reuseport.c:596\nRead of size 4 at addr ffffc9000051e004 by task slowme/10208\nCPU: 6 UID: 1000 PID: 10208 Comm: slowme Not tainted 7.0.0-geb7ac95ff75e #32 PREEMPT(full)\nHardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n <IRQ>\n dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xca/0x240 mm/kasan/report.c:482\n kasan_report+0x118/0x150 mm/kasan/report.c:595\n reuseport_select_sock+0xedc/0x1220 net/core/sock_reuseport.c:596\n udp4_lib_lookup2+0x3bc/0x950 net/ipv4/udp.c:495\n __udp4_lib_lookup+0x768/0xe20 net/ipv4/udp.c:723\n __udp4_lib_lookup_skb+0x297/0x390 net/ipv4/udp.c:752\n __udp4_lib_rcv+0x1312/0x2620 net/ipv4/udp.c:2752\n ip_protocol_deliver_rcu+0x282/0x440 net/ipv4/ip_input.c:207\n ip_local_deliver_finish+0x3bb/0x6f0 net/ipv4/ip_input.c:241\n NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318\n NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318\n __netif_receive_skb_one_core net/core/dev.c:6181 [inline]\n __netif_receive_skb net/core/dev.c:6294 [inline]\n process_backlog+0xaa4/0x1960 net/core/dev.c:6645\n __napi_poll+0xae/0x340 net/core/dev.c:7709\n napi_poll net/core/dev.c:7772 [inline]\n net_rx_action+0x5d7/0xf50 net/core/dev.c:7929\n handle_softirqs+0x22b/0x870 kernel/softirq.c:622\n do_softirq+0x76/0xd0 kernel/softirq.c:523\n </IRQ>\n <TASK>\n __local_bh_enable_ip+0xf8/0x130 kernel/softirq.c:450\n local_bh_enable include/linux/bottom_half.h:33 [inline]\n rcu_read_unlock_bh include/linux/rcupdate.h:924 [inline]\n __dev_queue_xmit+0x1dd7/0x3710 net/core/dev.c:4890\n neigh_output include/net/neighbour.h:556 [inline]\n ip_finish_output2+0xca9/0x1070 net/ipv4/ip_output.c:237\n NF_HOOK_COND include/linux/netfilter.h:307 [inline]\n ip_output+0x29f/0x450 net/ipv4/ip_output.c:438\n ip_send_skb+0x45/0xc0 net/ipv4/ip_output.c:1508\n udp_send_skb+0xb04/0x1510 net/ipv4/udp.c:1195\n udp_sendmsg+0x1a71/0x2350 net/ipv4/udp.c:1485\n sock_sendmsg_nosec net/socket.c:727 [inline]\n __sock_sendmsg net/socket.c:742 [inline]\n __sys_sendto+0x554/0x680 net/socket.c:2206\n __do_sys_sendto net/socket.c:2213 [inline]\n __se_sys_sendto net/socket.c:2209 [inline]\n __x64_sys_sendto+0xde/0x100 net/socket.c:2209\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x160/0xf80 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x415a2d\nCode: b3 66 2e 0f 1f 84 00 00 00 00 00 66 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f6bc31e41e8 EFLAGS: 00000212 ORIG_RAX: 000000000000002c\nRAX: ffffffffffffffda RBX: 00007f6bc31e4cdc RCX: 0000000000415a2d\nRDX: 0000000000000001 RSI: 00007f6bc31e421f RDI: 0000000000000003\nRBP: 00007f6bc31e4240 R08: 00007f6bc31e4220 R09: 0000000000000010\nR10: 0000000000000000 R11: \n---truncated---",
            "updated_at": "2026-09-08T09:18:10.877",
            "published_at": "2026-06-19T15:16:35.487",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "538950a1b7527a0a52ccd9337e3fcd304f027f13 through before 08264d5bba0bdd3a79bc2984fee09286aba0c4eb (git); 538950a1b7527a0a52ccd9337e3fcd304f027f13 through before fec41484e7c2aa7ded44c541bba98872be937754 (git); 538950a1b7527a0a52ccd9337e3fcd304f027f13 through before c3e3fddda6b5d9ba505d218b4055e7d8a282ac57 (git); 538950a1b7527a0a52ccd9337e3fcd304f027f13 through before f8b8f1d4bb76098e87b8269a0631019648330e6d (git); 538950a1b7527a0a52ccd9337e3fcd304f027f13 through before 298db6167f81e9c470a57cf652e4e47757b4293e (git); 538950a1b7527a0a52ccd9337e3fcd304f027f13 through before 87dfb977bdb6eaa47e9993a34e18f44970f88b1f (git); 538950a1b7527a0a52ccd9337e3fcd304f027f13 through before 90e47dc5c572d1c73971ac51c7428803f42b78eb (git); 538950a1b7527a0a52ccd9337e3fcd304f027f13 through before 18fc650ccd7fe3376eca89203668cfb8268f60df (git); 4.5; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Free reuseport cBPF prog after RCU grace period.\n\nEulgyu Kim reported the splat below with a repro. [0]\n\nThe repro sets up a UDP reuseport group with a cBPF prog and\nreplaces it with a new one while another thread is sending\na UDP packet to the group.\n\nThe reuseport prog is freed by sk_reuseport_prog_free().\nbpf_prog_put() is called for \"e\"BPF prog to destruct through\nmultiple stages while cBPF prog is freed immediately by\nbpf_release_orig_filter() and bpf_prog_free().\n\nIf a reuseport prog is detached from the setsockopt() path\n(reuseport_attach_prog() or reuseport_detach_prog()),\nsk_reuseport_prog_free() is called without waiting for RCU\nreaders to complete, resulting in various bugs.\n\nLet's defer freeing the reuseport cBPF prog after one RCU\ngrace period.\n\nNote \"e\"BPF prog is safe as is unless the fast path starts\nto touch fields destroyed in bpf_prog_put_deferred() and\n__bpf_prog_put_noref().\n\n[0]:\nBUG: KASAN: vmalloc-out-of-bounds in reuseport_select_sock+0xedc/0x1220 net/core/sock_reuseport.c:596\nRead of size 4 at addr ffffc9000051e004 by task slowme/10208\nCPU: 6 UID: 1000 PID: 10208 Comm: slowme Not tainted 7.0.0-geb7ac95ff75e #32 PREEMPT(full)\nHardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n <IRQ>\n dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xca/0x240 mm/kasan/report.c:482\n kasan_report+0x118/0x150 mm/kasan/report.c:595\n reuseport_select_sock+0xedc/0x1220 net/core/sock_reuseport.c:596\n udp4_lib_lookup2+0x3bc/0x950 net/ipv4/udp.c:495\n __udp4_lib_lookup+0x768/0xe20 net/ipv4/udp.c:723\n __udp4_lib_lookup_skb+0x297/0x390 net/ipv4/udp.c:752\n __udp4_lib_rcv+0x1312/0x2620 net/ipv4/udp.c:2752\n ip_protocol_deliver_rcu+0x282/0x440 net/ipv4/ip_input.c:207\n ip_local_deliver_finish+0x3bb/0x6f0 net/ipv4/ip_input.c:241\n NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318\n NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318\n __netif_receive_skb_one_core net/core/dev.c:6181 [inline]\n __netif_receive_skb net/core/dev.c:6294 [inline]\n process_backlog+0xaa4/0x1960 net/core/dev.c:6645\n __napi_poll+0xae/0x340 net/core/dev.c:7709\n napi_poll net/core/dev.c:7772 [inline]\n net_rx_action+0x5d7/0xf50 net/core/dev.c:7929\n handle_softirqs+0x22b/0x870 kernel/softirq.c:622\n do_softirq+0x76/0xd0 kernel/softirq.c:523\n </IRQ>\n <TASK>\n __local_bh_enable_ip+0xf8/0x130 kernel/softirq.c:450\n local_bh_enable include/linux/bottom_half.h:33 [inline]\n rcu_read_unlock_bh include/linux/rcupdate.h:924 [inline]\n __dev_queue_xmit+0x1dd7/0x3710 net/core/dev.c:4890\n neigh_output include/net/neighbour.h:556 [inline]\n ip_finish_output2+0xca9/0x1070 net/ipv4/ip_output.c:237\n NF_HOOK_COND include/linux/netfilter.h:307 [inline]\n ip_output+0x29f/0x450 net/ipv4/ip_output.c:438\n ip_send_skb+0x45/0xc0 net/ipv4/ip_output.c:1508\n udp_send_skb+0xb04/0x1510 net/ipv4/udp.c:1195\n udp_sendmsg+0x1a71/0x2350 net/ipv4/udp.c:1485\n sock_sendmsg_nosec net/socket.c:727 [inline]\n __sock_sendmsg net/socket.c:742 [inline]\n __sys_sendto+0x554/0x680 net/socket.c:2206\n __do_sys_sendto net/socket.c:2213 [inline]\n __se_sys_sendto net/socket.c:2209 [inline]\n __x64_sys_sendto+0xde/0x100 net/socket.c:2209\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x160/0xf80 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x415a2d\nCode: b3 66 2e 0f 1f 84 00 00 00 00 00 66 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f6bc31e41e8 EFLAGS: 00000212 ORIG_RAX: 000000000000002c\nRAX: ffffffffffffffda RBX: 00007f6bc31e4cdc RCX: 0000000000415a2d\nRDX: 0000000000000001 RSI: 00007f6bc31e421f RDI: 0000000000000003\nRBP: 00007f6bc31e4240 R08: 00007f6bc31e4220 R09: 0000000000000010\nR10: 0000000000000000 R11: \n---truncated---",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/08264d5bba0bdd3a79bc2984fee09286aba0c4eb",
                "https://git.kernel.org/stable/c/18fc650ccd7fe3376eca89203668cfb8268f60df",
                "https://git.kernel.org/stable/c/298db6167f81e9c470a57cf652e4e47757b4293e",
                "https://git.kernel.org/stable/c/87dfb977bdb6eaa47e9993a34e18f44970f88b1f",
                "https://git.kernel.org/stable/c/90e47dc5c572d1c73971ac51c7428803f42b78eb",
                "https://git.kernel.org/stable/c/c3e3fddda6b5d9ba505d218b4055e7d8a282ac57",
                "https://git.kernel.org/stable/c/f8b8f1d4bb76098e87b8269a0631019648330e6d",
                "https://git.kernel.org/stable/c/fec41484e7c2aa7ded44c541bba98872be937754",
                "https://access.redhat.com/security/cve/CVE-2026-52910",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2490779",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52910.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-19T15:16:35.487",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52910"
                }
            ]
        },
        {
            "id": "CVE-2026-52857",
            "vendor": "pterodactyl",
            "product": "wings",
            "title": "wings vulnerability",
            "summary": "Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in parser.go can process an oversized non-file parser configuration file and exhaust Wings process memory. This issue is fixed in version 1.13.0.",
            "updated_at": "2026-09-10T20:12:43.783",
            "published_at": "2026-07-31T16:17:06.490",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.13.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in parser.go can process an oversized non-file parser configuration file and exhaust Wings process memory. This issue is fixed in version 1.13.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pterodactyl/wings/commit/5f71f65711b6b9e6f913bec94a7b36d9a5eaae49",
                "https://github.com/pterodactyl/wings/releases/tag/v1.13.0",
                "https://github.com/pterodactyl/wings/security/advisories/GHSA-q6hh-gp44-4hcm"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T16:17:06.490",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52857"
                }
            ]
        },
        {
            "id": "CVE-2026-52856",
            "vendor": "pterodactyl",
            "product": "wings",
            "title": "wings vulnerability",
            "summary": "Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.",
            "updated_at": "2026-09-10T20:12:43.783",
            "published_at": "2026-07-31T17:16:33.460",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.13.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-129",
            "what_happened": "Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pterodactyl/wings/commit/8e49c7c0eda815d3ada171831876a1c14c493026",
                "https://github.com/pterodactyl/wings/releases/tag/v1.13.0",
                "https://github.com/pterodactyl/wings/security/advisories/GHSA-ghrq-5wpp-hxx5"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T17:16:33.460",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52856"
                }
            ]
        },
        {
            "id": "CVE-2026-52855",
            "vendor": "pterodactyl",
            "product": "wings",
            "title": "wings vulnerability",
            "summary": "Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and {{config.docker.registries}} from the full daemon configuration. This issue is fixed in version 1.12.3.",
            "updated_at": "2026-09-10T20:12:43.783",
            "published_at": "2026-07-31T17:16:33.313",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.12.3",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and {{config.docker.registries}} from the full daemon configuration. This issue is fixed in version 1.12.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pterodactyl/wings/commit/eb65e27ae077a63e38518c490768486af1cd86a9",
                "https://github.com/pterodactyl/wings/releases/tag/v1.12.3",
                "https://github.com/pterodactyl/wings/security/advisories/GHSA-pfvc-3p5h-x7h6"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T17:16:33.313",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52855"
                }
            ]
        },
        {
            "id": "CVE-2026-52791",
            "vendor": "containers",
            "product": "fuse-overlayfs",
            "title": "fuse-overlayfs vulnerability",
            "summary": "fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file, allowing a low-privileged process to leave the upper-layer file with mode 4777. This issue is fixed in version 1.17.",
            "updated_at": "2026-09-10T20:04:54.367",
            "published_at": "2026-07-29T17:16:52.187",
            "cvss": 2,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.17",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branch preserves SUID and SGID mode bits in main.c during open(O_TRUNC) and truncate handling on a copied-up file, allowing a low-privileged process to leave the upper-layer file with mode 4777. This issue is fixed in version 1.17.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/containers/fuse-overlayfs/commit/97e0d968a782fc259ebde112db1e9b9ff1ad724f",
                "https://github.com/containers/fuse-overlayfs/releases/tag/v1.17",
                "https://github.com/containers/fuse-overlayfs/security/advisories/GHSA-2cc4-p72c-v85h"
            ],
            "timeline": [
                {
                    "at": "2026-07-29T17:16:52.187",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52791"
                }
            ]
        },
        {
            "id": "CVE-2026-52521",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature.",
            "updated_at": "2026-09-09T16:04:24.933",
            "published_at": "2026-08-03T21:16:40.503",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/LING12138-sg/MyCVE-Report",
                "https://github.com/zblogcn/zblogphp"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:40.503",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52521"
                }
            ]
        },
        {
            "id": "CVE-2026-52371",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resources via supplying a crafted HTTP request.",
            "updated_at": "2026-09-09T15:44:20.970",
            "published_at": "2026-07-31T22:17:02.673",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resources via supplying a crafted HTTP request.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/RichardKabuto/xxl-job-ssrf-poc"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T22:17:02.673",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52371"
                }
            ]
        },
        {
            "id": "CVE-2026-52297",
            "vendor": "FFmpeg",
            "product": "FFmpeg",
            "title": "FFmpeg vulnerability",
            "summary": "FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.",
            "updated_at": "2026-09-13T22:17:00.433",
            "published_at": "2026-09-13T22:17:00.433",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 9.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-125",
            "what_happened": "FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22988",
                "https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/8439e0203744a30d280668fcd086f74ed5001da1",
                "https://github.com/Kenan-Kamel/VulnerabilitiesReference/tree/main/FFmpeg/ExtradataPadding"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T22:17:00.433",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52297"
                }
            ]
        },
        {
            "id": "CVE-2026-52296",
            "vendor": "FFmpeg",
            "product": "FFmpeg",
            "title": "FFmpeg vulnerability",
            "summary": "FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.",
            "updated_at": "2026-09-13T22:17:00.297",
            "published_at": "2026-09-13T22:17:00.297",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 9.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-125",
            "what_happened": "FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22988",
                "https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/23227a444de4a8f7696f46660cdd044b460f7e47",
                "https://github.com/Kenan-Kamel/VulnerabilitiesReference/tree/main/FFmpeg/ExtradataPadding"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T22:17:00.297",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52296"
                }
            ]
        },
        {
            "id": "CVE-2026-52295",
            "vendor": "FFmpeg",
            "product": "FFmpeg",
            "title": "FFmpeg vulnerability",
            "summary": "FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.",
            "updated_at": "2026-09-13T22:16:59.693",
            "published_at": "2026-09-01T18:17:43.940",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 9.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-125",
            "what_happened": "FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22988",
                "https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/8439e0203744a30d280668fcd086f74ed5001da1",
                "https://github.com/Kenan-Kamel/VulnerabilitiesReference/tree/main/FFmpeg/ExtradataPadding"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T18:17:43.940",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52295"
                }
            ]
        },
        {
            "id": "CVE-2026-52232",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.",
            "updated_at": "2026-09-09T15:44:20.970",
            "published_at": "2026-07-31T22:17:02.553",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/whitewhale-dmb/Vulnerability-Research/tree/main/CVE-2026-52232"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T22:17:02.553",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52232"
                }
            ]
        },
        {
            "id": "CVE-2026-52102",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.",
            "updated_at": "2026-09-09T16:04:24.933",
            "published_at": "2026-08-03T21:16:40.273",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gist.github.com/NtGabrielGomes/46817d363821cf8c5ff4882c811a4325",
                "https://github.com/openmediavault/openmediavault",
                "https://www.openmediavault.org"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:40.273",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52102"
                }
            ]
        },
        {
            "id": "CVE-2026-52023",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()",
            "updated_at": "2026-09-15T19:08:17.017",
            "published_at": "2026-09-01T18:17:43.360",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-415",
            "what_happened": "An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-09-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/kamailio/kamailio/issues/4671"
                }
            ],
            "references": [
                "https://github.com/kamailio/kamailio/commit/722c06b3efc53ccb369ce812c685c7d069508187",
                "https://github.com/kamailio/kamailio/issues/4671"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T18:17:43.360",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-52023"
                }
            ]
        },
        {
            "id": "CVE-2026-51775",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.php component",
            "updated_at": "2026-09-09T16:04:24.933",
            "published_at": "2026-08-03T21:16:40.153",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.php component",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gitee.com/Tor443/security-advisory/blob/master/README.md"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:40.153",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-51775"
                }
            ]
        },
        {
            "id": "CVE-2026-51407",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Fullhan FH8626V100 - Multiple Vulnerabilities",
            "summary": "Fullhan FH8626V100 - Multiple Vulnerabilities",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 98,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52674",
                    "author": "Amir Aliu",
                    "first_seen": "2026-09-02",
                    "confidence": "High",
                    "title": "Fullhan FH8626V100 - Multiple Vulnerabilities",
                    "summary": "Fullhan FH8626V100 - Multiple Vulnerabilities",
                    "url": "https://www.exploit-db.com/exploits/52674",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52674"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52674"
                }
            ]
        },
        {
            "id": "CVE-2026-51406",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Fullhan FH8626V100 - Multiple Vulnerabilities",
            "summary": "Fullhan FH8626V100 - Multiple Vulnerabilities",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 98,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52674",
                    "author": "Amir Aliu",
                    "first_seen": "2026-09-02",
                    "confidence": "High",
                    "title": "Fullhan FH8626V100 - Multiple Vulnerabilities",
                    "summary": "Fullhan FH8626V100 - Multiple Vulnerabilities",
                    "url": "https://www.exploit-db.com/exploits/52674",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52674"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52674"
                }
            ]
        },
        {
            "id": "CVE-2026-51405",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Fullhan FH8626V100 - Multiple Vulnerabilities",
            "summary": "Fullhan FH8626V100 - Multiple Vulnerabilities",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 98,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52674",
                    "author": "Amir Aliu",
                    "first_seen": "2026-09-02",
                    "confidence": "High",
                    "title": "Fullhan FH8626V100 - Multiple Vulnerabilities",
                    "summary": "Fullhan FH8626V100 - Multiple Vulnerabilities",
                    "url": "https://www.exploit-db.com/exploits/52674",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52674"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52674"
                }
            ]
        },
        {
            "id": "CVE-2026-51404",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Fullhan FH8626V100 - Multiple Vulnerabilities",
            "summary": "Fullhan FH8626V100 - Multiple Vulnerabilities",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 98,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52674",
                    "author": "Amir Aliu",
                    "first_seen": "2026-09-02",
                    "confidence": "High",
                    "title": "Fullhan FH8626V100 - Multiple Vulnerabilities",
                    "summary": "Fullhan FH8626V100 - Multiple Vulnerabilities",
                    "url": "https://www.exploit-db.com/exploits/52674",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52674"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52674"
                }
            ]
        },
        {
            "id": "CVE-2026-51403",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Fullhan FH8626V100 - Multiple Vulnerabilities",
            "summary": "Fullhan FH8626V100 - Multiple Vulnerabilities",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 98,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52674",
                    "author": "Amir Aliu",
                    "first_seen": "2026-09-02",
                    "confidence": "High",
                    "title": "Fullhan FH8626V100 - Multiple Vulnerabilities",
                    "summary": "Fullhan FH8626V100 - Multiple Vulnerabilities",
                    "url": "https://www.exploit-db.com/exploits/52674",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52674"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52674"
                }
            ]
        },
        {
            "id": "CVE-2026-51402",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Fullhan FH8626V100 - Multiple Vulnerabilities",
            "summary": "Fullhan FH8626V100 - Multiple Vulnerabilities",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 98,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52674",
                    "author": "Amir Aliu",
                    "first_seen": "2026-09-02",
                    "confidence": "High",
                    "title": "Fullhan FH8626V100 - Multiple Vulnerabilities",
                    "summary": "Fullhan FH8626V100 - Multiple Vulnerabilities",
                    "url": "https://www.exploit-db.com/exploits/52674",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52674"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52674"
                }
            ]
        },
        {
            "id": "CVE-2026-51190",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "The \"s init\" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL ending in \".git\" bypasses the only input check, allowing OS command injection when a user runs \"s init\" with an attacker-controlled argument.",
            "updated_at": "2026-09-09T16:04:24.933",
            "published_at": "2026-08-03T21:16:40.033",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "The \"s init\" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL ending in \".git\" bypasses the only input check, allowing OS command injection when a user runs \"s init\" with an attacker-controlled argument.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gist.github.com/j311yl0v3u/5600afea3bea1337805c2e335bd4ae8e"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:40.033",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-51190"
                }
            ]
        },
        {
            "id": "CVE-2026-51134",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "C-MOR  6.0104 - Directory Traversal",
            "summary": "C-MOR  6.0104 - Directory Traversal",
            "updated_at": "2026-08-30T22:00:00Z",
            "published_at": "2026-08-30T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 169,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "C-MOR 6.0104 Directory Traversal",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52666",
                    "author": "Samir Shamdin",
                    "first_seen": "2026-08-31",
                    "confidence": "High",
                    "title": "C-MOR  6.0104 - Directory Traversal",
                    "summary": "C-MOR  6.0104 - Directory Traversal",
                    "url": "https://www.exploit-db.com/exploits/52666",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "CXSecurity WLB-2026090004",
                    "author": "Fadi Kaakahji",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "C-MOR 6.0104 Directory Traversal",
                    "summary": "C-MOR 6.0104 Directory Traversal",
                    "what_happened": "C-MOR 6.0104 Directory Traversal",
                    "cvss": 0,
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "url": "https://cxsecurity.com/issue/WLB-2026090004",
                    "cwe": "Unknown"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52666",
                "https://cxsecurity.com/issue/WLB-2026090004"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52666"
                }
            ]
        },
        {
            "id": "CVE-2026-51133",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "C-MOR  6.0104 - Cross-Site Scripting (XSS)",
            "summary": "C-MOR  6.0104 - Cross-Site Scripting (XSS)",
            "updated_at": "2026-08-30T22:00:00Z",
            "published_at": "2026-08-30T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 96,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52665",
                    "author": "Samir Shamdin",
                    "first_seen": "2026-08-31",
                    "confidence": "High",
                    "title": "C-MOR  6.0104 - Cross-Site Scripting (XSS)",
                    "summary": "C-MOR  6.0104 - Cross-Site Scripting (XSS)",
                    "url": "https://www.exploit-db.com/exploits/52665",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52665"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52665"
                }
            ]
        },
        {
            "id": "CVE-2026-50558",
            "vendor": "brightio",
            "product": "penelope",
            "title": "penelope vulnerability",
            "summary": "Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar archives returned by remote sessions without validating member paths, allowing a malicious or compromised session to write files outside the intended download directory and potentially overwrite ~/.penelope/peneloperc. This issue is fixed in version 0.20.0.",
            "updated_at": "2026-09-10T20:05:05.293",
            "published_at": "2026-07-29T16:17:52.900",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 0.20.0",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-22",
            "what_happened": "Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar archives returned by remote sessions without validating member paths, allowing a malicious or compromised session to write files outside the intended download directory and potentially overwrite ~/.penelope/peneloperc. This issue is fixed in version 0.20.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/brightio/penelope/commit/a040afb5db32c7e80b5e8a2f9b2164cf911cfa62",
                "https://github.com/brightio/penelope/releases/tag/v0.20.0",
                "https://github.com/brightio/penelope/security/advisories/GHSA-f42x-p2mx-hm8r"
            ],
            "timeline": [
                {
                    "at": "2026-07-29T16:17:52.900",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50558"
                }
            ]
        },
        {
            "id": "CVE-2026-50522",
            "vendor": "Microsoft",
            "product": "SharePoint",
            "title": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
            "summary": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.",
            "updated_at": "2026-07-21T22:00:00Z",
            "published_at": "2026-07-21T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-07-21T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-50416",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
            "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
            "updated_at": "2026-09-11T22:10:10Z",
            "published_at": "2026-09-11T22:10:10Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 85,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                },
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-54121-Certighost",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:10:10Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2026-50349",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1607",
            "title": "Windows 10 Version 1607 vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "updated_at": "2026-09-09T05:17:24.193",
            "published_at": "2026-09-08T18:17:38.537",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.14393.0 through before 10.0.14393.9512 (custom); 10.0.17763.0 through before 10.0.17763.9245 (custom); 10.0.19044.0 through before 10.0.19044.7725 (custom); 10.0.19045.0 through before 10.0.19045.7725 (custom); 10.0.22631.0 through before 10.0.22631.7582 (custom); 10.0.26100.0 through before 10.0.26100.9445 (custom); 10.0.26200.0 through before 10.0.26200.9445 (custom); 10.0.28000.0 through before 10.0.28000.2954 (custom); 6.2.9200.0 through before 6.2.9200.26349 (custom); 6.3.9600.0 through before 6.3.9600.23397 (custom); 10.0.20348.0 through before 10.0.20348.5622 (custom); 10.0.26100.0 through before 10.0.26100.33438 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50349"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T18:17:38.537",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50349"
                }
            ]
        },
        {
            "id": "CVE-2026-50237",
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4.12",
            "title": "Red Hat OpenShift Container Platform 4.12 vulnerability",
            "summary": "A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.",
            "updated_at": "2026-09-05T13:18:13.053",
            "published_at": "2026-08-11T12:17:38.347",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:54188",
                "https://access.redhat.com/errata/RHSA-2026:54206",
                "https://access.redhat.com/errata/RHSA-2026:54545",
                "https://access.redhat.com/errata/RHSA-2026:54555",
                "https://access.redhat.com/errata/RHSA-2026:54583",
                "https://access.redhat.com/errata/RHSA-2026:54602",
                "https://access.redhat.com/errata/RHSA-2026:54770",
                "https://access.redhat.com/errata/RHSA-2026:56789",
                "https://access.redhat.com/errata/RHSA-2026:56854",
                "https://access.redhat.com/errata/RHSA-2026:56912",
                "https://access.redhat.com/errata/RHSA-2026:60023",
                "https://access.redhat.com/security/cve/CVE-2026-50237",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2484746"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T12:17:38.347",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50237"
                }
            ]
        },
        {
            "id": "CVE-2026-50236",
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4.14",
            "title": "Red Hat OpenShift Container Platform 4.14 vulnerability",
            "summary": "An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.",
            "updated_at": "2026-09-07T18:17:21.550",
            "published_at": "2026-08-11T12:17:38.183",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:54545",
                "https://access.redhat.com/errata/RHSA-2026:54555",
                "https://access.redhat.com/errata/RHSA-2026:54583",
                "https://access.redhat.com/errata/RHSA-2026:54602",
                "https://access.redhat.com/errata/RHSA-2026:54770",
                "https://access.redhat.com/errata/RHSA-2026:56789",
                "https://access.redhat.com/errata/RHSA-2026:56854",
                "https://access.redhat.com/errata/RHSA-2026:56912",
                "https://access.redhat.com/errata/RHSA-2026:60023",
                "https://access.redhat.com/security/cve/CVE-2026-50236",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2484745"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T12:17:38.183",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50236"
                }
            ]
        },
        {
            "id": "CVE-2026-50010",
            "vendor": "netty",
            "product": "netty",
            "title": "netty vulnerability",
            "summary": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm=\"HTTPS\" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
            "updated_at": "2026-09-11T13:18:15.037",
            "published_at": "2026-06-12T16:16:31.180",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 4.2.0.Final, < 4.2.15.Final; < 4.1.135.Final",
            "fixed": "See vendor advisory",
            "source_count": 23,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-347",
            "what_happened": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm=\"HTTPS\" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final",
                "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final",
                "https://github.com/netty/netty/security/advisories/GHSA-c653-97m9-rcg9",
                "https://access.redhat.com/errata/RHSA-2026:26017",
                "https://access.redhat.com/errata/RHSA-2026:26018",
                "https://access.redhat.com/errata/RHSA-2026:26586",
                "https://access.redhat.com/errata/RHSA-2026:28573",
                "https://access.redhat.com/errata/RHSA-2026:34608",
                "https://access.redhat.com/errata/RHSA-2026:37390",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:49700",
                "https://access.redhat.com/errata/RHSA-2026:49701",
                "https://access.redhat.com/errata/RHSA-2026:50085",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/errata/RHSA-2026:62260",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-50010",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2488429",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50010.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-12T16:16:31.180",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50010"
                }
            ]
        },
        {
            "id": "CVE-2026-49975",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "http2-bomb exploit",
            "summary": "Exploit for CVE-2026-49975. CVSS 7.5.",
            "updated_at": "2026-09-14T18:31:57Z",
            "published_at": "2026-09-14T18:31:57Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "HTTP/2 stream amplification via HEADERS frames with many internal references causing memory DoS.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for http2-bomb CVE-2026-49975",
                    "summary": "HTTP/2 stream amplification via HEADERS frames with many internal references causing memory DoS.",
                    "what_happened": "HTTP/2 stream amplification via HEADERS frames with many internal references causing memory DoS.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-OBRIGE-HTTP2-BOMB",
                        "https://kitploit.com/zh/tools/github/obrige/http2-bomb/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-13T17:54:16",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-OBRIGE-HTTP2-BOMB"
                },
                {
                    "title": "Exploit for http2-bomb CVE-2026-49975",
                    "summary": "HTTP/2 stream amplification via HEADERS frames with many internal references causing memory DoS.",
                    "what_happened": "HTTP/2 stream amplification via HEADERS frames with many internal references causing memory DoS.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-OBRIGE-HTTP2-BOMB",
                        "https://kitploit.com/zh/tools/github/obrige/http2-bomb/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-13T17:54:16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/obrige/http2-bomb/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-OBRIGE-HTTP2-BOMB",
                "https://kitploit.com/zh/tools/github/obrige/http2-bomb/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T18:31:57Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-OBRIGE-HTTP2-BOMB"
                }
            ]
        },
        {
            "id": "CVE-2026-49881",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:18:01.847",
            "published_at": "2026-09-08T19:17:58.470",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In serviceClassExists of InCallController.java, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:58.470",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49881"
                }
            ]
        },
        {
            "id": "CVE-2026-49879",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:18:01.723",
            "published_at": "2026-09-08T19:17:58.370",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:58.370",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49879"
                }
            ]
        },
        {
            "id": "CVE-2026-49869",
            "vendor": "Kestra",
            "product": "Kestra OSS",
            "title": "Kestra OSS OS Command Injection Vulnerability",
            "summary": "Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 93,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Kestra OSS contains an OS command injection vulnerability that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Ap0dexMe0/CVE-2026-49869",
                    "author": "Ap0dexMe0",
                    "first_seen": "2026-06-30",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 2,
                    "title": "Kestra Auth-Bypass Vulnerability Checker",
                    "summary": "Kestra Auth-Bypass Vulnerability Checker",
                    "url": "https://github.com/Ap0dexMe0/CVE-2026-49869"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/Ap0dexMe0/CVE-2026-49869"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-49509",
            "vendor": "Samsung Opensource",
            "product": "rLottie",
            "title": "rLottie vulnerability",
            "summary": "Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers.\n\nThis issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630.",
            "updated_at": "2026-09-06T22:17:20.363",
            "published_at": "2026-09-04T00:17:12.820",
            "cvss": 4.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "25648aef19187b3f87f4d9420b8d761453ad4630",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers.\n\nThis issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Samsung/rlottie/pull/604"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T00:17:12.820",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49509"
                }
            ]
        },
        {
            "id": "CVE-2026-49487",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "In Apache Airflow before 3.3.0, the REST API task-instance detail and list\nendpoints returned a deferred task's trigger kwargs without masking. When a\ndeferred operator passed a secret (for example a provider API key) into its\ntrigger, any authenticated user with DAG-scoped task-instance read access for\nthat DAG could read that secret in clear text while the task was deferred.\nUsers should upgrade to apache-airflow 3.3.0 or later, which masks sensitive\nvalues in trigger kwargs returned by the API.",
            "updated_at": "2026-09-16T15:17:37.447",
            "published_at": "2026-07-07T10:16:41.723",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "In Apache Airflow before 3.3.0, the REST API task-instance detail and list\nendpoints returned a deferred task's trigger kwargs without masking. When a\ndeferred operator passed a secret (for example a provider API key) into its\ntrigger, any authenticated user with DAG-scoped task-instance read access for\nthat DAG could read that secret in clear text while the task was deferred.\nUsers should upgrade to apache-airflow 3.3.0 or later, which masks sensitive\nvalues in trigger kwargs returned by the API.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/67868",
                "https://lists.apache.org/thread/qlw6pozlzlfhkvmbgqsbjlq6vj4v0pc4",
                "http://www.openwall.com/lists/oss-security/2026/07/07/6"
            ],
            "timeline": [
                {
                    "at": "2026-07-07T10:16:41.723",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49487"
                }
            ]
        },
        {
            "id": "CVE-2026-49486",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow FTP provider",
            "title": "Apache Airflow FTP provider vulnerability",
            "summary": "The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTPSFileTransmitOperator` to move files over FTPS exposed file contents and credentials-in-transit to a network attacker able to observe the data connection. Upgrade apache-airflow-providers-ftp to `3.15.1` or later, which issues `PROT P` to encrypt the data channel.",
            "updated_at": "2026-09-16T15:17:37.280",
            "published_at": "2026-06-26T08:16:23.830",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.15.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-319",
            "what_happened": "The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTPSFileTransmitOperator` to move files over FTPS exposed file contents and credentials-in-transit to a network attacker able to observe the data connection. Upgrade apache-airflow-providers-ftp to `3.15.1` or later, which issues `PROT P` to encrypt the data channel.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/67946",
                "https://lists.apache.org/thread/gwnsxlt9hfj5pc543wxtogbnjdn04xj1",
                "http://www.openwall.com/lists/oss-security/2026/06/26/1"
            ],
            "timeline": [
                {
                    "at": "2026-06-26T08:16:23.830",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49486"
                }
            ]
        },
        {
            "id": "CVE-2026-49441",
            "vendor": "wazuh",
            "product": "wazuh",
            "title": "wazuh vulnerability",
            "summary": "Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged branch of process_files_from_worker() in framework/wazuh/core/cluster/master.py trusts a peer-controlled file_path key from files_metadata.json. The destination is joined to WAZUH_PATH without proving that it remains inside the directory selected by cluster_item_key. A cluster peer holding the shared Fernet key can upload a crafted extra-valid archive and overwrite security-sensitive files such as /var/ossec/etc/ossec.conf. Replacing ossec.conf can configure root-executed commands and lead to code execution after a service reload. This issue is fixed in versions 4.14.6 and 5.0.0-beta3.",
            "updated_at": "2026-09-15T19:21:34.670",
            "published_at": "2026-08-19T17:18:54.073",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.3.0, < 4.14.6; >= 5.0.0-beta1, < 5.0.0-beta3",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-73",
            "what_happened": "Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged branch of process_files_from_worker() in framework/wazuh/core/cluster/master.py trusts a peer-controlled file_path key from files_metadata.json. The destination is joined to WAZUH_PATH without proving that it remains inside the directory selected by cluster_item_key. A cluster peer holding the shared Fernet key can upload a crafted extra-valid archive and overwrite security-sensitive files such as /var/ossec/etc/ossec.conf. Replacing ossec.conf can configure root-executed commands and lead to code execution after a service reload. This issue is fixed in versions 4.14.6 and 5.0.0-beta3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-19",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-3v57-hgvj-3vj2"
                }
            ],
            "references": [
                "https://github.com/wazuh/wazuh/commit/7f13682cf5f01f69452f723a608ab2d89cfb2133",
                "https://github.com/wazuh/wazuh/pull/36296",
                "https://github.com/wazuh/wazuh/releases/tag/v4.14.6",
                "https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta3",
                "https://github.com/wazuh/wazuh/security/advisories/GHSA-3v57-hgvj-3vj2"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T17:18:54.073",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49441"
                }
            ]
        },
        {
            "id": "CVE-2026-49392",
            "vendor": "wazuh",
            "product": "wazuh",
            "title": "wazuh vulnerability",
            "summary": "Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLite row filters. On non-Windows systems, FIMDBCreator::encodeString() does not escape the value. A local user who can create a filename in a File Integrity Monitoring directory can inject a UNION SELECT expression when wazuh-syscheckd processes or deletes that path. The confirmed primitive manipulates SELECT result sets consumed by the FIM code; stacked statements and remote code execution were not demonstrated. This issue is fixed in versions 4.14.6 and 5.0.0-beta3.",
            "updated_at": "2026-09-15T19:23:30.010",
            "published_at": "2026-08-19T17:18:53.770",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.6.0, < 4.14.6; >= 5.0.0-beta1, < 5.0.0-beta3",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.6.0 until 4.14.6 and 5.0.0-beta3, DB::getFile() and DB::searchFile() in src/syscheckd/src/db/src/file.cpp concatenate a monitored file path into SQLite row filters. On non-Windows systems, FIMDBCreator::encodeString() does not escape the value. A local user who can create a filename in a File Integrity Monitoring directory can inject a UNION SELECT expression when wazuh-syscheckd processes or deletes that path. The confirmed primitive manipulates SELECT result sets consumed by the FIM code; stacked statements and remote code execution were not demonstrated. This issue is fixed in versions 4.14.6 and 5.0.0-beta3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-19",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/wazuh/wazuh/commit/8e4e25b971dfb7b15bc492f10f8a350e6b37e70e"
                },
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-19",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-9c4x-mrjh-rmw5"
                }
            ],
            "references": [
                "https://github.com/wazuh/wazuh/commit/8e4e25b971dfb7b15bc492f10f8a350e6b37e70e",
                "https://github.com/wazuh/wazuh/pull/36399",
                "https://github.com/wazuh/wazuh/releases/tag/v4.14.6",
                "https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta3",
                "https://github.com/wazuh/wazuh/security/advisories/GHSA-9c4x-mrjh-rmw5"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T17:18:53.770",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49392"
                }
            ]
        },
        {
            "id": "CVE-2026-49332",
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4.12",
            "title": "Red Hat OpenShift Container Platform 4.12 vulnerability",
            "summary": "A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.",
            "updated_at": "2026-09-06T18:17:21.720",
            "published_at": "2026-07-28T13:18:46.067",
            "cvss": 8.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-436",
            "what_happened": "A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:50681",
                "https://access.redhat.com/errata/RHSA-2026:50758",
                "https://access.redhat.com/errata/RHSA-2026:51007",
                "https://access.redhat.com/errata/RHSA-2026:51013",
                "https://access.redhat.com/errata/RHSA-2026:51022",
                "https://access.redhat.com/errata/RHSA-2026:51025",
                "https://access.redhat.com/errata/RHSA-2026:51038",
                "https://access.redhat.com/errata/RHSA-2026:54188",
                "https://access.redhat.com/errata/RHSA-2026:54206",
                "https://access.redhat.com/errata/RHSA-2026:56912",
                "https://access.redhat.com/errata/RHSA-2026:60023",
                "https://access.redhat.com/security/cve/CVE-2026-49332",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2483253"
            ],
            "timeline": [
                {
                    "at": "2026-07-28T13:18:46.067",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49332"
                }
            ]
        },
        {
            "id": "CVE-2026-49296",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire source file without redacting Dags the caller was not authorized to read, bypassing per-DAG read authorization. Deployments that co-locate multiple Dags in a single file and rely on per-DAG access control to limit source visibility are affected; single-Dag-per-file deployments are not. Upgrade to apache-airflow 3.3.0 or later.",
            "updated_at": "2026-09-16T15:17:36.500",
            "published_at": "2026-07-07T10:16:41.603",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.0.0 through before 3.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire source file without redacting Dags the caller was not authorized to read, bypassing per-DAG read authorization. Deployments that co-locate multiple Dags in a single file and rely on per-DAG access control to limit source visibility are affected; single-Dag-per-file deployments are not. Upgrade to apache-airflow 3.3.0 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/67662",
                "https://lists.apache.org/thread/qqv41t3oydkn9o14r2rfz1wkdrsp5jzn",
                "http://www.openwall.com/lists/oss-security/2026/07/07/5"
            ],
            "timeline": [
                {
                    "at": "2026-07-07T10:16:41.603",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49296"
                }
            ]
        },
        {
            "id": "CVE-2026-49176",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-49176_LPE_POC exploit",
            "summary": "Exploit for CVE-2026-49176. CVSS 7.8.",
            "updated_at": "2026-09-14T18:31:22Z",
            "published_at": "2026-09-14T18:31:22Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Local privilege escalation in Windows WalletService via ESE callback loading DLL as SYSTEM.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-49176_LPE_POC",
                    "summary": "Local privilege escalation in Windows WalletService via ESE callback loading DLL as SYSTEM.",
                    "what_happened": "Local privilege escalation in Windows WalletService via ESE callback loading DLL as SYSTEM.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DAVIDCARLIEZ-CVE-2026-49176_LPE_POC",
                        "https://kitploit.com/en/tools/github/davidcarliez/cve-2026-49176_lpe_poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-07T18:30:58",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DAVIDCARLIEZ-CVE-2026-49176_LPE_POC"
                },
                {
                    "title": "Exploit for CVE-2026-49176_LPE_POC",
                    "summary": "Local privilege escalation in Windows WalletService via ESE callback loading DLL as SYSTEM.",
                    "what_happened": "Local privilege escalation in Windows WalletService via ESE callback loading DLL as SYSTEM.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DAVIDCARLIEZ-CVE-2026-49176_LPE_POC",
                        "https://kitploit.com/en/tools/github/davidcarliez/cve-2026-49176_lpe_poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-07T18:30:58",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/davidcarliez/cve-2026-49176_lpe_poc/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DAVIDCARLIEZ-CVE-2026-49176_LPE_POC",
                "https://kitploit.com/en/tools/github/davidcarliez/cve-2026-49176_lpe_poc/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T18:31:22Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DAVIDCARLIEZ-CVE-2026-49176_LPE_POC"
                }
            ]
        },
        {
            "id": "CVE-2026-49132",
            "vendor": "Deciso B.V.",
            "product": "OPNsense",
            "title": "OPNsense vulnerability",
            "summary": "OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate description field via the trust certificate API. The unsanitized description value is persisted and later rendered in the Dashboard Certificates widget through Certificates.js, which interpolates the raw value into HTML attribute and text content sinks without encoding, causing injected scripts to execute in the browser of any authenticated user who views the Dashboard, enabling session hijacking or credential theft.",
            "updated_at": "2026-09-16T20:32:21.400",
            "published_at": "2026-08-03T21:16:39.900",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.1.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate description field via the trust certificate API. The unsanitized description value is persisted and later rendered in the Dashboard Certificates widget through Certificates.js, which interpolates the raw value into HTML attribute and text content sinks without encoding, causing injected scripts to execute in the browser of any authenticated user who views the Dashboard, enabling session hijacking or credential theft.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.opnsense.org/releases/CE_26.1.html#june-02-2026",
                "https://github.com/opnsense/core/commit/12b021ff11db38705e92ac4c9af5e07d602da6ba",
                "https://www.vulncheck.com/advisories/opnsense-stored-xss-via-certificate-description-field"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:39.900",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49132"
                }
            ]
        },
        {
            "id": "CVE-2026-49131",
            "vendor": "Deciso B.V.",
            "product": "OPNsense",
            "title": "OPNsense vulnerability",
            "summary": "OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by embedding payloads in the firewall rule description field via the filter API endpoint. The unsanitized description value is persisted and later rendered through the default cell formatter in opnsense_bootgrid.js, which assigns raw cell content to innerHTML, causing injected scripts to execute in the browser of any authenticated user who views the Firewall Rules page, enabling session hijacking or credential theft.",
            "updated_at": "2026-09-16T20:32:21.400",
            "published_at": "2026-08-03T21:16:39.750",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.1.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by embedding payloads in the firewall rule description field via the filter API endpoint. The unsanitized description value is persisted and later rendered through the default cell formatter in opnsense_bootgrid.js, which assigns raw cell content to innerHTML, causing injected scripts to execute in the browser of any authenticated user who views the Firewall Rules page, enabling session hijacking or credential theft.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.opnsense.org/releases/CE_26.1.html#june-02-2026",
                "https://github.com/opnsense/core/commit/b11d6b340716e240868ab19a369e058a46f0876f",
                "https://www.vulncheck.com/advisories/opnsense-stored-xss-via-firewall-rule-description-field"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:39.750",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49131"
                }
            ]
        },
        {
            "id": "CVE-2026-49069",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "WordPress Plugin WPZOOM Portfolio 1.4.21 -  Reflected Cross-Site Scripting (XSS)",
            "summary": "WordPress Plugin WPZOOM Portfolio 1.4.21 -  Reflected Cross-Site Scripting (XSS)",
            "updated_at": "2026-08-20T22:00:00Z",
            "published_at": "2026-08-20T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 187,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "WordPress Plugin WPZOOM Portfolio 1.4.21 Reflected Cross-Site Scripting (XSS)",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52611",
                    "author": "Kent Apostol",
                    "first_seen": "2026-07-06",
                    "confidence": "High",
                    "title": "WordPress Plugin WPZOOM Portfolio 1.4.21 -  Reflected Cross-Site Scripting (XSS)",
                    "summary": "WordPress Plugin WPZOOM Portfolio 1.4.21 -  Reflected Cross-Site Scripting (XSS)",
                    "url": "https://www.exploit-db.com/exploits/52611",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "CXSecurity WLB-2026080012",
                    "author": "Kent Apostol",
                    "first_seen": "2026-08-21",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "WordPress Plugin WPZOOM Portfolio 1.4.21 Reflected Cross-Site Scripting (XSS)",
                    "summary": "WordPress Plugin WPZOOM Portfolio 1.4.21 Reflected Cross-Site Scripting (XSS)",
                    "what_happened": "WordPress Plugin WPZOOM Portfolio 1.4.21 Reflected Cross-Site Scripting (XSS)",
                    "cvss": 0,
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "url": "https://cxsecurity.com/issue/WLB-2026080012",
                    "cwe": "Unknown"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52611",
                "https://cxsecurity.com/issue/WLB-2026080012"
            ],
            "timeline": [
                {
                    "at": "2026-08-20T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52611"
                }
            ]
        },
        {
            "id": "CVE-2026-49030",
            "vendor": "n/a",
            "product": "n/a",
            "title": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.",
            "summary": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.",
            "updated_at": "2026-09-13T22:16:59.620",
            "published_at": "2026-09-13T21:17:01.643",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: none.  Reason: This candidate was withdrawn by its CNA.  Further investigation showed that it was not a security issue.  Notes: none.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/unjs/pathe/issues/240"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:17:01.643",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49030"
                }
            ]
        },
        {
            "id": "CVE-2026-48909",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Joomla Extension 4.1.4 - PHP Object injection",
            "summary": "Joomla Extension 4.1.4 - PHP Object injection",
            "updated_at": "2026-08-11T22:00:00Z",
            "published_at": "2026-08-11T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Joomla Extension 4.1.4 PHP Object injection",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52617",
                    "author": "Amin İsayev",
                    "first_seen": "2026-07-06",
                    "confidence": "High",
                    "title": "Joomla Extension 4.1.4 - PHP Object injection",
                    "summary": "Joomla Extension 4.1.4 - PHP Object injection",
                    "url": "https://www.exploit-db.com/exploits/52617",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "CXSecurity WLB-2026080009",
                    "author": "Amin İsayev",
                    "first_seen": "2026-08-12",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Joomla Extension 4.1.4 PHP Object injection",
                    "summary": "Joomla Extension 4.1.4 PHP Object injection",
                    "what_happened": "Joomla Extension 4.1.4 PHP Object injection",
                    "cvss": 0,
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "url": "https://cxsecurity.com/issue/WLB-2026080009",
                    "cwe": "Unknown"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52617",
                "https://cxsecurity.com/issue/WLB-2026080009"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52617"
                }
            ]
        },
        {
            "id": "CVE-2026-48907",
            "vendor": "Widget Factory",
            "product": "Joomla Content Editor",
            "title": "Widget Factory Joomla Content Editor Improper Access Control Vulnerability",
            "summary": "Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.",
            "updated_at": "2026-08-26T12:34:07Z",
            "published_at": "2026-08-26T12:34:07Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1187,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-284",
            "what_happened": "Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52630",
                    "author": "Jared Brits",
                    "first_seen": "2026-08-10",
                    "confidence": "High",
                    "title": "Joomla 2.9.99.4 - Unauthenticated Remote Code Execution",
                    "summary": "Joomla 2.9.99.4 - Unauthenticated Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/52630",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 52645",
                    "author": "Jared Brits",
                    "first_seen": "2026-08-17",
                    "confidence": "High",
                    "title": "Joomla JCE_2.9.15 - Remote Code Execution",
                    "summary": "Joomla JCE_2.9.15 - Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/52645",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "CVE-Intel · K3ysTr0K3R/CVE-2026-48907",
                    "author": "K3ysTr0K3R",
                    "first_seen": "2026-06-29",
                    "last_seen": "2026-08-26T12:34:07Z",
                    "pushed_at": "2026-06-29T21:21:45Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 3,
                    "forks": 1,
                    "topics": [
                        "cve-2026-48907",
                        "exploit",
                        "joomla",
                        "joomla-rce",
                        "poc",
                        "proof-of-concept",
                        "rce"
                    ],
                    "title": "CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)",
                    "repository_description": "CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)",
                    "summary": "CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)",
                    "source": "CVE-Intel",
                    "url": "https://github.com/K3ysTr0K3R/CVE-2026-48907",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "CWE-284",
                    "kev": false,
                    "epss": 0.781,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-05",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "CVE-Intel · gh1mau/masta-cve-2026-48907",
                    "author": "gh1mau",
                    "first_seen": "2026-06-27",
                    "last_seen": "2026-08-26T12:30:58Z",
                    "pushed_at": "2026-06-27T05:25:46Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 58,
                    "forks": 11,
                    "topics": [],
                    "title": "cve-2026-48907 scanner",
                    "repository_description": "cve-2026-48907 scanner",
                    "summary": "cve-2026-48907 scanner",
                    "source": "CVE-Intel",
                    "url": "https://github.com/gh1mau/masta-cve-2026-48907",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "CWE-284",
                    "kev": false,
                    "epss": 0.781,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-05",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "CVE-Intel · ksotaria1337/-CVE-2026-48907-",
                    "author": "ksotaria1337",
                    "first_seen": "2026-08-26",
                    "last_seen": "2026-08-26T10:51:57Z",
                    "pushed_at": "2026-08-26T10:50:18Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "-CVE-2026-48907-",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/ksotaria1337/-CVE-2026-48907-",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "CWE-284",
                    "kev": false,
                    "epss": 0.781,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-05",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "CVE-Intel · CerberusMrXi/JCEzploit-CVE-2026-48907",
                    "author": "CerberusMrXi",
                    "first_seen": "2026-08-21",
                    "last_seen": "2026-08-25T20:31:01Z",
                    "pushed_at": "2026-08-21T18:25:53Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "JCEzploit is a powerful, fully-automated RCE exploit for Joomla JCE (CVE-2026-48907) featuring interactive shell, batch command execution, file download capability, and proxy support. Built with Python & Rich for penetration testers. Ethical use only. By Sudeepa Wanigarathna.",
                    "repository_description": "JCEzploit is a powerful, fully-automated RCE exploit for Joomla JCE (CVE-2026-48907) featuring interactive shell, batch command execution, file download capability, and proxy support. Built with Python & Rich for penetration testers. Ethical use only. By Sudeepa Wanigarathna.",
                    "summary": "JCEzploit is a powerful, fully-automated RCE exploit for Joomla JCE (CVE-2026-48907) featuring interactive shell, batch command execution, file download capability, and proxy support. Built with Python & Rich for penetration testers. Ethical use only. By Sudeepa Wanigarathna.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/CerberusMrXi/JCEzploit-CVE-2026-48907",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "CWE-284",
                    "kev": false,
                    "epss": 0.781,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-05",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "CVE-Intel · 0xgh057r3c0n/CVE-2026-48907",
                    "author": "0xgh057r3c0n",
                    "first_seen": "2026-06-22",
                    "last_seen": "2026-08-21T07:50:04Z",
                    "pushed_at": "2026-06-27T22:38:03Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 3,
                    "forks": 2,
                    "topics": [],
                    "title": "CVE-2025-48907 - Unauthenticated RCE exploit for Joomla JCE < 2.9.99.5",
                    "repository_description": "CVE-2025-48907 - Unauthenticated RCE exploit for Joomla JCE < 2.9.99.5",
                    "summary": "CVE-2025-48907 - Unauthenticated RCE exploit for Joomla JCE < 2.9.99.5",
                    "source": "CVE-Intel",
                    "url": "https://github.com/0xgh057r3c0n/CVE-2026-48907",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "CWE-284",
                    "kev": false,
                    "epss": 0.781,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-05",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "CVE-Intel · sec0x/CVE-2026-48907",
                    "author": "sec0x",
                    "first_seen": "2026-06-22",
                    "last_seen": "2026-08-05T00:07:31Z",
                    "pushed_at": "2026-08-05T00:07:03Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 1,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-48907",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/sec0x/CVE-2026-48907",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "CWE-284",
                    "kev": false,
                    "epss": 0.781,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-05",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "CVE-Intel · pssec-io/CVE-2026-48907",
                    "author": "pssec-io",
                    "first_seen": "2026-06-30",
                    "last_seen": "2026-07-23T10:41:43Z",
                    "pushed_at": "2026-06-30T15:37:03Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "PHP",
                    "stars": 1,
                    "forks": 0,
                    "topics": [
                        "cve-2026-48907",
                        "joomla",
                        "poc",
                        "proof-of-concept",
                        "pssec",
                        "pssec-io"
                    ],
                    "title": "POC for CVE-2026-48907",
                    "repository_description": "POC for CVE-2026-48907",
                    "summary": "POC for CVE-2026-48907",
                    "source": "CVE-Intel",
                    "url": "https://github.com/pssec-io/CVE-2026-48907",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "CWE-284",
                    "kev": false,
                    "epss": 0.781,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-05",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "CVE-Intel · ChiefYoru/CVE-2026-48907_PoC",
                    "author": "ChiefYoru",
                    "first_seen": "2026-07-19",
                    "last_seen": "2026-07-19T09:02:15Z",
                    "pushed_at": "2026-07-19T08:21:30Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 1,
                    "forks": 0,
                    "topics": [],
                    "title": "Unauthenticated Remote Code Execution (RCE) vulnerability in the JCE (Joomla Content Editor) extension for Joomla",
                    "repository_description": "Unauthenticated Remote Code Execution (RCE) vulnerability in the JCE (Joomla Content Editor) extension for Joomla",
                    "summary": "Unauthenticated Remote Code Execution (RCE) vulnerability in the JCE (Joomla Content Editor) extension for Joomla",
                    "source": "CVE-Intel",
                    "url": "https://github.com/ChiefYoru/CVE-2026-48907_PoC",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "CWE-284",
                    "kev": false,
                    "epss": 0.781,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-05",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "bayu06802/CVE-2026-48907",
                    "author": "bayu06802",
                    "first_seen": "2026-07-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Python & template nuclei",
                    "summary": "Python & template nuclei",
                    "url": "https://github.com/bayu06802/CVE-2026-48907"
                },
                {
                    "repository": "NoXiVaR/CVE-2026-48907",
                    "author": "NoXiVaR",
                    "first_seen": "2026-07-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-48907 PoC",
                    "summary": "CVE-2026-48907 PoC",
                    "url": "https://github.com/NoXiVaR/CVE-2026-48907"
                },
                {
                    "repository": "Almavj/Joomla_CVE_2026_48907",
                    "author": "Almavj",
                    "first_seen": "2026-06-29",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 0,
                    "title": "cve-2026-48907 scanner",
                    "summary": "cve-2026-48907 scanner",
                    "url": "https://github.com/Almavj/Joomla_CVE_2026_48907"
                },
                {
                    "repository": "xitexploiter96-dot/CVE-2026-48907-",
                    "author": "xitexploiter96-dot",
                    "first_seen": "2026-06-29",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-48907 repository",
                    "summary": "",
                    "url": "https://github.com/xitexploiter96-dot/CVE-2026-48907-"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52630",
                "https://www.exploit-db.com/exploits/52645",
                "https://github.com/K3ysTr0K3R/CVE-2026-48907",
                "https://github.com/gh1mau/masta-cve-2026-48907",
                "https://github.com/ksotaria1337/-CVE-2026-48907-",
                "https://github.com/CerberusMrXi/JCEzploit-CVE-2026-48907",
                "https://github.com/0xgh057r3c0n/CVE-2026-48907",
                "https://github.com/sec0x/CVE-2026-48907",
                "https://github.com/pssec-io/CVE-2026-48907",
                "https://github.com/ChiefYoru/CVE-2026-48907_PoC",
                "https://github.com/bayu06802/CVE-2026-48907",
                "https://github.com/NoXiVaR/CVE-2026-48907",
                "https://github.com/Almavj/Joomla_CVE_2026_48907",
                "https://github.com/xitexploiter96-dot/CVE-2026-48907-"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T12:34:07Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "epss": 0.781,
            "cve_status": "Awaiting Analysis",
            "cve_published_at": "2026-06-05"
        },
        {
            "id": "CVE-2026-48892",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option names were not in `sensitive_config_values`, so the masker did not redact them. An authenticated UI/API user with Config read permission could retrieve plaintext secrets-backend credentials (Vault `role_id` / `secret_id`, etc.) from the Config API output. Affects deployments that configure secrets backends via per-key environment overrides. Users are advised to upgrade to `apache-airflow` 3.3.0 or later.",
            "updated_at": "2026-09-16T15:17:36.267",
            "published_at": "2026-07-07T10:16:41.480",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option names were not in `sensitive_config_values`, so the masker did not redact them. An authenticated UI/API user with Config read permission could retrieve plaintext secrets-backend credentials (Vault `role_id` / `secret_id`, etc.) from the Config API output. Affects deployments that configure secrets backends via per-key environment overrides. Users are advised to upgrade to `apache-airflow` 3.3.0 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/67622",
                "https://lists.apache.org/thread/pq5yy40079h6tzh3fxvw28dd8dbk72hk",
                "http://www.openwall.com/lists/oss-security/2026/07/07/4"
            ],
            "timeline": [
                {
                    "at": "2026-07-07T10:16:41.480",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48892"
                }
            ]
        },
        {
            "id": "CVE-2026-48891",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of trigger / sensor dependency entries. An authenticated UI user with read permission on some Dags could enumerate the identifiers of other Dags they were not authorized to read by inspecting the dependency graph for trigger / sensor references. Affects deployments that rely on per-Dag read scoping to keep Dag identifiers private across teams. This is a residual gap in the fix for CVE-2026-28563, which filtered the top-level Dag key but did not propagate the filter into the trigger / sensor dep-source / dep-target fields. Users who already upgraded for CVE-2026-28563 should additionally upgrade to `apache-airflow` 3.3.0 or later to cover the residual trigger / sensor dependency leak.",
            "updated_at": "2026-09-16T15:17:36.110",
            "published_at": "2026-07-07T10:16:41.373",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of trigger / sensor dependency entries. An authenticated UI user with read permission on some Dags could enumerate the identifiers of other Dags they were not authorized to read by inspecting the dependency graph for trigger / sensor references. Affects deployments that rely on per-Dag read scoping to keep Dag identifiers private across teams. This is a residual gap in the fix for CVE-2026-28563, which filtered the top-level Dag key but did not propagate the filter into the trigger / sensor dep-source / dep-target fields. Users who already upgraded for CVE-2026-28563 should additionally upgrade to `apache-airflow` 3.3.0 or later to cover the residual trigger / sensor dependency leak.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/67627",
                "https://lists.apache.org/thread/wzc8nflg94rq6w8f5tvtlo0o3g4wjrfl",
                "https://www.cve.org/CVERecord?id=CVE-2026-28563"
            ],
            "timeline": [
                {
                    "at": "2026-07-07T10:16:41.373",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48891"
                }
            ]
        },
        {
            "id": "CVE-2026-48859",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication.\n\nWhen the SSH daemon is configured with the user_passwords or password option, ssh_auth:check_password/3 performs a PBKDF2-SHA256 computation with 600,000 iterations (~300ms) for valid usernames, but returns immediately (~0ms) for invalid usernames via the ssh_options:get_password_option/2 path. This timing difference is detectable in a single authentication attempt and allows an unauthenticated attacker to distinguish valid from invalid usernames.\n\nThe user_passwords and password options are documented as intended for test purposes; the recommended alternative is pwdfun, which is not affected by this vulnerability.\n\nThis vulnerability is associated with program files lib/ssh/src/ssh_auth.erl and lib/ssh/src/ssh_options.erl.\n\nThis issue affects OTP from OTP 29.0 before OTP 29.0.2, corresponding to ssh from 6.0 before 6.0.1.",
            "updated_at": "2026-09-08T01:17:31.137",
            "published_at": "2026-06-10T16:17:12.373",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "29.0 through before 29.0.2 (otp); 6.0 through before 6.0.1 (otp); 032d1bc9491a3975c68faf9bc7776115d6ae3005 through before c342092ef4b369bb409d5b71ac8fd83bab74aedf (git)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-208",
            "what_happened": "Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication.\n\nWhen the SSH daemon is configured with the user_passwords or password option, ssh_auth:check_password/3 performs a PBKDF2-SHA256 computation with 600,000 iterations (~300ms) for valid usernames, but returns immediately (~0ms) for invalid usernames via the ssh_options:get_password_option/2 path. This timing difference is detectable in a single authentication attempt and allows an unauthenticated attacker to distinguish valid from invalid usernames.\n\nThe user_passwords and password options are documented as intended for test purposes; the recommended alternative is pwdfun, which is not affected by this vulnerability.\n\nThis vulnerability is associated with program files lib/ssh/src/ssh_auth.erl and lib/ssh/src/ssh_options.erl.\n\nThis issue affects OTP from OTP 29.0 before OTP 29.0.2, corresponding to ssh from 6.0 before 6.0.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-48859.html",
                "https://github.com/erlang/otp/commit/c342092ef4b369bb409d5b71ac8fd83bab74aedf",
                "https://github.com/erlang/otp/security/advisories/GHSA-3w6p-vwhf-wvp4",
                "https://osv.dev/vulnerability/EEF-CVE-2026-48859",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions"
            ],
            "timeline": [
                {
                    "at": "2026-06-10T16:17:12.373",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48859"
                }
            ]
        },
        {
            "id": "CVE-2026-48828",
            "vendor": "Apache Software Foundation",
            "product": "Apache Airflow",
            "title": "Apache Airflow vulnerability",
            "summary": "The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodable variable values. An authenticated UI/API user with bulk Variable read permission could retrieve plaintext values from JSON variables whose key would otherwise trigger redaction. Affects deployments that store sensitive values in JSON-typed Airflow Variables under secret-suffixed key names. Users are advised to upgrade to `apache-airflow` 3.3.0 or later (the fix landed on `main` after 3.2.2; no 3.2.x backport).",
            "updated_at": "2026-09-16T15:17:35.930",
            "published_at": "2026-07-07T10:16:41.260",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodable variable values. An authenticated UI/API user with bulk Variable read permission could retrieve plaintext values from JSON variables whose key would otherwise trigger redaction. Affects deployments that store sensitive values in JSON-typed Airflow Variables under secret-suffixed key names. Users are advised to upgrade to `apache-airflow` 3.3.0 or later (the fix landed on `main` after 3.2.2; no 3.2.x backport).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/apache/airflow/pull/67495",
                "https://lists.apache.org/thread/y9kf314t6dhnv994hr11wj3tbow847yc",
                "http://www.openwall.com/lists/oss-security/2026/07/07/2"
            ],
            "timeline": [
                {
                    "at": "2026-07-07T10:16:41.260",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48828"
                }
            ]
        },
        {
            "id": "CVE-2026-48779",
            "vendor": "websockets",
            "product": "ws",
            "title": "ws vulnerability",
            "summary": "ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.",
            "updated_at": "2026-09-11T13:18:14.097",
            "published_at": "2026-06-17T13:20:42.887",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.1.0, < 5.2.5; >= 6.0.0, < 6.2.4; >= 7.0.0, < 7.5.11; >= 8.0.0, < 8.21.0",
            "fixed": "See vendor advisory",
            "source_count": 54,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-06-17",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/websockets/ws/security/advisories/GHSA-96hv-2xvq-fx4p"
                }
            ],
            "references": [
                "https://github.com/websockets/ws/commit/86d3e8a5fb0246ed373860c5fbb0de88824a27f7",
                "https://github.com/websockets/ws/commit/b5372ac67bb97a773727b8e9f5035a8123556d53",
                "https://github.com/websockets/ws/commit/bca91adf15677e47dbe4f959653452727be28b94",
                "https://github.com/websockets/ws/commit/fd36cd864fcdf62a08273a99e19a7d975401fee8",
                "https://github.com/websockets/ws/security/advisories/GHSA-96hv-2xvq-fx4p",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:33155",
                "https://access.redhat.com/errata/RHSA-2026:33160",
                "https://access.redhat.com/errata/RHSA-2026:33163",
                "https://access.redhat.com/errata/RHSA-2026:33173",
                "https://access.redhat.com/errata/RHSA-2026:33183",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:34342",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:37272",
                "https://access.redhat.com/errata/RHSA-2026:40984",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41941",
                "https://access.redhat.com/errata/RHSA-2026:41944",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:56366",
                "https://access.redhat.com/errata/RHSA-2026:56431",
                "https://access.redhat.com/errata/RHSA-2026:57013",
                "https://access.redhat.com/errata/RHSA-2026:57590",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-48779",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2489661",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48779.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-17T13:20:42.887",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48779"
                }
            ]
        },
        {
            "id": "CVE-2026-48746",
            "vendor": "vllm-project",
            "product": "vllm",
            "title": "vllm vulnerability",
            "summary": "vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.",
            "updated_at": "2026-09-16T13:18:00.653",
            "published_at": "2026-06-22T23:16:30.490",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 0.3.0, < 0.22.0",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-444",
            "what_happened": "vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API without providing the configured VLLM_API_KEY or --api-key. This vulnerability is fixed in 0.22.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/vllm-project/vllm/pull/43426",
                "https://github.com/vllm-project/vllm/security/advisories/GHSA-94f4-hr76-p5j6",
                "https://x41-dsec.de/lab/advisories/x41-2026-002-starlette",
                "https://access.redhat.com/errata/RHSA-2026:30088",
                "https://access.redhat.com/errata/RHSA-2026:30089",
                "https://access.redhat.com/errata/RHSA-2026:36005",
                "https://access.redhat.com/errata/RHSA-2026:36006",
                "https://access.redhat.com/errata/RHSA-2026:42132",
                "https://access.redhat.com/errata/RHSA-2026:42142",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:43038",
                "https://access.redhat.com/errata/RHSA-2026:61627",
                "https://access.redhat.com/errata/RHSA-2026:61629",
                "https://access.redhat.com/security/cve/CVE-2026-48746",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2491581",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48746.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-22T23:16:30.490",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48746"
                }
            ]
        },
        {
            "id": "CVE-2026-48710",
            "vendor": "Kludex",
            "product": "Starlette",
            "title": "Kludex Starlette HTTP Request/Response Smuggling Vulnerability",
            "summary": "Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 270,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CuteeCat/CVE-2026-48710",
                    "author": "CuteeCat",
                    "first_seen": "2026-08-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-48710漏洞验证代码",
                    "summary": "CVE-2026-48710漏洞验证代码",
                    "url": "https://github.com/CuteeCat/CVE-2026-48710"
                },
                {
                    "repository": "sb-ox/repro-OXDEV-77637-uv-workspace",
                    "author": "sb-ox",
                    "first_seen": "2026-08-03",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 0,
                    "title": "OXDEV-77637 repro fixture: uv workspace whose transitive CVE (starlette 0.25.0 / CVE-2026-48710) is dropped when the lean clone omits workspace-member pyproject.toml. Tag: repro-OXDEV-77637",
                    "summary": "OXDEV-77637 repro fixture: uv workspace whose transitive CVE (starlette 0.25.0 / CVE-2026-48710) is dropped when the lean clone omits workspace-member pyproject.toml. Tag: repro-OXDEV-77637",
                    "url": "https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace"
                },
                {
                    "repository": "eris-ths/supply-chain-guard",
                    "author": "eris-ths",
                    "first_seen": "2026-04-01",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 3,
                    "title": "Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during axios RAT (2026-03-31) and Starlette BadHost CVE-2026-48710 (2026-05-22).",
                    "summary": "Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during axios RAT (2026-03-31) and Starlette BadHost CVE-2026-48710 (2026-05-22).",
                    "url": "https://github.com/eris-ths/supply-chain-guard"
                },
                {
                    "repository": "Bhanunamikaze/BadHost-CVE-2026-48710-Exploit",
                    "author": "Bhanunamikaze",
                    "first_seen": "2026-05-28",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": "Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI",
                    "summary": "Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI",
                    "url": "https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit"
                },
                {
                    "repository": "xtremebeing/starlette-host-header-lab",
                    "author": "xtremebeing",
                    "first_seen": "2026-05-27",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 1,
                    "title": "Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710",
                    "summary": "Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710",
                    "url": "https://github.com/xtremebeing/starlette-host-header-lab"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/CuteeCat/CVE-2026-48710",
                "https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace",
                "https://github.com/eris-ths/supply-chain-guard",
                "https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit",
                "https://github.com/xtremebeing/starlette-host-header-lab"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-48611",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for nns-ctf-php-is-my-passion CVE-2026-48611",
            "summary": "Outdated phpBB version vulnerability exploited in CTF to gain administrator access.",
            "updated_at": "2026-09-11T17:29:33Z",
            "published_at": "2026-09-11T17:29:33Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 42,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Outdated phpBB version vulnerability exploited in CTF to gain administrator access.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-11T19:20:28+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "nns-ctf-php-is-my-passion exploit",
                    "summary": "Proof-of-concept exploit for CVE-2026-48611. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=62D7394D-F264-50EA-8659-5CA513BCC4B7"
                },
                {
                    "title": "Exploit for nns-ctf-php-is-my-passion CVE-2026-48611",
                    "summary": "Outdated phpBB version vulnerability exploited in CTF to gain administrator access.",
                    "what_happened": "Outdated phpBB version vulnerability exploited in CTF to gain administrator access.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=62D7394D-F264-50EA-8659-5CA513BCC4B7",
                        "https://github.com/1Lance1/nns-ctf-php-is-my-passion"
                    ],
                    "repository": "1Lance1/nns-ctf-php-is-my-passion",
                    "author": "1Lance1",
                    "first_seen": "2026-09-11T19:29:33",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://github.com/1Lance1/nns-ctf-php-is-my-passion"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=62D7394D-F264-50EA-8659-5CA513BCC4B7",
                "https://github.com/1Lance1/nns-ctf-php-is-my-passion"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T17:29:33Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=62D7394D-F264-50EA-8659-5CA513BCC4B7"
                }
            ],
            "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-48523",
            "vendor": "jpadilla",
            "product": "pyjwt",
            "title": "pyjwt vulnerability",
            "summary": "PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, advertise an allowed algorithm in the JWT header, and still be accepted. The issue affects the documented PyJWKClient.get_signing_key_from_jwt(...) flow. This vulnerability is fixed in 2.13.0.",
            "updated_at": "2026-09-16T20:16:33.817",
            "published_at": "2026-05-28T16:16:29.280",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 80,
            "confidence_label": "verified",
            "affected": ">= 2.9.0, < 2.13.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-347",
            "what_happened": "PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, advertise an allowed algorithm in the JWT header, and still be accepted. The issue affects the documented PyJWKClient.get_signing_key_from_jwt(...) flow. This vulnerability is fixed in 2.13.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-28",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f"
                }
            ],
            "references": [
                "https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f"
            ],
            "timeline": [
                {
                    "at": "2026-05-28T16:16:29.280",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48523"
                }
            ]
        },
        {
            "id": "CVE-2026-48162",
            "vendor": "wazuh",
            "product": "wazuh",
            "title": "wazuh vulnerability",
            "summary": "Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI.send_tmp_file() in framework/wazuh/core/cluster/dapi/dapi.py joins an attacker-controlled tmp_file value to WAZUH_PATH without canonicalization or confinement. A cluster peer holding the shared Fernet key can use traversal or an absolute path to make the master return any readable file over the cluster channel. Reading /var/ossec/api/configuration/security/private_key.pem allows the peer to forge administrator REST API tokens offline and then exercise administrative privileges without creating an account. This issue is fixed in versions 4.14.6 and 5.0.0-beta3.",
            "updated_at": "2026-09-15T19:24:45.713",
            "published_at": "2026-08-19T17:18:51.233",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.0.0, < 4.14.6; >= 5.0.0-beta1, < 5.0.0-beta3",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-73",
            "what_happened": "Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI.send_tmp_file() in framework/wazuh/core/cluster/dapi/dapi.py joins an attacker-controlled tmp_file value to WAZUH_PATH without canonicalization or confinement. A cluster peer holding the shared Fernet key can use traversal or an absolute path to make the master return any readable file over the cluster channel. Reading /var/ossec/api/configuration/security/private_key.pem allows the peer to forge administrator REST API tokens offline and then exercise administrative privileges without creating an account. This issue is fixed in versions 4.14.6 and 5.0.0-beta3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-19",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc"
                }
            ],
            "references": [
                "https://github.com/wazuh/wazuh/commit/de1eeedbe336744934be4e20d87d84a76e438cee",
                "https://github.com/wazuh/wazuh/pull/36246",
                "https://github.com/wazuh/wazuh/releases/tag/v4.14.6",
                "https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta3",
                "https://github.com/wazuh/wazuh/security/advisories/GHSA-r6f5-h662-8ffc"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T17:18:51.233",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48162"
                }
            ]
        },
        {
            "id": "CVE-2026-48154",
            "vendor": "pilinux",
            "product": "gorest",
            "title": "gorest vulnerability",
            "summary": "GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronized package-level map used to store 2FA secrets. Multiple HTTP handlers in handler/login.go and handler/twoFA.go read from and write to this map concurrently, and because Go's runtime treats unsynchronized concurrent map access as an unrecoverable fatal error, an attacker can repeatedly trigger this condition to crash the process on demand. This results in high, repeatable availability impact with no confidentiality or integrity consequences. This issue has been fixed in version 1.12.2.",
            "updated_at": "2026-09-10T20:37:00.427",
            "published_at": "2026-08-04T20:16:52.017",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.12.2",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronized package-level map used to store 2FA secrets. Multiple HTTP handlers in handler/login.go and handler/twoFA.go read from and write to this map concurrently, and because Go's runtime treats unsynchronized concurrent map access as an unrecoverable fatal error, an attacker can repeatedly trigger this condition to crash the process on demand. This results in high, repeatable availability impact with no confidentiality or integrity consequences. This issue has been fixed in version 1.12.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pilinux/gorest/commit/117ff55fc21b47442da07c44c30b403af2da407b",
                "https://github.com/pilinux/gorest/pull/391",
                "https://github.com/pilinux/gorest/security/advisories/GHSA-cpwg-x64r-rgwg"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T20:16:52.017",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48154"
                }
            ]
        },
        {
            "id": "CVE-2026-48113",
            "vendor": "jpillora",
            "product": "chisel",
            "title": "chisel vulnerability",
            "summary": "Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and tunnel traffic to arbitrary destinations reachable from the server. The ACL is enforced only during the initial handshake against declared remotes, but never on subsequent SSH channels that carry actual traffic. A malicious client can authenticate with a permitted remote, then open channels to any host:port it wants. This issue has been fixed in version 1.11.5.",
            "updated_at": "2026-09-10T20:36:14.340",
            "published_at": "2026-08-03T21:16:39.597",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.11.5",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and tunnel traffic to arbitrary destinations reachable from the server. The ACL is enforced only during the initial handshake against declared remotes, but never on subsequent SSH channels that carry actual traffic. A malicious client can authenticate with a permitted remote, then open channels to any host:port it wants. This issue has been fixed in version 1.11.5.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jpillora/chisel/commit/44310b65667a97901874ffdf4815b3732c22eaa3",
                "https://github.com/jpillora/chisel/security/advisories/GHSA-24fp-5v3p-rvpw"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:39.597",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48113"
                }
            ]
        },
        {
            "id": "CVE-2026-48098",
            "vendor": "0x5t4l1n",
            "product": "NexTOR_IP_CHANGER",
            "title": "NexTOR_IP_CHANGER vulnerability",
            "summary": "NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute privileged system commands using `sudo` and `shell=True` directly inside application logic. In environments where passwordless sudo (`NOPASSWD`) is enabled, privileged commands may execute silently without explicit user confirmation. Version 2.0.0 fixes the issue.",
            "updated_at": "2026-09-10T20:42:39.707",
            "published_at": "2026-08-07T19:17:47.780",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.0.0",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute privileged system commands using `sudo` and `shell=True` directly inside application logic. In environments where passwordless sudo (`NOPASSWD`) is enabled, privileged commands may execute silently without explicit user confirmation. Version 2.0.0 fixes the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/0x5t4l1n/NexTOR_IP_CHANGER/security/advisories/GHSA-fpxg-q9p5-5wvm"
            ],
            "timeline": [
                {
                    "at": "2026-08-07T19:17:47.780",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48098"
                }
            ]
        },
        {
            "id": "CVE-2026-48097",
            "vendor": "0x5t4l1n",
            "product": "NexTOR_IP_CHANGER",
            "title": "NexTOR_IP_CHANGER vulnerability",
            "summary": "NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of `shell=True` with commands that rely on executable resolution through the `PATH` environment variable. An attacker controlling the execution environment can place malicious executables such as sudo earlier in the `PATH`, resulting in execution of attacker-controlled code. Version 2.0.0 fixes the issue.",
            "updated_at": "2026-09-10T20:42:39.707",
            "published_at": "2026-08-07T19:17:47.627",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.0.0",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of `shell=True` with commands that rely on executable resolution through the `PATH` environment variable. An attacker controlling the execution environment can place malicious executables such as sudo earlier in the `PATH`, resulting in execution of attacker-controlled code. Version 2.0.0 fixes the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/0x5t4l1n/NexTOR_IP_CHANGER/releases/tag/v2.0",
                "https://github.com/0x5t4l1n/NexTOR_IP_CHANGER/security/advisories/GHSA-vx6r-vwjq-567w"
            ],
            "timeline": [
                {
                    "at": "2026-08-07T19:17:47.627",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48097"
                }
            ]
        },
        {
            "id": "CVE-2026-48094",
            "vendor": "dartiss",
            "product": "shareopenly",
            "title": "shareopenly vulnerability",
            "summary": "The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the absence of WordPress's `esc_url()` escaping function on the `$url` variable before it is rendered into HTML content. This variable is constructed from `home_url( add_query_arg( array(), $wp->request ) )` and is concatenated directly into an HTML `href` attribute on every singular post or page where the plugin's sharing link is displayed. WordPress's security handbook mandates that every URL placed in HTML output must be passed through `esc_url()`, which both HTML-encodes special characters (converting `\"`, `<`, `>` into their safe HTML entity equivalents) and strips dangerous URI schemes such as `javascript:` and `data:`. The omission of this function means that if the `$url` value ever contains HTML-special characters or a dangerous URI scheme — through a `home_url` WordPress filter applied by another plugin or theme, through certain web server or hosting configurations, or through future code changes — the unescaped content will be injected verbatim into the rendered HTML of every post or page on the site. Version 1.2.1 contains a patch for the issue.",
            "updated_at": "2026-09-10T20:42:39.707",
            "published_at": "2026-08-07T13:16:49.493",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.2.1",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the absence of WordPress's `esc_url()` escaping function on the `$url` variable before it is rendered into HTML content. This variable is constructed from `home_url( add_query_arg( array(), $wp->request ) )` and is concatenated directly into an HTML `href` attribute on every singular post or page where the plugin's sharing link is displayed. WordPress's security handbook mandates that every URL placed in HTML output must be passed through `esc_url()`, which both HTML-encodes special characters (converting `\"`, `<`, `>` into their safe HTML entity equivalents) and strips dangerous URI schemes such as `javascript:` and `data:`. The omission of this function means that if the `$url` value ever contains HTML-special characters or a dangerous URI scheme — through a `home_url` WordPress filter applied by another plugin or theme, through certain web server or hosting configurations, or through future code changes — the unescaped content will be injected verbatim into the rendered HTML of every post or page on the site. Version 1.2.1 contains a patch for the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/dartiss/shareopenly/commit/faf58f0497f3a024ea52c425122ef5aa22e0d7f6",
                "https://github.com/dartiss/shareopenly/releases/tag/1.2.1",
                "https://github.com/dartiss/shareopenly/security/advisories/GHSA-v43f-f7jq-7hh5"
            ],
            "timeline": [
                {
                    "at": "2026-08-07T13:16:49.493",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48094"
                }
            ]
        },
        {
            "id": "CVE-2026-48063",
            "vendor": "WhiskeySockets",
            "product": "Baileys",
            "title": "Baileys vulnerability",
            "summary": "Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session  can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload. This allows anyone to spoof messages. The same exploit also allows an attacker to corrupt the app state sync system by sending fake key shares, and also allows for history sync spoofing which also serves the same problem, injecting fake previous context or \"on-demand\" sync. This issue has been fixed in versions 6.7.22 and 7.0.0-rc12.",
            "updated_at": "2026-09-10T20:31:16.483",
            "published_at": "2026-08-03T21:16:39.450",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 6.7.22; >= 7.0.0-rc.1, < 7.0.0-rc12",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-290",
            "what_happened": "Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session  can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload. This allows anyone to spoof messages. The same exploit also allows an attacker to corrupt the app state sync system by sending fake key shares, and also allows for history sync spoofing which also serves the same problem, injecting fake previous context or \"on-demand\" sync. This issue has been fixed in versions 6.7.22 and 7.0.0-rc12.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WhiskeySockets/Baileys/commit/3beb08eecfcb4e65722e674034bd84fb11a9de35",
                "https://github.com/WhiskeySockets/Baileys/security/advisories/GHSA-qvv5-jq5g-4cgg"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:39.450",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48063"
                }
            ]
        },
        {
            "id": "CVE-2026-48061",
            "vendor": "litestar-org",
            "product": "litestar",
            "title": "litestar vulnerability",
            "summary": "Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whitelisted domain. The AllowedHostsMiddleware trusts the X-Forwarded-Host header as a fallback when the Host header is absent. Since X-Forwarded-Host is a client-controllable header, this enables host header injection attacks such as password reset poisoning, cache poisoning, and server-side request routing manipulation. Any application using AllowedHostsConfig is affected when deployed without a reverse proxy that strips X-Forwarded-Host, or when accepting HTTP/1.0 connections. This issue has been fixed in version 2.22.0.",
            "updated_at": "2026-09-10T20:37:00.427",
            "published_at": "2026-08-03T21:16:39.303",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.22.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-644",
            "what_happened": "Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whitelisted domain. The AllowedHostsMiddleware trusts the X-Forwarded-Host header as a fallback when the Host header is absent. Since X-Forwarded-Host is a client-controllable header, this enables host header injection attacks such as password reset poisoning, cache poisoning, and server-side request routing manipulation. Any application using AllowedHostsConfig is affected when deployed without a reverse proxy that strips X-Forwarded-Host, or when accepting HTTP/1.0 connections. This issue has been fixed in version 2.22.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/litestar-org/litestar/commit/6930a20ceb543912cd651b42deae5b9f3637a262",
                "https://github.com/litestar-org/litestar/security/advisories/GHSA-3qmc-cj7q-62hv"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:39.303",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48061"
                }
            ]
        },
        {
            "id": "CVE-2026-48059",
            "vendor": "netty",
            "product": "netty",
            "title": "netty vulnerability",
            "summary": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested `PP2_TYPE_SSL` TLVs (type-length-value records) at depth two or greater. The leak occurs on the successful parse path — no exception is thrown, the message fires downstream, the decoder removes itself, and the application releases the `HAProxyMessage` normally. Yet the underlying cumulation buffer (a pooled, potentially direct `ByteBuf` allocated by the channel) remains permanently pinned. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
            "updated_at": "2026-09-11T13:18:13.667",
            "published_at": "2026-06-12T16:16:30.720",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 4.2.0.Final, < 4.2.15.Final; < 4.1.135.Final",
            "fixed": "See vendor advisory",
            "source_count": 20,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-401",
            "what_happened": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native or heap memory on every connection when a client sends a syntactically valid header containing nested `PP2_TYPE_SSL` TLVs (type-length-value records) at depth two or greater. The leak occurs on the successful parse path — no exception is thrown, the message fires downstream, the decoder removes itself, and the application releases the `HAProxyMessage` normally. Yet the underlying cumulation buffer (a pooled, potentially direct `ByteBuf` allocated by the channel) remains permanently pinned. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final",
                "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final",
                "https://github.com/netty/netty/security/advisories/GHSA-h2qv-fj59-j46j",
                "https://access.redhat.com/errata/RHSA-2026:26017",
                "https://access.redhat.com/errata/RHSA-2026:26018",
                "https://access.redhat.com/errata/RHSA-2026:26586",
                "https://access.redhat.com/errata/RHSA-2026:34608",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:37390",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:50085",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/security/cve/CVE-2026-48059",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2488437",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48059.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-12T16:16:30.720",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48059"
                }
            ]
        },
        {
            "id": "CVE-2026-48054",
            "vendor": "OpenZeppelin",
            "product": "contracts-wizard",
            "title": "contracts-wizard vulnerability",
            "summary": "OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `opts.name` (ERC20/ERC721) and `opts.uri` (ERC1155) directly into TypeScript string literals at `zip-hardhat.ts:48` and `:50` without any JavaScript string escaping. No authentication is required: an attacker crafts a URL such as `https[:]//wizard[.]openzeppelin[.]com/#/erc20?name=\");require(\"child_process\").execSync(\"...\");(\"` and shares it with a developer. When the victim downloads the resulting zip archive and runs `npx hardhat test`, the injected Node.js code executes with the developer's local OS privileges. Version 0.10.9 fixes the issue.",
            "updated_at": "2026-09-14T18:17:48.623",
            "published_at": "2026-08-06T22:17:09.530",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 0.10.9",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `opts.name` (ERC20/ERC721) and `opts.uri` (ERC1155) directly into TypeScript string literals at `zip-hardhat.ts:48` and `:50` without any JavaScript string escaping. No authentication is required: an attacker crafts a URL such as `https[:]//wizard[.]openzeppelin[.]com/#/erc20?name=\");require(\"child_process\").execSync(\"...\");(\"` and shares it with a developer. When the victim downloads the resulting zip archive and runs `npx hardhat test`, the injected Node.js code executes with the developer's local OS privileges. Version 0.10.9 fixes the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/OpenZeppelin/contracts-wizard/commit/ec12c44f8d9e0491eba31037f95b36e98ec58b5f",
                "https://github.com/OpenZeppelin/contracts-wizard/releases/tag/%40openzeppelin%2Fwizard%400.10.9",
                "https://github.com/OpenZeppelin/contracts-wizard/security/advisories/GHSA-4x76-22x2-rx8v"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:17:09.530",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48054"
                }
            ]
        },
        {
            "id": "CVE-2026-48043",
            "vendor": "netty",
            "product": "netty",
            "title": "netty vulnerability",
            "summary": "Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it. A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
            "updated_at": "2026-09-11T13:18:13.180",
            "published_at": "2026-06-12T16:16:30.587",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 4.2.0.Final, < 4.2.15.Final; < 4.1.135.Final",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListener` class orchestrates HTTP/2 decompression by embedding a per-stream `EmbeddedChannel` that runs the appropriate decompression codec (gzip, deflate, zstd) and forwards decompressed chunks to a wrapped listener. Each decompressed chunk is a pooled `ByteBuf` handed to an anonymous `ChannelInboundHandlerAdapter` tail handler, which becomes the sole owner responsible for releasing it. A remote peer could send frames that would result in the flow-controller throwing and so trigger a resource leak which at the end might take down the whole JVM due OOME. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final",
                "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final",
                "https://github.com/netty/netty/security/advisories/GHSA-c2gf-v879-257j",
                "https://access.redhat.com/errata/RHSA-2026:26017",
                "https://access.redhat.com/errata/RHSA-2026:26018",
                "https://access.redhat.com/errata/RHSA-2026:26586",
                "https://access.redhat.com/errata/RHSA-2026:34608",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:37390",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:48124",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:50085",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/security/cve/CVE-2026-48043",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2488442",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48043.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-12T16:16:30.587",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48043"
                }
            ]
        },
        {
            "id": "CVE-2026-48039",
            "vendor": "pipeboard-co",
            "product": "meta-ads-mcp",
            "title": "meta-ads-mcp vulnerability",
            "summary": "Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers without issuing a `401` response, allowing any network-reachable caller to invoke MCP tools without authentication. When no per-request credential is present, tool handlers fall back to the `META_ACCESS_TOKEN` environment variable, and when the downstream Meta Graph API call fails, `api.py:263–269` serialises the raw `httpx` request URL—including the operator's `access_token` as a query parameter—into the JSON-RPC response body, delivering the credential to the unauthenticated caller. Version 1.0.109 fixes the issue.",
            "updated_at": "2026-09-10T20:42:39.707",
            "published_at": "2026-08-07T20:16:51.723",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.0.109",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool handlers without issuing a `401` response, allowing any network-reachable caller to invoke MCP tools without authentication. When no per-request credential is present, tool handlers fall back to the `META_ACCESS_TOKEN` environment variable, and when the downstream Meta Graph API call fails, `api.py:263–269` serialises the raw `httpx` request URL—including the operator's `access_token` as a query parameter—into the JSON-RPC response body, delivering the credential to the unauthenticated caller. Version 1.0.109 fixes the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pipeboard-co/meta-ads-mcp/releases/tag/1.0.109",
                "https://github.com/pipeboard-co/meta-ads-mcp/security/advisories/GHSA-9gw6-46qc-99vr",
                "https://github.com/pypa/advisory-database/tree/main/vulns/meta-ads-mcp/PYSEC-2026-413.yaml"
            ],
            "timeline": [
                {
                    "at": "2026-08-07T20:16:51.723",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48039"
                }
            ]
        },
        {
            "id": "CVE-2026-48031",
            "vendor": "dhax",
            "product": "go-base",
            "title": "go-base vulnerability",
            "summary": "go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string \"random\", letting any attacker who reads the public repository forge tokens for arbitrary users, including admin roles, and completely bypass authentication on all protected endpoints. This value is set in two places: the dev.env template (line 10) and a programmatic fallback in cmd/serve.go (line 35), so the application uses it even when no .env file is present. The original mitigation in auth/jwt/tokenauth.go (lines 22 to 25) only caught the exact string \"random\", letting other weak secrets through, and replaced it with an in-memory key that was not persisted, invalidating all tokens on every restart and effectively causing a denial-of-service. This issue has been fixed in version 2026-05-18.",
            "updated_at": "2026-09-10T20:31:16.483",
            "published_at": "2026-08-03T20:17:24.200",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2026-05-18",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-798",
            "what_happened": "go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string \"random\", letting any attacker who reads the public repository forge tokens for arbitrary users, including admin roles, and completely bypass authentication on all protected endpoints. This value is set in two places: the dev.env template (line 10) and a programmatic fallback in cmd/serve.go (line 35), so the application uses it even when no .env file is present. The original mitigation in auth/jwt/tokenauth.go (lines 22 to 25) only caught the exact string \"random\", letting other weak secrets through, and replaced it with an in-memory key that was not persisted, invalidating all tokens on every restart and effectively causing a denial-of-service. This issue has been fixed in version 2026-05-18.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/dhax/go-base/commit/cc82b9740fa6b08e0fad409cd4b418e240dd0e00",
                "https://github.com/dhax/go-base/pull/31",
                "https://github.com/dhax/go-base/security/advisories/GHSA-mqq6-462x-jxmm"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T20:17:24.200",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48031"
                }
            ]
        },
        {
            "id": "CVE-2026-48024",
            "vendor": "wazuh",
            "product": "wazuh",
            "title": "wazuh vulnerability",
            "summary": "Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerge_info() in framework/wazuh/core/cluster/cluster.py constructs paths from peer-controlled merge_type and name values in a merged synchronization archive. process_files_from_worker() in framework/wazuh/core/cluster/master.py does not adequately confine the resulting path to the declared cluster item directory. A cluster peer holding the shared Fernet key can use traversal in files_metadata.json or a merged-file header to write files such as /var/ossec/etc/ossec.conf. Replacing ossec.conf can configure root-executed commands and lead to code execution when Wazuh services reload. This issue is fixed in versions 4.14.6 and 5.0.0-beta3.",
            "updated_at": "2026-09-15T19:25:16.253",
            "published_at": "2026-08-19T17:18:51.093",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.0.0, < 4.14.6; >= 5.0.0-beta1, < 5.0.0-beta3",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerge_info() in framework/wazuh/core/cluster/cluster.py constructs paths from peer-controlled merge_type and name values in a merged synchronization archive. process_files_from_worker() in framework/wazuh/core/cluster/master.py does not adequately confine the resulting path to the declared cluster item directory. A cluster peer holding the shared Fernet key can use traversal in files_metadata.json or a merged-file header to write files such as /var/ossec/etc/ossec.conf. Replacing ossec.conf can configure root-executed commands and lead to code execution when Wazuh services reload. This issue is fixed in versions 4.14.6 and 5.0.0-beta3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-19",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc"
                }
            ],
            "references": [
                "https://github.com/wazuh/wazuh/commit/88fc89fdfb1bf37b9d826e9c281a3d22655733de",
                "https://github.com/wazuh/wazuh/pull/36204",
                "https://github.com/wazuh/wazuh/releases/tag/v4.14.6",
                "https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta3",
                "https://github.com/wazuh/wazuh/security/advisories/GHSA-gh4h-fx78-q8xc"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T17:18:51.093",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48024"
                }
            ]
        },
        {
            "id": "CVE-2026-47858",
            "vendor": "Spring",
            "product": "Spring Tools for Eclipse",
            "title": "Spring Tools for Eclipse vulnerability",
            "summary": "Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution.\nAffected Spring Products and Versions:\nSpring Tools for Eclipse: 5.2.0 and earlier\nSpring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier",
            "updated_at": "2026-09-08T20:06:31.953",
            "published_at": "2026-07-30T06:25:52.120",
            "cvss": 8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 5.2.0 (custom); 0 through 2.2.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution.\nAffected Spring Products and Versions:\nSpring Tools for Eclipse: 5.2.0 and earlier\nSpring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://spring.io/security/cve-2026-47858"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T06:25:52.120",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47858"
                }
            ]
        },
        {
            "id": "CVE-2026-47718",
            "vendor": "frangoteam",
            "product": "FUXA",
            "title": "FUXA vulnerability",
            "summary": "FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue.",
            "updated_at": "2026-09-16T13:42:42.783",
            "published_at": "2026-08-12T23:17:20.783",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "= 1.3.0-2773",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/frangoteam/FUXA/releases/tag/v1.3.1",
                "https://github.com/frangoteam/FUXA/security/advisories/GHSA-r9g5-7q8j-958c"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T23:17:20.783",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47718"
                }
            ]
        },
        {
            "id": "CVE-2026-47717",
            "vendor": "frangoteam",
            "product": "FUXA",
            "title": "FUXA vulnerability",
            "summary": "FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.",
            "updated_at": "2026-09-16T13:42:42.757",
            "published_at": "2026-08-12T23:17:20.643",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "= 1.3.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-201",
            "what_happened": "FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/frangoteam/FUXA/releases/tag/v1.3.1",
                "https://github.com/frangoteam/FUXA/security/advisories/GHSA-q3w6-q3hc-c5x6"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T23:17:20.643",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47717"
                }
            ]
        },
        {
            "id": "CVE-2026-47682",
            "vendor": "cvat-ai",
            "product": "cvat",
            "title": "cvat vulnerability",
            "summary": "CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage that's been added to a CVAT instance, or ability to add new cloud storages, is able to overwrite arbitrary files on the server's filesystem. This issue has been fixed in version 2.65.0.",
            "updated_at": "2026-09-10T20:36:14.340",
            "published_at": "2026-08-04T20:16:51.747",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 1.6.0< 2.65.0",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage that's been added to a CVAT instance, or ability to add new cloud storages, is able to overwrite arbitrary files on the server's filesystem. This issue has been fixed in version 2.65.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cvat-ai/cvat/commit/6fda3e3285a185ae50039d1af8c8f0e9319b671c",
                "https://github.com/cvat-ai/cvat/security/advisories/GHSA-6f87-4g86-p9gw"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T20:16:51.747",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47682"
                }
            ]
        },
        {
            "id": "CVE-2026-47211",
            "vendor": "Q00",
            "product": "ouroboros",
            "title": "ouroboros vulnerability",
            "summary": "Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user clones a malicious repository and runs Ouroboros commands within that directory, it can lead to arbitrary code execution and potential system takeover. The vulnerability stems from Ouroboros loading the .env file from the current working directory. Execution-affecting environment variables such as OUROBOROS_CLI_PATH, OPENCODE_CLI_PATH, and other backend selectors are accepted directly from this local .env. An attacker can include a malicious script in the repository and point the CLI path variable to it (e.g., OUROBOROS_CLI_PATH=./malicious_script.sh). When the user executes a command like ouroboros init or any command that instantiates the adapter, the malicious script is executed instead of the intended CLI. This issue has been fixed in version 0.39.0.",
            "updated_at": "2026-09-10T20:31:16.483",
            "published_at": "2026-08-03T20:17:24.030",
            "cvss": 8.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 0.39.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-426",
            "what_happened": "Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user clones a malicious repository and runs Ouroboros commands within that directory, it can lead to arbitrary code execution and potential system takeover. The vulnerability stems from Ouroboros loading the .env file from the current working directory. Execution-affecting environment variables such as OUROBOROS_CLI_PATH, OPENCODE_CLI_PATH, and other backend selectors are accepted directly from this local .env. An attacker can include a malicious script in the repository and point the CLI path variable to it (e.g., OUROBOROS_CLI_PATH=./malicious_script.sh). When the user executes a command like ouroboros init or any command that instantiates the adapter, the malicious script is executed instead of the intended CLI. This issue has been fixed in version 0.39.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Q00/ouroboros/commit/4e70b760b4eb157469b58645339ba831f6513d37",
                "https://github.com/Q00/ouroboros/pull/1078",
                "https://github.com/Q00/ouroboros/security/advisories/GHSA-c4m7-2gwp-vw76"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T20:17:24.030",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-47211"
                }
            ]
        },
        {
            "id": "CVE-2026-46817",
            "vendor": "Oracle",
            "product": "E-Business Suite",
            "title": "Oracle E-Business Suite Improper Privilege Management Vulnerability",
            "summary": "Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.",
            "updated_at": "2026-07-14T22:00:00Z",
            "published_at": "2026-07-14T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-07-14T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-46728",
            "vendor": "denx",
            "product": "U-Boot",
            "title": "U-Boot vulnerability",
            "summary": "Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.",
            "updated_at": "2026-09-11T15:55:09.027",
            "published_at": "2026-05-16T22:16:13.317",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 2026.04 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-346",
            "what_happened": "Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-16",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4"
                }
            ],
            "references": [
                "https://github.com/barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4",
                "https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241"
            ],
            "timeline": [
                {
                    "at": "2026-05-16T22:16:13.317",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46728"
                }
            ]
        },
        {
            "id": "CVE-2026-46595",
            "vendor": "golang.org/x/crypto",
            "product": "golang.org/x/crypto/ssh",
            "title": "golang.org/x/crypto/ssh vulnerability",
            "summary": "Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.",
            "updated_at": "2026-09-11T13:18:12.367",
            "published_at": "2026-05-22T04:16:25.550",
            "cvss": 10,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.52.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/781642",
                "https://go.dev/issue/79570",
                "https://groups.google.com/g/golang-announce/c/a082jnz-LvI",
                "https://pkg.go.dev/vuln/GO-2026-5023",
                "https://access.redhat.com/errata/RHSA-2026:23262",
                "https://access.redhat.com/errata/RHSA-2026:23264",
                "https://access.redhat.com/errata/RHSA-2026:26546",
                "https://access.redhat.com/errata/RHSA-2026:26547",
                "https://access.redhat.com/errata/RHSA-2026:30650",
                "https://access.redhat.com/errata/RHSA-2026:30651",
                "https://access.redhat.com/errata/RHSA-2026:33524",
                "https://access.redhat.com/errata/RHSA-2026:33531",
                "https://access.redhat.com/errata/RHSA-2026:36207",
                "https://access.redhat.com/errata/RHSA-2026:36648",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:36797",
                "https://access.redhat.com/errata/RHSA-2026:36808",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:37275",
                "https://access.redhat.com/errata/RHSA-2026:37387",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41036",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43692",
                "https://access.redhat.com/errata/RHSA-2026:47737",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:54531",
                "https://access.redhat.com/errata/RHSA-2026:59467",
                "https://access.redhat.com/errata/RHSA-2026:59558",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:61314",
                "https://access.redhat.com/errata/RHSA-2026:66022",
                "https://access.redhat.com/errata/RHSA-2026:66521",
                "https://access.redhat.com/security/cve/CVE-2026-46595",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2480689",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46595.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-22T04:16:25.550",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46595"
                }
            ]
        },
        {
            "id": "CVE-2026-46579",
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4.12",
            "title": "Red Hat OpenShift Container Platform 4.12 vulnerability",
            "summary": "A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.",
            "updated_at": "2026-09-09T15:17:07.280",
            "published_at": "2026-05-29T11:16:17.050",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 27,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-287",
            "what_happened": "A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:27009",
                "https://access.redhat.com/errata/RHSA-2026:27044",
                "https://access.redhat.com/errata/RHSA-2026:27063",
                "https://access.redhat.com/errata/RHSA-2026:37580",
                "https://access.redhat.com/errata/RHSA-2026:40022",
                "https://access.redhat.com/errata/RHSA-2026:40828",
                "https://access.redhat.com/errata/RHSA-2026:43227",
                "https://access.redhat.com/errata/RHSA-2026:43253",
                "https://access.redhat.com/errata/RHSA-2026:43331",
                "https://access.redhat.com/errata/RHSA-2026:47703",
                "https://access.redhat.com/errata/RHSA-2026:47728",
                "https://access.redhat.com/security/cve/CVE-2026-46579",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2483181",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46579.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-29T11:16:17.050",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46579"
                }
            ]
        },
        {
            "id": "CVE-2026-46333",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-46333 exploit",
            "summary": "Exploit for CVE-2026-46333. CVSS 7.8.",
            "updated_at": "2026-09-07T19:19:32Z",
            "published_at": "2026-09-07T19:19:32Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 34,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-07T19:19:32+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2026-46333 exploit",
                    "summary": "Exploit for CVE-2026-46333. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-STUDIOGANGSTER-CVE-2026-46333"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-STUDIOGANGSTER-CVE-2026-46333"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:19:32Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-STUDIOGANGSTER-CVE-2026-46333"
                }
            ]
        },
        {
            "id": "CVE-2026-46331",
            "vendor": "Linux",
            "product": "Linux",
            "title": "CVE-2026-46331",
            "summary": "CVE-2026-46331",
            "updated_at": "2026-09-02T13:17:55.903",
            "published_at": "2026-06-16T08:16:23.993",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "abe35bf3be51482593076d516a680d79e5fbc8e1 through before 544d857b42a1734b923040e13aa61a6fd4746cf2 (git); b773640d5bb9e2acfd91e2695717af04d47aa116 through before d5d01d35a5a7d36f7cb679b67d9cbdd5205672dc (git); 8b796475fd7882663a870456466a4fb315cc1bd6 through before a071e057518decc5e3bec89855758f5f8786f2c5 (git); 8b796475fd7882663a870456466a4fb315cc1bd6 through before b685d6ef6f07a3b5ce814565a25f39f2157538a5 (git); 8b796475fd7882663a870456466a4fb315cc1bd6 through before 2bec122b9fb91507a758ab5e3e5c4fbe7cb3f61b (git); 8b796475fd7882663a870456466a4fb315cc1bd6 through before b198ed4e52580a7238c7c7082f03906f8b310313 (git); 8b796475fd7882663a870456466a4fb315cc1bd6 through before 3dee9d0c198faeb95d052c1b94c2958751a28512 (git); 8b796475fd7882663a870456466a4fb315cc1bd6 through before 899ee91156e57784090c5565e4f31bd7dbffbc5a (git); d0c38a914b0c4c21d553da801003d36979016726 (git); 2ec2dd7d51a9320151f275ddbb2b53260fb32ca1 (git); c19cc520b3d69904e9518d401ad0df7f4702aca0 (git); 5.10.117 through before 5.10.260 (semver); 5.15.41 through before 5.15.211 (semver); 4.19.244 through before 4.20 (semver); 5.4.195 through before 5.5 (semver); 5.17.9 through before 5.18 (semver); 5.18",
            "fixed": "See vendor advisory",
            "source_count": 985,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix pedit partial COW leading to page cache corruption\n\ntcf_pedit_act() computes the COW range for skb_ensure_writable()\nonce before the key loop using tcfp_off_max_hint, but the hint does\nnot account for the runtime header offset added by typed keys. This\ncan leave part of the write region un-COW'd.\n\nFix by moving skb_ensure_writable() inside the per-key loop where\nthe actual write offset is known, and add overflow checking on the\noffset arithmetic. For negative offsets (e.g. Ethernet header edits\nat ingress), use skb_cow() to COW the headroom instead. Guard\noffset_valid() against INT_MIN, where negation is undefined.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · 0xBlackash/CVE-2026-46331",
                    "author": "0xBlackash",
                    "first_seen": "2026-06-26",
                    "last_seen": "2026-08-26T08:01:58Z",
                    "pushed_at": "2026-06-26T19:09:41Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "C",
                    "stars": 30,
                    "forks": 5,
                    "topics": [],
                    "title": "CVE-2026-46331",
                    "repository_description": "CVE-2026-46331",
                    "summary": "CVE-2026-46331",
                    "source": "CVE-Intel",
                    "url": "https://github.com/0xBlackash/CVE-2026-46331",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix pedit partial COW leading to page cache corruption\n\ntcf_pedit_act() computes the COW range for skb_ensure_writable()\nonce before the key loop using tcfp_off_max_hint, but the hint does\nnot account for the runtime header offset added by typed keys. This\ncan leave part of the write region un-COW'd.\n\nFix by moving skb_ensure_writable() inside the per-key loop where\nthe actual write offset is known, and add overflow checking on the\noffset arithmetic. For negative offsets (e.g. Ethernet header edits\nat ingress), use skb_cow() to COW the headroom instead. Guard\noffset_valid() against INT_MIN, where negation is undefined.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00525,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-16",
                    "cve_status": "Received"
                },
                {
                    "repository": "CVE-Intel · douglasmun/pagecache-lpe-containment-kit",
                    "author": "douglasmun",
                    "first_seen": "2026-06-27",
                    "last_seen": "2026-08-25T07:08:22Z",
                    "pushed_at": "2026-06-27T15:25:16Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "LPE",
                    "language": "Shell",
                    "stars": 3,
                    "forks": 1,
                    "topics": [
                        "blue-team",
                        "bpftrace",
                        "container-security",
                        "cve",
                        "defensive-security",
                        "ebpf",
                        "hardening",
                        "kernel-security"
                    ],
                    "title": "Educational, defensive kit for two Linux page-cache-corruption LPEs (DirtyClone CVE-2026-43503, pedit COW CVE-2026-46331): hardening, detection, verification, seccomp + validation harness. Detection and prevention only — no exploit code. TLP:CLEAR.",
                    "repository_description": "Educational, defensive kit for two Linux page-cache-corruption LPEs (DirtyClone CVE-2026-43503, pedit COW CVE-2026-46331): hardening, detection, verification, seccomp + validation harness. Detection and prevention only — no exploit code. TLP:CLEAR.",
                    "summary": "Educational, defensive kit for two Linux page-cache-corruption LPEs (DirtyClone CVE-2026-43503, pedit COW CVE-2026-46331): hardening, detection, verification, seccomp + validation harness. Detection and prevention only — no exploit code. TLP:CLEAR.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/douglasmun/pagecache-lpe-containment-kit",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix pedit partial COW leading to page cache corruption\n\ntcf_pedit_act() computes the COW range for skb_ensure_writable()\nonce before the key loop using tcfp_off_max_hint, but the hint does\nnot account for the runtime header offset added by typed keys. This\ncan leave part of the write region un-COW'd.\n\nFix by moving skb_ensure_writable() inside the per-key loop where\nthe actual write offset is known, and add overflow checking on the\noffset arithmetic. For negative offsets (e.g. Ethernet header edits\nat ingress), use skb_cow() to COW the headroom instead. Guard\noffset_valid() against INT_MIN, where negation is undefined.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00525,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-16",
                    "cve_status": "Received"
                },
                {
                    "repository": "CVE-Intel · sgkdev/packet_edit_meme",
                    "author": "sgkdev",
                    "first_seen": "2026-06-17",
                    "last_seen": "2026-08-20T18:02:33Z",
                    "pushed_at": "2026-06-17T04:55:06Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "C",
                    "stars": 142,
                    "forks": 45,
                    "topics": [],
                    "title": "PACKET_EDIT_MEME.c (aka CVE-2026-46331): yet another page cache poisoning nightmare",
                    "repository_description": "PACKET_EDIT_MEME.c (aka CVE-2026-46331): yet another page cache poisoning nightmare",
                    "summary": "PACKET_EDIT_MEME.c (aka CVE-2026-46331): yet another page cache poisoning nightmare",
                    "source": "CVE-Intel",
                    "url": "https://github.com/sgkdev/packet_edit_meme",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix pedit partial COW leading to page cache corruption\n\ntcf_pedit_act() computes the COW range for skb_ensure_writable()\nonce before the key loop using tcfp_off_max_hint, but the hint does\nnot account for the runtime header offset added by typed keys. This\ncan leave part of the write region un-COW'd.\n\nFix by moving skb_ensure_writable() inside the per-key loop where\nthe actual write offset is known, and add overflow checking on the\noffset arithmetic. For negative offsets (e.g. Ethernet header edits\nat ingress), use skb_cow() to COW the headroom instead. Guard\noffset_valid() against INT_MIN, where negation is undefined.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00525,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-16",
                    "cve_status": "Received"
                },
                {
                    "repository": "CVE-Intel · vulnquest58/dirtyclone-exploit",
                    "author": "vulnquest58",
                    "first_seen": "2026-06-28",
                    "last_seen": "2026-08-20T07:20:53Z",
                    "pushed_at": "2026-06-28T11:46:11Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "LPE",
                    "language": "C",
                    "stars": 6,
                    "forks": 1,
                    "topics": [],
                    "title": "CVE-2026-46331 — Linux Kernel Local Privilege Escalation TC pedit + IPsec TEE Page Cache Corruption · Affected kernels: ≤ 6.12.9",
                    "repository_description": "CVE-2026-46331 — Linux Kernel Local Privilege Escalation TC pedit + IPsec TEE Page Cache Corruption · Affected kernels: ≤ 6.12.9",
                    "summary": "CVE-2026-46331 — Linux Kernel Local Privilege Escalation TC pedit + IPsec TEE Page Cache Corruption · Affected kernels: ≤ 6.12.9",
                    "source": "CVE-Intel",
                    "url": "https://github.com/vulnquest58/dirtyclone-exploit",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix pedit partial COW leading to page cache corruption\n\ntcf_pedit_act() computes the COW range for skb_ensure_writable()\nonce before the key loop using tcfp_off_max_hint, but the hint does\nnot account for the runtime header offset added by typed keys. This\ncan leave part of the write region un-COW'd.\n\nFix by moving skb_ensure_writable() inside the per-key loop where\nthe actual write offset is known, and add overflow checking on the\noffset arithmetic. For negative offsets (e.g. Ethernet header edits\nat ingress), use skb_cow() to COW the headroom instead. Guard\noffset_valid() against INT_MIN, where negation is undefined.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00525,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-16",
                    "cve_status": "Received"
                },
                {
                    "repository": "CVE-Intel · rjt-gupta/page-cache-corruption-lpes",
                    "author": "rjt-gupta",
                    "first_seen": "2026-07-22",
                    "last_seen": "2026-08-07T18:30:45Z",
                    "pushed_at": "2026-07-22T22:53:02Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "C",
                    "stars": 12,
                    "forks": 4,
                    "topics": [],
                    "title": "CVE-2026-46331 and CVE-2026-43503",
                    "repository_description": "CVE-2026-46331 and CVE-2026-43503",
                    "summary": "CVE-2026-46331 and CVE-2026-43503",
                    "source": "CVE-Intel",
                    "url": "https://github.com/rjt-gupta/page-cache-corruption-lpes",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix pedit partial COW leading to page cache corruption\n\ntcf_pedit_act() computes the COW range for skb_ensure_writable()\nonce before the key loop using tcfp_off_max_hint, but the hint does\nnot account for the runtime header offset added by typed keys. This\ncan leave part of the write region un-COW'd.\n\nFix by moving skb_ensure_writable() inside the per-key loop where\nthe actual write offset is known, and add overflow checking on the\noffset arithmetic. For negative offsets (e.g. Ethernet header edits\nat ingress), use skb_cow() to COW the headroom instead. Guard\noffset_valid() against INT_MIN, where negation is undefined.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00525,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-16",
                    "cve_status": "Received"
                },
                {
                    "repository": "CVE-Intel · nawalacheker1/CVE-2026-46331",
                    "author": "nawalacheker1",
                    "first_seen": "2026-07-30",
                    "last_seen": "2026-07-31T05:29:04Z",
                    "pushed_at": "2026-07-31T05:28:57Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "Exploit",
                    "language": "",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-46331",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/nawalacheker1/CVE-2026-46331",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix pedit partial COW leading to page cache corruption\n\ntcf_pedit_act() computes the COW range for skb_ensure_writable()\nonce before the key loop using tcfp_off_max_hint, but the hint does\nnot account for the runtime header offset added by typed keys. This\ncan leave part of the write region un-COW'd.\n\nFix by moving skb_ensure_writable() inside the per-key loop where\nthe actual write offset is known, and add overflow checking on the\noffset arithmetic. For negative offsets (e.g. Ethernet header edits\nat ingress), use skb_cow() to COW the headroom instead. Guard\noffset_valid() against INT_MIN, where negation is undefined.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00525,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-16",
                    "cve_status": "Received"
                },
                {
                    "repository": "CVE-Intel · cherrycherrymay/PoC-CVE-2026-46331",
                    "author": "cherrycherrymay",
                    "first_seen": "2026-07-24",
                    "last_seen": "2026-07-24T13:12:20Z",
                    "pushed_at": "2026-07-24T13:11:15Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "LPE",
                    "language": "",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "Pedit COW – Linux Kernel Local Privilege Escalation (CVE-2026-46331)",
                    "repository_description": "Pedit COW – Linux Kernel Local Privilege Escalation (CVE-2026-46331)",
                    "summary": "Pedit COW – Linux Kernel Local Privilege Escalation (CVE-2026-46331)",
                    "source": "CVE-Intel",
                    "url": "https://github.com/cherrycherrymay/PoC-CVE-2026-46331",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix pedit partial COW leading to page cache corruption\n\ntcf_pedit_act() computes the COW range for skb_ensure_writable()\nonce before the key loop using tcfp_off_max_hint, but the hint does\nnot account for the runtime header offset added by typed keys. This\ncan leave part of the write region un-COW'd.\n\nFix by moving skb_ensure_writable() inside the per-key loop where\nthe actual write offset is known, and add overflow checking on the\noffset arithmetic. For negative offsets (e.g. Ethernet header edits\nat ingress), use skb_cow() to COW the headroom instead. Guard\noffset_valid() against INT_MIN, where negation is undefined.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00525,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-16",
                    "cve_status": "Received"
                },
                {
                    "repository": "CVE-Intel · V0IDNETWORK/CVE-2026-46331",
                    "author": "V0IDNETWORK",
                    "first_seen": "2026-07-01",
                    "last_seen": "2026-07-23T16:21:44Z",
                    "pushed_at": "2026-07-01T02:22:37Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "C++",
                    "stars": 1,
                    "forks": 0,
                    "topics": [],
                    "title": "pedit COW",
                    "repository_description": "pedit COW",
                    "summary": "pedit COW",
                    "source": "CVE-Intel",
                    "url": "https://github.com/V0IDNETWORK/CVE-2026-46331",
                    "cvss": 0,
                    "severity": "",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix pedit partial COW leading to page cache corruption\n\ntcf_pedit_act() computes the COW range for skb_ensure_writable()\nonce before the key loop using tcfp_off_max_hint, but the hint does\nnot account for the runtime header offset added by typed keys. This\ncan leave part of the write region un-COW'd.\n\nFix by moving skb_ensure_writable() inside the per-key loop where\nthe actual write offset is known, and add overflow checking on the\noffset arithmetic. For negative offsets (e.g. Ethernet header edits\nat ingress), use skb_cow() to COW the headroom instead. Guard\noffset_valid() against INT_MIN, where negation is undefined.",
                    "cvss_vector": "",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00525,
                    "metadata_source": "",
                    "cve_published_at": "2026-06-16",
                    "cve_status": "Received"
                },
                {
                    "repository": "MarwahHadi/CVE-2026-46331-pedit-cow",
                    "author": "MarwahHadi",
                    "first_seen": "2026-07-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Write-up and exploitation steps for the pedit COW vulnerability (CVE-2026-46331)",
                    "summary": "Write-up and exploitation steps for the pedit COW vulnerability (CVE-2026-46331)",
                    "url": "https://github.com/MarwahHadi/CVE-2026-46331-pedit-cow"
                },
                {
                    "repository": "yanxinwu946/CVE-2026-46331",
                    "author": "yanxinwu946",
                    "first_seen": "2026-07-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 4,
                    "title": "CVE-2026-46331 act_pedit page-cache corruption exploit, with Alpine PIE fix",
                    "summary": "CVE-2026-46331 act_pedit page-cache corruption exploit, with Alpine PIE fix",
                    "url": "https://github.com/yanxinwu946/CVE-2026-46331"
                },
                {
                    "repository": "g0thamRabb1t/CVE-2026-46331-pedit-COW-detection",
                    "author": "g0thamRabb1t",
                    "first_seen": "2026-06-30",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Defensive validation of CVE-2026-46331 / pedit COW with auditd, AppArmor, mitigation comparison and detection logic.",
                    "summary": "Defensive validation of CVE-2026-46331 / pedit COW with auditd, AppArmor, mitigation comparison and detection logic.",
                    "url": "https://github.com/g0thamRabb1t/CVE-2026-46331-pedit-COW-detection"
                },
                {
                    "repository": "seguridadentrerios/CVE-2026-46331",
                    "author": "seguridadentrerios",
                    "first_seen": "2026-06-30",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Chequeo y Fix de la vulnerabilidad \"pedit COW\"",
                    "summary": "Chequeo y Fix de la vulnerabilidad \"pedit COW\"",
                    "url": "https://github.com/seguridadentrerios/CVE-2026-46331"
                },
                {
                    "repository": "Quaerendir/cve-2026-46331-audit",
                    "author": "Quaerendir",
                    "first_seen": "2026-06-29",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "cve-2026-46331-audit script",
                    "summary": "cve-2026-46331-audit script",
                    "url": "https://github.com/Quaerendir/cve-2026-46331-audit"
                },
                {
                    "title": "Exploit for Integer Overflow or Wraparound in Linux Linux_Kernel CVE-2026-46331",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=F8A81E36-CC39-5112-9A0D-C5CD3E6097FE",
                        "https://github.com/theendofabbys/pedit-cow"
                    ],
                    "repository": "Sploitus",
                    "author": "theendofabbys",
                    "first_seen": "2026-09-15T13:57:19",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=F8A81E36-CC39-5112-9A0D-C5CD3E6097FE"
                },
                {
                    "title": "Exploit for Integer Overflow or Wraparound in Linux Linux_Kernel CVE-2026-46331",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=F8A81E36-CC39-5112-9A0D-C5CD3E6097FE",
                        "https://github.com/theendofabbys/pedit-cow"
                    ],
                    "repository": "theendofabbys/pedit-cow",
                    "author": "theendofabbys",
                    "first_seen": "2026-09-15T13:57:19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://github.com/theendofabbys/pedit-cow"
                }
            ],
            "references": [
                "https://github.com/0xBlackash/CVE-2026-46331",
                "https://github.com/douglasmun/pagecache-lpe-containment-kit",
                "https://github.com/sgkdev/packet_edit_meme",
                "https://github.com/vulnquest58/dirtyclone-exploit",
                "https://github.com/rjt-gupta/page-cache-corruption-lpes",
                "https://github.com/nawalacheker1/CVE-2026-46331",
                "https://github.com/cherrycherrymay/PoC-CVE-2026-46331",
                "https://github.com/V0IDNETWORK/CVE-2026-46331",
                "https://github.com/MarwahHadi/CVE-2026-46331-pedit-cow",
                "https://github.com/yanxinwu946/CVE-2026-46331",
                "https://github.com/g0thamRabb1t/CVE-2026-46331-pedit-COW-detection",
                "https://github.com/seguridadentrerios/CVE-2026-46331",
                "https://github.com/Quaerendir/cve-2026-46331-audit",
                "https://sploitus.com/exploit?id=F8A81E36-CC39-5112-9A0D-C5CD3E6097FE",
                "https://github.com/theendofabbys/pedit-cow",
                "https://git.kernel.org/stable/c/2bec122b9fb91507a758ab5e3e5c4fbe7cb3f61b",
                "https://git.kernel.org/stable/c/3dee9d0c198faeb95d052c1b94c2958751a28512",
                "https://git.kernel.org/stable/c/544d857b42a1734b923040e13aa61a6fd4746cf2",
                "https://git.kernel.org/stable/c/899ee91156e57784090c5565e4f31bd7dbffbc5a",
                "https://git.kernel.org/stable/c/a071e057518decc5e3bec89855758f5f8786f2c5",
                "https://git.kernel.org/stable/c/b198ed4e52580a7238c7c7082f03906f8b310313",
                "https://git.kernel.org/stable/c/b685d6ef6f07a3b5ce814565a25f39f2157538a5",
                "https://git.kernel.org/stable/c/d5d01d35a5a7d36f7cb679b67d9cbdd5205672dc",
                "https://access.redhat.com/errata/RHSA-2026:27288",
                "https://access.redhat.com/errata/RHSA-2026:27353",
                "https://access.redhat.com/errata/RHSA-2026:27354",
                "https://access.redhat.com/errata/RHSA-2026:27355",
                "https://access.redhat.com/errata/RHSA-2026:27704",
                "https://access.redhat.com/errata/RHSA-2026:27705",
                "https://access.redhat.com/errata/RHSA-2026:27706",
                "https://access.redhat.com/errata/RHSA-2026:27707",
                "https://access.redhat.com/errata/RHSA-2026:27708",
                "https://access.redhat.com/errata/RHSA-2026:27709",
                "https://access.redhat.com/errata/RHSA-2026:27713",
                "https://access.redhat.com/errata/RHSA-2026:27731",
                "https://access.redhat.com/errata/RHSA-2026:27789",
                "https://access.redhat.com/errata/RHSA-2026:28887",
                "https://access.redhat.com/errata/RHSA-2026:28962",
                "https://access.redhat.com/errata/RHSA-2026:29080",
                "https://access.redhat.com/errata/RHSA-2026:29794",
                "https://access.redhat.com/errata/RHSA-2026:29799",
                "https://access.redhat.com/errata/RHSA-2026:29833",
                "https://access.redhat.com/errata/RHSA-2026:29856",
                "https://access.redhat.com/errata/RHSA-2026:29863",
                "https://access.redhat.com/errata/RHSA-2026:33219",
                "https://access.redhat.com/errata/RHSA-2026:33220",
                "https://access.redhat.com/errata/RHSA-2026:33221",
                "https://access.redhat.com/errata/RHSA-2026:33222",
                "https://access.redhat.com/errata/RHSA-2026:33223",
                "https://access.redhat.com/errata/RHSA-2026:33224",
                "https://access.redhat.com/errata/RHSA-2026:33225",
                "https://access.redhat.com/errata/RHSA-2026:33666",
                "https://access.redhat.com/errata/RHSA-2026:34048",
                "https://access.redhat.com/errata/RHSA-2026:34098",
                "https://access.redhat.com/errata/RHSA-2026:40021",
                "https://access.redhat.com/security/cve/CVE-2026-46331",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2479492",
                "https://github.com/sgkdev/packet_edit_meme/tree/main",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46331.json"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T08:01:58Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/0xBlackash/CVE-2026-46331"
                },
                {
                    "at": "2026-06-16T08:16:23.993",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46331"
                }
            ],
            "epss": 0.00525,
            "cve_status": "Received",
            "cve_published_at": "2026-06-16",
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "enrichment_checked_at": "2026-09-16T16:06:04Z"
        },
        {
            "id": "CVE-2026-46323",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gro: don't merge zcopy skbs\n\nskb_gro_receive() can currently copy frags between the source and GRO\nskb, without checking the zerocopy status, and in particular the\nSKBFL_MANAGED_FRAG_REFS flag.\n\nWhen SKBFL_MANAGED_FRAG_REFS is set, the skb doesn't hold a reference\non the pages in shinfo->frags. Appending those frags to another skb's\nfrags without fixing up the page refcount can lead to UAF.\n\nWhen either the last skb in the GRO chain (the one we would append\nfrags to) or the source skb is zerocopy, don't merge the skbs.",
            "updated_at": "2026-09-08T09:18:10.030",
            "published_at": "2026-06-09T13:16:37.753",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "753f1ca4e1e50248a1b760c9774d6d6b354562cc through before 3c6cc9f2ca65b6dd61b1af75452dc0e1cd0aad8d (git); 753f1ca4e1e50248a1b760c9774d6d6b354562cc through before 1f9c828556416fbe3f49386708ce999fc4d4da06 (git); 753f1ca4e1e50248a1b760c9774d6d6b354562cc through before 479084ae0e1d9cb7929cb4298d35623de189f80a (git); 753f1ca4e1e50248a1b760c9774d6d6b354562cc through before e334cbf3388fd9334503a778a82d9e9f14dd2f71 (git); 753f1ca4e1e50248a1b760c9774d6d6b354562cc through before 44bea2032af0425e4ce6d26a8af0ede79db49ec1 (git); 753f1ca4e1e50248a1b760c9774d6d6b354562cc through before 4db79a322db8c97f7b73b8a347395ef4d685eb40 (git); 6.0; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 24,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gro: don't merge zcopy skbs\n\nskb_gro_receive() can currently copy frags between the source and GRO\nskb, without checking the zerocopy status, and in particular the\nSKBFL_MANAGED_FRAG_REFS flag.\n\nWhen SKBFL_MANAGED_FRAG_REFS is set, the skb doesn't hold a reference\non the pages in shinfo->frags. Appending those frags to another skb's\nfrags without fixing up the page refcount can lead to UAF.\n\nWhen either the last skb in the GRO chain (the one we would append\nfrags to) or the source skb is zerocopy, don't merge the skbs.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1f9c828556416fbe3f49386708ce999fc4d4da06",
                "https://git.kernel.org/stable/c/3c6cc9f2ca65b6dd61b1af75452dc0e1cd0aad8d",
                "https://git.kernel.org/stable/c/44bea2032af0425e4ce6d26a8af0ede79db49ec1",
                "https://git.kernel.org/stable/c/479084ae0e1d9cb7929cb4298d35623de189f80a",
                "https://git.kernel.org/stable/c/4db79a322db8c97f7b73b8a347395ef4d685eb40",
                "https://git.kernel.org/stable/c/e334cbf3388fd9334503a778a82d9e9f14dd2f71",
                "https://access.redhat.com/errata/RHSA-2026:27708",
                "https://access.redhat.com/errata/RHSA-2026:27731",
                "https://access.redhat.com/errata/RHSA-2026:27735",
                "https://access.redhat.com/errata/RHSA-2026:36018",
                "https://access.redhat.com/errata/RHSA-2026:44230",
                "https://access.redhat.com/errata/RHSA-2026:44231",
                "https://access.redhat.com/errata/RHSA-2026:44259",
                "https://access.redhat.com/errata/RHSA-2026:44262",
                "https://access.redhat.com/errata/RHSA-2026:44270",
                "https://access.redhat.com/errata/RHSA-2026:47727",
                "https://access.redhat.com/errata/RHSA-2026:62639",
                "https://access.redhat.com/errata/RHSA-2026:62640",
                "https://access.redhat.com/errata/RHSA-2026:62641",
                "https://access.redhat.com/errata/RHSA-2026:62642",
                "https://access.redhat.com/security/cve/CVE-2026-46323",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2479832",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46323.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-09T13:16:37.753",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46323"
                }
            ]
        },
        {
            "id": "CVE-2026-46316",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry\n\nvgic_its_invalidate_cache() walks the per-ITS translation cache with\nxa_for_each() and drops the cache's reference on each entry with\nvgic_put_irq(). It puts the iterated pointer, though, rather than the\nvalue returned by xa_erase().\n\nThe function is called from contexts that do not exclude one another: the\nITS command handlers hold its_lock, the GITS_CTLR write path holds\ncmd_lock, and the path that clears EnableLPIs in a redistributor's\nGICR_CTLR holds neither. Two or more of them can drain the same cache\nconcurrently, and if each one observes the same entry, erases it and then\nputs it, the single reference the cache holds on that entry is dropped\nmore than once. The entry can then be freed while an ITE still maps it.\n\nxa_erase() is atomic and returns the previous entry, so put only the entry\nthat this context actually removed. The cache reference is then dropped\nexactly once per entry even when the invalidations run concurrently, and\nthe behavior is unchanged when only one context runs.",
            "updated_at": "2026-09-16T13:18:00.307",
            "published_at": "2026-06-09T13:16:36.887",
            "cvss": 9.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8201d1028caa4fae88e222c4e8cf541fdf45b821 through before b7b72e88046328c9fdc638fe887d4240257dd5dc (git); 8201d1028caa4fae88e222c4e8cf541fdf45b821 through before 2bbc395e81bd29c543a0529a678327e932a7ec69 (git); 8201d1028caa4fae88e222c4e8cf541fdf45b821 through before 9121f4605ab94969f62d1b5714ca3c6c69bd202f (git); 8201d1028caa4fae88e222c4e8cf541fdf45b821 through before 13031fb6b8357fbbcded2a7f4cba73e4781ee594 (git); 6.10",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-911",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry\n\nvgic_its_invalidate_cache() walks the per-ITS translation cache with\nxa_for_each() and drops the cache's reference on each entry with\nvgic_put_irq(). It puts the iterated pointer, though, rather than the\nvalue returned by xa_erase().\n\nThe function is called from contexts that do not exclude one another: the\nITS command handlers hold its_lock, the GITS_CTLR write path holds\ncmd_lock, and the path that clears EnableLPIs in a redistributor's\nGICR_CTLR holds neither. Two or more of them can drain the same cache\nconcurrently, and if each one observes the same entry, erases it and then\nputs it, the single reference the cache holds on that entry is dropped\nmore than once. The entry can then be freed while an ITE still maps it.\n\nxa_erase() is atomic and returns the previous entry, so put only the entry\nthat this context actually removed. The cache reference is then dropped\nexactly once per entry even when the invalidations run concurrently, and\nthe behavior is unchanged when only one context runs.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/13031fb6b8357fbbcded2a7f4cba73e4781ee594",
                "https://git.kernel.org/stable/c/2bbc395e81bd29c543a0529a678327e932a7ec69",
                "https://git.kernel.org/stable/c/9121f4605ab94969f62d1b5714ca3c6c69bd202f",
                "https://git.kernel.org/stable/c/b7b72e88046328c9fdc638fe887d4240257dd5dc",
                "https://access.redhat.com/errata/RHSA-2026:34911",
                "https://access.redhat.com/errata/RHSA-2026:36018",
                "https://access.redhat.com/errata/RHSA-2026:38902",
                "https://access.redhat.com/errata/RHSA-2026:39371",
                "https://access.redhat.com/errata/RHSA-2026:40764",
                "https://access.redhat.com/errata/RHSA-2026:40779",
                "https://access.redhat.com/errata/RHSA-2026:40787",
                "https://access.redhat.com/errata/RHSA-2026:44231",
                "https://access.redhat.com/security/cve/CVE-2026-46316",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2486982",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46316.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-09T13:16:36.887",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46316"
                }
            ]
        },
        {
            "id": "CVE-2026-46306",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nflow_dissector: do not dissect PPPoE PFC frames\n\nRFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT\nRECOMMENDED for PPPoE. In practice, pppd does not support negotiating\nPFC for PPPoE sessions, and the flow dissector driver has assumed an\nuncompressed frame until the blamed commit.\n\nDuring the review process of that commit [1], support for PFC is\nsuggested. However, having a compressed (1-byte) protocol field means\nthe subsequent PPP payload is shifted by one byte, causing 4-byte\nmisalignment for the network header and an unaligned access exception\non some architectures.\n\nThe exception can be reproduced by sending a PPPoE PFC frame to an\nethernet interface of a MIPS board, with RPS enabled, even if no PPPoE\nsession is active on that interface:\n\n$ 0   : 00000000 80c40000 00000000 85144817\n$ 4   : 00000008 00000100 80a75758 81dc9bb8\n$ 8   : 00000010 8087ae2c 0000003d 00000000\n$12   : 000000e0 00000039 00000000 00000000\n$16   : 85043240 80a75758 81dc9bb8 00006488\n$20   : 0000002f 00000007 85144810 80a70000\n$24   : 81d1bda0 00000000\n$28   : 81dc8000 81dc9aa8 00000000 805ead08\nHi    : 00009d51\nLo    : 2163358a\nepc   : 805e91f0 __skb_flow_dissect+0x1b0/0x1b50\nra    : 805ead08 __skb_get_hash_net+0x74/0x12c\nStatus: 11000403        KERNEL EXL IE\nCause : 40800010 (ExcCode 04)\nBadVA : 85144817\nPrId  : 0001992f (MIPS 1004Kc)\nCall Trace:\n[<805e91f0>] __skb_flow_dissect+0x1b0/0x1b50\n[<805ead08>] __skb_get_hash_net+0x74/0x12c\n[<805ef330>] get_rps_cpu+0x1b8/0x3fc\n[<805fca70>] netif_receive_skb_list_internal+0x324/0x364\n[<805fd120>] napi_complete_done+0x68/0x2a4\n[<8058de5c>] mtk_napi_rx+0x228/0xfec\n[<805fd398>] __napi_poll+0x3c/0x1c4\n[<805fd754>] napi_threaded_poll_loop+0x234/0x29c\n[<805fd848>] napi_threaded_poll+0x8c/0xb0\n[<80053544>] kthread+0x104/0x12c\n[<80002bd8>] ret_from_kernel_thread+0x14/0x1c\n\nCode: 02d51821  1060045b  00000000 <8c640000> 3084000f  2c820005  144001a2  00042080  8e220000\n\nTo reduce the attack surface and maintain performance, do not process\nPPPoE PFC frames.\n\n[1] https://lore.kernel.org/r/20220630231016.GA392@debian.home",
            "updated_at": "2026-09-08T09:18:09.837",
            "published_at": "2026-06-08T17:16:49.383",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10f665b52a75df6eb26ddebbbc072ee264183731 through before e7c811ca372d53c2be7d01a1614e71fae1054836 (git); d7e541e86122d21f71eb71c5dfa7fb1eb6623fe8 through before abc5bc84e0f2edc7ea2d437afa6ef3fe1fc43200 (git); 46126db9c86110e5fc1e369b9bb89735ddefdae4 through before 18ae9eacfc95cc715c0606b2c86e8aa8a86cf3e3 (git); 46126db9c86110e5fc1e369b9bb89735ddefdae4 through before db104b0d8a7856397c0469d83a4289adf7c54863 (git); 46126db9c86110e5fc1e369b9bb89735ddefdae4 through before 6044392d9cace3a3672b02c8bc7d38b502e51734 (git); 46126db9c86110e5fc1e369b9bb89735ddefdae4 through before 0d00b9015069712944934bab09eaa6c542143049 (git); 46126db9c86110e5fc1e369b9bb89735ddefdae4 through before 7c93f353eab4ea911e394630f07d72e040a729d8 (git); 46126db9c86110e5fc1e369b9bb89735ddefdae4 through before d6c19b31a3c1d519fabdcf0aa239e6b6109b9473 (git); 6.0; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nflow_dissector: do not dissect PPPoE PFC frames\n\nRFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT\nRECOMMENDED for PPPoE. In practice, pppd does not support negotiating\nPFC for PPPoE sessions, and the flow dissector driver has assumed an\nuncompressed frame until the blamed commit.\n\nDuring the review process of that commit [1], support for PFC is\nsuggested. However, having a compressed (1-byte) protocol field means\nthe subsequent PPP payload is shifted by one byte, causing 4-byte\nmisalignment for the network header and an unaligned access exception\non some architectures.\n\nThe exception can be reproduced by sending a PPPoE PFC frame to an\nethernet interface of a MIPS board, with RPS enabled, even if no PPPoE\nsession is active on that interface:\n\n$ 0   : 00000000 80c40000 00000000 85144817\n$ 4   : 00000008 00000100 80a75758 81dc9bb8\n$ 8   : 00000010 8087ae2c 0000003d 00000000\n$12   : 000000e0 00000039 00000000 00000000\n$16   : 85043240 80a75758 81dc9bb8 00006488\n$20   : 0000002f 00000007 85144810 80a70000\n$24   : 81d1bda0 00000000\n$28   : 81dc8000 81dc9aa8 00000000 805ead08\nHi    : 00009d51\nLo    : 2163358a\nepc   : 805e91f0 __skb_flow_dissect+0x1b0/0x1b50\nra    : 805ead08 __skb_get_hash_net+0x74/0x12c\nStatus: 11000403        KERNEL EXL IE\nCause : 40800010 (ExcCode 04)\nBadVA : 85144817\nPrId  : 0001992f (MIPS 1004Kc)\nCall Trace:\n[<805e91f0>] __skb_flow_dissect+0x1b0/0x1b50\n[<805ead08>] __skb_get_hash_net+0x74/0x12c\n[<805ef330>] get_rps_cpu+0x1b8/0x3fc\n[<805fca70>] netif_receive_skb_list_internal+0x324/0x364\n[<805fd120>] napi_complete_done+0x68/0x2a4\n[<8058de5c>] mtk_napi_rx+0x228/0xfec\n[<805fd398>] __napi_poll+0x3c/0x1c4\n[<805fd754>] napi_threaded_poll_loop+0x234/0x29c\n[<805fd848>] napi_threaded_poll+0x8c/0xb0\n[<80053544>] kthread+0x104/0x12c\n[<80002bd8>] ret_from_kernel_thread+0x14/0x1c\n\nCode: 02d51821  1060045b  00000000 <8c640000> 3084000f  2c820005  144001a2  00042080  8e220000\n\nTo reduce the attack surface and maintain performance, do not process\nPPPoE PFC frames.\n\n[1] https://lore.kernel.org/r/20220630231016.GA392@debian.home",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0d00b9015069712944934bab09eaa6c542143049",
                "https://git.kernel.org/stable/c/18ae9eacfc95cc715c0606b2c86e8aa8a86cf3e3",
                "https://git.kernel.org/stable/c/6044392d9cace3a3672b02c8bc7d38b502e51734",
                "https://git.kernel.org/stable/c/7c93f353eab4ea911e394630f07d72e040a729d8",
                "https://git.kernel.org/stable/c/abc5bc84e0f2edc7ea2d437afa6ef3fe1fc43200",
                "https://git.kernel.org/stable/c/d6c19b31a3c1d519fabdcf0aa239e6b6109b9473",
                "https://git.kernel.org/stable/c/db104b0d8a7856397c0469d83a4289adf7c54863",
                "https://git.kernel.org/stable/c/e7c811ca372d53c2be7d01a1614e71fae1054836",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-08T17:16:49.383",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46306"
                }
            ]
        },
        {
            "id": "CVE-2026-46303",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nisofs: validate Rock Ridge CE continuation extent against volume size\n\nrock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE\nrecord and passes it to sb_bread() without checking that the block\nnumber is within the mounted ISO 9660 volume.  commit e595447e177b\n(\"[PATCH] rock.c: handle corrupted directories\") added cont_offset\nand cont_size rejection for the CE continuation but did not validate\nthe extent block number itself.  commit f54e18f1b831 (\"isofs: Fix\ninfinite looping over CE entries\") later capped the CE chain length\nat RR_MAX_CE_ENTRIES = 32 but again left the block number unchecked.\n\nWith a crafted ISO mounted via udisks2 (desktop optical auto-mount)\nor via CAP_SYS_ADMIN mount, rs->cont_extent can therefore point at\nan out-of-range block or at blocks belonging to an adjacent\nfilesystem on the same block device.  sb_bread() on an out-of-range\nblock returns NULL cleanly via the block layer EIO path, so there\nis no memory-safety violation.  For in-range reads of adjacent-\nfilesystem data, the CE buffer is parsed as Rock Ridge records and\nonly the text of SL sub-records reaches userspace through\nreadlink(), which makes the info-leak channel narrow and difficult\nto exploit; still, rejecting the malformed CE outright matches the\nrejection shape already present in the same function for\ncont_offset and cont_size.\n\nAdd an ISOFS_SB(sb)->s_nzones bounds check to rock_continue() next\nto the existing offset/size rejection, printing the same\ncorrupted-directory-entry notice.",
            "updated_at": "2026-09-08T09:18:09.583",
            "published_at": "2026-06-08T17:16:48.853",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f54e18f1b831c92f6512d2eedb224cd63d607d3d through before 8356fb821016797f5677cbeee5ddc0d32a95b4be (git); f54e18f1b831c92f6512d2eedb224cd63d607d3d through before d582e12378bc1637f337622feef762f53c43fd57 (git); f54e18f1b831c92f6512d2eedb224cd63d607d3d through before bf1bc673c587f5ef7e9c09b94aea7c5a7847d4d9 (git); f54e18f1b831c92f6512d2eedb224cd63d607d3d through before c9b37c8b73f6368e4750e5ccb0632c380b43c6e5 (git); f54e18f1b831c92f6512d2eedb224cd63d607d3d through before 22b36fa081f38ab397c7697f9d539211b51a0cfc (git); f54e18f1b831c92f6512d2eedb224cd63d607d3d through before e69da8eeab74b4f4505024c38a17bce060fe7df8 (git); f54e18f1b831c92f6512d2eedb224cd63d607d3d through before ef048470c90bc8c1b8318bb2ce329da9ef64b9fe (git); f54e18f1b831c92f6512d2eedb224cd63d607d3d through before a36d990f591320e9dd379ab30063ebfe91d47e1f (git); 08313e26e06d4aa9ce1cbba1a8e359e9cab9ad56 (git); 212c4d33ca83e2144064fe9c2911607fbed5386f (git); 96e44adce250199ec9b2b928be66365779ff1b59 (git); 1fe5620fcd6c2f0a4a927ee10c8e53196da392f3 (git); fbce0d7dc8965c9fb8d411862040239d4a768c71 (git); 8190393a88f2b0321263a54f2a9eb5a2aa43be7e (git); 486aa789eadcf44ed87f972b209299c516454693 (git); b6d20edb6e7cedb4eedb9e0193d20dd488ebae84 (git); 2.6.32.66 through before 2.6.33 (semver); 3.2.67 through before 3.3 (semver); 3.4.107 through before 3.5 (semver); 3.10.64 through before 3.11 (semver); 3.12.36 through before 3.13 (semver); 3.14.28 through before 3.15 (semver); 3.17.8 through before 3.18 (semver); 3.18.2 through before 3.19 (semver); 3.19; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-401",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nisofs: validate Rock Ridge CE continuation extent against volume size\n\nrock_continue() reads rs->cont_extent verbatim from the Rock Ridge CE\nrecord and passes it to sb_bread() without checking that the block\nnumber is within the mounted ISO 9660 volume.  commit e595447e177b\n(\"[PATCH] rock.c: handle corrupted directories\") added cont_offset\nand cont_size rejection for the CE continuation but did not validate\nthe extent block number itself.  commit f54e18f1b831 (\"isofs: Fix\ninfinite looping over CE entries\") later capped the CE chain length\nat RR_MAX_CE_ENTRIES = 32 but again left the block number unchecked.\n\nWith a crafted ISO mounted via udisks2 (desktop optical auto-mount)\nor via CAP_SYS_ADMIN mount, rs->cont_extent can therefore point at\nan out-of-range block or at blocks belonging to an adjacent\nfilesystem on the same block device.  sb_bread() on an out-of-range\nblock returns NULL cleanly via the block layer EIO path, so there\nis no memory-safety violation.  For in-range reads of adjacent-\nfilesystem data, the CE buffer is parsed as Rock Ridge records and\nonly the text of SL sub-records reaches userspace through\nreadlink(), which makes the info-leak channel narrow and difficult\nto exploit; still, rejecting the malformed CE outright matches the\nrejection shape already present in the same function for\ncont_offset and cont_size.\n\nAdd an ISOFS_SB(sb)->s_nzones bounds check to rock_continue() next\nto the existing offset/size rejection, printing the same\ncorrupted-directory-entry notice.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/22b36fa081f38ab397c7697f9d539211b51a0cfc",
                "https://git.kernel.org/stable/c/8356fb821016797f5677cbeee5ddc0d32a95b4be",
                "https://git.kernel.org/stable/c/a36d990f591320e9dd379ab30063ebfe91d47e1f",
                "https://git.kernel.org/stable/c/bf1bc673c587f5ef7e9c09b94aea7c5a7847d4d9",
                "https://git.kernel.org/stable/c/c9b37c8b73f6368e4750e5ccb0632c380b43c6e5",
                "https://git.kernel.org/stable/c/d582e12378bc1637f337622feef762f53c43fd57",
                "https://git.kernel.org/stable/c/e69da8eeab74b4f4505024c38a17bce060fe7df8",
                "https://git.kernel.org/stable/c/ef048470c90bc8c1b8318bb2ce329da9ef64b9fe",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-06-08T17:16:48.853",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46303"
                }
            ]
        },
        {
            "id": "CVE-2026-46300",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: preserve shared-frag marker during coalescing\n\nskb_try_coalesce() can attach paged frags from @from to @to.  If @from\nhas SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same\nexternally-owned or page-cache-backed frags, but the shared-frag marker\nis currently lost.\n\nThat breaks the invariant relied on by later in-place writers.  In\nparticular, ESP input checks skb_has_shared_frag() before deciding\nwhether an uncloned nonlinear skb can skip skb_cow_data().  If TCP\nreceive coalescing has moved shared frags into an unmarked skb, ESP can\nsee skb_has_shared_frag() as false and decrypt in place over page-cache\nbacked frags.\n\nPropagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged\nfrags.  The tailroom copy path does not need the marker because it copies\nbytes into @to's linear data rather than transferring frag descriptors.",
            "updated_at": "2026-09-08T09:18:09.057",
            "published_at": "2026-05-23T12:17:02.660",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "cef401de7be8c4e155c6746bfccf721a4fa5fab9 through before 3599e6b3cc1ada96883d496a50a210d3afbb6987 (git); cef401de7be8c4e155c6746bfccf721a4fa5fab9 through before 2f2b16022a2e10ca7bccfb98db5ed2ec0f72641c (git); cef401de7be8c4e155c6746bfccf721a4fa5fab9 through before 9d3e5fd19fe1063bf607219e8562fbd567b8e8d5 (git); cef401de7be8c4e155c6746bfccf721a4fa5fab9 through before 78bf6b6bb19541d19fbda6242e7cfe2c682763c0 (git); cef401de7be8c4e155c6746bfccf721a4fa5fab9 through before 760e1addc27ba1a7beb4a0a7e8b3e9ec49e7a34e (git); cef401de7be8c4e155c6746bfccf721a4fa5fab9 through before 3bd9e113d50034db99d7ef69fd8e5242d15e414a (git); cef401de7be8c4e155c6746bfccf721a4fa5fab9 through before 3884358a9286b17f389a72b1426fc4547c23c111 (git); cef401de7be8c4e155c6746bfccf721a4fa5fab9 through before f84eca5817390257cef78013d0112481c503b4a3 (git); 3.9; V3.1.6 through before V3.1.7 (custom); V3.1.5 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 110,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skbuff: preserve shared-frag marker during coalescing\n\nskb_try_coalesce() can attach paged frags from @from to @to.  If @from\nhas SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same\nexternally-owned or page-cache-backed frags, but the shared-frag marker\nis currently lost.\n\nThat breaks the invariant relied on by later in-place writers.  In\nparticular, ESP input checks skb_has_shared_frag() before deciding\nwhether an uncloned nonlinear skb can skip skb_cow_data().  If TCP\nreceive coalescing has moved shared frags into an unmarked skb, ESP can\nsee skb_has_shared_frag() as false and decrypt in place over page-cache\nbacked frags.\n\nPropagate SKBFL_SHARED_FRAG when skb_try_coalesce() transfers paged\nfrags.  The tailroom copy path does not need the marker because it copies\nbytes into @to's linear data rather than transferring frag descriptors.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52591",
                    "author": "nu11secur1ty",
                    "first_seen": "2026-05-29",
                    "confidence": "High",
                    "title": "Linux Kernel -  Local Privilege Escalation",
                    "summary": "Linux Kernel -  Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/52591",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://git.kernel.org/stable/c/2f2b16022a2e10ca7bccfb98db5ed2ec0f72641c",
                "https://git.kernel.org/stable/c/3599e6b3cc1ada96883d496a50a210d3afbb6987",
                "https://git.kernel.org/stable/c/3884358a9286b17f389a72b1426fc4547c23c111",
                "https://git.kernel.org/stable/c/3bd9e113d50034db99d7ef69fd8e5242d15e414a",
                "https://git.kernel.org/stable/c/760e1addc27ba1a7beb4a0a7e8b3e9ec49e7a34e",
                "https://git.kernel.org/stable/c/78bf6b6bb19541d19fbda6242e7cfe2c682763c0",
                "https://git.kernel.org/stable/c/9d3e5fd19fe1063bf607219e8562fbd567b8e8d5",
                "https://git.kernel.org/stable/c/f84eca5817390257cef78013d0112481c503b4a3",
                "http://www.openwall.com/lists/oss-security/2026/05/13/5",
                "http://www.openwall.com/lists/oss-security/2026/05/21/11",
                "http://www.openwall.com/lists/oss-security/2026/05/21/12",
                "http://www.openwall.com/lists/oss-security/2026/05/21/13",
                "https://access.redhat.com/errata/RHBA-2026:20032",
                "https://access.redhat.com/errata/RHSA-2026:19521",
                "https://access.redhat.com/errata/RHSA-2026:19540",
                "https://access.redhat.com/errata/RHSA-2026:19568",
                "https://access.redhat.com/errata/RHSA-2026:19569",
                "https://access.redhat.com/errata/RHSA-2026:19664",
                "https://access.redhat.com/errata/RHSA-2026:19666",
                "https://access.redhat.com/errata/RHSA-2026:19705",
                "https://access.redhat.com/errata/RHSA-2026:19711",
                "https://access.redhat.com/errata/RHSA-2026:19875",
                "https://access.redhat.com/errata/RHSA-2026:20051",
                "https://access.redhat.com/errata/RHSA-2026:20054",
                "https://access.redhat.com/errata/RHSA-2026:20087",
                "https://access.redhat.com/errata/RHSA-2026:20129",
                "https://access.redhat.com/errata/RHSA-2026:20130",
                "https://access.redhat.com/errata/RHSA-2026:20299",
                "https://access.redhat.com/errata/RHSA-2026:20593",
                "https://access.redhat.com/errata/RHSA-2026:21656",
                "https://access.redhat.com/errata/RHSA-2026:21690",
                "https://access.redhat.com/errata/RHSA-2026:21695",
                "https://access.redhat.com/errata/RHSA-2026:21702",
                "https://access.redhat.com/errata/RHSA-2026:23233",
                "https://access.redhat.com/errata/RHSA-2026:23240",
                "https://access.redhat.com/errata/RHSA-2026:23245",
                "https://access.redhat.com/errata/RHSA-2026:23468",
                "https://access.redhat.com/errata/RHSA-2026:23469",
                "https://access.redhat.com/errata/RHSA-2026:23470",
                "https://access.redhat.com/errata/RHSA-2026:23471",
                "https://access.redhat.com/errata/RHSA-2026:24814",
                "https://access.redhat.com/errata/RHSA-2026:25044",
                "https://access.redhat.com/errata/RHSA-2026:28887",
                "https://access.redhat.com/errata/RHSA-2026:33486",
                "https://access.redhat.com/errata/RHSA-2026:34098",
                "https://access.redhat.com/security/cve/CVE-2026-46300",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2477015",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46300.json",
                "https://www.exploit-db.com/exploits/52591"
            ],
            "timeline": [
                {
                    "at": "2026-05-23T12:17:02.660",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46300"
                }
            ]
        },
        {
            "id": "CVE-2026-46193",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: ah: account for ESN high bits in async callbacks\n\nAH allocates its temporary auth/ICV layout differently when ESN is enabled:\nthe async ahash setup appends a 4-byte seqhi slot before the ICV or\nauth_data area, but the async completion callbacks still reconstruct the\ntemporary layout as if seqhi were absent.\n\nWith an async AH implementation selected, that makes AH copy or compare\nthe wrong bytes on both the IPv4 and IPv6 paths. In UML repro on IPv4 AH\nwith ESN and forced async hmac(sha1), ping fails with 100% packet loss,\nand the callback logs show the pre-fix drift:\n\n  ah4 output_done: esn=1 err=0 icv_off=20 expected_off=24\n  ah4 input_done: esn=1 auth_off=20 expected_auth_off=24 icv_off=32 expected_icv_off=36\n\nReconstruct the callback-side layout the same way the setup path built it\nby skipping the ESN seqhi slot before locating the saved auth_data or ICV.\nPer RFC 4302, the ESN high-order 32 bits participate in the AH ICV\ncomputation, so the async callbacks must account for the seqhi slot.\n\nPost-fix, the same IPv4 AH+ESN+forced-async-hmac(sha1) UML repro shows\nthe corrected offset (ah4 output_done: esn=1 err=0 icv_off=24\nexpected_off=24) and ping succeeds; net/ipv4/ah4.o and net/ipv6/ah6.o\nbuild clean at W=1. IPv6 AH+ESN was not exercised at runtime, and the\nchange has not been tested against a real async hardware AH engine.",
            "updated_at": "2026-09-08T09:18:08.903",
            "published_at": "2026-05-28T10:16:34.923",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "d4d573d0334d07341beffdcf97e2b85d3955d8ae through before ec406c26c97594124e79d14516b729a8d5dced62 (git); d4d573d0334d07341beffdcf97e2b85d3955d8ae through before 1dae77078ceb4bab833f7a4935f05c5b8c97b9ba (git); d4d573d0334d07341beffdcf97e2b85d3955d8ae through before 0555d4f526232b3c9e3afbcd490c0c0793aefec6 (git); d4d573d0334d07341beffdcf97e2b85d3955d8ae through before 729899a2aa8bda7844be0cdcd3b470f11b912eda (git); d4d573d0334d07341beffdcf97e2b85d3955d8ae through before 7db99a09b3bc87268287bc7ab5f2e7f382b5ad87 (git); d4d573d0334d07341beffdcf97e2b85d3955d8ae through before 2ffaa7a94f9a4d22724364a1821735a0231d9f8d (git); d4d573d0334d07341beffdcf97e2b85d3955d8ae through before ec54093e6a8f87e800bb6aa15eb7fc1e33faa524 (git); 3.15; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: ah: account for ESN high bits in async callbacks\n\nAH allocates its temporary auth/ICV layout differently when ESN is enabled:\nthe async ahash setup appends a 4-byte seqhi slot before the ICV or\nauth_data area, but the async completion callbacks still reconstruct the\ntemporary layout as if seqhi were absent.\n\nWith an async AH implementation selected, that makes AH copy or compare\nthe wrong bytes on both the IPv4 and IPv6 paths. In UML repro on IPv4 AH\nwith ESN and forced async hmac(sha1), ping fails with 100% packet loss,\nand the callback logs show the pre-fix drift:\n\n  ah4 output_done: esn=1 err=0 icv_off=20 expected_off=24\n  ah4 input_done: esn=1 auth_off=20 expected_auth_off=24 icv_off=32 expected_icv_off=36\n\nReconstruct the callback-side layout the same way the setup path built it\nby skipping the ESN seqhi slot before locating the saved auth_data or ICV.\nPer RFC 4302, the ESN high-order 32 bits participate in the AH ICV\ncomputation, so the async callbacks must account for the seqhi slot.\n\nPost-fix, the same IPv4 AH+ESN+forced-async-hmac(sha1) UML repro shows\nthe corrected offset (ah4 output_done: esn=1 err=0 icv_off=24\nexpected_off=24) and ping succeeds; net/ipv4/ah4.o and net/ipv6/ah6.o\nbuild clean at W=1. IPv6 AH+ESN was not exercised at runtime, and the\nchange has not been tested against a real async hardware AH engine.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0555d4f526232b3c9e3afbcd490c0c0793aefec6",
                "https://git.kernel.org/stable/c/1dae77078ceb4bab833f7a4935f05c5b8c97b9ba",
                "https://git.kernel.org/stable/c/2ffaa7a94f9a4d22724364a1821735a0231d9f8d",
                "https://git.kernel.org/stable/c/729899a2aa8bda7844be0cdcd3b470f11b912eda",
                "https://git.kernel.org/stable/c/7db99a09b3bc87268287bc7ab5f2e7f382b5ad87",
                "https://git.kernel.org/stable/c/ec406c26c97594124e79d14516b729a8d5dced62",
                "https://git.kernel.org/stable/c/ec54093e6a8f87e800bb6aa15eb7fc1e33faa524",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-28T10:16:34.923",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46193"
                }
            ]
        },
        {
            "id": "CVE-2026-46173",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nexit: prevent preemption of oopsing TASK_DEAD task\n\nWhen an already-exiting task oopses, make_task_dead() currently calls\ndo_task_dead() with preemption enabled.  That is forbidden:\ndo_task_dead() calls __schedule(), which has a comment saying \"WARNING:\nmust be called with preemption disabled!\".\n\nIf an oopsing task is preempted in do_task_dead(), between becoming\nTASK_DEAD and entering the scheduler explicitly, bad things happen:\nfinish_task_switch() assumes that once the scheduler has switched away\nfrom a TASK_DEAD task, the task can never run again and its stack is no\nlonger needed; but that assumption apparently doesn't hold if the dead\ntask was preempted (the SM_PREEMPT case).\n\nThis means that the scheduler ends up repeatedly dropping references on\nthe dead task's stack, which can lead to use-after-free or double-free\nof the entire task stack; in other words, two tasks can end up running\non the same stack, resulting in various kinds of memory corruption.\n\n(This does not just affect \"recursively oopsing\" tasks; it is enough to\noops once during task exit, for example in a file_operations::release\nhandler)",
            "updated_at": "2026-09-08T09:18:08.613",
            "published_at": "2026-05-28T10:16:32.923",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7f80a2fd7db9a55894fd841915236aca611291b5 through before 3d6fb8a7690c23e3213c4b008f64d89a44b98737 (git); 7f80a2fd7db9a55894fd841915236aca611291b5 through before 640b4c00fb0e2920327435f6176cbefc3c546165 (git); 7f80a2fd7db9a55894fd841915236aca611291b5 through before 7b2800ba5f5f77a8ee7f4cbadb19cf1264597a34 (git); 7f80a2fd7db9a55894fd841915236aca611291b5 through before 6f49f94f3b11fe8bff1bf2a054143789e76aaf17 (git); 7f80a2fd7db9a55894fd841915236aca611291b5 through before 9756b3db5db6c2f5eccb32dddbd88eb4c54f575e (git); 7f80a2fd7db9a55894fd841915236aca611291b5 through before c1fa0bb633e4a6b11e83ffc57fa5abe8ebb87891 (git); 5.17; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nexit: prevent preemption of oopsing TASK_DEAD task\n\nWhen an already-exiting task oopses, make_task_dead() currently calls\ndo_task_dead() with preemption enabled.  That is forbidden:\ndo_task_dead() calls __schedule(), which has a comment saying \"WARNING:\nmust be called with preemption disabled!\".\n\nIf an oopsing task is preempted in do_task_dead(), between becoming\nTASK_DEAD and entering the scheduler explicitly, bad things happen:\nfinish_task_switch() assumes that once the scheduler has switched away\nfrom a TASK_DEAD task, the task can never run again and its stack is no\nlonger needed; but that assumption apparently doesn't hold if the dead\ntask was preempted (the SM_PREEMPT case).\n\nThis means that the scheduler ends up repeatedly dropping references on\nthe dead task's stack, which can lead to use-after-free or double-free\nof the entire task stack; in other words, two tasks can end up running\non the same stack, resulting in various kinds of memory corruption.\n\n(This does not just affect \"recursively oopsing\" tasks; it is enough to\noops once during task exit, for example in a file_operations::release\nhandler)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/3d6fb8a7690c23e3213c4b008f64d89a44b98737",
                "https://git.kernel.org/stable/c/640b4c00fb0e2920327435f6176cbefc3c546165",
                "https://git.kernel.org/stable/c/6f49f94f3b11fe8bff1bf2a054143789e76aaf17",
                "https://git.kernel.org/stable/c/7b2800ba5f5f77a8ee7f4cbadb19cf1264597a34",
                "https://git.kernel.org/stable/c/9756b3db5db6c2f5eccb32dddbd88eb4c54f575e",
                "https://git.kernel.org/stable/c/c1fa0bb633e4a6b11e83ffc57fa5abe8ebb87891",
                "https://project-zero.issues.chromium.org/issues/510793286",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-28T10:16:32.923",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46173"
                }
            ]
        },
        {
            "id": "CVE-2026-46172",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: xfrm6: release dst on error in xfrm6_rcv_encap()\n\nxfrm6_rcv_encap() performs an IPv6 route lookup when the skb does not\nalready have a dst attached. ip6_route_input_lookup() returns a\nreferenced dst entry even when the lookup resolves to an error route.\n\nIf dst->error is set, xfrm6_rcv_encap() drops the skb without attaching\nthe dst to the skb and without releasing the reference returned by the\nlookup. Repeated packets hitting this path therefore leak dst entries.\n\nRelease the dst before jumping to the drop path.",
            "updated_at": "2026-09-08T09:18:08.457",
            "published_at": "2026-05-28T10:16:32.830",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0146dca70b877b73c5fd9c67912b8a0ca8a7bac7 through before a0721bcd72641c32b281f227a94505b31cf54117 (git); 0146dca70b877b73c5fd9c67912b8a0ca8a7bac7 through before a20b34f6e854fe6f2aa82528fae7a88759919eb4 (git); 0146dca70b877b73c5fd9c67912b8a0ca8a7bac7 through before 870560015ce6e0d8f841c6a8aba33c44be52c727 (git); 0146dca70b877b73c5fd9c67912b8a0ca8a7bac7 through before c2efc4956981066df2fef1cc77391b523db6d8e4 (git); 0146dca70b877b73c5fd9c67912b8a0ca8a7bac7 through before 554c9b090c8ac5b1c5c507f4badf8d5d0c9c6e13 (git); 0146dca70b877b73c5fd9c67912b8a0ca8a7bac7 through before 9d5047782f9bd2829e529df69209bf3232eb561f (git); 0146dca70b877b73c5fd9c67912b8a0ca8a7bac7 through before 6a5eec0a2a0e99ec9743cf8f1c4082178811d90a (git); 0146dca70b877b73c5fd9c67912b8a0ca8a7bac7 through before bc0fcb9823cd0894934cf968b525c575833d7078 (git); 5.8; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: xfrm6: release dst on error in xfrm6_rcv_encap()\n\nxfrm6_rcv_encap() performs an IPv6 route lookup when the skb does not\nalready have a dst attached. ip6_route_input_lookup() returns a\nreferenced dst entry even when the lookup resolves to an error route.\n\nIf dst->error is set, xfrm6_rcv_encap() drops the skb without attaching\nthe dst to the skb and without releasing the reference returned by the\nlookup. Repeated packets hitting this path therefore leak dst entries.\n\nRelease the dst before jumping to the drop path.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/554c9b090c8ac5b1c5c507f4badf8d5d0c9c6e13",
                "https://git.kernel.org/stable/c/6a5eec0a2a0e99ec9743cf8f1c4082178811d90a",
                "https://git.kernel.org/stable/c/870560015ce6e0d8f841c6a8aba33c44be52c727",
                "https://git.kernel.org/stable/c/9d5047782f9bd2829e529df69209bf3232eb561f",
                "https://git.kernel.org/stable/c/a0721bcd72641c32b281f227a94505b31cf54117",
                "https://git.kernel.org/stable/c/a20b34f6e854fe6f2aa82528fae7a88759919eb4",
                "https://git.kernel.org/stable/c/bc0fcb9823cd0894934cf968b525c575833d7078",
                "https://git.kernel.org/stable/c/c2efc4956981066df2fef1cc77391b523db6d8e4",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-28T10:16:32.830",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46172"
                }
            ]
        },
        {
            "id": "CVE-2026-46170",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: ADD_ADDR rtx: free sk if last\n\nWhen an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(),\nand released at the end.\n\nIf at that moment, it was the last reference being held, the sk would\nnot be freed. sock_put() should then be called instead of __sock_put().\n\nBut that's not enough: if it is the last reference, sock_put() will call\nsk_free(), which will end up calling sk_stop_timer_sync() on the same\ntimer, and waiting indefinitely to finish. So it is needed to mark that\nthe timer is done at the end of the timer handler when it has not been\nrescheduled, not to call sk_stop_timer_sync() on \"itself\".",
            "updated_at": "2026-09-14T12:17:42.270",
            "published_at": "2026-05-28T10:16:32.650",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before aa8cabde7e83bf96269ee47427dc9b59e3ed8e60 (git); 00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before 1f26487e83e69462540bb1047139472957c913c6 (git); 00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before 5da972efed3dc7599da6e2b5e8d906d1b7b1a728 (git); 00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before 6a3af482188f6db4186d1605f64d911d7330abb3 (git); 00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before 531c537b8fb620beabccfb1594e8d43cbebbb87a (git); 00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before b74ad20198652b6b39a761c277ba65ae82b1e107 (git); 00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before 8143a224785ceaf2b0856e08d4498916f38228fb (git); 00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before b7b9a461569734d33d3259d58d2507adfac107ed (git); 5.10",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: ADD_ADDR rtx: free sk if last\n\nWhen an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(),\nand released at the end.\n\nIf at that moment, it was the last reference being held, the sk would\nnot be freed. sock_put() should then be called instead of __sock_put().\n\nBut that's not enough: if it is the last reference, sock_put() will call\nsk_free(), which will end up calling sk_stop_timer_sync() on the same\ntimer, and waiting indefinitely to finish. So it is needed to mark that\nthe timer is done at the end of the timer handler when it has not been\nrescheduled, not to call sk_stop_timer_sync() on \"itself\".",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1f26487e83e69462540bb1047139472957c913c6",
                "https://git.kernel.org/stable/c/531c537b8fb620beabccfb1594e8d43cbebbb87a",
                "https://git.kernel.org/stable/c/5da972efed3dc7599da6e2b5e8d906d1b7b1a728",
                "https://git.kernel.org/stable/c/6a3af482188f6db4186d1605f64d911d7330abb3",
                "https://git.kernel.org/stable/c/8143a224785ceaf2b0856e08d4498916f38228fb",
                "https://git.kernel.org/stable/c/aa8cabde7e83bf96269ee47427dc9b59e3ed8e60",
                "https://git.kernel.org/stable/c/b74ad20198652b6b39a761c277ba65ae82b1e107",
                "https://git.kernel.org/stable/c/b7b9a461569734d33d3259d58d2507adfac107ed"
            ],
            "timeline": [
                {
                    "at": "2026-05-28T10:16:32.650",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46170"
                }
            ]
        },
        {
            "id": "CVE-2026-46158",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: ADD_ADDR rtx: always decrease sk refcount\n\nWhen an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer().\nIt should then be released in all cases at the end.\n\nSome (unlikely) checks were returning directly instead of calling\nsock_put() to decrease the refcount. Jump to a new 'exit' label to call\n__sock_put() (which will become sock_put() in the next commit) to fix\nthis potential leak.\n\nWhile at it, drop the '!msk' check which cannot happen because it is\nnever reset, and explicitly mark the remaining one as \"unlikely\".",
            "updated_at": "2026-09-14T12:17:42.110",
            "published_at": "2026-05-28T10:16:31.460",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before f5555a6d7c472849fdf2b426e3d0a85103118793 (git); 00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before e9ba34301d2e90f63f97c76ad9eb98e5250fe961 (git); 00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before 81d8142148164176385c279c7c1e1d581867423d (git); 00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before 9426265e157dd77ec237c795901ed4dea6d69b5c (git); 00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before b41dd76f3b9735096c21d3e799a2b9fe36498d57 (git); 00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before acd3d3562315c99f3c0db16f0fcc5f0306638982 (git); 00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before 25e37407442b8766ec2cf52fb4e31b5c3d3aeeae (git); 00cfd77b9063dcdf3628a7087faba60de85a9cc8 through before 9634cb35af17019baec21ca648516ce376fa10e6 (git); 5.10",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: ADD_ADDR rtx: always decrease sk refcount\n\nWhen an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer().\nIt should then be released in all cases at the end.\n\nSome (unlikely) checks were returning directly instead of calling\nsock_put() to decrease the refcount. Jump to a new 'exit' label to call\n__sock_put() (which will become sock_put() in the next commit) to fix\nthis potential leak.\n\nWhile at it, drop the '!msk' check which cannot happen because it is\nnever reset, and explicitly mark the remaining one as \"unlikely\".",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/25e37407442b8766ec2cf52fb4e31b5c3d3aeeae",
                "https://git.kernel.org/stable/c/81d8142148164176385c279c7c1e1d581867423d",
                "https://git.kernel.org/stable/c/9426265e157dd77ec237c795901ed4dea6d69b5c",
                "https://git.kernel.org/stable/c/9634cb35af17019baec21ca648516ce376fa10e6",
                "https://git.kernel.org/stable/c/acd3d3562315c99f3c0db16f0fcc5f0306638982",
                "https://git.kernel.org/stable/c/b41dd76f3b9735096c21d3e799a2b9fe36498d57",
                "https://git.kernel.org/stable/c/e9ba34301d2e90f63f97c76ad9eb98e5250fe961",
                "https://git.kernel.org/stable/c/f5555a6d7c472849fdf2b426e3d0a85103118793"
            ],
            "timeline": [
                {
                    "at": "2026-05-28T10:16:31.460",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46158"
                }
            ]
        },
        {
            "id": "CVE-2026-46132",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo\n\nrtnl_fill_vfinfo() declares struct ifla_vf_broadcast on the stack\nwithout initialisation:\n\n\tstruct ifla_vf_broadcast vf_broadcast;\n\nThe struct contains a single fixed 32-byte field:\n\n\t/* include/uapi/linux/if_link.h */\n\tstruct ifla_vf_broadcast {\n\t\t__u8 broadcast[32];\n\t};\n\nThe function then copies dev->broadcast into it using dev->addr_len\nas the length:\n\n\tmemcpy(vf_broadcast.broadcast, dev->broadcast, dev->addr_len);\n\nOn Ethernet devices (the overwhelming majority of SR-IOV NICs)\ndev->addr_len is 6, so only the first 6 bytes of broadcast[] are\nwritten. The remaining 26 bytes retain whatever was previously on\nthe kernel stack. The full struct is then handed to userspace via:\n\n\tnla_put(skb, IFLA_VF_BROADCAST,\n\t\tsizeof(vf_broadcast), &vf_broadcast)\n\nleaking up to 26 bytes of uninitialised kernel stack per VF per\nRTM_GETLINK request, repeatable.\n\nThe other vf_* structs in the same function are explicitly zeroed\nfor exactly this reason - see the memset() calls for ivi,\nvf_vlan_info, node_guid and port_guid a few lines above.\nvf_broadcast was simply missed when it was added.\n\nReachability: any unprivileged local process can open AF_NETLINK /\nNETLINK_ROUTE without capabilities and send RTM_GETLINK with an\nIFLA_EXT_MASK attribute carrying RTEXT_FILTER_VF. The kernel walks\neach VF and emits IFLA_VF_BROADCAST, leaking 26 bytes of stack per\nVF per request. Stack residue at this call site can include return\naddresses and transient sensitive data; KASAN with stack\ninstrumentation, or KMSAN, will flag the nla_put() when reproduced.\n\nZero the on-stack struct before the partial memcpy, matching the\nexisting pattern used for the other vf_* structs in the same\nfunction.",
            "updated_at": "2026-09-08T09:18:08.247",
            "published_at": "2026-05-28T10:16:28.753",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "75345f888f700c4ab2448287e35d48c760b202e6 through before 14271b401ec6a4bf0d88054106fc2956084717e1 (git); 75345f888f700c4ab2448287e35d48c760b202e6 through before cccce3190ba4356432b9f22369b56123d3d89f0d (git); 75345f888f700c4ab2448287e35d48c760b202e6 through before a44fbb631cba646532f3948636626f81717365a7 (git); 75345f888f700c4ab2448287e35d48c760b202e6 through before 0653c0516234c8258975d268a749115fc0f0ff00 (git); 75345f888f700c4ab2448287e35d48c760b202e6 through before c5b1b92ab7eff1a6e8c507ddde6fd02fabd0cfa8 (git); 75345f888f700c4ab2448287e35d48c760b202e6 through before fbe0e6197225e6a83cf113a67a4b425f8de0bcd5 (git); 75345f888f700c4ab2448287e35d48c760b202e6 through before 38bcc21f52246badb3154b6158dcb381d98de011 (git); 75345f888f700c4ab2448287e35d48c760b202e6 through before 4b9e327991815e128ad3af75c3a04630a63ce3e0 (git); 5.3; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-908",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo\n\nrtnl_fill_vfinfo() declares struct ifla_vf_broadcast on the stack\nwithout initialisation:\n\n\tstruct ifla_vf_broadcast vf_broadcast;\n\nThe struct contains a single fixed 32-byte field:\n\n\t/* include/uapi/linux/if_link.h */\n\tstruct ifla_vf_broadcast {\n\t\t__u8 broadcast[32];\n\t};\n\nThe function then copies dev->broadcast into it using dev->addr_len\nas the length:\n\n\tmemcpy(vf_broadcast.broadcast, dev->broadcast, dev->addr_len);\n\nOn Ethernet devices (the overwhelming majority of SR-IOV NICs)\ndev->addr_len is 6, so only the first 6 bytes of broadcast[] are\nwritten. The remaining 26 bytes retain whatever was previously on\nthe kernel stack. The full struct is then handed to userspace via:\n\n\tnla_put(skb, IFLA_VF_BROADCAST,\n\t\tsizeof(vf_broadcast), &vf_broadcast)\n\nleaking up to 26 bytes of uninitialised kernel stack per VF per\nRTM_GETLINK request, repeatable.\n\nThe other vf_* structs in the same function are explicitly zeroed\nfor exactly this reason - see the memset() calls for ivi,\nvf_vlan_info, node_guid and port_guid a few lines above.\nvf_broadcast was simply missed when it was added.\n\nReachability: any unprivileged local process can open AF_NETLINK /\nNETLINK_ROUTE without capabilities and send RTM_GETLINK with an\nIFLA_EXT_MASK attribute carrying RTEXT_FILTER_VF. The kernel walks\neach VF and emits IFLA_VF_BROADCAST, leaking 26 bytes of stack per\nVF per request. Stack residue at this call site can include return\naddresses and transient sensitive data; KASAN with stack\ninstrumentation, or KMSAN, will flag the nla_put() when reproduced.\n\nZero the on-stack struct before the partial memcpy, matching the\nexisting pattern used for the other vf_* structs in the same\nfunction.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0653c0516234c8258975d268a749115fc0f0ff00",
                "https://git.kernel.org/stable/c/14271b401ec6a4bf0d88054106fc2956084717e1",
                "https://git.kernel.org/stable/c/38bcc21f52246badb3154b6158dcb381d98de011",
                "https://git.kernel.org/stable/c/4b9e327991815e128ad3af75c3a04630a63ce3e0",
                "https://git.kernel.org/stable/c/a44fbb631cba646532f3948636626f81717365a7",
                "https://git.kernel.org/stable/c/c5b1b92ab7eff1a6e8c507ddde6fd02fabd0cfa8",
                "https://git.kernel.org/stable/c/cccce3190ba4356432b9f22369b56123d3d89f0d",
                "https://git.kernel.org/stable/c/fbe0e6197225e6a83cf113a67a4b425f8de0bcd5",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-28T10:16:28.753",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46132"
                }
            ]
        },
        {
            "id": "CVE-2026-46117",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()\n\nSashiko points out that the user can specify WQs sharing the same CQ as a\npart of the uAPI and this will trigger the WARN_ON() then go on to corrupt\nthe kernel.\n\nJust reject it outright and fail the QP creation.",
            "updated_at": "2026-09-16T13:17:59.973",
            "published_at": "2026-05-28T10:16:27.203",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c15d7802a42402a87880a17eee89ff023e49ecc0 through before 9cc0c6b1ba8cd5c55aef043e1384de0a8b4efa71 (git); c15d7802a42402a87880a17eee89ff023e49ecc0 through before 9ef65af26b2a6738bf15812042e84b3112402d3a (git); c15d7802a42402a87880a17eee89ff023e49ecc0 through before db991ba50087ad99fa12a2c483aa3be19671ea73 (git); c15d7802a42402a87880a17eee89ff023e49ecc0 through before 159f2efabc89d3f931d38f2d35876535d4abf0a3 (git); 6.8",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-617",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()\n\nSashiko points out that the user can specify WQs sharing the same CQ as a\npart of the uAPI and this will trigger the WARN_ON() then go on to corrupt\nthe kernel.\n\nJust reject it outright and fail the QP creation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/159f2efabc89d3f931d38f2d35876535d4abf0a3",
                "https://git.kernel.org/stable/c/9cc0c6b1ba8cd5c55aef043e1384de0a8b4efa71",
                "https://git.kernel.org/stable/c/9ef65af26b2a6738bf15812042e84b3112402d3a",
                "https://git.kernel.org/stable/c/db991ba50087ad99fa12a2c483aa3be19671ea73",
                "https://access.redhat.com/errata/RHSA-2026:27789",
                "https://access.redhat.com/errata/RHSA-2026:30129",
                "https://access.redhat.com/errata/RHSA-2026:42550",
                "https://access.redhat.com/errata/RHSA-2026:42552",
                "https://access.redhat.com/errata/RHSA-2026:65712",
                "https://access.redhat.com/errata/RHSA-2026:67720",
                "https://access.redhat.com/security/cve/CVE-2026-46117",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2482576",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46117.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-28T10:16:27.203",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46117"
                }
            ]
        },
        {
            "id": "CVE-2026-46116",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: defensively unhash xfrm_state lists in __xfrm_state_delete\n\nKASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s\nhlist_del_rcu calls under syzkaller load on linux-6.12.y stable\n(reproduced on 6.12.47, also reachable via the same code path on\ntorvalds/master and on the ipsec tree). Nine unique signatures cluster\nin the xfrm_state lifecycle, the load-bearing one being:\n\n  BUG: KASAN: slab-use-after-free in __hlist_del include/linux/list.h:990 [inline]\n  BUG: KASAN: slab-use-after-free in hlist_del_rcu include/linux/rculist.h:516 [inline]\n  BUG: KASAN: slab-use-after-free in __xfrm_state_delete net/xfrm/xfrm_state.c\n  Write of size 8 at addr ffff8881198bcb70 by task kworker/u8:9/435\n\n  Workqueue: netns cleanup_net\n  Call Trace:\n   __hlist_del / hlist_del_rcu\n   __xfrm_state_delete\n   xfrm_state_delete\n   xfrm_state_flush\n   xfrm_state_fini\n   ops_exit_list\n   cleanup_net\n\nThe other observed signatures hit the same slab object from\n__xfrm_state_lookup, xfrm_alloc_spi, __xfrm_state_insert and an OOB\nwrite variant of __xfrm_state_delete, all on the byseq/byspi\nhash chains.\n\n__xfrm_state_delete() guards its byseq and byspi unhashes with\nvalue-based predicates:\n\n\tif (x->km.seq)\n\t\thlist_del_rcu(&x->byseq);\n\tif (x->id.spi)\n\t\thlist_del_rcu(&x->byspi);\n\nwhile everywhere else in the file (e.g. state_cache, state_cache_input)\nthe safer hlist_unhashed() check is used. xfrm_alloc_spi() sets\nx->id.spi = newspi inside xfrm_state_lock and then immediately inserts\ninto byspi, but a path that observes x->id.spi != 0 outside of\nxfrm_state_lock can still skip-or-hit the byspi unhash inconsistently\nwith whether x is actually on the list. The same holds for x->km.seq\nversus byseq, and the bydst/bysrc unhashes have no predicate at all,\nso a second __xfrm_state_delete() on the same object writes through\nLIST_POISON pprev.\n\nThe defensive change here:\n\n  - Use hlist_del_init_rcu() instead of hlist_del_rcu() on bydst,\n    bysrc, byseq and byspi so a second deletion is a no-op rather\n    than a write through LIST_POISON pprev. The byseq/byspi nodes\n    are already initialised in xfrm_state_alloc().\n  - Test hlist_unhashed() rather than the value predicate for\n    byseq/byspi, so the unhash decision tracks list state rather than\n    mutable scalar fields.\n\nEmpirical verification: applied this patch on top of v6.12.47, rebuilt,\nand re-ran the same syzkaller harness for 1h16m on a previously-crashy\nconfiguration that produced ~100 hits each of slab-use-after-free\nRead in xfrm_alloc_spi / Read in __xfrm_state_lookup / Write in\n__xfrm_state_delete. After the patch, 7.1M execs across 32 VMs at\n~1550 exec/sec produced zero xfrm_state UAF/OOB hits. /proc/slabinfo\nconfirms the xfrm_state slab is actively allocated and freed during\nthe run (~143 KiB resident), so the fuzzer is still exercising those\ncode paths -- they just no longer crash.\n\nReproduction:\n\n  - Linux 6.12.47 x86_64 + KASAN_GENERIC + KASAN_INLINE + KCOV\n  - syzkaller @ 746545b8b1e4c3a128db8652b340d3df90ce61db\n  - 32 QEMU/KVM VMs x 2 vCPU on AWS c5.metal bare metal\n  - 9 unique signatures collected in ~9h, all within xfrm_state\n    lifecycle",
            "updated_at": "2026-09-15T12:17:49.593",
            "published_at": "2026-05-28T10:16:27.080",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7b4dc3600e4877178ba94c7fbf7e520421378aa6 through before 6b4dc3181b4bfc5f5fc33ab33b1dc6e15759f4b6 (git); 7b4dc3600e4877178ba94c7fbf7e520421378aa6 through before 3943fcad7694a7d0b15aeabe7d3cc2a2eb8e92e8 (git); 7b4dc3600e4877178ba94c7fbf7e520421378aa6 through before 2c617848ae6e4f07a3e397f604208c293bbecacc (git); 7b4dc3600e4877178ba94c7fbf7e520421378aa6 through before b4a53add2fa8f1b5aa17d4c5686c320785fab182 (git); 7b4dc3600e4877178ba94c7fbf7e520421378aa6 through before 26edb0a3c99f9d958c212be68b21f1221614dcf0 (git); 7b4dc3600e4877178ba94c7fbf7e520421378aa6 through before 4980162de555cb838f1a189ce7d2cbf5d2e7b050 (git); 7b4dc3600e4877178ba94c7fbf7e520421378aa6 through before a2e2d08fb070fab4947447171f1c4e3ca5a188e5 (git); 7b4dc3600e4877178ba94c7fbf7e520421378aa6 through before 14acf9652e5690de3c7486c6db5fb8dafd0a32a3 (git); 2.6.19; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 33,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: defensively unhash xfrm_state lists in __xfrm_state_delete\n\nKASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s\nhlist_del_rcu calls under syzkaller load on linux-6.12.y stable\n(reproduced on 6.12.47, also reachable via the same code path on\ntorvalds/master and on the ipsec tree). Nine unique signatures cluster\nin the xfrm_state lifecycle, the load-bearing one being:\n\n  BUG: KASAN: slab-use-after-free in __hlist_del include/linux/list.h:990 [inline]\n  BUG: KASAN: slab-use-after-free in hlist_del_rcu include/linux/rculist.h:516 [inline]\n  BUG: KASAN: slab-use-after-free in __xfrm_state_delete net/xfrm/xfrm_state.c\n  Write of size 8 at addr ffff8881198bcb70 by task kworker/u8:9/435\n\n  Workqueue: netns cleanup_net\n  Call Trace:\n   __hlist_del / hlist_del_rcu\n   __xfrm_state_delete\n   xfrm_state_delete\n   xfrm_state_flush\n   xfrm_state_fini\n   ops_exit_list\n   cleanup_net\n\nThe other observed signatures hit the same slab object from\n__xfrm_state_lookup, xfrm_alloc_spi, __xfrm_state_insert and an OOB\nwrite variant of __xfrm_state_delete, all on the byseq/byspi\nhash chains.\n\n__xfrm_state_delete() guards its byseq and byspi unhashes with\nvalue-based predicates:\n\n\tif (x->km.seq)\n\t\thlist_del_rcu(&x->byseq);\n\tif (x->id.spi)\n\t\thlist_del_rcu(&x->byspi);\n\nwhile everywhere else in the file (e.g. state_cache, state_cache_input)\nthe safer hlist_unhashed() check is used. xfrm_alloc_spi() sets\nx->id.spi = newspi inside xfrm_state_lock and then immediately inserts\ninto byspi, but a path that observes x->id.spi != 0 outside of\nxfrm_state_lock can still skip-or-hit the byspi unhash inconsistently\nwith whether x is actually on the list. The same holds for x->km.seq\nversus byseq, and the bydst/bysrc unhashes have no predicate at all,\nso a second __xfrm_state_delete() on the same object writes through\nLIST_POISON pprev.\n\nThe defensive change here:\n\n  - Use hlist_del_init_rcu() instead of hlist_del_rcu() on bydst,\n    bysrc, byseq and byspi so a second deletion is a no-op rather\n    than a write through LIST_POISON pprev. The byseq/byspi nodes\n    are already initialised in xfrm_state_alloc().\n  - Test hlist_unhashed() rather than the value predicate for\n    byseq/byspi, so the unhash decision tracks list state rather than\n    mutable scalar fields.\n\nEmpirical verification: applied this patch on top of v6.12.47, rebuilt,\nand re-ran the same syzkaller harness for 1h16m on a previously-crashy\nconfiguration that produced ~100 hits each of slab-use-after-free\nRead in xfrm_alloc_spi / Read in __xfrm_state_lookup / Write in\n__xfrm_state_delete. After the patch, 7.1M execs across 32 VMs at\n~1550 exec/sec produced zero xfrm_state UAF/OOB hits. /proc/slabinfo\nconfirms the xfrm_state slab is actively allocated and freed during\nthe run (~143 KiB resident), so the fuzzer is still exercising those\ncode paths -- they just no longer crash.\n\nReproduction:\n\n  - Linux 6.12.47 x86_64 + KASAN_GENERIC + KASAN_INLINE + KCOV\n  - syzkaller @ 746545b8b1e4c3a128db8652b340d3df90ce61db\n  - 32 QEMU/KVM VMs x 2 vCPU on AWS c5.metal bare metal\n  - 9 unique signatures collected in ~9h, all within xfrm_state\n    lifecycle",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/14acf9652e5690de3c7486c6db5fb8dafd0a32a3",
                "https://git.kernel.org/stable/c/26edb0a3c99f9d958c212be68b21f1221614dcf0",
                "https://git.kernel.org/stable/c/2c617848ae6e4f07a3e397f604208c293bbecacc",
                "https://git.kernel.org/stable/c/3943fcad7694a7d0b15aeabe7d3cc2a2eb8e92e8",
                "https://git.kernel.org/stable/c/4980162de555cb838f1a189ce7d2cbf5d2e7b050",
                "https://git.kernel.org/stable/c/6b4dc3181b4bfc5f5fc33ab33b1dc6e15759f4b6",
                "https://git.kernel.org/stable/c/a2e2d08fb070fab4947447171f1c4e3ca5a188e5",
                "https://git.kernel.org/stable/c/b4a53add2fa8f1b5aa17d4c5686c320785fab182",
                "https://access.redhat.com/errata/RHSA-2026:36018",
                "https://access.redhat.com/errata/RHSA-2026:39179",
                "https://access.redhat.com/errata/RHSA-2026:39180",
                "https://access.redhat.com/errata/RHSA-2026:39371",
                "https://access.redhat.com/errata/RHSA-2026:41234",
                "https://access.redhat.com/errata/RHSA-2026:41235",
                "https://access.redhat.com/errata/RHSA-2026:42919",
                "https://access.redhat.com/errata/RHSA-2026:43231",
                "https://access.redhat.com/errata/RHSA-2026:44385",
                "https://access.redhat.com/errata/RHSA-2026:47632",
                "https://access.redhat.com/errata/RHSA-2026:47633",
                "https://access.redhat.com/errata/RHSA-2026:47739",
                "https://access.redhat.com/errata/RHSA-2026:47869",
                "https://access.redhat.com/errata/RHSA-2026:49033",
                "https://access.redhat.com/errata/RHSA-2026:59142",
                "https://access.redhat.com/errata/RHSA-2026:59143",
                "https://access.redhat.com/errata/RHSA-2026:59145",
                "https://access.redhat.com/errata/RHSA-2026:59146",
                "https://access.redhat.com/errata/RHSA-2026:59147",
                "https://access.redhat.com/errata/RHSA-2026:59148",
                "https://access.redhat.com/errata/RHSA-2026:59149",
                "https://access.redhat.com/security/cve/CVE-2026-46116",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2482523",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46116.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-28T10:16:27.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46116"
                }
            ]
        },
        {
            "id": "CVE-2026-46101",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: reject zero shift in nft_bitwise\n\nReject zero shift operands for nft_bitwise left and right shift\nexpressions during initialization.\n\nThe carry propagation logic computes the carry from the adjacent 32-bit\nword using BITS_PER_TYPE(u32) - shift. A zero shift operand turns this\ninto a 32-bit shift, which is undefined behaviour.\n\nReject zero shift operands in the control plane, alongside the existing\ncheck for values greater than or equal to 32, so malformed rules never\nreach the packet path.",
            "updated_at": "2026-09-08T09:18:07.610",
            "published_at": "2026-05-27T14:17:32.147",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "567d746b55bc66d3800c9ae91d50f0c5deb2fd93 through before 9baa08d6b6b096fad70049533f0d705d85fdc979 (git); 567d746b55bc66d3800c9ae91d50f0c5deb2fd93 through before 4fccea585631621c975883911a08d15b6671f7dc (git); 567d746b55bc66d3800c9ae91d50f0c5deb2fd93 through before 9ad26c272405f53834871cc2e46b9b5393a666c3 (git); 567d746b55bc66d3800c9ae91d50f0c5deb2fd93 through before bffef0acec9c3b837a785248a893137fb7f26c95 (git); 567d746b55bc66d3800c9ae91d50f0c5deb2fd93 through before ca24f1243ad1a4d12d6a23876bbbe3ed02099853 (git); 567d746b55bc66d3800c9ae91d50f0c5deb2fd93 through before 6f820139d16a4c9865a145d4a9cf9c92cc632c14 (git); 567d746b55bc66d3800c9ae91d50f0c5deb2fd93 through before f370205974f171a5868c13ff30d7642fed46e47b (git); 567d746b55bc66d3800c9ae91d50f0c5deb2fd93 through before fe11e5c40817b84abaa5d83bfb6586d8412bfd07 (git); 5.6; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: reject zero shift in nft_bitwise\n\nReject zero shift operands for nft_bitwise left and right shift\nexpressions during initialization.\n\nThe carry propagation logic computes the carry from the adjacent 32-bit\nword using BITS_PER_TYPE(u32) - shift. A zero shift operand turns this\ninto a 32-bit shift, which is undefined behaviour.\n\nReject zero shift operands in the control plane, alongside the existing\ncheck for values greater than or equal to 32, so malformed rules never\nreach the packet path.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/4fccea585631621c975883911a08d15b6671f7dc",
                "https://git.kernel.org/stable/c/6f820139d16a4c9865a145d4a9cf9c92cc632c14",
                "https://git.kernel.org/stable/c/9ad26c272405f53834871cc2e46b9b5393a666c3",
                "https://git.kernel.org/stable/c/9baa08d6b6b096fad70049533f0d705d85fdc979",
                "https://git.kernel.org/stable/c/bffef0acec9c3b837a785248a893137fb7f26c95",
                "https://git.kernel.org/stable/c/ca24f1243ad1a4d12d6a23876bbbe3ed02099853",
                "https://git.kernel.org/stable/c/f370205974f171a5868c13ff30d7642fed46e47b",
                "https://git.kernel.org/stable/c/fe11e5c40817b84abaa5d83bfb6586d8412bfd07",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T14:17:32.147",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46101"
                }
            ]
        },
        {
            "id": "CVE-2026-46090",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: aloop: Fix peer runtime UAF during format-change stop\n\nloopback_check_format() may stop the capture side when playback starts\nwith parameters that no longer match a running capture stream. Commit\n826af7fa62e3 (\"ALSA: aloop: Fix racy access at PCM trigger\") moved\nthe peer lookup under cable->lock, but the actual snd_pcm_stop() still\nruns after dropping that lock.\n\nA concurrent close can clear the capture entry from cable->streams[] and\ndetach or free its runtime while the playback trigger path still holds a\nstale peer substream pointer.\n\nKeep a per-cable count of in-flight peer stops before dropping\ncable->lock, and make free_cable() wait for those stops before\ndetaching the runtime. This preserves the existing behavior while\nmaking the peer runtime lifetime explicit.",
            "updated_at": "2026-09-14T12:17:41.723",
            "published_at": "2026-05-27T14:17:30.547",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "597603d615d2b19a9e451d8cfac24372856a522d through before 83bd62fa9620ac98d5d694bde14c50f98c8e7189 (git); 597603d615d2b19a9e451d8cfac24372856a522d through before 345c24b2bcf0923dfae1ab41497351c68214ff76 (git); 597603d615d2b19a9e451d8cfac24372856a522d through before 3727a3541788412c393eec236ad228d72efe19c7 (git); 597603d615d2b19a9e451d8cfac24372856a522d through before d258cdce50ff3e02392917258e81a0ce9555c327 (git); 597603d615d2b19a9e451d8cfac24372856a522d through before 03f52a9c170431e8f10e156b9dc0dae80b3e9198 (git); 597603d615d2b19a9e451d8cfac24372856a522d through before bdd9503c3d222d2735b56c7a8b4422ccf3de6e5c (git); 597603d615d2b19a9e451d8cfac24372856a522d through before 5d45e34bf001344e2966dabca1897561bbc9e913 (git); 597603d615d2b19a9e451d8cfac24372856a522d through before e5c33cdc6f402eab8abd36ecf436b22c9d3a8aff (git); 2.6.37",
            "fixed": "See vendor advisory",
            "source_count": 25,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: aloop: Fix peer runtime UAF during format-change stop\n\nloopback_check_format() may stop the capture side when playback starts\nwith parameters that no longer match a running capture stream. Commit\n826af7fa62e3 (\"ALSA: aloop: Fix racy access at PCM trigger\") moved\nthe peer lookup under cable->lock, but the actual snd_pcm_stop() still\nruns after dropping that lock.\n\nA concurrent close can clear the capture entry from cable->streams[] and\ndetach or free its runtime while the playback trigger path still holds a\nstale peer substream pointer.\n\nKeep a per-cable count of in-flight peer stops before dropping\ncable->lock, and make free_cable() wait for those stops before\ndetaching the runtime. This preserves the existing behavior while\nmaking the peer runtime lifetime explicit.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/03f52a9c170431e8f10e156b9dc0dae80b3e9198",
                "https://git.kernel.org/stable/c/345c24b2bcf0923dfae1ab41497351c68214ff76",
                "https://git.kernel.org/stable/c/3727a3541788412c393eec236ad228d72efe19c7",
                "https://git.kernel.org/stable/c/5d45e34bf001344e2966dabca1897561bbc9e913",
                "https://git.kernel.org/stable/c/83bd62fa9620ac98d5d694bde14c50f98c8e7189",
                "https://git.kernel.org/stable/c/bdd9503c3d222d2735b56c7a8b4422ccf3de6e5c",
                "https://git.kernel.org/stable/c/d258cdce50ff3e02392917258e81a0ce9555c327",
                "https://git.kernel.org/stable/c/e5c33cdc6f402eab8abd36ecf436b22c9d3a8aff",
                "https://access.redhat.com/errata/RHSA-2026:27353",
                "https://access.redhat.com/errata/RHSA-2026:27354",
                "https://access.redhat.com/errata/RHSA-2026:30848",
                "https://access.redhat.com/errata/RHSA-2026:33215",
                "https://access.redhat.com/errata/RHSA-2026:33685",
                "https://access.redhat.com/errata/RHSA-2026:33899",
                "https://access.redhat.com/errata/RHSA-2026:33900",
                "https://access.redhat.com/errata/RHSA-2026:34094",
                "https://access.redhat.com/errata/RHSA-2026:34095",
                "https://access.redhat.com/errata/RHSA-2026:34443",
                "https://access.redhat.com/errata/RHSA-2026:35844",
                "https://access.redhat.com/errata/RHSA-2026:35863",
                "https://access.redhat.com/errata/RHSA-2026:35896",
                "https://access.redhat.com/errata/RHSA-2026:41236",
                "https://access.redhat.com/security/cve/CVE-2026-46090",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2481980",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46090.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T14:17:30.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46090"
                }
            ]
        },
        {
            "id": "CVE-2026-46086",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: use a stable FDB dst snapshot in RCU readers\n\nLocal FDB entries can be rewritten in place by `fdb_delete_local()`, which\nupdates `f->dst` to another port or to `NULL` while keeping the entry\nalive. Several bridge RCU readers inspect `f->dst`, including\n`br_fdb_fillbuf()` through the `brforward_read()` sysfs path.\n\nThese readers currently load `f->dst` multiple times and can therefore\nobserve inconsistent values across the check and later dereference.\nIn `br_fdb_fillbuf()`, this means a concurrent local-FDB update can change\n`f->dst` after the NULL check and before the `port_no` dereference,\nleading to a NULL-ptr-deref.\n\nFix this by taking a single `READ_ONCE()` snapshot of `f->dst` in each\naffected RCU reader and using that snapshot for the rest of the access\nsequence. Also publish the in-place `f->dst` updates in `fdb_delete_local()`\nwith `WRITE_ONCE()` so the readers and writer use matching access patterns.",
            "updated_at": "2026-09-08T09:18:07.390",
            "published_at": "2026-05-27T14:17:30.080",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "960b589f86c74ce582922fcb996103271081f4de through before c502fa9f094cb03d1d1685c71e2105ab359bc2b8 (git); 960b589f86c74ce582922fcb996103271081f4de through before a6ae4511c07b91f597e461406c6330f0d4ff810e (git); 960b589f86c74ce582922fcb996103271081f4de through before 1406c4e0ed1eaf8a29801ab1163d00fb7ee4359a (git); 960b589f86c74ce582922fcb996103271081f4de through before 0b9e4bbfb7c949151e3acd44ed4aa33614d2e110 (git); 960b589f86c74ce582922fcb996103271081f4de through before 81af4137a30c4c2dc694dea8cacb180bd66000ef (git); 960b589f86c74ce582922fcb996103271081f4de through before 5424e678f9b304e148cf5dcc047cffc7a56a3bb5 (git); 960b589f86c74ce582922fcb996103271081f4de through before 9a2d9d4e657b23dc21f24cf139e3aeff0b61341f (git); 960b589f86c74ce582922fcb996103271081f4de through before df4601653201de21b487c3e7fffd464790cab808 (git); 3.14; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: use a stable FDB dst snapshot in RCU readers\n\nLocal FDB entries can be rewritten in place by `fdb_delete_local()`, which\nupdates `f->dst` to another port or to `NULL` while keeping the entry\nalive. Several bridge RCU readers inspect `f->dst`, including\n`br_fdb_fillbuf()` through the `brforward_read()` sysfs path.\n\nThese readers currently load `f->dst` multiple times and can therefore\nobserve inconsistent values across the check and later dereference.\nIn `br_fdb_fillbuf()`, this means a concurrent local-FDB update can change\n`f->dst` after the NULL check and before the `port_no` dereference,\nleading to a NULL-ptr-deref.\n\nFix this by taking a single `READ_ONCE()` snapshot of `f->dst` in each\naffected RCU reader and using that snapshot for the rest of the access\nsequence. Also publish the in-place `f->dst` updates in `fdb_delete_local()`\nwith `WRITE_ONCE()` so the readers and writer use matching access patterns.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0b9e4bbfb7c949151e3acd44ed4aa33614d2e110",
                "https://git.kernel.org/stable/c/1406c4e0ed1eaf8a29801ab1163d00fb7ee4359a",
                "https://git.kernel.org/stable/c/5424e678f9b304e148cf5dcc047cffc7a56a3bb5",
                "https://git.kernel.org/stable/c/81af4137a30c4c2dc694dea8cacb180bd66000ef",
                "https://git.kernel.org/stable/c/9a2d9d4e657b23dc21f24cf139e3aeff0b61341f",
                "https://git.kernel.org/stable/c/a6ae4511c07b91f597e461406c6330f0d4ff810e",
                "https://git.kernel.org/stable/c/c502fa9f094cb03d1d1685c71e2105ab359bc2b8",
                "https://git.kernel.org/stable/c/df4601653201de21b487c3e7fffd464790cab808",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T14:17:30.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46086"
                }
            ]
        },
        {
            "id": "CVE-2026-46054",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: fix overlayfs mmap() and mprotect() access checks\n\nThe existing SELinux security model for overlayfs is to allow access if\nthe current task is able to access the top level file (the \"user\" file)\nand the mounter's credentials are sufficient to access the lower\nlevel file (the \"backing\" file).  Unfortunately, the current code does\nnot properly enforce these access controls for both mmap() and mprotect()\noperations on overlayfs filesystems.\n\nThis patch makes use of the newly created security_mmap_backing_file()\nLSM hook to provide the missing backing file enforcement for mmap()\noperations, and leverages the backing file API and new LSM blob to\nprovide the necessary information to properly enforce the mprotect()\naccess controls.",
            "updated_at": "2026-09-16T13:17:59.623",
            "published_at": "2026-05-27T14:17:25.043",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2f502839e85ab265f03f25f30d6463154aee5473 through before bc6c380c1159de52a252ed11f19a42c47f60a735 (git); 2f502839e85ab265f03f25f30d6463154aee5473 through before 8bacd09f12c27710228562e4d13163e58c5f4a45 (git); 2f502839e85ab265f03f25f30d6463154aee5473 through before d844702198395d3f80222777030f69db6be6b709 (git); 2f502839e85ab265f03f25f30d6463154aee5473 through before cd0e707a927a70cdfd8bc5a512a9719a87f5ed51 (git); 2f502839e85ab265f03f25f30d6463154aee5473 through before 82544d36b1729153c8aeb179e84750f0c085d3b1 (git); 4.19",
            "fixed": "See vendor advisory",
            "source_count": 20,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-280",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: fix overlayfs mmap() and mprotect() access checks\n\nThe existing SELinux security model for overlayfs is to allow access if\nthe current task is able to access the top level file (the \"user\" file)\nand the mounter's credentials are sufficient to access the lower\nlevel file (the \"backing\" file).  Unfortunately, the current code does\nnot properly enforce these access controls for both mmap() and mprotect()\noperations on overlayfs filesystems.\n\nThis patch makes use of the newly created security_mmap_backing_file()\nLSM hook to provide the missing backing file enforcement for mmap()\noperations, and leverages the backing file API and new LSM blob to\nprovide the necessary information to properly enforce the mprotect()\naccess controls.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/82544d36b1729153c8aeb179e84750f0c085d3b1",
                "https://git.kernel.org/stable/c/8bacd09f12c27710228562e4d13163e58c5f4a45",
                "https://git.kernel.org/stable/c/bc6c380c1159de52a252ed11f19a42c47f60a735",
                "https://git.kernel.org/stable/c/cd0e707a927a70cdfd8bc5a512a9719a87f5ed51",
                "https://git.kernel.org/stable/c/d844702198395d3f80222777030f69db6be6b709",
                "https://access.redhat.com/errata/RHSA-2026:25191",
                "https://access.redhat.com/errata/RHSA-2026:27811",
                "https://access.redhat.com/errata/RHSA-2026:27812",
                "https://access.redhat.com/errata/RHSA-2026:30848",
                "https://access.redhat.com/errata/RHSA-2026:51746",
                "https://access.redhat.com/errata/RHSA-2026:52649",
                "https://access.redhat.com/errata/RHSA-2026:52667",
                "https://access.redhat.com/errata/RHSA-2026:52764",
                "https://access.redhat.com/errata/RHSA-2026:59091",
                "https://access.redhat.com/errata/RHSA-2026:59473",
                "https://access.redhat.com/errata/RHSA-2026:67721",
                "https://access.redhat.com/errata/RHSA-2026:67723",
                "https://access.redhat.com/security/cve/CVE-2026-46054",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2482025",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46054.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T14:17:25.043",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46054"
                }
            ]
        },
        {
            "id": "CVE-2026-46046",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix missing brelse() in ext4_xattr_inode_dec_ref_all()\n\nThe commit c8e008b60492 (\"ext4: ignore xattrs past end\")\nintroduced a refcount leak in when block_csum is false.\n\next4_xattr_inode_dec_ref_all() calls ext4_get_inode_loc() to\nget iloc.bh, but never releases it with brelse().",
            "updated_at": "2026-09-08T09:18:07.223",
            "published_at": "2026-05-27T14:17:24.083",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "76c365fa7e2a8bb85f0190cdb4b8cdc99b2fdce3 through before dd98a5603a212ea9c96c6982ccdbcc748fdb9a56 (git); f737418b6de31c962c7192777ee4018906975383 through before 153ab2c52355fbebcae622db8e7b506492c73a29 (git); cf9291a3449b04688b81e32621e88de8f4314b54 through before b706d00206a9e82362a9633efbd8b5775650169b (git); 362a90cecd36e8a5c415966d0b75b04a0270e4dd through before 1bc1107a3a403a6d440673ed6666f7b07ef868a8 (git); eb59cc31b6ea076021d14b04e7faab1636b87d0e through before 097227f1ffe1a85bc3c359f81c71e3d40e06e920 (git); c8e008b60492cf6fd31ef127aea6d02fd3d314cd through before 1e6b0a69bf2c9c819255c7566e4355536d81d9cf (git); c8e008b60492cf6fd31ef127aea6d02fd3d314cd through before f072906688933bf47fabbaf63560be03357c8298 (git); c8e008b60492cf6fd31ef127aea6d02fd3d314cd through before 77d059519382bd66283e6a4e83ee186e87e7708f (git); 6aff941cb0f7d0c897c3698ad2e30672709135e3 (git); 3bc6317033f365ce578eb6039445fb66162722fd (git); 836e625b03a666cf93ff5be328c8cb30336db872 (git); 5.10.237 through before 5.10.258 (semver); 5.15.181 through before 5.15.209 (semver); 6.1.135 through before 6.1.175 (semver); 6.6.88 through before 6.6.140 (semver); 6.12.24 through before 6.12.86 (semver); 5.4.293 through before 5.5 (semver); 6.13.12 through before 6.14 (semver); 6.14.3 through before 6.15 (semver); 6.15; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix missing brelse() in ext4_xattr_inode_dec_ref_all()\n\nThe commit c8e008b60492 (\"ext4: ignore xattrs past end\")\nintroduced a refcount leak in when block_csum is false.\n\next4_xattr_inode_dec_ref_all() calls ext4_get_inode_loc() to\nget iloc.bh, but never releases it with brelse().",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/097227f1ffe1a85bc3c359f81c71e3d40e06e920",
                "https://git.kernel.org/stable/c/153ab2c52355fbebcae622db8e7b506492c73a29",
                "https://git.kernel.org/stable/c/1bc1107a3a403a6d440673ed6666f7b07ef868a8",
                "https://git.kernel.org/stable/c/1e6b0a69bf2c9c819255c7566e4355536d81d9cf",
                "https://git.kernel.org/stable/c/77d059519382bd66283e6a4e83ee186e87e7708f",
                "https://git.kernel.org/stable/c/b706d00206a9e82362a9633efbd8b5775650169b",
                "https://git.kernel.org/stable/c/dd98a5603a212ea9c96c6982ccdbcc748fdb9a56",
                "https://git.kernel.org/stable/c/f072906688933bf47fabbaf63560be03357c8298",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T14:17:24.083",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46046"
                }
            ]
        },
        {
            "id": "CVE-2026-46040",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ninotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails\n\nWhen fsnotify_add_inode_mark_locked() fails in inotify_new_watch(),\nthe error path calls inotify_remove_from_idr() but does not call\ndec_inotify_watches() to undo the preceding inc_inotify_watches().\nThis leaks a watch count, and repeated failures can exhaust the\nmax_user_watches limit with -ENOSPC even when no watches are active.\n\nPrior to commit 1cce1eea0aff (\"inotify: Convert to using per-namespace\nlimits\"), the watch count was incremented after fsnotify_add_mark_locked()\nsucceeded, so this path was not affected. The conversion moved\ninc_inotify_watches() before the mark insertion without adding the\ncorresponding rollback.\n\nAdd the missing dec_inotify_watches() call in the error path.",
            "updated_at": "2026-09-08T09:18:07.063",
            "published_at": "2026-05-27T14:17:23.387",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1cce1eea0aff51201753fcaca421df825b0813b6 through before 3ab58cf42c46bf2366d2f55ae5c59299d5e178b7 (git); 1cce1eea0aff51201753fcaca421df825b0813b6 through before 10edf7e0ffdc7faa18e2244b17722c1b882b8273 (git); 1cce1eea0aff51201753fcaca421df825b0813b6 through before 3ad9ccea1b25435f6179b57aa891960beb7ce8f9 (git); 1cce1eea0aff51201753fcaca421df825b0813b6 through before 8bcc1cd237ab5ccfdd102869fa031c541943cf40 (git); 1cce1eea0aff51201753fcaca421df825b0813b6 through before 73ddc8518a32baff6bc17afda4ee1ebae5b4ed12 (git); 1cce1eea0aff51201753fcaca421df825b0813b6 through before fdaa42ca370d056428e5e171247c8fdce8dff36a (git); 1cce1eea0aff51201753fcaca421df825b0813b6 through before 9e48844f708eb48bae4e79cb21edc097c966306d (git); 1cce1eea0aff51201753fcaca421df825b0813b6 through before 6a320935fa4293e9e599ec9f85dc9eb3be7029f8 (git); 4.11; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ninotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails\n\nWhen fsnotify_add_inode_mark_locked() fails in inotify_new_watch(),\nthe error path calls inotify_remove_from_idr() but does not call\ndec_inotify_watches() to undo the preceding inc_inotify_watches().\nThis leaks a watch count, and repeated failures can exhaust the\nmax_user_watches limit with -ENOSPC even when no watches are active.\n\nPrior to commit 1cce1eea0aff (\"inotify: Convert to using per-namespace\nlimits\"), the watch count was incremented after fsnotify_add_mark_locked()\nsucceeded, so this path was not affected. The conversion moved\ninc_inotify_watches() before the mark insertion without adding the\ncorresponding rollback.\n\nAdd the missing dec_inotify_watches() call in the error path.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/10edf7e0ffdc7faa18e2244b17722c1b882b8273",
                "https://git.kernel.org/stable/c/3ab58cf42c46bf2366d2f55ae5c59299d5e178b7",
                "https://git.kernel.org/stable/c/3ad9ccea1b25435f6179b57aa891960beb7ce8f9",
                "https://git.kernel.org/stable/c/6a320935fa4293e9e599ec9f85dc9eb3be7029f8",
                "https://git.kernel.org/stable/c/73ddc8518a32baff6bc17afda4ee1ebae5b4ed12",
                "https://git.kernel.org/stable/c/8bcc1cd237ab5ccfdd102869fa031c541943cf40",
                "https://git.kernel.org/stable/c/9e48844f708eb48bae4e79cb21edc097c966306d",
                "https://git.kernel.org/stable/c/fdaa42ca370d056428e5e171247c8fdce8dff36a",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T14:17:23.387",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46040"
                }
            ]
        },
        {
            "id": "CVE-2026-46037",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: icmp: validate reply type before using icmp_pointers\n\nExtended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type.\nThat value is outside the range covered by icmp_pointers[], which only\ndescribes the traditional ICMP types up to NR_ICMP_TYPES.\n\nAvoid consulting icmp_pointers[] for reply types outside that range, and\nuse array_index_nospec() for the remaining in-range lookup. Normal ICMP\nreplies keep their existing behavior unchanged.",
            "updated_at": "2026-09-08T09:18:06.897",
            "published_at": "2026-05-27T14:17:23.027",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "d329ea5bd8845f0b196bf41b18b6173340d6e0e4 through before b3a88fc5ae024d43c5ecf653f3bbe837e4a6dc99 (git); d329ea5bd8845f0b196bf41b18b6173340d6e0e4 through before 93df2af4f491de33827550b9d420f01808c0706b (git); d329ea5bd8845f0b196bf41b18b6173340d6e0e4 through before 92e7c209036dcc0e8ffdf806fdfd3645b263bea5 (git); d329ea5bd8845f0b196bf41b18b6173340d6e0e4 through before bc64a66e0b9ad937d3d49934242ee62b01ba9a94 (git); d329ea5bd8845f0b196bf41b18b6173340d6e0e4 through before c2178ff1c70ebfc2ab9651b230c58a34683db759 (git); d329ea5bd8845f0b196bf41b18b6173340d6e0e4 through before d700c34a5d186b9ba0715bcb19e0ff80ffbfbfc1 (git); d329ea5bd8845f0b196bf41b18b6173340d6e0e4 through before 67bf002a2d7387a6312138210d0bd06e3cf4879b (git); 5.13; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: icmp: validate reply type before using icmp_pointers\n\nExtended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type.\nThat value is outside the range covered by icmp_pointers[], which only\ndescribes the traditional ICMP types up to NR_ICMP_TYPES.\n\nAvoid consulting icmp_pointers[] for reply types outside that range, and\nuse array_index_nospec() for the remaining in-range lookup. Normal ICMP\nreplies keep their existing behavior unchanged.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/67bf002a2d7387a6312138210d0bd06e3cf4879b",
                "https://git.kernel.org/stable/c/92e7c209036dcc0e8ffdf806fdfd3645b263bea5",
                "https://git.kernel.org/stable/c/93df2af4f491de33827550b9d420f01808c0706b",
                "https://git.kernel.org/stable/c/b3a88fc5ae024d43c5ecf653f3bbe837e4a6dc99",
                "https://git.kernel.org/stable/c/bc64a66e0b9ad937d3d49934242ee62b01ba9a94",
                "https://git.kernel.org/stable/c/c2178ff1c70ebfc2ab9651b230c58a34683db759",
                "https://git.kernel.org/stable/c/d700c34a5d186b9ba0715bcb19e0ff80ffbfbfc1",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T14:17:23.027",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46037"
                }
            ]
        },
        {
            "id": "CVE-2026-46033",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: authencesn - reject short ahash digests during instance creation\n\nauthencesn requires either a zero authsize or an authsize of at least\n4 bytes because the ESN encrypt/decrypt paths always move 4 bytes of\nhigh-order sequence number data at the end of the authenticated data.\n\nWhile crypto_authenc_esn_setauthsize() already rejects explicit\nnon-zero authsizes in the range 1..3, crypto_authenc_esn_create()\nstill copied auth->digestsize into inst->alg.maxauthsize without\nvalidating it.  The AEAD core then initialized the tfm's default\nauthsize from that value.\n\nAs a result, selecting an ahash with digest size 1..3, such as\ncbcmac(cipher_null), exposed authencesn instances whose default\nauthsize was invalid even though setauthsize() would have rejected the\nsame value.  AF_ALG could then trigger the ESN tail handling with a\ntoo-short tag and hit an out-of-bounds access.\n\nReject authencesn instances whose ahash digest size is in the invalid\nnon-zero range 1..3 so that no tfm can inherit an unsupported default\nauthsize.",
            "updated_at": "2026-09-08T09:18:06.620",
            "published_at": "2026-05-27T14:17:22.313",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f15f05b0a5de667c821a9727c33bce9d1d9b26dd through before 77f59fb2d3aa33e90ec6cbbf45dcfb20ab82b1a9 (git); f15f05b0a5de667c821a9727c33bce9d1d9b26dd through before 2f31cd1e64a079c845bca31d2da7b3c90a311726 (git); f15f05b0a5de667c821a9727c33bce9d1d9b26dd through before d4c6a6d08e70bb1083c7c405fc7faacbf19aebc0 (git); f15f05b0a5de667c821a9727c33bce9d1d9b26dd through before b69933e97efea238ebbfcf70c2b1be1cd03f13e3 (git); f15f05b0a5de667c821a9727c33bce9d1d9b26dd through before 67f1f0933cc3d78dde222842bcad2778ec7a0b88 (git); f15f05b0a5de667c821a9727c33bce9d1d9b26dd through before b42821c15445f93daea3e76ada682b2b7181c476 (git); f15f05b0a5de667c821a9727c33bce9d1d9b26dd through before 9aff81e8217e9de2929084b03b3c7f81988c112b (git); f15f05b0a5de667c821a9727c33bce9d1d9b26dd through before 5db6ef9847717329f12c5ea8aba7e9f588a980c0 (git); 4.11; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: authencesn - reject short ahash digests during instance creation\n\nauthencesn requires either a zero authsize or an authsize of at least\n4 bytes because the ESN encrypt/decrypt paths always move 4 bytes of\nhigh-order sequence number data at the end of the authenticated data.\n\nWhile crypto_authenc_esn_setauthsize() already rejects explicit\nnon-zero authsizes in the range 1..3, crypto_authenc_esn_create()\nstill copied auth->digestsize into inst->alg.maxauthsize without\nvalidating it.  The AEAD core then initialized the tfm's default\nauthsize from that value.\n\nAs a result, selecting an ahash with digest size 1..3, such as\ncbcmac(cipher_null), exposed authencesn instances whose default\nauthsize was invalid even though setauthsize() would have rejected the\nsame value.  AF_ALG could then trigger the ESN tail handling with a\ntoo-short tag and hit an out-of-bounds access.\n\nReject authencesn instances whose ahash digest size is in the invalid\nnon-zero range 1..3 so that no tfm can inherit an unsupported default\nauthsize.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2f31cd1e64a079c845bca31d2da7b3c90a311726",
                "https://git.kernel.org/stable/c/5db6ef9847717329f12c5ea8aba7e9f588a980c0",
                "https://git.kernel.org/stable/c/67f1f0933cc3d78dde222842bcad2778ec7a0b88",
                "https://git.kernel.org/stable/c/77f59fb2d3aa33e90ec6cbbf45dcfb20ab82b1a9",
                "https://git.kernel.org/stable/c/9aff81e8217e9de2929084b03b3c7f81988c112b",
                "https://git.kernel.org/stable/c/b42821c15445f93daea3e76ada682b2b7181c476",
                "https://git.kernel.org/stable/c/b69933e97efea238ebbfcf70c2b1be1cd03f13e3",
                "https://git.kernel.org/stable/c/d4c6a6d08e70bb1083c7c405fc7faacbf19aebc0",
                "https://access.redhat.com/security/cve/CVE-2026-46033",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2482000",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-46033.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T14:17:22.313",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46033"
                }
            ]
        },
        {
            "id": "CVE-2026-46021",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: core: Fix thermal zone governor cleanup issues\n\nIf thermal_zone_device_register_with_trips() fails after adding\na thermal governor to the thermal zone being registered, the\ngovernor is not removed from it as appropriate which may lead to\na memory leak.\n\nIn turn, thermal_zone_device_unregister() calls thermal_set_governor()\nwithout acquiring the thermal zone lock beforehand which may race with\na governor update via sysfs and may lead to a use-after-free in that\ncase.\n\nAddress these issues by adding two thermal_set_governor() calls, one to\nthermal_release() to remove the governor from the given thermal zone,\nand one to the thermal zone registration error path to cover failures\npreceding the thermal zone device registration.",
            "updated_at": "2026-09-08T09:18:06.463",
            "published_at": "2026-05-27T14:17:20.567",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before a172fa18bc370b776ac1510abb0dcb50a7a35fac (git); e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before 8e563d8db50f303171aceb79eec0807e7ba06951 (git); e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before d4eb861adde5ce22e459fbd29366f47bb2167977 (git); e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before 37a430a2d4e66ec8238da6c7f7e48809bf265e13 (git); e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before f412e541d25a3dfaf3d53e012ade6ff03cae8a45 (git); e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before 75f8f3c3e09122270986de9d7aa347d701676761 (git); e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before 64d4ebf91d082034bbc5ae3ba2d7fd800bc02d06 (git); e33df1d2f3a0141cd79e770f31999ba0dd7ebfa8 through before 41ff66baf81c6541f4f985dd7eac4494d03d9440 (git); 4.2; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-401",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: core: Fix thermal zone governor cleanup issues\n\nIf thermal_zone_device_register_with_trips() fails after adding\na thermal governor to the thermal zone being registered, the\ngovernor is not removed from it as appropriate which may lead to\na memory leak.\n\nIn turn, thermal_zone_device_unregister() calls thermal_set_governor()\nwithout acquiring the thermal zone lock beforehand which may race with\na governor update via sysfs and may lead to a use-after-free in that\ncase.\n\nAddress these issues by adding two thermal_set_governor() calls, one to\nthermal_release() to remove the governor from the given thermal zone,\nand one to the thermal zone registration error path to cover failures\npreceding the thermal zone device registration.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/37a430a2d4e66ec8238da6c7f7e48809bf265e13",
                "https://git.kernel.org/stable/c/41ff66baf81c6541f4f985dd7eac4494d03d9440",
                "https://git.kernel.org/stable/c/64d4ebf91d082034bbc5ae3ba2d7fd800bc02d06",
                "https://git.kernel.org/stable/c/75f8f3c3e09122270986de9d7aa347d701676761",
                "https://git.kernel.org/stable/c/8e563d8db50f303171aceb79eec0807e7ba06951",
                "https://git.kernel.org/stable/c/a172fa18bc370b776ac1510abb0dcb50a7a35fac",
                "https://git.kernel.org/stable/c/d4eb861adde5ce22e459fbd29366f47bb2167977",
                "https://git.kernel.org/stable/c/f412e541d25a3dfaf3d53e012ade6ff03cae8a45",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T14:17:20.567",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46021"
                }
            ]
        },
        {
            "id": "CVE-2026-46015",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: call sk_data_ready() after listener migration\n\nWhen inet_csk_listen_stop() migrates an established child socket from\na closing listener to another socket in the same SO_REUSEPORT group,\nthe target listener gets a new accept-queue entry via\ninet_csk_reqsk_queue_add(), but that path never notifies the target\nlistener's waiters. A nonblocking accept() still works because it\nchecks the queue directly, but poll()/epoll_wait() waiters and\nblocking accept() callers can also remain asleep indefinitely.\n\nCall READ_ONCE(nsk->sk_data_ready)(nsk) after a successful migration\nin inet_csk_listen_stop().\n\nHowever, after inet_csk_reqsk_queue_add() succeeds, the ref acquired\nin reuseport_migrate_sock() is effectively transferred to\nnreq->rsk_listener. Another CPU can then dequeue nreq via accept()\nor listener shutdown, hit reqsk_put(), and drop that listener ref.\nSince listeners are SOCK_RCU_FREE, wrap the post-queue_add()\ndereferences of nsk in rcu_read_lock()/rcu_read_unlock(), which also\ncovers the existing sock_net(nsk) access in that path.\n\nThe reqsk_timer_handler() path does not need the same changes for two\nreasons: half-open requests become readable only after the final ACK,\nwhere tcp_child_process() already wakes the listener; and once nreq is\nvisible via inet_ehash_insert(), the success path no longer touches\nnsk directly.",
            "updated_at": "2026-09-08T09:18:06.277",
            "published_at": "2026-05-27T14:17:19.840",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "54b92e84193749c9968aff2dd46e3b0f42643e18 through before 7aa7933a5607b1e5b56f322d17265c1d0ea02c51 (git); 54b92e84193749c9968aff2dd46e3b0f42643e18 through before 14e9bb6eba8f59dcc637702e4744ae5e30660d76 (git); 54b92e84193749c9968aff2dd46e3b0f42643e18 through before ab5fdcd535645f6dbe6e9e21d96a08d141e88b4b (git); 54b92e84193749c9968aff2dd46e3b0f42643e18 through before bebd058ef40c67a81fe6d9ee8beaa4ede90e0704 (git); 54b92e84193749c9968aff2dd46e3b0f42643e18 through before 83bb57635d7cbafde32f865b577ecfd969f02337 (git); 54b92e84193749c9968aff2dd46e3b0f42643e18 through before 12625b4da84caf4d84a04988710a7b9bcf702b18 (git); 54b92e84193749c9968aff2dd46e3b0f42643e18 through before 3864c6ba1e041bc75342353a70fa2a2c6f909923 (git); 5.14; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: call sk_data_ready() after listener migration\n\nWhen inet_csk_listen_stop() migrates an established child socket from\na closing listener to another socket in the same SO_REUSEPORT group,\nthe target listener gets a new accept-queue entry via\ninet_csk_reqsk_queue_add(), but that path never notifies the target\nlistener's waiters. A nonblocking accept() still works because it\nchecks the queue directly, but poll()/epoll_wait() waiters and\nblocking accept() callers can also remain asleep indefinitely.\n\nCall READ_ONCE(nsk->sk_data_ready)(nsk) after a successful migration\nin inet_csk_listen_stop().\n\nHowever, after inet_csk_reqsk_queue_add() succeeds, the ref acquired\nin reuseport_migrate_sock() is effectively transferred to\nnreq->rsk_listener. Another CPU can then dequeue nreq via accept()\nor listener shutdown, hit reqsk_put(), and drop that listener ref.\nSince listeners are SOCK_RCU_FREE, wrap the post-queue_add()\ndereferences of nsk in rcu_read_lock()/rcu_read_unlock(), which also\ncovers the existing sock_net(nsk) access in that path.\n\nThe reqsk_timer_handler() path does not need the same changes for two\nreasons: half-open requests become readable only after the final ACK,\nwhere tcp_child_process() already wakes the listener; and once nreq is\nvisible via inet_ehash_insert(), the success path no longer touches\nnsk directly.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/12625b4da84caf4d84a04988710a7b9bcf702b18",
                "https://git.kernel.org/stable/c/14e9bb6eba8f59dcc637702e4744ae5e30660d76",
                "https://git.kernel.org/stable/c/3864c6ba1e041bc75342353a70fa2a2c6f909923",
                "https://git.kernel.org/stable/c/7aa7933a5607b1e5b56f322d17265c1d0ea02c51",
                "https://git.kernel.org/stable/c/83bb57635d7cbafde32f865b577ecfd969f02337",
                "https://git.kernel.org/stable/c/ab5fdcd535645f6dbe6e9e21d96a08d141e88b4b",
                "https://git.kernel.org/stable/c/bebd058ef40c67a81fe6d9ee8beaa4ede90e0704",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T14:17:19.840",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46015"
                }
            ]
        },
        {
            "id": "CVE-2026-45998",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix potential UAF after skb_unshare() failure\n\nIf skb_unshare() fails to unshare a packet due to allocation failure in\nrxrpc_input_packet(), the skb pointer in the parent (rxrpc_io_thread())\nwill be NULL'd out.  This will likely cause the call to\ntrace_rxrpc_rx_done() to oops.\n\nFix this by moving the unsharing down to where rxrpc_input_call_event()\ncalls rxrpc_input_call_packet().  There are a number of places prior to\nthat where we ignore DATA packets for a variety of reasons (such as the\ncall already being complete) for which an unshare is then avoided.\n\nAnd with that, rxrpc_input_packet() doesn't need to take a pointer to the\npointer to the packet, so change that to just a pointer.",
            "updated_at": "2026-09-16T13:17:59.330",
            "published_at": "2026-05-27T14:17:17.407",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2d1faf7a0ca3c0b327cf064c80e4e775532c9319 through before e3bf143b1e98fb3d6d9e6825bcd683974d478e8c (git); 2d1faf7a0ca3c0b327cf064c80e4e775532c9319 through before bf20f46d94f1db38e6ffc0ca204a5fe0de01b495 (git); 2d1faf7a0ca3c0b327cf064c80e4e775532c9319 through before 996b0487b3cdda4c91811dbb1c9564626bc840bd (git); 2d1faf7a0ca3c0b327cf064c80e4e775532c9319 through before 8fde6296c4d4da2be7ab761305ab7f232b94eefd (git); 2d1faf7a0ca3c0b327cf064c80e4e775532c9319 through before 1f2740150f904bfa60e4bad74d65add3ccb5e7f8 (git); 6.2",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix potential UAF after skb_unshare() failure\n\nIf skb_unshare() fails to unshare a packet due to allocation failure in\nrxrpc_input_packet(), the skb pointer in the parent (rxrpc_io_thread())\nwill be NULL'd out.  This will likely cause the call to\ntrace_rxrpc_rx_done() to oops.\n\nFix this by moving the unsharing down to where rxrpc_input_call_event()\ncalls rxrpc_input_call_packet().  There are a number of places prior to\nthat where we ignore DATA packets for a variety of reasons (such as the\ncall already being complete) for which an unshare is then avoided.\n\nAnd with that, rxrpc_input_packet() doesn't need to take a pointer to the\npointer to the packet, so change that to just a pointer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1f2740150f904bfa60e4bad74d65add3ccb5e7f8",
                "https://git.kernel.org/stable/c/8fde6296c4d4da2be7ab761305ab7f232b94eefd",
                "https://git.kernel.org/stable/c/996b0487b3cdda4c91811dbb1c9564626bc840bd",
                "https://git.kernel.org/stable/c/bf20f46d94f1db38e6ffc0ca204a5fe0de01b495",
                "https://git.kernel.org/stable/c/e3bf143b1e98fb3d6d9e6825bcd683974d478e8c",
                "https://access.redhat.com/errata/RHSA-2026:34911",
                "https://access.redhat.com/errata/RHSA-2026:55445",
                "https://access.redhat.com/errata/RHSA-2026:65708",
                "https://access.redhat.com/errata/RHSA-2026:65712",
                "https://access.redhat.com/errata/RHSA-2026:67721",
                "https://access.redhat.com/errata/RHSA-2026:67723",
                "https://access.redhat.com/security/cve/CVE-2026-45998",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2482024",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45998.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T14:17:17.407",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45998"
                }
            ]
        },
        {
            "id": "CVE-2026-45897",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_counter: serialize reset with spinlock\n\nAdd a global static spinlock to serialize counter fetch+reset\noperations, preventing concurrent dump-and-reset from underrunning\nvalues.\n\nThe lock is taken before fetching the total so that two parallel\nresets cannot both read the same counter values and then both\nsubtract them.\n\nA global lock is used for simplicity since resets are infrequent.\nIf this becomes a bottleneck, it can be replaced with a per-net\nlock later.",
            "updated_at": "2026-09-14T12:17:41.570",
            "published_at": "2026-05-27T14:17:03.977",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "fb1adb05ea87b6149e65a31e511756c4f470d0cd through before e13194e60217db02c2e7202375d9e5951267d87b (git); f123293db16dcd0cd81b246ae60e6362f0025d0a through before de6601f1374fab124cd9276df6671f64d940ceb4 (git); 3cb03edb4de33fd04c4ea55f47397b96a8657c53 through before 48cf7918d10c66cb6b05226fa3fa5daf0c891089 (git); 3cb03edb4de33fd04c4ea55f47397b96a8657c53 through before cd968dcdec6aee79a2d399e4f6e0eca63c3b45e1 (git); 3cb03edb4de33fd04c4ea55f47397b96a8657c53 through before 0cdc6d5a26f2d1f7f15a43526841b679445c32e2 (git); 3cb03edb4de33fd04c4ea55f47397b96a8657c53 through before 779c60a5190c42689534172f4b49e927c9959e4e (git); 6.1.107 through before 6.1.188 (semver); 6.6.48 through before 6.6.157 (semver); 6.7",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_counter: serialize reset with spinlock\n\nAdd a global static spinlock to serialize counter fetch+reset\noperations, preventing concurrent dump-and-reset from underrunning\nvalues.\n\nThe lock is taken before fetching the total so that two parallel\nresets cannot both read the same counter values and then both\nsubtract them.\n\nA global lock is used for simplicity since resets are infrequent.\nIf this becomes a bottleneck, it can be replaced with a per-net\nlock later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0cdc6d5a26f2d1f7f15a43526841b679445c32e2",
                "https://git.kernel.org/stable/c/48cf7918d10c66cb6b05226fa3fa5daf0c891089",
                "https://git.kernel.org/stable/c/779c60a5190c42689534172f4b49e927c9959e4e",
                "https://git.kernel.org/stable/c/cd968dcdec6aee79a2d399e4f6e0eca63c3b45e1",
                "https://git.kernel.org/stable/c/de6601f1374fab124cd9276df6671f64d940ceb4",
                "https://git.kernel.org/stable/c/e13194e60217db02c2e7202375d9e5951267d87b"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T14:17:03.977",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45897"
                }
            ]
        },
        {
            "id": "CVE-2026-45841",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO\n\nnf_osf_match_one() computes ctx->window % f->wss.val in the\nOSF_WSS_MODULO branch with no guard for f->wss.val == 0. A\nCAP_NET_ADMIN user can add such a fingerprint via nfnetlink; a\nsubsequent matching TCP SYN divides by zero and panics the kernel.\n\nReject the bogus fingerprint in nfnl_osf_add_callback() above the\nper-option for-loop. f->wss is per-fingerprint, not per-option, so\nthe check must run regardless of f->opt_num (including 0). Also\nreject wss.wc >= OSF_WSS_MAX; nf_osf_match_one() already treats that\nas \"should not happen\".\n\nCrash:\n Oops: divide error: 0000 [#1] SMP KASAN NOPTI\n RIP: 0010:nf_osf_match_one (net/netfilter/nfnetlink_osf.c:98)\n Call Trace:\n <IRQ>\n  nf_osf_match (net/netfilter/nfnetlink_osf.c:220)\n  xt_osf_match_packet (net/netfilter/xt_osf.c:32)\n  ipt_do_table (net/ipv4/netfilter/ip_tables.c:348)\n  nf_hook_slow (net/netfilter/core.c:622)\n  ip_local_deliver (net/ipv4/ip_input.c:265)\n  ip_rcv (include/linux/skbuff.h:1162)\n  __netif_receive_skb_one_core (net/core/dev.c:6181)\n  process_backlog (net/core/dev.c:6642)\n  __napi_poll (net/core/dev.c:7710)\n  net_rx_action (net/core/dev.c:7945)\n  handle_softirqs (kernel/softirq.c:622)",
            "updated_at": "2026-09-08T09:18:06.090",
            "published_at": "2026-05-27T11:16:23.493",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before cb833bbc1b3c51e08652d3c86298307c07d3f2db (git); 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before 26900306a5a2c3e4f75c643a064525526bb6e5f3 (git); 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before 0694618cf3e9b120666e31f5f383a6e466d95a0d (git); 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before 8def8fbd23f40e945febe913d04b731012ce0082 (git); 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before c55940895245d8ef658ab381248a28755218d625 (git); 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before fb965b1cfe92b28d28b5ebe3116b81dbef9f2d2f (git); 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before 9a05e195618a6d474f2bcd5b6376d0ffc2f00366 (git); 11eeef41d5f63c7d2f7fdfcc733eb7fb137cc384 through before 2195574dc6d9017d32ac346987e12659f931d932 (git); 2.6.31; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-369",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO\n\nnf_osf_match_one() computes ctx->window % f->wss.val in the\nOSF_WSS_MODULO branch with no guard for f->wss.val == 0. A\nCAP_NET_ADMIN user can add such a fingerprint via nfnetlink; a\nsubsequent matching TCP SYN divides by zero and panics the kernel.\n\nReject the bogus fingerprint in nfnl_osf_add_callback() above the\nper-option for-loop. f->wss is per-fingerprint, not per-option, so\nthe check must run regardless of f->opt_num (including 0). Also\nreject wss.wc >= OSF_WSS_MAX; nf_osf_match_one() already treats that\nas \"should not happen\".\n\nCrash:\n Oops: divide error: 0000 [#1] SMP KASAN NOPTI\n RIP: 0010:nf_osf_match_one (net/netfilter/nfnetlink_osf.c:98)\n Call Trace:\n <IRQ>\n  nf_osf_match (net/netfilter/nfnetlink_osf.c:220)\n  xt_osf_match_packet (net/netfilter/xt_osf.c:32)\n  ipt_do_table (net/ipv4/netfilter/ip_tables.c:348)\n  nf_hook_slow (net/netfilter/core.c:622)\n  ip_local_deliver (net/ipv4/ip_input.c:265)\n  ip_rcv (include/linux/skbuff.h:1162)\n  __netif_receive_skb_one_core (net/core/dev.c:6181)\n  process_backlog (net/core/dev.c:6642)\n  __napi_poll (net/core/dev.c:7710)\n  net_rx_action (net/core/dev.c:7945)\n  handle_softirqs (kernel/softirq.c:622)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0694618cf3e9b120666e31f5f383a6e466d95a0d",
                "https://git.kernel.org/stable/c/2195574dc6d9017d32ac346987e12659f931d932",
                "https://git.kernel.org/stable/c/26900306a5a2c3e4f75c643a064525526bb6e5f3",
                "https://git.kernel.org/stable/c/8def8fbd23f40e945febe913d04b731012ce0082",
                "https://git.kernel.org/stable/c/9a05e195618a6d474f2bcd5b6376d0ffc2f00366",
                "https://git.kernel.org/stable/c/c55940895245d8ef658ab381248a28755218d625",
                "https://git.kernel.org/stable/c/cb833bbc1b3c51e08652d3c86298307c07d3f2db",
                "https://git.kernel.org/stable/c/fb965b1cfe92b28d28b5ebe3116b81dbef9f2d2f",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T11:16:23.493",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45841"
                }
            ]
        },
        {
            "id": "CVE-2026-45798",
            "vendor": "wazuh",
            "product": "wazuh",
            "title": "wazuh vulnerability",
            "summary": "Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with strncpy() but does not explicitly terminate the buffer. The function is reachable before authentication through wazuh-authd on TCP port 1515 when anonymous TLS enrollment is enabled. A version string of at least nine non-null bytes can cause strchr() and strtok() to read beyond ver2 and can make strtok() write a null byte into adjacent stack memory, allowing a remote denial of service. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.",
            "updated_at": "2026-09-15T19:25:59.467",
            "published_at": "2026-08-19T17:18:49.730",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.5.0, < 4.14.6; >= 5.0.0-beta1, < 5.0.0-beta2",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with strncpy() but does not explicitly terminate the buffer. The function is reachable before authentication through wazuh-authd on TCP port 1515 when anonymous TLS enrollment is enabled. A version string of at least nine non-null bytes can cause strchr() and strtok() to read beyond ver2 and can make strtok() write a null byte into adjacent stack memory, allowing a remote denial of service. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-19",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-4fvp-jfc3-qr6r"
                }
            ],
            "references": [
                "https://github.com/wazuh/wazuh/commit/b6aac379982d6144b8da38450cbea6c8dc15be44",
                "https://github.com/wazuh/wazuh/pull/36059",
                "https://github.com/wazuh/wazuh/releases/tag/v4.14.6",
                "https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta2",
                "https://github.com/wazuh/wazuh/security/advisories/GHSA-4fvp-jfc3-qr6r"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T17:18:49.730",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45798"
                }
            ]
        },
        {
            "id": "CVE-2026-45736",
            "vendor": "websockets",
            "product": "ws",
            "title": "ws vulnerability",
            "summary": "ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.",
            "updated_at": "2026-09-11T13:18:11.290",
            "published_at": "2026-05-15T15:16:54.103",
            "cvss": 4.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 8.0.0, < 8.20.1",
            "fixed": "See vendor advisory",
            "source_count": 54,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-908",
            "what_happened": "ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-15",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/websockets/ws/security/advisories/GHSA-58qx-3vcg-4xpx"
                }
            ],
            "references": [
                "https://github.com/websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086",
                "https://github.com/websockets/ws/security/advisories/GHSA-58qx-3vcg-4xpx",
                "https://access.redhat.com/errata/RHSA-2026:26638",
                "https://access.redhat.com/errata/RHSA-2026:26994",
                "https://access.redhat.com/errata/RHSA-2026:27171",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:34374",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:37272",
                "https://access.redhat.com/errata/RHSA-2026:40768",
                "https://access.redhat.com/errata/RHSA-2026:40792",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:44235",
                "https://access.redhat.com/errata/RHSA-2026:44263",
                "https://access.redhat.com/errata/RHSA-2026:44267",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:48693",
                "https://access.redhat.com/errata/RHSA-2026:56366",
                "https://access.redhat.com/errata/RHSA-2026:56431",
                "https://access.redhat.com/errata/RHSA-2026:56928",
                "https://access.redhat.com/errata/RHSA-2026:57013",
                "https://access.redhat.com/errata/RHSA-2026:57590",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:7655",
                "https://access.redhat.com/security/cve/CVE-2026-45736",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2477914",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45736.json",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545"
            ],
            "timeline": [
                {
                    "at": "2026-05-15T15:16:54.103",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45736"
                }
            ]
        },
        {
            "id": "CVE-2026-45659",
            "vendor": "Microsoft",
            "product": "SharePoint Server",
            "title": "Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability",
            "summary": "Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.",
            "updated_at": "2026-09-11T13:02:18Z",
            "published_at": "2026-09-11T13:02:18Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 46,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-14T18:33:17+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "sharepoint-deserialization-security-assessment exploit",
                    "summary": "Exploit for CVE-2026-45659. CVSS 8.8.",
                    "cvss": 8.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AMNSECURITY-SHAREPOINT-DESERIALIZATION-SECURITY-ASSESSMENT"
                },
                {
                    "title": "Exploit for sharepoint-deserialization-security-assessment CVE-2026-45659",
                    "summary": "Deserialization RCE in Microsoft SharePoint (CVE-2026-45659) enables remote code execution.",
                    "what_happened": "Deserialization RCE in Microsoft SharePoint (CVE-2026-45659) enables remote code execution.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-502",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AMNSECURITY-SHAREPOINT-DESERIALIZATION-SECURITY-ASSESSMENT",
                        "https://kitploit.com/zh/tools/github/amnsecurity/sharepoint-deserialization-security-assessment/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-11T15:02:18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/amnsecurity/sharepoint-deserialization-security-assessment/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AMNSECURITY-SHAREPOINT-DESERIALIZATION-SECURITY-ASSESSMENT",
                "https://kitploit.com/zh/tools/github/amnsecurity/sharepoint-deserialization-security-assessment/"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T13:02:18Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-45618",
            "vendor": "harttle",
            "product": "liquidjs",
            "title": "liquidjs vulnerability",
            "summary": "LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.",
            "updated_at": "2026-09-16T13:42:43.330",
            "published_at": "2026-08-11T20:17:40.163",
            "cvss": 10,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 10.26.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/harttle/liquidjs/releases/tag/v10.26.0",
                "https://github.com/harttle/liquidjs/security/advisories/GHSA-gf2q-c269-pqgc"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T20:17:40.163",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45618"
                }
            ]
        },
        {
            "id": "CVE-2026-45531",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:18:01.617",
            "published_at": "2026-09-08T19:17:58.107",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:58.107",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45531"
                }
            ]
        },
        {
            "id": "CVE-2026-45528",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
            "updated_at": "2026-09-10T04:18:01.500",
            "published_at": "2026-09-08T19:17:58.007",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:58.007",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45528"
                }
            ]
        },
        {
            "id": "CVE-2026-45520",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:18:01.390",
            "published_at": "2026-09-08T19:17:57.630",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:57.630",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45520"
                }
            ]
        },
        {
            "id": "CVE-2026-45515",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:18:01.277",
            "published_at": "2026-09-08T19:17:57.437",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:57.437",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45515"
                }
            ]
        },
        {
            "id": "CVE-2026-45447",
            "vendor": "OpenSSL",
            "product": "OpenSSL",
            "title": "OpenSSL vulnerability",
            "summary": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
            "updated_at": "2026-09-11T13:18:10.853",
            "published_at": "2026-06-09T17:17:19.277",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.0.1 (semver); 3.6.0 through before 3.6.3 (semver); 3.5.0 through before 3.5.7 (semver); 3.4.0 through before 3.4.6 (semver); 3.0.0 through before 3.0.21 (semver); 1.1.1 through before 1.1.1zh (custom); 1.0.2 through before 1.0.2zq (custom)",
            "fixed": "See vendor advisory",
            "source_count": 28,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "Issue summary: A specially crafted PKCS#7 or S/MIME signed message could\ntrigger a use-after-free during PKCS#7 signature verification.\n\nImpact summary: A use-after-free may result in process crashes, heap\ncorruption, or potentially remote code execution.\n\nWhen processing a PKCS#7 or S/MIME signed message, if the SignedData\ndigestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may\nincorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent\nuse of the BIO by the calling application results in a use-after-free\ncondition.\n\nIn the common case this occurs when the application later calls\nBIO_free() on the BIO originally passed to PKCS7_verify(). Depending\non allocator behavior and application-specific BIO usage patterns, this\nmay result in a crash or other memory corruption. In some application\ncontexts this may potentially be exploitable for remote code execution.\n\nApplications that process PKCS#7 or S/MIME signed messages using OpenSSL\nPKCS#7 APIs may be affected. Applications using the CMS APIs for this\nprocessing are not affected.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nissue, as the affected code is outside the OpenSSL FIPS module boundary.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openssl/openssl/commit/3aad5eb7af4de4ee0633c30a8541a54d9bbde63c",
                "https://github.com/openssl/openssl/commit/7d4a980c62258c5910cc883936e0c8dbab4d75a8",
                "https://github.com/openssl/openssl/commit/9dfd688ad2290fc5075cacbc9bf0c9a93eefed54",
                "https://github.com/openssl/openssl/commit/a541ae8bfe849a30cc885e8780715c0f488e496c",
                "https://github.com/openssl/openssl/commit/c505d7559da5d5f9f2c3913c6883a5562ce7273e",
                "https://openssl-library.org/news/secadv/20260609.txt",
                "https://access.redhat.com/errata/RHSA-2026:25237",
                "https://access.redhat.com/errata/RHSA-2026:25239",
                "https://access.redhat.com/errata/RHSA-2026:26275",
                "https://access.redhat.com/errata/RHSA-2026:26319",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:34102",
                "https://access.redhat.com/errata/RHSA-2026:35869",
                "https://access.redhat.com/errata/RHSA-2026:36215",
                "https://access.redhat.com/errata/RHSA-2026:36217",
                "https://access.redhat.com/errata/RHSA-2026:39009",
                "https://access.redhat.com/errata/RHSA-2026:39012",
                "https://access.redhat.com/errata/RHSA-2026:39981",
                "https://access.redhat.com/errata/RHSA-2026:44438",
                "https://access.redhat.com/errata/RHSA-2026:47735",
                "https://access.redhat.com/errata/RHSA-2026:47737",
                "https://access.redhat.com/errata/RHSA-2026:58563",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/errata/RHSA-2026:59831",
                "https://access.redhat.com/errata/RHSA-2026:66524",
                "https://access.redhat.com/security/cve/CVE-2026-45447",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2481898",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45447.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-09T17:17:19.277",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45447"
                }
            ]
        },
        {
            "id": "CVE-2026-45416",
            "vendor": "netty",
            "product": "netty",
            "title": "netty vulnerability",
            "summary": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
            "updated_at": "2026-09-11T13:18:10.310",
            "published_at": "2026-06-12T15:16:26.940",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 4.2.0.Final, < 4.2.15.Final; < 4.1.135.Final",
            "fixed": "See vendor advisory",
            "source_count": 24,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handshake length and, when the ClientHello does not fit in the first record, eagerly allocates `ctx.alloc().buffer(handshakeLength)` (line 161). The guard at line 140 is `handshakeLength > maxClientHelloLength && maxClientHelloLength != 0`, and the commonly-used SniHandler/AbstractSniHandler constructors (SniHandler(Mapping), SniHandler(AsyncMapping), AbstractSniHandler()) pass maxClientHelloLength=0 and handshakeTimeoutMillis=0, so the length guard is disabled and no timeout is scheduled. A 16 MiB request exceeds the default pooled chunk size and becomes a huge/unpooled allocation performed immediately. The buffer is retained in the handler until the channel closes. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final",
                "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final",
                "https://github.com/netty/netty/security/advisories/GHSA-x4gw-5cx5-pgmh",
                "https://access.redhat.com/errata/RHSA-2026:26017",
                "https://access.redhat.com/errata/RHSA-2026:26018",
                "https://access.redhat.com/errata/RHSA-2026:26586",
                "https://access.redhat.com/errata/RHSA-2026:28573",
                "https://access.redhat.com/errata/RHSA-2026:34608",
                "https://access.redhat.com/errata/RHSA-2026:37390",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:49700",
                "https://access.redhat.com/errata/RHSA-2026:49701",
                "https://access.redhat.com/errata/RHSA-2026:50085",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:62260",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-45416",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2488391",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45416.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-12T15:16:26.940",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45416"
                }
            ]
        },
        {
            "id": "CVE-2026-45293",
            "vendor": "WordPress",
            "product": "WordPress-Coding-Standards",
            "title": "WordPress-Coding-Standards vulnerability",
            "summary": "WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets) reconstructed the $ver argument passed to functions such as wp_enqueue_script() and ran it through eval() inside its is_falsy() method, so a maliciously crafted argument such as 'system'('id') would execute during a scan; as a result, running PHPCS with WordPressCS over untrusted PHP (for example a CI pipeline that lints pull requests, or a developer reviewing third-party code) could lead to arbitrary command execution on the scanning host. The WordPress-Core and WordPress-Docs rulesets are not affected. This issue is fixed in version 3.4.1.",
            "updated_at": "2026-09-09T20:50:00.950",
            "published_at": "2026-07-28T16:18:13.503",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 0.14.1, < 3.4.1",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-95",
            "what_happened": "WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPress.WP.EnqueuedResourceParameters sniff (active in the WordPress and WordPress-Extra rulesets) reconstructed the $ver argument passed to functions such as wp_enqueue_script() and ran it through eval() inside its is_falsy() method, so a maliciously crafted argument such as 'system'('id') would execute during a scan; as a result, running PHPCS with WordPressCS over untrusted PHP (for example a CI pipeline that lints pull requests, or a developer reviewing third-party code) could lead to arbitrary command execution on the scanning host. The WordPress-Core and WordPress-Docs rulesets are not affected. This issue is fixed in version 3.4.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/WordPress/WordPress-Coding-Standards/commit/a29048d0bbef5cf25d42349c74e4072d3cbc8325",
                "https://github.com/WordPress/WordPress-Coding-Standards/pull/2771",
                "https://github.com/WordPress/WordPress-Coding-Standards/releases/tag/3.4.1",
                "https://github.com/WordPress/WordPress-Coding-Standards/security/advisories/GHSA-3pwp-g2mj-5p3v"
            ],
            "timeline": [
                {
                    "at": "2026-07-28T16:18:13.503",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45293"
                }
            ]
        },
        {
            "id": "CVE-2026-45200",
            "vendor": "Imagination Technologies",
            "product": "Graphics DDK",
            "title": "Graphics DDK vulnerability",
            "summary": "Software installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scenario that when freed would cause double free and kernel heap corruption.\n\n\n\nScenario caused by fabricating a specific combination of flags on the allocation interface that would cause an incorrect double free event when freed.",
            "updated_at": "2026-09-09T05:17:24.040",
            "published_at": "2026-09-04T02:17:19.113",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "24.2 RTM2 (custom); 25.1 RTM2 through 25.3 RTM (custom); 26.1 RTM1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "Software installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scenario that when freed would cause double free and kernel heap corruption.\n\n\n\nScenario caused by fabricating a specific combination of flags on the allocation interface that would cause an incorrect double free event when freed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.imaginationtech.com/gpu-driver-vulnerabilities/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T02:17:19.113",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45200"
                }
            ]
        },
        {
            "id": "CVE-2026-45186",
            "vendor": "libexpat project",
            "product": "libexpat",
            "title": "libexpat vulnerability",
            "summary": "In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.",
            "updated_at": "2026-09-16T13:17:58.967",
            "published_at": "2026-05-10T07:16:07.883",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 2.8.1 (semver); V3.1.5 through before V3.1.6 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-407",
            "what_happened": "In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/libexpat/libexpat/pull/1216"
                }
            ],
            "references": [
                "https://github.com/libexpat/libexpat/pull/1216",
                "http://www.openwall.com/lists/oss-security/2026/05/11/16",
                "https://access.redhat.com/errata/RHSA-2026:22715",
                "https://access.redhat.com/errata/RHSA-2026:22721",
                "https://access.redhat.com/errata/RHSA-2026:23230",
                "https://access.redhat.com/errata/RHSA-2026:26319",
                "https://access.redhat.com/errata/RHSA-2026:27201",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/security/cve/CVE-2026-45186",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2468575",
                "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45186.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-10T07:16:07.883",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45186"
                }
            ]
        },
        {
            "id": "CVE-2026-45115",
            "vendor": "mybb",
            "product": "mybb",
            "title": "Exploitarium-Detections CVE-2026-45115",
            "summary": "MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to perform JavaScript code injection through a specially crafted username. The User CP Buddy/Ignore list and the Select Buddies list in Private Messages pass usernames through htmlspecialchars_uni(), which may leave single quotes unescaped. The payload is triggered when a victim chooses Yes in Please Confirm while removing the username in usercp.php, or selects the username through the onclick handler in the xmlhttp.php Select Buddies popup. The uniquely identifying implementation details include Private Messages Select Buddies list, and unescaped single quotes. This issue is fixed in version 1.8.40.",
            "updated_at": "2026-09-08T21:02:26.047",
            "published_at": "2026-08-18T16:17:06.180",
            "cvss": 8.7,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "< 1.8.40",
            "fixed": "See vendor advisory",
            "source_count": 53,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to perform JavaScript code injection through a specially crafted username. The User CP Buddy/Ignore list and the Select Buddies list in Private Messages pass usernames through htmlspecialchars_uni(), which may leave single quotes unescaped. The payload is triggered when a victim chooses Yes in Please Confirm while removing the username in usercp.php, or selects the username through the onclick handler in the xmlhttp.php Select Buddies popup. The uniquely identifying implementation details include Private Messages Select Buddies list, and unescaped single quotes. This issue is fixed in version 1.8.40.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploitarium-Detections CVE-2026-45115",
                    "summary": "KQL Sentinel/XDR detection rules covering bikini/exploitarium 15+ vulnerability targets.",
                    "what_happened": "KQL Sentinel/XDR detection rules covering bikini/exploitarium 15+ vulnerability targets.",
                    "cvss": 8.7,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ETHAN-ANDREWS-EXPLOITARIUM-DETECTIONS",
                        "https://kitploit.com/en/tools/github/ethan-andrews/exploitarium-detections/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-11T00:54:57",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ETHAN-ANDREWS-EXPLOITARIUM-DETECTIONS"
                },
                {
                    "title": "Exploitarium-Detections CVE-2026-45115",
                    "summary": "KQL Sentinel/XDR detection rules covering bikini/exploitarium 15+ vulnerability targets.",
                    "what_happened": "KQL Sentinel/XDR detection rules covering bikini/exploitarium 15+ vulnerability targets.",
                    "cvss": 8.7,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ETHAN-ANDREWS-EXPLOITARIUM-DETECTIONS",
                        "https://kitploit.com/en/tools/github/ethan-andrews/exploitarium-detections/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-11T00:54:57",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/ethan-andrews/exploitarium-detections/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ETHAN-ANDREWS-EXPLOITARIUM-DETECTIONS",
                "https://kitploit.com/en/tools/github/ethan-andrews/exploitarium-detections/",
                "https://github.com/mybb/mybb/releases/tag/mybb_1840",
                "https://github.com/mybb/mybb/security/advisories/GHSA-p766-qqxv-rfc2",
                "https://mybb.com/versions/1.8.40"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:54:57Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ETHAN-ANDREWS-EXPLOITARIUM-DETECTIONS"
                },
                {
                    "at": "2026-08-18T16:17:06.180",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45115"
                }
            ],
            "enrichment_checked_at": "2026-09-11T04:05:33Z",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2026-44901",
            "vendor": "wazuh",
            "product": "wazuh",
            "title": "wazuh vulnerability",
            "summary": "Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a cluster worker's JSON response. During a distributed API merge, attacker-controlled type names are resolved through Python builtins without an allowlist. A compromised worker can set sort_casting to exec and place Python source in affected_items, causing the master to execute the payload as root when responses from multiple nodes are merged. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.",
            "updated_at": "2026-09-15T19:28:41.820",
            "published_at": "2026-08-19T17:18:49.283",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.0.0, < 4.14.6; >= 5.0.0-beta1, < 5.0.0-beta2",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a cluster worker's JSON response. During a distributed API merge, attacker-controlled type names are resolved through Python builtins without an allowlist. A compromised worker can set sort_casting to exec and place Python source in affected_items, causing the master to execute the payload as root when responses from multiple nodes are merged. This issue is fixed in versions 4.14.6 and 5.0.0-beta2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-19",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-8c6v-7g3w-prrq"
                }
            ],
            "references": [
                "https://github.com/wazuh/wazuh/commit/b29849f8abb08d78f257e6106b6111a8a1b0e621",
                "https://github.com/wazuh/wazuh/pull/35757",
                "https://github.com/wazuh/wazuh/releases/tag/v4.14.6",
                "https://github.com/wazuh/wazuh/releases/tag/v5.0.0-beta2",
                "https://github.com/wazuh/wazuh/security/advisories/GHSA-8c6v-7g3w-prrq"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T17:18:49.283",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44901"
                }
            ]
        },
        {
            "id": "CVE-2026-44893",
            "vendor": "netty",
            "product": "netty",
            "title": "netty vulnerability",
            "summary": "Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.retainedSlice(header.readerIndex(), length)` and only then reads the 1-byte client field and 4-byte verify field. If the attacker sets the TLV length below 5, the subsequent readByte/readInt throws IndexOutOfBoundsException. HAProxyMessageDecoder only catches HAProxyProtocolException around this call, so the IOOBE propagates and the retained slice on the pooled cumulation buffer is never released. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
            "updated_at": "2026-09-11T13:18:09.893",
            "published_at": "2026-06-12T15:16:26.103",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 4.2.0.Final, < 4.2.15.Final; < 4.1.135.Final",
            "fixed": "See vendor advisory",
            "source_count": 20,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-703",
            "what_happened": "Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior to versions 4.1.135.Final and 4.2.15.Final, when decoding a PP2_TYPE_SSL TLV, HAProxyMessage.readNextTLV() first calls `header.retainedSlice(header.readerIndex(), length)` and only then reads the 1-byte client field and 4-byte verify field. If the attacker sets the TLV length below 5, the subsequent readByte/readInt throws IndexOutOfBoundsException. HAProxyMessageDecoder only catches HAProxyProtocolException around this call, so the IOOBE propagates and the retained slice on the pooled cumulation buffer is never released. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final",
                "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final",
                "https://github.com/netty/netty/security/advisories/GHSA-cc37-9q2j-3hfv",
                "https://access.redhat.com/errata/RHSA-2026:26017",
                "https://access.redhat.com/errata/RHSA-2026:26018",
                "https://access.redhat.com/errata/RHSA-2026:26586",
                "https://access.redhat.com/errata/RHSA-2026:34608",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:37390",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:50085",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/security/cve/CVE-2026-44893",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2488383",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44893.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-12T15:16:26.103",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44893"
                }
            ]
        },
        {
            "id": "CVE-2026-44766",
            "vendor": "SAP_SE",
            "product": "SAP S/4HANA (Intercompany Matching and Reconciliation)",
            "title": "SAP S/4HANA (Intercompany Matching and Reconciliation) vulnerability",
            "summary": "SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality, with no impact on integrity and availability of the application.",
            "updated_at": "2026-09-08T01:17:30.997",
            "published_at": "2026-09-08T01:17:30.997",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "SAPSCORE 136; S4CORE 104; 105; 106; 107; 108; 109",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without proper validation. This could allow the user to access sensitive information, resulting in high impact on confidentiality, with no impact on integrity and availability of the application.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3756450",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:30.997",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44766"
                }
            ]
        },
        {
            "id": "CVE-2026-44756",
            "vendor": "SAP_SE",
            "product": "SAP Extended Passport (EPP) Processing",
            "title": "SAP Extended Passport (EPP) Processing vulnerability",
            "summary": "A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.",
            "updated_at": "2026-09-08T01:17:30.840",
            "published_at": "2026-09-08T01:17:30.840",
            "cvss": 10,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "KRNL64NUC 7.22; 7.22EXT; KRNL64UC 7.22; 7.53; 8.04; WEBDISP 9.16; 9.18; 9.19; 9.20; KERNEL 7.22; 7.54; 7.77; 7.89; 7.93; 9.16",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3747649",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:17:30.840",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44756"
                }
            ]
        },
        {
            "id": "CVE-2026-44745",
            "vendor": "SAP_SE",
            "product": "SAP Approuter",
            "title": "SAP Approuter vulnerability",
            "summary": "SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.",
            "updated_at": "2026-09-08T20:20:34.980",
            "published_at": "2026-07-14T01:16:17.320",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "SAP Approuter node.js package < 21.2.0",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-601",
            "what_happened": "SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3741519",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-07-14T01:16:17.320",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44745"
                }
            ]
        },
        {
            "id": "CVE-2026-44741",
            "vendor": "pimcore",
            "product": "pimcore",
            "title": "pimcore vulnerability",
            "summary": "Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTAMP(DATE(FROM_UNIXTIME(...)))` SQL expression without parameterization or allowlist validation. Versiosn 2.3.6 and 1.7.18 fix the issue.",
            "updated_at": "2026-09-16T13:42:43.377",
            "published_at": "2026-08-12T18:17:29.823",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.7.18; >= 2.0.0-RC1, < 2.3.6",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a `UNIX_TIMESTAMP(DATE(FROM_UNIXTIME(...)))` SQL expression without parameterization or allowlist validation. Versiosn 2.3.6 and 1.7.18 fix the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pimcore/admin-ui-classic-bundle/commit/80e57a23d9e19574eddfe9b08e8f26785b2b0d90",
                "https://github.com/pimcore/admin-ui-classic-bundle/pull/1111",
                "https://github.com/pimcore/admin-ui-classic-bundle/releases/tag/v2.3.6",
                "https://github.com/pimcore/pimcore/security/advisories/GHSA-h4ph-crvj-9h92"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T18:17:29.823",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44741"
                }
            ]
        },
        {
            "id": "CVE-2026-44706",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-44706 exploit",
            "summary": "Exploit for CVE-2026-44706. CVSS 8.5.",
            "updated_at": "2026-09-14T04:52:23Z",
            "published_at": "2026-09-14T04:52:23Z",
            "cvss": 8.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 23,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "SQL injection in Chatwoot ≤ 4.11.1 FilterService lets agents read full PostgreSQL database.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-44706",
                    "summary": "SQL injection in Chatwoot ≤ 4.11.1 FilterService lets agents read full PostgreSQL database.",
                    "what_happened": "SQL injection in Chatwoot ≤ 4.11.1 FilterService lets agents read full PostgreSQL database.",
                    "cvss": 8.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HAKAIOFFSEC-CVE-2026-44706",
                        "https://kitploit.com/hi/tools/github/hakaioffsec/cve-2026-44706/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T16:40:20",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HAKAIOFFSEC-CVE-2026-44706"
                },
                {
                    "title": "Exploit for CVE-2026-44706",
                    "summary": "SQL injection in Chatwoot ≤ 4.11.1 FilterService lets agents read full PostgreSQL database.",
                    "what_happened": "SQL injection in Chatwoot ≤ 4.11.1 FilterService lets agents read full PostgreSQL database.",
                    "cvss": 8.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HAKAIOFFSEC-CVE-2026-44706",
                        "https://kitploit.com/hi/tools/github/hakaioffsec/cve-2026-44706/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T16:40:20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/hakaioffsec/cve-2026-44706/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HAKAIOFFSEC-CVE-2026-44706",
                "https://kitploit.com/hi/tools/github/hakaioffsec/cve-2026-44706/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:52:23Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HAKAIOFFSEC-CVE-2026-44706"
                }
            ]
        },
        {
            "id": "CVE-2026-44578",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for nextjs-cve-2026-44578 CVE-2026-44578",
            "summary": "SSRF in Next.js WebSocket Upgrade Handler exposing multi-cloud metadata endpoints.",
            "updated_at": "2026-09-02T12:19:53Z",
            "published_at": "2026-09-02T12:19:53Z",
            "cvss": 8.6,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 65,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "SSRF in Next.js WebSocket Upgrade Handler exposing multi-cloud metadata endpoints.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for nextjs-cve-2026-44578 CVE-2026-44578",
                    "summary": "SSRF in Next.js WebSocket Upgrade Handler exposing multi-cloud metadata endpoints.",
                    "what_happened": "SSRF in Next.js WebSocket Upgrade Handler exposing multi-cloud metadata endpoints.",
                    "cvss": 8.6,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LOVE07OJ-NEXTJS-CVE-2026-44578",
                        "https://kitploit.com/ru/tools/github/love07oj/nextjs-cve-2026-44578/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-02T14:19:53",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LOVE07OJ-NEXTJS-CVE-2026-44578"
                },
                {
                    "title": "Exploit for nextjs-cve-2026-44578 CVE-2026-44578",
                    "summary": "SSRF in Next.js WebSocket Upgrade Handler exposing multi-cloud metadata endpoints.",
                    "what_happened": "SSRF in Next.js WebSocket Upgrade Handler exposing multi-cloud metadata endpoints.",
                    "cvss": 8.6,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LOVE07OJ-NEXTJS-CVE-2026-44578",
                        "https://kitploit.com/ru/tools/github/love07oj/nextjs-cve-2026-44578/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-02T14:19:53",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/love07oj/nextjs-cve-2026-44578/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LOVE07OJ-NEXTJS-CVE-2026-44578",
                "https://kitploit.com/ru/tools/github/love07oj/nextjs-cve-2026-44578/"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T12:19:53Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LOVE07OJ-NEXTJS-CVE-2026-44578"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2026-44496",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads document.cookie. The practical impact is client-side availability degradation, such as freezing the affected browser tab while axios prepares a request. The issue does not affect ordinary Node.js HTTP adapter usage, React Native, or web workers, where axios does not read document.cookie. This vulnerability is fixed in 0.32.0 and 1.16.0.",
            "updated_at": "2026-09-11T13:18:09.287",
            "published_at": "2026-06-11T17:16:33.590",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.16.0; < 0.32.0",
            "fixed": "See vendor advisory",
            "source_count": 69,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metacharacters. In standard browser environments, an attacker who can influence the cookie name passed to axios can cause expensive regex backtracking while axios reads document.cookie. The practical impact is client-side availability degradation, such as freezing the affected browser tab while axios prepares a request. The issue does not affect ordinary Node.js HTTP adapter usage, React Native, or web workers, where axios does not read document.cookie. This vulnerability is fixed in 0.32.0 and 1.16.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-06-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-hfxv-24rg-xrqf"
                }
            ],
            "references": [
                "https://github.com/axios/axios/security/advisories/GHSA-hfxv-24rg-xrqf",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:27044",
                "https://access.redhat.com/errata/RHSA-2026:27063",
                "https://access.redhat.com/errata/RHSA-2026:28571",
                "https://access.redhat.com/errata/RHSA-2026:28964",
                "https://access.redhat.com/errata/RHSA-2026:29082",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:30076",
                "https://access.redhat.com/errata/RHSA-2026:30650",
                "https://access.redhat.com/errata/RHSA-2026:30651",
                "https://access.redhat.com/errata/RHSA-2026:33155",
                "https://access.redhat.com/errata/RHSA-2026:33160",
                "https://access.redhat.com/errata/RHSA-2026:33163",
                "https://access.redhat.com/errata/RHSA-2026:33173",
                "https://access.redhat.com/errata/RHSA-2026:33183",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:33683",
                "https://access.redhat.com/errata/RHSA-2026:34766",
                "https://access.redhat.com/errata/RHSA-2026:36611",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:36883",
                "https://access.redhat.com/errata/RHSA-2026:41055",
                "https://access.redhat.com/errata/RHSA-2026:41064",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:42085",
                "https://access.redhat.com/errata/RHSA-2026:42142",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:46903",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/errata/RHSA-2026:56789",
                "https://access.redhat.com/errata/RHSA-2026:57191",
                "https://access.redhat.com/errata/RHSA-2026:59360",
                "https://access.redhat.com/errata/RHSA-2026:59833",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-44496",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2487943",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44496.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-11T17:16:33.590",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44496"
                }
            ]
        },
        {
            "id": "CVE-2026-44495",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions may treat that inherited value as request configuration or as an option validator. Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-pollution vulnerability or equivalent attacker control over Object.prototype before Axios creates a request. This vulnerability is fixed in 0.31.1 and 1.15.2.",
            "updated_at": "2026-09-11T13:18:08.610",
            "published_at": "2026-06-11T17:16:33.450",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.15.2; >= 0.19.0, < 0.31.1",
            "fixed": "See vendor advisory",
            "source_count": 75,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-94",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions may treat that inherited value as request configuration or as an option validator. Axios does not itself create the prototype pollution. Exploitability requires a separate prototype-pollution vulnerability or equivalent attacker control over Object.prototype before Axios creates a request. This vulnerability is fixed in 0.31.1 and 1.15.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-06-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-3g43-6gmg-66jw"
                }
            ],
            "references": [
                "https://github.com/axios/axios/security/advisories/GHSA-3g43-6gmg-66jw",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:27044",
                "https://access.redhat.com/errata/RHSA-2026:27063",
                "https://access.redhat.com/errata/RHSA-2026:27944",
                "https://access.redhat.com/errata/RHSA-2026:28964",
                "https://access.redhat.com/errata/RHSA-2026:29082",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:30650",
                "https://access.redhat.com/errata/RHSA-2026:30651",
                "https://access.redhat.com/errata/RHSA-2026:33155",
                "https://access.redhat.com/errata/RHSA-2026:33160",
                "https://access.redhat.com/errata/RHSA-2026:33163",
                "https://access.redhat.com/errata/RHSA-2026:33173",
                "https://access.redhat.com/errata/RHSA-2026:33183",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:34160",
                "https://access.redhat.com/errata/RHSA-2026:34374",
                "https://access.redhat.com/errata/RHSA-2026:36108",
                "https://access.redhat.com/errata/RHSA-2026:36611",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:36883",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:40768",
                "https://access.redhat.com/errata/RHSA-2026:40792",
                "https://access.redhat.com/errata/RHSA-2026:40795",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41055",
                "https://access.redhat.com/errata/RHSA-2026:41064",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:42142",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:46903",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/errata/RHSA-2026:53840",
                "https://access.redhat.com/errata/RHSA-2026:54188",
                "https://access.redhat.com/errata/RHSA-2026:54555",
                "https://access.redhat.com/errata/RHSA-2026:57191",
                "https://access.redhat.com/errata/RHSA-2026:59833",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-44495",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2487937",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44495.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-11T17:16:33.450",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44495"
                }
            ]
        },
        {
            "id": "CVE-2026-44494",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepting, reading, and modifying all HTTP traffic including authentication credentials. The HTTP adapter at lib/adapters/http.js:670 reads config.proxy via standard property access, which traverses the prototype chain. Because proxy is not present in Axios defaults, the merged config object has no own proxy property, making it trivially injectable via prototype pollution. Once injected, setProxy() routes all HTTP requests through the attacker's proxy server. This vulnerability is fixed in 1.16.0.",
            "updated_at": "2026-09-11T13:18:07.983",
            "published_at": "2026-06-11T17:16:33.313",
            "cvss": 8.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.16.0",
            "fixed": "See vendor advisory",
            "source_count": 76,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-441",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into a full Man-in-the-Middle (MITM) attack — intercepting, reading, and modifying all HTTP traffic including authentication credentials. The HTTP adapter at lib/adapters/http.js:670 reads config.proxy via standard property access, which traverses the prototype chain. Because proxy is not present in Axios defaults, the merged config object has no own proxy property, making it trivially injectable via prototype pollution. Once injected, setProxy() routes all HTTP requests through the attacker's proxy server. This vulnerability is fixed in 1.16.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-06-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-35jp-ww65-95wh"
                }
            ],
            "references": [
                "https://github.com/axios/axios/security/advisories/GHSA-35jp-ww65-95wh",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:27044",
                "https://access.redhat.com/errata/RHSA-2026:28964",
                "https://access.redhat.com/errata/RHSA-2026:29082",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:29800",
                "https://access.redhat.com/errata/RHSA-2026:29864",
                "https://access.redhat.com/errata/RHSA-2026:30650",
                "https://access.redhat.com/errata/RHSA-2026:30651",
                "https://access.redhat.com/errata/RHSA-2026:33005",
                "https://access.redhat.com/errata/RHSA-2026:33155",
                "https://access.redhat.com/errata/RHSA-2026:33160",
                "https://access.redhat.com/errata/RHSA-2026:33163",
                "https://access.redhat.com/errata/RHSA-2026:33173",
                "https://access.redhat.com/errata/RHSA-2026:33183",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:34525",
                "https://access.redhat.com/errata/RHSA-2026:34527",
                "https://access.redhat.com/errata/RHSA-2026:34530",
                "https://access.redhat.com/errata/RHSA-2026:34794",
                "https://access.redhat.com/errata/RHSA-2026:36108",
                "https://access.redhat.com/errata/RHSA-2026:36611",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:36883",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:40792",
                "https://access.redhat.com/errata/RHSA-2026:40795",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41055",
                "https://access.redhat.com/errata/RHSA-2026:41064",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:42085",
                "https://access.redhat.com/errata/RHSA-2026:42142",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:46903",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/errata/RHSA-2026:54188",
                "https://access.redhat.com/errata/RHSA-2026:57191",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-44494",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2487942",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44494.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-11T17:16:33.313",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44494"
                }
            ]
        },
        {
            "id": "CVE-2026-44492",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes through the configured proxy. Node.js resolves these addresses to the underlying IPv4 host, so the request reaches the internal service via the proxy rather than being blocked. This vulnerability is fixed in 0.32.0 and 1.16.0.",
            "updated_at": "2026-09-11T13:18:07.357",
            "published_at": "2026-06-11T17:16:33.167",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.16.0; < 0.32.0",
            "fixed": "See vendor advisory",
            "source_count": 71,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6 addresses. When NO_PROXY lists an IPv4 address such as 127.0.0.1 or 169.254.169.254, a request URL using the IPv4-mapped IPv6 form (::ffff:7f00:1, ::ffff:a9fe:a9fe) still routes through the configured proxy. Node.js resolves these addresses to the underlying IPv4 host, so the request reaches the internal service via the proxy rather than being blocked. This vulnerability is fixed in 0.32.0 and 1.16.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-06-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-pjwm-pj3p-43mv"
                }
            ],
            "references": [
                "https://github.com/axios/axios/security/advisories/GHSA-pjwm-pj3p-43mv",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:27044",
                "https://access.redhat.com/errata/RHSA-2026:27063",
                "https://access.redhat.com/errata/RHSA-2026:28964",
                "https://access.redhat.com/errata/RHSA-2026:29082",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:30650",
                "https://access.redhat.com/errata/RHSA-2026:30651",
                "https://access.redhat.com/errata/RHSA-2026:33005",
                "https://access.redhat.com/errata/RHSA-2026:33155",
                "https://access.redhat.com/errata/RHSA-2026:33160",
                "https://access.redhat.com/errata/RHSA-2026:33163",
                "https://access.redhat.com/errata/RHSA-2026:33173",
                "https://access.redhat.com/errata/RHSA-2026:33183",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:34766",
                "https://access.redhat.com/errata/RHSA-2026:36108",
                "https://access.redhat.com/errata/RHSA-2026:36611",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:36883",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41055",
                "https://access.redhat.com/errata/RHSA-2026:41064",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:42085",
                "https://access.redhat.com/errata/RHSA-2026:42142",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:46903",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/errata/RHSA-2026:54188",
                "https://access.redhat.com/errata/RHSA-2026:57191",
                "https://access.redhat.com/errata/RHSA-2026:59833",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-44492",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2487938",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44492.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-11T17:16:33.167",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44492"
                }
            ]
        },
        {
            "id": "CVE-2026-44488",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments where axios resolved to the fetch adapter, could receive or send bodies larger than maxContentLength or maxBodyLength despite those limits being explicitly configured. This can cause resource exhaustion in server-side usage when a malicious or compromised server returns an oversized response, when an attacker can supply a large data: URL, or when an application forwards attacker-controlled request bodies through axios while relying on maxBodyLength as a boundary. This vulnerability is fixed in 0.32.0 and 1.16.0.",
            "updated_at": "2026-09-11T13:18:06.717",
            "published_at": "2026-06-11T17:16:32.750",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.7.0, < 1.16.0",
            "fixed": "See vendor advisory",
            "source_count": 76,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Applications that selected adapter: 'fetch', or ran in environments where axios resolved to the fetch adapter, could receive or send bodies larger than maxContentLength or maxBodyLength despite those limits being explicitly configured. This can cause resource exhaustion in server-side usage when a malicious or compromised server returns an oversized response, when an attacker can supply a large data: URL, or when an application forwards attacker-controlled request bodies through axios while relying on maxBodyLength as a boundary. This vulnerability is fixed in 0.32.0 and 1.16.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-06-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-777c-7fjr-54vf"
                }
            ],
            "references": [
                "https://github.com/axios/axios/security/advisories/GHSA-777c-7fjr-54vf",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:27044",
                "https://access.redhat.com/errata/RHSA-2026:27063",
                "https://access.redhat.com/errata/RHSA-2026:28964",
                "https://access.redhat.com/errata/RHSA-2026:29082",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:30650",
                "https://access.redhat.com/errata/RHSA-2026:30651",
                "https://access.redhat.com/errata/RHSA-2026:33155",
                "https://access.redhat.com/errata/RHSA-2026:33160",
                "https://access.redhat.com/errata/RHSA-2026:33163",
                "https://access.redhat.com/errata/RHSA-2026:33173",
                "https://access.redhat.com/errata/RHSA-2026:33183",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:34160",
                "https://access.redhat.com/errata/RHSA-2026:34374",
                "https://access.redhat.com/errata/RHSA-2026:34525",
                "https://access.redhat.com/errata/RHSA-2026:34527",
                "https://access.redhat.com/errata/RHSA-2026:34530",
                "https://access.redhat.com/errata/RHSA-2026:36611",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:36883",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:40768",
                "https://access.redhat.com/errata/RHSA-2026:40792",
                "https://access.redhat.com/errata/RHSA-2026:40795",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41055",
                "https://access.redhat.com/errata/RHSA-2026:41064",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:42085",
                "https://access.redhat.com/errata/RHSA-2026:42142",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:46903",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/errata/RHSA-2026:54188",
                "https://access.redhat.com/errata/RHSA-2026:54555",
                "https://access.redhat.com/errata/RHSA-2026:57191",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-44488",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2487949",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44488.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-11T17:16:32.750",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44488"
                }
            ]
        },
        {
            "id": "CVE-2026-44487",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redirected URL is no longer proxied. Under affected redirect shapes, the final origin can receive the proxy credential that was intended only for the outbound proxy. This vulnerability is fixed in 0.32.0 and 1.16.0.",
            "updated_at": "2026-09-11T13:18:06.053",
            "published_at": "2026-06-11T17:16:32.607",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.16.0; < 0.32.0",
            "fixed": "See vendor advisory",
            "source_count": 76,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-201",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct redirect flows. This affects Node.js usage, where an initial HTTP request is sent through an authenticated HTTP proxy, redirects are followed, and the redirected URL is no longer proxied. Under affected redirect shapes, the final origin can receive the proxy credential that was intended only for the outbound proxy. This vulnerability is fixed in 0.32.0 and 1.16.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-06-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-p92q-9vqr-4j8v"
                }
            ],
            "references": [
                "https://github.com/axios/axios/security/advisories/GHSA-p92q-9vqr-4j8v",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:27044",
                "https://access.redhat.com/errata/RHSA-2026:27063",
                "https://access.redhat.com/errata/RHSA-2026:28964",
                "https://access.redhat.com/errata/RHSA-2026:29082",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:29864",
                "https://access.redhat.com/errata/RHSA-2026:30650",
                "https://access.redhat.com/errata/RHSA-2026:30651",
                "https://access.redhat.com/errata/RHSA-2026:33155",
                "https://access.redhat.com/errata/RHSA-2026:33160",
                "https://access.redhat.com/errata/RHSA-2026:33163",
                "https://access.redhat.com/errata/RHSA-2026:33173",
                "https://access.redhat.com/errata/RHSA-2026:33183",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:34374",
                "https://access.redhat.com/errata/RHSA-2026:34525",
                "https://access.redhat.com/errata/RHSA-2026:34527",
                "https://access.redhat.com/errata/RHSA-2026:34530",
                "https://access.redhat.com/errata/RHSA-2026:36611",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:36883",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:40768",
                "https://access.redhat.com/errata/RHSA-2026:40792",
                "https://access.redhat.com/errata/RHSA-2026:40795",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41055",
                "https://access.redhat.com/errata/RHSA-2026:41064",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:42085",
                "https://access.redhat.com/errata/RHSA-2026:42142",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:46903",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/errata/RHSA-2026:54188",
                "https://access.redhat.com/errata/RHSA-2026:54206",
                "https://access.redhat.com/errata/RHSA-2026:57191",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-44487",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2487948",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44487.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-11T17:16:32.607",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44487"
                }
            ]
        },
        {
            "id": "CVE-2026-44486",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header. If Axios then follows a redirect and the redirected request is no longer sent through that proxy, the stale Proxy-Authorization header can remain on the redirected request and be sent to the redirect target. This affects Node.js's use of Axios with automatic redirects enabled and an authenticated proxy configuration. Browser adapters are not affected. This vulnerability is fixed in 0.32.0 and 1.16.0.",
            "updated_at": "2026-09-11T13:18:05.413",
            "published_at": "2026-06-11T17:16:32.450",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.16.0; < 0.32.0",
            "fixed": "See vendor advisory",
            "source_count": 70,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent through an authenticated proxy, Axios may add a Proxy-Authorization header. If Axios then follows a redirect and the redirected request is no longer sent through that proxy, the stale Proxy-Authorization header can remain on the redirected request and be sent to the redirect target. This affects Node.js's use of Axios with automatic redirects enabled and an authenticated proxy configuration. Browser adapters are not affected. This vulnerability is fixed in 0.32.0 and 1.16.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-06-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-j5f8-grm9-p9fc"
                }
            ],
            "references": [
                "https://github.com/axios/axios/security/advisories/GHSA-j5f8-grm9-p9fc",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:27044",
                "https://access.redhat.com/errata/RHSA-2026:27063",
                "https://access.redhat.com/errata/RHSA-2026:28964",
                "https://access.redhat.com/errata/RHSA-2026:29082",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:30650",
                "https://access.redhat.com/errata/RHSA-2026:30651",
                "https://access.redhat.com/errata/RHSA-2026:33155",
                "https://access.redhat.com/errata/RHSA-2026:33160",
                "https://access.redhat.com/errata/RHSA-2026:33163",
                "https://access.redhat.com/errata/RHSA-2026:33173",
                "https://access.redhat.com/errata/RHSA-2026:33183",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:34766",
                "https://access.redhat.com/errata/RHSA-2026:36611",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:36883",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41055",
                "https://access.redhat.com/errata/RHSA-2026:41064",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:42085",
                "https://access.redhat.com/errata/RHSA-2026:42142",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:46903",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/errata/RHSA-2026:50681",
                "https://access.redhat.com/errata/RHSA-2026:54188",
                "https://access.redhat.com/errata/RHSA-2026:54206",
                "https://access.redhat.com/errata/RHSA-2026:57191",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-44486",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2487947",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44486.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-11T17:16:32.450",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44486"
                }
            ]
        },
        {
            "id": "CVE-2026-44432",
            "vendor": "urllib3",
            "product": "urllib3",
            "title": "urllib3 vulnerability",
            "summary": "urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.",
            "updated_at": "2026-09-10T13:20:11.887",
            "published_at": "2026-05-13T16:16:57.303",
            "cvss": 8.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 2.6.0, < 2.7.0",
            "fixed": "See vendor advisory",
            "source_count": 62,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-409",
            "what_happened": "urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j",
                "https://access.redhat.com/errata/RHSA-2026:15862",
                "https://access.redhat.com/errata/RHSA-2026:20338",
                "https://access.redhat.com/errata/RHSA-2026:22934",
                "https://access.redhat.com/errata/RHSA-2026:24000",
                "https://access.redhat.com/errata/RHSA-2026:24009",
                "https://access.redhat.com/errata/RHSA-2026:24014",
                "https://access.redhat.com/errata/RHSA-2026:24069",
                "https://access.redhat.com/errata/RHSA-2026:24374",
                "https://access.redhat.com/errata/RHSA-2026:24476",
                "https://access.redhat.com/errata/RHSA-2026:24483",
                "https://access.redhat.com/errata/RHSA-2026:24540",
                "https://access.redhat.com/errata/RHSA-2026:24541",
                "https://access.redhat.com/errata/RHSA-2026:24542",
                "https://access.redhat.com/errata/RHSA-2026:24544",
                "https://access.redhat.com/errata/RHSA-2026:25039",
                "https://access.redhat.com/errata/RHSA-2026:25143",
                "https://access.redhat.com/errata/RHSA-2026:25928",
                "https://access.redhat.com/errata/RHSA-2026:26212",
                "https://access.redhat.com/errata/RHSA-2026:26304",
                "https://access.redhat.com/errata/RHSA-2026:27929",
                "https://access.redhat.com/errata/RHSA-2026:28000",
                "https://access.redhat.com/errata/RHSA-2026:28157",
                "https://access.redhat.com/errata/RHSA-2026:28158",
                "https://access.redhat.com/errata/RHSA-2026:28159",
                "https://access.redhat.com/errata/RHSA-2026:28571",
                "https://access.redhat.com/errata/RHSA-2026:30076",
                "https://access.redhat.com/errata/RHSA-2026:30078",
                "https://access.redhat.com/errata/RHSA-2026:30087",
                "https://access.redhat.com/errata/RHSA-2026:30088",
                "https://access.redhat.com/errata/RHSA-2026:30089",
                "https://access.redhat.com/errata/RHSA-2026:32992",
                "https://access.redhat.com/errata/RHSA-2026:33313",
                "https://access.redhat.com/errata/RHSA-2026:33683",
                "https://access.redhat.com/errata/RHSA-2026:34160",
                "https://access.redhat.com/errata/RHSA-2026:34374",
                "https://access.redhat.com/errata/RHSA-2026:34526",
                "https://access.redhat.com/errata/RHSA-2026:34531",
                "https://access.redhat.com/errata/RHSA-2026:34533",
                "https://access.redhat.com/errata/RHSA-2026:34607",
                "https://access.redhat.com/errata/RHSA-2026:36350",
                "https://access.redhat.com/errata/RHSA-2026:37275",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:42079",
                "https://access.redhat.com/errata/RHSA-2026:42132",
                "https://access.redhat.com/errata/RHSA-2026:42144",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43038",
                "https://access.redhat.com/errata/RHSA-2026:44481",
                "https://access.redhat.com/errata/RHSA-2026:51206",
                "https://access.redhat.com/errata/RHSA-2026:56347",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/errata/RHSA-2026:59409",
                "https://access.redhat.com/errata/RHSA-2026:60362",
                "https://access.redhat.com/errata/RHSA-2026:60371",
                "https://access.redhat.com/errata/RHSA-2026:7625",
                "https://access.redhat.com/errata/RHSA-2026:7634",
                "https://access.redhat.com/security/cve/CVE-2026-44432",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2477154",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44432.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-13T16:16:57.303",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44432"
                }
            ]
        },
        {
            "id": "CVE-2026-44402",
            "vendor": "Voltronic Power",
            "product": "SNMP Web Pro",
            "title": "Exploit for CVE-2026-44402",
            "summary": "Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.",
            "updated_at": "2026-09-04T18:17:52.080",
            "published_at": "2026-09-04T16:17:25.250",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "1.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 81,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-44402",
                    "summary": "Unauthenticated RCE in Voltronic Power SNMP Web Pro 1.1 via upload.cgi firmware endpoint.",
                    "what_happened": "Unauthenticated RCE in Voltronic Power SNMP Web Pro 1.1 via upload.cgi firmware endpoint.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "references": [
                        "https://sploitus.com/exploit?id=A8B1CF3F-2B63-5B3F-A99B-2A07E3DD8B25",
                        "https://github.com/0xCyp1337/CVE-2026-44402"
                    ],
                    "repository": "Sploitus",
                    "author": "0xCyp1337",
                    "first_seen": "2026-09-06T13:59:40",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=A8B1CF3F-2B63-5B3F-A99B-2A07E3DD8B25"
                },
                {
                    "title": "Exploit for CVE-2026-44402",
                    "summary": "Unauthenticated RCE in Voltronic Power SNMP Web Pro 1.1 via upload.cgi firmware endpoint.",
                    "what_happened": "Unauthenticated RCE in Voltronic Power SNMP Web Pro 1.1 via upload.cgi firmware endpoint.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "references": [
                        "https://sploitus.com/exploit?id=A8B1CF3F-2B63-5B3F-A99B-2A07E3DD8B25",
                        "https://github.com/0xCyp1337/CVE-2026-44402"
                    ],
                    "repository": "0xCyp1337/CVE-2026-44402",
                    "author": "0xCyp1337",
                    "first_seen": "2026-09-06T13:59:40",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/0xCyp1337/CVE-2026-44402"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=A8B1CF3F-2B63-5B3F-A99B-2A07E3DD8B25",
                "https://github.com/0xCyp1337/CVE-2026-44402",
                "https://github.com/Virgula0/CVE-2026-44402",
                "https://voltronicpower.com/",
                "https://www.vulncheck.com/advisories/voltronic-power-snmp-web-pro-unauthenticated-rce-via-upload-cgi"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T11:59:40Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=A8B1CF3F-2B63-5B3F-A99B-2A07E3DD8B25"
                },
                {
                    "at": "2026-09-04T16:17:25.250",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44402"
                }
            ],
            "enrichment_checked_at": "2026-09-06T16:05:27Z",
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
        },
        {
            "id": "CVE-2026-44401",
            "vendor": "Typemill",
            "product": "Typemill",
            "title": "Typemill vulnerability",
            "summary": "Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious JavaScript URIs by supplying unsanitized href values in Markdown links. Attackers can craft Markdown links using the javascript: scheme through ParsedownExtension.php or TwigMarkdownExtension.php, storing a persistent payload that executes in the browser of every visitor who clicks the link, enabling session cookie theft, authenticated request forgery, and credential harvesting.",
            "updated_at": "2026-09-10T20:44:57.447",
            "published_at": "2026-08-10T20:17:30.870",
            "cvss": 4.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.0.0 through 2.23.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that allows authenticated users with theme-configuration access to inject malicious JavaScript URIs by supplying unsanitized href values in Markdown links. Attackers can craft Markdown links using the javascript: scheme through ParsedownExtension.php or TwigMarkdownExtension.php, storing a persistent payload that executes in the browser of every visitor who clicks the link, enabling session cookie theft, authenticated request forgery, and credential harvesting.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/sn0x-sharma/CVE-2026-44401",
                "https://github.com/typemill/typemill",
                "https://github.com/typemill/typemill/releases/tag/v2.23.0",
                "https://www.vulncheck.com/advisories/typemill-cms-2-x-persistent-xss-via-markdown-javascript-uri"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T20:17:30.870",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44401"
                }
            ]
        },
        {
            "id": "CVE-2026-44249",
            "vendor": "netty",
            "product": "netty",
            "title": "netty vulnerability",
            "summary": "Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
            "updated_at": "2026-09-11T13:18:04.870",
            "published_at": "2026-06-11T22:16:56.707",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 4.2.0.Final, < 4.2.15.Final; < 4.1.135.Final",
            "fixed": "See vendor advisory",
            "source_count": 25,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-284",
            "what_happened": "Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final",
                "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final",
                "https://github.com/netty/netty/security/advisories/GHSA-3qp7-7mw8-wx86",
                "https://access.redhat.com/errata/RHSA-2026:26017",
                "https://access.redhat.com/errata/RHSA-2026:26018",
                "https://access.redhat.com/errata/RHSA-2026:26586",
                "https://access.redhat.com/errata/RHSA-2026:28573",
                "https://access.redhat.com/errata/RHSA-2026:34608",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:37390",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:48124",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:49700",
                "https://access.redhat.com/errata/RHSA-2026:49701",
                "https://access.redhat.com/errata/RHSA-2026:50085",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-44249",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2488081",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44249.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-11T22:16:56.707",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44249"
                }
            ]
        },
        {
            "id": "CVE-2026-44248",
            "vendor": "netty",
            "product": "netty",
            "title": "netty vulnerability",
            "summary": "Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.",
            "updated_at": "2026-09-11T13:18:04.643",
            "published_at": "2026-05-13T19:17:27.143",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 4.2.0.Alpha1, < 4.2.13.Final; < 4.1.133.Final",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT 5 header Properties section is parsed and buffered before any message size limit is applied. Specifically, in MqttDecoder, the decodeVariableHeader() method is called before the bytesRemainingBeforeVariableHeader > maxBytesInMessage check. The decodeVariableHeader() can call other methods which will call decodeProperties(). Effectively, Netty does not apply any limits to the size of the properties being decoded. Additionally, because MqttDecoder extends ReplayingDecoder, Netty will repeatedly re-parse the enormous Properties sections and buffer the bytes in memory, until the entire thing parses to completion. This can cause high resource usage in both CPU and memory. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/netty/netty/security/advisories/GHSA-jfg9-48mv-9qgx",
                "https://access.redhat.com/errata/RHSA-2026:37390",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-44248",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2477231",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44248.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-13T19:17:27.143",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-44248"
                }
            ]
        },
        {
            "id": "CVE-2026-43965",
            "vendor": "Gleam",
            "product": "Gleam",
            "title": "Gleam vulnerability",
            "summary": "Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content.\n\nPackage keys read from build/packages/packages.toml by LocalPackages::read_from_disc are passed without validation to paths.build_packages_package(), which constructs a filesystem path by joining the project build directory with the attacker-controlled key. The resulting path is then passed to fs::delete_directory (which calls remove_dir_all). No check is performed to ensure the path remains within the intended build/packages/ directory. Both absolute paths and relative traversal sequences (e.g. ../) are accepted as package keys, allowing deletion of arbitrary directories.\n\nAn attacker who can cause a victim to run gleam deps download on a project containing a malicious build/packages/packages.toml (e.g. by committing the normally-gitignored file to a repository) can cause arbitrary directories on the victim's system to be recursively deleted.\n\nThis issue affects Gleam from 0.18.0-rc1 until 1.17.0.",
            "updated_at": "2026-09-08T01:17:30.670",
            "published_at": "2026-06-02T14:16:54.053",
            "cvss": 5.6,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.18.0-rc1 through before 1.17.0 (semver); ed7aec0484f10d60978b63788c8a6497590855ab through before 690ca069817bee5f77a28fc3e360627c1da19291 (git); v0.18.0-rc1-elixir through before v1.17.0-elixir (other); v0.18.0-rc1-erlang through before v1.17.0-erlang (other); v0.18.0-rc1-node through before v1.17.0-node (other); v0.18.0-rc1-node-slim through before v1.17.0-node-slim (other); v0.18.0-rc1-elixir-slim through before v1.17.0-elixir-slim (other); v0.18.0-rc1-erlang-slim through before v1.17.0-erlang-slim (other); v0.18.0-rc1-erlang-alpine through before v1.17.0-erlang-alpine (other); v0.18.0-rc1-elixir-alpine through before v1.17.0-elixir-alpine (other); v0.18.0-rc1-node-alpine through before v1.17.0-node-alpine (other); v0.18.0-rc1-scratch through before v1.17.0-scratch (other)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content.\n\nPackage keys read from build/packages/packages.toml by LocalPackages::read_from_disc are passed without validation to paths.build_packages_package(), which constructs a filesystem path by joining the project build directory with the attacker-controlled key. The resulting path is then passed to fs::delete_directory (which calls remove_dir_all). No check is performed to ensure the path remains within the intended build/packages/ directory. Both absolute paths and relative traversal sequences (e.g. ../) are accepted as package keys, allowing deletion of arbitrary directories.\n\nAn attacker who can cause a victim to run gleam deps download on a project containing a malicious build/packages/packages.toml (e.g. by committing the normally-gitignored file to a repository) can cause arbitrary directories on the victim's system to be recursively deleted.\n\nThis issue affects Gleam from 0.18.0-rc1 until 1.17.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-43965.html",
                "https://github.com/gleam-lang/gleam/commit/690ca069817bee5f77a28fc3e360627c1da19291",
                "https://github.com/gleam-lang/gleam/security/advisories/GHSA-jqvf-f6p2-wrv3",
                "https://osv.dev/vulnerability/EEF-CVE-2026-43965"
            ],
            "timeline": [
                {
                    "at": "2026-06-02T14:16:54.053",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43965"
                }
            ]
        },
        {
            "id": "CVE-2026-43869",
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift",
            "title": "Apache Thrift vulnerability",
            "summary": "Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.",
            "updated_at": "2026-09-07T13:19:52.227",
            "published_at": "2026-05-05T08:16:01.063",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.23.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 18,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-297",
            "what_happened": "Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://lists.apache.org/thread/3hsgl1b69wzq3ry39scqbv2dhyl3j52r",
                "http://www.openwall.com/lists/oss-security/2026/05/05/3",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:24503",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:25273",
                "https://access.redhat.com/errata/RHSA-2026:26586",
                "https://access.redhat.com/errata/RHSA-2026:27126",
                "https://access.redhat.com/errata/RHSA-2026:28010",
                "https://access.redhat.com/errata/RHSA-2026:30651",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/security/cve/CVE-2026-43869",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2466660",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43869.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-05T08:16:01.063",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43869"
                }
            ]
        },
        {
            "id": "CVE-2026-43833",
            "vendor": "tbc",
            "product": "tbc",
            "title": "tbc vulnerability",
            "summary": "Full details and mitigation steps are currently restricted and will be published at a later date.",
            "updated_at": "2026-09-11T13:18:04.307",
            "published_at": "2026-07-31T04:17:22.380",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "tbc",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Full details and mitigation steps are currently restricted and will be published at a later date.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-xxx",
                "https://github.com/CVEProject/cvelistV5/blob/8846a06bd73fefb0d7b7e205f1e21f97d0b9cbe2/cves/2026/43xxx/CVE-2026-43833.json"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T04:17:22.380",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43833"
                }
            ]
        },
        {
            "id": "CVE-2026-43832",
            "vendor": "tbc",
            "product": "tbc",
            "title": "tbc vulnerability",
            "summary": "Full details and mitigation steps are currently restricted and will be published at a later date.",
            "updated_at": "2026-09-11T13:18:04.147",
            "published_at": "2026-07-31T04:17:22.187",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "tbc",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "Full details and mitigation steps are currently restricted and will be published at a later date.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-xxx",
                "https://github.com/CVEProject/cvelistV5/blob/8846a06bd73fefb0d7b7e205f1e21f97d0b9cbe2/cves/2026/43xxx/CVE-2026-43832.json"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T04:17:22.187",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43832"
                }
            ]
        },
        {
            "id": "CVE-2026-43831",
            "vendor": "tbc",
            "product": "tbc",
            "title": "tbc vulnerability",
            "summary": "Full details and mitigation steps are currently restricted and will be published at a later date.",
            "updated_at": "2026-09-11T13:18:04.007",
            "published_at": "2026-07-31T04:17:21.963",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "tbc",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "Full details and mitigation steps are currently restricted and will be published at a later date.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-xxx",
                "https://github.com/CVEProject/cvelistV5/blob/8846a06bd73fefb0d7b7e205f1e21f97d0b9cbe2/cves/2026/43xxx/CVE-2026-43831.json"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T04:17:21.963",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43831"
                }
            ]
        },
        {
            "id": "CVE-2026-43830",
            "vendor": "tbc",
            "product": "tbc",
            "title": "tbc vulnerability",
            "summary": "Full details and mitigation steps are currently restricted and will be published at a later date.",
            "updated_at": "2026-09-11T13:18:03.870",
            "published_at": "2026-07-31T04:17:21.760",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "tbc",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "Full details and mitigation steps are currently restricted and will be published at a later date.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-xxx",
                "https://github.com/CVEProject/cvelistV5/blob/8846a06bd73fefb0d7b7e205f1e21f97d0b9cbe2/cves/2026/43xxx/CVE-2026-43830.json"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T04:17:21.760",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43830"
                }
            ]
        },
        {
            "id": "CVE-2026-43829",
            "vendor": "tbc",
            "product": "tbc",
            "title": "tbc vulnerability",
            "summary": "Full details and mitigation steps are currently restricted and will be published at a later date.",
            "updated_at": "2026-09-11T13:18:03.703",
            "published_at": "2026-07-31T04:17:20.193",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "tbc",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "Full details and mitigation steps are currently restricted and will be published at a later date.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-xxx",
                "https://github.com/CVEProject/cvelistV5/blob/8846a06bd73fefb0d7b7e205f1e21f97d0b9cbe2/cves/2026/43xxx/CVE-2026-43829.json"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T04:17:20.193",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43829"
                }
            ]
        },
        {
            "id": "CVE-2026-43795",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:12.127",
            "published_at": "2026-08-17T22:17:11.560",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, visionOS 27. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:11.560",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43795"
                }
            ]
        },
        {
            "id": "CVE-2026-43794",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.",
            "updated_at": "2026-09-14T21:17:11.910",
            "published_at": "2026-08-17T22:17:11.457",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6.1 (custom); before 18.7.10 (custom); before 26.6.2 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2, tvOS 27, visionOS 27, watchOS 27. Processing maliciously crafted web content may lead to memory corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/148281",
                "https://support.apple.com/en-us/148282",
                "https://support.apple.com/en-us/148286",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:17:11.457",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43794"
                }
            ]
        },
        {
            "id": "CVE-2026-43763",
            "vendor": "Apple",
            "product": "macOS",
            "title": "macOS vulnerability",
            "summary": "A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.8, macOS Sequoia 15.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may be able to read files outside of its sandbox.",
            "updated_at": "2026-09-14T21:17:10.897",
            "published_at": "2026-07-27T21:17:00.663",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 14.8.8 (custom); before 15.7.8 (custom); before 15.8 (custom); before 26.6 (custom); before 26.7 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.8, macOS Sequoia 15.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may be able to read files outside of its sandbox.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/128067",
                "https://support.apple.com/en-us/128071",
                "https://support.apple.com/en-us/128072",
                "https://support.apple.com/en-us/149042",
                "https://support.apple.com/en-us/149043"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T21:17:00.663",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43763"
                }
            ]
        },
        {
            "id": "CVE-2026-43760",
            "vendor": "Apple",
            "product": "macOS",
            "title": "macOS vulnerability",
            "summary": "An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may be able to access user-sensitive data.",
            "updated_at": "2026-09-14T21:17:10.500",
            "published_at": "2026-07-27T21:17:00.557",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 14.8.8 (custom); before 26.6 (custom); before 26.7 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6, macOS Tahoe 26.7. An app may be able to access user-sensitive data.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/128067",
                "https://support.apple.com/en-us/128072",
                "https://support.apple.com/en-us/149042",
                "https://reverse.put.as/2026/07/29/its-a-pre-auth-stupid/"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T21:17:00.557",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43760"
                }
            ]
        },
        {
            "id": "CVE-2026-43748",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
            "updated_at": "2026-09-14T21:17:10.323",
            "published_at": "2026-07-27T21:16:59.550",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.6 (custom); before 15.7.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/128066",
                "https://support.apple.com/en-us/128067",
                "https://support.apple.com/en-us/128071"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T21:16:59.550",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43748"
                }
            ]
        },
        {
            "id": "CVE-2026-43746",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "updated_at": "2026-09-14T21:17:10.137",
            "published_at": "2026-06-29T20:17:37.973",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.5.2 (custom); before 18.7.10 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/127594",
                "https://support.apple.com/en-us/127595",
                "https://support.apple.com/en-us/127685",
                "https://support.apple.com/en-us/148287"
            ],
            "timeline": [
                {
                    "at": "2026-06-29T20:17:37.973",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43746"
                }
            ]
        },
        {
            "id": "CVE-2026-43743",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, iOS 26.7 and iPadOS 26.7, macOS Tahoe 26.5.2, macOS Tahoe 26.7, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
            "updated_at": "2026-09-14T21:17:09.950",
            "published_at": "2026-06-29T20:17:37.783",
            "cvss": 4.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.5.2 (custom); before 26.7 (custom); before 26.6 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, iOS 26.7 and iPadOS 26.7, macOS Tahoe 26.5.2, macOS Tahoe 26.7, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/127594",
                "https://support.apple.com/en-us/127595",
                "https://support.apple.com/en-us/128068",
                "https://support.apple.com/en-us/128069",
                "https://support.apple.com/en-us/149041",
                "https://support.apple.com/en-us/149042"
            ],
            "timeline": [
                {
                    "at": "2026-06-29T20:17:37.783",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43743"
                }
            ]
        },
        {
            "id": "CVE-2026-43738",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog may result in disclosure of process memory.",
            "updated_at": "2026-09-14T21:17:09.670",
            "published_at": "2026-07-27T21:16:58.420",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 18.7.10 (custom); before 27 (custom); before 14.8.8 (custom); before 15.7.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog may result in disclosure of process memory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/128071",
                "https://support.apple.com/en-us/128072",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149034",
                "https://support.apple.com/en-us/149035"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T21:16:58.420",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43738"
                }
            ]
        },
        {
            "id": "CVE-2026-43715",
            "vendor": "Apple",
            "product": "Safari",
            "title": "Safari vulnerability",
            "summary": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, iOS 26.7 and iPadOS 26.7, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.",
            "updated_at": "2026-09-14T21:17:09.273",
            "published_at": "2026-06-29T20:17:36.173",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.5.2 (custom); before 26.7 (custom); before 26.6 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, iOS 26.7 and iPadOS 26.7, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/127594",
                "https://support.apple.com/en-us/127595",
                "https://support.apple.com/en-us/127685",
                "https://support.apple.com/en-us/128068",
                "https://support.apple.com/en-us/128069",
                "https://support.apple.com/en-us/128070",
                "https://support.apple.com/en-us/149041"
            ],
            "timeline": [
                {
                    "at": "2026-06-29T20:17:36.173",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43715"
                }
            ]
        },
        {
            "id": "CVE-2026-43698",
            "vendor": "Apple",
            "product": "macOS",
            "title": "macOS vulnerability",
            "summary": "An injection issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.7. An app may be able to gain root privileges.",
            "updated_at": "2026-09-14T21:17:08.973",
            "published_at": "2026-07-27T21:16:53.370",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 14.8.8 (custom); before 15.7.8 (custom); before 26.7 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-88",
            "what_happened": "An injection issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.7. An app may be able to gain root privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/128071",
                "https://support.apple.com/en-us/128072",
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149042"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T21:16:53.370",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43698"
                }
            ]
        },
        {
            "id": "CVE-2026-43691",
            "vendor": "Apple",
            "product": "macOS",
            "title": "macOS vulnerability",
            "summary": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.",
            "updated_at": "2026-09-15T04:18:05.620",
            "published_at": "2026-09-14T21:17:08.443",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 15.8 (custom); before 26.7 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149042",
                "https://support.apple.com/en-us/149043"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:08.443",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43691"
                }
            ]
        },
        {
            "id": "CVE-2026-43689",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. A malicious app may be able to gain root privileges.",
            "updated_at": "2026-09-15T04:18:05.033",
            "published_at": "2026-09-14T21:17:08.237",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.7 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, visionOS 27. A malicious app may be able to gain root privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/149034",
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149038",
                "https://support.apple.com/en-us/149041"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:08.237",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43689"
                }
            ]
        },
        {
            "id": "CVE-2026-43686",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may lead to kernel memory corruption.",
            "updated_at": "2026-09-16T04:18:22.803",
            "published_at": "2026-09-14T21:17:07.903",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.7 (custom); before 27 (custom); before 15.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Connecting to a malicious NFS server may lead to kernel memory corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/149034",
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038",
                "https://support.apple.com/en-us/149041",
                "https://support.apple.com/en-us/149042",
                "https://support.apple.com/en-us/149043"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:07.903",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43686"
                }
            ]
        },
        {
            "id": "CVE-2026-43684",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27, macOS Sequoia 15.8. An app may be able to cause unexpected system termination or corrupt kernel memory.",
            "updated_at": "2026-09-16T04:18:22.410",
            "published_at": "2026-09-14T21:17:07.800",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.7 (custom); before 15.8 (custom); before 27 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27, macOS Sequoia 15.8. An app may be able to cause unexpected system termination or corrupt kernel memory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149041",
                "https://support.apple.com/en-us/149043"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:07.800",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43684"
                }
            ]
        },
        {
            "id": "CVE-2026-43661",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, iOS 26.7 and iPadOS 26.7, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.",
            "updated_at": "2026-09-14T21:17:06.590",
            "published_at": "2026-05-11T21:19:01.823",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 18.7.10 (custom); before 26.5 (custom); before 26.7 (custom); before 14.8.8 (custom); before 15.7.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, iOS 26.7 and iPadOS 26.7, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing a maliciously crafted image may corrupt process memory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/127110",
                "https://support.apple.com/en-us/127115",
                "https://support.apple.com/en-us/127118",
                "https://support.apple.com/en-us/127119",
                "https://support.apple.com/en-us/128071",
                "https://support.apple.com/en-us/128072",
                "https://support.apple.com/en-us/148287",
                "https://support.apple.com/en-us/149041"
            ],
            "timeline": [
                {
                    "at": "2026-05-11T21:19:01.823",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43661"
                }
            ]
        },
        {
            "id": "CVE-2026-43502",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/rds: handle zerocopy send cleanup before the message is queued\n\nA zerocopy send can fail after user pages have been pinned but before\nthe message is attached to the sending socket.\n\nThe purge path currently infers zerocopy state from rm->m_rs, so an\nunqueued message can be cleaned up as if it owned normal payload pages.\nHowever, zerocopy ownership is really determined by the presence of\nop_mmp_znotifier, regardless of whether the message has reached the\nsocket queue.\n\nCapture op_mmp_znotifier up front in rds_message_purge() and use it as\nthe cleanup discriminator. If the message is already associated with a\nsocket, keep the existing completion path. Otherwise, drop the pinned\npage accounting directly and release the notifier before putting the\npayload pages.\n\nThis keeps early send failure cleanup consistent with the zerocopy\nlifetime rules without changing the normal queued completion path.",
            "updated_at": "2026-09-15T04:18:04.333",
            "published_at": "2026-05-21T13:16:19.520",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3 through before e9aefdc5c53fe9aed108c14e3d155710a1bb14c9 (git); 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3 through before 46662f7dc59475995609bf3e9d27eb36f4acf26f (git); 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3 through before 1e262db7675e27f42c3f3f47d6011855f4454f24 (git); 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3 through before 21d70744e6d3bbf9293aa1ee6fba7c53ad75275e (git); 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3 through before 3abc8983b2bae3f487f77d9da5527d7d6b210d46 (git); 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3 through before 14ef6fd18db2494098b21e0471bf27a1d8e9993e (git); 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3 through before 0f5c185fc79a59ee9991234dd6d2a3e5afa6e75b (git); 0cebaccef3acbdfbc2d85880a2efb765d2f4e2e3 through before 44b550d88b267320459d518c0743a241ab2108fa (git); 4.17",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-401",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/rds: handle zerocopy send cleanup before the message is queued\n\nA zerocopy send can fail after user pages have been pinned but before\nthe message is attached to the sending socket.\n\nThe purge path currently infers zerocopy state from rm->m_rs, so an\nunqueued message can be cleaned up as if it owned normal payload pages.\nHowever, zerocopy ownership is really determined by the presence of\nop_mmp_znotifier, regardless of whether the message has reached the\nsocket queue.\n\nCapture op_mmp_znotifier up front in rds_message_purge() and use it as\nthe cleanup discriminator. If the message is already associated with a\nsocket, keep the existing completion path. Otherwise, drop the pinned\npage accounting directly and release the notifier before putting the\npayload pages.\n\nThis keeps early send failure cleanup consistent with the zerocopy\nlifetime rules without changing the normal queued completion path.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0f5c185fc79a59ee9991234dd6d2a3e5afa6e75b",
                "https://git.kernel.org/stable/c/14ef6fd18db2494098b21e0471bf27a1d8e9993e",
                "https://git.kernel.org/stable/c/1e262db7675e27f42c3f3f47d6011855f4454f24",
                "https://git.kernel.org/stable/c/21d70744e6d3bbf9293aa1ee6fba7c53ad75275e",
                "https://git.kernel.org/stable/c/3abc8983b2bae3f487f77d9da5527d7d6b210d46",
                "https://git.kernel.org/stable/c/44b550d88b267320459d518c0743a241ab2108fa",
                "https://git.kernel.org/stable/c/46662f7dc59475995609bf3e9d27eb36f4acf26f",
                "https://git.kernel.org/stable/c/e9aefdc5c53fe9aed108c14e3d155710a1bb14c9",
                "https://github.com/NebuSec/CyberMeowfia/tree/main/security-research/Linux-CVE-2026-43502-openSUSE-6.4.0-150600"
            ],
            "timeline": [
                {
                    "at": "2026-05-21T13:16:19.520",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43502"
                }
            ]
        },
        {
            "id": "CVE-2026-43501",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: rpl: reserve mac_len headroom when recompressed SRH grows\n\nipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps\nthe next segment into ipv6_hdr->daddr, recompresses, then pulls the old\nheader and pushes the new one plus the IPv6 header back.  The\nrecompressed header can be larger than the received one when the swap\nreduces the common-prefix length the segments share with daddr (CmprI=0,\nCmprE>0, seg[0][0] != daddr[0] gives the maximum +8 bytes).\n\npskb_expand_head() was gated on segments_left == 0, so on earlier\nsegments the push consumed unchecked headroom.  Once skb_push() leaves\nfewer than skb->mac_len bytes in front of data,\nskb_mac_header_rebuild()'s call to:\n\n\tskb_set_mac_header(skb, -skb->mac_len);\n\nwill store (data - head) - mac_len into the u16 mac_header field, which\nwraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB\npast skb->head.\n\nA single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two\nsegment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one\npass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv.\n\nFix this by expanding the head whenever the remaining room is less than\nthe push size plus mac_len, and request that much extra so the rebuilt\nMAC header fits afterwards.",
            "updated_at": "2026-09-08T09:18:05.747",
            "published_at": "2026-05-21T13:16:19.410",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3 through before bde199c72d319a4e207f88daabc888317504e2fb (git); 8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3 through before be1fa0aa9b4fdd5a8b7a61ba520a690a68391e6e (git); 8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3 through before 0a9e8053f1f8a8e1bfc1dd61ffe67be6c1180402 (git); 8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3 through before 8e8be63465a5e80394c70324603dfea1bfdad48f (git); 8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3 through before 4babc2d9fda2df43823b85d08a0180b68f1b0854 (git); 8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3 through before c261d07a80576dc8ccf394ef8f074f8c67a06b37 (git); 8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3 through before 7398ebefbfd4f8a31d4f665a4213302fa995494b (git); 8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3 through before 9e6bf146b55999a095bb14f73a843942456d1adc (git); 5.7; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 19,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: rpl: reserve mac_len headroom when recompressed SRH grows\n\nipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps\nthe next segment into ipv6_hdr->daddr, recompresses, then pulls the old\nheader and pushes the new one plus the IPv6 header back.  The\nrecompressed header can be larger than the received one when the swap\nreduces the common-prefix length the segments share with daddr (CmprI=0,\nCmprE>0, seg[0][0] != daddr[0] gives the maximum +8 bytes).\n\npskb_expand_head() was gated on segments_left == 0, so on earlier\nsegments the push consumed unchecked headroom.  Once skb_push() leaves\nfewer than skb->mac_len bytes in front of data,\nskb_mac_header_rebuild()'s call to:\n\n\tskb_set_mac_header(skb, -skb->mac_len);\n\nwill store (data - head) - mac_len into the u16 mac_header field, which\nwraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB\npast skb->head.\n\nA single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two\nsegment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one\npass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv.\n\nFix this by expanding the head whenever the remaining room is less than\nthe push size plus mac_len, and request that much extra so the rebuilt\nMAC header fits afterwards.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0a9e8053f1f8a8e1bfc1dd61ffe67be6c1180402",
                "https://git.kernel.org/stable/c/4babc2d9fda2df43823b85d08a0180b68f1b0854",
                "https://git.kernel.org/stable/c/7398ebefbfd4f8a31d4f665a4213302fa995494b",
                "https://git.kernel.org/stable/c/8e8be63465a5e80394c70324603dfea1bfdad48f",
                "https://git.kernel.org/stable/c/9e6bf146b55999a095bb14f73a843942456d1adc",
                "https://git.kernel.org/stable/c/bde199c72d319a4e207f88daabc888317504e2fb",
                "https://git.kernel.org/stable/c/be1fa0aa9b4fdd5a8b7a61ba520a690a68391e6e",
                "https://git.kernel.org/stable/c/c261d07a80576dc8ccf394ef8f074f8c67a06b37",
                "https://access.redhat.com/errata/RHSA-2026:25191",
                "https://access.redhat.com/errata/RHSA-2026:25217",
                "https://access.redhat.com/errata/RHSA-2026:27713",
                "https://access.redhat.com/errata/RHSA-2026:27731",
                "https://access.redhat.com/errata/RHSA-2026:33900",
                "https://access.redhat.com/errata/RHSA-2026:34094",
                "https://access.redhat.com/errata/RHSA-2026:34095",
                "https://access.redhat.com/security/cve/CVE-2026-43501",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2480457",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43501.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-21T13:16:19.410",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43501"
                }
            ]
        },
        {
            "id": "CVE-2026-43499",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Use waiter::task instead of current in remove_waiter()\n\nremove_waiter() is used by the slowlock paths, but it is also used for\nproxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from\nfutex_requeue().\n\nIn the latter case waiter::task is not current, but remove_waiter()\noperates on current for the dequeue operation. That results in several\nproblems:\n\n  1) the rbtree dequeue happens without waiter::task::pi_lock being held\n\n  2) the waiter task's pi_blocked_on state is not cleared, which leaves a\n     dangling pointer primed for UAF around.\n\n  3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter\n     task\n\nUse waiter::task instead of current in all related operations in\nremove_waiter() to cure those problems.\n\n[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the\n  \tchangelog ]",
            "updated_at": "2026-09-08T09:18:05.213",
            "published_at": "2026-05-21T13:16:19.300",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8161239a8bcce9ad6b537c04a1fa3b5c68bae693 through before f3fa3424bceb128d2be4b3745506b22844b87db7 (git); 8161239a8bcce9ad6b537c04a1fa3b5c68bae693 through before 838ce5cb5d93c3ab8b27e75bc6ad905a94b752fd (git); 8161239a8bcce9ad6b537c04a1fa3b5c68bae693 through before d8cce4773c2b23d819baf5abedc62f7b430e8745 (git); 8161239a8bcce9ad6b537c04a1fa3b5c68bae693 through before 8a1fc8d698ac5e5916e3082a0f74450d71f9611f (git); 8161239a8bcce9ad6b537c04a1fa3b5c68bae693 through before 6d52dfcb2a5db86e346cf51f8fcf2071b8085166 (git); 8161239a8bcce9ad6b537c04a1fa3b5c68bae693 through before 3fb7394a837740770f0d6b4b30567e60786a63f2 (git); 8161239a8bcce9ad6b537c04a1fa3b5c68bae693 through before 88614876370aac8ad1050ad785a4c095ba17ac11 (git); 8161239a8bcce9ad6b537c04a1fa3b5c68bae693 through before 3bfdc63936dd4773109b7b8c280c0f3b5ae7d349 (git); 2.6.39; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1010,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Use waiter::task instead of current in remove_waiter()\n\nremove_waiter() is used by the slowlock paths, but it is also used for\nproxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from\nfutex_requeue().\n\nIn the latter case waiter::task is not current, but remove_waiter()\noperates on current for the dequeue operation. That results in several\nproblems:\n\n  1) the rbtree dequeue happens without waiter::task::pi_lock being held\n\n  2) the waiter task's pi_blocked_on state is not cleared, which leaves a\n     dangling pointer primed for UAF around.\n\n  3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter\n     task\n\nUse waiter::task instead of current in all related operations in\nremove_waiter() to cure those problems.\n\n[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the\n  \tchangelog ]",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · BuSung-dev/Root-My-Galaxy",
                    "author": "BuSung-dev",
                    "first_seen": "2026-07-17",
                    "last_seen": "2026-08-26T13:14:51Z",
                    "pushed_at": "2026-08-24T07:49:18Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Kotlin",
                    "stars": 925,
                    "forks": 185,
                    "topics": [],
                    "title": "KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499",
                    "repository_description": "KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499",
                    "summary": "KSU installer for supported Samsung Galaxy firmware with CVE-2026-43499",
                    "source": "CVE-Intel",
                    "url": "https://github.com/BuSung-dev/Root-My-Galaxy",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Use waiter::task instead of current in remove_waiter()\n\nremove_waiter() is used by the slowlock paths, but it is also used for\nproxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from\nfutex_requeue().\n\nIn the latter case waiter::task is not current, but remove_waiter()\noperates on current for the dequeue operation. That results in several\nproblems:\n\n  1) the rbtree dequeue happens without waiter::task::pi_lock being held\n\n  2) the waiter task's pi_blocked_on state is not cleared, which leaves a\n     dangling pointer primed for UAF around.\n\n  3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter\n     task\n\nUse waiter::task instead of current in all related operations in\nremove_waiter() to cure those problems.\n\n[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the\n  \tchangelog ]",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00768,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-05-21",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "CVE-Intel · rsyzee/ghostlock-infinix-hot70",
                    "author": "rsyzee",
                    "first_seen": "2026-08-26",
                    "last_seen": "2026-08-26T13:02:43Z",
                    "pushed_at": "2026-08-26T13:02:43Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "PoC",
                    "language": "",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.",
                    "repository_description": "Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.",
                    "summary": "Proof-of-concept kernel exploit for GhostLock (CVE-2026-43499) on the Infinix Hot 70.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/rsyzee/ghostlock-infinix-hot70",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Use waiter::task instead of current in remove_waiter()\n\nremove_waiter() is used by the slowlock paths, but it is also used for\nproxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from\nfutex_requeue().\n\nIn the latter case waiter::task is not current, but remove_waiter()\noperates on current for the dequeue operation. That results in several\nproblems:\n\n  1) the rbtree dequeue happens without waiter::task::pi_lock being held\n\n  2) the waiter task's pi_blocked_on state is not cleared, which leaves a\n     dangling pointer primed for UAF around.\n\n  3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter\n     task\n\nUse waiter::task instead of current in all related operations in\nremove_waiter() to cure those problems.\n\n[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the\n  \tchangelog ]",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00768,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-05-21",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "CVE-Intel · JoinChang/ghostlock-oneplus",
                    "author": "JoinChang",
                    "first_seen": "2026-07-12",
                    "last_seen": "2026-08-26T12:47:07Z",
                    "pushed_at": "2026-08-21T19:19:03Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "C",
                    "stars": 284,
                    "forks": 60,
                    "topics": [
                        "android",
                        "coloros",
                        "ghostlock",
                        "kernelsu",
                        "oneplus",
                        "root"
                    ],
                    "title": "GhostLock (CVE-2026-43499) kernel exploit for OnePlus devices with locked bootloader",
                    "repository_description": "GhostLock (CVE-2026-43499) kernel exploit for OnePlus devices with locked bootloader",
                    "summary": "GhostLock (CVE-2026-43499) kernel exploit for OnePlus devices with locked bootloader",
                    "source": "CVE-Intel",
                    "url": "https://github.com/JoinChang/ghostlock-oneplus",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Use waiter::task instead of current in remove_waiter()\n\nremove_waiter() is used by the slowlock paths, but it is also used for\nproxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from\nfutex_requeue().\n\nIn the latter case waiter::task is not current, but remove_waiter()\noperates on current for the dequeue operation. That results in several\nproblems:\n\n  1) the rbtree dequeue happens without waiter::task::pi_lock being held\n\n  2) the waiter task's pi_blocked_on state is not cleared, which leaves a\n     dangling pointer primed for UAF around.\n\n  3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter\n     task\n\nUse waiter::task instead of current in all related operations in\nremove_waiter() to cure those problems.\n\n[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the\n  \tchangelog ]",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00768,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-05-21",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "CVE-Intel · alex193a/Root-My-Pixel",
                    "author": "alex193a",
                    "first_seen": "2026-08-02",
                    "last_seen": "2026-08-26T11:33:49Z",
                    "pushed_at": "2026-08-24T18:11:05Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Kotlin",
                    "stars": 217,
                    "forks": 44,
                    "topics": [
                        "cve",
                        "exploit",
                        "google",
                        "jailbreak",
                        "pixel",
                        "root"
                    ],
                    "title": "Jailbreak supported Google Pixel phones with CVE-2026-43499",
                    "repository_description": "Jailbreak supported Google Pixel phones with CVE-2026-43499",
                    "summary": "Jailbreak supported Google Pixel phones with CVE-2026-43499",
                    "source": "CVE-Intel",
                    "url": "https://github.com/alex193a/Root-My-Pixel",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Use waiter::task instead of current in remove_waiter()\n\nremove_waiter() is used by the slowlock paths, but it is also used for\nproxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from\nfutex_requeue().\n\nIn the latter case waiter::task is not current, but remove_waiter()\noperates on current for the dequeue operation. That results in several\nproblems:\n\n  1) the rbtree dequeue happens without waiter::task::pi_lock being held\n\n  2) the waiter task's pi_blocked_on state is not cleared, which leaves a\n     dangling pointer primed for UAF around.\n\n  3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter\n     task\n\nUse waiter::task instead of current in all related operations in\nremove_waiter() to cure those problems.\n\n[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the\n  \tchangelog ]",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00768,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-05-21",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "CVE-Intel · yakidango-official/GhostLock-H80GT",
                    "author": "yakidango-official",
                    "first_seen": "2026-08-23",
                    "last_seen": "2026-08-26T09:36:40Z",
                    "pushed_at": "2026-08-26T09:35:33Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "LPE",
                    "language": "C",
                    "stars": 3,
                    "forks": 3,
                    "topics": [],
                    "title": "Honor 80 GT privilege escalation PoC: GhostLock (CVE-2026-43499) + custom KernelSU module loading",
                    "repository_description": "Honor 80 GT privilege escalation PoC: GhostLock (CVE-2026-43499) + custom KernelSU module loading",
                    "summary": "Honor 80 GT privilege escalation PoC: GhostLock (CVE-2026-43499) + custom KernelSU module loading",
                    "source": "CVE-Intel",
                    "url": "https://github.com/yakidango-official/GhostLock-H80GT",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Use waiter::task instead of current in remove_waiter()\n\nremove_waiter() is used by the slowlock paths, but it is also used for\nproxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from\nfutex_requeue().\n\nIn the latter case waiter::task is not current, but remove_waiter()\noperates on current for the dequeue operation. That results in several\nproblems:\n\n  1) the rbtree dequeue happens without waiter::task::pi_lock being held\n\n  2) the waiter task's pi_blocked_on state is not cleared, which leaves a\n     dangling pointer primed for UAF around.\n\n  3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter\n     task\n\nUse waiter::task instead of current in all related operations in\nremove_waiter() to cure those problems.\n\n[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the\n  \tchangelog ]",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00768,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-05-21",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "CVE-Intel · Linuxoid-cn/CVE-2026-43499-Poc-Analysis",
                    "author": "Linuxoid-cn",
                    "first_seen": "2026-07-14",
                    "last_seen": "2026-08-26T09:35:54Z",
                    "pushed_at": "2026-07-30T11:28:07Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "C",
                    "stars": 77,
                    "forks": 24,
                    "topics": [],
                    "title": "Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.",
                    "repository_description": "Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.",
                    "summary": "Vulnerability analysis and Proof of Concept (PoC) for CVE-2026-43499 affecting Xiaomi devices. For educational and research purposes only.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Linuxoid-cn/CVE-2026-43499-Poc-Analysis",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Use waiter::task instead of current in remove_waiter()\n\nremove_waiter() is used by the slowlock paths, but it is also used for\nproxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from\nfutex_requeue().\n\nIn the latter case waiter::task is not current, but remove_waiter()\noperates on current for the dequeue operation. That results in several\nproblems:\n\n  1) the rbtree dequeue happens without waiter::task::pi_lock being held\n\n  2) the waiter task's pi_blocked_on state is not cleared, which leaves a\n     dangling pointer primed for UAF around.\n\n  3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter\n     task\n\nUse waiter::task instead of current in all related operations in\nremove_waiter() to cure those problems.\n\n[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the\n  \tchangelog ]",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00768,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-05-21",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "CVE-Intel · CakesTwix/Android-CVE-2026-43499",
                    "author": "CakesTwix",
                    "first_seen": "2026-07-13",
                    "last_seen": "2026-08-26T09:35:03Z",
                    "pushed_at": "2026-07-20T07:22:42Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Kotlin",
                    "stars": 59,
                    "forks": 8,
                    "topics": [],
                    "title": "Android version CVE-2026-43499 tester",
                    "repository_description": "Android version CVE-2026-43499 tester",
                    "summary": "Android version CVE-2026-43499 tester",
                    "source": "CVE-Intel",
                    "url": "https://github.com/CakesTwix/Android-CVE-2026-43499",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Use waiter::task instead of current in remove_waiter()\n\nremove_waiter() is used by the slowlock paths, but it is also used for\nproxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from\nfutex_requeue().\n\nIn the latter case waiter::task is not current, but remove_waiter()\noperates on current for the dequeue operation. That results in several\nproblems:\n\n  1) the rbtree dequeue happens without waiter::task::pi_lock being held\n\n  2) the waiter task's pi_blocked_on state is not cleared, which leaves a\n     dangling pointer primed for UAF around.\n\n  3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter\n     task\n\nUse waiter::task instead of current in all related operations in\nremove_waiter() to cure those problems.\n\n[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the\n  \tchangelog ]",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00768,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-05-21",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "CVE-Intel · JingMatrix/pixel-ksu-root",
                    "author": "JingMatrix",
                    "first_seen": "2026-08-25",
                    "last_seen": "2026-08-26T05:30:50Z",
                    "pushed_at": "2026-08-25T12:38:48Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "C",
                    "stars": 8,
                    "forks": 2,
                    "topics": [],
                    "title": "adb-driven KernelSU loader for stock Google Pixel: temporary kernel R/W via CVE-2026-43499 (GhostLock), then late-loads a signature-matched kernelsu.ko for the running KMI. Manager-agnostic.",
                    "repository_description": "adb-driven KernelSU loader for stock Google Pixel: temporary kernel R/W via CVE-2026-43499 (GhostLock), then late-loads a signature-matched kernelsu.ko for the running KMI. Manager-agnostic.",
                    "summary": "adb-driven KernelSU loader for stock Google Pixel: temporary kernel R/W via CVE-2026-43499 (GhostLock), then late-loads a signature-matched kernelsu.ko for the running KMI. Manager-agnostic.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/JingMatrix/pixel-ksu-root",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtmutex: Use waiter::task instead of current in remove_waiter()\n\nremove_waiter() is used by the slowlock paths, but it is also used for\nproxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from\nfutex_requeue().\n\nIn the latter case waiter::task is not current, but remove_waiter()\noperates on current for the dequeue operation. That results in several\nproblems:\n\n  1) the rbtree dequeue happens without waiter::task::pi_lock being held\n\n  2) the waiter task's pi_blocked_on state is not cleared, which leaves a\n     dangling pointer primed for UAF around.\n\n  3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter\n     task\n\nUse waiter::task instead of current in all related operations in\nremove_waiter() to cure those problems.\n\n[ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the\n  \tchangelog ]",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "kev": false,
                    "epss": 0.00768,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-05-21",
                    "cve_status": "Awaiting Analysis"
                },
                {
                    "repository": "NanoTurtle1145/root-my-s24",
                    "author": "NanoTurtle1145",
                    "first_seen": "2026-08-16",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 36,
                    "title": "Using CVE-2026-43499 to root your Galaxy S24 Series(SM-S92X0 ,(China / Hong Kong SAR / Taiwan))",
                    "summary": "Using CVE-2026-43499 to root your Galaxy S24 Series(SM-S92X0 ,(China / Hong Kong SAR / Taiwan))",
                    "url": "https://github.com/NanoTurtle1145/root-my-s24"
                },
                {
                    "repository": "YuKongA/ghostlock-app",
                    "author": "YuKongA",
                    "first_seen": "2026-07-29",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 728,
                    "title": "GhostLock One-Tap Execution App (CVE-2026-43499)",
                    "summary": "GhostLock One-Tap Execution App (CVE-2026-43499)",
                    "url": "https://github.com/YuKongA/ghostlock-app"
                },
                {
                    "repository": "sarabpal-dev/IonStack-S22U",
                    "author": "sarabpal-dev",
                    "first_seen": "2026-08-08",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 65,
                    "title": "CVE-2026-43499 full exploit chain for Samsung Galaxy S22 Ultra (Android 5.10 kernel)",
                    "summary": "CVE-2026-43499 full exploit chain for Samsung Galaxy S22 Ultra (Android 5.10 kernel)",
                    "url": "https://github.com/sarabpal-dev/IonStack-S22U"
                },
                {
                    "repository": "Cxyofficial/K50G-POCOF4GT-CVE-2026-43499-PoC",
                    "author": "Cxyofficial",
                    "first_seen": "2026-09-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-43499 repository",
                    "summary": "",
                    "url": "https://github.com/Cxyofficial/K50G-POCOF4GT-CVE-2026-43499-PoC"
                },
                {
                    "repository": "lkeld/CVE-2026-43499-poc",
                    "author": "lkeld",
                    "first_seen": "2026-09-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 2,
                    "title": "CVE-2026-43499 repository",
                    "summary": "",
                    "url": "https://github.com/lkeld/CVE-2026-43499-poc"
                },
                {
                    "repository": "ankitrawatgit/iQOO-Z9_5G-vivo-T3_5G-Root-GhostLock",
                    "author": "ankitrawatgit",
                    "first_seen": "2026-08-22",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 8,
                    "title": "An iQOO Z9 5G and vivo T3 5G jailbreak/root CVE-2026-43499 Android application and payloads. Both devices use the MediaTek Dimensity 7200 (MT6886) platform. Kernel version 5.15.178.",
                    "summary": "An iQOO Z9 5G and vivo T3 5G jailbreak/root CVE-2026-43499 Android application and payloads. Both devices use the MediaTek Dimensity 7200 (MT6886) platform. Kernel version 5.15.178.",
                    "url": "https://github.com/ankitrawatgit/iQOO-Z9_5G-vivo-T3_5G-Root-GhostLock"
                },
                {
                    "repository": "zzzxxxxxxxxxx/GhostLock-GOT-W29",
                    "author": "zzzxxxxxxxxxx",
                    "first_seen": "2026-08-10",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2026-43499 (GhostLock) research on HUAWEI MatePad Pro 11 GOT-W29",
                    "summary": "CVE-2026-43499 (GhostLock) research on HUAWEI MatePad Pro 11 GOT-W29",
                    "url": "https://github.com/zzzxxxxxxxxxx/GhostLock-GOT-W29"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-06T20:35:26+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "GhostLock-for-OnePlus15T exploit",
                    "summary": "Exploit for CVE-2026-43499. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CUTEAPLANE-GHOSTLOCK-FOR-ONEPLUS15T"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-08T14:32:22+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2026-43499 exploit",
                    "summary": "Exploit for CVE-2026-43499. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CASPY123-CVE-2026-43499"
                },
                {
                    "title": "Exploit for Use After Free in Arm Bifrost_Gpu_Kernel_Driver CVE-2022-38181 CVE-2026-43499",
                    "summary": "Use After Free in Arm Bifrost kbase JIT driver (CVE-2022-38181) enabling kernel root exploit.",
                    "what_happened": "Use After Free in Arm Bifrost kbase JIT driver (CVE-2022-38181) enabling kernel root exploit.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=B7F4C122-DCF4-5F88-B125-FCF4479408A9",
                        "https://github.com/artur9010/amazon-mustang-hack"
                    ],
                    "repository": "Sploitus",
                    "author": "artur9010",
                    "first_seen": "2026-09-11T21:05:23",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B7F4C122-DCF4-5F88-B125-FCF4479408A9"
                },
                {
                    "title": "Exploit for Use After Free in Arm Bifrost_Gpu_Kernel_Driver CVE-2022-38181 CVE-2026-43499",
                    "summary": "Use After Free in Arm Bifrost kbase JIT driver (CVE-2022-38181) enabling kernel root exploit.",
                    "what_happened": "Use After Free in Arm Bifrost kbase JIT driver (CVE-2022-38181) enabling kernel root exploit.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=B7F4C122-DCF4-5F88-B125-FCF4479408A9",
                        "https://github.com/artur9010/amazon-mustang-hack"
                    ],
                    "repository": "artur9010/amazon-mustang-hack",
                    "author": "artur9010",
                    "first_seen": "2026-09-11T21:05:23",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/artur9010/amazon-mustang-hack"
                },
                {
                    "title": "Exploit for Use After Free in Linux Linux_Kernel CVE-2026-43499",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=245B0070-8347-5D2E-B2C4-A13F7A33572C",
                        "https://github.com/MuhamadRifkii/CVE-2026-43499-POCO-X3-GT"
                    ],
                    "repository": "Sploitus",
                    "author": "MuhamadRifkii",
                    "first_seen": "2026-09-12T08:12:03",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=245B0070-8347-5D2E-B2C4-A13F7A33572C"
                },
                {
                    "title": "Exploit for Use After Free in Linux Linux_Kernel CVE-2026-43499",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=245B0070-8347-5D2E-B2C4-A13F7A33572C",
                        "https://github.com/MuhamadRifkii/CVE-2026-43499-POCO-X3-GT"
                    ],
                    "repository": "MuhamadRifkii/CVE-2026-43499-POCO-X3-GT",
                    "author": "MuhamadRifkii",
                    "first_seen": "2026-09-12T08:12:03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://github.com/MuhamadRifkii/CVE-2026-43499-POCO-X3-GT"
                },
                {
                    "title": "Exploit for sh53d-temp-root CVE-2026-43499",
                    "summary": "Temporary root PoC for SHARP AQUOS wish3 SH-53D via GhostLock (CVE-2026-43499) on Android 13.",
                    "what_happened": "Temporary root PoC for SHARP AQUOS wish3 SH-53D via GhostLock (CVE-2026-43499) on Android 13.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=281E6083-AD47-5D4A-B3F4-414DD4312101",
                        "https://github.com/mouseos/sh53d-temp-root"
                    ],
                    "repository": "Sploitus",
                    "author": "mouseos",
                    "first_seen": "2026-09-12T12:09:42",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=281E6083-AD47-5D4A-B3F4-414DD4312101"
                },
                {
                    "title": "Exploit for Use After Free in Linux Linux_Kernel CVE-2026-43499",
                    "summary": "Use After Free in Linux Kernel enabling local privilege escalation with embedded KernelSU.",
                    "what_happened": "Use After Free in Linux Kernel enabling local privilege escalation with embedded KernelSU.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=B3C0FF23-3715-5ADF-BFF4-021FD2591410",
                        "https://github.com/huaguiqi/asus_i005-CVE-2026-43499"
                    ],
                    "repository": "Sploitus",
                    "author": "huaguiqi",
                    "first_seen": "2026-09-12T12:49:03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B3C0FF23-3715-5ADF-BFF4-021FD2591410"
                },
                {
                    "title": "Exploit for sh53d-temp-root CVE-2026-43499",
                    "summary": "Temporary root PoC for SHARP AQUOS wish3 SH-53D via GhostLock (CVE-2026-43499) on Android 13.",
                    "what_happened": "Temporary root PoC for SHARP AQUOS wish3 SH-53D via GhostLock (CVE-2026-43499) on Android 13.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=281E6083-AD47-5D4A-B3F4-414DD4312101",
                        "https://github.com/mouseos/sh53d-temp-root"
                    ],
                    "repository": "mouseos/sh53d-temp-root",
                    "author": "mouseos",
                    "first_seen": "2026-09-12T12:09:42",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/mouseos/sh53d-temp-root"
                },
                {
                    "title": "Exploit for Use After Free in Linux Linux_Kernel CVE-2026-43499",
                    "summary": "Use After Free in Linux Kernel enabling local privilege escalation with embedded KernelSU.",
                    "what_happened": "Use After Free in Linux Kernel enabling local privilege escalation with embedded KernelSU.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=B3C0FF23-3715-5ADF-BFF4-021FD2591410",
                        "https://github.com/huaguiqi/asus_i005-CVE-2026-43499"
                    ],
                    "repository": "huaguiqi/asus_i005-CVE-2026-43499",
                    "author": "huaguiqi",
                    "first_seen": "2026-09-12T12:49:03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/huaguiqi/asus_i005-CVE-2026-43499"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T15:06:45+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "asus_i005-CVE-2026-43499 exploit",
                    "summary": "Exploit for CVE-2026-43499. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HUAGUIQI-ASUS_I005-CVE-2026-43499"
                },
                {
                    "title": "Exploit for Root-My-Device-Payloads CVE-2026-43499",
                    "summary": "Root-My-Device-Payloads: kernel exploit payloads for rooting specific MediaTek Android devices.",
                    "what_happened": "Root-My-Device-Payloads: kernel exploit payloads for rooting specific MediaTek Android devices.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=48CE8948-1467-5A73-8444-58A038C91C7C",
                        "https://github.com/Dimonchik225820/Root-My-Device-Payloads"
                    ],
                    "repository": "Sploitus",
                    "author": "Dimonchik225820",
                    "first_seen": "2026-09-13T14:00:44",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=48CE8948-1467-5A73-8444-58A038C91C7C"
                },
                {
                    "title": "Exploit for Root-My-Device-Payloads CVE-2026-43499",
                    "summary": "Root-My-Device-Payloads: kernel exploit payloads for rooting specific MediaTek Android devices.",
                    "what_happened": "Root-My-Device-Payloads: kernel exploit payloads for rooting specific MediaTek Android devices.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=48CE8948-1467-5A73-8444-58A038C91C7C",
                        "https://github.com/Dimonchik225820/Root-My-Device-Payloads"
                    ],
                    "repository": "Dimonchik225820/Root-My-Device-Payloads",
                    "author": "Dimonchik225820",
                    "first_seen": "2026-09-13T14:00:44",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/Dimonchik225820/Root-My-Device-Payloads"
                },
                {
                    "title": "Exploit for Use After Free in Linux Linux_Kernel CVE-2026-43499",
                    "summary": "Use-after-free in Qualcomm 4.19 kernel rtmutex remove_waiter() enabling local privilege escalation.",
                    "what_happened": "Use-after-free in Qualcomm 4.19 kernel rtmutex remove_waiter() enabling local privilege escalation.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-416",
                    "references": [
                        "https://sploitus.com/exploit?id=91EA059D-A324-5C1F-B26D-A8D9C38120C9",
                        "https://github.com/ccp-p/ghostlock-cve-2026-43499-4.19-k40"
                    ],
                    "repository": "Sploitus",
                    "author": "ccp-p",
                    "first_seen": "2026-09-13T23:50:31",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=91EA059D-A324-5C1F-B26D-A8D9C38120C9"
                },
                {
                    "title": "Exploit for Use After Free in Linux Linux_Kernel CVE-2026-43499",
                    "summary": "Use-after-free in Qualcomm 4.19 kernel rtmutex remove_waiter() enabling local privilege escalation.",
                    "what_happened": "Use-after-free in Qualcomm 4.19 kernel rtmutex remove_waiter() enabling local privilege escalation.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-416",
                    "references": [
                        "https://sploitus.com/exploit?id=91EA059D-A324-5C1F-B26D-A8D9C38120C9",
                        "https://github.com/ccp-p/ghostlock-cve-2026-43499-4.19-k40"
                    ],
                    "repository": "ccp-p/ghostlock-cve-2026-43499-4.19-k40",
                    "author": "ccp-p",
                    "first_seen": "2026-09-13T23:50:31",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ccp-p/ghostlock-cve-2026-43499-4.19-k40"
                },
                {
                    "title": "Exploit for Use After Free in Linux Linux_Kernel CVE-2026-43499",
                    "summary": "Use-after-free in Linux kernel futex PI (CVE-2026-43499) enables root on Chromecast with Google TV.",
                    "what_happened": "Use-after-free in Linux kernel futex PI (CVE-2026-43499) enables root on Chromecast with Google TV.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=A2311EA3-DFB8-5EE4-BA16-80ECE38AB833",
                        "https://github.com/k-o-n-t-o-r/ghostlock-sabrina"
                    ],
                    "repository": "Sploitus",
                    "author": "k-o-n-t-o-r",
                    "first_seen": "2026-09-14T20:16:21",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=A2311EA3-DFB8-5EE4-BA16-80ECE38AB833"
                },
                {
                    "title": "Exploit for Use After Free in Linux Linux_Kernel CVE-2026-43499",
                    "summary": "Use-after-free in Linux kernel futex PI (CVE-2026-43499) enables root on Chromecast with Google TV.",
                    "what_happened": "Use-after-free in Linux kernel futex PI (CVE-2026-43499) enables root on Chromecast with Google TV.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=A2311EA3-DFB8-5EE4-BA16-80ECE38AB833",
                        "https://github.com/k-o-n-t-o-r/ghostlock-sabrina"
                    ],
                    "repository": "k-o-n-t-o-r/ghostlock-sabrina",
                    "author": "k-o-n-t-o-r",
                    "first_seen": "2026-09-14T20:16:21",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/k-o-n-t-o-r/ghostlock-sabrina"
                },
                {
                    "title": "Exploit for Use After Free in Linux Linux_Kernel CVE-2026-43499",
                    "summary": "Use After Free in Linux kernel 5.4.61 on Sharp AQUOS R6 enabling root via ADB.",
                    "what_happened": "Use After Free in Linux kernel 5.4.61 on Sharp AQUOS R6 enabling root via ADB.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=65ABE089-2201-563D-90C3-03040E87E4B0",
                        "https://github.com/mouseos/aquos-r6-ghostlock"
                    ],
                    "repository": "Sploitus",
                    "author": "mouseos",
                    "first_seen": "2026-09-14T23:25:42",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=65ABE089-2201-563D-90C3-03040E87E4B0"
                },
                {
                    "title": "Exploit for Use After Free in Linux Linux_Kernel CVE-2026-43499",
                    "summary": "Use After Free in Linux kernel 5.4.61 on Sharp AQUOS R6 enabling root via ADB.",
                    "what_happened": "Use After Free in Linux kernel 5.4.61 on Sharp AQUOS R6 enabling root via ADB.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=65ABE089-2201-563D-90C3-03040E87E4B0",
                        "https://github.com/mouseos/aquos-r6-ghostlock"
                    ],
                    "repository": "mouseos/aquos-r6-ghostlock",
                    "author": "mouseos",
                    "first_seen": "2026-09-14T23:25:42",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://github.com/mouseos/aquos-r6-ghostlock"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-15T10:57:09+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Root-My-Device exploit",
                    "summary": "Exploit for CVE-2026-43499. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WITAQUA-TOOLS-ROOT-MY-DEVICE"
                }
            ],
            "references": [
                "https://github.com/BuSung-dev/Root-My-Galaxy",
                "https://github.com/rsyzee/ghostlock-infinix-hot70",
                "https://github.com/JoinChang/ghostlock-oneplus",
                "https://github.com/alex193a/Root-My-Pixel",
                "https://github.com/yakidango-official/GhostLock-H80GT",
                "https://github.com/Linuxoid-cn/CVE-2026-43499-Poc-Analysis",
                "https://github.com/CakesTwix/Android-CVE-2026-43499",
                "https://github.com/JingMatrix/pixel-ksu-root",
                "https://github.com/NanoTurtle1145/root-my-s24",
                "https://github.com/YuKongA/ghostlock-app",
                "https://github.com/sarabpal-dev/IonStack-S22U",
                "https://github.com/Cxyofficial/K50G-POCOF4GT-CVE-2026-43499-PoC",
                "https://github.com/lkeld/CVE-2026-43499-poc",
                "https://github.com/ankitrawatgit/iQOO-Z9_5G-vivo-T3_5G-Root-GhostLock",
                "https://github.com/zzzxxxxxxxxxx/GhostLock-GOT-W29",
                "https://git.kernel.org/stable/c/3bfdc63936dd4773109b7b8c280c0f3b5ae7d349",
                "https://git.kernel.org/stable/c/3fb7394a837740770f0d6b4b30567e60786a63f2",
                "https://git.kernel.org/stable/c/6d52dfcb2a5db86e346cf51f8fcf2071b8085166",
                "https://git.kernel.org/stable/c/838ce5cb5d93c3ab8b27e75bc6ad905a94b752fd",
                "https://git.kernel.org/stable/c/88614876370aac8ad1050ad785a4c095ba17ac11",
                "https://git.kernel.org/stable/c/8a1fc8d698ac5e5916e3082a0f74450d71f9611f",
                "https://git.kernel.org/stable/c/d8cce4773c2b23d819baf5abedc62f7b430e8745",
                "https://git.kernel.org/stable/c/f3fa3424bceb128d2be4b3745506b22844b87db7",
                "http://www.openwall.com/lists/oss-security/2026/07/08/12",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CUTEAPLANE-GHOSTLOCK-FOR-ONEPLUS15T",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CASPY123-CVE-2026-43499",
                "https://sploitus.com/exploit?id=B7F4C122-DCF4-5F88-B125-FCF4479408A9",
                "https://github.com/artur9010/amazon-mustang-hack",
                "https://sploitus.com/exploit?id=245B0070-8347-5D2E-B2C4-A13F7A33572C",
                "https://github.com/MuhamadRifkii/CVE-2026-43499-POCO-X3-GT",
                "https://sploitus.com/exploit?id=281E6083-AD47-5D4A-B3F4-414DD4312101",
                "https://github.com/mouseos/sh53d-temp-root",
                "https://sploitus.com/exploit?id=B3C0FF23-3715-5ADF-BFF4-021FD2591410",
                "https://github.com/huaguiqi/asus_i005-CVE-2026-43499",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HUAGUIQI-ASUS_I005-CVE-2026-43499",
                "https://sploitus.com/exploit?id=48CE8948-1467-5A73-8444-58A038C91C7C",
                "https://github.com/Dimonchik225820/Root-My-Device-Payloads",
                "https://sploitus.com/exploit?id=91EA059D-A324-5C1F-B26D-A8D9C38120C9",
                "https://github.com/ccp-p/ghostlock-cve-2026-43499-4.19-k40",
                "https://sploitus.com/exploit?id=A2311EA3-DFB8-5EE4-BA16-80ECE38AB833",
                "https://github.com/k-o-n-t-o-r/ghostlock-sabrina",
                "https://sploitus.com/exploit?id=65ABE089-2201-563D-90C3-03040E87E4B0",
                "https://github.com/mouseos/aquos-r6-ghostlock",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WITAQUA-TOOLS-ROOT-MY-DEVICE"
            ],
            "timeline": [
                {
                    "at": "2026-05-21T13:16:19.300",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43499"
                }
            ],
            "severity": "HIGH",
            "epss": 0.00768,
            "metadata_source": "CNA",
            "cve_status": "Awaiting Analysis",
            "cve_published_at": "2026-05-21",
            "enrichment_checked_at": "2026-09-06T22:05:25Z"
        },
        {
            "id": "CVE-2026-43492",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nlib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()\n\nYiming reports an integer underflow in mpi_read_raw_from_sgl() when\nsubtracting \"lzeros\" from the unsigned \"nbytes\".\n\nFor this to happen, the scatterlist \"sgl\" needs to occupy more bytes\nthan the \"nbytes\" parameter and the first \"nbytes + 1\" bytes of the\nscatterlist must be zero.  Under these conditions, the while loop\niterating over the scatterlist will count more zeroes than \"nbytes\",\nsubtract the number of zeroes from \"nbytes\" and cause the underflow.\n\nWhen commit 2d4d1eea540b (\"lib/mpi: Add mpi sgl helpers\") originally\nintroduced the bug, it couldn't be triggered because all callers of\nmpi_read_raw_from_sgl() passed a scatterlist whose length was equal to\n\"nbytes\".\n\nHowever since commit 63ba4d67594a (\"KEYS: asymmetric: Use new crypto\ninterface without scatterlists\"), the underflow can now actually be\ntriggered.  When invoking a KEYCTL_PKEY_ENCRYPT system call with a\nlarger \"out_len\" than \"in_len\" and filling the \"in\" buffer with zeroes,\ncrypto_akcipher_sync_prep() will create an all-zero scatterlist used for\nboth the \"src\" and \"dst\" member of struct akcipher_request and thereby\nfulfil the conditions to trigger the bug:\n\n  sys_keyctl()\n    keyctl_pkey_e_d_s()\n      asymmetric_key_eds_op()\n        software_key_eds_op()\n          crypto_akcipher_sync_encrypt()\n            crypto_akcipher_sync_prep()\n              crypto_akcipher_encrypt()\n                rsa_enc()\n                  mpi_read_raw_from_sgl()\n\nTo the user this will be visible as a DoS as the kernel spins forever,\ncausing soft lockup splats as a side effect.\n\nFix it.",
            "updated_at": "2026-09-08T09:18:05.027",
            "published_at": "2026-05-19T12:16:18.880",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2d4d1eea540b27c72488fd1914674c42473d53df through before a1793a48881ec8d26e9c79b0ee65753f1c6846a4 (git); 2d4d1eea540b27c72488fd1914674c42473d53df through before 1abd50fc3cfa16fc2074a3c8c2729c50fd9d7043 (git); 2d4d1eea540b27c72488fd1914674c42473d53df through before 6d63615c796c085b4984e3031b9fa77fffb47360 (git); 2d4d1eea540b27c72488fd1914674c42473d53df through before 2aa77a18dc7f2670497fe3ee5acbeda0b57659e5 (git); 2d4d1eea540b27c72488fd1914674c42473d53df through before 26d3a97ad46c7a9226ec04d4bf35bd4998a97d16 (git); 2d4d1eea540b27c72488fd1914674c42473d53df through before 8637dfb4c1d8a7026ef681f2477c6de8b71c4003 (git); 2d4d1eea540b27c72488fd1914674c42473d53df through before 30e513e755bb381afce6fb57cdc8694136193f22 (git); 2d4d1eea540b27c72488fd1914674c42473d53df through before 8c2f1288250a90a4b5cabed5d888d7e3aeed4035 (git); 4.4; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nlib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()\n\nYiming reports an integer underflow in mpi_read_raw_from_sgl() when\nsubtracting \"lzeros\" from the unsigned \"nbytes\".\n\nFor this to happen, the scatterlist \"sgl\" needs to occupy more bytes\nthan the \"nbytes\" parameter and the first \"nbytes + 1\" bytes of the\nscatterlist must be zero.  Under these conditions, the while loop\niterating over the scatterlist will count more zeroes than \"nbytes\",\nsubtract the number of zeroes from \"nbytes\" and cause the underflow.\n\nWhen commit 2d4d1eea540b (\"lib/mpi: Add mpi sgl helpers\") originally\nintroduced the bug, it couldn't be triggered because all callers of\nmpi_read_raw_from_sgl() passed a scatterlist whose length was equal to\n\"nbytes\".\n\nHowever since commit 63ba4d67594a (\"KEYS: asymmetric: Use new crypto\ninterface without scatterlists\"), the underflow can now actually be\ntriggered.  When invoking a KEYCTL_PKEY_ENCRYPT system call with a\nlarger \"out_len\" than \"in_len\" and filling the \"in\" buffer with zeroes,\ncrypto_akcipher_sync_prep() will create an all-zero scatterlist used for\nboth the \"src\" and \"dst\" member of struct akcipher_request and thereby\nfulfil the conditions to trigger the bug:\n\n  sys_keyctl()\n    keyctl_pkey_e_d_s()\n      asymmetric_key_eds_op()\n        software_key_eds_op()\n          crypto_akcipher_sync_encrypt()\n            crypto_akcipher_sync_prep()\n              crypto_akcipher_encrypt()\n                rsa_enc()\n                  mpi_read_raw_from_sgl()\n\nTo the user this will be visible as a DoS as the kernel spins forever,\ncausing soft lockup splats as a side effect.\n\nFix it.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1abd50fc3cfa16fc2074a3c8c2729c50fd9d7043",
                "https://git.kernel.org/stable/c/26d3a97ad46c7a9226ec04d4bf35bd4998a97d16",
                "https://git.kernel.org/stable/c/2aa77a18dc7f2670497fe3ee5acbeda0b57659e5",
                "https://git.kernel.org/stable/c/30e513e755bb381afce6fb57cdc8694136193f22",
                "https://git.kernel.org/stable/c/6d63615c796c085b4984e3031b9fa77fffb47360",
                "https://git.kernel.org/stable/c/8637dfb4c1d8a7026ef681f2477c6de8b71c4003",
                "https://git.kernel.org/stable/c/8c2f1288250a90a4b5cabed5d888d7e3aeed4035",
                "https://git.kernel.org/stable/c/a1793a48881ec8d26e9c79b0ee65753f1c6846a4",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-19T12:16:18.880",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43492"
                }
            ]
        },
        {
            "id": "CVE-2026-43391",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnsfs: tighten permission checks for handle opening\n\nEven privileged services should not necessarily be able to see other\nprivileged service's namespaces so they can't leak information to each\nother. Use may_see_all_namespaces() helper that centralizes this policy\nuntil the nstree adapts.",
            "updated_at": "2026-09-07T16:17:28.400",
            "published_at": "2026-05-08T15:16:50.490",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5222470b2fbb3740f931f189db33dd1367b1ae75 through before 24ebaf6676ae4f74f4856eb645959b15e62bc1b4 (git); 5222470b2fbb3740f931f189db33dd1367b1ae75 through before 1797ee11451f1b2be69863a9f5bd43b948813fdf (git); 5222470b2fbb3740f931f189db33dd1367b1ae75 through before d2324a9317f00013facb0ba00b00440e19d2af5e (git); 6.18",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnsfs: tighten permission checks for handle opening\n\nEven privileged services should not necessarily be able to see other\nprivileged service's namespaces so they can't leak information to each\nother. Use may_see_all_namespaces() helper that centralizes this policy\nuntil the nstree adapts.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1797ee11451f1b2be69863a9f5bd43b948813fdf",
                "https://git.kernel.org/stable/c/24ebaf6676ae4f74f4856eb645959b15e62bc1b4",
                "https://git.kernel.org/stable/c/d2324a9317f00013facb0ba00b00440e19d2af5e"
            ],
            "timeline": [
                {
                    "at": "2026-05-08T15:16:50.490",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43391"
                }
            ]
        },
        {
            "id": "CVE-2026-43344",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/intel/uncore: Fix die ID init and look up bugs\n\nIn snbep_pci2phy_map_init(), in the nr_node_ids > 8 path,\nuncore_device_to_die() may return -1 when all CPUs associated\nwith the UBOX device are offline.\n\nRemove the WARN_ON_ONCE(die_id == -1) check for two reasons:\n\n- The current code breaks out of the loop. This is incorrect because\n  pci_get_device() does not guarantee iteration in domain or bus order,\n  so additional UBOX devices may be skipped during the scan.\n\n- Returning -EINVAL is incorrect, since marking offline buses with\n  die_id == -1 is expected and should not be treated as an error.\n\nSeparately, when NUMA is disabled on a NUMA-capable platform,\npcibus_to_node() returns NUMA_NO_NODE, causing uncore_device_to_die()\nto return -1 for all PCI devices.  As a result,\nspr_update_device_location(), used on Intel SPR and EMR, ignores the\ncorresponding PMON units and does not add them to the RB tree.\n\nFix this by using uncore_pcibus_to_dieid(), which retrieves topology\nfrom the UBOX GIDNIDMAP register and works regardless of whether NUMA\nis enabled in Linux.  This requires snbep_pci2phy_map_init() to be\nadded in spr_uncore_pci_init().\n\nKeep uncore_device_to_die() only for the nr_node_ids > 8 case, where\nNUMA is expected to be enabled.",
            "updated_at": "2026-09-14T12:17:41.427",
            "published_at": "2026-05-08T14:16:44.433",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9a7832ce3d920426a36cdd78eda4b3568d4d09e3 through before 184870af0e73f8ea2577c751fa098681465249f2 (git); 9a7832ce3d920426a36cdd78eda4b3568d4d09e3 through before bdb35811ff41a1678620a407056b6372f350028a (git); 9a7832ce3d920426a36cdd78eda4b3568d4d09e3 through before c79ef3342632e71ac8612a2a1cc17ac84dd258b4 (git); 9a7832ce3d920426a36cdd78eda4b3568d4d09e3 through before 6a5dc3ee97581da2907fc7acd62853f07184de67 (git); 9a7832ce3d920426a36cdd78eda4b3568d4d09e3 through before a16d1ec4dd0cdcf689f324adde6067083bce9099 (git); 5.12",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-617",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/intel/uncore: Fix die ID init and look up bugs\n\nIn snbep_pci2phy_map_init(), in the nr_node_ids > 8 path,\nuncore_device_to_die() may return -1 when all CPUs associated\nwith the UBOX device are offline.\n\nRemove the WARN_ON_ONCE(die_id == -1) check for two reasons:\n\n- The current code breaks out of the loop. This is incorrect because\n  pci_get_device() does not guarantee iteration in domain or bus order,\n  so additional UBOX devices may be skipped during the scan.\n\n- Returning -EINVAL is incorrect, since marking offline buses with\n  die_id == -1 is expected and should not be treated as an error.\n\nSeparately, when NUMA is disabled on a NUMA-capable platform,\npcibus_to_node() returns NUMA_NO_NODE, causing uncore_device_to_die()\nto return -1 for all PCI devices.  As a result,\nspr_update_device_location(), used on Intel SPR and EMR, ignores the\ncorresponding PMON units and does not add them to the RB tree.\n\nFix this by using uncore_pcibus_to_dieid(), which retrieves topology\nfrom the UBOX GIDNIDMAP register and works regardless of whether NUMA\nis enabled in Linux.  This requires snbep_pci2phy_map_init() to be\nadded in spr_uncore_pci_init().\n\nKeep uncore_device_to_die() only for the nr_node_ids > 8 case, where\nNUMA is expected to be enabled.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/6a5dc3ee97581da2907fc7acd62853f07184de67",
                "https://git.kernel.org/stable/c/a16d1ec4dd0cdcf689f324adde6067083bce9099",
                "https://git.kernel.org/stable/c/bdb35811ff41a1678620a407056b6372f350028a",
                "https://git.kernel.org/stable/c/c79ef3342632e71ac8612a2a1cc17ac84dd258b4",
                "https://git.kernel.org/stable/c/184870af0e73f8ea2577c751fa098681465249f2"
            ],
            "timeline": [
                {
                    "at": "2026-05-08T14:16:44.433",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43344"
                }
            ]
        },
        {
            "id": "CVE-2026-43329",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: strictly check for maximum number of actions\n\nThe maximum number of flowtable hardware offload actions in IPv6 is:\n\n* ethernet mangling (4 payload actions, 2 for each ethernet address)\n* SNAT (4 payload actions)\n* DNAT (4 payload actions)\n* Double VLAN (4 vlan actions, 2 for popping vlan, and 2 for pushing)\n  for QinQ.\n* Redirect (1 action)\n\nWhich makes 17, while the maximum is 16. But act_ct supports for tunnels\nactions too. Note that payload action operates at 32-bit word level, so\nmangling an IPv6 address takes 4 payload actions.\n\nUpdate flow_action_entry_next() calls to check for the maximum number of\nsupported actions.\n\nWhile at it, rise the maximum number of actions per flow from 16 to 24\nso this works fine with IPv6 setups.",
            "updated_at": "2026-09-15T12:17:48.337",
            "published_at": "2026-05-08T14:16:42.520",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c29f74e0df7a02b8303bcdce93a7c0132d62577a through before ead66c77303f760f6c30be96e2e20d5a77cef614 (git); c29f74e0df7a02b8303bcdce93a7c0132d62577a through before fe9018d3e94329f1951b00805a8640bc06f56ead (git); c29f74e0df7a02b8303bcdce93a7c0132d62577a through before 5382bb03e9c33b089d60788478b922a2dca284cc (git); c29f74e0df7a02b8303bcdce93a7c0132d62577a through before 57c78bd2e2dd08897acd35b2bf8bcef322e36f5e (git); c29f74e0df7a02b8303bcdce93a7c0132d62577a through before 504c9456699dcf4d15195ef34a0fa94a80bfc877 (git); c29f74e0df7a02b8303bcdce93a7c0132d62577a through before 879959a7a2be814dd57568655eafa3d8f4d0309e (git); c29f74e0df7a02b8303bcdce93a7c0132d62577a through before 76522fcdbc3a02b568f5d957f7e66fc194abb893 (git); 5.5",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: flowtable: strictly check for maximum number of actions\n\nThe maximum number of flowtable hardware offload actions in IPv6 is:\n\n* ethernet mangling (4 payload actions, 2 for each ethernet address)\n* SNAT (4 payload actions)\n* DNAT (4 payload actions)\n* Double VLAN (4 vlan actions, 2 for popping vlan, and 2 for pushing)\n  for QinQ.\n* Redirect (1 action)\n\nWhich makes 17, while the maximum is 16. But act_ct supports for tunnels\nactions too. Note that payload action operates at 32-bit word level, so\nmangling an IPv6 address takes 4 payload actions.\n\nUpdate flow_action_entry_next() calls to check for the maximum number of\nsupported actions.\n\nWhile at it, rise the maximum number of actions per flow from 16 to 24\nso this works fine with IPv6 setups.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/504c9456699dcf4d15195ef34a0fa94a80bfc877",
                "https://git.kernel.org/stable/c/5382bb03e9c33b089d60788478b922a2dca284cc",
                "https://git.kernel.org/stable/c/57c78bd2e2dd08897acd35b2bf8bcef322e36f5e",
                "https://git.kernel.org/stable/c/76522fcdbc3a02b568f5d957f7e66fc194abb893",
                "https://git.kernel.org/stable/c/879959a7a2be814dd57568655eafa3d8f4d0309e",
                "https://git.kernel.org/stable/c/ead66c77303f760f6c30be96e2e20d5a77cef614",
                "https://git.kernel.org/stable/c/fe9018d3e94329f1951b00805a8640bc06f56ead",
                "https://access.redhat.com/errata/RHSA-2026:23329",
                "https://access.redhat.com/errata/RHSA-2026:26427",
                "https://access.redhat.com/errata/RHSA-2026:26428",
                "https://access.redhat.com/errata/RHSA-2026:27713",
                "https://access.redhat.com/errata/RHSA-2026:30848",
                "https://access.redhat.com/errata/RHSA-2026:33215",
                "https://access.redhat.com/errata/RHSA-2026:33899",
                "https://access.redhat.com/errata/RHSA-2026:33900",
                "https://access.redhat.com/errata/RHSA-2026:34094",
                "https://access.redhat.com/errata/RHSA-2026:34095",
                "https://access.redhat.com/errata/RHSA-2026:35863",
                "https://access.redhat.com/errata/RHSA-2026:35896",
                "https://access.redhat.com/errata/RHSA-2026:40764",
                "https://access.redhat.com/errata/RHSA-2026:43252",
                "https://access.redhat.com/errata/RHSA-2026:44230",
                "https://access.redhat.com/errata/RHSA-2026:44231",
                "https://access.redhat.com/errata/RHSA-2026:44259",
                "https://access.redhat.com/errata/RHSA-2026:44262",
                "https://access.redhat.com/errata/RHSA-2026:47702",
                "https://access.redhat.com/errata/RHSA-2026:47727",
                "https://access.redhat.com/errata/RHSA-2026:54187",
                "https://access.redhat.com/errata/RHSA-2026:55618",
                "https://access.redhat.com/errata/RHSA-2026:55761",
                "https://access.redhat.com/errata/RHSA-2026:55762",
                "https://access.redhat.com/errata/RHSA-2026:55763",
                "https://access.redhat.com/errata/RHSA-2026:55837",
                "https://access.redhat.com/errata/RHSA-2026:56224",
                "https://access.redhat.com/errata/RHSA-2026:56225",
                "https://access.redhat.com/errata/RHSA-2026:56853",
                "https://access.redhat.com/errata/RHSA-2026:56911",
                "https://access.redhat.com/security/cve/CVE-2026-43329",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2468124",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43329.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-08T14:16:42.520",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43329"
                }
            ]
        },
        {
            "id": "CVE-2026-43303",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_alloc: clear page->private in free_pages_prepare()\n\nSeveral subsystems (slub, shmem, ttm, etc.) use page->private but don't\nclear it before freeing pages.  When these pages are later allocated as\nhigh-order pages and split via split_page(), tail pages retain stale\npage->private values.\n\nThis causes a use-after-free in the swap subsystem.  The swap code uses\npage->private to track swap count continuations, assuming freshly\nallocated pages have page->private == 0.  When stale values are present,\nswap_count_continued() incorrectly assumes the continuation list is valid\nand iterates over uninitialized page->lru containing LIST_POISON values,\ncausing a crash:\n\n  KASAN: maybe wild-memory-access in range [0xdead000000000100-0xdead000000000107]\n  RIP: 0010:__do_sys_swapoff+0x1151/0x1860\n\nFix this by clearing page->private in free_pages_prepare(), ensuring all\nfreed pages have clean state regardless of previous use.",
            "updated_at": "2026-09-08T09:18:04.847",
            "published_at": "2026-05-08T14:16:37.583",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3b8000ae185cb068adbda5f966a3835053c85fd4 through before e7790ab165713b79b1617ce659742ceb3a859d05 (git); 3b8000ae185cb068adbda5f966a3835053c85fd4 through before 3edb8ebbf79b9016040e8f3421d723ae3d542b32 (git); 3b8000ae185cb068adbda5f966a3835053c85fd4 through before f9719e32a67b4b00b3c9b133e8b5ffa72a26b67b (git); 3b8000ae185cb068adbda5f966a3835053c85fd4 through before 23b82b7a26182ad840ae67d390d7ec9771e8c00f (git); 3b8000ae185cb068adbda5f966a3835053c85fd4 through before d757c793853ec5483eb41ec2942c300b8fa720fb (git); 3b8000ae185cb068adbda5f966a3835053c85fd4 through before ac1ea219590c09572ed5992dc233bbf7bb70fef9 (git); 5.18; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/page_alloc: clear page->private in free_pages_prepare()\n\nSeveral subsystems (slub, shmem, ttm, etc.) use page->private but don't\nclear it before freeing pages.  When these pages are later allocated as\nhigh-order pages and split via split_page(), tail pages retain stale\npage->private values.\n\nThis causes a use-after-free in the swap subsystem.  The swap code uses\npage->private to track swap count continuations, assuming freshly\nallocated pages have page->private == 0.  When stale values are present,\nswap_count_continued() incorrectly assumes the continuation list is valid\nand iterates over uninitialized page->lru containing LIST_POISON values,\ncausing a crash:\n\n  KASAN: maybe wild-memory-access in range [0xdead000000000100-0xdead000000000107]\n  RIP: 0010:__do_sys_swapoff+0x1151/0x1860\n\nFix this by clearing page->private in free_pages_prepare(), ensuring all\nfreed pages have clean state regardless of previous use.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/23b82b7a26182ad840ae67d390d7ec9771e8c00f",
                "https://git.kernel.org/stable/c/3edb8ebbf79b9016040e8f3421d723ae3d542b32",
                "https://git.kernel.org/stable/c/ac1ea219590c09572ed5992dc233bbf7bb70fef9",
                "https://git.kernel.org/stable/c/d757c793853ec5483eb41ec2942c300b8fa720fb",
                "https://git.kernel.org/stable/c/e7790ab165713b79b1617ce659742ceb3a859d05",
                "https://git.kernel.org/stable/c/f9719e32a67b4b00b3c9b133e8b5ffa72a26b67b",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-08T14:16:37.583",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43303"
                }
            ]
        },
        {
            "id": "CVE-2026-43288",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: move ext4_percpu_param_init() before ext4_mb_init()\n\nWhen running `kvm-xfstests -c ext4/1k -C 1 generic/383` with the\n`DOUBLE_CHECK` macro defined, the following panic is triggered:\n\n==================================================================\nEXT4-fs error (device vdc): ext4_validate_block_bitmap:423:\n                        comm mount: bg 0: bad block bitmap checksum\nBUG: unable to handle page fault for address: ff110000fa2cc000\nPGD 3e01067 P4D 3e02067 PUD 0\nOops: Oops: 0000 [#1] SMP NOPTI\nCPU: 0 UID: 0 PID: 2386 Comm: mount Tainted: G W\n                        6.18.0-gba65a4e7120a-dirty #1152 PREEMPT(none)\nRIP: 0010:percpu_counter_add_batch+0x13/0xa0\nCall Trace:\n <TASK>\n ext4_mark_group_bitmap_corrupted+0xcb/0xe0\n ext4_validate_block_bitmap+0x2a1/0x2f0\n ext4_read_block_bitmap+0x33/0x50\n mb_group_bb_bitmap_alloc+0x33/0x80\n ext4_mb_add_groupinfo+0x190/0x250\n ext4_mb_init_backend+0x87/0x290\n ext4_mb_init+0x456/0x640\n __ext4_fill_super+0x1072/0x1680\n ext4_fill_super+0xd3/0x280\n get_tree_bdev_flags+0x132/0x1d0\n vfs_get_tree+0x29/0xd0\n vfs_cmd_create+0x59/0xe0\n __do_sys_fsconfig+0x4f6/0x6b0\n do_syscall_64+0x50/0x1f0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n==================================================================\n\nThis issue can be reproduced using the following commands:\n        mkfs.ext4 -F -q -b 1024 /dev/sda 5G\n        tune2fs -O quota,project /dev/sda\n        mount /dev/sda /tmp/test\n\nWith DOUBLE_CHECK defined, mb_group_bb_bitmap_alloc() reads\nand validates the block bitmap. When the validation fails,\next4_mark_group_bitmap_corrupted() attempts to update\nsbi->s_freeclusters_counter. However, this percpu_counter has not been\ninitialized yet at this point, which leads to the panic described above.\n\nFix this by moving the execution of ext4_percpu_param_init() to occur\nbefore ext4_mb_init(), ensuring the per-CPU counters are initialized\nbefore they are used.",
            "updated_at": "2026-09-14T12:17:41.257",
            "published_at": "2026-05-08T14:16:35.737",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "d5e03cbb0c88cd1be39f2adc37d602230045964b through before 0b3d80c56957862ba477ca0ce30c12cad9179c2b (git); d5e03cbb0c88cd1be39f2adc37d602230045964b through before 0d5fcb063cdabb9aeaa8554b7fedad2092c4150e (git); d5e03cbb0c88cd1be39f2adc37d602230045964b through before 9e9fb259bcddf459a0168f4a964e979e500a68a5 (git); d5e03cbb0c88cd1be39f2adc37d602230045964b through before bf5b609524497c195f801cd5707252384aed8149 (git); d5e03cbb0c88cd1be39f2adc37d602230045964b through before aec095f3cc6cf209effd93278ce35be27db81d73 (git); d5e03cbb0c88cd1be39f2adc37d602230045964b through before 270564513489d98b721a1e4a10017978d5213bff (git); 3.17",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-908",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: move ext4_percpu_param_init() before ext4_mb_init()\n\nWhen running `kvm-xfstests -c ext4/1k -C 1 generic/383` with the\n`DOUBLE_CHECK` macro defined, the following panic is triggered:\n\n==================================================================\nEXT4-fs error (device vdc): ext4_validate_block_bitmap:423:\n                        comm mount: bg 0: bad block bitmap checksum\nBUG: unable to handle page fault for address: ff110000fa2cc000\nPGD 3e01067 P4D 3e02067 PUD 0\nOops: Oops: 0000 [#1] SMP NOPTI\nCPU: 0 UID: 0 PID: 2386 Comm: mount Tainted: G W\n                        6.18.0-gba65a4e7120a-dirty #1152 PREEMPT(none)\nRIP: 0010:percpu_counter_add_batch+0x13/0xa0\nCall Trace:\n <TASK>\n ext4_mark_group_bitmap_corrupted+0xcb/0xe0\n ext4_validate_block_bitmap+0x2a1/0x2f0\n ext4_read_block_bitmap+0x33/0x50\n mb_group_bb_bitmap_alloc+0x33/0x80\n ext4_mb_add_groupinfo+0x190/0x250\n ext4_mb_init_backend+0x87/0x290\n ext4_mb_init+0x456/0x640\n __ext4_fill_super+0x1072/0x1680\n ext4_fill_super+0xd3/0x280\n get_tree_bdev_flags+0x132/0x1d0\n vfs_get_tree+0x29/0xd0\n vfs_cmd_create+0x59/0xe0\n __do_sys_fsconfig+0x4f6/0x6b0\n do_syscall_64+0x50/0x1f0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n==================================================================\n\nThis issue can be reproduced using the following commands:\n        mkfs.ext4 -F -q -b 1024 /dev/sda 5G\n        tune2fs -O quota,project /dev/sda\n        mount /dev/sda /tmp/test\n\nWith DOUBLE_CHECK defined, mb_group_bb_bitmap_alloc() reads\nand validates the block bitmap. When the validation fails,\next4_mark_group_bitmap_corrupted() attempts to update\nsbi->s_freeclusters_counter. However, this percpu_counter has not been\ninitialized yet at this point, which leads to the panic described above.\n\nFix this by moving the execution of ext4_percpu_param_init() to occur\nbefore ext4_mb_init(), ensuring the per-CPU counters are initialized\nbefore they are used.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0b3d80c56957862ba477ca0ce30c12cad9179c2b",
                "https://git.kernel.org/stable/c/0d5fcb063cdabb9aeaa8554b7fedad2092c4150e",
                "https://git.kernel.org/stable/c/270564513489d98b721a1e4a10017978d5213bff",
                "https://git.kernel.org/stable/c/9e9fb259bcddf459a0168f4a964e979e500a68a5",
                "https://git.kernel.org/stable/c/aec095f3cc6cf209effd93278ce35be27db81d73",
                "https://git.kernel.org/stable/c/bf5b609524497c195f801cd5707252384aed8149"
            ],
            "timeline": [
                {
                    "at": "2026-05-08T14:16:35.737",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43288"
                }
            ]
        },
        {
            "id": "CVE-2026-43284",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: esp: avoid in-place decrypt on shared skb frags\n\nMSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP\nmarks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),\nso later paths that may modify packet data can first make a private\ncopy. The IPv4/IPv6 datagram append paths did not set this flag when\nsplicing pages into UDP skbs.\n\nThat leaves an ESP-in-UDP packet made from shared pipe pages looking\nlike an ordinary uncloned nonlinear skb. ESP input then takes the no-COW\nfast path for uncloned skbs without a frag_list and decrypts in place\nover data that is not owned privately by the skb.\n\nMark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching\nTCP. Also make ESP input fall back to skb_cow_data() when the flag is\npresent, so ESP does not decrypt externally backed frags in place.\nPrivate nonlinear skb frags still use the existing fast path.\n\nThis intentionally does not change ESP output. In esp_output_head(),\nthe path that appends the ESP trailer to existing skb tailroom without\ncalling skb_cow_data() is not reachable for nonlinear skbs:\nskb_tailroom() returns zero when skb->data_len is nonzero, while ESP\ntailen is positive. Thus ESP output will either use the separate\ndestination-frag path or fall back to skb_cow_data().",
            "updated_at": "2026-09-08T09:18:03.953",
            "published_at": "2026-05-08T08:16:43.827",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "cac2661c53f35cbe651bef9b07026a5a05ab8ce0 through before a6cb440f274a22456ef3e86b457344f1678f38f9 (git); cac2661c53f35cbe651bef9b07026a5a05ab8ce0 through before ab8b995323e5237041472d07e5055f5f7dcdf15b (git); cac2661c53f35cbe651bef9b07026a5a05ab8ce0 through before fe785bb3a8096dffcc4048a85cd0c83337eeecad (git); cac2661c53f35cbe651bef9b07026a5a05ab8ce0 through before 5d55c7336f8032d434adcc5fab987ccc93a44aec (git); cac2661c53f35cbe651bef9b07026a5a05ab8ce0 through before 8253aab4659ca16116b522203c2a6b18dccacea7 (git); cac2661c53f35cbe651bef9b07026a5a05ab8ce0 through before 50ed1e7873100f77abad20fd31c51029bc49cd03 (git); cac2661c53f35cbe651bef9b07026a5a05ab8ce0 through before b54edf1e9a3fd3491bdcb82a21f8d21315271e0d (git); cac2661c53f35cbe651bef9b07026a5a05ab8ce0 through before 71a1d9d985d26716f74d21f18ee8cac821b06e97 (git); cac2661c53f35cbe651bef9b07026a5a05ab8ce0 through before 52646cbd00e765a6db9c3afe9535f26218276034 (git); cac2661c53f35cbe651bef9b07026a5a05ab8ce0 through before f4c50a4034e62ab75f1d5cdd191dd5f9c77fdff4 (git); 4.11; V3.1.6 through before V3.1.7 (custom); V3.1.5 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 210,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-123",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: esp: avoid in-place decrypt on shared skb frags\n\nMSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP\nmarks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),\nso later paths that may modify packet data can first make a private\ncopy. The IPv4/IPv6 datagram append paths did not set this flag when\nsplicing pages into UDP skbs.\n\nThat leaves an ESP-in-UDP packet made from shared pipe pages looking\nlike an ordinary uncloned nonlinear skb. ESP input then takes the no-COW\nfast path for uncloned skbs without a frag_list and decrypts in place\nover data that is not owned privately by the skb.\n\nMark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching\nTCP. Also make ESP input fall back to skb_cow_data() when the flag is\npresent, so ESP does not decrypt externally backed frags in place.\nPrivate nonlinear skb frags still use the existing fast path.\n\nThis intentionally does not change ESP output. In esp_output_head(),\nthe path that appends the ESP trailer to existing skb tailroom without\ncalling skb_cow_data() is not reachable for nonlinear skbs:\nskb_tailroom() returns zero when skb->data_len is nonzero, while ESP\ntailen is positive. Thus ESP output will either use the separate\ndestination-frag path or fall back to skb_cow_data().",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-08",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/V4bel/dirtyfrag"
                },
                {
                    "repository": "Exploit-DB 52591",
                    "author": "nu11secur1ty",
                    "first_seen": "2026-05-29",
                    "confidence": "High",
                    "title": "Linux Kernel -  Local Privilege Escalation",
                    "summary": "Linux Kernel -  Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/52591",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 52585",
                    "author": "nu11secur1ty",
                    "first_seen": "2026-05-27",
                    "confidence": "High",
                    "title": "Linux Kernel - Local Privilege Escalation",
                    "summary": "Linux Kernel - Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/52585",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://git.kernel.org/stable/c/50ed1e7873100f77abad20fd31c51029bc49cd03",
                "https://git.kernel.org/stable/c/52646cbd00e765a6db9c3afe9535f26218276034",
                "https://git.kernel.org/stable/c/5d55c7336f8032d434adcc5fab987ccc93a44aec",
                "https://git.kernel.org/stable/c/71a1d9d985d26716f74d21f18ee8cac821b06e97",
                "https://git.kernel.org/stable/c/8253aab4659ca16116b522203c2a6b18dccacea7",
                "https://git.kernel.org/stable/c/a6cb440f274a22456ef3e86b457344f1678f38f9",
                "https://git.kernel.org/stable/c/ab8b995323e5237041472d07e5055f5f7dcdf15b",
                "https://git.kernel.org/stable/c/b54edf1e9a3fd3491bdcb82a21f8d21315271e0d",
                "https://git.kernel.org/stable/c/f4c50a4034e62ab75f1d5cdd191dd5f9c77fdff4",
                "https://git.kernel.org/stable/c/fe785bb3a8096dffcc4048a85cd0c83337eeecad",
                "http://www.openwall.com/lists/oss-security/2026/05/08/7",
                "http://www.openwall.com/lists/oss-security/2026/05/13/6",
                "http://www.openwall.com/lists/oss-security/2026/05/14/2",
                "http://www.openwall.com/lists/oss-security/2026/05/14/4",
                "https://www.vicarius.io/vsociety/posts/cve-2026-43284-detection-script-dirty-frag-linux-kernel-local-privilege-escalation",
                "https://www.vicarius.io/vsociety/posts/cve-2026-43284-mitigation-script-dirty-frag-linux-kernel-local-privilege-escalation",
                "https://access.redhat.com/errata/RHSA-2026:16061",
                "https://access.redhat.com/errata/RHSA-2026:16062",
                "https://access.redhat.com/errata/RHSA-2026:16100",
                "https://access.redhat.com/errata/RHSA-2026:16155",
                "https://access.redhat.com/errata/RHSA-2026:16157",
                "https://access.redhat.com/errata/RHSA-2026:16160",
                "https://access.redhat.com/errata/RHSA-2026:16161",
                "https://access.redhat.com/errata/RHSA-2026:16171",
                "https://access.redhat.com/errata/RHSA-2026:16176",
                "https://access.redhat.com/errata/RHSA-2026:16180",
                "https://access.redhat.com/errata/RHSA-2026:16195",
                "https://access.redhat.com/errata/RHSA-2026:16196",
                "https://access.redhat.com/errata/RHSA-2026:16201",
                "https://access.redhat.com/errata/RHSA-2026:16202",
                "https://access.redhat.com/errata/RHSA-2026:16203",
                "https://access.redhat.com/errata/RHSA-2026:16204",
                "https://access.redhat.com/errata/RHSA-2026:16206",
                "https://access.redhat.com/errata/RHSA-2026:16254",
                "https://access.redhat.com/errata/RHSA-2026:16312",
                "https://access.redhat.com/errata/RHSA-2026:16314",
                "https://access.redhat.com/errata/RHSA-2026:16328",
                "https://access.redhat.com/errata/RHSA-2026:17795",
                "https://access.redhat.com/errata/RHSA-2026:18025",
                "https://access.redhat.com/errata/RHSA-2026:19074",
                "https://access.redhat.com/errata/RHSA-2026:19225",
                "https://access.redhat.com/errata/RHSA-2026:19564",
                "https://access.redhat.com/errata/RHSA-2026:19568",
                "https://access.redhat.com/errata/RHSA-2026:19569",
                "https://access.redhat.com/errata/RHSA-2026:19572",
                "https://access.redhat.com/errata/RHSA-2026:19573",
                "https://access.redhat.com/errata/RHSA-2026:19574",
                "https://access.redhat.com/errata/RHSA-2026:19575",
                "https://access.redhat.com/errata/RHSA-2026:19577",
                "https://access.redhat.com/errata/RHSA-2026:21695",
                "https://access.redhat.com/errata/RHSA-2026:23233",
                "https://access.redhat.com/errata/RHSA-2026:26542",
                "https://access.redhat.com/errata/RHSA-2026:33486",
                "https://access.redhat.com/errata/RHSA-2026:34098",
                "https://access.redhat.com/security/cve/CVE-2026-43284",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2467771",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
                "https://github.com/V4bel/dirtyfrag",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43284.json",
                "https://www.exploit-db.com/exploits/52591",
                "https://www.exploit-db.com/exploits/52585"
            ],
            "timeline": [
                {
                    "at": "2026-05-08T08:16:43.827",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43284"
                }
            ]
        },
        {
            "id": "CVE-2026-43216",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Drop the lock in skb_may_tx_timestamp()\n\nskb_may_tx_timestamp() may acquire sock::sk_callback_lock. The lock must\nnot be taken in IRQ context, only softirq is okay. A few drivers receive\nthe timestamp via a dedicated interrupt and complete the TX timestamp\nfrom that handler. This will lead to a deadlock if the lock is already\nwrite-locked on the same CPU.\n\nTaking the lock can be avoided. The socket (pointed by the skb) will\nremain valid until the skb is released. The ->sk_socket and ->file\nmember will be set to NULL once the user closes the socket which may\nhappen before the timestamp arrives.\nIf we happen to observe the pointer while the socket is closing but\nbefore the pointer is set to NULL then we may use it because both\npointer (and the file's cred member) are RCU freed.\n\nDrop the lock. Use READ_ONCE() to obtain the individual pointer. Add a\nmatching WRITE_ONCE() where the pointer are cleared.",
            "updated_at": "2026-09-08T09:18:03.780",
            "published_at": "2026-05-06T12:16:41.190",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "b245be1f4db1a0394e4b6eb66059814b46670ac3 through before 4839cbda8f13e99ce2bb3b593f5cc3288415684b (git); b245be1f4db1a0394e4b6eb66059814b46670ac3 through before 3709d73ace37e9aaebb688f5a5cf706d74350b64 (git); b245be1f4db1a0394e4b6eb66059814b46670ac3 through before cf7599116c4c0082fd25cb1bf0254631da0ed06e (git); b245be1f4db1a0394e4b6eb66059814b46670ac3 through before cd2463ec60f0d6e460078037c86f9d0947ee1ff6 (git); b245be1f4db1a0394e4b6eb66059814b46670ac3 through before c770217044d9cbe16a1f7c385cf080ed06a2fc04 (git); b245be1f4db1a0394e4b6eb66059814b46670ac3 through before f3e4cceafad27c9363c33622732f86722846ec6f (git); b245be1f4db1a0394e4b6eb66059814b46670ac3 through before e4c6efb3b70ff87f1df99efce2f8893717695718 (git); b245be1f4db1a0394e4b6eb66059814b46670ac3 through before 983512f3a87fd8dc4c94dfa6b596b6e57df5aad7 (git); 4.0; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Drop the lock in skb_may_tx_timestamp()\n\nskb_may_tx_timestamp() may acquire sock::sk_callback_lock. The lock must\nnot be taken in IRQ context, only softirq is okay. A few drivers receive\nthe timestamp via a dedicated interrupt and complete the TX timestamp\nfrom that handler. This will lead to a deadlock if the lock is already\nwrite-locked on the same CPU.\n\nTaking the lock can be avoided. The socket (pointed by the skb) will\nremain valid until the skb is released. The ->sk_socket and ->file\nmember will be set to NULL once the user closes the socket which may\nhappen before the timestamp arrives.\nIf we happen to observe the pointer while the socket is closing but\nbefore the pointer is set to NULL then we may use it because both\npointer (and the file's cred member) are RCU freed.\n\nDrop the lock. Use READ_ONCE() to obtain the individual pointer. Add a\nmatching WRITE_ONCE() where the pointer are cleared.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/3709d73ace37e9aaebb688f5a5cf706d74350b64",
                "https://git.kernel.org/stable/c/4839cbda8f13e99ce2bb3b593f5cc3288415684b",
                "https://git.kernel.org/stable/c/983512f3a87fd8dc4c94dfa6b596b6e57df5aad7",
                "https://git.kernel.org/stable/c/c770217044d9cbe16a1f7c385cf080ed06a2fc04",
                "https://git.kernel.org/stable/c/cd2463ec60f0d6e460078037c86f9d0947ee1ff6",
                "https://git.kernel.org/stable/c/cf7599116c4c0082fd25cb1bf0254631da0ed06e",
                "https://git.kernel.org/stable/c/e4c6efb3b70ff87f1df99efce2f8893717695718",
                "https://git.kernel.org/stable/c/f3e4cceafad27c9363c33622732f86722846ec6f",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-06T12:16:41.190",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43216"
                }
            ]
        },
        {
            "id": "CVE-2026-43198",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix potential race in tcp_v6_syn_recv_sock()\n\nCode in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock()\nis done too late.\n\nAfter tcp_v4_syn_recv_sock(), the child socket is already visible\nfrom TCP ehash table and other cpus might use it.\n\nSince newinet->pinet6 is still pointing to the listener ipv6_pinfo\nbad things can happen as syzbot found.\n\nMove the problematic code in tcp_v6_mapped_child_init()\nand call this new helper from tcp_v4_syn_recv_sock() before\nthe ehash insertion.\n\nThis allows the removal of one tcp_sync_mss(), since\ntcp_v4_syn_recv_sock() will call it with the correct\ncontext.",
            "updated_at": "2026-09-14T12:17:40.837",
            "published_at": "2026-05-06T12:16:38.857",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before aef4a9ae95d1bc4f7897065011e6261026719aeb (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before dad1fe7db6c6519138430ac8f5e589c18f83bfc9 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before a7e761ba55efaa9c49e0afdd304bb78167af3429 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before cd644e6dc72eec8d9d988717ea1c54f8668ded69 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 9ed654e340f4c73bc6f0af2fbc90ac293e645ce0 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before fe89b2f05b854847784f91127319172945c1fadd (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 7178e2a8027423b2af17ab95df73a749a5b72e5b (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 858d2a4f67ff69e645a43487ef7ea7f28f06deae (git); 2.6.12",
            "fixed": "See vendor advisory",
            "source_count": 25,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-362",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix potential race in tcp_v6_syn_recv_sock()\n\nCode in tcp_v6_syn_recv_sock() after the call to tcp_v4_syn_recv_sock()\nis done too late.\n\nAfter tcp_v4_syn_recv_sock(), the child socket is already visible\nfrom TCP ehash table and other cpus might use it.\n\nSince newinet->pinet6 is still pointing to the listener ipv6_pinfo\nbad things can happen as syzbot found.\n\nMove the problematic code in tcp_v6_mapped_child_init()\nand call this new helper from tcp_v4_syn_recv_sock() before\nthe ehash insertion.\n\nThis allows the removal of one tcp_sync_mss(), since\ntcp_v4_syn_recv_sock() will call it with the correct\ncontext.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/7178e2a8027423b2af17ab95df73a749a5b72e5b",
                "https://git.kernel.org/stable/c/858d2a4f67ff69e645a43487ef7ea7f28f06deae",
                "https://git.kernel.org/stable/c/9ed654e340f4c73bc6f0af2fbc90ac293e645ce0",
                "https://git.kernel.org/stable/c/a7e761ba55efaa9c49e0afdd304bb78167af3429",
                "https://git.kernel.org/stable/c/aef4a9ae95d1bc4f7897065011e6261026719aeb",
                "https://git.kernel.org/stable/c/cd644e6dc72eec8d9d988717ea1c54f8668ded69",
                "https://git.kernel.org/stable/c/dad1fe7db6c6519138430ac8f5e589c18f83bfc9",
                "https://git.kernel.org/stable/c/fe89b2f05b854847784f91127319172945c1fadd",
                "https://access.redhat.com/errata/RHSA-2026:30129",
                "https://access.redhat.com/errata/RHSA-2026:33215",
                "https://access.redhat.com/errata/RHSA-2026:33285",
                "https://access.redhat.com/errata/RHSA-2026:34094",
                "https://access.redhat.com/errata/RHSA-2026:34443",
                "https://access.redhat.com/errata/RHSA-2026:35863",
                "https://access.redhat.com/errata/RHSA-2026:35894",
                "https://access.redhat.com/errata/RHSA-2026:35896",
                "https://access.redhat.com/errata/RHSA-2026:35904",
                "https://access.redhat.com/errata/RHSA-2026:36073",
                "https://access.redhat.com/errata/RHSA-2026:36216",
                "https://access.redhat.com/errata/RHSA-2026:36348",
                "https://access.redhat.com/errata/RHSA-2026:36349",
                "https://access.redhat.com/errata/RHSA-2026:41236",
                "https://access.redhat.com/security/cve/CVE-2026-43198",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2467228",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43198.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-06T12:16:38.857",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43198"
                }
            ]
        },
        {
            "id": "CVE-2026-43133",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation\n\nCommit cc3ed80ae69f (\"KVM: nSVM: always use vmcb01 to for vmsave/vmload\nof guest state\") made KVM always use vmcb01 for the fields controlled by\nVMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code\nto always use vmcb01.\n\nAs a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not\nintercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01\ninstead of the current VMCB.",
            "updated_at": "2026-09-15T12:17:48.040",
            "published_at": "2026-05-06T12:16:30.480",
            "cvss": 7.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "cc3ed80ae69f454c3d904af9f65394a540099723 through before 10063e1251c1485034a018236080792ad083dcc5 (git); cc3ed80ae69f454c3d904af9f65394a540099723 through before c3b7015000988ba35ecd5648f4b2283960f00543 (git); cc3ed80ae69f454c3d904af9f65394a540099723 through before 3880e331b0b31d0d5d3702b124f6c93539cd478a (git); cc3ed80ae69f454c3d904af9f65394a540099723 through before fce2fd4a2ca05670a91015aacccf96a1c26268fd (git); cc3ed80ae69f454c3d904af9f65394a540099723 through before d464cf1ed900d47c85393d40b00017b6adfc2e6c (git); cc3ed80ae69f454c3d904af9f65394a540099723 through before 0004ecb798b30e90d7ebfe74efae2d9423315a64 (git); cc3ed80ae69f454c3d904af9f65394a540099723 through before 127ccae2c185f62e6ecb4bf24f9cb307e9b9c619 (git); 5.13",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-628",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation\n\nCommit cc3ed80ae69f (\"KVM: nSVM: always use vmcb01 to for vmsave/vmload\nof guest state\") made KVM always use vmcb01 for the fields controlled by\nVMSAVE/VMLOAD, but it missed updating the VMLOAD/VMSAVE emulation code\nto always use vmcb01.\n\nAs a result, if VMSAVE/VMLOAD is executed by an L2 guest and is not\nintercepted by L1, KVM will mistakenly use vmcb02. Always use vmcb01\ninstead of the current VMCB.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0004ecb798b30e90d7ebfe74efae2d9423315a64",
                "https://git.kernel.org/stable/c/10063e1251c1485034a018236080792ad083dcc5",
                "https://git.kernel.org/stable/c/127ccae2c185f62e6ecb4bf24f9cb307e9b9c619",
                "https://git.kernel.org/stable/c/3880e331b0b31d0d5d3702b124f6c93539cd478a",
                "https://git.kernel.org/stable/c/c3b7015000988ba35ecd5648f4b2283960f00543",
                "https://git.kernel.org/stable/c/d464cf1ed900d47c85393d40b00017b6adfc2e6c",
                "https://git.kernel.org/stable/c/fce2fd4a2ca05670a91015aacccf96a1c26268fd",
                "https://access.redhat.com/errata/RHSA-2026:65334",
                "https://access.redhat.com/errata/RHSA-2026:66180",
                "https://access.redhat.com/security/cve/CVE-2026-43133",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2467065",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43133.json",
                "https://access.redhat.com/errata/RHSA-2026:66357",
                "https://access.redhat.com/errata/RHSA-2026:67468",
                "https://access.redhat.com/errata/RHSA-2026:67469"
            ],
            "timeline": [
                {
                    "at": "2026-05-06T12:16:30.480",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43133"
                }
            ]
        },
        {
            "id": "CVE-2026-43116",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: ensure safe access to master conntrack\n\nHolding reference on the expectation is not sufficient, the master\nconntrack object can just go away, making exp->master invalid.\n\nTo access exp->master safely:\n\n- Grab the nf_conntrack_expect_lock, this gets serialized with\n  clean_from_lists() which also holds this lock when the master\n  conntrack goes away.\n\n- Hold reference on master conntrack via nf_conntrack_find_get().\n  Not so easy since the master tuple to look up for the master conntrack\n  is not available in the existing problematic paths.\n\nThis patch goes for extending the nf_conntrack_expect_lock section\nto address this issue for simplicity, in the cases that are described\nbelow this is just slightly extending the lock section.\n\nThe add expectation command already holds a reference to the master\nconntrack from ctnetlink_create_expect().\n\nHowever, the delete expectation command needs to grab the spinlock\nbefore looking up for the expectation. Expand the existing spinlock\nsection to address this to cover the expectation lookup. Note that,\nthe nf_ct_expect_iterate_net() calls already grabs the spinlock while\niterating over the expectation table, which is correct.\n\nThe get expectation command needs to grab the spinlock to ensure master\nconntrack does not go away. This also expands the existing spinlock\nsection to cover the expectation lookup too. I needed to move the\nnetlink skb allocation out of the spinlock to keep it GFP_KERNEL.\n\nFor the expectation events, the IPEXP_DESTROY event is already delivered\nunder the spinlock, just move the delivery of IPEXP_NEW under the\nspinlock too because the master conntrack event cache is reached through\nexp->master.\n\nWhile at it, add lockdep notations to help identify what codepaths need\nto grab the spinlock.",
            "updated_at": "2026-09-08T09:18:03.600",
            "published_at": "2026-05-06T10:16:25.400",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c1d10adb4a521de5760112853f42aaeefcec96eb through before 9e1196d27ef496f404c76f7a9d03761142d991c4 (git); c1d10adb4a521de5760112853f42aaeefcec96eb through before 5e1c1d22268ae710c238342c8030c21daf298168 (git); c1d10adb4a521de5760112853f42aaeefcec96eb through before d52fa1fa7440676b8c238037a050ab008c22737f (git); c1d10adb4a521de5760112853f42aaeefcec96eb through before f338ced0473849c9f6ed0b77ca99f1aab5826787 (git); c1d10adb4a521de5760112853f42aaeefcec96eb through before 497f99b26fffdc5635706d1b4811f1ed8ee21a5b (git); c1d10adb4a521de5760112853f42aaeefcec96eb through before bffcaad9afdfe45d7fc777397d3b83c1e3ebffe5 (git); 2.6.16; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-362",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ctnetlink: ensure safe access to master conntrack\n\nHolding reference on the expectation is not sufficient, the master\nconntrack object can just go away, making exp->master invalid.\n\nTo access exp->master safely:\n\n- Grab the nf_conntrack_expect_lock, this gets serialized with\n  clean_from_lists() which also holds this lock when the master\n  conntrack goes away.\n\n- Hold reference on master conntrack via nf_conntrack_find_get().\n  Not so easy since the master tuple to look up for the master conntrack\n  is not available in the existing problematic paths.\n\nThis patch goes for extending the nf_conntrack_expect_lock section\nto address this issue for simplicity, in the cases that are described\nbelow this is just slightly extending the lock section.\n\nThe add expectation command already holds a reference to the master\nconntrack from ctnetlink_create_expect().\n\nHowever, the delete expectation command needs to grab the spinlock\nbefore looking up for the expectation. Expand the existing spinlock\nsection to address this to cover the expectation lookup. Note that,\nthe nf_ct_expect_iterate_net() calls already grabs the spinlock while\niterating over the expectation table, which is correct.\n\nThe get expectation command needs to grab the spinlock to ensure master\nconntrack does not go away. This also expands the existing spinlock\nsection to cover the expectation lookup too. I needed to move the\nnetlink skb allocation out of the spinlock to keep it GFP_KERNEL.\n\nFor the expectation events, the IPEXP_DESTROY event is already delivered\nunder the spinlock, just move the delivery of IPEXP_NEW under the\nspinlock too because the master conntrack event cache is reached through\nexp->master.\n\nWhile at it, add lockdep notations to help identify what codepaths need\nto grab the spinlock.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/497f99b26fffdc5635706d1b4811f1ed8ee21a5b",
                "https://git.kernel.org/stable/c/5e1c1d22268ae710c238342c8030c21daf298168",
                "https://git.kernel.org/stable/c/9e1196d27ef496f404c76f7a9d03761142d991c4",
                "https://git.kernel.org/stable/c/bffcaad9afdfe45d7fc777397d3b83c1e3ebffe5",
                "https://git.kernel.org/stable/c/d52fa1fa7440676b8c238037a050ab008c22737f",
                "https://git.kernel.org/stable/c/f338ced0473849c9f6ed0b77ca99f1aab5826787",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-06T10:16:25.400",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43116"
                }
            ]
        },
        {
            "id": "CVE-2026-43114",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry\n\nNew test case fails unexpectedly when avx2 matching functions are used.\n\nThe test first loads a ranomly generated pipapo set\nwith 'ipv4 . port' key, i.e.  nft -f foo.\n\nThis works.  Then, it reloads the set after a flush:\n(echo flush set t s; cat foo) | nft -f -\n\nThis is expected to work, because its the same set after all and it was\nalready loaded once.\n\nBut with avx2, this fails: nft reports a clashing element.\n\nThe reported clash is of following form:\n\n    We successfully re-inserted\n      a . b\n      c . d\n\nThen we try to insert a . d\n\navx2 finds the already existing a . d, which (due to 'flush set') is marked\nas invalid in the new generation.  It skips the element and moves to next.\n\nDue to incorrect masking, the skip-step finds the next matching\nelement *only considering the first field*,\n\ni.e. we return the already reinserted \"a . b\", even though the\nlast field is different and the entry should not have been matched.\n\nNo such error is reported for the generic c implementation (no avx2) or when\nthe last field has to use the 'nft_pipapo_avx2_lookup_slow' fallback.\n\nBisection points to\n7711f4bb4b36 (\"netfilter: nft_set_pipapo: fix range overlap detection\")\nbut that fix merely uncovers this bug.\n\nBefore this commit, the wrong element is returned, but erronously\nreported as a full, identical duplicate.\n\nThe root-cause is too early return in the avx2 match functions.\nWhen we process the last field, we should continue to process data\nuntil the entire input size has been consumed to make sure no stale\nbits remain in the map.",
            "updated_at": "2026-09-16T13:17:57.820",
            "published_at": "2026-05-06T10:16:25.163",
            "cvss": 9.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7400b063969bdca4a06cd97f1294d765c8eecbe1 through before f8c39983fc9c1a978c82e6f2df7bfba8a8561587 (git); 7400b063969bdca4a06cd97f1294d765c8eecbe1 through before c7babe2f28b507e17f28e9f753b7caec72d4857f (git); 7400b063969bdca4a06cd97f1294d765c8eecbe1 through before 1c43f0dd8691ddf8884793b481ddc7511cf593c3 (git); 7400b063969bdca4a06cd97f1294d765c8eecbe1 through before fa4f1f52528c73989d820f32bfca06bec5afeece (git); 7400b063969bdca4a06cd97f1294d765c8eecbe1 through before 3d53f9aafd469ae1ea27051e00f5b96ca1b55d52 (git); 7400b063969bdca4a06cd97f1294d765c8eecbe1 through before 07de44424bb7f17ef9357e8535df96d9e97c40cb (git); 7400b063969bdca4a06cd97f1294d765c8eecbe1 through before 0abbc43f71d99baadeeba6fa3fe1c80b676f57ed (git); 7400b063969bdca4a06cd97f1294d765c8eecbe1 through before d3c0037ffe1273fa1961e779ff6906234d6cf53c (git); 5.7",
            "fixed": "See vendor advisory",
            "source_count": 26,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-480",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry\n\nNew test case fails unexpectedly when avx2 matching functions are used.\n\nThe test first loads a ranomly generated pipapo set\nwith 'ipv4 . port' key, i.e.  nft -f foo.\n\nThis works.  Then, it reloads the set after a flush:\n(echo flush set t s; cat foo) | nft -f -\n\nThis is expected to work, because its the same set after all and it was\nalready loaded once.\n\nBut with avx2, this fails: nft reports a clashing element.\n\nThe reported clash is of following form:\n\n    We successfully re-inserted\n      a . b\n      c . d\n\nThen we try to insert a . d\n\navx2 finds the already existing a . d, which (due to 'flush set') is marked\nas invalid in the new generation.  It skips the element and moves to next.\n\nDue to incorrect masking, the skip-step finds the next matching\nelement *only considering the first field*,\n\ni.e. we return the already reinserted \"a . b\", even though the\nlast field is different and the entry should not have been matched.\n\nNo such error is reported for the generic c implementation (no avx2) or when\nthe last field has to use the 'nft_pipapo_avx2_lookup_slow' fallback.\n\nBisection points to\n7711f4bb4b36 (\"netfilter: nft_set_pipapo: fix range overlap detection\")\nbut that fix merely uncovers this bug.\n\nBefore this commit, the wrong element is returned, but erronously\nreported as a full, identical duplicate.\n\nThe root-cause is too early return in the avx2 match functions.\nWhen we process the last field, we should continue to process data\nuntil the entire input size has been consumed to make sure no stale\nbits remain in the map.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/07de44424bb7f17ef9357e8535df96d9e97c40cb",
                "https://git.kernel.org/stable/c/0abbc43f71d99baadeeba6fa3fe1c80b676f57ed",
                "https://git.kernel.org/stable/c/1c43f0dd8691ddf8884793b481ddc7511cf593c3",
                "https://git.kernel.org/stable/c/3d53f9aafd469ae1ea27051e00f5b96ca1b55d52",
                "https://git.kernel.org/stable/c/c7babe2f28b507e17f28e9f753b7caec72d4857f",
                "https://git.kernel.org/stable/c/d3c0037ffe1273fa1961e779ff6906234d6cf53c",
                "https://git.kernel.org/stable/c/f8c39983fc9c1a978c82e6f2df7bfba8a8561587",
                "https://git.kernel.org/stable/c/fa4f1f52528c73989d820f32bfca06bec5afeece",
                "https://access.redhat.com/errata/RHSA-2026:59723",
                "https://access.redhat.com/errata/RHSA-2026:62568",
                "https://access.redhat.com/errata/RHSA-2026:62638",
                "https://access.redhat.com/errata/RHSA-2026:62639",
                "https://access.redhat.com/errata/RHSA-2026:62640",
                "https://access.redhat.com/errata/RHSA-2026:62641",
                "https://access.redhat.com/errata/RHSA-2026:62642",
                "https://access.redhat.com/errata/RHSA-2026:63093",
                "https://access.redhat.com/errata/RHSA-2026:64767",
                "https://access.redhat.com/errata/RHSA-2026:65712",
                "https://access.redhat.com/security/cve/CVE-2026-43114",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2466994",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43114.json",
                "https://access.redhat.com/errata/RHSA-2026:66351",
                "https://access.redhat.com/errata/RHSA-2026:66376",
                "https://access.redhat.com/errata/RHSA-2026:66370",
                "https://access.redhat.com/errata/RHSA-2026:67721",
                "https://access.redhat.com/errata/RHSA-2026:67723"
            ],
            "timeline": [
                {
                    "at": "2026-05-06T10:16:25.163",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43114"
                }
            ]
        },
        {
            "id": "CVE-2026-43112",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath\n\nWhen cifs_sanitize_prepath is called with an empty string or a string\ncontaining only delimiters (e.g., \"/\"), the current logic attempts to\ncheck *(cursor2 - 1) before cursor2 has advanced. This results in an\nout-of-bounds read.\n\nThis patch adds an early exit check after stripping prepended\ndelimiters. If no path content remains, the function returns NULL.\n\nThe bug was identified via manual audit and verified using a\nstandalone test case compiled with AddressSanitizer, which\ntriggered a SEGV on affected inputs.",
            "updated_at": "2026-09-15T12:17:46.460",
            "published_at": "2026-05-06T10:16:24.927",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c63433a09d6ae4c226fcbc66da4c58fc189fd746 through before a2ba20c17de8eb028f96b1d85f119d3d25655bd9 (git); a31080899d5fdafcccf7f39dd214a814a2c82626 through before fbced33599653471b4581dfe1abc7b467031f126 (git); a31080899d5fdafcccf7f39dd214a814a2c82626 through before 5d4fe469fe7dbff7d874c196bb680a82f2625d95 (git); a31080899d5fdafcccf7f39dd214a814a2c82626 through before 2d29214448ec0f4e7e18bb1c14dd4a6c07f1c439 (git); a31080899d5fdafcccf7f39dd214a814a2c82626 through before 86f9c23e0814cfdffda9eedf0c591c51ba209010 (git); a31080899d5fdafcccf7f39dd214a814a2c82626 through before 49b1ce6d7cfb6c5a49f68bf5ccfcfb6ba14e63c3 (git); a31080899d5fdafcccf7f39dd214a814a2c82626 through before 78ec5bf2f589ec7fd8f169394bfeca541b077317 (git); 5.15.11 through before 5.15.209 (semver); 5.16",
            "fixed": "See vendor advisory",
            "source_count": 36,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath\n\nWhen cifs_sanitize_prepath is called with an empty string or a string\ncontaining only delimiters (e.g., \"/\"), the current logic attempts to\ncheck *(cursor2 - 1) before cursor2 has advanced. This results in an\nout-of-bounds read.\n\nThis patch adds an early exit check after stripping prepended\ndelimiters. If no path content remains, the function returns NULL.\n\nThe bug was identified via manual audit and verified using a\nstandalone test case compiled with AddressSanitizer, which\ntriggered a SEGV on affected inputs.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2d29214448ec0f4e7e18bb1c14dd4a6c07f1c439",
                "https://git.kernel.org/stable/c/49b1ce6d7cfb6c5a49f68bf5ccfcfb6ba14e63c3",
                "https://git.kernel.org/stable/c/5d4fe469fe7dbff7d874c196bb680a82f2625d95",
                "https://git.kernel.org/stable/c/78ec5bf2f589ec7fd8f169394bfeca541b077317",
                "https://git.kernel.org/stable/c/86f9c23e0814cfdffda9eedf0c591c51ba209010",
                "https://git.kernel.org/stable/c/a2ba20c17de8eb028f96b1d85f119d3d25655bd9",
                "https://git.kernel.org/stable/c/fbced33599653471b4581dfe1abc7b467031f126",
                "https://access.redhat.com/errata/RHSA-2026:34911",
                "https://access.redhat.com/errata/RHSA-2026:36018",
                "https://access.redhat.com/errata/RHSA-2026:36365",
                "https://access.redhat.com/errata/RHSA-2026:36366",
                "https://access.redhat.com/errata/RHSA-2026:40764",
                "https://access.redhat.com/errata/RHSA-2026:52649",
                "https://access.redhat.com/errata/RHSA-2026:52764",
                "https://access.redhat.com/errata/RHSA-2026:53989",
                "https://access.redhat.com/errata/RHSA-2026:53990",
                "https://access.redhat.com/errata/RHSA-2026:56573",
                "https://access.redhat.com/errata/RHSA-2026:57402",
                "https://access.redhat.com/errata/RHSA-2026:57457",
                "https://access.redhat.com/errata/RHSA-2026:57543",
                "https://access.redhat.com/errata/RHSA-2026:59662",
                "https://access.redhat.com/errata/RHSA-2026:59663",
                "https://access.redhat.com/errata/RHSA-2026:59831",
                "https://access.redhat.com/errata/RHSA-2026:60019",
                "https://access.redhat.com/errata/RHSA-2026:62549",
                "https://access.redhat.com/errata/RHSA-2026:62558",
                "https://access.redhat.com/errata/RHSA-2026:62637",
                "https://access.redhat.com/errata/RHSA-2026:62638",
                "https://access.redhat.com/errata/RHSA-2026:62639",
                "https://access.redhat.com/errata/RHSA-2026:62640",
                "https://access.redhat.com/errata/RHSA-2026:62641",
                "https://access.redhat.com/errata/RHSA-2026:62642",
                "https://access.redhat.com/security/cve/CVE-2026-43112",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2467015",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43112.json",
                "https://access.redhat.com/errata/RHSA-2026:62409"
            ],
            "timeline": [
                {
                    "at": "2026-05-06T10:16:24.927",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43112"
                }
            ]
        },
        {
            "id": "CVE-2026-43089",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm_user: fix info leak in build_mapping()\n\nstruct xfrm_usersa_id has a one-byte padding hole after the proto\nfield, which ends up never getting set to zero before copying out to\nuserspace.  Fix that up by zeroing out the whole structure before\nsetting individual variables.",
            "updated_at": "2026-09-08T09:18:03.447",
            "published_at": "2026-05-06T10:16:22.200",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3a2dfbe8acb154905fdc2fd03ec56df42e6c4cc4 through before 521385cbd50ca9474396d88462fcdfa6489685d9 (git); 3a2dfbe8acb154905fdc2fd03ec56df42e6c4cc4 through before c2779ae9a3e5a044e5ccd564681511bbbcc5fc0f (git); 3a2dfbe8acb154905fdc2fd03ec56df42e6c4cc4 through before 72a8de41c3eb4dcf22bf3b674ea38fb2f75d6f32 (git); 3a2dfbe8acb154905fdc2fd03ec56df42e6c4cc4 through before d3125c541a96fb3c0fc7210112684baf22b6c24d (git); 3a2dfbe8acb154905fdc2fd03ec56df42e6c4cc4 through before 5a1a4b049ddde41466ccac0daeec326254b133f2 (git); 3a2dfbe8acb154905fdc2fd03ec56df42e6c4cc4 through before f779a6b6cdb6e12baa0663063ac59ab2a8f20c0c (git); 3a2dfbe8acb154905fdc2fd03ec56df42e6c4cc4 through before 700c9622b23c33b5933e6dcea816492c064e4e10 (git); 3a2dfbe8acb154905fdc2fd03ec56df42e6c4cc4 through before 1beb76b2053b68c491b78370794b8ff63c8f8c02 (git); 2.6.29; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-401",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm_user: fix info leak in build_mapping()\n\nstruct xfrm_usersa_id has a one-byte padding hole after the proto\nfield, which ends up never getting set to zero before copying out to\nuserspace.  Fix that up by zeroing out the whole structure before\nsetting individual variables.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1beb76b2053b68c491b78370794b8ff63c8f8c02",
                "https://git.kernel.org/stable/c/521385cbd50ca9474396d88462fcdfa6489685d9",
                "https://git.kernel.org/stable/c/5a1a4b049ddde41466ccac0daeec326254b133f2",
                "https://git.kernel.org/stable/c/700c9622b23c33b5933e6dcea816492c064e4e10",
                "https://git.kernel.org/stable/c/72a8de41c3eb4dcf22bf3b674ea38fb2f75d6f32",
                "https://git.kernel.org/stable/c/c2779ae9a3e5a044e5ccd564681511bbbcc5fc0f",
                "https://git.kernel.org/stable/c/d3125c541a96fb3c0fc7210112684baf22b6c24d",
                "https://git.kernel.org/stable/c/f779a6b6cdb6e12baa0663063ac59ab2a8f20c0c",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-06T10:16:22.200",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43089"
                }
            ]
        },
        {
            "id": "CVE-2026-43088",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: af_key: zero aligned sockaddr tail in PF_KEY exports\n\nPF_KEY export paths use `pfkey_sockaddr_size()` when reserving sockaddr\npayload space, so IPv6 addresses occupy 32 bytes on the wire. However,\n`pfkey_sockaddr_fill()` initializes only the first 28 bytes of\n`struct sockaddr_in6`, leaving the final 4 aligned bytes uninitialized.\n\nNot every PF_KEY message is affected. The state and policy dump builders\nalready zero the whole message buffer before filling the sockaddr\npayloads. Keep the fix to the export paths that still append aligned\nsockaddr payloads with plain `skb_put()`:\n\n  - `SADB_ACQUIRE`\n  - `SADB_X_NAT_T_NEW_MAPPING`\n  - `SADB_X_MIGRATE`\n\nFix those paths by clearing only the aligned sockaddr tail after\n`pfkey_sockaddr_fill()`.",
            "updated_at": "2026-09-14T12:17:40.640",
            "published_at": "2026-05-06T10:16:22.090",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 6df5f90175fe4c584e9960b6c00131a7bf2b5399 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 746ee79d9e140f0e9e56f5123eaa88ad9332de7b (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before e357c3cf8a44d4ec1f49ad6981e4ab9704354347 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 3c19cb8a84ef709d57943bd6664cf31cb91ba6ec (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 11cbf294bac623bd57296f231199193087f57b4a (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before edd446ee7cd3d02cac246168063d5b3e9ea68460 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 2e74f974359b5382ecbe8536abbb5b837eb6c724 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 426c355742f02cf743b347d9d7dbdc1bfbfa31ef (git); 2.6.12",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: af_key: zero aligned sockaddr tail in PF_KEY exports\n\nPF_KEY export paths use `pfkey_sockaddr_size()` when reserving sockaddr\npayload space, so IPv6 addresses occupy 32 bytes on the wire. However,\n`pfkey_sockaddr_fill()` initializes only the first 28 bytes of\n`struct sockaddr_in6`, leaving the final 4 aligned bytes uninitialized.\n\nNot every PF_KEY message is affected. The state and policy dump builders\nalready zero the whole message buffer before filling the sockaddr\npayloads. Keep the fix to the export paths that still append aligned\nsockaddr payloads with plain `skb_put()`:\n\n  - `SADB_ACQUIRE`\n  - `SADB_X_NAT_T_NEW_MAPPING`\n  - `SADB_X_MIGRATE`\n\nFix those paths by clearing only the aligned sockaddr tail after\n`pfkey_sockaddr_fill()`.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/11cbf294bac623bd57296f231199193087f57b4a",
                "https://git.kernel.org/stable/c/2e74f974359b5382ecbe8536abbb5b837eb6c724",
                "https://git.kernel.org/stable/c/3c19cb8a84ef709d57943bd6664cf31cb91ba6ec",
                "https://git.kernel.org/stable/c/426c355742f02cf743b347d9d7dbdc1bfbfa31ef",
                "https://git.kernel.org/stable/c/6df5f90175fe4c584e9960b6c00131a7bf2b5399",
                "https://git.kernel.org/stable/c/746ee79d9e140f0e9e56f5123eaa88ad9332de7b",
                "https://git.kernel.org/stable/c/e357c3cf8a44d4ec1f49ad6981e4ab9704354347",
                "https://git.kernel.org/stable/c/edd446ee7cd3d02cac246168063d5b3e9ea68460"
            ],
            "timeline": [
                {
                    "at": "2026-05-06T10:16:22.090",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43088"
                }
            ]
        },
        {
            "id": "CVE-2026-43085",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator\n\nWhen batching multiple NFLOG messages (inst->qlen > 1), __nfulnl_send()\nappends an NLMSG_DONE terminator with sizeof(struct nfgenmsg) payload via\nnlmsg_put(), but never initializes the nfgenmsg bytes. The nlmsg_put()\nhelper only zeroes alignment padding after the payload, not the payload\nitself, so four bytes of stale kernel heap data are leaked to userspace\nin the NLMSG_DONE message body.\n\nUse nfnl_msg_put() to build the NLMSG_DONE terminator, which initializes\nthe nfgenmsg payload via nfnl_fill_hdr(), consistent with how\n__build_packet_message() already constructs NFULNL_MSG_PACKET headers.",
            "updated_at": "2026-09-08T09:18:02.693",
            "published_at": "2026-05-06T10:16:21.720",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "29c5d4afba51c71cfeadd3f74f3c42e064483fb0 through before 296f18e1c3a87c915a92ed27832d5040a22d1072 (git); 29c5d4afba51c71cfeadd3f74f3c42e064483fb0 through before 9e2182865de781c41ab16b7985e9d26dcefea867 (git); 29c5d4afba51c71cfeadd3f74f3c42e064483fb0 through before 57cc509d82b46150a11dcecc8b25eaa177eda34d (git); 29c5d4afba51c71cfeadd3f74f3c42e064483fb0 through before 368c22aea490f6f50df831b4f9e3623787686c5b (git); 29c5d4afba51c71cfeadd3f74f3c42e064483fb0 through before d1399632ba255d2e02c757af5d9f5d9279ce168c (git); 29c5d4afba51c71cfeadd3f74f3c42e064483fb0 through before d552bcfca323d175664d7444989b04f55666978a (git); 29c5d4afba51c71cfeadd3f74f3c42e064483fb0 through before 15d209bccf9273b4a8b4e579ba0e92d065b6ec8c (git); 29c5d4afba51c71cfeadd3f74f3c42e064483fb0 through before 1f3083aec8836213da441270cdb1ab612dd82cf4 (git); 2.6.23; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator\n\nWhen batching multiple NFLOG messages (inst->qlen > 1), __nfulnl_send()\nappends an NLMSG_DONE terminator with sizeof(struct nfgenmsg) payload via\nnlmsg_put(), but never initializes the nfgenmsg bytes. The nlmsg_put()\nhelper only zeroes alignment padding after the payload, not the payload\nitself, so four bytes of stale kernel heap data are leaked to userspace\nin the NLMSG_DONE message body.\n\nUse nfnl_msg_put() to build the NLMSG_DONE terminator, which initializes\nthe nfgenmsg payload via nfnl_fill_hdr(), consistent with how\n__build_packet_message() already constructs NFULNL_MSG_PACKET headers.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/15d209bccf9273b4a8b4e579ba0e92d065b6ec8c",
                "https://git.kernel.org/stable/c/1f3083aec8836213da441270cdb1ab612dd82cf4",
                "https://git.kernel.org/stable/c/296f18e1c3a87c915a92ed27832d5040a22d1072",
                "https://git.kernel.org/stable/c/368c22aea490f6f50df831b4f9e3623787686c5b",
                "https://git.kernel.org/stable/c/57cc509d82b46150a11dcecc8b25eaa177eda34d",
                "https://git.kernel.org/stable/c/9e2182865de781c41ab16b7985e9d26dcefea867",
                "https://git.kernel.org/stable/c/d1399632ba255d2e02c757af5d9f5d9279ce168c",
                "https://git.kernel.org/stable/c/d552bcfca323d175664d7444989b04f55666978a",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-06T10:16:21.720",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43085"
                }
            ]
        },
        {
            "id": "CVE-2026-43071",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndcache: Limit the minimal number of bucket to two\n\nThere is an OOB read problem on dentry_hashtable when user sets\n'dhash_entries=1':\n  BUG: unable to handle page fault for address: ffff888b30b774b0\n  #PF: supervisor read access in kernel mode\n  #PF: error_code(0x0000) - not-present page\n  Oops: Oops: 0000 [#1] SMP PTI\n  RIP: 0010:__d_lookup+0x56/0x120\n   Call Trace:\n    d_lookup.cold+0x16/0x5d\n    lookup_dcache+0x27/0xf0\n    lookup_one_qstr_excl+0x2a/0x180\n    start_dirop+0x55/0xa0\n    simple_start_creating+0x8d/0xa0\n    debugfs_start_creating+0x8c/0x180\n    debugfs_create_dir+0x1d/0x1c0\n    pinctrl_init+0x6d/0x140\n    do_one_initcall+0x6d/0x3d0\n    kernel_init_freeable+0x39f/0x460\n    kernel_init+0x2a/0x260\n\nThere will be only one bucket in dentry_hashtable when dhash_entries is\nset as one, and d_hash_shift is calculated as 32 by dcache_init(). Then,\nfollowing process will access more than one buckets(which memory region\nis not allocated) in dentry_hashtable:\n d_lookup\n  b = d_hash(hash)\n    dentry_hashtable + ((u32)hashlen >> d_hash_shift)\n    // The C standard defines the behavior of right shift amounts\n    // exceeding the bit width of the operand as undefined. The\n    // result of '(u32)hashlen >> d_hash_shift' becomes 'hashlen',\n    // so 'b' will point to an unallocated memory region.\n  hlist_bl_for_each_entry_rcu(b)\n   hlist_bl_first_rcu(head)\n    h->first  // read OOB!\n\nFix it by limiting the minimal number of dentry_hashtable bucket to two,\nso that 'd_hash_shift' won't exceeds the bit width of type u32.",
            "updated_at": "2026-09-08T09:18:02.470",
            "published_at": "2026-05-05T16:16:16.420",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "99d263d4c5b2f541dfacb5391e22e8c91ea982a6 through before 45b06bb5ea96f75ad81d7ef446f832ea6b0026fe (git); 99d263d4c5b2f541dfacb5391e22e8c91ea982a6 through before 426ef05e82ee52c8d0e95fc0808b7383d8352d73 (git); 99d263d4c5b2f541dfacb5391e22e8c91ea982a6 through before ddd57ebce245f9c7e2f6902a6c087d6186d2385d (git); 99d263d4c5b2f541dfacb5391e22e8c91ea982a6 through before 755b40903eff563768d4d96fd4ef51ec48adde3b (git); 99d263d4c5b2f541dfacb5391e22e8c91ea982a6 through before 5718df131ab78897a9dd1f2e71c3ba732d4392af (git); 99d263d4c5b2f541dfacb5391e22e8c91ea982a6 through before 277cedabb0ab86baae83fa58218be13c6d3e5526 (git); 99d263d4c5b2f541dfacb5391e22e8c91ea982a6 through before f08fe8891c3eeb63b73f9f1f6d97aa629c821579 (git); d4c96061fddd129778ce8b70fb093aa532f422d0 (git); be2378cbffe50ce0161f0fdee914adee98af53dc (git); a8be8af18485f9fade90e1743d940252a39eec84 (git); b5cf3193759f7cd1cfbeef11f5cf067bbce22e55 (git); 3.10.55 through before 3.11 (semver); 3.12.29 through before 3.13 (semver); 3.14.19 through before 3.15 (semver); 3.16.3 through before 3.17 (semver); 3.17; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ndcache: Limit the minimal number of bucket to two\n\nThere is an OOB read problem on dentry_hashtable when user sets\n'dhash_entries=1':\n  BUG: unable to handle page fault for address: ffff888b30b774b0\n  #PF: supervisor read access in kernel mode\n  #PF: error_code(0x0000) - not-present page\n  Oops: Oops: 0000 [#1] SMP PTI\n  RIP: 0010:__d_lookup+0x56/0x120\n   Call Trace:\n    d_lookup.cold+0x16/0x5d\n    lookup_dcache+0x27/0xf0\n    lookup_one_qstr_excl+0x2a/0x180\n    start_dirop+0x55/0xa0\n    simple_start_creating+0x8d/0xa0\n    debugfs_start_creating+0x8c/0x180\n    debugfs_create_dir+0x1d/0x1c0\n    pinctrl_init+0x6d/0x140\n    do_one_initcall+0x6d/0x3d0\n    kernel_init_freeable+0x39f/0x460\n    kernel_init+0x2a/0x260\n\nThere will be only one bucket in dentry_hashtable when dhash_entries is\nset as one, and d_hash_shift is calculated as 32 by dcache_init(). Then,\nfollowing process will access more than one buckets(which memory region\nis not allocated) in dentry_hashtable:\n d_lookup\n  b = d_hash(hash)\n    dentry_hashtable + ((u32)hashlen >> d_hash_shift)\n    // The C standard defines the behavior of right shift amounts\n    // exceeding the bit width of the operand as undefined. The\n    // result of '(u32)hashlen >> d_hash_shift' becomes 'hashlen',\n    // so 'b' will point to an unallocated memory region.\n  hlist_bl_for_each_entry_rcu(b)\n   hlist_bl_first_rcu(head)\n    h->first  // read OOB!\n\nFix it by limiting the minimal number of dentry_hashtable bucket to two,\nso that 'd_hash_shift' won't exceeds the bit width of type u32.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/277cedabb0ab86baae83fa58218be13c6d3e5526",
                "https://git.kernel.org/stable/c/426ef05e82ee52c8d0e95fc0808b7383d8352d73",
                "https://git.kernel.org/stable/c/45b06bb5ea96f75ad81d7ef446f832ea6b0026fe",
                "https://git.kernel.org/stable/c/5718df131ab78897a9dd1f2e71c3ba732d4392af",
                "https://git.kernel.org/stable/c/755b40903eff563768d4d96fd4ef51ec48adde3b",
                "https://git.kernel.org/stable/c/ddd57ebce245f9c7e2f6902a6c087d6186d2385d",
                "https://git.kernel.org/stable/c/f08fe8891c3eeb63b73f9f1f6d97aa629c821579",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-05T16:16:16.420",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43071"
                }
            ]
        },
        {
            "id": "CVE-2026-43009",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix incorrect pruning due to atomic fetch precision tracking\n\nWhen backtrack_insn encounters a BPF_STX instruction with BPF_ATOMIC\nand BPF_FETCH, the src register (or r0 for BPF_CMPXCHG) also acts as\na destination, thus receiving the old value from the memory location.\n\nThe current backtracking logic does not account for this. It treats\natomic fetch operations the same as regular stores where the src\nregister is only an input. This leads the backtrack_insn to fail to\npropagate precision to the stack location, which is then not marked\nas precise!\n\nLater, the verifier's path pruning can incorrectly consider two states\nequivalent when they differ in terms of stack state. Meaning, two\nbranches can be treated as equivalent and thus get pruned when they\nshould not be seen as such.\n\nFix it as follows: Extend the BPF_LDX handling in backtrack_insn to\nalso cover atomic fetch operations via is_atomic_fetch_insn() helper.\nWhen the fetch dst register is being tracked for precision, clear it,\nand propagate precision over to the stack slot. For non-stack memory,\nthe precision walk stops at the atomic instruction, same as regular\nBPF_LDX. This covers all fetch variants.\n\nBefore:\n\n  0: (b7) r1 = 8                        ; R1=8\n  1: (7b) *(u64 *)(r10 -8) = r1         ; R1=8 R10=fp0 fp-8=8\n  2: (b7) r2 = 0                        ; R2=0\n  3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)          ; R2=8 R10=fp0 fp-8=mmmmmmmm\n  4: (bf) r3 = r10                      ; R3=fp0 R10=fp0\n  5: (0f) r3 += r2\n  mark_precise: frame0: last_idx 5 first_idx 0 subseq_idx -1\n  mark_precise: frame0: regs=r2 stack= before 4: (bf) r3 = r10\n  mark_precise: frame0: regs=r2 stack= before 3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)\n  mark_precise: frame0: regs=r2 stack= before 2: (b7) r2 = 0\n  6: R2=8 R3=fp8\n  6: (b7) r0 = 0                        ; R0=0\n  7: (95) exit\n\nAfter:\n\n  0: (b7) r1 = 8                        ; R1=8\n  1: (7b) *(u64 *)(r10 -8) = r1         ; R1=8 R10=fp0 fp-8=8\n  2: (b7) r2 = 0                        ; R2=0\n  3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)          ; R2=8 R10=fp0 fp-8=mmmmmmmm\n  4: (bf) r3 = r10                      ; R3=fp0 R10=fp0\n  5: (0f) r3 += r2\n  mark_precise: frame0: last_idx 5 first_idx 0 subseq_idx -1\n  mark_precise: frame0: regs=r2 stack= before 4: (bf) r3 = r10\n  mark_precise: frame0: regs=r2 stack= before 3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)\n  mark_precise: frame0: regs= stack=-8 before 2: (b7) r2 = 0\n  mark_precise: frame0: regs= stack=-8 before 1: (7b) *(u64 *)(r10 -8) = r1\n  mark_precise: frame0: regs=r1 stack= before 0: (b7) r1 = 8\n  6: R2=8 R3=fp8\n  6: (b7) r0 = 0                        ; R0=0\n  7: (95) exit",
            "updated_at": "2026-09-07T16:17:28.090",
            "published_at": "2026-05-01T15:16:44.770",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5ca419f2864a2c60940dcf4bbaeb69546200e36f through before ea150ffa9fc9f78c5cf22e1f7b06b6d016b1017c (git); 5ca419f2864a2c60940dcf4bbaeb69546200e36f through before 7ffbe45b1d227e24659998a91cfd4c27af457e71 (git); 5ca419f2864a2c60940dcf4bbaeb69546200e36f through before 179ee84a89114b854ac2dd1d293633a7f6c8dac1 (git); 5.12",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix incorrect pruning due to atomic fetch precision tracking\n\nWhen backtrack_insn encounters a BPF_STX instruction with BPF_ATOMIC\nand BPF_FETCH, the src register (or r0 for BPF_CMPXCHG) also acts as\na destination, thus receiving the old value from the memory location.\n\nThe current backtracking logic does not account for this. It treats\natomic fetch operations the same as regular stores where the src\nregister is only an input. This leads the backtrack_insn to fail to\npropagate precision to the stack location, which is then not marked\nas precise!\n\nLater, the verifier's path pruning can incorrectly consider two states\nequivalent when they differ in terms of stack state. Meaning, two\nbranches can be treated as equivalent and thus get pruned when they\nshould not be seen as such.\n\nFix it as follows: Extend the BPF_LDX handling in backtrack_insn to\nalso cover atomic fetch operations via is_atomic_fetch_insn() helper.\nWhen the fetch dst register is being tracked for precision, clear it,\nand propagate precision over to the stack slot. For non-stack memory,\nthe precision walk stops at the atomic instruction, same as regular\nBPF_LDX. This covers all fetch variants.\n\nBefore:\n\n  0: (b7) r1 = 8                        ; R1=8\n  1: (7b) *(u64 *)(r10 -8) = r1         ; R1=8 R10=fp0 fp-8=8\n  2: (b7) r2 = 0                        ; R2=0\n  3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)          ; R2=8 R10=fp0 fp-8=mmmmmmmm\n  4: (bf) r3 = r10                      ; R3=fp0 R10=fp0\n  5: (0f) r3 += r2\n  mark_precise: frame0: last_idx 5 first_idx 0 subseq_idx -1\n  mark_precise: frame0: regs=r2 stack= before 4: (bf) r3 = r10\n  mark_precise: frame0: regs=r2 stack= before 3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)\n  mark_precise: frame0: regs=r2 stack= before 2: (b7) r2 = 0\n  6: R2=8 R3=fp8\n  6: (b7) r0 = 0                        ; R0=0\n  7: (95) exit\n\nAfter:\n\n  0: (b7) r1 = 8                        ; R1=8\n  1: (7b) *(u64 *)(r10 -8) = r1         ; R1=8 R10=fp0 fp-8=8\n  2: (b7) r2 = 0                        ; R2=0\n  3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)          ; R2=8 R10=fp0 fp-8=mmmmmmmm\n  4: (bf) r3 = r10                      ; R3=fp0 R10=fp0\n  5: (0f) r3 += r2\n  mark_precise: frame0: last_idx 5 first_idx 0 subseq_idx -1\n  mark_precise: frame0: regs=r2 stack= before 4: (bf) r3 = r10\n  mark_precise: frame0: regs=r2 stack= before 3: (db) r2 = atomic64_fetch_add((u64 *)(r10 -8), r2)\n  mark_precise: frame0: regs= stack=-8 before 2: (b7) r2 = 0\n  mark_precise: frame0: regs= stack=-8 before 1: (7b) *(u64 *)(r10 -8) = r1\n  mark_precise: frame0: regs=r1 stack= before 0: (b7) r1 = 8\n  6: R2=8 R3=fp8\n  6: (b7) r0 = 0                        ; R0=0\n  7: (95) exit",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/179ee84a89114b854ac2dd1d293633a7f6c8dac1",
                "https://git.kernel.org/stable/c/7ffbe45b1d227e24659998a91cfd4c27af457e71",
                "https://git.kernel.org/stable/c/ea150ffa9fc9f78c5cf22e1f7b06b6d016b1017c"
            ],
            "timeline": [
                {
                    "at": "2026-05-01T15:16:44.770",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43009"
                }
            ]
        },
        {
            "id": "CVE-2026-43003",
            "vendor": "OpenStack",
            "product": "ironic-python-agent",
            "title": "ironic-python-agent vulnerability",
            "summary": "An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.",
            "updated_at": "2026-09-07T13:19:51.667",
            "published_at": "2026-05-01T09:16:17.440",
            "cvss": 8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 10.2.3 (semver); 11.0.0 through before 11.2.1 (semver); 11.3.0 through before 11.5.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-829",
            "what_happened": "An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading to code execution in the case of a malicious image.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugs.launchpad.net/ironic-python-agent/+bug/2148310",
                "https://github.com/openstack/ironic-python-agent/blob/236b33abffe6688afc39c21e351cc3889b3db2dd/ironic_python_agent/efi_utils.py#L134-L139",
                "http://www.openwall.com/lists/oss-security/2026/06/16/11",
                "https://access.redhat.com/errata/RHSA-2026:51038",
                "https://access.redhat.com/errata/RHSA-2026:57801",
                "https://access.redhat.com/errata/RHSA-2026:60446",
                "https://access.redhat.com/errata/RHSA-2026:60454",
                "https://access.redhat.com/security/cve/CVE-2026-43003",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2464306",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43003.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-01T09:16:17.440",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43003"
                }
            ]
        },
        {
            "id": "CVE-2026-43002",
            "vendor": "OpenStack",
            "product": "Horizon",
            "title": "Horizon vulnerability",
            "summary": "An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.",
            "updated_at": "2026-09-10T21:22:48.593",
            "published_at": "2026-05-05T17:17:04.920",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "25.6.0 through before 25.7.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 27,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-696",
            "what_happened": "An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "bugs.launchpad.net",
                    "author": "NVD reference",
                    "first_seen": "2026-05-05",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://bugs.launchpad.net/horizon/+bug/2150331"
                }
            ],
            "references": [
                "https://bugs.launchpad.net/horizon/+bug/2150331",
                "https://security.openstack.org/ossa/OSSA-2026-009.html",
                "https://www.openwall.com/lists/oss-security/2026/05/05/7"
            ],
            "timeline": [
                {
                    "at": "2026-05-05T17:17:04.920",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-43002"
                }
            ]
        },
        {
            "id": "CVE-2026-42978",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Use After Free in Microsoft",
            "summary": "Proof-of-concept exploit for CVE-2026-42978. CVSS 7.8.",
            "updated_at": "2026-09-11T22:10:10Z",
            "published_at": "2026-09-11T22:10:10Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 158,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Use After Free in Microsoft CVE-2026-42978",
                    "summary": "Use-After-Free and race condition in Windows Push Notifications (WpnService) with PoC research.",
                    "what_happened": "Use-After-Free and race condition in Windows Push Notifications (WpnService) with PoC research.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=BFC6879E-FC83-58F4-9A74-5DE915C4DB33",
                        "https://github.com/SyntaxMethod/CVE-2026-42978-PoC-Research"
                    ],
                    "repository": "Sploitus",
                    "author": "SyntaxMethod",
                    "first_seen": "2026-09-11T20:00:48",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=BFC6879E-FC83-58F4-9A74-5DE915C4DB33"
                },
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                },
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-54121-Certighost",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                },
                {
                    "title": "Exploit for Use After Free in Microsoft CVE-2026-42978",
                    "summary": "Use-After-Free and race condition in Windows Push Notifications (WpnService) with PoC research.",
                    "what_happened": "Use-After-Free and race condition in Windows Push Notifications (WpnService) with PoC research.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=BFC6879E-FC83-58F4-9A74-5DE915C4DB33",
                        "https://github.com/SyntaxMethod/CVE-2026-42978-PoC-Research"
                    ],
                    "repository": "SyntaxMethod/CVE-2026-42978-PoC-Research",
                    "author": "SyntaxMethod",
                    "first_seen": "2026-09-11T20:00:48",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://github.com/SyntaxMethod/CVE-2026-42978-PoC-Research"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T15:06:58+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2026-42978-PoC-Research exploit",
                    "summary": "Exploit for CVE-2026-42978. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GRIZZZER-CVE-2026-42978-POC-RESEARCH"
                },
                {
                    "title": "Exploit for CVE-2026-42978-PoC-Research",
                    "summary": "Local privilege escalation via use-after-free in Windows Push Notifications service (WpnService).",
                    "what_happened": "Local privilege escalation via use-after-free in Windows Push Notifications service (WpnService).",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "High",
                    "cwe": "CWE-362",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GRIZZZER-CVE-2026-42978-POC-RESEARCH",
                        "https://kitploit.com/zh/tools/github/grizzzer/cve-2026-42978-poc-research/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-05T15:44:03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/grizzzer/cve-2026-42978-poc-research/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=BFC6879E-FC83-58F4-9A74-5DE915C4DB33",
                "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost",
                "https://github.com/SyntaxMethod/CVE-2026-42978-PoC-Research",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GRIZZZER-CVE-2026-42978-POC-RESEARCH",
                "https://kitploit.com/zh/tools/github/grizzzer/cve-2026-42978-poc-research/"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:10:10Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=BFC6879E-FC83-58F4-9A74-5DE915C4DB33"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2026-42977",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-42978-PoC-Research",
            "summary": "Local privilege escalation via use-after-free in Windows Push Notifications service (WpnService).",
            "updated_at": "2026-09-05T13:44:03Z",
            "published_at": "2026-09-05T13:44:03Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 33,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "Local privilege escalation via use-after-free in Windows Push Notifications service (WpnService).",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-42978-PoC-Research",
                    "summary": "Local privilege escalation via use-after-free in Windows Push Notifications service (WpnService).",
                    "what_happened": "Local privilege escalation via use-after-free in Windows Push Notifications service (WpnService).",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "High",
                    "cwe": "CWE-362",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GRIZZZER-CVE-2026-42978-POC-RESEARCH",
                        "https://kitploit.com/zh/tools/github/grizzzer/cve-2026-42978-poc-research/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T15:44:03",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GRIZZZER-CVE-2026-42978-POC-RESEARCH"
                },
                {
                    "title": "Exploit for CVE-2026-42978-PoC-Research",
                    "summary": "Local privilege escalation via use-after-free in Windows Push Notifications service (WpnService).",
                    "what_happened": "Local privilege escalation via use-after-free in Windows Push Notifications service (WpnService).",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "High",
                    "cwe": "CWE-362",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GRIZZZER-CVE-2026-42978-POC-RESEARCH",
                        "https://kitploit.com/zh/tools/github/grizzzer/cve-2026-42978-poc-research/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-05T15:44:03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/grizzzer/cve-2026-42978-poc-research/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GRIZZZER-CVE-2026-42978-POC-RESEARCH",
                "https://kitploit.com/zh/tools/github/grizzzer/cve-2026-42978-poc-research/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T13:44:03Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GRIZZZER-CVE-2026-42978-POC-RESEARCH"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-42965",
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4.19",
            "title": "Red Hat OpenShift Container Platform 4.19 vulnerability",
            "summary": "A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metadata endpoint, leading to the disclosure of instance credentials and other sensitive metadata. This bypasses previous security measures for validating IP addresses.",
            "updated_at": "2026-09-09T15:17:06.990",
            "published_at": "2026-05-29T11:16:16.923",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metadata endpoint, leading to the disclosure of instance credentials and other sensitive metadata. This bypasses previous security measures for validating IP addresses.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:54583",
                "https://access.redhat.com/errata/RHSA-2026:54602",
                "https://access.redhat.com/errata/RHSA-2026:54770",
                "https://access.redhat.com/errata/RHSA-2026:57408",
                "https://access.redhat.com/security/cve/CVE-2026-42965",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2483184",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42965.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-29T11:16:16.923",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42965"
                }
            ]
        },
        {
            "id": "CVE-2026-42945",
            "vendor": "F5",
            "product": "NGINX Plus",
            "title": "NGINX Plus vulnerability",
            "summary": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
            "updated_at": "2026-09-10T13:20:09.723",
            "published_at": "2026-05-13T16:16:50.190",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "R36 through before R36 P4 (custom); R32 through before R32 P6 (custom); 0.6.27 through before 1.30.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 59,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-122",
            "what_happened": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/DepthFirstDisclosures/Nginx-Rift"
                }
            ],
            "references": [
                "https://my.f5.com/manage/s/article/K000161019",
                "https://depthfirst.com/nginx-rift",
                "https://github.com/DepthFirstDisclosures/Nginx-Rift",
                "https://access.redhat.com/errata/RHSA-2026:17417",
                "https://access.redhat.com/errata/RHSA-2026:17751",
                "https://access.redhat.com/errata/RHSA-2026:17752",
                "https://access.redhat.com/errata/RHSA-2026:17753",
                "https://access.redhat.com/errata/RHSA-2026:17790",
                "https://access.redhat.com/errata/RHSA-2026:17791",
                "https://access.redhat.com/errata/RHSA-2026:17792",
                "https://access.redhat.com/errata/RHSA-2026:17793",
                "https://access.redhat.com/errata/RHSA-2026:17794",
                "https://access.redhat.com/errata/RHSA-2026:18029",
                "https://access.redhat.com/errata/RHSA-2026:18041",
                "https://access.redhat.com/errata/RHSA-2026:18063",
                "https://access.redhat.com/errata/RHSA-2026:19159",
                "https://access.redhat.com/errata/RHSA-2026:19371",
                "https://access.redhat.com/errata/RHSA-2026:19372",
                "https://access.redhat.com/errata/RHSA-2026:19374",
                "https://access.redhat.com/errata/RHSA-2026:20442",
                "https://access.redhat.com/errata/RHSA-2026:20444",
                "https://access.redhat.com/errata/RHSA-2026:21275",
                "https://access.redhat.com/errata/RHSA-2026:22382",
                "https://access.redhat.com/errata/RHSA-2026:22383",
                "https://access.redhat.com/errata/RHSA-2026:22388",
                "https://access.redhat.com/errata/RHSA-2026:22389",
                "https://access.redhat.com/errata/RHSA-2026:22390",
                "https://access.redhat.com/errata/RHSA-2026:22393",
                "https://access.redhat.com/errata/RHSA-2026:22394",
                "https://access.redhat.com/errata/RHSA-2026:22396",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/security/cve/CVE-2026-42945",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2477116",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42945.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-13T16:16:50.190",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42945"
                }
            ]
        },
        {
            "id": "CVE-2026-42897",
            "vendor": "Microsoft",
            "product": "Microsoft",
            "title": "Microsoft Exchange Server Cross-Site Scripting Vulnerability",
            "summary": "Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.",
            "updated_at": "2026-09-15T10:56:34Z",
            "published_at": "2026-09-15T10:56:34Z",
            "cvss": 8.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-42897",
                    "summary": "CSS-Exchange HealthChecker fails to detect outbound URL rewrite rules, creating a blind spot.",
                    "what_happened": "CSS-Exchange HealthChecker fails to detect outbound URL rewrite rules, creating a blind spot.",
                    "cvss": 8.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ATIILLA-CVE-2026-42897",
                        "https://kitploit.com/ja/tools/github/atiilla/cve-2026-42897/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-12T11:27:38",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ATIILLA-CVE-2026-42897"
                },
                {
                    "title": "Exploit for CVE-2026-42897",
                    "summary": "CSS-Exchange HealthChecker fails to detect outbound URL rewrite rules, creating a blind spot.",
                    "what_happened": "CSS-Exchange HealthChecker fails to detect outbound URL rewrite rules, creating a blind spot.",
                    "cvss": 8.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ATIILLA-CVE-2026-42897",
                        "https://kitploit.com/ja/tools/github/atiilla/cve-2026-42897/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-12T11:27:38",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/atiilla/cve-2026-42897/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ATIILLA-CVE-2026-42897",
                "https://kitploit.com/ja/tools/github/atiilla/cve-2026-42897/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T10:56:34Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-42795",
            "vendor": "Gleam",
            "product": "Gleam",
            "title": "Gleam vulnerability",
            "summary": "Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball.\n\nThe file collection helpers (gleam_files, native_files, private_files) in compiler-cli/src/fs.rs use follow_links(true) when walking publishable directories such as src/ and priv/. The collected paths are added to the package archive via add_path_to_tar in compiler-cli/src/publish.rs without verifying that the resolved target remains within the project root. A symlink placed under a publishable directory will cause gleam export hex-tarball or gleam publish to embed the contents of the symlink target into the generated Hex package.\n\nAn attacker with write access to the project repository can place a symlink in src/ or priv/ pointing to an arbitrary file. When a maintainer or CI pipeline runs gleam publish or gleam export hex-tarball, local files readable by the publisher (such as secrets, tokens, or SSH keys) are silently embedded into the published package artifact.\n\nThis issue affects Gleam from 0.10.0-rc1 until 1.17.0.",
            "updated_at": "2026-09-08T01:17:30.483",
            "published_at": "2026-06-02T14:16:53.883",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.10.0-rc1 through before 1.17.0 (semver); c82a2d83bd0c06cafdc196820deb3f89a9b3ff7c through before 6435a5528b9ae0449e2f32be579641ec485f6866 (git); v0.10.0-rc1-elixir through before v1.17.0-elixir (other); v0.10.0-rc1-erlang through before v1.17.0-erlang (other); v0.10.0-rc1-node through before v1.17.0-node (other); v0.10.0-rc1-node-slim through before v1.17.0-node-slim (other); v0.10.0-rc1-elixir-slim through before v1.17.0-elixir-slim (other); v0.10.0-rc1-erlang-slim through before v1.17.0-erlang-slim (other); v0.10.0-rc1-erlang-alpine through before v1.17.0-erlang-alpine (other); v0.10.0-rc1-elixir-alpine through before v1.17.0-elixir-alpine (other); v0.10.0-rc1-node-alpine through before v1.17.0-node-alpine (other); v0.10.0-rc1-scratch through before v1.17.0-scratch (other)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-59",
            "what_happened": "Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball.\n\nThe file collection helpers (gleam_files, native_files, private_files) in compiler-cli/src/fs.rs use follow_links(true) when walking publishable directories such as src/ and priv/. The collected paths are added to the package archive via add_path_to_tar in compiler-cli/src/publish.rs without verifying that the resolved target remains within the project root. A symlink placed under a publishable directory will cause gleam export hex-tarball or gleam publish to embed the contents of the symlink target into the generated Hex package.\n\nAn attacker with write access to the project repository can place a symlink in src/ or priv/ pointing to an arbitrary file. When a maintainer or CI pipeline runs gleam publish or gleam export hex-tarball, local files readable by the publisher (such as secrets, tokens, or SSH keys) are silently embedded into the published package artifact.\n\nThis issue affects Gleam from 0.10.0-rc1 until 1.17.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-42795.html",
                "https://github.com/gleam-lang/gleam/commit/6435a5528b9ae0449e2f32be579641ec485f6866",
                "https://github.com/gleam-lang/gleam/security/advisories/GHSA-qhh5-fg4c-8gqc",
                "https://osv.dev/vulnerability/EEF-CVE-2026-42795"
            ],
            "timeline": [
                {
                    "at": "2026-06-02T14:16:53.883",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42795"
                }
            ]
        },
        {
            "id": "CVE-2026-42587",
            "vendor": "netty",
            "product": "netty",
            "title": "netty vulnerability",
            "summary": "Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.",
            "updated_at": "2026-09-11T13:18:03.143",
            "published_at": "2026-05-13T19:17:24.460",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.2.0.Alpha1, < 4.2.13.Final; < 4.1.133.Final",
            "fixed": "See vendor advisory",
            "source_count": 43,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpContentDecompressor accepts a maxAllocation parameter to limit decompression buffer size and prevent decompression bomb attacks. This limit is correctly enforced for gzip and deflate encodings via ZlibDecoder, but is silently ignored when the content encoding is br (Brotli), zstd, or snappy. An attacker can bypass the configured decompression limit by sending a compressed payload with Content-Encoding: br instead of Content-Encoding: gzip, causing unbounded memory allocation and out-of-memory denial of service. The same vulnerability exists in DelegatingDecompressorFrameListener for HTTP/2 connections. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/netty/netty/security/advisories/GHSA-f6hv-jmp6-3vwv"
                }
            ],
            "references": [
                "https://github.com/netty/netty/security/advisories/GHSA-f6hv-jmp6-3vwv",
                "https://access.redhat.com/errata/RHSA-2026:23808",
                "https://access.redhat.com/errata/RHSA-2026:24502",
                "https://access.redhat.com/errata/RHSA-2026:25123",
                "https://access.redhat.com/errata/RHSA-2026:28010",
                "https://access.redhat.com/errata/RHSA-2026:34608",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:37390",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:49700",
                "https://access.redhat.com/errata/RHSA-2026:50085",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-42587",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2477220",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42587.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-13T19:17:24.460",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42587"
                }
            ]
        },
        {
            "id": "CVE-2026-42584",
            "vendor": "netty",
            "product": "netty",
            "title": "netty vulnerability",
            "summary": "Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.",
            "updated_at": "2026-09-11T13:18:02.623",
            "published_at": "2026-05-13T19:17:24.043",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.2.0.Alpha1, < 4.2.13.Final; < 4.1.133.Final",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-444",
            "what_happened": "Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpClientCodec pairs each inbound response with an outbound request by queue.poll() once per response, including for 1xx. If the client pipelines GET then HEAD and the server sends 103, then 200 with GET body, then 200 for HEAD, the queue pairs HEAD with the first 200. The HEAD rule then skips reading that message’s body, so the GET entity bytes stay on the stream and the following 200 is parsed from the wrong offset. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/netty/netty/security/advisories/GHSA-57rv-r2g8-2cj3"
                }
            ],
            "references": [
                "https://github.com/netty/netty/security/advisories/GHSA-57rv-r2g8-2cj3",
                "https://access.redhat.com/errata/RHSA-2026:23808",
                "https://access.redhat.com/errata/RHSA-2026:24502",
                "https://access.redhat.com/errata/RHSA-2026:25123",
                "https://access.redhat.com/errata/RHSA-2026:28010",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:37390",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:49700",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-42584",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2477224",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42584.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-13T19:17:24.043",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42584"
                }
            ]
        },
        {
            "id": "CVE-2026-42581",
            "vendor": "netty",
            "product": "netty",
            "title": "netty vulnerability",
            "summary": "Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.",
            "updated_at": "2026-09-11T13:18:02.100",
            "published_at": "2026-05-13T19:17:23.627",
            "cvss": 5.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.2.0.Alpha1, < 4.2.13.Final; < 4.1.133.Final",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-444",
            "what_happened": "Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpObjectDecoder strips a conflicting Content-Length header when a request carries both Transfer-Encoding: chunked and Content-Length, but only for HTTP/1.1 messages. The guard is absent for HTTP/1.0. An attacker that sends an HTTP/1.0 request with both headers causes Netty to decode the body as chunked while leaving Content-Length intact in the forwarded HttpMessage. Any downstream proxy or handler that trusts Content-Length over Transfer-Encoding will disagree on message boundaries, enabling request smuggling. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/netty/netty/security/advisories/GHSA-xxqh-mfjm-7mv9"
                }
            ],
            "references": [
                "https://github.com/netty/netty/security/advisories/GHSA-xxqh-mfjm-7mv9",
                "https://access.redhat.com/errata/RHSA-2026:23808",
                "https://access.redhat.com/errata/RHSA-2026:24502",
                "https://access.redhat.com/errata/RHSA-2026:25123",
                "https://access.redhat.com/errata/RHSA-2026:28010",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:37390",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:49700",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-42581",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2477232",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42581.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-13T19:17:23.627",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42581"
                }
            ]
        },
        {
            "id": "CVE-2026-42578",
            "vendor": "netty",
            "product": "netty",
            "title": "netty vulnerability",
            "summary": "Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.",
            "updated_at": "2026-09-11T13:18:01.580",
            "published_at": "2026-05-13T19:17:23.210",
            "cvss": 2.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 4.2.0.Alpha1, < 4.2.13.Final; < 4.1.133.Final",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-113",
            "what_happened": "Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's HttpProxyHandler constructs HTTP CONNECT requests with header validation explicitly disabled. The newInitialMessage() method creates headers using DefaultHttpHeadersFactory.headersFactory().withValidation(false), then adds user-provided outboundHeaders without any CRLF validation. This allows an attacker who can influence the outbound headers to inject arbitrary HTTP headers into the CONNECT request sent to the proxy server. This vulnerability is fixed in 4.2.13.Final and 4.1.133.Final.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/netty/netty/security/advisories/GHSA-45q3-82m4-75jr"
                }
            ],
            "references": [
                "https://github.com/netty/netty/security/advisories/GHSA-45q3-82m4-75jr",
                "https://access.redhat.com/errata/RHSA-2026:23808",
                "https://access.redhat.com/errata/RHSA-2026:24502",
                "https://access.redhat.com/errata/RHSA-2026:25123",
                "https://access.redhat.com/errata/RHSA-2026:28010",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:37390",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:49700",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-42578",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2477226",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42578.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-13T19:17:23.210",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42578"
                }
            ]
        },
        {
            "id": "CVE-2026-42536",
            "vendor": "Apache Software Foundation",
            "product": "Apache HTTP Server",
            "title": "Exploit for Classic Buffer Overflow in Apache Http_Server CVE-2026-42536",
            "summary": "Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
            "updated_at": "2026-09-10T13:20:09.447",
            "published_at": "2026-06-08T16:16:39.263",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "2.4.0 through 2.4.67 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 43,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\n\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Classic Buffer Overflow in Apache Http_Server CVE-2026-42536",
                    "summary": "Heap overflow in Apache HTTP Server mod_xml2enc causing worker crash and DoS in 2.4.0-2.4.67.",
                    "what_happened": "Heap overflow in Apache HTTP Server mod_xml2enc causing worker crash and DoS in 2.4.0-2.4.67.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=92C0957A-F7CF-5B24-B6B3-B6B5F0C22EC9",
                        "https://github.com/erberkan/CVE-2026-42536-PoC"
                    ],
                    "repository": "Sploitus",
                    "author": "erberkan",
                    "first_seen": "2026-09-13T18:55:41",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=92C0957A-F7CF-5B24-B6B3-B6B5F0C22EC9"
                },
                {
                    "title": "Exploit for Classic Buffer Overflow in Apache Http_Server CVE-2026-42536",
                    "summary": "Heap overflow in Apache HTTP Server mod_xml2enc causing worker crash and DoS in 2.4.0-2.4.67.",
                    "what_happened": "Heap overflow in Apache HTTP Server mod_xml2enc causing worker crash and DoS in 2.4.0-2.4.67.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=92C0957A-F7CF-5B24-B6B3-B6B5F0C22EC9",
                        "https://github.com/erberkan/CVE-2026-42536-PoC"
                    ],
                    "repository": "erberkan/CVE-2026-42536-PoC",
                    "author": "erberkan",
                    "first_seen": "2026-09-13T18:55:41",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/erberkan/CVE-2026-42536-PoC"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=92C0957A-F7CF-5B24-B6B3-B6B5F0C22EC9",
                "https://github.com/erberkan/CVE-2026-42536-PoC",
                "https://httpd.apache.org/security/vulnerabilities_24.html",
                "http://www.openwall.com/lists/oss-security/2026/06/08/9",
                "https://access.redhat.com/errata/RHSA-2026:25042",
                "https://access.redhat.com/errata/RHSA-2026:34109",
                "https://access.redhat.com/errata/RHSA-2026:41906",
                "https://access.redhat.com/errata/RHSA-2026:42828",
                "https://access.redhat.com/errata/RHSA-2026:47046",
                "https://access.redhat.com/errata/RHSA-2026:53371",
                "https://access.redhat.com/errata/RHSA-2026:56868",
                "https://access.redhat.com/errata/RHSA-2026:56869",
                "https://access.redhat.com/errata/RHSA-2026:62165",
                "https://access.redhat.com/errata/RHSA-2026:66323",
                "https://access.redhat.com/security/cve/CVE-2026-42536",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2486411",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42536.json"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T16:55:41Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=92C0957A-F7CF-5B24-B6B3-B6B5F0C22EC9"
                },
                {
                    "at": "2026-06-08T16:16:39.263",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42536"
                }
            ],
            "enrichment_checked_at": "2026-09-13T22:05:27Z",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
            "id": "CVE-2026-42533",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.",
            "summary": "nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.",
            "updated_at": "2026-08-26T13:19:17Z",
            "published_at": "2026-08-26T13:19:17Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 907,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · imbas007/CVE-2026-42533",
                    "author": "imbas007",
                    "first_seen": "2026-07-27",
                    "last_seen": "2026-08-26T13:19:17Z",
                    "pushed_at": "2026-07-27T08:09:53Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 35,
                    "forks": 9,
                    "topics": [],
                    "title": "nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.",
                    "repository_description": "nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.",
                    "summary": "nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/imbas007/CVE-2026-42533"
                },
                {
                    "repository": "CVE-Intel · suominen/CVE-2026-42533",
                    "author": "suominen",
                    "first_seen": "2026-07-21",
                    "last_seen": "2026-08-25T15:47:29Z",
                    "pushed_at": "2026-08-25T15:32:41Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Shell",
                    "stars": 0,
                    "forks": 0,
                    "topics": [
                        "cve",
                        "nginx",
                        "security"
                    ],
                    "title": "Tracking the nginx CVE-2026-42533 map/regex capture-clobbering heap overflow",
                    "repository_description": "Tracking the nginx CVE-2026-42533 map/regex capture-clobbering heap overflow",
                    "summary": "Tracking the nginx CVE-2026-42533 map/regex capture-clobbering heap overflow",
                    "source": "CVE-Intel",
                    "url": "https://github.com/suominen/CVE-2026-42533"
                },
                {
                    "repository": "CVE-Intel · Leeyoonjoo/CVE-2026-42533",
                    "author": "Leeyoonjoo",
                    "first_seen": "2026-08-12",
                    "last_seen": "2026-08-17T10:30:32Z",
                    "pushed_at": "2026-08-17T10:30:28Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-42533",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Leeyoonjoo/CVE-2026-42533"
                },
                {
                    "repository": "CVE-Intel · 0xCyberstan/CVE-2026-42533-POC",
                    "author": "0xCyberstan",
                    "first_seen": "2026-08-05",
                    "last_seen": "2026-08-17T08:41:26Z",
                    "pushed_at": "2026-08-05T18:22:15Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 1,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE.",
                    "repository_description": "CVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE.",
                    "summary": "CVE-2026-42533: pre-auth nginx heap overflow and info leak from PCRE capture clobbering in the map/script engine, chained to RCE.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/0xCyberstan/CVE-2026-42533-POC"
                },
                {
                    "repository": "CVE-Intel · 0xCyberstan/CVE-2026-42533-Config-Scanner",
                    "author": "0xCyberstan",
                    "first_seen": "2026-07-04",
                    "last_seen": "2026-08-14T02:03:26Z",
                    "pushed_at": "2026-07-20T15:12:42Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 30,
                    "forks": 5,
                    "topics": [],
                    "title": "Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).",
                    "repository_description": "Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).",
                    "summary": "Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).",
                    "source": "CVE-Intel",
                    "url": "https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner"
                },
                {
                    "repository": "CVE-Intel · Daniyal48/ghostlock-vagrant-box",
                    "author": "Daniyal48",
                    "first_seen": "2026-07-20",
                    "last_seen": "2026-08-05T12:47:31Z",
                    "pushed_at": "2026-07-20T08:10:14Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "LPE",
                    "language": "",
                    "stars": 1,
                    "forks": 0,
                    "topics": [],
                    "title": "An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).",
                    "repository_description": "An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).",
                    "summary": "An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Daniyal48/ghostlock-vagrant-box"
                },
                {
                    "repository": "CVE-Intel · jelasin/CVE-2026-42533",
                    "author": "jelasin",
                    "first_seen": "2026-07-27",
                    "last_seen": "2026-07-29T11:51:08Z",
                    "pushed_at": "2026-07-29T10:27:50Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "C",
                    "stars": 0,
                    "forks": 1,
                    "topics": [],
                    "title": "CVE-2026-42533",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/jelasin/CVE-2026-42533"
                },
                {
                    "repository": "CVE-Intel · ChPratik/NGINX_2026_CVE_Bundle_CTI_Report",
                    "author": "ChPratik",
                    "first_seen": "2026-07-28",
                    "last_seen": "2026-07-28T07:35:17Z",
                    "pushed_at": "2026-07-28T07:32:31Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "Exploit",
                    "language": "",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533",
                    "repository_description": "Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533",
                    "summary": "Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533",
                    "source": "CVE-Intel",
                    "url": "https://github.com/ChPratik/NGINX_2026_CVE_Bundle_CTI_Report"
                },
                {
                    "repository": "FranklinF25/cve-2026-42533",
                    "author": "FranklinF25",
                    "first_seen": "2026-08-29",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-42533 repository",
                    "summary": "",
                    "url": "https://github.com/FranklinF25/cve-2026-42533"
                },
                {
                    "repository": "gagaltotal/CVE-2026-42533-nginx",
                    "author": "gagaltotal",
                    "first_seen": "2026-07-23",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-42533 Nginx",
                    "summary": "CVE-2026-42533 Nginx",
                    "url": "https://github.com/gagaltotal/CVE-2026-42533-nginx"
                },
                {
                    "repository": "seguridadentrerios/CVE-2026-42533",
                    "author": "seguridadentrerios",
                    "first_seen": "2026-07-22",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": "Vulnerabilidad en NGINX",
                    "summary": "Vulnerabilidad en NGINX",
                    "url": "https://github.com/seguridadentrerios/CVE-2026-42533"
                }
            ],
            "references": [
                "https://github.com/imbas007/CVE-2026-42533",
                "https://github.com/suominen/CVE-2026-42533",
                "https://github.com/Leeyoonjoo/CVE-2026-42533",
                "https://github.com/0xCyberstan/CVE-2026-42533-POC",
                "https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner",
                "https://github.com/Daniyal48/ghostlock-vagrant-box",
                "https://github.com/jelasin/CVE-2026-42533",
                "https://github.com/ChPratik/NGINX_2026_CVE_Bundle_CTI_Report",
                "https://github.com/FranklinF25/cve-2026-42533",
                "https://github.com/gagaltotal/CVE-2026-42533-nginx",
                "https://github.com/seguridadentrerios/CVE-2026-42533"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T13:19:17Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/imbas007/CVE-2026-42533"
                }
            ]
        },
        {
            "id": "CVE-2026-42508",
            "vendor": "golang.org/x/crypto",
            "product": "golang.org/x/crypto/ssh/knownhosts",
            "title": "golang.org/x/crypto/ssh/knownhosts vulnerability",
            "summary": "Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.",
            "updated_at": "2026-09-15T12:17:45.777",
            "published_at": "2026-05-22T04:16:25.440",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.52.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 49,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/781220",
                "https://go.dev/issue/79568",
                "https://groups.google.com/g/golang-announce/c/a082jnz-LvI",
                "https://pkg.go.dev/vuln/GO-2026-5021",
                "https://access.redhat.com/errata/RHSA-2026:23262",
                "https://access.redhat.com/errata/RHSA-2026:23264",
                "https://access.redhat.com/errata/RHSA-2026:26546",
                "https://access.redhat.com/errata/RHSA-2026:26547",
                "https://access.redhat.com/errata/RHSA-2026:35833",
                "https://access.redhat.com/errata/RHSA-2026:36648",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:36797",
                "https://access.redhat.com/errata/RHSA-2026:36808",
                "https://access.redhat.com/errata/RHSA-2026:37072",
                "https://access.redhat.com/errata/RHSA-2026:37123",
                "https://access.redhat.com/errata/RHSA-2026:37387",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41036",
                "https://access.redhat.com/errata/RHSA-2026:41064",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:43692",
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:47735",
                "https://access.redhat.com/errata/RHSA-2026:47737",
                "https://access.redhat.com/errata/RHSA-2026:49944",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:51288",
                "https://access.redhat.com/errata/RHSA-2026:52857",
                "https://access.redhat.com/errata/RHSA-2026:52910",
                "https://access.redhat.com/errata/RHSA-2026:54400",
                "https://access.redhat.com/errata/RHSA-2026:57194",
                "https://access.redhat.com/errata/RHSA-2026:59467",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:61314",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66022",
                "https://access.redhat.com/errata/RHSA-2026:66521",
                "https://access.redhat.com/security/cve/CVE-2026-42508",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2480688",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42508.json",
                "https://access.redhat.com/errata/RHSA-2026:67450"
            ],
            "timeline": [
                {
                    "at": "2026-05-22T04:16:25.440",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42508"
                }
            ]
        },
        {
            "id": "CVE-2026-42505",
            "vendor": "Go standard library",
            "product": "crypto/tls",
            "title": "crypto/tls vulnerability",
            "summary": "Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.",
            "updated_at": "2026-09-16T20:14:44.473",
            "published_at": "2026-07-08T17:17:21.497",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.25.12 (semver); 1.26.0-0 through before 1.26.5 (semver); 1.27.0-0 through before 1.27.0-rc.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-201",
            "what_happened": "Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/775960",
                "https://go.dev/issue/79282",
                "https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc",
                "https://pkg.go.dev/vuln/GO-2026-5856"
            ],
            "timeline": [
                {
                    "at": "2026-07-08T17:17:21.497",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42505"
                }
            ]
        },
        {
            "id": "CVE-2026-42499",
            "vendor": "Go standard library",
            "product": "net/mail",
            "title": "net/mail vulnerability",
            "summary": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.",
            "updated_at": "2026-09-15T12:17:44.543",
            "published_at": "2026-05-07T20:16:44.540",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.25.10 (semver); 1.26.0-0 through before 1.26.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 95,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1046",
            "what_happened": "Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/771520",
                "https://go.dev/issue/78987",
                "https://groups.google.com/g/golang-announce/c/qcCIEXso47M",
                "https://pkg.go.dev/vuln/GO-2026-4977",
                "https://access.redhat.com/errata/RHSA-2026:17713",
                "https://access.redhat.com/errata/RHSA-2026:17714",
                "https://access.redhat.com/errata/RHSA-2026:22112",
                "https://access.redhat.com/errata/RHSA-2026:22120",
                "https://access.redhat.com/errata/RHSA-2026:22121",
                "https://access.redhat.com/errata/RHSA-2026:33120",
                "https://access.redhat.com/errata/RHSA-2026:33123",
                "https://access.redhat.com/errata/RHSA-2026:33142",
                "https://access.redhat.com/errata/RHSA-2026:33150",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:34364",
                "https://access.redhat.com/errata/RHSA-2026:36319",
                "https://access.redhat.com/errata/RHSA-2026:36625",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:36797",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43038",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:43692",
                "https://access.redhat.com/errata/RHSA-2026:47952",
                "https://access.redhat.com/errata/RHSA-2026:49702",
                "https://access.redhat.com/errata/RHSA-2026:49712",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/errata/RHSA-2026:50843",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:54274",
                "https://access.redhat.com/errata/RHSA-2026:54283",
                "https://access.redhat.com/errata/RHSA-2026:54284",
                "https://access.redhat.com/errata/RHSA-2026:54285",
                "https://access.redhat.com/errata/RHSA-2026:54286",
                "https://access.redhat.com/errata/RHSA-2026:54287",
                "https://access.redhat.com/errata/RHSA-2026:54531",
                "https://access.redhat.com/errata/RHSA-2026:54552",
                "https://access.redhat.com/errata/RHSA-2026:54555",
                "https://access.redhat.com/errata/RHSA-2026:54583",
                "https://access.redhat.com/errata/RHSA-2026:54602",
                "https://access.redhat.com/errata/RHSA-2026:56340",
                "https://access.redhat.com/errata/RHSA-2026:56785",
                "https://access.redhat.com/errata/RHSA-2026:56789",
                "https://access.redhat.com/errata/RHSA-2026:56852",
                "https://access.redhat.com/errata/RHSA-2026:56854",
                "https://access.redhat.com/errata/RHSA-2026:56910",
                "https://access.redhat.com/errata/RHSA-2026:56912",
                "https://access.redhat.com/errata/RHSA-2026:57194",
                "https://access.redhat.com/errata/RHSA-2026:57482",
                "https://access.redhat.com/errata/RHSA-2026:57487",
                "https://access.redhat.com/errata/RHSA-2026:57649",
                "https://access.redhat.com/errata/RHSA-2026:57845",
                "https://access.redhat.com/errata/RHSA-2026:57914",
                "https://access.redhat.com/errata/RHSA-2026:59467",
                "https://access.redhat.com/errata/RHSA-2026:59830",
                "https://access.redhat.com/errata/RHSA-2026:59833",
                "https://access.redhat.com/errata/RHSA-2026:60018",
                "https://access.redhat.com/errata/RHSA-2026:60023",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:61253",
                "https://access.redhat.com/errata/RHSA-2026:62260",
                "https://access.redhat.com/errata/RHSA-2026:62406",
                "https://access.redhat.com/errata/RHSA-2026:62407",
                "https://access.redhat.com/errata/RHSA-2026:62753",
                "https://access.redhat.com/errata/RHSA-2026:62754",
                "https://access.redhat.com/errata/RHSA-2026:62803",
                "https://access.redhat.com/errata/RHSA-2026:63022",
                "https://access.redhat.com/errata/RHSA-2026:63163",
                "https://access.redhat.com/errata/RHSA-2026:63332",
                "https://access.redhat.com/security/cve/CVE-2026-42499",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2467809",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42499.json",
                "https://access.redhat.com/errata/RHSA-2026:51112",
                "https://access.redhat.com/errata/RHSA-2026:63636",
                "https://access.redhat.com/errata/RHSA-2026:64818",
                "https://access.redhat.com/errata/RHSA-2026:65116",
                "https://access.redhat.com/errata/RHSA-2026:65117",
                "https://access.redhat.com/errata/RHSA-2026:65153",
                "https://access.redhat.com/errata/RHSA-2026:65335",
                "https://access.redhat.com/errata/RHSA-2026:65336",
                "https://access.redhat.com/errata/RHSA-2026:65534",
                "https://access.redhat.com/errata/RHSA-2026:65886",
                "https://access.redhat.com/errata/RHSA-2026:65895",
                "https://access.redhat.com/errata/RHSA-2026:66327",
                "https://access.redhat.com/errata/RHSA-2026:66022",
                "https://access.redhat.com/errata/RHSA-2026:50319",
                "https://access.redhat.com/errata/RHSA-2026:50336",
                "https://access.redhat.com/errata/RHSA-2026:67148",
                "https://access.redhat.com/errata/RHSA-2026:67517"
            ],
            "timeline": [
                {
                    "at": "2026-05-07T20:16:44.540",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42499"
                }
            ]
        },
        {
            "id": "CVE-2026-42338",
            "vendor": "beaugunderson",
            "product": "ip-address",
            "title": "ip-address vulnerability",
            "summary": "ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.",
            "updated_at": "2026-09-11T13:17:59.167",
            "published_at": "2026-05-12T20:16:41.130",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 10.1.1",
            "fixed": "See vendor advisory",
            "source_count": 56,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emitted by the Address6 constructor for invalid input) can contain unescaped attacker-controlled content in one branch. An application that (1) passes untrusted input to Address6 and (2) renders the output of these methods, or the thrown error's parseMessage, as HTML (e.g. via innerHTML) is vulnerable to cross-site scripting. This vulnerability is fixed in 10.1.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g"
                }
            ],
            "references": [
                "https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g",
                "https://access.redhat.com/errata/RHSA-2026:33155",
                "https://access.redhat.com/errata/RHSA-2026:33160",
                "https://access.redhat.com/errata/RHSA-2026:33163",
                "https://access.redhat.com/errata/RHSA-2026:33173",
                "https://access.redhat.com/errata/RHSA-2026:33183",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:34374",
                "https://access.redhat.com/errata/RHSA-2026:35841",
                "https://access.redhat.com/errata/RHSA-2026:35842",
                "https://access.redhat.com/errata/RHSA-2026:35891",
                "https://access.redhat.com/errata/RHSA-2026:35892",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:39246",
                "https://access.redhat.com/errata/RHSA-2026:39868",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41947",
                "https://access.redhat.com/errata/RHSA-2026:44237",
                "https://access.redhat.com/errata/RHSA-2026:44263",
                "https://access.redhat.com/errata/RHSA-2026:44267",
                "https://access.redhat.com/errata/RHSA-2026:51200",
                "https://access.redhat.com/errata/RHSA-2026:52399",
                "https://access.redhat.com/errata/RHSA-2026:56928",
                "https://access.redhat.com/errata/RHSA-2026:57590",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:62335",
                "https://access.redhat.com/errata/RHSA-2026:62336",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-42338",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2476810",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42338.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-12T20:16:41.130",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42338"
                }
            ]
        },
        {
            "id": "CVE-2026-42264",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request. This issue has been patched in version 1.15.2.",
            "updated_at": "2026-09-11T13:17:58.653",
            "published_at": "2026-05-08T04:16:20.313",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.15.2",
            "fixed": "See vendor advisory",
            "source_count": 44,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-1321",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via direct property access without hasOwnProperty guards, making them exploitable as prototype pollution gadgets. When Object.prototype is polluted by another dependency in the same process, axios silently picks up these polluted values on every outbound HTTP request. This issue has been patched in version 1.15.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-08",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-q8qp-cvcw-x6jj"
                }
            ],
            "references": [
                "https://github.com/axios/axios/commit/47915144662f2733e6c051bdcb895a8c8f0586aa",
                "https://github.com/axios/axios/pull/10779",
                "https://github.com/axios/axios/releases/tag/v1.15.2",
                "https://github.com/axios/axios/security/advisories/GHSA-q8qp-cvcw-x6jj",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:33173",
                "https://access.redhat.com/errata/RHSA-2026:36207",
                "https://access.redhat.com/errata/RHSA-2026:37287",
                "https://access.redhat.com/errata/RHSA-2026:37288",
                "https://access.redhat.com/errata/RHSA-2026:37297",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:42142",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:62260",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-42264",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2467927",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42264.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-08T04:16:20.313",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42264"
                }
            ]
        },
        {
            "id": "CVE-2026-42198",
            "vendor": "pgjdbc",
            "product": "pgjdbc",
            "title": "pgjdbc vulnerability",
            "summary": "pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough value, the client spends an unbounded amount of CPU time inside PBKDF2 before authentication can fail. A single attempt ties up a CPU core. Repeated or concurrent attempts exhaust client CPU and can wedge connection pools. In affected versions, loginTimeout did not fully mitigate this problem. When loginTimeout expired, the caller could stop waiting, but the worker thread performing the connection attempt could continue running and burning CPU inside the SCRAM PBKDF2 computation. This issue has been patched in version 42.7.11.",
            "updated_at": "2026-09-11T13:17:58.347",
            "published_at": "2026-04-29T16:16:25.427",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 42.2.0, < 42.7.11",
            "fixed": "See vendor advisory",
            "source_count": 18,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough value, the client spends an unbounded amount of CPU time inside PBKDF2 before authentication can fail. A single attempt ties up a CPU core. Repeated or concurrent attempts exhaust client CPU and can wedge connection pools. In affected versions, loginTimeout did not fully mitigate this problem. When loginTimeout expired, the caller could stop waiting, but the worker thread performing the connection attempt could continue running and burning CPU inside the SCRAM PBKDF2 computation. This issue has been patched in version 42.7.11.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pgjdbc/pgjdbc/releases/tag/REL42.7.11",
                "https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-98qh-xjc8-98pq",
                "https://access.redhat.com/errata/RHSA-2026:19098",
                "https://access.redhat.com/errata/RHSA-2026:22304",
                "https://access.redhat.com/errata/RHSA-2026:24348",
                "https://access.redhat.com/errata/RHSA-2026:25030",
                "https://access.redhat.com/errata/RHSA-2026:52928",
                "https://access.redhat.com/errata/RHSA-2026:52929",
                "https://access.redhat.com/errata/RHSA-2026:52930",
                "https://access.redhat.com/errata/RHSA-2026:52978",
                "https://access.redhat.com/errata/RHSA-2026:54532",
                "https://access.redhat.com/errata/RHSA-2026:59277",
                "https://access.redhat.com/errata/RHSA-2026:59278",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-42198",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2463857",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42198.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-29T16:16:25.427",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42198"
                }
            ]
        },
        {
            "id": "CVE-2026-42167",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE",
            "summary": "CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE",
            "updated_at": "2026-08-24T22:00:00Z",
            "published_at": "2026-08-24T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 431,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "ProFTPD mod_sql post-authentication SQLi RCE",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52658",
                    "author": "youcef-!",
                    "first_seen": "2026-08-25",
                    "confidence": "High",
                    "title": "CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE",
                    "summary": "CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE",
                    "url": "https://www.exploit-db.com/exploits/52658",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "kaleth4/CVE-2026-42167",
                    "author": "kaleth4",
                    "first_seen": "2026-05-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-42167 repository",
                    "summary": "",
                    "url": "https://github.com/kaleth4/CVE-2026-42167"
                },
                {
                    "repository": "jimmexploit/CVE-2026-42167-PoC",
                    "author": "jimmexploit",
                    "first_seen": "2026-05-02",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": "ProFTPD SQL injection PoC",
                    "summary": "ProFTPD SQL injection PoC",
                    "url": "https://github.com/jimmexploit/CVE-2026-42167-PoC"
                },
                {
                    "repository": "efeanilarslan/CVE-2026-42167-Exploit",
                    "author": "efeanilarslan",
                    "first_seen": "2026-05-02",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Python exploit for CVE-2026-42167 (ProFTPD mod_sql). Features automated file scanning and timing-based blind data exfiltration.",
                    "summary": "Python exploit for CVE-2026-42167 (ProFTPD mod_sql). Features automated file scanning and timing-based blind data exfiltration.",
                    "url": "https://github.com/efeanilarslan/CVE-2026-42167-Exploit"
                },
                {
                    "repository": "Sl4cK0TH/CVE-2026-42167-PoC",
                    "author": "Sl4cK0TH",
                    "first_seen": "2026-05-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Pre-Auth RCE in ProFTPD via mod_sql is_escaped_text() bypass (CVE-2026-42167)",
                    "summary": "Pre-Auth RCE in ProFTPD via mod_sql is_escaped_text() bypass (CVE-2026-42167)",
                    "url": "https://github.com/Sl4cK0TH/CVE-2026-42167-PoC"
                },
                {
                    "repository": "ZeroPathAI/proftpd-CVE-2026-42167-poc",
                    "author": "ZeroPathAI",
                    "first_seen": "2026-04-28",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 24,
                    "title": "POCs to demonstrate CVE-2026-42167 in ProFTPD",
                    "summary": "POCs to demonstrate CVE-2026-42167 in ProFTPD",
                    "url": "https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc"
                },
                {
                    "repository": "dinosn/proftpd-CVE-2026-42167-analysis",
                    "author": "dinosn",
                    "first_seen": "2026-04-29",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 3,
                    "title": "Independent reproduction, code-level root-cause analysis, and realistic-exposure write-up for CVE-2026-42167 (ProFTPD mod_sql is_escaped_text() bypass).",
                    "summary": "Independent reproduction, code-level root-cause analysis, and realistic-exposure write-up for CVE-2026-42167 (ProFTPD mod_sql is_escaped_text() bypass).",
                    "url": "https://github.com/dinosn/proftpd-CVE-2026-42167-analysis"
                },
                {
                    "repository": "CXSecurity WLB-2026090006",
                    "author": "Anonymous",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "ProFTPD mod_sql post-authentication SQLi RCE",
                    "summary": "ProFTPD mod_sql post-authentication SQLi RCE",
                    "what_happened": "ProFTPD mod_sql post-authentication SQLi RCE",
                    "cvss": 0,
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "url": "https://cxsecurity.com/issue/WLB-2026090006",
                    "cwe": "Unknown"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52658",
                "https://github.com/kaleth4/CVE-2026-42167",
                "https://github.com/jimmexploit/CVE-2026-42167-PoC",
                "https://github.com/efeanilarslan/CVE-2026-42167-Exploit",
                "https://github.com/Sl4cK0TH/CVE-2026-42167-PoC",
                "https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc",
                "https://github.com/dinosn/proftpd-CVE-2026-42167-analysis",
                "https://cxsecurity.com/issue/WLB-2026090006"
            ],
            "timeline": [
                {
                    "at": "2026-08-24T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52658"
                }
            ]
        },
        {
            "id": "CVE-2026-42154",
            "vendor": "prometheus",
            "product": "prometheus",
            "title": "prometheus vulnerability",
            "summary": "Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.",
            "updated_at": "2026-09-10T13:20:07.003",
            "published_at": "2026-05-04T19:16:04.397",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.5.3; >= 3.6.0, < 3.11.3",
            "fixed": "See vendor advisory",
            "source_count": 52,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated attacker can send a small payload that causes a huge heap allocation per request. Under concurrent load this can exhaust available memory and crash the Prometheus process. This issue has been patched in versions 3.5.3 and 3.11.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/prometheus/prometheus/pull/18584",
                "https://github.com/prometheus/prometheus/pull/18585",
                "https://github.com/prometheus/prometheus/releases/tag/v3.11.3",
                "https://github.com/prometheus/prometheus/releases/tag/v3.5.3",
                "https://github.com/prometheus/prometheus/security/advisories/GHSA-8rm2-7qqf-34qm",
                "https://access.redhat.com/errata/RHSA-2026:25039",
                "https://access.redhat.com/errata/RHSA-2026:25245",
                "https://access.redhat.com/errata/RHSA-2026:29770",
                "https://access.redhat.com/errata/RHSA-2026:30651",
                "https://access.redhat.com/errata/RHSA-2026:34357",
                "https://access.redhat.com/errata/RHSA-2026:34359",
                "https://access.redhat.com/errata/RHSA-2026:34364",
                "https://access.redhat.com/errata/RHSA-2026:34794",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:40792",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:40970",
                "https://access.redhat.com/errata/RHSA-2026:40972",
                "https://access.redhat.com/errata/RHSA-2026:40974",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41030",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:42852",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:44235",
                "https://access.redhat.com/errata/RHSA-2026:44263",
                "https://access.redhat.com/errata/RHSA-2026:44622",
                "https://access.redhat.com/errata/RHSA-2026:47149",
                "https://access.redhat.com/errata/RHSA-2026:47728",
                "https://access.redhat.com/errata/RHSA-2026:47952",
                "https://access.redhat.com/errata/RHSA-2026:48699",
                "https://access.redhat.com/errata/RHSA-2026:50758",
                "https://access.redhat.com/errata/RHSA-2026:50843",
                "https://access.redhat.com/errata/RHSA-2026:53412",
                "https://access.redhat.com/errata/RHSA-2026:53413",
                "https://access.redhat.com/errata/RHSA-2026:53415",
                "https://access.redhat.com/errata/RHSA-2026:53530",
                "https://access.redhat.com/errata/RHSA-2026:54288",
                "https://access.redhat.com/errata/RHSA-2026:56340",
                "https://access.redhat.com/errata/RHSA-2026:56789",
                "https://access.redhat.com/errata/RHSA-2026:56912",
                "https://access.redhat.com/errata/RHSA-2026:59833",
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/security/cve/CVE-2026-42154",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2466505",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42154.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-04T19:16:04.397",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42154"
                }
            ]
        },
        {
            "id": "CVE-2026-42151",
            "vendor": "prometheus",
            "product": "prometheus",
            "title": "prometheus vulnerability",
            "summary": "Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.",
            "updated_at": "2026-09-10T13:20:06.057",
            "published_at": "2026-05-04T19:16:04.220",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 3.5.3; >= 3.6.0, < 3.11.3",
            "fixed": "See vendor advisory",
            "source_count": 56,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/prometheus/prometheus/pull/18587",
                "https://github.com/prometheus/prometheus/pull/18590",
                "https://github.com/prometheus/prometheus/releases/tag/v3.11.3",
                "https://github.com/prometheus/prometheus/releases/tag/v3.5.3",
                "https://github.com/prometheus/prometheus/security/advisories/GHSA-wg65-39gg-5wfj",
                "https://access.redhat.com/errata/RHSA-2026:25039",
                "https://access.redhat.com/errata/RHSA-2026:25245",
                "https://access.redhat.com/errata/RHSA-2026:25504",
                "https://access.redhat.com/errata/RHSA-2026:34357",
                "https://access.redhat.com/errata/RHSA-2026:34359",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:36797",
                "https://access.redhat.com/errata/RHSA-2026:37267",
                "https://access.redhat.com/errata/RHSA-2026:37271",
                "https://access.redhat.com/errata/RHSA-2026:37272",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:40768",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:40970",
                "https://access.redhat.com/errata/RHSA-2026:40972",
                "https://access.redhat.com/errata/RHSA-2026:40974",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41030",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:42852",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:44622",
                "https://access.redhat.com/errata/RHSA-2026:47149",
                "https://access.redhat.com/errata/RHSA-2026:47952",
                "https://access.redhat.com/errata/RHSA-2026:50843",
                "https://access.redhat.com/errata/RHSA-2026:50874",
                "https://access.redhat.com/errata/RHSA-2026:53412",
                "https://access.redhat.com/errata/RHSA-2026:53413",
                "https://access.redhat.com/errata/RHSA-2026:53415",
                "https://access.redhat.com/errata/RHSA-2026:53530",
                "https://access.redhat.com/errata/RHSA-2026:54288",
                "https://access.redhat.com/errata/RHSA-2026:54427",
                "https://access.redhat.com/errata/RHSA-2026:56340",
                "https://access.redhat.com/errata/RHSA-2026:57191",
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/errata/RHSA-2026:60387",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/errata/RHSA-2026:60389",
                "https://access.redhat.com/errata/RHSA-2026:60390",
                "https://access.redhat.com/errata/RHSA-2026:60391",
                "https://access.redhat.com/errata/RHSA-2026:60441",
                "https://access.redhat.com/errata/RHSA-2026:60477",
                "https://access.redhat.com/security/cve/CVE-2026-42151",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2466507",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42151.json",
                "https://access.redhat.com/errata/RHSA-2026:63103"
            ],
            "timeline": [
                {
                    "at": "2026-05-04T19:16:04.220",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42151"
                }
            ]
        },
        {
            "id": "CVE-2026-42044",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, invisible modification of all JSON API responses — including privilege escalation, balance manipulation, and authorization bypass. The default transformResponse function at lib/defaults/index.js:124 calls JSON.parse(data, this.parseReviver), where this is the merged config object. Because parseReviver is not present in Axios defaults, not validated by assertOptions, and not subject to any constraints, a polluted Object.prototype.parseReviver function is called for every key-value pair in every JSON response, allowing the attacker to selectively modify individual values while leaving the rest of the response intact. This vulnerability is fixed in 1.15.2.",
            "updated_at": "2026-09-10T13:20:05.490",
            "published_at": "2026-04-24T18:16:31.613",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.15.2",
            "fixed": "See vendor advisory",
            "source_count": 68,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-915",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution in the application's dependency tree to be escalated into surgical, invisible modification of all JSON API responses — including privilege escalation, balance manipulation, and authorization bypass. The default transformResponse function at lib/defaults/index.js:124 calls JSON.parse(data, this.parseReviver), where this is the merged config object. Because parseReviver is not present in Axios defaults, not validated by assertOptions, and not subject to any constraints, a polluted Object.prototype.parseReviver function is called for every key-value pair in every JSON response, allowing the attacker to selectively modify individual values while leaving the rest of the response intact. This vulnerability is fixed in 1.15.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-24",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-3w6x-2g7m-8v23"
                }
            ],
            "references": [
                "https://github.com/axios/axios/security/advisories/GHSA-3w6x-2g7m-8v23",
                "https://access.redhat.com/errata/RHSA-2026:16532",
                "https://access.redhat.com/errata/RHSA-2026:16534",
                "https://access.redhat.com/errata/RHSA-2026:16535",
                "https://access.redhat.com/errata/RHSA-2026:16542",
                "https://access.redhat.com/errata/RHSA-2026:17657",
                "https://access.redhat.com/errata/RHSA-2026:17699",
                "https://access.redhat.com/errata/RHSA-2026:19109",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:20338",
                "https://access.redhat.com/errata/RHSA-2026:20454",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:21338",
                "https://access.redhat.com/errata/RHSA-2026:21772",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22629",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24471",
                "https://access.redhat.com/errata/RHSA-2026:24473",
                "https://access.redhat.com/errata/RHSA-2026:24536",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:25041",
                "https://access.redhat.com/errata/RHSA-2026:25089",
                "https://access.redhat.com/errata/RHSA-2026:25271",
                "https://access.redhat.com/errata/RHSA-2026:25273",
                "https://access.redhat.com/errata/RHSA-2026:26214",
                "https://access.redhat.com/errata/RHSA-2026:26225",
                "https://access.redhat.com/errata/RHSA-2026:26232",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:34608",
                "https://access.redhat.com/errata/RHSA-2026:36107",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/security/cve/CVE-2026-42044",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2461624",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42044.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-24T18:16:31.613",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42044"
                }
            ]
        },
        {
            "id": "CVE-2026-42043",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vulnerability is due to an incomplete for CVE-2025-62718, This vulnerability is fixed in 1.15.1 and 0.31.1.",
            "updated_at": "2026-09-10T13:20:04.973",
            "published_at": "2026-04-24T18:16:31.457",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.15.1; < 0.31.1",
            "fixed": "See vendor advisory",
            "source_count": 67,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-183",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the NO_PROXY protection. This vulnerability is due to an incomplete for CVE-2025-62718, This vulnerability is fixed in 1.15.1 and 0.31.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-24",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-pmwg-cvhr-8vh7"
                }
            ],
            "references": [
                "https://github.com/axios/axios/security/advisories/GHSA-pmwg-cvhr-8vh7",
                "https://access.redhat.com/errata/RHSA-2026:14937",
                "https://access.redhat.com/errata/RHSA-2026:16476",
                "https://access.redhat.com/errata/RHSA-2026:16532",
                "https://access.redhat.com/errata/RHSA-2026:16534",
                "https://access.redhat.com/errata/RHSA-2026:16535",
                "https://access.redhat.com/errata/RHSA-2026:16542",
                "https://access.redhat.com/errata/RHSA-2026:16874",
                "https://access.redhat.com/errata/RHSA-2026:17468",
                "https://access.redhat.com/errata/RHSA-2026:17474",
                "https://access.redhat.com/errata/RHSA-2026:17657",
                "https://access.redhat.com/errata/RHSA-2026:17699",
                "https://access.redhat.com/errata/RHSA-2026:19109",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:21338",
                "https://access.redhat.com/errata/RHSA-2026:21772",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22619",
                "https://access.redhat.com/errata/RHSA-2026:22629",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24536",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:25041",
                "https://access.redhat.com/errata/RHSA-2026:25089",
                "https://access.redhat.com/errata/RHSA-2026:25271",
                "https://access.redhat.com/errata/RHSA-2026:25273",
                "https://access.redhat.com/errata/RHSA-2026:26214",
                "https://access.redhat.com/errata/RHSA-2026:26225",
                "https://access.redhat.com/errata/RHSA-2026:26232",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:48670",
                "https://access.redhat.com/security/cve/CVE-2026-42043",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2461626",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42043.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-24T18:16:31.457",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42043"
                }
            ]
        },
        {
            "id": "CVE-2026-42041",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys merge strategy, which uses JavaScript's in operator — an operator that inherently traverses the prototype chain. When Object.prototype.validateStatus is polluted with () => true, all HTTP status codes are accepted as success. This vulnerability is fixed in 1.15.1 and 0.31.1.",
            "updated_at": "2026-09-10T13:20:04.420",
            "published_at": "2026-04-24T18:16:31.133",
            "cvss": 4.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.15.1; < 0.31.1",
            "fixed": "See vendor advisory",
            "source_count": 67,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-287",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulnerable to a Prototype Pollution \"Gadget\" attack that allows any Object.prototype pollution to silently suppress all HTTP error responses (401, 403, 500, etc.), causing them to be treated as successful responses. This completely bypasses application-level authentication and error handling. The root cause is that validateStatus is the only config property using the mergeDirectKeys merge strategy, which uses JavaScript's in operator — an operator that inherently traverses the prototype chain. When Object.prototype.validateStatus is polluted with () => true, all HTTP status codes are accepted as success. This vulnerability is fixed in 1.15.1 and 0.31.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-24",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-w9j2-pvgh-6h63"
                }
            ],
            "references": [
                "https://github.com/axios/axios/security/advisories/GHSA-w9j2-pvgh-6h63",
                "https://access.redhat.com/errata/RHSA-2026:14937",
                "https://access.redhat.com/errata/RHSA-2026:16476",
                "https://access.redhat.com/errata/RHSA-2026:16532",
                "https://access.redhat.com/errata/RHSA-2026:16534",
                "https://access.redhat.com/errata/RHSA-2026:16535",
                "https://access.redhat.com/errata/RHSA-2026:16542",
                "https://access.redhat.com/errata/RHSA-2026:16874",
                "https://access.redhat.com/errata/RHSA-2026:17468",
                "https://access.redhat.com/errata/RHSA-2026:17474",
                "https://access.redhat.com/errata/RHSA-2026:17657",
                "https://access.redhat.com/errata/RHSA-2026:17699",
                "https://access.redhat.com/errata/RHSA-2026:19109",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:21338",
                "https://access.redhat.com/errata/RHSA-2026:21772",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22619",
                "https://access.redhat.com/errata/RHSA-2026:22629",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24536",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:25041",
                "https://access.redhat.com/errata/RHSA-2026:25089",
                "https://access.redhat.com/errata/RHSA-2026:25271",
                "https://access.redhat.com/errata/RHSA-2026:25273",
                "https://access.redhat.com/errata/RHSA-2026:26214",
                "https://access.redhat.com/errata/RHSA-2026:26225",
                "https://access.redhat.com/errata/RHSA-2026:26232",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/security/cve/CVE-2026-42041",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2461629",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42041.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-24T18:16:31.133",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42041"
                }
            ]
        },
        {
            "id": "CVE-2026-42039",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.31.1.",
            "updated_at": "2026-09-10T13:20:03.880",
            "published_at": "2026-04-24T18:16:30.827",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.15.1; < 0.31.1",
            "fixed": "See vendor advisory",
            "source_count": 69,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-674",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively walks nested objects with no depth limit, so a deeply nested value passed as request data crashes the Node.js process with a RangeError. This vulnerability is fixed in 1.15.1 and 0.31.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-24",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-62hf-57xw-28j9"
                }
            ],
            "references": [
                "https://github.com/axios/axios/security/advisories/GHSA-62hf-57xw-28j9",
                "https://access.redhat.com/errata/RHSA-2026:14937",
                "https://access.redhat.com/errata/RHSA-2026:16476",
                "https://access.redhat.com/errata/RHSA-2026:16532",
                "https://access.redhat.com/errata/RHSA-2026:16534",
                "https://access.redhat.com/errata/RHSA-2026:16535",
                "https://access.redhat.com/errata/RHSA-2026:16542",
                "https://access.redhat.com/errata/RHSA-2026:16874",
                "https://access.redhat.com/errata/RHSA-2026:17468",
                "https://access.redhat.com/errata/RHSA-2026:17474",
                "https://access.redhat.com/errata/RHSA-2026:17657",
                "https://access.redhat.com/errata/RHSA-2026:17699",
                "https://access.redhat.com/errata/RHSA-2026:19109",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:21338",
                "https://access.redhat.com/errata/RHSA-2026:21772",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22619",
                "https://access.redhat.com/errata/RHSA-2026:22629",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24473",
                "https://access.redhat.com/errata/RHSA-2026:24536",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:25041",
                "https://access.redhat.com/errata/RHSA-2026:25089",
                "https://access.redhat.com/errata/RHSA-2026:25271",
                "https://access.redhat.com/errata/RHSA-2026:25273",
                "https://access.redhat.com/errata/RHSA-2026:26214",
                "https://access.redhat.com/errata/RHSA-2026:26225",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:48085",
                "https://access.redhat.com/errata/RHSA-2026:48670",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/security/cve/CVE-2026-42039",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2461630",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42039.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-24T18:16:30.827",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42039"
                }
            ]
        },
        {
            "id": "CVE-2026-42033",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON response before the application sees it, or (b) fully hijack the underlying HTTP transport, gaining access to request credentials, headers, and body. The precondition is prototype pollution from a separate source in the same process. This vulnerability is fixed in 1.15.1 and 0.31.1.",
            "updated_at": "2026-09-10T13:20:03.087",
            "published_at": "2026-04-24T18:16:29.993",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.15.1; < 0.31.1",
            "fixed": "See vendor advisory",
            "source_count": 67,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-1321",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) silently intercept and modify every JSON response before the application sees it, or (b) fully hijack the underlying HTTP transport, gaining access to request credentials, headers, and body. The precondition is prototype pollution from a separate source in the same process. This vulnerability is fixed in 1.15.1 and 0.31.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-24",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-pf86-5x62-jrwf"
                }
            ],
            "references": [
                "https://github.com/axios/axios/security/advisories/GHSA-pf86-5x62-jrwf",
                "https://access.redhat.com/errata/RHSA-2026:14937",
                "https://access.redhat.com/errata/RHSA-2026:16476",
                "https://access.redhat.com/errata/RHSA-2026:16532",
                "https://access.redhat.com/errata/RHSA-2026:16534",
                "https://access.redhat.com/errata/RHSA-2026:16535",
                "https://access.redhat.com/errata/RHSA-2026:16542",
                "https://access.redhat.com/errata/RHSA-2026:16874",
                "https://access.redhat.com/errata/RHSA-2026:17468",
                "https://access.redhat.com/errata/RHSA-2026:17474",
                "https://access.redhat.com/errata/RHSA-2026:17657",
                "https://access.redhat.com/errata/RHSA-2026:17699",
                "https://access.redhat.com/errata/RHSA-2026:19109",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:21338",
                "https://access.redhat.com/errata/RHSA-2026:21772",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22619",
                "https://access.redhat.com/errata/RHSA-2026:22629",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24536",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:25041",
                "https://access.redhat.com/errata/RHSA-2026:25089",
                "https://access.redhat.com/errata/RHSA-2026:25271",
                "https://access.redhat.com/errata/RHSA-2026:25273",
                "https://access.redhat.com/errata/RHSA-2026:26214",
                "https://access.redhat.com/errata/RHSA-2026:26225",
                "https://access.redhat.com/errata/RHSA-2026:26232",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:48670",
                "https://access.redhat.com/security/cve/CVE-2026-42033",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2461607",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42033.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-24T18:16:29.993",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42033"
                }
            ]
        },
        {
            "id": "CVE-2026-42018",
            "vendor": "jfrog",
            "product": "artifactory",
            "title": "artifactory vulnerability",
            "summary": "JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.",
            "updated_at": "2026-09-12T04:16:33.587",
            "published_at": "2026-08-12T18:17:29.473",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "before 7.111.20 (custom); 7.117.0 through before 7.117.27 (custom); 7.125.0 through before 7.125.19 (custom); 7.133.0 through before 7.133.28 (custom); 7.146.0 through before 7.146.8 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
                "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42018",
                "https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T18:17:29.473",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42018"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-42016",
            "vendor": "jfrog",
            "product": "artifactory",
            "title": "artifactory vulnerability",
            "summary": "JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.",
            "updated_at": "2026-09-12T04:16:32.483",
            "published_at": "2026-07-27T20:16:39.613",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "before 7.133.11 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases",
                "https://docs.jfrog.com/releases/docs/jfrog-security-advisories",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-42016",
                "https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T20:16:39.613",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42016"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-42010",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.",
            "updated_at": "2026-09-15T12:17:43.750",
            "published_at": "2026-05-07T12:16:17.977",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0",
            "fixed": "See vendor advisory",
            "source_count": 58,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-170",
            "what_happened": "A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacker could exploit this by sending a specially crafted username, leading to an authentication bypass. This vulnerability allows an attacker to gain unauthorized access by circumventing the authentication process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:13274",
                "https://access.redhat.com/errata/RHSA-2026:20611",
                "https://access.redhat.com/errata/RHSA-2026:20612",
                "https://access.redhat.com/errata/RHSA-2026:20613",
                "https://access.redhat.com/errata/RHSA-2026:26319",
                "https://access.redhat.com/errata/RHSA-2026:26409",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:30004",
                "https://access.redhat.com/errata/RHSA-2026:30849",
                "https://access.redhat.com/errata/RHSA-2026:30850",
                "https://access.redhat.com/errata/RHSA-2026:32962",
                "https://access.redhat.com/errata/RHSA-2026:33125",
                "https://access.redhat.com/errata/RHSA-2026:34764",
                "https://access.redhat.com/errata/RHSA-2026:34788",
                "https://access.redhat.com/errata/RHSA-2026:34790",
                "https://access.redhat.com/errata/RHSA-2026:36004",
                "https://access.redhat.com/errata/RHSA-2026:36005",
                "https://access.redhat.com/errata/RHSA-2026:36006",
                "https://access.redhat.com/errata/RHSA-2026:40762",
                "https://access.redhat.com/errata/RHSA-2026:41921",
                "https://access.redhat.com/errata/RHSA-2026:56853",
                "https://access.redhat.com/errata/RHSA-2026:57483",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/errata/RHSA-2026:59831",
                "https://access.redhat.com/errata/RHSA-2026:60019",
                "https://access.redhat.com/errata/RHSA-2026:62409",
                "https://access.redhat.com/security/cve/CVE-2026-42010",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2467289",
                "https://www.gnutls.org/security-new.html#GNUTLS-SA-2026-04-29-4",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42010.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-07T12:16:17.977",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42010"
                }
            ]
        },
        {
            "id": "CVE-2026-41940",
            "vendor": "WebPros",
            "product": "cPanel & WHM and WP2 (WordPress Squared)",
            "title": "WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability",
            "summary": "WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
            "updated_at": "2026-08-26T10:03:34Z",
            "published_at": "2026-08-26T10:03:34Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1356,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52574",
                    "author": "nu11secur1ty",
                    "first_seen": "2026-05-26",
                    "confidence": "High",
                    "title": "cPanel - CRLF Injection",
                    "summary": "cPanel - CRLF Injection",
                    "url": "https://www.exploit-db.com/exploits/52574",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "CVE-Intel · Kagantua/cPanelWHM-AuthBypass",
                    "author": "Kagantua",
                    "first_seen": "2026-04-30",
                    "last_seen": "2026-08-26T10:03:34Z",
                    "pushed_at": "2026-04-30T07:05:29Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "Bypass",
                    "language": "",
                    "stars": 11,
                    "forks": 7,
                    "topics": [],
                    "title": "CVE-2026-41940",
                    "repository_description": "CVE-2026-41940",
                    "summary": "CVE-2026-41940",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Kagantua/cPanelWHM-AuthBypass",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-306",
                    "kev": true,
                    "epss": 0.98527,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-29",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · ynsmroztas/cPanelSniper",
                    "author": "ynsmroztas",
                    "first_seen": "2026-05-01",
                    "last_seen": "2026-08-25T23:35:54Z",
                    "pushed_at": "2026-05-01T12:10:32Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Injection",
                    "language": "Python",
                    "stars": 494,
                    "forks": 137,
                    "topics": [],
                    "title": "CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection",
                    "repository_description": "CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection",
                    "summary": "CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection",
                    "source": "CVE-Intel",
                    "url": "https://github.com/ynsmroztas/cPanelSniper",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-306",
                    "kev": true,
                    "epss": 0.98527,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-29",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · lanicer/cve-2026-41940-PoC",
                    "author": "lanicer",
                    "first_seen": "2026-08-19",
                    "last_seen": "2026-08-25T20:03:13Z",
                    "pushed_at": "2026-08-20T10:15:12Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Bypass",
                    "language": "Python",
                    "stars": 529,
                    "forks": 96,
                    "topics": [
                        "cpanel",
                        "cve",
                        "cve-2026-41940",
                        "cve-scanning",
                        "vulnerability-research"
                    ],
                    "title": "A cPanel and WHM authentication bypassing tool",
                    "repository_description": "A cPanel and WHM authentication bypassing tool",
                    "summary": "A cPanel and WHM authentication bypassing tool",
                    "source": "CVE-Intel",
                    "url": "https://github.com/lanicer/cve-2026-41940-PoC",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-306",
                    "kev": true,
                    "epss": 0.98527,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-29",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · Defacto-ridgepole254/CVE-2026-41940-Exploit-PoC",
                    "author": "Defacto-ridgepole254",
                    "first_seen": "2026-05-06",
                    "last_seen": "2026-08-25T04:00:53Z",
                    "pushed_at": "2026-08-25T04:00:07Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "Bypass",
                    "language": "",
                    "stars": 1,
                    "forks": 2,
                    "topics": [
                        "authentication-bypass",
                        "cpanel",
                        "cpanel-exploit",
                        "cve",
                        "cve-2026-41940",
                        "cve-exploit",
                        "exploit",
                        "poc"
                    ],
                    "title": "Test authentication bypass vulnerabilities in cPanel and WHM using this proof of concept exploit tool written in Go.",
                    "repository_description": "Test authentication bypass vulnerabilities in cPanel and WHM using this proof of concept exploit tool written in Go.",
                    "summary": "Test authentication bypass vulnerabilities in cPanel and WHM using this proof of concept exploit tool written in Go.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Defacto-ridgepole254/CVE-2026-41940-Exploit-PoC",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-306",
                    "kev": true,
                    "epss": 0.98527,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-29",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · t4xo/CVE-2026-41940",
                    "author": "t4xo",
                    "first_seen": "2026-08-22",
                    "last_seen": "2026-08-22T11:37:37Z",
                    "pushed_at": "2026-08-22T11:37:08Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Zero-Day",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "ts zeroday exp made by nullsec white team",
                    "repository_description": "ts zeroday exp made by nullsec white team",
                    "summary": "ts zeroday exp made by nullsec white team",
                    "source": "CVE-Intel",
                    "url": "https://github.com/t4xo/CVE-2026-41940",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-306",
                    "kev": true,
                    "epss": 0.98527,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-29",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · XsanFlip/poc-cpanel-cve-2026-41940",
                    "author": "XsanFlip",
                    "first_seen": "2026-05-01",
                    "last_seen": "2026-08-20T10:42:34Z",
                    "pushed_at": "2026-05-01T16:35:37Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "Python",
                    "stars": 64,
                    "forks": 11,
                    "topics": [],
                    "title": "poc-cpanel-cve-2026-41940",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/XsanFlip/poc-cpanel-cve-2026-41940",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-306",
                    "kev": true,
                    "epss": 0.98527,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-29",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · ilmndwntr/CVE-2026-41940-MASS-EXPLOIT",
                    "author": "ilmndwntr",
                    "first_seen": "2026-04-30",
                    "last_seen": "2026-08-19T23:06:41Z",
                    "pushed_at": "2026-04-30T12:11:51Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 14,
                    "forks": 9,
                    "topics": [],
                    "title": "CVE-2026-41940 SUPPORT SINGLE & MASS SCAN EXPLOIT",
                    "repository_description": "CVE-2026-41940 SUPPORT SINGLE & MASS SCAN EXPLOIT",
                    "summary": "CVE-2026-41940 SUPPORT SINGLE & MASS SCAN EXPLOIT",
                    "source": "CVE-Intel",
                    "url": "https://github.com/ilmndwntr/CVE-2026-41940-MASS-EXPLOIT",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-306",
                    "kev": true,
                    "epss": 0.98527,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-29",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · murrez/CVE-2026-41940",
                    "author": "murrez",
                    "first_seen": "2026-05-06",
                    "last_seen": "2026-08-18T14:03:34Z",
                    "pushed_at": "2026-05-12T06:28:19Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Bypass",
                    "language": "Python",
                    "stars": 5,
                    "forks": 1,
                    "topics": [],
                    "title": "PoC for CVE-2026-41940: WHM/cPanel authentication bypass chain (Python 2.7). For authorized security research and testing only.",
                    "repository_description": "PoC for CVE-2026-41940: WHM/cPanel authentication bypass chain (Python 2.7). For authorized security research and testing only.",
                    "summary": "PoC for CVE-2026-41940: WHM/cPanel authentication bypass chain (Python 2.7). For authorized security research and testing only.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/murrez/CVE-2026-41940",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-306",
                    "kev": true,
                    "epss": 0.98527,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-29",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "keithbennedict/CVE-2026-41940-Linux",
                    "author": "keithbennedict",
                    "first_seen": "2026-08-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-41940 repository",
                    "summary": "",
                    "url": "https://github.com/keithbennedict/CVE-2026-41940-Linux"
                },
                {
                    "repository": "ZildanZ/CVE-2026-41940",
                    "author": "ZildanZ",
                    "first_seen": "2026-05-05",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-41940 repository",
                    "summary": "",
                    "url": "https://github.com/ZildanZ/CVE-2026-41940"
                },
                {
                    "repository": "CerberusMrXi/cPanel-WHM-CVE-2026-41940-auth-bypass-exploit",
                    "author": "CerberusMrXi",
                    "first_seen": "2026-07-26",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 3,
                    "title": "Critical authentication bypass exploit for cPanel/WHM CVE-2026-41940. Leverages CRLF injection in cpsrvd daemon to gain root WHM access without credentials. Includes version detection, verbose logging, proxy support, JSON reporting, and post-exploitation account enumeration. For authorized security testing only.",
                    "summary": "Critical authentication bypass exploit for cPanel/WHM CVE-2026-41940. Leverages CRLF injection in cpsrvd daemon to gain root WHM access without credentials. Includes version detection, verbose logging, proxy support, JSON reporting, and post-exploitation account enumeration. For authorized security testing only.",
                    "url": "https://github.com/CerberusMrXi/cPanel-WHM-CVE-2026-41940-auth-bypass-exploit"
                },
                {
                    "repository": "AnotherSec/CVE-2026-41940",
                    "author": "AnotherSec",
                    "first_seen": "2026-07-24",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": "CVE-2026-41940",
                    "summary": "CVE-2026-41940",
                    "url": "https://github.com/AnotherSec/CVE-2026-41940"
                },
                {
                    "repository": "razureink/cve-2026-41940-cpanel_authbypass_reproduction",
                    "author": "razureink",
                    "first_seen": "2026-07-23",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": "CVE Reproduction: cve-2026-41940-cpanel_authbypass_reproduction",
                    "summary": "CVE Reproduction: cve-2026-41940-cpanel_authbypass_reproduction",
                    "url": "https://github.com/razureink/cve-2026-41940-cpanel_authbypass_reproduction"
                },
                {
                    "repository": "oguz-kagan-akar/CVE-2026-41940-analysis",
                    "author": "oguz-kagan-akar",
                    "first_seen": "2026-07-18",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Technical analysis of the cPanel/WHM auth bypass",
                    "summary": "Technical analysis of the cPanel/WHM auth bypass",
                    "url": "https://github.com/oguz-kagan-akar/CVE-2026-41940-analysis"
                },
                {
                    "repository": "tc4dy/CVE-2026-41940-PoC-Exploit",
                    "author": "tc4dy",
                    "first_seen": "2026-05-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 10,
                    "title": "🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy, custom UA, keep-alive, retries, SSL verify, colored output, file save support. ⚡ Advanced PoC for pentesters. ",
                    "summary": "🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy, custom UA, keep-alive, retries, SSL verify, colored output, file save support. ⚡ Advanced PoC for pentesters. ",
                    "url": "https://github.com/tc4dy/CVE-2026-41940-PoC-Exploit"
                },
                {
                    "repository": "george1-adel/CVE-2026-41940_exploit",
                    "author": "george1-adel",
                    "first_seen": "2026-05-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 2,
                    "title": "CVE-2026-41940 repository",
                    "summary": "",
                    "url": "https://github.com/george1-adel/CVE-2026-41940_exploit"
                },
                {
                    "repository": "0xgh057r3c0n/CVE-2026-41940",
                    "author": "0xgh057r3c0n",
                    "first_seen": "2026-09-05",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": "cPanel & WHM - Authentication Bypass via Session-File CRLF Injection",
                    "summary": "cPanel & WHM - Authentication Bypass via Session-File CRLF Injection",
                    "url": "https://github.com/0xgh057r3c0n/CVE-2026-41940"
                },
                {
                    "title": "Exploit for CVE-2026-0073-Android-ADBD-bypass-POC_zh_CN",
                    "summary": "Type confusion in adbd TLS auth via EVP_PKEY_cmp gives unauthenticated shell on Android 14+.",
                    "what_happened": "Type confusion in adbd TLS auth via EVP_PKEY_cmp gives unauthenticated shell on Android 14+.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CTN-QVO-CVE-2026-0073-ANDROID-ADBD-BYPASS-POC_ZH_CN",
                        "https://kitploit.com/ru/tools/github/ctn-qvo/cve-2026-0073-android-adbd-bypass-poc_zh_cn/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-27T03:58:19",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CTN-QVO-CVE-2026-0073-ANDROID-ADBD-BYPASS-POC_ZH_CN"
                },
                {
                    "title": "Exploit for CVE-2026-0073-Android-ADBD-bypass-POC_zh_CN",
                    "summary": "Type confusion in adbd TLS auth via EVP_PKEY_cmp gives unauthenticated shell on Android 14+.",
                    "what_happened": "Type confusion in adbd TLS auth via EVP_PKEY_cmp gives unauthenticated shell on Android 14+.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CTN-QVO-CVE-2026-0073-ANDROID-ADBD-BYPASS-POC_ZH_CN",
                        "https://kitploit.com/ru/tools/github/ctn-qvo/cve-2026-0073-android-adbd-bypass-poc_zh_cn/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-27T03:58:19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/ctn-qvo/cve-2026-0073-android-adbd-bypass-poc_zh_cn/"
                },
                {
                    "title": "Exploit for Missing Authentication for Critical Function in Cpanel CVE-2026-41940",
                    "summary": "Unauthenticated CRLF injection in cPanel & WHM session files enables root-level access.",
                    "what_happened": "Unauthenticated CRLF injection in cPanel & WHM session files enables root-level access.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=C54881F0-FC7D-56AD-8132-6F5B0BF6166F",
                        "https://github.com/ctdal/cve-2026-41940-PoC"
                    ],
                    "repository": "Sploitus",
                    "author": "ctdal",
                    "first_seen": "2026-09-16T13:50:03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=C54881F0-FC7D-56AD-8132-6F5B0BF6166F"
                },
                {
                    "title": "Exploit for Missing Authentication for Critical Function in Cpanel CVE-2026-41940",
                    "summary": "Unauthenticated CRLF injection in cPanel & WHM session files enables root-level access.",
                    "what_happened": "Unauthenticated CRLF injection in cPanel & WHM session files enables root-level access.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=C54881F0-FC7D-56AD-8132-6F5B0BF6166F",
                        "https://github.com/ctdal/cve-2026-41940-PoC"
                    ],
                    "repository": "ctdal/cve-2026-41940-PoC",
                    "author": "ctdal",
                    "first_seen": "2026-09-16T13:50:03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ctdal/cve-2026-41940-PoC"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52574",
                "https://github.com/Kagantua/cPanelWHM-AuthBypass",
                "https://github.com/ynsmroztas/cPanelSniper",
                "https://github.com/lanicer/cve-2026-41940-PoC",
                "https://github.com/Defacto-ridgepole254/CVE-2026-41940-Exploit-PoC",
                "https://github.com/t4xo/CVE-2026-41940",
                "https://github.com/XsanFlip/poc-cpanel-cve-2026-41940",
                "https://github.com/ilmndwntr/CVE-2026-41940-MASS-EXPLOIT",
                "https://github.com/murrez/CVE-2026-41940",
                "https://github.com/keithbennedict/CVE-2026-41940-Linux",
                "https://github.com/ZildanZ/CVE-2026-41940",
                "https://github.com/CerberusMrXi/cPanel-WHM-CVE-2026-41940-auth-bypass-exploit",
                "https://github.com/AnotherSec/CVE-2026-41940",
                "https://github.com/razureink/cve-2026-41940-cpanel_authbypass_reproduction",
                "https://github.com/oguz-kagan-akar/CVE-2026-41940-analysis",
                "https://github.com/tc4dy/CVE-2026-41940-PoC-Exploit",
                "https://github.com/george1-adel/CVE-2026-41940_exploit",
                "https://github.com/0xgh057r3c0n/CVE-2026-41940",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CTN-QVO-CVE-2026-0073-ANDROID-ADBD-BYPASS-POC_ZH_CN",
                "https://kitploit.com/ru/tools/github/ctn-qvo/cve-2026-0073-android-adbd-bypass-poc_zh_cn/",
                "https://sploitus.com/exploit?id=C54881F0-FC7D-56AD-8132-6F5B0BF6166F",
                "https://github.com/ctdal/cve-2026-41940-PoC"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T10:03:34Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "epss": 0.98527,
            "severity": "CRITICAL",
            "metadata_source": "CNA",
            "cve_status": "Analyzed",
            "cve_published_at": "2026-04-29",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-41674",
            "vendor": "xmldom",
            "product": "xmldom",
            "title": "xmldom vulnerability",
            "summary": "xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatim without any escaping or validation. When these fields are set programmatically to attacker-controlled strings, XMLSerializer.serializeToString can produce output where the DOCTYPE declaration is terminated early and arbitrary markup appears outside it. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.",
            "updated_at": "2026-09-10T13:20:02.843",
            "published_at": "2026-05-07T04:16:33.433",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "xmldom <= 0.6.0; @xmldom/xmldom >= 0.9.0, < 0.9.10; @xmldom/xmldom < 0.8.13",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-91",
            "what_happened": "xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior, the package serializes DocumentType node fields (internalSubset, publicId, systemId) verbatim without any escaping or validation. When these fields are set programmatically to attacker-controlled strings, XMLSerializer.serializeToString can produce output where the DOCTYPE declaration is terminated early and arbitrary markup appears outside it. This issue has been patched in versions @xmldom/xmldom versions 0.9.10 and 0.8.13.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/xmldom/xmldom/commit/372008f9ae0e20fd69f761c7b79e202598267314",
                "https://github.com/xmldom/xmldom/releases/tag/0.8.13",
                "https://github.com/xmldom/xmldom/releases/tag/0.9.10",
                "https://github.com/xmldom/xmldom/security/advisories/GHSA-f6ww-3ggp-fr8h",
                "https://access.redhat.com/errata/RHSA-2026:20034",
                "https://access.redhat.com/errata/RHSA-2026:21338",
                "https://access.redhat.com/errata/RHSA-2026:21703",
                "https://access.redhat.com/errata/RHSA-2026:26234",
                "https://access.redhat.com/security/cve/CVE-2026-41674",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2467620",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41674.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-07T04:16:33.433",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41674"
                }
            ]
        },
        {
            "id": "CVE-2026-41607",
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift",
            "title": "Apache Thrift vulnerability",
            "summary": "Out-of-bounds Read vulnerability in Apache Thrift.\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.",
            "updated_at": "2026-09-07T13:19:32.093",
            "published_at": "2026-04-28T10:16:03.573",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.23.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "Out-of-bounds Read vulnerability in Apache Thrift.\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql",
                "http://www.openwall.com/lists/oss-security/2026/04/28/2",
                "https://access.redhat.com/errata/RHSA-2026:14885",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/security/cve/CVE-2026-41607",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2463412",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41607.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-28T10:16:03.573",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41607"
                }
            ]
        },
        {
            "id": "CVE-2026-41606",
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift",
            "title": "Apache Thrift vulnerability",
            "summary": "Uncontrolled Recursion vulnerability in Apache Thrift.\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.",
            "updated_at": "2026-09-07T13:19:31.500",
            "published_at": "2026-04-28T10:16:03.463",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.23.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-674",
            "what_happened": "Uncontrolled Recursion vulnerability in Apache Thrift.\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql",
                "http://www.openwall.com/lists/oss-security/2026/04/28/3",
                "https://access.redhat.com/errata/RHSA-2026:14885",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/security/cve/CVE-2026-41606",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2463408",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41606.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-28T10:16:03.463",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41606"
                }
            ]
        },
        {
            "id": "CVE-2026-41605",
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift",
            "title": "Apache Thrift vulnerability",
            "summary": "Integer Overflow or Wraparound vulnerability in Apache Thrift.\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.",
            "updated_at": "2026-09-07T13:19:30.917",
            "published_at": "2026-04-28T10:16:03.350",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.23.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "Integer Overflow or Wraparound vulnerability in Apache Thrift.\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql",
                "http://www.openwall.com/lists/oss-security/2026/04/28/4",
                "https://access.redhat.com/errata/RHSA-2026:14885",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/security/cve/CVE-2026-41605",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2463418",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41605.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-28T10:16:03.350",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41605"
                }
            ]
        },
        {
            "id": "CVE-2026-41604",
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift",
            "title": "Apache Thrift vulnerability",
            "summary": "Out-of-bounds Read vulnerability in Apache Thrift.\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.",
            "updated_at": "2026-09-07T13:19:30.323",
            "published_at": "2026-04-28T10:16:03.230",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.23.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "Out-of-bounds Read vulnerability in Apache Thrift.\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql",
                "http://www.openwall.com/lists/oss-security/2026/04/28/5",
                "https://access.redhat.com/errata/RHSA-2026:14885",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/security/cve/CVE-2026-41604",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2463416",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41604.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-28T10:16:03.230",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41604"
                }
            ]
        },
        {
            "id": "CVE-2026-41602",
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift",
            "title": "Apache Thrift vulnerability",
            "summary": "Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.",
            "updated_at": "2026-09-07T13:19:29.703",
            "published_at": "2026-04-28T10:16:03.000",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.23.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql",
                "http://www.openwall.com/lists/oss-security/2026/04/28/6",
                "https://access.redhat.com/errata/RHSA-2026:14162",
                "https://access.redhat.com/errata/RHSA-2026:14885",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:24503",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:25273",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/security/cve/CVE-2026-41602",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2463407",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41602.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-28T10:16:03.000",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41602"
                }
            ]
        },
        {
            "id": "CVE-2026-41456",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Bludit CMS  3.20.0 - Reflected Cross-Site Scripting",
            "summary": "Bludit CMS  3.20.0 - Reflected Cross-Site Scripting",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 98,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52678",
                    "author": "Ranjit Kumar Singh",
                    "first_seen": "2026-09-02",
                    "confidence": "High",
                    "title": "Bludit CMS  3.20.0 - Reflected Cross-Site Scripting",
                    "summary": "Bludit CMS  3.20.0 - Reflected Cross-Site Scripting",
                    "url": "https://www.exploit-db.com/exploits/52678",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52678"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52678"
                }
            ]
        },
        {
            "id": "CVE-2026-41453",
            "vendor": "krayin",
            "product": "laravel-crm",
            "title": "laravel-crm vulnerability",
            "summary": "Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw() call in LeadDataGrid.php. Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, including user credential hashes, CRM records, and application configuration data.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-08-03T17:16:37.213",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.2.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw() call in LeadDataGrid.php. Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, including user credential hashes, CRM records, and application configuration data.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/krayin/laravel-crm/commit/2a3724cb7e9e65ab98f2b42c8ca2c98dede48f62",
                "https://github.com/krayin/laravel-crm/releases/tag/v2.2.4",
                "https://jivasecurity.com/writeups/krayin-lead-datagrid-sqli-cve-2026-41453",
                "https://www.vulncheck.com/advisories/krayin-crm-blind-sql-injection-via-leaddatagrid-php-rotten-lead-parameter"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T17:16:37.213",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41453"
                }
            ]
        },
        {
            "id": "CVE-2026-41452",
            "vendor": "krayin",
            "product": "laravel-crm",
            "title": "laravel-crm vulnerability",
            "summary": "Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-08-03T17:16:37.047",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.2.0 (semver); 2.2.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arbitrary name, email, and password values to the admin-config-setup endpoint, which performs an unauthenticated updateOrInsert targeting the hardcoded administrator user ID, enabling full administrative access to all CRM data.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jivasecurity.com/writeups/krayin-installer-bypass-account-takeover-cve-2026-41452",
                "https://www.vulncheck.com/advisories/krayin-crm-missing-authentication-via-install-api-admin-config-setup"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T17:16:37.047",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41452"
                }
            ]
        },
        {
            "id": "CVE-2026-41242",
            "vendor": "protobufjs",
            "product": "protobuf.js",
            "title": "protobuf.js vulnerability",
            "summary": "protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the \"type\" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.",
            "updated_at": "2026-09-07T13:19:28.157",
            "published_at": "2026-04-18T17:16:13.983",
            "cvss": 9.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 7.5.5; >= 8.0.0-experimental, < 8.0.1",
            "fixed": "See vendor advisory",
            "source_count": 47,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the \"type\" fields of protobuf definitions, which will then execute during object decoding using that definition. Versions 8.0.1 and 7.5.5 patch the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-18",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-xq3m-2v4x-88gg"
                }
            ],
            "references": [
                "https://github.com/protobufjs/protobuf.js/commit/535df444ac060243722ac5d672db205e5c531d75",
                "https://github.com/protobufjs/protobuf.js/commit/ff7b2afef8754837cc6dc64c864cd111ab477956",
                "https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.5.5",
                "https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.0.1",
                "https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-xq3m-2v4x-88gg",
                "https://access.redhat.com/errata/RHSA-2026:21338",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:26234",
                "https://access.redhat.com/errata/RHSA-2026:37275",
                "https://access.redhat.com/errata/RHSA-2026:62260",
                "https://access.redhat.com/security/cve/CVE-2026-41242",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2459442",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41242.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-18T17:16:13.983",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41242"
                }
            ]
        },
        {
            "id": "CVE-2026-41096",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
            "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
            "updated_at": "2026-09-11T22:10:10Z",
            "published_at": "2026-09-11T22:10:10Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 85,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                },
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-54121-Certighost",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:10:10Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2026-41089",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
            "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
            "updated_at": "2026-09-11T22:10:10Z",
            "published_at": "2026-09-11T22:10:10Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 357,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                },
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-54121-Certighost",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                },
                {
                    "repository": "CVE-Intel · opensource-arrozconpollo191/CVE-2026-41089-Netlogon-RCE",
                    "author": "opensource-arrozconpollo191",
                    "first_seen": "2026-07-22",
                    "last_seen": "2026-08-26T10:49:49Z",
                    "pushed_at": "2026-08-26T10:45:32Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 1,
                    "forks": 0,
                    "topics": [
                        "active-directory",
                        "buffer-overflow",
                        "cve-2026-41089",
                        "cybersecurity",
                        "domain-controller",
                        "exploit-poc",
                        "netlogon-rce",
                        "privilege-escalation"
                    ],
                    "title": "Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.",
                    "repository_description": "Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.",
                    "summary": "Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/opensource-arrozconpollo191/CVE-2026-41089-Netlogon-RCE",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-121",
                    "kev": false,
                    "epss": 0.79622,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-05-12",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · HydraSoft/CVE-2026-41089-Netlogon-RCE",
                    "author": "HydraSoft",
                    "first_seen": "2026-07-21",
                    "last_seen": "2026-08-25T08:21:52Z",
                    "pushed_at": "2026-08-24T04:08:31Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "HTML",
                    "stars": 16,
                    "forks": 10,
                    "topics": [
                        "active-directory",
                        "buffer-overflow",
                        "cve-2026-41089",
                        "cybersecurity",
                        "domain-controller",
                        "exploit-poc",
                        "netlogon-rce",
                        "privilege-escalation"
                    ],
                    "title": "Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon service affecting Domain Controllers.",
                    "repository_description": "Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon service affecting Domain Controllers.",
                    "summary": "Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows Netlogon service affecting Domain Controllers.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/HydraSoft/CVE-2026-41089-Netlogon-RCE",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-121",
                    "kev": false,
                    "epss": 0.79622,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-05-12",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · 0xABCD01/CVE-2026-41089",
                    "author": "0xABCD01",
                    "first_seen": "2026-06-01",
                    "last_seen": "2026-08-24T15:13:49Z",
                    "pushed_at": "2026-06-02T08:30:55Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "Python",
                    "stars": 212,
                    "forks": 66,
                    "topics": [
                        "buffer-overflow",
                        "cldap",
                        "cve",
                        "cve-2026-41089",
                        "exploit",
                        "poc",
                        "vulnerability",
                        "vulnerability-detection"
                    ],
                    "title": "CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)",
                    "repository_description": "CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)",
                    "summary": "CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)",
                    "source": "CVE-Intel",
                    "url": "https://github.com/0xABCD01/CVE-2026-41089",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-121",
                    "kev": false,
                    "epss": 0.79622,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-05-12",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · ADScanPro/CVE-2026-41089-LongLogon",
                    "author": "ADScanPro",
                    "first_seen": "2026-06-03",
                    "last_seen": "2026-08-24T10:19:22Z",
                    "pushed_at": "2026-06-04T08:11:31Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "DoS",
                    "language": "Python",
                    "stars": 14,
                    "forks": 2,
                    "topics": [
                        "active-directory",
                        "buffer-overflow",
                        "cldap",
                        "cve",
                        "cve-2026-41089",
                        "domain-controller",
                        "exploit",
                        "longlogon"
                    ],
                    "title": "CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overflow. The binary-verified analysis the public PoCs got wrong.",
                    "repository_description": "CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overflow. The binary-verified analysis the public PoCs got wrong.",
                    "summary": "CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overflow. The binary-verified analysis the public PoCs got wrong.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/ADScanPro/CVE-2026-41089-LongLogon",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-121",
                    "kev": false,
                    "epss": 0.79622,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-05-12",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · jelasin/CVE-2026-41089",
                    "author": "jelasin",
                    "first_seen": "2026-06-01",
                    "last_seen": "2026-08-19T02:55:49Z",
                    "pushed_at": "2026-06-01T04:26:51Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "PoC",
                    "language": "",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)",
                    "repository_description": "CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)",
                    "summary": "CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)",
                    "source": "CVE-Intel",
                    "url": "https://github.com/jelasin/CVE-2026-41089",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-121",
                    "kev": false,
                    "epss": 0.79622,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-05-12",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · 0xBlackash/CVE-2026-41089",
                    "author": "0xBlackash",
                    "first_seen": "2026-06-02",
                    "last_seen": "2026-07-28T01:21:31Z",
                    "pushed_at": "2026-06-05T00:49:43Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 10,
                    "forks": 1,
                    "topics": [],
                    "title": "CVE-2026-41089",
                    "repository_description": "CVE-2026-41089",
                    "summary": "CVE-2026-41089",
                    "source": "CVE-Intel",
                    "url": "https://github.com/0xBlackash/CVE-2026-41089",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-121",
                    "kev": false,
                    "epss": 0.79622,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-05-12",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · hnytgl/CVE-2026-41089",
                    "author": "hnytgl",
                    "first_seen": "2026-06-03",
                    "last_seen": "2026-06-28T06:42:18Z",
                    "pushed_at": "2026-06-24T12:48:34Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 14,
                    "forks": 13,
                    "topics": [],
                    "title": "CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞，单包即可崩溃 lsass.exe，导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。",
                    "repository_description": "CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞，单包即可崩溃 lsass.exe，导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。",
                    "summary": "CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞，单包即可崩溃 lsass.exe，导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。",
                    "source": "CVE-Intel",
                    "url": "https://github.com/hnytgl/CVE-2026-41089",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-121",
                    "kev": false,
                    "epss": 0.79622,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-05-12",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · hnytgl/CVE-2026-41089-Detector",
                    "author": "hnytgl",
                    "first_seen": "2026-06-03",
                    "last_seen": "2026-06-06T07:20:55Z",
                    "pushed_at": "2026-06-06T06:19:46Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 0,
                    "forks": 1,
                    "topics": [],
                    "title": "这是一个用于防御巡检的 CVE-2026-41089 检测脚本。该漏洞是 Microsoft 在 2026 年 5 月安全更新中披露的 Windows Netlogon 远程代码执行漏洞。",
                    "repository_description": "这是一个用于防御巡检的 CVE-2026-41089 检测脚本。该漏洞是 Microsoft 在 2026 年 5 月安全更新中披露的 Windows Netlogon 远程代码执行漏洞。",
                    "summary": "这是一个用于防御巡检的 CVE-2026-41089 检测脚本。该漏洞是 Microsoft 在 2026 年 5 月安全更新中披露的 Windows Netlogon 远程代码执行漏洞。",
                    "source": "CVE-Intel",
                    "url": "https://github.com/hnytgl/CVE-2026-41089-Detector",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-121",
                    "kev": false,
                    "epss": 0.79622,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-05-12",
                    "cve_status": "Analyzed"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost",
                "https://github.com/opensource-arrozconpollo191/CVE-2026-41089-Netlogon-RCE",
                "https://github.com/HydraSoft/CVE-2026-41089-Netlogon-RCE",
                "https://github.com/0xABCD01/CVE-2026-41089",
                "https://github.com/ADScanPro/CVE-2026-41089-LongLogon",
                "https://github.com/jelasin/CVE-2026-41089",
                "https://github.com/0xBlackash/CVE-2026-41089",
                "https://github.com/hnytgl/CVE-2026-41089",
                "https://github.com/hnytgl/CVE-2026-41089-Detector"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:10:10Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                }
            ],
            "epss": 0.79622,
            "severity": "CRITICAL",
            "metadata_source": "NIST",
            "cve_status": "Analyzed",
            "cve_published_at": "2026-05-12",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2026-40984",
            "vendor": "Spring",
            "product": "Micrometer",
            "title": "Micrometer vulnerability",
            "summary": "In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.\n\nAffected versions:\nmicrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17.\nmicrometer-jetty11 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.\nmicrometer-jetty12 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.",
            "updated_at": "2026-09-11T13:17:58.057",
            "published_at": "2026-06-09T05:16:34.780",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.16.0 through before 1.16.5.1 (custom); 1.15.0 through before 1.15.11.1 (custom); 1.14.0 through before 1.14.16 (custom); 1.13.0 through before 1.13.19 (custom); 1.9.0 through before 1.9.18 (custom); 1.16.0 through before 1.16.6 (custom); 1.15.0 through before 1.15.11. (custom); 1.14.0 through before 1.14.15.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.\n\nAffected versions:\nmicrometer-core 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18; 1.9.0 through 1.9.17.\nmicrometer-jetty11 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.\nmicrometer-jetty12 1.16.0 through 1.16.5; 1.15.0 through 1.15.11; 1.14.0 through 1.14.15; 1.13.0 through 1.13.18.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://spring.io/security/cve-2026-40984",
                "https://access.redhat.com/errata/RHSA-2026:36839",
                "https://access.redhat.com/errata/RHSA-2026:37390",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:50848",
                "https://access.redhat.com/errata/RHSA-2026:50849",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:62260",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-40984",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2486716",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40984.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-09T05:16:34.780",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40984"
                }
            ]
        },
        {
            "id": "CVE-2026-40983",
            "vendor": "Spring",
            "product": "Micrometer",
            "title": "Micrometer vulnerability",
            "summary": "In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.\n\nAffected versions:\nMicrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.",
            "updated_at": "2026-09-11T13:17:57.763",
            "published_at": "2026-06-09T05:16:34.653",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.16.0 through before 1.16.5.1 (custom); 1.15.0 through before 1.15.11.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.\n\nAffected versions:\nMicrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://spring.io/security/cve-2026-40983",
                "https://access.redhat.com/errata/RHSA-2026:36839",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:50848",
                "https://access.redhat.com/errata/RHSA-2026:50849",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:62260",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/security/cve/CVE-2026-40983",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2486697",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40983.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-09T05:16:34.653",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40983"
                }
            ]
        },
        {
            "id": "CVE-2026-40895",
            "vendor": "follow-redirects",
            "product": "follow-redirects",
            "title": "follow-redirects vulnerability",
            "summary": "follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization, proxy-authorization, and cookie headers (matched by regex at index.js). Any custom authentication header (e.g., X-API-Key, X-Auth-Token, Api-Key, Token) is forwarded verbatim to the redirect target. This vulnerability is fixed in 1.16.0.",
            "updated_at": "2026-09-10T13:20:02.063",
            "published_at": "2026-04-21T21:16:44.337",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.16.0",
            "fixed": "See vendor advisory",
            "source_count": 48,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization, proxy-authorization, and cookie headers (matched by regex at index.js). Any custom authentication header (e.g., X-API-Key, X-Auth-Token, Api-Key, Token) is forwarded verbatim to the redirect target. This vulnerability is fixed in 1.16.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/follow-redirects/follow-redirects/security/advisories/GHSA-r4q5-vmmm-2653",
                "https://access.redhat.com/errata/RHSA-2026:13826",
                "https://access.redhat.com/errata/RHSA-2026:14937",
                "https://access.redhat.com/errata/RHSA-2026:16476",
                "https://access.redhat.com/errata/RHSA-2026:16532",
                "https://access.redhat.com/errata/RHSA-2026:16534",
                "https://access.redhat.com/errata/RHSA-2026:16535",
                "https://access.redhat.com/errata/RHSA-2026:16542",
                "https://access.redhat.com/errata/RHSA-2026:16874",
                "https://access.redhat.com/errata/RHSA-2026:17657",
                "https://access.redhat.com/errata/RHSA-2026:17699",
                "https://access.redhat.com/errata/RHSA-2026:17789",
                "https://access.redhat.com/errata/RHSA-2026:19109",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:21338",
                "https://access.redhat.com/errata/RHSA-2026:21772",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22629",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24536",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:24766",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:25271",
                "https://access.redhat.com/errata/RHSA-2026:25273",
                "https://access.redhat.com/errata/RHSA-2026:26010",
                "https://access.redhat.com/errata/RHSA-2026:27004",
                "https://access.redhat.com/errata/RHSA-2026:27044",
                "https://access.redhat.com/errata/RHSA-2026:27063",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:40768",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:44235",
                "https://access.redhat.com/errata/RHSA-2026:44263",
                "https://access.redhat.com/errata/RHSA-2026:44267",
                "https://access.redhat.com/errata/RHSA-2026:47728",
                "https://access.redhat.com/errata/RHSA-2026:48699",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/security/cve/CVE-2026-40895",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2460297",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40895.json",
                "https://access.redhat.com/errata/RHSA-2026:65126"
            ],
            "timeline": [
                {
                    "at": "2026-04-21T21:16:44.337",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40895"
                }
            ]
        },
        {
            "id": "CVE-2026-40542",
            "vendor": "Apache Software Foundation",
            "product": "Apache HttpClient",
            "title": "Apache HttpClient vulnerability",
            "summary": "Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.",
            "updated_at": "2026-09-07T13:19:25.860",
            "published_at": "2026-04-22T08:16:12.780",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5.6 through before 5.6.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 16,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-304",
            "what_happened": "Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://lists.apache.org/thread/tfmgv86xr0z1y096vs3z0y315t1v3o97",
                "http://www.openwall.com/lists/oss-security/2026/04/22/5",
                "https://access.redhat.com/errata/RHSA-2026:60239",
                "https://access.redhat.com/errata/RHSA-2026:60246",
                "https://access.redhat.com/errata/RHSA-2026:60247",
                "https://access.redhat.com/errata/RHSA-2026:60248",
                "https://access.redhat.com/errata/RHSA-2026:60249",
                "https://access.redhat.com/errata/RHSA-2026:60250",
                "https://access.redhat.com/errata/RHSA-2026:60251",
                "https://access.redhat.com/errata/RHSA-2026:60252",
                "https://access.redhat.com/errata/RHSA-2026:60254",
                "https://access.redhat.com/errata/RHSA-2026:60256",
                "https://access.redhat.com/errata/RHSA-2026:60259",
                "https://access.redhat.com/security/cve/CVE-2026-40542",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2460518",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40542.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-22T08:16:12.780",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40542"
                }
            ]
        },
        {
            "id": "CVE-2026-40476",
            "vendor": "webonyx",
            "product": "graphql-php",
            "title": "graphql-php vulnerability",
            "summary": "graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same response name. An attacker can send a query with thousands of repeated identical fields, causing excessive CPU usage during validation before execution begins. This is not mitigated by existing QueryDepth or QueryComplexity rules. This issue has been fixed in version 15.31.5.",
            "updated_at": "2026-09-14T20:16:43.900",
            "published_at": "2026-04-17T22:16:33.360",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 15.31.5",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-407",
            "what_happened": "graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation rule performs O(n²) pairwise comparisons of fields sharing the same response name. An attacker can send a query with thousands of repeated identical fields, causing excessive CPU usage during validation before execution begins. This is not mitigated by existing QueryDepth or QueryComplexity rules. This issue has been fixed in version 15.31.5.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/webonyx/graphql-php/releases/tag/v15.31.5",
                "https://github.com/webonyx/graphql-php/security/advisories/GHSA-68jq-c3rv-pcrr",
                "http://www.openwall.com/lists/oss-security/2026/09/14/26"
            ],
            "timeline": [
                {
                    "at": "2026-04-17T22:16:33.360",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40476"
                }
            ]
        },
        {
            "id": "CVE-2026-40192",
            "vendor": "python-pillow",
            "product": "Pillow",
            "title": "Pillow vulnerability",
            "summary": "Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.",
            "updated_at": "2026-09-10T13:20:01.390",
            "published_at": "2026-04-15T23:16:10.053",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 10.3.0, < 12.2.0",
            "fixed": "See vendor advisory",
            "source_count": 35,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file could cause unbounded memory consumption, leading to denial of service (OOM crash or severe performance degradation). If users are unable to immediately upgrade, they should only open specific image formats, excluding FITS, as a workaround.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628",
                "https://github.com/python-pillow/Pillow/pull/9521",
                "https://github.com/python-pillow/Pillow/security/advisories/GHSA-whj4-6x5x-4v2j",
                "https://pillow.readthedocs.io/en/stable/releasenotes/12.2.0.html#prevent-fits-decompression-bomb",
                "https://access.redhat.com/errata/RHSA-2026:16008",
                "https://access.redhat.com/errata/RHSA-2026:16009",
                "https://access.redhat.com/errata/RHSA-2026:16030",
                "https://access.redhat.com/errata/RHSA-2026:16174",
                "https://access.redhat.com/errata/RHSA-2026:17609",
                "https://access.redhat.com/errata/RHSA-2026:17611",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22629",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24761",
                "https://access.redhat.com/errata/RHSA-2026:24762",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:24866",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:27076",
                "https://access.redhat.com/errata/RHSA-2026:34365",
                "https://access.redhat.com/errata/RHSA-2026:34366",
                "https://access.redhat.com/errata/RHSA-2026:34368",
                "https://access.redhat.com/errata/RHSA-2026:37275",
                "https://access.redhat.com/errata/RHSA-2026:57387",
                "https://access.redhat.com/errata/RHSA-2026:61627",
                "https://access.redhat.com/errata/RHSA-2026:61628",
                "https://access.redhat.com/errata/RHSA-2026:61629",
                "https://access.redhat.com/security/cve/CVE-2026-40192",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2458856",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40192.json",
                "https://access.redhat.com/errata/RHSA-2026:65126"
            ],
            "timeline": [
                {
                    "at": "2026-04-15T23:16:10.053",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40192"
                }
            ]
        },
        {
            "id": "CVE-2026-40175",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.",
            "updated_at": "2026-09-07T13:19:23.890",
            "published_at": "2026-04-10T20:16:22.800",
            "cvss": 4.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.15.0; < 0.31.0; before V3.1.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 88,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-113",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound requests. This vulnerability is fixed in 1.15.0 and 0.3.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx"
                }
            ],
            "references": [
                "https://github.com/axios/axios/commit/03cdfc99e8db32a390e12128208b6778492cee9c",
                "https://github.com/axios/axios/commit/363185461b90b1b78845dc8a99a1f103d9b122a1",
                "https://github.com/axios/axios/pull/10660",
                "https://github.com/axios/axios/pull/10688",
                "https://github.com/axios/axios/releases/tag/v0.31.0",
                "https://github.com/axios/axios/releases/tag/v1.15.0",
                "https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx",
                "https://github.com/axios/axios/pull/10660#issuecomment-4224168081",
                "https://access.redhat.com/errata/RHSA-2026:10104",
                "https://access.redhat.com/errata/RHSA-2026:10153",
                "https://access.redhat.com/errata/RHSA-2026:10172",
                "https://access.redhat.com/errata/RHSA-2026:10175",
                "https://access.redhat.com/errata/RHSA-2026:11414",
                "https://access.redhat.com/errata/RHSA-2026:13542",
                "https://access.redhat.com/errata/RHSA-2026:13548",
                "https://access.redhat.com/errata/RHSA-2026:13571",
                "https://access.redhat.com/errata/RHSA-2026:13826",
                "https://access.redhat.com/errata/RHSA-2026:14774",
                "https://access.redhat.com/errata/RHSA-2026:14937",
                "https://access.redhat.com/errata/RHSA-2026:15091",
                "https://access.redhat.com/errata/RHSA-2026:16874",
                "https://access.redhat.com/errata/RHSA-2026:17468",
                "https://access.redhat.com/errata/RHSA-2026:17474",
                "https://access.redhat.com/errata/RHSA-2026:17657",
                "https://access.redhat.com/errata/RHSA-2026:17699",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:20041",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:24762",
                "https://access.redhat.com/errata/RHSA-2026:25041",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:53661",
                "https://access.redhat.com/errata/RHSA-2026:53676",
                "https://access.redhat.com/errata/RHSA-2026:53735",
                "https://access.redhat.com/errata/RHSA-2026:53736",
                "https://access.redhat.com/errata/RHSA-2026:53752",
                "https://access.redhat.com/errata/RHSA-2026:53778",
                "https://access.redhat.com/errata/RHSA-2026:53789",
                "https://access.redhat.com/errata/RHSA-2026:53799",
                "https://access.redhat.com/errata/RHSA-2026:53835",
                "https://access.redhat.com/errata/RHSA-2026:53840",
                "https://access.redhat.com/errata/RHSA-2026:8483",
                "https://access.redhat.com/errata/RHSA-2026:8484",
                "https://access.redhat.com/errata/RHSA-2026:8490",
                "https://access.redhat.com/errata/RHSA-2026:8491",
                "https://access.redhat.com/errata/RHSA-2026:8493",
                "https://access.redhat.com/errata/RHSA-2026:8499",
                "https://access.redhat.com/errata/RHSA-2026:8500",
                "https://access.redhat.com/errata/RHSA-2026:8501",
                "https://access.redhat.com/errata/RHSA-2026:9742",
                "https://access.redhat.com/security/cve/CVE-2026-40175",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2457432",
                "https://cert-portal.siemens.com/productcert/html/ssa-876049.html",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40175.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-10T20:16:22.800",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40175"
                }
            ]
        },
        {
            "id": "CVE-2026-39987",
            "vendor": "Marimo",
            "product": "Marimo",
            "title": "Marimo Remote Code Execution Vulnerability",
            "summary": "Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 96,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52673",
                    "author": "Jason Bernier",
                    "first_seen": "2026-09-02",
                    "confidence": "High",
                    "title": "Marimo  0.20.4 - RCE",
                    "summary": "Marimo  0.20.4 - RCE",
                    "url": "https://www.exploit-db.com/exploits/52673",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52673"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-39892",
            "vendor": "pyca",
            "product": "cryptography",
            "title": "cryptography vulnerability",
            "summary": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.",
            "updated_at": "2026-09-10T13:20:00.007",
            "published_at": "2026-04-08T21:17:01.547",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 45.0.0, < 46.0.7",
            "fixed": "See vendor advisory",
            "source_count": 30,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in 46.0.7.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pyca/cryptography/security/advisories/GHSA-p423-j2cm-9vmq",
                "http://www.openwall.com/lists/oss-security/2026/04/08/12",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:20338",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22629",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24483",
                "https://access.redhat.com/errata/RHSA-2026:24761",
                "https://access.redhat.com/errata/RHSA-2026:24762",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:24866",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:30088",
                "https://access.redhat.com/errata/RHSA-2026:30089",
                "https://access.redhat.com/errata/RHSA-2026:37275",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:43651",
                "https://access.redhat.com/errata/RHSA-2026:43670",
                "https://access.redhat.com/errata/RHSA-2026:43851",
                "https://access.redhat.com/errata/RHSA-2026:43853",
                "https://access.redhat.com/errata/RHSA-2026:43854",
                "https://access.redhat.com/errata/RHSA-2026:43855",
                "https://access.redhat.com/errata/RHSA-2026:46956",
                "https://access.redhat.com/errata/RHSA-2026:7295",
                "https://access.redhat.com/security/cve/CVE-2026-39892",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2456735",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39892.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-08T21:17:01.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39892"
                }
            ]
        },
        {
            "id": "CVE-2026-39835",
            "vendor": "golang.org/x/crypto",
            "product": "golang.org/x/crypto/ssh",
            "title": "golang.org/x/crypto/ssh vulnerability",
            "summary": "SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.",
            "updated_at": "2026-09-11T13:17:56.500",
            "published_at": "2026-05-22T04:16:24.530",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.52.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 59,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be caused to panic by a client presenting a certificate. CertChecker now returns an error instead of panicking when these callbacks are nil.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/781660",
                "https://go.dev/issue/79563",
                "https://groups.google.com/g/golang-announce/c/a082jnz-LvI",
                "https://pkg.go.dev/vuln/GO-2026-5015",
                "https://access.redhat.com/errata/RHSA-2026:26546",
                "https://access.redhat.com/errata/RHSA-2026:26547",
                "https://access.redhat.com/errata/RHSA-2026:36199",
                "https://access.redhat.com/errata/RHSA-2026:36207",
                "https://access.redhat.com/errata/RHSA-2026:36319",
                "https://access.redhat.com/errata/RHSA-2026:36625",
                "https://access.redhat.com/errata/RHSA-2026:36648",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:36797",
                "https://access.redhat.com/errata/RHSA-2026:37072",
                "https://access.redhat.com/errata/RHSA-2026:37123",
                "https://access.redhat.com/errata/RHSA-2026:37268",
                "https://access.redhat.com/errata/RHSA-2026:37271",
                "https://access.redhat.com/errata/RHSA-2026:37272",
                "https://access.redhat.com/errata/RHSA-2026:37286",
                "https://access.redhat.com/errata/RHSA-2026:37296",
                "https://access.redhat.com/errata/RHSA-2026:37387",
                "https://access.redhat.com/errata/RHSA-2026:37410",
                "https://access.redhat.com/errata/RHSA-2026:38504",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:40969",
                "https://access.redhat.com/errata/RHSA-2026:40972",
                "https://access.redhat.com/errata/RHSA-2026:40974",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41036",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:43692",
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:47735",
                "https://access.redhat.com/errata/RHSA-2026:47949",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:51036",
                "https://access.redhat.com/errata/RHSA-2026:51038",
                "https://access.redhat.com/errata/RHSA-2026:52857",
                "https://access.redhat.com/errata/RHSA-2026:52910",
                "https://access.redhat.com/errata/RHSA-2026:54525",
                "https://access.redhat.com/errata/RHSA-2026:57194",
                "https://access.redhat.com/errata/RHSA-2026:59467",
                "https://access.redhat.com/errata/RHSA-2026:59593",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:62260",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66022",
                "https://access.redhat.com/errata/RHSA-2026:66521",
                "https://access.redhat.com/security/cve/CVE-2026-39835",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2480680",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39835.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-22T04:16:24.530",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39835"
                }
            ]
        },
        {
            "id": "CVE-2026-39832",
            "vendor": "golang.org/x/crypto",
            "product": "golang.org/x/crypto/ssh/agent",
            "title": "golang.org/x/crypto/ssh/agent vulnerability",
            "summary": "When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.",
            "updated_at": "2026-09-15T12:17:40.787",
            "published_at": "2026-05-22T04:16:22.663",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.52.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 41,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serialized in the request. Destination restrictions were silently stripped when forwarding keys, allowing unrestricted use of the key on the remote host. The client now serializes all constraint extensions. Additionally, the in-memory keyring returned by NewKeyring() now rejects keys with unsupported constraint extensions instead of silently ignoring them.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/778640",
                "https://go.dev/cl/778641",
                "https://go.dev/issue/79435",
                "https://groups.google.com/g/golang-announce/c/a082jnz-LvI",
                "https://pkg.go.dev/vuln/GO-2026-5006",
                "https://access.redhat.com/errata/RHSA-2026:35833",
                "https://access.redhat.com/errata/RHSA-2026:36199",
                "https://access.redhat.com/errata/RHSA-2026:36319",
                "https://access.redhat.com/errata/RHSA-2026:36625",
                "https://access.redhat.com/errata/RHSA-2026:36648",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:36797",
                "https://access.redhat.com/errata/RHSA-2026:37072",
                "https://access.redhat.com/errata/RHSA-2026:37123",
                "https://access.redhat.com/errata/RHSA-2026:37271",
                "https://access.redhat.com/errata/RHSA-2026:37387",
                "https://access.redhat.com/errata/RHSA-2026:37410",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:40972",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41036",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:43692",
                "https://access.redhat.com/errata/RHSA-2026:49944",
                "https://access.redhat.com/errata/RHSA-2026:52857",
                "https://access.redhat.com/errata/RHSA-2026:52910",
                "https://access.redhat.com/errata/RHSA-2026:57194",
                "https://access.redhat.com/errata/RHSA-2026:59579",
                "https://access.redhat.com/errata/RHSA-2026:61314",
                "https://access.redhat.com/errata/RHSA-2026:66521",
                "https://access.redhat.com/security/cve/CVE-2026-39832",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2480685",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39832.json",
                "https://access.redhat.com/errata/RHSA-2026:67450"
            ],
            "timeline": [
                {
                    "at": "2026-05-22T04:16:22.663",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39832"
                }
            ]
        },
        {
            "id": "CVE-2026-39830",
            "vendor": "golang.org/x/crypto",
            "product": "golang.org/x/crypto/ssh",
            "title": "golang.org/x/crypto/ssh vulnerability",
            "summary": "A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.",
            "updated_at": "2026-09-16T13:17:53.697",
            "published_at": "2026-05-22T04:16:22.440",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.52.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 60,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/781640",
                "https://go.dev/cl/781664",
                "https://go.dev/issue/79564",
                "https://groups.google.com/g/golang-announce/c/a082jnz-LvI",
                "https://pkg.go.dev/vuln/GO-2026-5017",
                "https://access.redhat.com/errata/RHSA-2026:29455",
                "https://access.redhat.com/errata/RHSA-2026:35833",
                "https://access.redhat.com/errata/RHSA-2026:36199",
                "https://access.redhat.com/errata/RHSA-2026:36207",
                "https://access.redhat.com/errata/RHSA-2026:36319",
                "https://access.redhat.com/errata/RHSA-2026:36625",
                "https://access.redhat.com/errata/RHSA-2026:36648",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:36797",
                "https://access.redhat.com/errata/RHSA-2026:36808",
                "https://access.redhat.com/errata/RHSA-2026:37072",
                "https://access.redhat.com/errata/RHSA-2026:37268",
                "https://access.redhat.com/errata/RHSA-2026:37271",
                "https://access.redhat.com/errata/RHSA-2026:37272",
                "https://access.redhat.com/errata/RHSA-2026:37275",
                "https://access.redhat.com/errata/RHSA-2026:37278",
                "https://access.redhat.com/errata/RHSA-2026:37286",
                "https://access.redhat.com/errata/RHSA-2026:37296",
                "https://access.redhat.com/errata/RHSA-2026:37387",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:40969",
                "https://access.redhat.com/errata/RHSA-2026:40972",
                "https://access.redhat.com/errata/RHSA-2026:40974",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41036",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:43692",
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:47735",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:49944",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:52857",
                "https://access.redhat.com/errata/RHSA-2026:52910",
                "https://access.redhat.com/errata/RHSA-2026:54400",
                "https://access.redhat.com/errata/RHSA-2026:54531",
                "https://access.redhat.com/errata/RHSA-2026:57194",
                "https://access.redhat.com/errata/RHSA-2026:57801",
                "https://access.redhat.com/errata/RHSA-2026:59467",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:61314",
                "https://access.redhat.com/errata/RHSA-2026:65964",
                "https://access.redhat.com/errata/RHSA-2026:66022",
                "https://access.redhat.com/errata/RHSA-2026:66521",
                "https://access.redhat.com/security/cve/CVE-2026-39830",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2480684",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39830.json",
                "https://access.redhat.com/errata/RHSA-2026:67450"
            ],
            "timeline": [
                {
                    "at": "2026-05-22T04:16:22.440",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39830"
                }
            ]
        },
        {
            "id": "CVE-2026-39829",
            "vendor": "golang.org/x/crypto",
            "product": "golang.org/x/crypto/ssh",
            "title": "golang.org/x/crypto/ssh vulnerability",
            "summary": "The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.",
            "updated_at": "2026-09-16T13:17:52.280",
            "published_at": "2026-05-22T04:16:22.310",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.52.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 75,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-347",
            "what_happened": "The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or DSA parameter could cause several minutes of CPU consumption during signature verification. This could be triggered by unauthenticated clients during public key authentication. RSA moduli are now limited to 8192 bits, and DSA parameters are validated per FIPS 186-2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/781641",
                "https://go.dev/cl/781661",
                "https://go.dev/issue/79565",
                "https://groups.google.com/g/golang-announce/c/a082jnz-LvI",
                "https://pkg.go.dev/vuln/GO-2026-5018",
                "https://access.redhat.com/errata/RHSA-2026:26546",
                "https://access.redhat.com/errata/RHSA-2026:26547",
                "https://access.redhat.com/errata/RHSA-2026:29455",
                "https://access.redhat.com/errata/RHSA-2026:35833",
                "https://access.redhat.com/errata/RHSA-2026:36199",
                "https://access.redhat.com/errata/RHSA-2026:36207",
                "https://access.redhat.com/errata/RHSA-2026:36319",
                "https://access.redhat.com/errata/RHSA-2026:36625",
                "https://access.redhat.com/errata/RHSA-2026:36648",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:36797",
                "https://access.redhat.com/errata/RHSA-2026:36808",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:36883",
                "https://access.redhat.com/errata/RHSA-2026:37072",
                "https://access.redhat.com/errata/RHSA-2026:37123",
                "https://access.redhat.com/errata/RHSA-2026:37268",
                "https://access.redhat.com/errata/RHSA-2026:37271",
                "https://access.redhat.com/errata/RHSA-2026:37272",
                "https://access.redhat.com/errata/RHSA-2026:37278",
                "https://access.redhat.com/errata/RHSA-2026:37286",
                "https://access.redhat.com/errata/RHSA-2026:37296",
                "https://access.redhat.com/errata/RHSA-2026:37387",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:40969",
                "https://access.redhat.com/errata/RHSA-2026:40972",
                "https://access.redhat.com/errata/RHSA-2026:40974",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41036",
                "https://access.redhat.com/errata/RHSA-2026:41055",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:43692",
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:46903",
                "https://access.redhat.com/errata/RHSA-2026:47735",
                "https://access.redhat.com/errata/RHSA-2026:47949",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:48693",
                "https://access.redhat.com/errata/RHSA-2026:49944",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:52857",
                "https://access.redhat.com/errata/RHSA-2026:52910",
                "https://access.redhat.com/errata/RHSA-2026:54400",
                "https://access.redhat.com/errata/RHSA-2026:54432",
                "https://access.redhat.com/errata/RHSA-2026:57191",
                "https://access.redhat.com/errata/RHSA-2026:57194",
                "https://access.redhat.com/errata/RHSA-2026:57365",
                "https://access.redhat.com/errata/RHSA-2026:57801",
                "https://access.redhat.com/errata/RHSA-2026:59467",
                "https://access.redhat.com/errata/RHSA-2026:59559",
                "https://access.redhat.com/errata/RHSA-2026:59593",
                "https://access.redhat.com/errata/RHSA-2026:60446",
                "https://access.redhat.com/errata/RHSA-2026:60454",
                "https://access.redhat.com/errata/RHSA-2026:60477",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:61314",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:65964",
                "https://access.redhat.com/errata/RHSA-2026:66022",
                "https://access.redhat.com/security/cve/CVE-2026-39829",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2480681",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39829.json",
                "https://access.redhat.com/errata/RHSA-2026:67450"
            ],
            "timeline": [
                {
                    "at": "2026-05-22T04:16:22.310",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39829"
                }
            ]
        },
        {
            "id": "CVE-2026-39828",
            "vendor": "golang.org/x/crypto",
            "product": "golang.org/x/crypto/ssh",
            "title": "golang.org/x/crypto/ssh vulnerability",
            "summary": "When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.",
            "updated_at": "2026-09-11T13:17:51.260",
            "published_at": "2026-05-22T04:16:22.190",
            "cvss": 6.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.52.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 56,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were silently discarded, potentially dropping certificate restrictions such as force-command after a second factor succeeded. Returning non-nil Permissions with PartialSuccessError now results in a connection error.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/781621",
                "https://go.dev/issue/79562",
                "https://groups.google.com/g/golang-announce/c/a082jnz-LvI",
                "https://pkg.go.dev/vuln/GO-2026-5014",
                "https://access.redhat.com/errata/RHSA-2026:26546",
                "https://access.redhat.com/errata/RHSA-2026:26547",
                "https://access.redhat.com/errata/RHSA-2026:36105",
                "https://access.redhat.com/errata/RHSA-2026:36167",
                "https://access.redhat.com/errata/RHSA-2026:36207",
                "https://access.redhat.com/errata/RHSA-2026:36319",
                "https://access.redhat.com/errata/RHSA-2026:36625",
                "https://access.redhat.com/errata/RHSA-2026:36648",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:36797",
                "https://access.redhat.com/errata/RHSA-2026:36808",
                "https://access.redhat.com/errata/RHSA-2026:37268",
                "https://access.redhat.com/errata/RHSA-2026:37271",
                "https://access.redhat.com/errata/RHSA-2026:37272",
                "https://access.redhat.com/errata/RHSA-2026:37278",
                "https://access.redhat.com/errata/RHSA-2026:37286",
                "https://access.redhat.com/errata/RHSA-2026:37296",
                "https://access.redhat.com/errata/RHSA-2026:37387",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:40969",
                "https://access.redhat.com/errata/RHSA-2026:40972",
                "https://access.redhat.com/errata/RHSA-2026:40974",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41036",
                "https://access.redhat.com/errata/RHSA-2026:41055",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:43692",
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:46903",
                "https://access.redhat.com/errata/RHSA-2026:47735",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:51038",
                "https://access.redhat.com/errata/RHSA-2026:52857",
                "https://access.redhat.com/errata/RHSA-2026:52910",
                "https://access.redhat.com/errata/RHSA-2026:54531",
                "https://access.redhat.com/errata/RHSA-2026:57191",
                "https://access.redhat.com/errata/RHSA-2026:57194",
                "https://access.redhat.com/errata/RHSA-2026:59467",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:66022",
                "https://access.redhat.com/errata/RHSA-2026:66521",
                "https://access.redhat.com/security/cve/CVE-2026-39828",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2480687",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39828.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-22T04:16:22.190",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39828"
                }
            ]
        },
        {
            "id": "CVE-2026-39821",
            "vendor": "Go standard library",
            "product": "net/http",
            "title": "net/http vulnerability",
            "summary": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".",
            "updated_at": "2026-09-15T12:17:34.803",
            "published_at": "2026-05-22T16:16:20.410",
            "cvss": 9.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.25.13 (semver); 1.26.0-0 through before 1.26.6 (semver); 1.27.0-0 through before 1.27.0-rc.3 (semver); before 0.55.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 157,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-1289",
            "what_happened": "The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject \"example.com\" but permit \"xn--example-.com\". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name \"example.com\".",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/767220",
                "https://go.dev/issue/78760",
                "https://groups.google.com/g/golang-announce/c/94pEornpRlI",
                "https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8",
                "https://pkg.go.dev/vuln/GO-2026-5026",
                "https://access.redhat.com/errata/RHSA-2026:23262",
                "https://access.redhat.com/errata/RHSA-2026:23264",
                "https://access.redhat.com/errata/RHSA-2026:26546",
                "https://access.redhat.com/errata/RHSA-2026:26547",
                "https://access.redhat.com/errata/RHSA-2026:30650",
                "https://access.redhat.com/errata/RHSA-2026:30651",
                "https://access.redhat.com/errata/RHSA-2026:30853",
                "https://access.redhat.com/errata/RHSA-2026:30854",
                "https://access.redhat.com/errata/RHSA-2026:30855",
                "https://access.redhat.com/errata/RHSA-2026:33155",
                "https://access.redhat.com/errata/RHSA-2026:33160",
                "https://access.redhat.com/errata/RHSA-2026:33163",
                "https://access.redhat.com/errata/RHSA-2026:33173",
                "https://access.redhat.com/errata/RHSA-2026:33183",
                "https://access.redhat.com/errata/RHSA-2026:33524",
                "https://access.redhat.com/errata/RHSA-2026:33531",
                "https://access.redhat.com/errata/RHSA-2026:34342",
                "https://access.redhat.com/errata/RHSA-2026:34357",
                "https://access.redhat.com/errata/RHSA-2026:34359",
                "https://access.redhat.com/errata/RHSA-2026:34364",
                "https://access.redhat.com/errata/RHSA-2026:34789",
                "https://access.redhat.com/errata/RHSA-2026:35826",
                "https://access.redhat.com/errata/RHSA-2026:35827",
                "https://access.redhat.com/errata/RHSA-2026:35828",
                "https://access.redhat.com/errata/RHSA-2026:35829",
                "https://access.redhat.com/errata/RHSA-2026:35830",
                "https://access.redhat.com/errata/RHSA-2026:35831",
                "https://access.redhat.com/errata/RHSA-2026:35993",
                "https://access.redhat.com/errata/RHSA-2026:35994",
                "https://access.redhat.com/errata/RHSA-2026:36105",
                "https://access.redhat.com/errata/RHSA-2026:36167",
                "https://access.redhat.com/errata/RHSA-2026:36207",
                "https://access.redhat.com/errata/RHSA-2026:36648",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:36797",
                "https://access.redhat.com/errata/RHSA-2026:36808",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:36883",
                "https://access.redhat.com/errata/RHSA-2026:37387",
                "https://access.redhat.com/errata/RHSA-2026:37435",
                "https://access.redhat.com/errata/RHSA-2026:37436",
                "https://access.redhat.com/errata/RHSA-2026:38995",
                "https://access.redhat.com/errata/RHSA-2026:39005",
                "https://access.redhat.com/errata/RHSA-2026:39573",
                "https://access.redhat.com/errata/RHSA-2026:39879",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41030",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41036",
                "https://access.redhat.com/errata/RHSA-2026:41055",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41930",
                "https://access.redhat.com/errata/RHSA-2026:42043",
                "https://access.redhat.com/errata/RHSA-2026:42047",
                "https://access.redhat.com/errata/RHSA-2026:42048",
                "https://access.redhat.com/errata/RHSA-2026:42049",
                "https://access.redhat.com/errata/RHSA-2026:42050",
                "https://access.redhat.com/errata/RHSA-2026:42051",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:42079",
                "https://access.redhat.com/errata/RHSA-2026:42080",
                "https://access.redhat.com/errata/RHSA-2026:42082",
                "https://access.redhat.com/errata/RHSA-2026:42132",
                "https://access.redhat.com/errata/RHSA-2026:42142",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42150",
                "https://access.redhat.com/errata/RHSA-2026:42151",
                "https://access.redhat.com/errata/RHSA-2026:42240",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:42852",
                "https://access.redhat.com/errata/RHSA-2026:43038",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:43692",
                "https://access.redhat.com/errata/RHSA-2026:44622",
                "https://access.redhat.com/errata/RHSA-2026:44624",
                "https://access.redhat.com/errata/RHSA-2026:46395",
                "https://access.redhat.com/errata/RHSA-2026:47149",
                "https://access.redhat.com/errata/RHSA-2026:47735",
                "https://access.redhat.com/errata/RHSA-2026:47737",
                "https://access.redhat.com/errata/RHSA-2026:47952",
                "https://access.redhat.com/errata/RHSA-2026:49702",
                "https://access.redhat.com/errata/RHSA-2026:49712",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/errata/RHSA-2026:50843",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:51112",
                "https://access.redhat.com/errata/RHSA-2026:51187",
                "https://access.redhat.com/errata/RHSA-2026:51194",
                "https://access.redhat.com/errata/RHSA-2026:51341",
                "https://access.redhat.com/errata/RHSA-2026:52826",
                "https://access.redhat.com/errata/RHSA-2026:53374",
                "https://access.redhat.com/errata/RHSA-2026:53412",
                "https://access.redhat.com/errata/RHSA-2026:53413",
                "https://access.redhat.com/errata/RHSA-2026:53415",
                "https://access.redhat.com/errata/RHSA-2026:53530",
                "https://access.redhat.com/errata/RHSA-2026:54191",
                "https://access.redhat.com/errata/RHSA-2026:54274",
                "https://access.redhat.com/errata/RHSA-2026:54283",
                "https://access.redhat.com/errata/RHSA-2026:54284",
                "https://access.redhat.com/errata/RHSA-2026:54285",
                "https://access.redhat.com/errata/RHSA-2026:54286",
                "https://access.redhat.com/errata/RHSA-2026:54287",
                "https://access.redhat.com/errata/RHSA-2026:54395",
                "https://access.redhat.com/errata/RHSA-2026:54401",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:54441",
                "https://access.redhat.com/errata/RHSA-2026:54531",
                "https://access.redhat.com/errata/RHSA-2026:54580",
                "https://access.redhat.com/errata/RHSA-2026:54757",
                "https://access.redhat.com/errata/RHSA-2026:56143",
                "https://access.redhat.com/errata/RHSA-2026:56223",
                "https://access.redhat.com/errata/RHSA-2026:56340",
                "https://access.redhat.com/errata/RHSA-2026:56431",
                "https://access.redhat.com/errata/RHSA-2026:57194",
                "https://access.redhat.com/errata/RHSA-2026:57541",
                "https://access.redhat.com/errata/RHSA-2026:57649",
                "https://access.redhat.com/errata/RHSA-2026:57845",
                "https://access.redhat.com/errata/RHSA-2026:59546",
                "https://access.redhat.com/errata/RHSA-2026:59549",
                "https://access.redhat.com/errata/RHSA-2026:59562",
                "https://access.redhat.com/errata/RHSA-2026:60315",
                "https://access.redhat.com/errata/RHSA-2026:60354",
                "https://access.redhat.com/errata/RHSA-2026:60387",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:61245",
                "https://access.redhat.com/errata/RHSA-2026:61253",
                "https://access.redhat.com/errata/RHSA-2026:62549",
                "https://access.redhat.com/errata/RHSA-2026:63134",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:65153",
                "https://access.redhat.com/errata/RHSA-2026:65359",
                "https://access.redhat.com/errata/RHSA-2026:65534",
                "https://access.redhat.com/errata/RHSA-2026:65886",
                "https://access.redhat.com/errata/RHSA-2026:66016",
                "https://access.redhat.com/errata/RHSA-2026:66022",
                "https://access.redhat.com/errata/RHSA-2026:66432",
                "https://access.redhat.com/security/cve/CVE-2026-39821",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2480756",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39821.json",
                "https://access.redhat.com/errata/RHSA-2026:67149",
                "https://access.redhat.com/errata/RHSA-2026:67159",
                "https://access.redhat.com/errata/RHSA-2026:67160",
                "https://access.redhat.com/errata/RHSA-2026:66350",
                "https://access.redhat.com/errata/RHSA-2026:67287",
                "https://access.redhat.com/errata/RHSA-2026:67319",
                "https://access.redhat.com/errata/RHSA-2026:67517"
            ],
            "timeline": [
                {
                    "at": "2026-05-22T16:16:20.410",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39821"
                }
            ]
        },
        {
            "id": "CVE-2026-39820",
            "vendor": "Go standard library",
            "product": "net/mail",
            "title": "net/mail vulnerability",
            "summary": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.",
            "updated_at": "2026-09-15T12:17:33.590",
            "published_at": "2026-05-07T20:16:43.187",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.25.10 (semver); 1.26.0-0 through before 1.26.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 91,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/759940",
                "https://go.dev/issue/78566",
                "https://groups.google.com/g/golang-announce/c/qcCIEXso47M",
                "https://pkg.go.dev/vuln/GO-2026-4986",
                "https://access.redhat.com/errata/RHSA-2026:22112",
                "https://access.redhat.com/errata/RHSA-2026:22120",
                "https://access.redhat.com/errata/RHSA-2026:22121",
                "https://access.redhat.com/errata/RHSA-2026:23262",
                "https://access.redhat.com/errata/RHSA-2026:23264",
                "https://access.redhat.com/errata/RHSA-2026:33120",
                "https://access.redhat.com/errata/RHSA-2026:33123",
                "https://access.redhat.com/errata/RHSA-2026:33142",
                "https://access.redhat.com/errata/RHSA-2026:33150",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:34364",
                "https://access.redhat.com/errata/RHSA-2026:36319",
                "https://access.redhat.com/errata/RHSA-2026:36625",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:36797",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43038",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:43692",
                "https://access.redhat.com/errata/RHSA-2026:47952",
                "https://access.redhat.com/errata/RHSA-2026:49702",
                "https://access.redhat.com/errata/RHSA-2026:49712",
                "https://access.redhat.com/errata/RHSA-2026:50205",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/errata/RHSA-2026:50843",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:54274",
                "https://access.redhat.com/errata/RHSA-2026:54283",
                "https://access.redhat.com/errata/RHSA-2026:54284",
                "https://access.redhat.com/errata/RHSA-2026:54285",
                "https://access.redhat.com/errata/RHSA-2026:54286",
                "https://access.redhat.com/errata/RHSA-2026:54287",
                "https://access.redhat.com/errata/RHSA-2026:54531",
                "https://access.redhat.com/errata/RHSA-2026:54552",
                "https://access.redhat.com/errata/RHSA-2026:54555",
                "https://access.redhat.com/errata/RHSA-2026:54583",
                "https://access.redhat.com/errata/RHSA-2026:54602",
                "https://access.redhat.com/errata/RHSA-2026:54883",
                "https://access.redhat.com/errata/RHSA-2026:56340",
                "https://access.redhat.com/errata/RHSA-2026:56789",
                "https://access.redhat.com/errata/RHSA-2026:56852",
                "https://access.redhat.com/errata/RHSA-2026:56854",
                "https://access.redhat.com/errata/RHSA-2026:57194",
                "https://access.redhat.com/errata/RHSA-2026:57401",
                "https://access.redhat.com/errata/RHSA-2026:57482",
                "https://access.redhat.com/errata/RHSA-2026:57487",
                "https://access.redhat.com/errata/RHSA-2026:57649",
                "https://access.redhat.com/errata/RHSA-2026:57845",
                "https://access.redhat.com/errata/RHSA-2026:57914",
                "https://access.redhat.com/errata/RHSA-2026:59467",
                "https://access.redhat.com/errata/RHSA-2026:59830",
                "https://access.redhat.com/errata/RHSA-2026:59833",
                "https://access.redhat.com/errata/RHSA-2026:60018",
                "https://access.redhat.com/errata/RHSA-2026:60023",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:61253",
                "https://access.redhat.com/errata/RHSA-2026:62260",
                "https://access.redhat.com/errata/RHSA-2026:62406",
                "https://access.redhat.com/errata/RHSA-2026:62407",
                "https://access.redhat.com/errata/RHSA-2026:62753",
                "https://access.redhat.com/errata/RHSA-2026:62754",
                "https://access.redhat.com/errata/RHSA-2026:62803",
                "https://access.redhat.com/errata/RHSA-2026:63022",
                "https://access.redhat.com/security/cve/CVE-2026-39820",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2467820",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39820.json",
                "https://access.redhat.com/errata/RHSA-2026:51112",
                "https://access.redhat.com/errata/RHSA-2026:65116",
                "https://access.redhat.com/errata/RHSA-2026:65117",
                "https://access.redhat.com/errata/RHSA-2026:65153",
                "https://access.redhat.com/errata/RHSA-2026:65335",
                "https://access.redhat.com/errata/RHSA-2026:65336",
                "https://access.redhat.com/errata/RHSA-2026:65534",
                "https://access.redhat.com/errata/RHSA-2026:65886",
                "https://access.redhat.com/errata/RHSA-2026:65895",
                "https://access.redhat.com/errata/RHSA-2026:66016",
                "https://access.redhat.com/errata/RHSA-2026:66327",
                "https://access.redhat.com/errata/RHSA-2026:66022",
                "https://access.redhat.com/errata/RHSA-2026:50319",
                "https://access.redhat.com/errata/RHSA-2026:50336",
                "https://access.redhat.com/errata/RHSA-2026:67517"
            ],
            "timeline": [
                {
                    "at": "2026-05-07T20:16:43.187",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39820"
                }
            ]
        },
        {
            "id": "CVE-2026-39808",
            "vendor": "Fortinet",
            "product": "FortiSandbox",
            "title": "Fortinet FortiSandbox OS Command Injection Vulnerability",
            "summary": "Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.",
            "updated_at": "2026-07-15T22:00:00Z",
            "published_at": "2026-07-15T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-07-15T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-39031",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "cve-2026-39031-lansweeper-lsrunase2-lsencrypt2 exploit",
            "summary": "Exploit for CVE-2026-39031. CVSS 5.5.",
            "updated_at": "2026-09-06T08:29:13Z",
            "published_at": "2026-09-06T08:29:13Z",
            "cvss": 5.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-06T08:29:13+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "cve-2026-39031-lansweeper-lsrunase2-lsencrypt2 exploit",
                    "summary": "Exploit for CVE-2026-39031. CVSS 5.5.",
                    "cvss": 5.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-USER6400-CVE-2026-39031-LANSWEEPER-LSRUNASE2-LSENCRYPT2"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-USER6400-CVE-2026-39031-LANSWEEPER-LSRUNASE2-LSENCRYPT2"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:29:13Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-USER6400-CVE-2026-39031-LANSWEEPER-LSRUNASE2-LSENCRYPT2"
                }
            ]
        },
        {
            "id": "CVE-2026-38924",
            "vendor": "Oraios AI",
            "product": "Serena",
            "title": "Serena vulnerability",
            "summary": "In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a \"potential security hazard\" but the Serena documentation, at the time of the issue report proposing 127.0.0.1 instead of 0.0.0.0, recommended \"use a sandboxed environment for running Serena.\"",
            "updated_at": "2026-09-14T03:16:36.893",
            "published_at": "2026-09-14T03:16:36.893",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.0.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-669",
            "what_happened": "In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was a \"potential security hazard\" but the Serena documentation, at the time of the issue report proposing 127.0.0.1 instead of 0.0.0.0, recommended \"use a sandboxed environment for running Serena.\"",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://dash.security/blog/cve-2026-38924-unauthenticated-rce-in-the-serena-mcp-server",
                "https://github.com/oraios/serena/commit/a7af5c1f8a9ea27102eac9e72f64dd97dbfefff3",
                "https://github.com/oraios/serena/commit/b00ae292ac2d49947506886f44eb1cad7b7d7cd1",
                "https://github.com/oraios/serena/compare/v0.1.4...v1.0.0",
                "https://github.com/oraios/serena/security/advisories/GHSA-m922-r24v-6wff"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T03:16:36.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-38924"
                }
            ]
        },
        {
            "id": "CVE-2026-38710",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the system.setclock interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.",
            "updated_at": "2026-09-09T16:04:24.933",
            "published_at": "2026-07-31T21:17:30.830",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the system.setclock interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.cudy.com/pages/security-advisory/cudy-sa-26-7-vufm-1-e"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T21:17:30.830",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-38710"
                }
            ]
        },
        {
            "id": "CVE-2026-38332",
            "vendor": "cdcseacave",
            "product": "TinyEXIF",
            "title": "TinyEXIF vulnerability",
            "summary": "TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.",
            "updated_at": "2026-09-13T21:17:01.460",
            "published_at": "2026-09-13T21:17:01.460",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.1.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-125",
            "what_happened": "TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cdcseacave/TinyEXIF/issues/24",
                "https://github.com/cdcseacave/TinyEXIF/pull/25",
                "https://github.com/cdcseacave/TinyEXIF/security/advisories/GHSA-jqj2-8c2j-gx82"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:17:01.460",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-38332"
                }
            ]
        },
        {
            "id": "CVE-2026-38076",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
            "updated_at": "2026-09-14T14:17:07.643",
            "published_at": "2026-07-09T22:17:03.983",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "http://artifex.com",
                "https://gist.github.com/dkjsone/c237b83ffa9ebd7028b5db7f410fcf78",
                "https://github.com/ArtifexSoftware/jbig2dec",
                "https://lists.debian.org/debian-lts-announce/2026/09/msg00014.html"
            ],
            "timeline": [
                {
                    "at": "2026-07-09T22:17:03.983",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-38076"
                }
            ]
        },
        {
            "id": "CVE-2026-38059",
            "vendor": "ST Engineering iDirect",
            "product": "Evolution iQ‑Series terminals",
            "title": "Evolution iQ‑Series terminals vulnerability",
            "summary": "The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version. The DID and TPK are used for satellite network authentication in the iDirect platform, potentially enabling terminal impersonation and network reconnaissance.",
            "updated_at": "2026-09-11T15:17:01.553",
            "published_at": "2026-07-10T15:16:39.563",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.5.2.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version. The DID and TPK are used for satellite network authentication in the iDirect platform, potentially enabling terminal impersonation and network reconnaissance.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-01.json",
                "https://support.idirect.net",
                "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01"
            ],
            "timeline": [
                {
                    "at": "2026-07-10T15:16:39.563",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-38059"
                }
            ]
        },
        {
            "id": "CVE-2026-38057",
            "vendor": "ST Engineering iDirect",
            "product": "Evolution iQ‑Series terminals",
            "title": "Evolution iQ‑Series terminals vulnerability",
            "summary": "The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.",
            "updated_at": "2026-09-11T15:17:01.250",
            "published_at": "2026-07-10T15:16:39.397",
            "cvss": 7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.5.2.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-352",
            "what_happened": "The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-01.json",
                "https://support.idirect.net",
                "https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01"
            ],
            "timeline": [
                {
                    "at": "2026-07-10T15:16:39.397",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-38057"
                }
            ]
        },
        {
            "id": "CVE-2026-37065",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-37065 exploit",
            "summary": "Exploit for CVE-2026-37065. CVSS 9.1.",
            "updated_at": "2026-09-13T18:33:50Z",
            "published_at": "2026-09-13T18:33:50Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:33:50+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2026-37065 exploit",
                    "summary": "Exploit for CVE-2026-37065. CVSS 9.1.",
                    "cvss": 9.1,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JFS-JFS-CVE-2026-37065"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JFS-JFS-CVE-2026-37065"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:33:50Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JFS-JFS-CVE-2026-37065"
                }
            ]
        },
        {
            "id": "CVE-2026-37008",
            "vendor": "CrewAI",
            "product": "CrewAI",
            "title": "CrewAI vulnerability",
            "summary": "CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library without relying in any import statements. In other words, a within-process sandbox cannot merely account for the import system and instead must account for the complete runtime of the Python interpreter.",
            "updated_at": "2026-09-13T21:17:01.303",
            "published_at": "2026-09-13T21:17:01.303",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before fb2323b3deb3ec62b3965526857e77a2264e4cd0 (git)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-424",
            "what_happened": "CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library without relying in any import statements. In other words, a within-process sandbox cannot merely account for the import system and instead must account for the complete runtime of the Python interpreter.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.python.org/3/library/ctypes.html",
                "https://github.com/crewAIInc/crewAI/commit/fb2323b3deb3ec62b3965526857e77a2264e4cd0",
                "https://yerangamage.com/cves/detail/?slug=crewai-sandbox-escape"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:17:01.303",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-37008"
                }
            ]
        },
        {
            "id": "CVE-2026-36989",
            "vendor": "LuxSoft",
            "product": "LuxCal Web Calendar",
            "title": "LuxCal Web Calendar vulnerability",
            "summary": "A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.",
            "updated_at": "2026-09-13T21:17:01.140",
            "published_at": "2026-09-13T21:17:01.140",
            "cvss": 5.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 5.3.4L (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gist.github.com/mathysEthical/8c3c426e89c6e48911acf8513fd1f075",
                "https://mathys.reboux.pro/CVE/2026/36989/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:17:01.140",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-36989"
                }
            ]
        },
        {
            "id": "CVE-2026-36669",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-36669-FengOffice exploit",
            "summary": "Exploit for CVE-2026-36669. CVSS 9.8.",
            "updated_at": "2026-09-05T08:11:22Z",
            "published_at": "2026-09-05T08:11:22Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 153,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-434",
            "what_happened": "Unauthenticated file upload in Feng Office 3.11.13.11 via ck_upload_handler.php enabling XSS.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-36669-FengOffice",
                    "summary": "Unauthenticated file upload in Feng Office 3.11.13.11 via ck_upload_handler.php enabling XSS.",
                    "what_happened": "Unauthenticated file upload in Feng Office 3.11.13.11 via ck_upload_handler.php enabling XSS.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FIRSTLAX6T-CVE-2026-36669-FENGOFFICE",
                        "https://kitploit.com/zh/tools/github/firstlax6t/cve-2026-36669-fengoffice/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T08:11:22",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FIRSTLAX6T-CVE-2026-36669-FENGOFFICE"
                },
                {
                    "title": "Exploit for CVE-2026-36669-FengOffice",
                    "summary": "Unauthenticated file upload in Feng Office 3.11.13.11 via ck_upload_handler.php enabling XSS.",
                    "what_happened": "Unauthenticated file upload in Feng Office 3.11.13.11 via ck_upload_handler.php enabling XSS.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FIRSTLAX6T-CVE-2026-36669-FENGOFFICE",
                        "https://kitploit.com/zh/tools/github/firstlax6t/cve-2026-36669-fengoffice/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-05T08:11:22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/firstlax6t/cve-2026-36669-fengoffice/"
                },
                {
                    "repository": "firstlax6t/CVE-2026-36669-FengOffice",
                    "author": "firstlax6t",
                    "first_seen": "2026-07-15",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-36669 repository",
                    "summary": "",
                    "url": "https://github.com/firstlax6t/CVE-2026-36669-FengOffice"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FIRSTLAX6T-CVE-2026-36669-FENGOFFICE",
                "https://kitploit.com/zh/tools/github/firstlax6t/cve-2026-36669-fengoffice/",
                "https://github.com/firstlax6t/CVE-2026-36669-FengOffice"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:11:22Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FIRSTLAX6T-CVE-2026-36669-FENGOFFICE"
                }
            ]
        },
        {
            "id": "CVE-2026-36453",
            "vendor": "Rhymix",
            "product": "Rhymix",
            "title": "Rhymix vulnerability",
            "summary": "Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.",
            "updated_at": "2026-09-13T21:16:59.947",
            "published_at": "2026-09-13T21:16:59.947",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.1.31 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-425",
            "what_happened": "Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/rhymix/rhymix/commit/f131a616eb990e2b070a8381c3106ae979d40989",
                "https://rhymix.org/community/1932364"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T21:16:59.947",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-36453"
                }
            ]
        },
        {
            "id": "CVE-2026-35867",
            "vendor": "LB-LINK",
            "product": "AC1900 firmware",
            "title": "AC1900 firmware vulnerability",
            "summary": "A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able to make a \"POST /goform/set_LimitClient_cfg\" call but does not already have administrative access to the device.",
            "updated_at": "2026-09-13T22:16:59.473",
            "published_at": "2026-09-13T22:16:59.473",
            "cvss": 3.1,
            "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-78",
            "what_happened": "A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where an actor is able to make a \"POST /goform/set_LimitClient_cfg\" call but does not already have administrative access to the device.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Orcust-Automaton/Vulnerability/blob/main/LB-Link/AC1900_AZ2/bs_SetLimitCli_info.md"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T22:16:59.473",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35867"
                }
            ]
        },
        {
            "id": "CVE-2026-35469",
            "vendor": "moby",
            "product": "spdystream",
            "title": "spdystream vulnerability",
            "summary": "spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.",
            "updated_at": "2026-09-11T13:17:46.747",
            "published_at": "2026-04-16T22:16:37.920",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 0.5.1",
            "fixed": "See vendor advisory",
            "source_count": 89,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/moby/spdystream/releases/tag/v0.5.1",
                "https://github.com/moby/spdystream/security/advisories/GHSA-pc3f-x583-g7j2",
                "https://access.redhat.com/errata/RHSA-2026:11070",
                "https://access.redhat.com/errata/RHSA-2026:11217",
                "https://access.redhat.com/errata/RHSA-2026:12118",
                "https://access.redhat.com/errata/RHSA-2026:13791",
                "https://access.redhat.com/errata/RHSA-2026:13829",
                "https://access.redhat.com/errata/RHSA-2026:17121",
                "https://access.redhat.com/errata/RHSA-2026:17123",
                "https://access.redhat.com/errata/RHSA-2026:17449",
                "https://access.redhat.com/errata/RHSA-2026:17468",
                "https://access.redhat.com/errata/RHSA-2026:17469",
                "https://access.redhat.com/errata/RHSA-2026:17475",
                "https://access.redhat.com/errata/RHSA-2026:17598",
                "https://access.redhat.com/errata/RHSA-2026:17599",
                "https://access.redhat.com/errata/RHSA-2026:17704",
                "https://access.redhat.com/errata/RHSA-2026:19099",
                "https://access.redhat.com/errata/RHSA-2026:19108",
                "https://access.redhat.com/errata/RHSA-2026:20034",
                "https://access.redhat.com/errata/RHSA-2026:20041",
                "https://access.redhat.com/errata/RHSA-2026:20042",
                "https://access.redhat.com/errata/RHSA-2026:20089",
                "https://access.redhat.com/errata/RHSA-2026:21658",
                "https://access.redhat.com/errata/RHSA-2026:21692",
                "https://access.redhat.com/errata/RHSA-2026:21697",
                "https://access.redhat.com/errata/RHSA-2026:23235",
                "https://access.redhat.com/errata/RHSA-2026:25009",
                "https://access.redhat.com/errata/RHSA-2026:25046",
                "https://access.redhat.com/errata/RHSA-2026:25187",
                "https://access.redhat.com/errata/RHSA-2026:25194",
                "https://access.redhat.com/errata/RHSA-2026:25201",
                "https://access.redhat.com/errata/RHSA-2026:25207",
                "https://access.redhat.com/errata/RHSA-2026:27004",
                "https://access.redhat.com/errata/RHSA-2026:27010",
                "https://access.redhat.com/errata/RHSA-2026:27063",
                "https://access.redhat.com/errata/RHSA-2026:27903",
                "https://access.redhat.com/errata/RHSA-2026:27914",
                "https://access.redhat.com/errata/RHSA-2026:27941",
                "https://access.redhat.com/errata/RHSA-2026:27983",
                "https://access.redhat.com/errata/RHSA-2026:29795",
                "https://access.redhat.com/errata/RHSA-2026:29801",
                "https://access.redhat.com/errata/RHSA-2026:29835",
                "https://access.redhat.com/errata/RHSA-2026:29857",
                "https://access.redhat.com/errata/RHSA-2026:29858",
                "https://access.redhat.com/errata/RHSA-2026:29865",
                "https://access.redhat.com/errata/RHSA-2026:33071",
                "https://access.redhat.com/errata/RHSA-2026:33078",
                "https://access.redhat.com/errata/RHSA-2026:34050",
                "https://access.redhat.com/errata/RHSA-2026:34099",
                "https://access.redhat.com/errata/RHSA-2026:34100",
                "https://access.redhat.com/errata/RHSA-2026:34755",
                "https://access.redhat.com/errata/RHSA-2026:34766",
                "https://access.redhat.com/errata/RHSA-2026:34769",
                "https://access.redhat.com/errata/RHSA-2026:34791",
                "https://access.redhat.com/errata/RHSA-2026:34794",
                "https://access.redhat.com/errata/RHSA-2026:36162",
                "https://access.redhat.com/errata/RHSA-2026:36621",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:37187",
                "https://access.redhat.com/errata/RHSA-2026:37193",
                "https://access.redhat.com/errata/RHSA-2026:37387",
                "https://access.redhat.com/errata/RHSA-2026:37580",
                "https://access.redhat.com/errata/RHSA-2026:37581",
                "https://access.redhat.com/errata/RHSA-2026:37629",
                "https://access.redhat.com/errata/RHSA-2026:40022",
                "https://access.redhat.com/errata/RHSA-2026:40023",
                "https://access.redhat.com/errata/RHSA-2026:40030",
                "https://access.redhat.com/errata/RHSA-2026:40828",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:43227",
                "https://access.redhat.com/errata/RHSA-2026:43253",
                "https://access.redhat.com/errata/RHSA-2026:44237",
                "https://access.redhat.com/errata/RHSA-2026:44267",
                "https://access.redhat.com/errata/RHSA-2026:47728",
                "https://access.redhat.com/errata/RHSA-2026:47729",
                "https://access.redhat.com/errata/RHSA-2026:51007",
                "https://access.redhat.com/errata/RHSA-2026:51013",
                "https://access.redhat.com/errata/RHSA-2026:51022",
                "https://access.redhat.com/errata/RHSA-2026:51422",
                "https://access.redhat.com/errata/RHSA-2026:53655",
                "https://access.redhat.com/errata/RHSA-2026:56431",
                "https://access.redhat.com/errata/RHSA-2026:59557",
                "https://access.redhat.com/errata/RHSA-2026:60023",
                "https://access.redhat.com/errata/RHSA-2026:61314",
                "https://access.redhat.com/security/cve/CVE-2026-35469",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2457729",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35469.json",
                "https://access.redhat.com/errata/RHSA-2026:63046",
                "https://access.redhat.com/errata/RHSA-2026:66521"
            ],
            "timeline": [
                {
                    "at": "2026-04-16T22:16:37.920",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35469"
                }
            ]
        },
        {
            "id": "CVE-2026-34986",
            "vendor": "go-jose",
            "product": "go-jose",
            "title": "go-jose vulnerability",
            "summary": "Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reachable by calling cipher.KeyUnwrap() directly with any ciphertext parameter less than 16 bytes long, but calling this function directly is less common. Panics can lead to denial of service. This vulnerability is fixed in 4.1.4 and 3.0.5.",
            "updated_at": "2026-09-10T13:19:46.980",
            "published_at": "2026-04-06T17:17:11.870",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 4.0.0, < 4.1.4; < 3.0.5",
            "fixed": "See vendor advisory",
            "source_count": 147,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-248",
            "what_happened": "Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reachable by calling cipher.KeyUnwrap() directly with any ciphertext parameter less than 16 bytes long, but calling this function directly is less common. Panics can lead to denial of service. This vulnerability is fixed in 4.1.4 and 3.0.5.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/go-jose/go-jose/security/advisories/GHSA-78h2-9frx-2jm8",
                "https://pkg.go.dev/github.com/go-jose/go-jose/v4#pkg-constants",
                "https://access.redhat.com/errata/RHSA-2026:10125",
                "https://access.redhat.com/errata/RHSA-2026:10130",
                "https://access.redhat.com/errata/RHSA-2026:10135",
                "https://access.redhat.com/errata/RHSA-2026:10175",
                "https://access.redhat.com/errata/RHSA-2026:11070",
                "https://access.redhat.com/errata/RHSA-2026:11217",
                "https://access.redhat.com/errata/RHSA-2026:11512",
                "https://access.redhat.com/errata/RHSA-2026:11688",
                "https://access.redhat.com/errata/RHSA-2026:11856",
                "https://access.redhat.com/errata/RHSA-2026:11916",
                "https://access.redhat.com/errata/RHSA-2026:11996",
                "https://access.redhat.com/errata/RHSA-2026:12116",
                "https://access.redhat.com/errata/RHSA-2026:12277",
                "https://access.redhat.com/errata/RHSA-2026:12279",
                "https://access.redhat.com/errata/RHSA-2026:13791",
                "https://access.redhat.com/errata/RHSA-2026:13829",
                "https://access.redhat.com/errata/RHSA-2026:16696",
                "https://access.redhat.com/errata/RHSA-2026:17040",
                "https://access.redhat.com/errata/RHSA-2026:17121",
                "https://access.redhat.com/errata/RHSA-2026:17123",
                "https://access.redhat.com/errata/RHSA-2026:17287",
                "https://access.redhat.com/errata/RHSA-2026:17448",
                "https://access.redhat.com/errata/RHSA-2026:17458",
                "https://access.redhat.com/errata/RHSA-2026:17459",
                "https://access.redhat.com/errata/RHSA-2026:17468",
                "https://access.redhat.com/errata/RHSA-2026:17474",
                "https://access.redhat.com/errata/RHSA-2026:17547",
                "https://access.redhat.com/errata/RHSA-2026:17550",
                "https://access.redhat.com/errata/RHSA-2026:17598",
                "https://access.redhat.com/errata/RHSA-2026:17789",
                "https://access.redhat.com/errata/RHSA-2026:18584",
                "https://access.redhat.com/errata/RHSA-2026:18585",
                "https://access.redhat.com/errata/RHSA-2026:19017",
                "https://access.redhat.com/errata/RHSA-2026:19099",
                "https://access.redhat.com/errata/RHSA-2026:19108",
                "https://access.redhat.com/errata/RHSA-2026:19135",
                "https://access.redhat.com/errata/RHSA-2026:19173",
                "https://access.redhat.com/errata/RHSA-2026:19186",
                "https://access.redhat.com/errata/RHSA-2026:19353",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:19719",
                "https://access.redhat.com/errata/RHSA-2026:19720",
                "https://access.redhat.com/errata/RHSA-2026:19721",
                "https://access.redhat.com/errata/RHSA-2026:20034",
                "https://access.redhat.com/errata/RHSA-2026:20041",
                "https://access.redhat.com/errata/RHSA-2026:20569",
                "https://access.redhat.com/errata/RHSA-2026:20607",
                "https://access.redhat.com/errata/RHSA-2026:20609",
                "https://access.redhat.com/errata/RHSA-2026:20946",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:21703",
                "https://access.redhat.com/errata/RHSA-2026:21709",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:21931",
                "https://access.redhat.com/errata/RHSA-2026:21932",
                "https://access.redhat.com/errata/RHSA-2026:22258",
                "https://access.redhat.com/errata/RHSA-2026:22260",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:22450",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22629",
                "https://access.redhat.com/errata/RHSA-2026:22714",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:22937",
                "https://access.redhat.com/errata/RHSA-2026:23228",
                "https://access.redhat.com/errata/RHSA-2026:23241",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24471",
                "https://access.redhat.com/errata/RHSA-2026:24475",
                "https://access.redhat.com/errata/RHSA-2026:24477",
                "https://access.redhat.com/errata/RHSA-2026:24479",
                "https://access.redhat.com/errata/RHSA-2026:24482",
                "https://access.redhat.com/errata/RHSA-2026:24484",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:25127",
                "https://access.redhat.com/errata/RHSA-2026:25187",
                "https://access.redhat.com/errata/RHSA-2026:25194",
                "https://access.redhat.com/errata/RHSA-2026:25206",
                "https://access.redhat.com/errata/RHSA-2026:25248",
                "https://access.redhat.com/errata/RHSA-2026:25250",
                "https://access.redhat.com/errata/RHSA-2026:25252",
                "https://access.redhat.com/errata/RHSA-2026:26054",
                "https://access.redhat.com/errata/RHSA-2026:26568",
                "https://access.redhat.com/errata/RHSA-2026:26585",
                "https://access.redhat.com/errata/RHSA-2026:26636",
                "https://access.redhat.com/errata/RHSA-2026:27001",
                "https://access.redhat.com/errata/RHSA-2026:27004",
                "https://access.redhat.com/errata/RHSA-2026:27044",
                "https://access.redhat.com/errata/RHSA-2026:27063",
                "https://access.redhat.com/errata/RHSA-2026:27856",
                "https://access.redhat.com/errata/RHSA-2026:28198",
                "https://access.redhat.com/errata/RHSA-2026:29854",
                "https://access.redhat.com/errata/RHSA-2026:30650",
                "https://access.redhat.com/errata/RHSA-2026:32991",
                "https://access.redhat.com/errata/RHSA-2026:33722",
                "https://access.redhat.com/errata/RHSA-2026:34099",
                "https://access.redhat.com/errata/RHSA-2026:34192",
                "https://access.redhat.com/errata/RHSA-2026:34196",
                "https://access.redhat.com/errata/RHSA-2026:34197",
                "https://access.redhat.com/errata/RHSA-2026:34364",
                "https://access.redhat.com/errata/RHSA-2026:34794",
                "https://access.redhat.com/errata/RHSA-2026:35833",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:37387",
                "https://access.redhat.com/errata/RHSA-2026:40984",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41941",
                "https://access.redhat.com/errata/RHSA-2026:41944",
                "https://access.redhat.com/errata/RHSA-2026:44267",
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:47952",
                "https://access.redhat.com/errata/RHSA-2026:48085",
                "https://access.redhat.com/errata/RHSA-2026:48676",
                "https://access.redhat.com/errata/RHSA-2026:48790",
                "https://access.redhat.com/errata/RHSA-2026:49944",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:54602",
                "https://access.redhat.com/errata/RHSA-2026:56366",
                "https://access.redhat.com/errata/RHSA-2026:56431",
                "https://access.redhat.com/errata/RHSA-2026:56968",
                "https://access.redhat.com/errata/RHSA-2026:57013",
                "https://access.redhat.com/errata/RHSA-2026:57408",
                "https://access.redhat.com/errata/RHSA-2026:57487",
                "https://access.redhat.com/errata/RHSA-2026:57590",
                "https://access.redhat.com/errata/RHSA-2026:60023",
                "https://access.redhat.com/errata/RHSA-2026:60444",
                "https://access.redhat.com/errata/RHSA-2026:60449",
                "https://access.redhat.com/errata/RHSA-2026:60452",
                "https://access.redhat.com/errata/RHSA-2026:62260",
                "https://access.redhat.com/errata/RHSA-2026:8490",
                "https://access.redhat.com/errata/RHSA-2026:8491",
                "https://access.redhat.com/errata/RHSA-2026:8493",
                "https://access.redhat.com/errata/RHSA-2026:9385",
                "https://access.redhat.com/errata/RHSA-2026:9388",
                "https://access.redhat.com/errata/RHSA-2026:9448",
                "https://access.redhat.com/errata/RHSA-2026:9453",
                "https://access.redhat.com/security/cve/CVE-2026-34986",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2455470",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34986.json",
                "https://access.redhat.com/errata/RHSA-2026:62548",
                "https://access.redhat.com/errata/RHSA-2026:62550"
            ],
            "timeline": [
                {
                    "at": "2026-04-06T17:17:11.870",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34986"
                }
            ]
        },
        {
            "id": "CVE-2026-34486",
            "vendor": "Apache",
            "product": "Tomcat",
            "title": "Apache Tomcat Missing Encryption of Sensitive Data Vulnerability",
            "summary": "Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.",
            "updated_at": "2026-08-03T22:00:00Z",
            "published_at": "2026-08-03T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-33997",
            "vendor": "moby",
            "product": "moby",
            "title": "moby vulnerability",
            "summary": "Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1.",
            "updated_at": "2026-09-07T13:19:06.793",
            "published_at": "2026-03-31T03:15:57.523",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 29.3.1",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-193",
            "what_happened": "Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the user. Plugins that request exactly one privilege are also affected, because no comparison is performed at all. This issue has been patched in version 29.3.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/moby/moby/releases/tag/docker-v29.3.1",
                "https://github.com/moby/moby/security/advisories/GHSA-pxq6-2prw-chj9",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/security/cve/CVE-2026-33997",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2453277",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33997.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-31T03:15:57.523",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33997"
                }
            ]
        },
        {
            "id": "CVE-2026-33970",
            "vendor": "Samsung",
            "product": "Exynos 850 firmware",
            "title": "Exynos 850 firmware vulnerability",
            "summary": "An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when processing a malformed RRC Reconfiguration message.",
            "updated_at": "2026-09-14T03:16:36.750",
            "published_at": "2026-09-14T03:16:36.750",
            "cvss": 3.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-24 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-476",
            "what_happened": "An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when processing a malformed RRC Reconfiguration message.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-33970/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T03:16:36.750",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33970"
                }
            ]
        },
        {
            "id": "CVE-2026-33968",
            "vendor": "Samsung",
            "product": "Exynos 1330 firmware",
            "title": "Exynos 1330 firmware vulnerability",
            "summary": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access.",
            "updated_at": "2026-09-14T03:16:36.607",
            "published_at": "2026-09-14T03:16:36.607",
            "cvss": 2.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-15 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-125",
            "what_happened": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-33968/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T03:16:36.607",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33968"
                }
            ]
        },
        {
            "id": "CVE-2026-33967",
            "vendor": "Samsung",
            "product": "Exynos 1330 firmware",
            "title": "Exynos 1330 firmware vulnerability",
            "summary": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corruption.",
            "updated_at": "2026-09-14T03:16:36.463",
            "published_at": "2026-09-14T03:16:36.463",
            "cvss": 2.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-15 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-787",
            "what_happened": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-33967/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T03:16:36.463",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33967"
                }
            ]
        },
        {
            "id": "CVE-2026-33966",
            "vendor": "Samsung",
            "product": "Exynos 1330 firmware",
            "title": "Exynos 1330 firmware vulnerability",
            "summary": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code.",
            "updated_at": "2026-09-14T03:16:36.313",
            "published_at": "2026-09-14T03:16:36.313",
            "cvss": 2.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-15 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-215",
            "what_happened": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-33966/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T03:16:36.313",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33966"
                }
            ]
        },
        {
            "id": "CVE-2026-33964",
            "vendor": "Samsung",
            "product": "Exynos 1580 firmware",
            "title": "Exynos 1580 firmware vulnerability",
            "summary": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service.",
            "updated_at": "2026-09-14T02:17:14.987",
            "published_at": "2026-09-14T02:17:14.987",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-29 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-822",
            "what_happened": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent to the camera driver, causing limited information disclosure or denial of service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-33964/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:14.987",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33964"
                }
            ]
        },
        {
            "id": "CVE-2026-33963",
            "vendor": "Samsung",
            "product": "Exynos 1330 firmware",
            "title": "Exynos 1330 firmware vulnerability",
            "summary": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.",
            "updated_at": "2026-09-14T02:17:14.850",
            "published_at": "2026-09-14T02:17:14.850",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-29 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-121",
            "what_happened": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-33963/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:14.850",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33963"
                }
            ]
        },
        {
            "id": "CVE-2026-33962",
            "vendor": "Samsung",
            "product": "Exynos 850 firmware",
            "title": "Exynos 850 firmware vulnerability",
            "summary": "An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage.",
            "updated_at": "2026-09-14T02:17:14.703",
            "published_at": "2026-09-14T02:17:14.703",
            "cvss": 2.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2026-02-02 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-125",
            "what_happened": "An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-33962/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:14.703",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33962"
                }
            ]
        },
        {
            "id": "CVE-2026-33960",
            "vendor": "Samsung",
            "product": "Exynos 1330 firmware",
            "title": "Exynos 1330 firmware vulnerability",
            "summary": "An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl command to the Wi-Fi interface device can lead to improper buffer size allocation, resulting in an out-of-bounds write and causing a denial of service (DoS).",
            "updated_at": "2026-09-14T02:17:14.547",
            "published_at": "2026-09-14T02:17:14.547",
            "cvss": 2.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-18 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-787",
            "what_happened": "An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl command to the Wi-Fi interface device can lead to improper buffer size allocation, resulting in an out-of-bounds write and causing a denial of service (DoS).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-33960/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:14.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33960"
                }
            ]
        },
        {
            "id": "CVE-2026-33957",
            "vendor": "Samsung",
            "product": "Exynos 1580 firmware",
            "title": "Exynos 1580 firmware vulnerability",
            "summary": "An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially leading to memory corruption or information leakage.",
            "updated_at": "2026-09-14T02:17:14.390",
            "published_at": "2026-09-14T02:17:14.390",
            "cvss": 4.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2026-01-07 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-787",
            "what_happened": "An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially leading to memory corruption or information leakage.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-33957/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:14.390",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33957"
                }
            ]
        },
        {
            "id": "CVE-2026-33956",
            "vendor": "Samsung",
            "product": "Exynos 1330 firmware",
            "title": "Exynos 1330 firmware vulnerability",
            "summary": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malformed message to the test_msg sysfs entry causes an out-of-bounds write, leading to denial of service.",
            "updated_at": "2026-09-14T02:17:14.230",
            "published_at": "2026-09-14T02:17:14.230",
            "cvss": 2.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-02 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-787",
            "what_happened": "An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malformed message to the test_msg sysfs entry causes an out-of-bounds write, leading to denial of service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-33956/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:14.230",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33956"
                }
            ]
        },
        {
            "id": "CVE-2026-33894",
            "vendor": "digitalbazaar",
            "product": "forge",
            "title": "forge vulnerability",
            "summary": "Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attackers can forge signatures by stuffing “garbage” bytes within the ASN structure in order to construct a signature that passes verification, enabling Bleichenbacher style forgery. This issue is similar to CVE-2022-24771, but adds bytes in an addition field within the ASN structure, rather than outside of it.  Additionally, forge does not validate that signatures include a minimum of 8 bytes of padding as defined by the specification, providing attackers additional space to construct Bleichenbacher forgeries. Version 1.4.0 patches the issue.",
            "updated_at": "2026-09-10T13:18:25.977",
            "published_at": "2026-03-27T21:17:25.983",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.4.0",
            "fixed": "See vendor advisory",
            "source_count": 4113,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attackers can forge signatures by stuffing “garbage” bytes within the ASN structure in order to construct a signature that passes verification, enabling Bleichenbacher style forgery. This issue is similar to CVE-2022-24771, but adds bytes in an addition field within the ASN structure, rather than outside of it.  Additionally, forge does not validate that signatures include a minimum of 8 bytes of padding as defined by the specification, providing attackers additional space to construct Bleichenbacher forgeries. Version 1.4.0 patches the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://datatracker.ietf.org/doc/html/rfc2313#section-8",
                "https://github.com/digitalbazaar/forge/security/advisories/GHSA-ppp5-5v6c-4jwp",
                "https://mailarchive.ietf.org/arch/msg/openpgp/5rnE9ZRN1AokBVj3VqblGlP63QE",
                "https://www.rfc-editor.org/rfc/rfc8017.html",
                "https://access.redhat.com/errata/RHSA-2026:13826",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22629",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24761",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:34342",
                "https://access.redhat.com/errata/RHSA-2026:9742",
                "https://access.redhat.com/security/cve/CVE-2026-33894",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2452464",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33894.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-27T21:17:25.983",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33894"
                }
            ]
        },
        {
            "id": "CVE-2026-33871",
            "vendor": "netty",
            "product": "netty",
            "title": "netty vulnerability",
            "summary": "Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.",
            "updated_at": "2026-09-14T13:18:18.077",
            "published_at": "2026-03-27T20:16:34.833",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 4.1.132.Final; >= 4.2.0.Alpha1, < 4.2.10.Final",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to cause excessive CPU consumption with minimal bandwidth, rendering the server unresponsive. Versions 4.1.132.Final and 4.2.10.Final fix the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/netty/netty/security/advisories/GHSA-w9fj-cfpg-grvv",
                "https://access.redhat.com/errata/RHSA-2026:10175",
                "https://access.redhat.com/errata/RHSA-2026:10184",
                "https://access.redhat.com/errata/RHSA-2026:13571",
                "https://access.redhat.com/errata/RHSA-2026:14272",
                "https://access.redhat.com/errata/RHSA-2026:14276",
                "https://access.redhat.com/errata/RHSA-2026:17668",
                "https://access.redhat.com/errata/RHSA-2026:17789",
                "https://access.redhat.com/errata/RHSA-2026:18054",
                "https://access.redhat.com/errata/RHSA-2026:18055",
                "https://access.redhat.com/errata/RHSA-2026:18059",
                "https://access.redhat.com/errata/RHSA-2026:22619",
                "https://access.redhat.com/errata/RHSA-2026:34608",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:7109",
                "https://access.redhat.com/errata/RHSA-2026:7380",
                "https://access.redhat.com/errata/RHSA-2026:8159",
                "https://access.redhat.com/errata/RHSA-2026:8509",
                "https://access.redhat.com/security/cve/CVE-2026-33871",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2452456",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33871.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-27T20:16:34.833",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33871"
                }
            ]
        },
        {
            "id": "CVE-2026-33870",
            "vendor": "netty",
            "product": "netty",
            "title": "netty vulnerability",
            "summary": "Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.",
            "updated_at": "2026-09-14T13:18:17.593",
            "published_at": "2026-03-27T20:16:34.663",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 4.1.132.Final; >= 4.2.0.Alpha1, < 4.2.10.Final",
            "fixed": "See vendor advisory",
            "source_count": 33,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-444",
            "what_happened": "Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, Netty incorrectly parses quoted strings in HTTP/1.1 chunked transfer encoding extension values, enabling request smuggling attacks. Versions 4.1.132.Final and 4.2.10.Final fix the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-27",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/netty/netty/security/advisories/GHSA-pwqr-wmgm-9rr8"
                }
            ],
            "references": [
                "https://github.com/netty/netty/security/advisories/GHSA-pwqr-wmgm-9rr8",
                "https://w4ke.info/2025/06/18/funky-chunks.html",
                "https://w4ke.info/2025/10/29/funky-chunks-2.html",
                "https://www.rfc-editor.org/rfc/rfc9110",
                "https://access.redhat.com/errata/RHSA-2026:10175",
                "https://access.redhat.com/errata/RHSA-2026:10184",
                "https://access.redhat.com/errata/RHSA-2026:13571",
                "https://access.redhat.com/errata/RHSA-2026:14272",
                "https://access.redhat.com/errata/RHSA-2026:14276",
                "https://access.redhat.com/errata/RHSA-2026:17668",
                "https://access.redhat.com/errata/RHSA-2026:17789",
                "https://access.redhat.com/errata/RHSA-2026:18054",
                "https://access.redhat.com/errata/RHSA-2026:18055",
                "https://access.redhat.com/errata/RHSA-2026:18059",
                "https://access.redhat.com/errata/RHSA-2026:22619",
                "https://access.redhat.com/errata/RHSA-2026:34608",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:7109",
                "https://access.redhat.com/errata/RHSA-2026:7380",
                "https://access.redhat.com/errata/RHSA-2026:8159",
                "https://access.redhat.com/errata/RHSA-2026:8509",
                "https://access.redhat.com/security/cve/CVE-2026-33870",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2452453",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33870.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-27T20:16:34.663",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33870"
                }
            ]
        },
        {
            "id": "CVE-2026-33824",
            "vendor": "Microsoft",
            "product": "Internet Key Exchange (IKE) Service Extensions",
            "title": "Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability",
            "summary": "Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.",
            "updated_at": "2026-08-17T22:00:00Z",
            "published_at": "2026-08-17T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-17T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-33816",
            "vendor": "github.com/jackc/pgx/v5",
            "product": "github.com/jackc/pgx/v5/pgproto3",
            "title": "github.com/jackc/pgx/v5/pgproto3 vulnerability",
            "summary": "Memory-safety vulnerability in github.com/jackc/pgx/v5.",
            "updated_at": "2026-09-10T13:18:25.350",
            "published_at": "2026-04-07T16:16:24.920",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.9.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 26,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "Memory-safety vulnerability in github.com/jackc/pgx/v5.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://pkg.go.dev/vuln/GO-2026-4772",
                "https://access.redhat.com/errata/RHSA-2026:11070",
                "https://access.redhat.com/errata/RHSA-2026:11217",
                "https://access.redhat.com/errata/RHSA-2026:13791",
                "https://access.redhat.com/errata/RHSA-2026:13829",
                "https://access.redhat.com/errata/RHSA-2026:13907",
                "https://access.redhat.com/errata/RHSA-2026:17789",
                "https://access.redhat.com/errata/RHSA-2026:19137",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:24475",
                "https://access.redhat.com/errata/RHSA-2026:24479",
                "https://access.redhat.com/errata/RHSA-2026:24482",
                "https://access.redhat.com/errata/RHSA-2026:24503",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:25273",
                "https://access.redhat.com/errata/RHSA-2026:26519",
                "https://access.redhat.com/errata/RHSA-2026:26636",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:40984",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:62866",
                "https://access.redhat.com/security/cve/CVE-2026-33816",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2455972",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33816.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-07T16:16:24.920",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33816"
                }
            ]
        },
        {
            "id": "CVE-2026-33815",
            "vendor": "github.com/jackc/pgx/v5",
            "product": "github.com/jackc/pgx/v5/pgproto3",
            "title": "github.com/jackc/pgx/v5/pgproto3 vulnerability",
            "summary": "Memory-safety vulnerability in github.com/jackc/pgx/v5.",
            "updated_at": "2026-09-10T13:18:24.803",
            "published_at": "2026-04-07T16:16:24.813",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.9.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "Memory-safety vulnerability in github.com/jackc/pgx/v5.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://pkg.go.dev/vuln/GO-2026-4771",
                "https://access.redhat.com/errata/RHSA-2026:11070",
                "https://access.redhat.com/errata/RHSA-2026:11217",
                "https://access.redhat.com/errata/RHSA-2026:13791",
                "https://access.redhat.com/errata/RHSA-2026:13829",
                "https://access.redhat.com/errata/RHSA-2026:17789",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:24475",
                "https://access.redhat.com/errata/RHSA-2026:24479",
                "https://access.redhat.com/errata/RHSA-2026:24482",
                "https://access.redhat.com/errata/RHSA-2026:24503",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:25273",
                "https://access.redhat.com/errata/RHSA-2026:26636",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:40984",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/security/cve/CVE-2026-33815",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2455975",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33815.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-07T16:16:24.813",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33815"
                }
            ]
        },
        {
            "id": "CVE-2026-33814",
            "vendor": "golang.org/x/net",
            "product": "golang.org/x/net/http2",
            "title": "golang.org/x/net/http2 vulnerability",
            "summary": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.",
            "updated_at": "2026-09-16T13:17:43.937",
            "published_at": "2026-05-07T20:16:42.880",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.53.0 (semver); before 1.25.10 (semver); 1.26.0-0 through before 1.26.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 70,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-835",
            "what_happened": "When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/761581",
                "https://go.dev/cl/761640",
                "https://go.dev/issue/78476",
                "https://groups.google.com/g/golang-announce/c/qcCIEXso47M",
                "https://pkg.go.dev/vuln/GO-2026-4918",
                "https://access.redhat.com/errata/RHSA-2026:22112",
                "https://access.redhat.com/errata/RHSA-2026:22120",
                "https://access.redhat.com/errata/RHSA-2026:22121",
                "https://access.redhat.com/errata/RHSA-2026:23262",
                "https://access.redhat.com/errata/RHSA-2026:23264",
                "https://access.redhat.com/errata/RHSA-2026:33120",
                "https://access.redhat.com/errata/RHSA-2026:33123",
                "https://access.redhat.com/errata/RHSA-2026:33142",
                "https://access.redhat.com/errata/RHSA-2026:33150",
                "https://access.redhat.com/errata/RHSA-2026:34342",
                "https://access.redhat.com/errata/RHSA-2026:37387",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:43692",
                "https://access.redhat.com/errata/RHSA-2026:49702",
                "https://access.redhat.com/errata/RHSA-2026:49712",
                "https://access.redhat.com/errata/RHSA-2026:50205",
                "https://access.redhat.com/errata/RHSA-2026:54274",
                "https://access.redhat.com/errata/RHSA-2026:54283",
                "https://access.redhat.com/errata/RHSA-2026:54284",
                "https://access.redhat.com/errata/RHSA-2026:54285",
                "https://access.redhat.com/errata/RHSA-2026:54286",
                "https://access.redhat.com/errata/RHSA-2026:54287",
                "https://access.redhat.com/errata/RHSA-2026:56854",
                "https://access.redhat.com/errata/RHSA-2026:56912",
                "https://access.redhat.com/errata/RHSA-2026:57191",
                "https://access.redhat.com/errata/RHSA-2026:57194",
                "https://access.redhat.com/errata/RHSA-2026:57365",
                "https://access.redhat.com/errata/RHSA-2026:57367",
                "https://access.redhat.com/errata/RHSA-2026:57408",
                "https://access.redhat.com/errata/RHSA-2026:57545",
                "https://access.redhat.com/errata/RHSA-2026:57649",
                "https://access.redhat.com/errata/RHSA-2026:57845",
                "https://access.redhat.com/errata/RHSA-2026:59833",
                "https://access.redhat.com/errata/RHSA-2026:60023",
                "https://access.redhat.com/errata/RHSA-2026:60025",
                "https://access.redhat.com/errata/RHSA-2026:60441",
                "https://access.redhat.com/errata/RHSA-2026:60442",
                "https://access.redhat.com/errata/RHSA-2026:60446",
                "https://access.redhat.com/errata/RHSA-2026:60447",
                "https://access.redhat.com/errata/RHSA-2026:60454",
                "https://access.redhat.com/errata/RHSA-2026:60477",
                "https://access.redhat.com/errata/RHSA-2026:60478",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:60668",
                "https://access.redhat.com/errata/RHSA-2026:61253",
                "https://access.redhat.com/security/cve/CVE-2026-33814",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2467815",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33814.json",
                "https://access.redhat.com/errata/RHSA-2026:62550",
                "https://access.redhat.com/errata/RHSA-2026:62551",
                "https://access.redhat.com/errata/RHSA-2026:63046",
                "https://access.redhat.com/errata/RHSA-2026:63047",
                "https://access.redhat.com/errata/RHSA-2026:63048",
                "https://access.redhat.com/errata/RHSA-2026:63050",
                "https://access.redhat.com/errata/RHSA-2026:63091",
                "https://access.redhat.com/errata/RHSA-2026:63096",
                "https://access.redhat.com/errata/RHSA-2026:63097",
                "https://access.redhat.com/errata/RHSA-2026:63103",
                "https://access.redhat.com/errata/RHSA-2026:63104",
                "https://access.redhat.com/errata/RHSA-2026:63636",
                "https://access.redhat.com/errata/RHSA-2026:63637",
                "https://access.redhat.com/errata/RHSA-2026:63639",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:62410",
                "https://access.redhat.com/errata/RHSA-2026:66350"
            ],
            "timeline": [
                {
                    "at": "2026-05-07T20:16:42.880",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33814"
                }
            ]
        },
        {
            "id": "CVE-2026-33811",
            "vendor": "Go standard library",
            "product": "net",
            "title": "net vulnerability",
            "summary": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.",
            "updated_at": "2026-09-15T12:17:24.830",
            "published_at": "2026-05-07T20:16:42.770",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.25.10 (semver); 1.26.0-0 through before 1.26.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 132,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-415",
            "what_happened": "When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/767860",
                "https://go.dev/issue/78803",
                "https://groups.google.com/g/golang-announce/c/qcCIEXso47M",
                "https://pkg.go.dev/vuln/GO-2026-4981",
                "https://access.redhat.com/errata/RHSA-2026:22112",
                "https://access.redhat.com/errata/RHSA-2026:22120",
                "https://access.redhat.com/errata/RHSA-2026:22121",
                "https://access.redhat.com/errata/RHSA-2026:23262",
                "https://access.redhat.com/errata/RHSA-2026:23264",
                "https://access.redhat.com/errata/RHSA-2026:33120",
                "https://access.redhat.com/errata/RHSA-2026:33123",
                "https://access.redhat.com/errata/RHSA-2026:33142",
                "https://access.redhat.com/errata/RHSA-2026:33150",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:34357",
                "https://access.redhat.com/errata/RHSA-2026:34359",
                "https://access.redhat.com/errata/RHSA-2026:34364",
                "https://access.redhat.com/errata/RHSA-2026:35832",
                "https://access.redhat.com/errata/RHSA-2026:35993",
                "https://access.redhat.com/errata/RHSA-2026:35994",
                "https://access.redhat.com/errata/RHSA-2026:35995",
                "https://access.redhat.com/errata/RHSA-2026:36207",
                "https://access.redhat.com/errata/RHSA-2026:36319",
                "https://access.redhat.com/errata/RHSA-2026:36617",
                "https://access.redhat.com/errata/RHSA-2026:36625",
                "https://access.redhat.com/errata/RHSA-2026:36648",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36776",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:36797",
                "https://access.redhat.com/errata/RHSA-2026:38504",
                "https://access.redhat.com/errata/RHSA-2026:39266",
                "https://access.redhat.com/errata/RHSA-2026:39272",
                "https://access.redhat.com/errata/RHSA-2026:39319",
                "https://access.redhat.com/errata/RHSA-2026:39573",
                "https://access.redhat.com/errata/RHSA-2026:39810",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41030",
                "https://access.redhat.com/errata/RHSA-2026:41055",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:42043",
                "https://access.redhat.com/errata/RHSA-2026:42047",
                "https://access.redhat.com/errata/RHSA-2026:42048",
                "https://access.redhat.com/errata/RHSA-2026:42049",
                "https://access.redhat.com/errata/RHSA-2026:42050",
                "https://access.redhat.com/errata/RHSA-2026:42051",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:42079",
                "https://access.redhat.com/errata/RHSA-2026:42082",
                "https://access.redhat.com/errata/RHSA-2026:42132",
                "https://access.redhat.com/errata/RHSA-2026:42150",
                "https://access.redhat.com/errata/RHSA-2026:42151",
                "https://access.redhat.com/errata/RHSA-2026:42240",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:42852",
                "https://access.redhat.com/errata/RHSA-2026:42946",
                "https://access.redhat.com/errata/RHSA-2026:43038",
                "https://access.redhat.com/errata/RHSA-2026:43692",
                "https://access.redhat.com/errata/RHSA-2026:44622",
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:47149",
                "https://access.redhat.com/errata/RHSA-2026:47735",
                "https://access.redhat.com/errata/RHSA-2026:47952",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:49702",
                "https://access.redhat.com/errata/RHSA-2026:49703",
                "https://access.redhat.com/errata/RHSA-2026:49712",
                "https://access.redhat.com/errata/RHSA-2026:50205",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/errata/RHSA-2026:50319",
                "https://access.redhat.com/errata/RHSA-2026:50336",
                "https://access.redhat.com/errata/RHSA-2026:50843",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:51057",
                "https://access.redhat.com/errata/RHSA-2026:51187",
                "https://access.redhat.com/errata/RHSA-2026:51194",
                "https://access.redhat.com/errata/RHSA-2026:51341",
                "https://access.redhat.com/errata/RHSA-2026:53412",
                "https://access.redhat.com/errata/RHSA-2026:53413",
                "https://access.redhat.com/errata/RHSA-2026:53415",
                "https://access.redhat.com/errata/RHSA-2026:53530",
                "https://access.redhat.com/errata/RHSA-2026:54168",
                "https://access.redhat.com/errata/RHSA-2026:54191",
                "https://access.redhat.com/errata/RHSA-2026:54274",
                "https://access.redhat.com/errata/RHSA-2026:54283",
                "https://access.redhat.com/errata/RHSA-2026:54284",
                "https://access.redhat.com/errata/RHSA-2026:54285",
                "https://access.redhat.com/errata/RHSA-2026:54286",
                "https://access.redhat.com/errata/RHSA-2026:54287",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:54441",
                "https://access.redhat.com/errata/RHSA-2026:54500",
                "https://access.redhat.com/errata/RHSA-2026:54552",
                "https://access.redhat.com/errata/RHSA-2026:54556",
                "https://access.redhat.com/errata/RHSA-2026:54584",
                "https://access.redhat.com/errata/RHSA-2026:54602",
                "https://access.redhat.com/errata/RHSA-2026:54603",
                "https://access.redhat.com/errata/RHSA-2026:54757",
                "https://access.redhat.com/errata/RHSA-2026:56340",
                "https://access.redhat.com/errata/RHSA-2026:56785",
                "https://access.redhat.com/errata/RHSA-2026:56789",
                "https://access.redhat.com/errata/RHSA-2026:56790",
                "https://access.redhat.com/errata/RHSA-2026:56852",
                "https://access.redhat.com/errata/RHSA-2026:56855",
                "https://access.redhat.com/errata/RHSA-2026:56910",
                "https://access.redhat.com/errata/RHSA-2026:56912",
                "https://access.redhat.com/errata/RHSA-2026:56913",
                "https://access.redhat.com/errata/RHSA-2026:57191",
                "https://access.redhat.com/errata/RHSA-2026:57194",
                "https://access.redhat.com/errata/RHSA-2026:57482",
                "https://access.redhat.com/errata/RHSA-2026:57488",
                "https://access.redhat.com/errata/RHSA-2026:57649",
                "https://access.redhat.com/errata/RHSA-2026:59467",
                "https://access.redhat.com/errata/RHSA-2026:59559",
                "https://access.redhat.com/errata/RHSA-2026:60018",
                "https://access.redhat.com/errata/RHSA-2026:60025",
                "https://access.redhat.com/errata/RHSA-2026:60302",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:61253",
                "https://access.redhat.com/errata/RHSA-2026:61313",
                "https://access.redhat.com/security/cve/CVE-2026-33811",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2467822",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33811.json",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:65534",
                "https://access.redhat.com/errata/RHSA-2026:65886",
                "https://access.redhat.com/errata/RHSA-2026:66022",
                "https://access.redhat.com/errata/RHSA-2026:67149",
                "https://access.redhat.com/errata/RHSA-2026:67287",
                "https://access.redhat.com/errata/RHSA-2026:67319"
            ],
            "timeline": [
                {
                    "at": "2026-05-07T20:16:42.770",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33811"
                }
            ]
        },
        {
            "id": "CVE-2026-33810",
            "vendor": "Go standard library",
            "product": "crypto/x509",
            "title": "crypto/x509 vulnerability",
            "summary": "When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.",
            "updated_at": "2026-09-16T13:17:40.520",
            "published_at": "2026-04-08T02:16:03.950",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.26.0-0 through before 1.26.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 85,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/763763",
                "https://go.dev/issue/78332",
                "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU",
                "https://pkg.go.dev/vuln/GO-2026-4866",
                "http://www.openwall.com/lists/oss-security/2026/04/19/4",
                "http://www.openwall.com/lists/oss-security/2026/04/20/1",
                "https://access.redhat.com/errata/RHSA-2026:10155",
                "https://access.redhat.com/errata/RHSA-2026:10158",
                "https://access.redhat.com/errata/RHSA-2026:13545",
                "https://access.redhat.com/errata/RHSA-2026:14391",
                "https://access.redhat.com/errata/RHSA-2026:19135",
                "https://access.redhat.com/errata/RHSA-2026:19144",
                "https://access.redhat.com/errata/RHSA-2026:19353",
                "https://access.redhat.com/errata/RHSA-2026:19714",
                "https://access.redhat.com/errata/RHSA-2026:19719",
                "https://access.redhat.com/errata/RHSA-2026:19720",
                "https://access.redhat.com/errata/RHSA-2026:19721",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:21772",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22485",
                "https://access.redhat.com/errata/RHSA-2026:22862",
                "https://access.redhat.com/errata/RHSA-2026:22958",
                "https://access.redhat.com/errata/RHSA-2026:22959",
                "https://access.redhat.com/errata/RHSA-2026:22960",
                "https://access.redhat.com/errata/RHSA-2026:22961",
                "https://access.redhat.com/errata/RHSA-2026:22962",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:24478",
                "https://access.redhat.com/errata/RHSA-2026:25089",
                "https://access.redhat.com/errata/RHSA-2026:26568",
                "https://access.redhat.com/errata/RHSA-2026:26571",
                "https://access.redhat.com/errata/RHSA-2026:26585",
                "https://access.redhat.com/errata/RHSA-2026:28047",
                "https://access.redhat.com/errata/RHSA-2026:29854",
                "https://access.redhat.com/errata/RHSA-2026:34192",
                "https://access.redhat.com/errata/RHSA-2026:34196",
                "https://access.redhat.com/errata/RHSA-2026:34197",
                "https://access.redhat.com/errata/RHSA-2026:34365",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:39810",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:42043",
                "https://access.redhat.com/errata/RHSA-2026:42047",
                "https://access.redhat.com/errata/RHSA-2026:42049",
                "https://access.redhat.com/errata/RHSA-2026:42050",
                "https://access.redhat.com/errata/RHSA-2026:42051",
                "https://access.redhat.com/errata/RHSA-2026:47952",
                "https://access.redhat.com/errata/RHSA-2026:49702",
                "https://access.redhat.com/errata/RHSA-2026:49703",
                "https://access.redhat.com/errata/RHSA-2026:49712",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:51288",
                "https://access.redhat.com/errata/RHSA-2026:54757",
                "https://access.redhat.com/errata/RHSA-2026:56143",
                "https://access.redhat.com/errata/RHSA-2026:56223",
                "https://access.redhat.com/errata/RHSA-2026:57126",
                "https://access.redhat.com/errata/RHSA-2026:57649",
                "https://access.redhat.com/errata/RHSA-2026:59546",
                "https://access.redhat.com/errata/RHSA-2026:61253",
                "https://access.redhat.com/errata/RHSA-2026:61313",
                "https://access.redhat.com/errata/RHSA-2026:61907",
                "https://access.redhat.com/errata/RHSA-2026:62577",
                "https://access.redhat.com/errata/RHSA-2026:62578",
                "https://access.redhat.com/errata/RHSA-2026:63332",
                "https://access.redhat.com/errata/RHSA-2026:7291",
                "https://access.redhat.com/errata/RHSA-2026:9385",
                "https://access.redhat.com/security/cve/CVE-2026-33810",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2456335",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33810.json",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:65359",
                "https://access.redhat.com/errata/RHSA-2026:65534",
                "https://access.redhat.com/errata/RHSA-2026:65880",
                "https://access.redhat.com/errata/RHSA-2026:65895",
                "https://access.redhat.com/errata/RHSA-2026:66327",
                "https://access.redhat.com/errata/RHSA-2026:67134",
                "https://access.redhat.com/errata/RHSA-2026:67149",
                "https://access.redhat.com/errata/RHSA-2026:67159",
                "https://access.redhat.com/errata/RHSA-2026:67160",
                "https://access.redhat.com/errata/RHSA-2026:67517",
                "https://access.redhat.com/errata/RHSA-2026:67518"
            ],
            "timeline": [
                {
                    "at": "2026-04-08T02:16:03.950",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33810"
                }
            ]
        },
        {
            "id": "CVE-2026-33630",
            "vendor": "c-ares",
            "product": "c-ares",
            "title": "c-ares vulnerability",
            "summary": "c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is present at multiple points in the resend/finish path (timeout handling, response handling, and query dispatch). If the query, or for ares_getaddrinfo() the owning host_query, is freed as a side effect of that callback, it is then accessed and/or freed a second time. This vulnerability is fixed in ver 1.34.7.",
            "updated_at": "2026-09-05T03:17:15.290",
            "published_at": "2026-09-03T19:17:27.420",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 1.32.3, < 1.34.7",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-415",
            "what_happened": "c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is present at multiple points in the resend/finish path (timeout handling, response handling, and query dispatch). If the query, or for ares_getaddrinfo() the owning host_query, is freed as a side effect of that callback, it is then accessed and/or freed a second time. This vulnerability is fixed in ver 1.34.7.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/c-ares/c-ares/commit/1fa3b86a0b8d18fe7b60f3228a01d770feb026bc",
                "https://github.com/c-ares/c-ares/commit/d823199b688052dcdc1646f2ab4cb8c16b1c644a",
                "https://github.com/c-ares/c-ares/pull/1237",
                "https://github.com/c-ares/c-ares/releases/tag/v1.34.7",
                "https://github.com/c-ares/c-ares/security/advisories/GHSA-6wfj-rwm7-3542"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T19:17:27.420",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33630"
                }
            ]
        },
        {
            "id": "CVE-2026-33487",
            "vendor": "russellhaering",
            "product": "goxmldsig",
            "title": "goxmldsig vulnerability",
            "summary": "goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID. In Go versions before 1.22, or when `go.mod` uses an older version, there is a loop variable capture issue. The code takes the address of the loop variable `_ref` instead of its value. As a result, if more than one reference matches the ID or if the loop logic is incorrect, the `ref` pointer will always end up pointing to the last element in the `SignedInfo.References` slice after the loop. goxmlsig version 1.6.0 contains a patch.",
            "updated_at": "2026-09-07T13:18:56.680",
            "published_at": "2026-03-26T18:16:30.070",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 1.6.0",
            "fixed": "See vendor advisory",
            "source_count": 46,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-347",
            "what_happened": "goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in `validate.go` goes through the references in the `SignedInfo` block to find one that matches the signed element's ID. In Go versions before 1.22, or when `go.mod` uses an older version, there is a loop variable capture issue. The code takes the address of the loop variable `_ref` instead of its value. As a result, if more than one reference matches the ID or if the loop logic is incorrect, the `ref` pointer will always end up pointing to the last element in the `SignedInfo.References` slice after the loop. goxmlsig version 1.6.0 contains a patch.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-26",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-479m-364c-43vc"
                }
            ],
            "references": [
                "https://github.com/russellhaering/goxmldsig/security/advisories/GHSA-479m-364c-43vc",
                "https://access.redhat.com/errata/RHSA-2026:13548",
                "https://access.redhat.com/errata/RHSA-2026:20943",
                "https://access.redhat.com/errata/RHSA-2026:20946",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/security/cve/CVE-2026-33487",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451814",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33487.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-26T18:16:30.070",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33487"
                }
            ]
        },
        {
            "id": "CVE-2026-33439",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Vulnerable endpoint description for CVE-2026-33439 in OpenAM",
            "summary": "Vulnerable endpoint description for CVE-2026-33439 in OpenAM",
            "updated_at": "2026-09-11T22:00:00Z",
            "published_at": "2026-09-11T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 53,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · shreyas-malhotra/CVE-2026-33439-OpenAM",
                    "author": "shreyas-malhotra",
                    "first_seen": "2026-04-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Vulnerable endpoint description for CVE-2026-33439 in OpenAM",
                    "summary": "Vulnerable endpoint description for CVE-2026-33439 in OpenAM",
                    "url": "https://github.com/shreyas-malhotra/CVE-2026-33439-OpenAM"
                },
                {
                    "repository": "PoC-in-GitHub · Ibonok/CVE-2026-33439-PoC",
                    "author": "Ibonok",
                    "first_seen": "2026-04-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2026-33439",
                    "summary": "CVE-2026-33439",
                    "url": "https://github.com/Ibonok/CVE-2026-33439-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · TheMalwareGuardian/CVE-2026-33439",
                    "author": "TheMalwareGuardian",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "First publicly shared exploit implementation for CVE-2026-33439 (OpenAM pre-auth RCE via jato.clientSession deserialization).",
                    "summary": "First publicly shared exploit implementation for CVE-2026-33439 (OpenAM pre-auth RCE via jato.clientSession deserialization).",
                    "url": "https://github.com/TheMalwareGuardian/CVE-2026-33439"
                },
                {
                    "repository": "PoC-in-GitHub · infernosalex/CVE-2026-33439-Python-PoC",
                    "author": "infernosalex",
                    "first_seen": "2026-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Python PoC for CVE-2026-33439, an OpenAM pre-authentication RCE via jato.clientSession deserialization",
                    "summary": "Python PoC for CVE-2026-33439, an OpenAM pre-authentication RCE via jato.clientSession deserialization",
                    "url": "https://github.com/infernosalex/CVE-2026-33439-Python-PoC"
                }
            ],
            "references": [
                "https://github.com/shreyas-malhotra/CVE-2026-33439-OpenAM",
                "https://github.com/Ibonok/CVE-2026-33439-PoC",
                "https://github.com/TheMalwareGuardian/CVE-2026-33439",
                "https://github.com/infernosalex/CVE-2026-33439-Python-PoC"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/shreyas-malhotra/CVE-2026-33439-OpenAM"
                }
            ]
        },
        {
            "id": "CVE-2026-33247",
            "vendor": "nats-io",
            "product": "nats-server",
            "title": "nats-server vulnerability",
            "summary": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any user who can see the monitoring port, if that too is enabled. The `/debug/vars` end-point contains an unredacted copy of argv. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, configure credentials inside a configuration file instead of via argv, and do not enable the monitoring port if using secrets in argv. Best practice remains to not expose the monitoring port to the Internet, or to untrusted network sources.",
            "updated_at": "2026-09-07T13:18:56.093",
            "published_at": "2026-03-25T20:16:33.223",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.11.15; >= 2.12.0-RC.1, < 2.12.6",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-215",
            "what_happened": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any user who can see the monitoring port, if that too is enabled. The `/debug/vars` end-point contains an unredacted copy of argv. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, configure credentials inside a configuration file instead of via argv, and do not enable the monitoring port if using secrets in argv. Best practice remains to not expose the monitoring port to the Internet, or to untrusted network sources.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://advisories.nats.io/CVE/secnote-2026-14.txt",
                "https://github.com/nats-io/nats-server/security/advisories/GHSA-x6g4-f6q3-fqvv",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/security/cve/CVE-2026-33247",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451486",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33247.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-25T20:16:33.223",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33247"
                }
            ]
        },
        {
            "id": "CVE-2026-33243",
            "vendor": "barebox",
            "product": "barebox",
            "title": "barebox vulnerability",
            "summary": "barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booting different images than those that were verified as part of a signed configuration. mkimage(1) sets the hashed-nodes property of the FIT signature node to list which nodes of the FIT were hashed as part of the signing process as these will need to be verified later on by the bootloader. However, hashed-nodes itself is not part of the hash and could therefore be modified to allow booting different images than those that have been verified. This issue has been patched in barebox versions 2026.03.1 and backported to 2025.09.3.",
            "updated_at": "2026-09-11T15:55:06.403",
            "published_at": "2026-03-20T23:16:47.167",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 2016.03.0, < 2025.09.3; >= 2025.10.0, < 2026.03.1",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-345",
            "what_happened": "barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature verification vulnerability to trick the bootloader into booting different images than those that were verified as part of a signed configuration. mkimage(1) sets the hashed-nodes property of the FIT signature node to list which nodes of the FIT were hashed as part of the signing process as these will need to be verified later on by the bootloader. However, hashed-nodes itself is not part of the hash and could therefore be modified to allow booting different images than those that have been verified. This issue has been patched in barebox versions 2026.03.1 and backported to 2025.09.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/barebox/barebox/commit/aca01795056d51060cb096f9a1ea309361743e05",
                "https://github.com/barebox/barebox/security/advisories/GHSA-3fvj-q26p-j6h4"
            ],
            "timeline": [
                {
                    "at": "2026-03-20T23:16:47.167",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33243"
                }
            ]
        },
        {
            "id": "CVE-2026-33219",
            "vendor": "nats-io",
            "product": "nats-server",
            "title": "nats-server vulnerability",
            "summary": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of data. This is a milder variant of CVE-2026-27571. That earlier issue was a compression bomb, this vulnerability is not. Attacks against this new issue thus require significant client bandwidth. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable websockets if not required for project deployment.",
            "updated_at": "2026-09-07T13:18:55.297",
            "published_at": "2026-03-25T20:16:32.777",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.11.15; >= 2.12.0-RC.1, < 2.12.6",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of data. This is a milder variant of CVE-2026-27571. That earlier issue was a compression bomb, this vulnerability is not. Attacks against this new issue thus require significant client bandwidth. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable websockets if not required for project deployment.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://advisories.nats.io/CVE/secnote-2026-02.txt",
                "https://advisories.nats.io/CVE/secnote-2026-11.txt",
                "https://github.com/advisories/GHSA-qrvq-68c2-7grw",
                "https://github.com/nats-io/nats-server/security/advisories/GHSA-8r68-gvr4-jh7j",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/security/cve/CVE-2026-33219",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451445",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33219.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-25T20:16:32.777",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33219"
                }
            ]
        },
        {
            "id": "CVE-2026-33218",
            "vendor": "nats-io",
            "product": "nats-server",
            "title": "nats-server vulnerability",
            "summary": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable leafnode support if not needed or restrict network connections to the leafnode port, if plausible without compromising the service offered.",
            "updated_at": "2026-09-07T13:18:54.770",
            "published_at": "2026-03-25T20:16:32.623",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< < 2.11.15; >= 2.12.0-RC.1, < 2.12.6",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, disable leafnode support if not needed or restrict network connections to the leafnode port, if plausible without compromising the service offered.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://advisories.nats.io/CVE/secnote-2026-10.txt",
                "https://github.com/nats-io/nats-server/security/advisories/GHSA-vprv-35vv-q339",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/security/cve/CVE-2026-33218",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451450",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33218.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-25T20:16:32.623",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33218"
                }
            ]
        },
        {
            "id": "CVE-2026-33217",
            "vendor": "nats-io",
            "product": "nats-server",
            "title": "nats-server vulnerability",
            "summary": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing MQTT clients to bypass ACL checks for MQTT subjects. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.",
            "updated_at": "2026-09-07T13:18:54.217",
            "published_at": "2026-03-25T20:16:32.473",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.11.15; >= 2.12.0-RC.1, < 2.12.6",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing MQTT clients to bypass ACL checks for MQTT subjects. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://advisories.nats.io/CVE/secnote-2026-07.txt",
                "https://github.com/nats-io/nats-server/security/advisories/GHSA-jxxm-27vp-c3m5",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/security/cve/CVE-2026-33217",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451446",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33217.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-25T20:16:32.473",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33217"
                }
            ]
        },
        {
            "id": "CVE-2026-33216",
            "vendor": "nats-io",
            "product": "nats-server",
            "title": "nats-server vulnerability",
            "summary": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions 2.11.14 and 2.12.6 contain a fix. As a workaround, ensure monitoring end-points are adequately secured. Best practice remains to not expose the monitoring endpoint to the Internet or other untrusted network users.",
            "updated_at": "2026-09-07T13:18:53.723",
            "published_at": "2026-03-25T20:16:32.320",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.11.15; >= 2.12.0-RC.1, < 2.12.6",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-256",
            "what_happened": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions 2.11.14 and 2.12.6 contain a fix. As a workaround, ensure monitoring end-points are adequately secured. Best practice remains to not expose the monitoring endpoint to the Internet or other untrusted network users.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://advisories.nats.io/CVE/secnote-2026-05.txt",
                "https://github.com/nats-io/nats-server/commit/b5b63cfc35a57075e09c1f57503d31721bed8099",
                "https://github.com/nats-io/nats-server/security/advisories/GHSA-v722-jcv5-w7mc",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/security/cve/CVE-2026-33216",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451448",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33216.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-25T20:16:32.320",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33216"
                }
            ]
        },
        {
            "id": "CVE-2026-33211",
            "vendor": "tektoncd",
            "product": "pipeline",
            "title": "pipeline vulnerability",
            "summary": "Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `ResolutionRequests` (e.g. by creating `TaskRuns` or `PipelineRuns` that use the git resolver) can read arbitrary files from the resolver pod's filesystem, including ServiceAccount tokens. The file contents are returned base64-encoded in `resolutionrequest.status.data`. Versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2 contain a patch.",
            "updated_at": "2026-09-07T13:18:53.013",
            "published_at": "2026-03-24T00:16:29.320",
            "cvss": 9.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 1.0.0, < 1.0.1; >= 1.1.0, < 1.3.3; >= 1.4.0, < 1.6.1; >= 1.7.0, < 1.9.2; >= 1.10.0, < 1.10.2",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create `ResolutionRequests` (e.g. by creating `TaskRuns` or `PipelineRuns` that use the git resolver) can read arbitrary files from the resolver pod's filesystem, including ServiceAccount tokens. The file contents are returned base64-encoded in `resolutionrequest.status.data`. Versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2 contain a patch.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/tektoncd/pipeline/commit/10fa538f9a2b6d01c75138f1ed7ba3da0e34687c",
                "https://github.com/tektoncd/pipeline/commit/318006c4e3a5",
                "https://github.com/tektoncd/pipeline/commit/3ca7bc6e6dd1d97f80b84f78370d91edaf023cbd",
                "https://github.com/tektoncd/pipeline/commit/961388fcf3374bc7656d28ab58ca84987e0a75ae",
                "https://github.com/tektoncd/pipeline/commit/b1fee65b88aa969069c14c120045e97c37d9ee5e",
                "https://github.com/tektoncd/pipeline/commit/cdb4e1e97a4f3170f9bc2cbfff83a6c8107bc3db",
                "https://github.com/tektoncd/pipeline/commit/ec7755031a183b345cf9e64bea0e0505c1b9cb78",
                "https://github.com/tektoncd/pipeline/security/advisories/GHSA-j5q5-j9gm-2w5c",
                "https://access.redhat.com/errata/RHSA-2026:10026",
                "https://access.redhat.com/errata/RHSA-2026:10066",
                "https://access.redhat.com/errata/RHSA-2026:10125",
                "https://access.redhat.com/errata/RHSA-2026:10155",
                "https://access.redhat.com/errata/RHSA-2026:10158",
                "https://access.redhat.com/errata/RHSA-2026:21931",
                "https://access.redhat.com/errata/RHSA-2026:21932",
                "https://access.redhat.com/errata/RHSA-2026:24484",
                "https://access.redhat.com/errata/RHSA-2026:6166",
                "https://access.redhat.com/errata/RHSA-2026:6170",
                "https://access.redhat.com/security/cve/CVE-2026-33211",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2450554",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33211.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-24T00:16:29.320",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33211"
                }
            ]
        },
        {
            "id": "CVE-2026-33186",
            "vendor": "grpc",
            "product": "grpc-go",
            "title": "grpc-go vulnerability",
            "summary": "gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, \"deny\" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback \"allow\" rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a security policy contains specific \"deny\" rules for canonical paths but allows other requests by default (a fallback \"allow\" rule). The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server. The fix in version 1.79.3 ensures that any request with a `:path` that does not start with a leading slash is immediately rejected with a `codes.Unimplemented` error, preventing it from reaching authorization interceptors or handlers with a non-canonical path string. While upgrading is the most secure and recommended path, users can mitigate the vulnerability using one of the following methods: Use a validating interceptor (recommended mitigation); infrastructure-level normalization; and/or policy hardening.",
            "updated_at": "2026-09-16T13:17:34.020",
            "published_at": "2026-03-20T23:16:45.180",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 1.79.3",
            "fixed": "See vendor advisory",
            "source_count": 233,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, \"deny\" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback \"allow\" rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a security policy contains specific \"deny\" rules for canonical paths but allows other requests by default (a fallback \"allow\" rule). The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server. The fix in version 1.79.3 ensures that any request with a `:path` that does not start with a leading slash is immediately rejected with a `codes.Unimplemented` error, preventing it from reaching authorization interceptors or handlers with a non-canonical path string. While upgrading is the most secure and recommended path, users can mitigate the vulnerability using one of the following methods: Use a validating interceptor (recommended mitigation); infrastructure-level normalization; and/or policy hardening.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3",
                "https://access.redhat.com/errata/RHSA-2026:10093",
                "https://access.redhat.com/errata/RHSA-2026:10094",
                "https://access.redhat.com/errata/RHSA-2026:10105",
                "https://access.redhat.com/errata/RHSA-2026:10107",
                "https://access.redhat.com/errata/RHSA-2026:10125",
                "https://access.redhat.com/errata/RHSA-2026:10126",
                "https://access.redhat.com/errata/RHSA-2026:10130",
                "https://access.redhat.com/errata/RHSA-2026:10131",
                "https://access.redhat.com/errata/RHSA-2026:10153",
                "https://access.redhat.com/errata/RHSA-2026:10155",
                "https://access.redhat.com/errata/RHSA-2026:10158",
                "https://access.redhat.com/errata/RHSA-2026:10172",
                "https://access.redhat.com/errata/RHSA-2026:10175",
                "https://access.redhat.com/errata/RHSA-2026:10698",
                "https://access.redhat.com/errata/RHSA-2026:10705",
                "https://access.redhat.com/errata/RHSA-2026:10706",
                "https://access.redhat.com/errata/RHSA-2026:11070",
                "https://access.redhat.com/errata/RHSA-2026:11408",
                "https://access.redhat.com/errata/RHSA-2026:11803",
                "https://access.redhat.com/errata/RHSA-2026:11856",
                "https://access.redhat.com/errata/RHSA-2026:11916",
                "https://access.redhat.com/errata/RHSA-2026:11996",
                "https://access.redhat.com/errata/RHSA-2026:12116",
                "https://access.redhat.com/errata/RHSA-2026:12118",
                "https://access.redhat.com/errata/RHSA-2026:12119",
                "https://access.redhat.com/errata/RHSA-2026:12277",
                "https://access.redhat.com/errata/RHSA-2026:12279",
                "https://access.redhat.com/errata/RHSA-2026:12283",
                "https://access.redhat.com/errata/RHSA-2026:12337",
                "https://access.redhat.com/errata/RHSA-2026:13548",
                "https://access.redhat.com/errata/RHSA-2026:13791",
                "https://access.redhat.com/errata/RHSA-2026:13829",
                "https://access.redhat.com/errata/RHSA-2026:14775",
                "https://access.redhat.com/errata/RHSA-2026:15092",
                "https://access.redhat.com/errata/RHSA-2026:17123",
                "https://access.redhat.com/errata/RHSA-2026:17448",
                "https://access.redhat.com/errata/RHSA-2026:17459",
                "https://access.redhat.com/errata/RHSA-2026:17468",
                "https://access.redhat.com/errata/RHSA-2026:17474",
                "https://access.redhat.com/errata/RHSA-2026:17475",
                "https://access.redhat.com/errata/RHSA-2026:17598",
                "https://access.redhat.com/errata/RHSA-2026:17599",
                "https://access.redhat.com/errata/RHSA-2026:17789",
                "https://access.redhat.com/errata/RHSA-2026:18068",
                "https://access.redhat.com/errata/RHSA-2026:18585",
                "https://access.redhat.com/errata/RHSA-2026:19099",
                "https://access.redhat.com/errata/RHSA-2026:19108",
                "https://access.redhat.com/errata/RHSA-2026:19109",
                "https://access.redhat.com/errata/RHSA-2026:19135",
                "https://access.redhat.com/errata/RHSA-2026:19207",
                "https://access.redhat.com/errata/RHSA-2026:19353",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:19719",
                "https://access.redhat.com/errata/RHSA-2026:19720",
                "https://access.redhat.com/errata/RHSA-2026:19721",
                "https://access.redhat.com/errata/RHSA-2026:20034",
                "https://access.redhat.com/errata/RHSA-2026:20035",
                "https://access.redhat.com/errata/RHSA-2026:20041",
                "https://access.redhat.com/errata/RHSA-2026:20042",
                "https://access.redhat.com/errata/RHSA-2026:20088",
                "https://access.redhat.com/errata/RHSA-2026:20089",
                "https://access.redhat.com/errata/RHSA-2026:20322",
                "https://access.redhat.com/errata/RHSA-2026:20436",
                "https://access.redhat.com/errata/RHSA-2026:20943",
                "https://access.redhat.com/errata/RHSA-2026:20946",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:21657",
                "https://access.redhat.com/errata/RHSA-2026:21658",
                "https://access.redhat.com/errata/RHSA-2026:21691",
                "https://access.redhat.com/errata/RHSA-2026:21692",
                "https://access.redhat.com/errata/RHSA-2026:21696",
                "https://access.redhat.com/errata/RHSA-2026:21697",
                "https://access.redhat.com/errata/RHSA-2026:21703",
                "https://access.redhat.com/errata/RHSA-2026:21704",
                "https://access.redhat.com/errata/RHSA-2026:21709",
                "https://access.redhat.com/errata/RHSA-2026:21710",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:21931",
                "https://access.redhat.com/errata/RHSA-2026:21932",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:22450",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22485",
                "https://access.redhat.com/errata/RHSA-2026:22645",
                "https://access.redhat.com/errata/RHSA-2026:22689",
                "https://access.redhat.com/errata/RHSA-2026:22714",
                "https://access.redhat.com/errata/RHSA-2026:22800",
                "https://access.redhat.com/errata/RHSA-2026:22937",
                "https://access.redhat.com/errata/RHSA-2026:22959",
                "https://access.redhat.com/errata/RHSA-2026:22961",
                "https://access.redhat.com/errata/RHSA-2026:23228",
                "https://access.redhat.com/errata/RHSA-2026:23234",
                "https://access.redhat.com/errata/RHSA-2026:23235",
                "https://access.redhat.com/errata/RHSA-2026:23241",
                "https://access.redhat.com/errata/RHSA-2026:23246",
                "https://access.redhat.com/errata/RHSA-2026:23247",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:24484",
                "https://access.redhat.com/errata/RHSA-2026:24506",
                "https://access.redhat.com/errata/RHSA-2026:24535",
                "https://access.redhat.com/errata/RHSA-2026:24536",
                "https://access.redhat.com/errata/RHSA-2026:24759",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:25009",
                "https://access.redhat.com/errata/RHSA-2026:25045",
                "https://access.redhat.com/errata/RHSA-2026:25127",
                "https://access.redhat.com/errata/RHSA-2026:25182",
                "https://access.redhat.com/errata/RHSA-2026:25183",
                "https://access.redhat.com/errata/RHSA-2026:25187",
                "https://access.redhat.com/errata/RHSA-2026:25194",
                "https://access.redhat.com/errata/RHSA-2026:25195",
                "https://access.redhat.com/errata/RHSA-2026:25201",
                "https://access.redhat.com/errata/RHSA-2026:26412",
                "https://access.redhat.com/errata/RHSA-2026:26413",
                "https://access.redhat.com/errata/RHSA-2026:26416",
                "https://access.redhat.com/errata/RHSA-2026:26420",
                "https://access.redhat.com/errata/RHSA-2026:26519",
                "https://access.redhat.com/errata/RHSA-2026:26568",
                "https://access.redhat.com/errata/RHSA-2026:26997",
                "https://access.redhat.com/errata/RHSA-2026:26999",
                "https://access.redhat.com/errata/RHSA-2026:27001",
                "https://access.redhat.com/errata/RHSA-2026:27004",
                "https://access.redhat.com/errata/RHSA-2026:27063",
                "https://access.redhat.com/errata/RHSA-2026:27076",
                "https://access.redhat.com/errata/RHSA-2026:27712",
                "https://access.redhat.com/errata/RHSA-2026:27856",
                "https://access.redhat.com/errata/RHSA-2026:27892",
                "https://access.redhat.com/errata/RHSA-2026:27893",
                "https://access.redhat.com/errata/RHSA-2026:27901",
                "https://access.redhat.com/errata/RHSA-2026:27957",
                "https://access.redhat.com/errata/RHSA-2026:28047",
                "https://access.redhat.com/errata/RHSA-2026:28893",
                "https://access.redhat.com/errata/RHSA-2026:28964",
                "https://access.redhat.com/errata/RHSA-2026:29079",
                "https://access.redhat.com/errata/RHSA-2026:29082",
                "https://access.redhat.com/errata/RHSA-2026:29854",
                "https://access.redhat.com/errata/RHSA-2026:34049",
                "https://access.redhat.com/errata/RHSA-2026:34097",
                "https://access.redhat.com/errata/RHSA-2026:34099",
                "https://access.redhat.com/errata/RHSA-2026:34100",
                "https://access.redhat.com/errata/RHSA-2026:34364",
                "https://access.redhat.com/errata/RHSA-2026:34769",
                "https://access.redhat.com/errata/RHSA-2026:34794",
                "https://access.redhat.com/errata/RHSA-2026:34795",
                "https://access.redhat.com/errata/RHSA-2026:36611",
                "https://access.redhat.com/errata/RHSA-2026:36621",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:37192",
                "https://access.redhat.com/errata/RHSA-2026:37275",
                "https://access.redhat.com/errata/RHSA-2026:37580",
                "https://access.redhat.com/errata/RHSA-2026:37585",
                "https://access.redhat.com/errata/RHSA-2026:40022",
                "https://access.redhat.com/errata/RHSA-2026:40030",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40792",
                "https://access.redhat.com/errata/RHSA-2026:40795",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:40984",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41941",
                "https://access.redhat.com/errata/RHSA-2026:41944",
                "https://access.redhat.com/errata/RHSA-2026:42049",
                "https://access.redhat.com/errata/RHSA-2026:42051",
                "https://access.redhat.com/errata/RHSA-2026:42150",
                "https://access.redhat.com/errata/RHSA-2026:42151",
                "https://access.redhat.com/errata/RHSA-2026:42240",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:43225",
                "https://access.redhat.com/errata/RHSA-2026:43227",
                "https://access.redhat.com/errata/RHSA-2026:43253",
                "https://access.redhat.com/errata/RHSA-2026:43331",
                "https://access.redhat.com/errata/RHSA-2026:43692",
                "https://access.redhat.com/errata/RHSA-2026:44233",
                "https://access.redhat.com/errata/RHSA-2026:44235",
                "https://access.redhat.com/errata/RHSA-2026:47728",
                "https://access.redhat.com/errata/RHSA-2026:47952",
                "https://access.redhat.com/errata/RHSA-2026:48699",
                "https://access.redhat.com/errata/RHSA-2026:48790",
                "https://access.redhat.com/errata/RHSA-2026:50758",
                "https://access.redhat.com/errata/RHSA-2026:50843",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:53728",
                "https://access.redhat.com/errata/RHSA-2026:53763",
                "https://access.redhat.com/errata/RHSA-2026:53773",
                "https://access.redhat.com/errata/RHSA-2026:53804",
                "https://access.redhat.com/errata/RHSA-2026:54191",
                "https://access.redhat.com/errata/RHSA-2026:54274",
                "https://access.redhat.com/errata/RHSA-2026:54286",
                "https://access.redhat.com/errata/RHSA-2026:54531",
                "https://access.redhat.com/errata/RHSA-2026:54757",
                "https://access.redhat.com/errata/RHSA-2026:56366",
                "https://access.redhat.com/errata/RHSA-2026:56431",
                "https://access.redhat.com/errata/RHSA-2026:56789",
                "https://access.redhat.com/errata/RHSA-2026:56854",
                "https://access.redhat.com/errata/RHSA-2026:56912",
                "https://access.redhat.com/errata/RHSA-2026:56959",
                "https://access.redhat.com/errata/RHSA-2026:57013",
                "https://access.redhat.com/errata/RHSA-2026:57365",
                "https://access.redhat.com/errata/RHSA-2026:59833",
                "https://access.redhat.com/errata/RHSA-2026:60146",
                "https://access.redhat.com/errata/RHSA-2026:61245",
                "https://access.redhat.com/errata/RHSA-2026:6174",
                "https://access.redhat.com/errata/RHSA-2026:6428",
                "https://access.redhat.com/errata/RHSA-2026:6564",
                "https://access.redhat.com/errata/RHSA-2026:6802",
                "https://access.redhat.com/errata/RHSA-2026:7110",
                "https://access.redhat.com/errata/RHSA-2026:7128",
                "https://access.redhat.com/errata/RHSA-2026:7245",
                "https://access.redhat.com/errata/RHSA-2026:8151",
                "https://access.redhat.com/errata/RHSA-2026:8338",
                "https://access.redhat.com/errata/RHSA-2026:8433",
                "https://access.redhat.com/errata/RHSA-2026:8449",
                "https://access.redhat.com/errata/RHSA-2026:8483",
                "https://access.redhat.com/errata/RHSA-2026:8484",
                "https://access.redhat.com/errata/RHSA-2026:8490",
                "https://access.redhat.com/errata/RHSA-2026:8491",
                "https://access.redhat.com/errata/RHSA-2026:8493",
                "https://access.redhat.com/errata/RHSA-2026:9385",
                "https://access.redhat.com/errata/RHSA-2026:9388",
                "https://access.redhat.com/errata/RHSA-2026:9440",
                "https://access.redhat.com/errata/RHSA-2026:9448",
                "https://access.redhat.com/errata/RHSA-2026:9453",
                "https://access.redhat.com/errata/RHSA-2026:9872",
                "https://access.redhat.com/security/cve/CVE-2026-33186",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2449833",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33186.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-20T23:16:45.180",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33186"
                }
            ]
        },
        {
            "id": "CVE-2026-32746",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "telnetd 2.7 - Buffer Overflow",
            "summary": "telnetd 2.7 - Buffer Overflow",
            "updated_at": "2026-09-03T14:50:17Z",
            "published_at": "2026-09-03T14:50:17Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 148,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Kangaroo bypasses authentication on telnet servers version 2.7 or lower (CVE-2026-32746).",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52556",
                    "author": "jeffbarron",
                    "first_seen": "2026-05-07",
                    "confidence": "High",
                    "title": "telnetd 2.7 - Buffer Overflow",
                    "summary": "telnetd 2.7 - Buffer Overflow",
                    "url": "https://www.exploit-db.com/exploits/52556",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for Kangaroo CVE-2026-32746",
                    "summary": "Kangaroo bypasses authentication on telnet servers version 2.7 or lower (CVE-2026-32746).",
                    "what_happened": "Kangaroo bypasses authentication on telnet servers version 2.7 or lower (CVE-2026-32746).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MONKEYSEC-SYS-KANGAROO",
                        "https://kitploit.com/ru/tools/github/monkeysec-sys/kangaroo/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T16:50:17",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MONKEYSEC-SYS-KANGAROO"
                },
                {
                    "title": "Exploit for Kangaroo CVE-2026-32746",
                    "summary": "Kangaroo bypasses authentication on telnet servers version 2.7 or lower (CVE-2026-32746).",
                    "what_happened": "Kangaroo bypasses authentication on telnet servers version 2.7 or lower (CVE-2026-32746).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MONKEYSEC-SYS-KANGAROO",
                        "https://kitploit.com/ru/tools/github/monkeysec-sys/kangaroo/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-03T16:50:17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/monkeysec-sys/kangaroo/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52556",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MONKEYSEC-SYS-KANGAROO",
                "https://kitploit.com/ru/tools/github/monkeysec-sys/kangaroo/"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T14:50:17Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52556"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-32686",
            "vendor": "ericmj",
            "product": "decimal",
            "title": "decimal vulnerability",
            "summary": "Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service.\n\nThe decimal library does not bound the exponent on parsed input. Storing a decimal with a very large exponent (e.g. Decimal.new(\"1e1000000000\")) is accepted without error. Subsequent calls to arithmetic functions (Decimal.add/2, Decimal.sub/2, Decimal.div/2M), Decimal.to_string/2M with :normalM or :xsdM format, Decimal.to_integer/1M, Decimal.round/3M, or Decimal.compare/3M with a threshold allocate memory proportional to the exponent value, which can exhaust available memory and crash the BEAM VM.\n\nAny application that accepts user-supplied decimal input and subsequently performs arithmetic, rounding, conversion to integer, or string formatting on it is exposed. A single malicious request is sufficient to cause an out-of-memory crash.\n\nThis issue affects decimal: from 0.1.0 before 3.0.0.",
            "updated_at": "2026-09-08T14:17:21.870",
            "published_at": "2026-05-07T15:16:05.370",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.1.0 through before 3.0.0 (semver); bc11f4a2b6fb61fc1360a0ab4e79141bba918841 through before 6a523f3a73b8c9974540e21c7aa88f1258bb35ae (git)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service.\n\nThe decimal library does not bound the exponent on parsed input. Storing a decimal with a very large exponent (e.g. Decimal.new(\"1e1000000000\")) is accepted without error. Subsequent calls to arithmetic functions (Decimal.add/2, Decimal.sub/2, Decimal.div/2M), Decimal.to_string/2M with :normalM or :xsdM format, Decimal.to_integer/1M, Decimal.round/3M, or Decimal.compare/3M with a threshold allocate memory proportional to the exponent value, which can exhaust available memory and crash the BEAM VM.\n\nAny application that accepts user-supplied decimal input and subsequently performs arithmetic, rounding, conversion to integer, or string formatting on it is exposed. A single malicious request is sufficient to cause an out-of-memory crash.\n\nThis issue affects decimal: from 0.1.0 before 3.0.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-32686.html",
                "https://github.com/ericmj/decimal/commit/6a523f3a73b8c9974540e21c7aa88f1258bb35ae",
                "https://github.com/ericmj/decimal/commit/bc11f4a2b6fb61fc1360a0ab4e79141bba918841",
                "https://github.com/ericmj/decimal/security/advisories/GHSA-rhv4-8758-jx7v",
                "https://osv.dev/vulnerability/EEF-CVE-2026-32686"
            ],
            "timeline": [
                {
                    "at": "2026-05-07T15:16:05.370",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32686"
                }
            ]
        },
        {
            "id": "CVE-2026-32685",
            "vendor": "Gleam",
            "product": "Gleam",
            "title": "Gleam vulnerability",
            "summary": "Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory.\n\nThe documentation.pages entries from gleam.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended project and documentation output directories. The documentation.pages[].path field can be used to write generated documentation files outside the intended build/dev/docs/<package>/ output directory. The documentation.pages[].source field can be used to read files outside the project directory and embed their contents into generated documentation output.\n\nAn attacker who can convince a victim to run gleam docs build on an untrusted project, or with untrusted gleam.toml content, can cause local files readable by the victim to be included in generated documentation artifacts, and can cause generated documentation files to be written outside the intended docs output directory.\n\nThis issue affects Gleam from 1.16.0 until 1.17.0.",
            "updated_at": "2026-09-08T01:17:30.287",
            "published_at": "2026-06-02T14:16:50.610",
            "cvss": 4.6,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.16.0 through before 1.17.0 (semver); 61ed8deb6572b5591ad17d6302c1a38607522f16 through before 81570611906b6b0039c948037094d09a68700f3a (git); v1.16.0-elixir through before v1.17.0-elixir (other); v1.16.0-erlang through before v1.17.0-erlang (other); v1.16.0-node through before v1.17.0-node (other); v1.16.0-node-slim through before v1.17.0-node-slim (other); v1.16.0-elixir-slim through before v1.17.0-elixir-slim (other); v1.16.0-erlang-slim through before v1.17.0-erlang-slim (other); v1.16.0-erlang-alpine through before v1.17.0-erlang-alpine (other); v1.16.0-elixir-alpine through before v1.17.0-elixir-alpine (other); v1.16.0-node-alpine through before v1.17.0-node-alpine (other); v1.16.0-scratch through before v1.17.0-scratch (other)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory.\n\nThe documentation.pages entries from gleam.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended project and documentation output directories. The documentation.pages[].path field can be used to write generated documentation files outside the intended build/dev/docs/<package>/ output directory. The documentation.pages[].source field can be used to read files outside the project directory and embed their contents into generated documentation output.\n\nAn attacker who can convince a victim to run gleam docs build on an untrusted project, or with untrusted gleam.toml content, can cause local files readable by the victim to be included in generated documentation artifacts, and can cause generated documentation files to be written outside the intended docs output directory.\n\nThis issue affects Gleam from 1.16.0 until 1.17.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-32685.html",
                "https://github.com/gleam-lang/gleam/commit/81570611906b6b0039c948037094d09a68700f3a",
                "https://github.com/gleam-lang/gleam/commit/c9230cd3045de8fd8481dae3a4557c0146df1430",
                "https://github.com/gleam-lang/gleam/security/advisories/GHSA-wjx8-7w8m-p4v7",
                "https://osv.dev/vulnerability/EEF-CVE-2026-32685"
            ],
            "timeline": [
                {
                    "at": "2026-06-02T14:16:50.610",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32685"
                }
            ]
        },
        {
            "id": "CVE-2026-32597",
            "vendor": "jpadilla",
            "product": "pyjwt",
            "title": "pyjwt vulnerability",
            "summary": "PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.",
            "updated_at": "2026-09-10T13:18:12.027",
            "published_at": "2026-03-13T19:55:09.500",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 2.12.0",
            "fixed": "See vendor advisory",
            "source_count": 61,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-345",
            "what_happened": "PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f"
                }
            ],
            "references": [
                "https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f",
                "https://lists.debian.org/debian-lts-announce/2026/05/msg00008.html",
                "https://access.redhat.com/errata/RHSA-2026:10140",
                "https://access.redhat.com/errata/RHSA-2026:10141",
                "https://access.redhat.com/errata/RHSA-2026:10184",
                "https://access.redhat.com/errata/RHSA-2026:12176",
                "https://access.redhat.com/errata/RHSA-2026:13508",
                "https://access.redhat.com/errata/RHSA-2026:13512",
                "https://access.redhat.com/errata/RHSA-2026:13545",
                "https://access.redhat.com/errata/RHSA-2026:13553",
                "https://access.redhat.com/errata/RHSA-2026:13672",
                "https://access.redhat.com/errata/RHSA-2026:13916",
                "https://access.redhat.com/errata/RHSA-2026:17083",
                "https://access.redhat.com/errata/RHSA-2026:19138",
                "https://access.redhat.com/errata/RHSA-2026:19355",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:21431",
                "https://access.redhat.com/errata/RHSA-2026:21517",
                "https://access.redhat.com/errata/RHSA-2026:22330",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:26226",
                "https://access.redhat.com/errata/RHSA-2026:37275",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/errata/RHSA-2026:6720",
                "https://access.redhat.com/errata/RHSA-2026:6912",
                "https://access.redhat.com/errata/RHSA-2026:6926",
                "https://access.redhat.com/errata/RHSA-2026:8437",
                "https://access.redhat.com/errata/RHSA-2026:8746",
                "https://access.redhat.com/errata/RHSA-2026:8747",
                "https://access.redhat.com/errata/RHSA-2026:8748",
                "https://access.redhat.com/security/cve/CVE-2026-32597",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2447194",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32597.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-13T19:55:09.500",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32597"
                }
            ]
        },
        {
            "id": "CVE-2026-32591",
            "vendor": "Red Hat",
            "product": "Red Hat Quay 3.10",
            "title": "Red Hat Quay 3.10 vulnerability",
            "summary": "A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An attacker with organization administrator privileges could supply a crafted hostname to force the Quay server to make requests to internal network services, cloud infrastructure endpoints, or other resources that should not be accessible from the Quay application.",
            "updated_at": "2026-09-10T13:18:11.060",
            "published_at": "2026-04-08T18:26:00.107",
            "cvss": 5.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate external service. An attacker with organization administrator privileges could supply a crafted hostname to force the Quay server to make requests to internal network services, cloud infrastructure endpoints, or other resources that should not be accessible from the Quay application.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:24833",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:48085",
                "https://access.redhat.com/security/cve/CVE-2026-32591",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2446965",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32591.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-08T18:26:00.107",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32591"
                }
            ]
        },
        {
            "id": "CVE-2026-32589",
            "vendor": "Red Hat",
            "product": "mirror registry for Red Hat OpenShift 2.0",
            "title": "mirror registry for Red Hat OpenShift 2.0 vulnerability",
            "summary": "A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel another user's in-progress image upload.",
            "updated_at": "2026-09-10T13:18:10.047",
            "published_at": "2026-04-08T18:25:59.790",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow the attacker to read, modify, or cancel another user's in-progress image upload.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22629",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:28441",
                "https://access.redhat.com/security/cve/CVE-2026-32589",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2446963",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32589.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-08T18:25:59.790",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32589"
                }
            ]
        },
        {
            "id": "CVE-2026-32286",
            "vendor": "github.com/jackc/pgproto3/v2",
            "product": "github.com/jackc/pgproto3/v2",
            "title": "github.com/jackc/pgproto3/v2 vulnerability",
            "summary": "The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.",
            "updated_at": "2026-09-10T13:18:08.907",
            "published_at": "2026-03-26T20:16:12.303",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.0.0 through 2.3.3",
            "fixed": "See vendor advisory",
            "source_count": 23,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-129",
            "what_happened": "The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/advisories/GHSA-jqcq-xjh3-6g23",
                "https://github.com/golang/vulndb/issues/4518",
                "https://github.com/jackc/pgx/issues/2507",
                "https://pkg.go.dev/vuln/GO-2026-4518",
                "https://access.redhat.com/errata/RHSA-2026:11070",
                "https://access.redhat.com/errata/RHSA-2026:11217",
                "https://access.redhat.com/errata/RHSA-2026:11856",
                "https://access.redhat.com/errata/RHSA-2026:11916",
                "https://access.redhat.com/errata/RHSA-2026:11996",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:22450",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22714",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/security/cve/CVE-2026-32286",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451847",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32286.json",
                "https://securityinfinity.com/research/memory-safety-vulnerabilities-in-go-postgresql-wire-protocol-parsers-pgproto3-pgx"
            ],
            "timeline": [
                {
                    "at": "2026-03-26T20:16:12.303",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32286"
                }
            ]
        },
        {
            "id": "CVE-2026-32285",
            "vendor": "github.com/buger/jsonparser",
            "product": "github.com/buger/jsonparser",
            "title": "github.com/buger/jsonparser vulnerability",
            "summary": "The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.",
            "updated_at": "2026-09-07T13:18:44.957",
            "published_at": "2026-03-26T20:16:12.197",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 1.1.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 55,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-129",
            "what_happened": "The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative slice index and a runtime panic, allowing a denial of service attack.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "securityinfinity.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-26",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://securityinfinity.com/research/buger-jsonparser-negative-slice-panic-dos-2026"
                }
            ],
            "references": [
                "https://github.com/buger/jsonparser/issues/275",
                "https://github.com/golang/vulndb/issues/4514",
                "https://pkg.go.dev/vuln/GO-2026-4514",
                "https://access.redhat.com/errata/RHSA-2026:13548",
                "https://access.redhat.com/errata/RHSA-2026:17121",
                "https://access.redhat.com/errata/RHSA-2026:17123",
                "https://access.redhat.com/errata/RHSA-2026:19099",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:34364",
                "https://access.redhat.com/errata/RHSA-2026:35111",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:61314",
                "https://access.redhat.com/errata/RHSA-2026:7191",
                "https://access.redhat.com/errata/RHSA-2026:9385",
                "https://access.redhat.com/security/cve/CVE-2026-32285",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451846",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32285.json",
                "https://securityinfinity.com/research/buger-jsonparser-negative-slice-panic-dos-2026"
            ],
            "timeline": [
                {
                    "at": "2026-03-26T20:16:12.197",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32285"
                }
            ]
        },
        {
            "id": "CVE-2026-32283",
            "vendor": "Go standard library",
            "product": "crypto/tls",
            "title": "crypto/tls vulnerability",
            "summary": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.",
            "updated_at": "2026-09-15T12:17:16.233",
            "published_at": "2026-04-08T02:16:03.580",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.25.9 (semver); 1.26.0-0 through before 1.26.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 142,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/763767",
                "https://go.dev/issue/78334",
                "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU",
                "https://pkg.go.dev/vuln/GO-2026-4870",
                "https://access.redhat.com/errata/RHSA-2026:10217",
                "https://access.redhat.com/errata/RHSA-2026:10219",
                "https://access.redhat.com/errata/RHSA-2026:10704",
                "https://access.redhat.com/errata/RHSA-2026:11507",
                "https://access.redhat.com/errata/RHSA-2026:11514",
                "https://access.redhat.com/errata/RHSA-2026:11704",
                "https://access.redhat.com/errata/RHSA-2026:11711",
                "https://access.redhat.com/errata/RHSA-2026:11712",
                "https://access.redhat.com/errata/RHSA-2026:11863",
                "https://access.redhat.com/errata/RHSA-2026:11881",
                "https://access.redhat.com/errata/RHSA-2026:14162",
                "https://access.redhat.com/errata/RHSA-2026:14200",
                "https://access.redhat.com/errata/RHSA-2026:14391",
                "https://access.redhat.com/errata/RHSA-2026:15980",
                "https://access.redhat.com/errata/RHSA-2026:16021",
                "https://access.redhat.com/errata/RHSA-2026:16024",
                "https://access.redhat.com/errata/RHSA-2026:16101",
                "https://access.redhat.com/errata/RHSA-2026:16102",
                "https://access.redhat.com/errata/RHSA-2026:16875",
                "https://access.redhat.com/errata/RHSA-2026:17075",
                "https://access.redhat.com/errata/RHSA-2026:17084",
                "https://access.redhat.com/errata/RHSA-2026:17287",
                "https://access.redhat.com/errata/RHSA-2026:18027",
                "https://access.redhat.com/errata/RHSA-2026:18032",
                "https://access.redhat.com/errata/RHSA-2026:19126",
                "https://access.redhat.com/errata/RHSA-2026:19132",
                "https://access.redhat.com/errata/RHSA-2026:19133",
                "https://access.redhat.com/errata/RHSA-2026:19134",
                "https://access.redhat.com/errata/RHSA-2026:19135",
                "https://access.redhat.com/errata/RHSA-2026:19136",
                "https://access.redhat.com/errata/RHSA-2026:19137",
                "https://access.redhat.com/errata/RHSA-2026:19139",
                "https://access.redhat.com/errata/RHSA-2026:19144",
                "https://access.redhat.com/errata/RHSA-2026:19156",
                "https://access.redhat.com/errata/RHSA-2026:19350",
                "https://access.redhat.com/errata/RHSA-2026:19351",
                "https://access.redhat.com/errata/RHSA-2026:19352",
                "https://access.redhat.com/errata/RHSA-2026:19353",
                "https://access.redhat.com/errata/RHSA-2026:19369",
                "https://access.redhat.com/errata/RHSA-2026:19450",
                "https://access.redhat.com/errata/RHSA-2026:19550",
                "https://access.redhat.com/errata/RHSA-2026:19634",
                "https://access.redhat.com/errata/RHSA-2026:19714",
                "https://access.redhat.com/errata/RHSA-2026:19715",
                "https://access.redhat.com/errata/RHSA-2026:19719",
                "https://access.redhat.com/errata/RHSA-2026:19720",
                "https://access.redhat.com/errata/RHSA-2026:19721",
                "https://access.redhat.com/errata/RHSA-2026:19722",
                "https://access.redhat.com/errata/RHSA-2026:19750",
                "https://access.redhat.com/errata/RHSA-2026:19839",
                "https://access.redhat.com/errata/RHSA-2026:20556",
                "https://access.redhat.com/errata/RHSA-2026:20569",
                "https://access.redhat.com/errata/RHSA-2026:20570",
                "https://access.redhat.com/errata/RHSA-2026:20571",
                "https://access.redhat.com/errata/RHSA-2026:20607",
                "https://access.redhat.com/errata/RHSA-2026:20608",
                "https://access.redhat.com/errata/RHSA-2026:20609",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:22450",
                "https://access.redhat.com/errata/RHSA-2026:22485",
                "https://access.redhat.com/errata/RHSA-2026:22709",
                "https://access.redhat.com/errata/RHSA-2026:22713",
                "https://access.redhat.com/errata/RHSA-2026:22714",
                "https://access.redhat.com/errata/RHSA-2026:22937",
                "https://access.redhat.com/errata/RHSA-2026:23102",
                "https://access.redhat.com/errata/RHSA-2026:23103",
                "https://access.redhat.com/errata/RHSA-2026:23228",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:24337",
                "https://access.redhat.com/errata/RHSA-2026:24470",
                "https://access.redhat.com/errata/RHSA-2026:24761",
                "https://access.redhat.com/errata/RHSA-2026:24762",
                "https://access.redhat.com/errata/RHSA-2026:25248",
                "https://access.redhat.com/errata/RHSA-2026:25250",
                "https://access.redhat.com/errata/RHSA-2026:25251",
                "https://access.redhat.com/errata/RHSA-2026:25252",
                "https://access.redhat.com/errata/RHSA-2026:26447",
                "https://access.redhat.com/errata/RHSA-2026:26571",
                "https://access.redhat.com/errata/RHSA-2026:26636",
                "https://access.redhat.com/errata/RHSA-2026:27076",
                "https://access.redhat.com/errata/RHSA-2026:28038",
                "https://access.redhat.com/errata/RHSA-2026:28047",
                "https://access.redhat.com/errata/RHSA-2026:28074",
                "https://access.redhat.com/errata/RHSA-2026:29035",
                "https://access.redhat.com/errata/RHSA-2026:29195",
                "https://access.redhat.com/errata/RHSA-2026:29455",
                "https://access.redhat.com/errata/RHSA-2026:29703",
                "https://access.redhat.com/errata/RHSA-2026:33722",
                "https://access.redhat.com/errata/RHSA-2026:34192",
                "https://access.redhat.com/errata/RHSA-2026:34196",
                "https://access.redhat.com/errata/RHSA-2026:34197",
                "https://access.redhat.com/errata/RHSA-2026:34365",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:39810",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:47712",
                "https://access.redhat.com/errata/RHSA-2026:47714",
                "https://access.redhat.com/errata/RHSA-2026:47716",
                "https://access.redhat.com/errata/RHSA-2026:47719",
                "https://access.redhat.com/errata/RHSA-2026:47721",
                "https://access.redhat.com/errata/RHSA-2026:47722",
                "https://access.redhat.com/errata/RHSA-2026:47910",
                "https://access.redhat.com/errata/RHSA-2026:48036",
                "https://access.redhat.com/errata/RHSA-2026:48790",
                "https://access.redhat.com/errata/RHSA-2026:49509",
                "https://access.redhat.com/errata/RHSA-2026:49600",
                "https://access.redhat.com/errata/RHSA-2026:49944",
                "https://access.redhat.com/errata/RHSA-2026:51288",
                "https://access.redhat.com/errata/RHSA-2026:54191",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:54757",
                "https://access.redhat.com/errata/RHSA-2026:55898",
                "https://access.redhat.com/errata/RHSA-2026:55900",
                "https://access.redhat.com/errata/RHSA-2026:55901",
                "https://access.redhat.com/errata/RHSA-2026:55902",
                "https://access.redhat.com/errata/RHSA-2026:55903",
                "https://access.redhat.com/errata/RHSA-2026:56910",
                "https://access.redhat.com/errata/RHSA-2026:57409",
                "https://access.redhat.com/errata/RHSA-2026:57801",
                "https://access.redhat.com/errata/RHSA-2026:57802",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:7291",
                "https://access.redhat.com/errata/RHSA-2026:7385",
                "https://access.redhat.com/security/cve/CVE-2026-32283",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2456338",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32283.json",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:65343",
                "https://access.redhat.com/errata/RHSA-2026:65514",
                "https://access.redhat.com/errata/RHSA-2026:66084",
                "https://access.redhat.com/errata/RHSA-2026:66022",
                "https://access.redhat.com/errata/RHSA-2026:66401",
                "https://access.redhat.com/errata/RHSA-2026:66523",
                "https://access.redhat.com/errata/RHSA-2026:67319"
            ],
            "timeline": [
                {
                    "at": "2026-04-08T02:16:03.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32283"
                }
            ]
        },
        {
            "id": "CVE-2026-32280",
            "vendor": "Go standard library",
            "product": "crypto/x509",
            "title": "crypto/x509 vulnerability",
            "summary": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.",
            "updated_at": "2026-09-16T13:17:31.120",
            "published_at": "2026-04-08T02:16:03.247",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.25.9 (semver); 1.26.0-0 through before 1.26.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 196,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/758320",
                "https://go.dev/issue/78282",
                "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU",
                "https://pkg.go.dev/vuln/GO-2026-4947",
                "https://access.redhat.com/errata/RHSA-2026:10217",
                "https://access.redhat.com/errata/RHSA-2026:10219",
                "https://access.redhat.com/errata/RHSA-2026:10704",
                "https://access.redhat.com/errata/RHSA-2026:11507",
                "https://access.redhat.com/errata/RHSA-2026:11514",
                "https://access.redhat.com/errata/RHSA-2026:11688",
                "https://access.redhat.com/errata/RHSA-2026:13545",
                "https://access.redhat.com/errata/RHSA-2026:13791",
                "https://access.redhat.com/errata/RHSA-2026:13826",
                "https://access.redhat.com/errata/RHSA-2026:13829",
                "https://access.redhat.com/errata/RHSA-2026:14020",
                "https://access.redhat.com/errata/RHSA-2026:14162",
                "https://access.redhat.com/errata/RHSA-2026:14200",
                "https://access.redhat.com/errata/RHSA-2026:14391",
                "https://access.redhat.com/errata/RHSA-2026:15980",
                "https://access.redhat.com/errata/RHSA-2026:16021",
                "https://access.redhat.com/errata/RHSA-2026:16024",
                "https://access.redhat.com/errata/RHSA-2026:16101",
                "https://access.redhat.com/errata/RHSA-2026:16476",
                "https://access.redhat.com/errata/RHSA-2026:16477",
                "https://access.redhat.com/errata/RHSA-2026:16505",
                "https://access.redhat.com/errata/RHSA-2026:16508",
                "https://access.redhat.com/errata/RHSA-2026:16532",
                "https://access.redhat.com/errata/RHSA-2026:16534",
                "https://access.redhat.com/errata/RHSA-2026:16535",
                "https://access.redhat.com/errata/RHSA-2026:16537",
                "https://access.redhat.com/errata/RHSA-2026:16542",
                "https://access.redhat.com/errata/RHSA-2026:16874",
                "https://access.redhat.com/errata/RHSA-2026:16875",
                "https://access.redhat.com/errata/RHSA-2026:17084",
                "https://access.redhat.com/errata/RHSA-2026:17287",
                "https://access.redhat.com/errata/RHSA-2026:18027",
                "https://access.redhat.com/errata/RHSA-2026:18032",
                "https://access.redhat.com/errata/RHSA-2026:19133",
                "https://access.redhat.com/errata/RHSA-2026:19135",
                "https://access.redhat.com/errata/RHSA-2026:19144",
                "https://access.redhat.com/errata/RHSA-2026:19350",
                "https://access.redhat.com/errata/RHSA-2026:19353",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19450",
                "https://access.redhat.com/errata/RHSA-2026:19550",
                "https://access.redhat.com/errata/RHSA-2026:19634",
                "https://access.redhat.com/errata/RHSA-2026:19714",
                "https://access.redhat.com/errata/RHSA-2026:19715",
                "https://access.redhat.com/errata/RHSA-2026:19719",
                "https://access.redhat.com/errata/RHSA-2026:19720",
                "https://access.redhat.com/errata/RHSA-2026:19721",
                "https://access.redhat.com/errata/RHSA-2026:19722",
                "https://access.redhat.com/errata/RHSA-2026:19750",
                "https://access.redhat.com/errata/RHSA-2026:19839",
                "https://access.redhat.com/errata/RHSA-2026:20556",
                "https://access.redhat.com/errata/RHSA-2026:20569",
                "https://access.redhat.com/errata/RHSA-2026:20570",
                "https://access.redhat.com/errata/RHSA-2026:20571",
                "https://access.redhat.com/errata/RHSA-2026:20607",
                "https://access.redhat.com/errata/RHSA-2026:20608",
                "https://access.redhat.com/errata/RHSA-2026:20609",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:21338",
                "https://access.redhat.com/errata/RHSA-2026:21655",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:21772",
                "https://access.redhat.com/errata/RHSA-2026:22130",
                "https://access.redhat.com/errata/RHSA-2026:22141",
                "https://access.redhat.com/errata/RHSA-2026:22258",
                "https://access.redhat.com/errata/RHSA-2026:22260",
                "https://access.redhat.com/errata/RHSA-2026:22268",
                "https://access.redhat.com/errata/RHSA-2026:22309",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22415",
                "https://access.redhat.com/errata/RHSA-2026:22422",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22485",
                "https://access.redhat.com/errata/RHSA-2026:22709",
                "https://access.redhat.com/errata/RHSA-2026:22713",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:22862",
                "https://access.redhat.com/errata/RHSA-2026:22958",
                "https://access.redhat.com/errata/RHSA-2026:22959",
                "https://access.redhat.com/errata/RHSA-2026:22960",
                "https://access.redhat.com/errata/RHSA-2026:22961",
                "https://access.redhat.com/errata/RHSA-2026:22962",
                "https://access.redhat.com/errata/RHSA-2026:23102",
                "https://access.redhat.com/errata/RHSA-2026:23103",
                "https://access.redhat.com/errata/RHSA-2026:23244",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24337",
                "https://access.redhat.com/errata/RHSA-2026:24359",
                "https://access.redhat.com/errata/RHSA-2026:24470",
                "https://access.redhat.com/errata/RHSA-2026:24478",
                "https://access.redhat.com/errata/RHSA-2026:24716",
                "https://access.redhat.com/errata/RHSA-2026:24761",
                "https://access.redhat.com/errata/RHSA-2026:24762",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:25089",
                "https://access.redhat.com/errata/RHSA-2026:25127",
                "https://access.redhat.com/errata/RHSA-2026:25180",
                "https://access.redhat.com/errata/RHSA-2026:25248",
                "https://access.redhat.com/errata/RHSA-2026:25250",
                "https://access.redhat.com/errata/RHSA-2026:25251",
                "https://access.redhat.com/errata/RHSA-2026:25252",
                "https://access.redhat.com/errata/RHSA-2026:25253",
                "https://access.redhat.com/errata/RHSA-2026:26447",
                "https://access.redhat.com/errata/RHSA-2026:26568",
                "https://access.redhat.com/errata/RHSA-2026:26571",
                "https://access.redhat.com/errata/RHSA-2026:26585",
                "https://access.redhat.com/errata/RHSA-2026:26636",
                "https://access.redhat.com/errata/RHSA-2026:27076",
                "https://access.redhat.com/errata/RHSA-2026:28038",
                "https://access.redhat.com/errata/RHSA-2026:28047",
                "https://access.redhat.com/errata/RHSA-2026:28074",
                "https://access.redhat.com/errata/RHSA-2026:28196",
                "https://access.redhat.com/errata/RHSA-2026:28198",
                "https://access.redhat.com/errata/RHSA-2026:28441",
                "https://access.redhat.com/errata/RHSA-2026:28886",
                "https://access.redhat.com/errata/RHSA-2026:28961",
                "https://access.redhat.com/errata/RHSA-2026:29035",
                "https://access.redhat.com/errata/RHSA-2026:29195",
                "https://access.redhat.com/errata/RHSA-2026:29455",
                "https://access.redhat.com/errata/RHSA-2026:29702",
                "https://access.redhat.com/errata/RHSA-2026:29703",
                "https://access.redhat.com/errata/RHSA-2026:29854",
                "https://access.redhat.com/errata/RHSA-2026:33722",
                "https://access.redhat.com/errata/RHSA-2026:34097",
                "https://access.redhat.com/errata/RHSA-2026:34192",
                "https://access.redhat.com/errata/RHSA-2026:34196",
                "https://access.redhat.com/errata/RHSA-2026:34197",
                "https://access.redhat.com/errata/RHSA-2026:34365",
                "https://access.redhat.com/errata/RHSA-2026:36319",
                "https://access.redhat.com/errata/RHSA-2026:36625",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:39810",
                "https://access.redhat.com/errata/RHSA-2026:39894",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:42043",
                "https://access.redhat.com/errata/RHSA-2026:42047",
                "https://access.redhat.com/errata/RHSA-2026:42049",
                "https://access.redhat.com/errata/RHSA-2026:42050",
                "https://access.redhat.com/errata/RHSA-2026:42051",
                "https://access.redhat.com/errata/RHSA-2026:47712",
                "https://access.redhat.com/errata/RHSA-2026:47714",
                "https://access.redhat.com/errata/RHSA-2026:47716",
                "https://access.redhat.com/errata/RHSA-2026:47719",
                "https://access.redhat.com/errata/RHSA-2026:47721",
                "https://access.redhat.com/errata/RHSA-2026:47722",
                "https://access.redhat.com/errata/RHSA-2026:47910",
                "https://access.redhat.com/errata/RHSA-2026:47952",
                "https://access.redhat.com/errata/RHSA-2026:48036",
                "https://access.redhat.com/errata/RHSA-2026:48790",
                "https://access.redhat.com/errata/RHSA-2026:49509",
                "https://access.redhat.com/errata/RHSA-2026:49526",
                "https://access.redhat.com/errata/RHSA-2026:49600",
                "https://access.redhat.com/errata/RHSA-2026:49838",
                "https://access.redhat.com/errata/RHSA-2026:49944",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:51288",
                "https://access.redhat.com/errata/RHSA-2026:54191",
                "https://access.redhat.com/errata/RHSA-2026:54603",
                "https://access.redhat.com/errata/RHSA-2026:54757",
                "https://access.redhat.com/errata/RHSA-2026:56785",
                "https://access.redhat.com/errata/RHSA-2026:56789",
                "https://access.redhat.com/errata/RHSA-2026:56852",
                "https://access.redhat.com/errata/RHSA-2026:56855",
                "https://access.redhat.com/errata/RHSA-2026:56910",
                "https://access.redhat.com/errata/RHSA-2026:56912",
                "https://access.redhat.com/errata/RHSA-2026:56913",
                "https://access.redhat.com/errata/RHSA-2026:57409",
                "https://access.redhat.com/errata/RHSA-2026:57482",
                "https://access.redhat.com/errata/RHSA-2026:57488",
                "https://access.redhat.com/errata/RHSA-2026:59830",
                "https://access.redhat.com/errata/RHSA-2026:59833",
                "https://access.redhat.com/errata/RHSA-2026:59834",
                "https://access.redhat.com/errata/RHSA-2026:60018",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:61685",
                "https://access.redhat.com/errata/RHSA-2026:61906",
                "https://access.redhat.com/errata/RHSA-2026:61907",
                "https://access.redhat.com/errata/RHSA-2026:9385",
                "https://access.redhat.com/security/cve/CVE-2026-32280",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2456339",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32280.json",
                "https://access.redhat.com/errata/RHSA-2026:65534",
                "https://access.redhat.com/errata/RHSA-2026:65886",
                "https://access.redhat.com/errata/RHSA-2026:66401",
                "https://access.redhat.com/errata/RHSA-2026:67319"
            ],
            "timeline": [
                {
                    "at": "2026-04-08T02:16:03.247",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32280"
                }
            ]
        },
        {
            "id": "CVE-2026-32146",
            "vendor": "Gleam",
            "product": "Gleam",
            "title": "Gleam vulnerability",
            "summary": "Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download.\n\nDependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended dependency directory, allowing attacker-controlled paths (via relative traversal such as ../ or absolute paths) to target filesystem locations outside that directory. When resolving git dependencies (e.g. via gleam deps download), the computed path is used for filesystem operations including directory deletion and creation.\n\nThis vulnerability occurs during the dependency resolution and download phase, which is generally expected to be limited to fetching and preparing dependencies within a confined directory. A malicious direct or transitive git dependency can exploit this issue to delete and overwrite arbitrary directories outside the intended dependency directory, including attacker-chosen absolute paths, potentially causing data loss. In some environments, this may be further leveraged to achieve code execution, for example by overwriting git hooks or shell configuration files.\n\nThis issue affects Gleam from 1.9.0-rc1 until 1.15.4.",
            "updated_at": "2026-09-08T01:17:28.607",
            "published_at": "2026-04-11T14:16:03.640",
            "cvss": 8.3,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "1.9.0-rc1 through before * (semver); a4fde22445ab8e5cc79c2ff48971616cb570702c through before * (git); v1.9.0-rc1-elixir through before v1.15.4-elixir (other); v1.9.0-rc1-erlang through before v1.15.4-erlang (other); v1.9.0-rc1-node through before v1.15.4-node (other); v1.9.0-rc1-node-slim through before v1.15.4-node-slim (other); v1.9.0-rc1-elixir-slim through before v1.15.4-elixir-slim (other); v1.9.0-rc1-erlang-slim through before v1.15.4-erlang-slim (other); v1.9.0-rc1-erlang-alpine through before v1.15.4-erlang-alpine (other); v1.9.0-rc1-elixir-alpine through before v1.15.4-elixir-alpine (other); v1.9.0-rc1-node-alpine through before v1.15.4-node-alpine (other); v1.9.0-rc1-scratch through before v1.15.4-scratch (other)",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download.\n\nDependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended dependency directory, allowing attacker-controlled paths (via relative traversal such as ../ or absolute paths) to target filesystem locations outside that directory. When resolving git dependencies (e.g. via gleam deps download), the computed path is used for filesystem operations including directory deletion and creation.\n\nThis vulnerability occurs during the dependency resolution and download phase, which is generally expected to be limited to fetching and preparing dependencies within a confined directory. A malicious direct or transitive git dependency can exploit this issue to delete and overwrite arbitrary directories outside the intended dependency directory, including attacker-chosen absolute paths, potentially causing data loss. In some environments, this may be further leveraged to achieve code execution, for example by overwriting git hooks or shell configuration files.\n\nThis issue affects Gleam from 1.9.0-rc1 until 1.15.4.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/gleam-lang/gleam/security/advisories/GHSA-vq5j-55vx-wq8j"
                }
            ],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-32146.html",
                "https://github.com/gleam-lang/gleam/commit/1aa5d8e594b0aa240bb213fce6ee19c65e6d5bcf",
                "https://github.com/gleam-lang/gleam/commit/2dc0467f822c75de94697a912755d172928ee40a",
                "https://github.com/gleam-lang/gleam/security/advisories/GHSA-vq5j-55vx-wq8j",
                "https://osv.dev/vulnerability/EEF-CVE-2026-32146",
                "https://access.redhat.com/security/cve/CVE-2026-32146",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2457578",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32146.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-11T14:16:03.640",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32146"
                }
            ]
        },
        {
            "id": "CVE-2026-31912",
            "vendor": "The Tcpdump Group",
            "product": "libpcap",
            "title": "libpcap vulnerability",
            "summary": "libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer.  In particular uncommon use cases a crafted filter program can cause the interpreter to try reading the OS process memory in the 32GiB around the buffer on 64-bit architectures and in the entire address space on 32-bit architectures.",
            "updated_at": "2026-09-05T19:16:55.823",
            "published_at": "2026-09-05T19:16:55.823",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.10.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer.  In particular uncommon use cases a crafted filter program can cause the interpreter to try reading the OS process memory in the 32GiB around the buffer on 64-bit architectures and in the entire address space on 32-bit architectures.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T19:16:55.823",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31912"
                }
            ]
        },
        {
            "id": "CVE-2026-31911",
            "vendor": "The Tcpdump Group",
            "product": "libpcap",
            "title": "libpcap vulnerability",
            "summary": "libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode.  In particular uncommon use cases a crafted filter program can terminate the OS process.",
            "updated_at": "2026-09-05T19:16:55.707",
            "published_at": "2026-09-05T19:16:55.707",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.10.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-617",
            "what_happened": "libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode.  In particular uncommon use cases a crafted filter program can terminate the OS process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T19:16:55.707",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31911"
                }
            ]
        },
        {
            "id": "CVE-2026-31807",
            "vendor": "OpenSSH",
            "product": "OpenSSH Agent",
            "title": "OpenSSH agent forwarding path validation",
            "summary": "A path validation error in an agent-forwarding workflow can expose an unintended local socket under specific forwarding configurations.",
            "updated_at": "2026-09-01T09:38:00Z",
            "published_at": "2026-09-01T07:12:00Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "≤ 9.9p1",
            "fixed": "10.0p1",
            "source_count": 63,
            "kev": false,
            "attack_vector": "Remote",
            "authentication": "Required",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "The forwarding path is insufficiently constrained in a narrow agent-forwarding configuration. A remote actor with an existing authenticated path may influence how a local socket is resolved.",
            "why_matters": "Agent forwarding often bridges trust boundaries. A validation failure can expose credentials or administrative workflows beyond the intended host.",
            "mitigations": [
                "Upgrade to OpenSSH 10.0p1 or later.",
                "Disable agent forwarding where it is not operationally required.",
                "Restrict forwarding to explicitly trusted hosts and review agent socket access."
            ],
            "pocs": [
                {
                    "repository": "openssh-forwarding-validation",
                    "author": "research-lab",
                    "first_seen": "Sep 1, 2026",
                    "confidence": "High",
                    "url": "https://github.com/search?q=CVE-2026-31807&type=repositories"
                }
            ],
            "references": [
                "https://github.com/search?q=CVE-2026-31807&type=repositories"
            ]
        },
        {
            "id": "CVE-2026-31700",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()\n\nIn tpacket_snd(), when PACKET_VNET_HDR is enabled, vnet_hdr points\ndirectly into the mmap'd TX ring buffer shared with userspace. The\nkernel validates the header via __packet_snd_vnet_parse() but then\nre-reads all fields later in virtio_net_hdr_to_skb(). A concurrent\nuserspace thread can modify the vnet_hdr fields between validation\nand use, bypassing all safety checks.\n\nThe non-TPACKET path (packet_snd()) already correctly copies vnet_hdr\nto a stack-local variable. All other vnet_hdr consumers in the kernel\n(tun.c, tap.c, virtio_net.c) also use stack copies. The TPACKET TX\npath is the only caller of virtio_net_hdr_to_skb() that reads directly\nfrom user-controlled shared memory.\n\nFix this by copying vnet_hdr from the mmap'd ring buffer to a\nstack-local variable before validation and use, consistent with the\napproach used in packet_snd() and all other callers.",
            "updated_at": "2026-09-08T09:17:59.693",
            "published_at": "2026-05-01T14:16:19.907",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1d036d25e5609ba73fee6a88db01c306b140d512 through before 0f4c9754956b86de158a4af5278c5cf5bda9439e (git); 1d036d25e5609ba73fee6a88db01c306b140d512 through before 714aa973da8163925eda7efd49361ccbee21ee46 (git); 1d036d25e5609ba73fee6a88db01c306b140d512 through before 1490f82353bdabc09265a74e645b07f05cf4188e (git); 1d036d25e5609ba73fee6a88db01c306b140d512 through before 74e2db36fe50e3ad9d5300d7fd0e6e2a15a6d121 (git); 1d036d25e5609ba73fee6a88db01c306b140d512 through before 3a1bf9116ea31470b89692585c3910dfe830dcdd (git); 1d036d25e5609ba73fee6a88db01c306b140d512 through before 28324a3b62d9ce7f9bdd65a8ce63f382041d1b27 (git); 1d036d25e5609ba73fee6a88db01c306b140d512 through before 48a6ef291a17639e1b6ae0fbe9c8b2bb87d7804b (git); 1d036d25e5609ba73fee6a88db01c306b140d512 through before 2c054e17d9d41f1020376806c7f750834ced4dc5 (git); 4.6; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-362",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd()\n\nIn tpacket_snd(), when PACKET_VNET_HDR is enabled, vnet_hdr points\ndirectly into the mmap'd TX ring buffer shared with userspace. The\nkernel validates the header via __packet_snd_vnet_parse() but then\nre-reads all fields later in virtio_net_hdr_to_skb(). A concurrent\nuserspace thread can modify the vnet_hdr fields between validation\nand use, bypassing all safety checks.\n\nThe non-TPACKET path (packet_snd()) already correctly copies vnet_hdr\nto a stack-local variable. All other vnet_hdr consumers in the kernel\n(tun.c, tap.c, virtio_net.c) also use stack copies. The TPACKET TX\npath is the only caller of virtio_net_hdr_to_skb() that reads directly\nfrom user-controlled shared memory.\n\nFix this by copying vnet_hdr from the mmap'd ring buffer to a\nstack-local variable before validation and use, consistent with the\napproach used in packet_snd() and all other callers.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0f4c9754956b86de158a4af5278c5cf5bda9439e",
                "https://git.kernel.org/stable/c/1490f82353bdabc09265a74e645b07f05cf4188e",
                "https://git.kernel.org/stable/c/28324a3b62d9ce7f9bdd65a8ce63f382041d1b27",
                "https://git.kernel.org/stable/c/2c054e17d9d41f1020376806c7f750834ced4dc5",
                "https://git.kernel.org/stable/c/3a1bf9116ea31470b89692585c3910dfe830dcdd",
                "https://git.kernel.org/stable/c/48a6ef291a17639e1b6ae0fbe9c8b2bb87d7804b",
                "https://git.kernel.org/stable/c/714aa973da8163925eda7efd49361ccbee21ee46",
                "https://git.kernel.org/stable/c/74e2db36fe50e3ad9d5300d7fd0e6e2a15a6d121",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-05-01T14:16:19.907",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31700"
                }
            ]
        },
        {
            "id": "CVE-2026-31681",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_multiport: validate range encoding in checkentry\n\nports_match_v1() treats any non-zero pflags entry as the start of a\nport range and unconditionally consumes the next ports[] element as\nthe range end.\n\nThe checkentry path currently validates protocol, flags and count, but\nit does not validate the range encoding itself. As a result, malformed\nrules can mark the last slot as a range start or place two range starts\nback to back, leaving ports_match_v1() to step past the last valid\nports[] element while interpreting the rule.\n\nReject malformed multiport v1 rules in checkentry by validating that\neach range start has a following element and that the following element\nis not itself marked as another range start.",
            "updated_at": "2026-09-08T09:17:59.380",
            "published_at": "2026-04-25T09:16:01.800",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "a89ecb6a2ef732d04058d87801e2b6bd7e5c7089 through before 8c5bf8f5b478f569191c4a7982de7cd5f5f73c1a (git); a89ecb6a2ef732d04058d87801e2b6bd7e5c7089 through before c9749f6232c845e31c21d4cc72200211df15d8a2 (git); a89ecb6a2ef732d04058d87801e2b6bd7e5c7089 through before b67d638cbee9975c765feb45c126e96ed11ec802 (git); a89ecb6a2ef732d04058d87801e2b6bd7e5c7089 through before 36bf0d98e180a7c384c8d8a59b0d2d4b80e5eb16 (git); a89ecb6a2ef732d04058d87801e2b6bd7e5c7089 through before aec14808271f2bf2b656de6ff12dfe73c5fd3b67 (git); a89ecb6a2ef732d04058d87801e2b6bd7e5c7089 through before 8368ce8eb01f0b91111d814703696e780d0ef12f (git); a89ecb6a2ef732d04058d87801e2b6bd7e5c7089 through before 1e4baa853f1cc4227e04f52d6860524707cfb294 (git); a89ecb6a2ef732d04058d87801e2b6bd7e5c7089 through before ff64c5bfef12461df8450e0f50bb693b5269c720 (git); 2.6.17; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_multiport: validate range encoding in checkentry\n\nports_match_v1() treats any non-zero pflags entry as the start of a\nport range and unconditionally consumes the next ports[] element as\nthe range end.\n\nThe checkentry path currently validates protocol, flags and count, but\nit does not validate the range encoding itself. As a result, malformed\nrules can mark the last slot as a range start or place two range starts\nback to back, leaving ports_match_v1() to step past the last valid\nports[] element while interpreting the rule.\n\nReject malformed multiport v1 rules in checkentry by validating that\neach range start has a following element and that the following element\nis not itself marked as another range start.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1e4baa853f1cc4227e04f52d6860524707cfb294",
                "https://git.kernel.org/stable/c/36bf0d98e180a7c384c8d8a59b0d2d4b80e5eb16",
                "https://git.kernel.org/stable/c/8368ce8eb01f0b91111d814703696e780d0ef12f",
                "https://git.kernel.org/stable/c/8c5bf8f5b478f569191c4a7982de7cd5f5f73c1a",
                "https://git.kernel.org/stable/c/aec14808271f2bf2b656de6ff12dfe73c5fd3b67",
                "https://git.kernel.org/stable/c/b67d638cbee9975c765feb45c126e96ed11ec802",
                "https://git.kernel.org/stable/c/c9749f6232c845e31c21d4cc72200211df15d8a2",
                "https://git.kernel.org/stable/c/ff64c5bfef12461df8450e0f50bb693b5269c720",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-04-25T09:16:01.800",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31681"
                }
            ]
        },
        {
            "id": "CVE-2026-31663",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: hold dev ref until after transport_finish NF_HOOK\n\nAfter async crypto completes, xfrm_input_resume() calls dev_put()\nimmediately on re-entry before the skb reaches transport_finish.\nThe skb->dev pointer is then used inside NF_HOOK and its okfn,\nwhich can race with device teardown.\n\nRemove the dev_put from the async resumption entry and instead\ndrop the reference after the NF_HOOK call in transport_finish,\nusing a saved device pointer since NF_HOOK may consume the skb.\nThis covers NF_DROP, NF_QUEUE and NF_STOLEN paths that skip\nthe okfn.\n\nFor non-transport exits (decaps, gro, drop) and secondary\nasync return points, release the reference inline when\nasync is set.",
            "updated_at": "2026-09-15T12:17:13.450",
            "published_at": "2026-04-24T15:16:45.947",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "acf568ee859f098279eadf551612f103afdacb4e through before 4236c30b437b80f673b9e08c8fae38b8d471ac9e (git); acf568ee859f098279eadf551612f103afdacb4e through before 0f451b43c88bf2b9c038b414be580efee42e031b (git); acf568ee859f098279eadf551612f103afdacb4e through before 5002beda5cac69d522dc54da0d5d463ed9c963d2 (git); acf568ee859f098279eadf551612f103afdacb4e through before 1c428b03840094410c5fb6a5db30640486bbbfcb (git); 69895c5ea0ca2e8d7de1e6d36965d0ab9730787f (git); 833760100588acfb267dac4d6a02ab9931237739 (git); e095ecaec6d94aa2156cceb98a85d409b51190f3 (git); 3.2.100 through before 3.3 (semver); 3.16.55 through before 3.17 (semver); 4.14.24 through before 4.15 (semver); 4.15",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-826",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: hold dev ref until after transport_finish NF_HOOK\n\nAfter async crypto completes, xfrm_input_resume() calls dev_put()\nimmediately on re-entry before the skb reaches transport_finish.\nThe skb->dev pointer is then used inside NF_HOOK and its okfn,\nwhich can race with device teardown.\n\nRemove the dev_put from the async resumption entry and instead\ndrop the reference after the NF_HOOK call in transport_finish,\nusing a saved device pointer since NF_HOOK may consume the skb.\nThis covers NF_DROP, NF_QUEUE and NF_STOLEN paths that skip\nthe okfn.\n\nFor non-transport exits (decaps, gro, drop) and secondary\nasync return points, release the reference inline when\nasync is set.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0f451b43c88bf2b9c038b414be580efee42e031b",
                "https://git.kernel.org/stable/c/1c428b03840094410c5fb6a5db30640486bbbfcb",
                "https://git.kernel.org/stable/c/4236c30b437b80f673b9e08c8fae38b8d471ac9e",
                "https://git.kernel.org/stable/c/5002beda5cac69d522dc54da0d5d463ed9c963d2",
                "https://access.redhat.com/errata/RHSA-2026:67471",
                "https://access.redhat.com/security/cve/CVE-2026-31663",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2461462",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31663.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-24T15:16:45.947",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31663"
                }
            ]
        },
        {
            "id": "CVE-2026-31449",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: validate p_idx bounds in ext4_ext_correct_indexes\n\next4_ext_correct_indexes() walks up the extent tree correcting\nindex entries when the first extent in a leaf is modified. Before\naccessing path[k].p_idx->ei_block, there is no validation that\np_idx falls within the valid range of index entries for that\nlevel.\n\nIf the on-disk extent header contains a corrupted or crafted\neh_entries value, p_idx can point past the end of the allocated\nbuffer, causing a slab-out-of-bounds read.\n\nFix this by validating path[k].p_idx against EXT_LAST_INDEX() at\nboth access sites: before the while loop and inside it. Return\n-EFSCORRUPTED if the index pointer is out of range, consistent\nwith how other bounds violations are handled in the ext4 extent\ntree code.",
            "updated_at": "2026-09-08T09:17:55.763",
            "published_at": "2026-04-22T14:16:38.933",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "a86c61812637c7dd0c57e29880cffd477b62f2e7 through before 39d6e2b67651614bac0dc6592fa9836321910067 (git); a86c61812637c7dd0c57e29880cffd477b62f2e7 through before c5839b34704c9c2f47f079451bdbb22de0da1ed1 (git); a86c61812637c7dd0c57e29880cffd477b62f2e7 through before 10242e640b36b91ad03d25f3dc77854bbdff8358 (git); a86c61812637c7dd0c57e29880cffd477b62f2e7 through before 4d08401aa13f1531216f1a7ae281ca4806e90a5c (git); a86c61812637c7dd0c57e29880cffd477b62f2e7 through before 407c944f217c17d4343148011acafebc604d55e1 (git); a86c61812637c7dd0c57e29880cffd477b62f2e7 through before 93f2e975ed658ce09db4d4c2877ca2c06540df83 (git); a86c61812637c7dd0c57e29880cffd477b62f2e7 through before 01bf1e0b997d82c0e353b51ed74ef99698043c33 (git); a86c61812637c7dd0c57e29880cffd477b62f2e7 through before 2acb5c12ebd860f30e4faf67e6cc8c44ddfe5fe8 (git); 2.6.19; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: validate p_idx bounds in ext4_ext_correct_indexes\n\next4_ext_correct_indexes() walks up the extent tree correcting\nindex entries when the first extent in a leaf is modified. Before\naccessing path[k].p_idx->ei_block, there is no validation that\np_idx falls within the valid range of index entries for that\nlevel.\n\nIf the on-disk extent header contains a corrupted or crafted\neh_entries value, p_idx can point past the end of the allocated\nbuffer, causing a slab-out-of-bounds read.\n\nFix this by validating path[k].p_idx against EXT_LAST_INDEX() at\nboth access sites: before the while loop and inside it. Return\n-EFSCORRUPTED if the index pointer is out of range, consistent\nwith how other bounds violations are handled in the ext4 extent\ntree code.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/01bf1e0b997d82c0e353b51ed74ef99698043c33",
                "https://git.kernel.org/stable/c/10242e640b36b91ad03d25f3dc77854bbdff8358",
                "https://git.kernel.org/stable/c/2acb5c12ebd860f30e4faf67e6cc8c44ddfe5fe8",
                "https://git.kernel.org/stable/c/39d6e2b67651614bac0dc6592fa9836321910067",
                "https://git.kernel.org/stable/c/407c944f217c17d4343148011acafebc604d55e1",
                "https://git.kernel.org/stable/c/4d08401aa13f1531216f1a7ae281ca4806e90a5c",
                "https://git.kernel.org/stable/c/93f2e975ed658ce09db4d4c2877ca2c06540df83",
                "https://git.kernel.org/stable/c/c5839b34704c9c2f47f079451bdbb22de0da1ed1",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-04-22T14:16:38.933",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31449"
                }
            ]
        },
        {
            "id": "CVE-2026-31431",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings.  Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.",
            "updated_at": "2026-09-08T15:13:07.273",
            "published_at": "2026-04-22T09:16:21.270",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "72548b093ee38a6d4f2a19e6ef1948ae05c181f7 through before 893d22e0135fa394db81df88697fba6032747667 (git); 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 through before 19d43105a97be0810edbda875f2cd03f30dc130c (git); 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 through before 961cfa271a918ad4ae452420e7c303149002875b (git); 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 through before 3115af9644c342b356f3f07a4dd1c8905cd9a6fc (git); 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 through before 8b88d99341f139e23bdeb1027a2a3ae10d341d82 (git); 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 through before fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8 (git); 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 through before ce42ee423e58dffa5ec03524054c9d8bfd4f6237 (git); 72548b093ee38a6d4f2a19e6ef1948ae05c181f7 through before a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5 (git); 4.14; before * (custom); before V6.0 (custom); before V21 Update 2 SR1 (custom); V3.1.6 through before V3.1.7 (custom); V3.1.5 through before * (custom); before V21 SP2 Update 1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 10135,
            "kev": true,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-669",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings.  Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · Liverwortenuresis371/copyfail-rs",
                    "author": "Liverwortenuresis371",
                    "first_seen": "2026-05-05",
                    "last_seen": "2026-08-26T10:41:21Z",
                    "pushed_at": "2026-08-26T10:38:53Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "LPE",
                    "language": "Rust",
                    "stars": 0,
                    "forks": 0,
                    "topics": [
                        "af-alg",
                        "auditd",
                        "copyfail",
                        "cve",
                        "cve-2026-31431",
                        "detection-engineering",
                        "ebpf",
                        "local-privilege-escalation"
                    ],
                    "title": "Exploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.",
                    "repository_description": "Exploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.",
                    "summary": "Exploit and detect CVE-2026-31431 vulnerabilities using a static binary that monitors system integrity and bypasses PAM authentication.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Liverwortenuresis371/copyfail-rs",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings.  Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-669",
                    "kev": true,
                    "epss": 0.99907,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-22",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · theori-io/copy-fail-CVE-2026-31431",
                    "author": "theori-io",
                    "first_seen": "2026-04-29",
                    "last_seen": "2026-08-26T07:37:15Z",
                    "pushed_at": "2026-04-29T21:21:46Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "LPE",
                    "language": "Python",
                    "stars": 4050,
                    "forks": 910,
                    "topics": [
                        "ai-security",
                        "cve-2026-31431",
                        "exploit",
                        "linux-kernel",
                        "privilege-escalation",
                        "privilege-escalation-exploits",
                        "security-research",
                        "theori"
                    ],
                    "title": "Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code",
                    "repository_description": "Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code",
                    "summary": "Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code",
                    "source": "CVE-Intel",
                    "url": "https://github.com/theori-io/copy-fail-CVE-2026-31431",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings.  Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-669",
                    "kev": true,
                    "epss": 0.99907,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-22",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail",
                    "author": "iss4cf0ng",
                    "first_seen": "2026-04-30",
                    "last_seen": "2026-08-25T13:15:07Z",
                    "pushed_at": "2026-04-30T15:39:36Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "LPE",
                    "language": "Rust",
                    "stars": 56,
                    "forks": 21,
                    "topics": [
                        "cve",
                        "cve-2026-31431",
                        "exploit",
                        "explotation",
                        "linux",
                        "linux-vulnerability",
                        "poc",
                        "privilege-escalation"
                    ],
                    "title": "Rust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter).",
                    "repository_description": "Rust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter).",
                    "summary": "Rust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter).",
                    "source": "CVE-Intel",
                    "url": "https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings.  Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-669",
                    "kev": true,
                    "epss": 0.99907,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-22",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · EynaExp/Copy-Fail-CVE-2026-31431-modernized",
                    "author": "EynaExp",
                    "first_seen": "2026-05-02",
                    "last_seen": "2026-08-25T07:56:01Z",
                    "pushed_at": "2026-05-02T07:50:43Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 3,
                    "forks": 0,
                    "topics": [],
                    "title": "A modernized version of Copy Fail PE",
                    "repository_description": "A modernized version of Copy Fail PE",
                    "summary": "A modernized version of Copy Fail PE",
                    "source": "CVE-Intel",
                    "url": "https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings.  Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-669",
                    "kev": true,
                    "epss": 0.99907,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-22",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail",
                    "author": "Dullpurple-sloop726",
                    "first_seen": "2026-05-06",
                    "last_seen": "2026-08-25T04:00:30Z",
                    "pushed_at": "2026-08-25T03:59:58Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "LPE",
                    "language": "Rust",
                    "stars": 3,
                    "forks": 0,
                    "topics": [
                        "af-alg",
                        "container-security",
                        "copy-fail",
                        "cve-2026-31431",
                        "educational",
                        "explotation",
                        "kernel-exploit",
                        "linux-vulnerability"
                    ],
                    "title": "Exploit CVE-2026-31431 on Linux using a Rust implementation to achieve local privilege escalation via an arbitrary page cache write primitive.",
                    "repository_description": "Exploit CVE-2026-31431 on Linux using a Rust implementation to achieve local privilege escalation via an arbitrary page cache write primitive.",
                    "summary": "Exploit CVE-2026-31431 on Linux using a Rust implementation to achieve local privilege escalation via an arbitrary page cache write primitive.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings.  Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-669",
                    "kev": true,
                    "epss": 0.99907,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-22",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · painoob/Copy-Fail-Exploit-CVE-2026-31431",
                    "author": "painoob",
                    "first_seen": "2026-04-29",
                    "last_seen": "2026-08-24T15:16:36Z",
                    "pushed_at": "2026-04-29T21:22:27Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 104,
                    "forks": 22,
                    "topics": [],
                    "title": "Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or .c elf) roots every Linux distribution shipped since 2017.",
                    "repository_description": "Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or .c elf) roots every Linux distribution shipped since 2017.",
                    "summary": "Most Linux LPEs need a race window or a kernel-specific offset. Copy Fail is a straight-line logic flaw, it needs neither. The same 732-byte Python script (or .c elf) roots every Linux distribution shipped since 2017.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings.  Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-669",
                    "kev": true,
                    "epss": 0.99907,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-22",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · 6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284",
                    "author": "6abc",
                    "first_seen": "2026-05-05",
                    "last_seen": "2026-08-24T14:12:39Z",
                    "pushed_at": "2026-08-13T13:20:57Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "C",
                    "stars": 1,
                    "forks": 0,
                    "topics": [],
                    "title": "Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings.  Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-669",
                    "kev": true,
                    "epss": 0.99907,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-22",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · xeloxa/copyfail-exploit",
                    "author": "xeloxa",
                    "first_seen": "2026-05-04",
                    "last_seen": "2026-08-24T08:30:43Z",
                    "pushed_at": "2026-05-05T07:01:53Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "LPE",
                    "language": "Python",
                    "stars": 24,
                    "forks": 4,
                    "topics": [
                        "af-alg",
                        "copy-fail",
                        "cve-2026-31431",
                        "exploit",
                        "linux-kernel",
                        "lpe",
                        "privilege-escalation",
                        "security-research"
                    ],
                    "title": "Copy Fail (CVE-2026-31431) LPE exploit. A clean, multi-arch Python reimplementation targeting the Linux kernel AF_ALG page cache vulnerability.",
                    "repository_description": "Copy Fail (CVE-2026-31431) LPE exploit. A clean, multi-arch Python reimplementation targeting the Linux kernel AF_ALG page cache vulnerability.",
                    "summary": "Copy Fail (CVE-2026-31431) LPE exploit. A clean, multi-arch Python reimplementation targeting the Linux kernel AF_ALG page cache vulnerability.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/xeloxa/copyfail-exploit",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_aead - Revert to operating out-of-place\n\nThis mostly reverts commit 72548b093ee3 except for the copying of\nthe associated data.\n\nThere is no benefit in operating in-place in algif_aead since the\nsource and destination come from different mappings.  Get rid of\nall the complexity added for in-place operation and just copy the\nAD directly.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-669",
                    "kev": true,
                    "epss": 0.99907,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-22",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "PoC-in-GitHub · John-Popovici/CVE-2026-31431-CopyFail-Linux-PrivEsc",
                    "author": "John-Popovici",
                    "first_seen": "2026-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A demo and explanation of CVE-2026-31431",
                    "summary": "A demo and explanation of CVE-2026-31431",
                    "url": "https://github.com/John-Popovici/CVE-2026-31431-CopyFail-Linux-PrivEsc"
                },
                {
                    "repository": "PoC-in-GitHub · Alfredooe/CVE-2026-31431",
                    "author": "Alfredooe",
                    "first_seen": "2026-04-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Golang implementation of CopyFail CVE-2026-31431",
                    "summary": "Golang implementation of CopyFail CVE-2026-31431",
                    "url": "https://github.com/Alfredooe/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · badsectorlabs/copyfail-go",
                    "author": "badsectorlabs",
                    "first_seen": "2026-04-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 361,
                    "title": "A Go implementation of copyfail (CVE-2026-31431)",
                    "summary": "A Go implementation of copyfail (CVE-2026-31431)",
                    "url": "https://github.com/badsectorlabs/copyfail-go"
                },
                {
                    "repository": "PoC-in-GitHub · tgies/copy-fail-c",
                    "author": "tgies",
                    "first_seen": "2026-04-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 445,
                    "title": "Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.",
                    "summary": "Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.",
                    "url": "https://github.com/tgies/copy-fail-c"
                },
                {
                    "repository": "PoC-in-GitHub · ZephrFish/CopyFail-CVE-2026-31431",
                    "author": "ZephrFish",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 29,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/ZephrFish/CopyFail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Crihexe/copy-fail-tiny-elf-CVE-2026-31431",
                    "author": "Crihexe",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 63,
                    "title": "Minimal no-libc Linux x86_64 ELF PoC build for Copy Fail (CVE-2026-31431)",
                    "summary": "Minimal no-libc Linux x86_64 ELF PoC build for Copy Fail (CVE-2026-31431)",
                    "url": "https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · b5null/CVE-2026-31431-C",
                    "author": "b5null",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/b5null/CVE-2026-31431-C"
                },
                {
                    "repository": "PoC-in-GitHub · Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC",
                    "author": "Percivalll",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · yiyihuohuo/CVE-2026-31431",
                    "author": "yiyihuohuo",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431EXP",
                    "summary": "CVE-2026-31431EXP",
                    "url": "https://github.com/yiyihuohuo/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · ruattd/cve-2026-31431",
                    "author": "ruattd",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Copy fail action runner test",
                    "summary": "Copy fail action runner test",
                    "url": "https://github.com/ruattd/cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Sndav/CVE-2026-31431-Advanced-Exploit",
                    "author": "Sndav",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 111,
                    "title": "CVE-2026-31431 纯文件利用",
                    "summary": "CVE-2026-31431 纯文件利用",
                    "url": "https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · luotian2/CVE-2026-31431",
                    "author": "luotian2",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/luotian2/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · insomnisec/Detections-CVE-2026-31431",
                    "author": "insomnisec",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Detection rules for CVE-2026-31431 Linux LPE Vulnerability - Credit: (Copy Fail) https://copy.fail",
                    "summary": "Detection rules for CVE-2026-31431 Linux LPE Vulnerability - Credit: (Copy Fail) https://copy.fail",
                    "url": "https://github.com/insomnisec/Detections-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · JnamerZ/CopyFail-CVE-2026-31431",
                    "author": "JnamerZ",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Rewrite https://github.com/theori-io/copy-fail-CVE-2026-31431 to C code",
                    "summary": "Rewrite https://github.com/theori-io/copy-fail-CVE-2026-31431 to C code",
                    "url": "https://github.com/JnamerZ/CopyFail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · vishwanathakuthota/copy-fail-CVE-2026-31431",
                    "author": "vishwanathakuthota",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "copy-fail-CVE-2026-31431",
                    "summary": "copy-fail-CVE-2026-31431",
                    "url": "https://github.com/vishwanathakuthota/copy-fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · desultory/CVE-2026-31431",
                    "author": "desultory",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/desultory/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · someCorp/copyFail-CVE-2026-31431-workaround-bash",
                    "author": "someCorp",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "copyFail-CVE-2026-31431-workaround-bash",
                    "summary": "copyFail-CVE-2026-31431-workaround-bash",
                    "url": "https://github.com/someCorp/copyFail-CVE-2026-31431-workaround-bash"
                },
                {
                    "repository": "PoC-in-GitHub · novysodope/copy-fail-CVE-2026-31431-C",
                    "author": "novysodope",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2026-31431 - standalone binary exploit (no Python required)",
                    "summary": "CVE-2026-31431 - standalone binary exploit (no Python required)",
                    "url": "https://github.com/novysodope/copy-fail-CVE-2026-31431-C"
                },
                {
                    "repository": "PoC-in-GitHub · thrandomv/cve-2026-31431-detection",
                    "author": "thrandomv",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Defensive detection package for CVE-2026-31431 (Linux kernel AF_ALG LPE). Sigma, Falco, auditd, KQL, and EQL rules mapped to MITRE ATT&CK T1068/T1611. Includes detection logic designed for auditd, eBPF, and EDR telemetry pipelines.",
                    "summary": "Defensive detection package for CVE-2026-31431 (Linux kernel AF_ALG LPE). Sigma, Falco, auditd, KQL, and EQL rules mapped to MITRE ATT&CK T1068/T1611. Includes detection logic designed for auditd, eBPF, and EDR telemetry pipelines.",
                    "url": "https://github.com/thrandomv/cve-2026-31431-detection"
                },
                {
                    "repository": "PoC-in-GitHub · Y5neKO/copy-fail-CVE-2026-31431-universal",
                    "author": "Y5neKO",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Multi-language implementation and compatibility with older versions of Python.",
                    "summary": "Multi-language implementation and compatibility with older versions of Python.",
                    "url": "https://github.com/Y5neKO/copy-fail-CVE-2026-31431-universal"
                },
                {
                    "repository": "PoC-in-GitHub · bigwario/copy-fail-CVE-2026-31431-C",
                    "author": "bigwario",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/bigwario/copy-fail-CVE-2026-31431-C"
                },
                {
                    "repository": "PoC-in-GitHub · twowb/CVE-2026-31431-",
                    "author": "twowb",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Linux提权漏洞二进制版CVE-2026-31431",
                    "summary": "Linux提权漏洞二进制版CVE-2026-31431",
                    "url": "https://github.com/twowb/CVE-2026-31431-"
                },
                {
                    "repository": "PoC-in-GitHub · arkdev1/check-cve-2026-31431",
                    "author": "arkdev1",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/arkdev1/check-cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · wuwu001/CVE-2026-31431-exploit",
                    "author": "wuwu001",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Linux local privilege escalation exploits for CVE-2026-31431, including raw and recoverable workflows.",
                    "summary": "Linux local privilege escalation exploits for CVE-2026-31431, including raw and recoverable workflows.",
                    "url": "https://github.com/wuwu001/CVE-2026-31431-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · ryan2929/CVE-2026-31431",
                    "author": "ryan2929",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/ryan2929/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · 0xShe/CVE-2026-31431",
                    "author": "0xShe",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 42,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/0xShe/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · WavesMan/cve-2026-31431-fleet-remediator",
                    "author": "WavesMan",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Fleet-scale CVE-2026-31431 audit and remediation orchestrator for Linux hosts via SSH, with strict host-key verification and multi-format reporting.",
                    "summary": "Fleet-scale CVE-2026-31431 audit and remediation orchestrator for Linux hosts via SSH, with strict host-key verification and multi-format reporting.",
                    "url": "https://github.com/WavesMan/cve-2026-31431-fleet-remediator"
                },
                {
                    "repository": "PoC-in-GitHub · wuzuowei/copy-fail-CVE-2026-31431",
                    "author": "wuzuowei",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/wuzuowei/copy-fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Isw-9/copy-fail-cve-2026-31431-aarch64",
                    "author": "Isw-9",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "References: https://github.com/theori-io/copy-fail-CVE-2026-31431; https://github.com/bigwario/copy-fail-CVE-2026-31431-C",
                    "summary": "References: https://github.com/theori-io/copy-fail-CVE-2026-31431; https://github.com/bigwario/copy-fail-CVE-2026-31431-C",
                    "url": "https://github.com/Isw-9/copy-fail-cve-2026-31431-aarch64"
                },
                {
                    "repository": "PoC-in-GitHub · st4rburn/RootRemover",
                    "author": "st4rburn",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Temporarily removes the root password using CVE-2026-31431",
                    "summary": "Temporarily removes the root password using CVE-2026-31431",
                    "url": "https://github.com/st4rburn/RootRemover"
                },
                {
                    "repository": "PoC-in-GitHub · freelabz/CVE-2026-31431",
                    "author": "freelabz",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "POC for CVE-2026-31431",
                    "summary": "POC for CVE-2026-31431",
                    "url": "https://github.com/freelabz/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · mrowkoob/copy-fail-mitigate-no-reboot",
                    "author": "mrowkoob",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Quick mitigation for copy-fail kernel bug CVE-2026-31431",
                    "summary": "Quick mitigation for copy-fail kernel bug CVE-2026-31431",
                    "url": "https://github.com/mrowkoob/copy-fail-mitigate-no-reboot"
                },
                {
                    "repository": "PoC-in-GitHub · nisec-eric/cve-2026-31431",
                    "author": "nisec-eric",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "AI for Work. x86_64 tested",
                    "summary": "AI for Work. x86_64 tested",
                    "url": "https://github.com/nisec-eric/cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · pascal-gujer/CVE-2026-31431",
                    "author": "pascal-gujer",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/pascal-gujer/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · eleveni386/CVE-2026-31431-Golang",
                    "author": "eleveni386",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 Golang版本。摆脱Python3.10依赖",
                    "summary": "CVE-2026-31431 Golang版本。摆脱Python3.10依赖",
                    "url": "https://github.com/eleveni386/CVE-2026-31431-Golang"
                },
                {
                    "repository": "PoC-in-GitHub · Linux-zs/cve-2026-31431-mitigation",
                    "author": "Linux-zs",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "cve-2026-31431 seccomp mitigation",
                    "summary": "cve-2026-31431 seccomp mitigation",
                    "url": "https://github.com/Linux-zs/cve-2026-31431-mitigation"
                },
                {
                    "repository": "PoC-in-GitHub · dixyes/fuck_cve_2026_31431",
                    "author": "dixyes",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "fuck CVE-2026-31431 for not stoppable machines",
                    "summary": "fuck CVE-2026-31431 for not stoppable machines",
                    "url": "https://github.com/dixyes/fuck_cve_2026_31431"
                },
                {
                    "repository": "PoC-in-GitHub · kadir/copy-fail-CVE-2026-31431-IOC",
                    "author": "kadir",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 31,
                    "title": "Detection, mitigation, and IOC toolkit for Copy Fail CVE-2026-31431 Linux kernel page-cache privilege escalation",
                    "summary": "Detection, mitigation, and IOC toolkit for Copy Fail CVE-2026-31431 Linux kernel page-cache privilege escalation",
                    "url": "https://github.com/kadir/copy-fail-CVE-2026-31431-IOC"
                },
                {
                    "repository": "PoC-in-GitHub · jbiniek/copy.fail-mitigation-MLM",
                    "author": "jbiniek",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Salt state to deploy a mitigation of the copy.fail vulnerability (CVE-2026-31431)",
                    "summary": "Salt state to deploy a mitigation of the copy.fail vulnerability (CVE-2026-31431)",
                    "url": "https://github.com/jbiniek/copy.fail-mitigation-MLM"
                },
                {
                    "repository": "PoC-in-GitHub · makitos666/CVE-2026-31431-Copy-Fail-Detection-Toolkit",
                    "author": "makitos666",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/makitos666/CVE-2026-31431-Copy-Fail-Detection-Toolkit"
                },
                {
                    "repository": "PoC-in-GitHub · lonelyor/CVE-2026-31431-exp",
                    "author": "lonelyor",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "根据py版本，升级成了c和rust版本，带加密混淆、0依赖（仅技术学习与分享）",
                    "summary": "根据py版本，升级成了c和rust版本，带加密混淆、0依赖（仅技术学习与分享）",
                    "url": "https://github.com/lonelyor/CVE-2026-31431-exp"
                },
                {
                    "repository": "PoC-in-GitHub · Phalanx-CCS/Copy-Fail",
                    "author": "Phalanx-CCS",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431 \"Copy Fail\" – Reachability Checker",
                    "summary": "CVE-2026-31431 \"Copy Fail\" – Reachability Checker",
                    "url": "https://github.com/Phalanx-CCS/Copy-Fail"
                },
                {
                    "repository": "PoC-in-GitHub · adampielak/CVE-2026-31431_SCA_WAZUH",
                    "author": "adampielak",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Wazuh SCA Linux hardening policy for Copy Fail (CVE-2026-31431)",
                    "summary": "Wazuh SCA Linux hardening policy for Copy Fail (CVE-2026-31431)",
                    "url": "https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH"
                },
                {
                    "repository": "PoC-in-GitHub · jiangban046-spec/CVE-2026-31431-exploit_py2_py3",
                    "author": "jiangban046-spec",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "一个兼容python2和python3的CVE-2026-31431脚本",
                    "summary": "一个兼容python2和python3的CVE-2026-31431脚本",
                    "url": "https://github.com/jiangban046-spec/CVE-2026-31431-exploit_py2_py3"
                },
                {
                    "repository": "PoC-in-GitHub · dorianhhuc/CVE-2026-31431",
                    "author": "dorianhhuc",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/dorianhhuc/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · 0xBlackash/CVE-2026-31431",
                    "author": "0xBlackash",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2026-31431",
                    "summary": "CVE-2026-31431",
                    "url": "https://github.com/0xBlackash/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · H1d3r/copy-fail_LPE_Interactive",
                    "author": "H1d3r",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431",
                    "summary": "CVE-2026-31431",
                    "url": "https://github.com/H1d3r/copy-fail_LPE_Interactive"
                },
                {
                    "repository": "PoC-in-GitHub · amdisrar/cve-2026-31431-mitigation",
                    "author": "amdisrar",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Temporary mitigation for Linux kernel local privilege escalation CVE-2026-31431 (AF_ALG interface)",
                    "summary": "Temporary mitigation for Linux kernel local privilege escalation CVE-2026-31431 (AF_ALG interface)",
                    "url": "https://github.com/amdisrar/cve-2026-31431-mitigation"
                },
                {
                    "repository": "PoC-in-GitHub · G01d3nW01f/CVE-2026-31431",
                    "author": "G01d3nW01f",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/G01d3nW01f/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · rio128128/copy-fail-CVE-2026-31431",
                    "author": "rio128128",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.",
                    "summary": "Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.",
                    "url": "https://github.com/rio128128/copy-fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · shadowabi/CVE-2026-31431-CopyFail-Universal-LPE",
                    "author": "shadowabi",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 58,
                    "title": "CVE-2026-31431 Copy Fail — Universal LPE exploit. Dynamic ELF offset + full-binary overwrite, Python 2/3 compatible with ctypes splice fallback",
                    "summary": "CVE-2026-31431 Copy Fail — Universal LPE exploit. Dynamic ELF offset + full-binary overwrite, Python 2/3 compatible with ctypes splice fallback",
                    "url": "https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE"
                },
                {
                    "repository": "PoC-in-GitHub · slauger/CVE-2026-31431",
                    "author": "slauger",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431 (Copy Fail) - Analysis and Mitigation for RHEL and OpenShift",
                    "summary": "CVE-2026-31431 (Copy Fail) - Analysis and Mitigation for RHEL and OpenShift",
                    "url": "https://github.com/slauger/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431",
                    "author": "Webhosting4U",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Detect and mitigate CVE-2026-31431",
                    "summary": "Detect and mitigate CVE-2026-31431",
                    "url": "https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · gmeghnag/TEST-CVE-2026-31431",
                    "author": "gmeghnag",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/gmeghnag/TEST-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC",
                    "author": "Percivalll",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 188,
                    "title": "PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers. Validated on Alibaba Cloud ACK, Amazon EKS and Google GKE.",
                    "summary": "PoC: fully unprivileged container escape to node-level code execution on Kubernetes via CVE-2026-31431 page-cache corruption + shared image layers. Validated on Alibaba Cloud ACK, Amazon EKS and Google GKE.",
                    "url": "https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · dicatalin/Copy_Fail_CVE-2026-31431_test_and_fix",
                    "author": "dicatalin",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/dicatalin/Copy_Fail_CVE-2026-31431_test_and_fix"
                },
                {
                    "repository": "PoC-in-GitHub · yandex-cloud-examples/yc-mk8s-copy-fail-mitigation",
                    "author": "yandex-cloud-examples",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "DaemonSet для митигации уязвимости CVE-2026-31431 (Copy Fail)",
                    "summary": "DaemonSet для митигации уязвимости CVE-2026-31431 (Copy Fail)",
                    "url": "https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation"
                },
                {
                    "repository": "PoC-in-GitHub · mfloresdacunha/CVE-2026-31431",
                    "author": "mfloresdacunha",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC exploit for CVE-2026-31431 (Copy Fail) — algif_aead page-cache scratch-write LPE",
                    "summary": "PoC exploit for CVE-2026-31431 (Copy Fail) — algif_aead page-cache scratch-write LPE",
                    "url": "https://github.com/mfloresdacunha/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Boos4721/copyfail-rs",
                    "author": "Boos4721",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2026-31431",
                    "summary": "CVE-2026-31431",
                    "url": "https://github.com/Boos4721/copyfail-rs"
                },
                {
                    "repository": "PoC-in-GitHub · eximiait/CVE-2026-31431",
                    "author": "eximiait",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Receta de ansible para verificar y mitigar CVE-2026-31431",
                    "summary": "Receta de ansible para verificar y mitigar CVE-2026-31431",
                    "url": "https://github.com/eximiait/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · JuanBindez/CVE-2026-31431",
                    "author": "JuanBindez",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 22,
                    "title": "Copy Fail - CVE-2026-31431",
                    "summary": "Copy Fail - CVE-2026-31431",
                    "url": "https://github.com/JuanBindez/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · XsanFlip/CVE-2026-31431-Patch",
                    "author": "XsanFlip",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2026-31431-Patch",
                    "summary": "CVE-2026-31431-Patch",
                    "url": "https://github.com/XsanFlip/CVE-2026-31431-Patch"
                },
                {
                    "repository": "PoC-in-GitHub · rshosting/CVE-2026-31431-patch",
                    "author": "rshosting",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A temporary mitigation for CVE-2026-31431 vulneribility",
                    "summary": "A temporary mitigation for CVE-2026-31431 vulneribility",
                    "url": "https://github.com/rshosting/CVE-2026-31431-patch"
                },
                {
                    "repository": "PoC-in-GitHub · wesmar/CVE-2026-31431",
                    "author": "wesmar",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2026-31431 is a bug in the handling of scatter-gather I/O operations and page cache references in the Linux kernel cryptographic subsystem — specifically in the AF_ALG socket implementation for AEAD algorithms (crypto/af_alg.c, crypto/aead.c).",
                    "summary": "CVE-2026-31431 is a bug in the handling of scatter-gather I/O operations and page cache references in the Linux kernel cryptographic subsystem — specifically in the AF_ALG socket implementation for AEAD algorithms (crypto/af_alg.c, crypto/aead.c).",
                    "url": "https://github.com/wesmar/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · wgnet/wg.copyfail.patch",
                    "author": "wgnet",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 24,
                    "title": "CVE-2026-31431 eBPF fix",
                    "summary": "CVE-2026-31431 eBPF fix",
                    "url": "https://github.com/wgnet/wg.copyfail.patch"
                },
                {
                    "repository": "PoC-in-GitHub · cs8425/copy-fail-go",
                    "author": "cs8425",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Copy Fail - CVE-2026-31431 in golang",
                    "summary": "Copy Fail - CVE-2026-31431 in golang",
                    "url": "https://github.com/cs8425/copy-fail-go"
                },
                {
                    "repository": "PoC-in-GitHub · diemoeve/copyfail-rs",
                    "author": "diemoeve",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "CopyFail (CVE-2026-31431): Linux kernel page-cache PrivEsc PoC + the only public detection tool. Novel PAM auth-bypass vector + Sigma/auditd/eBPF rules.",
                    "summary": "CopyFail (CVE-2026-31431): Linux kernel page-cache PrivEsc PoC + the only public detection tool. Novel PAM auth-bypass vector + Sigma/auditd/eBPF rules.",
                    "url": "https://github.com/diemoeve/copyfail-rs"
                },
                {
                    "repository": "PoC-in-GitHub · yxdm02/CVE-2026-31431",
                    "author": "yxdm02",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431",
                    "summary": "CVE-2026-31431",
                    "url": "https://github.com/yxdm02/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · grishinpv/CVE-2026-31431-old-python",
                    "author": "grishinpv",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 for python versions lower 3.10",
                    "summary": "CVE-2026-31431 for python versions lower 3.10",
                    "url": "https://github.com/grishinpv/CVE-2026-31431-old-python"
                },
                {
                    "repository": "PoC-in-GitHub · sammwyy/copyfail-rs",
                    "author": "sammwyy",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "Copy Fail exploit (CVE-2026-31431) but in Rust.",
                    "summary": "Copy Fail exploit (CVE-2026-31431) but in Rust.",
                    "url": "https://github.com/sammwyy/copyfail-rs"
                },
                {
                    "repository": "PoC-in-GitHub · SunL0w/PATCH-CVE-2026-31431-Ubuntu_Debian",
                    "author": "SunL0w",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Permanent Mitigation Script for CVE-2026-31431",
                    "summary": "Permanent Mitigation Script for CVE-2026-31431",
                    "url": "https://github.com/SunL0w/PATCH-CVE-2026-31431-Ubuntu_Debian"
                },
                {
                    "repository": "PoC-in-GitHub · scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431",
                    "author": "scriptzteam",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Paranoid disable whole AF_ALG + algif_* modules - Copy Fail (CVE-2026-31431)",
                    "summary": "Paranoid disable whole AF_ALG + algif_* modules - Copy Fail (CVE-2026-31431)",
                    "url": "https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · cozystack/copy-fail-blocker",
                    "author": "cozystack",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 34,
                    "title": "BPF-LSM mitigation for CVE-2026-31431 (Copy Fail) — denies AF_ALG socket creation cluster-wide",
                    "summary": "BPF-LSM mitigation for CVE-2026-31431 (Copy Fail) — denies AF_ALG socket creation cluster-wide",
                    "url": "https://github.com/cozystack/copy-fail-blocker"
                },
                {
                    "repository": "PoC-in-GitHub · leelong2020/cve-2026-31431",
                    "author": "leelong2020",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/leelong2020/cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · galoryber/CVE-2026-31431-cleaned",
                    "author": "galoryber",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431 cleaned up to be readable and thoroughly explained, including the embedded ELF",
                    "summary": "CVE-2026-31431 cleaned up to be readable and thoroughly explained, including the embedded ELF",
                    "url": "https://github.com/galoryber/CVE-2026-31431-cleaned"
                },
                {
                    "repository": "PoC-in-GitHub · vynazevedo/fail-CVE-2026-31431",
                    "author": "vynazevedo",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/vynazevedo/fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · MohamedKarrab/Copy-Fail-CVE-2026-31431",
                    "author": "MohamedKarrab",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/MohamedKarrab/Copy-Fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · w3llr00t3d/CVE-2026-31431-PoC",
                    "author": "w3llr00t3d",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "LPE exploit for CVE-2026-31431 CopyFail. Compatible with Python 3.9.",
                    "summary": "LPE exploit for CVE-2026-31431 CopyFail. Compatible with Python 3.9.",
                    "url": "https://github.com/w3llr00t3d/CVE-2026-31431-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · sec17br/CVE-2026-31431-Copy-Fail",
                    "author": "sec17br",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/sec17br/CVE-2026-31431-Copy-Fail"
                },
                {
                    "repository": "PoC-in-GitHub · mhdgning131/CopyFail-Patcher",
                    "author": "mhdgning131",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Here is patch script to CVE-2026-31431 CopyFail",
                    "summary": "Here is patch script to CVE-2026-31431 CopyFail",
                    "url": "https://github.com/mhdgning131/CopyFail-Patcher"
                },
                {
                    "repository": "PoC-in-GitHub · Xerxes-2/CVE-2026-31431-rs",
                    "author": "Xerxes-2",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/Xerxes-2/CVE-2026-31431-rs"
                },
                {
                    "repository": "PoC-in-GitHub · SeanRickerd/cve-2026-31431",
                    "author": "SeanRickerd",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "Exploit for cve-2026-31431",
                    "summary": "Exploit for cve-2026-31431",
                    "url": "https://github.com/SeanRickerd/cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · abdullaabdullazade/CVE-2026-31431",
                    "author": "abdullaabdullazade",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431",
                    "summary": "CVE-2026-31431",
                    "url": "https://github.com/abdullaabdullazade/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · weirdindiankid/copy-fail",
                    "author": "weirdindiankid",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 proof of concept.",
                    "summary": "CVE-2026-31431 proof of concept.",
                    "url": "https://github.com/weirdindiankid/copy-fail"
                },
                {
                    "repository": "PoC-in-GitHub · websecnl/CVE-2026-31431",
                    "author": "websecnl",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Linux algif_aead page-cache write to root - Local Privilege Escalation Exploit",
                    "summary": "Linux algif_aead page-cache write to root - Local Privilege Escalation Exploit",
                    "url": "https://github.com/websecnl/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Dabbleam/CVE-2026-31431-mitigation",
                    "author": "Dabbleam",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "eBPF-based daemon to mitigate CVE-2026-31431 on systems where `algif_aead` is built into the kernel, without a reboot!",
                    "summary": "eBPF-based daemon to mitigate CVE-2026-31431 on systems where `algif_aead` is built into the kernel, without a reboot!",
                    "url": "https://github.com/Dabbleam/CVE-2026-31431-mitigation"
                },
                {
                    "repository": "PoC-in-GitHub · selectel/mks-copy-fail-mitigation",
                    "author": "selectel",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "DaemonSet с реализацией временной меры для митигации уязвимости Copy Fail (CVE-2026-31431)",
                    "summary": "DaemonSet с реализацией временной меры для митигации уязвимости Copy Fail (CVE-2026-31431)",
                    "url": "https://github.com/selectel/mks-copy-fail-mitigation"
                },
                {
                    "repository": "PoC-in-GitHub · devstuff/harden-docker-seccomp",
                    "author": "devstuff",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Docker mitigation for CVE-2026-31431 ('Copy Fail'). Includes Kubernetes templates as well.",
                    "summary": "Docker mitigation for CVE-2026-31431 ('Copy Fail'). Includes Kubernetes templates as well.",
                    "url": "https://github.com/devstuff/harden-docker-seccomp"
                },
                {
                    "repository": "PoC-in-GitHub · yuspring/cve-2026-31431-poc",
                    "author": "yuspring",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/yuspring/cve-2026-31431-poc"
                },
                {
                    "repository": "PoC-in-GitHub · mishl-dev/CVE_2026_31431",
                    "author": "mishl-dev",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431 is a deterministic race‑free logic bug in the Linux kernel",
                    "summary": "CVE-2026-31431 is a deterministic race‑free logic bug in the Linux kernel",
                    "url": "https://github.com/mishl-dev/CVE_2026_31431"
                },
                {
                    "repository": "PoC-in-GitHub · Juguitos/copy-fail",
                    "author": "Juguitos",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2026-31431 - Copy Fail PoC (Python 3.10+)",
                    "summary": "CVE-2026-31431 - Copy Fail PoC (Python 3.10+)",
                    "url": "https://github.com/Juguitos/copy-fail"
                },
                {
                    "repository": "PoC-in-GitHub · DENNISDGR/CVE-2026-31431-poc",
                    "author": "DENNISDGR",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "An adapted version of the copy fail exploit to use parameters instead of dropping you into a root shell",
                    "summary": "An adapted version of the copy fail exploit to use parameters instead of dropping you into a root shell",
                    "url": "https://github.com/DENNISDGR/CVE-2026-31431-poc"
                },
                {
                    "repository": "PoC-in-GitHub · liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script",
                    "author": "liamromanis101",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "Detection Only.. working on an exploit PoC",
                    "summary": "Detection Only.. working on an exploit PoC",
                    "url": "https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script"
                },
                {
                    "repository": "PoC-in-GitHub · mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4",
                    "author": "mym0us3r",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "Wazuh 4.14.4 detection rules for CVE-2026-31431 (Copy Fail) - Linux Local Privilege Escalation via authencesn page cache write",
                    "summary": "Wazuh 4.14.4 detection rules for CVE-2026-31431 (Copy Fail) - Linux Local Privilege Escalation via authencesn page cache write",
                    "url": "https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4"
                },
                {
                    "repository": "PoC-in-GitHub · B1gN0Se/copy-fail-CVE-2026-31431",
                    "author": "B1gN0Se",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/B1gN0Se/copy-fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · maniakh/CVE-2026-31431---Copy-Fail-PoC",
                    "author": "maniakh",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Bu depo, Linux cekirdeginde (kernel) bulunan CVE-2026-31431 (Copy Fail) zafiyetini icermektedir. Zafiyet, algif_aead modülündeki bir optimizasyon hatasini kullanarak sayfa onbellegindeki (page cache) salt-okunur dosyalari manipule etmeye olanak tanir.",
                    "summary": "Bu depo, Linux cekirdeginde (kernel) bulunan CVE-2026-31431 (Copy Fail) zafiyetini icermektedir. Zafiyet, algif_aead modülündeki bir optimizasyon hatasini kullanarak sayfa onbellegindeki (page cache) salt-okunur dosyalari manipule etmeye olanak tanir.",
                    "url": "https://github.com/maniakh/CVE-2026-31431---Copy-Fail-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · meowteusz/copyfailautopatch",
                    "author": "meowteusz",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Detect and fix copy.fail CVE-2026-31431",
                    "summary": "Detect and fix copy.fail CVE-2026-31431",
                    "url": "https://github.com/meowteusz/copyfailautopatch"
                },
                {
                    "repository": "PoC-in-GitHub · effiesec/copy-fail-cve-2026-31431",
                    "author": "effiesec",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/effiesec/copy-fail-cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · offsecguy/CVE-2026-31431",
                    "author": "offsecguy",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Copy Fail is a straight-line logic flaw | C port | CVE-2026-31431",
                    "summary": "Copy Fail is a straight-line logic flaw | C port | CVE-2026-31431",
                    "url": "https://github.com/offsecguy/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · poyea/CVE-2026-31431.c",
                    "author": "poyea",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431 in C",
                    "summary": "CVE-2026-31431 in C",
                    "url": "https://github.com/poyea/CVE-2026-31431.c"
                },
                {
                    "repository": "PoC-in-GitHub · bryanvine/copy-fail-fix",
                    "author": "bryanvine",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Per-distro mitigation scripts for CVE-2026-31431 (\"Copy Fail\") Linux kernel LPE.",
                    "summary": "Per-distro mitigation scripts for CVE-2026-31431 (\"Copy Fail\") Linux kernel LPE.",
                    "url": "https://github.com/bryanvine/copy-fail-fix"
                },
                {
                    "repository": "PoC-in-GitHub · boliu83/cve-2026-31431-algif-aead-remediator",
                    "author": "boliu83",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Kubernetes DaemonSet to detect and remediate CVE-2026-31431 (GHSA-2274-3hgr-wxv6) — algif_aead LPE via modprobe blacklist",
                    "summary": "Kubernetes DaemonSet to detect and remediate CVE-2026-31431 (GHSA-2274-3hgr-wxv6) — algif_aead LPE via modprobe blacklist",
                    "url": "https://github.com/boliu83/cve-2026-31431-algif-aead-remediator"
                },
                {
                    "repository": "PoC-in-GitHub · Spoo1k/Copy-Fail-Exploit-CVE-2026-31431",
                    "author": "Spoo1k",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/Spoo1k/Copy-Fail-Exploit-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · 3jee/copy-fail-go",
                    "author": "3jee",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431 (copy-fail) - Go port of grenkoca's PoC with automatic SUID world-readable binary enumeration",
                    "summary": "CVE-2026-31431 (copy-fail) - Go port of grenkoca's PoC with automatic SUID world-readable binary enumeration",
                    "url": "https://github.com/3jee/copy-fail-go"
                },
                {
                    "repository": "PoC-in-GitHub · professional-slacker/alg_check",
                    "author": "professional-slacker",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431",
                    "summary": "CVE-2026-31431",
                    "url": "https://github.com/professional-slacker/alg_check"
                },
                {
                    "repository": "PoC-in-GitHub · aestechno/cve-2026-31431-ansible",
                    "author": "aestechno",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "cve-2026-31431 fix with ansible",
                    "summary": "cve-2026-31431 fix with ansible",
                    "url": "https://github.com/aestechno/cve-2026-31431-ansible"
                },
                {
                    "repository": "PoC-in-GitHub · ashok523/cve-2026-31431",
                    "author": "ashok523",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "he recently disclosed CVE-2026-31431 — also known as Copy Fail — is not something to take lightly.",
                    "summary": "he recently disclosed CVE-2026-31431 — also known as Copy Fail — is not something to take lightly.",
                    "url": "https://github.com/ashok523/cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · jodonnel/copyfail-briefing",
                    "author": "jodonnel",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 (Copy Fail) — Security briefings and remediation comparison",
                    "summary": "CVE-2026-31431 (Copy Fail) — Security briefings and remediation comparison",
                    "url": "https://github.com/jodonnel/copyfail-briefing"
                },
                {
                    "repository": "PoC-in-GitHub · deckhouse/d8-copy-fail-mitigation",
                    "author": "deckhouse",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 mitigation (Copy Fail)",
                    "summary": "CVE-2026-31431 mitigation (Copy Fail)",
                    "url": "https://github.com/deckhouse/d8-copy-fail-mitigation"
                },
                {
                    "repository": "PoC-in-GitHub · jneuhauser/copy-fail-CVE-2026-31431",
                    "author": "jneuhauser",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/jneuhauser/copy-fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · cyber-joker/copy-fail-python",
                    "author": "cyber-joker",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Python implementation of copyfail (CVE-2026-31431)",
                    "summary": "Python implementation of copyfail (CVE-2026-31431)",
                    "url": "https://github.com/cyber-joker/copy-fail-python"
                },
                {
                    "repository": "PoC-in-GitHub · HulnotHutu/CVE-2026-31431",
                    "author": "HulnotHutu",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "对 CVE-2026-31431 的复现分析、C 改编的 exp。",
                    "summary": "对 CVE-2026-31431 的复现分析、C 改编的 exp。",
                    "url": "https://github.com/HulnotHutu/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · mahradbt/copyfail-mitigation",
                    "author": "mahradbt",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Ansible playbooks to audit and mitigate CVE-2026-31431 (\"Copy Fail\"), a local privilege escalation vulnerability in the Linux kernel's `algif_aead` module affecting all major distributions since 2017.",
                    "summary": "Ansible playbooks to audit and mitigate CVE-2026-31431 (\"Copy Fail\"), a local privilege escalation vulnerability in the Linux kernel's `algif_aead` module affecting all major distributions since 2017.",
                    "url": "https://github.com/mahradbt/copyfail-mitigation"
                },
                {
                    "repository": "PoC-in-GitHub · OmerAti/almalinux-fix-cve-2026-31431",
                    "author": "OmerAti",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 Kernel Fix Script",
                    "summary": "CVE-2026-31431 Kernel Fix Script",
                    "url": "https://github.com/OmerAti/almalinux-fix-cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · ErdemOzgen/copy-fail-cve-2026-31431",
                    "author": "ErdemOzgen",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "Golang port of copy-fail-cve-2026-31431",
                    "summary": "Golang port of copy-fail-cve-2026-31431",
                    "url": "https://github.com/ErdemOzgen/copy-fail-cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Fulucky0-yuri/CVE-2026-31431-PocC",
                    "author": "Fulucky0-yuri",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431 C语言复现的poc，可在目标环境没有py时进行利用",
                    "summary": "CVE-2026-31431 C语言复现的poc，可在目标环境没有py时进行利用",
                    "url": "https://github.com/Fulucky0-yuri/CVE-2026-31431-PocC"
                },
                {
                    "repository": "PoC-in-GitHub · abhishekhargan/CVE-2026-31431",
                    "author": "abhishekhargan",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431: \"Copy Fail\" - Linux Kernel Local Privilege Escalation",
                    "summary": "CVE-2026-31431: \"Copy Fail\" - Linux Kernel Local Privilege Escalation",
                    "url": "https://github.com/abhishekhargan/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · MarioHY/cve_2026_31431_audit",
                    "author": "MarioHY",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A security auditing toolkit for CVE-2026-31431 vulnerability research",
                    "summary": "A security auditing toolkit for CVE-2026-31431 vulnerability research",
                    "url": "https://github.com/MarioHY/cve_2026_31431_audit"
                },
                {
                    "repository": "PoC-in-GitHub · AliHzSec/CVE-2026-31431",
                    "author": "AliHzSec",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2026-31431 Linux Local Privilege Escalation (LPE) Proof of Concept exploit",
                    "summary": "CVE-2026-31431 Linux Local Privilege Escalation (LPE) Proof of Concept exploit",
                    "url": "https://github.com/AliHzSec/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · kvakirsanov/CVE-2026-31431-live-process-code-injection",
                    "author": "kvakirsanov",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2026-31431 (Copy Fail) — Live Process Code Injection PoC",
                    "summary": "CVE-2026-31431 (Copy Fail) — Live Process Code Injection PoC",
                    "url": "https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection"
                },
                {
                    "repository": "PoC-in-GitHub · TheMalwareGuardian/CVE-2026-31431",
                    "author": "TheMalwareGuardian",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A structured explanation of CVE-2026-31431 (Copy Fail), connecting the three kernel changes that introduced the vulnerability and enabled its exploitation.",
                    "summary": "A structured explanation of CVE-2026-31431 (Copy Fail), connecting the three kernel changes that introduced the vulnerability and enabled its exploitation.",
                    "url": "https://github.com/TheMalwareGuardian/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · FrosterDL/CVE-2026-31431",
                    "author": "FrosterDL",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/FrosterDL/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · RecoFu/CVE-2026-31431-Copy-Fail",
                    "author": "RecoFu",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/RecoFu/CVE-2026-31431-Copy-Fail"
                },
                {
                    "repository": "PoC-in-GitHub · atgreen/block-copyfail",
                    "author": "atgreen",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "BPF LSM blocker for CVE-2026-31431 (Copy Fail) — blocks authencesn AF_ALG binds at runtime without rebooting",
                    "summary": "BPF LSM blocker for CVE-2026-31431 (Copy Fail) — blocks authencesn AF_ALG binds at runtime without rebooting",
                    "url": "https://github.com/atgreen/block-copyfail"
                },
                {
                    "repository": "PoC-in-GitHub · beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431",
                    "author": "beatbeast007",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Clean C version of Copy Fail (CVE-2026-31431) - Linux Local Privilege Escalation exploit using AF_ALG + authencesn + splice primitive.  Overwrites the page cache of /usr/bin/su with a tiny setuid shellcode to gain root privileges.  Educational proof-of-concept only.",
                    "summary": "Clean C version of Copy Fail (CVE-2026-31431) - Linux Local Privilege Escalation exploit using AF_ALG + authencesn + splice primitive.  Overwrites the page cache of /usr/bin/su with a tiny setuid shellcode to gain root privileges.  Educational proof-of-concept only.",
                    "url": "https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · sbeteta42/CVE-2026-31431_je_sappelle_RoOt",
                    "author": "sbeteta42",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431 -  Guide de Remédiation et Mesures de Protection",
                    "summary": "CVE-2026-31431 -  Guide de Remédiation et Mesures de Protection",
                    "url": "https://github.com/sbeteta42/CVE-2026-31431_je_sappelle_RoOt"
                },
                {
                    "repository": "PoC-in-GitHub · rvzsec/CVE-2026-31431",
                    "author": "rvzsec",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2026-31431 - Copy Fail | Linux LPE via authencesn page cache write. Unprivileged user to root on most distros since 2017. PoC in C and Python.",
                    "summary": "CVE-2026-31431 - Copy Fail | Linux LPE via authencesn page cache write. Unprivileged user to root on most distros since 2017. PoC in C and Python.",
                    "url": "https://github.com/rvzsec/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Silent0x0/Copy-Fail---CVE-2026-31431",
                    "author": "Silent0x0",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 \"Copy Fail\" - Analysis and defensive research for the Linux kernel AF_ALG privilege escalation vulnerability affecting all major distributions since 2017. 100% reliable LPE via authencesn logic flaw",
                    "summary": "CVE-2026-31431 \"Copy Fail\" - Analysis and defensive research for the Linux kernel AF_ALG privilege escalation vulnerability affecting all major distributions since 2017. 100% reliable LPE via authencesn logic flaw",
                    "url": "https://github.com/Silent0x0/Copy-Fail---CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · SpenserCai/copy_fail",
                    "author": "SpenserCai",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2026-31431 (Copy Fail) — Rust exploit PoC + eBPF runtime defense. Blocks Linux kernel AF_ALG page-cache LPE without rebooting (LSM/kprobe dual-mode).",
                    "summary": "CVE-2026-31431 (Copy Fail) — Rust exploit PoC + eBPF runtime defense. Blocks Linux kernel AF_ALG page-cache LPE without rebooting (LSM/kprobe dual-mode).",
                    "url": "https://github.com/SpenserCai/copy_fail"
                },
                {
                    "repository": "PoC-in-GitHub · K3ysTr0K3R/CVE-2026-31431-EXPLOIT",
                    "author": "K3ysTr0K3R",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 - Copy Fail - PoC exploit",
                    "summary": "CVE-2026-31431 - Copy Fail - PoC exploit",
                    "url": "https://github.com/K3ysTr0K3R/CVE-2026-31431-EXPLOIT"
                },
                {
                    "repository": "PoC-in-GitHub · povzayd/CVE-2026-31431",
                    "author": "povzayd",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Python exploit demonstrating an in‑memory AF_ALG‑based kernel vulnerability on certain Linux kernels.",
                    "summary": "Python exploit demonstrating an in‑memory AF_ALG‑based kernel vulnerability on certain Linux kernels.",
                    "url": "https://github.com/povzayd/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · sebinxavi/cve-checker-2026",
                    "author": "sebinxavi",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Multi-OS vulnerability checker for CVE-2026-31431 (Linux kernel) and CVE-2026-41940 (cPanel)",
                    "summary": "Multi-OS vulnerability checker for CVE-2026-31431 (Linux kernel) and CVE-2026-41940 (cPanel)",
                    "url": "https://github.com/sebinxavi/cve-checker-2026"
                },
                {
                    "repository": "PoC-in-GitHub · mlazzarotto/copy-fail-CVE-2026-31431-mitigation-ansible-playbook",
                    "author": "mlazzarotto",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "An Ansible Playbook to mitigate the vulnerability CVE-2026-31431 on RHEL-based and Debian-based OSes.",
                    "summary": "An Ansible Playbook to mitigate the vulnerability CVE-2026-31431 on RHEL-based and Debian-based OSes.",
                    "url": "https://github.com/mlazzarotto/copy-fail-CVE-2026-31431-mitigation-ansible-playbook"
                },
                {
                    "repository": "PoC-in-GitHub · ExploitEoom/CVE-2026-31431",
                    "author": "ExploitEoom",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CopyFail",
                    "summary": "CopyFail",
                    "url": "https://github.com/ExploitEoom/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · ben-slates/CVE-2026-31431-Exploit",
                    "author": "ben-slates",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/ben-slates/CVE-2026-31431-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · bootsareme/copyfail-deconstructed",
                    "author": "bootsareme",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Easy-to-understand version of CVE-2026-31431",
                    "summary": "Easy-to-understand version of CVE-2026-31431",
                    "url": "https://github.com/bootsareme/copyfail-deconstructed"
                },
                {
                    "repository": "PoC-in-GitHub · mrunalp/block-copyfail",
                    "author": "mrunalp",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "BPF LSM blocker for CVE-2026-31431 (Copy Fail) - zero-reboot remediation for OpenShift 4",
                    "summary": "BPF LSM blocker for CVE-2026-31431 (Copy Fail) - zero-reboot remediation for OpenShift 4",
                    "url": "https://github.com/mrunalp/block-copyfail"
                },
                {
                    "repository": "PoC-in-GitHub · 1amBa7Man/Linux-copy-fail-CVE-2026-31431",
                    "author": "1amBa7Man",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Proof-of-concept and technical analysis of CVE-2026-31431 (Copy Fail), a Linux kernel privilege escalation vulnerability affecting page cache integrity.",
                    "summary": "Proof-of-concept and technical analysis of CVE-2026-31431 (Copy Fail), a Linux kernel privilege escalation vulnerability affecting page cache integrity.",
                    "url": "https://github.com/1amBa7Man/Linux-copy-fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Lyutoon/CopyFail-Experiment",
                    "author": "Lyutoon",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Fully LLM generated exploit for CVE-2026-31431, written in C",
                    "summary": "Fully LLM generated exploit for CVE-2026-31431, written in C",
                    "url": "https://github.com/Lyutoon/CopyFail-Experiment"
                },
                {
                    "repository": "PoC-in-GitHub · ledlight33/copyfail-dfir",
                    "author": "ledlight33",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Interactive DFIR walkthrough of CVE-2026-31431 (Copy Fail) - from SIEM alert to confirmed verdict. Real Volatility 3 commands, verified methodology.",
                    "summary": "Interactive DFIR walkthrough of CVE-2026-31431 (Copy Fail) - from SIEM alert to confirmed verdict. Real Volatility 3 commands, verified methodology.",
                    "url": "https://github.com/ledlight33/copyfail-dfir"
                },
                {
                    "repository": "PoC-in-GitHub · Smarttfoxx/copyfail",
                    "author": "Smarttfoxx",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 20,
                    "title": "CVE-2026-31431 (Copy Fail) PoC - Linux kernel page cache corruption via authencesn AF_ALG + splice()",
                    "summary": "CVE-2026-31431 (Copy Fail) PoC - Linux kernel page cache corruption via authencesn AF_ALG + splice()",
                    "url": "https://github.com/Smarttfoxx/copyfail"
                },
                {
                    "repository": "PoC-in-GitHub · parmstro/cfDr",
                    "author": "parmstro",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Ansible playbook for detecting and remediating CVE-2026-31431 (Copy Fail) - Linux kernel local privilege escalation vulnerability",
                    "summary": "Ansible playbook for detecting and remediating CVE-2026-31431 (Copy Fail) - Linux kernel local privilege escalation vulnerability",
                    "url": "https://github.com/parmstro/cfDr"
                },
                {
                    "repository": "PoC-in-GitHub · Shotafry/CopyFail-Exploits-CVE-2026-31431",
                    "author": "Shotafry",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · glask1d/CVE-2026-31431-PoC",
                    "author": "glask1d",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Vibecoded PoC for CVE-2026-31431",
                    "summary": "Vibecoded PoC for CVE-2026-31431",
                    "url": "https://github.com/glask1d/CVE-2026-31431-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · monobrau/copyfailscan",
                    "author": "monobrau",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "SSH posture helper for CVE-2026-31431 (Copy Fail): kernel and algif_aead inventory",
                    "summary": "SSH posture helper for CVE-2026-31431 (Copy Fail): kernel and algif_aead inventory",
                    "url": "https://github.com/monobrau/copyfailscan"
                },
                {
                    "repository": "PoC-in-GitHub · Emmmmllll/copy-fail-zig",
                    "author": "Emmmmllll",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Zig implementation of the Copy Fail Linux LPE (CVE-2026-31431) https://copy.fail for security-research and defensive-detection purposes",
                    "summary": "Zig implementation of the Copy Fail Linux LPE (CVE-2026-31431) https://copy.fail for security-research and defensive-detection purposes",
                    "url": "https://github.com/Emmmmllll/copy-fail-zig"
                },
                {
                    "repository": "PoC-in-GitHub · kdjnb/fix_CVE-2026-31431",
                    "author": "kdjnb",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "破坏CVE-2026-31431所需的漏洞组件，从而达到无法通过CVE-2026-31431提权。",
                    "summary": "破坏CVE-2026-31431所需的漏洞组件，从而达到无法通过CVE-2026-31431提权。",
                    "url": "https://github.com/kdjnb/fix_CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · euriconicacio/copy-fail-CVE-2026-31431-poc",
                    "author": "euriconicacio",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/euriconicacio/copy-fail-CVE-2026-31431-poc"
                },
                {
                    "repository": "PoC-in-GitHub · ROSNLR5/modrosnlr5",
                    "author": "ROSNLR5",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Linux Kernel LPE PoC (CVE-2026-31431)",
                    "summary": "Linux Kernel LPE PoC (CVE-2026-31431)",
                    "url": "https://github.com/ROSNLR5/modrosnlr5"
                },
                {
                    "repository": "PoC-in-GitHub · TheMursalin/CVE-2026-31431",
                    "author": "TheMursalin",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/TheMursalin/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · qi4L/CVE-2026-31431-Container-Escape",
                    "author": "qi4L",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 27,
                    "title": "CVE-2026-31431 容器逃逸",
                    "summary": "CVE-2026-31431 容器逃逸",
                    "url": "https://github.com/qi4L/CVE-2026-31431-Container-Escape"
                },
                {
                    "repository": "PoC-in-GitHub · moaaz-mostafa123/CVE-2026-31431",
                    "author": "moaaz-mostafa123",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/moaaz-mostafa123/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · malwarekid/CVE-2026-31431",
                    "author": "malwarekid",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CopyFail is a proof-of-concept exploit for CVE-2026-31431, targeting a memory corruption vulnerability in the Linux Kernel Crypto API (`AF_ALG`). The exploit leverages the `splice` system call to perform unauthorized page-cache patching of the `/usr/bin/su` binary, enabling a password-less escalation to root.",
                    "summary": "CopyFail is a proof-of-concept exploit for CVE-2026-31431, targeting a memory corruption vulnerability in the Linux Kernel Crypto API (`AF_ALG`). The exploit leverages the `splice` system call to perform unauthorized page-cache patching of the `/usr/bin/su` binary, enabling a password-less escalation to root.",
                    "url": "https://github.com/malwarekid/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · xd20111/CVE-2026-31431",
                    "author": "xd20111",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431  Copy Fail - Local Privilege Escalation in the Linux kernel's authencesn cryptographic template via AF_ALG + splice()",
                    "summary": "CVE-2026-31431  Copy Fail - Local Privilege Escalation in the Linux kernel's authencesn cryptographic template via AF_ALG + splice()",
                    "url": "https://github.com/xd20111/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · MartinPham/copy-fail-CVE-2026-31431-php",
                    "author": "MartinPham",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2026-31431 (Copy Fail) PHP PoC",
                    "summary": "CVE-2026-31431 (Copy Fail) PHP PoC",
                    "url": "https://github.com/MartinPham/copy-fail-CVE-2026-31431-php"
                },
                {
                    "repository": "PoC-in-GitHub · krish-foren6/CVE-2026-31431-Report-Copy-fail-Vulnerability-",
                    "author": "krish-foren6",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Detailed analysis of the Copy Fail vulnerability (CVE-2026-31431) in the Linux kernel, including memory corruption mechanism, privilege escalation flow, and security impact.",
                    "summary": "Detailed analysis of the Copy Fail vulnerability (CVE-2026-31431) in the Linux kernel, including memory corruption mechanism, privilege escalation flow, and security impact.",
                    "url": "https://github.com/krish-foren6/CVE-2026-31431-Report-Copy-fail-Vulnerability-"
                },
                {
                    "repository": "PoC-in-GitHub · Trex1e/copyfail-CVE-2026-31431",
                    "author": "Trex1e",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Original repo: https://github.com/theori-io/copy-fail-CVE-2026-31431",
                    "summary": "Original repo: https://github.com/theori-io/copy-fail-CVE-2026-31431",
                    "url": "https://github.com/Trex1e/copyfail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · KanbaraAkihito/CVE-2026-31431-copyfail-rs",
                    "author": "KanbaraAkihito",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs"
                },
                {
                    "repository": "PoC-in-GitHub · mahdi13830510/CVE-2026-31431-mitigation-suite",
                    "author": "mahdi13830510",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "A defensive security toolkit specifically engineered to detect and mitigate CVE-2026-31431 and similar nftables / AF_ALG vulnerabilities. Includes non-destructive behavioral probes, module blacklisting automation, and Auditd/eBPF rules for real-time threat detection.",
                    "summary": "A defensive security toolkit specifically engineered to detect and mitigate CVE-2026-31431 and similar nftables / AF_ALG vulnerabilities. Includes non-destructive behavioral probes, module blacklisting automation, and Auditd/eBPF rules for real-time threat detection.",
                    "url": "https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite"
                },
                {
                    "repository": "PoC-in-GitHub · suominen/CVE-2026-31431",
                    "author": "suominen",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Tracking Copy Fail (CVE-2026-31431), the Linux algif_aead privilege escalation",
                    "summary": "Tracking Copy Fail (CVE-2026-31431), the Linux algif_aead privilege escalation",
                    "url": "https://github.com/suominen/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · M4xSec/CVE-2026-31431-RCE-Exploit",
                    "author": "M4xSec",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2026-31431 RCE Exploit. A critical Linux kernel LPE in the algif_aead crypto subsystem. Any unprivileged user can write 4 bytes into the page cache of any readable file and get root.",
                    "summary": "CVE-2026-31431 RCE Exploit. A critical Linux kernel LPE in the algif_aead crypto subsystem. Any unprivileged user can write 4 bytes into the page cache of any readable file and get root.",
                    "url": "https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · mmionf/copy-fail-CVE-2026-31431",
                    "author": "mmionf",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/mmionf/copy-fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · cxwx/cpp-CVE-2026-31431",
                    "author": "cxwx",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 cpp version for x86_64",
                    "summary": "CVE-2026-31431 cpp version for x86_64",
                    "url": "https://github.com/cxwx/cpp-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Huchangzhi/autorootlinux",
                    "author": "Huchangzhi",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "基于CVE-2026-31431的自动root脚本",
                    "summary": "基于CVE-2026-31431的自动root脚本",
                    "url": "https://github.com/Huchangzhi/autorootlinux"
                },
                {
                    "repository": "PoC-in-GitHub · Sl4cK0TH/CVE-2026-31431-PoC",
                    "author": "Sl4cK0TH",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/Sl4cK0TH/CVE-2026-31431-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · pulentoski/CVE-2026-31431",
                    "author": "pulentoski",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/pulentoski/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · joltcan/ansible-role-cve-2026-31431",
                    "author": "joltcan",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Ansible role: CVE-2026-31431 (Copy Fail) modprobe.d mitigation — disables algif_aead",
                    "summary": "Ansible role: CVE-2026-31431 (Copy Fail) modprobe.d mitigation — disables algif_aead",
                    "url": "https://github.com/joltcan/ansible-role-cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · sandraschi/copy-fail-mcp",
                    "author": "sandraschi",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 Copy Fail — Linux kernel LPE tester via MCP",
                    "summary": "CVE-2026-31431 Copy Fail — Linux kernel LPE tester via MCP",
                    "url": "https://github.com/sandraschi/copy-fail-mcp"
                },
                {
                    "repository": "PoC-in-GitHub · Gr-1m/CVE-2026-31431",
                    "author": "Gr-1m",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Copyfail (CVE-2026-31431) exp rewrite by Golang",
                    "summary": "Copyfail (CVE-2026-31431) exp rewrite by Golang",
                    "url": "https://github.com/Gr-1m/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · ctzisme/copyfail-guard",
                    "author": "ctzisme",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Detect and mitigate CVE-2026-31431 (Copy Fail) on Linux systems.",
                    "summary": "Detect and mitigate CVE-2026-31431 (Copy Fail) on Linux systems.",
                    "url": "https://github.com/ctzisme/copyfail-guard"
                },
                {
                    "repository": "PoC-in-GitHub · AvPrince26/copy-fail-CVE-2026-31431-Python-Golfing",
                    "author": "AvPrince26",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Golf Challenge for https://copy.golf/",
                    "summary": "Golf Challenge for https://copy.golf/",
                    "url": "https://github.com/AvPrince26/copy-fail-CVE-2026-31431-Python-Golfing"
                },
                {
                    "repository": "PoC-in-GitHub · pedromizz/copy-fail",
                    "author": "pedromizz",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "PoC of CVE-2026-31431",
                    "summary": "PoC of CVE-2026-31431",
                    "url": "https://github.com/pedromizz/copy-fail"
                },
                {
                    "repository": "PoC-in-GitHub · astounds/copy-fail-CVE-2026-31431",
                    "author": "astounds",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/astounds/copy-fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · jbnetwork-git/copy-fail-check",
                    "author": "jbnetwork-git",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 35,
                    "title": "CVE-2026-31431  Helper basado en https://copy.fail/",
                    "summary": "CVE-2026-31431  Helper basado en https://copy.fail/",
                    "url": "https://github.com/jbnetwork-git/copy-fail-check"
                },
                {
                    "repository": "PoC-in-GitHub · danimrtzp/CVE-2026-31431-REVSHELL",
                    "author": "danimrtzp",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/danimrtzp/CVE-2026-31431-REVSHELL"
                },
                {
                    "repository": "PoC-in-GitHub · pyroceper/copy-fail-CVE-2026-31431",
                    "author": "pyroceper",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CopyFail PoC in C",
                    "summary": "CopyFail PoC in C",
                    "url": "https://github.com/pyroceper/copy-fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · ForensicFoundry/cve-2026-31431-check",
                    "author": "ForensicFoundry",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Check local Linux mitigation/exposure status for CVE-2026-31431 \"Copy Fail\"",
                    "summary": "Check local Linux mitigation/exposure status for CVE-2026-31431 \"Copy Fail\"",
                    "url": "https://github.com/ForensicFoundry/cve-2026-31431-check"
                },
                {
                    "repository": "PoC-in-GitHub · vyahello/CVE-2026-31431",
                    "author": "vyahello",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "🚨 Linux local privilege escalation PoC for CVE-2026-31431",
                    "summary": "🚨 Linux local privilege escalation PoC for CVE-2026-31431",
                    "url": "https://github.com/vyahello/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · sibersan/cve-2026-31431-checker",
                    "author": "sibersan",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Detection tool for CVE-2026-31431 Copy Fail vulnerability in Linux kernels. Detection only - does not exploit.",
                    "summary": "Detection tool for CVE-2026-31431 Copy Fail vulnerability in Linux kernels. Detection only - does not exploit.",
                    "url": "https://github.com/sibersan/cve-2026-31431-checker"
                },
                {
                    "repository": "PoC-in-GitHub · ncmprbll/copy-fail-rs",
                    "author": "ncmprbll",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431",
                    "summary": "CVE-2026-31431",
                    "url": "https://github.com/ncmprbll/copy-fail-rs"
                },
                {
                    "repository": "PoC-in-GitHub · jamal-soc21/Weekly-Breach-Investigation--006",
                    "author": "jamal-soc21",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Repository documenting the Copy Fail (CVE-2026-31431) Linux kernel vulnerability, a local privilege escalation flaw enabling root access and mapped to MITRE ATT&CK techniques.",
                    "summary": "Repository documenting the Copy Fail (CVE-2026-31431) Linux kernel vulnerability, a local privilege escalation flaw enabling root access and mapped to MITRE ATT&CK techniques.",
                    "url": "https://github.com/jamal-soc21/Weekly-Breach-Investigation--006"
                },
                {
                    "repository": "PoC-in-GitHub · tfawnies/CVE-2026-31431",
                    "author": "tfawnies",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/tfawnies/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · ravindercodes/copy-fail-CVE-2026-31431",
                    "author": "ravindercodes",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/ravindercodes/copy-fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · ChernStepanov/CopyFail-for-dummies",
                    "author": "ChernStepanov",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A tiny explanation + PoC for CVE-2026-31431",
                    "summary": "A tiny explanation + PoC for CVE-2026-31431",
                    "url": "https://github.com/ChernStepanov/CopyFail-for-dummies"
                },
                {
                    "repository": "PoC-in-GitHub · kaleth4/CVE-2026-31431",
                    "author": "kaleth4",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/kaleth4/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · mCub3/CVE-2026-31431",
                    "author": "mCub3",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 (Copy Fail) – unprivileged root via AF_ALG page cache corruption. C PoC.",
                    "summary": "CVE-2026-31431 (Copy Fail) – unprivileged root via AF_ALG page cache corruption. C PoC.",
                    "url": "https://github.com/mCub3/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · juliosuas/copyfail-guard",
                    "author": "juliosuas",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Fast, auditable Linux mitigation for CVE-2026-31431 Copy Fail: algif_aead block, verification, and AF_ALG seccomp hardening.",
                    "summary": "Fast, auditable Linux mitigation for CVE-2026-31431 Copy Fail: algif_aead block, verification, and AF_ALG seccomp hardening.",
                    "url": "https://github.com/juliosuas/copyfail-guard"
                },
                {
                    "repository": "PoC-in-GitHub · codesource/copyfail-check",
                    "author": "codesource",
                    "first_seen": "2026-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Shell script to detect CVE-2026-31431 (Copy Fail) exposure and mitigations on Linux systems: kernel check, module state, boot params, AF_ALG reachability, and distro patch status.",
                    "summary": "Shell script to detect CVE-2026-31431 (Copy Fail) exposure and mitigations on Linux systems: kernel check, module state, boot params, AF_ALG reachability, and distro patch status.",
                    "url": "https://github.com/codesource/copyfail-check"
                },
                {
                    "repository": "PoC-in-GitHub · xn0kkx/CVE-2026-31431_CopyFail_LinuxKernel_LPE",
                    "author": "xn0kkx",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Educational rewrite of the Copy Fail PoC (CVE-2026-31431) — Linux kernel LPE via algif_aead in-place crypto + splice() page-cache write",
                    "summary": "Educational rewrite of the Copy Fail PoC (CVE-2026-31431) — Linux kernel LPE via algif_aead in-place crypto + splice() page-cache write",
                    "url": "https://github.com/xn0kkx/CVE-2026-31431_CopyFail_LinuxKernel_LPE"
                },
                {
                    "repository": "PoC-in-GitHub · MetaspIoit/CVE-2026-31431",
                    "author": "MetaspIoit",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "\"Copy Fail\" privilege escalation",
                    "summary": "\"Copy Fail\" privilege escalation",
                    "url": "https://github.com/MetaspIoit/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · kvendler/BigFix-CopyFail-AlmaLinux-Content",
                    "author": "kvendler",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository contains BigFix Content that I created for identifying the AlmaLinux systems that require patching to remediate CVE-2026-31431",
                    "summary": "This repository contains BigFix Content that I created for identifying the AlmaLinux systems that require patching to remediate CVE-2026-31431",
                    "url": "https://github.com/kvendler/BigFix-CopyFail-AlmaLinux-Content"
                },
                {
                    "repository": "PoC-in-GitHub · chavezvic/CopyFail-Penguin",
                    "author": "chavezvic",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A safe Linux checker for CopyFail/CVE-2026-31431 that reviews kernel version, update status, reboot status, and algif_aead exposure indicators.",
                    "summary": "A safe Linux checker for CopyFail/CVE-2026-31431 that reviews kernel version, update status, reboot status, and algif_aead exposure indicators.",
                    "url": "https://github.com/chavezvic/CopyFail-Penguin"
                },
                {
                    "repository": "PoC-in-GitHub · samanzamani/copy-fail-checker",
                    "author": "samanzamani",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Read-only Bash checker for the Copy Fail Linux kernel vulnerability (CVE-2026-31431)",
                    "summary": "Read-only Bash checker for the Copy Fail Linux kernel vulnerability (CVE-2026-31431)",
                    "url": "https://github.com/samanzamani/copy-fail-checker"
                },
                {
                    "repository": "PoC-in-GitHub · ochebotar/copy-fail-CVE-2026-31431-detection-probe",
                    "author": "ochebotar",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "Safe detection tooling for CVE-2026-31431 \"Copy Fail\" and CVE-2026-43284 \"Dirty Frag\" — a local privilege escalation in the Linux kernel's algif_aead module affecting all major distributions since 2017.",
                    "summary": "Safe detection tooling for CVE-2026-31431 \"Copy Fail\" and CVE-2026-43284 \"Dirty Frag\" — a local privilege escalation in the Linux kernel's algif_aead module affecting all major distributions since 2017.",
                    "url": "https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe"
                },
                {
                    "repository": "PoC-in-GitHub · g1nt0n1x/copy-fail-CVE-2026-31431-shell",
                    "author": "g1nt0n1x",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "PoC shell exploit for CVE-2026-31431 (copy_fail) — Linux LPE via AF_ALG + splice page-cache overwrite. Single-shot, no race condition, kernel 4.9–6.18.",
                    "summary": "PoC shell exploit for CVE-2026-31431 (copy_fail) — Linux LPE via AF_ALG + splice page-cache overwrite. Single-shot, no race condition, kernel 4.9–6.18.",
                    "url": "https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell"
                },
                {
                    "repository": "PoC-in-GitHub · Qengineering/RK35xx-CopyFail-Hotfix",
                    "author": "Qengineering",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "RK35xx CopyFail Hotfix: CVE-2026-31431 Patch for Ubuntu 24.04",
                    "summary": "RK35xx CopyFail Hotfix: CVE-2026-31431 Patch for Ubuntu 24.04",
                    "url": "https://github.com/Qengineering/RK35xx-CopyFail-Hotfix"
                },
                {
                    "repository": "PoC-in-GitHub · ShahaB108/CVE-2026-31431_Kernel_Checker",
                    "author": "ShahaB108",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "checking if kernel is VULNERABLE",
                    "summary": "checking if kernel is VULNERABLE",
                    "url": "https://github.com/ShahaB108/CVE-2026-31431_Kernel_Checker"
                },
                {
                    "repository": "PoC-in-GitHub · vasyapokemon/cve-2026-31431",
                    "author": "vasyapokemon",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 Copy Fail: Linux kernel algif_aead LPE — research, detection tooling, YARA rules, and patching guide",
                    "summary": "CVE-2026-31431 Copy Fail: Linux kernel algif_aead LPE — research, detection tooling, YARA rules, and patching guide",
                    "url": "https://github.com/vasyapokemon/cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Mrhudson69/cve-2026-31431",
                    "author": "Mrhudson69",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/Mrhudson69/cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · net0bsd/Mitigaciones",
                    "author": "net0bsd",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Mitigacion del CVE-2026-31431 BASH",
                    "summary": "Mitigacion del CVE-2026-31431 BASH",
                    "url": "https://github.com/net0bsd/Mitigaciones"
                },
                {
                    "repository": "PoC-in-GitHub · imkk000/play-go-copy-fail-cve-2026-31431",
                    "author": "imkk000",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/imkk000/play-go-copy-fail-cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · alvaroguzmancode/CVE-2026-31431-mitigacion",
                    "author": "alvaroguzmancode",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Explicación de la vulnerabilidad y cómo mitigarla",
                    "summary": "Explicación de la vulnerabilidad y cómo mitigarla",
                    "url": "https://github.com/alvaroguzmancode/CVE-2026-31431-mitigacion"
                },
                {
                    "repository": "PoC-in-GitHub · AdityaBhatt3010/CVE-2026-31431",
                    "author": "AdityaBhatt3010",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Linux Privilege Escalation | AF_ALG Crypto Abuse → Exploiting AEAD socket handling (CVE-2026-31431) to gain root via kernel-level manipulation",
                    "summary": "Linux Privilege Escalation | AF_ALG Crypto Abuse → Exploiting AEAD socket handling (CVE-2026-31431) to gain root via kernel-level manipulation",
                    "url": "https://github.com/AdityaBhatt3010/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · jshDevs/CVE_kernellinux_jsh",
                    "author": "jshDevs",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Framework modular Bash para auditar CVE-2026-31431 (CopyFail) y CVEs relacionados del kernel Linux en distros RPM-based (AlmaLinux, Rocky, CentOS Stream 8/9/10)",
                    "summary": "Framework modular Bash para auditar CVE-2026-31431 (CopyFail) y CVEs relacionados del kernel Linux en distros RPM-based (AlmaLinux, Rocky, CentOS Stream 8/9/10)",
                    "url": "https://github.com/jshDevs/CVE_kernellinux_jsh"
                },
                {
                    "repository": "PoC-in-GitHub · KhaosFarbauti/CVE-2026-31431",
                    "author": "KhaosFarbauti",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC for CVE-2026-31431 (Copy Fail)",
                    "summary": "PoC for CVE-2026-31431 (Copy Fail)",
                    "url": "https://github.com/KhaosFarbauti/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · rippsec/CVE-2026-31431-Copy-Fail",
                    "author": "rippsec",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/rippsec/CVE-2026-31431-Copy-Fail"
                },
                {
                    "repository": "PoC-in-GitHub · Silent4Labs/check-copyfail-cve-2026-31431",
                    "author": "Silent4Labs",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "It’s a read-only Linux risk assessment script for CVE-2026-31431 (\"Copy Fail\").",
                    "summary": "It’s a read-only Linux risk assessment script for CVE-2026-31431 (\"Copy Fail\").",
                    "url": "https://github.com/Silent4Labs/check-copyfail-cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · deadRabbit92/mitigate-copy-fail.yml",
                    "author": "deadRabbit92",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Mitigates CVE-2026-31431 (Copy Fail) by unloading and blacklisting algif_aead kernel module if it is loadable and has no active references.",
                    "summary": "Mitigates CVE-2026-31431 (Copy Fail) by unloading and blacklisting algif_aead kernel module if it is loadable and has no active references.",
                    "url": "https://github.com/deadRabbit92/mitigate-copy-fail.yml"
                },
                {
                    "repository": "PoC-in-GitHub · sudoytang/copyfail-arm64",
                    "author": "sudoytang",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Analysis and ARM64 reproduction of Copy Fail (CVE-2026-31431)",
                    "summary": "Analysis and ARM64 reproduction of Copy Fail (CVE-2026-31431)",
                    "url": "https://github.com/sudoytang/copyfail-arm64"
                },
                {
                    "repository": "PoC-in-GitHub · MrMixies/Copy-Fail---CVE-2026-31431",
                    "author": "MrMixies",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Script Python pour verifier si un systeme Linux est vulnerable a la faille CVE-2026-31431 (Copy Fail), une elevation de privileges locale dans le noyau Linux.",
                    "summary": "Script Python pour verifier si un systeme Linux est vulnerable a la faille CVE-2026-31431 (Copy Fail), une elevation de privileges locale dans le noyau Linux.",
                    "url": "https://github.com/MrMixies/Copy-Fail---CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Industri4l-H3ll-Xpl0it3rs/CVE-2026-31431-Copy-Fail",
                    "author": "Industri4l-H3ll-Xpl0it3rs",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 Exploit | by infrar3d",
                    "summary": "CVE-2026-31431 Exploit | by infrar3d",
                    "url": "https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-31431-Copy-Fail"
                },
                {
                    "repository": "PoC-in-GitHub · Rat5ak/CVE-2026-31431-CopyFail-static-ELF--POC",
                    "author": "Rat5ak",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "587-byte x86_64 LPE for CVE-2026-31431",
                    "summary": "587-byte x86_64 LPE for CVE-2026-31431",
                    "url": "https://github.com/Rat5ak/CVE-2026-31431-CopyFail-static-ELF--POC"
                },
                {
                    "repository": "PoC-in-GitHub · zhanghangorg/cve-2026-31431",
                    "author": "zhanghangorg",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/zhanghangorg/cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · itsystem/afalg-check",
                    "author": "itsystem",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Утилита для Linux, которая проверяет доступность `AF_ALG`/`algif_aead` и помогает оценить риск по `CVE-2026-31431`.",
                    "summary": "Утилита для Linux, которая проверяет доступность `AF_ALG`/`algif_aead` и помогает оценить риск по `CVE-2026-31431`.",
                    "url": "https://github.com/itsystem/afalg-check"
                },
                {
                    "repository": "PoC-in-GitHub · Detect-DefenseLab/CVE-2026-31431-detection-defense",
                    "author": "Detect-DefenseLab",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431: Detection & Defense Against io_uring Bypass of Existing Detection",
                    "summary": "CVE-2026-31431: Detection & Defense Against io_uring Bypass of Existing Detection",
                    "url": "https://github.com/Detect-DefenseLab/CVE-2026-31431-detection-defense"
                },
                {
                    "repository": "PoC-in-GitHub · ozergoker/CVE-2026-31431-copy-fail",
                    "author": "ozergoker",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "32-byte Python script roots every Linux distribution",
                    "summary": "32-byte Python script roots every Linux distribution",
                    "url": "https://github.com/ozergoker/CVE-2026-31431-copy-fail"
                },
                {
                    "repository": "PoC-in-GitHub · Raptoratack/CopyFail-Scanner-CVE-2026-31431",
                    "author": "Raptoratack",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/Raptoratack/CopyFail-Scanner-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · devtint/CVE-2026-31431",
                    "author": "devtint",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "https://devtint.github.io/CVE-2026-31431",
                    "summary": "https://devtint.github.io/CVE-2026-31431",
                    "url": "https://github.com/devtint/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · mrmtwoj/ubuntu-cve-2026-31431-mitigation",
                    "author": "mrmtwoj",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "دستورالعمل‌های کاهش ریسک و به‌روزرسانی برای CVE-2026-31431 در سیستم‌های اوبونتو، شامل مراحل ارتقاء کرنل و kmod.",
                    "summary": "دستورالعمل‌های کاهش ریسک و به‌روزرسانی برای CVE-2026-31431 در سیستم‌های اوبونتو، شامل مراحل ارتقاء کرنل و kmod.",
                    "url": "https://github.com/mrmtwoj/ubuntu-cve-2026-31431-mitigation"
                },
                {
                    "repository": "PoC-in-GitHub · RazvanDuda/GhostShell",
                    "author": "RazvanDuda",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 — Local Privilege Escalation via Linux Kernel Page Cache Corruption",
                    "summary": "CVE-2026-31431 — Local Privilege Escalation via Linux Kernel Page Cache Corruption",
                    "url": "https://github.com/RazvanDuda/GhostShell"
                },
                {
                    "repository": "PoC-in-GitHub · darioomatos/cve-2026-31431-copyfail",
                    "author": "darioomatos",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431 Copy Fail - LPE no kernel Linux",
                    "summary": "CVE-2026-31431 Copy Fail - LPE no kernel Linux",
                    "url": "https://github.com/darioomatos/cve-2026-31431-copyfail"
                },
                {
                    "repository": "PoC-in-GitHub · sgkdev/page_inject",
                    "author": "sgkdev",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 76,
                    "title": "CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer",
                    "summary": "CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer",
                    "url": "https://github.com/sgkdev/page_inject"
                },
                {
                    "repository": "PoC-in-GitHub · OneDemobird/copy-fail-CVE-2026-31431-pythonlower3.10",
                    "author": "OneDemobird",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "python3.10以下没有os.splice，搞了一个3.10以下版本也可以用的",
                    "summary": "python3.10以下没有os.splice，搞了一个3.10以下版本也可以用的",
                    "url": "https://github.com/OneDemobird/copy-fail-CVE-2026-31431-pythonlower3.10"
                },
                {
                    "repository": "PoC-in-GitHub · reubensammut/CVE-2026-31431-Copy-Fail",
                    "author": "reubensammut",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "My C rewrite of the Copy Fail exploit",
                    "summary": "My C rewrite of the Copy Fail exploit",
                    "url": "https://github.com/reubensammut/CVE-2026-31431-Copy-Fail"
                },
                {
                    "repository": "PoC-in-GitHub · zenzue/CVE-2026-31431-Checker-Mitigator",
                    "author": "zenzue",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/zenzue/CVE-2026-31431-Checker-Mitigator"
                },
                {
                    "repository": "PoC-in-GitHub · voxcia-io/copy-fail",
                    "author": "voxcia-io",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Tutorial Completo: Como Proteger seu contra a Vulnerabilidade CopyFail (CVE-2026-31431)",
                    "summary": "Tutorial Completo: Como Proteger seu contra a Vulnerabilidade CopyFail (CVE-2026-31431)",
                    "url": "https://github.com/voxcia-io/copy-fail"
                },
                {
                    "repository": "PoC-in-GitHub · luoqianlin/copyfail-c",
                    "author": "luoqianlin",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "C implementation for researching Copy Fail (CVE-2026-31431)",
                    "summary": "C implementation for researching Copy Fail (CVE-2026-31431)",
                    "url": "https://github.com/luoqianlin/copyfail-c"
                },
                {
                    "repository": "PoC-in-GitHub · tangjie1/CVE-2026-31431-Check",
                    "author": "tangjie1",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 Copy Fail Linux kernel vulnerability detection script",
                    "summary": "CVE-2026-31431 Copy Fail Linux kernel vulnerability detection script",
                    "url": "https://github.com/tangjie1/CVE-2026-31431-Check"
                },
                {
                    "repository": "PoC-in-GitHub · 0xN7y/CVE-2026-31431",
                    "author": "0xN7y",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Logic bug in the kernel's authencesn cryptographic template that escalate privilege",
                    "summary": "Logic bug in the kernel's authencesn cryptographic template that escalate privilege",
                    "url": "https://github.com/0xN7y/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · iblamenear/CVE-2026-31431-Copy-Fail---Advanced-LPE-Proof-of-Concept---C-Rewrite",
                    "author": "iblamenear",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Copy Fail (CVE-2026-31431) is a logic bug in the Linux kernel's authencesn cryptographic template. It lets an unprivileged local user trigger a deterministic, controlled 4-byte write into the page cache of any readable file on the system.",
                    "summary": "Copy Fail (CVE-2026-31431) is a logic bug in the Linux kernel's authencesn cryptographic template. It lets an unprivileged local user trigger a deterministic, controlled 4-byte write into the page cache of any readable file on the system.",
                    "url": "https://github.com/iblamenear/CVE-2026-31431-Copy-Fail---Advanced-LPE-Proof-of-Concept---C-Rewrite"
                },
                {
                    "repository": "PoC-in-GitHub · grabesec/XCP_ng_CVE-2026-31431_tester",
                    "author": "grabesec",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Test XCP_ng 8.3 for CVE-2026-31431Vulnerability",
                    "summary": "Test XCP_ng 8.3 for CVE-2026-31431Vulnerability",
                    "url": "https://github.com/grabesec/XCP_ng_CVE-2026-31431_tester"
                },
                {
                    "repository": "PoC-in-GitHub · philfry/cve-2026-31431-ftrace",
                    "author": "philfry",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "mitigation of cve-2026-31431 using ftrace",
                    "summary": "mitigation of cve-2026-31431 using ftrace",
                    "url": "https://github.com/philfry/cve-2026-31431-ftrace"
                },
                {
                    "repository": "PoC-in-GitHub · hans362/CVE-2026-31431-Copy-Fail-Container-Escape",
                    "author": "hans362",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Container escape on any docker container with healthcheck enabled via CVE-2026-31431",
                    "summary": "Container escape on any docker container with healthcheck enabled via CVE-2026-31431",
                    "url": "https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape"
                },
                {
                    "repository": "PoC-in-GitHub · StarxSky/CVE-2026-31431",
                    "author": "StarxSky",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "\"Copy Fail\"",
                    "summary": "\"Copy Fail\"",
                    "url": "https://github.com/StarxSky/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · pedro-lucas-melo/Estudo-de-Caso-CVE-2026-31431-CopyFail",
                    "author": "pedro-lucas-melo",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "🔐 Estudo de caso completo do CVE-2026-31431 (CopyFail) — vulnerabilidade crítica de escalada de privilégio no kernel Linux. Inclui análise técnica, scripts de verificação, hardening e playbook de resposta a incidentes. Fins educacionais.",
                    "summary": "🔐 Estudo de caso completo do CVE-2026-31431 (CopyFail) — vulnerabilidade crítica de escalada de privilégio no kernel Linux. Inclui análise técnica, scripts de verificação, hardening e playbook de resposta a incidentes. Fins educacionais.",
                    "url": "https://github.com/pedro-lucas-melo/Estudo-de-Caso-CVE-2026-31431-CopyFail"
                },
                {
                    "repository": "PoC-in-GitHub · ikow/CVE-2026-31431-live-code-corruption",
                    "author": "ikow",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 (Copy Fail) novel exploit: live code corruption via page cache. Overwrites libc exit() code through MAP_PRIVATE page sharing — affects ALL running processes.",
                    "summary": "CVE-2026-31431 (Copy Fail) novel exploit: live code corruption via page cache. Overwrites libc exit() code through MAP_PRIVATE page sharing — affects ALL running processes.",
                    "url": "https://github.com/ikow/CVE-2026-31431-live-code-corruption"
                },
                {
                    "repository": "PoC-in-GitHub · gagaltotal/cve-2026-31431-copy-fail",
                    "author": "gagaltotal",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2026-31431 Copy Fail",
                    "summary": "CVE-2026-31431 Copy Fail",
                    "url": "https://github.com/gagaltotal/cve-2026-31431-copy-fail"
                },
                {
                    "repository": "PoC-in-GitHub · Mr-bv/Copy-fail-CVE-2026-31431-Exploit-in-C",
                    "author": "Mr-bv",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Discovery and original disclosure of CVE-2026-31431: Theori / Xint. Public writeup: https://copy.fail/.",
                    "summary": "Discovery and original disclosure of CVE-2026-31431: Theori / Xint. Public writeup: https://copy.fail/.",
                    "url": "https://github.com/Mr-bv/Copy-fail-CVE-2026-31431-Exploit-in-C"
                },
                {
                    "repository": "PoC-in-GitHub · 0xer0/CVE-2026-31431-Copy-Fail-add-arm64",
                    "author": "0xer0",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2026-31431 漏洞利用python脚本，支持arm64,x86架构",
                    "summary": "CVE-2026-31431 漏洞利用python脚本，支持arm64,x86架构",
                    "url": "https://github.com/0xer0/CVE-2026-31431-Copy-Fail-add-arm64"
                },
                {
                    "repository": "PoC-in-GitHub · 361way/CVE-2026-31431",
                    "author": "361way",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431检测和测试",
                    "summary": "CVE-2026-31431检测和测试",
                    "url": "https://github.com/361way/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · adilkurtulmus/linux-copy-fail-CVE-2026-31431",
                    "author": "adilkurtulmus",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/adilkurtulmus/linux-copy-fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Vatson112/deny-af-alg-bpf",
                    "author": "Vatson112",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "BPF prog to fix CVE-2026-31431",
                    "summary": "BPF prog to fix CVE-2026-31431",
                    "url": "https://github.com/Vatson112/deny-af-alg-bpf"
                },
                {
                    "repository": "PoC-in-GitHub · kwilck/copyfail",
                    "author": "kwilck",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Copy Fail (CVE-2026-31431) is a logic flaw in the Linux kernel's algif_aead module — part of the AF_ALG userspace crypto API. It was disclosed on April 29, 2026 by Theori / Xint Code.",
                    "summary": "Copy Fail (CVE-2026-31431) is a logic flaw in the Linux kernel's algif_aead module — part of the AF_ALG userspace crypto API. It was disclosed on April 29, 2026 by Theori / Xint Code.",
                    "url": "https://github.com/kwilck/copyfail"
                },
                {
                    "repository": "PoC-in-GitHub · pvpaulo01/cve-2026-31431",
                    "author": "pvpaulo01",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Esse documento descreve o Exploit publico em python",
                    "summary": "Esse documento descreve o Exploit publico em python",
                    "url": "https://github.com/pvpaulo01/cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · tang-yikai/copy-fail-mitigation-with-bpftrace",
                    "author": "tang-yikai",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431, AKA Copy Fail, can be mitigated in one-line with bpftrace",
                    "summary": "CVE-2026-31431, AKA Copy Fail, can be mitigated in one-line with bpftrace",
                    "url": "https://github.com/tang-yikai/copy-fail-mitigation-with-bpftrace"
                },
                {
                    "repository": "PoC-in-GitHub · abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix",
                    "author": "abdelkabirouadoukou",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Technical deep dive, root cause analysis, and LKML patch workflow for CVE-2026-31431 (Linux kernel local privilege escalation in algif_aead).",
                    "summary": "Technical deep dive, root cause analysis, and LKML patch workflow for CVE-2026-31431 (Linux kernel local privilege escalation in algif_aead).",
                    "url": "https://github.com/abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix"
                },
                {
                    "repository": "PoC-in-GitHub · julichaan/CVE-2026-31431-python-copyfail-POC",
                    "author": "julichaan",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/julichaan/CVE-2026-31431-python-copyfail-POC"
                },
                {
                    "repository": "PoC-in-GitHub · guiimoraes/CVE-2026-31431",
                    "author": "guiimoraes",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "One-liner Python LPE for CVE-2026-31431 (CopyFail2). No compilation, no dependencies beyond Python+OpenSSL. Just curl | python3 and get root on Linux 6.5+.",
                    "summary": "One-liner Python LPE for CVE-2026-31431 (CopyFail2). No compilation, no dependencies beyond Python+OpenSSL. Just curl | python3 and get root on Linux 6.5+.",
                    "url": "https://github.com/guiimoraes/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Morton-Li/copy-fail-CVE-2026-31431",
                    "author": "Morton-Li",
                    "first_seen": "2026-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/Morton-Li/copy-fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · OpenPixelSystems/c-copy-fail",
                    "author": "OpenPixelSystems",
                    "first_seen": "2026-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431 in C for aarch64 and amd64",
                    "summary": "CVE-2026-31431 in C for aarch64 and amd64",
                    "url": "https://github.com/OpenPixelSystems/c-copy-fail"
                },
                {
                    "repository": "PoC-in-GitHub · p401a-ops/Copy-Fail",
                    "author": "p401a-ops",
                    "first_seen": "2026-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 (\"Copy Fail\") vulnerability detector & exploit on Astra linux 1.7.6 with 3.7+ python",
                    "summary": "CVE-2026-31431 (\"Copy Fail\") vulnerability detector & exploit on Astra linux 1.7.6 with 3.7+ python",
                    "url": "https://github.com/p401a-ops/Copy-Fail"
                },
                {
                    "repository": "PoC-in-GitHub · infiniroot/ansible-mitigate-copyfail-dirtyfrag",
                    "author": "infiniroot",
                    "first_seen": "2026-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Simple Ansible Playbook to mitigate against CopyFail (CVE-2026-31431) and DirtyFrag (CVE-2026-43284) vulnerabilities.",
                    "summary": "Simple Ansible Playbook to mitigate against CopyFail (CVE-2026-31431) and DirtyFrag (CVE-2026-43284) vulnerabilities.",
                    "url": "https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag"
                },
                {
                    "repository": "PoC-in-GitHub · KaraZajac/DIRTYFAIL",
                    "author": "KaraZajac",
                    "first_seen": "2026-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 29,
                    "title": "Detector + PoC for Linux page-cache write vulnerabilities: Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284/43500). Authorized security research only.",
                    "summary": "Detector + PoC for Linux page-cache write vulnerabilities: Copy Fail (CVE-2026-31431) and Dirty Frag (CVE-2026-43284/43500). Authorized security research only.",
                    "url": "https://github.com/KaraZajac/DIRTYFAIL"
                },
                {
                    "repository": "PoC-in-GitHub · ROSNLR5/MitigationToolkit-ROSN-LR5-Full",
                    "author": "ROSNLR5",
                    "first_seen": "2026-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Kernel LPE PoC & Mitigation Toolkit - ROSN-LR5-Full (CVE-2026-31431)",
                    "summary": "Kernel LPE PoC & Mitigation Toolkit - ROSN-LR5-Full (CVE-2026-31431)",
                    "url": "https://github.com/ROSNLR5/MitigationToolkit-ROSN-LR5-Full"
                },
                {
                    "repository": "PoC-in-GitHub · hori0729/CVE-2026-31431-Verificador-Exploit",
                    "author": "hori0729",
                    "first_seen": "2026-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Linux Kernel Local Privilege Escalation",
                    "summary": "Linux Kernel Local Privilege Escalation",
                    "url": "https://github.com/hori0729/CVE-2026-31431-Verificador-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · krisiasty/vcheck",
                    "author": "krisiasty",
                    "first_seen": "2026-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Vulnerability detection and mitigation tool for Copy Fail and Dirty Frag bugs (CVE-2026-31431, CVE-2026-43284, CVE-2026-43500)",
                    "summary": "Vulnerability detection and mitigation tool for Copy Fail and Dirty Frag bugs (CVE-2026-31431, CVE-2026-43284, CVE-2026-43500)",
                    "url": "https://github.com/krisiasty/vcheck"
                },
                {
                    "repository": "PoC-in-GitHub · vorkampfer/copy_fail_mitigation",
                    "author": "vorkampfer",
                    "first_seen": "2026-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This script will attempt to mitigate the copy_fail attack. CVE-2026-31431",
                    "summary": "This script will attempt to mitigate the copy_fail attack. CVE-2026-31431",
                    "url": "https://github.com/vorkampfer/copy_fail_mitigation"
                },
                {
                    "repository": "PoC-in-GitHub · Hunt-Benito/copy-fail-cve-2026-31431-linux-kernel-page-cache-lpe",
                    "author": "Hunt-Benito",
                    "first_seen": "2026-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/Hunt-Benito/copy-fail-cve-2026-31431-linux-kernel-page-cache-lpe"
                },
                {
                    "repository": "PoC-in-GitHub · Helios973/CVE-2026-31431_exp.c",
                    "author": "Helios973",
                    "first_seen": "2026-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/Helios973/CVE-2026-31431_exp.c"
                },
                {
                    "repository": "PoC-in-GitHub · haydenjames/CVE-2026-31431-check",
                    "author": "haydenjames",
                    "first_seen": "2026-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Read-only checker for CVE-2026-31431 (algif_aead local root). Reports kernel/module state and suggests mitigations.",
                    "summary": "Read-only checker for CVE-2026-31431 (algif_aead local root). Reports kernel/module state and suggests mitigations.",
                    "url": "https://github.com/haydenjames/CVE-2026-31431-check"
                },
                {
                    "repository": "PoC-in-GitHub · cleozi/Copy_Grail",
                    "author": "cleozi",
                    "first_seen": "2026-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Elegant C++ exploit for CVE-2026-31431 (Copy Fail) using AF_ALG authenticated encryption + splice(2) to overwrite setuid binary memory",
                    "summary": "Elegant C++ exploit for CVE-2026-31431 (Copy Fail) using AF_ALG authenticated encryption + splice(2) to overwrite setuid binary memory",
                    "url": "https://github.com/cleozi/Copy_Grail"
                },
                {
                    "repository": "PoC-in-GitHub · vorkampfer/copyfail2_electric_boogaloo_fix",
                    "author": "vorkampfer",
                    "first_seen": "2026-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A temporary mitigation against copy_fail variant (copyfail2_electric_boogaloo) - Unprivileged Linux LPE via xfrm ESP-in-UDP MSG_SPLICE_PAGES no-COW fast path. Page-cache write into any readable file. Overwrites a nologin line in /etc/passwd with sick::0:0:…:/:/bin/bash and sus into it. Same class as Copy Fail (CVE-2026-31431), different subsystem.",
                    "summary": "A temporary mitigation against copy_fail variant (copyfail2_electric_boogaloo) - Unprivileged Linux LPE via xfrm ESP-in-UDP MSG_SPLICE_PAGES no-COW fast path. Page-cache write into any readable file. Overwrites a nologin line in /etc/passwd with sick::0:0:…:/:/bin/bash and sus into it. Same class as Copy Fail (CVE-2026-31431), different subsystem.",
                    "url": "https://github.com/vorkampfer/copyfail2_electric_boogaloo_fix"
                },
                {
                    "repository": "PoC-in-GitHub · AdemZero/CVE-2026-31431",
                    "author": "AdemZero",
                    "first_seen": "2026-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Educational Proof of Concept for CVE-2026-31431 / Copy Fail Linux local privilege escalation via AF_ALG algif_aead",
                    "summary": "Educational Proof of Concept for CVE-2026-31431 / Copy Fail Linux local privilege escalation via AF_ALG algif_aead",
                    "url": "https://github.com/AdemZero/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Lutfifakee-Project/CVE-2026-31431",
                    "author": "Lutfifakee-Project",
                    "first_seen": "2026-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-31431 - Linux Kernel Page Cache Vulnerability",
                    "summary": "CVE-2026-31431 - Linux Kernel Page Cache Vulnerability",
                    "url": "https://github.com/Lutfifakee-Project/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · u1tr0nex/CVE-2026-31431-CopyFail-Lab",
                    "author": "u1tr0nex",
                    "first_seen": "2026-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Lab testing documentation for CVE-2026-31431 (Copy Fail) Linux kernel LPE",
                    "summary": "Lab testing documentation for CVE-2026-31431 (Copy Fail) Linux kernel LPE",
                    "url": "https://github.com/u1tr0nex/CVE-2026-31431-CopyFail-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · mauricioportela/CVE-2026-31431-Analysis",
                    "author": "mauricioportela",
                    "first_seen": "2026-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Relatório de Análise Técnica: Exploração de Falha de Isolamento no Kernel Linux (CVE-2026-31431)",
                    "summary": "Relatório de Análise Técnica: Exploração de Falha de Isolamento no Kernel Linux (CVE-2026-31431)",
                    "url": "https://github.com/mauricioportela/CVE-2026-31431-Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · dgrobinson0/CopyFile_CVE-2026-31431",
                    "author": "dgrobinson0",
                    "first_seen": "2026-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Exploit for CVE-2026-31431 (Copy Fail)",
                    "summary": "Exploit for CVE-2026-31431 (Copy Fail)",
                    "url": "https://github.com/dgrobinson0/CopyFile_CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · polyakovavv/copyfail",
                    "author": "polyakovavv",
                    "first_seen": "2026-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Copy Fail (CVE-2026-31431)",
                    "summary": "Copy Fail (CVE-2026-31431)",
                    "url": "https://github.com/polyakovavv/copyfail"
                },
                {
                    "repository": "PoC-in-GitHub · gbonacini/CVE-2026-31431",
                    "author": "gbonacini",
                    "first_seen": "2026-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A CVE-2026-31431 implementation in c++ and inline assembly dependency free",
                    "summary": "A CVE-2026-31431 implementation in c++ and inline assembly dependency free",
                    "url": "https://github.com/gbonacini/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · studiogangster/CVE-2026-31431",
                    "author": "studiogangster",
                    "first_seen": "2026-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "oen liner CVE-2026-31431 test. Created 'sandbox' on sudo user and tests if ir can escape to root",
                    "summary": "oen liner CVE-2026-31431 test. Created 'sandbox' on sudo user and tests if ir can escape to root",
                    "url": "https://github.com/studiogangster/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · paulorlima9/copyfail-fix",
                    "author": "paulorlima9",
                    "first_seen": "2026-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Quick mitigation and patch script for CVE-2026-31431 (Copy Fail) on Ubuntu/Debian VPS",
                    "summary": "Quick mitigation and patch script for CVE-2026-31431 (Copy Fail) on Ubuntu/Debian VPS",
                    "url": "https://github.com/paulorlima9/copyfail-fix"
                },
                {
                    "repository": "PoC-in-GitHub · sh4den/CVE-2026-31431-copyfail-aarch64",
                    "author": "sh4den",
                    "first_seen": "2026-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/sh4den/CVE-2026-31431-copyfail-aarch64"
                },
                {
                    "repository": "PoC-in-GitHub · DroPZsec/SplicePrivillegeEscalationFIX",
                    "author": "DroPZsec",
                    "first_seen": "2026-05-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "this little script blocks the new splice-ram-privlilleg ecalation fastly befor the contributers do it ( CVE-2026-31431)  (CopyFail fix)",
                    "summary": "this little script blocks the new splice-ram-privlilleg ecalation fastly befor the contributers do it ( CVE-2026-31431)  (CopyFail fix)",
                    "url": "https://github.com/DroPZsec/SplicePrivillegeEscalationFIX"
                },
                {
                    "repository": "PoC-in-GitHub · kuniyal08/Copy-Fail-CVE-2026-31431-Lab",
                    "author": "kuniyal08",
                    "first_seen": "2026-05-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Reproduced the fileless LPE CVE‑2026‑31431 (“Copy Fail”) on Kali Linux, then built auditd, Sigma & YARA detections to catch this stealthy kernel exploit that leaves no disk footprint.",
                    "summary": "Reproduced the fileless LPE CVE‑2026‑31431 (“Copy Fail”) on Kali Linux, then built auditd, Sigma & YARA detections to catch this stealthy kernel exploit that leaves no disk footprint.",
                    "url": "https://github.com/kuniyal08/Copy-Fail-CVE-2026-31431-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · SilverRuler/copy-fail-CVE-2026-31431",
                    "author": "SilverRuler",
                    "first_seen": "2026-05-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "copy-fail-CVE-2026-31431",
                    "summary": "copy-fail-CVE-2026-31431",
                    "url": "https://github.com/SilverRuler/copy-fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Sebastian294/cve-2026-31431",
                    "author": "Sebastian294",
                    "first_seen": "2026-05-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Analísis - POC - Mitigación",
                    "summary": "Analísis - POC - Mitigación",
                    "url": "https://github.com/Sebastian294/cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · 0xFuffM3/CVE-2026-31431-CopyFail",
                    "author": "0xFuffM3",
                    "first_seen": "2026-05-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/0xFuffM3/CVE-2026-31431-CopyFail"
                },
                {
                    "repository": "PoC-in-GitHub · dotPY-hax/CopyFail",
                    "author": "dotPY-hax",
                    "first_seen": "2026-05-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A CopyFail CVE-2026-31431 implementation in python that isnt slop! Bring your own payload",
                    "summary": "A CopyFail CVE-2026-31431 implementation in python that isnt slop! Bring your own payload",
                    "url": "https://github.com/dotPY-hax/CopyFail"
                },
                {
                    "repository": "PoC-in-GitHub · zKaaanon/ProyectoFinalSO",
                    "author": "zKaaanon",
                    "first_seen": "2026-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Estudio del bug CVE-2026-31431",
                    "summary": "Estudio del bug CVE-2026-31431",
                    "url": "https://github.com/zKaaanon/ProyectoFinalSO"
                },
                {
                    "repository": "PoC-in-GitHub · adityasingh108/CVE-2026-31431-Metasploit-exploit",
                    "author": "adityasingh108",
                    "first_seen": "2026-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Automated Metasploit post-exploitation module for CVE-2026-31431 (\"Copy Fail\"). Weaponizes a deterministic logic flaw in the Linux kernel AF_ALG subsystem to achieve local privilege escalation (LPE) to root by safely corrupting a setuid binary directly in the shared Page Cache (RAM) without modifying files on disk",
                    "summary": "Automated Metasploit post-exploitation module for CVE-2026-31431 (\"Copy Fail\"). Weaponizes a deterministic logic flaw in the Linux kernel AF_ALG subsystem to achieve local privilege escalation (LPE) to root by safely corrupting a setuid binary directly in the shared Page Cache (RAM) without modifying files on disk",
                    "url": "https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Maxime288/CVE-2026-31431-Copy-Fail-R-pertoire-de-Pr-vention",
                    "author": "Maxime288",
                    "first_seen": "2026-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/Maxime288/CVE-2026-31431-Copy-Fail-R-pertoire-de-Pr-vention"
                },
                {
                    "repository": "PoC-in-GitHub · Pithase/asm-copyfail",
                    "author": "Pithase",
                    "first_seen": "2026-05-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2026-31431 (Copy Fail) — Análisis y desarrollo en Ensamblador x86-64 | Analysis and development in x86-64 Assembly",
                    "summary": "CVE-2026-31431 (Copy Fail) — Análisis y desarrollo en Ensamblador x86-64 | Analysis and development in x86-64 Assembly",
                    "url": "https://github.com/Pithase/asm-copyfail"
                },
                {
                    "repository": "PoC-in-GitHub · 4xura/CVE-2026-31431-Copy-Fail",
                    "author": "4xura",
                    "first_seen": "2026-05-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "Research artifacts, PoC scripts, and lab assets for the Copy Fail Linux local privilege escalation writeup on https://4xura.com/binex/kernel/copy-fail",
                    "summary": "Research artifacts, PoC scripts, and lab assets for the Copy Fail Linux local privilege escalation writeup on https://4xura.com/binex/kernel/copy-fail",
                    "url": "https://github.com/4xura/CVE-2026-31431-Copy-Fail"
                },
                {
                    "repository": "PoC-in-GitHub · royayub/CVE-2026-31431",
                    "author": "royayub",
                    "first_seen": "2026-05-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Local Privilege Escalation. Flips the running user's UID to 0 in /etc/passwd's page cache, then invokes su for a root shell.",
                    "summary": "Local Privilege Escalation. Flips the running user's UID to 0 in /etc/passwd's page cache, then invokes su for a root shell.",
                    "url": "https://github.com/royayub/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · Yakovyakov/cve-2026-31431-mitigation",
                    "author": "Yakovyakov",
                    "first_seen": "2026-05-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Detection and mitigation tooling for CVE-2026-31431 (Copy Fail) on Linux kernels. Includes Phalanx-CCS and Silent4Labs scripts plus an Ansible playbook to apply temporary mitigation (block algif_aead module or boot parameter) across servers.",
                    "summary": "Detection and mitigation tooling for CVE-2026-31431 (Copy Fail) on Linux kernels. Includes Phalanx-CCS and Silent4Labs scripts plus an Ansible playbook to apply temporary mitigation (block algif_aead module or boot parameter) across servers.",
                    "url": "https://github.com/Yakovyakov/cve-2026-31431-mitigation"
                },
                {
                    "repository": "PoC-in-GitHub · cj667113/OCI-Ansible-Fix-CVE-2026-31431",
                    "author": "cj667113",
                    "first_seen": "2026-05-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/cj667113/OCI-Ansible-Fix-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · GubiczaP/cve-2026-31431-checker",
                    "author": "GubiczaP",
                    "first_seen": "2026-05-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Shell scanner for CVE-2026-31431 \"Copy Fail\" — a local privilege escalation via Linux kernel page cache corruption (algif_aead/AF_ALG). Checks kernel version, patch status, module state, setuid exposure and mitigations. Supports Debian 11–13 and Ubuntu 20.04–25.10. CI/CD-ready (exit codes + JSON output).",
                    "summary": "Shell scanner for CVE-2026-31431 \"Copy Fail\" — a local privilege escalation via Linux kernel page cache corruption (algif_aead/AF_ALG). Checks kernel version, patch status, module state, setuid exposure and mitigations. Supports Debian 11–13 and Ubuntu 20.04–25.10. CI/CD-ready (exit codes + JSON output).",
                    "url": "https://github.com/GubiczaP/cve-2026-31431-checker"
                },
                {
                    "repository": "PoC-in-GitHub · sgkdev/ptrace_may_dream",
                    "author": "sgkdev",
                    "first_seen": "2026-05-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 21,
                    "title": "CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer",
                    "summary": "CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer",
                    "url": "https://github.com/sgkdev/ptrace_may_dream"
                },
                {
                    "repository": "PoC-in-GitHub · yangh-beep/CVE-2026-31431-C",
                    "author": "yangh-beep",
                    "first_seen": "2026-05-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/yangh-beep/CVE-2026-31431-C"
                },
                {
                    "repository": "PoC-in-GitHub · JimmyPughtron/CVE-2026-31431-Copy-Fail---Minified-LPE-PoC",
                    "author": "JimmyPughtron",
                    "first_seen": "2026-05-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431-CopyFail---Minified-LPE-PoC",
                    "summary": "CVE-2026-31431-CopyFail---Minified-LPE-PoC",
                    "url": "https://github.com/JimmyPughtron/CVE-2026-31431-Copy-Fail---Minified-LPE-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · 4n4s4zi/copyfail-alpine",
                    "author": "4n4s4zi",
                    "first_seen": "2026-05-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "More portable PoC of copyfail LPE (CVE-2026-31431) that works on Alpine Linux",
                    "summary": "More portable PoC of copyfail LPE (CVE-2026-31431) that works on Alpine Linux",
                    "url": "https://github.com/4n4s4zi/copyfail-alpine"
                },
                {
                    "repository": "PoC-in-GitHub · 1m1ssher/copy-fail-python",
                    "author": "1m1ssher",
                    "first_seen": "2026-05-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Zero-dependency Python PoC for CVE-2026-31431, Linux kernel LPE via AF_ALG/splice page-cache corruption.",
                    "summary": "Zero-dependency Python PoC for CVE-2026-31431, Linux kernel LPE via AF_ALG/splice page-cache corruption.",
                    "url": "https://github.com/1m1ssher/copy-fail-python"
                },
                {
                    "repository": "PoC-in-GitHub · ridhinva/linux-kernel-algif-aead-checker",
                    "author": "ridhinva",
                    "first_seen": "2026-05-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Scanner: CVE-2026-31431 Linux kernel algif_aead Copy Fail vulnerability checker — Python PoC for heap overflow path",
                    "summary": "Scanner: CVE-2026-31431 Linux kernel algif_aead Copy Fail vulnerability checker — Python PoC for heap overflow path",
                    "url": "https://github.com/ridhinva/linux-kernel-algif-aead-checker"
                },
                {
                    "repository": "PoC-in-GitHub · Iamliuxiaozhen/copy_fail",
                    "author": "Iamliuxiaozhen",
                    "first_seen": "2026-05-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "copy_fail:CVE-2026-31431",
                    "summary": "copy_fail:CVE-2026-31431",
                    "url": "https://github.com/Iamliuxiaozhen/copy_fail"
                },
                {
                    "repository": "PoC-in-GitHub · songzzzz/CVE-2026-31431",
                    "author": "songzzzz",
                    "first_seen": "2026-05-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "aarch64 and x64 python POC",
                    "summary": "aarch64 and x64 python POC",
                    "url": "https://github.com/songzzzz/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · vishvacyber/Detection-Tool-Kit-for-CVE-2026-31431",
                    "author": "vishvacyber",
                    "first_seen": "2026-05-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/vishvacyber/Detection-Tool-Kit-for-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · nonameuserosint-hue/Copyfail-sh",
                    "author": "nonameuserosint-hue",
                    "first_seen": "2026-06-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A Bash implementation of copyfail (CVE-2026-31431)",
                    "summary": "A Bash implementation of copyfail (CVE-2026-31431)",
                    "url": "https://github.com/nonameuserosint-hue/Copyfail-sh"
                },
                {
                    "repository": "PoC-in-GitHub · tematemaru/CVE-2026-31431-simple-test",
                    "author": "tematemaru",
                    "first_seen": "2026-06-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/tematemaru/CVE-2026-31431-simple-test"
                },
                {
                    "repository": "PoC-in-GitHub · 1neptune/CopyFail",
                    "author": "1neptune",
                    "first_seen": "2026-06-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "go CVE-2026-31431 (CopyFail) local privilege escalation exploit",
                    "summary": "go CVE-2026-31431 (CopyFail) local privilege escalation exploit",
                    "url": "https://github.com/1neptune/CopyFail"
                },
                {
                    "repository": "PoC-in-GitHub · zs1n/copy-fail-CVE-2026-31431",
                    "author": "zs1n",
                    "first_seen": "2026-06-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit for Copy-Fail Vulnerability - Python3 Version",
                    "summary": "Exploit for Copy-Fail Vulnerability - Python3 Version",
                    "url": "https://github.com/zs1n/copy-fail-CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · t1ckprivate/CVE-2026-31431-Copy-Fail",
                    "author": "t1ckprivate",
                    "first_seen": "2026-06-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/t1ckprivate/CVE-2026-31431-Copy-Fail"
                },
                {
                    "repository": "PoC-in-GitHub · kinryulabs/rootpacket-cve-2026-31431",
                    "author": "kinryulabs",
                    "first_seen": "2026-06-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2026-31431 getroot from a Turkish Cryptominer",
                    "summary": "CVE-2026-31431 getroot from a Turkish Cryptominer",
                    "url": "https://github.com/kinryulabs/rootpacket-cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · SugiB3o/CVE-2026-31431",
                    "author": "SugiB3o",
                    "first_seen": "2026-06-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/SugiB3o/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · jihwan77/Linux-Kernel-Copy-Fail-CVE-2026-31431-",
                    "author": "jihwan77",
                    "first_seen": "2026-07-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "AF_ALG/splice 기반 Linux Page Cache 변조 취약점 분석 및 대응 실습",
                    "summary": "AF_ALG/splice 기반 Linux Page Cache 변조 취약점 분석 및 대응 실습",
                    "url": "https://github.com/jihwan77/Linux-Kernel-Copy-Fail-CVE-2026-31431-"
                },
                {
                    "repository": "PoC-in-GitHub · TeamN4C/SG-2026-0013",
                    "author": "TeamN4C",
                    "first_seen": "2026-07-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 Copy Fail PoC and exploit",
                    "summary": "CVE-2026-31431 Copy Fail PoC and exploit",
                    "url": "https://github.com/TeamN4C/SG-2026-0013"
                },
                {
                    "repository": "PoC-in-GitHub · TrevoCastles/CVE-2026-31431-copy-fail",
                    "author": "TrevoCastles",
                    "first_seen": "2026-08-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/TrevoCastles/CVE-2026-31431-copy-fail"
                },
                {
                    "repository": "PoC-in-GitHub · dev1681/CVE-2026-31431",
                    "author": "dev1681",
                    "first_seen": "2026-08-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "copyfail poc here",
                    "summary": "copyfail poc here",
                    "url": "https://github.com/dev1681/CVE-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · joaocalciolari07/copyfail-guard",
                    "author": "joaocalciolari07",
                    "first_seen": "2026-08-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Defensive detection & mitigation tool for CVE-2026-31431 (\"Copy Fail\") — Linux kernel algif_aead LPE. No exploit code included.",
                    "summary": "Defensive detection & mitigation tool for CVE-2026-31431 (\"Copy Fail\") — Linux kernel algif_aead LPE. No exploit code included.",
                    "url": "https://github.com/joaocalciolari07/copyfail-guard"
                },
                {
                    "repository": "PoC-in-GitHub · FranklinF25/cve-2026-31431",
                    "author": "FranklinF25",
                    "first_seen": "2026-09-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC for CVE-2026-31431",
                    "summary": "PoC for CVE-2026-31431",
                    "url": "https://github.com/FranklinF25/cve-2026-31431"
                },
                {
                    "repository": "PoC-in-GitHub · silentbyte69/copy-fail-CVE-2026-31431-cpp",
                    "author": "silentbyte69",
                    "first_seen": "2026-09-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "https://github.com/theori-io/copy-fail-CVE-2026-31431 but ported to c++ for fun",
                    "summary": "https://github.com/theori-io/copy-fail-CVE-2026-31431 but ported to c++ for fun",
                    "url": "https://github.com/silentbyte69/copy-fail-CVE-2026-31431-cpp"
                },
                {
                    "repository": "www.openwall.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-22",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://www.openwall.com/lists/oss-security/2026/04/29/23"
                },
                {
                    "repository": "www.openwall.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-22",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://www.openwall.com/lists/oss-security/2026/04/29/26"
                },
                {
                    "repository": "www.openwall.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-22",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://www.openwall.com/lists/oss-security/2026/04/30/18"
                },
                {
                    "repository": "www.openwall.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-22",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://www.openwall.com/lists/oss-security/2026/04/30/5"
                },
                {
                    "repository": "copy.fail",
                    "author": "NVD reference",
                    "first_seen": "2026-04-22",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://copy.fail"
                },
                {
                    "repository": "websec.net",
                    "author": "NVD reference",
                    "first_seen": "2026-04-22",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://websec.net/blog/cve-2026-31431-linux-algifaead-page-cache-write-to-root-69f38a4ccddd2db1f520f170"
                },
                {
                    "repository": "xint.io",
                    "author": "NVD reference",
                    "first_seen": "2026-04-22",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://xint.io/blog/copy-fail-linux-distributions#the-fix-6"
                },
                {
                    "repository": "PoC-in-GitHub · starscow/Copy-Fail-CVE-2026-31431-Kubernetes-PoC",
                    "author": "starscow",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-31431 repository",
                    "summary": "",
                    "url": "https://github.com/starscow/Copy-Fail-CVE-2026-31431-Kubernetes-PoC"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/Liverwortenuresis371/copyfail-rs",
                "https://github.com/theori-io/copy-fail-CVE-2026-31431",
                "https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail",
                "https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized",
                "https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail",
                "https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431",
                "https://github.com/6abc/Copy-Fail-CVE-2026-31431-dirty-frag-CVE-2026-43284",
                "https://github.com/xeloxa/copyfail-exploit",
                "https://github.com/John-Popovici/CVE-2026-31431-CopyFail-Linux-PrivEsc",
                "https://github.com/Alfredooe/CVE-2026-31431",
                "https://github.com/badsectorlabs/copyfail-go",
                "https://github.com/tgies/copy-fail-c",
                "https://github.com/ZephrFish/CopyFail-CVE-2026-31431",
                "https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431",
                "https://github.com/b5null/CVE-2026-31431-C",
                "https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC",
                "https://github.com/yiyihuohuo/CVE-2026-31431",
                "https://github.com/ruattd/cve-2026-31431",
                "https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit",
                "https://github.com/luotian2/CVE-2026-31431",
                "https://github.com/insomnisec/Detections-CVE-2026-31431",
                "https://github.com/JnamerZ/CopyFail-CVE-2026-31431",
                "https://github.com/vishwanathakuthota/copy-fail-CVE-2026-31431",
                "https://github.com/desultory/CVE-2026-31431",
                "https://github.com/someCorp/copyFail-CVE-2026-31431-workaround-bash",
                "https://github.com/novysodope/copy-fail-CVE-2026-31431-C",
                "https://github.com/thrandomv/cve-2026-31431-detection",
                "https://github.com/Y5neKO/copy-fail-CVE-2026-31431-universal",
                "https://github.com/bigwario/copy-fail-CVE-2026-31431-C",
                "https://github.com/twowb/CVE-2026-31431-",
                "https://github.com/arkdev1/check-cve-2026-31431",
                "https://github.com/wuwu001/CVE-2026-31431-exploit",
                "https://github.com/ryan2929/CVE-2026-31431",
                "https://github.com/0xShe/CVE-2026-31431",
                "https://github.com/WavesMan/cve-2026-31431-fleet-remediator",
                "https://github.com/wuzuowei/copy-fail-CVE-2026-31431",
                "https://github.com/Isw-9/copy-fail-cve-2026-31431-aarch64",
                "https://github.com/st4rburn/RootRemover",
                "https://github.com/freelabz/CVE-2026-31431",
                "https://github.com/mrowkoob/copy-fail-mitigate-no-reboot",
                "https://github.com/nisec-eric/cve-2026-31431",
                "https://github.com/pascal-gujer/CVE-2026-31431",
                "https://github.com/eleveni386/CVE-2026-31431-Golang",
                "https://github.com/Linux-zs/cve-2026-31431-mitigation",
                "https://github.com/dixyes/fuck_cve_2026_31431",
                "https://github.com/kadir/copy-fail-CVE-2026-31431-IOC",
                "https://github.com/jbiniek/copy.fail-mitigation-MLM",
                "https://github.com/makitos666/CVE-2026-31431-Copy-Fail-Detection-Toolkit",
                "https://github.com/lonelyor/CVE-2026-31431-exp",
                "https://github.com/Phalanx-CCS/Copy-Fail",
                "https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH",
                "https://github.com/jiangban046-spec/CVE-2026-31431-exploit_py2_py3",
                "https://github.com/dorianhhuc/CVE-2026-31431",
                "https://github.com/0xBlackash/CVE-2026-31431",
                "https://github.com/H1d3r/copy-fail_LPE_Interactive",
                "https://github.com/amdisrar/cve-2026-31431-mitigation",
                "https://github.com/G01d3nW01f/CVE-2026-31431",
                "https://github.com/rio128128/copy-fail-CVE-2026-31431",
                "https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE",
                "https://github.com/slauger/CVE-2026-31431",
                "https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431",
                "https://github.com/gmeghnag/TEST-CVE-2026-31431",
                "https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC",
                "https://github.com/dicatalin/Copy_Fail_CVE-2026-31431_test_and_fix",
                "https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation",
                "https://github.com/mfloresdacunha/CVE-2026-31431",
                "https://github.com/Boos4721/copyfail-rs",
                "https://github.com/eximiait/CVE-2026-31431",
                "https://github.com/JuanBindez/CVE-2026-31431",
                "https://github.com/XsanFlip/CVE-2026-31431-Patch",
                "https://github.com/rshosting/CVE-2026-31431-patch",
                "https://github.com/wesmar/CVE-2026-31431",
                "https://github.com/wgnet/wg.copyfail.patch",
                "https://github.com/cs8425/copy-fail-go",
                "https://github.com/diemoeve/copyfail-rs",
                "https://github.com/yxdm02/CVE-2026-31431",
                "https://github.com/grishinpv/CVE-2026-31431-old-python",
                "https://github.com/sammwyy/copyfail-rs",
                "https://github.com/SunL0w/PATCH-CVE-2026-31431-Ubuntu_Debian",
                "https://github.com/scriptzteam/Paranoid-Copy-Fail-CVE-2026-31431",
                "https://github.com/cozystack/copy-fail-blocker",
                "https://github.com/leelong2020/cve-2026-31431",
                "https://github.com/galoryber/CVE-2026-31431-cleaned",
                "https://github.com/vynazevedo/fail-CVE-2026-31431",
                "https://github.com/MohamedKarrab/Copy-Fail-CVE-2026-31431",
                "https://github.com/w3llr00t3d/CVE-2026-31431-PoC",
                "https://github.com/sec17br/CVE-2026-31431-Copy-Fail",
                "https://github.com/mhdgning131/CopyFail-Patcher",
                "https://github.com/Xerxes-2/CVE-2026-31431-rs",
                "https://github.com/SeanRickerd/cve-2026-31431",
                "https://github.com/abdullaabdullazade/CVE-2026-31431",
                "https://github.com/weirdindiankid/copy-fail",
                "https://github.com/websecnl/CVE-2026-31431",
                "https://github.com/Dabbleam/CVE-2026-31431-mitigation",
                "https://github.com/selectel/mks-copy-fail-mitigation",
                "https://github.com/devstuff/harden-docker-seccomp",
                "https://github.com/yuspring/cve-2026-31431-poc",
                "https://github.com/mishl-dev/CVE_2026_31431",
                "https://github.com/Juguitos/copy-fail",
                "https://github.com/DENNISDGR/CVE-2026-31431-poc",
                "https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script",
                "https://github.com/mym0us3r/COPY-FAIL-Detection-with-Wazuh-4.14.4",
                "https://github.com/B1gN0Se/copy-fail-CVE-2026-31431",
                "https://github.com/maniakh/CVE-2026-31431---Copy-Fail-PoC",
                "https://github.com/meowteusz/copyfailautopatch",
                "https://github.com/effiesec/copy-fail-cve-2026-31431",
                "https://github.com/offsecguy/CVE-2026-31431",
                "https://github.com/poyea/CVE-2026-31431.c",
                "https://github.com/bryanvine/copy-fail-fix",
                "https://github.com/boliu83/cve-2026-31431-algif-aead-remediator",
                "https://github.com/Spoo1k/Copy-Fail-Exploit-CVE-2026-31431",
                "https://github.com/3jee/copy-fail-go",
                "https://github.com/professional-slacker/alg_check",
                "https://github.com/aestechno/cve-2026-31431-ansible",
                "https://github.com/ashok523/cve-2026-31431",
                "https://github.com/jodonnel/copyfail-briefing",
                "https://github.com/deckhouse/d8-copy-fail-mitigation",
                "https://github.com/jneuhauser/copy-fail-CVE-2026-31431",
                "https://github.com/cyber-joker/copy-fail-python",
                "https://github.com/HulnotHutu/CVE-2026-31431",
                "https://github.com/mahradbt/copyfail-mitigation",
                "https://github.com/OmerAti/almalinux-fix-cve-2026-31431",
                "https://github.com/ErdemOzgen/copy-fail-cve-2026-31431",
                "https://github.com/Fulucky0-yuri/CVE-2026-31431-PocC",
                "https://github.com/abhishekhargan/CVE-2026-31431",
                "https://github.com/MarioHY/cve_2026_31431_audit",
                "https://github.com/AliHzSec/CVE-2026-31431",
                "https://github.com/kvakirsanov/CVE-2026-31431-live-process-code-injection",
                "https://github.com/TheMalwareGuardian/CVE-2026-31431",
                "https://github.com/FrosterDL/CVE-2026-31431",
                "https://github.com/RecoFu/CVE-2026-31431-Copy-Fail",
                "https://github.com/atgreen/block-copyfail",
                "https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431",
                "https://github.com/sbeteta42/CVE-2026-31431_je_sappelle_RoOt",
                "https://github.com/rvzsec/CVE-2026-31431",
                "https://github.com/Silent0x0/Copy-Fail---CVE-2026-31431",
                "https://github.com/SpenserCai/copy_fail",
                "https://github.com/K3ysTr0K3R/CVE-2026-31431-EXPLOIT",
                "https://github.com/povzayd/CVE-2026-31431",
                "https://github.com/sebinxavi/cve-checker-2026",
                "https://github.com/mlazzarotto/copy-fail-CVE-2026-31431-mitigation-ansible-playbook",
                "https://github.com/ExploitEoom/CVE-2026-31431",
                "https://github.com/ben-slates/CVE-2026-31431-Exploit",
                "https://github.com/bootsareme/copyfail-deconstructed",
                "https://github.com/mrunalp/block-copyfail",
                "https://github.com/1amBa7Man/Linux-copy-fail-CVE-2026-31431",
                "https://github.com/Lyutoon/CopyFail-Experiment",
                "https://github.com/ledlight33/copyfail-dfir",
                "https://github.com/Smarttfoxx/copyfail",
                "https://github.com/parmstro/cfDr",
                "https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431",
                "https://github.com/glask1d/CVE-2026-31431-PoC",
                "https://github.com/monobrau/copyfailscan",
                "https://github.com/Emmmmllll/copy-fail-zig",
                "https://github.com/kdjnb/fix_CVE-2026-31431",
                "https://github.com/euriconicacio/copy-fail-CVE-2026-31431-poc",
                "https://github.com/ROSNLR5/modrosnlr5",
                "https://github.com/TheMursalin/CVE-2026-31431",
                "https://github.com/qi4L/CVE-2026-31431-Container-Escape",
                "https://github.com/moaaz-mostafa123/CVE-2026-31431",
                "https://github.com/malwarekid/CVE-2026-31431",
                "https://github.com/xd20111/CVE-2026-31431",
                "https://github.com/MartinPham/copy-fail-CVE-2026-31431-php",
                "https://github.com/krish-foren6/CVE-2026-31431-Report-Copy-fail-Vulnerability-",
                "https://github.com/Trex1e/copyfail-CVE-2026-31431",
                "https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs",
                "https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite",
                "https://github.com/suominen/CVE-2026-31431",
                "https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit",
                "https://github.com/mmionf/copy-fail-CVE-2026-31431",
                "https://github.com/cxwx/cpp-CVE-2026-31431",
                "https://github.com/Huchangzhi/autorootlinux",
                "https://github.com/Sl4cK0TH/CVE-2026-31431-PoC",
                "https://github.com/pulentoski/CVE-2026-31431",
                "https://github.com/joltcan/ansible-role-cve-2026-31431",
                "https://github.com/sandraschi/copy-fail-mcp",
                "https://github.com/Gr-1m/CVE-2026-31431",
                "https://github.com/ctzisme/copyfail-guard",
                "https://github.com/AvPrince26/copy-fail-CVE-2026-31431-Python-Golfing",
                "https://github.com/pedromizz/copy-fail",
                "https://github.com/astounds/copy-fail-CVE-2026-31431",
                "https://github.com/jbnetwork-git/copy-fail-check",
                "https://github.com/danimrtzp/CVE-2026-31431-REVSHELL",
                "https://github.com/pyroceper/copy-fail-CVE-2026-31431",
                "https://github.com/ForensicFoundry/cve-2026-31431-check",
                "https://github.com/vyahello/CVE-2026-31431",
                "https://github.com/sibersan/cve-2026-31431-checker",
                "https://github.com/ncmprbll/copy-fail-rs",
                "https://github.com/jamal-soc21/Weekly-Breach-Investigation--006",
                "https://github.com/tfawnies/CVE-2026-31431",
                "https://github.com/ravindercodes/copy-fail-CVE-2026-31431",
                "https://github.com/ChernStepanov/CopyFail-for-dummies",
                "https://github.com/kaleth4/CVE-2026-31431",
                "https://github.com/mCub3/CVE-2026-31431",
                "https://github.com/juliosuas/copyfail-guard",
                "https://github.com/codesource/copyfail-check",
                "https://github.com/xn0kkx/CVE-2026-31431_CopyFail_LinuxKernel_LPE",
                "https://github.com/MetaspIoit/CVE-2026-31431",
                "https://github.com/kvendler/BigFix-CopyFail-AlmaLinux-Content",
                "https://github.com/chavezvic/CopyFail-Penguin",
                "https://github.com/samanzamani/copy-fail-checker",
                "https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe",
                "https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell",
                "https://github.com/Qengineering/RK35xx-CopyFail-Hotfix",
                "https://github.com/ShahaB108/CVE-2026-31431_Kernel_Checker",
                "https://github.com/vasyapokemon/cve-2026-31431",
                "https://github.com/Mrhudson69/cve-2026-31431",
                "https://github.com/net0bsd/Mitigaciones",
                "https://github.com/imkk000/play-go-copy-fail-cve-2026-31431",
                "https://github.com/alvaroguzmancode/CVE-2026-31431-mitigacion",
                "https://github.com/AdityaBhatt3010/CVE-2026-31431",
                "https://github.com/jshDevs/CVE_kernellinux_jsh",
                "https://github.com/KhaosFarbauti/CVE-2026-31431",
                "https://github.com/rippsec/CVE-2026-31431-Copy-Fail",
                "https://github.com/Silent4Labs/check-copyfail-cve-2026-31431",
                "https://github.com/deadRabbit92/mitigate-copy-fail.yml",
                "https://github.com/sudoytang/copyfail-arm64",
                "https://github.com/MrMixies/Copy-Fail---CVE-2026-31431",
                "https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-31431-Copy-Fail",
                "https://github.com/Rat5ak/CVE-2026-31431-CopyFail-static-ELF--POC",
                "https://github.com/zhanghangorg/cve-2026-31431",
                "https://github.com/itsystem/afalg-check",
                "https://github.com/Detect-DefenseLab/CVE-2026-31431-detection-defense",
                "https://github.com/ozergoker/CVE-2026-31431-copy-fail",
                "https://github.com/Raptoratack/CopyFail-Scanner-CVE-2026-31431",
                "https://github.com/devtint/CVE-2026-31431",
                "https://github.com/mrmtwoj/ubuntu-cve-2026-31431-mitigation",
                "https://github.com/RazvanDuda/GhostShell",
                "https://github.com/darioomatos/cve-2026-31431-copyfail",
                "https://github.com/sgkdev/page_inject",
                "https://github.com/OneDemobird/copy-fail-CVE-2026-31431-pythonlower3.10",
                "https://github.com/reubensammut/CVE-2026-31431-Copy-Fail",
                "https://github.com/zenzue/CVE-2026-31431-Checker-Mitigator",
                "https://github.com/voxcia-io/copy-fail",
                "https://github.com/luoqianlin/copyfail-c",
                "https://github.com/tangjie1/CVE-2026-31431-Check",
                "https://github.com/0xN7y/CVE-2026-31431",
                "https://github.com/iblamenear/CVE-2026-31431-Copy-Fail---Advanced-LPE-Proof-of-Concept---C-Rewrite",
                "https://github.com/grabesec/XCP_ng_CVE-2026-31431_tester",
                "https://github.com/philfry/cve-2026-31431-ftrace",
                "https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape",
                "https://github.com/StarxSky/CVE-2026-31431",
                "https://github.com/pedro-lucas-melo/Estudo-de-Caso-CVE-2026-31431-CopyFail",
                "https://github.com/ikow/CVE-2026-31431-live-code-corruption",
                "https://github.com/gagaltotal/cve-2026-31431-copy-fail",
                "https://github.com/Mr-bv/Copy-fail-CVE-2026-31431-Exploit-in-C",
                "https://github.com/0xer0/CVE-2026-31431-Copy-Fail-add-arm64",
                "https://github.com/361way/CVE-2026-31431",
                "https://github.com/adilkurtulmus/linux-copy-fail-CVE-2026-31431",
                "https://github.com/Vatson112/deny-af-alg-bpf",
                "https://github.com/kwilck/copyfail",
                "https://github.com/pvpaulo01/cve-2026-31431",
                "https://github.com/tang-yikai/copy-fail-mitigation-with-bpftrace",
                "https://github.com/abdelkabirouadoukou/CVE-2026-31431-Analysis-and-Fix",
                "https://github.com/julichaan/CVE-2026-31431-python-copyfail-POC",
                "https://github.com/guiimoraes/CVE-2026-31431",
                "https://github.com/Morton-Li/copy-fail-CVE-2026-31431",
                "https://github.com/OpenPixelSystems/c-copy-fail",
                "https://github.com/p401a-ops/Copy-Fail",
                "https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag",
                "https://github.com/KaraZajac/DIRTYFAIL",
                "https://github.com/ROSNLR5/MitigationToolkit-ROSN-LR5-Full",
                "https://github.com/hori0729/CVE-2026-31431-Verificador-Exploit",
                "https://github.com/krisiasty/vcheck",
                "https://github.com/vorkampfer/copy_fail_mitigation",
                "https://github.com/Hunt-Benito/copy-fail-cve-2026-31431-linux-kernel-page-cache-lpe",
                "https://github.com/Helios973/CVE-2026-31431_exp.c",
                "https://github.com/haydenjames/CVE-2026-31431-check",
                "https://github.com/cleozi/Copy_Grail",
                "https://github.com/vorkampfer/copyfail2_electric_boogaloo_fix",
                "https://github.com/AdemZero/CVE-2026-31431",
                "https://github.com/Lutfifakee-Project/CVE-2026-31431",
                "https://github.com/u1tr0nex/CVE-2026-31431-CopyFail-Lab",
                "https://github.com/mauricioportela/CVE-2026-31431-Analysis",
                "https://github.com/dgrobinson0/CopyFile_CVE-2026-31431",
                "https://github.com/polyakovavv/copyfail",
                "https://github.com/gbonacini/CVE-2026-31431",
                "https://github.com/studiogangster/CVE-2026-31431",
                "https://github.com/paulorlima9/copyfail-fix",
                "https://github.com/sh4den/CVE-2026-31431-copyfail-aarch64",
                "https://github.com/DroPZsec/SplicePrivillegeEscalationFIX",
                "https://github.com/kuniyal08/Copy-Fail-CVE-2026-31431-Lab",
                "https://github.com/SilverRuler/copy-fail-CVE-2026-31431",
                "https://github.com/Sebastian294/cve-2026-31431",
                "https://github.com/0xFuffM3/CVE-2026-31431-CopyFail",
                "https://github.com/dotPY-hax/CopyFail",
                "https://github.com/zKaaanon/ProyectoFinalSO",
                "https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit",
                "https://github.com/Maxime288/CVE-2026-31431-Copy-Fail-R-pertoire-de-Pr-vention",
                "https://github.com/Pithase/asm-copyfail",
                "https://github.com/4xura/CVE-2026-31431-Copy-Fail",
                "https://github.com/royayub/CVE-2026-31431",
                "https://github.com/Yakovyakov/cve-2026-31431-mitigation",
                "https://github.com/cj667113/OCI-Ansible-Fix-CVE-2026-31431",
                "https://github.com/GubiczaP/cve-2026-31431-checker",
                "https://github.com/sgkdev/ptrace_may_dream",
                "https://github.com/yangh-beep/CVE-2026-31431-C",
                "https://github.com/JimmyPughtron/CVE-2026-31431-Copy-Fail---Minified-LPE-PoC",
                "https://github.com/4n4s4zi/copyfail-alpine",
                "https://github.com/1m1ssher/copy-fail-python",
                "https://github.com/ridhinva/linux-kernel-algif-aead-checker",
                "https://github.com/Iamliuxiaozhen/copy_fail",
                "https://github.com/songzzzz/CVE-2026-31431",
                "https://github.com/vishvacyber/Detection-Tool-Kit-for-CVE-2026-31431",
                "https://github.com/nonameuserosint-hue/Copyfail-sh",
                "https://github.com/tematemaru/CVE-2026-31431-simple-test",
                "https://github.com/1neptune/CopyFail",
                "https://github.com/zs1n/copy-fail-CVE-2026-31431",
                "https://github.com/t1ckprivate/CVE-2026-31431-Copy-Fail",
                "https://github.com/kinryulabs/rootpacket-cve-2026-31431",
                "https://github.com/SugiB3o/CVE-2026-31431",
                "https://github.com/jihwan77/Linux-Kernel-Copy-Fail-CVE-2026-31431-",
                "https://github.com/TeamN4C/SG-2026-0013",
                "https://github.com/TrevoCastles/CVE-2026-31431-copy-fail",
                "https://github.com/dev1681/CVE-2026-31431",
                "https://github.com/joaocalciolari07/copyfail-guard",
                "https://github.com/FranklinF25/cve-2026-31431",
                "https://github.com/silentbyte69/copy-fail-CVE-2026-31431-cpp",
                "https://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130c",
                "https://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fc",
                "https://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667",
                "https://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82",
                "https://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875b",
                "https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5",
                "https://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237",
                "https://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8",
                "http://www.openwall.com/lists/oss-security/2026/04/29/23",
                "http://www.openwall.com/lists/oss-security/2026/04/29/25",
                "http://www.openwall.com/lists/oss-security/2026/04/29/26",
                "http://www.openwall.com/lists/oss-security/2026/04/30/10",
                "http://www.openwall.com/lists/oss-security/2026/04/30/11",
                "http://www.openwall.com/lists/oss-security/2026/04/30/12",
                "http://www.openwall.com/lists/oss-security/2026/04/30/14",
                "http://www.openwall.com/lists/oss-security/2026/04/30/15",
                "http://www.openwall.com/lists/oss-security/2026/04/30/16",
                "http://www.openwall.com/lists/oss-security/2026/04/30/17",
                "http://www.openwall.com/lists/oss-security/2026/04/30/18",
                "http://www.openwall.com/lists/oss-security/2026/04/30/2",
                "http://www.openwall.com/lists/oss-security/2026/04/30/20",
                "http://www.openwall.com/lists/oss-security/2026/04/30/5",
                "http://www.openwall.com/lists/oss-security/2026/04/30/6",
                "http://www.openwall.com/lists/oss-security/2026/05/01/10",
                "http://www.openwall.com/lists/oss-security/2026/05/01/12",
                "http://www.openwall.com/lists/oss-security/2026/05/01/15",
                "http://www.openwall.com/lists/oss-security/2026/05/01/16",
                "http://www.openwall.com/lists/oss-security/2026/05/01/17",
                "http://www.openwall.com/lists/oss-security/2026/05/01/18",
                "http://www.openwall.com/lists/oss-security/2026/05/01/2",
                "http://www.openwall.com/lists/oss-security/2026/05/01/22",
                "http://www.openwall.com/lists/oss-security/2026/05/01/23",
                "http://www.openwall.com/lists/oss-security/2026/05/01/24",
                "http://www.openwall.com/lists/oss-security/2026/05/01/3",
                "http://www.openwall.com/lists/oss-security/2026/05/02/14",
                "http://www.openwall.com/lists/oss-security/2026/05/02/15",
                "http://www.openwall.com/lists/oss-security/2026/05/02/16",
                "http://www.openwall.com/lists/oss-security/2026/05/02/17",
                "http://www.openwall.com/lists/oss-security/2026/05/02/18",
                "http://www.openwall.com/lists/oss-security/2026/05/02/19",
                "http://www.openwall.com/lists/oss-security/2026/05/02/20",
                "http://www.openwall.com/lists/oss-security/2026/05/02/21",
                "http://www.openwall.com/lists/oss-security/2026/05/02/23",
                "http://www.openwall.com/lists/oss-security/2026/05/02/24",
                "http://www.openwall.com/lists/oss-security/2026/05/02/25",
                "http://www.openwall.com/lists/oss-security/2026/05/02/4",
                "http://www.openwall.com/lists/oss-security/2026/05/02/5",
                "http://www.openwall.com/lists/oss-security/2026/05/02/6",
                "http://www.openwall.com/lists/oss-security/2026/05/02/7",
                "http://www.openwall.com/lists/oss-security/2026/05/02/8",
                "http://www.openwall.com/lists/oss-security/2026/05/03/10",
                "http://www.openwall.com/lists/oss-security/2026/05/03/12",
                "http://www.openwall.com/lists/oss-security/2026/05/03/13",
                "http://www.openwall.com/lists/oss-security/2026/05/03/3",
                "http://www.openwall.com/lists/oss-security/2026/05/03/4",
                "http://www.openwall.com/lists/oss-security/2026/05/03/5",
                "http://www.openwall.com/lists/oss-security/2026/05/03/6",
                "http://www.openwall.com/lists/oss-security/2026/05/04/1",
                "http://www.openwall.com/lists/oss-security/2026/05/04/10",
                "http://www.openwall.com/lists/oss-security/2026/05/04/11",
                "http://www.openwall.com/lists/oss-security/2026/05/04/12",
                "http://www.openwall.com/lists/oss-security/2026/05/04/13",
                "http://www.openwall.com/lists/oss-security/2026/05/04/14",
                "http://www.openwall.com/lists/oss-security/2026/05/04/2",
                "http://www.openwall.com/lists/oss-security/2026/05/04/24",
                "http://www.openwall.com/lists/oss-security/2026/05/04/27",
                "http://www.openwall.com/lists/oss-security/2026/05/04/28",
                "http://www.openwall.com/lists/oss-security/2026/05/04/29",
                "http://www.openwall.com/lists/oss-security/2026/05/04/31",
                "http://www.openwall.com/lists/oss-security/2026/05/04/8",
                "http://www.openwall.com/lists/oss-security/2026/05/04/9",
                "http://www.openwall.com/lists/oss-security/2026/05/06/5",
                "http://www.openwall.com/lists/oss-security/2026/05/07/12",
                "http://www.openwall.com/lists/oss-security/2026/05/07/2",
                "http://www.openwall.com/lists/oss-security/2026/05/08/13",
                "http://www.openwall.com/lists/oss-security/2026/05/18/3",
                "https://copy.fail",
                "https://websec.net/blog/cve-2026-31431-linux-algifaead-page-cache-write-to-root-69f38a4ccddd2db1f520f170",
                "https://www.kb.cert.org/vuls/id/260001",
                "https://access.redhat.com/errata/RHSA-2026:13565",
                "https://access.redhat.com/errata/RHSA-2026:13566",
                "https://access.redhat.com/errata/RHSA-2026:13577",
                "https://access.redhat.com/errata/RHSA-2026:13578",
                "https://access.redhat.com/errata/RHSA-2026:13681",
                "https://access.redhat.com/errata/RHSA-2026:13690",
                "https://access.redhat.com/errata/RHSA-2026:13727",
                "https://access.redhat.com/errata/RHSA-2026:13729",
                "https://access.redhat.com/errata/RHSA-2026:13734",
                "https://access.redhat.com/errata/RHSA-2026:13811",
                "https://access.redhat.com/errata/RHSA-2026:13862",
                "https://access.redhat.com/errata/RHSA-2026:13885",
                "https://access.redhat.com/errata/RHSA-2026:13887",
                "https://access.redhat.com/errata/RHSA-2026:13932",
                "https://access.redhat.com/errata/RHSA-2026:13936",
                "https://access.redhat.com/errata/RHSA-2026:14097",
                "https://access.redhat.com/errata/RHSA-2026:14112",
                "https://access.redhat.com/errata/RHSA-2026:14137",
                "https://access.redhat.com/errata/RHSA-2026:14165",
                "https://access.redhat.com/errata/RHSA-2026:14230",
                "https://access.redhat.com/errata/RHSA-2026:14301",
                "https://access.redhat.com/errata/RHSA-2026:14339",
                "https://access.redhat.com/errata/RHSA-2026:14773",
                "https://access.redhat.com/errata/RHSA-2026:14926",
                "https://access.redhat.com/errata/RHSA-2026:15087",
                "https://access.redhat.com/errata/RHSA-2026:15976",
                "https://access.redhat.com/errata/RHSA-2026:15978",
                "https://access.redhat.com/errata/RHSA-2026:16018",
                "https://access.redhat.com/errata/RHSA-2026:16063",
                "https://access.redhat.com/errata/RHSA-2026:16111",
                "https://access.redhat.com/errata/RHSA-2026:16208",
                "https://access.redhat.com/errata/RHSA-2026:16209",
                "https://access.redhat.com/errata/RHSA-2026:16210",
                "https://access.redhat.com/errata/RHSA-2026:19074",
                "https://access.redhat.com/errata/RHSA-2026:19225",
                "https://access.redhat.com/errata/RHSA-2026:33486",
                "https://access.redhat.com/security/cve/CVE-2026-31431",
                "https://access.redhat.com/security/cve/cve-2026-31431#cve-details-mitigation",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2460538",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-265688.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-328642.html",
                "https://lore.kernel.org/linux-cve-announce/2026042214-CVE-2026-31431-3d65@gregkh/",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31431.json",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-31431",
                "https://xint.io/blog/copy-fail-linux-distributions#the-fix-6",
                "https://github.com/starscow/Copy-Fail-CVE-2026-31431-Kubernetes-PoC"
            ],
            "timeline": [
                {
                    "at": "2026-04-22T09:16:21.270",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31431"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "severity": "HIGH",
            "epss": 0.99907,
            "metadata_source": "CNA",
            "cve_status": "Analyzed",
            "cve_published_at": "2026-04-22"
        },
        {
            "id": "CVE-2026-31420",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: mrp: reject zero test interval to avoid OOM panic\n\nbr_mrp_start_test() and br_mrp_start_in_test() accept the user-supplied\ninterval value from netlink without validation. When interval is 0,\nusecs_to_jiffies(0) yields 0, causing the delayed work\n(br_mrp_test_work_expired / br_mrp_in_test_work_expired) to reschedule\nitself with zero delay. This creates a tight loop on system_percpu_wq\nthat allocates and transmits MRP test frames at maximum rate, exhausting\nall system memory and causing a kernel panic via OOM deadlock.\n\nThe same zero-interval issue applies to br_mrp_start_in_test_parse()\nfor interconnect test frames.\n\nUse NLA_POLICY_MIN(NLA_U32, 1) in the nla_policy tables for both\nIFLA_BRIDGE_MRP_START_TEST_INTERVAL and\nIFLA_BRIDGE_MRP_START_IN_TEST_INTERVAL, so zero is rejected at the\nnetlink attribute parsing layer before the value ever reaches the\nworkqueue scheduling code. This is consistent with how other bridge\nsubsystems (br_fdb, br_mst) enforce range constraints on netlink\nattributes.",
            "updated_at": "2026-09-14T12:17:40.467",
            "published_at": "2026-04-13T14:16:11.617",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "20f6a05ef63594feb0c6dfbd629da0448b43124d through before 610073ffb77ffd2b5eca182d2ac264de4834a175 (git); 20f6a05ef63594feb0c6dfbd629da0448b43124d through before ec8850be9b2b3beac1c7967d95f169dd2785979d (git); 20f6a05ef63594feb0c6dfbd629da0448b43124d through before 1ec86b4b9e28170a2565cf36f0e6e2b96b55134d (git); 20f6a05ef63594feb0c6dfbd629da0448b43124d through before 2120bd8546cd6a63c558d135773aa8f41c8259fc (git); 20f6a05ef63594feb0c6dfbd629da0448b43124d through before 630a15a31c2034b5b697f4aabc769b9d80d82446 (git); 20f6a05ef63594feb0c6dfbd629da0448b43124d through before e8ec80430bfa520e7352155d6ac632e527cba7aa (git); 20f6a05ef63594feb0c6dfbd629da0448b43124d through before c9bc352f716d1bebfe43354bce539ec2d0223b30 (git); 20f6a05ef63594feb0c6dfbd629da0448b43124d through before fa6e24963342de4370e3a3c9af41e38277b74cf3 (git); 5.8",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-667",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: mrp: reject zero test interval to avoid OOM panic\n\nbr_mrp_start_test() and br_mrp_start_in_test() accept the user-supplied\ninterval value from netlink without validation. When interval is 0,\nusecs_to_jiffies(0) yields 0, causing the delayed work\n(br_mrp_test_work_expired / br_mrp_in_test_work_expired) to reschedule\nitself with zero delay. This creates a tight loop on system_percpu_wq\nthat allocates and transmits MRP test frames at maximum rate, exhausting\nall system memory and causing a kernel panic via OOM deadlock.\n\nThe same zero-interval issue applies to br_mrp_start_in_test_parse()\nfor interconnect test frames.\n\nUse NLA_POLICY_MIN(NLA_U32, 1) in the nla_policy tables for both\nIFLA_BRIDGE_MRP_START_TEST_INTERVAL and\nIFLA_BRIDGE_MRP_START_IN_TEST_INTERVAL, so zero is rejected at the\nnetlink attribute parsing layer before the value ever reaches the\nworkqueue scheduling code. This is consistent with how other bridge\nsubsystems (br_fdb, br_mst) enforce range constraints on netlink\nattributes.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1ec86b4b9e28170a2565cf36f0e6e2b96b55134d",
                "https://git.kernel.org/stable/c/2120bd8546cd6a63c558d135773aa8f41c8259fc",
                "https://git.kernel.org/stable/c/610073ffb77ffd2b5eca182d2ac264de4834a175",
                "https://git.kernel.org/stable/c/630a15a31c2034b5b697f4aabc769b9d80d82446",
                "https://git.kernel.org/stable/c/c9bc352f716d1bebfe43354bce539ec2d0223b30",
                "https://git.kernel.org/stable/c/e8ec80430bfa520e7352155d6ac632e527cba7aa",
                "https://git.kernel.org/stable/c/ec8850be9b2b3beac1c7967d95f169dd2785979d",
                "https://git.kernel.org/stable/c/fa6e24963342de4370e3a3c9af41e38277b74cf3"
            ],
            "timeline": [
                {
                    "at": "2026-04-13T14:16:11.617",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31420"
                }
            ]
        },
        {
            "id": "CVE-2026-31278",
            "vendor": "supremainc",
            "product": "BioStar 2",
            "title": "BioStar 2 vulnerability",
            "summary": "An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.",
            "updated_at": "2026-09-14T02:17:14.080",
            "published_at": "2026-09-14T02:17:14.080",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 2.9.12 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-319",
            "what_happened": "An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "mda1r/CVE-2026-31278",
                    "author": "mda1r",
                    "first_seen": "2026-03-25",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE write-up for Active Directory credential exposure vulnerability in Suprema BioStar 2",
                    "summary": "CVE write-up for Active Directory credential exposure vulnerability in Suprema BioStar 2",
                    "url": "https://github.com/mda1r/CVE-2026-31278"
                }
            ],
            "references": [
                "https://github.com/mda1r/biostar2-ad-credential-exposure",
                "https://www.supremainc.com",
                "https://github.com/mda1r/CVE-2026-31278"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:14.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31278"
                }
            ]
        },
        {
            "id": "CVE-2026-31153",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "A stored cross-site scripting (XSS) vulnerability in Bynder before 12 January 2026 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.",
            "updated_at": "2026-09-16T15:17:34.803",
            "published_at": "2026-04-06T15:17:09.670",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A stored cross-site scripting (XSS) vulnerability in Bynder before 12 January 2026 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2026-31153",
                "https://www.bynder.com/en/"
            ],
            "timeline": [
                {
                    "at": "2026-04-06T15:17:09.670",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-31153"
                }
            ]
        },
        {
            "id": "CVE-2026-30922",
            "vendor": "pyasn1",
            "product": "pyasn1",
            "title": "pyasn1 vulnerability",
            "summary": "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with \"Indefinite Length\" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.",
            "updated_at": "2026-09-10T13:18:04.640",
            "published_at": "2026-03-18T04:17:18.397",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 0.6.3",
            "fixed": "See vendor advisory",
            "source_count": 69,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-674",
            "what_happened": "pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with \"Indefinite Length\" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-18",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/pyasn1/pyasn1/security/advisories/GHSA-jr27-m4p2-rc6r"
                }
            ],
            "references": [
                "https://github.com/pyasn1/pyasn1/commit/25ad481c19fdb006e20485ef3fc2e5b3eff30ef0",
                "https://github.com/pyasn1/pyasn1/security/advisories/GHSA-jr27-m4p2-rc6r",
                "http://www.openwall.com/lists/oss-security/2026/03/20/4",
                "https://lists.debian.org/debian-lts-announce/2026/05/msg00001.html",
                "https://access.redhat.com/errata/RHSA-2026:10184",
                "https://access.redhat.com/errata/RHSA-2026:12176",
                "https://access.redhat.com/errata/RHSA-2026:13508",
                "https://access.redhat.com/errata/RHSA-2026:13512",
                "https://access.redhat.com/errata/RHSA-2026:13545",
                "https://access.redhat.com/errata/RHSA-2026:13553",
                "https://access.redhat.com/errata/RHSA-2026:13902",
                "https://access.redhat.com/errata/RHSA-2026:13916",
                "https://access.redhat.com/errata/RHSA-2026:13917",
                "https://access.redhat.com/errata/RHSA-2026:14020",
                "https://access.redhat.com/errata/RHSA-2026:16009",
                "https://access.redhat.com/errata/RHSA-2026:17083",
                "https://access.redhat.com/errata/RHSA-2026:17611",
                "https://access.redhat.com/errata/RHSA-2026:19138",
                "https://access.redhat.com/errata/RHSA-2026:19355",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:20588",
                "https://access.redhat.com/errata/RHSA-2026:22131",
                "https://access.redhat.com/errata/RHSA-2026:22132",
                "https://access.redhat.com/errata/RHSA-2026:22133",
                "https://access.redhat.com/errata/RHSA-2026:22134",
                "https://access.redhat.com/errata/RHSA-2026:22135",
                "https://access.redhat.com/errata/RHSA-2026:22969",
                "https://access.redhat.com/errata/RHSA-2026:22970",
                "https://access.redhat.com/errata/RHSA-2026:22987",
                "https://access.redhat.com/errata/RHSA-2026:24761",
                "https://access.redhat.com/errata/RHSA-2026:24762",
                "https://access.redhat.com/errata/RHSA-2026:37275",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:6309",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/errata/RHSA-2026:6720",
                "https://access.redhat.com/errata/RHSA-2026:6912",
                "https://access.redhat.com/errata/RHSA-2026:6926",
                "https://access.redhat.com/errata/RHSA-2026:8437",
                "https://access.redhat.com/security/cve/CVE-2026-30922",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2448553",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-30922.json",
                "https://access.redhat.com/errata/RHSA-2026:65126"
            ],
            "timeline": [
                {
                    "at": "2026-03-18T04:17:18.397",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30922"
                }
            ]
        },
        {
            "id": "CVE-2026-30368",
            "vendor": "Lightspeed",
            "product": "Lightspeed Classroom",
            "title": "Lightspeed Classroom vulnerability",
            "summary": "A client-side authorization flaw in Lightspeed Systems Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devices.",
            "updated_at": "2026-09-08T19:17:57.183",
            "published_at": "2026-04-24T16:16:34.993",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5.1.2.1763770643 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-863",
            "what_happened": "A client-side authorization flaw in Lightspeed Systems Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devices.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://tasty-hovercraft-9b9.notion.site/Enabling-Unauthorized-Remote-Control-of-Student-Devices-with-Lightspeed-Classroom-2ec5157f5b4a800c9eefc5526479820a",
                "https://truekas.dev/blog/lightspeed",
                "https://www.incognitotgt.me/blog/lightspeed",
                "https://www.lightspeedsystems.com/products/lightspeed-classroom-management/",
                "https://github.com/truekas/ls-poc"
            ],
            "timeline": [
                {
                    "at": "2026-04-24T16:16:34.993",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-30368"
                }
            ]
        },
        {
            "id": "CVE-2026-29812",
            "vendor": "CyberPanel",
            "product": "CyberPanel",
            "title": "CyberPanel vulnerability",
            "summary": "CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.",
            "updated_at": "2026-09-13T20:16:51.157",
            "published_at": "2026-09-13T20:16:51.157",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.4.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-778",
            "what_happened": "CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/usmannasir/cyberpanel/commit/0a099b1b193946555fbdd387a28486b1521f9961"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T20:16:51.157",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29812"
                }
            ]
        },
        {
            "id": "CVE-2026-29811",
            "vendor": "CyberPanel",
            "product": "CyberPanel",
            "title": "CyberPanel vulnerability",
            "summary": "CyberPanel before 2.4.4 attempts to detect an \"alais\" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled \"alias\") via an ORM query filter rather than a Python \"if\" statement.",
            "updated_at": "2026-09-13T20:16:51.020",
            "published_at": "2026-09-13T20:16:51.020",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.4.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-1025",
            "what_happened": "CyberPanel before 2.4.4 attempts to detect an \"alais\" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled \"alias\") via an ORM query filter rather than a Python \"if\" statement.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/usmannasir/cyberpanel/commit/0a099b1b193946555fbdd387a28486b1521f9961"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T20:16:51.020",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29811"
                }
            ]
        },
        {
            "id": "CVE-2026-29810",
            "vendor": "CyberPanel",
            "product": "CyberPanel",
            "title": "CyberPanel vulnerability",
            "summary": "CyberPanel before 2.4.4 omits a \"return 0\" that is required by the business logic.",
            "updated_at": "2026-09-13T20:16:50.880",
            "published_at": "2026-09-13T20:16:50.880",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.4.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-390",
            "what_happened": "CyberPanel before 2.4.4 omits a \"return 0\" that is required by the business logic.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/usmannasir/cyberpanel/commit/0a099b1b193946555fbdd387a28486b1521f9961"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T20:16:50.880",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29810"
                }
            ]
        },
        {
            "id": "CVE-2026-29785",
            "vendor": "nats-io",
            "product": "nats-server",
            "title": "nats-server vulnerability",
            "summary": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the \"leafnode\" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used). Versions 2.11.14 and 2.12.5 contain a fix. As a workaround, disable compression on the leafnode port.",
            "updated_at": "2026-09-07T13:18:37.967",
            "published_at": "2026-03-25T20:16:30.373",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 2.11.14; >= 2.12.0-RC.1, < 2.12.5",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the \"leafnode\" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication and requires that compression be enabled (which it is, by default, when leafnodes are used). Versions 2.11.14 and 2.12.5 contain a fix. As a workaround, disable compression on the leafnode port.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://advisories.nats.io/CVE/secnote-2026-04.txt",
                "https://github.com/nats-io/nats-server/commit/a1488de6f2ba6e666aef0f9cce0016f7f167d6a8",
                "https://github.com/nats-io/nats-server/security/advisories/GHSA-52jh-2xxh-pwh6",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/security/cve/CVE-2026-29785",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451444",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29785.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-25T20:16:30.373",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29785"
                }
            ]
        },
        {
            "id": "CVE-2026-29711",
            "vendor": "Acme",
            "product": "Edge Gateway",
            "title": "Acme Edge Gateway authentication bypass",
            "summary": "An authentication boundary flaw may allow a remote unauthenticated actor to access administrative functions on affected gateways.",
            "updated_at": "2026-09-01T09:27:00Z",
            "published_at": "2026-05-24T00:37:00Z",
            "cvss": 8.8,
            "severity": "HIGH",
            "epss": 0.61234,
            "metadata_source": "NIST",
            "cve_status": "Analyzed",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "review",
            "affected": "≤ 3.2.4",
            "fixed": "3.2.5",
            "source_count": 111,
            "kev": true,
            "attack_vector": "Remote",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-288",
            "what_happened": "A flaw in the authentication boundary of Acme Edge Gateway allows a remote unauthenticated actor to access administrative endpoints intended for authorized users. The issue stems from improper validation of session state before routing requests to privileged functionality.",
            "why_matters": "Successful use can result in administrative access to the gateway, including configuration changes and service disruption. Internet-facing, centrally deployed gateways have the highest exposure.",
            "mitigations": [
                "Upgrade to Acme Edge Gateway 3.2.5 or later.",
                "Monitor for unusual administrative actions and configuration changes.",
                "Restrict administrative interfaces to trusted networks.",
                "Review gateway access logs for unauthenticated requests to administrative paths."
            ],
            "pocs": [
                {
                    "repository": "CVE-2026-29711-poc",
                    "author": "0x4D31F",
                    "first_seen": "May 24, 2026",
                    "confidence": "Low",
                    "url": "https://github.com/search?q=CVE-2026-29711&type=repositories"
                },
                {
                    "repository": "CVE-Intel · infosec-research/Acme-Edge-CVE-2026-29711",
                    "author": "infosec-research",
                    "first_seen": "2026-05-24",
                    "last_seen": "2026-05-26T14:30:00Z",
                    "pushed_at": "2026-05-26T13:45:00Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Bypass",
                    "language": "PHP",
                    "stars": 18,
                    "forks": 4,
                    "topics": [
                        "cve",
                        "proof-of-concept"
                    ],
                    "title": "Authentication bypass demonstration for CVE-2026-29711",
                    "repository_description": "Authentication bypass demonstration for CVE-2026-29711",
                    "summary": "Authentication bypass demonstration for CVE-2026-29711",
                    "severity": "HIGH",
                    "epss": 0.61234,
                    "metadata_source": "NIST",
                    "cve_status": "Analyzed",
                    "source": "CVE-Intel",
                    "url": "https://github.com/infosec-research/Acme-Edge-CVE-2026-29711"
                }
            ],
            "timeline": [
                {
                    "at": "May 23, 2026 21:14 UTC",
                    "label": "Vendor advisory published",
                    "url": "#"
                },
                {
                    "at": "May 24, 2026 00:37 UTC",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29711"
                },
                {
                    "at": "May 24, 2026 05:02 UTC",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "May 24, 2026 08:41 UTC",
                    "label": "Public PoC repository observed",
                    "url": "https://github.com/search?q=CVE-2026-29711&type=repositories"
                }
            ],
            "references": [
                "https://github.com/search?q=CVE-2026-29711&type=repositories",
                "https://github.com/infosec-research/Acme-Edge-CVE-2026-29711"
            ]
        },
        {
            "id": "CVE-2026-29181",
            "vendor": "open-telemetry",
            "product": "opentelemetry-go",
            "title": "opentelemetry-go vulnerability",
            "summary": "OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.",
            "updated_at": "2026-09-11T13:17:25.487",
            "published_at": "2026-04-07T21:17:16.003",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.36.0, < 1.41.0",
            "fixed": "See vendor advisory",
            "source_count": 30,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggage: header lines, even when each individual value is within the 8192-byte per-value parse limit. This vulnerability is fixed in 1.41.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-07",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-mh2q-q3fh-2475"
                }
            ],
            "references": [
                "https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-mh2q-q3fh-2475",
                "https://access.redhat.com/errata/RHSA-2026:25271",
                "https://access.redhat.com/errata/RHSA-2026:47735",
                "https://access.redhat.com/errata/RHSA-2026:61314",
                "https://access.redhat.com/errata/RHSA-2026:63140",
                "https://access.redhat.com/errata/RHSA-2026:66521",
                "https://access.redhat.com/security/cve/CVE-2026-29181",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2456252",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29181.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-07T21:17:16.003",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29181"
                }
            ]
        },
        {
            "id": "CVE-2026-29074",
            "vendor": "svg",
            "product": "svgo",
            "title": "svgo vulnerability",
            "summary": "SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards against entity expansion or recursion. This can result in a small XML file (811 bytes) stalling the application and even crashing the Node.js process with JavaScript heap out of memory. This issue has been patched in versions 2.8.1, 3.3.3, and 4.0.1.",
            "updated_at": "2026-09-10T13:18:03.533",
            "published_at": "2026-03-06T08:16:26.920",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 2.1.0, < 2.8.1; >= 3.0.0, < 3.3.3; = 4.0.0",
            "fixed": "See vendor advisory",
            "source_count": 54,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-776",
            "what_happened": "SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before version 3.3.3, and before version 4.0.1, SVGO accepts XML with custom entities, without guards against entity expansion or recursion. This can result in a small XML file (811 bytes) stalling the application and even crashing the Node.js process with JavaScript heap out of memory. This issue has been patched in versions 2.8.1, 3.3.3, and 4.0.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/svg/svgo/security/advisories/GHSA-xpqw-6gx7-v673"
                }
            ],
            "references": [
                "https://github.com/svg/svgo/security/advisories/GHSA-xpqw-6gx7-v673",
                "https://access.redhat.com/errata/RHSA-2026:11856",
                "https://access.redhat.com/errata/RHSA-2026:11916",
                "https://access.redhat.com/errata/RHSA-2026:13512",
                "https://access.redhat.com/errata/RHSA-2026:13545",
                "https://access.redhat.com/errata/RHSA-2026:13553",
                "https://access.redhat.com/errata/RHSA-2026:13826",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:21772",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:48085",
                "https://access.redhat.com/errata/RHSA-2026:5807",
                "https://access.redhat.com/errata/RHSA-2026:6277",
                "https://access.redhat.com/errata/RHSA-2026:6309",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/errata/RHSA-2026:6926",
                "https://access.redhat.com/errata/RHSA-2026:7110",
                "https://access.redhat.com/errata/RHSA-2026:8483",
                "https://access.redhat.com/errata/RHSA-2026:8484",
                "https://access.redhat.com/errata/RHSA-2026:8490",
                "https://access.redhat.com/errata/RHSA-2026:8491",
                "https://access.redhat.com/errata/RHSA-2026:8493",
                "https://access.redhat.com/errata/RHSA-2026:9742",
                "https://access.redhat.com/security/cve/CVE-2026-29074",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2445132",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29074.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-06T08:16:26.920",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29074"
                }
            ]
        },
        {
            "id": "CVE-2026-29063",
            "vendor": "immutable-js",
            "product": "immutable-js",
            "title": "immutable-js vulnerability",
            "summary": "Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.",
            "updated_at": "2026-09-10T13:18:02.623",
            "published_at": "2026-03-06T19:16:21.557",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 3.8.3; < 4.3.7; < 5.1.5",
            "fixed": "See vendor advisory",
            "source_count": 97,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1321",
            "what_happened": "Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/immutable-js/immutable-js/security/advisories/GHSA-wf6x-7x77-mvgw"
                }
            ],
            "references": [
                "https://github.com/immutable-js/immutable-js/releases/tag/v3.8.3",
                "https://github.com/immutable-js/immutable-js/releases/tag/v4.3.8",
                "https://github.com/immutable-js/immutable-js/releases/tag/v5.1.5",
                "https://github.com/immutable-js/immutable-js/security/advisories/GHSA-wf6x-7x77-mvgw",
                "https://access.redhat.com/errata/RHSA-2026:11070",
                "https://access.redhat.com/errata/RHSA-2026:11217",
                "https://access.redhat.com/errata/RHSA-2026:11414",
                "https://access.redhat.com/errata/RHSA-2026:11858",
                "https://access.redhat.com/errata/RHSA-2026:11916",
                "https://access.redhat.com/errata/RHSA-2026:12118",
                "https://access.redhat.com/errata/RHSA-2026:13542",
                "https://access.redhat.com/errata/RHSA-2026:13548",
                "https://access.redhat.com/errata/RHSA-2026:13791",
                "https://access.redhat.com/errata/RHSA-2026:13826",
                "https://access.redhat.com/errata/RHSA-2026:13829",
                "https://access.redhat.com/errata/RHSA-2026:13847",
                "https://access.redhat.com/errata/RHSA-2026:13853",
                "https://access.redhat.com/errata/RHSA-2026:17469",
                "https://access.redhat.com/errata/RHSA-2026:17598",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19409",
                "https://access.redhat.com/errata/RHSA-2026:19410",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:20034",
                "https://access.redhat.com/errata/RHSA-2026:20041",
                "https://access.redhat.com/errata/RHSA-2026:20042",
                "https://access.redhat.com/errata/RHSA-2026:20088",
                "https://access.redhat.com/errata/RHSA-2026:21657",
                "https://access.redhat.com/errata/RHSA-2026:21658",
                "https://access.redhat.com/errata/RHSA-2026:21703",
                "https://access.redhat.com/errata/RHSA-2026:21931",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:23246",
                "https://access.redhat.com/errata/RHSA-2026:24473",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:26225",
                "https://access.redhat.com/errata/RHSA-2026:26232",
                "https://access.redhat.com/errata/RHSA-2026:27063",
                "https://access.redhat.com/errata/RHSA-2026:28893",
                "https://access.redhat.com/errata/RHSA-2026:28964",
                "https://access.redhat.com/errata/RHSA-2026:29857",
                "https://access.redhat.com/errata/RHSA-2026:29864",
                "https://access.redhat.com/errata/RHSA-2026:34049",
                "https://access.redhat.com/errata/RHSA-2026:34099",
                "https://access.redhat.com/errata/RHSA-2026:34100",
                "https://access.redhat.com/errata/RHSA-2026:34342",
                "https://access.redhat.com/errata/RHSA-2026:36621",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:40022",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:40984",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41941",
                "https://access.redhat.com/errata/RHSA-2026:41944",
                "https://access.redhat.com/errata/RHSA-2026:6428",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/errata/RHSA-2026:6720",
                "https://access.redhat.com/errata/RHSA-2026:6926",
                "https://access.redhat.com/errata/RHSA-2026:7329",
                "https://access.redhat.com/errata/RHSA-2026:8218",
                "https://access.redhat.com/errata/RHSA-2026:8483",
                "https://access.redhat.com/errata/RHSA-2026:8484",
                "https://access.redhat.com/errata/RHSA-2026:8490",
                "https://access.redhat.com/errata/RHSA-2026:8491",
                "https://access.redhat.com/errata/RHSA-2026:8493",
                "https://access.redhat.com/errata/RHSA-2026:9742",
                "https://access.redhat.com/errata/RHSA-2026:9848",
                "https://access.redhat.com/security/cve/CVE-2026-29063",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2445291",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29063.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-06T19:16:21.557",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-29063"
                }
            ]
        },
        {
            "id": "CVE-2026-29053",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Ghost_CMS 6.19.0  - Remote Code Execution",
            "summary": "Ghost_CMS 6.19.0  - Remote Code Execution",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 198,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52676",
                    "author": "Maksim Rogov",
                    "first_seen": "2026-09-02",
                    "confidence": "High",
                    "title": "Ghost_CMS 6.19.0  - Remote Code Execution",
                    "summary": "Ghost_CMS 6.19.0  - Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/52676",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "AC8999/CVE-2026-29053",
                    "author": "AC8999",
                    "first_seen": "2026-04-21",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": "(RCE) vulnerability discovered in Ghost CMS (specifically affecting versions 0.7.2 through 6.19.0)",
                    "summary": "(RCE) vulnerability discovered in Ghost CMS (specifically affecting versions 0.7.2 through 6.19.0)",
                    "url": "https://github.com/AC8999/CVE-2026-29053"
                },
                {
                    "repository": "rootxran/CVE-2026-29053",
                    "author": "rootxran",
                    "first_seen": "2026-03-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-29053 repository",
                    "summary": "",
                    "url": "https://github.com/rootxran/CVE-2026-29053"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52676",
                "https://github.com/AC8999/CVE-2026-29053",
                "https://github.com/rootxran/CVE-2026-29053"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52676"
                }
            ]
        },
        {
            "id": "CVE-2026-28969",
            "vendor": "Apple",
            "product": "iOS and iPadOS",
            "title": "iOS and iPadOS vulnerability",
            "summary": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.7, macOS Sequoia 15.8, macOS Sonoma 14.8.7, macOS Tahoe 26.5, macOS Tahoe 26.7, tvOS 26.5, tvOS 27, visionOS 26.5, visionOS 27, watchOS 26.5, watchOS 27. An app may be able to cause unexpected system termination.",
            "updated_at": "2026-09-14T21:17:06.153",
            "published_at": "2026-05-11T21:18:57.700",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 18.7.9 (custom); before 26.5 (custom); before 27 (custom); before 14.8.7 (custom); before 15.7.7 (custom); before 15.8 (custom); before 26.7 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.7.7, macOS Sequoia 15.8, macOS Sonoma 14.8.7, macOS Tahoe 26.5, macOS Tahoe 26.7, tvOS 26.5, tvOS 27, visionOS 26.5, visionOS 27, watchOS 26.5, watchOS 27. An app may be able to cause unexpected system termination.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.apple.com/en-us/127110",
                "https://support.apple.com/en-us/127111",
                "https://support.apple.com/en-us/127115",
                "https://support.apple.com/en-us/127116",
                "https://support.apple.com/en-us/127117",
                "https://support.apple.com/en-us/127118",
                "https://support.apple.com/en-us/127119",
                "https://support.apple.com/en-us/127120",
                "https://support.apple.com/en-us/149034",
                "https://support.apple.com/en-us/149035",
                "https://support.apple.com/en-us/149036",
                "https://support.apple.com/en-us/149037",
                "https://support.apple.com/en-us/149038",
                "https://support.apple.com/en-us/149042",
                "https://support.apple.com/en-us/149043"
            ],
            "timeline": [
                {
                    "at": "2026-05-11T21:18:57.700",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28969"
                }
            ]
        },
        {
            "id": "CVE-2026-28808",
            "vendor": "Erlang",
            "product": "OTP",
            "title": "OTP vulnerability",
            "summary": "Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias.\n\nWhen script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the DocumentRoot-relative path while mod_cgi executes the script at the ScriptAlias-resolved path. This path mismatch allows unauthenticated access to CGI scripts that directory rules were meant to protect.\n\nThis vulnerability is associated with program files lib/inets/src/http_server/mod_alias.erl, lib/inets/src/http_server/mod_auth.erl, and lib/inets/src/http_server/mod_cgi.erl.\n\nThis issue affects OTP from OTP 17.0 before OTP 26.2.5.19, OTP 27.3.4.10, and OTP 28.4.2, corresponding to inets from 5.10 before 9.1.0.6, 9.3.2.4, and 9.6.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "updated_at": "2026-09-08T14:17:21.527",
            "published_at": "2026-04-07T13:16:46.320",
            "cvss": 8.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17.0 through before * (otp); 5.10 through before * (otp); 07b8f441ca711f9812fad9e9115bab3c3aa92f79 through before * (git)",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias.\n\nWhen script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-based access controls against the DocumentRoot-relative path while mod_cgi executes the script at the ScriptAlias-resolved path. This path mismatch allows unauthenticated access to CGI scripts that directory rules were meant to protect.\n\nThis vulnerability is associated with program files lib/inets/src/http_server/mod_alias.erl, lib/inets/src/http_server/mod_auth.erl, and lib/inets/src/http_server/mod_cgi.erl.\n\nThis issue affects OTP from OTP 17.0 before OTP 26.2.5.19, OTP 27.3.4.10, and OTP 28.4.2, corresponding to inets from 5.10 before 9.1.0.6, 9.3.2.4, and 9.6.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-28808.html",
                "https://github.com/erlang/otp/commit/07b8f441ca711f9812fad9e9115bab3c3aa92f79",
                "https://github.com/erlang/otp/commit/8fc71ac6af4fbcc54103bec2983ef22e82942688",
                "https://github.com/erlang/otp/commit/9dfa0c51eac97866078e808dec2183cb7871ff7c",
                "https://github.com/erlang/otp/security/advisories/GHSA-3vhp-h532-mc3f",
                "https://osv.dev/vulnerability/EEF-CVE-2026-28808",
                "https://www.erlang.org/doc/system/versions.html#order-of-versions",
                "https://access.redhat.com/security/cve/CVE-2026-28808",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2455909",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28808.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-07T13:16:46.320",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28808"
                }
            ]
        },
        {
            "id": "CVE-2026-28802",
            "vendor": "authlib",
            "product": "authlib",
            "title": "authlib vulnerability",
            "summary": "Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected.. This issue has been patched in version 1.6.7.",
            "updated_at": "2026-09-10T13:18:02.380",
            "published_at": "2026-03-06T07:16:01.053",
            "cvss": 7.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.6.5, < 1.6.7",
            "fixed": "See vendor advisory",
            "source_count": 37,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-347",
            "what_happened": "Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected.. This issue has been patched in version 1.6.7.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/authlib/authlib/security/advisories/GHSA-7wc2-qxgw-g8gg"
                }
            ],
            "references": [
                "https://github.com/authlib/authlib/commit/a61c2acb807496e67f32051b5f1b1d5ccf8f0a75",
                "https://github.com/authlib/authlib/commit/b87c32ed07b8ae7f805873e1c9cafd1016761df7",
                "https://github.com/authlib/authlib/security/advisories/GHSA-7wc2-qxgw-g8gg",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:4942",
                "https://access.redhat.com/errata/RHSA-2026:5168",
                "https://access.redhat.com/errata/RHSA-2026:5665",
                "https://access.redhat.com/errata/RHSA-2026:6309",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/security/cve/CVE-2026-28802",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2445120",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28802.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-06T07:16:01.053",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28802"
                }
            ]
        },
        {
            "id": "CVE-2026-28780",
            "vendor": "Apache Software Foundation",
            "product": "Apache HTTP Server",
            "title": "Apache HTTP Server vulnerability",
            "summary": "Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.\nIf mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.",
            "updated_at": "2026-09-14T13:17:54.970",
            "published_at": "2026-05-05T22:16:00.390",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.4.66 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.\nIf mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.\n\nThis issue affects Apache HTTP Server: through 2.4.66.\n\nUsers are recommended to upgrade to version 2.4.67, which fixes the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://httpd.apache.org/security/vulnerabilities_24.html",
                "http://www.openwall.com/lists/oss-security/2026/05/05/9",
                "https://access.redhat.com/errata/RHSA-2026:21391",
                "https://access.redhat.com/errata/RHSA-2026:21433",
                "https://access.redhat.com/errata/RHSA-2026:22140",
                "https://access.redhat.com/errata/RHSA-2026:27200",
                "https://access.redhat.com/errata/RHSA-2026:27201",
                "https://access.redhat.com/errata/RHSA-2026:36373",
                "https://access.redhat.com/errata/RHSA-2026:36831",
                "https://access.redhat.com/errata/RHSA-2026:36846",
                "https://access.redhat.com/errata/RHSA-2026:47046",
                "https://access.redhat.com/errata/RHSA-2026:62165",
                "https://access.redhat.com/errata/RHSA-2026:66323",
                "https://access.redhat.com/security/cve/CVE-2026-28780",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2466913",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28780.json",
                "https://access.redhat.com/errata/RHSA-2026:67152"
            ],
            "timeline": [
                {
                    "at": "2026-05-05T22:16:00.390",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28780"
                }
            ]
        },
        {
            "id": "CVE-2026-28668",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:18:01.163",
            "published_at": "2026-09-08T19:17:56.980",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:56.980",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28668"
                }
            ]
        },
        {
            "id": "CVE-2026-28666",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:18:01.050",
            "published_at": "2026-09-08T19:17:56.887",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:56.887",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28666"
                }
            ]
        },
        {
            "id": "CVE-2026-28663",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:18:00.927",
            "published_at": "2026-09-08T19:17:56.677",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In buildIntentSenderForUser of LauncherAppsService.java, there is a possible way to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:56.677",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28663"
                }
            ]
        },
        {
            "id": "CVE-2026-28662",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:18:00.807",
            "published_at": "2026-09-08T19:17:56.570",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:56.570",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28662"
                }
            ]
        },
        {
            "id": "CVE-2026-28658",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:18:00.693",
            "published_at": "2026-09-08T19:17:56.313",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In findMetaAuthUid of AccountsDb.java, there is a possible frp bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:56.313",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28658"
                }
            ]
        },
        {
            "id": "CVE-2026-28657",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:18:00.580",
            "published_at": "2026-09-08T19:17:56.207",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In onActivityResult of AppWidgetConfigActivityProxy.java, there is a possible unauthorized URI permission grant due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:56.207",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28657"
                }
            ]
        },
        {
            "id": "CVE-2026-28656",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
            "updated_at": "2026-09-10T04:18:00.457",
            "published_at": "2026-09-08T19:17:56.100",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/wear/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:56.100",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28656"
                }
            ]
        },
        {
            "id": "CVE-2026-28655",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple functions of RemoteViews.java, there is a possible background activity launch bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:18:00.357",
            "published_at": "2026-09-08T19:17:55.970",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In multiple functions of RemoteViews.java, there is a possible background activity launch bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:55.970",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28655"
                }
            ]
        },
        {
            "id": "CVE-2026-28653",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-11T04:17:43.387",
            "published_at": "2026-09-08T19:17:55.857",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "In multiple functions of rw_t3t.cc, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:55.857",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28653"
                }
            ]
        },
        {
            "id": "CVE-2026-28650",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In setHiddenWhileSuspended of WindowState.java, there is a possible overlay bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:18:00.243",
            "published_at": "2026-09-08T19:17:55.643",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In setHiddenWhileSuspended of WindowState.java, there is a possible overlay bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:55.643",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28650"
                }
            ]
        },
        {
            "id": "CVE-2026-28644",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:18:00.120",
            "published_at": "2026-09-08T19:17:55.543",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In startNextMatchingActivity of ActivityTaskManagerService.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:55.543",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28644"
                }
            ]
        },
        {
            "id": "CVE-2026-28642",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In executeRequest of ActivityStarter.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:59.987",
            "published_at": "2026-09-08T19:17:55.450",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In executeRequest of ActivityStarter.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:55.450",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28642"
                }
            ]
        },
        {
            "id": "CVE-2026-28639",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:59.867",
            "published_at": "2026-09-08T19:17:55.360",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:55.360",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28639"
                }
            ]
        },
        {
            "id": "CVE-2026-28636",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In setupLayout of PickActivity.java, there is a possible bypass of the \"Install unknown apps\" security restriction due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:59.747",
            "published_at": "2026-09-08T19:17:55.177",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In setupLayout of PickActivity.java, there is a possible bypass of the \"Install unknown apps\" security restriction due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:55.177",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28636"
                }
            ]
        },
        {
            "id": "CVE-2026-28634",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In handleUssdRequest of PhoneInterfaceManager.java, there is a possible way to send a USSD request without permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:59.127",
            "published_at": "2026-09-08T19:17:55.080",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In handleUssdRequest of PhoneInterfaceManager.java, there is a possible way to send a USSD request without permission due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:55.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28634"
                }
            ]
        },
        {
            "id": "CVE-2026-28631",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:58.897",
            "published_at": "2026-09-08T19:17:54.880",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In buildMiniResolver of IntentForwarderActivity.java, there is a possible consent bypass due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:54.880",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28631"
                }
            ]
        },
        {
            "id": "CVE-2026-28626",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In onCreate of SetupPassthroughActivity.java, there is a possible way to launch arbitrary activity due to Intent redirection . This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
            "updated_at": "2026-09-10T04:17:58.610",
            "published_at": "2026-09-08T19:17:54.530",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In onCreate of SetupPassthroughActivity.java, there is a possible way to launch arbitrary activity due to Intent redirection . This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:54.530",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28626"
                }
            ]
        },
        {
            "id": "CVE-2026-28624",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple locations, there is a possible read/write access to files without the proper permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:58.453",
            "published_at": "2026-09-08T19:17:54.420",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In multiple locations, there is a possible read/write access to files without the proper permissions due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:54.420",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28624"
                }
            ]
        },
        {
            "id": "CVE-2026-28620",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple locations, there is a possible unauthorized URI access due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:58.290",
            "published_at": "2026-09-08T19:17:54.083",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In multiple locations, there is a possible unauthorized URI access due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:54.083",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28620"
                }
            ]
        },
        {
            "id": "CVE-2026-28618",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:58.167",
            "published_at": "2026-09-08T19:17:53.970",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In dec_frm_prepare of oapv.c, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:53.970",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28618"
                }
            ]
        },
        {
            "id": "CVE-2026-28616",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In Setup Wizard, there is a possible way to force connection to a malicious network due to confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-11T04:17:42.280",
            "published_at": "2026-09-08T19:17:53.740",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android SoC",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-441",
            "what_happened": "In Setup Wizard, there is a possible way to force connection to a malicious network due to confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:53.740",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28616"
                }
            ]
        },
        {
            "id": "CVE-2026-28614",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:58.057",
            "published_at": "2026-09-08T19:17:53.620",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In onCreate of SlicePermissionActivity.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:53.620",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28614"
                }
            ]
        },
        {
            "id": "CVE-2026-28613",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch an arbitrary intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
            "updated_at": "2026-09-10T04:17:57.917",
            "published_at": "2026-09-08T19:17:53.507",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In initAppLinkTypeAndIntent of ChannelImpl.java, there is a possible launch an arbitrary intent due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:53.507",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28613"
                }
            ]
        },
        {
            "id": "CVE-2026-28612",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In resolveActivity of ActivityStarter.java, there is a possible way to perform Intent Redirection attacks due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:57.743",
            "published_at": "2026-09-08T19:17:53.330",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In resolveActivity of ActivityStarter.java, there is a possible way to perform Intent Redirection attacks due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:53.330",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28612"
                }
            ]
        },
        {
            "id": "CVE-2026-28611",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple functions of NfcService.java, there is a possible silent payment session hijacking enablement due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:57.583",
            "published_at": "2026-09-08T19:17:53.150",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16; 15",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In multiple functions of NfcService.java, there is a possible silent payment session hijacking enablement due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:53.150",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28611"
                }
            ]
        },
        {
            "id": "CVE-2026-28609",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:57.237",
            "published_at": "2026-09-08T19:17:53.053",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In read of MatroskaExtractor.cpp, there is a possible out-of-bounds write due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:53.053",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28609"
                }
            ]
        },
        {
            "id": "CVE-2026-28607",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:55.597",
            "published_at": "2026-09-08T19:17:52.920",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In multiple functions in multiple locations, there is a possible background activity launch bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:52.920",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28607"
                }
            ]
        },
        {
            "id": "CVE-2026-28606",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalation of privilege without user consent with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-11T04:17:42.130",
            "published_at": "2026-09-08T19:17:52.823",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalation of privilege without user consent with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:52.823",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28606"
                }
            ]
        },
        {
            "id": "CVE-2026-28604",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple locations, there is a possible use after free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:53.570",
            "published_at": "2026-09-08T19:17:52.727",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In multiple locations, there is a possible use after free due to a race condition. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:52.727",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28604"
                }
            ]
        },
        {
            "id": "CVE-2026-28603",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:53.277",
            "published_at": "2026-09-08T19:17:52.630",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible read/write access to private files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:52.630",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28603"
                }
            ]
        },
        {
            "id": "CVE-2026-28602",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In setClipboardAccessNotificationsEnabledForUser of ClipboardService.java, there is a possible mult-iuser isolation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-11T04:17:40.270",
            "published_at": "2026-09-08T19:17:52.530",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "In setClipboardAccessNotificationsEnabledForUser of ClipboardService.java, there is a possible mult-iuser isolation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:52.530",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28602"
                }
            ]
        },
        {
            "id": "CVE-2026-28600",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:53.170",
            "published_at": "2026-09-08T19:17:52.430",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In onCreate of PaymentDefaultDialog.java, there is a possible way to change default payment app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:52.430",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28600"
                }
            ]
        },
        {
            "id": "CVE-2026-28599",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In addCreatorToken of ActivityManagerService.java, there is a possible Intent Redirection Bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:52.733",
            "published_at": "2026-09-08T19:17:52.337",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In addCreatorToken of ActivityManagerService.java, there is a possible Intent Redirection Bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:52.337",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28599"
                }
            ]
        },
        {
            "id": "CVE-2026-28594",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple locations, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:52.473",
            "published_at": "2026-09-08T19:17:52.147",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In multiple locations, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:52.147",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28594"
                }
            ]
        },
        {
            "id": "CVE-2026-28593",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:52.360",
            "published_at": "2026-09-08T19:17:52.043",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In getItemList of SettingsFragment.java, there is a possible user interaction bypass due to misleading or insufficient UI. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:52.043",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28593"
                }
            ]
        },
        {
            "id": "CVE-2026-28590",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple locations, there is a possible improper encryption key validation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:52.073",
            "published_at": "2026-09-08T19:17:51.930",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In multiple locations, there is a possible improper encryption key validation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:51.930",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28590"
                }
            ]
        },
        {
            "id": "CVE-2026-28583",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:51.780",
            "published_at": "2026-09-08T19:17:51.710",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In validate_camera_metadata_structure of camera_metadata.c, there is a possible out of bounds write due to a logical error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:51.710",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28583"
                }
            ]
        },
        {
            "id": "CVE-2026-28581",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local escalation with User execution privileges needed. User interaction is needed for exploitation.",
            "updated_at": "2026-09-08T19:17:51.403",
            "published_at": "2026-06-01T22:16:25.110",
            "cvss": 4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local escalation with User execution privileges needed. User interaction is needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-01T22:16:25.110",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28581"
                }
            ]
        },
        {
            "id": "CVE-2026-28572",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:51.033",
            "published_at": "2026-09-08T19:17:51.277",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16-qpr2",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In onCreate of InstallLaunch.kt, there is a possible misleading UI due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:51.277",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28572"
                }
            ]
        },
        {
            "id": "CVE-2026-28498",
            "vendor": "authlib",
            "product": "authlib",
            "title": "authlib vulnerability",
            "summary": "Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.",
            "updated_at": "2026-09-10T13:18:01.797",
            "published_at": "2026-03-16T18:16:07.717",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 1.6.9",
            "fixed": "See vendor advisory",
            "source_count": 37,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-354",
            "what_happened": "Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-16",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/authlib/authlib/security/advisories/GHSA-m344-f55w-2m6j"
                }
            ],
            "references": [
                "https://github.com/authlib/authlib/commit/b9bb2b25bf8b7e01512d847a95c1749646eaa72b",
                "https://github.com/authlib/authlib/releases/tag/v1.6.9",
                "https://github.com/authlib/authlib/security/advisories/GHSA-m344-f55w-2m6j",
                "https://access.redhat.com/errata/RHSA-2026:6309",
                "https://access.redhat.com/errata/RHSA-2026:6497",
                "https://access.redhat.com/errata/RHSA-2026:6567",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/errata/RHSA-2026:6720",
                "https://access.redhat.com/errata/RHSA-2026:6912",
                "https://access.redhat.com/security/cve/CVE-2026-28498",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2448182",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28498.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-16T18:16:07.717",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28498"
                }
            ]
        },
        {
            "id": "CVE-2026-28402",
            "vendor": "Google",
            "product": "Chromium",
            "title": "Chromium V8 type confusion",
            "summary": "A type-confusion condition in V8 may allow crafted web content to violate browser process memory safety.",
            "updated_at": "2026-09-01T09:15:00Z",
            "published_at": "2026-08-31T19:20:00Z",
            "cvss": 8.1,
            "confidence": 64,
            "confidence_label": "observed",
            "affected": "138.0.7204.0",
            "fixed": "138.0.7204.12",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Remote",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-843",
            "what_happened": "An incorrect object type assumption in V8 can lead to unsafe memory access when processing specially formed JavaScript.",
            "why_matters": "Browsers process untrusted content continuously, making memory-safety defects relevant even when additional containment must be bypassed.",
            "mitigations": [
                "Update Chromium-based browsers to the latest stable release.",
                "Confirm managed browser fleets apply automatic updates.",
                "Monitor vendor advisories for revised affected-version ranges."
            ],
            "pocs": [],
            "references": []
        },
        {
            "id": "CVE-2026-28384",
            "vendor": "Canonical",
            "product": "lxd",
            "title": "lxd vulnerability",
            "summary": "An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This issue affected LXD from 4.12 through 6.6 and was fixed in the snap versions 5.0.6-e49d9f4 (channel 5.0/stable), 5.21.4-1374f39 (channel 5.21/stable), and 6.7-1f11451 (channel 6.0 stable). The channel 4.0/stable is not affected as it contains version 4.0.10.",
            "updated_at": "2026-09-11T15:33:43.067",
            "published_at": "2026-03-12T15:16:27.247",
            "cvss": 9.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.0 through before 6.7 (semver); 5.21.0 through before 5.21.4 (semver); 5.0.0 through before 5.0.6 (semver); 4.12",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged user to execute commands as the LXD daemon on the LXD server via API calls to the image and backup endpoints. This issue affected LXD from 4.12 through 6.6 and was fixed in the snap versions 5.0.6-e49d9f4 (channel 5.0/stable), 5.21.4-1374f39 (channel 5.21/stable), and 6.7-1f11451 (channel 6.0 stable). The channel 4.0/stable is not affected as it contains version 4.0.10.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://discourse.ubuntu.com/t/lxd-authenticated-remote-code-execution-fixes-available/78365",
                "https://github.com/canonical/lxd/commit/043696a13171ace7dd4c2b32d34ce039ab629052",
                "https://github.com/canonical/lxd/commit/7046979645c2ce1b63b2f9e60ddf6cbc4c4b78f9",
                "https://github.com/canonical/lxd/commit/b7b411caf5c4971bfe2386c72128f44d7e2aaf4f",
                "https://github.com/canonical/lxd/security/advisories/GHSA-4rmf-rcp8-2r9g"
            ],
            "timeline": [
                {
                    "at": "2026-03-12T15:16:27.247",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28384"
                }
            ]
        },
        {
            "id": "CVE-2026-28265",
            "vendor": "Dell",
            "product": "PowerStore",
            "title": "PowerStore vulnerability",
            "summary": "PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.",
            "updated_at": "2026-09-11T13:30:54.337",
            "published_at": "2026-04-01T08:16:05.490",
            "cvss": 4.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.4.0.0-2692403 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-35",
            "what_happened": "PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000444169/dsa-2026-157-dell-powerstore-t-security-update-for-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2026-04-01T08:16:05.490",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-28265"
                }
            ]
        },
        {
            "id": "CVE-2026-27962",
            "vendor": "authlib",
            "product": "authlib",
            "title": "authlib vulnerability",
            "summary": "Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to any JWS deserialization function, the library extracts and uses the cryptographic key embedded in the attacker-controlled JWT jwk header field. An attacker can sign a token with their own private key, embed the matching public key in the header, and have the server accept the forged token as cryptographically valid — bypassing authentication and authorization entirely. This issue has been patched in version 1.6.9.",
            "updated_at": "2026-09-10T13:18:01.463",
            "published_at": "2026-03-16T18:16:07.383",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 1.6.9",
            "fixed": "See vendor advisory",
            "source_count": 36,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-347",
            "what_happened": "Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to any JWS deserialization function, the library extracts and uses the cryptographic key embedded in the attacker-controlled JWT jwk header field. An attacker can sign a token with their own private key, embed the matching public key in the header, and have the server accept the forged token as cryptographically valid — bypassing authentication and authorization entirely. This issue has been patched in version 1.6.9.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-16",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/authlib/authlib/security/advisories/GHSA-wvwj-cvrp-7pv5"
                }
            ],
            "references": [
                "https://github.com/authlib/authlib/commit/a5d4b2d4c9e46bfa11c82f85fdc2bcc0b50ae681",
                "https://github.com/authlib/authlib/releases/tag/v1.6.9",
                "https://github.com/authlib/authlib/security/advisories/GHSA-wvwj-cvrp-7pv5",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:48085",
                "https://access.redhat.com/errata/RHSA-2026:5665",
                "https://access.redhat.com/errata/RHSA-2026:7314",
                "https://access.redhat.com/security/cve/CVE-2026-27962",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2448164",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27962.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-16T18:16:07.383",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27962"
                }
            ]
        },
        {
            "id": "CVE-2026-27912",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "POC tool for ResetNightmare (CVE-2026-27912)",
            "summary": "POC tool for ResetNightmare (CVE-2026-27912)",
            "updated_at": "2026-08-26T09:08:08Z",
            "published_at": "2026-08-26T09:08:08Z",
            "cvss": 8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 280,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · Semperis-Community/ResetNightmare",
                    "author": "Semperis-Community",
                    "first_seen": "2026-08-02",
                    "last_seen": "2026-08-26T09:08:08Z",
                    "pushed_at": "2026-08-20T16:44:53Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "PowerShell",
                    "stars": 208,
                    "forks": 37,
                    "topics": [],
                    "title": "POC tool for ResetNightmare (CVE-2026-27912)",
                    "repository_description": "POC tool for ResetNightmare (CVE-2026-27912)",
                    "summary": "POC tool for ResetNightmare (CVE-2026-27912)",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Semperis-Community/ResetNightmare",
                    "cvss": 8,
                    "severity": "HIGH",
                    "cve_description": "Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.",
                    "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-285",
                    "kev": false,
                    "epss": 0.00409,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-04-14",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · oxstussz-eng/Kerberos-CVE-2026-27912",
                    "author": "oxstussz-eng",
                    "first_seen": "2026-08-14",
                    "last_seen": "2026-08-23T09:44:49Z",
                    "pushed_at": "2026-08-14T15:07:53Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "Python",
                    "stars": 2,
                    "forks": 0,
                    "topics": [],
                    "title": "PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security research only.",
                    "repository_description": "PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security research only.",
                    "summary": "PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security research only.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/oxstussz-eng/Kerberos-CVE-2026-27912",
                    "cvss": 8,
                    "severity": "HIGH",
                    "cve_description": "Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.",
                    "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-285",
                    "kev": false,
                    "epss": 0.00409,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-04-14",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · mihat2/ResetNightmare-impacket",
                    "author": "mihat2",
                    "first_seen": "2026-08-08",
                    "last_seen": "2026-08-20T10:17:39Z",
                    "pushed_at": "2026-08-11T18:15:39Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "Python",
                    "stars": 4,
                    "forks": 4,
                    "topics": [
                        "active-directory",
                        "active-directory-security",
                        "cve",
                        "cve-2026-27912",
                        "impacket",
                        "kadmin-changepw",
                        "kerberos",
                        "ldap"
                    ],
                    "title": "CVE-2026-27912 (ResetNightmare) — Linux/impacket port of Semperis Community's Invoke-ResetNightmare PoC",
                    "repository_description": "CVE-2026-27912 (ResetNightmare) — Linux/impacket port of Semperis Community's Invoke-ResetNightmare PoC",
                    "summary": "CVE-2026-27912 (ResetNightmare) — Linux/impacket port of Semperis Community's Invoke-ResetNightmare PoC",
                    "source": "CVE-Intel",
                    "url": "https://github.com/mihat2/ResetNightmare-impacket",
                    "cvss": 8,
                    "severity": "HIGH",
                    "cve_description": "Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.",
                    "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-285",
                    "kev": false,
                    "epss": 0.00409,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-04-14",
                    "cve_status": "Analyzed"
                }
            ],
            "references": [
                "https://github.com/Semperis-Community/ResetNightmare",
                "https://github.com/oxstussz-eng/Kerberos-CVE-2026-27912",
                "https://github.com/mihat2/ResetNightmare-impacket"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T09:08:08Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/Semperis-Community/ResetNightmare"
                }
            ],
            "epss": 0.00409,
            "severity": "HIGH",
            "metadata_source": "NIST",
            "cve_status": "Analyzed",
            "cve_published_at": "2026-04-14",
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-27889",
            "vendor": "nats-io",
            "product": "nats-server",
            "title": "nats-server vulnerability",
            "summary": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic in the nats-server.  This happens before authentication, and so is exposed to anyone who can connect to the websockets port. Versions 2.11.14 and 2.12.5 contains a fix. A workaround is available. The vulnerability only affects deployments which use WebSockets and which expose the network port to untrusted end-points. If one is able to do so, a defense in depth of restricting either of these will mitigate the attack.",
            "updated_at": "2026-09-07T13:18:35.750",
            "published_at": "2026-03-25T20:16:27.210",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 2.2.0, < 2.11.14; >= 2.12.0, < 2.12.5",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic in the nats-server.  This happens before authentication, and so is exposed to anyone who can connect to the websockets port. Versions 2.11.14 and 2.12.5 contains a fix. A workaround is available. The vulnerability only affects deployments which use WebSockets and which expose the network port to untrusted end-points. If one is able to do so, a defense in depth of restricting either of these will mitigate the attack.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://advisories.nats.io/CVE/secnote-2026-03.txt",
                "https://github.com/nats-io/nats-server/security/advisories/GHSA-pq2q-rcw4-3hr6",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/security/cve/CVE-2026-27889",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451447",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27889.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-25T20:16:27.210",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27889"
                }
            ]
        },
        {
            "id": "CVE-2026-27830",
            "vendor": "swaldman",
            "product": "c3p0",
            "title": "c3p0 vulnerability",
            "summary": "c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map<String,Map<String,String>>`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execute unexpected code on the application's `CLASSPATH`. The danger of this vulnerability was strongly magnified by vulnerabilities in c3p0's main dependency, mchange-commons-java. This library includes code that mirrors early implementations of JNDI functionality, including ungated support for remote `factoryClassLocation` values. Attackers could set c3p0's `userOverridesAsString` hex-encoded serialized objects that include objects \"indirectly serialized\" via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke download and execution of malicious code from a remote `factoryClassLocation`. Although hazard presented by c3p0's vulnerabilites are exarcerbated by vulnerabilities in mchange-commons-java, use of Java-serialized-object hex as the format for a writable Java-Bean property, of objects that may be exposed across JNDI interfaces, represents a serious independent fragility. The `userOverridesAsString` property of c3p0 `ConnectionPoolDataSource` classes has been reimplemented to use a safe CSV-based format, rather than rely upon potentially dangerous Java object deserialization. c3p0-0.12.0+ and above depend upon mchange-commons-java 0.4.0+, which gates support for remote `factoryClassLocation` values by configuration parameters that default to restrictive values. c3p0 additionally enforces the new mchange-commons-java `com.mchange.v2.naming.nameGuardClassName` to prevent injection of unexpected, potentially remote JNDI names. There is no supported workaround for versions of c3p0 prior to 0.12.0.",
            "updated_at": "2026-09-14T13:17:54.607",
            "published_at": "2026-02-26T01:16:24.583",
            "cvss": 8.9,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 0.12.0",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `javax.naming.Reference` instances. Several c3p0 `ConnectionPoolDataSource` implementations have a property called `userOverridesAsString` which conceptually represents a `Map<String,Map<String,String>>`. Prior to v0.12.0, that property was maintained as a hex-encoded serialized object. Any attacker able to reset this property, on an existing `ConnectionPoolDataSource` or via maliciously crafted serialized objects or `javax.naming.Reference` instances could be tailored execute unexpected code on the application's `CLASSPATH`. The danger of this vulnerability was strongly magnified by vulnerabilities in c3p0's main dependency, mchange-commons-java. This library includes code that mirrors early implementations of JNDI functionality, including ungated support for remote `factoryClassLocation` values. Attackers could set c3p0's `userOverridesAsString` hex-encoded serialized objects that include objects \"indirectly serialized\" via JNDI references. Deserialization of those objects and dereferencing of the embedded `javax.naming.Reference` objects could provoke download and execution of malicious code from a remote `factoryClassLocation`. Although hazard presented by c3p0's vulnerabilites are exarcerbated by vulnerabilities in mchange-commons-java, use of Java-serialized-object hex as the format for a writable Java-Bean property, of objects that may be exposed across JNDI interfaces, represents a serious independent fragility. The `userOverridesAsString` property of c3p0 `ConnectionPoolDataSource` classes has been reimplemented to use a safe CSV-based format, rather than rely upon potentially dangerous Java object deserialization. c3p0-0.12.0+ and above depend upon mchange-commons-java 0.4.0+, which gates support for remote `factoryClassLocation` values by configuration parameters that default to restrictive values. c3p0 additionally enforces the new mchange-commons-java `com.mchange.v2.naming.nameGuardClassName` to prevent injection of unexpected, potentially remote JNDI names. There is no supported workaround for versions of c3p0 prior to 0.12.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/swaldman/c3p0/commit/e14cbd8166e423e2e9a9d6f08b2add3433492d6e",
                "https://github.com/swaldman/c3p0/security/advisories/GHSA-5476-xc4j-rqcv",
                "https://mogwailabs.de/en/blog/2025/02/c3p0-you-little-rascal",
                "https://www.mchange.com/projects/c3p0/#configuring_security",
                "https://www.mchange.com/projects/c3p0/#security-note",
                "https://access.redhat.com/errata/RHSA-2026:18054",
                "https://access.redhat.com/errata/RHSA-2026:18055",
                "https://access.redhat.com/errata/RHSA-2026:18059",
                "https://access.redhat.com/errata/RHSA-2026:28385",
                "https://access.redhat.com/errata/RHSA-2026:3890",
                "https://access.redhat.com/errata/RHSA-2026:4285",
                "https://access.redhat.com/security/cve/CVE-2026-27830",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2442908",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27830.json"
            ],
            "timeline": [
                {
                    "at": "2026-02-26T01:16:24.583",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27830"
                }
            ]
        },
        {
            "id": "CVE-2026-27690",
            "vendor": "SAP_SE",
            "product": "SAP Approuter",
            "title": "SAP Approuter vulnerability",
            "summary": "Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.",
            "updated_at": "2026-09-08T20:22:05.330",
            "published_at": "2026-07-14T01:16:17.193",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "SAP Approuter node.js package < 20.10.0",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-444",
            "what_happened": "Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://me.sap.com/notes/3720138",
                "https://url.sap/sapsecuritypatchday"
            ],
            "timeline": [
                {
                    "at": "2026-07-14T01:16:17.193",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27690"
                }
            ]
        },
        {
            "id": "CVE-2026-27641",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-27641-Flask-Reuploaded exploit",
            "summary": "Exploit for CVE-2026-27641. CVSS 9.8.",
            "updated_at": "2026-09-06T08:25:17Z",
            "published_at": "2026-09-06T08:25:17Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-06T08:25:17+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2026-27641-Flask-Reuploaded exploit",
                    "summary": "Exploit for CVE-2026-27641. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MAX78000-CVE-2026-27641-FLASK-REUPLOADED"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MAX78000-CVE-2026-27641-FLASK-REUPLOADED"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:25:17Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MAX78000-CVE-2026-27641-FLASK-REUPLOADED"
                }
            ]
        },
        {
            "id": "CVE-2026-27606",
            "vendor": "rollup",
            "product": "rollup",
            "title": "rollup vulnerability",
            "summary": "Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine allows an attacker to control output filenames (e.g., via CLI named inputs, manual chunk aliases, or malicious plugins) and use traversal sequences (`../`) to overwrite files anywhere on the host filesystem that the build process has permissions for. This can lead to persistent Remote Code Execution (RCE) by overwriting critical system or user configuration files. Versions 2.80.0, 3.30.0, and 4.59.0 contain a patch for the issue.",
            "updated_at": "2026-09-10T13:18:01.097",
            "published_at": "2026-02-25T03:16:04.603",
            "cvss": 8.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 2.80.0; >= 3.0.0, < 3.30.0; >= 4.0.0, < 4.59.0",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine allows an attacker to control output filenames (e.g., via CLI named inputs, manual chunk aliases, or malicious plugins) and use traversal sequences (`../`) to overwrite files anywhere on the host filesystem that the build process has permissions for. This can lead to persistent Remote Code Execution (RCE) by overwriting critical system or user configuration files. Versions 2.80.0, 3.30.0, and 4.59.0 contain a patch for the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-02-25",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/rollup/rollup/security/advisories/GHSA-mw96-cpmx-2vgc"
                }
            ],
            "references": [
                "https://github.com/rollup/rollup/commit/c60770d7aaf750e512c1b2774989ea4596e660b2",
                "https://github.com/rollup/rollup/commit/c8cf1f9c48c516285758c1e11f08a54f304fd44e",
                "https://github.com/rollup/rollup/commit/d6dee5e99bb82aac0bee1df4ab9efbde455452c3",
                "https://github.com/rollup/rollup/releases/tag/v2.80.0",
                "https://github.com/rollup/rollup/releases/tag/v3.30.0",
                "https://github.com/rollup/rollup/releases/tag/v4.59.0",
                "https://github.com/rollup/rollup/security/advisories/GHSA-mw96-cpmx-2vgc",
                "https://access.redhat.com/errata/RHSA-2026:10175",
                "https://access.redhat.com/errata/RHSA-2026:13508",
                "https://access.redhat.com/errata/RHSA-2026:13512",
                "https://access.redhat.com/errata/RHSA-2026:13545",
                "https://access.redhat.com/errata/RHSA-2026:5132",
                "https://access.redhat.com/errata/RHSA-2026:5649",
                "https://access.redhat.com/errata/RHSA-2026:5665",
                "https://access.redhat.com/errata/RHSA-2026:6174",
                "https://access.redhat.com/errata/RHSA-2026:6802",
                "https://access.redhat.com/errata/RHSA-2026:8483",
                "https://access.redhat.com/security/cve/CVE-2026-27606",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2442530",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27606.json"
            ],
            "timeline": [
                {
                    "at": "2026-02-25T03:16:04.603",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27606"
                }
            ]
        },
        {
            "id": "CVE-2026-27483",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "MindsDB  25.9.1.1 - Path Traversal",
            "summary": "MindsDB  25.9.1.1 - Path Traversal",
            "updated_at": "2026-09-12T15:06:19Z",
            "published_at": "2026-09-12T15:06:19Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 66,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Path Traversal RCE in MindsDB 25.9.1.0 enabling remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52547",
                    "author": "thewhiteh4t",
                    "first_seen": "2026-05-04",
                    "confidence": "High",
                    "title": "MindsDB  25.9.1.1 - Path Traversal",
                    "summary": "MindsDB  25.9.1.1 - Path Traversal",
                    "url": "https://www.exploit-db.com/exploits/52547",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for cve-2026-27483-lab CVE-2026-27483",
                    "summary": "Path Traversal RCE in MindsDB 25.9.1.0 enabling remote code execution.",
                    "what_happened": "Path Traversal RCE in MindsDB 25.9.1.0 enabling remote code execution.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NABHAN-MOHY-CVE-2026-27483-LAB",
                        "https://kitploit.com/ru/tools/github/nabhan-mohy/cve-2026-27483-lab/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T22:35:21",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NABHAN-MOHY-CVE-2026-27483-LAB"
                },
                {
                    "title": "Exploit for cve-2026-27483-lab CVE-2026-27483",
                    "summary": "Path Traversal RCE in MindsDB 25.9.1.0 enabling remote code execution.",
                    "what_happened": "Path Traversal RCE in MindsDB 25.9.1.0 enabling remote code execution.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NABHAN-MOHY-CVE-2026-27483-LAB",
                        "https://kitploit.com/ru/tools/github/nabhan-mohy/cve-2026-27483-lab/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T22:35:21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/nabhan-mohy/cve-2026-27483-lab/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52547",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NABHAN-MOHY-CVE-2026-27483-LAB",
                "https://kitploit.com/ru/tools/github/nabhan-mohy/cve-2026-27483-lab/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T15:06:19Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52547"
                }
            ]
        },
        {
            "id": "CVE-2026-27459",
            "vendor": "pyca",
            "product": "pyopenssl",
            "title": "pyopenssl vulnerability",
            "summary": "pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.",
            "updated_at": "2026-09-10T13:17:59.900",
            "published_at": "2026-03-18T00:16:19.273",
            "cvss": 7.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 22.0.0, < 26.0.0",
            "fixed": "See vendor advisory",
            "source_count": 26,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-120",
            "what_happened": "pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow an OpenSSL provided buffer. Starting in version 26.0.0, cookie values that are too long are now rejected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pyca/pyopenssl/blob/358cbf29c4e364c59930e53a270116249581eaa3/CHANGELOG.rst",
                "https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408",
                "https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4",
                "https://access.redhat.com/errata/RHSA-2026:10754",
                "https://access.redhat.com/errata/RHSA-2026:11856",
                "https://access.redhat.com/errata/RHSA-2026:11916",
                "https://access.redhat.com/errata/RHSA-2026:11996",
                "https://access.redhat.com/errata/RHSA-2026:13508",
                "https://access.redhat.com/errata/RHSA-2026:13512",
                "https://access.redhat.com/errata/RHSA-2026:13545",
                "https://access.redhat.com/errata/RHSA-2026:13553",
                "https://access.redhat.com/errata/RHSA-2026:14835",
                "https://access.redhat.com/errata/RHSA-2026:14873",
                "https://access.redhat.com/errata/RHSA-2026:14874",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:48085",
                "https://access.redhat.com/errata/RHSA-2026:48758",
                "https://access.redhat.com/errata/RHSA-2026:59153",
                "https://access.redhat.com/errata/RHSA-2026:7224",
                "https://access.redhat.com/errata/RHSA-2026:8437",
                "https://access.redhat.com/security/cve/CVE-2026-27459",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2448503",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27459.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-18T00:16:19.273",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27459"
                }
            ]
        },
        {
            "id": "CVE-2026-27446",
            "vendor": "Apache Software Foundation",
            "product": "Apache Artemis",
            "title": "Apache Artemis vulnerability",
            "summary": "Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This could potentially result in message injection into any queue and/or message exfiltration from any queue via the rogue broker. This impacts environments that allow both:\n\n- incoming Core protocol connections from untrusted sources to the broker\n\n- outgoing Core protocol connections from the broker to untrusted targets\n\nThis issue affects:\n\n- Apache Artemis from 2.50.0 through 2.51.0\n\n- Apache ActiveMQ Artemis from 2.11.0 through 2.44.0.\n\nUsers are recommended to upgrade to Apache Artemis version 2.52.0, which fixes the issue.\n\nThe issue can be mitigated by one of the following:\n\n- Remove Core protocol support from any acceptor receiving connections from untrusted sources. Incoming Core protocol connections are supported by default via the \"artemis\" acceptor listening on port 61616. See the \"protocols\" URL parameter configured for the acceptor. An acceptor URL without this parameter supports all protocols by default, including Core.\n\n- Use two-way SSL (i.e. certificate-based authentication) in order to force every client to present the proper SSL certificate when establishing a connection before any message protocol handshake is attempted. This will prevent unauthenticated exploitation of this vulnerability.\n\n- Implement and deploy a Core interceptor to deny all Core downstream federation connect packets. Such packets have a type of (int) -16 or (byte) 0xfffffff0. Documentation for interceptors is available at  https://artemis.apache.org/components/artemis/documentation/latest/intercepting-operations.html .",
            "updated_at": "2026-09-14T13:17:52.790",
            "published_at": "2026-03-04T09:15:56.837",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.50.0 through 2.51.0 (semver); 2.11.0 through 2.44.0 (semver); before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker. This could potentially result in message injection into any queue and/or message exfiltration from any queue via the rogue broker. This impacts environments that allow both:\n\n- incoming Core protocol connections from untrusted sources to the broker\n\n- outgoing Core protocol connections from the broker to untrusted targets\n\nThis issue affects:\n\n- Apache Artemis from 2.50.0 through 2.51.0\n\n- Apache ActiveMQ Artemis from 2.11.0 through 2.44.0.\n\nUsers are recommended to upgrade to Apache Artemis version 2.52.0, which fixes the issue.\n\nThe issue can be mitigated by one of the following:\n\n- Remove Core protocol support from any acceptor receiving connections from untrusted sources. Incoming Core protocol connections are supported by default via the \"artemis\" acceptor listening on port 61616. See the \"protocols\" URL parameter configured for the acceptor. An acceptor URL without this parameter supports all protocols by default, including Core.\n\n- Use two-way SSL (i.e. certificate-based authentication) in order to force every client to present the proper SSL certificate when establishing a connection before any message protocol handshake is attempted. This will prevent unauthenticated exploitation of this vulnerability.\n\n- Implement and deploy a Core interceptor to deny all Core downstream federation connect packets. Such packets have a type of (int) -16 or (byte) 0xfffffff0. Documentation for interceptors is available at  https://artemis.apache.org/components/artemis/documentation/latest/intercepting-operations.html .",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://lists.apache.org/thread/jwpsdc8tdxotm98od8n8n30fqlzoc8gg",
                "http://www.openwall.com/lists/oss-security/2026/03/03/4",
                "http://www.openwall.com/lists/oss-security/2026/03/04/1",
                "https://access.redhat.com/errata/RHSA-2026:17668",
                "https://access.redhat.com/errata/RHSA-2026:18054",
                "https://access.redhat.com/errata/RHSA-2026:18055",
                "https://access.redhat.com/errata/RHSA-2026:18059",
                "https://access.redhat.com/errata/RHSA-2026:3955",
                "https://access.redhat.com/errata/RHSA-2026:3957",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/security/cve/CVE-2026-27446",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2444320",
                "https://cert-portal.siemens.com/productcert/html/ssa-085541.html",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27446.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-04T09:15:56.837",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27446"
                }
            ]
        },
        {
            "id": "CVE-2026-27258",
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service",
            "title": "Adobe Experience Manager as a Cloud Service vulnerability",
            "summary": "Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.",
            "updated_at": "2026-09-08T20:17:32.480",
            "published_at": "2026-04-14T18:16:56.247",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2026.7.0 (custom); 0 through SP2 (custom); 0 through 6.5.24 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html"
            ],
            "timeline": [
                {
                    "at": "2026-04-14T18:16:56.247",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27258"
                }
            ]
        },
        {
            "id": "CVE-2026-27238",
            "vendor": "Adobe",
            "product": "InDesign Desktop",
            "title": "InDesign Desktop vulnerability",
            "summary": "InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "updated_at": "2026-09-16T18:17:08.797",
            "published_at": "2026-04-14T17:16:47.717",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 21.2 (semver); 0 through 20.5.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html",
                "https://helpx.adobe.com/security/products/indesign/apsb26-32.html"
            ],
            "timeline": [
                {
                    "at": "2026-04-14T17:16:47.717",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27238"
                }
            ]
        },
        {
            "id": "CVE-2026-27222",
            "vendor": "Adobe",
            "product": "Adobe Experience Manager as a Cloud Service",
            "title": "Adobe Experience Manager as a Cloud Service vulnerability",
            "summary": "Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.",
            "updated_at": "2026-09-08T20:17:31.397",
            "published_at": "2026-04-14T20:16:32.927",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2026.7.0 (custom); 0 through SP2 (custom); 0 through 6.5.24 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://helpx.adobe.com/security/products/experience-manager/apsb26-98.html"
            ],
            "timeline": [
                {
                    "at": "2026-04-14T20:16:32.927",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27222"
                }
            ]
        },
        {
            "id": "CVE-2026-27145",
            "vendor": "Go standard library",
            "product": "crypto/x509",
            "title": "crypto/x509 vulnerability",
            "summary": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.",
            "updated_at": "2026-09-11T13:17:23.340",
            "published_at": "2026-06-02T23:16:35.570",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.25.11 (semver); 1.26.0-0 through before 1.26.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 98,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-606",
            "what_happened": "(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, \".\") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadratically based on the number of SAN entries multiplied by the hostname's label count. Because x509.Verify validates hostnames before building the certificate chain, this overhead occurred even for untrusted certificates.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/783621",
                "https://go.dev/issue/79694",
                "https://groups.google.com/g/golang-announce/c/tKs3rmcBcKw",
                "https://pkg.go.dev/vuln/GO-2026-5037",
                "https://access.redhat.com/errata/RHSA-2026:23262",
                "https://access.redhat.com/errata/RHSA-2026:23264",
                "https://access.redhat.com/errata/RHSA-2026:29980",
                "https://access.redhat.com/errata/RHSA-2026:29981",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:34357",
                "https://access.redhat.com/errata/RHSA-2026:34359",
                "https://access.redhat.com/errata/RHSA-2026:35832",
                "https://access.redhat.com/errata/RHSA-2026:36317",
                "https://access.redhat.com/errata/RHSA-2026:36648",
                "https://access.redhat.com/errata/RHSA-2026:36797",
                "https://access.redhat.com/errata/RHSA-2026:38995",
                "https://access.redhat.com/errata/RHSA-2026:39005",
                "https://access.redhat.com/errata/RHSA-2026:39573",
                "https://access.redhat.com/errata/RHSA-2026:39879",
                "https://access.redhat.com/errata/RHSA-2026:41030",
                "https://access.redhat.com/errata/RHSA-2026:41036",
                "https://access.redhat.com/errata/RHSA-2026:41930",
                "https://access.redhat.com/errata/RHSA-2026:42043",
                "https://access.redhat.com/errata/RHSA-2026:42047",
                "https://access.redhat.com/errata/RHSA-2026:42049",
                "https://access.redhat.com/errata/RHSA-2026:42050",
                "https://access.redhat.com/errata/RHSA-2026:42051",
                "https://access.redhat.com/errata/RHSA-2026:42079",
                "https://access.redhat.com/errata/RHSA-2026:42080",
                "https://access.redhat.com/errata/RHSA-2026:42082",
                "https://access.redhat.com/errata/RHSA-2026:42142",
                "https://access.redhat.com/errata/RHSA-2026:42150",
                "https://access.redhat.com/errata/RHSA-2026:42151",
                "https://access.redhat.com/errata/RHSA-2026:42240",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:42946",
                "https://access.redhat.com/errata/RHSA-2026:44622",
                "https://access.redhat.com/errata/RHSA-2026:46394",
                "https://access.redhat.com/errata/RHSA-2026:46395",
                "https://access.redhat.com/errata/RHSA-2026:47149",
                "https://access.redhat.com/errata/RHSA-2026:47735",
                "https://access.redhat.com/errata/RHSA-2026:47737",
                "https://access.redhat.com/errata/RHSA-2026:49702",
                "https://access.redhat.com/errata/RHSA-2026:49703",
                "https://access.redhat.com/errata/RHSA-2026:49705",
                "https://access.redhat.com/errata/RHSA-2026:49712",
                "https://access.redhat.com/errata/RHSA-2026:49729",
                "https://access.redhat.com/errata/RHSA-2026:49744",
                "https://access.redhat.com/errata/RHSA-2026:49765",
                "https://access.redhat.com/errata/RHSA-2026:49770",
                "https://access.redhat.com/errata/RHSA-2026:50205",
                "https://access.redhat.com/errata/RHSA-2026:50319",
                "https://access.redhat.com/errata/RHSA-2026:51057",
                "https://access.redhat.com/errata/RHSA-2026:51187",
                "https://access.redhat.com/errata/RHSA-2026:52946",
                "https://access.redhat.com/errata/RHSA-2026:53374",
                "https://access.redhat.com/errata/RHSA-2026:53412",
                "https://access.redhat.com/errata/RHSA-2026:53413",
                "https://access.redhat.com/errata/RHSA-2026:53415",
                "https://access.redhat.com/errata/RHSA-2026:53416",
                "https://access.redhat.com/errata/RHSA-2026:53530",
                "https://access.redhat.com/errata/RHSA-2026:54168",
                "https://access.redhat.com/errata/RHSA-2026:54401",
                "https://access.redhat.com/errata/RHSA-2026:54427",
                "https://access.redhat.com/errata/RHSA-2026:54432",
                "https://access.redhat.com/errata/RHSA-2026:54435",
                "https://access.redhat.com/errata/RHSA-2026:54441",
                "https://access.redhat.com/errata/RHSA-2026:54500",
                "https://access.redhat.com/errata/RHSA-2026:54525",
                "https://access.redhat.com/errata/RHSA-2026:54531",
                "https://access.redhat.com/errata/RHSA-2026:54603",
                "https://access.redhat.com/errata/RHSA-2026:54757",
                "https://access.redhat.com/errata/RHSA-2026:55899",
                "https://access.redhat.com/errata/RHSA-2026:57194",
                "https://access.redhat.com/errata/RHSA-2026:57482",
                "https://access.redhat.com/errata/RHSA-2026:57488",
                "https://access.redhat.com/errata/RHSA-2026:57649",
                "https://access.redhat.com/errata/RHSA-2026:59556",
                "https://access.redhat.com/errata/RHSA-2026:59557",
                "https://access.redhat.com/errata/RHSA-2026:59558",
                "https://access.redhat.com/errata/RHSA-2026:59559",
                "https://access.redhat.com/errata/RHSA-2026:59579",
                "https://access.redhat.com/errata/RHSA-2026:59593",
                "https://access.redhat.com/errata/RHSA-2026:60025",
                "https://access.redhat.com/errata/RHSA-2026:60315",
                "https://access.redhat.com/errata/RHSA-2026:60354",
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/errata/RHSA-2026:60387",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/errata/RHSA-2026:60390",
                "https://access.redhat.com/errata/RHSA-2026:60391",
                "https://access.redhat.com/errata/RHSA-2026:61253",
                "https://access.redhat.com/errata/RHSA-2026:61314",
                "https://access.redhat.com/errata/RHSA-2026:63016",
                "https://access.redhat.com/errata/RHSA-2026:66022",
                "https://access.redhat.com/security/cve/CVE-2026-27145",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2484207",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27145.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-02T23:16:35.570",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27145"
                }
            ]
        },
        {
            "id": "CVE-2026-27140",
            "vendor": "Go toolchain",
            "product": "cmd/go",
            "title": "cmd/go vulnerability",
            "summary": "SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.",
            "updated_at": "2026-09-10T13:17:57.537",
            "published_at": "2026-04-08T02:16:02.887",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.25.9 (semver); 1.26.0-0 through before 1.26.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 24,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/763768",
                "https://go.dev/issue/78335",
                "https://groups.google.com/g/golang-announce/c/0uYbvbPZRWU",
                "https://pkg.go.dev/vuln/GO-2026-4871",
                "https://access.redhat.com/errata/RHSA-2026:10217",
                "https://access.redhat.com/errata/RHSA-2026:10219",
                "https://access.redhat.com/errata/RHSA-2026:10704",
                "https://access.redhat.com/errata/RHSA-2026:16021",
                "https://access.redhat.com/errata/RHSA-2026:16024",
                "https://access.redhat.com/errata/RHSA-2026:16494",
                "https://access.redhat.com/errata/RHSA-2026:16497",
                "https://access.redhat.com/errata/RHSA-2026:16498",
                "https://access.redhat.com/errata/RHSA-2026:16694",
                "https://access.redhat.com/errata/RHSA-2026:16697",
                "https://access.redhat.com/errata/RHSA-2026:16698",
                "https://access.redhat.com/errata/RHSA-2026:23246",
                "https://access.redhat.com/errata/RHSA-2026:25182",
                "https://access.redhat.com/errata/RHSA-2026:34099",
                "https://access.redhat.com/errata/RHSA-2026:56854",
                "https://access.redhat.com/errata/RHSA-2026:57408",
                "https://access.redhat.com/errata/RHSA-2026:57545",
                "https://access.redhat.com/security/cve/CVE-2026-27140",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2456341",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27140.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-08T02:16:02.887",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27140"
                }
            ]
        },
        {
            "id": "CVE-2026-27137",
            "vendor": "Go standard library",
            "product": "crypto/x509",
            "title": "crypto/x509 vulnerability",
            "summary": "When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.",
            "updated_at": "2026-09-16T13:17:27.477",
            "published_at": "2026-03-06T22:16:00.850",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.26.0-0 through before 1.26.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 67,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/752182",
                "https://go.dev/issue/77952",
                "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk",
                "https://pkg.go.dev/vuln/GO-2026-4599",
                "https://access.redhat.com/errata/RHSA-2026:10125",
                "https://access.redhat.com/errata/RHSA-2026:10158",
                "https://access.redhat.com/errata/RHSA-2026:10169",
                "https://access.redhat.com/errata/RHSA-2026:10175",
                "https://access.redhat.com/errata/RHSA-2026:10184",
                "https://access.redhat.com/errata/RHSA-2026:10225",
                "https://access.redhat.com/errata/RHSA-2026:10250",
                "https://access.redhat.com/errata/RHSA-2026:10929",
                "https://access.redhat.com/errata/RHSA-2026:11800",
                "https://access.redhat.com/errata/RHSA-2026:13545",
                "https://access.redhat.com/errata/RHSA-2026:14879",
                "https://access.redhat.com/errata/RHSA-2026:19022",
                "https://access.redhat.com/errata/RHSA-2026:19049",
                "https://access.redhat.com/errata/RHSA-2026:19132",
                "https://access.redhat.com/errata/RHSA-2026:19181",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:22450",
                "https://access.redhat.com/errata/RHSA-2026:22714",
                "https://access.redhat.com/errata/RHSA-2026:22862",
                "https://access.redhat.com/errata/RHSA-2026:22937",
                "https://access.redhat.com/errata/RHSA-2026:23228",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:26568",
                "https://access.redhat.com/errata/RHSA-2026:26585",
                "https://access.redhat.com/errata/RHSA-2026:28038",
                "https://access.redhat.com/errata/RHSA-2026:28047",
                "https://access.redhat.com/errata/RHSA-2026:29854",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:39810",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:49702",
                "https://access.redhat.com/errata/RHSA-2026:49703",
                "https://access.redhat.com/errata/RHSA-2026:49712",
                "https://access.redhat.com/errata/RHSA-2026:5110",
                "https://access.redhat.com/errata/RHSA-2026:54757",
                "https://access.redhat.com/errata/RHSA-2026:5549",
                "https://access.redhat.com/errata/RHSA-2026:56143",
                "https://access.redhat.com/errata/RHSA-2026:56223",
                "https://access.redhat.com/errata/RHSA-2026:57649",
                "https://access.redhat.com/errata/RHSA-2026:61253",
                "https://access.redhat.com/errata/RHSA-2026:7291",
                "https://access.redhat.com/errata/RHSA-2026:8151",
                "https://access.redhat.com/errata/RHSA-2026:8167",
                "https://access.redhat.com/errata/RHSA-2026:8337",
                "https://access.redhat.com/errata/RHSA-2026:8338",
                "https://access.redhat.com/errata/RHSA-2026:8842",
                "https://access.redhat.com/errata/RHSA-2026:9052",
                "https://access.redhat.com/errata/RHSA-2026:9385",
                "https://access.redhat.com/errata/RHSA-2026:9697",
                "https://access.redhat.com/errata/RHSA-2026:9698",
                "https://access.redhat.com/errata/RHSA-2026:9699",
                "https://access.redhat.com/errata/RHSA-2026:9872",
                "https://access.redhat.com/security/cve/CVE-2026-27137",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2445345",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27137.json",
                "https://access.redhat.com/errata/RHSA-2026:67159",
                "https://access.redhat.com/errata/RHSA-2026:67160",
                "https://access.redhat.com/errata/RHSA-2026:67517",
                "https://access.redhat.com/errata/RHSA-2026:67518"
            ],
            "timeline": [
                {
                    "at": "2026-03-06T22:16:00.850",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-27137"
                }
            ]
        },
        {
            "id": "CVE-2026-27119",
            "vendor": "ExampleCMS",
            "product": "ExampleCMS",
            "title": "ExampleCMS unrestricted file upload",
            "summary": "An authenticated content editor can upload a file type outside the intended media policy.",
            "updated_at": "2026-09-01T08:59:00Z",
            "published_at": "2026-08-31T16:00:00Z",
            "cvss": 7.5,
            "confidence": 59,
            "confidence_label": "observed",
            "affected": "≤ 2.6.3",
            "fixed": "2.6.4",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Remote",
            "authentication": "Required",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "The media upload workflow relies on an incomplete file-type validation sequence for authenticated editors.",
            "why_matters": "Content-management systems frequently expose uploaded content through the web tier, increasing the impact of policy bypasses.",
            "mitigations": [
                "Upgrade to ExampleCMS 2.6.4.",
                "Restrict editor roles.",
                "Store uploaded files outside executable web paths."
            ],
            "pocs": [],
            "references": []
        },
        {
            "id": "CVE-2026-26278",
            "vendor": "NaturalIntelligence",
            "product": "fast-xml-parser",
            "title": "fast-xml-parser vulnerability",
            "summary": "fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application. Version 5.3.6 fixes the issue. As a workaround, avoid using DOCTYPE parsing by `processEntities: false` option.",
            "updated_at": "2026-09-10T13:17:56.203",
            "published_at": "2026-02-19T20:25:43.717",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 5.0.0, < 5.3.6; >= 4.1.3, < 4.5.4",
            "fixed": "See vendor advisory",
            "source_count": 39,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-776",
            "what_happened": "fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to do an unlimited amount of entity expansion. With a very small XML input, it’s possible to make the parser spend seconds or even minutes processing a single request, effectively freezing the application. Version 5.3.6 fixes the issue. As a workaround, avoid using DOCTYPE parsing by `processEntities: false` option.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-02-19",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-jmr7-xgp7-cmfj"
                }
            ],
            "references": [
                "https://github.com/NaturalIntelligence/fast-xml-parser/commit/910dae5be2de2955e968558fadf6e8f74f117a77",
                "https://github.com/NaturalIntelligence/fast-xml-parser/releases/tag/v5.3.6",
                "https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-jmr7-xgp7-cmfj",
                "https://access.redhat.com/errata/RHSA-2026:40984",
                "https://access.redhat.com/errata/RHSA-2026:41941",
                "https://access.redhat.com/errata/RHSA-2026:41944",
                "https://access.redhat.com/errata/RHSA-2026:51349",
                "https://access.redhat.com/errata/RHSA-2026:6174",
                "https://access.redhat.com/errata/RHSA-2026:6802",
                "https://access.redhat.com/errata/RHSA-2026:7110",
                "https://access.redhat.com/errata/RHSA-2026:7128",
                "https://access.redhat.com/security/cve/CVE-2026-26278",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2441120",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26278.json"
            ],
            "timeline": [
                {
                    "at": "2026-02-19T20:25:43.717",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26278"
                }
            ]
        },
        {
            "id": "CVE-2026-26007",
            "vendor": "pyca",
            "product": "cryptography",
            "title": "cryptography vulnerability",
            "summary": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.",
            "updated_at": "2026-09-10T13:17:55.693",
            "published_at": "2026-02-10T22:17:00.307",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 46.0.5",
            "fixed": "See vendor advisory",
            "source_count": 26,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-345",
            "what_happened": "cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pyca/cryptography/commit/0eebb9dbb6343d9bc1d91e5a2482ed4e054a6d8c",
                "https://github.com/pyca/cryptography/security/advisories/GHSA-r6ph-v2qm-q3c2",
                "http://www.openwall.com/lists/oss-security/2026/02/10/4",
                "https://access.redhat.com/errata/RHSA-2026:10184",
                "https://access.redhat.com/errata/RHSA-2026:12176",
                "https://access.redhat.com/errata/RHSA-2026:13512",
                "https://access.redhat.com/errata/RHSA-2026:13545",
                "https://access.redhat.com/errata/RHSA-2026:13553",
                "https://access.redhat.com/errata/RHSA-2026:13672",
                "https://access.redhat.com/errata/RHSA-2026:19355",
                "https://access.redhat.com/errata/RHSA-2026:21431",
                "https://access.redhat.com/errata/RHSA-2026:21517",
                "https://access.redhat.com/errata/RHSA-2026:22330",
                "https://access.redhat.com/errata/RHSA-2026:22993",
                "https://access.redhat.com/errata/RHSA-2026:2694",
                "https://access.redhat.com/errata/RHSA-2026:5168",
                "https://access.redhat.com/errata/RHSA-2026:5665",
                "https://access.redhat.com/errata/RHSA-2026:6308",
                "https://access.redhat.com/errata/RHSA-2026:6309",
                "https://access.redhat.com/errata/RHSA-2026:6497",
                "https://access.redhat.com/errata/RHSA-2026:6567",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/errata/RHSA-2026:7295",
                "https://access.redhat.com/security/cve/CVE-2026-26007",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2438762",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26007.json"
            ],
            "timeline": [
                {
                    "at": "2026-02-10T22:17:00.307",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26007"
                }
            ]
        },
        {
            "id": "CVE-2026-25990",
            "vendor": "python-pillow",
            "product": "Pillow",
            "title": "Pillow vulnerability",
            "summary": "Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.",
            "updated_at": "2026-09-10T13:17:55.220",
            "published_at": "2026-02-11T21:16:20.670",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 10.3.0, < 12.1.1",
            "fixed": "See vendor advisory",
            "source_count": 26,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa",
                "https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc",
                "http://www.openwall.com/lists/oss-security/2026/02/12/1",
                "https://access.redhat.com/errata/RHSA-2026:10184",
                "https://access.redhat.com/errata/RHSA-2026:14873",
                "https://access.redhat.com/errata/RHSA-2026:14874",
                "https://access.redhat.com/errata/RHSA-2026:16174",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:28385",
                "https://access.redhat.com/errata/RHSA-2026:3461",
                "https://access.redhat.com/errata/RHSA-2026:3462",
                "https://access.redhat.com/errata/RHSA-2026:4128",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:4942",
                "https://access.redhat.com/errata/RHSA-2026:5168",
                "https://access.redhat.com/errata/RHSA-2026:5665",
                "https://access.redhat.com/errata/RHSA-2026:6277",
                "https://access.redhat.com/errata/RHSA-2026:6278",
                "https://access.redhat.com/errata/RHSA-2026:6308",
                "https://access.redhat.com/errata/RHSA-2026:6309",
                "https://access.redhat.com/errata/RHSA-2026:6497",
                "https://access.redhat.com/errata/RHSA-2026:6567",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/security/cve/CVE-2026-25990",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2439170",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25990.json"
            ],
            "timeline": [
                {
                    "at": "2026-02-11T21:16:20.670",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25990"
                }
            ]
        },
        {
            "id": "CVE-2026-25896",
            "vendor": "NaturalIntelligence",
            "product": "fast-xml-parser",
            "title": "fast-xml-parser vulnerability",
            "summary": "fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&lt;, &gt;, &amp;, &quot;, &apos;) with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.",
            "updated_at": "2026-09-10T13:17:54.697",
            "published_at": "2026-02-20T21:19:27.470",
            "cvss": 9.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 5.0.0, < 5.3.5; >= 4.1.3, < 4.5.4",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-185",
            "what_happened": "fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement, allowing an attacker to shadow built-in XML entities (&lt;, &gt;, &amp;, &quot;, &apos;) with arbitrary values. This bypasses entity encoding and leads to XSS when parsed output is rendered. This vulnerability is fixed in 5.3.5.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-02-20",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-m7jm-9gc2-mpf2"
                }
            ],
            "references": [
                "https://github.com/NaturalIntelligence/fast-xml-parser/commit/943ef0eb1b2d3284e72dd74f44a042ee9f07026e",
                "https://github.com/NaturalIntelligence/fast-xml-parser/commit/ddcd0acf26ddd682cb0dc15a2bd6aa3b96bb1e69",
                "https://github.com/NaturalIntelligence/fast-xml-parser/releases/tag/v5.3.5",
                "https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-m7jm-9gc2-mpf2",
                "https://access.redhat.com/errata/RHSA-2026:40984",
                "https://access.redhat.com/errata/RHSA-2026:41941",
                "https://access.redhat.com/errata/RHSA-2026:41944",
                "https://access.redhat.com/errata/RHSA-2026:51349",
                "https://access.redhat.com/errata/RHSA-2026:6174",
                "https://access.redhat.com/errata/RHSA-2026:6802",
                "https://access.redhat.com/errata/RHSA-2026:7110",
                "https://access.redhat.com/errata/RHSA-2026:7128",
                "https://access.redhat.com/security/cve/CVE-2026-25896",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2441501",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25896.json"
            ],
            "timeline": [
                {
                    "at": "2026-02-20T21:19:27.470",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25896"
                }
            ]
        },
        {
            "id": "CVE-2026-25687",
            "vendor": "Zscaler",
            "product": "Client Connector",
            "title": "Client Connector vulnerability",
            "summary": "A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.",
            "updated_at": "2026-09-15T04:18:03.757",
            "published_at": "2026-09-14T15:17:05.090",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.6 through before 4.6.0.486 (custom); 4.7 through before 4.7.0.350 (custom); 4.8 through before 4.8.0.267 (custom); 4.9 through before 4.9.0.412 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-366",
            "what_happened": "A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T15:17:05.090",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25687"
                }
            ]
        },
        {
            "id": "CVE-2026-25679",
            "vendor": "Go standard library",
            "product": "net/url",
            "title": "net/url vulnerability",
            "summary": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.",
            "updated_at": "2026-09-14T13:17:41.583",
            "published_at": "2026-03-06T22:16:00.720",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.25.8 (semver); 1.26.0-0 through before 1.26.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 260,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-425",
            "what_happened": "url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/752180",
                "https://go.dev/issue/77578",
                "https://groups.google.com/g/golang-announce/c/EdhZqrQ98hk",
                "https://pkg.go.dev/vuln/GO-2026-4601",
                "https://access.redhat.com/errata/RHSA-2026:10065",
                "https://access.redhat.com/errata/RHSA-2026:10125",
                "https://access.redhat.com/errata/RHSA-2026:10133",
                "https://access.redhat.com/errata/RHSA-2026:10140",
                "https://access.redhat.com/errata/RHSA-2026:10141",
                "https://access.redhat.com/errata/RHSA-2026:10158",
                "https://access.redhat.com/errata/RHSA-2026:10169",
                "https://access.redhat.com/errata/RHSA-2026:10175",
                "https://access.redhat.com/errata/RHSA-2026:10184",
                "https://access.redhat.com/errata/RHSA-2026:10225",
                "https://access.redhat.com/errata/RHSA-2026:10250",
                "https://access.redhat.com/errata/RHSA-2026:10701",
                "https://access.redhat.com/errata/RHSA-2026:10712",
                "https://access.redhat.com/errata/RHSA-2026:10929",
                "https://access.redhat.com/errata/RHSA-2026:11217",
                "https://access.redhat.com/errata/RHSA-2026:11375",
                "https://access.redhat.com/errata/RHSA-2026:11412",
                "https://access.redhat.com/errata/RHSA-2026:11413",
                "https://access.redhat.com/errata/RHSA-2026:11686",
                "https://access.redhat.com/errata/RHSA-2026:11688",
                "https://access.redhat.com/errata/RHSA-2026:11747",
                "https://access.redhat.com/errata/RHSA-2026:11749",
                "https://access.redhat.com/errata/RHSA-2026:11768",
                "https://access.redhat.com/errata/RHSA-2026:11800",
                "https://access.redhat.com/errata/RHSA-2026:11856",
                "https://access.redhat.com/errata/RHSA-2026:11916",
                "https://access.redhat.com/errata/RHSA-2026:11996",
                "https://access.redhat.com/errata/RHSA-2026:12028",
                "https://access.redhat.com/errata/RHSA-2026:12029",
                "https://access.redhat.com/errata/RHSA-2026:12030",
                "https://access.redhat.com/errata/RHSA-2026:12031",
                "https://access.redhat.com/errata/RHSA-2026:12032",
                "https://access.redhat.com/errata/RHSA-2026:12033",
                "https://access.redhat.com/errata/RHSA-2026:12282",
                "https://access.redhat.com/errata/RHSA-2026:13508",
                "https://access.redhat.com/errata/RHSA-2026:13512",
                "https://access.redhat.com/errata/RHSA-2026:13545",
                "https://access.redhat.com/errata/RHSA-2026:13642",
                "https://access.redhat.com/errata/RHSA-2026:13643",
                "https://access.redhat.com/errata/RHSA-2026:13671",
                "https://access.redhat.com/errata/RHSA-2026:13791",
                "https://access.redhat.com/errata/RHSA-2026:13829",
                "https://access.redhat.com/errata/RHSA-2026:14020",
                "https://access.redhat.com/errata/RHSA-2026:14100",
                "https://access.redhat.com/errata/RHSA-2026:14774",
                "https://access.redhat.com/errata/RHSA-2026:14868",
                "https://access.redhat.com/errata/RHSA-2026:14879",
                "https://access.redhat.com/errata/RHSA-2026:15091",
                "https://access.redhat.com/errata/RHSA-2026:16102",
                "https://access.redhat.com/errata/RHSA-2026:16696",
                "https://access.redhat.com/errata/RHSA-2026:16874",
                "https://access.redhat.com/errata/RHSA-2026:16875",
                "https://access.redhat.com/errata/RHSA-2026:17040",
                "https://access.redhat.com/errata/RHSA-2026:17084",
                "https://access.redhat.com/errata/RHSA-2026:17287",
                "https://access.redhat.com/errata/RHSA-2026:17598",
                "https://access.redhat.com/errata/RHSA-2026:19017",
                "https://access.redhat.com/errata/RHSA-2026:19022",
                "https://access.redhat.com/errata/RHSA-2026:19026",
                "https://access.redhat.com/errata/RHSA-2026:19027",
                "https://access.redhat.com/errata/RHSA-2026:19031",
                "https://access.redhat.com/errata/RHSA-2026:19032",
                "https://access.redhat.com/errata/RHSA-2026:19049",
                "https://access.redhat.com/errata/RHSA-2026:19055",
                "https://access.redhat.com/errata/RHSA-2026:19126",
                "https://access.redhat.com/errata/RHSA-2026:19128",
                "https://access.redhat.com/errata/RHSA-2026:19132",
                "https://access.redhat.com/errata/RHSA-2026:19133",
                "https://access.redhat.com/errata/RHSA-2026:19135",
                "https://access.redhat.com/errata/RHSA-2026:19181",
                "https://access.redhat.com/errata/RHSA-2026:19184",
                "https://access.redhat.com/errata/RHSA-2026:19185",
                "https://access.redhat.com/errata/RHSA-2026:19207",
                "https://access.redhat.com/errata/RHSA-2026:19350",
                "https://access.redhat.com/errata/RHSA-2026:19353",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19475",
                "https://access.redhat.com/errata/RHSA-2026:19634",
                "https://access.redhat.com/errata/RHSA-2026:19719",
                "https://access.redhat.com/errata/RHSA-2026:19720",
                "https://access.redhat.com/errata/RHSA-2026:19721",
                "https://access.redhat.com/errata/RHSA-2026:19750",
                "https://access.redhat.com/errata/RHSA-2026:20041",
                "https://access.redhat.com/errata/RHSA-2026:20088",
                "https://access.redhat.com/errata/RHSA-2026:20581",
                "https://access.redhat.com/errata/RHSA-2026:20582",
                "https://access.redhat.com/errata/RHSA-2026:20584",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:21655",
                "https://access.redhat.com/errata/RHSA-2026:21657",
                "https://access.redhat.com/errata/RHSA-2026:21691",
                "https://access.redhat.com/errata/RHSA-2026:21696",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:22450",
                "https://access.redhat.com/errata/RHSA-2026:22627",
                "https://access.redhat.com/errata/RHSA-2026:22714",
                "https://access.redhat.com/errata/RHSA-2026:22733",
                "https://access.redhat.com/errata/RHSA-2026:22862",
                "https://access.redhat.com/errata/RHSA-2026:22937",
                "https://access.redhat.com/errata/RHSA-2026:23228",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:24386",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:25043",
                "https://access.redhat.com/errata/RHSA-2026:25127",
                "https://access.redhat.com/errata/RHSA-2026:25180",
                "https://access.redhat.com/errata/RHSA-2026:25248",
                "https://access.redhat.com/errata/RHSA-2026:25250",
                "https://access.redhat.com/errata/RHSA-2026:25251",
                "https://access.redhat.com/errata/RHSA-2026:25252",
                "https://access.redhat.com/errata/RHSA-2026:25253",
                "https://access.redhat.com/errata/RHSA-2026:26445",
                "https://access.redhat.com/errata/RHSA-2026:26527",
                "https://access.redhat.com/errata/RHSA-2026:26541",
                "https://access.redhat.com/errata/RHSA-2026:26568",
                "https://access.redhat.com/errata/RHSA-2026:26585",
                "https://access.redhat.com/errata/RHSA-2026:26636",
                "https://access.redhat.com/errata/RHSA-2026:27076",
                "https://access.redhat.com/errata/RHSA-2026:28047",
                "https://access.redhat.com/errata/RHSA-2026:28441",
                "https://access.redhat.com/errata/RHSA-2026:28886",
                "https://access.redhat.com/errata/RHSA-2026:28893",
                "https://access.redhat.com/errata/RHSA-2026:28961",
                "https://access.redhat.com/errata/RHSA-2026:29035",
                "https://access.redhat.com/errata/RHSA-2026:29195",
                "https://access.redhat.com/errata/RHSA-2026:29455",
                "https://access.redhat.com/errata/RHSA-2026:29702",
                "https://access.redhat.com/errata/RHSA-2026:29703",
                "https://access.redhat.com/errata/RHSA-2026:29854",
                "https://access.redhat.com/errata/RHSA-2026:33722",
                "https://access.redhat.com/errata/RHSA-2026:34097",
                "https://access.redhat.com/errata/RHSA-2026:34365",
                "https://access.redhat.com/errata/RHSA-2026:36317",
                "https://access.redhat.com/errata/RHSA-2026:36319",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36796",
                "https://access.redhat.com/errata/RHSA-2026:39810",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:41019",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:42150",
                "https://access.redhat.com/errata/RHSA-2026:42151",
                "https://access.redhat.com/errata/RHSA-2026:48036",
                "https://access.redhat.com/errata/RHSA-2026:49944",
                "https://access.redhat.com/errata/RHSA-2026:5110",
                "https://access.redhat.com/errata/RHSA-2026:51288",
                "https://access.redhat.com/errata/RHSA-2026:52389",
                "https://access.redhat.com/errata/RHSA-2026:52390",
                "https://access.redhat.com/errata/RHSA-2026:52391",
                "https://access.redhat.com/errata/RHSA-2026:54191",
                "https://access.redhat.com/errata/RHSA-2026:54757",
                "https://access.redhat.com/errata/RHSA-2026:5549",
                "https://access.redhat.com/errata/RHSA-2026:56785",
                "https://access.redhat.com/errata/RHSA-2026:56852",
                "https://access.redhat.com/errata/RHSA-2026:56910",
                "https://access.redhat.com/errata/RHSA-2026:57482",
                "https://access.redhat.com/errata/RHSA-2026:5941",
                "https://access.redhat.com/errata/RHSA-2026:5942",
                "https://access.redhat.com/errata/RHSA-2026:5943",
                "https://access.redhat.com/errata/RHSA-2026:5944",
                "https://access.redhat.com/errata/RHSA-2026:59830",
                "https://access.redhat.com/errata/RHSA-2026:60018",
                "https://access.redhat.com/errata/RHSA-2026:6341",
                "https://access.redhat.com/errata/RHSA-2026:6344",
                "https://access.redhat.com/errata/RHSA-2026:6382",
                "https://access.redhat.com/errata/RHSA-2026:6383",
                "https://access.redhat.com/errata/RHSA-2026:6388",
                "https://access.redhat.com/errata/RHSA-2026:6564",
                "https://access.redhat.com/errata/RHSA-2026:6720",
                "https://access.redhat.com/errata/RHSA-2026:6802",
                "https://access.redhat.com/errata/RHSA-2026:6949",
                "https://access.redhat.com/errata/RHSA-2026:7005",
                "https://access.redhat.com/errata/RHSA-2026:7009",
                "https://access.redhat.com/errata/RHSA-2026:7011",
                "https://access.redhat.com/errata/RHSA-2026:7259",
                "https://access.redhat.com/errata/RHSA-2026:7291",
                "https://access.redhat.com/errata/RHSA-2026:7315",
                "https://access.redhat.com/errata/RHSA-2026:7328",
                "https://access.redhat.com/errata/RHSA-2026:7385",
                "https://access.redhat.com/errata/RHSA-2026:7665",
                "https://access.redhat.com/errata/RHSA-2026:7669",
                "https://access.redhat.com/errata/RHSA-2026:7674",
                "https://access.redhat.com/errata/RHSA-2026:7833",
                "https://access.redhat.com/errata/RHSA-2026:7834",
                "https://access.redhat.com/errata/RHSA-2026:7876",
                "https://access.redhat.com/errata/RHSA-2026:7877",
                "https://access.redhat.com/errata/RHSA-2026:7878",
                "https://access.redhat.com/errata/RHSA-2026:7879",
                "https://access.redhat.com/errata/RHSA-2026:7883",
                "https://access.redhat.com/errata/RHSA-2026:7992",
                "https://access.redhat.com/errata/RHSA-2026:8151",
                "https://access.redhat.com/errata/RHSA-2026:8167",
                "https://access.redhat.com/errata/RHSA-2026:8314",
                "https://access.redhat.com/errata/RHSA-2026:8322",
                "https://access.redhat.com/errata/RHSA-2026:8324",
                "https://access.redhat.com/errata/RHSA-2026:8337",
                "https://access.redhat.com/errata/RHSA-2026:8338",
                "https://access.redhat.com/errata/RHSA-2026:8433",
                "https://access.redhat.com/errata/RHSA-2026:8434",
                "https://access.redhat.com/errata/RHSA-2026:8456",
                "https://access.redhat.com/errata/RHSA-2026:8483",
                "https://access.redhat.com/errata/RHSA-2026:8484",
                "https://access.redhat.com/errata/RHSA-2026:8490",
                "https://access.redhat.com/errata/RHSA-2026:8491",
                "https://access.redhat.com/errata/RHSA-2026:8493",
                "https://access.redhat.com/errata/RHSA-2026:8840",
                "https://access.redhat.com/errata/RHSA-2026:8841",
                "https://access.redhat.com/errata/RHSA-2026:8842",
                "https://access.redhat.com/errata/RHSA-2026:8845",
                "https://access.redhat.com/errata/RHSA-2026:8847",
                "https://access.redhat.com/errata/RHSA-2026:8848",
                "https://access.redhat.com/errata/RHSA-2026:8849",
                "https://access.redhat.com/errata/RHSA-2026:8851",
                "https://access.redhat.com/errata/RHSA-2026:8852",
                "https://access.redhat.com/errata/RHSA-2026:8853",
                "https://access.redhat.com/errata/RHSA-2026:8855",
                "https://access.redhat.com/errata/RHSA-2026:8856",
                "https://access.redhat.com/errata/RHSA-2026:8860",
                "https://access.redhat.com/errata/RHSA-2026:8877",
                "https://access.redhat.com/errata/RHSA-2026:8878",
                "https://access.redhat.com/errata/RHSA-2026:8879",
                "https://access.redhat.com/errata/RHSA-2026:8881",
                "https://access.redhat.com/errata/RHSA-2026:8882",
                "https://access.redhat.com/errata/RHSA-2026:8930",
                "https://access.redhat.com/errata/RHSA-2026:8931",
                "https://access.redhat.com/errata/RHSA-2026:8949",
                "https://access.redhat.com/errata/RHSA-2026:9043",
                "https://access.redhat.com/errata/RHSA-2026:9044",
                "https://access.redhat.com/errata/RHSA-2026:9052",
                "https://access.redhat.com/errata/RHSA-2026:9090",
                "https://access.redhat.com/errata/RHSA-2026:9093",
                "https://access.redhat.com/errata/RHSA-2026:9094",
                "https://access.redhat.com/errata/RHSA-2026:9097",
                "https://access.redhat.com/errata/RHSA-2026:9098",
                "https://access.redhat.com/errata/RHSA-2026:9108",
                "https://access.redhat.com/errata/RHSA-2026:9109",
                "https://access.redhat.com/errata/RHSA-2026:9385",
                "https://access.redhat.com/errata/RHSA-2026:9434",
                "https://access.redhat.com/errata/RHSA-2026:9435",
                "https://access.redhat.com/errata/RHSA-2026:9436",
                "https://access.redhat.com/errata/RHSA-2026:9439",
                "https://access.redhat.com/errata/RHSA-2026:9440",
                "https://access.redhat.com/errata/RHSA-2026:9448",
                "https://access.redhat.com/errata/RHSA-2026:9453",
                "https://access.redhat.com/errata/RHSA-2026:9461",
                "https://access.redhat.com/errata/RHSA-2026:9695",
                "https://access.redhat.com/errata/RHSA-2026:9742",
                "https://access.redhat.com/errata/RHSA-2026:9872",
                "https://access.redhat.com/security/cve/CVE-2026-25679",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2445356",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25679.json",
                "https://access.redhat.com/errata/RHSA-2026:66401"
            ],
            "timeline": [
                {
                    "at": "2026-03-06T22:16:00.720",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25679"
                }
            ]
        },
        {
            "id": "CVE-2026-25639",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.",
            "updated_at": "2026-09-10T13:17:46.000",
            "published_at": "2026-02-09T21:15:49.010",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.13.5; < 0.30.3",
            "fixed": "See vendor advisory",
            "source_count": 75,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-754",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object created via JSON.parse(), causing complete denial of service. This vulnerability is fixed in versions 0.30.3 and 1.13.5.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-02-09",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-43fc-jf86-j433"
                }
            ],
            "references": [
                "https://github.com/axios/axios/commit/28c721588c7a77e7503d0a434e016f852c597b57",
                "https://github.com/axios/axios/commit/d7ff1409c68168d3057fc3891f911b2b92616f9e",
                "https://github.com/axios/axios/pull/7369",
                "https://github.com/axios/axios/pull/7388",
                "https://github.com/axios/axios/releases/tag/v0.30.3",
                "https://github.com/axios/axios/releases/tag/v1.13.5",
                "https://github.com/axios/axios/security/advisories/GHSA-43fc-jf86-j433",
                "https://access.redhat.com/errata/RHSA-2026:10184",
                "https://access.redhat.com/errata/RHSA-2026:11414",
                "https://access.redhat.com/errata/RHSA-2026:13542",
                "https://access.redhat.com/errata/RHSA-2026:13548",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:25041",
                "https://access.redhat.com/errata/RHSA-2026:2694",
                "https://access.redhat.com/errata/RHSA-2026:3087",
                "https://access.redhat.com/errata/RHSA-2026:3105",
                "https://access.redhat.com/errata/RHSA-2026:3106",
                "https://access.redhat.com/errata/RHSA-2026:3107",
                "https://access.redhat.com/errata/RHSA-2026:3109",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:41064",
                "https://access.redhat.com/errata/RHSA-2026:4942",
                "https://access.redhat.com/errata/RHSA-2026:5142",
                "https://access.redhat.com/errata/RHSA-2026:5168",
                "https://access.redhat.com/errata/RHSA-2026:5174",
                "https://access.redhat.com/errata/RHSA-2026:5633",
                "https://access.redhat.com/errata/RHSA-2026:5636",
                "https://access.redhat.com/errata/RHSA-2026:5665",
                "https://access.redhat.com/errata/RHSA-2026:5807",
                "https://access.redhat.com/errata/RHSA-2026:6170",
                "https://access.redhat.com/errata/RHSA-2026:6174",
                "https://access.redhat.com/errata/RHSA-2026:6192",
                "https://access.redhat.com/errata/RHSA-2026:6277",
                "https://access.redhat.com/errata/RHSA-2026:6308",
                "https://access.redhat.com/errata/RHSA-2026:6309",
                "https://access.redhat.com/errata/RHSA-2026:6428",
                "https://access.redhat.com/errata/RHSA-2026:6497",
                "https://access.redhat.com/errata/RHSA-2026:6567",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/errata/RHSA-2026:6802",
                "https://access.redhat.com/errata/RHSA-2026:7249",
                "https://access.redhat.com/errata/RHSA-2026:8218",
                "https://access.redhat.com/errata/RHSA-2026:8229",
                "https://access.redhat.com/errata/RHSA-2026:8499",
                "https://access.redhat.com/errata/RHSA-2026:8500",
                "https://access.redhat.com/errata/RHSA-2026:8501",
                "https://access.redhat.com/errata/RHSA-2026:9848",
                "https://access.redhat.com/security/cve/CVE-2026-25639",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2438237",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25639.json"
            ],
            "timeline": [
                {
                    "at": "2026-02-09T21:15:49.010",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25639"
                }
            ]
        },
        {
            "id": "CVE-2026-25574",
            "vendor": "Linux",
            "product": "Linux kernel",
            "title": "Linux kernel netfilter use-after-free",
            "summary": "A lifecycle error in a netfilter object can cause a stale reference to be reused by a local process.",
            "updated_at": "2026-09-01T08:47:00Z",
            "published_at": "2026-08-30T11:18:00Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "5.10–6.8.9",
            "fixed": "Vendor dependent",
            "source_count": 62,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Local user",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A netfilter object can remain reachable after its expected lifecycle has ended, creating a stale-reference condition.",
            "why_matters": "Kernel memory-safety issues can cross local privilege boundaries. Distribution-specific backports make package-level verification important.",
            "mitigations": [
                "Apply the kernel update provided by the operating-system vendor.",
                "Review container and local-user exposure.",
                "Use distribution advisories rather than upstream version alone to determine status."
            ],
            "pocs": [
                {
                    "repository": "netfilter-uaf-reproducer",
                    "author": "kernel-research",
                    "first_seen": "Aug 31, 2026",
                    "confidence": "High",
                    "url": "https://github.com/search?q=CVE-2026-25574&type=repositories"
                }
            ],
            "references": [
                "https://github.com/search?q=CVE-2026-25574&type=repositories"
            ]
        },
        {
            "id": "CVE-2026-25552",
            "vendor": "TryGhost",
            "product": "Ghost-CLI",
            "title": "Ghost-CLI vulnerability",
            "summary": "Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers can append attacker-controlled values to the header chain using the $proxy_add_x_forwarded_for directive to present an arbitrary IP address, circumventing Ghost's rate-limiting mechanisms on self-hosted instances.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-07-31T19:17:08.663",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.30.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-348",
            "what_happened": "Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers can append attacker-controlled values to the header chain using the $proxy_add_x_forwarded_for directive to present an arbitrary IP address, circumventing Ghost's rate-limiting mechanisms on self-hosted instances.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/TryGhost/Ghost-CLI/security/advisories/GHSA-wjx2-9fpq-8997",
                "https://www.vulncheck.com/advisories/ghost-cli-ip-spoofing-via-x-forwarded-for-header"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T19:17:08.663",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25552"
                }
            ]
        },
        {
            "id": "CVE-2026-25550",
            "vendor": "Seagull Software, LLC.",
            "product": "BarTender 2010",
            "title": "BarTender 2010 vulnerability",
            "summary": "Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe. The service registers an unauthenticated singleton endpoint — BarTenderSystem for BarTender 2016 <= R9, and DataServiceSingleton for BarTender 2019 <= R10 — configured with BinaryServerFormatterSinkProvider and TypeFilterLevel set to Full. An unauthenticated remote attacker can exploit .NET Remoting object unmarshalling to read or write arbitrary files on the server using the .NET WebClient class, or coerce NTLMv2 authentication by supplying a UNC path to an attacker-controlled server, enabling sensitive credential disclosure, remote code execution, or lateral movement depending on service account privileges and network environment. The service runs in the context of NT AUTHORITY\\\\SYSTEM. This vulnerability is corrected in BarTender 12.0.1. Users of affected releases should upgrade to BarTender 12.0.1 or later.",
            "updated_at": "2026-09-16T16:17:07.137",
            "published_at": "2026-06-04T18:16:28.747",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 10.1 R4 (custom); 0 through R9 (custom); 0 through R10 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe. The service registers an unauthenticated singleton endpoint — BarTenderSystem for BarTender 2016 <= R9, and DataServiceSingleton for BarTender 2019 <= R10 — configured with BinaryServerFormatterSinkProvider and TypeFilterLevel set to Full. An unauthenticated remote attacker can exploit .NET Remoting object unmarshalling to read or write arbitrary files on the server using the .NET WebClient class, or coerce NTLMv2 authentication by supplying a UNC path to an attacker-controlled server, enabling sensitive credential disclosure, remote code execution, or lateral movement depending on service account privileges and network environment. The service runs in the context of NT AUTHORITY\\\\SYSTEM. This vulnerability is corrected in BarTender 12.0.1. Users of affected releases should upgrade to BarTender 12.0.1 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gist.github.com/VAMorales/dde5b1c0415a8505ccd6fafdb095a618",
                "https://portal.seagullscientific.com/downloads/bartender",
                "https://trust.seagullsoftware.com/?tcuUid=55ed135f-683c-4e9b-a59d-7d4373c0ac7e",
                "https://www.vulncheck.com/advisories/seagull-software-bartender-unauthenticated-rce-via-net-remoting-service"
            ],
            "timeline": [
                {
                    "at": "2026-06-04T18:16:28.747",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25550"
                }
            ]
        },
        {
            "id": "CVE-2026-25544",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Payload CMS 3.72.0 - Blind SQL Injection",
            "summary": "Payload CMS 3.72.0 - Blind SQL Injection",
            "updated_at": "2026-08-31T22:00:00Z",
            "published_at": "2026-08-31T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 96,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52671",
                    "author": "cardosource",
                    "first_seen": "2026-09-01",
                    "confidence": "High",
                    "title": "Payload CMS 3.72.0 - Blind SQL Injection",
                    "summary": "Payload CMS 3.72.0 - Blind SQL Injection",
                    "url": "https://www.exploit-db.com/exploits/52671",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52671"
            ],
            "timeline": [
                {
                    "at": "2026-08-31T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52671"
                }
            ]
        },
        {
            "id": "CVE-2026-25470",
            "vendor": "ACPT",
            "product": "ACPT (Pro) - Custom Post Types Plugin for WordPress",
            "title": "ACPT (Pro) - Custom Post Types Plugin for WordPress vulnerability",
            "summary": "Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions.",
            "updated_at": "2026-09-14T15:17:04.963",
            "published_at": "2026-06-17T13:20:11.603",
            "cvss": 10,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a through before 2.0.52 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://patchstack.com/database/wordpress/plugin/advanced-custom-post-type/vulnerability/wordpress-acpt-pro-custom-post-types-plugin-for-wordpress-plugin-2-0-47-remote-code-execution-rce-vulnerability?_s_id=cve"
            ],
            "timeline": [
                {
                    "at": "2026-06-17T13:20:11.603",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-25470"
                }
            ]
        },
        {
            "id": "CVE-2026-25253",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Gideon CVE-2024-21887",
            "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
            "updated_at": "2026-09-05T09:04:57Z",
            "published_at": "2026-09-05T09:04:57Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 27,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Gideon CVE-2024-21887",
                    "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                        "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T11:04:57",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON"
                },
                {
                    "title": "Exploit for Gideon CVE-2024-21887",
                    "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                        "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T11:04:57",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                "https://kitploit.com/ru/tools/github/cogensec/gideon/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T09:04:57Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-25157",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Gideon CVE-2024-21887",
            "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
            "updated_at": "2026-09-05T09:04:57Z",
            "published_at": "2026-09-05T09:04:57Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 27,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Gideon CVE-2024-21887",
                    "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                        "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T11:04:57",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON"
                },
                {
                    "title": "Exploit for Gideon CVE-2024-21887",
                    "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                        "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T11:04:57",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                "https://kitploit.com/ru/tools/github/cogensec/gideon/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T09:04:57Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-25089",
            "vendor": "Fortinet",
            "product": "FortiSandbox",
            "title": "Fortinet FortiSandbox OS Command Injection Vulnerability",
            "summary": "Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.",
            "updated_at": "2026-07-15T22:00:00Z",
            "published_at": "2026-07-15T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-07-15T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-16",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-24842",
            "vendor": "isaacs",
            "product": "node-tar",
            "title": "node-tar vulnerability",
            "summary": "node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.",
            "updated_at": "2026-09-07T13:18:17.380",
            "published_at": "2026-01-28T01:16:14.947",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 7.5.7",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-01-28",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-34x7-hfp2-rc4v"
                }
            ],
            "references": [
                "https://github.com/isaacs/node-tar/commit/f4a7aa9bc3d717c987fdf1480ff7a64e87ffdb46",
                "https://github.com/isaacs/node-tar/security/advisories/GHSA-34x7-hfp2-rc4v",
                "https://access.redhat.com/errata/RHSA-2026:18480",
                "https://access.redhat.com/errata/RHSA-2026:18868",
                "https://access.redhat.com/errata/RHSA-2026:2900",
                "https://access.redhat.com/errata/RHSA-2026:33371",
                "https://access.redhat.com/errata/RHSA-2026:5447",
                "https://access.redhat.com/errata/RHSA-2026:6192",
                "https://access.redhat.com/security/cve/CVE-2026-24842",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2433645",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24842.json"
            ],
            "timeline": [
                {
                    "at": "2026-01-28T01:16:14.947",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24842"
                }
            ]
        },
        {
            "id": "CVE-2026-24763",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Gideon CVE-2024-21887",
            "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
            "updated_at": "2026-09-05T09:04:57Z",
            "published_at": "2026-09-05T09:04:57Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 27,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Gideon CVE-2024-21887",
                    "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                        "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T11:04:57",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON"
                },
                {
                    "title": "Exploit for Gideon CVE-2024-21887",
                    "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                        "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T11:04:57",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                "https://kitploit.com/ru/tools/github/cogensec/gideon/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T09:04:57Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-24708",
            "vendor": "OpenStack",
            "product": "Nova",
            "title": "Nova vulnerability",
            "summary": "An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.",
            "updated_at": "2026-09-11T13:17:13.113",
            "published_at": "2026-02-18T18:24:33.087",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 30.2.2 (semver); 31.0.0 through before 31.2.1 (semver); 32.0.0 through before 32.1.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-669",
            "what_happened": "An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize operation that could destroy data on the host system. Only compute nodes using the Flat image backend (usually configured with use_cow_images=False) are affected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugs.launchpad.net/nova/+bug/2137507",
                "https://www.openwall.com/lists/oss-security/2026/02/17/7",
                "https://lists.debian.org/debian-lts-announce/2026/02/msg00025.html",
                "https://access.redhat.com/errata/RHSA-2026:54757",
                "https://access.redhat.com/errata/RHSA-2026:66401",
                "https://access.redhat.com/errata/RHSA-2026:7884",
                "https://access.redhat.com/security/cve/CVE-2026-24708",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2430312",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24708.json"
            ],
            "timeline": [
                {
                    "at": "2026-02-18T18:24:33.087",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24708"
                }
            ]
        },
        {
            "id": "CVE-2026-24332",
            "vendor": "Discord",
            "product": "WebSocket API service",
            "title": "WebSocket API service vulnerability",
            "summary": "Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with \"status\": \"offline\"), whereas offline users are omitted from the presences array. This is arguably inconsistent with the UI description of Invisible as \"You will appear offline.\" NOTE: a third-party report suggests that this was remediated later in 2026.",
            "updated_at": "2026-09-13T00:17:06.233",
            "published_at": "2026-01-22T08:16:00.857",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2026-01-16 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-204",
            "what_happened": "Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with \"status\": \"offline\"), whereas offline users are omitted from the presences array. This is arguably inconsistent with the UI description of Invisible as \"You will appear offline.\" NOTE: a third-party report suggests that this was remediated later in 2026.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://xmrcat.org/discord-invisibility-bypass"
            ],
            "timeline": [
                {
                    "at": "2026-01-22T08:16:00.857",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24332"
                }
            ]
        },
        {
            "id": "CVE-2026-24291",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
            "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
            "updated_at": "2026-09-11T22:10:10Z",
            "published_at": "2026-09-11T22:10:10Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 102,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4"
                },
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                },
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-54121-Certighost",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T15:06:51+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "RegPwn exploit",
                    "summary": "Exploit for CVE-2026-24291. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MDSECACTIVEBREACH-REGPWN"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MDSECACTIVEBREACH-REGPWN"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:10:10Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2026-24110",
            "vendor": "Microsoft",
            "product": "Windows Print Service",
            "title": "Windows print service boundary error",
            "summary": "A service boundary error may permit local privilege escalation under a constrained set of spooler configurations.",
            "updated_at": "2026-09-01T08:31:00Z",
            "published_at": "2026-08-29T09:00:00Z",
            "cvss": 7.8,
            "confidence": 73,
            "confidence_label": "observed",
            "affected": "Server 2022–2025",
            "fixed": "Latest security update",
            "source_count": 8,
            "kev": true,
            "attack_vector": "Local",
            "authentication": "Local user",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "A print-service operation applies insufficient authorization checks when transitioning a job between trust contexts.",
            "why_matters": "Print services are commonly present on enterprise hosts and may provide a path from an existing user context to elevated permissions.",
            "mitigations": [
                "Apply the latest vendor security update.",
                "Disable the print service where it is not required.",
                "Monitor service configuration changes."
            ],
            "pocs": [],
            "references": []
        },
        {
            "id": "CVE-2026-24061",
            "vendor": "GNU",
            "product": "InetUtils",
            "title": "GNU InetUtils Argument Injection Vulnerability",
            "summary": "GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a \"-f root\" value for the USER environment variable.",
            "updated_at": "2026-08-26T10:23:43Z",
            "published_at": "2026-08-26T10:23:43Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1704,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-88",
            "what_happened": "GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a \"-f root\" value for the USER environment variable.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52524",
                    "author": "aliguliyev",
                    "first_seen": "2026-04-29",
                    "confidence": "High",
                    "title": "GNU InetUtils 2.6 - Telnetd Remote Privilege Escalation",
                    "summary": "GNU InetUtils 2.6 - Telnetd Remote Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/52524",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "CVE-Intel · obrunolima1910/CVE-2026-24061",
                    "author": "obrunolima1910",
                    "first_seen": "2026-02-03",
                    "last_seen": "2026-08-26T10:23:43Z",
                    "pushed_at": "2026-08-26T10:21:17Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Bypass",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [
                        "agent",
                        "auth",
                        "book",
                        "computer-vision",
                        "cv",
                        "deep-learning",
                        "gluon",
                        "image-classification"
                    ],
                    "title": "🚨 Exploit CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd, for instant root shell access without authentication.",
                    "repository_description": "🚨 Exploit CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd, for instant root shell access without authentication.",
                    "summary": "🚨 Exploit CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd, for instant root shell access without authentication.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/obrunolima1910/CVE-2026-24061",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-88",
                    "kev": true,
                    "epss": 0.97878,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-01-21",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · jacubes/CVE-2026-24061",
                    "author": "jacubes",
                    "first_seen": "2026-03-08",
                    "last_seen": "2026-08-24T15:14:38Z",
                    "pushed_at": "2026-08-20T10:06:17Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "Python",
                    "stars": 824,
                    "forks": 15,
                    "topics": [
                        "cve",
                        "cve-2026-24061",
                        "cve-poc",
                        "exploit",
                        "vulnerability"
                    ],
                    "title": "CVE-2026-24061 exploit PoC",
                    "repository_description": "CVE-2026-24061 exploit PoC",
                    "summary": "CVE-2026-24061 exploit PoC",
                    "source": "CVE-Intel",
                    "url": "https://github.com/jacubes/CVE-2026-24061",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-88",
                    "kev": true,
                    "epss": 0.97878,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-01-21",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · SafeBreach-Labs/CVE-2026-24061",
                    "author": "SafeBreach-Labs",
                    "first_seen": "2026-01-22",
                    "last_seen": "2026-08-24T14:53:01Z",
                    "pushed_at": "2026-01-22T19:37:20Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 207,
                    "forks": 47,
                    "topics": [],
                    "title": "Exploitation of CVE-2026-24061",
                    "repository_description": "Exploitation of CVE-2026-24061",
                    "summary": "Exploitation of CVE-2026-24061",
                    "source": "CVE-Intel",
                    "url": "https://github.com/SafeBreach-Labs/CVE-2026-24061",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-88",
                    "kev": true,
                    "epss": 0.97878,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-01-21",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · franckferman/CVE-2026-24061",
                    "author": "franckferman",
                    "first_seen": "2026-02-02",
                    "last_seen": "2026-08-21T01:27:11Z",
                    "pushed_at": "2026-03-27T13:51:19Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Injection",
                    "language": "Python",
                    "stars": 4,
                    "forks": 0,
                    "topics": [
                        "authentication-bypass",
                        "cve",
                        "cve-2026-24061",
                        "cves",
                        "exploit",
                        "exploitation",
                        "exploiting",
                        "inetutils"
                    ],
                    "title": "GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.",
                    "repository_description": "GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.",
                    "summary": "GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/franckferman/CVE-2026-24061",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-88",
                    "kev": true,
                    "epss": 0.97878,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-01-21",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · ekomsSavior/telnet_scan",
                    "author": "ekomsSavior",
                    "first_seen": "2026-03-26",
                    "last_seen": "2026-08-19T23:49:50Z",
                    "pushed_at": "2026-05-22T01:07:58Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 12,
                    "forks": 6,
                    "topics": [],
                    "title": "scanner/exploiter CVE-2026-24061 & CVE-2026-32746",
                    "repository_description": "scanner/exploiter CVE-2026-24061 & CVE-2026-32746",
                    "summary": "scanner/exploiter CVE-2026-24061 & CVE-2026-32746",
                    "source": "CVE-Intel",
                    "url": "https://github.com/ekomsSavior/telnet_scan",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-88",
                    "kev": true,
                    "epss": 0.97878,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-01-21",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · 0p5cur/CVE-2026-24061-POC",
                    "author": "0p5cur",
                    "first_seen": "2026-01-24",
                    "last_seen": "2026-08-11T18:49:26Z",
                    "pushed_at": "2026-08-11T18:48:52Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 7,
                    "forks": 3,
                    "topics": [
                        "cve",
                        "cve-2026-24061",
                        "poc",
                        "rce",
                        "root",
                        "telnet",
                        "telnet-server",
                        "unauthenticated-rce"
                    ],
                    "title": "CVE-2026-24061's poc : a critical authentication bypass in telnetd leading to RCE as root Affects systems with telnetd versions containing the vulnerability from 2015 onwards.",
                    "repository_description": "CVE-2026-24061's poc : a critical authentication bypass in telnetd leading to RCE as root Affects systems with telnetd versions containing the vulnerability from 2015 onwards.",
                    "summary": "CVE-2026-24061's poc : a critical authentication bypass in telnetd leading to RCE as root Affects systems with telnetd versions containing the vulnerability from 2015 onwards.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/0p5cur/CVE-2026-24061-POC",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-88",
                    "kev": true,
                    "epss": 0.97878,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-01-21",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · s-vx/CVE-2026-24061",
                    "author": "s-vx",
                    "first_seen": "2026-07-25",
                    "last_seen": "2026-07-25T20:22:56Z",
                    "pushed_at": "2026-07-25T20:16:02Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Bypass",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "Auth Bypass in inetutils-telnetd",
                    "repository_description": "Auth Bypass in inetutils-telnetd",
                    "summary": "Auth Bypass in inetutils-telnetd",
                    "source": "CVE-Intel",
                    "url": "https://github.com/s-vx/CVE-2026-24061",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-88",
                    "kev": true,
                    "epss": 0.97878,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-01-21",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · Lingzesec/CVE-2026-24061-GUI",
                    "author": "Lingzesec",
                    "first_seen": "2026-01-26",
                    "last_seen": "2026-07-24T01:11:06Z",
                    "pushed_at": "2026-01-28T02:28:40Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 17,
                    "forks": 1,
                    "topics": [],
                    "title": "CVE-2026-24061 GNU Inetutils telnetd 身份验证绕过漏洞检测与利用 GUI 工具",
                    "repository_description": "CVE-2026-24061 GNU Inetutils telnetd 身份验证绕过漏洞检测与利用 GUI 工具",
                    "summary": "CVE-2026-24061 GNU Inetutils telnetd 身份验证绕过漏洞检测与利用 GUI 工具",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Lingzesec/CVE-2026-24061-GUI",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a \"-f root\" value for the USER environment variable.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-88",
                    "kev": true,
                    "epss": 0.97878,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-01-21",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "PoC-in-GitHub · leonjza/inetutils-telnetd-auth-bypass",
                    "author": "leonjza",
                    "first_seen": "2026-01-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "A small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass.",
                    "summary": "A small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass.",
                    "url": "https://github.com/leonjza/inetutils-telnetd-auth-bypass"
                },
                {
                    "repository": "PoC-in-GitHub · duy-31/CVE-2026-24061---telnetd",
                    "author": "duy-31",
                    "first_seen": "2026-01-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Bypass d’authentification Telnet menant à un accès root",
                    "summary": "Bypass d’authentification Telnet menant à un accès root",
                    "url": "https://github.com/duy-31/CVE-2026-24061---telnetd"
                },
                {
                    "repository": "PoC-in-GitHub · TryA9ain/CVE-2026-24061",
                    "author": "TryA9ain",
                    "first_seen": "2026-01-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "CVE-2026-24061 Batch Scanning Tool",
                    "summary": "CVE-2026-24061 Batch Scanning Tool",
                    "url": "https://github.com/TryA9ain/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · parameciumzhang/Tell-Me-Root",
                    "author": "parameciumzhang",
                    "first_seen": "2026-01-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 21,
                    "title": "基于cve-2026-24061 telnet远程认证绕过漏洞的批量检测利用工具",
                    "summary": "基于cve-2026-24061 telnet远程认证绕过漏洞的批量检测利用工具",
                    "url": "https://github.com/parameciumzhang/Tell-Me-Root"
                },
                {
                    "repository": "PoC-in-GitHub · Chocapikk/CVE-2026-24061",
                    "author": "Chocapikk",
                    "first_seen": "2026-01-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/Chocapikk/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · JayGLXR/CVE-2026-24061-POC",
                    "author": "JayGLXR",
                    "first_seen": "2026-01-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 67,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/JayGLXR/CVE-2026-24061-POC"
                },
                {
                    "repository": "PoC-in-GitHub · h3athen/CVE-2026-24061",
                    "author": "h3athen",
                    "first_seen": "2026-01-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "CVE-2026-24061 - Exploit",
                    "summary": "CVE-2026-24061 - Exploit",
                    "url": "https://github.com/h3athen/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · xuemian168/CVE-2026-24061",
                    "author": "xuemian168",
                    "first_seen": "2026-01-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/xuemian168/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · monstertsl/CVE-2026-24061",
                    "author": "monstertsl",
                    "first_seen": "2026-01-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-24061 漏洞检测工具",
                    "summary": "CVE-2026-24061 漏洞检测工具",
                    "url": "https://github.com/monstertsl/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · r00tuser111/CVE-2026-24061",
                    "author": "r00tuser111",
                    "first_seen": "2026-01-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 环境",
                    "summary": "CVE-2026-24061 环境",
                    "url": "https://github.com/r00tuser111/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · balgan/CVE-2026-24061",
                    "author": "balgan",
                    "first_seen": "2026-01-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "inetutils-telnetd Authentication Bypass - working",
                    "summary": "inetutils-telnetd Authentication Bypass - working",
                    "url": "https://github.com/balgan/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · sh4den/CVE-2026-24061",
                    "author": "sh4den",
                    "first_seen": "2026-01-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers to gain instant root shell access via malicious NEW_ENVIRON telnet option exploitation.",
                    "summary": "Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers to gain instant root shell access via malicious NEW_ENVIRON telnet option exploitation.",
                    "url": "https://github.com/sh4den/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · z3n70/CVE-2026-24061",
                    "author": "z3n70",
                    "first_seen": "2026-01-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/z3n70/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · Mr-Zapi/CVE-2026-24061",
                    "author": "Mr-Zapi",
                    "first_seen": "2026-01-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Nuclei template for CVE-2026-24061",
                    "summary": "Nuclei template for CVE-2026-24061",
                    "url": "https://github.com/Mr-Zapi/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · midox008/CVE-2026-24061",
                    "author": "midox008",
                    "first_seen": "2026-01-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "GNU Inetutils telnetd Remote Authentication Bypass",
                    "summary": "GNU Inetutils telnetd Remote Authentication Bypass",
                    "url": "https://github.com/midox008/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · BrainBob/CVE-2026-24061",
                    "author": "BrainBob",
                    "first_seen": "2026-01-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/BrainBob/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · BrainBob/Telnet-TestVuln-CVE-2026-24061",
                    "author": "BrainBob",
                    "first_seen": "2026-01-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/BrainBob/Telnet-TestVuln-CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · shivam-bathla/CVE-2026-24061-setup",
                    "author": "shivam-bathla",
                    "first_seen": "2026-01-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Docker setup for CVE-2026-24061",
                    "summary": "Docker setup for CVE-2026-24061",
                    "url": "https://github.com/shivam-bathla/CVE-2026-24061-setup"
                },
                {
                    "repository": "PoC-in-GitHub · madfxr/Twenty-Three-Scanner",
                    "author": "madfxr",
                    "first_seen": "2026-01-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2026-24061 - GNU InetUtils Telnetd Remote Authentication Bypass",
                    "summary": "CVE-2026-24061 - GNU InetUtils Telnetd Remote Authentication Bypass",
                    "url": "https://github.com/madfxr/Twenty-Three-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · Alter-N0X/CVE-2026-24061-POC",
                    "author": "Alter-N0X",
                    "first_seen": "2026-01-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 - GNU InetUtils telnetd authentication bypass POC + Docker lab environment for testing",
                    "summary": "CVE-2026-24061 - GNU InetUtils telnetd authentication bypass POC + Docker lab environment for testing",
                    "url": "https://github.com/Alter-N0X/CVE-2026-24061-POC"
                },
                {
                    "repository": "PoC-in-GitHub · typeconfused/CVE-2026-24061",
                    "author": "typeconfused",
                    "first_seen": "2026-01-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "GNU telnetd service from GNU InetUtils authentication-bypass",
                    "summary": "GNU telnetd service from GNU InetUtils authentication-bypass",
                    "url": "https://github.com/typeconfused/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · Mefhika120/Ashwesker-CVE-2026-24061",
                    "author": "Mefhika120",
                    "first_seen": "2026-01-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061",
                    "summary": "CVE-2026-24061",
                    "url": "https://github.com/Mefhika120/Ashwesker-CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · infat0x/CVE-2026-24061",
                    "author": "infat0x",
                    "first_seen": "2026-01-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-24061 PoC",
                    "summary": "CVE-2026-24061 PoC",
                    "url": "https://github.com/infat0x/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · ms0x08-dev/CVE-2026-24061-POC",
                    "author": "ms0x08-dev",
                    "first_seen": "2026-01-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/ms0x08-dev/CVE-2026-24061-POC"
                },
                {
                    "repository": "PoC-in-GitHub · punitdarji/telnetd-cve-2026-24061",
                    "author": "punitdarji",
                    "first_seen": "2026-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/punitdarji/telnetd-cve-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · XsanFlip/CVE-2026-24061-Scanner",
                    "author": "XsanFlip",
                    "first_seen": "2026-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061-Scanner by XsanLahci",
                    "summary": "CVE-2026-24061-Scanner by XsanLahci",
                    "url": "https://github.com/XsanFlip/CVE-2026-24061-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · LucasPDiniz/CVE-2026-24061",
                    "author": "LucasPDiniz",
                    "first_seen": "2026-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Vulnerability in GNU InetUtils telnetd Enables Remote Root Access",
                    "summary": "Vulnerability in GNU InetUtils telnetd Enables Remote Root Access",
                    "url": "https://github.com/LucasPDiniz/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · FurkanKAYAPINAR/CVE-2026-24061-telnet2root",
                    "author": "FurkanKAYAPINAR",
                    "first_seen": "2026-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/FurkanKAYAPINAR/CVE-2026-24061-telnet2root"
                },
                {
                    "repository": "PoC-in-GitHub · androidteacher/CVE-2026-24061-PoC-Telnetd",
                    "author": "androidteacher",
                    "first_seen": "2026-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/androidteacher/CVE-2026-24061-PoC-Telnetd"
                },
                {
                    "repository": "PoC-in-GitHub · cumakurt/tscan",
                    "author": "cumakurt",
                    "first_seen": "2026-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Telnetd Auth Bypass Scanner (CVE-2026-24061)  A Python-based scanner for detecting and exploiting the CVE-2026-24061 vulnerability in GNU Inetutils telnetd services. This tool scans IP addresses or networks for vulnerable telnetd services that allow authentication bypass leading to root shell access.",
                    "summary": "Telnetd Auth Bypass Scanner (CVE-2026-24061)  A Python-based scanner for detecting and exploiting the CVE-2026-24061 vulnerability in GNU Inetutils telnetd services. This tool scans IP addresses or networks for vulnerable telnetd services that allow authentication bypass leading to root shell access.",
                    "url": "https://github.com/cumakurt/tscan"
                },
                {
                    "repository": "PoC-in-GitHub · novitahk/Exploit-CVE-2026-24061",
                    "author": "novitahk",
                    "first_seen": "2026-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Payload CVE-2026-24061",
                    "summary": "Payload CVE-2026-24061",
                    "url": "https://github.com/novitahk/Exploit-CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · Gabs-hub/CVE-2026-24061_Lab",
                    "author": "Gabs-hub",
                    "first_seen": "2026-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Lab to show the CVE-2026-24061",
                    "summary": "Lab to show the CVE-2026-24061",
                    "url": "https://github.com/Gabs-hub/CVE-2026-24061_Lab"
                },
                {
                    "repository": "PoC-in-GitHub · MY0723/GNU-Inetutils-telnet-CVE-2026-24061-",
                    "author": "MY0723",
                    "first_seen": "2026-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "GNU Inetutils telnet远程认证绕过漏洞(CVE-2026-24061)，该漏洞源于 GNU Inetutils telnetd 组件中对环境变量处理不当，攻击者可利用该漏洞，通过构造恶意的 USER 环境变量并发送至受影响的 telnet 服务，触发认证绕过机制，进而实现无需密码直接获取root权限。",
                    "summary": "GNU Inetutils telnet远程认证绕过漏洞(CVE-2026-24061)，该漏洞源于 GNU Inetutils telnetd 组件中对环境变量处理不当，攻击者可利用该漏洞，通过构造恶意的 USER 环境变量并发送至受影响的 telnet 服务，触发认证绕过机制，进而实现无需密码直接获取root权限。",
                    "url": "https://github.com/MY0723/GNU-Inetutils-telnet-CVE-2026-24061-"
                },
                {
                    "repository": "PoC-in-GitHub · 0x7556/CVE-2026-24061",
                    "author": "0x7556",
                    "first_seen": "2026-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 Telnet RCE Exploit For Linux MacOS Windows",
                    "summary": "CVE-2026-24061 Telnet RCE Exploit For Linux MacOS Windows",
                    "url": "https://github.com/0x7556/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · Parad0x7e/CVE-2026-24061",
                    "author": "Parad0x7e",
                    "first_seen": "2026-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/Parad0x7e/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · dotelpenguin/telnetd_CVE-2026-24061_tester",
                    "author": "dotelpenguin",
                    "first_seen": "2026-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Checks for CVE-2026-24061 Telnetd exploit",
                    "summary": "Checks for CVE-2026-24061 Telnetd exploit",
                    "url": "https://github.com/dotelpenguin/telnetd_CVE-2026-24061_tester"
                },
                {
                    "repository": "PoC-in-GitHub · JakeSwiz/telnet-inetutils-auth-bypass-CVE-2026-24061",
                    "author": "JakeSwiz",
                    "first_seen": "2026-01-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This is a simple PoC that allows you to highlight the severity of the ongoing and actively exploited Telnet bug that is going on right now. Why people are still using Telnet... beyond me.",
                    "summary": "This is a simple PoC that allows you to highlight the severity of the ongoing and actively exploited Telnet bug that is going on right now. Why people are still using Telnet... beyond me.",
                    "url": "https://github.com/JakeSwiz/telnet-inetutils-auth-bypass-CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · buzz075/CVE-2026-24061",
                    "author": "buzz075",
                    "first_seen": "2026-01-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Scanner for CVE-2026-24061",
                    "summary": "Scanner for CVE-2026-24061",
                    "url": "https://github.com/buzz075/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · X-croot/CVE-2026-24061_POC",
                    "author": "X-croot",
                    "first_seen": "2026-02-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "POC Script for CVE-2026-24061 (GNU Telnetd Exploit)",
                    "summary": "POC Script for CVE-2026-24061 (GNU Telnetd Exploit)",
                    "url": "https://github.com/X-croot/CVE-2026-24061_POC"
                },
                {
                    "repository": "PoC-in-GitHub · SeptembersEND/CVE--2026-24061",
                    "author": "SeptembersEND",
                    "first_seen": "2026-02-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A docker image for CVE-2026-24061 in InetUtils telnetd.",
                    "summary": "A docker image for CVE-2026-24061 in InetUtils telnetd.",
                    "url": "https://github.com/SeptembersEND/CVE--2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · lavabyte/telnet-CVE-2026-24061",
                    "author": "lavabyte",
                    "first_seen": "2026-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/lavabyte/telnet-CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · canpilayda/inetutils-telnetd-cve-2026-24061",
                    "author": "canpilayda",
                    "first_seen": "2026-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/canpilayda/inetutils-telnetd-cve-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · killsystema/scan-cve-2026-24061",
                    "author": "killsystema",
                    "first_seen": "2026-02-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/killsystema/scan-cve-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · nrnw/CVE-2026-24061-GNU-inetutils-Telnet-Detector",
                    "author": "nrnw",
                    "first_seen": "2026-02-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A passive detection tool for identifying potential exposure to CVE-2026-24061 in GNU inetutils telnet installations",
                    "summary": "A passive detection tool for identifying potential exposure to CVE-2026-24061 in GNU inetutils telnet installations",
                    "url": "https://github.com/nrnw/CVE-2026-24061-GNU-inetutils-Telnet-Detector"
                },
                {
                    "repository": "PoC-in-GitHub · scumfrog/cve-2026-24061",
                    "author": "scumfrog",
                    "first_seen": "2026-02-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 PoC",
                    "summary": "CVE-2026-24061 PoC",
                    "url": "https://github.com/scumfrog/cve-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · tiborscholtz/CVE-2026-24061",
                    "author": "tiborscholtz",
                    "first_seen": "2026-02-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A lightweight Docker lab for experimenting with Telnet protocol negotiation, explained in the CVE-2026-24061 exploit, which contains automatic username injection using the NEW-ENVIRON option.",
                    "summary": "A lightweight Docker lab for experimenting with Telnet protocol negotiation, explained in the CVE-2026-24061 exploit, which contains automatic username injection using the NEW-ENVIRON option.",
                    "url": "https://github.com/tiborscholtz/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · athack-ctf/chall2026-telneted",
                    "author": "athack-ctf",
                    "first_seen": "2026-02-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "[AtHack 2026] Pwn challenge about telnetd CVE-2026-24061",
                    "summary": "[AtHack 2026] Pwn challenge about telnetd CVE-2026-24061",
                    "url": "https://github.com/athack-ctf/chall2026-telneted"
                },
                {
                    "repository": "PoC-in-GitHub · mbanyamer/CVE-2026-24061-GNU-Inetutils-telnetd-Remote-Authentication-Bypass-Root-Shell-",
                    "author": "mbanyamer",
                    "first_seen": "2026-02-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/mbanyamer/CVE-2026-24061-GNU-Inetutils-telnetd-Remote-Authentication-Bypass-Root-Shell-"
                },
                {
                    "repository": "PoC-in-GitHub · setuju/telnetd",
                    "author": "setuju",
                    "first_seen": "2026-03-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Idk what to do here, ill edit soon, but its for the telnetd CVE-2026-24061",
                    "summary": "Idk what to do here, ill edit soon, but its for the telnetd CVE-2026-24061",
                    "url": "https://github.com/setuju/telnetd"
                },
                {
                    "repository": "PoC-in-GitHub · 0xBlackash/CVE-2026-24061",
                    "author": "0xBlackash",
                    "first_seen": "2026-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-24061",
                    "summary": "CVE-2026-24061",
                    "url": "https://github.com/0xBlackash/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · HD0x01/CVE-2026-24061-NSE",
                    "author": "HD0x01",
                    "first_seen": "2026-03-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "The script performs a full Telnet negotiation mirroring the exact byte sequence of a real telnet -a client session.",
                    "summary": "The script performs a full Telnet negotiation mirroring the exact byte sequence of a real telnet -a client session.",
                    "url": "https://github.com/HD0x01/CVE-2026-24061-NSE"
                },
                {
                    "repository": "PoC-in-GitHub · przemytn/CVE-2026-24061",
                    "author": "przemytn",
                    "first_seen": "2026-03-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 PoC - telnetd auth bypass",
                    "summary": "CVE-2026-24061 PoC - telnetd auth bypass",
                    "url": "https://github.com/przemytn/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · ahmadsadeeq/TelnetdBypass-",
                    "author": "ahmadsadeeq",
                    "first_seen": "2026-06-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 — GNU InetUtils Telnetd Authentication Bypass Scanner",
                    "summary": "CVE-2026-24061 — GNU InetUtils Telnetd Authentication Bypass Scanner",
                    "url": "https://github.com/ahmadsadeeq/TelnetdBypass-"
                },
                {
                    "repository": "PoC-in-GitHub · tc4dy/CVE-2026-24061-PoC-Exploit",
                    "author": "tc4dy",
                    "first_seen": "2026-06-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "🚀 CVE-2026-24061 - GNU inetutils-telnetd Auth Bypass Exploit - Full Control 💥 CRLF injection via NEW_ENVIRON leads to auth bypass & instant root shell. ✅ Single/Mass exploitation, multi-threading, custom port/user, pipe mode, session keep-alive, colored output, retries, timeout support. ⚡ Python & Bash versions. Critical CVSS 9.8.",
                    "summary": "🚀 CVE-2026-24061 - GNU inetutils-telnetd Auth Bypass Exploit - Full Control 💥 CRLF injection via NEW_ENVIRON leads to auth bypass & instant root shell. ✅ Single/Mass exploitation, multi-threading, custom port/user, pipe mode, session keep-alive, colored output, retries, timeout support. ⚡ Python & Bash versions. Critical CVSS 9.8.",
                    "url": "https://github.com/tc4dy/CVE-2026-24061-PoC-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · K3ysTr0K3R/CVE-2026-24061",
                    "author": "K3ysTr0K3R",
                    "first_seen": "2026-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass",
                    "summary": "A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass",
                    "url": "https://github.com/K3ysTr0K3R/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · anxs3c/CVE-2026-24061-GNU-InetUtils-telnetd",
                    "author": "anxs3c",
                    "first_seen": "2026-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability",
                    "summary": "GNU-InetUtils-telnetd-Authentication-Bypass-Vulnerability",
                    "url": "https://github.com/anxs3c/CVE-2026-24061-GNU-InetUtils-telnetd"
                },
                {
                    "repository": "PoC-in-GitHub · akpmarcelin/CVE-2026-24061-lab",
                    "author": "akpmarcelin",
                    "first_seen": "2026-06-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/akpmarcelin/CVE-2026-24061-lab"
                },
                {
                    "repository": "PoC-in-GitHub · kyukazamiqq/CVE-2026-24061",
                    "author": "kyukazamiqq",
                    "first_seen": "2026-06-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 repository",
                    "summary": "",
                    "url": "https://github.com/kyukazamiqq/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · harygovind/CVE-2026-24061",
                    "author": "harygovind",
                    "first_seen": "2026-07-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061-PoC",
                    "summary": "CVE-2026-24061-PoC",
                    "url": "https://github.com/harygovind/CVE-2026-24061"
                },
                {
                    "repository": "PoC-in-GitHub · stoerti2/Abyssal",
                    "author": "stoerti2",
                    "first_seen": "2026-07-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Abyssal is a high-performance Telnet vulnerability scanner for CVE-2026-24061,  delivering root shells on vulnerable systems with false-positive detection.",
                    "summary": "Abyssal is a high-performance Telnet vulnerability scanner for CVE-2026-24061,  delivering root shells on vulnerable systems with false-positive detection.",
                    "url": "https://github.com/stoerti2/Abyssal"
                },
                {
                    "repository": "PoC-in-GitHub · iLokaas/CVE-2026-24061-payload",
                    "author": "iLokaas",
                    "first_seen": "2026-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass",
                    "summary": "A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass",
                    "url": "https://github.com/iLokaas/CVE-2026-24061-payload"
                },
                {
                    "repository": "PoC-in-GitHub · Ish3ng0m4/CVE-2026-24061-Telnetd",
                    "author": "Ish3ng0m4",
                    "first_seen": "2026-09-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-24061 GNU Inetutils Telnetd Authentication Bypass",
                    "summary": "CVE-2026-24061 GNU Inetutils Telnetd Authentication Bypass",
                    "url": "https://github.com/Ish3ng0m4/CVE-2026-24061-Telnetd"
                },
                {
                    "repository": "PoC-in-GitHub · skyejacobson/CyberhawksLab-telnetCVE",
                    "author": "skyejacobson",
                    "first_seen": "2026-09-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Writeup/finding of CVE-2026-24061 within the Cyberhawks lab",
                    "summary": "Writeup/finding of CVE-2026-24061 within the Cyberhawks lab",
                    "url": "https://github.com/skyejacobson/CyberhawksLab-telnetCVE"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52524",
                "https://github.com/obrunolima1910/CVE-2026-24061",
                "https://github.com/jacubes/CVE-2026-24061",
                "https://github.com/SafeBreach-Labs/CVE-2026-24061",
                "https://github.com/franckferman/CVE-2026-24061",
                "https://github.com/ekomsSavior/telnet_scan",
                "https://github.com/0p5cur/CVE-2026-24061-POC",
                "https://github.com/s-vx/CVE-2026-24061",
                "https://github.com/Lingzesec/CVE-2026-24061-GUI",
                "https://github.com/leonjza/inetutils-telnetd-auth-bypass",
                "https://github.com/duy-31/CVE-2026-24061---telnetd",
                "https://github.com/TryA9ain/CVE-2026-24061",
                "https://github.com/parameciumzhang/Tell-Me-Root",
                "https://github.com/Chocapikk/CVE-2026-24061",
                "https://github.com/JayGLXR/CVE-2026-24061-POC",
                "https://github.com/h3athen/CVE-2026-24061",
                "https://github.com/xuemian168/CVE-2026-24061",
                "https://github.com/monstertsl/CVE-2026-24061",
                "https://github.com/r00tuser111/CVE-2026-24061",
                "https://github.com/balgan/CVE-2026-24061",
                "https://github.com/sh4den/CVE-2026-24061",
                "https://github.com/z3n70/CVE-2026-24061",
                "https://github.com/Mr-Zapi/CVE-2026-24061",
                "https://github.com/midox008/CVE-2026-24061",
                "https://github.com/BrainBob/CVE-2026-24061",
                "https://github.com/BrainBob/Telnet-TestVuln-CVE-2026-24061",
                "https://github.com/shivam-bathla/CVE-2026-24061-setup",
                "https://github.com/madfxr/Twenty-Three-Scanner",
                "https://github.com/Alter-N0X/CVE-2026-24061-POC",
                "https://github.com/typeconfused/CVE-2026-24061",
                "https://github.com/Mefhika120/Ashwesker-CVE-2026-24061",
                "https://github.com/infat0x/CVE-2026-24061",
                "https://github.com/ms0x08-dev/CVE-2026-24061-POC",
                "https://github.com/punitdarji/telnetd-cve-2026-24061",
                "https://github.com/XsanFlip/CVE-2026-24061-Scanner",
                "https://github.com/LucasPDiniz/CVE-2026-24061",
                "https://github.com/FurkanKAYAPINAR/CVE-2026-24061-telnet2root",
                "https://github.com/androidteacher/CVE-2026-24061-PoC-Telnetd",
                "https://github.com/cumakurt/tscan",
                "https://github.com/novitahk/Exploit-CVE-2026-24061",
                "https://github.com/Gabs-hub/CVE-2026-24061_Lab",
                "https://github.com/MY0723/GNU-Inetutils-telnet-CVE-2026-24061-",
                "https://github.com/0x7556/CVE-2026-24061",
                "https://github.com/Parad0x7e/CVE-2026-24061",
                "https://github.com/dotelpenguin/telnetd_CVE-2026-24061_tester",
                "https://github.com/JakeSwiz/telnet-inetutils-auth-bypass-CVE-2026-24061",
                "https://github.com/buzz075/CVE-2026-24061",
                "https://github.com/X-croot/CVE-2026-24061_POC",
                "https://github.com/SeptembersEND/CVE--2026-24061",
                "https://github.com/lavabyte/telnet-CVE-2026-24061",
                "https://github.com/canpilayda/inetutils-telnetd-cve-2026-24061",
                "https://github.com/killsystema/scan-cve-2026-24061",
                "https://github.com/nrnw/CVE-2026-24061-GNU-inetutils-Telnet-Detector",
                "https://github.com/scumfrog/cve-2026-24061",
                "https://github.com/tiborscholtz/CVE-2026-24061",
                "https://github.com/athack-ctf/chall2026-telneted",
                "https://github.com/mbanyamer/CVE-2026-24061-GNU-Inetutils-telnetd-Remote-Authentication-Bypass-Root-Shell-",
                "https://github.com/setuju/telnetd",
                "https://github.com/0xBlackash/CVE-2026-24061",
                "https://github.com/HD0x01/CVE-2026-24061-NSE",
                "https://github.com/przemytn/CVE-2026-24061",
                "https://github.com/ahmadsadeeq/TelnetdBypass-",
                "https://github.com/tc4dy/CVE-2026-24061-PoC-Exploit",
                "https://github.com/K3ysTr0K3R/CVE-2026-24061",
                "https://github.com/anxs3c/CVE-2026-24061-GNU-InetUtils-telnetd",
                "https://github.com/akpmarcelin/CVE-2026-24061-lab",
                "https://github.com/kyukazamiqq/CVE-2026-24061",
                "https://github.com/harygovind/CVE-2026-24061",
                "https://github.com/stoerti2/Abyssal",
                "https://github.com/iLokaas/CVE-2026-24061-payload",
                "https://github.com/Ish3ng0m4/CVE-2026-24061-Telnetd",
                "https://github.com/skyejacobson/CyberhawksLab-telnetCVE"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T10:23:43Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "epss": 0.97878,
            "severity": "CRITICAL",
            "metadata_source": "CNA",
            "cve_status": "Analyzed",
            "cve_published_at": "2026-01-21",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-24049",
            "vendor": "pypa",
            "product": "wheel",
            "title": "wheel vulnerability",
            "summary": "wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.",
            "updated_at": "2026-09-10T13:17:45.017",
            "published_at": "2026-01-22T05:16:23.157",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 0.40.0, < 0.46.2",
            "fixed": "See vendor advisory",
            "source_count": 75,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-01-22",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx"
                }
            ],
            "references": [
                "https://github.com/pypa/wheel/commit/7a7d2de96b22a9adf9208afcc9547e1001569fef",
                "https://github.com/pypa/wheel/releases/tag/0.46.2",
                "https://github.com/pypa/wheel/security/advisories/GHSA-8rrh-rw8j-w5fx",
                "https://access.redhat.com/errata/RHSA-2026:10184",
                "https://access.redhat.com/errata/RHSA-2026:13545",
                "https://access.redhat.com/errata/RHSA-2026:14020",
                "https://access.redhat.com/errata/RHSA-2026:1504",
                "https://access.redhat.com/errata/RHSA-2026:17599",
                "https://access.redhat.com/errata/RHSA-2026:1902",
                "https://access.redhat.com/errata/RHSA-2026:1939",
                "https://access.redhat.com/errata/RHSA-2026:1942",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:20089",
                "https://access.redhat.com/errata/RHSA-2026:2090",
                "https://access.redhat.com/errata/RHSA-2026:2106",
                "https://access.redhat.com/errata/RHSA-2026:2139",
                "https://access.redhat.com/errata/RHSA-2026:2675",
                "https://access.redhat.com/errata/RHSA-2026:2681",
                "https://access.redhat.com/errata/RHSA-2026:2694",
                "https://access.redhat.com/errata/RHSA-2026:2695",
                "https://access.redhat.com/errata/RHSA-2026:2710",
                "https://access.redhat.com/errata/RHSA-2026:2754",
                "https://access.redhat.com/errata/RHSA-2026:2762",
                "https://access.redhat.com/errata/RHSA-2026:2823",
                "https://access.redhat.com/errata/RHSA-2026:2865",
                "https://access.redhat.com/errata/RHSA-2026:2866",
                "https://access.redhat.com/errata/RHSA-2026:2900",
                "https://access.redhat.com/errata/RHSA-2026:2925",
                "https://access.redhat.com/errata/RHSA-2026:3461",
                "https://access.redhat.com/errata/RHSA-2026:3462",
                "https://access.redhat.com/errata/RHSA-2026:3713",
                "https://access.redhat.com/errata/RHSA-2026:3782",
                "https://access.redhat.com/errata/RHSA-2026:3958",
                "https://access.redhat.com/errata/RHSA-2026:3959",
                "https://access.redhat.com/errata/RHSA-2026:3960",
                "https://access.redhat.com/errata/RHSA-2026:4185",
                "https://access.redhat.com/errata/RHSA-2026:4215",
                "https://access.redhat.com/errata/RHSA-2026:4271",
                "https://access.redhat.com/errata/RHSA-2026:4942",
                "https://access.redhat.com/errata/RHSA-2026:5119",
                "https://access.redhat.com/errata/RHSA-2026:61628",
                "https://access.redhat.com/errata/RHSA-2026:6192",
                "https://access.redhat.com/errata/RHSA-2026:62115",
                "https://access.redhat.com/errata/RHSA-2026:6555",
                "https://access.redhat.com/errata/RHSA-2026:6562",
                "https://access.redhat.com/errata/RHSA-2026:6565",
                "https://access.redhat.com/errata/RHSA-2026:7250",
                "https://access.redhat.com/security/cve/CVE-2026-24049",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2431959",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24049.json"
            ],
            "timeline": [
                {
                    "at": "2026-01-22T05:16:23.157",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24049"
                }
            ]
        },
        {
            "id": "CVE-2026-23980",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-23980 — Authenticated error-based SQL injection in Apache Superset < 6.0.0 via sqlExpression bypass",
            "summary": "Exploit for CVE-2026-23980 — Authenticated error-based SQL injection in Apache Superset < 6.0.0 via sqlExpression bypass",
            "updated_at": "2026-09-12T22:00:00Z",
            "published_at": "2026-09-12T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 27,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · oscar-mine/CVE-2026-23980-Exploit",
                    "author": "oscar-mine",
                    "first_seen": "2026-04-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit for CVE-2026-23980 — Authenticated error-based SQL injection in Apache Superset < 6.0.0 via sqlExpression bypass",
                    "summary": "Exploit for CVE-2026-23980 — Authenticated error-based SQL injection in Apache Superset < 6.0.0 via sqlExpression bypass",
                    "url": "https://github.com/oscar-mine/CVE-2026-23980-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · hyphenTBG/CVE-2026-23980",
                    "author": "hyphenTBG",
                    "first_seen": "2026-09-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Modified exploit of CVE-2026-23980",
                    "summary": "Modified exploit of CVE-2026-23980",
                    "url": "https://github.com/hyphenTBG/CVE-2026-23980"
                }
            ],
            "references": [
                "https://github.com/oscar-mine/CVE-2026-23980-Exploit",
                "https://github.com/hyphenTBG/CVE-2026-23980"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/oscar-mine/CVE-2026-23980-Exploit"
                }
            ]
        },
        {
            "id": "CVE-2026-23940",
            "vendor": "hexpm",
            "product": "hexpm",
            "title": "hexpm vulnerability",
            "summary": "Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation.\n\nPublishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball. This can terminate the affected application instance and result in a denial of service for package publishing and potentially other package-processing functionality.\n\nThis issue affects hex.pm: before 2026-03-10.",
            "updated_at": "2026-09-08T14:17:21.340",
            "published_at": "2026-03-13T19:54:14.640",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2026-03-10 (date); 82911daf5f8fb2ab44f298e3ba22b90bc1ae3746 through before 495f01607d3eae4aed7ad09b2f54f31ec7a7df01 (git)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Uncontrolled Resource Consumption vulnerability in hexpm hexpm/hexpm allows Excessive Allocation.\n\nPublishing an oversized package can cause Hex.pm to run out of memory while extracting the uploaded package tarball. This can terminate the affected application instance and result in a denial of service for package publishing and potentially other package-processing functionality.\n\nThis issue affects hex.pm: before 2026-03-10.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.erlef.org/cves/CVE-2026-23940.html",
                "https://github.com/hexpm/hexpm/commit/495f01607d3eae4aed7ad09b2f54f31ec7a7df01",
                "https://github.com/hexpm/hexpm/commit/82911daf5f8fb2ab44f298e3ba22b90bc1ae3746",
                "https://github.com/hexpm/hexpm/security/advisories/GHSA-jp8w-gxf6-8hcr",
                "https://osv.dev/vulnerability/EEF-CVE-2026-23940"
            ],
            "timeline": [
                {
                    "at": "2026-03-13T19:54:14.640",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23940"
                }
            ]
        },
        {
            "id": "CVE-2026-23923",
            "vendor": "Zabbix",
            "product": "Zabbix",
            "title": "Zabbix vulnerability",
            "summary": "An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.",
            "updated_at": "2026-09-10T21:16:44.433",
            "published_at": "2026-03-24T19:16:50.740",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.4.0 through 7.4.6 (git)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-470",
            "what_happened": "An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.zabbix.com/browse/ZBX-27641"
            ],
            "timeline": [
                {
                    "at": "2026-03-24T19:16:50.740",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23923"
                }
            ]
        },
        {
            "id": "CVE-2026-23921",
            "vendor": "Zabbix",
            "product": "Zabbix",
            "title": "Zabbix vulnerability",
            "summary": "A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.",
            "updated_at": "2026-09-10T21:13:20.120",
            "published_at": "2026-03-24T19:16:50.563",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.0.0 through 7.0.21 (git); 7.2.0 through 7.2.14 (git); 7.4.0 through 7.4.5 (git)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.zabbix.com/browse/ZBX-27640"
            ],
            "timeline": [
                {
                    "at": "2026-03-24T19:16:50.563",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23921"
                }
            ]
        },
        {
            "id": "CVE-2026-23920",
            "vendor": "Zabbix",
            "product": "Zabbix",
            "title": "Zabbix vulnerability",
            "summary": "Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.",
            "updated_at": "2026-09-10T21:15:39.950",
            "published_at": "2026-03-24T19:16:49.557",
            "cvss": 7.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.0.0 through 7.0.21 (git); 7.2.0 through 7.2.14 (git); 7.4.0 through 7.4.5 (git)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://support.zabbix.com/browse/ZBX-27639"
            ],
            "timeline": [
                {
                    "at": "2026-03-24T19:16:49.557",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23920"
                }
            ]
        },
        {
            "id": "CVE-2026-23855",
            "vendor": "Dell",
            "product": "iDRAC9",
            "title": "iDRAC9 vulnerability",
            "summary": "Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.",
            "updated_at": "2026-09-11T04:17:40.123",
            "published_at": "2026-09-09T17:17:19.837",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 7.30.10.50 or later (semver); before 7.00.00.184 or later (semver); before 1.30.30.50 or later (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000504998/dsa-2026-392-security-update-for-dell-idrac9-and-idrac10-vulnerability"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T17:17:19.837",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23855"
                }
            ]
        },
        {
            "id": "CVE-2026-23793",
            "vendor": "Samsung",
            "product": "Exynos 1330 firmware",
            "title": "Exynos 1330 firmware vulnerability",
            "summary": "An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400. An out-of-bounds memory access vulnerability in the camera GDC driver may lead to kernel memory corruption under certain conditions.",
            "updated_at": "2026-09-14T02:17:13.947",
            "published_at": "2026-09-14T02:17:13.947",
            "cvss": 3.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-08 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-787",
            "what_happened": "An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400. An out-of-bounds memory access vulnerability in the camera GDC driver may lead to kernel memory corruption under certain conditions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-23793/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:13.947",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23793"
                }
            ]
        },
        {
            "id": "CVE-2026-23792",
            "vendor": "Samsung",
            "product": "Exynos 1080 firmware",
            "title": "Exynos 1080 firmware vulnerability",
            "summary": "An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410. Incorrect handling of unauthenticated downlink RRC Setup messages can cause the baseband to crash.",
            "updated_at": "2026-09-14T02:17:13.807",
            "published_at": "2026-09-14T02:17:13.807",
            "cvss": 4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-10-22 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-346",
            "what_happened": "An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410. Incorrect handling of unauthenticated downlink RRC Setup messages can cause the baseband to crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-23792/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:13.807",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23792"
                }
            ]
        },
        {
            "id": "CVE-2026-23791",
            "vendor": "Samsung",
            "product": "Exynos 1280 firmware",
            "title": "Exynos 1280 firmware vulnerability",
            "summary": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory corruption and potential privilege escalation.",
            "updated_at": "2026-09-14T02:17:13.673",
            "published_at": "2026-09-14T02:17:13.673",
            "cvss": 4.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-29 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-787",
            "what_happened": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory corruption and potential privilege escalation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-23791/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:13.673",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23791"
                }
            ]
        },
        {
            "id": "CVE-2026-23790",
            "vendor": "Samsung",
            "product": "Exynos 1280 firmware",
            "title": "Exynos 1280 firmware vulnerability",
            "summary": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free.",
            "updated_at": "2026-09-14T02:17:13.537",
            "published_at": "2026-09-14T02:17:13.537",
            "cvss": 4.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-29 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-415",
            "what_happened": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory corruption and a potential use-after-free.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-23790/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:13.537",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23790"
                }
            ]
        },
        {
            "id": "CVE-2026-23789",
            "vendor": "Samsung",
            "product": "Exynos 850 firmware",
            "title": "Exynos 850 firmware vulnerability",
            "summary": "An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling) leads to kernel memory corruption and potential arbitrary code execution.",
            "updated_at": "2026-09-14T02:17:13.397",
            "published_at": "2026-09-14T02:17:13.397",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-23 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-415",
            "what_happened": "An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of dma_buf references during error handling) leads to kernel memory corruption and potential arbitrary code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-23789/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:13.397",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23789"
                }
            ]
        },
        {
            "id": "CVE-2026-23788",
            "vendor": "Samsung",
            "product": "Exynos 1280 firmware",
            "title": "Exynos 1280 firmware vulnerability",
            "summary": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash.",
            "updated_at": "2026-09-14T02:17:13.267",
            "published_at": "2026-09-14T02:17:13.267",
            "cvss": 4.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-25 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-122",
            "what_happened": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-23788/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T02:17:13.267",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23788"
                }
            ]
        },
        {
            "id": "CVE-2026-23787",
            "vendor": "Samsung",
            "product": "Exynos 1280 firmware",
            "title": "Exynos 1280 firmware vulnerability",
            "summary": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the Exynos DRM HDR driver (due to improper cleanup upon vmap failure) leads to a kernel crash.",
            "updated_at": "2026-09-14T02:17:13.140",
            "published_at": "2026-09-14T01:16:27.677",
            "cvss": 4.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-24 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the Exynos DRM HDR driver (due to improper cleanup upon vmap failure) leads to a kernel crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-23787/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T01:16:27.677",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23787"
                }
            ]
        },
        {
            "id": "CVE-2026-23786",
            "vendor": "Samsung",
            "product": "Exynos 1280 firmware",
            "title": "Exynos 1280 firmware vulnerability",
            "summary": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A TOCTOU race condition in the Exynos DRM HDR Driver leads to a heap overflow, causing a kernel crash.",
            "updated_at": "2026-09-14T02:17:12.230",
            "published_at": "2026-09-14T01:16:27.473",
            "cvss": 2.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2025-12-24 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-367",
            "what_happened": "An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A TOCTOU race condition in the Exynos DRM HDR Driver leads to a heap overflow, causing a kernel crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2026-23786/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T01:16:27.473",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23786"
                }
            ]
        },
        {
            "id": "CVE-2026-23745",
            "vendor": "isaacs",
            "product": "node-tar",
            "title": "node-tar vulnerability",
            "summary": "node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets. This vulnerability is fixed in 7.5.3.",
            "updated_at": "2026-09-07T13:18:15.473",
            "published_at": "2026-01-16T22:16:26.830",
            "cvss": 8.2,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "< 7.5.3",
            "fixed": "See vendor advisory",
            "source_count": 48,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets. This vulnerability is fixed in 7.5.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-01-16",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/isaacs/node-tar/security/advisories/GHSA-8qq5-rm4j-mr97"
                }
            ],
            "references": [
                "https://github.com/isaacs/node-tar/commit/340eb285b6d986e91969a1170d7fe9b0face405e",
                "https://github.com/isaacs/node-tar/security/advisories/GHSA-8qq5-rm4j-mr97",
                "https://access.redhat.com/errata/RHSA-2026:18480",
                "https://access.redhat.com/errata/RHSA-2026:18868",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:2144",
                "https://access.redhat.com/errata/RHSA-2026:2900",
                "https://access.redhat.com/errata/RHSA-2026:2926",
                "https://access.redhat.com/errata/RHSA-2026:3782",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:6192",
                "https://access.redhat.com/security/cve/CVE-2026-23745",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2430538",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23745.json"
            ],
            "timeline": [
                {
                    "at": "2026-01-16T22:16:26.830",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23745"
                }
            ]
        },
        {
            "id": "CVE-2026-23744",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "MCPJam Inspector - Remote Code Execution",
            "summary": "MCPJam Inspector - Remote Code Execution",
            "updated_at": "2026-08-22T22:00:00Z",
            "published_at": "2026-08-22T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1677,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52625",
                    "author": "Diamorphine",
                    "first_seen": "2026-07-07",
                    "confidence": "High",
                    "title": "MCPJam Inspector - Remote Code Execution",
                    "summary": "MCPJam Inspector - Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/52625",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · boroeurnprach/CVE-2026-23744-PoC",
                    "author": "boroeurnprach",
                    "first_seen": "2026-01-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, an attacker can trigger the installation and execution of a malicious MCP server by sending a crafted HTTP request. Version 1.4.3 contains a patch for this issue.",
                    "summary": "CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by default, an attacker can trigger the installation and execution of a malicious MCP server by sending a crafted HTTP request. Version 1.4.3 contains a patch for this issue.",
                    "url": "https://github.com/boroeurnprach/CVE-2026-23744-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · rootdirective-sec/CVE-2026-23744-Lab",
                    "author": "rootdirective-sec",
                    "first_seen": "2026-02-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-23744 repository",
                    "summary": "",
                    "url": "https://github.com/rootdirective-sec/CVE-2026-23744-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · suljov/CVE-2026-23744-Remote-Code-Execution-POC",
                    "author": "suljov",
                    "first_seen": "2026-03-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "MCPJam inspector contains a remote code execution",
                    "summary": "MCPJam inspector contains a remote code execution",
                    "url": "https://github.com/suljov/CVE-2026-23744-Remote-Code-Execution-POC"
                },
                {
                    "repository": "PoC-in-GitHub · H1sok444/CVE-2026-23744-PoC",
                    "author": "H1sok444",
                    "first_seen": "2026-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-23744 repository",
                    "summary": "",
                    "url": "https://github.com/H1sok444/CVE-2026-23744-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · fckoo/mcpjaminspector-unauth-rce",
                    "author": "fckoo",
                    "first_seen": "2026-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-23744 RCE in MCPJam inspector <= 1.4.2",
                    "summary": "CVE-2026-23744 RCE in MCPJam inspector <= 1.4.2",
                    "url": "https://github.com/fckoo/mcpjaminspector-unauth-rce"
                },
                {
                    "repository": "PoC-in-GitHub · FrenzisRed/CVE-2026-23744",
                    "author": "FrenzisRed",
                    "first_seen": "2026-03-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2026-23744 - MCPJam inspector Remote-Code-Execution: Proof Of Concept (POC",
                    "summary": "CVE-2026-23744 - MCPJam inspector Remote-Code-Execution: Proof Of Concept (POC",
                    "url": "https://github.com/FrenzisRed/CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · InzegoSec/CVE-2026-23744",
                    "author": "InzegoSec",
                    "first_seen": "2026-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Exploit to MCPJam Inspector <=1.4.2",
                    "summary": "Exploit to MCPJam Inspector <=1.4.2",
                    "url": "https://github.com/InzegoSec/CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · z4yd3/PoC-CVE-2026-23744",
                    "author": "z4yd3",
                    "first_seen": "2026-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Remote Code Execution on MCPJam Inspector <= 1.4.2",
                    "summary": "Remote Code Execution on MCPJam Inspector <= 1.4.2",
                    "url": "https://github.com/z4yd3/PoC-CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · ctzisme/CVE-2026-23744",
                    "author": "ctzisme",
                    "first_seen": "2026-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC for CVE-2026-23744, demonstrating an unauthenticated RCE in MCPJam Inspector (<= 1.4.2).",
                    "summary": "PoC for CVE-2026-23744, demonstrating an unauthenticated RCE in MCPJam Inspector (<= 1.4.2).",
                    "url": "https://github.com/ctzisme/CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · AhmadF77/CVE-2026-23744",
                    "author": "AhmadF77",
                    "first_seen": "2026-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "python script for exploiting CVE-2026-23744",
                    "summary": "python script for exploiting CVE-2026-23744",
                    "url": "https://github.com/AhmadF77/CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · fcjaviergarcia/CVE-2026-23744-POC",
                    "author": "fcjaviergarcia",
                    "first_seen": "2026-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Proof of Concept (PoC) exploit for CVE-2026-23744, a vulnerability affecting MCPJam Inspector that allows remote command execution (RCE) through exposed internal debugging endpoints",
                    "summary": "Proof of Concept (PoC) exploit for CVE-2026-23744, a vulnerability affecting MCPJam Inspector that allows remote command execution (RCE) through exposed internal debugging endpoints",
                    "url": "https://github.com/fcjaviergarcia/CVE-2026-23744-POC"
                },
                {
                    "repository": "PoC-in-GitHub · 0xg00se/CVE-2026-23744-script",
                    "author": "0xg00se",
                    "first_seen": "2026-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Exploit script for CVE-2026-23744",
                    "summary": "Exploit script for CVE-2026-23744",
                    "url": "https://github.com/0xg00se/CVE-2026-23744-script"
                },
                {
                    "repository": "PoC-in-GitHub · d3vn0mi/CVE-2026-23744-POC",
                    "author": "d3vn0mi",
                    "first_seen": "2026-03-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Python PoC for CVE-2026-23744, unauthenticated RCE in MCP servers via the /api/mcp/connect serverConfig command field (default port 6274)",
                    "summary": "Python PoC for CVE-2026-23744, unauthenticated RCE in MCP servers via the /api/mcp/connect serverConfig command field (default port 6274)",
                    "url": "https://github.com/d3vn0mi/CVE-2026-23744-POC"
                },
                {
                    "repository": "PoC-in-GitHub · CyLock11/CVE-2026-23744",
                    "author": "CyLock11",
                    "first_seen": "2026-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-23744 - MCP Connect RCE via Unauthenticated Command Injection",
                    "summary": "CVE-2026-23744 - MCP Connect RCE via Unauthenticated Command Injection",
                    "url": "https://github.com/CyLock11/CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · luiskrnr/exploit-CVE-2026-23744",
                    "author": "luiskrnr",
                    "first_seen": "2026-04-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets attackers send crafted HTTP request that installs an MCP server and runs code remotely, because the service listens on 0.0.0.0 (instead of 127.0.0.1) by default.",
                    "summary": "MCPJam Inspector is a local-first development platform for MCP servers. In versions 1.4.2 (and earlier), a RCE flaw lets attackers send crafted HTTP request that installs an MCP server and runs code remotely, because the service listens on 0.0.0.0 (instead of 127.0.0.1) by default.",
                    "url": "https://github.com/luiskrnr/exploit-CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · p1ctur3p3rf3ct/CVE-2026-23744",
                    "author": "p1ctur3p3rf3ct",
                    "first_seen": "2026-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-23744 PoC",
                    "summary": "CVE-2026-23744 PoC",
                    "url": "https://github.com/p1ctur3p3rf3ct/CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · thisisish/HTB-DevHub",
                    "author": "thisisish",
                    "first_seen": "2026-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2026-23744 RCE + Privilege Escalation",
                    "summary": "CVE-2026-23744 RCE + Privilege Escalation",
                    "url": "https://github.com/thisisish/HTB-DevHub"
                },
                {
                    "repository": "PoC-in-GitHub · SrGinebras/CVE-2026-23744-RCE-for-MCPjam-inspector-v1.4.2",
                    "author": "SrGinebras",
                    "first_seen": "2026-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-23744 repository",
                    "summary": "",
                    "url": "https://github.com/SrGinebras/CVE-2026-23744-RCE-for-MCPjam-inspector-v1.4.2"
                },
                {
                    "repository": "PoC-in-GitHub · sbouabid-sec/CVE-2026-23744-POC",
                    "author": "sbouabid-sec",
                    "first_seen": "2026-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-23744 — Proof of concept exploit for an unauthenticated Remote Code Execution vulnerability in MCPJam Inspector <= 1.4.2.",
                    "summary": "CVE-2026-23744 — Proof of concept exploit for an unauthenticated Remote Code Execution vulnerability in MCPJam Inspector <= 1.4.2.",
                    "url": "https://github.com/sbouabid-sec/CVE-2026-23744-POC"
                },
                {
                    "repository": "PoC-in-GitHub · Least-Significant-Bit/CVE-2026-23744",
                    "author": "Least-Significant-Bit",
                    "first_seen": "2026-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Remote Code Execution in MCPJam 1.4.2 and older",
                    "summary": "Remote Code Execution in MCPJam 1.4.2 and older",
                    "url": "https://github.com/Least-Significant-Bit/CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · afifudinmtop/MCPJam-Inspector-1.4.2-Remote-Code-Execution-CVE-2026-23744",
                    "author": "afifudinmtop",
                    "first_seen": "2026-06-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-23744 repository",
                    "summary": "",
                    "url": "https://github.com/afifudinmtop/MCPJam-Inspector-1.4.2-Remote-Code-Execution-CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · alisster00/CVE-2026-23744-RCE",
                    "author": "alisster00",
                    "first_seen": "2026-06-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This utility was created during research involving MCPJam v1.4.2. The application exposes an API endpoint that accepts a server configuration object. Under certain conditions, insufficient validation may allow unintended command execution.",
                    "summary": "This utility was created during research involving MCPJam v1.4.2. The application exposes an API endpoint that accepts a server configuration object. Under certain conditions, insufficient validation may allow unintended command execution.",
                    "url": "https://github.com/alisster00/CVE-2026-23744-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · m2sousa/CVE-2026-23744",
                    "author": "m2sousa",
                    "first_seen": "2026-06-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-23744 Proof-of-concept.",
                    "summary": "CVE-2026-23744 Proof-of-concept.",
                    "url": "https://github.com/m2sousa/CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · MrR0b0t19/CVE-2026-23744-PoC",
                    "author": "MrR0b0t19",
                    "first_seen": "2026-06-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-23744 repository",
                    "summary": "",
                    "url": "https://github.com/MrR0b0t19/CVE-2026-23744-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · jf-gondim/mcp-pwn",
                    "author": "jf-gondim",
                    "first_seen": "2026-06-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC exploit for CVE-2026-23744 — unauthenticated RCE in MCPJam Inspector via unvalidated serverConfig command injection on /api/mcp/connect, enabling reverse shell as process owner without credentials.",
                    "summary": "PoC exploit for CVE-2026-23744 — unauthenticated RCE in MCPJam Inspector via unvalidated serverConfig command injection on /api/mcp/connect, enabling reverse shell as process owner without credentials.",
                    "url": "https://github.com/jf-gondim/mcp-pwn"
                },
                {
                    "repository": "PoC-in-GitHub · avivyap/CVE-2026-23744",
                    "author": "avivyap",
                    "first_seen": "2026-06-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-23744",
                    "summary": "CVE-2026-23744",
                    "url": "https://github.com/avivyap/CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · Dahalsamir/CVE-2026-23744-MCPJAM-RCE-exploit",
                    "author": "Dahalsamir",
                    "first_seen": "2026-06-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an attacker to supply arbitrary server configuration parameters through the /api/mcp/connect endpoint.",
                    "summary": "This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an attacker to supply arbitrary server configuration parameters through the /api/mcp/connect endpoint.",
                    "url": "https://github.com/Dahalsamir/CVE-2026-23744-MCPJAM-RCE-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · keeieb79/CVE-2026-23744-poc",
                    "author": "keeieb79",
                    "first_seen": "2026-06-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "cve-2026-23744 python exploit",
                    "summary": "cve-2026-23744 python exploit",
                    "url": "https://github.com/keeieb79/CVE-2026-23744-poc"
                },
                {
                    "repository": "PoC-in-GitHub · oryk0/CVE-2026-23744",
                    "author": "oryk0",
                    "first_seen": "2026-06-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-23744 Reverse shell",
                    "summary": "CVE-2026-23744 Reverse shell",
                    "url": "https://github.com/oryk0/CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · kennedy-aikohi/mcpjam-cve-2026-23744-validator",
                    "author": "kennedy-aikohi",
                    "first_seen": "2026-06-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-23744 repository",
                    "summary": "",
                    "url": "https://github.com/kennedy-aikohi/mcpjam-cve-2026-23744-validator"
                },
                {
                    "repository": "PoC-in-GitHub · rohit-sundar/cve-2026-23744",
                    "author": "rohit-sundar",
                    "first_seen": "2026-06-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-23744 repository",
                    "summary": "",
                    "url": "https://github.com/rohit-sundar/cve-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · daemoncibsec/mcpExec",
                    "author": "daemoncibsec",
                    "first_seen": "2026-06-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "POC for CVE-2026-23744 for a python revshell",
                    "summary": "POC for CVE-2026-23744 for a python revshell",
                    "url": "https://github.com/daemoncibsec/mcpExec"
                },
                {
                    "repository": "PoC-in-GitHub · timgad794/DevHub-HTB-Walkthrough",
                    "author": "timgad794",
                    "first_seen": "2026-06-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Hack The Box - DevHub Machine Walkthrough (Medium Linux, CVE-2026-23744, Chisel Tunneling, Jupyter, Root Privilege Escalation)",
                    "summary": "Hack The Box - DevHub Machine Walkthrough (Medium Linux, CVE-2026-23744, Chisel Tunneling, Jupyter, Root Privilege Escalation)",
                    "url": "https://github.com/timgad794/DevHub-HTB-Walkthrough"
                },
                {
                    "repository": "PoC-in-GitHub · diamorphine666/CVE-2026-23744-exploit",
                    "author": "diamorphine666",
                    "first_seen": "2026-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit for MCPJam Inspector - Remote Code Execution (CVE-2026-23744)",
                    "summary": "Exploit for MCPJam Inspector - Remote Code Execution (CVE-2026-23744)",
                    "url": "https://github.com/diamorphine666/CVE-2026-23744-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · 0x77FSec/CVE-2026-23744",
                    "author": "0x77FSec",
                    "first_seen": "2026-07-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-23744 repository",
                    "summary": "",
                    "url": "https://github.com/0x77FSec/CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · ozcanpng/CVE-2026-23744",
                    "author": "ozcanpng",
                    "first_seen": "2026-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-23744 MCPJam Inspector unauthenticated RCE PoC",
                    "summary": "CVE-2026-23744 MCPJam Inspector unauthenticated RCE PoC",
                    "url": "https://github.com/ozcanpng/CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · CerberusMrXi/CVE-2026-23744-MCPJam-Exploit",
                    "author": "CerberusMrXi",
                    "first_seen": "2026-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw in versions <=1.4.2 and helps security researchers verify patches. For authorized testing and educational purposes only. Includes multiple payload options, command execution, and session management.",
                    "summary": "A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw in versions <=1.4.2 and helps security researchers verify patches. For authorized testing and educational purposes only. Includes multiple payload options, command execution, and session management.",
                    "url": "https://github.com/CerberusMrXi/CVE-2026-23744-MCPJam-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · nullRoot-Red/CVE-2026-23744",
                    "author": "nullRoot-Red",
                    "first_seen": "2026-07-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+).",
                    "summary": "Proof-of-concept and offensive security research analyzing CVE-2026-23744 (MCPJam Inspector Unauthenticated RCE, Patched in v1.4.3+).",
                    "url": "https://github.com/nullRoot-Red/CVE-2026-23744"
                },
                {
                    "repository": "PoC-in-GitHub · Mluex0/CVE-2026-23744-PoC",
                    "author": "Mluex0",
                    "first_seen": "2026-08-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with PTY.",
                    "summary": "CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with PTY.",
                    "url": "https://github.com/Mluex0/CVE-2026-23744-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · sonnelon/CVE-2026-23744-PoC",
                    "author": "sonnelon",
                    "first_seen": "2026-08-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "The poc of CVE-2026-23744",
                    "summary": "The poc of CVE-2026-23744",
                    "url": "https://github.com/sonnelon/CVE-2026-23744-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · itsC1SCO/mcpjam-to-root",
                    "author": "itsC1SCO",
                    "first_seen": "2026-08-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "From MCPJam Inspector RCE to root — CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege escalation",
                    "summary": "From MCPJam Inspector RCE to root — CVE-2026-23744, JupyterLab token disclosure, kernel execution, and OPSMCP privilege escalation",
                    "url": "https://github.com/itsC1SCO/mcpjam-to-root"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52625",
                "https://github.com/boroeurnprach/CVE-2026-23744-PoC",
                "https://github.com/rootdirective-sec/CVE-2026-23744-Lab",
                "https://github.com/suljov/CVE-2026-23744-Remote-Code-Execution-POC",
                "https://github.com/H1sok444/CVE-2026-23744-PoC",
                "https://github.com/fckoo/mcpjaminspector-unauth-rce",
                "https://github.com/FrenzisRed/CVE-2026-23744",
                "https://github.com/InzegoSec/CVE-2026-23744",
                "https://github.com/z4yd3/PoC-CVE-2026-23744",
                "https://github.com/ctzisme/CVE-2026-23744",
                "https://github.com/AhmadF77/CVE-2026-23744",
                "https://github.com/fcjaviergarcia/CVE-2026-23744-POC",
                "https://github.com/0xg00se/CVE-2026-23744-script",
                "https://github.com/d3vn0mi/CVE-2026-23744-POC",
                "https://github.com/CyLock11/CVE-2026-23744",
                "https://github.com/luiskrnr/exploit-CVE-2026-23744",
                "https://github.com/p1ctur3p3rf3ct/CVE-2026-23744",
                "https://github.com/thisisish/HTB-DevHub",
                "https://github.com/SrGinebras/CVE-2026-23744-RCE-for-MCPjam-inspector-v1.4.2",
                "https://github.com/sbouabid-sec/CVE-2026-23744-POC",
                "https://github.com/Least-Significant-Bit/CVE-2026-23744",
                "https://github.com/afifudinmtop/MCPJam-Inspector-1.4.2-Remote-Code-Execution-CVE-2026-23744",
                "https://github.com/alisster00/CVE-2026-23744-RCE",
                "https://github.com/m2sousa/CVE-2026-23744",
                "https://github.com/MrR0b0t19/CVE-2026-23744-PoC",
                "https://github.com/jf-gondim/mcp-pwn",
                "https://github.com/avivyap/CVE-2026-23744",
                "https://github.com/Dahalsamir/CVE-2026-23744-MCPJAM-RCE-exploit",
                "https://github.com/keeieb79/CVE-2026-23744-poc",
                "https://github.com/oryk0/CVE-2026-23744",
                "https://github.com/kennedy-aikohi/mcpjam-cve-2026-23744-validator",
                "https://github.com/rohit-sundar/cve-2026-23744",
                "https://github.com/daemoncibsec/mcpExec",
                "https://github.com/timgad794/DevHub-HTB-Walkthrough",
                "https://github.com/diamorphine666/CVE-2026-23744-exploit",
                "https://github.com/0x77FSec/CVE-2026-23744",
                "https://github.com/ozcanpng/CVE-2026-23744",
                "https://github.com/CerberusMrXi/CVE-2026-23744-MCPJam-Exploit",
                "https://github.com/nullRoot-Red/CVE-2026-23744",
                "https://github.com/Mluex0/CVE-2026-23744-PoC",
                "https://github.com/sonnelon/CVE-2026-23744-PoC",
                "https://github.com/itsC1SCO/mcpjam-to-root"
            ],
            "timeline": [
                {
                    "at": "2026-08-22T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52625"
                }
            ]
        },
        {
            "id": "CVE-2026-23459",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS\n\nBlamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which\ncall iptunnel_xmit_stats().\n\niptunnel_xmit_stats() was assuming tunnels were only using\nNETDEV_PCPU_STAT_TSTATS.\n\n@syncp offset in pcpu_sw_netstats and pcpu_dstats is different.\n\n32bit kernels would either have corruptions or freezes if the syncp\nsequence was overwritten.\n\nThis patch also moves pcpu_stat_type closer to dev->{t,d}stats to avoid\na potential cache line miss since iptunnel_xmit_stats() needs to read it.",
            "updated_at": "2026-09-07T16:17:27.923",
            "published_at": "2026-04-03T16:16:32.833",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "cb1c1f3b7ef908408064734fb6bdaf5811b8b84c through before e40e2d11ced8119d3e4469ebe91264bc1cf71530 (git); be226352e8dc77d3313c096b2d8e7f69bf6980fc through before 5d562153b4719234227f99c2fb529f98a6a44d15 (git); be226352e8dc77d3313c096b2d8e7f69bf6980fc through before 0d087d00161f562d5047cc4009bb0c6a19daf9f1 (git); be226352e8dc77d3313c096b2d8e7f69bf6980fc through before 8431c602f551549f082bbfa67f3003f2d8e3e132 (git); 1db9041e91ac574f1cecc0e98e69ac35832e8088 (git); 6.6.153 through before 6.7 (semver); 6.14",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS\n\nBlamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which\ncall iptunnel_xmit_stats().\n\niptunnel_xmit_stats() was assuming tunnels were only using\nNETDEV_PCPU_STAT_TSTATS.\n\n@syncp offset in pcpu_sw_netstats and pcpu_dstats is different.\n\n32bit kernels would either have corruptions or freezes if the syncp\nsequence was overwritten.\n\nThis patch also moves pcpu_stat_type closer to dev->{t,d}stats to avoid\na potential cache line miss since iptunnel_xmit_stats() needs to read it.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0d087d00161f562d5047cc4009bb0c6a19daf9f1",
                "https://git.kernel.org/stable/c/5d562153b4719234227f99c2fb529f98a6a44d15",
                "https://git.kernel.org/stable/c/8431c602f551549f082bbfa67f3003f2d8e3e132",
                "https://git.kernel.org/stable/c/e40e2d11ced8119d3e4469ebe91264bc1cf71530"
            ],
            "timeline": [
                {
                    "at": "2026-04-03T16:16:32.833",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23459"
                }
            ]
        },
        {
            "id": "CVE-2026-23448",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check\n\ncdc_ncm_rx_verify_ndp16() validates that the NDP header and its DPE\nentries fit within the skb. The first check correctly accounts for\nndpoffset:\n\n  if ((ndpoffset + sizeof(struct usb_cdc_ncm_ndp16)) > skb_in->len)\n\nbut the second check omits it:\n\n  if ((sizeof(struct usb_cdc_ncm_ndp16) +\n       ret * (sizeof(struct usb_cdc_ncm_dpe16))) > skb_in->len)\n\nThis validates the DPE array size against the total skb length as if\nthe NDP were at offset 0, rather than at ndpoffset. When the NDP is\nplaced near the end of the NTB (large wNdpIndex), the DPE entries can\nextend past the skb data buffer even though the check passes.\ncdc_ncm_rx_fixup() then reads out-of-bounds memory when iterating\nthe DPE array.\n\nAdd ndpoffset to the nframes bounds check and use struct_size_t() to\nexpress the NDP-plus-DPE-array size more clearly.",
            "updated_at": "2026-09-14T12:17:40.310",
            "published_at": "2026-04-03T16:16:30.863",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "ff06ab13a4ccae4acb44a2d4e3ece367b616ab50 through before 63c35b8fce77a7892e8fa06c540d4943145506eb (git); ff06ab13a4ccae4acb44a2d4e3ece367b616ab50 through before f1c7701d3ac91b62d672c13690cf295821f0d5c3 (git); ff06ab13a4ccae4acb44a2d4e3ece367b616ab50 through before 789204f980730258c983102c027c375238009c80 (git); ff06ab13a4ccae4acb44a2d4e3ece367b616ab50 through before 403f94ddcb36c552fbef51dea735b131e3dcde8b (git); ff06ab13a4ccae4acb44a2d4e3ece367b616ab50 through before dce9dda0e3707e887977db44407989e9ead26611 (git); ff06ab13a4ccae4acb44a2d4e3ece367b616ab50 through before 2aa8a4fa8d5b7d0e1ebcec100e1a4d80a1f4b21a (git); 3.8",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-129",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check\n\ncdc_ncm_rx_verify_ndp16() validates that the NDP header and its DPE\nentries fit within the skb. The first check correctly accounts for\nndpoffset:\n\n  if ((ndpoffset + sizeof(struct usb_cdc_ncm_ndp16)) > skb_in->len)\n\nbut the second check omits it:\n\n  if ((sizeof(struct usb_cdc_ncm_ndp16) +\n       ret * (sizeof(struct usb_cdc_ncm_dpe16))) > skb_in->len)\n\nThis validates the DPE array size against the total skb length as if\nthe NDP were at offset 0, rather than at ndpoffset. When the NDP is\nplaced near the end of the NTB (large wNdpIndex), the DPE entries can\nextend past the skb data buffer even though the check passes.\ncdc_ncm_rx_fixup() then reads out-of-bounds memory when iterating\nthe DPE array.\n\nAdd ndpoffset to the nframes bounds check and use struct_size_t() to\nexpress the NDP-plus-DPE-array size more clearly.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2aa8a4fa8d5b7d0e1ebcec100e1a4d80a1f4b21a",
                "https://git.kernel.org/stable/c/403f94ddcb36c552fbef51dea735b131e3dcde8b",
                "https://git.kernel.org/stable/c/63c35b8fce77a7892e8fa06c540d4943145506eb",
                "https://git.kernel.org/stable/c/789204f980730258c983102c027c375238009c80",
                "https://git.kernel.org/stable/c/dce9dda0e3707e887977db44407989e9ead26611",
                "https://git.kernel.org/stable/c/f1c7701d3ac91b62d672c13690cf295821f0d5c3"
            ],
            "timeline": [
                {
                    "at": "2026-04-03T16:16:30.863",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23448"
                }
            ]
        },
        {
            "id": "CVE-2026-23447",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check\n\nThe same bounds-check bug fixed for NDP16 in the previous patch also\nexists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated\nagainst the total skb length without accounting for ndpoffset, allowing\nout-of-bounds reads when the NDP32 is placed near the end of the NTB.\n\nAdd ndpoffset to the nframes bounds check and use struct_size_t() to\nexpress the NDP-plus-DPE-array size more clearly.\n\nCompile-tested only.",
            "updated_at": "2026-09-14T12:17:39.423",
            "published_at": "2026-04-03T16:16:30.663",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0fa81b304a7973a499f844176ca031109487dd31 through before baf246d6680befde2086b1df9eb3aaba3fb6853f (git); 0fa81b304a7973a499f844176ca031109487dd31 through before 125f932a76a97904ef8a555f1dd53e5d0e288c54 (git); 0fa81b304a7973a499f844176ca031109487dd31 through before af0d1613d6751489dbf9f69aac1123f0b1e566e5 (git); 0fa81b304a7973a499f844176ca031109487dd31 through before a5bd5a2710310c965ea4153cba4210988a3454e2 (git); 0fa81b304a7973a499f844176ca031109487dd31 through before de70da1fb1d152e981ecb3157f7ec2b633005c16 (git); 0fa81b304a7973a499f844176ca031109487dd31 through before 77914255155e68a20aa41175edeecf8121dac391 (git); 8cf7db86a8984ffa3a3388a8df12bc0aa4c79bd7 (git); 4ca8b8855264cf1439cdab3da7049bd1e3c2a9e6 (git); a270ca35a9499b58366d696d3290eaa4697a42db (git); 4.14.317 through before 4.15 (semver); 4.19.285 through before 4.20 (semver); 5.4.245 through before 5.5 (semver); 5.7",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-129",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check\n\nThe same bounds-check bug fixed for NDP16 in the previous patch also\nexists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated\nagainst the total skb length without accounting for ndpoffset, allowing\nout-of-bounds reads when the NDP32 is placed near the end of the NTB.\n\nAdd ndpoffset to the nframes bounds check and use struct_size_t() to\nexpress the NDP-plus-DPE-array size more clearly.\n\nCompile-tested only.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/125f932a76a97904ef8a555f1dd53e5d0e288c54",
                "https://git.kernel.org/stable/c/77914255155e68a20aa41175edeecf8121dac391",
                "https://git.kernel.org/stable/c/a5bd5a2710310c965ea4153cba4210988a3454e2",
                "https://git.kernel.org/stable/c/af0d1613d6751489dbf9f69aac1123f0b1e566e5",
                "https://git.kernel.org/stable/c/baf246d6680befde2086b1df9eb3aaba3fb6853f",
                "https://git.kernel.org/stable/c/de70da1fb1d152e981ecb3157f7ec2b633005c16"
            ],
            "timeline": [
                {
                    "at": "2026-04-03T16:16:30.663",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23447"
                }
            ]
        },
        {
            "id": "CVE-2026-23399",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnf_tables: nft_dynset: fix possible stateful expression memleak in error path\n\nIf cloning the second stateful expression in the element via GFP_ATOMIC\nfails, then the first stateful expression remains in place without being\nreleased.\n\n   unreferenced object (percpu) 0x607b97e9cab8 (size 16):\n     comm \"softirq\", pid 0, jiffies 4294931867\n     hex dump (first 16 bytes on cpu 3):\n       00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n     backtrace (crc 0):\n       pcpu_alloc_noprof+0x453/0xd80\n       nft_counter_clone+0x9c/0x190 [nf_tables]\n       nft_expr_clone+0x8f/0x1b0 [nf_tables]\n       nft_dynset_new+0x2cb/0x5f0 [nf_tables]\n       nft_rhash_update+0x236/0x11c0 [nf_tables]\n       nft_dynset_eval+0x11f/0x670 [nf_tables]\n       nft_do_chain+0x253/0x1700 [nf_tables]\n       nft_do_chain_ipv4+0x18d/0x270 [nf_tables]\n       nf_hook_slow+0xaa/0x1e0\n       ip_local_deliver+0x209/0x330",
            "updated_at": "2026-09-08T09:17:49.613",
            "published_at": "2026-03-28T08:15:56.720",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "563125a73ac30d7036ae69ca35c40500562c1de4 through before eb7bf413e59945df03d4567b73ce464eebe2f4ea (git); 563125a73ac30d7036ae69ca35c40500562c1de4 through before 4357dbb1d9c35ca0b4443d71c98a48e6666f7689 (git); 563125a73ac30d7036ae69ca35c40500562c1de4 through before e6661add2d9c6913e1dad97336595e23a2bed195 (git); 563125a73ac30d7036ae69ca35c40500562c1de4 through before d1354873cbe3b344899c4311ac05897fd83e3f21 (git); 563125a73ac30d7036ae69ca35c40500562c1de4 through before 31641c682db73353e4647e40735c7f2a75ff58ef (git); 563125a73ac30d7036ae69ca35c40500562c1de4 through before c88a9fd26cee365bec932196f76175772a941cca (git); 563125a73ac30d7036ae69ca35c40500562c1de4 through before 0548a13b5a145b16e4da0628b5936baf35f51b43 (git); 5.11; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-401",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnf_tables: nft_dynset: fix possible stateful expression memleak in error path\n\nIf cloning the second stateful expression in the element via GFP_ATOMIC\nfails, then the first stateful expression remains in place without being\nreleased.\n\n   unreferenced object (percpu) 0x607b97e9cab8 (size 16):\n     comm \"softirq\", pid 0, jiffies 4294931867\n     hex dump (first 16 bytes on cpu 3):\n       00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n     backtrace (crc 0):\n       pcpu_alloc_noprof+0x453/0xd80\n       nft_counter_clone+0x9c/0x190 [nf_tables]\n       nft_expr_clone+0x8f/0x1b0 [nf_tables]\n       nft_dynset_new+0x2cb/0x5f0 [nf_tables]\n       nft_rhash_update+0x236/0x11c0 [nf_tables]\n       nft_dynset_eval+0x11f/0x670 [nf_tables]\n       nft_do_chain+0x253/0x1700 [nf_tables]\n       nft_do_chain_ipv4+0x18d/0x270 [nf_tables]\n       nf_hook_slow+0xaa/0x1e0\n       ip_local_deliver+0x209/0x330",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0548a13b5a145b16e4da0628b5936baf35f51b43",
                "https://git.kernel.org/stable/c/31641c682db73353e4647e40735c7f2a75ff58ef",
                "https://git.kernel.org/stable/c/4357dbb1d9c35ca0b4443d71c98a48e6666f7689",
                "https://git.kernel.org/stable/c/c88a9fd26cee365bec932196f76175772a941cca",
                "https://git.kernel.org/stable/c/d1354873cbe3b344899c4311ac05897fd83e3f21",
                "https://git.kernel.org/stable/c/e6661add2d9c6913e1dad97336595e23a2bed195",
                "https://git.kernel.org/stable/c/eb7bf413e59945df03d4567b73ce464eebe2f4ea",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-03-28T08:15:56.720",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23399"
                }
            ]
        },
        {
            "id": "CVE-2026-23255",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: add proper RCU protection to /proc/net/ptype\n\nYin Fengwei reported an RCU stall in ptype_seq_show() and provided\na patch.\n\nReal issue is that ptype_seq_next() and ptype_seq_show() violate\nRCU rules.\n\nptype_seq_show() runs under rcu_read_lock(), and reads pt->dev\nto get device name without any barrier.\n\nAt the same time, concurrent writers can remove a packet_type structure\n(which is correctly freed after an RCU grace period) and clear pt->dev\nwithout an RCU grace period.\n\nDefine ptype_iter_state to carry a dev pointer along seq_net_private:\n\nstruct ptype_iter_state {\n\tstruct seq_net_private\tp;\n\tstruct net_device\t*dev; // added in this patch\n};\n\nWe need to record the device pointer in ptype_get_idx() and\nptype_seq_next() so that ptype_seq_show() is safe against\nconcurrent pt->dev changes.\n\nWe also need to add full RCU protection in ptype_seq_next().\n(Missing READ_ONCE() when reading list.next values)\n\nMany thanks to Dong Chenchen for providing a repro.",
            "updated_at": "2026-09-08T09:17:46.567",
            "published_at": "2026-03-18T18:16:23.687",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before e974a10a52618f7f57a4bce173a0ed96acd4e5dc (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 002a73470b56848e4c81efeaaedd471e92d66d8d (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before dcefd3f0b9ed8288654c75254bdcee8e1085e861 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 589a530ae44d0c80f523fcfd1a15af8087f27d35 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before f613e8b4afea0cd17c7168e8b00e25bc8d33175d (git); 2.6.12; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: add proper RCU protection to /proc/net/ptype\n\nYin Fengwei reported an RCU stall in ptype_seq_show() and provided\na patch.\n\nReal issue is that ptype_seq_next() and ptype_seq_show() violate\nRCU rules.\n\nptype_seq_show() runs under rcu_read_lock(), and reads pt->dev\nto get device name without any barrier.\n\nAt the same time, concurrent writers can remove a packet_type structure\n(which is correctly freed after an RCU grace period) and clear pt->dev\nwithout an RCU grace period.\n\nDefine ptype_iter_state to carry a dev pointer along seq_net_private:\n\nstruct ptype_iter_state {\n\tstruct seq_net_private\tp;\n\tstruct net_device\t*dev; // added in this patch\n};\n\nWe need to record the device pointer in ptype_get_idx() and\nptype_seq_next() so that ptype_seq_show() is safe against\nconcurrent pt->dev changes.\n\nWe also need to add full RCU protection in ptype_seq_next().\n(Missing READ_ONCE() when reading list.next values)\n\nMany thanks to Dong Chenchen for providing a repro.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/002a73470b56848e4c81efeaaedd471e92d66d8d",
                "https://git.kernel.org/stable/c/589a530ae44d0c80f523fcfd1a15af8087f27d35",
                "https://git.kernel.org/stable/c/dcefd3f0b9ed8288654c75254bdcee8e1085e861",
                "https://git.kernel.org/stable/c/e974a10a52618f7f57a4bce173a0ed96acd4e5dc",
                "https://git.kernel.org/stable/c/f613e8b4afea0cd17c7168e8b00e25bc8d33175d",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2026-03-18T18:16:23.687",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23255"
                }
            ]
        },
        {
            "id": "CVE-2026-23201",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix oops due to invalid pointer for kfree() in parse_longname()\n\nThis fixes a kernel oops when reading ceph snapshot directories (.snap),\nfor example by simply running `ls /mnt/my_ceph/.snap`.\n\nThe variable str is guarded by __free(kfree), but advanced by one for\nskipping the initial '_' in snapshot names. Thus, kfree() is called\nwith an invalid pointer.  This patch removes the need for advancing the\npointer so kfree() is called with correct memory pointer.\n\nSteps to reproduce:\n\n1. Create snapshots on a cephfs volume (I've 63 snaps in my testcase)\n\n2. Add cephfs mount to fstab\n$ echo \"samba-fileserver@.files=/volumes/datapool/stuff/3461082b-ecc9-4e82-8549-3fd2590d3fb6      /mnt/test/stuff   ceph     acl,noatime,_netdev    0       0\" >> /etc/fstab\n\n3. Reboot the system\n$ systemctl reboot\n\n4. Check if it's really mounted\n$ mount | grep stuff\n\n5. List snapshots (expected 63 snapshots on my system)\n$ ls /mnt/test/stuff/.snap\n\nNow ls hangs forever and the kernel log shows the oops.",
            "updated_at": "2026-09-14T12:17:39.287",
            "published_at": "2026-02-14T17:15:57.950",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4b9aee707c4580511983a0998547f3b28514e6a6 through before c9a129c82ddf82a50b4f8960d2609714ca2dbd26 (git); bb80f7618832d26f7e395f52f82b1dac76223e5f through before 8c9af7339de419819cfc641d551675d38ff99abf (git); 101841c38346f4ca41dc1802c867da990ffb32eb through before e258ed369c9e04caa7d2fd49785d753ae4034cb6 (git); 101841c38346f4ca41dc1802c867da990ffb32eb through before bc8dedae022ce3058659c3addef3ec4b41d15e00 (git); 3145b2b11492d61c512bbc59660bb823bc757f48 (git); 493479af8af3ab907f49e99323777d498a4fbd2b (git); 6.12.42 through before 6.12.70 (semver); 6.15.10 through before 6.16 (semver); 6.16.1 through before 6.17 (semver); 6.17",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix oops due to invalid pointer for kfree() in parse_longname()\n\nThis fixes a kernel oops when reading ceph snapshot directories (.snap),\nfor example by simply running `ls /mnt/my_ceph/.snap`.\n\nThe variable str is guarded by __free(kfree), but advanced by one for\nskipping the initial '_' in snapshot names. Thus, kfree() is called\nwith an invalid pointer.  This patch removes the need for advancing the\npointer so kfree() is called with correct memory pointer.\n\nSteps to reproduce:\n\n1. Create snapshots on a cephfs volume (I've 63 snaps in my testcase)\n\n2. Add cephfs mount to fstab\n$ echo \"samba-fileserver@.files=/volumes/datapool/stuff/3461082b-ecc9-4e82-8549-3fd2590d3fb6      /mnt/test/stuff   ceph     acl,noatime,_netdev    0       0\" >> /etc/fstab\n\n3. Reboot the system\n$ systemctl reboot\n\n4. Check if it's really mounted\n$ mount | grep stuff\n\n5. List snapshots (expected 63 snapshots on my system)\n$ ls /mnt/test/stuff/.snap\n\nNow ls hangs forever and the kernel log shows the oops.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/8c9af7339de419819cfc641d551675d38ff99abf",
                "https://git.kernel.org/stable/c/bc8dedae022ce3058659c3addef3ec4b41d15e00",
                "https://git.kernel.org/stable/c/c9a129c82ddf82a50b4f8960d2609714ca2dbd26",
                "https://git.kernel.org/stable/c/e258ed369c9e04caa7d2fd49785d753ae4034cb6"
            ],
            "timeline": [
                {
                    "at": "2026-02-14T17:15:57.950",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23201"
                }
            ]
        },
        {
            "id": "CVE-2026-23191",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: aloop: Fix racy access at PCM trigger\n\nThe PCM trigger callback of aloop driver tries to check the PCM state\nand stop the stream of the tied substream in the corresponding cable.\nSince both check and stop operations are performed outside the cable\nlock, this may result in UAF when a program attempts to trigger\nfrequently while opening/closing the tied stream, as spotted by\nfuzzers.\n\nFor addressing the UAF, this patch changes two things:\n- It covers the most of code in loopback_check_format() with\n  cable->lock spinlock, and add the proper NULL checks.  This avoids\n  already some racy accesses.\n- In addition, now we try to check the state of the capture PCM stream\n  that may be stopped in this function, which was the major pain point\n  leading to UAF.",
            "updated_at": "2026-09-14T12:17:39.100",
            "published_at": "2026-02-14T17:15:56.917",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "b1c73fc8e697eb73e23603e465e9af2711ed4183 through before f57467114f40c5aacebbea96fb4ff9e5cd2b7f18 (git); b1c73fc8e697eb73e23603e465e9af2711ed4183 through before c99be0d5af02adebe9cb6f9869d20397fa9935a3 (git); b1c73fc8e697eb73e23603e465e9af2711ed4183 through before f3ce8be893726899e3053cf8059ecc95d8410359 (git); b1c73fc8e697eb73e23603e465e9af2711ed4183 through before 0e6245b2424d126ac90018142d09f0707e12998b (git); b1c73fc8e697eb73e23603e465e9af2711ed4183 through before bad15420050db1803767e58756114800cce91ea4 (git); b1c73fc8e697eb73e23603e465e9af2711ed4183 through before 5727ccf9d19ca414cb76d9b647883822e2789c2e (git); b1c73fc8e697eb73e23603e465e9af2711ed4183 through before 826af7fa62e347464b1b4e0ba2fe19a92438084f (git); 2.6.37",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: aloop: Fix racy access at PCM trigger\n\nThe PCM trigger callback of aloop driver tries to check the PCM state\nand stop the stream of the tied substream in the corresponding cable.\nSince both check and stop operations are performed outside the cable\nlock, this may result in UAF when a program attempts to trigger\nfrequently while opening/closing the tied stream, as spotted by\nfuzzers.\n\nFor addressing the UAF, this patch changes two things:\n- It covers the most of code in loopback_check_format() with\n  cable->lock spinlock, and add the proper NULL checks.  This avoids\n  already some racy accesses.\n- In addition, now we try to check the state of the capture PCM stream\n  that may be stopped in this function, which was the major pain point\n  leading to UAF.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0e6245b2424d126ac90018142d09f0707e12998b",
                "https://git.kernel.org/stable/c/5727ccf9d19ca414cb76d9b647883822e2789c2e",
                "https://git.kernel.org/stable/c/826af7fa62e347464b1b4e0ba2fe19a92438084f",
                "https://git.kernel.org/stable/c/bad15420050db1803767e58756114800cce91ea4",
                "https://git.kernel.org/stable/c/c99be0d5af02adebe9cb6f9869d20397fa9935a3",
                "https://git.kernel.org/stable/c/f3ce8be893726899e3053cf8059ecc95d8410359",
                "https://git.kernel.org/stable/c/f57467114f40c5aacebbea96fb4ff9e5cd2b7f18"
            ],
            "timeline": [
                {
                    "at": "2026-02-14T17:15:56.917",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23191"
                }
            ]
        },
        {
            "id": "CVE-2026-23137",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nof: unittest: Fix memory leak in unittest_data_add()\n\nIn unittest_data_add(), if of_resolve_phandles() fails, the allocated\nunittest_data is not freed, leading to a memory leak.\n\nFix this by using scope-based cleanup helper __free(kfree) for automatic\nresource cleanup. This ensures unittest_data is automatically freed when\nit goes out of scope in error paths.\n\nFor the success path, use retain_and_null_ptr() to transfer ownership\nof the memory to the device tree and prevent double freeing.",
            "updated_at": "2026-09-14T12:17:38.967",
            "published_at": "2026-02-14T16:15:53.703",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2eb46da2a760e5764c48b752a5ef320e02b96b21 through before 58baf98d1bdab897fd796f39a16061bade229d71 (git); 2eb46da2a760e5764c48b752a5ef320e02b96b21 through before f09b0f705bd7197863b90256ef533a6414d1db2c (git); 2eb46da2a760e5764c48b752a5ef320e02b96b21 through before 235a1eb8d2dcc49a6cf0a5ee1aa85544a5d0054b (git); 3.18",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-401",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nof: unittest: Fix memory leak in unittest_data_add()\n\nIn unittest_data_add(), if of_resolve_phandles() fails, the allocated\nunittest_data is not freed, leading to a memory leak.\n\nFix this by using scope-based cleanup helper __free(kfree) for automatic\nresource cleanup. This ensures unittest_data is automatically freed when\nit goes out of scope in error paths.\n\nFor the success path, use retain_and_null_ptr() to transfer ownership\nof the memory to the device tree and prevent double freeing.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/235a1eb8d2dcc49a6cf0a5ee1aa85544a5d0054b",
                "https://git.kernel.org/stable/c/58baf98d1bdab897fd796f39a16061bade229d71",
                "https://git.kernel.org/stable/c/f09b0f705bd7197863b90256ef533a6414d1db2c"
            ],
            "timeline": [
                {
                    "at": "2026-02-14T16:15:53.703",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23137"
                }
            ]
        },
        {
            "id": "CVE-2026-22948",
            "vendor": "Cisco",
            "product": "Secure Access Appliance",
            "title": "Cisco appliance request parser inconsistency",
            "summary": "Different request parsing paths can disagree about a protected route on affected appliances.",
            "updated_at": "2026-09-01T08:12:00Z",
            "published_at": "2026-08-28T18:05:00Z",
            "cvss": 9.1,
            "confidence": 82,
            "confidence_label": "observed",
            "affected": "4.8.x",
            "fixed": "4.8.7",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Remote",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-444",
            "what_happened": "Two request parsing layers disagree about how a protected route is normalized.",
            "why_matters": "Edge appliances sit at a sensitive network boundary and are frequently accessible from less-trusted networks.",
            "mitigations": [
                "Upgrade to version 4.8.7.",
                "Restrict management interfaces.",
                "Review reverse-proxy and appliance logs for normalization anomalies."
            ],
            "pocs": [],
            "references": []
        },
        {
            "id": "CVE-2026-22797",
            "vendor": "OpenStack",
            "product": "keystonemiddleware",
            "title": "keystonemiddleware vulnerability",
            "summary": "An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middleware are affected.",
            "updated_at": "2026-09-10T13:17:43.557",
            "published_at": "2026-01-19T18:16:04.950",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.5.0 through before 10.7.2 (semver); 10.8.0 through before 10.9.1 (semver); 10.10.0 through before 10.12.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-290",
            "what_happened": "An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize incoming authentication headers before processing OAuth 2.0 tokens. By sending forged identity headers such as X-Is-Admin-Project, X-Roles, or X-User-Id, an authenticated attacker may escalate privileges or impersonate other users. All deployments using the external_oauth2_token middleware are affected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://launchpad.net/bugs/2129018",
                "https://www.openwall.com/lists/oss-security/2026/01/16/9",
                "http://www.openwall.com/lists/oss-security/2026/01/15/1",
                "http://www.openwall.com/lists/oss-security/2026/01/16/2",
                "http://www.openwall.com/lists/oss-security/2026/01/16/3",
                "http://www.openwall.com/lists/oss-security/2026/01/16/9",
                "https://access.redhat.com/errata/RHSA-2026:3402",
                "https://access.redhat.com/errata/RHSA-2026:3855",
                "https://access.redhat.com/errata/RHSA-2026:4434",
                "https://access.redhat.com/errata/RHSA-2026:5133",
                "https://access.redhat.com/errata/RHSA-2026:5907",
                "https://access.redhat.com/security/cve/CVE-2026-22797",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2430879",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22797.json"
            ],
            "timeline": [
                {
                    "at": "2026-01-19T18:16:04.950",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22797"
                }
            ]
        },
        {
            "id": "CVE-2026-22732",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Forced Browsing in Vmware Spring_Security CVE-2026-22732",
            "summary": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "updated_at": "2026-09-11T11:16:21Z",
            "published_at": "2026-09-11T11:16:21Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-425",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Forced Browsing in Vmware Spring_Security CVE-2026-22732",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-425",
                    "references": [
                        "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE",
                        "https://github.com/dylan-chainguard/cve-2026-22732-poc"
                    ],
                    "repository": "Sploitus",
                    "author": "dylan-chainguard",
                    "first_seen": "2026-09-11T13:16:21",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE"
                },
                {
                    "title": "Exploit for Forced Browsing in Vmware Spring_Security CVE-2026-22732",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-425",
                    "references": [
                        "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE",
                        "https://github.com/dylan-chainguard/cve-2026-22732-poc"
                    ],
                    "repository": "dylan-chainguard/cve-2026-22732-poc",
                    "author": "dylan-chainguard",
                    "first_seen": "2026-09-11T13:16:21",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/dylan-chainguard/cve-2026-22732-poc"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE",
                "https://github.com/dylan-chainguard/cve-2026-22732-poc"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T11:16:21Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2026-22708",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Gideon CVE-2024-21887",
            "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
            "updated_at": "2026-09-05T09:04:57Z",
            "published_at": "2026-09-05T09:04:57Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 27,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Gideon CVE-2024-21887",
                    "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                        "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T11:04:57",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON"
                },
                {
                    "title": "Exploit for Gideon CVE-2024-21887",
                    "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                        "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T11:04:57",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                "https://kitploit.com/ru/tools/github/cogensec/gideon/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T09:04:57Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-22029",
            "vendor": "remix-run",
            "product": "react-router",
            "title": "react-router vulnerability",
            "summary": "React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode (<BrowserRouter>) is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0.",
            "updated_at": "2026-09-10T13:17:42.633",
            "published_at": "2026-01-10T03:15:48.870",
            "cvss": 8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 7.0.0, < 7.12.0; < 1.23.2",
            "fixed": "See vendor advisory",
            "source_count": 42,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-79",
            "what_happened": "React Router is a router for React. In @remix-run/router version prior to 1.23.2 and react-router 7.0.0 through 7.11.0, React Router (and Remix v1/v2) SPA open navigation redirects originating from loaders or actions in Framework Mode, Data Mode, or the unstable RSC modes can result in unsafe URLs causing unintended javascript execution on the client. This is only an issue if you are creating redirect paths from untrusted content or via an open redirect. There is no impact if Declarative Mode (<BrowserRouter>) is being used. This issue has been patched in @remix-run/router version 1.23.2 and react-router version 7.12.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/remix-run/react-router/security/advisories/GHSA-2w69-qvjg-hvjx",
                "https://access.redhat.com/errata/RHSA-2026:13542",
                "https://access.redhat.com/errata/RHSA-2026:13548",
                "https://access.redhat.com/errata/RHSA-2026:1517",
                "https://access.redhat.com/errata/RHSA-2026:17468",
                "https://access.redhat.com/errata/RHSA-2026:17469",
                "https://access.redhat.com/errata/RHSA-2026:17474",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:20041",
                "https://access.redhat.com/errata/RHSA-2026:20042",
                "https://access.redhat.com/errata/RHSA-2026:2147",
                "https://access.redhat.com/errata/RHSA-2026:2148",
                "https://access.redhat.com/errata/RHSA-2026:2149",
                "https://access.redhat.com/errata/RHSA-2026:21658",
                "https://access.redhat.com/errata/RHSA-2026:2350",
                "https://access.redhat.com/errata/RHSA-2026:2456",
                "https://access.redhat.com/errata/RHSA-2026:2568",
                "https://access.redhat.com/errata/RHSA-2026:2572",
                "https://access.redhat.com/errata/RHSA-2026:26413",
                "https://access.redhat.com/errata/RHSA-2026:26420",
                "https://access.redhat.com/errata/RHSA-2026:2694",
                "https://access.redhat.com/errata/RHSA-2026:3087",
                "https://access.redhat.com/errata/RHSA-2026:34100",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:3782",
                "https://access.redhat.com/errata/RHSA-2026:3958",
                "https://access.redhat.com/errata/RHSA-2026:3959",
                "https://access.redhat.com/errata/RHSA-2026:3960",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:40984",
                "https://access.redhat.com/errata/RHSA-2026:41064",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:5633",
                "https://access.redhat.com/errata/RHSA-2026:5636",
                "https://access.redhat.com/errata/RHSA-2026:8218",
                "https://access.redhat.com/errata/RHSA-2026:8229",
                "https://access.redhat.com/errata/RHSA-2026:9848",
                "https://access.redhat.com/security/cve/CVE-2026-22029",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2428412",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22029.json"
            ],
            "timeline": [
                {
                    "at": "2026-01-10T03:15:48.870",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-22029"
                }
            ]
        },
        {
            "id": "CVE-2026-21962",
            "vendor": "Oracle",
            "product": "HTTP Server and Oracle Weblogic Server Proxy Plug-in",
            "title": "Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability",
            "summary": "Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.",
            "updated_at": "2026-08-23T22:00:00Z",
            "published_at": "2026-08-23T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 48,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-23T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-21858",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
            "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
            "updated_at": "2026-09-11T22:10:10Z",
            "published_at": "2026-09-11T22:10:10Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 43,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                },
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:10:10Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2026-21852",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-21852 repository",
            "summary": "Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536, CVE-2026-21852, CVE-2026-30615 + Pillar Rules File Backdoor patterns.",
            "updated_at": "2026-09-12T22:00:00Z",
            "published_at": "2026-09-12T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 53,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · atiilla/CVE-2026-21852-PoC",
                    "author": "atiilla",
                    "first_seen": "2026-02-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 24,
                    "title": "CVE-2026-21852 repository",
                    "summary": "",
                    "url": "https://github.com/atiilla/CVE-2026-21852-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · TreRB/ai-ide-config-guard",
                    "author": "TreRB",
                    "first_seen": "2026-04-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536, CVE-2026-21852, CVE-2026-30615 + Pillar Rules File Backdoor patterns.",
                    "summary": "Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536, CVE-2026-21852, CVE-2026-30615 + Pillar Rules File Backdoor patterns.",
                    "url": "https://github.com/TreRB/ai-ide-config-guard"
                },
                {
                    "repository": "PoC-in-GitHub · Perufitlife/dotclaude-security",
                    "author": "Perufitlife",
                    "first_seen": "2026-06-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Scan a repo's .claude/ config (settings.json hooks, MCP servers, env, allowed-tools) for the RCE & API-key-exfiltration footguns (CVE-2025-59536, CVE-2026-21852) that fire when you clone+open an untrusted repository. Static, zero-dep, local-first.",
                    "summary": "Scan a repo's .claude/ config (settings.json hooks, MCP servers, env, allowed-tools) for the RCE & API-key-exfiltration footguns (CVE-2025-59536, CVE-2026-21852) that fire when you clone+open an untrusted repository. Static, zero-dep, local-first.",
                    "url": "https://github.com/Perufitlife/dotclaude-security"
                },
                {
                    "repository": "PoC-in-GitHub · abhishek2512mishra/claude-code-security-audit",
                    "author": "abhishek2512mishra",
                    "first_seen": "2026-09-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Security scanner auditing Claude Code environments for CVE-2026-21852 pre-trust execution, hook hijacking, and eBPF lockdown.",
                    "summary": "Security scanner auditing Claude Code environments for CVE-2026-21852 pre-trust execution, hook hijacking, and eBPF lockdown.",
                    "url": "https://github.com/abhishek2512mishra/claude-code-security-audit"
                }
            ],
            "references": [
                "https://github.com/atiilla/CVE-2026-21852-PoC",
                "https://github.com/TreRB/ai-ide-config-guard",
                "https://github.com/Perufitlife/dotclaude-security",
                "https://github.com/abhishek2512mishra/claude-code-security-audit"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/atiilla/CVE-2026-21852-PoC"
                }
            ]
        },
        {
            "id": "CVE-2026-21803",
            "vendor": "Apple",
            "product": "WebKit",
            "title": "WebKit out-of-bounds read",
            "summary": "Malformed web content can trigger an out-of-bounds read in an image-processing path.",
            "updated_at": "2026-09-01T07:55:00Z",
            "published_at": "2026-08-28T13:44:00Z",
            "cvss": 6.5,
            "confidence": 78,
            "confidence_label": "observed",
            "affected": "Vendor advisory",
            "fixed": "Latest OS update",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Remote",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "An image-processing path can read beyond the expected object boundary when handling malformed web content.",
            "why_matters": "The affected engine is used across several system applications, broadening potential content exposure.",
            "mitigations": [
                "Apply the latest operating-system and browser updates.",
                "Prioritize managed mobile and desktop fleets.",
                "Review the vendor advisory for platform-specific fixed versions."
            ],
            "pocs": [],
            "references": []
        },
        {
            "id": "CVE-2026-21728",
            "vendor": "Grafana",
            "product": "Tempo",
            "title": "Tempo vulnerability",
            "summary": "Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.\n\nMitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.",
            "updated_at": "2026-09-07T13:18:11.477",
            "published_at": "2026-04-24T09:16:03.710",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.3.0 through 2.8.3 (semver); 2.9.0 through 2.9.1 (semver); 2.10.0 through 2.10.1 (semver); 1.0.0 through 2.8.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.\n\nMitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://grafana.com/security/security-advisories/cve-2026-21728",
                "https://access.redhat.com/errata/RHSA-2026:21769",
                "https://access.redhat.com/errata/RHSA-2026:22347",
                "https://access.redhat.com/errata/RHSA-2026:22423",
                "https://access.redhat.com/errata/RHSA-2026:23345",
                "https://access.redhat.com/errata/RHSA-2026:24503",
                "https://access.redhat.com/security/cve/CVE-2026-21728",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2461395",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21728.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-24T09:16:03.710",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21728"
                }
            ]
        },
        {
            "id": "CVE-2026-21587",
            "vendor": "Atlassian",
            "product": "Jira Service Management Data Center",
            "title": "Jira Service Management Data Center vulnerability",
            "summary": "This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. \n\t\n\tThis Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. \n\t\n\tAtlassian recommends that Jira Service Management Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\t\t\n\t\t* Jira Service Management Data Center 11.3: Upgrade to a release greater than or equal to 11.3.11\n\t\t\n\t\t\n\t\n\tSee the release notes (https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html). You can download the latest version of Jira Service Management Data Center from the download center (https://www.atlassian.com/software/jira/service-management/download-archives). \n\t\n\tThis vulnerability was reported via our Penetration Testing program.",
            "updated_at": "2026-09-16T04:18:22.153",
            "published_at": "2026-09-15T17:17:11.893",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.3.0 to 11.3.10",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. \n\t\n\tThis Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. \n\t\n\tAtlassian recommends that Jira Service Management Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\n\t\t\n\t\t* Jira Service Management Data Center 11.3: Upgrade to a release greater than or equal to 11.3.11\n\t\t\n\t\t\n\t\n\tSee the release notes (https://confluence.atlassian.com/servicemanagement/jira-service-management-release-notes-780083086.html). You can download the latest version of Jira Service Management Data Center from the download center (https://www.atlassian.com/software/jira/service-management/download-archives). \n\t\n\tThis vulnerability was reported via our Penetration Testing program.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://confluence.atlassian.com/pages/viewpage.action?pageId=1822852209",
                "https://jira.atlassian.com/browse/JSDSERVER-16747"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T17:17:11.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21587"
                }
            ]
        },
        {
            "id": "CVE-2026-21586",
            "vendor": "Atlassian",
            "product": "Confluence Data Center",
            "title": "Confluence Data Center vulnerability",
            "summary": "This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center.\r\n\r\nThis Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code.\r\n\r\nAtlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.24\r\n\r\n Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.17\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was reported via our Penetration Testing program.",
            "updated_at": "2026-09-16T04:18:21.760",
            "published_at": "2026-09-15T17:17:11.580",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.2.1 to 10.2.15; 10.1.0 to 10.1.2; 10.0.2 to 10.0.3; 9.5.1 to 9.5.4; 9.4.0 to 9.4.1; 9.3.1 to 9.3.2; 9.2.0 to 9.2.23; 9.1.1; 8.9.7 to 8.9.8; 8.5.16 to 8.5.31; 7.19.28 to 7.19.30",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-285",
            "what_happened": "This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center.\r\n\r\nThis Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code.\r\n\r\nAtlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions:\r\n Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.24\r\n\r\n Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.17\r\n\r\nSee the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]).\r\n\r\nThis vulnerability was reported via our Penetration Testing program.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://confluence.atlassian.com/pages/viewpage.action?pageId=1822852209",
                "https://jira.atlassian.com/browse/CONFSERVER-104418"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T17:17:11.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21586"
                }
            ]
        },
        {
            "id": "CVE-2026-21441",
            "vendor": "urllib3",
            "product": "urllib3",
            "title": "urllib3 vulnerability",
            "summary": "urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.",
            "updated_at": "2026-09-15T12:16:58.133",
            "published_at": "2026-01-07T22:15:44.040",
            "cvss": 8.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": ">= 1.22, < 2.6.3",
            "fixed": "See vendor advisory",
            "source_count": 118,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-409",
            "what_happened": "urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7b",
                "https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99",
                "https://lists.debian.org/debian-lts-announce/2026/01/msg00017.html",
                "https://access.redhat.com/errata/RHSA-2026:0981",
                "https://access.redhat.com/errata/RHSA-2026:0990",
                "https://access.redhat.com/errata/RHSA-2026:10184",
                "https://access.redhat.com/errata/RHSA-2026:1038",
                "https://access.redhat.com/errata/RHSA-2026:1041",
                "https://access.redhat.com/errata/RHSA-2026:1042",
                "https://access.redhat.com/errata/RHSA-2026:1086",
                "https://access.redhat.com/errata/RHSA-2026:1087",
                "https://access.redhat.com/errata/RHSA-2026:1088",
                "https://access.redhat.com/errata/RHSA-2026:1089",
                "https://access.redhat.com/errata/RHSA-2026:1166",
                "https://access.redhat.com/errata/RHSA-2026:1168",
                "https://access.redhat.com/errata/RHSA-2026:1176",
                "https://access.redhat.com/errata/RHSA-2026:1224",
                "https://access.redhat.com/errata/RHSA-2026:1226",
                "https://access.redhat.com/errata/RHSA-2026:1239",
                "https://access.redhat.com/errata/RHSA-2026:1240",
                "https://access.redhat.com/errata/RHSA-2026:1241",
                "https://access.redhat.com/errata/RHSA-2026:1254",
                "https://access.redhat.com/errata/RHSA-2026:1485",
                "https://access.redhat.com/errata/RHSA-2026:14877",
                "https://access.redhat.com/errata/RHSA-2026:1504",
                "https://access.redhat.com/errata/RHSA-2026:1546",
                "https://access.redhat.com/errata/RHSA-2026:1596",
                "https://access.redhat.com/errata/RHSA-2026:1599",
                "https://access.redhat.com/errata/RHSA-2026:1609",
                "https://access.redhat.com/errata/RHSA-2026:1618",
                "https://access.redhat.com/errata/RHSA-2026:1619",
                "https://access.redhat.com/errata/RHSA-2026:1652",
                "https://access.redhat.com/errata/RHSA-2026:1674",
                "https://access.redhat.com/errata/RHSA-2026:1676",
                "https://access.redhat.com/errata/RHSA-2026:1693",
                "https://access.redhat.com/errata/RHSA-2026:1704",
                "https://access.redhat.com/errata/RHSA-2026:1706",
                "https://access.redhat.com/errata/RHSA-2026:1712",
                "https://access.redhat.com/errata/RHSA-2026:1717",
                "https://access.redhat.com/errata/RHSA-2026:1726",
                "https://access.redhat.com/errata/RHSA-2026:1729",
                "https://access.redhat.com/errata/RHSA-2026:1730",
                "https://access.redhat.com/errata/RHSA-2026:1734",
                "https://access.redhat.com/errata/RHSA-2026:1735",
                "https://access.redhat.com/errata/RHSA-2026:1736",
                "https://access.redhat.com/errata/RHSA-2026:17456",
                "https://access.redhat.com/errata/RHSA-2026:17457",
                "https://access.redhat.com/errata/RHSA-2026:17460",
                "https://access.redhat.com/errata/RHSA-2026:17461",
                "https://access.redhat.com/errata/RHSA-2026:17462",
                "https://access.redhat.com/errata/RHSA-2026:17463",
                "https://access.redhat.com/errata/RHSA-2026:1791",
                "https://access.redhat.com/errata/RHSA-2026:1792",
                "https://access.redhat.com/errata/RHSA-2026:1793",
                "https://access.redhat.com/errata/RHSA-2026:1794",
                "https://access.redhat.com/errata/RHSA-2026:1803",
                "https://access.redhat.com/errata/RHSA-2026:1805",
                "https://access.redhat.com/errata/RHSA-2026:1942",
                "https://access.redhat.com/errata/RHSA-2026:1957",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:2106",
                "https://access.redhat.com/errata/RHSA-2026:2126",
                "https://access.redhat.com/errata/RHSA-2026:2137",
                "https://access.redhat.com/errata/RHSA-2026:2139",
                "https://access.redhat.com/errata/RHSA-2026:2144",
                "https://access.redhat.com/errata/RHSA-2026:2256",
                "https://access.redhat.com/errata/RHSA-2026:2456",
                "https://access.redhat.com/errata/RHSA-2026:2500",
                "https://access.redhat.com/errata/RHSA-2026:25127",
                "https://access.redhat.com/errata/RHSA-2026:2563",
                "https://access.redhat.com/errata/RHSA-2026:2681",
                "https://access.redhat.com/errata/RHSA-2026:2695",
                "https://access.redhat.com/errata/RHSA-2026:2717",
                "https://access.redhat.com/errata/RHSA-2026:2718",
                "https://access.redhat.com/errata/RHSA-2026:2723",
                "https://access.redhat.com/errata/RHSA-2026:2728",
                "https://access.redhat.com/errata/RHSA-2026:2760",
                "https://access.redhat.com/errata/RHSA-2026:2762",
                "https://access.redhat.com/errata/RHSA-2026:2764",
                "https://access.redhat.com/errata/RHSA-2026:2765",
                "https://access.redhat.com/errata/RHSA-2026:28043",
                "https://access.redhat.com/errata/RHSA-2026:28441",
                "https://access.redhat.com/errata/RHSA-2026:2900",
                "https://access.redhat.com/errata/RHSA-2026:2911",
                "https://access.redhat.com/errata/RHSA-2026:2919",
                "https://access.redhat.com/errata/RHSA-2026:2924",
                "https://access.redhat.com/errata/RHSA-2026:2925",
                "https://access.redhat.com/errata/RHSA-2026:2926",
                "https://access.redhat.com/errata/RHSA-2026:3296",
                "https://access.redhat.com/errata/RHSA-2026:33154",
                "https://access.redhat.com/errata/RHSA-2026:3406",
                "https://access.redhat.com/errata/RHSA-2026:3444",
                "https://access.redhat.com/errata/RHSA-2026:3461",
                "https://access.redhat.com/errata/RHSA-2026:3462",
                "https://access.redhat.com/errata/RHSA-2026:3713",
                "https://access.redhat.com/errata/RHSA-2026:3782",
                "https://access.redhat.com/errata/RHSA-2026:3869",
                "https://access.redhat.com/errata/RHSA-2026:3874",
                "https://access.redhat.com/errata/RHSA-2026:3884",
                "https://access.redhat.com/errata/RHSA-2026:3960",
                "https://access.redhat.com/errata/RHSA-2026:4185",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:4215",
                "https://access.redhat.com/errata/RHSA-2026:4271",
                "https://access.redhat.com/errata/RHSA-2026:4466",
                "https://access.redhat.com/errata/RHSA-2026:4467",
                "https://access.redhat.com/errata/RHSA-2026:44696",
                "https://access.redhat.com/errata/RHSA-2026:51357",
                "https://access.redhat.com/errata/RHSA-2026:5459",
                "https://access.redhat.com/errata/RHSA-2026:61628",
                "https://access.redhat.com/errata/RHSA-2026:6287",
                "https://access.redhat.com/errata/RHSA-2026:6292",
                "https://access.redhat.com/errata/RHSA-2026:8151",
                "https://access.redhat.com/errata/RHSA-2026:8500",
                "https://access.redhat.com/errata/RHSA-2026:8501",
                "https://access.redhat.com/security/cve/CVE-2026-21441",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2427726",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21441.json"
            ],
            "timeline": [
                {
                    "at": "2026-01-07T22:15:44.040",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21441"
                }
            ]
        },
        {
            "id": "CVE-2026-21104",
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices",
            "title": "Samsung Mobile Devices vulnerability",
            "summary": "Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.",
            "updated_at": "2026-09-11T04:17:39.597",
            "published_at": "2026-09-09T05:17:22.723",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T05:17:22.723",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21104"
                }
            ]
        },
        {
            "id": "CVE-2026-21102",
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices",
            "title": "Samsung Mobile Devices vulnerability",
            "summary": "Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.",
            "updated_at": "2026-09-11T04:17:38.333",
            "published_at": "2026-09-09T05:17:22.490",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T05:17:22.490",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21102"
                }
            ]
        },
        {
            "id": "CVE-2026-21101",
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices",
            "title": "Samsung Mobile Devices vulnerability",
            "summary": "Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.",
            "updated_at": "2026-09-11T04:17:37.010",
            "published_at": "2026-09-09T05:17:22.370",
            "cvss": 8.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T05:17:22.370",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21101"
                }
            ]
        },
        {
            "id": "CVE-2026-21096",
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices",
            "title": "Samsung Mobile Devices vulnerability",
            "summary": "Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.",
            "updated_at": "2026-09-11T04:17:36.577",
            "published_at": "2026-09-09T05:17:21.783",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T05:17:21.783",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21096"
                }
            ]
        },
        {
            "id": "CVE-2026-21095",
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices",
            "title": "Samsung Mobile Devices vulnerability",
            "summary": "Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.",
            "updated_at": "2026-09-11T04:17:36.393",
            "published_at": "2026-09-09T05:17:21.663",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T05:17:21.663",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21095"
                }
            ]
        },
        {
            "id": "CVE-2026-21087",
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices",
            "title": "Samsung Mobile Devices vulnerability",
            "summary": "Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.",
            "updated_at": "2026-09-11T04:17:36.230",
            "published_at": "2026-09-09T05:17:20.707",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T05:17:20.707",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21087"
                }
            ]
        },
        {
            "id": "CVE-2026-21085",
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices",
            "title": "Samsung Mobile Devices vulnerability",
            "summary": "Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.",
            "updated_at": "2026-09-11T04:17:35.460",
            "published_at": "2026-09-09T05:17:20.473",
            "cvss": 8.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=09"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T05:17:20.473",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21085"
                }
            ]
        },
        {
            "id": "CVE-2026-21042",
            "vendor": "Samsung Mobile",
            "product": "Samsung Mobile Devices",
            "title": "Samsung Mobile Devices vulnerability",
            "summary": "Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows remote attackers to execute arbitrary code.",
            "updated_at": "2026-09-09T05:17:20.337",
            "published_at": "2026-07-10T05:16:34.797",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows remote attackers to execute arbitrary code.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=07"
            ],
            "timeline": [
                {
                    "at": "2026-07-10T05:16:34.797",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21042"
                }
            ]
        },
        {
            "id": "CVE-2026-20981",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "samsung-android-lpe exploit",
            "summary": "Exploit for CVE-2026-20980 and CVE-2026-20981. CVSS 7.",
            "updated_at": "2026-09-07T19:21:04Z",
            "published_at": "2026-09-07T19:21:04Z",
            "cvss": 7,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 34,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-07T19:21:04+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "samsung-android-lpe exploit",
                    "summary": "Exploit for CVE-2026-20980 and CVE-2026-20981. CVSS 7.",
                    "cvss": 7,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-VIKRAMADITYA015-SAMSUNG-ANDROID-LPE"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-VIKRAMADITYA015-SAMSUNG-ANDROID-LPE"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:21:04Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-VIKRAMADITYA015-SAMSUNG-ANDROID-LPE"
                }
            ]
        },
        {
            "id": "CVE-2026-20980",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "samsung-android-lpe exploit",
            "summary": "Exploit for CVE-2026-20980 and CVE-2026-20981. CVSS 7.",
            "updated_at": "2026-09-07T19:21:04Z",
            "published_at": "2026-09-07T19:21:04Z",
            "cvss": 7,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 34,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-07T19:21:04+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "samsung-android-lpe exploit",
                    "summary": "Exploit for CVE-2026-20980 and CVE-2026-20981. CVSS 7.",
                    "cvss": 7,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-VIKRAMADITYA015-SAMSUNG-ANDROID-LPE"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-VIKRAMADITYA015-SAMSUNG-ANDROID-LPE"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:21:04Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-VIKRAMADITYA015-SAMSUNG-ANDROID-LPE"
                }
            ]
        },
        {
            "id": "CVE-2026-20896",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-20896 exploit",
            "summary": "Exploit for CVE-2026-20896. CVSS 9.8.",
            "updated_at": "2026-09-12T06:32:53Z",
            "published_at": "2026-09-12T06:32:53Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 35,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Gitea CVE-2026-20896 vulnerability where PoC exports browser-ready cookie files.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-20896",
                    "summary": "Gitea CVE-2026-20896 vulnerability where PoC exports browser-ready cookie files.",
                    "what_happened": "Gitea CVE-2026-20896 vulnerability where PoC exports browser-ready cookie files.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-XAOCZENON-CVE-2026-20896",
                        "https://kitploit.com/zh/tools/github/xaoczenon/cve-2026-20896/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-11T17:19:59",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-XAOCZENON-CVE-2026-20896"
                },
                {
                    "title": "Exploit for CVE-2026-20896",
                    "summary": "Gitea CVE-2026-20896 vulnerability where PoC exports browser-ready cookie files.",
                    "what_happened": "Gitea CVE-2026-20896 vulnerability where PoC exports browser-ready cookie files.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-XAOCZENON-CVE-2026-20896",
                        "https://kitploit.com/zh/tools/github/xaoczenon/cve-2026-20896/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-11T17:19:59",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/xaoczenon/cve-2026-20896/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-XAOCZENON-CVE-2026-20896",
                "https://kitploit.com/zh/tools/github/xaoczenon/cve-2026-20896/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:32:53Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-XAOCZENON-CVE-2026-20896"
                }
            ]
        },
        {
            "id": "CVE-2026-20841",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "🛠 Demonstrate remote code execution in Windows Notepad versions below 11.2510 using the CVE-2026-20841 proof of concept.",
            "summary": "🛠 Demonstrate remote code execution in Windows Notepad versions below 11.2510 using the CVE-2026-20841 proof of concept.",
            "updated_at": "2026-08-26T10:26:04Z",
            "published_at": "2026-08-26T10:26:04Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 895,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · 404godd/CVE-2026-20841-PoC",
                    "author": "404godd",
                    "first_seen": "2026-02-26",
                    "last_seen": "2026-08-26T10:26:04Z",
                    "pushed_at": "2026-08-26T10:24:25Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "RCE",
                    "language": "",
                    "stars": 0,
                    "forks": 0,
                    "topics": [
                        "agent",
                        "chinese",
                        "cv",
                        "cve-2016-0856",
                        "cve-2026-20841",
                        "deep-learning",
                        "ethereum",
                        "hacktoberfest"
                    ],
                    "title": "🛠 Demonstrate remote code execution in Windows Notepad versions below 11.2510 using the CVE-2026-20841 proof of concept.",
                    "repository_description": "🛠 Demonstrate remote code execution in Windows Notepad versions below 11.2510 using the CVE-2026-20841 proof of concept.",
                    "summary": "🛠 Demonstrate remote code execution in Windows Notepad versions below 11.2510 using the CVE-2026-20841 proof of concept.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/404godd/CVE-2026-20841-PoC",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-77",
                    "kev": false,
                    "epss": 0.1165,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-02-10",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · hamzamalik3461/CVE-2026-20841",
                    "author": "hamzamalik3461",
                    "first_seen": "2024-09-22",
                    "last_seen": "2026-08-26T03:34:31Z",
                    "pushed_at": "2026-08-26T03:33:42Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "RCE",
                    "language": "",
                    "stars": 1,
                    "forks": 2,
                    "topics": [
                        "agent",
                        "command-injection",
                        "cv",
                        "cve",
                        "cve-2016-0856",
                        "cve-2026-20841",
                        "ethereum",
                        "exploit"
                    ],
                    "title": "🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.",
                    "repository_description": "🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.",
                    "summary": "🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/hamzamalik3461/CVE-2026-20841",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-77",
                    "kev": false,
                    "epss": 0.1165,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-02-10",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · BTtea/CVE-2026-20841-PoC",
                    "author": "BTtea",
                    "first_seen": "2026-02-11",
                    "last_seen": "2026-08-23T14:24:35Z",
                    "pushed_at": "2026-02-11T05:56:43Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "PoC",
                    "language": "",
                    "stars": 141,
                    "forks": 21,
                    "topics": [],
                    "title": "PoC",
                    "repository_description": "PoC",
                    "summary": "PoC",
                    "source": "CVE-Intel",
                    "url": "https://github.com/BTtea/CVE-2026-20841-PoC",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-77",
                    "kev": false,
                    "epss": 0.1165,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-02-10",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · uky007/CVE-2026-20841_notepad_analysis",
                    "author": "uky007",
                    "first_seen": "2026-02-12",
                    "last_seen": "2026-08-20T01:06:23Z",
                    "pushed_at": "2026-02-12T08:06:24Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 3,
                    "forks": 1,
                    "topics": [],
                    "title": "CVE-2026-20841_notepad_analysis",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/uky007/CVE-2026-20841_notepad_analysis",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-77",
                    "kev": false,
                    "epss": 0.1165,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-02-10",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · 0xBlackash/CVE-2026-20841",
                    "author": "0xBlackash",
                    "first_seen": "2026-06-01",
                    "last_seen": "2026-06-03T05:49:04Z",
                    "pushed_at": "2026-06-02T09:16:26Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "JavaScript",
                    "stars": 1,
                    "forks": 1,
                    "topics": [],
                    "title": "CVE-2026-20841",
                    "repository_description": "CVE-2026-20841",
                    "summary": "CVE-2026-20841",
                    "source": "CVE-Intel",
                    "url": "https://github.com/0xBlackash/CVE-2026-20841",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-77",
                    "kev": false,
                    "epss": 0.1165,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-02-10",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · whiskeylab/notepad_CVE_2026_20841",
                    "author": "whiskeylab",
                    "first_seen": "2026-04-07",
                    "last_seen": "2026-04-07T15:08:54Z",
                    "pushed_at": "2026-04-07T15:07:24Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "Exploit",
                    "language": "",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "Notepad CVE-2026-20841",
                    "repository_description": "Notepad CVE-2026-20841",
                    "summary": "Notepad CVE-2026-20841",
                    "source": "CVE-Intel",
                    "url": "https://github.com/whiskeylab/notepad_CVE_2026_20841",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-77",
                    "kev": false,
                    "epss": 0.1165,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-02-10",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · atiilla/CVE-2026-20841",
                    "author": "atiilla",
                    "first_seen": "2026-02-12",
                    "last_seen": "2026-03-12T20:31:12Z",
                    "pushed_at": "2026-02-12T12:54:53Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 5,
                    "forks": 4,
                    "topics": [],
                    "title": "CVE-2026-20841",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/atiilla/CVE-2026-20841",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-77",
                    "kev": false,
                    "epss": 0.1165,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-02-10",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · tangent65536/CVE-2026-20841",
                    "author": "tangent65536",
                    "first_seen": "2026-02-11",
                    "last_seen": "2026-02-28T11:25:53Z",
                    "pushed_at": "2026-02-11T14:55:48Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 2,
                    "forks": 1,
                    "topics": [],
                    "title": "PoC for the \"Windows Notepad RCE\"",
                    "repository_description": "PoC for the \"Windows Notepad RCE\"",
                    "summary": "PoC for the \"Windows Notepad RCE\"",
                    "source": "CVE-Intel",
                    "url": "https://github.com/tangent65536/CVE-2026-20841",
                    "cvss": 7.8,
                    "severity": "HIGH",
                    "cve_description": "Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.",
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-77",
                    "kev": false,
                    "epss": 0.1165,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-02-10",
                    "cve_status": "Analyzed"
                },
                {
                    "title": "Exploit for CVE-2026-20841-PoC",
                    "summary": "RCE in Windows Notepad (notepad.exe) versions below 11.2510.",
                    "what_happened": "RCE in Windows Notepad (notepad.exe) versions below 11.2510.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BTTEA-CVE-2026-20841-POC",
                        "https://kitploit.com/ru/tools/github/bttea/cve-2026-20841-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-31T00:57:47",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BTTEA-CVE-2026-20841-POC"
                },
                {
                    "title": "Exploit for CVE-2026-20841-PoC",
                    "summary": "RCE in Windows Notepad (notepad.exe) versions below 11.2510.",
                    "what_happened": "RCE in Windows Notepad (notepad.exe) versions below 11.2510.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BTTEA-CVE-2026-20841-POC",
                        "https://kitploit.com/ru/tools/github/bttea/cve-2026-20841-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-31T00:57:47",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/bttea/cve-2026-20841-poc/"
                },
                {
                    "repository": "PoC-in-GitHub · RajaUzairAbdullah/CVE-2026-20841",
                    "author": "RajaUzairAbdullah",
                    "first_seen": "2026-02-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-20841 - Windows notepad.exe RCE",
                    "summary": "CVE-2026-20841 - Windows notepad.exe RCE",
                    "url": "https://github.com/RajaUzairAbdullah/CVE-2026-20841"
                },
                {
                    "repository": "PoC-in-GitHub · patchpoint/CVE-2026-20841",
                    "author": "patchpoint",
                    "first_seen": "2026-02-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "CVE-2026-20841 repository",
                    "summary": "",
                    "url": "https://github.com/patchpoint/CVE-2026-20841"
                },
                {
                    "repository": "PoC-in-GitHub · dogukankurnaz/CVE-2026-20841-PoC",
                    "author": "dogukankurnaz",
                    "first_seen": "2026-02-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2026-20841",
                    "summary": "CVE-2026-20841",
                    "url": "https://github.com/dogukankurnaz/CVE-2026-20841-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · SecureWithUmer/CVE-2026-20841",
                    "author": "SecureWithUmer",
                    "first_seen": "2026-02-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC for a remote code execution flaw in Windows Notepad's markdown renderer. The markdown engine does not restrict URL protocols, allowing arbitrary protocol handlers to be triggered via clickable links",
                    "summary": "PoC for a remote code execution flaw in Windows Notepad's markdown renderer. The markdown engine does not restrict URL protocols, allowing arbitrary protocol handlers to be triggered via clickable links",
                    "url": "https://github.com/SecureWithUmer/CVE-2026-20841"
                },
                {
                    "repository": "PoC-in-GitHub · hackfaiz/CVE-2026-20841-PoC",
                    "author": "hackfaiz",
                    "first_seen": "2026-02-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Proof of Concept for CVE-2026-20841",
                    "summary": "Proof of Concept for CVE-2026-20841",
                    "url": "https://github.com/hackfaiz/CVE-2026-20841-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · EleniChristopoulou/PoC-CVE-2026-20841",
                    "author": "EleniChristopoulou",
                    "first_seen": "2026-02-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-20841 repository",
                    "summary": "",
                    "url": "https://github.com/EleniChristopoulou/PoC-CVE-2026-20841"
                }
            ],
            "references": [
                "https://github.com/404godd/CVE-2026-20841-PoC",
                "https://github.com/hamzamalik3461/CVE-2026-20841",
                "https://github.com/BTtea/CVE-2026-20841-PoC",
                "https://github.com/uky007/CVE-2026-20841_notepad_analysis",
                "https://github.com/0xBlackash/CVE-2026-20841",
                "https://github.com/whiskeylab/notepad_CVE_2026_20841",
                "https://github.com/atiilla/CVE-2026-20841",
                "https://github.com/tangent65536/CVE-2026-20841",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BTTEA-CVE-2026-20841-POC",
                "https://kitploit.com/ru/tools/github/bttea/cve-2026-20841-poc/",
                "https://github.com/RajaUzairAbdullah/CVE-2026-20841",
                "https://github.com/patchpoint/CVE-2026-20841",
                "https://github.com/dogukankurnaz/CVE-2026-20841-PoC",
                "https://github.com/SecureWithUmer/CVE-2026-20841",
                "https://github.com/hackfaiz/CVE-2026-20841-PoC",
                "https://github.com/EleniChristopoulou/PoC-CVE-2026-20841"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T10:26:04Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/404godd/CVE-2026-20841-PoC"
                }
            ],
            "epss": 0.1165,
            "severity": "HIGH",
            "metadata_source": "CNA",
            "cve_status": "Analyzed",
            "cve_published_at": "2026-02-10",
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-20805",
            "vendor": "Microsoft",
            "product": "Windows",
            "title": "Microsoft Windows Information Disclosure Vulnerability",
            "summary": "Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.",
            "updated_at": "2026-09-11T22:10:10Z",
            "published_at": "2026-09-11T22:10:10Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 104,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4"
                },
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                },
                {
                    "title": "Exploit for Improper Authorization in Microsoft CVE-2026-20805 CVE-2026-24291 CVE-2026-41089 CVE-2026-41096 CV",
                    "summary": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "what_happened": "AD CS Certighost: CA issues DC cert via spoofed identity enabling full domain compromise.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-287",
                    "references": [
                        "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                        "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                    ],
                    "repository": "ZeroDayEvil/CVE-2026-54121-Certighost",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-11T23:13:58",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                "https://sploitus.com/exploit?id=238D0F6B-E4C8-57D9-8EAD-3ED01491B1C4",
                "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                "https://github.com/ZeroDayEvil/CVE-2026-54121-Certighost"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:10:10Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2026-20637",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-20637-AppleSEPKeyStore-UAF",
            "summary": "Use-After-Free in AppleSEPKeyStore allowing apps to cause unexpected system termination.",
            "updated_at": "2026-09-06T07:49:24Z",
            "published_at": "2026-09-06T07:49:24Z",
            "cvss": 6.2,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 71,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Use-After-Free in AppleSEPKeyStore allowing apps to cause unexpected system termination.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-20637-AppleSEPKeyStore-UAF",
                    "summary": "Use-After-Free in AppleSEPKeyStore allowing apps to cause unexpected system termination.",
                    "what_happened": "Use-After-Free in AppleSEPKeyStore allowing apps to cause unexpected system termination.",
                    "cvss": 6.2,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XJOHNNYDEV-CVE-2026-20637-APPLESEPKEYSTORE-UAF",
                        "https://kitploit.com/hi/tools/github/0xjohnnydev/cve-2026-20637-applesepkeystore-uaf/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T09:49:24",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XJOHNNYDEV-CVE-2026-20637-APPLESEPKEYSTORE-UAF"
                },
                {
                    "title": "Exploit for CVE-2026-20637-AppleSEPKeyStore-UAF",
                    "summary": "Use-After-Free in AppleSEPKeyStore allowing apps to cause unexpected system termination.",
                    "what_happened": "Use-After-Free in AppleSEPKeyStore allowing apps to cause unexpected system termination.",
                    "cvss": 6.2,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XJOHNNYDEV-CVE-2026-20637-APPLESEPKEYSTORE-UAF",
                        "https://kitploit.com/hi/tools/github/0xjohnnydev/cve-2026-20637-applesepkeystore-uaf/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T09:49:24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/0xjohnnydev/cve-2026-20637-applesepkeystore-uaf/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XJOHNNYDEV-CVE-2026-20637-APPLESEPKEYSTORE-UAF",
                "https://kitploit.com/hi/tools/github/0xjohnnydev/cve-2026-20637-applesepkeystore-uaf/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T07:49:24Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XJOHNNYDEV-CVE-2026-20637-APPLESEPKEYSTORE-UAF"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
            "id": "CVE-2026-20518",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10867524 / ALPS10876355; Issue ID: MSV-6674.",
            "updated_at": "2026-09-07T02:17:20.583",
            "published_at": "2026-09-07T02:17:20.583",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT6991; MT8755; MT8768; MT8771; MT8775; MT8781; MT8791T; MT8792; MT8793; MT8796; MT8797; MT8798; MT8799; MT8873; MT8883; MT8893; MT8910",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-125",
            "what_happened": "In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10867524 / ALPS10876355; Issue ID: MSV-6674.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:20.583",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20518"
                }
            ]
        },
        {
            "id": "CVE-2026-20517",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900510; Issue ID: MSV-6781.",
            "updated_at": "2026-09-07T02:17:20.470",
            "published_at": "2026-09-07T02:17:20.470",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT6991; MT8755; MT8768; MT8771; MT8775; MT8781; MT8791T; MT8792; MT8793; MT8796; MT8797; MT8798; MT8799; MT8873; MT8883; MT8893; MT8910",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-416",
            "what_happened": "In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900510; Issue ID: MSV-6781.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:20.470",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20517"
                }
            ]
        },
        {
            "id": "CVE-2026-20516",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11060069 / DTV04881615; Issue ID: MSV-7882.",
            "updated_at": "2026-09-08T18:38:19.590",
            "published_at": "2026-09-07T02:17:20.360",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "MT5586; MT5862; MT5867; MT5870; MT5871; MT5872; MT5873; MT5876; MT5877; MT5879; MT5888; MT5889; MT5895; MT5896; MT5897; MT9015; MT9025; MT9026; MT9027; MT9032; MT9603; MT9618; MT9633; MT9649; MT9660; MT9676; MT9687; MT9689; MT9972",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-926",
            "what_happened": "In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11060069 / DTV04881615; Issue ID: MSV-7882.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-20516",
                    "summary": "Confused deputy in MiracastService on Android TV allows local DoS or privilege escalation.",
                    "what_happened": "Confused deputy in MiracastService on Android TV allows local DoS or privilege escalation.",
                    "cvss": 5.5,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-926",
                    "references": [
                        "https://sploitus.com/exploit?id=3F026716-3776-5B5A-B9BC-3440B9EB0A6A",
                        "https://github.com/Dingo97/CVE-2026-20516"
                    ],
                    "repository": "Sploitus",
                    "author": "Dingo97",
                    "first_seen": "2026-09-11T09:13:16",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=3F026716-3776-5B5A-B9BC-3440B9EB0A6A"
                },
                {
                    "title": "Exploit for CVE-2026-20516",
                    "summary": "Confused deputy in MiracastService on Android TV allows local DoS or privilege escalation.",
                    "what_happened": "Confused deputy in MiracastService on Android TV allows local DoS or privilege escalation.",
                    "cvss": 5.5,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-926",
                    "references": [
                        "https://sploitus.com/exploit?id=3F026716-3776-5B5A-B9BC-3440B9EB0A6A",
                        "https://github.com/Dingo97/CVE-2026-20516"
                    ],
                    "repository": "Dingo97/CVE-2026-20516",
                    "author": "Dingo97",
                    "first_seen": "2026-09-11T09:13:16",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/Dingo97/CVE-2026-20516"
                }
            ],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026",
                "https://sploitus.com/exploit?id=3F026716-3776-5B5A-B9BC-3440B9EB0A6A",
                "https://github.com/Dingo97/CVE-2026-20516"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:20.360",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20516"
                }
            ],
            "enrichment_checked_at": "2026-09-11T10:05:28Z"
        },
        {
            "id": "CVE-2026-20515",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11122991; Issue ID: MSV-8132.",
            "updated_at": "2026-09-07T02:17:20.257",
            "published_at": "2026-09-07T02:17:20.257",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT6991; MT8799",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-416",
            "what_happened": "In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11122991; Issue ID: MSV-8132.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:20.257",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20515"
                }
            ]
        },
        {
            "id": "CVE-2026-20514",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087632; Issue ID: MSV-8244.",
            "updated_at": "2026-09-07T02:17:20.150",
            "published_at": "2026-09-07T02:17:20.150",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT2718; MT6739; MT6761; MT6765; MT6768; MT6781; MT6789; MT6833; MT6835; MT6853; MT6855; MT6877; MT6878; MT6879; MT6883; MT6885; MT6886; MT6889; MT6893; MT6895; MT6897; MT6899; MT6983; MT6985; MT6989; MT6991; MT6993; MT8126; MT8168; MT8171; MT8186; MT8188; MT8189; MT8195; MT8196; MT8321; MT8365; MT8367; MT8385; MT8390; MT8391; MT8668; MT8676; MT8678; MT8696; MT8755; MT8766; MT8768; MT8771; MT8775; MT8781; MT8786; MT8788E; MT8791T; MT8792; MT8793; MT8796; MT8797; MT8798; MT8799; MT8873; MT8883; MT8893; MT8910",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-307",
            "what_happened": "In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087632; Issue ID: MSV-8244.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:20.150",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20514"
                }
            ]
        },
        {
            "id": "CVE-2026-20513",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087533; Issue ID: MSV-8245.",
            "updated_at": "2026-09-07T02:17:20.040",
            "published_at": "2026-09-07T02:17:20.040",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT2718; MT6769; MT6781; MT6789; MT6833; MT6835; MT6853; MT6855; MT6858; MT6877; MT6878; MT6881; MT6886; MT6893; MT6895; MT6897; MT6899; MT6989; MT6991; MT6993; MT8126; MT8168; MT8171; MT8186; MT8188; MT8189; MT8195; MT8196; MT8321; MT8365; MT8367; MT8385; MT8390; MT8391; MT8668; MT8676; MT8678; MT8696; MT8755; MT8766; MT8768; MT8771; MT8775; MT8781; MT8786; MT8788E; MT8791T; MT8792; MT8793; MT8796; MT8797; MT8798; MT8799; MT8873; MT8883; MT8893; MT8910",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-35",
            "what_happened": "In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087533; Issue ID: MSV-8245.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:20.040",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20513"
                }
            ]
        },
        {
            "id": "CVE-2026-20512",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087540; Issue ID: MSV-8246.",
            "updated_at": "2026-09-07T02:17:19.923",
            "published_at": "2026-09-07T02:17:19.923",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT2718; MT6769; MT6781; MT6789; MT6833; MT6835; MT6853; MT6855; MT6858; MT6877; MT6878; MT6881; MT6886; MT6893; MT6895; MT6897; MT6899; MT6989; MT6991; MT6993; MT8126; MT8168; MT8171; MT8186; MT8188; MT8189; MT8195; MT8196; MT8321; MT8365; MT8367; MT8385; MT8390; MT8391; MT8668; MT8676; MT8678; MT8696; MT8755; MT8766; MT8768; MT8771; MT8775; MT8781; MT8786; MT8788E; MT8791T; MT8792; MT8793; MT8796; MT8797; MT8798; MT8799; MT8873; MT8883; MT8893; MT8910",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-307",
            "what_happened": "In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087540; Issue ID: MSV-8246.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:19.923",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20512"
                }
            ]
        },
        {
            "id": "CVE-2026-20511",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11123860; Issue ID: MSV-8890.",
            "updated_at": "2026-09-07T02:17:19.810",
            "published_at": "2026-09-07T02:17:19.810",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT6858; MT6881; MT6993; MT8668",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-416",
            "what_happened": "In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11123860; Issue ID: MSV-8890.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:19.810",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20511"
                }
            ]
        },
        {
            "id": "CVE-2026-20510",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11134622; Issue ID: MSV-8894.",
            "updated_at": "2026-09-07T02:17:19.697",
            "published_at": "2026-09-07T02:17:19.697",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT6761; MT6765; MT6768; MT6789; MT6833; MT6835; MT6853; MT6855; MT6877; MT6879; MT6886; MT6893; MT6895; MT6991; MT6993; MT8799; MT8910",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-415",
            "what_happened": "In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11134622; Issue ID: MSV-8894.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:19.697",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20510"
                }
            ]
        },
        {
            "id": "CVE-2026-20509",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue ID: MSV-9011.",
            "updated_at": "2026-09-07T02:17:19.587",
            "published_at": "2026-09-07T02:17:19.587",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT2718; MT6739; MT6761; MT6765; MT6768; MT6769; MT6781; MT6789; MT6833; MT6835; MT6853; MT6855; MT6858; MT6877; MT6878; MT6879; MT6881; MT6883; MT6885; MT6886; MT6889; MT6893; MT6895; MT6897; MT6899; MT6983; MT6985; MT6989; MT6991; MT6993; MT8171; MT8186; MT8188; MT8189; MT8196; MT8668; MT8676; MT8678; MT8696; MT8793",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-121",
            "what_happened": "In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue ID: MSV-9011.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:19.587",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20509"
                }
            ]
        },
        {
            "id": "CVE-2026-20508",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue ID: MSV-9012.",
            "updated_at": "2026-09-07T02:17:19.470",
            "published_at": "2026-09-07T02:17:19.470",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT2718; MT6739; MT6761; MT6765; MT6768; MT6769; MT6781; MT6789; MT6833; MT6835; MT6853; MT6855; MT6858; MT6877; MT6878; MT6879; MT6881; MT6883; MT6885; MT6886; MT6889; MT6893; MT6895; MT6897; MT6899; MT6983; MT6985; MT6989; MT6991; MT6993; MT8171; MT8186; MT8188; MT8189; MT8196; MT8668; MT8676; MT8678; MT8696; MT8793",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-843",
            "what_happened": "In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue ID: MSV-9012.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:19.470",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20508"
                }
            ]
        },
        {
            "id": "CVE-2026-20507",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID: MSV-9125.",
            "updated_at": "2026-09-07T02:17:19.360",
            "published_at": "2026-09-07T02:17:19.360",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT2718; MT6739; MT6761; MT6765; MT6768; MT6769; MT6781; MT6789; MT6833; MT6835; MT6853; MT6855; MT6858; MT6877; MT6878; MT6879; MT6881; MT6883; MT6885; MT6886; MT6889; MT6893; MT6895; MT6897; MT6899; MT6983; MT6985; MT6989; MT6991; MT6993; MT8126; MT8168; MT8171; MT8186; MT8188; MT8189; MT8196; MT8321; MT8365; MT8367; MT8385; MT8390; MT8391; MT8668; MT8676; MT8678; MT8696; MT8755; MT8766; MT8766R; MT8768; MT8771; MT8775; MT8781; MT8786; MT8788E; MT8791T; MT8792; MT8796; MT8797; MT8798; MT8799; MT8873; MT8883; MT8893; MT8910",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-416",
            "what_happened": "In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID: MSV-9125.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:19.360",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20507"
                }
            ]
        },
        {
            "id": "CVE-2026-20506",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID: MSV-9126.",
            "updated_at": "2026-09-07T02:17:19.250",
            "published_at": "2026-09-07T02:17:19.250",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT2718; MT6739; MT6761; MT6765; MT6768; MT6769; MT6781; MT6789; MT6833; MT6835; MT6853; MT6855; MT6858; MT6877; MT6878; MT6879; MT6881; MT6883; MT6885; MT6886; MT6889; MT6893; MT6895; MT6897; MT6899; MT6983; MT6985; MT6989; MT6991; MT6993; MT8126; MT8168; MT8171; MT8186; MT8188; MT8189; MT8196; MT8321; MT8365; MT8367; MT8385; MT8390; MT8391; MT8668; MT8676; MT8678; MT8696; MT8755; MT8766; MT8766R; MT8768; MT8771; MT8775; MT8781; MT8786; MT8788E; MT8791T; MT8792; MT8796; MT8797; MT8798; MT8799; MT8873; MT8883; MT8893; MT8910",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-416",
            "what_happened": "In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID: MSV-9126.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:19.250",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20506"
                }
            ]
        },
        {
            "id": "CVE-2026-20504",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.",
            "updated_at": "2026-09-09T02:55:33.787",
            "published_at": "2026-09-07T02:17:19.143",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT2735; MT6833; MT6853; MT6855; MT6873; MT6875; MT6877; MT6880; MT6883; MT6885; MT6889; MT6890; MT6891; MT6893; MT8675; MT8771; MT8791; MT8791T; MT8797",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-617",
            "what_happened": "In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:19.143",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20504"
                }
            ]
        },
        {
            "id": "CVE-2026-20503",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue ID: MSV-9020.",
            "updated_at": "2026-09-09T02:55:29.153",
            "published_at": "2026-09-07T02:17:19.030",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT2716; MT2735; MT2737; MT6813; MT6833; MT6835; MT6853; MT6855; MT6858; MT6873; MT6875; MT6877; MT6878; MT6879; MT6880; MT6881; MT6883; MT6885; MT6886; MT6889; MT6890; MT6891; MT6893; MT6895; MT6896; MT6897; MT6899; MT6980; MT6982VB; MT6983; MT6985; MT6986; MT6988; MT6989; MT6990; MT6991; MT6993; MT8668; MT8673; MT8675; MT8676; MT8678; MT8755; MT8771; MT8775; MT8791; MT8791T; MT8792; MT8793; MT8795T; MT8796; MT8797; MT8798; MT8863; MT8873; MT8883; MT8893",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-617",
            "what_happened": "In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue ID: MSV-9020.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:19.030",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20503"
                }
            ]
        },
        {
            "id": "CVE-2026-20502",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.",
            "updated_at": "2026-09-09T02:55:23.187",
            "published_at": "2026-09-07T02:17:18.917",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT2718; MT6580; MT6739; MT6761; MT6765; MT6768; MT6769; MT6779; MT6781; MT6785; MT6789; MT6833; MT6835; MT6853; MT6855; MT6858; MT6873; MT6877; MT6878; MT6879; MT6881; MT6883; MT6885; MT6886; MT6889; MT6893; MT6895; MT6897; MT6899; MT6983; MT6985; MT6989; MT6991; MT6993; MT8126; MT8171; MT8186; MT8188; MT8189; MT8195; MT8196; MT8367; MT8391; MT8395; MT8668; MT8676; MT8678; MT8696; MT8781; MT8788E; MT8792; MT8799; MT8910",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:18.917",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20502"
                }
            ]
        },
        {
            "id": "CVE-2026-20501",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197.",
            "updated_at": "2026-09-09T02:55:16.850",
            "published_at": "2026-09-07T02:17:18.800",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT2718; MT6580; MT6739; MT6761; MT6765; MT6768; MT6769; MT6779; MT6781; MT6785; MT6789; MT6833; MT6835; MT6853; MT6855; MT6858; MT6873; MT6877; MT6878; MT6879; MT6881; MT6883; MT6885; MT6886; MT6889; MT6893; MT6895; MT6897; MT6899; MT6983; MT6985; MT6989; MT6991; MT6993; MT8126; MT8171; MT8186; MT8188; MT8189; MT8195; MT8196; MT8367; MT8391; MT8395; MT8668; MT8676; MT8678; MT8696; MT8781; MT8788E; MT8792; MT8799; MT8910",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:18.800",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20501"
                }
            ]
        },
        {
            "id": "CVE-2026-20500",
            "vendor": "MediaTek, Inc.",
            "product": "MediaTek chipset",
            "title": "MediaTek chipset vulnerability",
            "summary": "In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232.",
            "updated_at": "2026-09-09T02:55:11.390",
            "published_at": "2026-09-07T02:17:18.673",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "MT2716; MT6835; MT6858; MT6878; MT6881; MT6897; MT6899; MT6982VB; MT6986; MT6988; MT6991; MT6993; MT8668; MT8676; MT8678; MT8755; MT8775; MT8792; MT8793; MT8863; MT8873; MT8883",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.mediatek.com/product-security-bulletin/September-2026"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:18.673",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20500"
                }
            ]
        },
        {
            "id": "CVE-2026-20353",
            "vendor": "Cisco",
            "product": "Cisco Secure Email",
            "title": "Cisco Secure Email vulnerability",
            "summary": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.",
            "updated_at": "2026-09-15T04:18:02.940",
            "published_at": "2026-09-14T17:17:43.000",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0-698; 13.5.1-277; 13.0.0-392; 14.2.0-620; 13.0.5-007; 13.5.4-038; 14.2.1-020; 14.3.0-032; 15.0.0-104; 15.0.1-030; 15.5.0-048; 15.5.1-055; 15.5.2-018; 16.0.0-050; 15.0.3-002; 16.0.0-054; 15.5.3-022; 16.0.1-017; 15.5.4-012; 16.0.4-016; 15.0.5-016; 16.0.2-112; 16.0.3-044",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-664",
            "what_happened": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T17:17:43.000",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20353"
                }
            ]
        },
        {
            "id": "CVE-2026-20349",
            "vendor": "Cisco",
            "product": "Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)",
            "title": "Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability",
            "summary": "Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.",
            "updated_at": "2026-08-10T22:00:00Z",
            "published_at": "2026-08-10T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-20316",
            "vendor": "Cisco",
            "product": "Cisco Secure Firewall Management Center (FMC)",
            "title": "Cisco Secure Firewall Management Center (FMC) vulnerability",
            "summary": "A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.\r\n\r\nThis vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.&nbsp;\r\nNote:&nbsp;If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.&nbsp;&nbsp;\r\nCisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.",
            "updated_at": "2026-09-16T21:17:10.150",
            "published_at": "2026-07-29T17:16:51.840",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 55,
            "confidence_label": "observed",
            "affected": "7.0.0; 7.0.0.1; 7.0.1; 7.0.1.1; 7.0.2; 7.2.0; 7.0.2.1; 7.0.3; 7.2.0.1; 7.0.4; 7.2.1; 7.0.5; 7.3.0; 7.2.2; 7.3.1; 7.2.3; 7.2.3.1; 7.2.4; 7.0.6; 7.2.4.1; 7.2.5; 7.3.1.1; 7.4.0; 7.0.6.1; 7.2.5.1; 7.4.1; 7.2.6; 7.4.1.1; 7.0.6.2; 7.2.7; 7.2.5.2; 7.3.1.2; 7.2.8; 7.6.0; 7.4.2; 7.2.8.1; 7.0.6.3; 7.4.2.1; 7.2.9; 7.0.7; 7.7.0; 7.4.2.2; 7.2.10; 7.6.1; 7.4.2.3; 7.0.8; 7.6.2; 7.7.10; 7.2.10.1; 7.0.8.1; 7.6.2.1; 7.2.10.2; 7.7.10.1; 7.4.2.4; 7.4.3; 7.6.3; 7.7.11; 7.6.4; 10.0.0; 7.4.4; 7.4.5; 7.0.9; 7.2.11; 7.7.12; 7.6.5; 7.4.6; 10.0.1; 7.4.7",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-259",
            "what_happened": "A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.\r\n\r\nThis vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.&nbsp;\r\nNote:&nbsp;If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.&nbsp;&nbsp;\r\nCisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20316"
            ],
            "timeline": [
                {
                    "at": "2026-07-29T17:16:51.840",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20316"
                },
                {
                    "at": "2026-07-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-20288",
            "vendor": "Cisco",
            "product": "Cisco Enterprise NFV Infrastructure Software",
            "title": "Cisco Enterprise NFV Infrastructure Software vulnerability",
            "summary": "A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with&nbsp;Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbsp;\r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.&nbsp;\r\nCisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes&nbsp;root.",
            "updated_at": "2026-09-16T04:18:19.750",
            "published_at": "2026-08-05T17:16:49.527",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.1.1; 3.9.1; 3.5.2; 3.12.2; 3.6.2; 3.9.2; 3.11.3; 3.11.1; 3.5.1; 3.3.1; 3.10.2; 3.12.1b; 3.4.1; 3.12.1a; 3.6.3; 3.8.1; 3.11.2; 3.12.1; 3.12.3; 3.10.1; 3.6.1; 3.10.3; 3.7.1; 4.1.2; 4.2.1; 4.2.2; 4.4.1; 4.4.2; 4.5.1; 4.4.3; 4.6.1; 4.7.1; 4.6.2-FC2; 4.6.2; 4.8.1; 4.8.2; 4.9.1; 4.6.3; 4.9.2; 4.10.1; 4.9.3; 4.11.1; 4.9.4; 4.12.1; 4.6.4; 4.12.2; 4.13.1; 4.9.5; 4.12.3; 4.14.1; 4.6.3-FC4; 4.9.4-FC3; 4.12.4; 4.15.1; 4.9.6; 4.15.2; 4.12.5; 4.15.3; 4.15.4; 4.12.6; 4.15.5; 4.12.7; 4.18.3; 26.1.1; 4.18.4; 4.16.1; 4.18.2a; 4.18.1; 4.18.2; 4.0(2g); 3.1(2i); 3.1(1d); 4.0(4i); 4.1(1c); 4.0(2c); 4.0(1e); 4.0(2h); 4.0(4h); 4.0(1h); 4.0(2l); 3.1(3g); 4.0(1.240); 4.0(2f); 4.0(1g); 4.0(2i); 3.1(3i); 4.0(4d); 4.1(1d); 3.1(3c); 4.0(4k); 3.1(2d); 3.1(3a); 3.1(3j); 4.0(2d); 4.1(1f); 4.0(4j); 4.0(2m); 4.0(2k); 4.0(1c); 4.0(4f); 4.0(4c); 3.1(3d); 3.1(2g); 3.1(2c); 4.0(1d); 3.1(2e); 4.0(1a); 4.0(1b); 3.1(3b); 4.0(4b); 3.1(2b); 4.0(4e); 3.1(3h); 4.0(4l); 4.1(1g); 4.1(2a); 4.0(2n); 4.1(1h); 3.1(3k); 4.1(2b); 4.0(2o); 4.0(4m); 4.1(2d); 4.1(3b); 4.0(2p); 4.1(2e); 4.1(2f); 4.0(4n); 4.0(2q); 4.1(3c); 4.0(2r); 4.1(3d); 4.1(2g); 4.1(2h); 4.1(3g); 4.1(3f); 4.1(2j); 4.1(2k); 4.1(3h); 4.2(2a); 4.1(3i); 4.2(2f); 4.2(2g); 4.2(3b); 4.1(3l); 4.2(3d); 4.3(1.230097); 4.2(1e); 4.2(1b); 4.2(1j); 4.2(1i); 4.2(1f); 4.2(1a); 4.2(1c); 4.2(1g); 4.3(1.230124); 4.1(2l); 4.2(3e); 4.3(1.230138); 4.2(3g); 4.3(2.230207); 4.2(3h); 4.2(3i); 4.3(2.230270); 4.1(3m); 4.1(2m); 4.3(2.240002); 4.3(3.240022); 4.2(3j); 4.1(3n); 4.3(2.240009); 4.3(3.240041); 4.2(3k); 4.3(3.240043); 4.3(4.240142); 4.3(2.240037); 4.3(2.240053); 4.3(4.240152); 4.2(3l); 4.3(2.240077); 4.3(4.242028); 4.3(4.241063); 4.3(4.242038); 4.2(3m); 4.3(2.240090); 4.3(5.240021); 4.3(2.240107); 4.3(4.242066); 4.2(3n); 4.3(5.250001); 4.2(3o); 4.3(2.250016); 4.3(2.250021); 4.3(5.250030); 4.3(2.250022); 4.3(6.250039); 4.3(6.250040); 4.3(5.250033); 4.3(6.250044); 4.3(6.250053); 4.3(2.250037); 4.3(2.250045); 4.3(4.252001); 4.3(4.252002); 6.0(1.250127); 4.2(3p); 6.0(1.250131); 4.3(6.250101); 6.0(1.250174); 4.3(6.250117); 4.3(5.250043); 4.3(5.250045); 4.3(6.250060); 6.0(1.250130); 4.3(4.241014); 4.3(2.250063); 6.0(1.250192); 4.3(6.260003); 6.0(1.250194); 4.3(6.260017); 4.3(2.260007); 6.0(2.260044); 6.0(2.260069); 4.3(6.260033); 4.2(3q); 3.2.7; 3.2.6; 3.2.4; 3.2.10; 3.2.2; 3.2.3; 3.2.1; 3.2.11.1; 3.2.8; 3.1.1; 3.1.2; 3.1.4; 3.1.3; 3.1.5; 3.1.0; 3.2.11.3; 3.2.11.5; 3.2.12.2; 3.2.13.6; 3.2.14; 3.2.15; 3.2.15.3; 3.2.16.1; 3.2.17.1",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-146",
            "what_happened": "A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with&nbsp;Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbsp;\r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.&nbsp;\r\nCisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes&nbsp;root.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU"
            ],
            "timeline": [
                {
                    "at": "2026-08-05T17:16:49.527",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20288"
                }
            ]
        },
        {
            "id": "CVE-2026-20280",
            "vendor": "Cisco",
            "product": "Cisco IOS XR Software",
            "title": "Cisco IOS XR Software vulnerability",
            "summary": "As part of Cisco's ongoing commitment to proactive security and product quality, the&nbsp;Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20280 are related to improper checking or handling of exceptional condition issues that are grouped under the Common Weakness Enumeration (CWE) CWE-703.",
            "updated_at": "2026-09-15T18:17:19.717",
            "published_at": "2026-09-02T17:17:33.580",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.5.29; 7.0.1; 6.5.26; 6.5.25; 6.5.28; 6.5.90; 7.1.1; 7.0.90; 6.7.1; 7.0.2; 7.1.15; 7.2.1; 7.1.2; 6.7.2; 7.0.11; 7.0.12; 7.0.14; 7.1.25; 7.2.12; 7.3.1; 7.1.3; 6.7.3; 7.4.1; 7.2.2; 6.7.4; 6.5.31; 7.3.15; 7.3.16; 6.8.1; 7.4.15; 6.5.32; 7.3.2; 7.5.1; 7.4.16; 7.3.27; 7.6.1; 7.5.2; 7.8.1; 7.6.15; 7.5.12; 7.8.12; 7.3.3; 7.7.1; 6.8.2; 7.3.4; 7.4.2; 6.7.35; 6.9.1; 7.6.2; 7.5.3; 7.7.2; 6.9.2; 7.9.1; 7.10.1; 7.8.2; 7.5.4; 6.5.33; 7.8.22; 7.7.21; 7.9.2; 7.3.5; 7.5.5; 7.11.1; 7.9.21; 7.10.2; 24.1.1; 7.6.3; 7.3.6; 7.5.52; 7.11.2; 24.2.1; 24.1.2; 24.2.11; 24.3.1; 24.4.1; 24.2.2; 7.8.23; 7.11.21; 24.2.20; 24.3.2; 24.4.10; 6.5.35; 25.1.1; 24.4.2; 24.3.20; 24.4.15; 25.2.1; 6.5.351; 25.1.2; 24.3.30; 25.3.1; 6.5.352; 24.4.30; 24.2.21; 25.4.1; 25.2.2; 25.2.15; 7.2.0; 7.0.0; 25.2.30; 6.5.353; 26.1.1; 25.1.30; 25.3.15; 26.2.100; 25.4.2; 26.2.1; 25.4.30; 26.1.2; 25.4.201; 26.2.101",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-703",
            "what_happened": "As part of Cisco's ongoing commitment to proactive security and product quality, the&nbsp;Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20280 are related to improper checking or handling of exceptional condition issues that are grouped under the Common Weakness Enumeration (CWE) CWE-703.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM",
                "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T17:17:33.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20280"
                }
            ]
        },
        {
            "id": "CVE-2026-20279",
            "vendor": "Cisco",
            "product": "Cisco IOS XR Software",
            "title": "Cisco IOS XR Software vulnerability",
            "summary": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20279 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.",
            "updated_at": "2026-09-15T18:17:19.553",
            "published_at": "2026-09-02T17:17:33.420",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.5.29; 7.0.1; 6.5.26; 6.5.25; 6.5.28; 6.5.90; 7.1.1; 7.0.90; 6.7.1; 7.0.2; 7.1.15; 7.2.1; 7.1.2; 6.7.2; 7.0.11; 7.0.12; 7.0.14; 7.1.25; 7.2.12; 7.3.1; 7.1.3; 6.7.3; 7.4.1; 7.2.2; 6.7.4; 6.5.31; 7.3.15; 7.3.16; 6.8.1; 7.4.15; 6.5.32; 7.3.2; 7.5.1; 7.4.16; 7.3.27; 7.6.1; 7.5.2; 7.8.1; 7.6.15; 7.5.12; 7.8.12; 7.3.3; 7.7.1; 6.8.2; 7.3.4; 7.4.2; 6.7.35; 6.9.1; 7.6.2; 7.5.3; 7.7.2; 6.9.2; 7.9.1; 7.10.1; 7.8.2; 7.5.4; 6.5.33; 7.8.22; 7.7.21; 7.9.2; 7.3.5; 7.5.5; 7.11.1; 7.9.21; 7.10.2; 24.1.1; 7.6.3; 7.3.6; 7.5.52; 7.11.2; 24.2.1; 24.1.2; 24.2.11; 24.3.1; 24.4.1; 24.2.2; 7.8.23; 7.11.21; 24.2.20; 24.3.2; 24.4.10; 6.5.35; 25.1.1; 24.4.2; 24.3.20; 24.4.15; 25.2.1; 6.5.351; 25.1.2; 24.3.30; 25.3.1; 6.5.352; 24.4.30; 24.2.21; 25.4.1; 25.2.2; 25.2.15; 7.2.0; 7.0.0; 25.2.30; 6.5.353; 26.1.1; 25.1.30; 25.3.15; 26.2.100; 25.4.2; 26.2.1; 25.4.30; 26.1.2; 25.4.201; 26.2.101",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20279 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM",
                "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T17:17:33.420",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20279"
                }
            ]
        },
        {
            "id": "CVE-2026-20278",
            "vendor": "Cisco",
            "product": "Cisco IOS XR Software",
            "title": "Cisco IOS XR Software vulnerability",
            "summary": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20278 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) CWE-707.",
            "updated_at": "2026-09-15T18:17:19.377",
            "published_at": "2026-09-02T17:17:33.267",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.5.29; 7.0.1; 6.5.26; 6.5.25; 6.5.28; 6.5.90; 7.1.1; 7.0.90; 6.7.1; 7.0.2; 7.1.15; 7.2.1; 7.1.2; 6.7.2; 7.0.11; 7.0.12; 7.0.14; 7.1.25; 7.2.12; 7.3.1; 7.1.3; 6.7.3; 7.4.1; 7.2.2; 6.7.4; 6.5.31; 7.3.15; 7.3.16; 6.8.1; 7.4.15; 6.5.32; 7.3.2; 7.5.1; 7.4.16; 7.3.27; 7.6.1; 7.5.2; 7.8.1; 7.6.15; 7.5.12; 7.8.12; 7.3.3; 7.7.1; 6.8.2; 7.3.4; 7.4.2; 6.7.35; 6.9.1; 7.6.2; 7.5.3; 7.7.2; 6.9.2; 7.9.1; 7.10.1; 7.8.2; 7.5.4; 6.5.33; 7.8.22; 7.7.21; 7.9.2; 7.3.5; 7.5.5; 7.11.1; 7.9.21; 7.10.2; 24.1.1; 7.6.3; 7.3.6; 7.5.52; 7.11.2; 24.2.1; 24.1.2; 24.2.11; 24.3.1; 24.4.1; 24.2.2; 7.8.23; 7.11.21; 24.2.20; 24.3.2; 24.4.10; 6.5.35; 25.1.1; 24.4.2; 24.3.20; 24.4.15; 25.2.1; 6.5.351; 25.1.2; 24.3.30; 25.3.1; 6.5.352; 24.4.30; 24.2.21; 25.4.1; 25.2.2; 25.2.15; 7.2.0; 7.0.0; 25.2.30; 6.5.353; 26.1.1; 25.1.30; 25.3.15; 26.2.100; 25.4.2; 26.2.1; 25.4.30; 26.1.2; 25.4.201; 26.2.101",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-707",
            "what_happened": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20278 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) CWE-707.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM",
                "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T17:17:33.267",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20278"
                }
            ]
        },
        {
            "id": "CVE-2026-20277",
            "vendor": "Cisco",
            "product": "Cisco IOS XR Software",
            "title": "Cisco IOS XR Software vulnerability",
            "summary": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20277 are related to protection mechanism failure issues that are grouped under the Common Weakness Enumeration (CWE) CWE-693.",
            "updated_at": "2026-09-15T18:17:19.230",
            "published_at": "2026-09-02T17:17:33.110",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.5.29; 7.0.1; 6.5.26; 6.5.25; 6.5.28; 6.5.90; 7.1.1; 7.0.90; 6.7.1; 7.0.2; 7.1.15; 7.2.1; 7.1.2; 6.7.2; 7.0.11; 7.0.12; 7.0.14; 7.1.25; 7.2.12; 7.3.1; 7.1.3; 6.7.3; 7.4.1; 7.2.2; 6.7.4; 6.5.31; 7.3.15; 7.3.16; 6.8.1; 7.4.15; 6.5.32; 7.3.2; 7.5.1; 7.4.16; 7.3.27; 7.6.1; 7.5.2; 7.8.1; 7.6.15; 7.5.12; 7.8.12; 7.3.3; 7.7.1; 6.8.2; 7.3.4; 7.4.2; 6.7.35; 6.9.1; 7.6.2; 7.5.3; 7.7.2; 6.9.2; 7.9.1; 7.10.1; 7.8.2; 7.5.4; 6.5.33; 7.8.22; 7.7.21; 7.9.2; 7.3.5; 7.5.5; 7.11.1; 7.9.21; 7.10.2; 24.1.1; 7.6.3; 7.3.6; 7.5.52; 7.11.2; 24.2.1; 24.1.2; 24.2.11; 24.3.1; 24.4.1; 24.2.2; 7.8.23; 7.11.21; 24.2.20; 24.3.2; 24.4.10; 6.5.35; 25.1.1; 24.4.2; 24.3.20; 24.4.15; 25.2.1; 6.5.351; 25.1.2; 24.3.30; 25.3.1; 6.5.352; 24.4.30; 24.2.21; 25.4.1; 25.2.2; 25.2.15; 7.2.0; 7.0.0; 25.2.30; 6.5.353; 26.1.1; 25.1.30; 25.3.15; 26.2.100; 25.4.2; 26.2.1; 25.4.30; 26.1.2; 25.4.201; 26.2.101",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-693",
            "what_happened": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20277 are related to protection mechanism failure issues that are grouped under the Common Weakness Enumeration (CWE) CWE-693.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM",
                "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T17:17:33.110",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20277"
                }
            ]
        },
        {
            "id": "CVE-2026-20276",
            "vendor": "Cisco",
            "product": "Cisco IOS XR Software",
            "title": "Cisco IOS XR Software vulnerability",
            "summary": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-691.",
            "updated_at": "2026-09-15T18:17:18.607",
            "published_at": "2026-09-02T17:17:32.957",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.5.29; 7.0.1; 6.5.26; 6.5.25; 6.5.28; 6.5.90; 7.1.1; 7.0.90; 6.7.1; 7.0.2; 7.1.15; 7.2.1; 7.1.2; 6.7.2; 7.0.11; 7.0.12; 7.0.14; 7.1.25; 7.2.12; 7.3.1; 7.1.3; 6.7.3; 7.4.1; 7.2.2; 6.7.4; 6.5.31; 7.3.15; 7.3.16; 6.8.1; 7.4.15; 6.5.32; 7.3.2; 7.5.1; 7.4.16; 7.3.27; 7.6.1; 7.5.2; 7.8.1; 7.6.15; 7.5.12; 7.8.12; 7.3.3; 7.7.1; 6.8.2; 7.3.4; 7.4.2; 6.7.35; 6.9.1; 7.6.2; 7.5.3; 7.7.2; 6.9.2; 7.9.1; 7.10.1; 7.8.2; 7.5.4; 6.5.33; 7.8.22; 7.7.21; 7.9.2; 7.3.5; 7.5.5; 7.11.1; 7.9.21; 7.10.2; 24.1.1; 7.6.3; 7.3.6; 7.5.52; 7.11.2; 24.2.1; 24.1.2; 24.2.11; 24.3.1; 24.4.1; 24.2.2; 7.8.23; 7.11.21; 24.2.20; 24.3.2; 24.4.10; 6.5.35; 25.1.1; 24.4.2; 24.3.20; 24.4.15; 25.2.1; 6.5.351; 25.1.2; 24.3.30; 25.3.1; 6.5.352; 24.4.30; 24.2.21; 25.4.1; 25.2.2; 25.2.15; 7.2.0; 7.0.0; 25.2.30; 6.5.353; 26.1.1; 25.1.30; 25.3.15; 26.2.100; 25.4.2; 26.2.1; 25.4.30; 26.1.2; 25.4.201; 26.2.101",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-691",
            "what_happened": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-691.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM",
                "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T17:17:32.957",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20276"
                }
            ]
        },
        {
            "id": "CVE-2026-20275",
            "vendor": "Cisco",
            "product": "Cisco IOS XR Software",
            "title": "Cisco IOS XR Software vulnerability",
            "summary": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20275 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-682.",
            "updated_at": "2026-09-15T18:17:18.413",
            "published_at": "2026-09-02T17:17:32.790",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.5.29; 7.0.1; 6.5.26; 6.5.25; 6.5.28; 6.5.90; 7.1.1; 7.0.90; 6.7.1; 7.0.2; 7.1.15; 7.2.1; 7.1.2; 6.7.2; 7.0.11; 7.0.12; 7.0.14; 7.1.25; 7.2.12; 7.3.1; 7.1.3; 6.7.3; 7.4.1; 7.2.2; 6.7.4; 6.5.31; 7.3.15; 7.3.16; 6.8.1; 7.4.15; 6.5.32; 7.3.2; 7.5.1; 7.4.16; 7.3.27; 7.6.1; 7.5.2; 7.8.1; 7.6.15; 7.5.12; 7.8.12; 7.3.3; 7.7.1; 6.8.2; 7.3.4; 7.4.2; 6.7.35; 6.9.1; 7.6.2; 7.5.3; 7.7.2; 6.9.2; 7.9.1; 7.10.1; 7.8.2; 7.5.4; 6.5.33; 7.8.22; 7.7.21; 7.9.2; 7.3.5; 7.5.5; 7.11.1; 7.9.21; 7.10.2; 24.1.1; 7.6.3; 7.3.6; 7.5.52; 7.11.2; 24.2.1; 24.1.2; 24.2.11; 24.3.1; 24.4.1; 24.2.2; 7.8.23; 7.11.21; 24.2.20; 24.3.2; 24.4.10; 6.5.35; 25.1.1; 24.4.2; 24.3.20; 24.4.15; 25.2.1; 6.5.351; 25.1.2; 24.3.30; 25.3.1; 6.5.352; 24.4.30; 24.2.21; 25.4.1; 25.2.2; 25.2.15; 7.2.0; 7.0.0; 25.2.30; 6.5.353; 26.1.1; 25.1.30; 25.3.15; 26.2.100; 25.4.2; 26.2.1; 25.4.30; 26.1.2; 25.4.201; 26.2.101",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-682",
            "what_happened": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20275 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-682.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM",
                "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T17:17:32.790",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20275"
                }
            ]
        },
        {
            "id": "CVE-2026-20274",
            "vendor": "Cisco",
            "product": "Cisco IOS XR Software",
            "title": "Cisco IOS XR Software vulnerability",
            "summary": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-664.",
            "updated_at": "2026-09-15T18:17:18.240",
            "published_at": "2026-09-02T17:17:32.630",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.5.29; 7.0.1; 6.5.26; 6.5.25; 6.5.28; 6.5.90; 7.1.1; 7.0.90; 6.7.1; 7.0.2; 7.1.15; 7.2.1; 7.1.2; 6.7.2; 7.0.11; 7.0.12; 7.0.14; 7.1.25; 7.2.12; 7.3.1; 7.1.3; 6.7.3; 7.4.1; 7.2.2; 6.7.4; 6.5.31; 7.3.15; 7.3.16; 6.8.1; 7.4.15; 6.5.32; 7.3.2; 7.5.1; 7.4.16; 7.3.27; 7.6.1; 7.5.2; 7.8.1; 7.6.15; 7.5.12; 7.8.12; 7.3.3; 7.7.1; 6.8.2; 7.3.4; 7.4.2; 6.7.35; 6.9.1; 7.6.2; 7.5.3; 7.7.2; 6.9.2; 7.9.1; 7.10.1; 7.8.2; 7.5.4; 6.5.33; 7.8.22; 7.7.21; 7.9.2; 7.3.5; 7.5.5; 7.11.1; 7.9.21; 7.10.2; 24.1.1; 7.6.3; 7.3.6; 7.5.52; 7.11.2; 24.2.1; 24.1.2; 24.2.11; 24.3.1; 24.4.1; 24.2.2; 7.8.23; 7.11.21; 24.2.20; 24.3.2; 24.4.10; 6.5.35; 25.1.1; 24.4.2; 24.3.20; 24.4.15; 25.2.1; 6.5.351; 25.1.2; 24.3.30; 25.3.1; 6.5.352; 24.4.30; 24.2.21; 25.4.1; 25.2.2; 25.2.15; 7.2.0; 7.0.0; 25.2.30; 6.5.353; 26.1.1; 25.1.30; 25.3.15; 26.2.100; 25.4.2; 26.2.1; 25.4.30; 26.1.2; 25.4.201; 26.2.101; 25.2.21",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-664",
            "what_happened": "As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-664.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM",
                "https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T17:17:32.630",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20274"
                }
            ]
        },
        {
            "id": "CVE-2026-20079",
            "vendor": "Cisco",
            "product": "Cisco Secure Firewall Management Center (FMC)",
            "title": "Cisco Secure Firewall Management Center (FMC) vulnerability",
            "summary": "A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp;\r\n\r\nThis vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow&nbsp;root access to the device.&nbsp;",
            "updated_at": "2026-09-16T17:17:16.340",
            "published_at": "2026-03-04T18:16:24.230",
            "cvss": 10,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "7.0.0; 7.0.0.1; 7.0.1; 7.1.0; 7.0.1.1; 7.1.0.1; 7.0.2; 7.2.0; 7.0.2.1; 7.0.3; 7.1.0.2; 7.2.0.1; 7.0.4; 7.2.1; 7.0.5; 7.3.0; 7.2.2; 7.3.1; 7.2.3; 7.1.0.3; 7.2.3.1; 7.2.4; 7.0.6; 7.2.4.1; 7.2.5; 7.3.1.1; 7.4.0; 7.0.6.1; 7.2.5.1; 7.4.1; 7.2.6; 7.4.1.1; 7.0.6.2; 7.2.7; 7.2.5.2; 7.3.1.2; 7.2.8; 7.6.0; 7.4.2; 7.2.8.1; 7.0.6.3; 7.4.2.1; 7.2.9; 7.0.7; 7.7.0; 7.4.2.2; 7.2.10; 7.6.1; 7.4.2.3; 7.0.8; 7.6.2; 7.7.10; 7.2.10.1; 7.0.8.1; 7.6.2.1; 7.2.10.2; 7.7.10.1; 7.4.2.4; 7.4.3; 7.6.3; 7.7.11; 7.6.4; 10.0.0; 7.4.4; 7.4.5; 7.0.9; 7.2.11; 7.7.12; 7.6.5; 7.4.6; 10.0.1; 7.4.7",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-288",
            "what_happened": "A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp;\r\n\r\nThis vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow&nbsp;root access to the device.&nbsp;",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "seclists.org",
                    "author": "NVD reference",
                    "first_seen": "2026-03-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://seclists.org/fulldisclosure/2026/Aug/80"
                },
                {
                    "repository": "blog.talosintelligence.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://blog.talosintelligence.com/fmc-ongoing-exploitation/"
                },
                {
                    "title": "Exploit for Authentication Bypass Using an Alternate Path or Channel in Cisco Secure_Firewall_Management_Cente",
                    "summary": "CVE-2026-20079 authentication bypass in Cisco Secure Firewall Management Center via CGISESSID.",
                    "what_happened": "CVE-2026-20079 authentication bypass in Cisco Secure Firewall Management Center via CGISESSID.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=EA2ECD75-AD35-54E6-9081-7E8EC3145347",
                        "https://github.com/DiegoArias008/CVE-2026-20079-checker"
                    ],
                    "repository": "Sploitus",
                    "author": "DiegoArias008",
                    "first_seen": "2026-09-13T22:58:13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=EA2ECD75-AD35-54E6-9081-7E8EC3145347"
                },
                {
                    "title": "Exploit for Authentication Bypass Using an Alternate Path or Channel in Cisco Secure_Firewall_Management_Cente",
                    "summary": "CVE-2026-20079 authentication bypass in Cisco Secure Firewall Management Center via CGISESSID.",
                    "what_happened": "CVE-2026-20079 authentication bypass in Cisco Secure Firewall Management Center via CGISESSID.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=EA2ECD75-AD35-54E6-9081-7E8EC3145347",
                        "https://github.com/DiegoArias008/CVE-2026-20079-checker"
                    ],
                    "repository": "DiegoArias008/CVE-2026-20079-checker",
                    "author": "DiegoArias008",
                    "first_seen": "2026-09-13T22:58:13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/DiegoArias008/CVE-2026-20079-checker"
                }
            ],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2",
                "http://seclists.org/fulldisclosure/2026/Aug/80",
                "https://blog.talosintelligence.com/fmc-ongoing-exploitation/",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20079",
                "https://sploitus.com/exploit?id=EA2ECD75-AD35-54E6-9081-7E8EC3145347",
                "https://github.com/DiegoArias008/CVE-2026-20079-checker"
            ],
            "timeline": [
                {
                    "at": "2026-03-04T18:16:24.230",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20079"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-19991",
            "vendor": "stiofansisland",
            "product": "UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP",
            "title": "UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP vulnerability",
            "summary": "The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is provided (process_account() calls uwp_validate_fields() and array_merges the result with the empty output of UsersWP_Files::validate_uploads()). At storage time the value is only checked with validate_file(), which passes any string that does not contain a literal '../'. When the value is later processed by upload_file_remove(), it is again gated with validate_file() and then normalized through uwp_get_file_relative_url(); that helper performs a global str_replace() of the uploads base URL against the stored URL, allowing a crafted URL containing embedded '..<uploads-baseurl>' tokens to collapse into '../../' traversal sequences after the last validation. The transformed value is then appended to the uploads base directory and passed to wp_delete_file() without any canonical containment check. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the affected site's server (including wp-config.",
            "updated_at": "2026-09-11T04:17:34.990",
            "published_at": "2026-09-11T04:17:34.990",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.2.70 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is provided (process_account() calls uwp_validate_fields() and array_merges the result with the empty output of UsersWP_Files::validate_uploads()). At storage time the value is only checked with validate_file(), which passes any string that does not contain a literal '../'. When the value is later processed by upload_file_remove(), it is again gated with validate_file() and then normalized through uwp_get_file_relative_url(); that helper performs a global str_replace() of the uploads base URL against the stored URL, allowing a crafted URL containing embedded '..<uploads-baseurl>' tokens to collapse into '../../' traversal sequences after the last validation. The transformed value is then appended to the uploads base directory and passed to wp_delete_file() without any canonical containment check. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the affected site's server (including wp-config.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/userswp/tags/1.2.70/includes/class-forms.php#L2076",
                "https://plugins.trac.wordpress.org/browser/userswp/tags/1.2.70/includes/class-forms.php#L2420",
                "https://plugins.trac.wordpress.org/browser/userswp/tags/1.2.70/includes/class-forms.php#L2432",
                "https://plugins.trac.wordpress.org/browser/userswp/tags/1.2.70/includes/class-validation.php#L194",
                "https://plugins.trac.wordpress.org/browser/userswp/tags/1.2.70/includes/helpers/misc.php#L2107",
                "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3650759%40userswp%2Ftrunk&old=3618724%40userswp%2Ftrunk&sfp_email=&sfph_mail=",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/dfa094d3-e8db-4402-ad23-e161b1b6181e?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T04:17:34.990",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19991"
                }
            ]
        },
        {
            "id": "CVE-2026-19985",
            "vendor": "comesio",
            "product": "Relevanssi – A Better Search",
            "title": "Relevanssi – A Better Search vulnerability",
            "summary": "The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'post_types', and 'orderby' request parameters. This is due to insufficient input sanitization and output escaping in the relevanssi_debug_array() function in lib/debug.php, which dumps user-supplied query variables through print_r() inside a <pre> block without HTML escaping. The debug path is enabled by supplying the relevanssi_debug=on request parameter when the administrator has previously enabled the 'Debugging mode' setting; the gate itself is a configuration check with no capability, nonce, or logged-in check (the vendor explicitly suppresses nonce verification on that line). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.",
            "updated_at": "2026-09-11T04:17:34.620",
            "published_at": "2026-09-11T04:17:34.620",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.28.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'post_types', and 'orderby' request parameters. This is due to insufficient input sanitization and output escaping in the relevanssi_debug_array() function in lib/debug.php, which dumps user-supplied query variables through print_r() inside a <pre> block without HTML escaping. The debug path is enabled by supplying the relevanssi_debug=on request parameter when the administrator has previously enabled the 'Debugging mode' setting; the gate itself is a configuration check with no capability, nonce, or logged-in check (the vendor explicitly suppresses nonce verification on that line). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.2/lib/debug.php#L27",
                "https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.2/lib/debug.php#L68",
                "https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.2/lib/search.php#L132",
                "https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.2/lib/search.php#L143",
                "https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.27.2/lib/search.php#L562",
                "https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.28.1/lib/debug.php#L27",
                "https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.28.1/lib/debug.php#L68",
                "https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.28.1/lib/search.php#L132",
                "https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.28.1/lib/search.php#L143",
                "https://plugins.trac.wordpress.org/browser/relevanssi/tags/4.28.1/lib/search.php#L562",
                "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3650355%40relevanssi%2Ftrunk&old=3529670%40relevanssi%2Ftrunk&sfp_email=&sfph_mail=",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/d07fe28c-f76e-42b2-b894-be316004235a?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T04:17:34.620",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19985"
                }
            ]
        },
        {
            "id": "CVE-2026-19949",
            "vendor": "servmask",
            "product": "All-in-One WP Migration and Backup",
            "title": "Exploit for CVE-2026-19949",
            "summary": "The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This can be leveraged to obtain the ai1wm_secret_key when a site administrator performs an archive restore and achieve remote code execution once able to leverage the ai1wm_secret_key value.",
            "updated_at": "2026-08-27T17:17:43.787",
            "published_at": "2026-08-25T12:16:23.783",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "0 through 7.109 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 86,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This can be leveraged to obtain the ai1wm_secret_key when a site administrator performs an archive restore and achieve remote code execution once able to leverage the ai1wm_secret_key value.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-19949",
                    "summary": "Exploit for CVE-2026-19949; no additional details provided.",
                    "what_happened": "Exploit for CVE-2026-19949; no additional details provided.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=5D396994-62DC-59F4-85AF-CCCE001A822C",
                        "https://github.com/katranSefa/CVE-2026-19949"
                    ],
                    "repository": "Sploitus",
                    "author": "katranSefa",
                    "first_seen": "2026-09-06T12:57:25",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=5D396994-62DC-59F4-85AF-CCCE001A822C"
                },
                {
                    "title": "Exploit for CVE-2026-19949",
                    "summary": "Exploit for CVE-2026-19949; no additional details provided.",
                    "what_happened": "Exploit for CVE-2026-19949; no additional details provided.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=5D396994-62DC-59F4-85AF-CCCE001A822C",
                        "https://github.com/katranSefa/CVE-2026-19949"
                    ],
                    "repository": "katranSefa/CVE-2026-19949",
                    "author": "katranSefa",
                    "first_seen": "2026-09-06T12:57:25",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/katranSefa/CVE-2026-19949"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=5D396994-62DC-59F4-85AF-CCCE001A822C",
                "https://github.com/katranSefa/CVE-2026-19949",
                "https://plugins.trac.wordpress.org/browser/all-in-one-wp-migration/tags/7.109/lib/controller/class-ai1wm-import-controller.php#L68",
                "https://plugins.trac.wordpress.org/browser/all-in-one-wp-migration/tags/7.109/lib/controller/class-ai1wm-main-controller.php#L1336",
                "https://plugins.trac.wordpress.org/browser/all-in-one-wp-migration/tags/7.109/lib/model/import/class-ai1wm-import-database.php#L1065",
                "https://plugins.trac.wordpress.org/browser/all-in-one-wp-migration/tags/7.109/lib/vendor/servmask/database/class-ai1wm-database.php#L1250",
                "https://plugins.trac.wordpress.org/browser/all-in-one-wp-migration/tags/7.109/lib/vendor/servmask/database/class-ai1wm-database.php#L1637",
                "https://plugins.trac.wordpress.org/browser/all-in-one-wp-migration/tags/7.109/lib/vendor/servmask/database/class-ai1wm-database.php#L1726",
                "https://plugins.trac.wordpress.org/changeset?reponame=&old=3656677%40all-in-one-wp-migration&new=3656677%40all-in-one-wp-migration",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/22e273d9-a268-4dc5-b1f6-3bc5c29232c5?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T10:57:25Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=5D396994-62DC-59F4-85AF-CCCE001A822C"
                },
                {
                    "at": "2026-08-25T12:16:23.783",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19949"
                }
            ],
            "enrichment_checked_at": "2026-09-06T16:05:30Z",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-19931",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection.",
            "updated_at": "2026-09-15T07:16:27.290",
            "published_at": "2026-09-06T18:17:20.733",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.64.1 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 8.21.0 through before 8.22.0 (semver); 6c6035532383e300c712e4c1cd9fdd749ed5cf59 through before 7103a93b05bc69ea98ed9d05d02fa9eeba533f2f (git); 8.21.0; 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-488",
            "what_happened": "A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user A's\npreviously authenticated connection.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-09-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3923520"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-19931.html",
                "https://curl.se/docs/CVE-2026-19931.json",
                "https://hackerone.com/reports/3923520"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T18:17:20.733",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19931"
                }
            ]
        },
        {
            "id": "CVE-2026-19887",
            "vendor": "uscnanbu",
            "product": "Welcart e-Commerce",
            "title": "Welcart e-Commerce vulnerability",
            "summary": "The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenticated attackers can store arbitrary 'reserve' key/value pairs as order metadata during a public checkout, then invoke the callback with an attacker-chosen 'option' parameter to select and unserialize that metadata without any provider signature, source-address, transaction-identity or ownership check. A POP chain is present in the TCPDF library bundled with the plugin itself, so no additional plugin or theme is required. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, including wp-config.php, which can lead to remote code execution when an attacker re-runs the WordPress installer against a database they control. Successful exploitation is contingent on an admin printing an invoice to trigger file deletion.",
            "updated_at": "2026-09-05T07:17:11.657",
            "published_at": "2026-09-05T07:17:11.657",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.12.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the Telecom EDY payment callback (usces_action_acting_transaction). Unauthenticated attackers can store arbitrary 'reserve' key/value pairs as order metadata during a public checkout, then invoke the callback with an attacker-chosen 'option' parameter to select and unserialize that metadata without any provider signature, source-address, transaction-identity or ownership check. A POP chain is present in the TCPDF library bundled with the plugin itself, so no additional plugin or theme is required. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, including wp-config.php, which can lead to remote code execution when an attacker re-runs the WordPress installer against a database they control. Successful exploitation is contingent on an admin printing an invoice to trigger file deletion.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/usc-e-shop/trunk/classes/cart.class.php#L546",
                "https://plugins.trac.wordpress.org/browser/usc-e-shop/trunk/classes/orderData.class.php#L41",
                "https://plugins.trac.wordpress.org/browser/usc-e-shop/trunk/functions/function.php#L218",
                "https://plugins.trac.wordpress.org/browser/usc-e-shop/trunk/functions/hoock_func.php#L517",
                "https://plugins.trac.wordpress.org/browser/usc-e-shop/trunk/includes/order_print.php#L16",
                "https://plugins.trac.wordpress.org/browser/usc-e-shop/trunk/pdf/tcpdf/tcpdf.php#L7794",
                "https://plugins.trac.wordpress.org/changeset/3673344/usc-e-shop/trunk/classes/orderData.class.php",
                "https://plugins.trac.wordpress.org/changeset?old_path=%2Fusc-e-shop/tags/2.12.1&new_path=%2Fusc-e-shop/tags/2.12.2",
                "https://plugins.trac.wordpress.org/changeset?reponame=&new=3673346%40usc-e-shop%2Ftags%2F2.12.2&old=3651925%40usc-e-shop%2Ftags%2F2.12.1",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/716a7c3c-2e26-4da9-a299-7dcbaa7e4895?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:11.657",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19887"
                }
            ]
        },
        {
            "id": "CVE-2026-19886",
            "vendor": "OriginLab",
            "product": "Origin Viewer",
            "title": "Origin Viewer vulnerability",
            "summary": "OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of OGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29340.",
            "updated_at": "2026-09-16T04:18:16.810",
            "published_at": "2026-09-15T19:17:18.353",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.9.5",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-119",
            "what_happened": "OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of OGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29340.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.zerodayinitiative.com/advisories/ZDI-26-586/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:18.353",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19886"
                }
            ]
        },
        {
            "id": "CVE-2026-19885",
            "vendor": "OriginLab",
            "product": "Origin Viewer",
            "title": "Origin Viewer vulnerability",
            "summary": "OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of OGWU files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29337.",
            "updated_at": "2026-09-16T04:18:16.060",
            "published_at": "2026-09-15T19:17:18.240",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.9.5",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of OGWU files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29337.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.zerodayinitiative.com/advisories/ZDI-26-585/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:18.240",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19885"
                }
            ]
        },
        {
            "id": "CVE-2026-19862",
            "vendor": "Unknown",
            "product": "JetFormBuilder",
            "title": "JetFormBuilder vulnerability",
            "summary": "The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message's addresses from a form field.",
            "updated_at": "2026-09-06T11:18:01.190",
            "published_at": "2026-09-06T10:17:14.563",
            "cvss": 4.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.6.5.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-93",
            "what_happened": "The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender. Exploitation requires the site to be configured to take one of the message's addresses from a form field.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/b3fe5552-6736-4479-9c61-c05bc3328b8e/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T10:17:14.563",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19862"
                }
            ]
        },
        {
            "id": "CVE-2026-19861",
            "vendor": "Unknown",
            "product": "JetFormBuilder — Dynamic Blocks Form Builder",
            "title": "JetFormBuilder — Dynamic Blocks Form Builder vulnerability",
            "summary": "The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injected script executes depends on the recipient's mail client, but the injected markup is rendered regardless.",
            "updated_at": "2026-09-06T11:18:01.043",
            "published_at": "2026-09-05T07:17:11.563",
            "cvss": 4.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.6.5.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-79",
            "what_happened": "The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other recipients. Whether injected script executes depends on the recipient's mail client, but the injected markup is rendered regardless.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/c9c834a3-dc65-4972-9315-d4dcc7f26599/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:11.563",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19861"
                }
            ]
        },
        {
            "id": "CVE-2026-19859",
            "vendor": "Unknown",
            "product": "JetFormBuilder",
            "title": "JetFormBuilder vulnerability",
            "summary": "The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion pass rather than after it, so the escaping can be bypassed.",
            "updated_at": "2026-09-06T11:18:00.937",
            "published_at": "2026-09-06T10:17:13.577",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.6.5.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion pass rather than after it, so the escaping can be bypassed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/19c115a5-4280-4b78-a460-140ecfc78d4f/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T10:17:13.577",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19859"
                }
            ]
        },
        {
            "id": "CVE-2026-19858",
            "vendor": "Unknown",
            "product": "JetFormBuilder — Dynamic Blocks Form Builder",
            "title": "JetFormBuilder — Dynamic Blocks Form Builder vulnerability",
            "summary": "The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft content, and secrets other JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 store in metadata.",
            "updated_at": "2026-09-06T11:18:00.793",
            "published_at": "2026-09-05T07:17:11.467",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.6.5.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated users to read arbitrary user, post and term properties and metadata, including password hashes, private and draft content, and secrets other JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 store in metadata.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/a9d091f3-6887-4f26-a736-ba26a81d2b32/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:11.467",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19858"
                }
            ]
        },
        {
            "id": "CVE-2026-19843",
            "vendor": "Red Hat",
            "product": "Red Hat Directory Server 13.0 EUS for RHEL 10",
            "title": "Red Hat Directory Server 13.0 EUS for RHEL 10 vulnerability",
            "summary": "A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.",
            "updated_at": "2026-09-08T02:17:26.270",
            "published_at": "2026-09-07T15:17:31.287",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:64768",
                "https://access.redhat.com/errata/RHSA-2026:64769",
                "https://access.redhat.com/security/cve/CVE-2026-19843",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2515965"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T15:17:31.287",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19843"
                }
            ]
        },
        {
            "id": "CVE-2026-19774",
            "vendor": "BlueZ",
            "product": "BlueZ",
            "title": "BlueZ vulnerability",
            "summary": "BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the handling of the stream endpoints. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-29429.",
            "updated_at": "2026-09-16T04:18:15.340",
            "published_at": "2026-09-15T19:17:17.867",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "b138a0849ba26310c3f40e78037565ce274d8737",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-121",
            "what_happened": "BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the handling of the stream endpoints. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-29429.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/bluez/bluez/pull/2251",
                "https://www.zerodayinitiative.com/advisories/ZDI-26-589/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:17.867",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19774"
                }
            ]
        },
        {
            "id": "CVE-2026-19773",
            "vendor": "libwebsockets",
            "product": "libwebsockets",
            "title": "libwebsockets vulnerability",
            "summary": "libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the parsing of HTTP/2 HPACK path header. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-31036.",
            "updated_at": "2026-09-16T04:18:01.260",
            "published_at": "2026-09-15T19:17:17.747",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "b4b5aed3903eaff09cd76a410f69bbe5dff66f8e",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of libwebsockets. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the parsing of HTTP/2 HPACK path header. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-31036.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/warmcat/libwebsockets/commit/824151862f37bc72f46d9a3e01d5b9408d313a0b",
                "https://www.zerodayinitiative.com/advisories/ZDI-26-590/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:17.747",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19773"
                }
            ]
        },
        {
            "id": "CVE-2026-19769",
            "vendor": "kstover",
            "product": "Ninja Forms – The Contact Form Builder That Grows With You",
            "title": "Ninja Forms – The Contact Form Builder That Grows With You vulnerability",
            "summary": "The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Ninja Forms File Uploads add-on to be active, as the attack routes the unwhitelisted child entry through the File Uploads handler to write an attacker-supplied HTML file containing arbitrary JavaScript into any web-server-writable directory, including the site root, where it is served from the site's own origin.",
            "updated_at": "2026-09-05T07:17:11.333",
            "published_at": "2026-09-05T07:17:11.333",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.15.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unmatched Array Key in all versions up to, and including, 3.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Ninja Forms File Uploads add-on to be active, as the attack routes the unwhitelisted child entry through the File Uploads handler to write an attacker-supplied HTML file containing arbitrary JavaScript into any web-server-writable directory, including the site root, where it is served from the site's own origin.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L303",
                "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L55",
                "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L609",
                "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.14.11/includes/AJAX/Controllers/Submission.php#L61",
                "https://plugins.trac.wordpress.org/changeset/3674413/ninja-forms/trunk/includes/AJAX/Controllers/Submission.php",
                "https://plugins.trac.wordpress.org/changeset?old_path=%2Fninja-forms/tags/3.15.1&new_path=%2Fninja-forms/tags/3.15.2",
                "https://plugins.trac.wordpress.org/changeset?reponame=&new=3674413%40ninja-forms%2Ftags%2F3.15.2&old=3663678%40ninja-forms%2Ftags%2F3.15.1",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/2330e381-7db3-4b79-8827-818d2ea954b5?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:11.333",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19769"
                }
            ]
        },
        {
            "id": "CVE-2026-19654",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.",
            "updated_at": "2026-09-15T19:17:17.583",
            "published_at": "2026-08-12T21:17:38.517",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.36.0 through before 8.2608.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:66405",
                "https://access.redhat.com/errata/RHSA-2026:67583",
                "https://access.redhat.com/errata/RHSA-2026:67584",
                "https://access.redhat.com/security/cve/CVE-2026-19654",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2502868",
                "https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T21:17:38.517",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19654"
                }
            ]
        },
        {
            "id": "CVE-2026-19634",
            "vendor": "DALIBO",
            "product": "PostgreSQL Anonymizer",
            "title": "PostgreSQL Anonymizer vulnerability",
            "summary": "PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules(), the malicious code is executed with superuser privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later",
            "updated_at": "2026-09-09T05:17:20.103",
            "published_at": "2026-09-06T16:16:50.603",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1 through before 3.1.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-89",
            "what_happened": "PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_database_rules() or anon.import_roles_rules(), the malicious code is executed with superuser privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/665"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T16:16:50.603",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19634"
                }
            ]
        },
        {
            "id": "CVE-2026-19633",
            "vendor": "DALIBO",
            "product": "PostgreSQL Anonymizer",
            "title": "PostgreSQL Anonymizer vulnerability",
            "summary": "PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later versions",
            "updated_at": "2026-09-09T05:17:19.990",
            "published_at": "2026-09-06T16:16:49.583",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1 through before 3.1.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later versions",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/665"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T16:16:49.583",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19633"
                }
            ]
        },
        {
            "id": "CVE-2026-19632",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-19632 - TranslatePress One-Day PoC",
            "summary": "CVE-2026-19632 - TranslatePress One-Day PoC",
            "updated_at": "2026-08-26T10:16:08Z",
            "published_at": "2026-08-26T10:16:08Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 94,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · YonLiud/CVE-2026-19632",
                    "author": "YonLiud",
                    "first_seen": "2026-08-26",
                    "last_seen": "2026-08-26T10:16:08Z",
                    "pushed_at": "2026-08-26T09:39:24Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [
                        "cve",
                        "poc",
                        "wordpress",
                        "wordpress-plugin"
                    ],
                    "title": "CVE-2026-19632 - TranslatePress One-Day PoC",
                    "repository_description": "CVE-2026-19632 - TranslatePress One-Day PoC",
                    "summary": "CVE-2026-19632 - TranslatePress One-Day PoC",
                    "source": "CVE-Intel",
                    "url": "https://github.com/YonLiud/CVE-2026-19632"
                }
            ],
            "references": [
                "https://github.com/YonLiud/CVE-2026-19632"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T10:16:08Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/YonLiud/CVE-2026-19632"
                }
            ]
        },
        {
            "id": "CVE-2026-19584",
            "vendor": "Rapid7",
            "product": "Velociraptor",
            "title": "Velociraptor vulnerability",
            "summary": "Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.",
            "updated_at": "2026-09-11T04:17:34.343",
            "published_at": "2026-09-10T03:17:00.063",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.77.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-94",
            "what_happened": "Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "http://docs.velociraptor.app/announcements/advisories/cve-2026-19584/",
                "https://github.com/Velocidex/velociraptor/pull/4967"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T03:17:00.063",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19584"
                }
            ]
        },
        {
            "id": "CVE-2026-19583",
            "vendor": "Rapid7",
            "product": "Velociraptor",
            "title": "Velociraptor vulnerability",
            "summary": "Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts (such as Linux.Sys.BashShell).",
            "updated_at": "2026-09-11T04:17:24.930",
            "published_at": "2026-09-10T03:16:59.010",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.77.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-732",
            "what_happened": "Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts (such as Linux.Sys.BashShell).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "http://docs.velociraptor.app/announcements/advisories/cve-2026-19583/",
                "https://github.com/Velocidex/velociraptor/pull/4967"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T03:16:59.010",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19583"
                }
            ]
        },
        {
            "id": "CVE-2026-19490",
            "vendor": "NetScaler",
            "product": "ADC",
            "title": "ADC vulnerability",
            "summary": "Vulnerability in NetScaler ADC and NetScaler Gateway.\n\nThis issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.",
            "updated_at": "2026-09-10T04:17:48.967",
            "published_at": "2026-08-19T13:17:45.000",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "review",
            "affected": "14.1 through 73.32 (patch); 13.1 through 63.21 (patch)",
            "fixed": "See vendor advisory",
            "source_count": 54,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-288",
            "what_happened": "Vulnerability in NetScaler ADC and NetScaler Gateway.\n\nThis issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · TarPeg007/CVE-2026-19490",
                    "author": "TarPeg007",
                    "first_seen": "2026-09-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC",
                    "summary": "NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC",
                    "url": "https://github.com/TarPeg007/CVE-2026-19490"
                }
            ],
            "references": [
                "https://github.com/TarPeg007/CVE-2026-19490",
                "https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696939",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-19490"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T13:17:45.000",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19490"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-19398",
            "vendor": "ASUS",
            "product": "FA507NV",
            "title": "FA507NV vulnerability",
            "summary": "An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the ' \nSecurity Update for ASUS FA507NV / FA507NU BIOS   ' section on the ASUS Security Advisory for more information.",
            "updated_at": "2026-09-09T04:17:56.747",
            "published_at": "2026-08-27T02:16:27.460",
            "cvss": 6.8,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "318 (custom); 318",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the ' \nSecurity Update for ASUS FA507NV / FA507NU BIOS   ' section on the ASUS Security Advisory for more information.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.asus.com/security-advisory"
            ],
            "timeline": [
                {
                    "at": "2026-08-27T02:16:27.460",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19398"
                }
            ]
        },
        {
            "id": "CVE-2026-19389",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.",
            "updated_at": "2026-09-16T13:17:19.903",
            "published_at": "2026-08-10T03:16:40.380",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds checks and cause out-of-bounds heap reads. This can result in application crash, denial of service, or limited information disclosure when untrusted media is processed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:55435",
                "https://access.redhat.com/errata/RHSA-2026:55865",
                "https://access.redhat.com/security/cve/CVE-2026-19389",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2513016",
                "https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12233",
                "https://gstreamer.freedesktop.org/releases/1.28/",
                "https://gstreamer.freedesktop.org/security/sa-2026-0075.html",
                "https://access.redhat.com/errata/RHSA-2026:67882",
                "https://access.redhat.com/errata/RHSA-2026:67883",
                "https://access.redhat.com/errata/RHSA-2026:67930",
                "https://access.redhat.com/errata/RHSA-2026:67931"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T03:16:40.380",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19389"
                }
            ]
        },
        {
            "id": "CVE-2026-19387",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.",
            "updated_at": "2026-09-16T07:16:33.107",
            "published_at": "2026-08-10T03:16:40.223",
            "cvss": 7.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated output buffer. This can lead to application crash, denial of service, memory corruption, or potentially arbitrary code execution when untrusted media is processed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:55433",
                "https://access.redhat.com/errata/RHSA-2026:55865",
                "https://access.redhat.com/errata/RHSA-2026:56521",
                "https://access.redhat.com/errata/RHSA-2026:65122",
                "https://access.redhat.com/errata/RHSA-2026:65123",
                "https://access.redhat.com/errata/RHSA-2026:65124",
                "https://access.redhat.com/errata/RHSA-2026:66406",
                "https://access.redhat.com/errata/RHSA-2026:66407",
                "https://access.redhat.com/errata/RHSA-2026:67151",
                "https://access.redhat.com/security/cve/CVE-2026-19387",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2513015",
                "https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12235",
                "https://gstreamer.freedesktop.org/releases/1.28/",
                "https://access.redhat.com/errata/RHSA-2026:67844"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T03:16:40.223",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19387"
                }
            ]
        },
        {
            "id": "CVE-2026-19130",
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1",
            "title": "multicluster engine for Kubernetes 2.1 vulnerability",
            "summary": "A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure. This allows access to sensitive credentials that should otherwise be protected.",
            "updated_at": "2026-09-07T19:17:26.523",
            "published_at": "2026-08-12T21:17:37.703",
            "cvss": 5.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-639",
            "what_happened": "A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom` labels, the attacker could intercept newly rotated provider credentials, leading to unauthorized information disclosure. This allows access to sensitive credentials that should otherwise be protected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:59556",
                "https://access.redhat.com/errata/RHSA-2026:59557",
                "https://access.redhat.com/errata/RHSA-2026:59558",
                "https://access.redhat.com/errata/RHSA-2026:59559",
                "https://access.redhat.com/errata/RHSA-2026:59579",
                "https://access.redhat.com/errata/RHSA-2026:59593",
                "https://access.redhat.com/security/cve/CVE-2026-19130",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2512105"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T21:17:37.703",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19130"
                }
            ]
        },
        {
            "id": "CVE-2026-19004",
            "vendor": "MongoDB",
            "product": "BI Connector ODBC Driver",
            "title": "BI Connector ODBC Driver vulnerability",
            "summary": "An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that returns crafted metadata. This may result in process termination, disclosure of process memory, or, under certain conditions, arbitrary code execution.",
            "updated_at": "2026-09-11T18:59:45.797",
            "published_at": "2026-08-12T21:17:37.577",
            "cvss": 8.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through before 1.4.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-122",
            "what_happened": "An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that returns crafted metadata. This may result in process termination, disclosure of process memory, or, under certain conditions, arbitrary code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T21:17:37.577",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19004"
                }
            ]
        },
        {
            "id": "CVE-2026-19003",
            "vendor": "MongoDB",
            "product": "BI Connector ODBC Driver",
            "title": "BI Connector ODBC Driver vulnerability",
            "summary": "A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the dialog's file and folder selection handling, and is reached only when a user opens the setup dialog for such a data source and initiates a file or folder selection. Depending on build configuration, the result may range from abnormal process termination to, under certain conditions, execution of unintended code in the context of the user running the dialog.",
            "updated_at": "2026-09-11T18:54:13.050",
            "published_at": "2026-08-12T22:17:15.153",
            "cvss": 8.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through before 1.4.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the dialog's file and folder selection handling, and is reached only when a user opens the setup dialog for such a data source and initiates a file or folder selection. Depending on build configuration, the result may range from abnormal process termination to, under certain conditions, execution of unintended code in the context of the user running the dialog.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T22:17:15.153",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19003"
                }
            ]
        },
        {
            "id": "CVE-2026-19002",
            "vendor": "MongoDB",
            "product": "BI Connector ODBC Driver",
            "title": "BI Connector ODBC Driver vulnerability",
            "summary": "A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to return malformed metadata. The resulting memory corruption may cause the client application to terminate abnormally or, under certain conditions, execute unintended code.",
            "updated_at": "2026-09-11T18:52:43.157",
            "published_at": "2026-08-12T21:17:37.440",
            "cvss": 8.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through before 1.4.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-120",
            "what_happened": "A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to return malformed metadata. The resulting memory corruption may cause the client application to terminate abnormally or, under certain conditions, execute unintended code.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T21:17:37.440",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19002"
                }
            ]
        },
        {
            "id": "CVE-2026-19001",
            "vendor": "MongoDB",
            "product": "BI Connector ODBC Driver",
            "title": "BI Connector ODBC Driver vulnerability",
            "summary": "The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.",
            "updated_at": "2026-09-11T18:53:56.270",
            "published_at": "2026-08-12T21:17:37.307",
            "cvss": 9.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through before 1.4.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-190",
            "what_happened": "The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and, under certain conditions, the potential for arbitrary code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T21:17:37.307",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-19001"
                }
            ]
        },
        {
            "id": "CVE-2026-18964",
            "vendor": "premio",
            "product": "Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty",
            "title": "Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty vulnerability",
            "summary": "The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. WordPress's server-side HTML encoding of the 's' search parameter in the &lt;title&gt; element is bypassed because the browser DOM API decodes HTML entities when jQuery's .text() method reads document.title, returning literal special characters that are then embedded unescaped into the constructed HTML attribute value.",
            "updated_at": "2026-09-11T04:17:24.760",
            "published_at": "2026-09-11T04:17:24.760",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.5.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. WordPress's server-side HTML encoding of the 's' search parameter in the &lt;title&gt; element is bypassed because the browser DOM API decodes HTML entities when jQuery's .text() method reads document.title, returning literal special characters that are then embedded unescaped into the constructed HTML attribute value.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/chaty/trunk/js/cht-front-script.min.js#L1",
                "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3637386%40chaty%2Ftrunk%2Fjs%2Fcht-front-script.min.js&old=3485342%40chaty%2Ftrunk%2Fjs%2Fcht-front-script.min.js&sfp_email=&sfph_mail=",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/918af0dc-afad-4645-b4ad-8b10a34e20b2?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T04:17:24.760",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18964"
                }
            ]
        },
        {
            "id": "CVE-2026-18963",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.4",
            "title": "CVE-2026-18963",
            "summary": "CVE-2026-18963",
            "updated_at": "2026-08-20T14:17:10.413",
            "published_at": "2026-08-18T17:16:57.083",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1038,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-640",
            "what_happened": "A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without needing to click the required email verification link. This can result in the attacker gaining full control over target user accounts by directly setting new credentials.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · Red-Darkin/CVE-2026-18963-keycloak",
                    "author": "Red-Darkin",
                    "first_seen": "2026-08-24",
                    "last_seen": "2026-08-26T12:33:22Z",
                    "pushed_at": "2026-08-25T18:22:45Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 16,
                    "forks": 3,
                    "topics": [],
                    "title": "CVE-2026-18963",
                    "repository_description": "CVE-2026-18963",
                    "summary": "CVE-2026-18963",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Red-Darkin/CVE-2026-18963-keycloak"
                },
                {
                    "repository": "CVE-Intel · Snizi/CVE-2026-18963-Exploit",
                    "author": "Snizi",
                    "first_seen": "2026-08-20",
                    "last_seen": "2026-08-26T08:33:39Z",
                    "pushed_at": "2026-08-20T22:38:38Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Bypass",
                    "language": "Python",
                    "stars": 24,
                    "forks": 6,
                    "topics": [
                        "account-takeover",
                        "authentication-bypass",
                        "cve-2026-18963",
                        "exploit",
                        "keycloak",
                        "oauth2",
                        "penetration-testing",
                        "poc"
                    ],
                    "title": "Exploit for KeyCloak CVE-2026-18963",
                    "repository_description": "Exploit for KeyCloak CVE-2026-18963",
                    "summary": "Exploit for KeyCloak CVE-2026-18963",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Snizi/CVE-2026-18963-Exploit"
                },
                {
                    "repository": "CVE-Intel · prot0tw/Keycloak_CVE-2026-18963_PoC",
                    "author": "prot0tw",
                    "first_seen": "2026-08-25",
                    "last_seen": "2026-08-26T08:14:10Z",
                    "pushed_at": "2026-08-26T08:13:39Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "Python",
                    "stars": 13,
                    "forks": 0,
                    "topics": [],
                    "title": "This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).",
                    "repository_description": "This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).",
                    "summary": "This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).",
                    "source": "CVE-Intel",
                    "url": "https://github.com/prot0tw/Keycloak_CVE-2026-18963_PoC"
                },
                {
                    "repository": "CVE-Intel · T0w0T/POC-CVE-2026-18963",
                    "author": "T0w0T",
                    "first_seen": "2026-08-24",
                    "last_seen": "2026-08-25T20:19:58Z",
                    "pushed_at": "2026-08-24T13:07:07Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "Python",
                    "stars": 2,
                    "forks": 0,
                    "topics": [],
                    "title": "POC-CVE-2026-18963",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/T0w0T/POC-CVE-2026-18963"
                },
                {
                    "repository": "CVE-Intel · debugactiveprocess/CVE-2026-18963",
                    "author": "debugactiveprocess",
                    "first_seen": "2026-08-25",
                    "last_seen": "2026-08-25T16:58:52Z",
                    "pushed_at": "2026-08-25T16:49:33Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "Exploit",
                    "language": "",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "Nuclei template to discover Keycloak reset-credentials endpoints related to CVE-2026-18963 exposure validation.",
                    "repository_description": "Nuclei template to discover Keycloak reset-credentials endpoints related to CVE-2026-18963 exposure validation.",
                    "summary": "Nuclei template to discover Keycloak reset-credentials endpoints related to CVE-2026-18963 exposure validation.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/debugactiveprocess/CVE-2026-18963"
                },
                {
                    "repository": "CVE-Intel · gman0x00/keycloak-CVE-2026-18963",
                    "author": "gman0x00",
                    "first_seen": "2026-08-25",
                    "last_seen": "2026-08-25T15:27:37Z",
                    "pushed_at": "2026-08-25T15:05:16Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "PoC, Dockerfile playground and root cause from patch diff analysis.",
                    "repository_description": "PoC, Dockerfile playground and root cause from patch diff analysis.",
                    "summary": "PoC, Dockerfile playground and root cause from patch diff analysis.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/gman0x00/keycloak-CVE-2026-18963"
                },
                {
                    "repository": "CVE-Intel · kyos-public/keycloak-cve-2026-18963-hunt",
                    "author": "kyos-public",
                    "first_seen": "2026-08-20",
                    "last_seen": "2026-08-25T09:13:33Z",
                    "pushed_at": "2026-08-24T15:28:14Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "Exploit",
                    "language": "",
                    "stars": 11,
                    "forks": 1,
                    "topics": [
                        "cve",
                        "incident-response",
                        "keycloak",
                        "postgresql",
                        "security"
                    ],
                    "title": "Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database",
                    "repository_description": "Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database",
                    "summary": "Hunt for CVE-2026-18963 exploitation traces (Keycloak unauthenticated account takeover) in the Keycloak database",
                    "source": "CVE-Intel",
                    "url": "https://github.com/kyos-public/keycloak-cve-2026-18963-hunt"
                },
                {
                    "repository": "CVE-Intel · minh3102011/CVE-2026-18963_analyst",
                    "author": "minh3102011",
                    "first_seen": "2026-08-24",
                    "last_seen": "2026-08-24T08:57:27Z",
                    "pushed_at": "2026-08-24T08:55:48Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "Exploit",
                    "language": "",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-18963_analyst",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/minh3102011/CVE-2026-18963_analyst"
                },
                {
                    "repository": "PoC-in-GitHub · BlackHatExploitation/Exploit-For-CVE-2026-18963",
                    "author": "BlackHatExploitation",
                    "first_seen": "2026-08-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit for CVE-2026-18963 by BlackHatExploitation",
                    "summary": "Exploit for CVE-2026-18963 by BlackHatExploitation",
                    "url": "https://github.com/BlackHatExploitation/Exploit-For-CVE-2026-18963"
                },
                {
                    "repository": "PoC-in-GitHub · alt3kx/CVE-2026-18963",
                    "author": "alt3kx",
                    "first_seen": "2026-08-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector",
                    "summary": "CVE-2026-18963 Keycloak Reset-Credentials State Bypass Detector",
                    "url": "https://github.com/alt3kx/CVE-2026-18963"
                },
                {
                    "repository": "PoC-in-GitHub · M4xSec/My-Exploits",
                    "author": "M4xSec",
                    "first_seen": "2026-08-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).",
                    "summary": "Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp Vault (CVE-2026-5006), HashiCorp Nomad (CVE-2026-7474).",
                    "url": "https://github.com/M4xSec/My-Exploits"
                },
                {
                    "repository": "PoC-in-GitHub · EQSTLab/CVE-2026-18963",
                    "author": "EQSTLab",
                    "first_seen": "2026-09-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Keycloak reset-credentials flow bypass",
                    "summary": "Keycloak reset-credentials flow bypass",
                    "url": "https://github.com/EQSTLab/CVE-2026-18963"
                },
                {
                    "title": "Exploit for CVE-2026-18963",
                    "summary": "Keycloak reset-credentials bypass leading to account takeover via exploit.",
                    "what_happened": "Keycloak reset-credentials bypass leading to account takeover via exploit.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=88FAD2B1-66D0-5B36-903D-3E231116548C",
                        "https://github.com/0xlyvio/CVE-2026-18963-keycloak"
                    ],
                    "repository": "Sploitus",
                    "author": "0xlyvio",
                    "first_seen": "2026-09-05T20:53:12",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=88FAD2B1-66D0-5B36-903D-3E231116548C"
                },
                {
                    "repository": "PoC-in-GitHub · 0xlyvio/CVE-2026-18963-keycloak",
                    "author": "0xlyvio",
                    "first_seen": "2026-09-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-18963 — Keycloak reset-credentials bypass -> Account Takeover",
                    "summary": "CVE-2026-18963 — Keycloak reset-credentials bypass -> Account Takeover",
                    "url": "https://github.com/0xlyvio/CVE-2026-18963-keycloak"
                },
                {
                    "repository": "PoC-in-GitHub · ynsmroztas/KeySniper",
                    "author": "ynsmroztas",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 109,
                    "title": "**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.",
                    "summary": "**CVE-2026-18963** — unauthenticated Keycloak account takeover via the reset-credentials flow.",
                    "url": "https://github.com/ynsmroztas/KeySniper"
                },
                {
                    "repository": "PoC-in-GitHub · ivanesk315/CVE-2026-18963",
                    "author": "ivanesk315",
                    "first_seen": "2026-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-18963 repository",
                    "summary": "",
                    "url": "https://github.com/ivanesk315/CVE-2026-18963"
                }
            ],
            "references": [
                "https://github.com/Red-Darkin/CVE-2026-18963-keycloak",
                "https://github.com/Snizi/CVE-2026-18963-Exploit",
                "https://github.com/prot0tw/Keycloak_CVE-2026-18963_PoC",
                "https://github.com/T0w0T/POC-CVE-2026-18963",
                "https://github.com/debugactiveprocess/CVE-2026-18963",
                "https://github.com/gman0x00/keycloak-CVE-2026-18963",
                "https://github.com/kyos-public/keycloak-cve-2026-18963-hunt",
                "https://github.com/minh3102011/CVE-2026-18963_analyst",
                "https://github.com/BlackHatExploitation/Exploit-For-CVE-2026-18963",
                "https://github.com/alt3kx/CVE-2026-18963",
                "https://github.com/M4xSec/My-Exploits",
                "https://github.com/EQSTLab/CVE-2026-18963",
                "https://access.redhat.com/errata/RHSA-2026:56519",
                "https://access.redhat.com/errata/RHSA-2026:56520",
                "https://access.redhat.com/errata/RHSA-2026:56523",
                "https://access.redhat.com/errata/RHSA-2026:56524",
                "https://access.redhat.com/security/cve/CVE-2026-18963",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2511595",
                "https://sploitus.com/exploit?id=88FAD2B1-66D0-5B36-903D-3E231116548C",
                "https://github.com/0xlyvio/CVE-2026-18963-keycloak",
                "https://github.com/ynsmroztas/KeySniper",
                "https://github.com/ivanesk315/CVE-2026-18963"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T12:33:22Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/Red-Darkin/CVE-2026-18963-keycloak"
                },
                {
                    "at": "2026-08-18T17:16:57.083",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18963"
                }
            ],
            "enrichment_checked_at": "2026-09-05T22:05:27Z",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2026-18924",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process.",
            "updated_at": "2026-09-15T07:16:27.063",
            "published_at": "2026-09-06T18:17:20.553",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.44.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 8.21.0 through before 8.22.0 (semver); ea7134ac874a66107e54ff93657ac565cf2ec4aa through before 90325ff0444cbdff368bda5d26d6405a0bb6ee43 (git); 8.21.0; 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-09-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3916059"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-18924.html",
                "https://curl.se/docs/CVE-2026-18924.json",
                "https://hackerone.com/reports/3916059"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T18:17:20.553",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18924"
                }
            ]
        },
        {
            "id": "CVE-2026-18922",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
            "title": "Red Hat Enterprise Linux 7 Extended Lifecycle Support vulnerability",
            "summary": "A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.",
            "updated_at": "2026-09-08T03:17:18.400",
            "published_at": "2026-09-07T15:17:31.157",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:64771",
                "https://access.redhat.com/security/cve/CVE-2026-18922",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2511388"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T15:17:31.157",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18922"
                }
            ]
        },
        {
            "id": "CVE-2026-18917",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.",
            "updated_at": "2026-09-15T07:16:26.900",
            "published_at": "2026-08-20T10:16:40.507",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denial of service or local privilege escalation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/security/cve/CVE-2026-18917",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2520161"
            ],
            "timeline": [
                {
                    "at": "2026-08-20T10:16:40.507",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18917"
                }
            ]
        },
        {
            "id": "CVE-2026-18905",
            "vendor": "IBM",
            "product": "ContextForge MCP Gateway (`mcp-contextforge-gateway`)",
            "title": "ContextForge MCP Gateway (`mcp-contextforge-gateway`) vulnerability",
            "summary": "IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.",
            "updated_at": "2026-09-15T15:21:14.713",
            "published_at": "2026-09-04T16:17:21.517",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "<= v1.0.6",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286053"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:17:21.517",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18905"
                }
            ]
        },
        {
            "id": "CVE-2026-18888",
            "vendor": "MongoDB",
            "product": "BI Connector ODBC Driver",
            "title": "BI Connector ODBC Driver vulnerability",
            "summary": "The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffer and corrupt adjacent memory. A user who can store data in a collection read through the BI Connector could use this to crash the application performing the read.",
            "updated_at": "2026-09-11T18:52:17.057",
            "published_at": "2026-08-12T21:17:37.170",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through before 1.4.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffer and corrupt adjacent memory. A user who can store data in a collection read through the BI Connector could use this to crash the application performing the read.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/mongodb/mongo-bi-connector-odbc-driver/releases/tag/v1.4.9"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T21:17:37.170",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18888"
                }
            ]
        },
        {
            "id": "CVE-2026-18874",
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Management for Kubernetes 2.11",
            "title": "Red Hat Advanced Cluster Management for Kubernetes 2.11 vulnerability",
            "summary": "A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper escaping of annotation values when they are rendered into YAML. Successful exploitation could lead to unauthorized modification or control over OLM Subscription configurations, potentially impacting software management within the cluster. This issue primarily affects systems where the 'volsync-addon-deploy-type: olm' annotation is explicitly enabled.",
            "updated_at": "2026-09-05T17:17:20.563",
            "published_at": "2026-08-19T18:16:36.080",
            "cvss": 6.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-94",
            "what_happened": "A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper escaping of annotation values when they are rendered into YAML. Successful exploitation could lead to unauthorized modification or control over OLM Subscription configurations, potentially impacting software management within the cluster. This issue primarily affects systems where the 'volsync-addon-deploy-type: olm' annotation is explicitly enabled.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/errata/RHSA-2026:60387",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/errata/RHSA-2026:60389",
                "https://access.redhat.com/errata/RHSA-2026:60390",
                "https://access.redhat.com/errata/RHSA-2026:60391",
                "https://access.redhat.com/security/cve/CVE-2026-18874",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2511115"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T18:16:36.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18874"
                }
            ]
        },
        {
            "id": "CVE-2026-18851",
            "vendor": "Ivanti",
            "product": "Endpoint Manager Mobile",
            "title": "Endpoint Manager Mobile vulnerability",
            "summary": "Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.",
            "updated_at": "2026-09-09T05:17:19.830",
            "published_at": "2026-09-08T15:18:42.533",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://hub.ivanti.com/s/article/Security-Advisory---Ivanti-Endpoint-Manager-Mobile-CVE-2026-18851?language=en_US"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T15:18:42.533",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18851"
                }
            ]
        },
        {
            "id": "CVE-2026-18843",
            "vendor": "The Beaver Builder Team",
            "product": "Beaver Builder Plugin (Starter Version)",
            "title": "Beaver Builder Plugin (Starter Version) vulnerability",
            "summary": "The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and including, 2.11.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",
            "updated_at": "2026-09-05T07:17:11.207",
            "published_at": "2026-09-05T07:17:11.207",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.11.0.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all versions up to, and including, 2.11.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/074c95bb-c68e-452d-bd2e-c44866aeedba?source=cve",
                "https://www.wpbeaverbuilder.com/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:11.207",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18843"
                }
            ]
        },
        {
            "id": "CVE-2026-18796",
            "vendor": "Nordic Semiconductor ASA",
            "product": "nRF5340",
            "title": "nRF5340 vulnerability",
            "summary": "Any application that\n     uses external QSPI flash for encrypted XIP on nRF5340 and relies on that\n     encryption for confidentiality and/or integrity of the externally stored\n     code. No specific nRF Connect SDK version is the root cause; the weakness\n     is in the on-the-fly decryption scheme.",
            "updated_at": "2026-09-07T09:17:15.570",
            "published_at": "2026-09-07T09:17:15.570",
            "cvss": 6.8,
            "cvss_vector": "CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "All build codes",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Physical",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-1342",
            "what_happened": "Any application that\n     uses external QSPI flash for encrypted XIP on nRF5340 and relies on that\n     encryption for confidentiality and/or integrity of the externally stored\n     code. No specific nRF Connect SDK version is the root cause; the weakness\n     is in the on-the-fly decryption scheme.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.nordicsemi.com/r/bundle/struct_sa/page/struct/sa.html"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T09:17:15.570",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18796"
                }
            ]
        },
        {
            "id": "CVE-2026-18754",
            "vendor": "GeoVision Inc.",
            "product": "GV-AS1620 (GV-Cloud)",
            "title": "GV-AS1620 (GV-Cloud) vulnerability",
            "summary": "The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.",
            "updated_at": "2026-09-09T15:41:02.580",
            "published_at": "2026-08-04T08:16:34.803",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "V1.16",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-321",
            "what_happened": "The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.geovision.com.tw/cyber_security.php"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T08:16:34.803",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18754"
                }
            ]
        },
        {
            "id": "CVE-2026-18753",
            "vendor": "GeoVision Inc.",
            "product": "GV-AS1620 (AS-Manager)",
            "title": "GV-AS1620 (AS-Manager) vulnerability",
            "summary": "The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.",
            "updated_at": "2026-09-09T15:41:02.580",
            "published_at": "2026-08-04T08:16:34.640",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "V2.07",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-321",
            "what_happened": "The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.geovision.com.tw/cyber_security.php"
            ],
            "timeline": [
                {
                    "at": "2026-08-04T08:16:34.640",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18753"
                }
            ]
        },
        {
            "id": "CVE-2026-18738",
            "vendor": "shlinkio",
            "product": "Shlink",
            "title": "Shlink vulnerability",
            "summary": "Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, or request path headers beginning with formula-triggering characters such as =, +, -, or @. Attackers can craft a single unauthenticated request against any short URL to embed DDE or WEBSERVICE formula payloads into CSV cells, which are then executed on an administrator's client machine when the exported CSV file is opened in a spreadsheet application that evaluates formulas.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-08-03T21:16:38.377",
            "cvss": 5.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5.0.0 through 5.1.5 (git)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1236",
            "what_happened": "Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, or request path headers beginning with formula-triggering characters such as =, +, -, or @. Attackers can craft a single unauthenticated request against any short URL to embed DDE or WEBSERVICE formula payloads into CSV cells, which are then executed on an administrator's client machine when the exported CSV file is opened in a spreadsheet application that evaluates formulas.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/shlinkio/shlink",
                "https://github.com/theopaid/CSV-formula-injection-in-visit-exports-shlink-",
                "https://www.vulncheck.com/advisories/shlink-csv-formula-injection-via-visit-export-cli"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:38.377",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18738"
                }
            ]
        },
        {
            "id": "CVE-2026-18737",
            "vendor": "shlinkio",
            "product": "Shlink",
            "title": "Shlink vulnerability",
            "summary": "Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value in the orderBy query parameter of the tag statistics endpoint. Attackers can craft a malicious direction string containing SQL subqueries that flows unsanitized into a Doctrine QueryBuilder ORDER BY clause, enabling time-based, boolean-oracle, and error-based extraction of sensitive data including long URLs, visitor records, IP addresses, geolocation data, user agents, and hashed API key secrets from any tenant.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-08-03T21:16:38.240",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.3.1 through 5.1.5 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value in the orderBy query parameter of the tag statistics endpoint. Attackers can craft a malicious direction string containing SQL subqueries that flows unsanitized into a Doctrine QueryBuilder ORDER BY clause, enabling time-based, boolean-oracle, and error-based extraction of sensitive data including long URLs, visitor records, IP addresses, geolocation data, user agents, and hashed API key secrets from any tenant.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/shlinkio/shlink",
                "https://github.com/theopaid/SQL-injection-in-GET-rest-v-n-tags-stats-via-the-orderBy-parameter-shlink-",
                "https://www.vulncheck.com/advisories/shlink-blind-sql-injection-via-tags-stats-orderby-parameter"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:38.240",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18737"
                }
            ]
        },
        {
            "id": "CVE-2026-18736",
            "vendor": "shlinkio",
            "product": "Shlink",
            "title": "Shlink vulnerability",
            "summary": "Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs pointing to public hosts that redirect to internal targets, including loopback addresses, link-local ranges, and cloud metadata endpoints such as 169.254.169.254, to exfiltrate internal service information via the HTML title element returned in the short URL creation response.",
            "updated_at": "2026-09-09T20:35:08.537",
            "published_at": "2026-08-03T21:16:38.093",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.6.0 through 5.1.5 (git)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs pointing to public hosts that redirect to internal targets, including loopback addresses, link-local ranges, and cloud metadata endpoints such as 169.254.169.254, to exfiltrate internal service information via the HTML title element returned in the short URL creation response.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/shlinkio/shlink",
                "https://github.com/theopaid/Server-side-request-forgery-through-short-URL-title-resolution-shlink-",
                "https://www.vulncheck.com/advisories/shlink-server-side-request-forgery-via-short-url-title-auto-resolution"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T21:16:38.093",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18736"
                }
            ]
        },
        {
            "id": "CVE-2026-18709",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. This could result in cross-shard data inconsistency, cluster clock corruption, and violation of transaction atomicity guarantees.",
            "updated_at": "2026-09-16T15:19:45.197",
            "published_at": "2026-08-11T19:17:25.827",
            "cvss": 5.9,
            "cvss_vector": "CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-862",
            "what_happened": "An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. This could result in cross-shard data inconsistency, cluster clock corruption, and violation of transaction atomicity guarantees.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-130544"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:25.827",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18709"
                }
            ]
        },
        {
            "id": "CVE-2026-18708",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored value processed during an internal maintenance cycle. This could result in corruption of query results affecting other users and denial of service targeted at their operations on the same database. Impact is limited to the scripting engine's execution sandbox, which does not provide access to database, filesystem, or network resources.",
            "updated_at": "2026-09-16T15:19:39.170",
            "published_at": "2026-08-11T19:17:25.670",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored value processed during an internal maintenance cycle. This could result in corruption of query results affecting other users and denial of service targeted at their operations on the same database. Impact is limited to the scripting engine's execution sandbox, which does not provide access to database, filesystem, or network resources.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-130167"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:25.670",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18708"
                }
            ]
        },
        {
            "id": "CVE-2026-18707",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service.",
            "updated_at": "2026-09-16T15:19:32.357",
            "published_at": "2026-08-11T19:17:25.517",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-617",
            "what_happened": "An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-128482"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:25.517",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18707"
                }
            ]
        },
        {
            "id": "CVE-2026-18706",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potentially, execution of unintended code.",
            "updated_at": "2026-09-16T15:19:25.793",
            "published_at": "2026-08-11T19:17:25.360",
            "cvss": 7.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potentially, execution of unintended code.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-128551"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:25.360",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18706"
                }
            ]
        },
        {
            "id": "CVE-2026-18705",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.",
            "updated_at": "2026-09-16T15:19:18.490",
            "published_at": "2026-08-11T19:17:25.207",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-807",
            "what_happened": "An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request forwarded to the search process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-129618"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:25.207",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18705"
                }
            ]
        },
        {
            "id": "CVE-2026-18704",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation stage being reachable by external clients without an appropriate authorization check on its embedded operations.",
            "updated_at": "2026-09-16T15:19:11.820",
            "published_at": "2026-08-11T19:17:25.050",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation stage being reachable by external clients without an appropriate authorization check on its embedded operations.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-129936"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:25.050",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18704"
                }
            ]
        },
        {
            "id": "CVE-2026-18703",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to restrict authentication to other mechanisms. This could allow authentication through a method the administrator intended to disable.",
            "updated_at": "2026-09-16T15:19:02.303",
            "published_at": "2026-08-11T19:17:24.900",
            "cvss": 2.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-863",
            "what_happened": "An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to restrict authentication to other mechanisms. This could allow authentication through a method the administrator intended to disable.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-127863"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:24.900",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18703"
                }
            ]
        },
        {
            "id": "CVE-2026-18702",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database. This could allow suppression of diagnostic logging server-wide, potentially obscuring unauthorized activity, or degrade operational monitoring by causing excessive log volume.",
            "updated_at": "2026-09-16T15:18:38.007",
            "published_at": "2026-08-11T19:17:24.743",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database. This could allow suppression of diagnostic logging server-wide, potentially obscuring unauthorized activity, or degrade operational monitoring by causing excessive log volume.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-130198"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:24.743",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18702"
                }
            ]
        },
        {
            "id": "CVE-2026-18701",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed query filter. This could result in a denial of service.",
            "updated_at": "2026-09-16T15:18:29.637",
            "published_at": "2026-08-11T19:17:24.580",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-843",
            "what_happened": "An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed query filter. This could result in a denial of service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-130111"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:24.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18701"
                }
            ]
        },
        {
            "id": "CVE-2026-18700",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed, through concurrent operations against a collection using a certain type of validator. This could result in a server crash, leading to a denial of service.",
            "updated_at": "2026-09-16T15:18:14.393",
            "published_at": "2026-08-11T19:17:24.417",
            "cvss": 6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed, through concurrent operations against a collection using a certain type of validator. This could result in a server crash, leading to a denial of service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-130117"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:24.417",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18700"
                }
            ]
        },
        {
            "id": "CVE-2026-18699",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. This could result in a denial of service, affecting connected clients and in-flight operations.",
            "updated_at": "2026-09-16T15:18:00.993",
            "published_at": "2026-08-11T19:17:24.270",
            "cvss": 6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. This could result in a denial of service, affecting connected clients and in-flight operations.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-130266"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:24.270",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18699"
                }
            ]
        },
        {
            "id": "CVE-2026-18698",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain deployment configurations, unauthorized modification of system collection data.",
            "updated_at": "2026-09-16T15:17:51.067",
            "published_at": "2026-08-11T19:17:24.120",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain deployment configurations, unauthorized modification of system collection data.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-130481"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:24.120",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18698"
                }
            ]
        },
        {
            "id": "CVE-2026-18697",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service, disrupting client connections routed through the affected mongos instance.",
            "updated_at": "2026-09-16T15:17:42.620",
            "published_at": "2026-08-11T19:17:23.983",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-617",
            "what_happened": "An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service, disrupting client connections routed through the affected mongos instance.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-130110"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:23.983",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18697"
                }
            ]
        },
        {
            "id": "CVE-2026-18696",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.",
            "updated_at": "2026-09-16T15:17:34.163",
            "published_at": "2026-08-11T19:17:23.853",
            "cvss": 7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target collection is determined between the authorization check and the actual operation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-130139"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:23.853",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18696"
                }
            ]
        },
        {
            "id": "CVE-2026-18695",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user with write access to cause the server process to terminate unexpectedly, resulting in a denial of service.",
            "updated_at": "2026-09-16T15:17:17.943",
            "published_at": "2026-08-11T19:17:23.717",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-617",
            "what_happened": "An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user with write access to cause the server process to terminate unexpectedly, resulting in a denial of service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-129460"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:23.717",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18695"
                }
            ]
        },
        {
            "id": "CVE-2026-18694",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation. Subsequent queries against this data could then result in the server accessing memory outside its intended bounds. This could result in a server crash (denial of service) and may expose a limited amount of server process memory.",
            "updated_at": "2026-09-16T15:16:51.150",
            "published_at": "2026-08-11T19:17:23.580",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation. Subsequent queries against this data could then result in the server accessing memory outside its intended bounds. This could result in a server crash (denial of service) and may expose a limited amount of server process memory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-130188"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:23.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18694"
                }
            ]
        },
        {
            "id": "CVE-2026-18693",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain document insertions. A subsequent insert into the affected bucket could then result in the server accessing memory outside its intended bounds, potentially causing a server crash (denial of service), exposure of limited memory contents, or memory corruption.",
            "updated_at": "2026-09-16T15:16:33.437",
            "published_at": "2026-08-11T19:17:23.450",
            "cvss": 7.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain document insertions. A subsequent insert into the affected bucket could then result in the server accessing memory outside its intended bounds, potentially causing a server crash (denial of service), exposure of limited memory contents, or memory corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-129994"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:23.450",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18693"
                }
            ]
        },
        {
            "id": "CVE-2026-18692",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed. Subsequent operations could then result in a server crash or, potentially, execution of unintended code.",
            "updated_at": "2026-09-16T15:16:27.380",
            "published_at": "2026-08-11T19:17:23.317",
            "cvss": 7.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed. Subsequent operations could then result in a server crash or, potentially, execution of unintended code.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-129887"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:23.317",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18692"
                }
            ]
        },
        {
            "id": "CVE-2026-18691",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be transmitted in a less-protected form, potentially allowing that credential to be recovered. If recovered, the credential could be used to authenticate as the internal superuser to nodes in the deployment.",
            "updated_at": "2026-09-16T15:16:15.303",
            "published_at": "2026-08-11T19:17:22.903",
            "cvss": 9,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-757",
            "what_happened": "An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be transmitted in a less-protected form, potentially allowing that credential to be recovered. If recovered, the credential could be used to authenticate as the internal superuser to nodes in the deployment.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-130264"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:22.903",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18691"
                }
            ]
        },
        {
            "id": "CVE-2026-18690",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and recreated without proper authorization.",
            "updated_at": "2026-09-16T15:14:48.000",
            "published_at": "2026-08-11T19:17:22.757",
            "cvss": 7.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and recreated without proper authorization.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-130481"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:22.757",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18690"
                }
            ]
        },
        {
            "id": "CVE-2026-18688",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in a server crash (denial of service) and may potentially expose a limited amount of memory contents.",
            "updated_at": "2026-09-16T15:14:18.697",
            "published_at": "2026-08-11T19:17:22.620",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver); 7.0 through before 7.0.40 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in a server crash (denial of service) and may potentially expose a limited amount of memory contents.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-129617"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:22.620",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18688"
                }
            ]
        },
        {
            "id": "CVE-2026-18687",
            "vendor": "MongoDB",
            "product": "MongoDB Server",
            "title": "MongoDB Server vulnerability",
            "summary": "MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.",
            "updated_at": "2026-09-16T15:14:07.103",
            "published_at": "2026-08-11T19:17:22.467",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.3.0 through before 8.3.8 (semver); 8.0 through before 8.0.29 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-191",
            "what_happened": "MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or excessive internal writes, resulting in resource exhaustion and corruption of encrypted index data.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jira.mongodb.org/browse/SERVER-130628"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T19:17:22.467",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18687"
                }
            ]
        },
        {
            "id": "CVE-2026-18579",
            "vendor": "opajaap",
            "product": "WP Photo Album Plus",
            "title": "WP Photo Album Plus vulnerability",
            "summary": "The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce failure path for the getshortcodedrenderedfenodelay action serves as the log-write trigger rather than an access barrier — a deliberately failed nonce check causes wppa_log() to record the attacker-supplied X-Forwarded-For value to disk, making the exploit fully reachable by unauthenticated callers via the wp_ajax_nopriv_wppa endpoint.",
            "updated_at": "2026-09-11T04:17:24.600",
            "published_at": "2026-09-11T04:17:24.600",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 9.2.08.003 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce failure path for the getshortcodedrenderedfenodelay action serves as the log-write trigger rather than an access barrier — a deliberately failed nonce check causes wppa_log() to record the attacker-supplied X-Forwarded-For value to disk, making the exploit fully reachable by unauthenticated callers via the wp_ajax_nopriv_wppa endpoint.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.07.002/js/wppa-admin-scripts.js#L2069",
                "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.07.002/wppa-ajax.php#L1246",
                "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.07.002/wppa-input.php#L560",
                "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.07.002/wppa-utils.php#L1960",
                "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.08.003/js/wppa-admin-scripts.js#L2069",
                "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.08.003/wppa-ajax.php#L1246",
                "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.08.003/wppa-input.php#L560",
                "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.08.003/wppa-utils.php#L1960",
                "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3641521%40wp-photo-album-plus%2Ftrunk%2Fjs%2Fwppa-admin-scripts.js&old=3625666%40wp-photo-album-plus%2Ftrunk%2Fjs%2Fwppa-admin-scripts.js&sfp_email=&sfph_mail=",
                "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3641521%40wp-photo-album-plus%2Ftrunk%2Fwppa-input.php&old=3619969%40wp-photo-album-plus%2Ftrunk%2Fwppa-input.php&sfp_email=&sfph_mail=",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/251943ed-65d2-4635-9c84-2cf671233543?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T04:17:24.600",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18579"
                }
            ]
        },
        {
            "id": "CVE-2026-18577",
            "vendor": "N-able",
            "product": "N-central",
            "title": "N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
            "summary": "N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.",
            "updated_at": "2026-08-02T22:00:00Z",
            "published_at": "2026-08-02T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-02T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-18573",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due to improper evaluation of the client state during an update operation, an attacker with client management permissions can bypass these security policies by first creating a public client and then updating it to a confidential client with weaker authentication. This can result in the persistence of clients that do not comply with the intended security hardening of the realm.",
            "updated_at": "2026-09-16T19:17:09.923",
            "published_at": "2026-08-02T06:16:42.673",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due to improper evaluation of the client state during an update operation, an attacker with client management permissions can bypass these security policies by first creating a public client and then updating it to a confidential client with weaker authentication. This can result in the persistence of clients that do not comply with the intended security hardening of the realm.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-18573",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2509764"
            ],
            "timeline": [
                {
                    "at": "2026-08-02T06:16:42.673",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18573"
                }
            ]
        },
        {
            "id": "CVE-2026-18572",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.",
            "updated_at": "2026-09-16T19:17:09.783",
            "published_at": "2026-08-02T06:16:42.290",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request that overrides the actual server time. This allows the user to bypass these time-based restrictions and access protected resources at unauthorized times.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-18572",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2509763"
            ],
            "timeline": [
                {
                    "at": "2026-08-02T06:16:42.290",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18572"
                }
            ]
        },
        {
            "id": "CVE-2026-18571",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.",
            "updated_at": "2026-09-16T19:17:09.640",
            "published_at": "2026-08-02T06:16:42.000",
            "cvss": 6.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-862",
            "what_happened": "A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-18571",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2509759"
            ],
            "timeline": [
                {
                    "at": "2026-08-02T06:16:42.000",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18571"
                }
            ]
        },
        {
            "id": "CVE-2026-18570",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it is explicitly provided in a request. By omitting this field, a delegated user can bypass the policy, resulting in a client created with full scope access. This allows the client to obtain tokens with unauthorized role mappings.",
            "updated_at": "2026-09-16T19:17:09.490",
            "published_at": "2026-08-02T06:16:41.230",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the executor only validates the fullScopeAllowed field when it is explicitly provided in a request. By omitting this field, a delegated user can bypass the policy, resulting in a client created with full scope access. This allows the client to obtain tokens with unauthorized role mappings.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-18570",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2509756"
            ],
            "timeline": [
                {
                    "at": "2026-08-02T06:16:41.230",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18570"
                }
            ]
        },
        {
            "id": "CVE-2026-18562",
            "vendor": "realmag777",
            "product": "HUSKY – Products Filter for WooCommerce Professional",
            "title": "HUSKY – Products Filter for WooCommerce Professional vulnerability",
            "summary": "The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3. This is due to insufficient input sanitization and output escaping in the wp_load_js() function, which reads filter values from the URL path via the url_request extension's parse_url_query() and embeds them into an inline JavaScript string using json_encode() without escaping single quotes. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.",
            "updated_at": "2026-09-11T04:17:24.457",
            "published_at": "2026-09-11T04:17:24.457",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.4.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3. This is due to insufficient input sanitization and output escaping in the wp_load_js() function, which reads filter values from the URL path via the url_request extension's parse_url_query() and embeds them into an inline JavaScript string using json_encode() without escaping single quotes. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/woocommerce-products-filter/tags/1.4.1/ext/url_request/classes/url_parser.php#L462",
                "https://plugins.trac.wordpress.org/browser/woocommerce-products-filter/tags/1.4.1/ext/url_request/classes/url_parser.php#L478",
                "https://plugins.trac.wordpress.org/browser/woocommerce-products-filter/tags/1.4.1/ext/url_request/classes/url_parser.php#L492",
                "https://plugins.trac.wordpress.org/browser/woocommerce-products-filter/tags/1.4.1/index.php#L1116",
                "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3640571%40woocommerce-products-filter%2Ftrunk&old=3637824%40woocommerce-products-filter%2Ftrunk&sfp_email=&sfph_mail=",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/dca6bd12-5adf-48fa-b24f-198f13250080?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T04:17:24.457",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18562"
                }
            ]
        },
        {
            "id": "CVE-2026-18561",
            "vendor": "unitecms",
            "product": "Unlimited Elements For Elementor",
            "title": "Unlimited Elements For Elementor vulnerability",
            "summary": "The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query in the getWhereString() function; when the parameter is supplied as an array, element zero is used verbatim as the SQL comparison operator and concatenated into the WHERE clause without sanitization, while normalizeAjaxInputData() strips WordPress's magic_quotes protection from the value. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
            "updated_at": "2026-09-11T04:17:20.480",
            "published_at": "2026-09-11T04:17:20.480",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.0.16 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query in the getWhereString() function; when the parameter is supplied as an array, element zero is used verbatim as the SQL comparison operator and concatenated into the WHERE clause without sanitization, while normalizeAjaxInputData() strips WordPress's magic_quotes protection from the value. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/framework/db.class.php#L216",
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_actions.class.php#L87",
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_addon.class.php#L304",
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_addons.class.php#L1387",
                "https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/trunk/provider/provider_functions.class.php#L611",
                "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3661670%40unlimited-elements-for-elementor%2Ftrunk&old=3628543%40unlimited-elements-for-elementor%2Ftrunk&sfp_email=&sfph_mail=",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/969d605d-e093-447c-abf7-0d56cb3ac569?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T04:17:20.480",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18561"
                }
            ]
        },
        {
            "id": "CVE-2026-18556",
            "vendor": "N-able",
            "product": "N-central",
            "title": "N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
            "summary": "N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.",
            "updated_at": "2026-08-03T22:00:00Z",
            "published_at": "2026-08-03T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-18508",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.",
            "updated_at": "2026-09-10T18:17:57.193",
            "published_at": "2026-08-03T16:16:28.387",
            "cvss": 4.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-59",
            "what_happened": "A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:50807",
                "https://access.redhat.com/errata/RHSA-2026:61581",
                "https://access.redhat.com/errata/RHSA-2026:61586",
                "https://access.redhat.com/errata/RHSA-2026:61783",
                "https://access.redhat.com/errata/RHSA-2026:66018",
                "https://access.redhat.com/security/cve/CVE-2026-18508",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2509843"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T16:16:28.387",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18508"
                }
            ]
        },
        {
            "id": "CVE-2026-18489",
            "vendor": "IBM",
            "product": "ContextForge MCP Gateway - Translate utility",
            "title": "ContextForge MCP Gateway - Translate utility vulnerability",
            "summary": "IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.",
            "updated_at": "2026-09-15T15:04:09.813",
            "published_at": "2026-09-04T17:16:56.550",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "<= 1.0.8",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-488",
            "what_happened": "IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposure of data elements to the wrong session.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286056"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T17:16:56.550",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18489"
                }
            ]
        },
        {
            "id": "CVE-2026-18486",
            "vendor": "IBM",
            "product": "ContextForge MCP Gateway",
            "title": "ContextForge MCP Gateway vulnerability",
            "summary": "IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.",
            "updated_at": "2026-09-15T15:05:06.320",
            "published_at": "2026-09-04T17:16:56.420",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "<= v1.0.7",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper validation of jq filters.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286052"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T17:16:56.420",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18486"
                }
            ]
        },
        {
            "id": "CVE-2026-18480",
            "vendor": "Unknown",
            "product": "SureCart",
            "title": "SureCart vulnerability",
            "summary": "The SureCart  WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone.",
            "updated_at": "2026-09-06T11:18:00.657",
            "published_at": "2026-09-06T07:16:43.097",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.6.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "The SureCart  WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses to any authenticated user, which together make the takeover reachable from a subscriber-level account alone.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/88839ada-9c59-44cb-96e6-3548e5a59b9f/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T07:16:43.097",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18480"
                }
            ]
        },
        {
            "id": "CVE-2026-18477",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.",
            "updated_at": "2026-09-10T18:17:56.970",
            "published_at": "2026-08-03T17:16:33.897",
            "cvss": 4.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-367",
            "what_happened": "A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:49361",
                "https://access.redhat.com/errata/RHSA-2026:61581",
                "https://access.redhat.com/errata/RHSA-2026:61586",
                "https://access.redhat.com/errata/RHSA-2026:61783",
                "https://access.redhat.com/errata/RHSA-2026:66018",
                "https://access.redhat.com/security/cve/CVE-2026-18477",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2509735"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T17:16:33.897",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18477"
                }
            ]
        },
        {
            "id": "CVE-2026-18453",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
            "title": "Red Hat Enterprise Linux 7 Extended Lifecycle Support vulnerability",
            "summary": "A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.",
            "updated_at": "2026-09-08T03:17:18.287",
            "published_at": "2026-09-07T15:17:31.017",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:64771",
                "https://access.redhat.com/security/cve/CVE-2026-18453",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2509696"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T15:17:31.017",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18453"
                }
            ]
        },
        {
            "id": "CVE-2026-18406",
            "vendor": "brainstormforce",
            "product": "SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz",
            "title": "SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz vulnerability",
            "summary": "The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
            "updated_at": "2026-09-05T07:17:11.040",
            "published_at": "2026-09-05T07:17:11.040",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.12.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/assets/build/entries.js#L172",
                "https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/inc/form-submit.php#L1451",
                "https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/inc/form-submit.php#L229",
                "https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/inc/form-submit.php#L93",
                "https://plugins.trac.wordpress.org/browser/sureforms/tags/2.12.2/inc/helper.php#L241",
                "https://plugins.trac.wordpress.org/changeset/3635980/sureforms/trunk/inc/form-submit.php",
                "https://plugins.trac.wordpress.org/changeset?old_path=%2Fsureforms/tags/2.12.2&new_path=%2Fsureforms/tags/2.12.3",
                "https://plugins.trac.wordpress.org/changeset?reponame=&new=3636000%40sureforms%2Ftags%2F2.12.3&old=3618798%40sureforms%2Ftags%2F2.12.2",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/8583c1f2-0820-492c-9fa1-d96e0ce2ddf2?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:11.040",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18406"
                }
            ]
        },
        {
            "id": "CVE-2026-18404",
            "vendor": "quadlayers",
            "product": "Social Chat – Click To Chat App Button",
            "title": "Social Chat – Click To Chat App Button vulnerability",
            "summary": "The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit requires no user interaction beyond page load, as setting auto_open and consent_enabled to 'yes' in the injected data-box JSON causes the consent box — and the embedded script — to execute immediately on page load.",
            "updated_at": "2026-09-05T06:17:09.577",
            "published_at": "2026-09-05T06:17:09.577",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 8.6.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit requires no user interaction beyond page load, as setting auto_open and consent_enabled to 'yes' in the injected data-box JSON causes the consent box — and the embedded script — to execute immediately on page load.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/wp-whatsapp-chat/tags/8.5.1/build/frontend/js/index.js#L2",
                "https://plugins.trac.wordpress.org/browser/wp-whatsapp-chat/tags/8.5.1/lib/controllers/class-frontend.php#L86",
                "https://plugins.trac.wordpress.org/browser/wp-whatsapp-chat/tags/8.6.1/build/frontend/js/index.js#L2",
                "https://plugins.trac.wordpress.org/browser/wp-whatsapp-chat/tags/8.6.1/lib/controllers/class-frontend.php#L86",
                "https://plugins.trac.wordpress.org/changeset?old_path=%2Fwp-whatsapp-chat/tags/8.6.2&new_path=%2Fwp-whatsapp-chat/tags/8.6.3",
                "https://plugins.trac.wordpress.org/changeset?reponame=&new=3667778%40wp-whatsapp-chat%2Ftags%2F8.6.3&old=3664149%40wp-whatsapp-chat%2Ftags%2F8.6.2",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/f159392b-5bc6-4c12-a924-13ea170bb7fa?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T06:17:09.577",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18404"
                }
            ]
        },
        {
            "id": "CVE-2026-18369",
            "vendor": "Red Hat",
            "product": "Red Hat Certificate System 10.4 EUS for RHEL-8",
            "title": "Red Hat Certificate System 10.4 EUS for RHEL-8 vulnerability",
            "summary": "A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker through the ACME challenge error.",
            "updated_at": "2026-09-14T06:16:57.240",
            "published_at": "2026-07-30T11:16:26.973",
            "cvss": 5.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns identifiers and follows HTTP redirects without validating that the target is a public address. An unauthenticated ACME account holder can exploit this to perform server-side request forgery (SSRF), making the Dogtag server send HTTP GET requests to internal network services. With the InMemory database backend, the response body of internal targets is disclosed to the attacker through the ACME challenge error.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:67110",
                "https://access.redhat.com/security/cve/CVE-2026-18369",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2509234"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T11:16:26.973",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18369"
                }
            ]
        },
        {
            "id": "CVE-2026-18366",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator",
            "summary": "Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator",
            "updated_at": "2026-09-04T22:00:00Z",
            "published_at": "2026-09-04T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 127,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · Nxploited/CVE-2026-18366",
                    "author": "Nxploited",
                    "first_seen": "2026-08-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator",
                    "summary": "Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator",
                    "url": "https://github.com/Nxploited/CVE-2026-18366"
                },
                {
                    "repository": "PoC-in-GitHub · ghostpels/CVE-2026-18366",
                    "author": "ghostpels",
                    "first_seen": "2026-08-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-18366: Events Manager < 7.4.1 — Unauthenticated Privilege Escalation to Administrator. Write-up and proof-of-concept (poc.py).",
                    "summary": "CVE-2026-18366: Events Manager < 7.4.1 — Unauthenticated Privilege Escalation to Administrator. Write-up and proof-of-concept (poc.py).",
                    "url": "https://github.com/ghostpels/CVE-2026-18366"
                },
                {
                    "repository": "PoC-in-GitHub · katranSefa/CVE-2026-18366",
                    "author": "katranSefa",
                    "first_seen": "2026-09-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-18366 repository",
                    "summary": "",
                    "url": "https://github.com/katranSefa/CVE-2026-18366"
                }
            ],
            "references": [
                "https://github.com/Nxploited/CVE-2026-18366",
                "https://github.com/ghostpels/CVE-2026-18366",
                "https://github.com/katranSefa/CVE-2026-18366"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/Nxploited/CVE-2026-18366"
                }
            ]
        },
        {
            "id": "CVE-2026-18355",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
            "title": "Red Hat Enterprise Linux 7 Extended Lifecycle Support vulnerability",
            "summary": "A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow.",
            "updated_at": "2026-09-08T03:17:18.177",
            "published_at": "2026-09-07T15:17:30.867",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-191",
            "what_happened": "A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:64771",
                "https://access.redhat.com/security/cve/CVE-2026-18355",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2509186"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T15:17:30.867",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18355"
                }
            ]
        },
        {
            "id": "CVE-2026-18313",
            "vendor": "The Tcpdump Group",
            "product": "libpcap",
            "title": "libpcap vulnerability",
            "summary": "rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use.  A malicious client can cause the server to leak memory substantially faster.",
            "updated_at": "2026-09-05T19:16:55.590",
            "published_at": "2026-09-05T19:16:55.590",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.9.x; 1.10.x through before 1.10.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-401",
            "what_happened": "rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use.  A malicious client can cause the server to leak memory substantially faster.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T19:16:55.590",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18313"
                }
            ]
        },
        {
            "id": "CVE-2026-18255",
            "vendor": "Red Hat",
            "product": "Red Hat Quay 3.10",
            "title": "Red Hat Quay 3.10 vulnerability",
            "summary": "A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.",
            "updated_at": "2026-09-10T22:16:55.223",
            "published_at": "2026-07-29T17:16:51.393",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a member of, allowing an attacker with read-only superuser privileges to impersonate any robot account.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:63307",
                "https://access.redhat.com/errata/RHSA-2026:65514",
                "https://access.redhat.com/errata/RHSA-2026:66084",
                "https://access.redhat.com/security/cve/CVE-2026-18255",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2508454",
                "https://access.redhat.com/errata/RHSA-2026:66523"
            ],
            "timeline": [
                {
                    "at": "2026-07-29T17:16:51.393",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18255"
                }
            ]
        },
        {
            "id": "CVE-2026-18238",
            "vendor": "The Tcpdump Group",
            "product": "libpcap",
            "title": "libpcap vulnerability",
            "summary": "The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers.  A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.",
            "updated_at": "2026-09-05T19:16:55.477",
            "published_at": "2026-09-05T19:16:55.477",
            "cvss": 5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.8.x; 1.9.x; 1.10.x through before 1.10.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-126",
            "what_happened": "The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers.  A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T19:16:55.477",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18238"
                }
            ]
        },
        {
            "id": "CVE-2026-18218",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a \"not-before\" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This issue can allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them.\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━",
            "updated_at": "2026-09-16T19:17:09.340",
            "published_at": "2026-07-31T08:16:28.177",
            "cvss": 4.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-862",
            "what_happened": "A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a \"not-before\" policy, the revocation may be silently ignored if the overall security realm already has an older, non-zero revocation policy in place. This issue can allow previously issued tokens to remain valid for refreshing sessions and accessing user information even after an administrator has attempted to invalidate them.\n━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-18218",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2508313"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T08:16:28.177",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18218"
                }
            ]
        },
        {
            "id": "CVE-2026-18215",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token from a completely different organization could gain access to the Keycloak realm, potentially accessing sensitive data or performing unauthorized actions.",
            "updated_at": "2026-09-16T19:17:09.193",
            "published_at": "2026-07-31T08:16:27.893",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-287",
            "what_happened": "Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token from a completely different organization could gain access to the Keycloak realm, potentially accessing sensitive data or performing unauthorized actions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-18215",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2508309"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T08:16:27.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18215"
                }
            ]
        },
        {
            "id": "CVE-2026-18214",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain restrictions. This means an attacker with a valid Google account from a different domain could bypass the security check and gain access to the Keycloak realm.",
            "updated_at": "2026-09-16T19:17:09.047",
            "published_at": "2026-07-31T08:16:27.753",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-862",
            "what_happened": "Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain restrictions. This means an attacker with a valid Google account from a different domain could bypass the security check and gain access to the Keycloak realm.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-18214",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2508308"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T08:16:27.753",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18214"
                }
            ]
        },
        {
            "id": "CVE-2026-18209",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is configured with a wildcard redirect URI, an attacker can use this to inject duplicate security parameters into the login response. If a client application is not configured correctly, it might trust the attacker's injected data instead of the real security information from Keycloak, leading to session fixation or account confusion.",
            "updated_at": "2026-09-16T19:17:08.720",
            "published_at": "2026-07-31T08:16:27.467",
            "cvss": 3.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-1288",
            "what_happened": "A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a redirect URL and ignores the fragment portion. When a client is configured with a wildcard redirect URI, an attacker can use this to inject duplicate security parameters into the login response. If a client application is not configured correctly, it might trust the attacker's injected data instead of the real security information from Keycloak, leading to session fixation or account confusion.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-18209",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2508305"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T08:16:27.467",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18209"
                }
            ]
        },
        {
            "id": "CVE-2026-18201",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.",
            "updated_at": "2026-09-16T19:17:08.577",
            "published_at": "2026-07-29T10:16:40.620",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Keycloak provides a way to manage identity providers and organizations through its administrative API. A flaw was discovered where an administrator with permission to manage identity providers could link a new provider to an organization without having the required permissions to manage that organization. This could allow an unauthorized administrator to influence how users log into specific organizations.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-18201",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2508290"
            ],
            "timeline": [
                {
                    "at": "2026-07-29T10:16:40.620",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18201"
                }
            ]
        },
        {
            "id": "CVE-2026-18056",
            "vendor": "hivepress",
            "product": "HivePress Authentication",
            "title": "HivePress Authentication vulnerability",
            "summary": "The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to the Facebook Graph API and trusting the returned email and ID verbatim, without performing any application ID or audience validation — specifically, no /debug_token verification and no comparison of the token's app_id against the configured hp_facebook_app_id. This makes it possible for unauthenticated attackers to authenticate as any existing WordPress user, including administrators, whose email address is associated with a Facebook account for which the attacker can obtain any valid access token. Important Note: To exploit the vulnerability, the attacker must obtain the victim's access token.",
            "updated_at": "2026-09-06T03:17:16.467",
            "published_at": "2026-09-06T03:17:16.467",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.1.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-287",
            "what_happened": "The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to the Facebook Graph API and trusting the returned email and ID verbatim, without performing any application ID or audience validation — specifically, no /debug_token verification and no comparison of the token's app_id against the configured hp_facebook_app_id. This makes it possible for unauthenticated attackers to authenticate as any existing WordPress user, including administrators, whose email address is associated with a Facebook account for which the attacker can obtain any valid access token. Important Note: To exploit the vulnerability, the attacker must obtain the victim's access token.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://developers.facebook.com/docs/facebook-login/guides/advanced/manual-flow/#confirm",
                "https://github.com/hivepress/hivepress-authentication/commit/f97d9109002905cf57597d15c535d1155dc64657",
                "https://plugins.trac.wordpress.org/browser/hivepress-authentication/tags/1.1.4/includes/components/class-facebook-authentication.php#L59",
                "https://plugins.trac.wordpress.org/browser/hivepress-authentication/tags/1.1.4/includes/controllers/class-authentication.php#L84",
                "https://plugins.trac.wordpress.org/changeset/3664231/hivepress-authentication",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/c0ba6392-e6f7-479a-8b9b-9cea4b140c71?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T03:17:16.467",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-18056"
                }
            ]
        },
        {
            "id": "CVE-2026-17585",
            "vendor": "wproyal",
            "product": "Royal Addons for Elementor – Addons and Templates Kit for Elementor",
            "title": "Royal Addons for Elementor – Addons and Templates Kit for Elementor vulnerability",
            "summary": "The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all published posts via character-by-character substring matching across the entire wp_postmeta table. The required nonce is emitted publicly via wp_localize_script on any frontend page that loads a Royal Elementor widget, meaning no authenticated session or prior action is needed to obtain it.",
            "updated_at": "2026-09-12T08:16:23.950",
            "published_at": "2026-09-12T08:16:23.950",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.7.1066 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1066 via the 'wpr_keyword' parameter. This makes it possible for unauthenticated attackers to extract arbitrary postmeta values from all published posts via character-by-character substring matching across the entire wp_postmeta table. The required nonce is emitted publicly via wp_localize_script on any frontend page that loads a Royal Elementor widget, meaning no authenticated session or prior action is needed to obtain it.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1061/classes/modules/wpr-ajax-search.php#L115",
                "https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1061/classes/modules/wpr-ajax-search.php#L155",
                "https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1061/classes/modules/wpr-ajax-search.php#L23",
                "https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1061/plugin.php#L655",
                "https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1064/classes/modules/wpr-ajax-search.php#L115",
                "https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1064/classes/modules/wpr-ajax-search.php#L155",
                "https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1064/classes/modules/wpr-ajax-search.php#L23",
                "https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.7.1064/plugin.php#L655",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/5eab79e6-cb47-4fe7-993a-e833bd6689f8?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T08:16:23.950",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17585"
                }
            ]
        },
        {
            "id": "CVE-2026-17543",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout",
            "summary": "Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.",
            "updated_at": "2026-08-26T11:32:38Z",
            "published_at": "2026-08-26T11:32:38Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 193,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · Hunt-Benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout",
                    "author": "Hunt-Benito",
                    "first_seen": "2026-08-06",
                    "last_seen": "2026-08-26T11:32:38Z",
                    "pushed_at": "2026-08-06T17:08:12Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Injection",
                    "language": "PHP",
                    "stars": 1,
                    "forks": 1,
                    "topics": [],
                    "title": "e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Hunt-Benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout"
                },
                {
                    "repository": "CVE-Intel · pratham220/CVE-2026-17543-PHP-Exposure-Validator",
                    "author": "pratham220",
                    "first_seen": "2026-08-04",
                    "last_seen": "2026-08-11T13:38:52Z",
                    "pushed_at": "2026-08-06T07:49:29Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "PowerShell",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.",
                    "repository_description": "Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.",
                    "summary": "Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/pratham220/CVE-2026-17543-PHP-Exposure-Validator"
                }
            ],
            "references": [
                "https://github.com/Hunt-Benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout",
                "https://github.com/pratham220/CVE-2026-17543-PHP-Exposure-Validator"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T11:32:38Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/Hunt-Benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout"
                }
            ]
        },
        {
            "id": "CVE-2026-17527",
            "vendor": "Red Hat",
            "product": "Red Hat Container Native Virtualization 4.14",
            "title": "Red Hat Container Native Virtualization 4.14 vulnerability",
            "summary": "In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC the caller can name, without requiring write access to the source namespace. A user or service account bound to the view role, commonly granted cluster-wide via ClusterRoleBinding, who also has ordinary write access (edit/admin) to any single namespace, can use this to exfiltrate the contents of any PVC in the cluster into a namespace they control, bypassing namespace isolation and the read-only guarantee of the view role.",
            "updated_at": "2026-09-08T17:17:33.263",
            "published_at": "2026-07-27T10:16:37.617",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the contents of any PVC the caller can name, without requiring write access to the source namespace. A user or service account bound to the view role, commonly granted cluster-wide via ClusterRoleBinding, who also has ordinary write access (edit/admin) to any single namespace, can use this to exfiltrate the contents of any PVC in the cluster into a namespace they control, bypassing namespace isolation and the read-only guarantee of the view role.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:59062",
                "https://access.redhat.com/errata/RHSA-2026:59083",
                "https://access.redhat.com/errata/RHSA-2026:59109",
                "https://access.redhat.com/errata/RHSA-2026:60117",
                "https://access.redhat.com/errata/RHSA-2026:60301",
                "https://access.redhat.com/errata/RHSA-2026:61666",
                "https://access.redhat.com/errata/RHSA-2026:62599",
                "https://access.redhat.com/security/cve/CVE-2026-17527",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2507413"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T10:16:37.617",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17527"
                }
            ]
        },
        {
            "id": "CVE-2026-17523",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet\n\nThis patch switches the timer to HRTIMER_MODE_SOFT, which executed the\ntimer callback in softirq context and removes the hrtimer_tasklet.",
            "updated_at": "2026-09-10T14:17:00.323",
            "published_at": "2026-07-27T10:16:36.270",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c53a6ee88b0a91bd012ef1b7988c0b93dae6f24d through before 79305a826f872fe446c6fbf8450f515053ef6951 (git); c53a6ee88b0a91bd012ef1b7988c0b93dae6f24d through before bf74aa86e111aa3b2fbb25db37e3a3fab71b5b68 (git); 2.6.29",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: switch timer to HRTIMER_MODE_SOFT and remove hrtimer_tasklet\n\nThis patch switches the timer to HRTIMER_MODE_SOFT, which executed the\ntimer callback in softirq context and removes the hrtimer_tasklet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/79305a826f872fe446c6fbf8450f515053ef6951",
                "https://git.kernel.org/stable/c/bf74aa86e111aa3b2fbb25db37e3a3fab71b5b68"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T10:16:36.270",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17523"
                }
            ]
        },
        {
            "id": "CVE-2026-17416",
            "vendor": "IBM",
            "product": "App Connect Enterprise",
            "title": "App Connect Enterprise vulnerability",
            "summary": "IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.",
            "updated_at": "2026-09-15T04:18:01.457",
            "published_at": "2026-09-14T20:16:41.733",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "13.0.1.0 through 13.0.8.0 (semver); 12.0.1.0 through 12.0.12.27 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286530"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T20:16:41.733",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17416"
                }
            ]
        },
        {
            "id": "CVE-2026-17156",
            "vendor": "IBM",
            "product": "App Connect Enterprise",
            "title": "App Connect Enterprise vulnerability",
            "summary": "IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.",
            "updated_at": "2026-09-15T04:18:00.813",
            "published_at": "2026-09-14T20:16:41.593",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "13.0.1.0 through 13.0.8.0 (semver); 12.0.1.0 through 12.0.12.27 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286530"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T20:16:41.593",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17156"
                }
            ]
        },
        {
            "id": "CVE-2026-17133",
            "vendor": "IBM",
            "product": "App Connect Enterprise",
            "title": "App Connect Enterprise vulnerability",
            "summary": "IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.",
            "updated_at": "2026-09-15T04:17:59.780",
            "published_at": "2026-09-14T20:16:41.460",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "13.0.1.0 through 13.0.8.0 (semver); 12.0.1.0 through 12.0.12.27 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286530"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T20:16:41.460",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17133"
                }
            ]
        },
        {
            "id": "CVE-2026-17107",
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1",
            "title": "multicluster engine for Kubernetes 2.1 vulnerability",
            "summary": "A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.",
            "updated_at": "2026-09-07T19:17:26.363",
            "published_at": "2026-07-24T19:16:55.907",
            "cvss": 8.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-441",
            "what_happened": "A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:47388",
                "https://access.redhat.com/errata/RHSA-2026:47735",
                "https://access.redhat.com/errata/RHSA-2026:47949",
                "https://access.redhat.com/errata/RHSA-2026:47953",
                "https://access.redhat.com/errata/RHSA-2026:47974",
                "https://access.redhat.com/errata/RHSA-2026:48284",
                "https://access.redhat.com/security/cve/CVE-2026-17107",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2506771"
            ],
            "timeline": [
                {
                    "at": "2026-07-24T19:16:55.907",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17107"
                }
            ]
        },
        {
            "id": "CVE-2026-17106",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp",
            "summary": "PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp",
            "updated_at": "2026-08-26T08:01:44Z",
            "published_at": "2026-08-26T08:01:44Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 283,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · masasron/CopyEscape-CVE-2026-17106",
                    "author": "masasron",
                    "first_seen": "2026-08-09",
                    "last_seen": "2026-08-26T08:01:44Z",
                    "pushed_at": "2026-08-09T21:04:41Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "C",
                    "stars": 21,
                    "forks": 4,
                    "topics": [],
                    "title": "PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp",
                    "repository_description": "PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp",
                    "summary": "PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp",
                    "source": "CVE-Intel",
                    "url": "https://github.com/masasron/CopyEscape-CVE-2026-17106"
                },
                {
                    "repository": "CVE-Intel · 686f6c61/POC-CopyEscape-CVE-2026-17106",
                    "author": "686f6c61",
                    "first_seen": "2026-08-12",
                    "last_seen": "2026-08-14T16:06:55Z",
                    "pushed_at": "2026-08-12T16:41:56Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "C",
                    "stars": 1,
                    "forks": 0,
                    "topics": [
                        "container-escape",
                        "cve",
                        "cve-2026-17106",
                        "docker",
                        "docker-security",
                        "exploit",
                        "inotify",
                        "ld-preload"
                    ],
                    "title": "PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker + monitor inotify + LD_PRELOAD. Variante macOS inocua y Linux destructiva.",
                    "repository_description": "PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker + monitor inotify + LD_PRELOAD. Variante macOS inocua y Linux destructiva.",
                    "summary": "PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker + monitor inotify + LD_PRELOAD. Variante macOS inocua y Linux destructiva.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/686f6c61/POC-CopyEscape-CVE-2026-17106"
                },
                {
                    "repository": "CVE-Intel · HackSpeak/CVE-2026-17106",
                    "author": "HackSpeak",
                    "first_seen": "2026-08-11",
                    "last_seen": "2026-08-12T10:41:42Z",
                    "pushed_at": "2026-08-11T11:35:07Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "C",
                    "stars": 1,
                    "forks": 0,
                    "topics": [],
                    "title": "CopyEscape (CVE-2026-17106) docker cp container-to-host arbitrary file write PoC mirror — Imperva Ron Masas, MIT; for authorized security testing",
                    "repository_description": "CopyEscape (CVE-2026-17106) docker cp container-to-host arbitrary file write PoC mirror — Imperva Ron Masas, MIT; for authorized security testing",
                    "summary": "CopyEscape (CVE-2026-17106) docker cp container-to-host arbitrary file write PoC mirror — Imperva Ron Masas, MIT; for authorized security testing",
                    "source": "CVE-Intel",
                    "url": "https://github.com/HackSpeak/CVE-2026-17106"
                }
            ],
            "references": [
                "https://github.com/masasron/CopyEscape-CVE-2026-17106",
                "https://github.com/686f6c61/POC-CopyEscape-CVE-2026-17106",
                "https://github.com/HackSpeak/CVE-2026-17106"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T08:01:44Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/masasron/CopyEscape-CVE-2026-17106"
                }
            ]
        },
        {
            "id": "CVE-2026-17059",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users they should not be able to access.",
            "updated_at": "2026-09-16T19:17:08.080",
            "published_at": "2026-07-24T15:17:13.300",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. The issue occurs because the system fails to check if an administrator has permission to view individual users when listing members of a role. This allows a restricted administrator to see private information, such as names and email addresses, for users they should not be able to access.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-17059",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2506746"
            ],
            "timeline": [
                {
                    "at": "2026-07-24T15:17:13.300",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-17059"
                }
            ]
        },
        {
            "id": "CVE-2026-16876",
            "vendor": "NEC Corporation",
            "product": "UNIVERGE IX-R/IX-V",
            "title": "UNIVERGE IX-R/IX-V vulnerability",
            "summary": "An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.",
            "updated_at": "2026-09-07T02:17:17.630",
            "published_at": "2026-09-07T02:17:17.630",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "All versions from Ver1.1 through Ver1.3, All versions from Ver1.4.21 through Ver1.4.28 and Ver1.5.23",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://jpn.nec.com/security-info/secinfo/nv26-005_en.html"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T02:17:17.630",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16876"
                }
            ]
        },
        {
            "id": "CVE-2026-16812",
            "vendor": "Arista",
            "product": "VeloCloud Orchestrator",
            "title": "Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability",
            "summary": "Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.",
            "updated_at": "2026-07-26T22:00:00Z",
            "published_at": "2026-07-26T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-07-26T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-16772",
            "vendor": "Akaunting",
            "product": "Akaunting",
            "title": "Akaunting vulnerability",
            "summary": "In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the `UpdateUser` job, which processes user-supplied role assignments via an unconditional `roles()->sync()` call without verifying whether the caller is authorized to manage roles. Users only require the default `update-auth-profile` permission to access the self-update path and assign themselves as admins. The API endpoints are properly permission‑gated and are not affected by this issue. This vulnerability has been remediated in v3.2.0, commit 80ef6d3b154a.",
            "updated_at": "2026-09-14T22:16:57.260",
            "published_at": "2026-08-14T16:16:50.290",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.1.21 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting full administrator privileges. This vulnerability is caused by a flaw in the `UpdateUser` job, which processes user-supplied role assignments via an unconditional `roles()->sync()` call without verifying whether the caller is authorized to manage roles. Users only require the default `update-auth-profile` permission to access the self-update path and assign themselves as admins. The API endpoints are properly permission‑gated and are not affected by this issue. This vulnerability has been remediated in v3.2.0, commit 80ef6d3b154a.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://vokecyber.com/research/cve-2026-16772-akaunting-privilege-escalation"
            ],
            "timeline": [
                {
                    "at": "2026-08-14T16:16:50.290",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16772"
                }
            ]
        },
        {
            "id": "CVE-2026-16730",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.",
            "updated_at": "2026-09-10T18:17:56.807",
            "published_at": "2026-07-24T12:16:47.717",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-755",
            "what_happened": "A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the dbus proxy.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:61340",
                "https://access.redhat.com/errata/RHSA-2026:61355",
                "https://access.redhat.com/errata/RHSA-2026:66018",
                "https://access.redhat.com/security/cve/CVE-2026-16730",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2506348",
                "https://github.com/bus1/dbus-broker/issues/435"
            ],
            "timeline": [
                {
                    "at": "2026-07-24T12:16:47.717",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16730"
                }
            ]
        },
        {
            "id": "CVE-2026-16726",
            "vendor": "panasonic",
            "product": "PANATERM v6",
            "title": "PANATERM v6 vulnerability",
            "summary": "Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows \nattackers  to stop Windows.",
            "updated_at": "2026-09-14T06:16:57.090",
            "published_at": "2026-09-14T06:16:57.090",
            "cvss": 6.8,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a through 6.0.13.0 (custom); n/a through 6.2.3.1 (custom); n/a through 7.5.0.0 (custom); n/a through 15.0.0.591 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows \nattackers  to stop Windows.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://industry.panasonic.com/global/en/products/motor/fa-motor/ac-servo/ptusbdrva5"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T06:16:57.090",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16726"
                }
            ]
        },
        {
            "id": "CVE-2026-16649",
            "vendor": "Gravity Forms",
            "product": "Gravity Forms",
            "title": "Gravity Forms vulnerability",
            "summary": "The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit survives save-time sanitization because wp_kses_post allows the required HTML tags and attributes, and the client-side tooltip script re-parses the browser-decoded aria-label value as innerHTML while only stripping script elements, leaving onerror and other event-handler attributes fully intact and executable.",
            "updated_at": "2026-09-05T07:17:10.917",
            "published_at": "2026-09-05T07:17:10.917",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.10.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The exploit survives save-time sanitization because wp_kses_post allows the required HTML tags and attributes, and the client-side tooltip script re-parses the browser-decoded aria-label value as innerHTML while only stripping script elements, leaving onerror and other event-handler attributes fully intact and executable.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.gravityforms.com/gravityforms-change-log/",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/187a420d-a5a5-4b0e-945b-c5694243e68f?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:10.917",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16649"
                }
            ]
        },
        {
            "id": "CVE-2026-16517",
            "vendor": "Red Hat",
            "product": "Red Hat Hardened Images",
            "title": "Red Hat Hardened Images vulnerability",
            "summary": "A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.",
            "updated_at": "2026-09-09T06:17:15.167",
            "published_at": "2026-07-21T23:17:00.587",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-190",
            "what_happened": "A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:43818",
                "https://access.redhat.com/security/cve/CVE-2026-16517",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2505492"
            ],
            "timeline": [
                {
                    "at": "2026-07-21T23:17:00.587",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16517"
                }
            ]
        },
        {
            "id": "CVE-2026-16482",
            "vendor": "rtcamp",
            "product": "rtMedia for WordPress, BuddyPress and bbPress",
            "title": "rtMedia for WordPress, BuddyPress and bbPress vulnerability",
            "summary": "The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is exploitable on any public page containing an rtMedia shortcode (e.g., [rtmedia_gallery]) when the rtmedia_shortcode GET parameter is set, because RTMediaQuery::query() merges $_REQUEST into the internal query while only validating top-level array keys, allowing the nested 'compare' subvalue to reach the vulnerable sink without authentication.",
            "updated_at": "2026-09-12T08:16:23.797",
            "published_at": "2026-09-12T08:16:23.797",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.7.11 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up to, and including, 4.7.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is exploitable on any public page containing an rtMedia shortcode (e.g., [rtmedia_gallery]) when the rtmedia_shortcode GET parameter is set, because RTMediaQuery::query() merges $_REQUEST into the internal query while only validating top-level array keys, allowing the nested 'compare' subvalue to reach the vulnerable sink without authentication.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/buddypress-media/tags/4.7.11/app/helper/RTMediaModel.php#L105",
                "https://plugins.trac.wordpress.org/browser/buddypress-media/tags/4.7.11/app/helper/RTMediaModel.php#L116",
                "https://plugins.trac.wordpress.org/browser/buddypress-media/tags/4.7.11/app/main/routers/query/RTMediaQuery.php#L611",
                "https://plugins.trac.wordpress.org/changeset/3652137/buddypress-media/tags/4.7.12/app/helper/db/RTDBModel.php",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/53d9b351-ba17-431a-b371-7dc1a87bd757?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T08:16:23.797",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16482"
                }
            ]
        },
        {
            "id": "CVE-2026-16481",
            "vendor": "Google",
            "product": "MCP Toolbox for Databases (googleapis/mcp-toolbox)",
            "title": "MCP Toolbox for Databases (googleapis/mcp-toolbox) vulnerability",
            "summary": "A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox.\n\nThe tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET request to it using an authenticated client. The underlying transport automatically attaches an Authorization: Bearer  header to every outbound request regardless of the destination host. An attacker can supply an arbitrary external URL to the pageURL parameter (either directly via the tool execution payload or implicitly via data-driven pagination tracking loops), leading Toolbox into sending its OAuth/service-account access token to an attacker-controlled listener. Depending on the configuration, this leaks either the end-user's token or the broader service-account access token (ADC), potentially exposing Protected Health Information (PHI) and secondary Google Cloud Platform services.",
            "updated_at": "2026-09-10T17:17:01.973",
            "published_at": "2026-07-27T19:17:14.970",
            "cvss": 6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.19.1 through 1.4.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-918",
            "what_happened": "A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox.\n\nThe tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET request to it using an authenticated client. The underlying transport automatically attaches an Authorization: Bearer  header to every outbound request regardless of the destination host. An attacker can supply an arbitrary external URL to the pageURL parameter (either directly via the tool execution payload or implicitly via data-driven pagination tracking loops), leading Toolbox into sending its OAuth/service-account access token to an attacker-controlled listener. Depending on the configuration, this leaks either the end-user's token or the broader service-account access token (ADC), potentially exposing Protected Health Information (PHI) and secondary Google Cloud Platform services.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/googleapis/mcp-toolbox/pull/3453"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T19:17:14.970",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16481"
                }
            ]
        },
        {
            "id": "CVE-2026-16313",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.",
            "updated_at": "2026-09-14T06:16:54.813",
            "published_at": "2026-07-28T17:16:37.807",
            "cvss": 7.6,
            "cvss_vector": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Physical",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-93",
            "what_happened": "A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database. This could allow an attacker who can present a crafted SCSI device to execute arbitrary commands as root when the device is disconnected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:50141",
                "https://access.redhat.com/errata/RHSA-2026:50142",
                "https://access.redhat.com/errata/RHSA-2026:54769",
                "https://access.redhat.com/errata/RHSA-2026:56130",
                "https://access.redhat.com/errata/RHSA-2026:59397",
                "https://access.redhat.com/errata/RHSA-2026:59555",
                "https://access.redhat.com/errata/RHSA-2026:59567",
                "https://access.redhat.com/errata/RHSA-2026:59568",
                "https://access.redhat.com/errata/RHSA-2026:61260",
                "https://access.redhat.com/errata/RHSA-2026:61261",
                "https://access.redhat.com/errata/RHSA-2026:63041",
                "https://access.redhat.com/errata/RHSA-2026:63100",
                "https://access.redhat.com/security/cve/CVE-2026-16313",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2502845",
                "https://github.com/doug-gilbert/sg3_utils/pull/83",
                "https://access.redhat.com/errata/RHSA-2026:63044",
                "https://access.redhat.com/errata/RHSA-2026:67157"
            ],
            "timeline": [
                {
                    "at": "2026-07-28T17:16:37.807",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16313"
                }
            ]
        },
        {
            "id": "CVE-2026-16310",
            "vendor": "LearnDash",
            "product": "MemberDash",
            "title": "MemberDash vulnerability",
            "summary": "The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including administrators, by supplying an arbitrary user ID during registration, and take over their account without any notification sent to the victim.",
            "updated_at": "2026-09-06T03:17:15.540",
            "published_at": "2026-09-06T03:17:15.540",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.8.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including administrators, by supplying an arbitrary user ID during registration, and take over their account without any notification sent to the victim.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.memberdashwp.com",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/222e0f27-f269-4751-9544-1a6cb03ab3a7?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T03:17:15.540",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16310"
                }
            ]
        },
        {
            "id": "CVE-2026-16242",
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1",
            "title": "multicluster engine for Kubernetes 2.1 vulnerability",
            "summary": "A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.",
            "updated_at": "2026-09-14T15:17:04.540",
            "published_at": "2026-07-20T08:16:29.833",
            "cvss": 9.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 19,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:46885",
                "https://access.redhat.com/errata/RHSA-2026:47388",
                "https://access.redhat.com/errata/RHSA-2026:47728",
                "https://access.redhat.com/errata/RHSA-2026:47735",
                "https://access.redhat.com/errata/RHSA-2026:47949",
                "https://access.redhat.com/errata/RHSA-2026:47953",
                "https://access.redhat.com/errata/RHSA-2026:47974",
                "https://access.redhat.com/errata/RHSA-2026:48284",
                "https://access.redhat.com/errata/RHSA-2026:48657",
                "https://access.redhat.com/errata/RHSA-2026:48670",
                "https://access.redhat.com/errata/RHSA-2026:48676",
                "https://access.redhat.com/errata/RHSA-2026:48693",
                "https://access.redhat.com/errata/RHSA-2026:48699",
                "https://access.redhat.com/errata/RHSA-2026:50758",
                "https://access.redhat.com/errata/RHSA-2026:56789",
                "https://access.redhat.com/errata/RHSA-2026:56912",
                "https://access.redhat.com/security/cve/CVE-2026-16242",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2502690",
                "https://github.com/openshift/hypershift/pull/9031"
            ],
            "timeline": [
                {
                    "at": "2026-07-20T08:16:29.833",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16242"
                }
            ]
        },
        {
            "id": "CVE-2026-16232",
            "vendor": "Check Point",
            "product": "SmartConsole",
            "title": "Check Point SmartConsole Improper Authentication Vulnerability",
            "summary": "Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.",
            "updated_at": "2026-07-21T22:00:00Z",
            "published_at": "2026-07-21T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-07-21T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-16140",
            "vendor": "OpenBMC",
            "product": "phosphor-net-ipmid",
            "title": "Exploit for CVE-2026-16140",
            "summary": "OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. This issue effectively allows for privilege escalation without re-authentication.",
            "updated_at": "2026-09-15T15:17:13.270",
            "published_at": "2026-09-15T14:16:50.290",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "0 through ba6efc502e6b1fabb8ed1ca677ae5eedd64b6361 (git)",
            "fixed": "See vendor advisory",
            "source_count": 16,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. This issue effectively allows for privilege escalation without re-authentication.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-16140",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-16140",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-16140"
                    ],
                    "repository": "Sploitus",
                    "author": "runZero",
                    "first_seen": "2026-09-15T14:16:50",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-16140"
                },
                {
                    "title": "Exploit for CVE-2026-16140",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-16140",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-16140"
                    ],
                    "repository": "web.nvd.nist.gov",
                    "author": "view",
                    "first_seen": "2026-09-15T14:16:50",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-16140"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=CVE-2026-16140",
                "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-16140",
                "https://www.runzero.com/advisories/openbmc-ipmi-privsec-rakp-cve-2026-16140/",
                "https://www.runzero.com/blog/lights-out-exposed/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T12:16:50Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-16140"
                },
                {
                    "at": "2026-09-15T14:16:50.290",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16140"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "enrichment_checked_at": "2026-09-15T22:05:29Z"
        },
        {
            "id": "CVE-2026-16118",
            "vendor": "xdg",
            "product": "xdgmime",
            "title": "xdgmime vulnerability",
            "summary": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
            "updated_at": "2026-09-11T10:16:51.150",
            "published_at": "2026-07-17T20:17:16.167",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:64799",
                "https://access.redhat.com/security/cve/CVE-2026-16118",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2501732",
                "https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41",
                "https://access.redhat.com/errata/RHSA-2026:64800",
                "https://access.redhat.com/errata/RHSA-2026:66451"
            ],
            "timeline": [
                {
                    "at": "2026-07-17T20:17:16.167",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16118"
                }
            ]
        },
        {
            "id": "CVE-2026-16108",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden default groups, even if they lack the specific permissions to view those groups. This can lead to the exposure of sensitive organizational structures or internal group names.",
            "updated_at": "2026-09-16T19:17:07.940",
            "published_at": "2026-07-17T17:17:14.653",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-1220",
            "what_happened": "A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned to new users within a realm. The issue allows a delegated administrator with realm-viewing permissions to see the names and identifiers of hidden default groups, even if they lack the specific permissions to view those groups. This can lead to the exposure of sensitive organizational structures or internal group names.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-16108",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2501740"
            ],
            "timeline": [
                {
                    "at": "2026-07-17T17:17:14.653",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16108"
                }
            ]
        },
        {
            "id": "CVE-2026-16106",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.",
            "updated_at": "2026-09-16T19:17:07.803",
            "published_at": "2026-07-17T17:17:14.510",
            "cvss": 4.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-1220",
            "what_happened": "A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator attempts to remove a child role from a composite role. Due to missing authorization checks, an attacker with limited administrative permissions can remove privileged roles they are not authorized to manage, leading to a loss of access for other users and administrators.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-16106",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2501739"
            ],
            "timeline": [
                {
                    "at": "2026-07-17T17:17:14.510",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16106"
                }
            ]
        },
        {
            "id": "CVE-2026-16105",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.",
            "updated_at": "2026-09-16T19:17:07.660",
            "published_at": "2026-07-31T08:16:25.940",
            "cvss": 4.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated administrator with manage-realm permissions to remove essential child roles from built-in admin roles, potentially disrupting administrative functions within a realm.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-16105",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2501738"
            ],
            "timeline": [
                {
                    "at": "2026-07-31T08:16:25.940",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16105"
                }
            ]
        },
        {
            "id": "CVE-2026-16104",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.",
            "updated_at": "2026-09-16T19:17:07.513",
            "published_at": "2026-07-17T17:17:14.393",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-212",
            "what_happened": "A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-16104",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2501737"
            ],
            "timeline": [
                {
                    "at": "2026-07-17T17:17:14.393",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16104"
                }
            ]
        },
        {
            "id": "CVE-2026-16093",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.",
            "updated_at": "2026-09-16T19:17:07.373",
            "published_at": "2026-07-17T17:17:14.133",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-807",
            "what_happened": "Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-16093",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2501729"
            ],
            "timeline": [
                {
                    "at": "2026-07-17T17:17:14.133",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16093"
                }
            ]
        },
        {
            "id": "CVE-2026-16089",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.",
            "updated_at": "2026-09-16T19:17:07.217",
            "published_at": "2026-07-17T15:16:46.317",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-472",
            "what_happened": "A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be redeemed by their own client, potentially allowing them to obtain access tokens for a victim's identity.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-16089",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2501724"
            ],
            "timeline": [
                {
                    "at": "2026-07-17T15:16:46.317",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16089"
                }
            ]
        },
        {
            "id": "CVE-2026-16072",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administrator can create new user accounts and add them to the organization without having the required user management permissions or access to the invited email account. This allows an administrator to bypass security boundaries and add unauthorized members to an organization.",
            "updated_at": "2026-09-16T19:17:07.060",
            "published_at": "2026-07-17T14:17:21.860",
            "cvss": 4.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-497",
            "what_happened": "A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application programming interface. By using this link, the administrator can create new user accounts and add them to the organization without having the required user management permissions or access to the invited email account. This allows an administrator to bypass security boundaries and add unauthorized members to an organization.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-16072",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2501721"
            ],
            "timeline": [
                {
                    "at": "2026-07-17T14:17:21.860",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16072"
                }
            ]
        },
        {
            "id": "CVE-2026-16033",
            "vendor": "Canonical",
            "product": "LXD",
            "title": "LXD vulnerability",
            "summary": "A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver execution paths). An attacker can exploit this flaw by providing a crafted image archive with malicious template directives containing path traversal sequences, causing LXD to access or write files outside the intended template directory on the host system.",
            "updated_at": "2026-09-11T18:23:30.367",
            "published_at": "2026-08-12T21:17:35.880",
            "cvss": 8.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "4.0.0 through before 4.0.12 (semver); 5.0.0 through before 5.0.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver execution paths). An attacker can exploit this flaw by providing a crafted image archive with malicious template directives containing path traversal sequences, causing LXD to access or write files outside the intended template directory on the host system.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-08-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/canonical/lxd/security/advisories/GHSA-9hcm-hxh5-7xxh"
                }
            ],
            "references": [
                "https://github.com/canonical/lxd/security/advisories/GHSA-9hcm-hxh5-7xxh"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T21:17:35.880",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16033"
                }
            ]
        },
        {
            "id": "CVE-2026-16028",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connect...",
            "summary": "Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table.\n\nWhen a stream reaches the CLOSED state, stream_state returns the concurrency slot and clears most of the stream's keys, but the entry itself stays in the connection stream table and nothing in the distribution removes it. Stream identifiers increase monotonically, so a peer can open and close streams on one connection indefinitely, each close leaving a residual entry that is retained for the life of the connection.\n\nSETTINGS_MAX_CONCURRENT_STREAMS does not bound this. That setting caps how many streams are live at once and is enforced, while the growth is made of streams the cap has already released, so it accumulates with concurrency never exceeding one. The client keeps the same table and grows the same way against a hostile server.\n\nMeasured against a server built on this module, roughly 920 bytes are retained per closed stream for about 19 bytes on the wire, so 100,000 sequential streams on one connection grow server resident memory by about 88 MiB. The streams are ordinary requests that the application accepts and completes.",
            "updated_at": "2026-09-07T21:17:29.760",
            "published_at": "2026-09-07T19:17:25.927",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.14 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-401",
            "what_happened": "Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table.\n\nWhen a stream reaches the CLOSED state, stream_state returns the concurrency slot and clears most of the stream's keys, but the entry itself stays in the connection stream table and nothing in the distribution removes it. Stream identifiers increase monotonically, so a peer can open and close streams on one connection indefinitely, each close leaving a residual entry that is retained for the life of the connection.\n\nSETTINGS_MAX_CONCURRENT_STREAMS does not bound this. That setting caps how many streams are live at once and is enforced, while the growth is made of streams the cap has already released, so it accumulates with concurrency never exceeding one. The client keeps the same table and grows the same way against a hostile server.\n\nMeasured against a server built on this module, roughly 920 bytes are retained per closed stream for about 19 bytes on the wire, so 100,000 sequential streams on one connection grow server resident memory by about 88 MiB. The streams are ordinary requests that the application accepts and completes.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/vlet/p5-Protocol-HTTP2/commit/27a488a34d74fd16f123e5e6186d4f677faa246f.patch",
                "https://metacpan.org/release/CRUX/Protocol-HTTP2-1.13/source/lib/Protocol/HTTP2/Stream.pm#L113-126",
                "https://metacpan.org/release/CRUX/Protocol-HTTP2-1.14/changes",
                "http://www.openwall.com/lists/oss-security/2026/09/07/2"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:17:25.927",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-16028"
                }
            ]
        },
        {
            "id": "CVE-2026-15984",
            "vendor": "Themovation",
            "product": "QuickCal",
            "title": "QuickCal vulnerability",
            "summary": "The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce guarding the unauthenticated booked_add_appt AJAX action is publicly embedded on any page rendering the booking calendar shortcode, making it trivially obtainable by unauthenticated attackers without any prior account or privilege.",
            "updated_at": "2026-09-05T07:17:10.793",
            "published_at": "2026-09-05T07:17:10.793",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.0.20 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce guarding the unauthenticated booked_add_appt AJAX action is publicly embedded on any page rendering the booking calendar shortcode, making it trivially obtainable by unauthenticated attackers without any prior account or privilege.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://codecanyon.net/item/quickcal-appointment-booking-calendar-for-wordpress/47981746",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/9bfcfc13-ccfb-4319-99a7-7d7510a11cfe?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:10.793",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15984"
                }
            ]
        },
        {
            "id": "CVE-2026-15981",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter",
            "summary": "SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter",
            "updated_at": "2026-09-04T22:00:00Z",
            "published_at": "2026-09-04T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 87,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Nxploited/CVE-2026-15981",
                    "author": "Nxploited",
                    "first_seen": "2026-07-26",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter",
                    "summary": "SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter",
                    "url": "https://github.com/Nxploited/CVE-2026-15981"
                },
                {
                    "repository": "katranSefa/CVE-2026-15981",
                    "author": "katranSefa",
                    "first_seen": "2026-09-05",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2026-15981 repository",
                    "summary": "",
                    "url": "https://github.com/katranSefa/CVE-2026-15981"
                }
            ],
            "references": [
                "https://github.com/Nxploited/CVE-2026-15981",
                "https://github.com/katranSefa/CVE-2026-15981"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/Nxploited/CVE-2026-15981"
                }
            ]
        },
        {
            "id": "CVE-2026-15945",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.",
            "updated_at": "2026-09-16T19:17:06.900",
            "published_at": "2026-07-16T18:16:42.693",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to view, the system incorrectly returns the full details of the parent group in the response, leading to the disclosure of sensitive group attributes and configuration.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68277",
                "https://access.redhat.com/errata/RHSA-2026:68278",
                "https://access.redhat.com/security/cve/CVE-2026-15945",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2501302"
            ],
            "timeline": [
                {
                    "at": "2026-07-16T18:16:42.693",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15945"
                }
            ]
        },
        {
            "id": "CVE-2026-15892",
            "vendor": "zephyrproject",
            "product": "zephyr",
            "title": "zephyr vulnerability",
            "summary": "The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_name buffer (and, for read, a data buffer) via k_malloc() when CONFIG_MCUMGR_GRP_SETTINGS_BUFFER_TYPE_HEAP is enabled, relying on the end: label to k_free() them. When CONFIG_MCUMGR_GRP_SETTINGS_ACCESS_HOOK is also enabled and the application access hook rejects a request by returning status MGMT_CB_ERROR_RC, the handler executed return ret_rc; directly, bypassing end: and leaking the heap allocation on every rejected request.\n\nThe settings handlers are reachable over the unauthenticated SMP transport (Bluetooth LE, UART, or UDP, depending on product configuration). The access hook is the mechanism applications use to deny unauthorized settings access, and MGMT_CB_ERROR_RC is a common rejection style, so an attacker who can send settings read/write/delete commands that the hook rejects triggers a heap leak on each attempt.\n\nBecause the leaked memory is never reclaimed until reboot, a sustained stream of rejected requests monotonically exhausts the kernel heap until k_malloc() fails, denying mcumgr service and impacting any other heap consumer on the device — a denial of service. The impact is availability-only; there is no memory corruption or information disclosure. Only configurations that select the heap buffer type, enable the access hook, and register a hook that returns MGMT_CB_ERROR_RC are affected (the default stack buffer type cannot leak).",
            "updated_at": "2026-09-13T23:16:28.023",
            "published_at": "2026-09-13T23:16:28.023",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.5.0 through before 4.4.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-401",
            "what_happened": "The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_name buffer (and, for read, a data buffer) via k_malloc() when CONFIG_MCUMGR_GRP_SETTINGS_BUFFER_TYPE_HEAP is enabled, relying on the end: label to k_free() them. When CONFIG_MCUMGR_GRP_SETTINGS_ACCESS_HOOK is also enabled and the application access hook rejects a request by returning status MGMT_CB_ERROR_RC, the handler executed return ret_rc; directly, bypassing end: and leaking the heap allocation on every rejected request.\n\nThe settings handlers are reachable over the unauthenticated SMP transport (Bluetooth LE, UART, or UDP, depending on product configuration). The access hook is the mechanism applications use to deny unauthorized settings access, and MGMT_CB_ERROR_RC is a common rejection style, so an attacker who can send settings read/write/delete commands that the hook rejects triggers a heap leak on each attempt.\n\nBecause the leaked memory is never reclaimed until reboot, a sustained stream of rejected requests monotonically exhausts the kernel heap until k_malloc() fails, denying mcumgr service and impacting any other heap consumer on the device — a denial of service. The impact is availability-only; there is no memory corruption or information disclosure. Only configurations that select the heap buffer type, enable the access hook, and register a hook that returns MGMT_CB_ERROR_RC are affected (the default stack buffer type cannot leak).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/zephyrproject-rtos/zephyr/commit/fabc488d5b44143e5bd70dd373182c4395a816b9",
                "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-rq68-wgv4-hcq3"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T23:16:28.023",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15892"
                }
            ]
        },
        {
            "id": "CVE-2026-15891",
            "vendor": "zephyrproject",
            "product": "zephyr",
            "title": "zephyr vulnerability",
            "summary": "The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result. That macro is a pure expression that does not assign to gw, so gw retained its NULL initializer regardless of the list contents.\n\nThe code then dereferences the NULL gw (gw->gw_id) and passes it to mqtt_sn_gw_destroy(), reaching k_mem_slab_free(&gateways, NULL). With CONFIG_MEM_SLAB_POINTER_VALIDATE enabled this triggers k_panic(); in the default configuration it performs a write through the NULL pointer ((char )mem = slab->free_list;) and corrupts the slab free list. The outcome is a crash/kernel panic or, on targets where address 0 is writable, silent memory-allocator corruption.\n\nThe vulnerable branch runs whenever the connected MQTT-SN gateway fails to answer keepalive PINGREQs for the configured number of retries. This condition is controlled by the remote peer: a malicious or compromised gateway, or an on-path/adjacent attacker that advertises itself as a gateway and then stops responding (or blackholes the real gateway's PINGRESPs), forces the client into the defect. MQTT-SN runs over UDP and no authentication is required.\n\nThe impact is a remotely triggerable denial of service (availability) of the affected MQTT-SN client; there is no attacker-controlled data written. The sibling remover process_advertise() uses SYS_SLIST_FOR_EACH_CONTAINER_SAFE and is not affected. The fix assigns the macro's return value to gw.",
            "updated_at": "2026-09-13T23:16:27.870",
            "published_at": "2026-09-13T23:16:27.870",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.1.0 through before 4.4.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result. That macro is a pure expression that does not assign to gw, so gw retained its NULL initializer regardless of the list contents.\n\nThe code then dereferences the NULL gw (gw->gw_id) and passes it to mqtt_sn_gw_destroy(), reaching k_mem_slab_free(&gateways, NULL). With CONFIG_MEM_SLAB_POINTER_VALIDATE enabled this triggers k_panic(); in the default configuration it performs a write through the NULL pointer ((char )mem = slab->free_list;) and corrupts the slab free list. The outcome is a crash/kernel panic or, on targets where address 0 is writable, silent memory-allocator corruption.\n\nThe vulnerable branch runs whenever the connected MQTT-SN gateway fails to answer keepalive PINGREQs for the configured number of retries. This condition is controlled by the remote peer: a malicious or compromised gateway, or an on-path/adjacent attacker that advertises itself as a gateway and then stops responding (or blackholes the real gateway's PINGRESPs), forces the client into the defect. MQTT-SN runs over UDP and no authentication is required.\n\nThe impact is a remotely triggerable denial of service (availability) of the affected MQTT-SN client; there is no attacker-controlled data written. The sibling remover process_advertise() uses SYS_SLIST_FOR_EACH_CONTAINER_SAFE and is not affected. The fix assigns the macro's return value to gw.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/zephyrproject-rtos/zephyr/commit/bd21e954c36be105a374bbc090623810f1a17ee3",
                "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-c4g8-4f9p-4746"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T23:16:27.870",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15891"
                }
            ]
        },
        {
            "id": "CVE-2026-15816",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.",
            "updated_at": "2026-09-15T12:16:57.790",
            "published_at": "2026-08-07T11:17:05.100",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-78",
            "what_happened": "A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time dracut sources its emergency hook scripts during standard boot-failure handling.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:54571",
                "https://access.redhat.com/errata/RHSA-2026:54575",
                "https://access.redhat.com/errata/RHSA-2026:54576",
                "https://access.redhat.com/errata/RHSA-2026:57580",
                "https://access.redhat.com/errata/RHSA-2026:57772",
                "https://access.redhat.com/errata/RHSA-2026:57775",
                "https://access.redhat.com/errata/RHSA-2026:57785",
                "https://access.redhat.com/errata/RHSA-2026:60440",
                "https://access.redhat.com/errata/RHSA-2026:60445",
                "https://access.redhat.com/errata/RHSA-2026:61252",
                "https://access.redhat.com/errata/RHSA-2026:62269",
                "https://access.redhat.com/errata/RHSA-2026:62409",
                "https://access.redhat.com/errata/RHSA-2026:62549",
                "https://access.redhat.com/errata/RHSA-2026:63041",
                "https://access.redhat.com/errata/RHSA-2026:63044",
                "https://access.redhat.com/errata/RHSA-2026:66357",
                "https://access.redhat.com/security/cve/CVE-2026-15816",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2459963",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2500889",
                "https://github.com/dracutdevs/dracut/blob/master/modules.d/40network/netroot.sh",
                "https://github.com/dracutdevs/dracut/blob/master/modules.d/99base/dracut-lib.sh"
            ],
            "timeline": [
                {
                    "at": "2026-08-07T11:17:05.100",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15816"
                }
            ]
        },
        {
            "id": "CVE-2026-15711",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by sending a non-compliant, oversized control frame. Because the parser handles this protocol violation improperly instead of throwing an immediate connection termination error, it triggers a internal processing crash, resulting in a remote denial of service (DoS) for applications utilizing libsoup WebSockets.",
            "updated_at": "2026-09-16T19:17:06.653",
            "published_at": "2026-07-14T20:16:57.177",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by sending a non-compliant, oversized control frame. Because the parser handles this protocol violation improperly instead of throwing an immediate connection termination error, it triggers a internal processing crash, resulting in a remote denial of service (DoS) for applications utilizing libsoup WebSockets.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68234",
                "https://access.redhat.com/errata/RHSA-2026:68235",
                "https://access.redhat.com/errata/RHSA-2026:68266",
                "https://access.redhat.com/security/cve/CVE-2026-15711",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2499924",
                "https://gitlab.gnome.org/GNOME/libsoup/-/issues/515"
            ],
            "timeline": [
                {
                    "at": "2026-07-14T20:16:57.177",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15711"
                }
            ]
        },
        {
            "id": "CVE-2026-15709",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS).",
            "updated_at": "2026-09-16T19:17:06.410",
            "published_at": "2026-07-14T20:16:57.027",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-409",
            "what_happened": "A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A separate check for decompressed size (max_total_message_size) exists but executes only after inflation is complete, and it is entirely disabled by default for client connections. A remote, unauthenticated attacker can exploit this by sending a small, highly compressed payload (a decompression bomb), causing unbounded memory allocation that triggers an Out-of-Memory (OOM) crash and a Denial of Service (DoS).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:68234",
                "https://access.redhat.com/errata/RHSA-2026:68235",
                "https://access.redhat.com/security/cve/CVE-2026-15709",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2499922",
                "https://gitlab.gnome.org/GNOME/libsoup/-/issues/511"
            ],
            "timeline": [
                {
                    "at": "2026-07-14T20:16:57.027",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15709"
                }
            ]
        },
        {
            "id": "CVE-2026-15630",
            "vendor": "Casdoor",
            "product": "Casdoor",
            "title": "Casdoor vulnerability",
            "summary": "A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).",
            "updated_at": "2026-09-11T19:17:41.810",
            "published_at": "2026-07-23T21:17:02.760",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before v4.3.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://vokecyber.com/research/cve-2026-15630-casdoor-cross-tenant-authz",
                "https://www.kb.cert.org/vuls/id/889462"
            ],
            "timeline": [
                {
                    "at": "2026-07-23T21:17:02.760",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15630"
                }
            ]
        },
        {
            "id": "CVE-2026-15588",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
            "updated_at": "2026-09-10T18:17:56.303",
            "published_at": "2026-07-20T12:17:55.220",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 24,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:39985",
                "https://access.redhat.com/errata/RHSA-2026:40485",
                "https://access.redhat.com/errata/RHSA-2026:42329",
                "https://access.redhat.com/errata/RHSA-2026:55440",
                "https://access.redhat.com/errata/RHSA-2026:57015",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/errata/RHSA-2026:61766",
                "https://access.redhat.com/errata/RHSA-2026:61783",
                "https://access.redhat.com/errata/RHSA-2026:63135",
                "https://access.redhat.com/errata/RHSA-2026:63138",
                "https://access.redhat.com/errata/RHSA-2026:63140",
                "https://access.redhat.com/errata/RHSA-2026:65762",
                "https://access.redhat.com/errata/RHSA-2026:65763",
                "https://access.redhat.com/errata/RHSA-2026:65767",
                "https://access.redhat.com/errata/RHSA-2026:65768",
                "https://access.redhat.com/errata/RHSA-2026:65769",
                "https://access.redhat.com/errata/RHSA-2026:65770",
                "https://access.redhat.com/errata/RHSA-2026:65771",
                "https://access.redhat.com/errata/RHSA-2026:65773",
                "https://access.redhat.com/security/cve/CVE-2026-15588",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2499675",
                "https://gitlab.gnome.org/GNOME/glib/-/issues/3985",
                "https://access.redhat.com/errata/RHSA-2026:66018"
            ],
            "timeline": [
                {
                    "at": "2026-07-20T12:17:55.220",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15588"
                }
            ]
        },
        {
            "id": "CVE-2026-15550",
            "vendor": "Saturday Drive",
            "product": "Ninja Forms - Save Progress",
            "title": "Ninja Forms - Save Progress vulnerability",
            "summary": "The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary database records from the 'wp_nf3_objects' table, such as saved submissions.",
            "updated_at": "2026-09-05T12:16:47.050",
            "published_at": "2026-09-05T12:16:47.050",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.0.30 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary database records from the 'wp_nf3_objects' table, such as saved submissions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://ninjaforms.com/extensions/save-progress/",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/a7d3e6ce-e6d7-455b-a43d-a14189b30491?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:16:47.050",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15550"
                }
            ]
        },
        {
            "id": "CVE-2026-15462",
            "vendor": "gingerplugins",
            "product": "Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons",
            "title": "Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons vulnerability",
            "summary": "The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to $wpdb->insert(), which wraps column identifiers in backticks without escaping them, allowing a backtick in an attacker-supplied key to break out of the column-identifier list into raw SQL; additionally, the use of filter_input() bypasses WordPress's wp_magic_quotes() protection, and the widget_id validation loop is skipped entirely when no valid widget_id is supplied, leaving $isValid at 1. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
            "updated_at": "2026-09-11T04:17:20.173",
            "published_at": "2026-09-11T04:17:20.173",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.4.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to $wpdb->insert(), which wraps column identifiers in backticks without escaping them, allowing a backtick in an attacker-supplied key to break out of the column-identifier list into raw SQL; additionally, the use of filter_input() bypasses WordPress's wp_magic_quotes() protection, and the widget_id validation loop is skipped entirely when no valid widget_id is supplied, leaving $isValid at 1. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/sticky-chat-widget/tags/1.4.2/includes/front-end.php#L141",
                "https://plugins.trac.wordpress.org/browser/sticky-chat-widget/tags/1.4.2/includes/front-end.php#L188",
                "https://plugins.trac.wordpress.org/browser/sticky-chat-widget/tags/1.4.2/includes/front-end.php#L60",
                "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3640407%40sticky-chat-widget%2Ftrunk%2Fincludes%2Ffront-end.php&old=3349742%40sticky-chat-widget%2Ftrunk%2Fincludes%2Ffront-end.php&sfp_email=&sfph_mail=",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/35a49ba9-02a6-47cf-98f0-053b06036b08?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T04:17:20.173",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15462"
                }
            ]
        },
        {
            "id": "CVE-2026-15451",
            "vendor": "MemberPress",
            "product": "MemberPress Corporate Accounts",
            "title": "MemberPress Corporate Accounts vulnerability",
            "summary": "The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like role or ID. This makes it possible for authenticated attackers, with subscriber-level access and above who hold a corporate account, to create new administrator accounts or hijack existing administrator accounts by overwriting their email addresses. The vulnerability was partially patched in version 1.5.39.",
            "updated_at": "2026-09-12T13:16:50.940",
            "published_at": "2026-09-12T13:16:50.940",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.5.39 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like role or ID. This makes it possible for authenticated attackers, with subscriber-level access and above who hold a corporate account, to create new administrator accounts or hijack existing administrator accounts by overwriting their email addresses. The vulnerability was partially patched in version 1.5.39.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://memberpress.com/addons/corporate-accounts/",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/ba49bbf9-649b-456e-bab8-9f0f74bdbaee?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:50.940",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15451"
                }
            ]
        },
        {
            "id": "CVE-2026-15409",
            "vendor": "SonicWall",
            "product": "SMA1000 Appliances",
            "title": "SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
            "summary": "SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.",
            "updated_at": "2026-09-07T19:21:35Z",
            "published_at": "2026-09-07T19:21:35Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 100,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-15409",
                    "summary": "Unauthenticated SSRF in SonicWall SMA1000 Series with CVSS 10.0 critical impact.",
                    "what_happened": "Unauthenticated SSRF in SonicWall SMA1000 Series with CVSS 10.0 critical impact.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XBLACKASH-CVE-2026-15409",
                        "https://kitploit.com/ar/tools/github/0xblackash/cve-2026-15409/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-31T03:13:46",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XBLACKASH-CVE-2026-15409"
                },
                {
                    "title": "Exploit for CVE-2026-15409",
                    "summary": "Unauthenticated SSRF in SonicWall SMA1000 Series with CVSS 10.0 critical impact.",
                    "what_happened": "Unauthenticated SSRF in SonicWall SMA1000 Series with CVSS 10.0 critical impact.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XBLACKASH-CVE-2026-15409",
                        "https://kitploit.com/ar/tools/github/0xblackash/cve-2026-15409/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-08-31T03:13:46",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/0xblackash/cve-2026-15409/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XBLACKASH-CVE-2026-15409",
                "https://kitploit.com/ar/tools/github/0xblackash/cve-2026-15409/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:21:35Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-15310",
            "vendor": "Python Software Foundation",
            "product": "CPython",
            "title": "CPython vulnerability",
            "summary": "When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion.",
            "updated_at": "2026-09-11T02:18:33.150",
            "published_at": "2026-08-25T15:16:30.027",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.15.0rc2 (python)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "When decompressing crafted zip files using the bzip/LZMA/Zstandard \n\ncompressions, Python could use an attacker-controlled size to \n\npre-allocate memory, possibly resulting in memory exhaustion.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/python/cpython/commit/1b424c0178a01e155fd0267dc28a8fc1159b33a8",
                "https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89",
                "https://github.com/python/cpython/commit/e2311cfb3dd518f008f312fe0631f4f7490d237a",
                "https://github.com/python/cpython/commit/f897dbf2f36a5935700b7c2d94d4681d2136b7d4",
                "https://github.com/python/cpython/issues/156002",
                "https://github.com/python/cpython/pull/156003",
                "https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T15:16:30.027",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15310"
                }
            ]
        },
        {
            "id": "CVE-2026-15253",
            "vendor": "Unknown vendor",
            "product": "Easy Media Replace",
            "title": "Exploit for CVE-2026-15253",
            "summary": "The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in the media library list view, allowing users with the Author role and above to inject arbitrary web scripts that are executed in the browser of a higher privileged user who views the media library.",
            "updated_at": "2026-08-26T16:30:52.723",
            "published_at": "2026-08-19T06:17:34.360",
            "cvss": 6.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "0 through 0.2.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in the media library list view, allowing users with the Author role and above to inject arbitrary web scripts that are executed in the browser of a higher privileged user who views the media library.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-15253",
                    "summary": "Stored XSS in Easy Media Replace <= 0.2.0 via media attachment title attribute.",
                    "what_happened": "Stored XSS in Easy Media Replace <= 0.2.0 via media attachment title attribute.",
                    "cvss": 6.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=14431B61-64C6-510A-9F64-88327C8B5F5E",
                        "https://github.com/testardou/CVE-2026-15253"
                    ],
                    "repository": "Sploitus",
                    "author": "testardou",
                    "first_seen": "2026-09-11T14:32:56",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=14431B61-64C6-510A-9F64-88327C8B5F5E"
                },
                {
                    "title": "Exploit for CVE-2026-15253",
                    "summary": "Stored XSS in Easy Media Replace <= 0.2.0 via media attachment title attribute.",
                    "what_happened": "Stored XSS in Easy Media Replace <= 0.2.0 via media attachment title attribute.",
                    "cvss": 6.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=14431B61-64C6-510A-9F64-88327C8B5F5E",
                        "https://github.com/testardou/CVE-2026-15253"
                    ],
                    "repository": "testardou/CVE-2026-15253",
                    "author": "testardou",
                    "first_seen": "2026-09-11T14:32:56",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://github.com/testardou/CVE-2026-15253"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=14431B61-64C6-510A-9F64-88327C8B5F5E",
                "https://github.com/testardou/CVE-2026-15253",
                "https://wpscan.com/vulnerability/46eda528-3737-4c0d-bf72-df7fc6423907/"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T12:32:56Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=14431B61-64C6-510A-9F64-88327C8B5F5E"
                },
                {
                    "at": "2026-08-19T06:17:34.360",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15253"
                }
            ],
            "enrichment_checked_at": "2026-09-11T16:05:33Z",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-15247",
            "vendor": "Unknown",
            "product": "Search Atlas SEO",
            "title": "Search Atlas SEO vulnerability",
            "summary": "The Search Atlas SEO  WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.",
            "updated_at": "2026-09-06T11:18:00.513",
            "published_at": "2026-09-05T07:17:10.693",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.6.24 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The Search Atlas SEO  WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/1618ba19-c410-440b-a2d9-1e1526614549/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:10.693",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15247"
                }
            ]
        },
        {
            "id": "CVE-2026-15141",
            "vendor": "TP-Link Systems Inc.",
            "product": "TL-WR820N v2",
            "title": "TL-WR820N v2 vulnerability",
            "summary": "The web\ninterface of the affected\ndevice relies on the HTTP referrer header as part of\nrequest validation.  Requests containing empty Referer value, or omitting\nthe Referer header entirely, may be accepted and processed due to insufficient\nvalidation logic.\n\n\n\n\n\nSuccessful exploitation may allow an adjacent attacker with access to the web management\ninterface to obtain device configuration details and other sensitive\ninformation.",
            "updated_at": "2026-09-09T02:55:52.650",
            "published_at": "2026-08-12T23:17:19.703",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.15.20 Build 260611 Rel.29552n (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-346",
            "what_happened": "The web\ninterface of the affected\ndevice relies on the HTTP referrer header as part of\nrequest validation.  Requests containing empty Referer value, or omitting\nthe Referer header entirely, may be accepted and processed due to insufficient\nvalidation logic.\n\n\n\n\n\nSuccessful exploitation may allow an adjacent attacker with access to the web management\ninterface to obtain device configuration details and other sensitive\ninformation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.tp-link.com/en/support/download/tl-wr820n/#Firmware",
                "https://www.tp-link.com/en/support/faq/5243/",
                "https://www.tp-link.com/kr/support/download/tl-wr820n/#Firmware"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T23:17:19.703",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15141"
                }
            ]
        },
        {
            "id": "CVE-2026-15013",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "miniOrange  5.4.3 - Unauthenticated Auth Bypass",
            "summary": "miniOrange  5.4.3 - Unauthenticated Auth Bypass",
            "updated_at": "2026-08-31T22:00:00Z",
            "published_at": "2026-08-31T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 137,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52668",
                    "author": "zer0dayf",
                    "first_seen": "2026-09-01",
                    "confidence": "High",
                    "title": "miniOrange  5.4.3 - Unauthenticated Auth Bypass",
                    "summary": "miniOrange  5.4.3 - Unauthenticated Auth Bypass",
                    "url": "https://www.exploit-db.com/exploits/52668",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "zer0dayf/CVE-2026-15013",
                    "author": "zer0dayf",
                    "first_seen": "2026-07-27",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": " CVE-2026-15013",
                    "summary": " CVE-2026-15013",
                    "url": "https://github.com/zer0dayf/CVE-2026-15013"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52668",
                "https://github.com/zer0dayf/CVE-2026-15013"
            ],
            "timeline": [
                {
                    "at": "2026-08-31T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52668"
                }
            ]
        },
        {
            "id": "CVE-2026-14975",
            "vendor": "JoomUnited",
            "product": "WP File Download",
            "title": "WP File Download vulnerability",
            "summary": "The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. An authenticated attacker with Subscriber-level access first poisons the _wpfd_file_metadata['file'] post-meta value via the unprotected file.save handler, after which the streaming endpoint — hooked on init with no authentication requirement — resolves and streams the traversed file path to any caller, including unauthenticated visitors.",
            "updated_at": "2026-09-05T07:17:10.560",
            "published_at": "2026-09-05T07:17:10.560",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 6.3.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. An authenticated attacker with Subscriber-level access first poisons the _wpfd_file_metadata['file'] post-meta value via the unprotected file.save handler, after which the streaming endpoint — hooked on init with no authentication requirement — resolves and streams the traversed file path to any caller, including unauthenticated visitors.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/wp-file-download/trunk/app/site/init.php#L225",
                "https://www.joomunited.com/changelog/wp-file-download-changelog",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/2b99e525-c1d3-463d-8b87-b7d7fdd535d1?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:10.560",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14975"
                }
            ]
        },
        {
            "id": "CVE-2026-14962",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-14962",
            "summary": "Unauthenticated SQL injection in ELEX WooCommerce Request a Quote up to 2.4.0 via AJAX action.",
            "updated_at": "2026-09-11T16:50:23Z",
            "published_at": "2026-09-11T16:50:23Z",
            "cvss": 8.6,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 42,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Unauthenticated SQL injection in ELEX WooCommerce Request a Quote up to 2.4.0 via AJAX action.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-11T18:47:35+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Exploit for CVE-2026-14962",
                    "summary": "Proof-of-concept exploit for CVE-2026-14962. CVSS 8.6.",
                    "cvss": 8.6,
                    "url": "https://sploitus.com/exploit?id=1827572E-4B22-5D4D-A969-CBB7418FEC3D"
                },
                {
                    "title": "Exploit for CVE-2026-14962",
                    "summary": "Unauthenticated SQL injection in ELEX WooCommerce Request a Quote up to 2.4.0 via AJAX action.",
                    "what_happened": "Unauthenticated SQL injection in ELEX WooCommerce Request a Quote up to 2.4.0 via AJAX action.",
                    "cvss": 8.6,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=1827572E-4B22-5D4D-A969-CBB7418FEC3D",
                        "https://github.com/cflowsec/CVE-2026-14962"
                    ],
                    "repository": "cflowsec/CVE-2026-14962",
                    "author": "cflowsec",
                    "first_seen": "2026-09-11T18:50:23",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/cflowsec/CVE-2026-14962"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=1827572E-4B22-5D4D-A969-CBB7418FEC3D",
                "https://github.com/cflowsec/CVE-2026-14962"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T16:50:23Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=1827572E-4B22-5D4D-A969-CBB7418FEC3D"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2026-14863",
            "vendor": "FileRun",
            "product": "FileRun",
            "title": "FileRun vulnerability",
            "summary": "FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation system passes filenames wrapped in shell double-quotes directly to exec() without escapeshellarg() sanitization, allowing filenames such as $(PAYLOAD).mp4 to survive the filename sanitizer and be evaluated as shell commands when ffmpeg, ImageMagick, vips, or stl-thumb processes the file during thumbnail generation.",
            "updated_at": "2026-09-16T13:42:42.700",
            "published_at": "2026-08-11T21:17:25.867",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2026.2.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation system passes filenames wrapped in shell double-quotes directly to exec() without escapeshellarg() sanitization, allowing filenames such as $(PAYLOAD).mp4 to survive the filename sanitizer and be evaluated as shell commands when ffmpeg, ImageMagick, vips, or stl-thumb processes the file during thumbnail generation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://filerun.com/",
                "https://filerun.com/index.php/changelog?v=2026.2.1",
                "https://www.vulncheck.com/advisories/filerun-rce-via-thumbnail-generation-command-injection",
                "https://www.vulncheck.com/blog/filerun-thumbnail-command-injection-rce"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T21:17:25.867",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14863"
                }
            ]
        },
        {
            "id": "CVE-2026-14805",
            "vendor": "StylemixThemes",
            "product": "Consulting - Business, Finance WordPress Theme",
            "title": "Exploit for CVE-2026-14805",
            "summary": "The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This is due to a combination of two flaws: (1) the masterstudy_ms_stm_set_discard_transient AJAX endpoint in admin/admin-notices/classes/STMHandler.php accepts an arbitrary transient key without capability checks or nonce validation, and (2) the developer access login mechanism in admin/classes/stm-theme-support.php authenticates users based on a transient value without proper cryptographic validation when in legacy string mode. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the stm_developer_access_token transient to a known value (1), then authenticate as any existing user including administrators by visiting a specially crafted URL, thereby achieving full privilege escalation to administrator.",
            "updated_at": "2026-09-15T14:37:14.523",
            "published_at": "2026-09-15T13:16:40.507",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "0 through 6.7.16 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-269",
            "what_happened": "The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This is due to a combination of two flaws: (1) the masterstudy_ms_stm_set_discard_transient AJAX endpoint in admin/admin-notices/classes/STMHandler.php accepts an arbitrary transient key without capability checks or nonce validation, and (2) the developer access login mechanism in admin/classes/stm-theme-support.php authenticates users based on a transient value without proper cryptographic validation when in legacy string mode. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the stm_developer_access_token transient to a known value (1), then authenticate as any existing user including administrators by visiting a specially crafted URL, thereby achieving full privilege escalation to administrator.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-14805",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-14805",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-14805"
                    ],
                    "repository": "Sploitus",
                    "author": "Wordfence",
                    "first_seen": "2026-09-15T14:37:14",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-14805"
                },
                {
                    "title": "Exploit for CVE-2026-14805",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=CVE-2026-14805",
                        "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-14805"
                    ],
                    "repository": "web.nvd.nist.gov",
                    "author": "view",
                    "first_seen": "2026-09-15T14:37:14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-14805"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=CVE-2026-14805",
                "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-14805",
                "https://themeforest.net/item/consulting-business-finance-wordpress-theme/14740561#item-description__changelog",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/bc8dffc2-ae5b-4482-9eba-adc439a52c26?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T12:37:14Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=CVE-2026-14805"
                },
                {
                    "at": "2026-09-15T13:16:40.507",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14805"
                }
            ],
            "enrichment_checked_at": "2026-09-15T16:05:37Z",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-14620",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "webpack_devserver 5.2.5 -  CSRF",
            "summary": "webpack_devserver 5.2.5 -  CSRF",
            "updated_at": "2026-08-16T22:00:00Z",
            "published_at": "2026-08-16T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52649",
                    "author": "Jorge González Milla",
                    "first_seen": "2026-08-17",
                    "confidence": "High",
                    "title": "webpack_devserver 5.2.5 -  CSRF",
                    "summary": "webpack_devserver 5.2.5 -  CSRF",
                    "url": "https://www.exploit-db.com/exploits/52649",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52649"
            ],
            "timeline": [
                {
                    "at": "2026-08-16T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52649"
                }
            ]
        },
        {
            "id": "CVE-2026-14457",
            "vendor": "OpenSSL",
            "product": "OpenSSL",
            "title": "OpenSSL vulnerability",
            "summary": "Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary.",
            "updated_at": "2026-09-11T21:14:35.873",
            "published_at": "2026-08-25T13:17:49.533",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.0.2 (semver); 3.6.0 through before 3.6.4 (semver); 3.5.0 through before 3.5.8 (semver); 3.4.0 through before 3.4.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)\nenabled, and only the private key (with no associated certificate) configured locally,\na NULL pointer dereference may occur when the remote peer solicits raw public keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\n\nImpact summary: The impact is limited to a possible Denial of Service as a result of\nan application abort, no data disclosure or remote command execution are possible.\n\nCWE: CWE-476: NULL Pointer Dereference\n\nDescription: While a passing comment in sample code in the documentation suggests\nthat key-only RPK configurations are supported, the best-practice RPK configuration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\n\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\n\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue, as the SSL protocol implementation\nis outside the OpenSSL FIPS module boundary.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/openssl/openssl/commit/1e8c398db67404babd3e5af999bb6bd86f720c76",
                "https://github.com/openssl/openssl/commit/581aaa0f0a35d214740f0fe1f5283ec41f1212e1",
                "https://github.com/openssl/openssl/commit/d0af20478688a6aa2f59d61caa3f82136b181d7f",
                "https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b",
                "https://openssl-library.org/news/secadv/20260825.txt"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T13:17:49.533",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14457"
                }
            ]
        },
        {
            "id": "CVE-2026-14444",
            "vendor": "Very Good Plugins",
            "product": "WP Fusion (Pro)",
            "title": "WP Fusion (Pro) vulnerability",
            "summary": "The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.47.13. This is due to insufficient authorization checks on the role parameter in the ThriveCart Auto Login handler's thrivecart() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, and who possess the access_key, to create a new user account with administrator privileges and gain full control over the WordPress site. The required access_key is intentionally shared with ThriveCart customers as part of the plugin's documented setup process, making it accessible to attackers who have made a purchase. The vulnerability is only exploitable when the ThriveCart Auto Login option is enabled.",
            "updated_at": "2026-09-07T14:16:51.947",
            "published_at": "2026-09-07T14:16:51.947",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.47.13 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-269",
            "what_happened": "The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.47.13. This is due to insufficient authorization checks on the role parameter in the ThriveCart Auto Login handler's thrivecart() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, and who possess the access_key, to create a new user account with administrator privileges and gain full control over the WordPress site. The required access_key is intentionally shared with ThriveCart customers as part of the plugin's documented setup process, making it accessible to attackers who have made a purchase. The vulnerability is only exploitable when the ThriveCart Auto Login option is enabled.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpfusion.com/documentation/faq/changelog/",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/b352994f-13f9-4139-94a9-0abdb52125a9?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:51.947",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14444"
                }
            ]
        },
        {
            "id": "CVE-2026-14297",
            "vendor": "Nordic Semiconductor ASA",
            "product": "nRF Connect SDK",
            "title": "nRF Connect SDK vulnerability",
            "summary": "A buffer overflow in the Bluetooth Continuous Glucose\n     Monitoring Service (CGMS) Record Access Control Point (RACP) write handler\n     allows an authenticated BLE peer to overflow a 20-byte static buffer into\n     adjacent BSS memory. The exploitable impact cannot be predetermined - it\n     is entirely dependent on the linker-assigned BSS layout of the specific\n     firmware build, which may vary.",
            "updated_at": "2026-09-07T09:17:15.430",
            "published_at": "2026-09-07T09:17:15.430",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.2.0 through 3.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "A buffer overflow in the Bluetooth Continuous Glucose\n     Monitoring Service (CGMS) Record Access Control Point (RACP) write handler\n     allows an authenticated BLE peer to overflow a 20-byte static buffer into\n     adjacent BSS memory. The exploitable impact cannot be predetermined - it\n     is entirely dependent on the linker-assigned BSS layout of the specific\n     firmware build, which may vary.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.nordicsemi.com/r/bundle/struct_sa/page/struct/sa.html"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T09:17:15.430",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14297"
                }
            ]
        },
        {
            "id": "CVE-2026-14296",
            "vendor": "Nordic Semiconductor ASA",
            "product": "nRF54H20",
            "title": "nRF54H20 vulnerability",
            "summary": "When using the Direct XIP\nupdate strategy, the main application image starts other cores (i.e. radio\ncore), based on the currently active slot without additional verification. The\nMCUboot in the bare (upstream) configuration assumes that if there is at least\na single slot for each image available, the system is bootable and continues\nthe boot process. This may lead to a situation when MCUboot picks different\nslot for different images (i.e. (a) for the main application and (b) for the\nradio image), boots the main application (from slot (a)) that afterwards starts\nthe radio image by providing an address of the unauthenticated slot ((a)\ninstead of (b)).",
            "updated_at": "2026-09-07T08:17:11.773",
            "published_at": "2026-09-07T08:17:11.773",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.2; 3.3",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-347",
            "what_happened": "When using the Direct XIP\nupdate strategy, the main application image starts other cores (i.e. radio\ncore), based on the currently active slot without additional verification. The\nMCUboot in the bare (upstream) configuration assumes that if there is at least\na single slot for each image available, the system is bootable and continues\nthe boot process. This may lead to a situation when MCUboot picks different\nslot for different images (i.e. (a) for the main application and (b) for the\nradio image), boots the main application (from slot (a)) that afterwards starts\nthe radio image by providing an address of the unauthenticated slot ((a)\ninstead of (b)).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.nordicsemi.com/r/bundle/struct_sa/page/struct/sa.html"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:17:11.773",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14296"
                }
            ]
        },
        {
            "id": "CVE-2026-14277",
            "vendor": "IBM",
            "product": "i Access Family",
            "title": "i Access Family vulnerability",
            "summary": "IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a session file.",
            "updated_at": "2026-09-16T04:17:57.260",
            "published_at": "2026-09-14T21:17:02.560",
            "cvss": 6.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.1.2.0 through 1.1.9.15 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a session file.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7287166"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:02.560",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14277"
                }
            ]
        },
        {
            "id": "CVE-2026-14276",
            "vendor": "IBM",
            "product": "i Access Family",
            "title": "i Access Family vulnerability",
            "summary": "IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action.",
            "updated_at": "2026-09-16T04:17:57.080",
            "published_at": "2026-09-14T21:17:02.413",
            "cvss": 6.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.1.2.0 through 1.1.9.15 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a malicious emulator macro RunProgram action.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7287166"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:02.413",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14276"
                }
            ]
        },
        {
            "id": "CVE-2026-14275",
            "vendor": "IBM",
            "product": "i Access Family",
            "title": "i Access Family vulnerability",
            "summary": "IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a STRPCCMD CL command.",
            "updated_at": "2026-09-16T04:17:56.870",
            "published_at": "2026-09-14T21:17:02.273",
            "cvss": 6.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.1.2.0 through 1.1.9.15 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a STRPCCMD CL command.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7287166"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:02.273",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14275"
                }
            ]
        },
        {
            "id": "CVE-2026-14227",
            "vendor": "MikroTik",
            "product": "RouterOS",
            "title": "RouterOS vulnerability",
            "summary": "An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose permissions have been reduced may continue accessing information.",
            "updated_at": "2026-09-08T19:30:43.093",
            "published_at": "2026-07-30T19:17:07.493",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "All versions",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-613",
            "what_happened": "An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose permissions have been reduced may continue accessing information.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-01"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T19:17:07.493",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14227"
                }
            ]
        },
        {
            "id": "CVE-2026-14199",
            "vendor": "Grafana",
            "product": "Grafana Enterprise",
            "title": "Grafana Enterprise vulnerability",
            "summary": "Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).",
            "updated_at": "2026-09-15T18:23:02.127",
            "published_at": "2026-09-02T16:17:14.517",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.0.0 through 11.6.17 (semver); 12.0.0 through 12.2.11 (semver); 12.3.0 through 12.3.11 (semver); 12.4.0 through 12.4.9 (semver); 13.0.0 through 13.0.7 (semver); 13.1.0 through 13.1.4 (semver); 13.2.0 through 13.2.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-290",
            "what_happened": "Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://grafana.com/security/security-advisories/cve-2026-14199"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T16:17:14.517",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14199"
                }
            ]
        },
        {
            "id": "CVE-2026-14164",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.",
            "updated_at": "2026-09-09T17:17:15.903",
            "published_at": "2026-06-30T07:16:32.170",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 20,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-415",
            "what_happened": "A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent processing of another archive entry can trigger a second free of the same memory region, resulting in a double-free condition. Successful exploitation may cause applications using the vulnerable libarchive API to terminate unexpectedly, leading to a denial of service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:30333",
                "https://access.redhat.com/errata/RHSA-2026:52674",
                "https://access.redhat.com/errata/RHSA-2026:52675",
                "https://access.redhat.com/errata/RHSA-2026:54387",
                "https://access.redhat.com/errata/RHSA-2026:54760",
                "https://access.redhat.com/errata/RHSA-2026:54769",
                "https://access.redhat.com/errata/RHSA-2026:56954",
                "https://access.redhat.com/errata/RHSA-2026:58558",
                "https://access.redhat.com/errata/RHSA-2026:58573",
                "https://access.redhat.com/errata/RHSA-2026:58574",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/errata/RHSA-2026:61783",
                "https://access.redhat.com/errata/RHSA-2026:63041",
                "https://access.redhat.com/errata/RHSA-2026:63100",
                "https://access.redhat.com/security/cve/CVE-2026-14164",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2493411",
                "https://github.com/libarchive/libarchive/issues/3069",
                "https://github.com/libarchive/libarchive/pull/3071",
                "https://access.redhat.com/errata/RHSA-2026:63044"
            ],
            "timeline": [
                {
                    "at": "2026-06-30T07:16:32.170",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-14164"
                }
            ]
        },
        {
            "id": "CVE-2026-13738",
            "vendor": "Commvault",
            "product": "Commvault Cloud",
            "title": "Commvault Cloud vulnerability",
            "summary": "CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations.  Software customers upgrade to resolved maintenance release.  Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.",
            "updated_at": "2026-09-11T14:25:13.003",
            "published_at": "2026-08-11T12:17:37.923",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.46.0 through 11.46.9 (custom); 11.44.0 through 11.44.10 (custom); 11.40.0 through 11.40.62 (custom); 11.36.0 through 11.36.113 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-863",
            "what_happened": "CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations.  Software customers upgrade to resolved maintenance release.  Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://documentation.commvault.com/securityadvisories/CV_2026_07_9.html"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T12:17:37.923",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13738"
                }
            ]
        },
        {
            "id": "CVE-2026-13676",
            "vendor": "fast-uri",
            "product": "fast-uri",
            "title": "fast-uri vulnerability",
            "summary": "fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) before passing the same URL to Node's URL or fetch can be bypassed when the two implementations resolve the same input to different hosts. Patches: upgrade to fast-uri 3.1.3 for the 3.x line or 4.0.1 for the 4.x line. Workarounds: enforce host policy using the same URL parser used for the actual request, or reject non-ASCII hosts before policy checks.",
            "updated_at": "2026-09-11T13:17:06.833",
            "published_at": "2026-06-29T14:16:47.967",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.0.1 (semver); 2.3.1 through before 3.1.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-436",
            "what_happened": "fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) before passing the same URL to Node's URL or fetch can be bypassed when the two implementations resolve the same input to different hosts. Patches: upgrade to fast-uri 3.1.3 for the 3.x line or 4.0.1 for the 4.x line. Workarounds: enforce host policy using the same URL parser used for the actual request, or reject non-ASCII hosts before policy checks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6",
                "https://access.redhat.com/errata/RHSA-2026:37186",
                "https://access.redhat.com/errata/RHSA-2026:37585",
                "https://access.redhat.com/errata/RHSA-2026:37628",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:40765",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41929",
                "https://access.redhat.com/errata/RHSA-2026:42815",
                "https://access.redhat.com/errata/RHSA-2026:43038",
                "https://access.redhat.com/errata/RHSA-2026:44239",
                "https://access.redhat.com/errata/RHSA-2026:44268",
                "https://access.redhat.com/errata/RHSA-2026:47728",
                "https://access.redhat.com/errata/RHSA-2026:48124",
                "https://access.redhat.com/errata/RHSA-2026:48126",
                "https://access.redhat.com/errata/RHSA-2026:49642",
                "https://access.redhat.com/errata/RHSA-2026:50340",
                "https://access.redhat.com/errata/RHSA-2026:50479",
                "https://access.redhat.com/errata/RHSA-2026:50758",
                "https://access.redhat.com/errata/RHSA-2026:51196",
                "https://access.redhat.com/errata/RHSA-2026:51197",
                "https://access.redhat.com/errata/RHSA-2026:51342",
                "https://access.redhat.com/errata/RHSA-2026:51348",
                "https://access.redhat.com/errata/RHSA-2026:51349",
                "https://access.redhat.com/errata/RHSA-2026:54760",
                "https://access.redhat.com/errata/RHSA-2026:56366",
                "https://access.redhat.com/errata/RHSA-2026:56431",
                "https://access.redhat.com/errata/RHSA-2026:57013",
                "https://access.redhat.com/errata/RHSA-2026:57191",
                "https://access.redhat.com/errata/RHSA-2026:57194",
                "https://access.redhat.com/errata/RHSA-2026:57590",
                "https://access.redhat.com/errata/RHSA-2026:59593",
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:61314",
                "https://access.redhat.com/errata/RHSA-2026:63371",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-13676",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2494197",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13676.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-29T14:16:47.967",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13676"
                }
            ]
        },
        {
            "id": "CVE-2026-13622",
            "vendor": "Red Hat",
            "product": "Red Hat Container Native Virtualization 4.12",
            "title": "Red Hat Container Native Virtualization 4.12 vulnerability",
            "summary": "A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.",
            "updated_at": "2026-09-07T22:17:21.297",
            "published_at": "2026-08-12T21:17:35.630",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHEA-2026:53670",
                "https://access.redhat.com/errata/RHSA-2026:51031",
                "https://access.redhat.com/errata/RHSA-2026:53655",
                "https://access.redhat.com/errata/RHSA-2026:53671",
                "https://access.redhat.com/errata/RHSA-2026:53684",
                "https://access.redhat.com/errata/RHSA-2026:53721",
                "https://access.redhat.com/errata/RHSA-2026:53728",
                "https://access.redhat.com/errata/RHSA-2026:53763",
                "https://access.redhat.com/errata/RHSA-2026:53797",
                "https://access.redhat.com/errata/RHSA-2026:53826",
                "https://access.redhat.com/errata/RHSA-2026:53838",
                "https://access.redhat.com/security/cve/CVE-2026-13622",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2494142"
            ],
            "timeline": [
                {
                    "at": "2026-08-12T21:17:35.630",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13622"
                }
            ]
        },
        {
            "id": "CVE-2026-13608",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation.",
            "updated_at": "2026-09-15T07:16:26.353",
            "published_at": "2026-09-06T18:17:19.810",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.82.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 8.21.0 through before 8.22.0 (semver); eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4 through before ea71c3b6b60e563651ea8596a975aef0c8199519 (git); 8.21.0; 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-923",
            "what_happened": "A flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle (MITM)\nattack can inject a premature or shortcut response that bypasses complete peer\nvalidation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-09-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3822248"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-13608.html",
                "https://curl.se/docs/CVE-2026-13608.json",
                "https://hackerone.com/reports/3822248"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T18:17:19.810",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13608"
                }
            ]
        },
        {
            "id": "CVE-2026-13447",
            "vendor": "inspireui",
            "product": "MStore API – Create Native Android & iOS Apps On The Cloud",
            "title": "MStore API – Create Native Android & iOS Apps On The Cloud vulnerability",
            "summary": "The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT signature against Google's actual public key certificates. This makes it possible for unauthenticated attackers to forge a Firebase Phone Auth JWT signed with a self-generated RSA key pair and impersonate any phone number, resulting in unauthorized access to existing WordPress accounts or creation of new arbitrary accounts.",
            "updated_at": "2026-09-05T06:17:09.403",
            "published_at": "2026-09-05T06:17:09.403",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.20.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-287",
            "what_happened": "The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT signature against Google's actual public key certificates. This makes it possible for unauthenticated attackers to forge a Firebase Phone Auth JWT signed with a self-generated RSA key pair and impersonate any phone number, resulting in unauthorized access to existing WordPress accounts or creation of new arbitrary accounts.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/mstore-api/tags/4.18.4/controllers/flutter-user.php#L829",
                "https://plugins.trac.wordpress.org/browser/mstore-api/tags/4.18.4/controllers/flutter-user.php#L940",
                "https://plugins.trac.wordpress.org/browser/mstore-api/tags/4.18.4/controllers/helpers/firebase-phone-auth-helper.php#L5",
                "https://plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/flutter-user.php#L829",
                "https://plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/flutter-user.php#L940",
                "https://plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/helpers/firebase-phone-auth-helper.php#L5",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/4a1127af-74f6-4748-9aee-5a8c6c2766a4?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T06:17:09.403",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13447"
                }
            ]
        },
        {
            "id": "CVE-2026-13293",
            "vendor": "IBM",
            "product": "MQ",
            "title": "MQ vulnerability",
            "summary": "IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.",
            "updated_at": "2026-09-16T04:17:56.637",
            "published_at": "2026-09-14T21:17:02.130",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.1.0.0 through 9.1.0.37 LTS (semver); 9.2.0.0 through 9.2.0.43 LTS (semver); 9.3.0.0 through 9.3.0.41 LTS (semver); 9.3.0.0 through 9.3.5.1 CD (semver); 9.4.0.0 through 9.4.0.25 LTS (semver); 9.4.0.0 through 9.4.5.1 CD (semver); 10.0.0.0",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote authenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7284896"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T21:17:02.130",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13293"
                }
            ]
        },
        {
            "id": "CVE-2026-13201",
            "vendor": "Red Hat",
            "product": "Red Hat Container Native Virtualization 4.13",
            "title": "Red Hat Container Native Virtualization 4.13 vulnerability",
            "summary": "A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following syscalls. When the leaf is a symlink, the kernel dereferences it, defeating the intended no-follow protection. An attacker with access to a virt-launcher pod can exploit this to redirect virt-handler's IPC socket connections, including the notify socket used for VM domain lifecycle events. By hijacking this socket, the attacker can inject arbitrary domain events into virt-handler, causing it to take incorrect lifecycle actions, corrupt VM state in the Kubernetes API, or crash — resulting in sustained denial of VM management services for all virtual machines on the affected node. Additionally, the same symlink following flaw allows virt-handler to apply file ownership or permission changes to unintended host paths.",
            "updated_at": "2026-09-08T19:17:50.267",
            "published_at": "2026-06-24T21:16:52.420",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4 through 4.22.0",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-61",
            "what_happened": "A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using link-following syscalls. When the leaf is a symlink, the kernel dereferences it, defeating the intended no-follow protection. An attacker with access to a virt-launcher pod can exploit this to redirect virt-handler's IPC socket connections, including the notify socket used for VM domain lifecycle events. By hijacking this socket, the attacker can inject arbitrary domain events into virt-handler, causing it to take incorrect lifecycle actions, corrupt VM state in the Kubernetes API, or crash — resulting in sustained denial of VM management services for all virtual machines on the affected node. Additionally, the same symlink following flaw allows virt-handler to apply file ownership or permission changes to unintended host paths.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:51031",
                "https://access.redhat.com/errata/RHSA-2026:53655",
                "https://access.redhat.com/errata/RHSA-2026:53671",
                "https://access.redhat.com/errata/RHSA-2026:53684",
                "https://access.redhat.com/errata/RHSA-2026:53721",
                "https://access.redhat.com/errata/RHSA-2026:53728",
                "https://access.redhat.com/errata/RHSA-2026:53763",
                "https://access.redhat.com/errata/RHSA-2026:53797",
                "https://access.redhat.com/errata/RHSA-2026:53826",
                "https://access.redhat.com/errata/RHSA-2026:53838",
                "https://access.redhat.com/security/cve/CVE-2026-13201",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2492203"
            ],
            "timeline": [
                {
                    "at": "2026-06-24T21:16:52.420",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13201"
                }
            ]
        },
        {
            "id": "CVE-2026-13159",
            "vendor": "Unknown",
            "product": "Real Estate Papi",
            "title": "Real Estate Papi vulnerability",
            "summary": "The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion  from the WordPress.org repository. Where the request runs in the session of a user who can activate , those  are activated as well.",
            "updated_at": "2026-09-06T11:18:00.363",
            "published_at": "2026-09-06T07:16:41.900",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.0.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to install a fixed set of companion  from the WordPress.org repository. Where the request runs in the session of a user who can activate , those  are activated as well.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/3eea9204-d9ea-474e-a299-31d1aa0385e0/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T07:16:41.900",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-13159"
                }
            ]
        },
        {
            "id": "CVE-2026-12985",
            "vendor": "Mattermost",
            "product": "Mattermost",
            "title": "Mattermost vulnerability",
            "summary": "Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a remote unauthenticated attacker to register an OAuth client with an attacker-controlled callback host that bypasses the configured redirect URI allowlist via a crafted redirect URI that places an allowlisted host/path suffix inside the query string.. Mattermost Advisory ID: MMSA-2026-00700",
            "updated_at": "2026-09-15T04:17:12.323",
            "published_at": "2026-09-14T15:17:04.270",
            "cvss": 6.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.9.0 through 11.9.0 (semver); 11.8.0 through 11.8.4 (semver); 11.7.0 through 11.7.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-601",
            "what_happened": "Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a remote unauthenticated attacker to register an OAuth client with an attacker-controlled callback host that bypasses the configured redirect URI allowlist via a crafted redirect URI that places an allowlisted host/path suffix inside the query string.. Mattermost Advisory ID: MMSA-2026-00700",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://mattermost.com/security-updates"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T15:17:04.270",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12985"
                }
            ]
        },
        {
            "id": "CVE-2026-12944",
            "vendor": "IBM",
            "product": "Langflow OSS",
            "title": "Langflow OSS vulnerability",
            "summary": "IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesystem, and (3) lateral movement to internal services (PostgreSQL, Redis) within the Docker network. The scanner incorrectly returns \"validated\": true, providing a false security signal.",
            "updated_at": "2026-09-16T04:17:56.407",
            "published_at": "2026-09-14T22:16:56.950",
            "cvss": 9.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through 1.10.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file exfiltration from the container filesystem, and (3) lateral movement to internal services (PostgreSQL, Redis) within the Docker network. The scanner incorrectly returns \"validated\": true, providing a false security signal.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7278919"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T22:16:56.950",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12944"
                }
            ]
        },
        {
            "id": "CVE-2026-12843",
            "vendor": "StellarWP",
            "product": "LearnDash LMS",
            "title": "LearnDash LMS vulnerability",
            "summary": "The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enroll arbitrary users in paid courses without payment verification, bypassing the entire payment system and gaining unauthorized access to premium educational content.",
            "updated_at": "2026-09-05T12:16:46.923",
            "published_at": "2026-09-05T12:16:46.923",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.25.0 through 5.1.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enroll arbitrary users in paid courses without payment verification, bypassing the entire payment system and gaining unauthorized access to premium educational content.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docs.nexcess.com/software/changelogs/learndash/sfwd-lms/5-1-6-1/",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/48d29e8d-4084-401e-82ff-e4750d739c7c?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:16:46.923",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12843"
                }
            ]
        },
        {
            "id": "CVE-2026-12757",
            "vendor": "icegram",
            "product": "Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress",
            "title": "Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress vulnerability",
            "summary": "The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.",
            "updated_at": "2026-09-07T14:16:51.053",
            "published_at": "2026-09-07T14:16:51.053",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 5.9.27 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.22/lite/includes/classes/class-es-handle-subscription.php#L165",
                "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.22/lite/includes/classes/class-es-handle-subscription.php#L260",
                "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.22/lite/includes/classes/class-es-mailer.php#L1133",
                "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.22/lite/includes/workflows/actions/class-es-action-send-email.php#L188",
                "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.26/lite/includes/classes/class-es-handle-subscription.php#L165",
                "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.26/lite/includes/classes/class-es-handle-subscription.php#L260",
                "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.26/lite/includes/classes/class-es-mailer.php#L1133",
                "https://plugins.trac.wordpress.org/browser/email-subscribers/tags/5.9.26/lite/includes/workflows/actions/class-es-action-send-email.php#L188",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/6d9b4448-2b63-4704-ac9e-c4db4784638c?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T14:16:51.053",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12757"
                }
            ]
        },
        {
            "id": "CVE-2026-12745",
            "vendor": "Ivanti",
            "product": "Neurons for ITSM",
            "title": "Neurons for ITSM vulnerability",
            "summary": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.",
            "updated_at": "2026-09-09T05:17:19.467",
            "published_at": "2026-09-08T15:18:41.190",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T15:18:41.190",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12745"
                }
            ]
        },
        {
            "id": "CVE-2026-12744",
            "vendor": "Ivanti",
            "product": "Neurons for ITSM",
            "title": "Neurons for ITSM vulnerability",
            "summary": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.",
            "updated_at": "2026-09-09T05:17:19.343",
            "published_at": "2026-09-08T15:18:41.080",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T15:18:41.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12744"
                }
            ]
        },
        {
            "id": "CVE-2026-12728",
            "vendor": "IBM",
            "product": "MQ",
            "title": "MQ vulnerability",
            "summary": "IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code due to a deserialization of untrusted data.",
            "updated_at": "2026-09-16T04:17:54.543",
            "published_at": "2026-09-15T18:17:14.547",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.1.0.0 through 9.1.0.37 LTS (semver); 9.2.0.0 through 9.2.0.43 LTS (semver); 9.3.0.0 through 9.3.0.41 LTS (semver); 9.3.0.0 through 9.3.5.1 CD (semver); 9.4.0.0 through 9.4.0.25 LTS (semver); 9.4.0.0 through 9.4.5.1 CD (semver); 10.0.0.0",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code due to a deserialization of untrusted data.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7284942"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T18:17:14.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12728"
                }
            ]
        },
        {
            "id": "CVE-2026-12651",
            "vendor": "Ivanti",
            "product": "Neurons for ITSM",
            "title": "Neurons for ITSM vulnerability",
            "summary": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
            "updated_at": "2026-09-09T05:17:19.217",
            "published_at": "2026-09-08T15:18:40.963",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T15:18:40.963",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12651"
                }
            ]
        },
        {
            "id": "CVE-2026-12650",
            "vendor": "Ivanti",
            "product": "Neurons for ITSM",
            "title": "Neurons for ITSM vulnerability",
            "summary": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
            "updated_at": "2026-09-09T05:17:19.100",
            "published_at": "2026-09-08T15:18:40.850",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T15:18:40.850",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12650"
                }
            ]
        },
        {
            "id": "CVE-2026-12648",
            "vendor": "Ivanti",
            "product": "Neurons for ITSM",
            "title": "Neurons for ITSM vulnerability",
            "summary": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
            "updated_at": "2026-09-09T05:17:18.980",
            "published_at": "2026-09-08T15:18:40.733",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T15:18:40.733",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12648"
                }
            ]
        },
        {
            "id": "CVE-2026-12647",
            "vendor": "Ivanti",
            "product": "Ivanti Neurons for ITSM",
            "title": "Ivanti Neurons for ITSM vulnerability",
            "summary": "A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
            "updated_at": "2026-09-09T05:17:18.860",
            "published_at": "2026-09-08T15:18:40.623",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T15:18:40.623",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12647"
                }
            ]
        },
        {
            "id": "CVE-2026-12646",
            "vendor": "Ivanti",
            "product": "Ivanti Neurons for ITSM",
            "title": "Ivanti Neurons for ITSM vulnerability",
            "summary": "A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
            "updated_at": "2026-09-09T05:17:18.737",
            "published_at": "2026-09-08T15:18:40.507",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T15:18:40.507",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12646"
                }
            ]
        },
        {
            "id": "CVE-2026-12645",
            "vendor": "Ivanti",
            "product": "Ivanti Neurons for ITSM",
            "title": "Ivanti Neurons for ITSM vulnerability",
            "summary": "A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
            "updated_at": "2026-09-09T05:17:18.610",
            "published_at": "2026-09-08T15:18:40.380",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-Multiple-CVEs?language=en_US"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T15:18:40.380",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12645"
                }
            ]
        },
        {
            "id": "CVE-2026-12562",
            "vendor": "Toptech Systems",
            "product": "RCU II+",
            "title": "RCU II+ vulnerability",
            "summary": "The RCU II+ and Multiload II+ are vulnerable to an unauthenticated \nservice that exposes a debug interface granting full root-level access \nto the embedded system. This vulnerability stems from a \nnetwork-accessible port running a Target Communications Framework (TCF) \nservice that does not require any authentication, allowing an attacker \nto directly interact with the Linux environment that powers the device. \nOnce connected, an attacker can freely view and modify the filesystem, \nmanipulate running processes, and control network interfaces, enabling \ndeep alteration of system behavior.",
            "updated_at": "2026-09-08T19:30:43.093",
            "published_at": "2026-07-30T22:16:53.343",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2025-11-24 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "The RCU II+ and Multiload II+ are vulnerable to an unauthenticated \nservice that exposes a debug interface granting full root-level access \nto the embedded system. This vulnerability stems from a \nnetwork-accessible port running a Target Communications Framework (TCF) \nservice that does not require any authentication, allowing an attacker \nto directly interact with the Linux environment that powers the device. \nOnce connected, an attacker can freely view and modify the filesystem, \nmanipulate running processes, and control network interfaces, enabling \ndeep alteration of system behavior.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-03.json",
                "https://s3.amazonaws.com/docs.toptech.com/index.html#downloads/Firmware/RCUII+_MLII+_SMPII+/",
                "https://s3.amazonaws.com/docs.toptech.com/nonpublic/2025%2012%2001%20RCU%20IIPlus%20MultiLoad%20IIPlus%20Vulnerability%20Notice.pdf",
                "https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.gz",
                "https://s3.amazonaws.com/docs.toptech.com/nonpublic/rcuiip_mliip_vrt.zip",
                "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-03"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T22:16:53.343",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12562"
                }
            ]
        },
        {
            "id": "CVE-2026-12478",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to trigger an OOB read in a libsoup-based client when max_incoming_payload_size is set to 0.",
            "updated_at": "2026-09-16T09:17:03.437",
            "published_at": "2026-07-14T10:16:30.957",
            "cvss": 4.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-125",
            "what_happened": "The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious WebSocket server can send a crafted unmasked frame with a payload length near UINT64_MAX to trigger an OOB read in a libsoup-based client when max_incoming_payload_size is set to 0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/security/cve/CVE-2026-12478",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2489655",
                "https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/518"
            ],
            "timeline": [
                {
                    "at": "2026-07-14T10:16:30.957",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12478"
                }
            ]
        },
        {
            "id": "CVE-2026-12355",
            "vendor": "IBM",
            "product": "MQ",
            "title": "MQ vulnerability",
            "summary": "IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an attacker to perform JNDI injection attacks due to insufficient input validation, potentially leading to information disclosure or remote code execution.",
            "updated_at": "2026-09-16T04:17:54.313",
            "published_at": "2026-09-15T18:17:13.980",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.1.0.0 through 9.1.0.37 LTS (semver); 9.2.0.0 through 9.2.0.43 LTS (semver); 9.3.0.0 through 9.3.0.41 LTS (semver); 9.3.0.0 through 9.3.5.1 CD (semver); 9.4.0.0 through 9.4.0.25 LTS (semver); 9.4.0.0 through 9.4.5.1 CD (semver); 10.0.0.0",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-74",
            "what_happened": "IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an attacker to perform JNDI injection attacks due to insufficient input validation, potentially leading to information disclosure or remote code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7284912"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T18:17:13.980",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12355"
                }
            ]
        },
        {
            "id": "CVE-2026-12354",
            "vendor": "IBM",
            "product": "MQ",
            "title": "MQ vulnerability",
            "summary": "IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code on the application server due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application.",
            "updated_at": "2026-09-16T04:17:54.130",
            "published_at": "2026-09-15T18:17:13.847",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.1.0.0 through 9.1.0.37 LTS (semver); 9.2.0.0 through 9.2.0.43 LTS (semver); 9.3.0.0 through 9.3.0.41 LTS (semver); 9.3.0.0 through 9.3.5.1 CD (semver); 9.4.0.0 through 9.4.0.25 LTS (semver); 9.4.0.0 through 9.4.5.1 CD (semver); 10.0.0.0",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-913",
            "what_happened": "IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code on the application server due to improper validation of JNDI names in the Resource Adapter Installation Verification Test application.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7284908"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T18:17:13.847",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12354"
                }
            ]
        },
        {
            "id": "CVE-2026-12351",
            "vendor": "IBM",
            "product": "MQ",
            "title": "MQ vulnerability",
            "summary": "IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed.",
            "updated_at": "2026-09-16T04:17:53.937",
            "published_at": "2026-09-15T18:17:13.727",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.3.0.0 through 9.3.0.41 LTS (semver); 9.3.0.0 through 9.3.5.1 CD (semver); 9.4.0.0 through 9.4.0.25 LTS (semver); 9.4.0.0 through 9.4.5.1 LTS (semver); 10.0.0.0",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7284541"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T18:17:13.727",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12351"
                }
            ]
        },
        {
            "id": "CVE-2026-12215",
            "vendor": "xootix",
            "product": "OTP Login & Register Woocommerce",
            "title": "OTP Login & Register Woocommerce vulnerability",
            "summary": "The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `process_otp_form` is keyed exclusively on the attacker-controlled `xoo_ml_user_ip_data` cookie's `ip_address` field, allowing unlimited counter resets by simply rotating the cookie, while the OTP itself is generated with PHP's non-cryptographic `rand()` function over a default space of only 9,000 possible values (1000–9999), and both the OTP issuance endpoint (`xoo_ml_login_with_otp`) and verification endpoint (`xoo_ml_otp_form_submit`) are registered as unauthenticated `wp_ajax_nopriv` actions with no nonce or capability checks. This makes it possible for unauthenticated attackers to brute-force the OTP for any registered account and obtain a full WordPress authentication session — including for administrator accounts — via `wp_set_auth_cookie()` in `login_user_with_otp()`. Exploitation requires the attacker to know the target user's registered phone number, which is used to trigger OTP issuance via the unauthenticated `xoo_ml_login_with_otp` endpoint.",
            "updated_at": "2026-09-11T04:17:20.013",
            "published_at": "2026-09-11T04:17:20.013",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.7.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `process_otp_form` is keyed exclusively on the attacker-controlled `xoo_ml_user_ip_data` cookie's `ip_address` field, allowing unlimited counter resets by simply rotating the cookie, while the OTP itself is generated with PHP's non-cryptographic `rand()` function over a default space of only 9,000 possible values (1000–9999), and both the OTP issuance endpoint (`xoo_ml_login_with_otp`) and verification endpoint (`xoo_ml_otp_form_submit`) are registered as unauthenticated `wp_ajax_nopriv` actions with no nonce or capability checks. This makes it possible for unauthenticated attackers to brute-force the OTP for any registered account and obtain a full WordPress authentication session — including for administrator accounts — via `wp_set_auth_cookie()` in `login_user_with_otp()`. Exploitation requires the attacker to know the target user's registered phone number, which is used to trigger OTP issuance via the unauthenticated `xoo_ml_login_with_otp` endpoint.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/mobile-login-woocommerce/tags/2.7.2/includes/class-xoo-ml-geolocation.php#L24",
                "https://plugins.trac.wordpress.org/browser/mobile-login-woocommerce/tags/2.7.2/includes/class-xoo-ml-otp-handler.php#L155",
                "https://plugins.trac.wordpress.org/browser/mobile-login-woocommerce/tags/2.7.2/includes/class-xoo-ml-otp-handler.php#L24",
                "https://plugins.trac.wordpress.org/browser/mobile-login-woocommerce/tags/2.7.2/includes/class-xoo-ml-verification.php#L472",
                "https://plugins.trac.wordpress.org/browser/mobile-login-woocommerce/tags/2.7.2/includes/class-xoo-ml-verification.php#L84",
                "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3639216%40mobile-login-woocommerce%2Ftrunk%2Fincludes%2Fclass-xoo-ml-otp-handler.php&old=3419316%40mobile-login-woocommerce%2Ftrunk%2Fincludes%2Fclass-xoo-ml-otp-handler.php&sfp_email=&sfph_mail=",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/4bd4b379-6d7d-4cfe-bb16-a931c5d68d02?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T04:17:20.013",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12215"
                }
            ]
        },
        {
            "id": "CVE-2026-12151",
            "vendor": "undici",
            "product": "undici",
            "title": "undici vulnerability",
            "summary": "Impact:\nThe undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.\n\nAffected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.\n\nAll releases starting at undici 6.17.0 are affected.\n\nPatches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds:\nNo workaround is available. The fix must be applied through an upgrade.",
            "updated_at": "2026-09-11T13:17:05.943",
            "published_at": "2026-06-17T17:16:42.370",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 6.26.0 (semver); 7.0.0 through before 7.28.0 (semver); 8.0.0 through before 8.5.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 31,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Impact:\nThe undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service.\n\nAffected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint.\n\nAll releases starting at undici 6.17.0 are affected.\n\nPatches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds:\nNo workaround is available. The fix must be applied through an upgrade.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89q",
                "https://access.redhat.com/errata/RHSA-2026:34342",
                "https://access.redhat.com/errata/RHSA-2026:35841",
                "https://access.redhat.com/errata/RHSA-2026:35842",
                "https://access.redhat.com/errata/RHSA-2026:35891",
                "https://access.redhat.com/errata/RHSA-2026:35892",
                "https://access.redhat.com/errata/RHSA-2026:36621",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:36820",
                "https://access.redhat.com/errata/RHSA-2026:38009",
                "https://access.redhat.com/errata/RHSA-2026:38236",
                "https://access.redhat.com/errata/RHSA-2026:39246",
                "https://access.redhat.com/errata/RHSA-2026:39868",
                "https://access.redhat.com/errata/RHSA-2026:41929",
                "https://access.redhat.com/errata/RHSA-2026:41947",
                "https://access.redhat.com/errata/RHSA-2026:47728",
                "https://access.redhat.com/errata/RHSA-2026:48124",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:52399",
                "https://access.redhat.com/errata/RHSA-2026:56366",
                "https://access.redhat.com/errata/RHSA-2026:56431",
                "https://access.redhat.com/errata/RHSA-2026:57013",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:62260",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-12151",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2489980",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-17T17:16:42.370",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12151"
                }
            ]
        },
        {
            "id": "CVE-2026-12143",
            "vendor": "form-data",
            "product": "form-data",
            "title": "form-data vulnerability",
            "summary": "form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the attacker to terminate the header line and inject additional headers, or to smuggle entire additional multipart parts, into the request the application forwards to a backend. This can let the attacker add or override form fields (e.g. set `is_admin=true`) seen by the downstream parser. This is an instance of CWE-93 (CRLF injection). The fix escapes CR, LF, and `\"` as `%0D`, `%0A`, and `%22` in field names and filenames, matching the serialization browsers use per the WHATWG HTML multipart/form-data encoding algorithm. Exploitation requires the consuming application to use untrusted input as a field name or filename; applications that use only fixed/trusted field names are not affected. Fixed in 2.5.6, 3.0.5, and 4.0.6.",
            "updated_at": "2026-09-11T13:17:04.787",
            "published_at": "2026-06-12T19:16:26.560",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.5.6 (semver); 3.0.0 through before 3.0.5 (semver); 4.0.0 through before 4.0.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 66,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-93",
            "what_happened": "form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (\") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the attacker to terminate the header line and inject additional headers, or to smuggle entire additional multipart parts, into the request the application forwards to a backend. This can let the attacker add or override form fields (e.g. set `is_admin=true`) seen by the downstream parser. This is an instance of CWE-93 (CRLF injection). The fix escapes CR, LF, and `\"` as `%0D`, `%0A`, and `%22` in field names and filenames, matching the serialization browsers use per the WHATWG HTML multipart/form-data encoding algorithm. Exploitation requires the consuming application to use untrusted input as a field name or filename; applications that use only fixed/trusted field names are not affected. Fixed in 2.5.6, 3.0.5, and 4.0.6.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cwe.mitre.org/data/definitions/93.html",
                "https://github.com/form-data/form-data/commit/64190db548c0179e37206858e39f27cf513e9435",
                "https://github.com/form-data/form-data/commit/be3f3cf553978bac15a5182f1f3c3d2d38ccf229",
                "https://github.com/form-data/form-data/commit/c7133499c2ee1b80c678e411244f4442bf902045",
                "https://github.com/form-data/form-data/security/advisories/GHSA-hmw2-7cc7-3qxx",
                "https://html.spec.whatwg.org/multipage/form-control-infrastructure.html#multipart-form-data",
                "https://www.npmjs.com/package/form-data",
                "https://access.redhat.com/errata/RHSA-2026:33155",
                "https://access.redhat.com/errata/RHSA-2026:33160",
                "https://access.redhat.com/errata/RHSA-2026:33163",
                "https://access.redhat.com/errata/RHSA-2026:33173",
                "https://access.redhat.com/errata/RHSA-2026:33183",
                "https://access.redhat.com/errata/RHSA-2026:34342",
                "https://access.redhat.com/errata/RHSA-2026:36319",
                "https://access.redhat.com/errata/RHSA-2026:36625",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:40262",
                "https://access.redhat.com/errata/RHSA-2026:41031",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41929",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:42146",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:43052",
                "https://access.redhat.com/errata/RHSA-2026:44263",
                "https://access.redhat.com/errata/RHSA-2026:44267",
                "https://access.redhat.com/errata/RHSA-2026:48124",
                "https://access.redhat.com/errata/RHSA-2026:48151",
                "https://access.redhat.com/errata/RHSA-2026:48693",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/errata/RHSA-2026:54770",
                "https://access.redhat.com/errata/RHSA-2026:56338",
                "https://access.redhat.com/errata/RHSA-2026:56366",
                "https://access.redhat.com/errata/RHSA-2026:56431",
                "https://access.redhat.com/errata/RHSA-2026:57013",
                "https://access.redhat.com/errata/RHSA-2026:57545",
                "https://access.redhat.com/errata/RHSA-2026:57590",
                "https://access.redhat.com/errata/RHSA-2026:57801",
                "https://access.redhat.com/errata/RHSA-2026:59136",
                "https://access.redhat.com/errata/RHSA-2026:59153",
                "https://access.redhat.com/errata/RHSA-2026:59155",
                "https://access.redhat.com/errata/RHSA-2026:59556",
                "https://access.redhat.com/errata/RHSA-2026:59557",
                "https://access.redhat.com/errata/RHSA-2026:59558",
                "https://access.redhat.com/errata/RHSA-2026:59559",
                "https://access.redhat.com/errata/RHSA-2026:59579",
                "https://access.redhat.com/errata/RHSA-2026:60387",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/errata/RHSA-2026:60389",
                "https://access.redhat.com/errata/RHSA-2026:60390",
                "https://access.redhat.com/errata/RHSA-2026:60391",
                "https://access.redhat.com/errata/RHSA-2026:60446",
                "https://access.redhat.com/errata/RHSA-2026:60477",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:62260",
                "https://access.redhat.com/errata/RHSA-2026:63047",
                "https://access.redhat.com/errata/RHSA-2026:63355",
                "https://access.redhat.com/errata/RHSA-2026:63373",
                "https://access.redhat.com/errata/RHSA-2026:66003",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/errata/RHSA-2026:66545",
                "https://access.redhat.com/security/cve/CVE-2026-12143",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2488480",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12143.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-12T19:16:26.560",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12143"
                }
            ]
        },
        {
            "id": "CVE-2026-12064",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.",
            "updated_at": "2026-09-15T07:16:26.150",
            "published_at": "2026-07-03T07:16:24.217",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.81.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 18270893abdb19f0ca170c118f8a2847dbd304be through before ab3bb8cd8be8f9d4acb97da0418abc279182041e (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-297",
            "what_happened": "When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3797526"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-12064.html",
                "https://curl.se/docs/CVE-2026-12064.json",
                "https://hackerone.com/reports/3797526"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:24.217",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-12064"
                }
            ]
        },
        {
            "id": "CVE-2026-11856",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`.",
            "updated_at": "2026-09-15T07:16:25.870",
            "published_at": "2026-07-03T07:16:23.973",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.10.6 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 334d78cd18a7310144383929bdcef34ffbf6159b through before 5c6b4880357ab3e72967c1c45cae0f96ffabc535 (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0; 7.32.0; 7.31.0; 7.30.0; 7.29.0; 7.28.1; 7.28.0; 7.27.0; 7.26.0; 7.25.0; 7.24.0; 7.23.1; 7.23.0; 7.22.0; 7.21.7; 7.21.6; 7.21.5; 7.21.4; 7.21.3; 7.21.2; 7.21.1; 7.21.0; 7.20.1; 7.20.0; 7.19.7; 7.19.6; 7.19.5; 7.19.4; 7.19.3; 7.19.2; 7.19.1; 7.19.0; 7.18.2; 7.18.1; 7.18.0; 7.17.1; 7.17.0; 7.16.4; 7.16.3; 7.16.2; 7.16.1; 7.16.0; 7.15.5; 7.15.4; 7.15.3; 7.15.2; 7.15.1; 7.15.0; 7.14.1; 7.14.0; 7.13.2; 7.13.1; 7.13.0; 7.12.3; 7.12.2; 7.12.1; 7.12.0; 7.11.2; 7.11.1; 7.11.0; 7.10.8; 7.10.7; 7.10.6",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-294",
            "what_happened": "Successfully using libcurl to do a transfer to a specific HTTP origin\n(`hostA`) with **Digest** authentication and then changing the origin to a\ndifferent one (`hostB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Authorization:` header field meant for `hostA`,\nto `hostB`.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3793260"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-11856.html",
                "https://curl.se/docs/CVE-2026-11856.json",
                "https://hackerone.com/reports/3793260"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:23.973",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11856"
                }
            ]
        },
        {
            "id": "CVE-2026-11841",
            "vendor": "SICK AG",
            "product": "InspectorP61x",
            "title": "InspectorP61x vulnerability",
            "summary": "An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.",
            "updated_at": "2026-09-09T15:52:04.827",
            "published_at": "2026-07-28T10:16:47.867",
            "cvss": 9.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.4.0 (custom); all versions; before 2.15.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-552",
            "what_happened": "An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices",
                "https://www.first.org/cvss/calculator/3.1",
                "https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.json",
                "https://www.sick.com/.well-known/csaf/white/2026/sca-2026-0010.pdf",
                "https://www.sick.com/media/docs/9/19/719/special_information_sick_operating_guidelines_cybersecurity_by_sick_en_im0106719.pdf",
                "https://www.sick.com/psirt"
            ],
            "timeline": [
                {
                    "at": "2026-07-28T10:16:47.867",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11841"
                }
            ]
        },
        {
            "id": "CVE-2026-11837",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links in their ~/.ssh directory to redirect file ownership changes to arbitrary system paths when an operator runs the authorized_key task as root, leading to local privilege escalation.",
            "updated_at": "2026-09-08T18:17:33.763",
            "published_at": "2026-06-10T05:16:38.510",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-59",
            "what_happened": "A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links in their ~/.ssh directory to redirect file ownership changes to arbitrary system paths when an operator runs the authorized_key task as root, leading to local privilege escalation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/security/cve/CVE-2026-11837",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2487424",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11837.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-10T05:16:38.510",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11837"
                }
            ]
        },
        {
            "id": "CVE-2026-11814",
            "vendor": "NETGEAR",
            "product": "BE9300",
            "title": "BE9300 vulnerability",
            "summary": "A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.",
            "updated_at": "2026-09-09T03:00:03.993",
            "published_at": "2026-08-11T16:17:28.540",
            "cvss": 4.9,
            "cvss_vector": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before V1.0.1.84 (custom); before V1.1.8.142 (custom); before V1.0.18.164 (custom); before V1.0.5.50 (custom); before V1.2.10.56 (custom); before V1.0.17.142 (custom); before V1.0.14.108 (custom); before V1.0.19.172 (custom); before V6.3.8.11 (custom); before V1.0.1.80 (custom); before V1.0.1.90 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 27,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory",
                "https://www.netgear.com/support/product/be9300/",
                "https://www.netgear.com/support/product/mr60/",
                "https://www.netgear.com/support/product/ms60/",
                "https://www.netgear.com/support/product/r6700ax/",
                "https://www.netgear.com/support/product/rax10/",
                "https://www.netgear.com/support/product/rax120/",
                "https://www.netgear.com/support/product/rax120v2/",
                "https://www.netgear.com/support/product/rax20/",
                "https://www.netgear.com/support/product/rax28/",
                "https://www.netgear.com/support/product/rax29/",
                "https://www.netgear.com/support/product/rax30/",
                "https://www.netgear.com/support/product/rax36s/",
                "https://www.netgear.com/support/product/rax43/",
                "https://www.netgear.com/support/product/rax45/",
                "https://www.netgear.com/support/product/rax50/",
                "https://www.netgear.com/support/product/rax70/",
                "https://www.netgear.com/support/product/rbr760/",
                "https://www.netgear.com/support/product/rbs760/",
                "https://www.netgear.com/support/product/rs100/",
                "https://www.netgear.com/support/product/rs200/",
                "https://www.netgear.com/support/product/rs280/",
                "https://www.netgear.com/support/product/rs300/",
                "https://www.netgear.com/support/product/rs500/",
                "https://www.netgear.com/support/product/rs600/",
                "https://www.netgear.com/support/product/rs70/",
                "https://www.netgear.com/support/product/rs90/"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T16:17:28.540",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11814"
                }
            ]
        },
        {
            "id": "CVE-2026-11739",
            "vendor": "NETGEAR",
            "product": "MR60",
            "title": "MR60 vulnerability",
            "summary": "A command injection vulnerability in certain affected NETGEAR Nighthawk \ndevices allows a network-adjacent attacker with the ability to intercept\n and modify local network traffic (attacker in the middle) to compromise\n the confidentiality and integrity of the affected device.",
            "updated_at": "2026-09-09T02:59:22.507",
            "published_at": "2026-08-11T16:17:28.260",
            "cvss": 4.9,
            "cvss_vector": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before V1.1.8.142 (custom); before V1.0.4.48 (custom); before V1.0.2.46 (custom); before V1.0.17.142 (custom); before V1.0.11.148 (custom); before V1.1.6.36 (custom); before V1.2.14.110 (custom); before V1.0.9.6 (custom); before V1.1.0.22 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 26,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-78",
            "what_happened": "A command injection vulnerability in certain affected NETGEAR Nighthawk \ndevices allows a network-adjacent attacker with the ability to intercept\n and modify local network traffic (attacker in the middle) to compromise\n the confidentiality and integrity of the affected device.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory",
                "https://www.netgear.com/support/product/mr60/",
                "https://www.netgear.com/support/product/mr70/",
                "https://www.netgear.com/support/product/mr90/",
                "https://www.netgear.com/support/product/ms60/",
                "https://www.netgear.com/support/product/ms70/",
                "https://www.netgear.com/support/product/ms90/",
                "https://www.netgear.com/support/product/rax20/",
                "https://www.netgear.com/support/product/rax200/",
                "https://www.netgear.com/support/product/rax35/",
                "https://www.netgear.com/support/product/rax35v2/",
                "https://www.netgear.com/support/product/rax41/",
                "https://www.netgear.com/support/product/rax41v2/",
                "https://www.netgear.com/support/product/rax42/",
                "https://www.netgear.com/support/product/rax42v2/",
                "https://www.netgear.com/support/product/rax43/",
                "https://www.netgear.com/support/product/rax43v2/",
                "https://www.netgear.com/support/product/rax45/",
                "https://www.netgear.com/support/product/rax49s/",
                "https://www.netgear.com/support/product/rax50/",
                "https://www.netgear.com/support/product/rax50v2/",
                "https://www.netgear.com/support/product/rax80/",
                "https://www.netgear.com/support/product/raxe500/",
                "https://www.netgear.com/support/product/rs700/",
                "https://www.netgear.com/support/product/xr1000/",
                "https://www.netgear.com/support/product/xr1000v2/"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T16:17:28.260",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11739"
                }
            ]
        },
        {
            "id": "CVE-2026-11738",
            "vendor": "NETGEAR",
            "product": "R7000",
            "title": "R7000 vulnerability",
            "summary": "Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.",
            "updated_at": "2026-09-09T02:59:45.560",
            "published_at": "2026-08-11T16:17:28.120",
            "cvss": 4.3,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before * (custom); before V1.2.14.114 (custom); before V1.0.7.66 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory",
                "https://www.netgear.com/support/product/r7000/",
                "https://www.netgear.com/support/product/raxe500/",
                "https://www.netgear.com/support/product/rs700/"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T16:17:28.120",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11738"
                }
            ]
        },
        {
            "id": "CVE-2026-11737",
            "vendor": "NETGEAR",
            "product": "RAX20",
            "title": "RAX20 vulnerability",
            "summary": "Insufficient input validation vulnerability in the listed \nNETGEAR models allows authenticated administrators connected to the \nlocal network to make unauthorized modification to the device software and \nfunctionality.",
            "updated_at": "2026-09-09T02:59:15.787",
            "published_at": "2026-08-11T16:17:27.917",
            "cvss": 4.3,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before V1.0.18.144 (custom); before V1.1.6.36 (custom); before V1.0.17.142 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "Insufficient input validation vulnerability in the listed \nNETGEAR models allows authenticated administrators connected to the \nlocal network to make unauthorized modification to the device software and \nfunctionality.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory",
                "https://www.netgear.com/support/product/rax20/",
                "https://www.netgear.com/support/product/rax41/",
                "https://www.netgear.com/support/product/rax41v2/",
                "https://www.netgear.com/support/product/rax42/",
                "https://www.netgear.com/support/product/rax42v2/",
                "https://www.netgear.com/support/product/rax43/",
                "https://www.netgear.com/support/product/rax43v2/",
                "https://www.netgear.com/support/product/rax45/",
                "https://www.netgear.com/support/product/rax49s/",
                "https://www.netgear.com/support/product/rax50/",
                "https://www.netgear.com/support/product/rax50v2/"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T16:17:27.917",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11737"
                }
            ]
        },
        {
            "id": "CVE-2026-11736",
            "vendor": "NETGEAR",
            "product": "RAX20",
            "title": "RAX20 vulnerability",
            "summary": "A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.",
            "updated_at": "2026-09-09T02:58:40.000",
            "published_at": "2026-08-11T16:17:27.653",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before * (custom); before V1.0.16.132 (custom); before V1.1.4.28 (custom); before V1.2.14.114 (custom); before V1.1.0.22 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 19,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-20",
            "what_happened": "A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory",
                "https://www.netgear.com/support/product/rax20/",
                "https://www.netgear.com/support/product/rax35v2/",
                "https://www.netgear.com/support/product/rax41/",
                "https://www.netgear.com/support/product/rax41v2/",
                "https://www.netgear.com/support/product/rax42/",
                "https://www.netgear.com/support/product/rax42v2/",
                "https://www.netgear.com/support/product/rax43/",
                "https://www.netgear.com/support/product/rax43v2/",
                "https://www.netgear.com/support/product/rax45/",
                "https://www.netgear.com/support/product/rax49s/",
                "https://www.netgear.com/support/product/rax50/",
                "https://www.netgear.com/support/product/rax50s/",
                "https://www.netgear.com/support/product/rax50v2/",
                "https://www.netgear.com/support/product/rax54sv2/",
                "https://www.netgear.com/support/product/raxe450/",
                "https://www.netgear.com/support/product/raxe500/",
                "https://www.netgear.com/support/product/xr1000/",
                "https://www.netgear.com/support/product/xr1000v2/"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T16:17:27.653",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11736"
                }
            ]
        },
        {
            "id": "CVE-2026-11735",
            "vendor": "NETGEAR",
            "product": "R7000",
            "title": "R7000 vulnerability",
            "summary": "A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.",
            "updated_at": "2026-09-09T02:58:25.340",
            "published_at": "2026-08-11T16:17:27.360",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:L/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before * (custom); before V1.0.16.132 (custom); before V1.1.4.28 (custom); before V1.2.14.114 (custom); before V1.1.0.22 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 20,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-121",
            "what_happened": "A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory",
                "https://www.netgear.com/support/product/r7000/",
                "https://www.netgear.com/support/product/rax20/",
                "https://www.netgear.com/support/product/rax35v2/",
                "https://www.netgear.com/support/product/rax41/",
                "https://www.netgear.com/support/product/rax41v2/",
                "https://www.netgear.com/support/product/rax42/",
                "https://www.netgear.com/support/product/rax42v2/",
                "https://www.netgear.com/support/product/rax43/",
                "https://www.netgear.com/support/product/rax43v2/",
                "https://www.netgear.com/support/product/rax45/",
                "https://www.netgear.com/support/product/rax49s/",
                "https://www.netgear.com/support/product/rax50/",
                "https://www.netgear.com/support/product/rax50s/",
                "https://www.netgear.com/support/product/rax50v2/",
                "https://www.netgear.com/support/product/rax54sv2/",
                "https://www.netgear.com/support/product/raxe450/",
                "https://www.netgear.com/support/product/raxe500/",
                "https://www.netgear.com/support/product/xr1000/",
                "https://www.netgear.com/support/product/xr1000v2/"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T16:17:27.360",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11735"
                }
            ]
        },
        {
            "id": "CVE-2026-11734",
            "vendor": "NETGEAR",
            "product": "MR70",
            "title": "MR70 vulnerability",
            "summary": "A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.",
            "updated_at": "2026-09-09T02:58:58.660",
            "published_at": "2026-08-11T16:17:27.140",
            "cvss": 1.1,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:L/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before V1.0.4.48 (custom); before V1.0.2.46 (custom); before V1.1.6.36 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory",
                "https://www.netgear.com/support/product/mr70/",
                "https://www.netgear.com/support/product/mr90/",
                "https://www.netgear.com/support/product/ms70/",
                "https://www.netgear.com/support/product/ms90/",
                "https://www.netgear.com/support/product/rax41/",
                "https://www.netgear.com/support/product/rax41v2/",
                "https://www.netgear.com/support/product/rax42/",
                "https://www.netgear.com/support/product/rax42v2/",
                "https://www.netgear.com/support/product/rax43/",
                "https://www.netgear.com/support/product/rax43v2/",
                "https://www.netgear.com/support/product/rax49s/",
                "https://www.netgear.com/support/product/rax50/",
                "https://www.netgear.com/support/product/rax50v2/"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T16:17:27.140",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11734"
                }
            ]
        },
        {
            "id": "CVE-2026-11733",
            "vendor": "NETGEAR",
            "product": "RAX41",
            "title": "RAX41 vulnerability",
            "summary": "A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.",
            "updated_at": "2026-09-09T02:59:07.753",
            "published_at": "2026-08-11T16:17:26.917",
            "cvss": 1.1,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before V1.1.6.36 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory",
                "https://www.netgear.com/support/product/rax41/",
                "https://www.netgear.com/support/product/rax41v2/",
                "https://www.netgear.com/support/product/rax42/",
                "https://www.netgear.com/support/product/rax42v2/",
                "https://www.netgear.com/support/product/rax43/",
                "https://www.netgear.com/support/product/rax43v2/",
                "https://www.netgear.com/support/product/rax49s/",
                "https://www.netgear.com/support/product/rax50/",
                "https://www.netgear.com/support/product/rax50v2/"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T16:17:26.917",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11733"
                }
            ]
        },
        {
            "id": "CVE-2026-11729",
            "vendor": "IBM",
            "product": "MQ",
            "title": "MQ vulnerability",
            "summary": "IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code in client applications due to unsafe deserialization that enables JNDI injection attacks.",
            "updated_at": "2026-09-16T04:17:52.520",
            "published_at": "2026-09-15T18:17:12.393",
            "cvss": 8.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.1.0.0 through 9.1.0.37 LTS (semver); 9.2.0.0 through 9.2.0.43 LTS (semver); 9.3.0.0 through 9.3.0.41 LTS (semver); 9.3.0.0 through 9.3.5.1 CD (semver); 9.4.0.0 through 9.4.0.25 LTS (semver); 9.4.0.0 through 9.4.5.1 CD (semver); 10.0.0.0",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-502",
            "what_happened": "IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to execute arbitrary code in client applications due to unsafe deserialization that enables JNDI injection attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7284941"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T18:17:12.393",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11729"
                }
            ]
        },
        {
            "id": "CVE-2026-11728",
            "vendor": "IBM",
            "product": "MQ",
            "title": "MQ vulnerability",
            "summary": "IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker to cause a denial of service or potentially execute arbitrary code in the client due to a heap buffer overflow when receiving messages from a malicious queue manager or through a man-in-the-middle attack.",
            "updated_at": "2026-09-16T04:17:52.090",
            "published_at": "2026-09-15T18:17:12.257",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.1.0.0 through 9.1.0.37 LTS (semver); 9.2.0.0 through 9.2.0.43 LTS (semver); 9.3.0.0 through 9.3.0.41 LTS (semver); 9.3.0.0 through 9.3.5.1 CD (semver); 9.4.0.0 through 9.4.0.25 LTS (semver); 9.4.0.0 through 9.4.5.1 CD (semver); 10.0.0.0",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-787",
            "what_happened": "IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow a remote attacker to cause a denial of service or potentially execute arbitrary code in the client due to a heap buffer overflow when receiving messages from a malicious queue manager or through a man-in-the-middle attack.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7284943"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T18:17:12.257",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11728"
                }
            ]
        },
        {
            "id": "CVE-2026-11586",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "By default, curl automatically responds to WebSocket PING frames. Because curl\nlacks an upper bound on memory allocation for unacknowledged frames, a\nmalicious server can exhaust all available memory by flooding curl with rapid,\nsequential PING messages.",
            "updated_at": "2026-09-15T07:16:25.700",
            "published_at": "2026-07-03T07:16:23.883",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.16.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 0b091328773c64e23f5c4739da74527093c6a5ab through before 849317ff5c5a5e13f50ec3d001e46ddffa77d8a4 (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "By default, curl automatically responds to WebSocket PING frames. Because curl\nlacks an upper bound on memory allocation for unacknowledged frames, a\nmalicious server can exhaust all available memory by flooding curl with rapid,\nsequential PING messages.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3788931"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-11586.html",
                "https://curl.se/docs/CVE-2026-11586.json",
                "https://hackerone.com/reports/3788931"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:23.883",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11586"
                }
            ]
        },
        {
            "id": "CVE-2026-11564",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "libcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup.\n\nAn easy handle that first uses default native CA trust can continue trusting\nthe native platform store after the application switches that same handle to\ncustom CA material for a later transfer.",
            "updated_at": "2026-09-15T07:16:25.530",
            "published_at": "2026-07-03T07:16:23.790",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.17.0 through before 8.20.1 (semver); eefd03c572996e5de4dec4fe295ad6f103e0eefc through before d69bfad3fa3daf5e72331f6870667607828d5891 (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "libcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup.\n\nAn easy handle that first uses default native CA trust can continue trusting\nthe native platform store after the application switches that same handle to\ncustom CA material for a later transfer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3788984"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-11564.html",
                "https://curl.se/docs/CVE-2026-11564.json",
                "https://hackerone.com/reports/3788984"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:23.790",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11564"
                }
            ]
        },
        {
            "id": "CVE-2026-11496",
            "vendor": "edgarrojas",
            "product": "PDF Builder for WooCommerce. Create invoices,packing slips and more",
            "title": "PDF Builder for WooCommerce. Create invoices,packing slips and more vulnerability",
            "summary": "The Woo PDF Invoice Builder plugin (also distributed as \"PDF Builder for WooCommerce\") for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8. This is due to the InspectOrder() AJAX handler (woocommerce-pdf-invoice-ajax.php:513), registered on wp_ajax_rednao_wcpdfinv_inspect_order, performing no capability check and no nonce verification before loading an arbitrary order by the attacker-supplied 'OrderNumber' POST field and serializing its full WC_Order::get_data() and meta to the response. This makes it possible for authenticated attackers with Subscriber-level access and above to read every WooCommerce order on the site — including billing/shipping address, email, phone number, payment method, gateway transaction ID, and order totals — by iterating order IDs.",
            "updated_at": "2026-09-11T04:17:19.807",
            "published_at": "2026-09-11T04:17:19.807",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.0.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The Woo PDF Invoice Builder plugin (also distributed as \"PDF Builder for WooCommerce\") for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8. This is due to the InspectOrder() AJAX handler (woocommerce-pdf-invoice-ajax.php:513), registered on wp_ajax_rednao_wcpdfinv_inspect_order, performing no capability check and no nonce verification before loading an arbitrary order by the attacker-supplied 'OrderNumber' POST field and serializing its full WC_Order::get_data() and meta to the response. This makes it possible for authenticated attackers with Subscriber-level access and above to read every WooCommerce order on the site — including billing/shipping address, email, phone number, payment method, gateway transaction ID, and order totals — by iterating order IDs.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/woo-pdf-invoice-builder/tags/2.0.8/utilities/WCInspector.php#L23",
                "https://plugins.trac.wordpress.org/browser/woo-pdf-invoice-builder/tags/2.0.8/woocommerce-pdf-invoice-ajax.php#L46",
                "https://plugins.trac.wordpress.org/browser/woo-pdf-invoice-builder/tags/2.0.8/woocommerce-pdf-invoice-ajax.php#L513",
                "https://plugins.trac.wordpress.org/browser/woo-pdf-invoice-builder/trunk/woocommerce-pdf-invoice-ajax.php#L513",
                "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3567364%40woo-pdf-invoice-builder%2Ftrunk%2Fwoocommerce-pdf-invoice-ajax.php&old=3544283%40woo-pdf-invoice-builder%2Ftrunk%2Fwoocommerce-pdf-invoice-ajax.php&sfp_email=&sfph_mail=",
                "https://wordpress.org/plugins/woo-pdf-invoice-builder/",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/5e3e7c1a-a9c0-4e92-868c-5785d891cf8f?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T04:17:19.807",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11496"
                }
            ]
        },
        {
            "id": "CVE-2026-11446",
            "vendor": "arraytics",
            "product": "Booktics – Appointment Booking Calendar for Service Businesses",
            "title": "Booktics – Appointment Booking Calendar for Service Businesses vulnerability",
            "summary": "The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.0.23. This is due to the create_order_permission() permission callback on the POST /wp-json/booktics/v1/orders REST route unconditionally returning true, combined with find_and_update_guest() overwriting an existing customer record's stored name, phone, and wp_user_id whenever the caller-supplied email matches, with no proof of ownership. This makes it possible for unauthenticated attackers to overwrite the contact details (name and phone) of any existing customer whose email address they know, poisoning downstream reminder emails, SMS, calendar invites, and CRM data.",
            "updated_at": "2026-09-11T04:17:17.197",
            "published_at": "2026-09-11T04:17:17.197",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.0.23 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.0.23. This is due to the create_order_permission() permission callback on the POST /wp-json/booktics/v1/orders REST route unconditionally returning true, combined with find_and_update_guest() overwriting an existing customer record's stored name, phone, and wp_user_id whenever the caller-supplied email matches, with no proof of ownership. This makes it possible for unauthenticated attackers to overwrite the contact details (name and phone) of any existing customer whose email address they know, poisoning downstream reminder emails, SMS, calendar invites, and CRM data.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/booktics/tags/1.0.18/core/order/controllers/order-controller.php#L172",
                "https://plugins.trac.wordpress.org/browser/booktics/tags/1.0.18/core/order/controllers/order-controller.php#L863",
                "https://plugins.trac.wordpress.org/browser/booktics/tags/1.0.21/core/order/controllers/order-controller.php#L172",
                "https://plugins.trac.wordpress.org/browser/booktics/tags/1.0.21/core/order/controllers/order-controller.php#L885",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/c86956bf-b013-4a84-b77e-8b1007238b27?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T04:17:17.197",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11446"
                }
            ]
        },
        {
            "id": "CVE-2026-11387",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-11387 repository",
            "summary": "SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress; SMS Alert <3.9.6; Unauthenticated Privilege Escalation (Forced Password Reset)",
            "updated_at": "2026-09-08T22:00:00Z",
            "published_at": "2026-09-08T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 47,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · 1beelze/CVE-2026-11387",
                    "author": "1beelze",
                    "first_seen": "2026-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-11387 repository",
                    "summary": "",
                    "url": "https://github.com/1beelze/CVE-2026-11387"
                },
                {
                    "repository": "PoC-in-GitHub · abraxas/CVE-2026-11387-WooCommerce-SMS-OTP",
                    "author": "abraxas",
                    "first_seen": "2026-09-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress; SMS Alert <3.9.6; Unauthenticated Privilege Escalation (Forced Password Reset)",
                    "summary": "SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress; SMS Alert <3.9.6; Unauthenticated Privilege Escalation (Forced Password Reset)",
                    "url": "https://github.com/abraxas/CVE-2026-11387-WooCommerce-SMS-OTP"
                }
            ],
            "references": [
                "https://github.com/1beelze/CVE-2026-11387",
                "https://github.com/abraxas/CVE-2026-11387-WooCommerce-SMS-OTP"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/1beelze/CVE-2026-11387"
                }
            ]
        },
        {
            "id": "CVE-2026-11355",
            "vendor": "designthemes",
            "product": "DT LMS – elearning,  WordPress LMS Plugin",
            "title": "DT LMS – elearning,  WordPress LMS Plugin vulnerability",
            "summary": "The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX handlers (including dtlms_save_poc_settings, dtlms_save_skin_settings, and dtlms_save_options_settings) in versions up to, and including, 1.1. These handlers are registered on the wp_ajax_nopriv_* hook and contain no capability check, no nonce verification, and pass user-supplied data directly to update_option(). This makes it possible for unauthenticated attackers to overwrite arbitrary plugin option values stored in the wp_options table, including Point-of-Contact email configuration and skin/branding settings, which can be used to alter the appearance and behavior of the LMS for all site visitors.",
            "updated_at": "2026-09-12T08:16:22.523",
            "published_at": "2026-09-12T08:16:22.523",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX handlers (including dtlms_save_poc_settings, dtlms_save_skin_settings, and dtlms_save_options_settings) in versions up to, and including, 1.1. These handlers are registered on the wp_ajax_nopriv_* hook and contain no capability check, no nonce verification, and pass user-supplied data directly to update_option(). This makes it possible for unauthenticated attackers to overwrite arbitrary plugin option values stored in the wp_options table, including Point-of-Contact email configuration and skin/branding settings, which can be used to alter the appearance and behavior of the LMS for all site visitors.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/dt-lms-lite/trunk/settings/settings-poc-utils.php#L102",
                "https://plugins.trac.wordpress.org/browser/dt-lms-lite/trunk/settings/settings-poc-utils.php#L97",
                "https://plugins.trac.wordpress.org/browser/dt-lms-lite/trunk/settings/settings-utils.php#L15",
                "https://plugins.trac.wordpress.org/browser/dt-lms-lite/trunk/settings/settings-utils.php#L53",
                "https://plugins.trac.wordpress.org/browser/dt-lms-lite/trunk/settings/settings-utils.php#L59",
                "https://plugins.trac.wordpress.org/changeset?reponame=&old=3585901%40dt-lms-lite&new=3585901%40dt-lms-lite",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/fe5bd645-0707-43ce-9316-d52f60035754?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T08:16:22.523",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11355"
                }
            ]
        },
        {
            "id": "CVE-2026-11352",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server\nto trigger a remote denial of service against a curl or libcurl client.\nBecause the helper function discards zero-length UDP datagrams before counting\nthem toward the per-call packet budget, a connected QUIC peer can continuously\nstream empty datagrams to indefinitely stall the client.",
            "updated_at": "2026-09-15T07:16:25.353",
            "published_at": "2026-07-03T07:16:23.693",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.18.0 through before 8.20.1 (semver); 6a3d0b6d631d5e9bec797306b5b41a9f440a088d through before 56eca2afb4806f1032872fa97d1834b3c1385276 (git); 8.20.0; 8.19.0; 8.18.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-835",
            "what_happened": "An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server\nto trigger a remote denial of service against a curl or libcurl client.\nBecause the helper function discards zero-length UDP datagrams before counting\nthem toward the per-call packet budget, a connected QUIC peer can continuously\nstream empty datagrams to indefinitely stall the client.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3783438"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-11352.html",
                "https://curl.se/docs/CVE-2026-11352.json",
                "https://hackerone.com/reports/3783438"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:23.693",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11352"
                }
            ]
        },
        {
            "id": "CVE-2026-11332",
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
            "title": "Red Hat Ansible Automation Platform 2.5 for RHEL 8 vulnerability",
            "summary": "A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.",
            "updated_at": "2026-09-15T12:16:56.910",
            "published_at": "2026-06-05T09:16:26.070",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-88",
            "what_happened": "A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:42079",
                "https://access.redhat.com/errata/RHSA-2026:42080",
                "https://access.redhat.com/errata/RHSA-2026:46836",
                "https://access.redhat.com/errata/RHSA-2026:50340",
                "https://access.redhat.com/errata/RHSA-2026:50344",
                "https://access.redhat.com/errata/RHSA-2026:50357",
                "https://access.redhat.com/errata/RHSA-2026:50479",
                "https://access.redhat.com/errata/RHSA-2026:57148",
                "https://access.redhat.com/errata/RHSA-2026:57149",
                "https://access.redhat.com/errata/RHSA-2026:63385",
                "https://access.redhat.com/errata/RHSA-2026:63386",
                "https://access.redhat.com/errata/RHSA-2026:63387",
                "https://access.redhat.com/errata/RHSA-2026:66248",
                "https://access.redhat.com/errata/RHSA-2026:67465",
                "https://access.redhat.com/errata/RHSA-2026:67466",
                "https://access.redhat.com/errata/RHSA-2026:67467",
                "https://access.redhat.com/security/cve/CVE-2026-11332",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2485379",
                "https://github.com/ansible/ansible",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11332.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-05T09:16:26.070",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-11332"
                }
            ]
        },
        {
            "id": "CVE-2026-11057",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-5281-CVE-2026-11057-fullchain",
            "summary": "Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
            "updated_at": "2026-08-26T08:07:16Z",
            "published_at": "2026-08-26T08:07:16Z",
            "cvss": 6.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 94,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-457",
            "what_happened": "Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · jaf0rk/CVE-2026-5281-CVE-2026-11057-fullchain",
                    "author": "jaf0rk",
                    "first_seen": "2026-08-25",
                    "last_seen": "2026-08-26T08:07:16Z",
                    "pushed_at": "2026-08-26T08:03:18Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "HTML",
                    "stars": 1,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-5281-CVE-2026-11057-fullchain",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/jaf0rk/CVE-2026-5281-CVE-2026-11057-fullchain",
                    "cvss": 6.5,
                    "severity": "MEDIUM",
                    "cve_description": "Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-457",
                    "kev": false,
                    "epss": 0.0025,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-06-04",
                    "cve_status": "Analyzed"
                }
            ],
            "references": [
                "https://github.com/jaf0rk/CVE-2026-5281-CVE-2026-11057-fullchain"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T08:07:16Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/jaf0rk/CVE-2026-5281-CVE-2026-11057-fullchain"
                }
            ],
            "epss": 0.0025,
            "severity": "MEDIUM",
            "metadata_source": "CNA",
            "cve_status": "Analyzed",
            "cve_published_at": "2026-06-04",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2026-10840",
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Builds 1.7.3",
            "title": "Red Hat OpenShift Builds 1.7.3 vulnerability",
            "summary": "A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secrets including the default ingress controller certificate.",
            "updated_at": "2026-09-06T02:17:18.100",
            "published_at": "2026-06-04T12:16:24.813",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-732",
            "what_happened": "A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete other tenants' Workload objects, or induce cert-manager to overwrite TLS Secrets including the default ingress controller certificate.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:36648",
                "https://access.redhat.com/errata/RHSA-2026:41036",
                "https://access.redhat.com/security/cve/CVE-2026-10840",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2484720",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10840.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-04T12:16:24.813",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10840"
                }
            ]
        },
        {
            "id": "CVE-2026-10536",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation.",
            "updated_at": "2026-09-15T07:16:25.137",
            "published_at": "2026-07-03T07:16:23.563",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.88.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 71b7e0161032927cdfb4e75ea40f65b8898b3956 through before bfbff7852f050232edd3e5ca5c6bf2021c340f5a (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A use-after-free vulnerability exists in libcurl when an application\nconfigures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or\n`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and\nfinally terminates the handle with `curl_easy_cleanup()`. During this final\ncleanup phase, libcurl attempts to access and modify an internal structure\nthat was already freed during the reset operation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3751697"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-10536.html",
                "https://curl.se/docs/CVE-2026-10536.json",
                "https://hackerone.com/reports/3751697"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:23.563",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10536"
                }
            ]
        },
        {
            "id": "CVE-2026-10196",
            "vendor": "getwpfunnels",
            "product": "Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails",
            "title": "Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails vulnerability",
            "summary": "The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code on the server. The vulnerability was partially patched in version 1.23.1.",
            "updated_at": "2026-09-05T12:16:46.790",
            "published_at": "2026-09-05T12:16:46.790",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.31.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code on the server. The vulnerability was partially patched in version 1.23.1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/mail-mint/tags/1.21.0/app/API/Actions/Frontend/FormAction.php#L59",
                "https://plugins.trac.wordpress.org/browser/mail-mint/tags/1.21.0/app/Database/models/ContactModel.php#L460",
                "https://plugins.trac.wordpress.org/browser/mail-mint/tags/1.21.0/vendor/posthog/posthog-php/lib/Consumer/ForkCurl.php#L96",
                "https://plugins.trac.wordpress.org/browser/mail-mint/trunk/app/API/Actions/Frontend/FormAction.php#L59",
                "https://plugins.trac.wordpress.org/browser/mail-mint/trunk/app/Database/models/ContactModel.php#L460",
                "https://plugins.trac.wordpress.org/browser/mail-mint/trunk/vendor/posthog/posthog-php/lib/Consumer/ForkCurl.php#L96",
                "https://plugins.trac.wordpress.org/changeset/3545065/",
                "https://plugins.trac.wordpress.org/changeset/3675453/",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/76c073d9-9572-43e4-82eb-49adf678535b?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:16:46.790",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10196"
                }
            ]
        },
        {
            "id": "CVE-2026-10148",
            "vendor": "melograno",
            "product": "Booking for Appointments and Events Calendar – Amelia",
            "title": "Booking for Appointments and Events Calendar – Amelia vulnerability",
            "summary": "The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of classes. This makes it possible for authenticated attackers, with Contributor-level access and above who can use Elementor, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 2.4.8.",
            "updated_at": "2026-09-12T13:16:50.193",
            "published_at": "2026-09-12T13:16:50.193",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.4.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and including 2.4.9. This is due to insufficient input sanitization and output escaping on the 'load_manually' parameter in the render() methods of classes. This makes it possible for authenticated attackers, with Contributor-level access and above who can use Elementor, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 2.4.8.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/ameliabooking/tags/2.2.1/src/Infrastructure/WP/Elementor/AmeliaEventsCalendarBookingElementorWidget.php#L186",
                "https://plugins.trac.wordpress.org/browser/ameliabooking/tags/2.2.1/src/Infrastructure/WP/Elementor/AmeliaEventsElementorWidget.php#L134",
                "https://plugins.trac.wordpress.org/browser/ameliabooking/tags/2.2.1/src/Infrastructure/WP/Elementor/AmeliaEventsListBookingElementorWidget.php#L247",
                "https://plugins.trac.wordpress.org/browser/ameliabooking/tags/2.2.1/src/Infrastructure/WP/Elementor/AmeliaStepBookingElementorWidget.php#L200",
                "https://plugins.trac.wordpress.org/browser/ameliabooking/tags/2.2.1/src/Infrastructure/WP/Elementor/AmeliaStepBookingElementorWidget.php#L226",
                "https://plugins.trac.wordpress.org/browser/ameliabooking/trunk/src/Infrastructure/WP/Elementor/AmeliaEventsCalendarBookingElementorWidget.php#L186",
                "https://plugins.trac.wordpress.org/browser/ameliabooking/trunk/src/Infrastructure/WP/Elementor/AmeliaEventsElementorWidget.php#L134",
                "https://plugins.trac.wordpress.org/browser/ameliabooking/trunk/src/Infrastructure/WP/Elementor/AmeliaEventsListBookingElementorWidget.php#L247",
                "https://plugins.trac.wordpress.org/browser/ameliabooking/trunk/src/Infrastructure/WP/Elementor/AmeliaStepBookingElementorWidget.php#L200",
                "https://plugins.trac.wordpress.org/browser/ameliabooking/trunk/src/Infrastructure/WP/Elementor/AmeliaStepBookingElementorWidget.php#L226",
                "https://plugins.trac.wordpress.org/changeset/3657136/",
                "https://plugins.trac.wordpress.org/changeset/3687762/",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/06ec5c60-169c-4bbb-92bf-802805d46c62?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T13:16:50.193",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10148"
                }
            ]
        },
        {
            "id": "CVE-2026-10090",
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Management for Kubernetes 2.11",
            "title": "Red Hat Advanced Cluster Management for Kubernetes 2.11 vulnerability",
            "summary": "A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped \"edit\" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies the Helm chart contents with its own elevated authority, without verifying whether the subscription creator holds the \"open-cluster-management:subscription-admin\" role and without restricting applied resources to the subscription namespace. This allows the attacker to include cluster-scoped resources in the Helm chart, such as a ClusterRoleBinding granting the attacker's ServiceAccount the \"cluster-admin\" ClusterRole. Successful exploitation results in full cluster-admin privilege escalation. This contradicts the ACM documentation which states that non-subscription-admin users should have resources deployed into the subscription namespace only.",
            "updated_at": "2026-09-05T15:17:28.010",
            "published_at": "2026-08-05T09:18:14.667",
            "cvss": 9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-267",
            "what_happened": "A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped \"edit\" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a Subscription resource referencing it. The app-subscription controller fetches and applies the Helm chart contents with its own elevated authority, without verifying whether the subscription creator holds the \"open-cluster-management:subscription-admin\" role and without restricting applied resources to the subscription namespace. This allows the attacker to include cluster-scoped resources in the Helm chart, such as a ClusterRoleBinding granting the attacker's ServiceAccount the \"cluster-admin\" ClusterRole. Successful exploitation results in full cluster-admin privilege escalation. This contradicts the ACM documentation which states that non-subscription-admin users should have resources deployed into the subscription namespace only.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:60386",
                "https://access.redhat.com/errata/RHSA-2026:60387",
                "https://access.redhat.com/errata/RHSA-2026:60388",
                "https://access.redhat.com/errata/RHSA-2026:60389",
                "https://access.redhat.com/errata/RHSA-2026:60390",
                "https://access.redhat.com/errata/RHSA-2026:60391",
                "https://access.redhat.com/security/cve/CVE-2026-10090",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2483292"
            ],
            "timeline": [
                {
                    "at": "2026-08-05T09:18:14.667",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10090"
                }
            ]
        },
        {
            "id": "CVE-2026-10059",
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1",
            "title": "multicluster engine for Kubernetes 2.1 vulnerability",
            "summary": "A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.",
            "updated_at": "2026-09-07T19:17:25.673",
            "published_at": "2026-08-05T09:18:13.720",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a ServiceAccount with cluster-wide administrative authority. This leads to a privilege escalation, allowing the tenant administrator to gain full control over the cluster.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:59556",
                "https://access.redhat.com/errata/RHSA-2026:59557",
                "https://access.redhat.com/errata/RHSA-2026:59558",
                "https://access.redhat.com/errata/RHSA-2026:59559",
                "https://access.redhat.com/errata/RHSA-2026:59579",
                "https://access.redhat.com/security/cve/CVE-2026-10059",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2483187"
            ],
            "timeline": [
                {
                    "at": "2026-08-05T09:18:13.720",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10059"
                }
            ]
        },
        {
            "id": "CVE-2026-10031",
            "vendor": "drakkan",
            "product": "SFTPGo",
            "title": "SFTPGo vulnerability",
            "summary": "SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link's directory permissions rather than the dereferenced target's directory permissions.",
            "updated_at": "2026-09-09T20:26:18.573",
            "published_at": "2026-07-30T23:16:51.347",
            "cvss": 2.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.7.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-863",
            "what_happened": "SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions are denied. Attackers can exploit the create_symlinks permission combined with read and write access in one directory to read or modify files in restricted directories, as operations are authorized against the link's directory permissions rather than the dereferenced target's directory permissions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/drakkan/sftpgo",
                "https://github.com/drakkan/sftpgo/releases/tag/v2.7.4",
                "https://github.com/drakkan/sftpgo/security/advisories/GHSA-fj9v-mxr3-w75w",
                "https://www.vulncheck.com/advisories/sftpgo-permission-bypass-via-symbolic-link-creation"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T23:16:51.347",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10031"
                }
            ]
        },
        {
            "id": "CVE-2026-9833",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-9833",
            "summary": "Reflected XSS in Tag Groups WordPress plugin before 2.2.0 via unescaped AJAX parameter.",
            "updated_at": "2026-09-11T10:00:28Z",
            "published_at": "2026-09-11T10:00:28Z",
            "cvss": 7.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 34,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Reflected XSS in Tag Groups WordPress plugin before 2.2.0 via unescaped AJAX parameter.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T15:07:04+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2026-9833 exploit",
                    "summary": "Exploit for CVE-2026-9833. CVSS 7.1.",
                    "cvss": 7.1,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AJ2108-CVE-2026-9833"
                },
                {
                    "title": "Exploit for CVE-2026-9833",
                    "summary": "Reflected XSS in Tag Groups WordPress plugin before 2.2.0 via unescaped AJAX parameter.",
                    "what_happened": "Reflected XSS in Tag Groups WordPress plugin before 2.2.0 via unescaped AJAX parameter.",
                    "cvss": 7.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-79",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AJ2108-CVE-2026-9833",
                        "https://kitploit.com/zh/tools/github/aj2108/cve-2026-9833/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-11T12:00:28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/aj2108/cve-2026-9833/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AJ2108-CVE-2026-9833",
                "https://kitploit.com/zh/tools/github/aj2108/cve-2026-9833/"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T10:00:28Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AJ2108-CVE-2026-9833"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
        },
        {
            "id": "CVE-2026-9830",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-9830 Proof of Concept",
            "summary": "CVE-2026-9830 Proof of Concept",
            "updated_at": "2026-08-26T12:56:07Z",
            "published_at": "2026-08-26T12:56:07Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 191,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · opaxial/CVE-2026-9830",
                    "author": "opaxial",
                    "first_seen": "2026-08-15",
                    "last_seen": "2026-08-26T12:56:07Z",
                    "pushed_at": "2026-08-20T21:56:15Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "PoC",
                    "language": "Python",
                    "stars": 343,
                    "forks": 5,
                    "topics": [
                        "cve",
                        "cve-2026-9830",
                        "cvss",
                        "exploit",
                        "exploit-db",
                        "latest",
                        "poc",
                        "proof-of-concept"
                    ],
                    "title": "CVE-2026-9830 Proof of Concept",
                    "repository_description": "CVE-2026-9830 Proof of Concept",
                    "summary": "CVE-2026-9830 Proof of Concept",
                    "source": "CVE-Intel",
                    "url": "https://github.com/opaxial/CVE-2026-9830"
                },
                {
                    "repository": "CVE-Intel · ChPratik/CVE-2026-9830",
                    "author": "ChPratik",
                    "first_seen": "2026-07-27",
                    "last_seen": "2026-07-27T16:42:49Z",
                    "pushed_at": "2026-07-27T16:39:18Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": false,
                    "artifact_type": "Exploit",
                    "language": "",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.",
                    "repository_description": "The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.",
                    "summary": "The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/ChPratik/CVE-2026-9830"
                }
            ],
            "references": [
                "https://github.com/opaxial/CVE-2026-9830",
                "https://github.com/ChPratik/CVE-2026-9830"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T12:56:07Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/opaxial/CVE-2026-9830"
                }
            ]
        },
        {
            "id": "CVE-2026-9804",
            "vendor": "Red Hat",
            "product": "Red Hat Container Native Virtualization 4.17",
            "title": "Red Hat Container Native Virtualization 4.17 vulnerability",
            "summary": "A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.",
            "updated_at": "2026-09-09T15:17:28.217",
            "published_at": "2026-05-28T09:16:49.500",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-59",
            "what_happened": "A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (PVC) that points outside its designated mount root, the attacker can read arbitrary files from the exporter pod's filesystem. This leads to information disclosure, potentially exposing sensitive data.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:27903",
                "https://access.redhat.com/errata/RHSA-2026:27913",
                "https://access.redhat.com/errata/RHSA-2026:27914",
                "https://access.redhat.com/errata/RHSA-2026:27983",
                "https://access.redhat.com/errata/RHSA-2026:28002",
                "https://access.redhat.com/security/cve/CVE-2026-9804",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2482487",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9804.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-28T09:16:49.500",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9804"
                }
            ]
        },
        {
            "id": "CVE-2026-9800",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.4",
            "title": "Red Hat build of Keycloak 26.4 vulnerability",
            "summary": "A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.",
            "updated_at": "2026-09-13T01:16:38.340",
            "published_at": "2026-06-25T17:17:04.180",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "26.4 through before 26.4.13; 26.6 through 26.6.4",
            "fixed": "See vendor advisory",
            "source_count": 19,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-1025",
            "what_happened": "A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorization policies, including role, scope, and User-Managed Access (UMA) permission checks. By including the configured access-denied page path within a request URL, either as a path segment or a query parameter, an attacker can gain unauthorized access to protected resources.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:30049",
                "https://access.redhat.com/errata/RHSA-2026:30050",
                "https://access.redhat.com/errata/RHSA-2026:30083",
                "https://access.redhat.com/errata/RHSA-2026:30084",
                "https://access.redhat.com/errata/RHSA-2026:36002",
                "https://access.redhat.com/errata/RHSA-2026:36013",
                "https://access.redhat.com/errata/RHSA-2026:50846",
                "https://access.redhat.com/errata/RHSA-2026:50847",
                "https://access.redhat.com/security/cve/CVE-2026-9800",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2482472",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9800.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-25T17:17:04.180",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9800"
                }
            ]
        },
        {
            "id": "CVE-2026-9796",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.6",
            "title": "Red Hat build of Keycloak 26.6 vulnerability",
            "summary": "A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots.",
            "updated_at": "2026-09-15T12:17:55.960",
            "published_at": "2026-05-28T05:16:41.153",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-367",
            "what_happened": "A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. The composite role relationship persists even after the attacker's own permissions are revoked and across system reboots.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:56523",
                "https://access.redhat.com/errata/RHSA-2026:56524",
                "https://access.redhat.com/security/cve/CVE-2026-9796",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2482464"
            ],
            "timeline": [
                {
                    "at": "2026-05-28T05:16:41.153",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9796"
                }
            ]
        },
        {
            "id": "CVE-2026-9736",
            "vendor": "IBM",
            "product": "Netezza Software",
            "title": "Netezza Software vulnerability",
            "summary": "IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.",
            "updated_at": "2026-09-05T03:17:24.683",
            "published_at": "2026-09-03T21:17:24.560",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "11.3.0.3 through Interim Fix 002 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-117",
            "what_happened": "IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7284359"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T21:17:24.560",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9736"
                }
            ]
        },
        {
            "id": "CVE-2026-9586",
            "vendor": "Sangoma",
            "product": "Switchvox",
            "title": "Sangoma Switchvox SQL Injection Vulnerability",
            "summary": "Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 50,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-9547",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.",
            "updated_at": "2026-09-15T07:16:35.310",
            "published_at": "2026-07-03T07:16:25.990",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.69.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 507cf6a13db0375eadd4655b4c64710db29e9cf2 through before 0b8dbbc63c98777e4584cb9fbd71df3464008ad1 (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-297",
            "what_happened": "When a libcurl-based application performs transfers via `SCP://` or `SFTP://`\nand utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an\nuntrusted server. This vulnerability occurs when a server presents a host key\ntype that does not match the specific key type already recorded for that host\nin the `known_hosts` file. Instead of rejecting the mismatch, the callback\nmechanism fails to properly enforce the restriction, allowing the connection\nto succeed without warning and risking a potential man-in-the-middle attack.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3751712"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-9547.html",
                "https://curl.se/docs/CVE-2026-9547.json",
                "https://hackerone.com/reports/3751712"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:25.990",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9547"
                }
            ]
        },
        {
            "id": "CVE-2026-9546",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "A vulnerability in libcurl caused the HTTP `Referer:` header to persist even\nwhen explicitly cleared. While the documentation states that passing NULL to\n`CURLOPT_REFERER` suppresses the header, the option failed to clear the\ninternal state. As a result, the previous referrer string was erroneously\nreused and sent in subsequent requests, potentially leaking sensitive\ninformation to unintended servers.",
            "updated_at": "2026-09-15T07:16:35.130",
            "published_at": "2026-07-03T07:16:25.893",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.18.0 through before 8.20.1 (semver); 2cb868242dc2ac9cd52ee64987ef51d5964a56f9 through before 862e8a74a84478d82973471b4f49dc2746c1780e (git); 8.20.0; 8.19.0; 8.18.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "A vulnerability in libcurl caused the HTTP `Referer:` header to persist even\nwhen explicitly cleared. While the documentation states that passing NULL to\n`CURLOPT_REFERER` suppresses the header, the option failed to clear the\ninternal state. As a result, the previous referrer string was erroneously\nreused and sent in subsequent requests, potentially leaking sensitive\ninformation to unintended servers.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3754343"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-9546.html",
                "https://curl.se/docs/CVE-2026-9546.json",
                "https://hackerone.com/reports/3754343"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:25.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9546"
                }
            ]
        },
        {
            "id": "CVE-2026-9545",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation.",
            "updated_at": "2026-09-15T07:16:34.947",
            "published_at": "2026-07-03T07:16:25.807",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.11.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 962097b8dd44ed5b9e7984bc1cdffdbdd566857f through before 7b9613fa9b1a5e04301a3920eef58e8138dad05e (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "In this scenario, libcurl first uses a proper HTTP/3 server for the initial\ntransfers, and when it makes a second transfer to the same site it has been\nreplaced by the attacker's impostor machine - without a valid certificate.\n\nWhen libcurl returns to the hostname the second time with a cached SSL session\n(`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the\n`CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might\nsend off the second request's bytes on that new connection *before* enforcing\nthe certificate verification failure. Potentially leaking sensitive\ninformation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3752888"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-9545.html",
                "https://curl.se/docs/CVE-2026-9545.json",
                "https://hackerone.com/reports/3752888"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:25.807",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9545"
                }
            ]
        },
        {
            "id": "CVE-2026-9323",
            "vendor": "urwid",
            "product": "urwid",
            "title": "urwid vulnerability",
            "summary": "The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Python's Mersenne Twister PRNG, which is not cryptographically secure. Each call consumes approximately 30 bits of PRNG state, and the Mersenne Twister internal state is approximately 19,937 bits, so an attacker who observes approximately 334 session IDs (for example via the X-Urwid-ID HTTP response header) can fully reconstruct the internal state and predict all past and future session IDs (Path B). The same identifier is also used as the filename of a FIFO created in the world-listable /tmp directory (for example /tmp/urwid375487765176907690.in), so any local user on the host can list /tmp to enumerate active session tokens directly (Path A). With a valid session ID, an attacker can read the victim's terminal screen via the polling endpoint, inject keystrokes into the victim's session (yielding OS-level code execution with the session owner's privileges if the session runs a shell), and inject exit sequences or flood the FIFO to terminate or crash the session. A prior Bandit S311 warning on this usage was suppressed with # noqa: S311 rather than fixed",
            "updated_at": "2026-09-15T08:17:07.543",
            "published_at": "2026-07-18T14:17:12.170",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 24acd12 (git)",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-338",
            "what_happened": "The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Python's Mersenne Twister PRNG, which is not cryptographically secure. Each call consumes approximately 30 bits of PRNG state, and the Mersenne Twister internal state is approximately 19,937 bits, so an attacker who observes approximately 334 session IDs (for example via the X-Urwid-ID HTTP response header) can fully reconstruct the internal state and predict all past and future session IDs (Path B). The same identifier is also used as the filename of a FIFO created in the world-listable /tmp directory (for example /tmp/urwid375487765176907690.in), so any local user on the host can list /tmp to enumerate active session tokens directly (Path A). With a valid session ID, an attacker can read the victim's terminal screen via the polling endpoint, inject keystrokes into the victim's session (yielding OS-level code execution with the session owner's privileges if the session runs a shell), and inject exit sequences or flood the FIFO to terminate or crash the session. A prior Bandit S311 warning on this usage was suppressed with # noqa: S311 rather than fixed",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/urwid/urwid",
                "https://github.com/urwid/urwid/commit/24acd12f0d0598036d0d577f2ee63e4a27b4a3d9",
                "https://github.com/urwid/urwid/issues/1127",
                "https://github.com/urwid/urwid/pull/1128",
                "https://github.com/urwid/urwid/security/advisories/GHSA-rjwp-g85x-gmjv",
                "https://www.vulncheck.com/advisories/insecure-prng-and-information-exposure-in-urwid-web-display-backend",
                "https://lists.debian.org/debian-lts-announce/2026/09/msg00015.html"
            ],
            "timeline": [
                {
                    "at": "2026-07-18T14:17:12.170",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9323"
                }
            ]
        },
        {
            "id": "CVE-2026-9277",
            "vendor": "Unknown vendor",
            "product": "shell-quote",
            "title": "shell-quote vulnerability",
            "summary": "shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\\n, \\r, U+2028, U+2029). A line terminator in `.op` therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is reachable in two ways: (1) direct construction of `{ op: '...\\n...' }` from external input, and (2) via `parse(cmd, envFn)` when `envFn` returns object tokens whose `.op` is attacker-influenced. Both are documented API surface. Fixed by replacing the per-character escape with strict shape validation: `.op` must match the parser's control-operator allowlist; `{ op: 'glob', pattern }` validates `pattern` and forbids line terminators; `{ comment }` validates `comment` and forbids line terminators; any other object shape throws `TypeError`.",
            "updated_at": "2026-09-14T13:19:33.133",
            "published_at": "2026-05-22T14:16:30.330",
            "cvss": 9.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.1.0 through before 1.8.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, which in JavaScript does not match line terminators (\\n, \\r, U+2028, U+2029). A line terminator in `.op` therefore passed through unescaped into the output; POSIX shells treat a literal newline as a command separator, so any content after it would execute as a second command. The vulnerable code path is reachable in two ways: (1) direct construction of `{ op: '...\\n...' }` from external input, and (2) via `parse(cmd, envFn)` when `envFn` returns object tokens whose `.op` is attacker-influenced. Both are documented API surface. Fixed by replacing the per-character escape with strict shape validation: `.op` must match the parser's control-operator allowlist; `{ op: 'glob', pattern }` validates `pattern` and forbids line terminators; `{ comment }` validates `comment` and forbids line terminators; any other object shape throws `TypeError`.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ljharb/shell-quote",
                "https://github.com/ljharb/shell-quote/commit/1518179",
                "https://github.com/ljharb/shell-quote/security/advisories/GHSA-w7jw-789q-3m8p",
                "https://www.npmjs.com/package/shell-quote",
                "http://www.openwall.com/lists/oss-security/2026/05/23/2",
                "https://access.redhat.com/errata/RHSA-2026:26072",
                "https://access.redhat.com/errata/RHSA-2026:26077",
                "https://access.redhat.com/errata/RHSA-2026:26079",
                "https://access.redhat.com/errata/RHSA-2026:26080",
                "https://access.redhat.com/errata/RHSA-2026:26090",
                "https://access.redhat.com/errata/RHSA-2026:26225",
                "https://access.redhat.com/errata/RHSA-2026:28010",
                "https://access.redhat.com/errata/RHSA-2026:28571",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:29795",
                "https://access.redhat.com/errata/RHSA-2026:29834",
                "https://access.redhat.com/errata/RHSA-2026:30076",
                "https://access.redhat.com/errata/RHSA-2026:33574",
                "https://access.redhat.com/errata/RHSA-2026:33683",
                "https://access.redhat.com/errata/RHSA-2026:34342",
                "https://access.redhat.com/errata/RHSA-2026:34791",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:40765",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:42796",
                "https://access.redhat.com/errata/RHSA-2026:44237",
                "https://access.redhat.com/errata/RHSA-2026:44263",
                "https://access.redhat.com/errata/RHSA-2026:44267",
                "https://access.redhat.com/errata/RHSA-2026:48699",
                "https://access.redhat.com/errata/RHSA-2026:50850",
                "https://access.redhat.com/errata/RHSA-2026:56854",
                "https://access.redhat.com/errata/RHSA-2026:56912",
                "https://access.redhat.com/errata/RHSA-2026:60023",
                "https://access.redhat.com/errata/RHSA-2026:62260",
                "https://access.redhat.com/errata/RHSA-2026:62410",
                "https://access.redhat.com/security/cve/CVE-2026-9277",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2480741",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-9277.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-22T14:16:30.330",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9277"
                }
            ]
        },
        {
            "id": "CVE-2026-9214",
            "vendor": "NETGEAR",
            "product": "R7000",
            "title": "R7000 vulnerability",
            "summary": "Insufficient input validation vulnerability in the NETGEAR R7000 models\n allows authenticated administrators connected to the local network to \nmake unauthorized modification to router software and functionality.",
            "updated_at": "2026-09-09T02:59:29.410",
            "published_at": "2026-08-11T16:17:40.490",
            "cvss": 4.3,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "V1.0.12.216 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "Insufficient input validation vulnerability in the NETGEAR R7000 models\n allows authenticated administrators connected to the local network to \nmake unauthorized modification to router software and functionality.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://kb.netgear.com/000070887/August-2026-NETGEAR-Security-Advisory",
                "https://www.netgear.com/support/product/r7000"
            ],
            "timeline": [
                {
                    "at": "2026-08-11T16:17:40.490",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9214"
                }
            ]
        },
        {
            "id": "CVE-2026-9198",
            "vendor": "IBM",
            "product": "Langflow",
            "title": "IBM Langflow Code Injection Vulnerability",
            "summary": "Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 147,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52675",
                    "author": "Richard Howe",
                    "first_seen": "2026-09-02",
                    "confidence": "High",
                    "title": "Langflow 1.10.0 - RCE",
                    "summary": "Langflow 1.10.0 - RCE",
                    "url": "https://www.exploit-db.com/exploits/52675",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52675"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-9176",
            "vendor": "IBM",
            "product": "WebSphere Application Server",
            "title": "WebSphere Application Server vulnerability",
            "summary": "IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.",
            "updated_at": "2026-09-12T04:16:45.190",
            "published_at": "2026-09-10T21:17:54.220",
            "cvss": 6.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.0; 8.5",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-94",
            "what_happened": "IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected resources.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ibm.com/support/pages/node/7286610"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T21:17:54.220",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9176"
                }
            ]
        },
        {
            "id": "CVE-2026-9165",
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Security 4.9",
            "title": "Red Hat Advanced Cluster Security 4.9 vulnerability",
            "summary": "A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.",
            "updated_at": "2026-09-08T08:17:13.800",
            "published_at": "2026-07-06T09:16:39.400",
            "cvss": 7.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:36207",
                "https://access.redhat.com/errata/RHSA-2026:36319",
                "https://access.redhat.com/errata/RHSA-2026:36625",
                "https://access.redhat.com/security/cve/CVE-2026-9165",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2480505"
            ],
            "timeline": [
                {
                    "at": "2026-07-06T09:16:39.400",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9165"
                }
            ]
        },
        {
            "id": "CVE-2026-9080",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed.",
            "updated_at": "2026-09-15T07:16:34.767",
            "published_at": "2026-07-03T07:16:25.713",
            "cvss": 7.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.13.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); cfc657a48dbafb4194676d4c9d841388b3a22210 through before 5ab34cba42e4ee4282fe8bab43f311d51b9bf9bd (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION`\ncallback triggers a use-after-free vulnerability, where libcurl attempts to\nstore a flag using a dangling struct pointer immediately after that pointer's\nmemory has been freed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3749204"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-9080.html",
                "https://curl.se/docs/CVE-2026-9080.json",
                "https://hackerone.com/reports/3749204"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:25.713",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9080"
                }
            ]
        },
        {
            "id": "CVE-2026-9079",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them.",
            "updated_at": "2026-09-15T07:16:34.597",
            "published_at": "2026-07-03T07:16:25.620",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.8.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); d5e83eb745762f48d8fafadc5df5dd3ae8d8941e through before 88c7e16cceec816a2df45c899d49b1e85513f193 (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-522",
            "what_happened": "libcurl had a flaw that when instructed to clear proxy authentication\ncredentials which made it not do so, leaving the old credentials around to get\nused for subsequent transfers that should not know nor use them.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3750295"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-9079.html",
                "https://curl.se/docs/CVE-2026-9079.json",
                "https://hackerone.com/reports/3750295"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:25.620",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9079"
                }
            ]
        },
        {
            "id": "CVE-2026-8932",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.",
            "updated_at": "2026-09-15T07:16:33.407",
            "published_at": "2026-07-03T07:16:25.363",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.7.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); a1d6ad26100bc493c7b04f1301b1634b7f5aa8b4 through before 7541ae569d82fb308a5e2d94916027da4fa3ba3e (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0; 7.32.0; 7.31.0; 7.30.0; 7.29.0; 7.28.1; 7.28.0; 7.27.0; 7.26.0; 7.25.0; 7.24.0; 7.23.1; 7.23.0; 7.22.0; 7.21.7; 7.21.6; 7.21.5; 7.21.4; 7.21.3; 7.21.2; 7.21.1; 7.21.0; 7.20.1; 7.20.0; 7.19.7; 7.19.6; 7.19.5; 7.19.4; 7.19.3; 7.19.2; 7.19.1; 7.19.0; 7.18.2; 7.18.1; 7.18.0; 7.17.1; 7.17.0; 7.16.4; 7.16.3; 7.16.2; 7.16.1; 7.16.0; 7.15.5; 7.15.4; 7.15.3; 7.15.2; 7.15.1; 7.15.0; 7.14.1; 7.14.0; 7.13.2; 7.13.1; 7.13.0; 7.12.3; 7.12.2; 7.12.1; 7.12.0; 7.11.2; 7.11.1; 7.11.0; 7.10.8; 7.10.7; 7.10.6; 7.10.5; 7.10.4; 7.10.3; 7.10.2; 7.10.1; 7.10; 7.9.8; 7.9.7; 7.9.6; 7.9.5; 7.9.4; 7.9.3; 7.9.2; 7.9.1; 7.9; 7.8.1; 7.8; 7.7.3; 7.7.2; 7.7.1; 7.7",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-305",
            "what_happened": "libcurl would reuse a previously created connection even when some mTLS config\nrelated option had been changed that should have prohibited reuse.\n\nlibcurl keeps previously used connections in a connection pool for subsequent\ntransfers to reuse if one of them matches the setup. However, some TLS\nsettings related to client certificates were left out from the configuration\nmatch checks, making them match too easily. In particular options related to\nthe private key.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3733910"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-8932.html",
                "https://curl.se/docs/CVE-2026-8932.json",
                "https://hackerone.com/reports/3733910"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:25.363",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8932"
                }
            ]
        },
        {
            "id": "CVE-2026-8927",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.",
            "updated_at": "2026-09-15T07:16:33.157",
            "published_at": "2026-07-03T07:16:25.123",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.12.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); fc6eff13b5414caf6edf22d73a3239e074a04216 through before 5c225384b8d52c67ce8259c6e4203bc57aacb567 (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0; 7.32.0; 7.31.0; 7.30.0; 7.29.0; 7.28.1; 7.28.0; 7.27.0; 7.26.0; 7.25.0; 7.24.0; 7.23.1; 7.23.0; 7.22.0; 7.21.7; 7.21.6; 7.21.5; 7.21.4; 7.21.3; 7.21.2; 7.21.1; 7.21.0; 7.20.1; 7.20.0; 7.19.7; 7.19.6; 7.19.5; 7.19.4; 7.19.3; 7.19.2; 7.19.1; 7.19.0; 7.18.2; 7.18.1; 7.18.0; 7.17.1; 7.17.0; 7.16.4; 7.16.3; 7.16.2; 7.16.1; 7.16.0; 7.15.5; 7.15.4; 7.15.3; 7.15.2; 7.15.1; 7.15.0; 7.14.1; 7.14.0; 7.13.2; 7.13.1; 7.13.0; 7.12.3; 7.12.2; 7.12.1; 7.12.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-294",
            "what_happened": "When reusing a libcurl handle for sequential transfers driven by\nenvironment-variable proxy configuration, libcurl fails to clear the proxy\nauthentication state between requests. Specifically, if the initial transfer\nauthenticates against `proxyA` using Digest auth, a subsequent transfer routed\nthrough `proxyB` erroneously leaks the `Proxy-Authorization:` header intended\nsolely for `proxyA`.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3744543"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-8927.html",
                "https://curl.se/docs/CVE-2026-8927.json",
                "https://hackerone.com/reports/3744543"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:25.123",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8927"
                }
            ]
        },
        {
            "id": "CVE-2026-8926",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username (without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user.",
            "updated_at": "2026-09-15T07:16:32.980",
            "published_at": "2026-07-03T07:16:25.037",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.11.1 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); e9b9bbac22c26cf67316fa8e6c6b9e831af31949 through before 4ae1d7cc2643e4773a136395f12bc02fc6867854 (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-522",
            "what_happened": "When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username (without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3735184"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-8926.html",
                "https://curl.se/docs/CVE-2026-8926.json",
                "https://hackerone.com/reports/3735184"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:25.037",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8926"
                }
            ]
        },
        {
            "id": "CVE-2026-8925",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "The curl logic that works with SASL authentication could end up cleaning up\nthe GSASL context *twice* without clearing the pointer in between, making it\n`free()` the same pointer twice.",
            "updated_at": "2026-09-15T07:16:32.800",
            "published_at": "2026-07-03T07:16:24.950",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); ab650379a8c25ca952f651476d25b4cdd77bb3fc through before 3da249e1f0716c06644ed3522a37a8bf81808012 (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-415",
            "what_happened": "The curl logic that works with SASL authentication could end up cleaning up\nthe GSASL context *twice* without clearing the pointer in between, making it\n`free()` the same pointer twice.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3735193"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-8925.html",
                "https://curl.se/docs/CVE-2026-8925.json",
                "https://hackerone.com/reports/3735193"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:24.950",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8925"
                }
            ]
        },
        {
            "id": "CVE-2026-8924",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.",
            "updated_at": "2026-09-15T07:16:32.573",
            "published_at": "2026-07-03T07:16:24.793",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.46.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); e77b5b7453c1e8ccd7ec0816890d98e2f392e465 through before 51beed175dbfc37da3113f6acce60c630c070ce8 (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-201",
            "what_happened": "A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set\n\"super cookies\" that bypass the Public Suffix List check. This enables an\nattacker-controlled origin to inject cookies that curl subsequently scopes and\ntransmits to unrelated third-party domains.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3733905"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-8924.html",
                "https://curl.se/docs/CVE-2026-8924.json",
                "https://hackerone.com/reports/3733905"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:24.793",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8924"
                }
            ]
        },
        {
            "id": "CVE-2026-8794",
            "vendor": "PaperCut",
            "product": "PaperCut NG/MF",
            "title": "PaperCut NG/MF vulnerability",
            "summary": "PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.",
            "updated_at": "2026-09-09T16:03:59.890",
            "published_at": "2026-08-03T08:17:21.273",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.0.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-208",
            "what_happened": "PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring response times during login attempts. The system executes a password hash comparison only when a valid account is supplied, creating a measurable timing oracle that reveals account existence.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-3-aug-2026/"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T08:17:21.273",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8794"
                }
            ]
        },
        {
            "id": "CVE-2026-8793",
            "vendor": "PaperCut",
            "product": "PaperCut NG/MF",
            "title": "PaperCut NG/MF vulnerability",
            "summary": "PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some configurations.",
            "updated_at": "2026-09-09T16:03:59.890",
            "published_at": "2026-08-03T08:17:21.097",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 26.0.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-307",
            "what_happened": "PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force or credential-stuffing attacks without triggering account lockout or rate-limiting mechanisms in some configurations.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.papercut.com/kb/Main/papercut-ng-mf-security-bulletin-3-aug-2026/"
            ],
            "timeline": [
                {
                    "at": "2026-08-03T08:17:21.097",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8793"
                }
            ]
        },
        {
            "id": "CVE-2026-8732",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-8732 exploit",
            "summary": "Exploit for CVE-2026-8732. CVSS 9.8.",
            "updated_at": "2026-09-06T08:32:45Z",
            "published_at": "2026-09-06T08:32:45Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 81,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Unauthenticated privilege escalation in WP Maps Pro ≤ 6.1.0 creates admin accounts via public nonce.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-8732",
                    "summary": "Unauthenticated privilege escalation in WP Maps Pro ≤ 6.1.0 creates admin accounts via public nonce.",
                    "what_happened": "Unauthenticated privilege escalation in WP Maps Pro ≤ 6.1.0 creates admin accounts via public nonce.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-XSHADOW-HERE-CVE-2026-8732",
                        "https://kitploit.com/ru/tools/github/xshadow-here/cve-2026-8732/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-01T14:29:22",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-XSHADOW-HERE-CVE-2026-8732"
                },
                {
                    "title": "Exploit for CVE-2026-8732",
                    "summary": "Unauthenticated privilege escalation in WP Maps Pro ≤ 6.1.0 creates admin accounts via public nonce.",
                    "what_happened": "Unauthenticated privilege escalation in WP Maps Pro ≤ 6.1.0 creates admin accounts via public nonce.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-XSHADOW-HERE-CVE-2026-8732",
                        "https://kitploit.com/ru/tools/github/xshadow-here/cve-2026-8732/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-01T14:29:22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/xshadow-here/cve-2026-8732/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-XSHADOW-HERE-CVE-2026-8732",
                "https://kitploit.com/ru/tools/github/xshadow-here/cve-2026-8732/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:32:45Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-XSHADOW-HERE-CVE-2026-8732"
                }
            ]
        },
        {
            "id": "CVE-2026-8643",
            "vendor": "Python Packaging Authority",
            "product": "pip",
            "title": "pip vulnerability",
            "summary": "pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.",
            "updated_at": "2026-09-16T13:18:08.000",
            "published_at": "2026-06-01T17:17:35.770",
            "cvss": 4.1,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "24.0 through before 26.1.2 (python)",
            "fixed": "See vendor advisory",
            "source_count": 42,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pypa/pip/pull/14000",
                "https://mail.python.org/archives/list/security-announce@python.org/thread/YV63UET5D3OOJY7O4M5XCVYO2YM4NBYJ/",
                "http://www.openwall.com/lists/oss-security/2026/06/01/5",
                "https://access.redhat.com/errata/RHSA-2026:33313",
                "https://access.redhat.com/errata/RHSA-2026:34374",
                "https://access.redhat.com/errata/RHSA-2026:34456",
                "https://access.redhat.com/errata/RHSA-2026:34739",
                "https://access.redhat.com/errata/RHSA-2026:34740",
                "https://access.redhat.com/errata/RHSA-2026:34741",
                "https://access.redhat.com/errata/RHSA-2026:34748",
                "https://access.redhat.com/errata/RHSA-2026:34749",
                "https://access.redhat.com/errata/RHSA-2026:34750",
                "https://access.redhat.com/errata/RHSA-2026:34752",
                "https://access.redhat.com/errata/RHSA-2026:34756",
                "https://access.redhat.com/errata/RHSA-2026:34758",
                "https://access.redhat.com/errata/RHSA-2026:34760",
                "https://access.redhat.com/errata/RHSA-2026:34765",
                "https://access.redhat.com/errata/RHSA-2026:34772",
                "https://access.redhat.com/errata/RHSA-2026:34773",
                "https://access.redhat.com/errata/RHSA-2026:34774",
                "https://access.redhat.com/errata/RHSA-2026:34775",
                "https://access.redhat.com/errata/RHSA-2026:34776",
                "https://access.redhat.com/errata/RHSA-2026:34777",
                "https://access.redhat.com/errata/RHSA-2026:34778",
                "https://access.redhat.com/errata/RHSA-2026:34780",
                "https://access.redhat.com/errata/RHSA-2026:34891",
                "https://access.redhat.com/errata/RHSA-2026:36193",
                "https://access.redhat.com/errata/RHSA-2026:36315",
                "https://access.redhat.com/errata/RHSA-2026:37275",
                "https://access.redhat.com/errata/RHSA-2026:37283",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:42079",
                "https://access.redhat.com/errata/RHSA-2026:42132",
                "https://access.redhat.com/errata/RHSA-2026:42144",
                "https://access.redhat.com/errata/RHSA-2026:42644",
                "https://access.redhat.com/errata/RHSA-2026:50479",
                "https://access.redhat.com/errata/RHSA-2026:54760",
                "https://access.redhat.com/errata/RHSA-2026:56347",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/security/cve/CVE-2026-8643",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2460927",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8643.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-01T17:17:35.770",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8643"
                }
            ]
        },
        {
            "id": "CVE-2026-8625",
            "vendor": "dearhive",
            "product": "DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer",
            "title": "DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer vulnerability",
            "summary": "The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom HTML block inner HTML)' parameter in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A Contributor-level attacker can insert a crafted .df-element div with data-df-lightbox='thumb' via a Custom HTML block, whose inner HTML is passed as the title argument to parseThumbs() at render time, enabling both innerHTML injection into a span element and attribute breakout via an onerror handler on a constructed img element.",
            "updated_at": "2026-09-05T06:17:10.690",
            "published_at": "2026-09-05T06:17:10.690",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.4.30 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom HTML block inner HTML)' parameter in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A Contributor-level attacker can insert a crafted .df-element div with data-df-lightbox='thumb' via a Custom HTML block, whose inner HTML is passed as the title argument to parseThumbs() at render time, enabling both innerHTML injection into a span element and attribute breakout via an onerror handler on a constructed img element.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/3d-flipbook-dflip-lite/tags/2.4.27/assets/js/dflip.js#L2712",
                "https://plugins.trac.wordpress.org/browser/3d-flipbook-dflip-lite/tags/2.4.27/assets/js/dflip.js#L2718",
                "https://plugins.trac.wordpress.org/browser/3d-flipbook-dflip-lite/tags/2.4.27/assets/js/dflip.js#L2791",
                "https://plugins.trac.wordpress.org/browser/3d-flipbook-dflip-lite/tags/2.4.27/assets/js/dflip.js#L2796",
                "https://plugins.trac.wordpress.org/changeset/3641463/3d-flipbook-dflip-lite/trunk/assets/js/dflip.js",
                "https://plugins.trac.wordpress.org/changeset?old_path=%2F3d-flipbook-dflip-lite/tags/2.4.30&new_path=%2F3d-flipbook-dflip-lite/tags/2.4.37",
                "https://plugins.trac.wordpress.org/changeset?reponame=&new=3641463%403d-flipbook-dflip-lite%2Ftags%2F2.4.37&old=3557511%403d-flipbook-dflip-lite%2Ftags%2F2.4.30",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/741150a3-1b2a-4b54-9dd5-992d3d7079dc?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T06:17:10.690",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8625"
                }
            ]
        },
        {
            "id": "CVE-2026-8623",
            "vendor": "dearhive",
            "product": "DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer",
            "title": "DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer vulnerability",
            "summary": "The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class attribute of .dvcss element)' parameter in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is embedded as a Base64-encoded JSON object in a CSS class name on a Custom HTML block; the frontend parseCSSElements() function decodes it client-side with atob() and JSON.parse() and renders the logo property as raw HTML, meaning no server-side or client-side sanitization intercepts the malicious script before DOM insertion.",
            "updated_at": "2026-09-05T06:17:10.547",
            "published_at": "2026-09-05T06:17:10.547",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.4.30 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class attribute of .dvcss element)' parameter in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is embedded as a Base64-encoded JSON object in a CSS class name on a Custom HTML block; the frontend parseCSSElements() function decodes it client-side with atob() and JSON.parse() and renders the logo property as raw HTML, meaning no server-side or client-side sanitization intercepts the malicious script before DOM insertion.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/3d-flipbook-dflip-lite/tags/2.4.27/assets/js/dflip.js#L11255",
                "https://plugins.trac.wordpress.org/browser/3d-flipbook-dflip-lite/tags/2.4.27/assets/js/dflip.js#L2687",
                "https://plugins.trac.wordpress.org/changeset/3641463/3d-flipbook-dflip-lite/trunk/assets/js/dflip.js",
                "https://plugins.trac.wordpress.org/changeset?old_path=%2F3d-flipbook-dflip-lite/tags/2.4.30&new_path=%2F3d-flipbook-dflip-lite/tags/2.4.37",
                "https://plugins.trac.wordpress.org/changeset?reponame=&new=3641463%403d-flipbook-dflip-lite%2Ftags%2F2.4.37&old=3557511%403d-flipbook-dflip-lite%2Ftags%2F2.4.30",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/27e2848d-6271-4bb9-92e2-0f8c8860745d?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T06:17:10.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8623"
                }
            ]
        },
        {
            "id": "CVE-2026-8458",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.",
            "updated_at": "2026-09-15T07:16:32.327",
            "published_at": "2026-07-03T07:16:24.630",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.43.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 97c272e5d173ad5f706443e2477f0a84f0044edd through before 5e99b73cf441d9c369768b9cd48b5389b9a2503d (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-488",
            "what_happened": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo Negotiate-authenticated ones, even when they are set to use different\n\"services\".\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different services.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3721183"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-8458.html",
                "https://curl.se/docs/CVE-2026-8458.json",
                "https://hackerone.com/reports/3721183"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:24.630",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8458"
                }
            ]
        },
        {
            "id": "CVE-2026-8452",
            "vendor": "Citrix",
            "product": "NetScaler ADC and NetScaler Gateway",
            "title": "Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability",
            "summary": "Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.",
            "updated_at": "2026-08-25T22:00:00Z",
            "published_at": "2026-08-25T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 48,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-8286",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.",
            "updated_at": "2026-09-15T07:16:31.617",
            "published_at": "2026-07-03T07:16:24.453",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.30.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); a1701eea289fe7ea80651f801cf992838a491dde through before a86efdd7ca5433de9231e650f18247de8319ad16 (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0; 7.32.0; 7.31.0; 7.30.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "A vulnerability exists where a new transfer that uses STARTTLS to upgrade the\nconnection might reuse an existing live connection even though the TLS\nconfiguration mismatches so it should not.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-07-03",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3718195"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-8286.html",
                "https://curl.se/docs/CVE-2026-8286.json",
                "https://hackerone.com/reports/3718195"
            ],
            "timeline": [
                {
                    "at": "2026-07-03T07:16:24.453",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-8286"
                }
            ]
        },
        {
            "id": "CVE-2026-8037",
            "vendor": "Progress",
            "product": "LoadMaster",
            "title": "Progress LoadMaster Command Injection Vulnerability",
            "summary": "Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.",
            "updated_at": "2026-08-06T22:00:00Z",
            "published_at": "2026-08-06T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-7888",
            "vendor": "Concrete CMS",
            "product": "Concrete CMS",
            "title": "Concrete CMS vulnerability",
            "summary": "Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize()\ncalls in the Workflow, Form block, and File/Set components that lack the\nallowed_classes restriction. The Form block and File/Set sinks were addressed in\n9.5.2; the Workflow component sinks were addressed in 9.5.3. An unauthenticated\nattacker may trigger arbitrary PHP object instantiation if a malicious serialized\npayload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan\n(dizconnect) for independently reporting the original components, and sh4d0byss for\nreporting the Workflow component wasn't fixed in 9.5.2. The Concrete CMS security team gave this\nvulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/\nVC:H/VI:H/VA:H/SC:N/SI:N/SA:N.",
            "updated_at": "2026-09-11T20:18:54.320",
            "published_at": "2026-06-03T19:16:38.910",
            "cvss": 8.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5.0 through 9.5.2 (git)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize()\ncalls in the Workflow, Form block, and File/Set components that lack the\nallowed_classes restriction. The Form block and File/Set sinks were addressed in\n9.5.2; the Workflow component sinks were addressed in 9.5.3. An unauthenticated\nattacker may trigger arbitrary PHP object instantiation if a malicious serialized\npayload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan\n(dizconnect) for independently reporting the original components, and sh4d0byss for\nreporting the Workflow component wasn't fixed in 9.5.2. The Concrete CMS security team gave this\nvulnerability a CVSS v.4.0 score of 8.4 with vector CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/\nVC:H/VI:H/VA:H/SC:N/SI:N/SA:N.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://documentation.concretecms.org/9-x/developers/introduction/version-history/952-release-notes"
            ],
            "timeline": [
                {
                    "at": "2026-06-03T19:16:38.910",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7888"
                }
            ]
        },
        {
            "id": "CVE-2026-7861",
            "vendor": "Next4Biz Information Technologies Inc.",
            "product": "CSM (Customer Service Management)",
            "title": "CSM (Customer Service Management) vulnerability",
            "summary": "Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection.\n\nThis issue affects CSM (Customer Service Management): before 8.0.3.",
            "updated_at": "2026-09-09T09:17:11.703",
            "published_at": "2026-09-07T15:17:32.153",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 8.0.3 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection.\n\nThis issue affects CSM (Customer Service Management): before 8.0.3.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1027"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T15:17:32.153",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7861"
                }
            ]
        },
        {
            "id": "CVE-2026-7860",
            "vendor": "vaadin",
            "product": "flow",
            "title": "flow vulnerability",
            "summary": "A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain credentials supplied as secrets, any failed frontend build can expose those secrets in clear text in CI logs and archived build artifacts.\n\n\nUsers of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:\n\nProduct version\nVaadin 23.0.0 - 23.6.9\nVaadin 24.0.0 - 24.9.16\nVaadin 24.10.0 - 24.10.3\nVaadin 25.0.0 - 25.0.10\nVaadin 25.1.0 - 25.1.4\n\nMitigation\nUpgrade to 23.6.10\nUpgrade to 24.9.17 or newer\nUpgrade to 24.10.4 or newer\nUpgrade to 25.0.11 or newer\nUpgrade to 25.1.5 or newer\n\nPlease note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, or 25 version.\n\nArtifactsMaven coordinatesVulnerable versionsFixed versioncom.vaadin:flow-plugin-base23.0.0 - 23.6.10≥23.6.11com.vaadin:flow-plugin-base24.0.0 - 24.9.17≥24.9.18com.vaadin:flow-plugin-base24.10.0 - 24.10.3≥24.10.4com.vaadin:flow-plugin-base25.0.0 - 25.0.11≥25.0.12com.vaadin:flow-plugin-base25.1.0 - 25.1.4≥25.1.5com.vaadin:flow-maven-plugin23.0.0 - 23.6.10≥23.6.11com.vaadin:flow-maven-plugin24.0.0 - 24.9.17≥24.9.18com.vaadin:flow-maven-plugin24.10.0 - 24.10.3≥24.10.4com.vaadin:flow-maven-plugin25.0.0 - 25.0.11≥25.0.12com.vaadin:flow-maven-plugin25.1.0 - 25.1.4≥25.1.5com.vaadin:flow-gradle-plugin23.0.0 - 23.6.10≥23.6.11com.vaadin:flow-gradle-plugin24.0.0 - 24.9.17≥24.9.18com.vaadin:flow-gradle-plugin24.10.0 - 24.10.3≥24.10.4com.vaadin:flow-gradle-plugin25.0.0 - 25.0.11≥25.0.12com.vaadin:flow-gradle-plugin25.1.0 - 25.1.4≥25.1.5",
            "updated_at": "2026-09-14T15:17:08.693",
            "published_at": "2026-05-19T12:16:19.960",
            "cvss": 1.6,
            "cvss_vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:A/V:C/RE:L/U:Green",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "23.0.0 through 23.6.10 (maven); 24.0.0 through 24.9.17 (maven); 24.10.0 through 24.10.3 (maven); 25.0.0 through 25.0.11 (maven); 25.1.0 through 25.1.4 (maven)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-209",
            "what_happened": "A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain credentials supplied as secrets, any failed frontend build can expose those secrets in clear text in CI logs and archived build artifacts.\n\n\nUsers of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:\n\nProduct version\nVaadin 23.0.0 - 23.6.9\nVaadin 24.0.0 - 24.9.16\nVaadin 24.10.0 - 24.10.3\nVaadin 25.0.0 - 25.0.10\nVaadin 25.1.0 - 25.1.4\n\nMitigation\nUpgrade to 23.6.10\nUpgrade to 24.9.17 or newer\nUpgrade to 24.10.4 or newer\nUpgrade to 25.0.11 or newer\nUpgrade to 25.1.5 or newer\n\nPlease note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 23, 24, or 25 version.\n\nArtifactsMaven coordinatesVulnerable versionsFixed versioncom.vaadin:flow-plugin-base23.0.0 - 23.6.10≥23.6.11com.vaadin:flow-plugin-base24.0.0 - 24.9.17≥24.9.18com.vaadin:flow-plugin-base24.10.0 - 24.10.3≥24.10.4com.vaadin:flow-plugin-base25.0.0 - 25.0.11≥25.0.12com.vaadin:flow-plugin-base25.1.0 - 25.1.4≥25.1.5com.vaadin:flow-maven-plugin23.0.0 - 23.6.10≥23.6.11com.vaadin:flow-maven-plugin24.0.0 - 24.9.17≥24.9.18com.vaadin:flow-maven-plugin24.10.0 - 24.10.3≥24.10.4com.vaadin:flow-maven-plugin25.0.0 - 25.0.11≥25.0.12com.vaadin:flow-maven-plugin25.1.0 - 25.1.4≥25.1.5com.vaadin:flow-gradle-plugin23.0.0 - 23.6.10≥23.6.11com.vaadin:flow-gradle-plugin24.0.0 - 24.9.17≥24.9.18com.vaadin:flow-gradle-plugin24.10.0 - 24.10.3≥24.10.4com.vaadin:flow-gradle-plugin25.0.0 - 25.0.11≥25.0.12com.vaadin:flow-gradle-plugin25.1.0 - 25.1.4≥25.1.5",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/vaadin/flow/pull/24219",
                "https://vaadin.com/security/cve-2026-7860"
            ],
            "timeline": [
                {
                    "at": "2026-05-19T12:16:19.960",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7860"
                }
            ]
        },
        {
            "id": "CVE-2026-7374",
            "vendor": "Red Hat",
            "product": "Red Hat Container Native Virtualization 4.12",
            "title": "Red Hat Container Native Virtualization 4.12 vulnerability",
            "summary": "A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.",
            "updated_at": "2026-09-09T15:17:10.817",
            "published_at": "2026-05-26T14:16:40.717",
            "cvss": 9.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.6.6 (semver); 1.7.0 through before 1.7.4 (semver); 1.8.0 through before 1.8.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 25,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-59",
            "what_happened": "A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connection. This enables the attacker to access any Unix socket on the host, potentially leading to full control of the node and the entire cluster.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:20720",
                "https://access.redhat.com/errata/RHSA-2026:20736",
                "https://access.redhat.com/errata/RHSA-2026:20763",
                "https://access.redhat.com/errata/RHSA-2026:20767",
                "https://access.redhat.com/errata/RHSA-2026:20782",
                "https://access.redhat.com/errata/RHSA-2026:20825",
                "https://access.redhat.com/errata/RHSA-2026:20866",
                "https://access.redhat.com/errata/RHSA-2026:20886",
                "https://access.redhat.com/errata/RHSA-2026:20890",
                "https://access.redhat.com/errata/RHSA-2026:20975",
                "https://access.redhat.com/security/cve/CVE-2026-7374",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2463728",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7374.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-26T14:16:40.717",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7374"
                }
            ]
        },
        {
            "id": "CVE-2026-7168",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.",
            "updated_at": "2026-09-15T07:16:29.890",
            "published_at": "2026-05-13T13:01:57.200",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.12.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.0 (semver); fc6eff13b5414caf6edf22d73a3239e074a04216 through before c1cfdf59acbaf9504c4578d4cf56cdd7c8594507 (git); 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0; 7.32.0; 7.31.0; 7.30.0; 7.29.0; 7.28.1; 7.28.0; 7.27.0; 7.26.0; 7.25.0; 7.24.0; 7.23.1; 7.23.0; 7.22.0; 7.21.7; 7.21.6; 7.21.5; 7.21.4; 7.21.3; 7.21.2; 7.21.1; 7.21.0; 7.20.1; 7.20.0; 7.19.7; 7.19.6; 7.19.5; 7.19.4; 7.19.3; 7.19.2; 7.19.1; 7.19.0; 7.18.2; 7.18.1; 7.18.0; 7.17.1; 7.17.0; 7.16.4; 7.16.3; 7.16.2; 7.16.1; 7.16.0; 7.15.5; 7.15.4; 7.15.3; 7.15.2; 7.15.1; 7.15.0; 7.14.1; 7.14.0; 7.13.2; 7.13.1; 7.13.0; 7.12.3; 7.12.2; 7.12.1; 7.12.0",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-294",
            "what_happened": "Successfully using libcurl to do a transfer over a specific HTTP proxy\n(`proxyA`) with **Digest** authentication and then changing the proxy host to\na second one (`proxyB`) for a second transfer, reusing the same handle, makes\nlibcurl wrongly pass on the `Proxy-Authorization:` header field meant for\n`proxyA`, to `proxyB`.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3697719"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-7168.html",
                "https://curl.se/docs/CVE-2026-7168.json",
                "https://hackerone.com/reports/3697719",
                "http://www.openwall.com/lists/oss-security/2026/04/29/14"
            ],
            "timeline": [
                {
                    "at": "2026-05-13T13:01:57.200",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7168"
                }
            ]
        },
        {
            "id": "CVE-2026-7163",
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1",
            "title": "multicluster engine for Kubernetes 2.1 vulnerability",
            "summary": "A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hub. \n\nThe credentials download endpoint (GET /v2/clusters/{cluster_id}/credentials, which returns the kubeadmin password) and the kubeconfig download endpoint are operational in AUTH_TYPE=local mode, the only authentication mode available in on-premises ACM/MCE hub deployments. The local authenticator unconditionally grants full administrative access to any request bearing a valid JWT, with no per-endpoint restrictions. A valid local JWT is embedded as a plaintext query parameter in InfraEnvStatus.ISODownloadURL and is readable by any user who has get rights on an InfraEnv object in their own namespace.\n\nThe affected components ship as part of Multicluster Engine (MCE). The Red Hat Advanced Cluster Management (ACM) deployments that include MCE are equally affected.\nThis issue does not affect the hosted SaaS offering (console.redhat.com), which uses a different authentication mode.\n\nSuccessful exploitation gives the attacker the kubeadmin password and kubeconfig for any OpenShift cluster provisioned through the affected hub, granting unrestricted root-level administrative access to those spoke clusters.",
            "updated_at": "2026-09-05T22:17:17.853",
            "published_at": "2026-04-30T14:16:36.093",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.7.0 through before 2.7.10 (semver); 2.9.0 through before 2.9.4 (semver); 2.10.0 through before 2.10.2 (semver); 2.11.0 through before 2.11.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-312",
            "what_happened": "A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials for arbitrary clusters provisioned through the hub. \n\nThe credentials download endpoint (GET /v2/clusters/{cluster_id}/credentials, which returns the kubeadmin password) and the kubeconfig download endpoint are operational in AUTH_TYPE=local mode, the only authentication mode available in on-premises ACM/MCE hub deployments. The local authenticator unconditionally grants full administrative access to any request bearing a valid JWT, with no per-endpoint restrictions. A valid local JWT is embedded as a plaintext query parameter in InfraEnvStatus.ISODownloadURL and is readable by any user who has get rights on an InfraEnv object in their own namespace.\n\nThe affected components ship as part of Multicluster Engine (MCE). The Red Hat Advanced Cluster Management (ACM) deployments that include MCE are equally affected.\nThis issue does not affect the hosted SaaS offering (console.redhat.com), which uses a different authentication mode.\n\nSuccessful exploitation gives the attacker the kubeadmin password and kubeconfig for any OpenShift cluster provisioned through the affected hub, granting unrestricted root-level administrative access to those spoke clusters.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:11511",
                "https://access.redhat.com/errata/RHSA-2026:11512",
                "https://access.redhat.com/errata/RHSA-2026:12116",
                "https://access.redhat.com/errata/RHSA-2026:12337",
                "https://access.redhat.com/errata/RHSA-2026:18584",
                "https://access.redhat.com/errata/RHSA-2026:18585",
                "https://access.redhat.com/security/cve/CVE-2026-7163",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2463152",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7163.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-30T14:16:36.093",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7163"
                }
            ]
        },
        {
            "id": "CVE-2026-6924",
            "vendor": "Silicon Labs",
            "product": "Silicon Labs Matter Github",
            "title": "Silicon Labs Matter Github vulnerability",
            "summary": "A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.",
            "updated_at": "2026-09-08T19:12:59.557",
            "published_at": "2026-07-23T21:17:05.447",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-336",
            "what_happened": "A bug in the entropy initialization for SiWx917 causes the DRBG to use a predictable seed. As such, all random numbers generated in the Matter code use the same stream of numbers. This vulnerability was discovered after the impacted repository was already deprecated.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/SiliconLabs/matter/tree/release_2.3.1-1.3",
                "https://siliconlabs.lightning.force.com/sfc/servlet.shepherd/document/download/a45Vm0000009SzZIAU?operationContext=S1"
            ],
            "timeline": [
                {
                    "at": "2026-07-23T21:17:05.447",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6924"
                }
            ]
        },
        {
            "id": "CVE-2026-6893",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.",
            "updated_at": "2026-09-15T12:17:52.943",
            "published_at": "2026-06-10T20:17:29.807",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 31,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-78",
            "what_happened": "A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malicious hostname, to a system using dracut's legacy DHCP path. These options are improperly handled and written into temporary shell scripts without proper escaping, leading to command injection. This allows the attacker to achieve root code execution within the initramfs, potentially compromising the system's boot and network behavior.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:26532",
                "https://access.redhat.com/errata/RHSA-2026:26533",
                "https://access.redhat.com/errata/RHSA-2026:26534",
                "https://access.redhat.com/errata/RHSA-2026:26713",
                "https://access.redhat.com/errata/RHSA-2026:57580",
                "https://access.redhat.com/errata/RHSA-2026:57772",
                "https://access.redhat.com/errata/RHSA-2026:57775",
                "https://access.redhat.com/errata/RHSA-2026:57785",
                "https://access.redhat.com/errata/RHSA-2026:61252",
                "https://access.redhat.com/errata/RHSA-2026:62269",
                "https://access.redhat.com/security/cve/CVE-2026-6893",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2459963",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6893.json",
                "https://access.redhat.com/errata/RHSA-2026:63044",
                "https://access.redhat.com/errata/RHSA-2026:62409",
                "https://access.redhat.com/errata/RHSA-2026:62549"
            ],
            "timeline": [
                {
                    "at": "2026-06-10T20:17:29.807",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6893"
                }
            ]
        },
        {
            "id": "CVE-2026-6881",
            "vendor": "Ellucian",
            "product": "Advance Web",
            "title": "Advance Web vulnerability",
            "summary": "A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.\n\n\n\nThis issue affects Advance Web: all versions; Legacy Advance: all versions.\n\n\n\nEllucian CRM Advance is not impacted.",
            "updated_at": "2026-09-09T15:52:04.827",
            "published_at": "2026-07-28T21:17:29.427",
            "cvss": 9.4,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query in the class credit field.\n\n\n\nThis issue affects Advance Web: all versions; Legacy Advance: all versions.\n\n\n\nEllucian CRM Advance is not impacted.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://labs.sra.io/posts/ellucian"
            ],
            "timeline": [
                {
                    "at": "2026-07-28T21:17:29.427",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6881"
                }
            ]
        },
        {
            "id": "CVE-2026-6857",
            "vendor": "Red Hat",
            "product": "Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14",
            "title": "Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 vulnerability",
            "summary": "A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over the affected system, impacting its confidentiality, integrity, and availability.",
            "updated_at": "2026-09-08T16:18:12.827",
            "published_at": "2026-04-22T13:16:22.583",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.14.7 (semver); 4.15.0 through before 4.18.2 (semver); 4.19.0 through before 4.20.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-502",
            "what_happened": "A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over the affected system, impacting its confidentiality, integrity, and availability.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:17668",
                "https://access.redhat.com/errata/RHSA-2026:22453",
                "https://access.redhat.com/security/cve/CVE-2026-6857",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2460003",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6857.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-22T13:16:22.583",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6857"
                }
            ]
        },
        {
            "id": "CVE-2026-6554",
            "vendor": "The Tcpdump Group",
            "product": "libpcap",
            "title": "libpcap vulnerability",
            "summary": "libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations.  In particular uncommon use cases a crafted filter program can cause the interpreter to loop infinitely.",
            "updated_at": "2026-09-05T19:16:56.067",
            "published_at": "2026-09-05T19:16:56.067",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.10.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-835",
            "what_happened": "libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations.  In particular uncommon use cases a crafted filter program can cause the interpreter to loop infinitely.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T19:16:56.067",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6554"
                }
            ]
        },
        {
            "id": "CVE-2026-6429",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.",
            "updated_at": "2026-09-15T07:16:29.557",
            "published_at": "2026-05-13T13:01:56.930",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.14.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.0 (semver); 01165e08e0d131b399fba2190f17af67e66f0888 through before b4024bf808bd558026fdc6096e8457f199ace306 (git); 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0; 7.32.0; 7.31.0; 7.30.0; 7.29.0; 7.28.1; 7.28.0; 7.27.0; 7.26.0; 7.25.0; 7.24.0; 7.23.1; 7.23.0; 7.22.0; 7.21.7; 7.21.6; 7.21.5; 7.21.4; 7.21.3; 7.21.2; 7.21.1; 7.21.0; 7.20.1; 7.20.0; 7.19.7; 7.19.6; 7.19.5; 7.19.4; 7.19.3; 7.19.2; 7.19.1; 7.19.0; 7.18.2; 7.18.1; 7.18.0; 7.17.1; 7.17.0; 7.16.4; 7.16.3; 7.16.2; 7.16.1; 7.16.0; 7.15.5; 7.15.4; 7.15.3; 7.15.2; 7.15.1; 7.15.0; 7.14.1; 7.14.0",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-200",
            "what_happened": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, libcurl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3677759"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-6429.html",
                "https://curl.se/docs/CVE-2026-6429.json",
                "https://hackerone.com/reports/3677759"
            ],
            "timeline": [
                {
                    "at": "2026-05-13T13:01:56.930",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6429"
                }
            ]
        },
        {
            "id": "CVE-2026-6322",
            "vendor": "fast-uri",
            "product": "fast-uri",
            "title": "fast-uri vulnerability",
            "summary": "fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a different authority than the input appeared to specify. Versions <= 3.1.1 are affected. Update to 3.1.2 or later.",
            "updated_at": "2026-09-10T13:20:29.023",
            "published_at": "2026-05-05T11:16:33.360",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.1.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 46,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-436",
            "what_happened": "fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator, changing the URI's authority to the second domain. Applications that normalize untrusted URLs before host allowlist checks, redirect validation, or outbound request routing can be steered to a different authority than the input appeared to specify. Versions <= 3.1.1 are affected. Update to 3.1.2 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/fastify/fast-uri/security/advisories/GHSA-v39h-62p7-jpjc",
                "https://access.redhat.com/errata/RHSA-2026:25271",
                "https://access.redhat.com/errata/RHSA-2026:25273",
                "https://access.redhat.com/errata/RHSA-2026:26225",
                "https://access.redhat.com/errata/RHSA-2026:26234",
                "https://access.redhat.com/errata/RHSA-2026:28571",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:29795",
                "https://access.redhat.com/errata/RHSA-2026:29796",
                "https://access.redhat.com/errata/RHSA-2026:29800",
                "https://access.redhat.com/errata/RHSA-2026:29834",
                "https://access.redhat.com/errata/RHSA-2026:30076",
                "https://access.redhat.com/errata/RHSA-2026:33683",
                "https://access.redhat.com/errata/RHSA-2026:34160",
                "https://access.redhat.com/errata/RHSA-2026:34342",
                "https://access.redhat.com/errata/RHSA-2026:34374",
                "https://access.redhat.com/errata/RHSA-2026:34766",
                "https://access.redhat.com/errata/RHSA-2026:34770",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36754",
                "https://access.redhat.com/errata/RHSA-2026:37186",
                "https://access.redhat.com/errata/RHSA-2026:37385",
                "https://access.redhat.com/errata/RHSA-2026:37628",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:41066",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41951",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:42142",
                "https://access.redhat.com/errata/RHSA-2026:43038",
                "https://access.redhat.com/errata/RHSA-2026:54395",
                "https://access.redhat.com/errata/RHSA-2026:54555",
                "https://access.redhat.com/errata/RHSA-2026:56366",
                "https://access.redhat.com/errata/RHSA-2026:56431",
                "https://access.redhat.com/errata/RHSA-2026:56928",
                "https://access.redhat.com/errata/RHSA-2026:56968",
                "https://access.redhat.com/errata/RHSA-2026:57013",
                "https://access.redhat.com/errata/RHSA-2026:57487",
                "https://access.redhat.com/errata/RHSA-2026:60520",
                "https://access.redhat.com/errata/RHSA-2026:60855",
                "https://access.redhat.com/errata/RHSA-2026:61783",
                "https://access.redhat.com/security/cve/CVE-2026-6322",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2466684",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6322.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-05T11:16:33.360",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6322"
                }
            ]
        },
        {
            "id": "CVE-2026-6321",
            "vendor": "fast-uri",
            "product": "fast-uri",
            "title": "fast-uri vulnerability",
            "summary": "fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Versions <= 3.1.0 are affected. Update to 3.1.1 or later.",
            "updated_at": "2026-09-10T13:20:28.160",
            "published_at": "2026-05-04T20:16:20.950",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.1.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 26,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like real slashes and parent-directory references, so distinct URIs could collapse onto the same normalized path. Applications that normalize or compare attacker-controlled URLs to enforce path-based policy can be bypassed, with a path that appears confined under an allowed prefix normalizing to a different location. Versions <= 3.1.0 are affected. Update to 3.1.1 or later.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/fastify/fast-uri/security/advisories/GHSA-q3j6-qgpj-74h6",
                "https://access.redhat.com/errata/RHSA-2026:19238",
                "https://access.redhat.com/errata/RHSA-2026:20338",
                "https://access.redhat.com/errata/RHSA-2026:21338",
                "https://access.redhat.com/errata/RHSA-2026:24473",
                "https://access.redhat.com/errata/RHSA-2026:24766",
                "https://access.redhat.com/errata/RHSA-2026:24866",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:25089",
                "https://access.redhat.com/errata/RHSA-2026:25123",
                "https://access.redhat.com/errata/RHSA-2026:26214",
                "https://access.redhat.com/errata/RHSA-2026:26234",
                "https://access.redhat.com/errata/RHSA-2026:26416",
                "https://access.redhat.com/errata/RHSA-2026:26420",
                "https://access.redhat.com/errata/RHSA-2026:34342",
                "https://access.redhat.com/errata/RHSA-2026:37385",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:42079",
                "https://access.redhat.com/errata/RHSA-2026:56366",
                "https://access.redhat.com/errata/RHSA-2026:56431",
                "https://access.redhat.com/errata/RHSA-2026:56928",
                "https://access.redhat.com/errata/RHSA-2026:57013",
                "https://access.redhat.com/security/cve/CVE-2026-6321",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2466582",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6321.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-04T20:16:20.950",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6321"
                }
            ]
        },
        {
            "id": "CVE-2026-6276",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.",
            "updated_at": "2026-09-15T07:16:29.343",
            "published_at": "2026-05-13T13:01:56.800",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.71.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.0 (semver); e15e51384a423be31318b3c9c7d612a1aae661fd through before 3a19987a87f393d9394fe5acc7643f6c263c92db (git); 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-346",
            "what_happened": "Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3671818"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-6276.html",
                "https://curl.se/docs/CVE-2026-6276.json",
                "https://hackerone.com/reports/3671818",
                "http://www.openwall.com/lists/oss-security/2026/04/29/13"
            ],
            "timeline": [
                {
                    "at": "2026-05-13T13:01:56.800",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6276"
                }
            ]
        },
        {
            "id": "CVE-2026-6253",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy",
            "updated_at": "2026-09-15T07:16:29.073",
            "published_at": "2026-05-13T13:01:56.570",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.14.1 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.0 (semver); 3b60bb725913ce7339aefef0a14b12df4c24db60 through before 188c2f166a20fa97c2325b2da7d0e5cecc13725f (git); 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0; 7.32.0; 7.31.0; 7.30.0; 7.29.0; 7.28.1; 7.28.0; 7.27.0; 7.26.0; 7.25.0; 7.24.0; 7.23.1; 7.23.0; 7.22.0; 7.21.7; 7.21.6; 7.21.5; 7.21.4; 7.21.3; 7.21.2; 7.21.1; 7.21.0; 7.20.1; 7.20.0; 7.19.7; 7.19.6; 7.19.5; 7.19.4; 7.19.3; 7.19.2; 7.19.1; 7.19.0; 7.18.2; 7.18.1; 7.18.0; 7.17.1; 7.17.0; 7.16.4; 7.16.3; 7.16.2; 7.16.1; 7.16.0; 7.15.5; 7.15.4; 7.15.3; 7.15.2; 7.15.1; 7.15.0; 7.14.1",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-522",
            "what_happened": "curl might erroneously pass on credentials for a first proxy to a second\nproxy.\n\nThis can happen when the following conditions are true:\n\n1. curl is setup to use specific different proxies for different URL schemes\n2. the first proxy needs credentials\n3. the second proxy uses no credentials\n4. while using the first proxy (using say `http://`), curl is asked to follow\n   a redirect to a URL using another scheme (say `https://`), accessed using a\n   second, different, proxy",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3669637"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-6253.html",
                "https://curl.se/docs/CVE-2026-6253.json",
                "https://hackerone.com/reports/3669637",
                "http://www.openwall.com/lists/oss-security/2026/04/29/11"
            ],
            "timeline": [
                {
                    "at": "2026-05-13T13:01:56.570",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6253"
                }
            ]
        },
        {
            "id": "CVE-2026-6244",
            "vendor": "The Tcpdump Group",
            "product": "libpcap",
            "title": "libpcap vulnerability",
            "summary": "libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero.  In particular uncommon use cases a crafted filter program can cause a division by zero.",
            "updated_at": "2026-09-05T19:16:55.950",
            "published_at": "2026-09-05T19:16:55.950",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.10.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-369",
            "what_happened": "libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero.  In particular uncommon use cases a crafted filter program can cause a division by zero.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T19:16:55.950",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-6244"
                }
            ]
        },
        {
            "id": "CVE-2026-5856",
            "vendor": "Contiki-NG",
            "product": "Contiki-NG",
            "title": "Contiki-NG vulnerability",
            "summary": "Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no packet-boundary check, and the caller in newdata() invokes it in a loop iterating nquestions times from the attacker-controlled DNS header before validating the transaction ID. An attacker who sets nquestions higher than the number of complete questions present causes skip_name() to walk past the UDP packet buffer, and the returned pointer is cast to struct dns_answer * for further memory reads. On builds with RESOLV_CONF_SUPPORTS_MDNS enabled, any peer on the local segment can trigger the read unauthenticated via a multicast UDP 5353 packet with no outstanding query required; on standard DNS builds an attacker who can inject a UDP response from port 53 during an outstanding query can trigger the same read. Impact is out-of-bounds read of uip_buf and adjacent memory, disclosing memory contents or crashing the resolver.",
            "updated_at": "2026-09-16T20:21:01.047",
            "published_at": "2026-08-06T22:18:10.743",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 04a3f0a0067d2ee87d1f297b6d0f4392d8c98ffe (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no packet-boundary check, and the caller in newdata() invokes it in a loop iterating nquestions times from the attacker-controlled DNS header before validating the transaction ID. An attacker who sets nquestions higher than the number of complete questions present causes skip_name() to walk past the UDP packet buffer, and the returned pointer is cast to struct dns_answer * for further memory reads. On builds with RESOLV_CONF_SUPPORTS_MDNS enabled, any peer on the local segment can trigger the read unauthenticated via a multicast UDP 5353 packet with no outstanding query required; on standard DNS builds an attacker who can inject a UDP response from port 53 during an outstanding query can trigger the same read. Impact is out-of-bounds read of uip_buf and adjacent memory, disclosing memory contents or crashing the resolver.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/contiki-ng/contiki-ng",
                "https://github.com/contiki-ng/contiki-ng/commit/04a3f0a0067d2ee87d1f297b6d0f4392d8c98ffe",
                "https://github.com/contiki-ng/contiki-ng/pull/3169"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:10.743",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5856"
                }
            ]
        },
        {
            "id": "CVE-2026-5855",
            "vendor": "Contiki-NG",
            "product": "Contiki-NG",
            "title": "Contiki-NG vulnerability",
            "summary": "Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while there is at least one byte remaining, so a crafted CoAP WRITE to any LwM2M endpoint whose final TLV supplies exactly one byte triggers up to five out-of-bounds reads of heap memory adjacent to the CoAP input buffer, disclosing memory contents (including key material and peer addresses) through the parsed tlv->id, tlv->length, and tlv->value fields. Corrupted tlv_len derived from the out-of-bounds memory further corrupts the caller's parse offset. In LwM2M NoSec mode, the default for constrained devices, no authentication is required.",
            "updated_at": "2026-09-16T20:21:01.047",
            "published_at": "2026-08-06T22:18:10.590",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before f1673b5766d4d4d514cefb8a0350f43653574997 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while there is at least one byte remaining, so a crafted CoAP WRITE to any LwM2M endpoint whose final TLV supplies exactly one byte triggers up to five out-of-bounds reads of heap memory adjacent to the CoAP input buffer, disclosing memory contents (including key material and peer addresses) through the parsed tlv->id, tlv->length, and tlv->value fields. Corrupted tlv_len derived from the out-of-bounds memory further corrupts the caller's parse offset. In LwM2M NoSec mode, the default for constrained devices, no authentication is required.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/contiki-ng/contiki-ng",
                "https://github.com/contiki-ng/contiki-ng/commit/f1673b5766d4d4d514cefb8a0350f43653574997",
                "https://github.com/contiki-ng/contiki-ng/pull/3165"
            ],
            "timeline": [
                {
                    "at": "2026-08-06T22:18:10.590",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5855"
                }
            ]
        },
        {
            "id": "CVE-2026-5846",
            "vendor": "Watchfire",
            "product": "BC550",
            "title": "BC550 vulnerability",
            "summary": "The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.",
            "updated_at": "2026-09-08T19:30:43.093",
            "published_at": "2026-07-30T22:16:55.107",
            "cvss": 7.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "12.30; 11.33; 12.35; 12.38; 13.00; 12.39",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-321",
            "what_happened": "The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries in the firmware directly from Watchfire's Remote Support filestore.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-211-09.json",
                "https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-09"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T22:16:55.107",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5846"
                }
            ]
        },
        {
            "id": "CVE-2026-5795",
            "vendor": "Eclipse Foundation",
            "product": "Eclipse Jetty",
            "title": "Eclipse Jetty vulnerability",
            "summary": "In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.\n\n\nUpon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals.\n\n\nA subsequent request using the same thread inherits the ThreadLocal values, leading to a broken access control and privilege escalation.",
            "updated_at": "2026-09-14T13:18:42.263",
            "published_at": "2026-04-08T14:16:32.633",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "12.1.0 through 12.1.7 (semver); 12.0.0 through 12.0.33 (semver); 11.0.0 through 11.0.28 (semver); 10.0.0 through 10.0.28 (semver); 9.4.0 through 9.4.60 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-226",
            "what_happened": "In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.\n\n\nUpon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals.\n\n\nA subsequent request using the same thread inherits the ThreadLocal values, leading to a broken access control and privilege escalation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/jetty/jetty.project/security/advisories/GHSA-r7p8-xq5m-436chttps://",
                "https://gitlab.eclipse.org/security/cve-assignment/-/issues/92",
                "https://access.redhat.com/errata/RHSA-2026:17668",
                "https://access.redhat.com/errata/RHSA-2026:25089",
                "https://access.redhat.com/errata/RHSA-2026:28573",
                "https://access.redhat.com/security/cve/CVE-2026-5795",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2456519",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5795.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-08T14:16:32.633",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5795"
                }
            ]
        },
        {
            "id": "CVE-2026-5773",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.",
            "updated_at": "2026-09-15T07:16:28.820",
            "published_at": "2026-05-13T13:01:56.307",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.40.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.0 (semver); aec2e865f06669b9cb5d26cc1148d70bc418b163 through before 74a169575d6412dc0ff532acdf94de35a6c2a571 (git); 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-488",
            "what_happened": "libcurl might in some circumstances reuse the wrong connection for SMB(S)\ntransfers.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a network transfer operation that was requested by an\napplication could wrongfully reuse an existing SMB connection to the same\nserver that was using a different \"share\" than the new subsequent transfer\nshould.\n\nThis could in unlucky situations lead to the download of the wrong file or the\nupload of a file to the wrong place. When this happens, the same credentials\nare used and the server name is the same.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3650689"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-5773.html",
                "https://curl.se/docs/CVE-2026-5773.json",
                "https://hackerone.com/reports/3650689",
                "http://www.openwall.com/lists/oss-security/2026/04/29/9"
            ],
            "timeline": [
                {
                    "at": "2026-05-13T13:01:56.307",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5773"
                }
            ]
        },
        {
            "id": "CVE-2026-5704",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.",
            "updated_at": "2026-09-10T22:16:58.033",
            "published_at": "2026-04-06T16:16:42.140",
            "cvss": 5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 79,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "bugzilla.redhat.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2455360"
                },
                {
                    "repository": "www.openwall.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://www.openwall.com/lists/oss-security/2026/04/11/10"
                },
                {
                    "repository": "www.openwall.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://www.openwall.com/lists/oss-security/2026/04/12/2"
                }
            ],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:61581",
                "https://access.redhat.com/errata/RHSA-2026:61586",
                "https://access.redhat.com/errata/RHSA-2026:61783",
                "https://access.redhat.com/errata/RHSA-2026:66018",
                "https://access.redhat.com/security/cve/CVE-2026-5704",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2455360",
                "http://www.openwall.com/lists/oss-security/2026/04/11/10",
                "http://www.openwall.com/lists/oss-security/2026/04/11/11",
                "http://www.openwall.com/lists/oss-security/2026/04/12/2",
                "https://access.redhat.com/errata/RHSA-2026:66514"
            ],
            "timeline": [
                {
                    "at": "2026-04-06T16:16:42.140",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5704"
                }
            ]
        },
        {
            "id": "CVE-2026-5680",
            "vendor": "Red Hat",
            "product": "Red Hat build of Apache Camel for Spring Boot 4",
            "title": "Red Hat build of Apache Camel for Spring Boot 4 vulnerability",
            "summary": "A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.",
            "updated_at": "2026-09-07T09:17:15.713",
            "published_at": "2026-08-27T17:18:58.397",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/security/cve/CVE-2026-5680",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2455350"
            ],
            "timeline": [
                {
                    "at": "2026-08-27T17:18:58.397",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5680"
                }
            ]
        },
        {
            "id": "CVE-2026-5598",
            "vendor": "Legion of the Bouncy Castle Inc.",
            "product": "BC-JAVA",
            "title": "BC-JAVA vulnerability",
            "summary": "Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules).\n\n This vulnerability is associated with program files FrodoEngine.Java.\n\n\n\nThis issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.",
            "updated_at": "2026-09-10T13:20:27.280",
            "published_at": "2026-04-15T10:16:49.757",
            "cvss": 8.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Red",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.71 through before 1.80.2 (maven); 1.81 through before 1.81.1 (maven); 1.82 through before 1.84 (maven)",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-385",
            "what_happened": "Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules).\n\n This vulnerability is associated with program files FrodoEngine.Java.\n\n\n\nThis issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/bcgit/bc-java/commit/8692e6b2b191fc4aafa32545c7a78bdb9bf110c5",
                "https://github.com/bcgit/bc-java/commit/94abbd56413dfdac651fd878bc60253871ef5e87",
                "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905598",
                "https://access.redhat.com/errata/RHSA-2026:12267",
                "https://access.redhat.com/errata/RHSA-2026:12269",
                "https://access.redhat.com/errata/RHSA-2026:18054",
                "https://access.redhat.com/errata/RHSA-2026:18055",
                "https://access.redhat.com/errata/RHSA-2026:18059",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/security/cve/CVE-2026-5598",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2458635",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5598.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-15T10:16:49.757",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5598"
                }
            ]
        },
        {
            "id": "CVE-2026-5588",
            "vendor": "Legion of the Bouncy Castle Inc.",
            "product": "BC-JAVA",
            "title": "BC-JAVA vulnerability",
            "summary": "Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules).\n\n This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java.\n\n\n\nThis issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11.",
            "updated_at": "2026-09-11T13:18:16.490",
            "published_at": "2026-04-15T10:16:49.597",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.67 through before 1.80.2 (maven); 1.81 through before 1.81.1 (maven); 1.82 through before 1.84 (maven); 2.0.6 through before 2.0.11 (maven); 2.1.7 through before 2.1.11 (maven); 2.73.7 through before 2.73.11 (maven)",
            "fixed": "See vendor advisory",
            "source_count": 29,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-327",
            "what_happened": "Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules).\n\n This vulnerability is associated with program files JcaContentVerifierProviderBuilder.Java, JcaContentVerfierProviderBuilder.Java.\n\n\n\nThis issue affects BC-JAVA: from 1.67 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84; BCPKIX-FIPS: from 2.0.6 before 2.0.11, from 2.1.7 before 2.1.11; BCPIX-LTS: from 2.73.7 before 2.73.11.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/bcgit/bc-java/commit/656bae0dbd9b1521f840521ff786e78749fe3057",
                "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%905588",
                "https://access.redhat.com/errata/RHSA-2026:11720",
                "https://access.redhat.com/errata/RHSA-2026:11721",
                "https://access.redhat.com/errata/RHSA-2026:13631",
                "https://access.redhat.com/errata/RHSA-2026:14272",
                "https://access.redhat.com/errata/RHSA-2026:14276",
                "https://access.redhat.com/errata/RHSA-2026:17668",
                "https://access.redhat.com/errata/RHSA-2026:18054",
                "https://access.redhat.com/errata/RHSA-2026:18055",
                "https://access.redhat.com/errata/RHSA-2026:18059",
                "https://access.redhat.com/errata/RHSA-2026:21772",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/errata/RHSA-2026:60239",
                "https://access.redhat.com/errata/RHSA-2026:60246",
                "https://access.redhat.com/errata/RHSA-2026:60247",
                "https://access.redhat.com/errata/RHSA-2026:60248",
                "https://access.redhat.com/errata/RHSA-2026:60249",
                "https://access.redhat.com/errata/RHSA-2026:60250",
                "https://access.redhat.com/errata/RHSA-2026:60251",
                "https://access.redhat.com/errata/RHSA-2026:60252",
                "https://access.redhat.com/errata/RHSA-2026:60254",
                "https://access.redhat.com/errata/RHSA-2026:60256",
                "https://access.redhat.com/errata/RHSA-2026:60259",
                "https://access.redhat.com/security/cve/CVE-2026-5588",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2458634",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-5588.json",
                "https://access.redhat.com/errata/RHSA-2026:66488"
            ],
            "timeline": [
                {
                    "at": "2026-04-15T10:16:49.597",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5588"
                }
            ]
        },
        {
            "id": "CVE-2026-5545",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...",
            "updated_at": "2026-09-15T07:16:28.633",
            "published_at": "2026-05-13T13:01:56.190",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.10.6 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.0 (semver); e56ae1426cb7a0a4a427cf8d6099a821fdaae428 through before 33e43985b8f3b9e66691d06e70be0395849856cd (git); 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0; 7.32.0; 7.31.0; 7.30.0; 7.29.0; 7.28.1; 7.28.0; 7.27.0; 7.26.0; 7.25.0; 7.24.0; 7.23.1; 7.23.0; 7.22.0; 7.21.7; 7.21.6; 7.21.5; 7.21.4; 7.21.3; 7.21.2; 7.21.1; 7.21.0; 7.20.1; 7.20.0; 7.19.7; 7.19.6; 7.19.5; 7.19.4; 7.19.3; 7.19.2; 7.19.1; 7.19.0; 7.18.2; 7.18.1; 7.18.0; 7.17.1; 7.17.0; 7.16.4; 7.16.3; 7.16.2; 7.16.1; 7.16.0; 7.15.5; 7.15.4; 7.15.3; 7.15.2; 7.15.1; 7.15.0; 7.14.1; 7.14.0; 7.13.2; 7.13.1; 7.13.0; 7.12.3; 7.12.2; 7.12.1; 7.12.0; 7.11.2; 7.11.1; 7.11.0; 7.10.8; 7.10.7; 7.10.6",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-305",
            "what_happened": "libcurl might in some circumstances reuse the wrong connection when asked to\ndo an authenticated HTTP(S) request after a Negotiate-authenticated one, when\nboth use the same host.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criteria must be met. Due to a logical\nerror in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials.\n\nAn application that first uses Negotiate authentication to a server with\n`user1:password1` and then does another operation to the same server asking\nfor any authentication method but for `user2:password2` (while the previous\nconnection is still alive) - the second request gets confused and wrongly\nreuses the same connection and sends the new request over that connection\nthinking it uses a mix of user1's and user2's credentials when it is in fact\nstill using the connection authenticated for user1...",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3642555"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-5545.html",
                "https://curl.se/docs/CVE-2026-5545.json",
                "https://hackerone.com/reports/3642555"
            ],
            "timeline": [
                {
                    "at": "2026-05-13T13:01:56.190",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-5545"
                }
            ]
        },
        {
            "id": "CVE-2026-5281",
            "vendor": "Google",
            "product": "Dawn",
            "title": "Google Dawn Use-After-Free Vulnerability",
            "summary": "Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.",
            "updated_at": "2026-08-26T08:07:16Z",
            "published_at": "2026-08-26T08:07:16Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 420,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "Google Dawn contains an use-after-free vulnerability that could allow a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. This vulnerability could affect multiple Chromium-based products including, but not limited to, Google Chrome, Microsoft Edge, and Opera.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · jaf0rk/CVE-2026-5281-CVE-2026-11057-fullchain",
                    "author": "jaf0rk",
                    "first_seen": "2026-08-25",
                    "last_seen": "2026-08-26T08:07:16Z",
                    "pushed_at": "2026-08-26T08:03:18Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "HTML",
                    "stars": 1,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-5281-CVE-2026-11057-fullchain",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/jaf0rk/CVE-2026-5281-CVE-2026-11057-fullchain",
                    "cvss": 8.8,
                    "severity": "HIGH",
                    "cve_description": "Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-416",
                    "kev": true,
                    "epss": 0.04938,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-01",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · TheMalwareGuardian/CVE-2026-5281",
                    "author": "TheMalwareGuardian",
                    "first_seen": "2026-04-06",
                    "last_seen": "2026-07-23T13:54:17Z",
                    "pushed_at": "2026-04-07T18:24:14Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 2,
                    "forks": 1,
                    "topics": [
                        "browser-exploitation",
                        "cve-2026-5281",
                        "google-chrome"
                    ],
                    "title": "CVE-2026-5281 (Chrome Dawn WebGPU UAF) analysis, lab validation tools, and reproducible environment for vulnerable vs patched builds.",
                    "repository_description": "CVE-2026-5281 (Chrome Dawn WebGPU UAF) analysis, lab validation tools, and reproducible environment for vulnerable vs patched builds.",
                    "summary": "CVE-2026-5281 (Chrome Dawn WebGPU UAF) analysis, lab validation tools, and reproducible environment for vulnerable vs patched builds.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/TheMalwareGuardian/CVE-2026-5281",
                    "cvss": 8.8,
                    "severity": "HIGH",
                    "cve_description": "Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-416",
                    "kev": true,
                    "epss": 0.04938,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-01",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · jaf0rk/CVE-2026-5281",
                    "author": "jaf0rk",
                    "first_seen": "2026-05-22",
                    "last_seen": "2026-07-18T02:15:41Z",
                    "pushed_at": "2026-07-18T02:15:38Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "HTML",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-5281",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/jaf0rk/CVE-2026-5281",
                    "cvss": 8.8,
                    "severity": "HIGH",
                    "cve_description": "Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-416",
                    "kev": true,
                    "epss": 0.04938,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-01",
                    "cve_status": "Analyzed"
                },
                {
                    "repository": "CVE-Intel · umair-aziz025/CVE-2026-5281-Research-Toolkit",
                    "author": "umair-aziz025",
                    "first_seen": "2026-04-02",
                    "last_seen": "2026-06-21T01:44:18Z",
                    "pushed_at": "2026-04-02T03:45:14Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 4,
                    "forks": 6,
                    "topics": [],
                    "title": "Chrome WebGPU Use-After-Free (CWE-416)  This toolkit is for security research and defensive verification around CVE-2026-5281. Patched Chrome version: 146.0.7680.178 Potentially vulnerable versions: anything below 146.0.7680.178",
                    "repository_description": "Chrome WebGPU Use-After-Free (CWE-416)  This toolkit is for security research and defensive verification around CVE-2026-5281. Patched Chrome version: 146.0.7680.178 Potentially vulnerable versions: anything below 146.0.7680.178",
                    "summary": "Chrome WebGPU Use-After-Free (CWE-416)  This toolkit is for security research and defensive verification around CVE-2026-5281. Patched Chrome version: 146.0.7680.178 Potentially vulnerable versions: anything below 146.0.7680.178",
                    "source": "CVE-Intel",
                    "url": "https://github.com/umair-aziz025/CVE-2026-5281-Research-Toolkit",
                    "cvss": 8.8,
                    "severity": "HIGH",
                    "cve_description": "Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-416",
                    "kev": true,
                    "epss": 0.04938,
                    "metadata_source": "CNA",
                    "cve_published_at": "2026-04-01",
                    "cve_status": "Analyzed"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/jaf0rk/CVE-2026-5281-CVE-2026-11057-fullchain",
                "https://github.com/TheMalwareGuardian/CVE-2026-5281",
                "https://github.com/jaf0rk/CVE-2026-5281",
                "https://github.com/umair-aziz025/CVE-2026-5281-Research-Toolkit"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T08:07:16Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "epss": 0.04938,
            "severity": "HIGH",
            "metadata_source": "CNA",
            "cve_status": "Analyzed",
            "cve_published_at": "2026-04-01",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-5027",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Langflow  1.8.4 - Path Traversal to Remote Code Execution",
            "summary": "Langflow  1.8.4 - Path Traversal to Remote Code Execution",
            "updated_at": "2026-08-30T22:00:00Z",
            "published_at": "2026-08-30T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 96,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52659",
                    "author": "cardosource",
                    "first_seen": "2026-08-31",
                    "confidence": "High",
                    "title": "Langflow  1.8.4 - Path Traversal to Remote Code Execution",
                    "summary": "Langflow  1.8.4 - Path Traversal to Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/52659",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52659"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52659"
                }
            ]
        },
        {
            "id": "CVE-2026-4948",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.",
            "updated_at": "2026-09-16T13:18:01.110",
            "published_at": "2026-03-27T06:16:39.543",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "up to 2.4.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-279",
            "what_happened": "A flaw was found in firewalld. A local unprivileged user can exploit this vulnerability by mis-authorizing two runtime D-Bus (Desktop Bus) setters, setZoneSettings2 and setPolicySettings. This mis-authorization allows the user to modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHBA-2026:28238",
                "https://access.redhat.com/errata/RHSA-2026:67585",
                "https://access.redhat.com/errata/RHSA-2026:67843",
                "https://access.redhat.com/security/cve/CVE-2026-4948",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2452086",
                "https://lists.debian.org/debian-lts-announce/2026/05/msg00029.html"
            ],
            "timeline": [
                {
                    "at": "2026-03-27T06:16:39.543",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4948"
                }
            ]
        },
        {
            "id": "CVE-2026-4926",
            "vendor": "path-to-regexp",
            "product": "path-to-regexp",
            "title": "path-to-regexp vulnerability",
            "summary": "Impact:\n\nA bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service.\n\nPatches:\n\nFixed in version 8.4.0.\n\nWorkarounds:\n\nLimit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.",
            "updated_at": "2026-09-07T13:20:21.263",
            "published_at": "2026-03-26T19:17:08.387",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.0.0 through before 8.4.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Impact:\n\nA bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service.\n\nPatches:\n\nFixed in version 8.4.0.\n\nWorkarounds:\n\nLimit the number of sequential optional groups in route patterns. Avoid passing user-controlled input as route patterns.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://access.redhat.com/errata/RHSA-2026:10153",
                "https://access.redhat.com/errata/RHSA-2026:10172",
                "https://access.redhat.com/errata/RHSA-2026:10175",
                "https://access.redhat.com/errata/RHSA-2026:13545",
                "https://access.redhat.com/errata/RHSA-2026:13826",
                "https://access.redhat.com/errata/RHSA-2026:17789",
                "https://access.redhat.com/errata/RHSA-2026:19409",
                "https://access.redhat.com/errata/RHSA-2026:19410",
                "https://access.redhat.com/errata/RHSA-2026:24761",
                "https://access.redhat.com/errata/RHSA-2026:24762",
                "https://access.redhat.com/errata/RHSA-2026:24866",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:50300",
                "https://access.redhat.com/errata/RHSA-2026:9385",
                "https://access.redhat.com/errata/RHSA-2026:9742",
                "https://access.redhat.com/security/cve/CVE-2026-4926",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451867",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4926.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-26T19:17:08.387",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4926"
                }
            ]
        },
        {
            "id": "CVE-2026-4897",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.",
            "updated_at": "2026-09-10T18:18:01.857",
            "published_at": "2026-03-26T15:16:43.017",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:59997",
                "https://access.redhat.com/errata/RHSA-2026:66287",
                "https://access.redhat.com/security/cve/CVE-2026-4897",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451739"
            ],
            "timeline": [
                {
                    "at": "2026-03-26T15:16:43.017",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4897"
                }
            ]
        },
        {
            "id": "CVE-2026-4878",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.",
            "updated_at": "2026-09-08T16:18:08.520",
            "published_at": "2026-04-09T16:16:31.987",
            "cvss": 6.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 135,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-367",
            "what_happened": "A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "www.openwall.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-09",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://www.openwall.com/lists/oss-security/2026/04/09/5"
                },
                {
                    "repository": "www.openwall.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-09",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://www.openwall.com/lists/oss-security/2026/04/09/6"
                }
            ],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:12423",
                "https://access.redhat.com/errata/RHSA-2026:12441",
                "https://access.redhat.com/errata/RHSA-2026:13285",
                "https://access.redhat.com/errata/RHSA-2026:14162",
                "https://access.redhat.com/errata/RHSA-2026:14937",
                "https://access.redhat.com/errata/RHSA-2026:19130",
                "https://access.redhat.com/errata/RHSA-2026:19346",
                "https://access.redhat.com/errata/RHSA-2026:19456",
                "https://access.redhat.com/errata/RHSA-2026:19458",
                "https://access.redhat.com/errata/RHSA-2026:20595",
                "https://access.redhat.com/errata/RHSA-2026:21254",
                "https://access.redhat.com/errata/RHSA-2026:21275",
                "https://access.redhat.com/errata/RHSA-2026:22634",
                "https://access.redhat.com/errata/RHSA-2026:22957",
                "https://access.redhat.com/errata/RHSA-2026:23233",
                "https://access.redhat.com/errata/RHSA-2026:23245",
                "https://access.redhat.com/errata/RHSA-2026:24346",
                "https://access.redhat.com/errata/RHSA-2026:25044",
                "https://access.redhat.com/errata/RHSA-2026:25096",
                "https://access.redhat.com/errata/RHSA-2026:25181",
                "https://access.redhat.com/errata/RHSA-2026:26542",
                "https://access.redhat.com/errata/RHSA-2026:27998",
                "https://access.redhat.com/errata/RHSA-2026:28887",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:30078",
                "https://access.redhat.com/errata/RHSA-2026:30087",
                "https://access.redhat.com/errata/RHSA-2026:30088",
                "https://access.redhat.com/errata/RHSA-2026:30089",
                "https://access.redhat.com/errata/RHSA-2026:34098",
                "https://access.redhat.com/errata/RHSA-2026:39981",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/errata/RHSA-2026:59831",
                "https://access.redhat.com/errata/RHSA-2026:7473",
                "https://access.redhat.com/security/cve/CVE-2026-4878",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2447554",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451615",
                "http://www.openwall.com/lists/oss-security/2026/04/07/14",
                "http://www.openwall.com/lists/oss-security/2026/04/07/4",
                "http://www.openwall.com/lists/oss-security/2026/04/08/9",
                "http://www.openwall.com/lists/oss-security/2026/04/09/5",
                "http://www.openwall.com/lists/oss-security/2026/04/09/6",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4878.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-09T16:16:31.987",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4878"
                }
            ]
        },
        {
            "id": "CVE-2026-4873",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.",
            "updated_at": "2026-09-15T07:16:28.367",
            "published_at": "2026-05-13T13:01:55.893",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.20.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.0 (semver); ec3bb8f727405642a471b4b1b9eb0118fc003104 through before 507e7be573b0a76fca597b75ff7cb27a66e7d865 (git); 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0; 7.32.0; 7.31.0; 7.30.0; 7.29.0; 7.28.1; 7.28.0; 7.27.0; 7.26.0; 7.25.0; 7.24.0; 7.23.1; 7.23.0; 7.22.0; 7.21.7; 7.21.6; 7.21.5; 7.21.4; 7.21.3; 7.21.2; 7.21.1; 7.21.0; 7.20.1; 7.20.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-319",
            "what_happened": "A vulnerability exists where a connection requiring TLS incorrectly reuses an\nexisting unencrypted connection from the same connection pool. If an initial\ntransfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request\nto that same host bypasses the TLS requirement and instead transmit data\nunencrypted.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-05-13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3621851"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-4873.html",
                "https://curl.se/docs/CVE-2026-4873.json",
                "https://hackerone.com/reports/3621851",
                "http://www.openwall.com/lists/oss-security/2026/04/29/7"
            ],
            "timeline": [
                {
                    "at": "2026-05-13T13:01:55.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4873"
                }
            ]
        },
        {
            "id": "CVE-2026-4800",
            "vendor": "lodash",
            "product": "lodash",
            "title": "lodash vulnerability",
            "summary": "Impact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function().\n\nPatches:\n\nUsers should upgrade to version 4.18.0.\n\nWorkarounds:\n\nDo not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.",
            "updated_at": "2026-09-10T13:20:23.210",
            "published_at": "2026-03-31T20:16:29.660",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.18.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 81,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-94",
            "what_happened": "Impact:\n\nThe fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation to options.imports key names. Both paths flow into the same Function() constructor sink.\n\nWhen an application passes untrusted input as options.imports key names, an attacker can inject default-parameter expressions that execute arbitrary code at template compilation time.\n\nAdditionally, _.template uses assignInWith to merge imports, which enumerates inherited properties via for..in. If Object.prototype has been polluted by any other vector, the polluted keys are copied into the imports object and passed to Function().\n\nPatches:\n\nUsers should upgrade to version 4.18.0.\n\nWorkarounds:\n\nDo not pass untrusted input as key names in options.imports. Only use developer-controlled, static key names.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cna.openjsf.org/security-advisories.html",
                "https://github.com/advisories/GHSA-35jh-r3h4-6jhm",
                "https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c",
                "https://access.redhat.com/errata/RHBA-2026:21387",
                "https://access.redhat.com/errata/RHSA-2026:10131",
                "https://access.redhat.com/errata/RHSA-2026:10175",
                "https://access.redhat.com/errata/RHSA-2026:10710",
                "https://access.redhat.com/errata/RHSA-2026:10713",
                "https://access.redhat.com/errata/RHSA-2026:11454",
                "https://access.redhat.com/errata/RHSA-2026:11469",
                "https://access.redhat.com/errata/RHSA-2026:11470",
                "https://access.redhat.com/errata/RHSA-2026:11471",
                "https://access.redhat.com/errata/RHSA-2026:11493",
                "https://access.redhat.com/errata/RHSA-2026:11494",
                "https://access.redhat.com/errata/RHSA-2026:11495",
                "https://access.redhat.com/errata/RHSA-2026:11516",
                "https://access.redhat.com/errata/RHSA-2026:12277",
                "https://access.redhat.com/errata/RHSA-2026:12279",
                "https://access.redhat.com/errata/RHSA-2026:13545",
                "https://access.redhat.com/errata/RHSA-2026:13553",
                "https://access.redhat.com/errata/RHSA-2026:13571",
                "https://access.redhat.com/errata/RHSA-2026:13826",
                "https://access.redhat.com/errata/RHSA-2026:14870",
                "https://access.redhat.com/errata/RHSA-2026:14871",
                "https://access.redhat.com/errata/RHSA-2026:16874",
                "https://access.redhat.com/errata/RHSA-2026:17448",
                "https://access.redhat.com/errata/RHSA-2026:17468",
                "https://access.redhat.com/errata/RHSA-2026:17469",
                "https://access.redhat.com/errata/RHSA-2026:17547",
                "https://access.redhat.com/errata/RHSA-2026:17549",
                "https://access.redhat.com/errata/RHSA-2026:17550",
                "https://access.redhat.com/errata/RHSA-2026:17598",
                "https://access.redhat.com/errata/RHSA-2026:17789",
                "https://access.redhat.com/errata/RHSA-2026:19008",
                "https://access.redhat.com/errata/RHSA-2026:19167",
                "https://access.redhat.com/errata/RHSA-2026:19409",
                "https://access.redhat.com/errata/RHSA-2026:19410",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:20041",
                "https://access.redhat.com/errata/RHSA-2026:20042",
                "https://access.redhat.com/errata/RHSA-2026:20943",
                "https://access.redhat.com/errata/RHSA-2026:20946",
                "https://access.redhat.com/errata/RHSA-2026:21658",
                "https://access.redhat.com/errata/RHSA-2026:22619",
                "https://access.redhat.com/errata/RHSA-2026:24331",
                "https://access.redhat.com/errata/RHSA-2026:24762",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:29795",
                "https://access.redhat.com/errata/RHSA-2026:34100",
                "https://access.redhat.com/errata/RHSA-2026:34342",
                "https://access.redhat.com/errata/RHSA-2026:34608",
                "https://access.redhat.com/errata/RHSA-2026:36621",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:37186",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40795",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:40984",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41941",
                "https://access.redhat.com/errata/RHSA-2026:41944",
                "https://access.redhat.com/errata/RHSA-2026:42078",
                "https://access.redhat.com/errata/RHSA-2026:44235",
                "https://access.redhat.com/errata/RHSA-2026:48699",
                "https://access.redhat.com/errata/RHSA-2026:54188",
                "https://access.redhat.com/errata/RHSA-2026:56789",
                "https://access.redhat.com/errata/RHSA-2026:56854",
                "https://access.redhat.com/errata/RHSA-2026:56912",
                "https://access.redhat.com/errata/RHSA-2026:59833",
                "https://access.redhat.com/errata/RHSA-2026:60023",
                "https://access.redhat.com/errata/RHSA-2026:8483",
                "https://access.redhat.com/errata/RHSA-2026:8484",
                "https://access.redhat.com/errata/RHSA-2026:8490",
                "https://access.redhat.com/errata/RHSA-2026:8491",
                "https://access.redhat.com/errata/RHSA-2026:8493",
                "https://access.redhat.com/errata/RHSA-2026:8498",
                "https://access.redhat.com/errata/RHSA-2026:9385",
                "https://access.redhat.com/errata/RHSA-2026:9742",
                "https://access.redhat.com/security/cve/CVE-2026-4800",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2453496",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4800.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-31T20:16:29.660",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4800"
                }
            ]
        },
        {
            "id": "CVE-2026-4740",
            "vendor": "Red Hat",
            "product": "multicluster engine for Kubernetes 2.1",
            "title": "multicluster engine for Kubernetes 2.1 vulnerability",
            "summary": "A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster.",
            "updated_at": "2026-09-08T12:16:54.783",
            "published_at": "2026-04-07T15:17:46.797",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 46,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-295",
            "what_happened": "A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "blog.arfevrier.fr",
                    "author": "NVD reference",
                    "first_seen": "2026-04-07",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://blog.arfevrier.fr/open-cluster-management-cross-cluster-escape/"
                }
            ],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:11414",
                "https://access.redhat.com/errata/RHSA-2026:13542",
                "https://access.redhat.com/errata/RHSA-2026:13853",
                "https://access.redhat.com/errata/RHSA-2026:8218",
                "https://access.redhat.com/errata/RHSA-2026:9848",
                "https://access.redhat.com/security/cve/CVE-2026-4740",
                "https://blog.arfevrier.fr/open-cluster-management-cross-cluster-escape/",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2450590",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4740.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-07T15:17:46.797",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4740"
                }
            ]
        },
        {
            "id": "CVE-2026-4602",
            "vendor": "n/a",
            "product": "jsrsasign",
            "title": "jsrsasign vulnerability",
            "summary": "Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.",
            "updated_at": "2026-09-10T13:20:22.877",
            "published_at": "2026-03-23T06:16:22.070",
            "cvss": 7.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 11.1.1 (semver); before * (semver)",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-681",
            "what_happened": "Versions of the package jsrsasign before 11.1.1 are vulnerable to Incorrect Conversion between Numeric Types due to handling negative exponents in ext/jsbn2.js. An attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "gist.github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-23",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gist.github.com/Kr0emer/7ecd2be7d17419e4677315ef3758faf5"
                }
            ],
            "references": [
                "https://gist.github.com/Kr0emer/7ecd2be7d17419e4677315ef3758faf5",
                "https://github.com/kjur/jsrsasign/commit/5ea1c32bb2aa894b4bd29849839afe4f98728195",
                "https://github.com/kjur/jsrsasign/pull/650",
                "https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812274",
                "https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15371175",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19409",
                "https://access.redhat.com/errata/RHSA-2026:19410",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/errata/RHSA-2026:6720",
                "https://access.redhat.com/errata/RHSA-2026:6912",
                "https://access.redhat.com/errata/RHSA-2026:6926",
                "https://access.redhat.com/security/cve/CVE-2026-4602",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2450206",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4602.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-23T06:16:22.070",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4602"
                }
            ]
        },
        {
            "id": "CVE-2026-4601",
            "vendor": "n/a",
            "product": "jsrsasign",
            "title": "jsrsasign vulnerability",
            "summary": "Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.",
            "updated_at": "2026-09-10T13:20:22.510",
            "published_at": "2026-03-23T06:16:21.893",
            "cvss": 8.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:H/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 11.1.1 (semver); before * (semver)",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-325",
            "what_happened": "Versions of the package jsrsasign before 11.1.1 are vulnerable to Missing Cryptographic Step via the KJUR.crypto.DSA.signWithMessageHash process in the DSA signing implementation. An attacker can recover the private key by forcing r or s to be zero, so the library emits an invalid signature without retrying, and then solves for x from the resulting signature.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "gist.github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-23",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gist.github.com/Kr0emer/93789fe6efe5519db9692d4ad1dad586"
                }
            ],
            "references": [
                "https://gist.github.com/Kr0emer/93789fe6efe5519db9692d4ad1dad586",
                "https://github.com/kjur/jsrsasign/commit/0710e392ec35de697ce11e4219c988ba2b5fe0eb",
                "https://github.com/kjur/jsrsasign/pull/645",
                "https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812269",
                "https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370941",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19409",
                "https://access.redhat.com/errata/RHSA-2026:19410",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/errata/RHSA-2026:6720",
                "https://access.redhat.com/errata/RHSA-2026:6912",
                "https://access.redhat.com/errata/RHSA-2026:6926",
                "https://access.redhat.com/security/cve/CVE-2026-4601",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2450209",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4601.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-23T06:16:21.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4601"
                }
            ]
        },
        {
            "id": "CVE-2026-4600",
            "vendor": "n/a",
            "product": "jsrsasign",
            "title": "jsrsasign vulnerability",
            "summary": "Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/dsa-2.0.js). An attacker can forge DSA signatures or X.509 certificates that X509.verifySignature() accepts by supplying malicious domain parameters such as g=1, y=1, and a fixed r=1, which make the verification equation true for any hash.",
            "updated_at": "2026-09-10T13:20:22.247",
            "published_at": "2026-03-23T06:16:21.697",
            "cvss": 8.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 11.1.1 (semver); before * (semver)",
            "fixed": "See vendor advisory",
            "source_count": 41,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-347",
            "what_happened": "Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter validation in KJUR.crypto.DSA.setPublic (and the related DSA/X509 verification flow in src/dsa-2.0.js). An attacker can forge DSA signatures or X.509 certificates that X509.verifySignature() accepts by supplying malicious domain parameters such as g=1, y=1, and a fixed r=1, which make the verification equation true for any hash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "gist.github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-23",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gist.github.com/Kr0emer/bf15ddc097176e951659a24a8e9002a7"
                }
            ],
            "references": [
                "https://gist.github.com/Kr0emer/bf15ddc097176e951659a24a8e9002a7",
                "https://github.com/kjur/jsrsasign/commit/37b4c06b145c7bfd6bc2a6df5d0a12c56b15ef60",
                "https://github.com/kjur/jsrsasign/pull/646",
                "https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812268",
                "https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370940",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19409",
                "https://access.redhat.com/errata/RHSA-2026:19410",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/errata/RHSA-2026:6720",
                "https://access.redhat.com/errata/RHSA-2026:6912",
                "https://access.redhat.com/errata/RHSA-2026:6926",
                "https://access.redhat.com/security/cve/CVE-2026-4600",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2450208",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4600.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-23T06:16:21.697",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4600"
                }
            ]
        },
        {
            "id": "CVE-2026-4599",
            "vendor": "n/a",
            "product": "jsrsasign",
            "title": "jsrsasign vulnerability",
            "summary": "Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.",
            "updated_at": "2026-09-10T13:20:21.650",
            "published_at": "2026-03-23T06:16:21.513",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.0.0 through before 11.1.1 (semver); 8.0.12 through before * (semver)",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1023",
            "what_happened": "Versions of the package jsrsasign from 7.0.0 and before 11.1.1 are vulnerable to Incomplete Comparison with Missing Factors via the getRandomBigIntegerZeroToMax and getRandomBigIntegerMinToMax functions in src/crypto-1.1.js; an attacker can recover the private key by exploiting the incorrect compareTo checks that accept out-of-range candidates and thus bias DSA nonces during signature generation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "gist.github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-23",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gist.github.com/Kr0emer/081681818b51605c91945126d74b4f20"
                }
            ],
            "references": [
                "https://gist.github.com/Kr0emer/081681818b51605c91945126d74b4f20",
                "https://github.com/kjur/jsrsasign/commit/ee4b013478366cb16cea9a4bdfb218b6077f83b1",
                "https://github.com/kjur/jsrsasign/pull/647",
                "https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812264",
                "https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370939",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19409",
                "https://access.redhat.com/errata/RHSA-2026:19410",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/errata/RHSA-2026:6720",
                "https://access.redhat.com/errata/RHSA-2026:6912",
                "https://access.redhat.com/errata/RHSA-2026:6926",
                "https://access.redhat.com/security/cve/CVE-2026-4599",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2450207",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4599.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-23T06:16:21.513",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4599"
                }
            ]
        },
        {
            "id": "CVE-2026-4598",
            "vendor": "n/a",
            "product": "jsrsasign",
            "title": "jsrsasign vulnerability",
            "summary": "Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., modInverse(0, m) or modInverse(-1, m)).",
            "updated_at": "2026-09-10T13:20:20.940",
            "published_at": "2026-03-23T06:16:21.300",
            "cvss": 7.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 11.1.1 (semver); before * (semver)",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-835",
            "what_happened": "Versions of the package jsrsasign before 11.1.1 are vulnerable to Infinite loop via the bnModInverse function in ext/jsbn2.js when the BigInteger.modInverse implementation receives zero or negative inputs, allowing an attacker to hang the process permanently by supplying such crafted values (e.g., modInverse(0, m) or modInverse(-1, m)).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "gist.github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-23",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gist.github.com/Kr0emer/a1bf5cd4547cc630d2dcc5e761de8264"
                }
            ],
            "references": [
                "https://gist.github.com/Kr0emer/a1bf5cd4547cc630d2dcc5e761de8264",
                "https://github.com/kjur/jsrsasign/commit/ca5b027240287a1e71fe63019fc4400332594323",
                "https://github.com/kjur/jsrsasign/pull/648",
                "https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-15812263",
                "https://security.snyk.io/vuln/SNYK-JS-JSRSASIGN-15370938",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19409",
                "https://access.redhat.com/errata/RHSA-2026:19410",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/errata/RHSA-2026:6720",
                "https://access.redhat.com/security/cve/CVE-2026-4598",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2450210",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4598.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-23T06:16:21.300",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4598"
                }
            ]
        },
        {
            "id": "CVE-2026-4361",
            "vendor": "Elegant Themes",
            "product": "Divi",
            "title": "Divi vulnerability",
            "summary": "The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()` instead of `wp_safe_remote_get()` to fetch a remote image URL, which does not restrict requests to private or reserved IP ranges. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application server. The response body is not returned to the attacker (blind SSRF), but two oracles exist: a status oracle (the returned URL string differs depending on whether the target responded with HTTP 200) and a timing oracle (response time varies by target reachability).",
            "updated_at": "2026-09-05T07:17:11.930",
            "published_at": "2026-09-05T07:17:11.930",
            "cvss": 5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.27.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `et_pb_set_video_oembed_thumbnail_resolution()` function using `wp_remote_get()` instead of `wp_safe_remote_get()` to fetch a remote image URL, which does not restrict requests to private or reserved IP ranges. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application server. The response body is not returned to the attacker (blind SSRF), but two oracles exist: a status oracle (the returned URL string differs depending on whether the target responded with HTTP 200) and a timing oracle (response time varies by target reachability).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.divichangelog.com/divi-update/divi-4/version-4-27-7",
                "https://www.elegantthemes.com/",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/f35c0de9-abed-4cbf-a28c-48f8133a1bad?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:11.930",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4361"
                }
            ]
        },
        {
            "id": "CVE-2026-4130",
            "vendor": "NI",
            "product": "SystemLink",
            "title": "SystemLink vulnerability",
            "summary": "There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.",
            "updated_at": "2026-09-12T04:16:36.827",
            "published_at": "2026-09-10T16:17:14.227",
            "cvss": 8.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 26.5.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-312",
            "what_happened": "There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/storage-of-sensitive-information-in-cleartext-in-ni-systemlink.html"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T16:17:14.227",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4130"
                }
            ]
        },
        {
            "id": "CVE-2026-4129",
            "vendor": "NI",
            "product": "SystemLink",
            "title": "SystemLink vulnerability",
            "summary": "There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.",
            "updated_at": "2026-09-12T04:16:36.557",
            "published_at": "2026-09-10T16:17:14.080",
            "cvss": 8.6,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 26.5.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/improper-access-controls-in-ni-systemlink.html"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T16:17:14.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4129"
                }
            ]
        },
        {
            "id": "CVE-2026-3891",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload",
            "summary": "WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload",
            "updated_at": "2026-08-20T22:00:00Z",
            "published_at": "2026-08-20T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 187,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "WooCommerce 1.5.0 Unauthenticated Arbitrary File Upload",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52642",
                    "author": "Mohammad Hossein Sadeghian",
                    "first_seen": "2026-08-17",
                    "confidence": "High",
                    "title": "WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload",
                    "summary": "WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload",
                    "url": "https://www.exploit-db.com/exploits/52642",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "CXSecurity WLB-2026080011",
                    "author": "Mohammad Hossein Sadeghian",
                    "first_seen": "2026-08-21",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "WooCommerce 1.5.0 Unauthenticated Arbitrary File Upload",
                    "summary": "WooCommerce 1.5.0 Unauthenticated Arbitrary File Upload",
                    "what_happened": "WooCommerce 1.5.0 Unauthenticated Arbitrary File Upload",
                    "cvss": 0,
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "url": "https://cxsecurity.com/issue/WLB-2026080011",
                    "cwe": "Unknown"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52642",
                "https://cxsecurity.com/issue/WLB-2026080011"
            ],
            "timeline": [
                {
                    "at": "2026-08-20T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52642"
                }
            ]
        },
        {
            "id": "CVE-2026-3853",
            "vendor": "Elegant Themes",
            "product": "Divi",
            "title": "Divi vulnerability",
            "summary": "The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions up to, and including, 4.27.6. This is due to the `image_src` field not being included in the `$url_options` whitelist (which only contains `url`, `button_link`, `button_url`), so it never receives `esc_url_raw()` at save time. On the server side, the value is rendered into a `data-image` HTML attribute using `esc_attr()`, which encodes double quotes as `&quot;`. However, the client-side JavaScript carousel code in `custom.unified.js` reads this attribute using jQuery's `.data('image')`, which returns the browser-decoded value (with `&quot;` decoded back to `\"`). The decoded value is then concatenated directly into an HTML string and injected into the DOM via `jQuery.after()` without re-escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user hovers over the carousel thumbnail.",
            "updated_at": "2026-09-05T07:17:11.803",
            "published_at": "2026-09-05T07:17:11.803",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 4.27.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider_item` shortcode in all versions up to, and including, 4.27.6. This is due to the `image_src` field not being included in the `$url_options` whitelist (which only contains `url`, `button_link`, `button_url`), so it never receives `esc_url_raw()` at save time. On the server side, the value is rendered into a `data-image` HTML attribute using `esc_attr()`, which encodes double quotes as `&quot;`. However, the client-side JavaScript carousel code in `custom.unified.js` reads this attribute using jQuery's `.data('image')`, which returns the browser-decoded value (with `&quot;` decoded back to `\"`). The decoded value is then concatenated directly into an HTML string and injected into the DOM via `jQuery.after()` without re-escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user hovers over the carousel thumbnail.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.divichangelog.com/divi-update/divi-4/version-4-27-7",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/d5de8f35-266f-45ce-8678-e52a33036b30?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:11.803",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3853"
                }
            ]
        },
        {
            "id": "CVE-2026-3844",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2026-3844",
            "summary": "The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if \"Host Files Locally - Gravatars\" is enabled, which is disabled by default.",
            "updated_at": "2026-08-26T10:21:42Z",
            "published_at": "2026-08-26T10:21:42Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 745,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if \"Host Files Locally - Gravatars\" is enabled, which is disabled by default.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "CVE-Intel · Alevtinka19/CVE-2026-3844",
                    "author": "Alevtinka19",
                    "first_seen": "2026-08-26",
                    "last_seen": "2026-08-26T10:21:42Z",
                    "pushed_at": "2026-08-26T10:19:29Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "PHP",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-3844",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Alevtinka19/CVE-2026-3844",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if \"Host Files Locally - Gravatars\" is enabled, which is disabled by default.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "kev": false,
                    "epss": 0.27701,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-04-23",
                    "cve_status": "Deferred"
                },
                {
                    "repository": "CVE-Intel · AnggaTechI/CVE-2026-3844",
                    "author": "AnggaTechI",
                    "first_seen": "2026-08-08",
                    "last_seen": "2026-08-14T19:56:11Z",
                    "pushed_at": "2026-08-08T12:05:37Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 2,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress).  CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with multi-threading.",
                    "repository_description": "CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress).  CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with multi-threading.",
                    "summary": "CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress).  CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with multi-threading.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/AnggaTechI/CVE-2026-3844",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if \"Host Files Locally - Gravatars\" is enabled, which is disabled by default.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "kev": false,
                    "epss": 0.27701,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-04-23",
                    "cve_status": "Deferred"
                },
                {
                    "repository": "CVE-Intel · tausifzaman/CVE-2026-3844",
                    "author": "tausifzaman",
                    "first_seen": "2026-04-24",
                    "last_seen": "2026-07-24T18:41:06Z",
                    "pushed_at": "2026-04-24T10:28:28Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 3,
                    "forks": 0,
                    "topics": [
                        "automation",
                        "cve",
                        "cve-2026-3844",
                        "exploit",
                        "hacking-script",
                        "hacking-tool",
                        "poc"
                    ],
                    "title": "PoC exploit for CVE-2026-3844, a critical unauthenticated file upload vulnerability in the WordPress Breeze plugin leading to RCE.",
                    "repository_description": "PoC exploit for CVE-2026-3844, a critical unauthenticated file upload vulnerability in the WordPress Breeze plugin leading to RCE.",
                    "summary": "PoC exploit for CVE-2026-3844, a critical unauthenticated file upload vulnerability in the WordPress Breeze plugin leading to RCE.",
                    "source": "CVE-Intel",
                    "url": "https://github.com/tausifzaman/CVE-2026-3844",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if \"Host Files Locally - Gravatars\" is enabled, which is disabled by default.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "kev": false,
                    "epss": 0.27701,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-04-23",
                    "cve_status": "Deferred"
                },
                {
                    "repository": "CVE-Intel · dinosn/CVE-2026-3844",
                    "author": "dinosn",
                    "first_seen": "2026-04-25",
                    "last_seen": "2026-07-08T11:02:10Z",
                    "pushed_at": "2026-04-25T17:53:39Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 5,
                    "forks": 1,
                    "topics": [],
                    "title": "CVE-2026-3844: Breeze Cache <= 2.4.4 Unauthenticated Arbitrary File Upload to RCE (CVSS 9.8)",
                    "repository_description": "CVE-2026-3844: Breeze Cache <= 2.4.4 Unauthenticated Arbitrary File Upload to RCE (CVSS 9.8)",
                    "summary": "CVE-2026-3844: Breeze Cache <= 2.4.4 Unauthenticated Arbitrary File Upload to RCE (CVSS 9.8)",
                    "source": "CVE-Intel",
                    "url": "https://github.com/dinosn/CVE-2026-3844",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if \"Host Files Locally - Gravatars\" is enabled, which is disabled by default.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "kev": false,
                    "epss": 0.27701,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-04-23",
                    "cve_status": "Deferred"
                },
                {
                    "repository": "CVE-Intel · Dhananjayasj/CVE-2026-3844-Breeze-Cache-WordPress-Plugin-Remote-Code-Execution",
                    "author": "Dhananjayasj",
                    "first_seen": "2026-06-06",
                    "last_seen": "2026-06-06T08:38:54Z",
                    "pushed_at": "2026-06-06T08:38:51Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 0,
                    "forks": 0,
                    "topics": [],
                    "title": "CVE-2026-3844-Breeze-Cache-WordPress-Plugin-Remote-Code-Execution",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/Dhananjayasj/CVE-2026-3844-Breeze-Cache-WordPress-Plugin-Remote-Code-Execution",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if \"Host Files Locally - Gravatars\" is enabled, which is disabled by default.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "kev": false,
                    "epss": 0.27701,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-04-23",
                    "cve_status": "Deferred"
                },
                {
                    "repository": "CVE-Intel · 0xgh057r3c0n/CVE-2026-3844",
                    "author": "0xgh057r3c0n",
                    "first_seen": "2026-04-24",
                    "last_seen": "2026-05-27T14:43:58Z",
                    "pushed_at": "2026-04-24T10:18:25Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 1,
                    "forks": 1,
                    "topics": [],
                    "title": "WordPress - Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload",
                    "repository_description": "WordPress - Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload",
                    "summary": "WordPress - Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload",
                    "source": "CVE-Intel",
                    "url": "https://github.com/0xgh057r3c0n/CVE-2026-3844",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if \"Host Files Locally - Gravatars\" is enabled, which is disabled by default.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "kev": false,
                    "epss": 0.27701,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-04-23",
                    "cve_status": "Deferred"
                },
                {
                    "repository": "CVE-Intel · rootdirective-sec/CVE-2026-3844-Lab",
                    "author": "rootdirective-sec",
                    "first_seen": "2026-05-08",
                    "last_seen": "2026-05-15T08:53:24Z",
                    "pushed_at": "2026-05-15T08:53:20Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "Exploit",
                    "language": "Python",
                    "stars": 0,
                    "forks": 1,
                    "topics": [],
                    "title": "CVE-2026-3844-Lab",
                    "repository_description": "",
                    "summary": "",
                    "source": "CVE-Intel",
                    "url": "https://github.com/rootdirective-sec/CVE-2026-3844-Lab",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if \"Host Files Locally - Gravatars\" is enabled, which is disabled by default.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "kev": false,
                    "epss": 0.27701,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-04-23",
                    "cve_status": "Deferred"
                },
                {
                    "repository": "CVE-Intel · halilkirazkaya/CVE-2026-3844",
                    "author": "halilkirazkaya",
                    "first_seen": "2026-04-30",
                    "last_seen": "2026-05-09T16:19:27Z",
                    "pushed_at": "2026-04-30T11:05:55Z",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "has_code": true,
                    "artifact_type": "RCE",
                    "language": "Python",
                    "stars": 4,
                    "forks": 0,
                    "topics": [
                        "breeze",
                        "cve-2026-3844",
                        "exploit",
                        "wordpress",
                        "wordpress-plugin"
                    ],
                    "title": "CVE-2026-3844 — Breeze Cache Plugin RCE Exploit",
                    "repository_description": "CVE-2026-3844 — Breeze Cache Plugin RCE Exploit",
                    "summary": "CVE-2026-3844 — Breeze Cache Plugin RCE Exploit",
                    "source": "CVE-Intel",
                    "url": "https://github.com/halilkirazkaya/CVE-2026-3844",
                    "cvss": 9.8,
                    "severity": "CRITICAL",
                    "cve_description": "The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if \"Host Files Locally - Gravatars\" is enabled, which is disabled by default.",
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "kev": false,
                    "epss": 0.27701,
                    "metadata_source": "NIST",
                    "cve_published_at": "2026-04-23",
                    "cve_status": "Deferred"
                }
            ],
            "references": [
                "https://github.com/Alevtinka19/CVE-2026-3844",
                "https://github.com/AnggaTechI/CVE-2026-3844",
                "https://github.com/tausifzaman/CVE-2026-3844",
                "https://github.com/dinosn/CVE-2026-3844",
                "https://github.com/Dhananjayasj/CVE-2026-3844-Breeze-Cache-WordPress-Plugin-Remote-Code-Execution",
                "https://github.com/0xgh057r3c0n/CVE-2026-3844",
                "https://github.com/rootdirective-sec/CVE-2026-3844-Lab",
                "https://github.com/halilkirazkaya/CVE-2026-3844"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T10:21:42Z",
                    "label": "Discovered through CVE-Intel",
                    "url": "https://github.com/Alevtinka19/CVE-2026-3844"
                }
            ],
            "epss": 0.27701,
            "severity": "CRITICAL",
            "metadata_source": "NIST",
            "cve_status": "Deferred",
            "cve_published_at": "2026-04-23",
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-3833",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.",
            "updated_at": "2026-09-14T13:18:33.013",
            "published_at": "2026-04-30T18:16:30.577",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 3.8.13 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 33,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-178",
            "what_happened": "A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subject Alternative Name (SAN), leading to a policy bypass where a certificate that should be rejected is instead accepted. This could result in unauthorized access or information disclosure.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "gitlab.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-30",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://gitlab.com/gnutls/gnutls/-/issues/1803"
                }
            ],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:13274",
                "https://access.redhat.com/errata/RHSA-2026:20611",
                "https://access.redhat.com/errata/RHSA-2026:20612",
                "https://access.redhat.com/errata/RHSA-2026:20613",
                "https://access.redhat.com/errata/RHSA-2026:26319",
                "https://access.redhat.com/errata/RHSA-2026:26409",
                "https://access.redhat.com/errata/RHSA-2026:29197",
                "https://access.redhat.com/errata/RHSA-2026:30004",
                "https://access.redhat.com/errata/RHSA-2026:30849",
                "https://access.redhat.com/errata/RHSA-2026:30850",
                "https://access.redhat.com/errata/RHSA-2026:32962",
                "https://access.redhat.com/errata/RHSA-2026:33125",
                "https://access.redhat.com/errata/RHSA-2026:41921",
                "https://access.redhat.com/errata/RHSA-2026:43575",
                "https://access.redhat.com/errata/RHSA-2026:57402",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/errata/RHSA-2026:59831",
                "https://access.redhat.com/errata/RHSA-2026:60019",
                "https://access.redhat.com/errata/RHSA-2026:62549",
                "https://access.redhat.com/security/cve/CVE-2026-3833",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2445763",
                "https://gitlab.com/gnutls/gnutls/-/issues/1803",
                "https://access.redhat.com/errata/RHSA-2026:62409"
            ],
            "timeline": [
                {
                    "at": "2026-04-30T18:16:30.577",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3833"
                }
            ]
        },
        {
            "id": "CVE-2026-3805",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When doing a second SMB request to the same host again, curl would wrongly use\na data pointer pointing into already freed memory.",
            "updated_at": "2026-09-14T21:17:06.383",
            "published_at": "2026-03-11T11:16:00.967",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.13.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.19.0 (semver); f4831daa9b2a97e8a2921d6b62cc4dfdd0d8646e through before e090be9f73a7a71459ef678c7cc4b1f75e3ea883 (git); 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "When doing a second SMB request to the same host again, curl would wrongly use\na data pointer pointing into already freed memory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3591944"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-3805.html",
                "https://curl.se/docs/CVE-2026-3805.json",
                "https://hackerone.com/reports/3591944",
                "http://www.openwall.com/lists/oss-security/2026/03/11/4"
            ],
            "timeline": [
                {
                    "at": "2026-03-11T11:16:00.967",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3805"
                }
            ]
        },
        {
            "id": "CVE-2026-3784",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.",
            "updated_at": "2026-09-15T07:16:27.963",
            "published_at": "2026-03-11T11:16:00.437",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.7.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.19.0 (semver); a1d6ad26100bc493c7b04f1301b1634b7f5aa8b4 through before 5f13a7645e565c5c1a06f3ef86e97afb856fb364 (git); 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0; 7.32.0; 7.31.0; 7.30.0; 7.29.0; 7.28.1; 7.28.0; 7.27.0; 7.26.0; 7.25.0; 7.24.0; 7.23.1; 7.23.0; 7.22.0; 7.21.7; 7.21.6; 7.21.5; 7.21.4; 7.21.3; 7.21.2; 7.21.1; 7.21.0; 7.20.1; 7.20.0; 7.19.7; 7.19.6; 7.19.5; 7.19.4; 7.19.3; 7.19.2; 7.19.1; 7.19.0; 7.18.2; 7.18.1; 7.18.0; 7.17.1; 7.17.0; 7.16.4; 7.16.3; 7.16.2; 7.16.1; 7.16.0; 7.15.5; 7.15.4; 7.15.3; 7.15.2; 7.15.1; 7.15.0; 7.14.1; 7.14.0; 7.13.2; 7.13.1; 7.13.0; 7.12.3; 7.12.2; 7.12.1; 7.12.0; 7.11.2; 7.11.1; 7.11.0; 7.10.8; 7.10.7; 7.10.6; 7.10.5; 7.10.4; 7.10.3; 7.10.2; 7.10.1; 7.10; 7.9.8; 7.9.7; 7.9.6; 7.9.5; 7.9.4; 7.9.3; 7.9.2; 7.9.1; 7.9; 7.8.1; 7.8; 7.7.3; 7.7.2; 7.7.1; 7.7; before V4.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-305",
            "what_happened": "curl would wrongly reuse an existing HTTP proxy connection doing CONNECT to a\nserver, even if the new request uses different credentials for the HTTP proxy.\nThe proper behavior is to create or use a separate connection.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3584903"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-3784.html",
                "https://curl.se/docs/CVE-2026-3784.json",
                "https://hackerone.com/reports/3584903",
                "http://www.openwall.com/lists/oss-security/2026/03/11/3",
                "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
            ],
            "timeline": [
                {
                    "at": "2026-03-11T11:16:00.437",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3784"
                }
            ]
        },
        {
            "id": "CVE-2026-3783",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.",
            "updated_at": "2026-09-15T07:16:27.720",
            "published_at": "2026-03-11T11:16:00.080",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.33.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.19.0 (semver); 06c1bea72faabb6fad4b7ef818aafaa336c9a7aa through before e3d7401a32a46516c9e5ee877e613e62ed35bddc (git); 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-522",
            "what_happened": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a redirect to a second URL, curl could leak that token to the second\nhostname under some circumstances.\n\nIf the hostname that the first request is redirected to has information in the\nused .netrc file, with either of the `machine` or `default` keywords, curl\nwould pass on the bearer token set for the first host also to the second one.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3583983"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2026-3783.html",
                "https://curl.se/docs/CVE-2026-3783.json",
                "https://hackerone.com/reports/3583983",
                "http://www.openwall.com/lists/oss-security/2026/03/11/2"
            ],
            "timeline": [
                {
                    "at": "2026-03-11T11:16:00.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3783"
                }
            ]
        },
        {
            "id": "CVE-2026-3576",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Planyo_Online_Reservation_System  3.0 - Arbitrary File Read via SSRF",
            "summary": "Planyo_Online_Reservation_System  3.0 - Arbitrary File Read via SSRF",
            "updated_at": "2026-08-10T22:00:00Z",
            "published_at": "2026-08-10T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52636",
                    "author": "Balachandar Gowrisankar",
                    "first_seen": "2026-08-11",
                    "confidence": "High",
                    "title": "Planyo_Online_Reservation_System  3.0 - Arbitrary File Read via SSRF",
                    "summary": "Planyo_Online_Reservation_System  3.0 - Arbitrary File Read via SSRF",
                    "url": "https://www.exploit-db.com/exploits/52636",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52636"
            ],
            "timeline": [
                {
                    "at": "2026-08-10T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52636"
                }
            ]
        },
        {
            "id": "CVE-2026-3416",
            "vendor": "WSO2",
            "product": "WSO2 API Manager",
            "title": "WSO2 API Manager vulnerability",
            "summary": "The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secrets. This enables malicious actors to forge event payloads with valid HMAC signatures, bypassing the API Gateway's authenticity verification.\n\nSuccessful exploitation could allow an attacker to predict shared secrets used for Webhook HMAC validation and forge event payloads with valid signatures. This may enable bypassing API Gateway authenticity checks, leading to unauthorized event injection, data manipulation, or downstream system compromise.",
            "updated_at": "2026-09-15T18:02:04.233",
            "published_at": "2026-09-03T13:05:37.847",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.1.0 through before 4.1.0.253 (custom); 4.2.0 through before 4.2.0.193 (custom); 4.3.0 through before 4.3.0.104 (custom); 4.4.0 through before 4.4.0.68 (custom); 4.5.0 through before 4.5.0.52 (custom); 4.5.0 through before 4.5.0.53 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-330",
            "what_happened": "The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secrets. This enables malicious actors to forge event payloads with valid HMAC signatures, bypassing the API Gateway's authenticity verification.\n\nSuccessful exploitation could allow an attacker to predict shared secrets used for Webhook HMAC validation and forge event payloads with valid signatures. This may enable bypassing API Gateway authenticity checks, leading to unauthorized event injection, data manipulation, or downstream system compromise.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5174/"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T13:05:37.847",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3416"
                }
            ]
        },
        {
            "id": "CVE-2026-3039",
            "vendor": "ISC",
            "product": "BIND 9",
            "title": "BIND 9 vulnerability",
            "summary": "BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets.  Typically these servers will be found in Active Directory integrated DNS deployments and/or Kerberos-secured DNS environments.\nThis issue affects BIND 9 versions 9.0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.9.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.",
            "updated_at": "2026-09-10T13:20:01.110",
            "published_at": "2026-05-20T13:16:23.647",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.0.0 through 9.16.50 (custom); 9.18.0 through 9.18.48 (custom); 9.20.0 through 9.20.22 (custom); 9.21.0 through 9.21.21 (custom); 9.9.3-S1 through 9.16.50-S1 (custom); 9.18.11-S1 through 9.18.48-S1 (custom); 9.20.9-S1 through 9.20.22-S1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-771",
            "what_happened": "BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets.  Typically these servers will be found in Active Directory integrated DNS deployments and/or Kerberos-secured DNS environments.\nThis issue affects BIND 9 versions 9.0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.9.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://downloads.isc.org/isc/bind9/9.18.49",
                "https://downloads.isc.org/isc/bind9/9.20.23",
                "https://downloads.isc.org/isc/bind9/9.21.22",
                "https://kb.isc.org/docs/cve-2026-3039",
                "https://access.redhat.com/errata/RHSA-2026:20334",
                "https://access.redhat.com/errata/RHSA-2026:23360",
                "https://access.redhat.com/errata/RHSA-2026:24338",
                "https://access.redhat.com/errata/RHSA-2026:24339",
                "https://access.redhat.com/errata/RHSA-2026:24367",
                "https://access.redhat.com/errata/RHSA-2026:24368",
                "https://access.redhat.com/errata/RHSA-2026:55441",
                "https://access.redhat.com/errata/RHSA-2026:57189",
                "https://access.redhat.com/errata/RHSA-2026:60383",
                "https://access.redhat.com/errata/RHSA-2026:62549",
                "https://access.redhat.com/security/cve/CVE-2026-3039",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2479767",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3039.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-20T13:16:23.647",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3039"
                }
            ]
        },
        {
            "id": "CVE-2026-3012",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.",
            "updated_at": "2026-09-15T12:17:42.833",
            "published_at": "2026-05-27T11:16:18.357",
            "cvss": 8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.16.0 through before 4.21.0",
            "fixed": "See vendor advisory",
            "source_count": 42,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-345",
            "what_happened": "A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:22644",
                "https://access.redhat.com/errata/RHSA-2026:22963",
                "https://access.redhat.com/errata/RHSA-2026:25049",
                "https://access.redhat.com/errata/RHSA-2026:25979",
                "https://access.redhat.com/errata/RHSA-2026:28053",
                "https://access.redhat.com/errata/RHSA-2026:28054",
                "https://access.redhat.com/errata/RHSA-2026:28055",
                "https://access.redhat.com/errata/RHSA-2026:28056",
                "https://access.redhat.com/errata/RHSA-2026:28057",
                "https://access.redhat.com/errata/RHSA-2026:29863",
                "https://access.redhat.com/errata/RHSA-2026:56786",
                "https://access.redhat.com/errata/RHSA-2026:56853",
                "https://access.redhat.com/errata/RHSA-2026:56911",
                "https://access.redhat.com/errata/RHSA-2026:57483",
                "https://access.redhat.com/errata/RHSA-2026:59831",
                "https://access.redhat.com/errata/RHSA-2026:60019",
                "https://access.redhat.com/errata/RHSA-2026:62409",
                "https://access.redhat.com/errata/RHSA-2026:62549",
                "https://access.redhat.com/security/cve/CVE-2026-3012",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2447319",
                "https://bugzilla.samba.org/show_bug.cgi?id=16003",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3012.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T11:16:18.357",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3012"
                }
            ]
        },
        {
            "id": "CVE-2026-3009",
            "vendor": "Red Hat",
            "product": "Red Hat build of Keycloak 26.4",
            "title": "Red Hat build of Keycloak 26.4 vulnerability",
            "summary": "A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative restriction. This undermines access control enforcement and may allow unauthorized authentication through a disabled external provider.",
            "updated_at": "2026-09-14T13:18:31.887",
            "published_at": "2026-03-05T19:16:18.193",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even after it has been disabled by an administrator. An attacker who knows the IdP alias can reuse a previously generated login request to bypass the administrative restriction. This undermines access control enforcement and may allow unauthorized authentication through a disabled external provider.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:3947",
                "https://access.redhat.com/errata/RHSA-2026:3948",
                "https://access.redhat.com/security/cve/CVE-2026-3009",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2441867",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3009.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-05T19:16:18.193",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3009"
                }
            ]
        },
        {
            "id": "CVE-2026-2670",
            "vendor": "Advantech",
            "product": "WISE-6610-NB",
            "title": "WISE-6610-NB vulnerability",
            "summary": "A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: \"The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data.\"",
            "updated_at": "2026-09-07T06:17:18.777",
            "published_at": "2026-02-18T22:16:27.360",
            "cvss": 7.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.2.1_20251110",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-77",
            "what_happened": "A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: \"The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data.\"",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/master-abc/cve/issues/37",
                "https://vuldb.com/cve/CVE-2026-2670",
                "https://vuldb.com/submit/753293",
                "https://vuldb.com/vuln/346467",
                "https://vuldb.com/vuln/346467/cti",
                "https://www.advantech.com/",
                "https://www.advantech.com/en-us/support/details/firmware?id=1-2K7AXRI",
                "https://www.advantech.com/zh-tw/security-advisory"
            ],
            "timeline": [
                {
                    "at": "2026-02-18T22:16:27.360",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2670"
                }
            ]
        },
        {
            "id": "CVE-2026-2377",
            "vendor": "Red Hat",
            "product": "Red Hat Quay 3.10",
            "title": "Red Hat Quay 3.10 vulnerability",
            "summary": "A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability, known as Server-Side Request Forgery (SSRF), could allow an attacker to send requests from the application's internal network, potentially leading to the disclosure of sensitive information.",
            "updated_at": "2026-09-10T13:18:04.373",
            "published_at": "2026-04-08T17:21:16.237",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-918",
            "what_happened": "A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability, known as Server-Side Request Forgery (SSRF), could allow an attacker to send requests from the application's internal network, potentially leading to the disclosure of sensitive information.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:22629",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/security/cve/CVE-2026-2377",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2439201",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2377.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-08T17:21:16.237",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2377"
                }
            ]
        },
        {
            "id": "CVE-2026-2340",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.",
            "updated_at": "2026-09-14T13:17:56.047",
            "published_at": "2026-05-27T14:16:44.387",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-280",
            "what_happened": "A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:22644",
                "https://access.redhat.com/errata/RHSA-2026:22963",
                "https://access.redhat.com/errata/RHSA-2026:25049",
                "https://access.redhat.com/errata/RHSA-2026:25979",
                "https://access.redhat.com/errata/RHSA-2026:28053",
                "https://access.redhat.com/errata/RHSA-2026:28054",
                "https://access.redhat.com/errata/RHSA-2026:28055",
                "https://access.redhat.com/errata/RHSA-2026:28056",
                "https://access.redhat.com/errata/RHSA-2026:28057",
                "https://access.redhat.com/errata/RHSA-2026:29863",
                "https://access.redhat.com/errata/RHSA-2026:56786",
                "https://access.redhat.com/errata/RHSA-2026:56853",
                "https://access.redhat.com/errata/RHSA-2026:56911",
                "https://access.redhat.com/errata/RHSA-2026:57483",
                "https://access.redhat.com/errata/RHSA-2026:59831",
                "https://access.redhat.com/errata/RHSA-2026:60019",
                "https://access.redhat.com/errata/RHSA-2026:62409",
                "https://access.redhat.com/errata/RHSA-2026:62549",
                "https://access.redhat.com/security/cve/CVE-2026-2340",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2447318",
                "https://bugzilla.samba.org/show_bug.cgi?id=15997"
            ],
            "timeline": [
                {
                    "at": "2026-05-27T14:16:44.387",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2340"
                }
            ]
        },
        {
            "id": "CVE-2026-2332",
            "vendor": "Eclipse Foundation",
            "product": "Eclipse Jetty",
            "title": "Eclipse Jetty vulnerability",
            "summary": "In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the \"funky chunks\" techniques outlined here:\n  *  https://w4ke.info/2025/06/18/funky-chunks.html\n\n  *  https://w4ke.info/2025/10/29/funky-chunks-2.html\n\n\nJetty terminates chunk extension parsing at \\r\\n inside quoted strings instead of treating this as an error.\n\n\n\n\nPOST / HTTP/1.1\nHost: localhost\nTransfer-Encoding: chunked\n\n1;ext=\"val\nX\n0\n\nGET /smuggled HTTP/1.1\n...\n\n\n\n\n\nNote how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.",
            "updated_at": "2026-09-10T13:18:03.987",
            "published_at": "2026-04-14T12:16:21.333",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "12.1.0 through 12.1.6 (semver); 12.0.0 through 12.0.32 (semver); 11.0.0 through 11.0.28 (semver); 10.0.0 through 10.0.27 (semver); 9.4.0 through 9.4.59 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 68,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-444",
            "what_happened": "In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the \"funky chunks\" techniques outlined here:\n  *  https://w4ke.info/2025/06/18/funky-chunks.html\n\n  *  https://w4ke.info/2025/10/29/funky-chunks-2.html\n\n\nJetty terminates chunk extension parsing at \\r\\n inside quoted strings instead of treating this as an error.\n\n\n\n\nPOST / HTTP/1.1\nHost: localhost\nTransfer-Encoding: chunked\n\n1;ext=\"val\nX\n0\n\nGET /smuggled HTTP/1.1\n...\n\n\n\n\n\nNote how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-14",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T15:06:04+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "jetty-line-check exploit",
                    "summary": "Exploit for CVE-2026-2332. CVSS 9.1.",
                    "cvss": 9.1,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-XIAOQIMIKKO-JETTY-LINE-CHECK"
                }
            ],
            "references": [
                "https://github.com/jetty/jetty.project/security/advisories/GHSA-355h-qmc2-wpwf",
                "https://gitlab.eclipse.org/security/cve-assignment/-/issues/89",
                "https://access.redhat.com/errata/RHSA-2026:10175",
                "https://access.redhat.com/errata/RHSA-2026:14272",
                "https://access.redhat.com/errata/RHSA-2026:17668",
                "https://access.redhat.com/errata/RHSA-2026:20568",
                "https://access.redhat.com/errata/RHSA-2026:21773",
                "https://access.redhat.com/errata/RHSA-2026:22453",
                "https://access.redhat.com/errata/RHSA-2026:25089",
                "https://access.redhat.com/errata/RHSA-2026:50221",
                "https://access.redhat.com/errata/RHSA-2026:50222",
                "https://access.redhat.com/errata/RHSA-2026:50223",
                "https://access.redhat.com/errata/RHSA-2026:50263",
                "https://access.redhat.com/errata/RHSA-2026:60239",
                "https://access.redhat.com/errata/RHSA-2026:60246",
                "https://access.redhat.com/errata/RHSA-2026:60247",
                "https://access.redhat.com/errata/RHSA-2026:60248",
                "https://access.redhat.com/errata/RHSA-2026:60249",
                "https://access.redhat.com/errata/RHSA-2026:60250",
                "https://access.redhat.com/errata/RHSA-2026:60251",
                "https://access.redhat.com/errata/RHSA-2026:60252",
                "https://access.redhat.com/errata/RHSA-2026:60254",
                "https://access.redhat.com/errata/RHSA-2026:60256",
                "https://access.redhat.com/errata/RHSA-2026:60259",
                "https://access.redhat.com/security/cve/CVE-2026-2332",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2458187",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2332.json",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-XIAOQIMIKKO-JETTY-LINE-CHECK"
            ],
            "timeline": [
                {
                    "at": "2026-04-14T12:16:21.333",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2332"
                }
            ]
        },
        {
            "id": "CVE-2026-2100",
            "vendor": "p11-glue",
            "product": "p11-kit",
            "title": "p11-kit vulnerability",
            "summary": "A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.",
            "updated_at": "2026-09-06T04:18:29.577",
            "published_at": "2026-03-26T21:17:04.247",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.26.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-824",
            "what_happened": "A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a remote token with specific IBM kyber or IBM btc derive mechanism parameters set to NULL. This could lead to the RPC-client attempting to return an uninitialized value, potentially resulting in a NULL dereference or undefined behavior. This issue may cause an application level denial of service or other unpredictable system states.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:18143",
                "https://access.redhat.com/errata/RHSA-2026:18599",
                "https://access.redhat.com/errata/RHSA-2026:21275",
                "https://access.redhat.com/errata/RHSA-2026:22634",
                "https://access.redhat.com/errata/RHSA-2026:27998",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/errata/RHSA-2026:7065",
                "https://access.redhat.com/security/cve/CVE-2026-2100",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2437308",
                "https://github.com/p11-glue/p11-kit/pull/740",
                "https://github.com/p11-glue/p11-kit/releases/tag/0.26.2"
            ],
            "timeline": [
                {
                    "at": "2026-03-26T21:17:04.247",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2100"
                }
            ]
        },
        {
            "id": "CVE-2026-2015",
            "vendor": "Portabilis",
            "product": "i-Educar",
            "title": "i-Educar vulnerability",
            "summary": "A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.11.0 is able to address this issue. Upgrading the affected component is advised. The vendor explains, that \"[t]he reported attack vector was tested against the corrected code, and the previously described behavior could no longer be reproduced\".",
            "updated_at": "2026-09-15T03:17:05.440",
            "published_at": "2026-02-06T11:15:51.127",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "2.0; 2.1; 2.2; 2.3; 2.4; 2.5; 2.6; 2.7; 2.8; 2.9; 2.10",
            "fixed": "See vendor advisory",
            "source_count": 19,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-266",
            "what_happened": "A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.11.0 is able to address this issue. Upgrading the affected component is advised. The vendor explains, that \"[t]he reported attack vector was tested against the corrected code, and the previously described behavior could no longer be reproduced\".",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-02-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/ViniCastro2001/Security_Reports/tree/main/i-educar/BFLA-Final-Status-Import"
                },
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-02-06",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/ViniCastro2001/Security_Reports/tree/main/i-educar/BFLA-Final-Status-Import#proof-of-concept-poc"
                }
            ],
            "references": [
                "https://github.com/ViniCastro2001/Security_Reports/tree/main/i-educar/BFLA-Final-Status-Import",
                "https://github.com/ViniCastro2001/Security_Reports/tree/main/i-educar/BFLA-Final-Status-Import#proof-of-concept-poc",
                "https://github.com/portabilis/i-educar/releases/tag/2.11.0",
                "https://vuldb.com/cve/CVE-2026-2015",
                "https://vuldb.com/submit/743760",
                "https://vuldb.com/vuln/344597",
                "https://vuldb.com/vuln/344597/cti"
            ],
            "timeline": [
                {
                    "at": "2026-02-06T11:15:51.127",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-2015"
                }
            ]
        },
        {
            "id": "CVE-2026-1965",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).",
            "updated_at": "2026-09-15T07:16:27.523",
            "published_at": "2026-03-11T11:15:59.177",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.10.6 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.19.0 (semver); e56ae1426cb7a0a4a427cf8d6099a821fdaae428 through before f1a39f221d57354990e3eeeddc3404aede2aff70 (git); 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0; 7.32.0; 7.31.0; 7.30.0; 7.29.0; 7.28.1; 7.28.0; 7.27.0; 7.26.0; 7.25.0; 7.24.0; 7.23.1; 7.23.0; 7.22.0; 7.21.7; 7.21.6; 7.21.5; 7.21.4; 7.21.3; 7.21.2; 7.21.1; 7.21.0; 7.20.1; 7.20.0; 7.19.7; 7.19.6; 7.19.5; 7.19.4; 7.19.3; 7.19.2; 7.19.1; 7.19.0; 7.18.2; 7.18.1; 7.18.0; 7.17.1; 7.17.0; 7.16.4; 7.16.3; 7.16.2; 7.16.1; 7.16.0; 7.15.5; 7.15.4; 7.15.3; 7.15.2; 7.15.1; 7.15.0; 7.14.1; 7.14.0; 7.13.2; 7.13.1; 7.13.0; 7.12.3; 7.12.2; 7.12.1; 7.12.0; 7.11.2; 7.11.1; 7.11.0; 7.10.8; 7.10.7; 7.10.6",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-305",
            "what_happened": "libcurl can in some circumstances reuse the wrong connection when asked to do\nan Negotiate-authenticated HTTP or HTTPS request.\n\nlibcurl features a pool of recent connections so that subsequent requests can\nreuse an existing connection to avoid overhead.\n\nWhen reusing a connection a range of criterion must first be met. Due to a\nlogical error in the code, a request that was issued by an application could\nwrongfully reuse an existing connection to the same server that was\nauthenticated using different credentials. One underlying reason being that\nNegotiate sometimes authenticates *connections* and not *requests*, contrary\nto how HTTP is designed to work.\n\nAn application that allows Negotiate authentication to a server (that responds\nwanting Negotiate) with `user1:password1` and then does another operation to\nthe same server also using Negotiate but with `user2:password2` (while the\nprevious connection is still alive) - the second request wrongly reused the\nsame connection and since it then sees that the Negotiate negotiation is\nalready made, it sends the request over that connection thinking it uses\nthe user2 credentials when it is in fact still using the connection\nauthenticated for user1...\n\nThe set of authentication methods to use is set with `CURLOPT_HTTPAUTH`.\n\nApplications can disable libcurl's reuse of connections and thus mitigate this\nproblem, by using one of the following libcurl options to alter how\nconnections are or are not reused: `CURLOPT_FRESH_CONNECT`,\n`CURLOPT_MAXCONNECTS` and `CURLMOPT_MAX_HOST_CONNECTIONS` (if using the\ncurl_multi API).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://curl.se/docs/CVE-2026-1965.html",
                "https://curl.se/docs/CVE-2026-1965.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-11T11:15:59.177",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1965"
                }
            ]
        },
        {
            "id": "CVE-2026-1784",
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift Container Platform 4.13",
            "title": "Red Hat OpenShift Container Platform 4.13 vulnerability",
            "summary": "The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.",
            "updated_at": "2026-09-09T15:17:06.550",
            "published_at": "2026-06-02T09:16:15.683",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-15",
            "what_happened": "The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:23241",
                "https://access.redhat.com/errata/RHSA-2026:23246",
                "https://access.redhat.com/errata/RHSA-2026:25045",
                "https://access.redhat.com/errata/RHSA-2026:25182",
                "https://access.redhat.com/errata/RHSA-2026:25194",
                "https://access.redhat.com/errata/RHSA-2026:26543",
                "https://access.redhat.com/errata/RHSA-2026:28893",
                "https://access.redhat.com/errata/RHSA-2026:28964",
                "https://access.redhat.com/security/cve/CVE-2026-1784",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2436075",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1784.json"
            ],
            "timeline": [
                {
                    "at": "2026-06-02T09:16:15.683",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1784"
                }
            ]
        },
        {
            "id": "CVE-2026-1519",
            "vendor": "ISC",
            "product": "BIND 9",
            "title": "BIND 9 vulnerability",
            "summary": "If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries).\nThis issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.",
            "updated_at": "2026-09-10T13:17:37.363",
            "published_at": "2026-03-25T14:16:33.110",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.11.0 through 9.16.50 (custom); 9.18.0 through 9.18.46 (custom); 9.20.0 through 9.20.20 (custom); 9.21.0 through 9.21.19 (custom); 9.11.3-S1 through 9.16.50-S1 (custom); 9.18.11-S1 through 9.18.46-S1 (custom); 9.20.9-S1 through 9.20.20-S1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 33,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-606",
            "what_happened": "If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries).\nThis issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://downloads.isc.org/isc/bind9/9.18.47",
                "https://downloads.isc.org/isc/bind9/9.20.21",
                "https://downloads.isc.org/isc/bind9/9.21.20",
                "https://kb.isc.org/docs/cve-2026-1519",
                "https://lists.debian.org/debian-lts-announce/2026/04/msg00008.html",
                "https://access.redhat.com/errata/RHSA-2026:11371",
                "https://access.redhat.com/errata/RHSA-2026:11372",
                "https://access.redhat.com/errata/RHSA-2026:15890",
                "https://access.redhat.com/errata/RHSA-2026:16060",
                "https://access.redhat.com/errata/RHSA-2026:16064",
                "https://access.redhat.com/errata/RHSA-2026:24500",
                "https://access.redhat.com/errata/RHSA-2026:24851",
                "https://access.redhat.com/errata/RHSA-2026:24934",
                "https://access.redhat.com/errata/RHSA-2026:25083",
                "https://access.redhat.com/errata/RHSA-2026:25171",
                "https://access.redhat.com/errata/RHSA-2026:25214",
                "https://access.redhat.com/errata/RHSA-2026:29110",
                "https://access.redhat.com/errata/RHSA-2026:29863",
                "https://access.redhat.com/errata/RHSA-2026:34048",
                "https://access.redhat.com/errata/RHSA-2026:36610",
                "https://access.redhat.com/errata/RHSA-2026:40021",
                "https://access.redhat.com/errata/RHSA-2026:43226",
                "https://access.redhat.com/errata/RHSA-2026:60019",
                "https://access.redhat.com/errata/RHSA-2026:62549",
                "https://access.redhat.com/errata/RHSA-2026:6935",
                "https://access.redhat.com/errata/RHSA-2026:7915",
                "https://access.redhat.com/errata/RHSA-2026:8075",
                "https://access.redhat.com/errata/RHSA-2026:8155",
                "https://access.redhat.com/errata/RHSA-2026:8312",
                "https://access.redhat.com/errata/RHSA-2026:8352",
                "https://access.redhat.com/security/cve/CVE-2026-1519",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451305",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1519.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-25T14:16:33.110",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-1519"
                }
            ]
        },
        {
            "id": "CVE-2026-1122",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-1122-IoT-Firmware-Update-Signature-Bypass-via-Low-Order-Point-Injection",
            "summary": "Ed25519 signature bypass in IoT firmware OTA via low-order point enabling malicious update.",
            "updated_at": "2026-08-30T18:58:38Z",
            "published_at": "2026-08-30T18:58:38Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 75,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Ed25519 signature bypass in IoT firmware OTA via low-order point enabling malicious update.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-1122-IoT-Firmware-Update-Signature-Bypass-via-Low-Order-Point-Injection",
                    "summary": "Ed25519 signature bypass in IoT firmware OTA via low-order point enabling malicious update.",
                    "what_happened": "Ed25519 signature bypass in IoT firmware OTA via low-order point enabling malicious update.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GEORGE0PAPASOTIRIOU-CVE-2026-1122-IOT-FIRMWARE-UPDATE-SIGNATURE-BYPASS-VIA-LOW-ORDER-POINT-INJECTION",
                        "https://kitploit.com/ru/tools/github/george0papasotiriou/cve-2026-1122-iot-firmware-update-signature-bypass-via-low-order-point-injection/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-30T20:58:38",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GEORGE0PAPASOTIRIOU-CVE-2026-1122-IOT-FIRMWARE-UPDATE-SIGNATURE-BYPASS-VIA-LOW-ORDER-POINT-INJECTION"
                },
                {
                    "title": "Exploit for CVE-2026-1122-IoT-Firmware-Update-Signature-Bypass-via-Low-Order-Point-Injection",
                    "summary": "Ed25519 signature bypass in IoT firmware OTA via low-order point enabling malicious update.",
                    "what_happened": "Ed25519 signature bypass in IoT firmware OTA via low-order point enabling malicious update.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GEORGE0PAPASOTIRIOU-CVE-2026-1122-IOT-FIRMWARE-UPDATE-SIGNATURE-BYPASS-VIA-LOW-ORDER-POINT-INJECTION",
                        "https://kitploit.com/ru/tools/github/george0papasotiriou/cve-2026-1122-iot-firmware-update-signature-bypass-via-low-order-point-injection/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-30T20:58:38",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/george0papasotiriou/cve-2026-1122-iot-firmware-update-signature-bypass-via-low-order-point-injection/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GEORGE0PAPASOTIRIOU-CVE-2026-1122-IOT-FIRMWARE-UPDATE-SIGNATURE-BYPASS-VIA-LOW-ORDER-POINT-INJECTION",
                "https://kitploit.com/ru/tools/github/george0papasotiriou/cve-2026-1122-iot-firmware-update-signature-bypass-via-low-order-point-injection/"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T18:58:38Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GEORGE0PAPASOTIRIOU-CVE-2026-1122-IOT-FIRMWARE-UPDATE-SIGNATURE-BYPASS-VIA-LOW-ORDER-POINT-INJECTION"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-0799",
            "vendor": "The Tcpdump Group",
            "product": "libpcap",
            "title": "libpcap vulnerability",
            "summary": "In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value.  In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.",
            "updated_at": "2026-09-05T19:16:55.320",
            "published_at": "2026-09-05T19:16:55.320",
            "cvss": 8.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.10.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value.  In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T19:16:55.320",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0799"
                }
            ]
        },
        {
            "id": "CVE-2026-0770",
            "vendor": "Langflow",
            "product": "Langflow",
            "title": "Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability",
            "summary": "Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.",
            "updated_at": "2026-07-20T22:00:00Z",
            "published_at": "2026-07-20T22:00:00Z",
            "cvss": 0,
            "confidence": 90,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52597",
                    "author": "Diamorphine",
                    "first_seen": "2026-05-29",
                    "confidence": "High",
                    "title": "Langflow 1.3.0 - Remote Code Execution",
                    "summary": "Langflow 1.3.0 - Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/52597",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52597"
            ],
            "timeline": [
                {
                    "at": "2026-07-20T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2026-0740",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Ninja Forms Uploads - Unauthenticated PHP File Upload",
            "summary": "Ninja Forms Uploads - Unauthenticated PHP File Upload",
            "updated_at": "2026-09-07T19:21:09Z",
            "published_at": "2026-09-07T19:21:09Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 99,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52560",
                    "author": "selim.lanouar",
                    "first_seen": "2026-05-13",
                    "confidence": "High",
                    "title": "Ninja Forms Uploads - Unauthenticated PHP File Upload",
                    "summary": "Ninja Forms Uploads - Unauthenticated PHP File Upload",
                    "url": "https://www.exploit-db.com/exploits/52560",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-07T19:21:09+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2026-0740 exploit",
                    "summary": "Exploit for CVE-2026-0740. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XGH057R3C0N-CVE-2026-0740"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52560",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XGH057R3C0N-CVE-2026-0740"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:21:09Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52560"
                }
            ]
        },
        {
            "id": "CVE-2026-0716",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.",
            "updated_at": "2026-09-16T08:16:35.803",
            "published_at": "2026-01-13T23:16:04.163",
            "cvss": 4.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-805",
            "what_happened": "A flaw was found in libsoup’s WebSocket frame processing when handling incoming messages. If a non-default configuration is used where the maximum incoming payload size is unset, the library may read memory outside the intended bounds. This can cause unintended memory exposure or a crash. Applications using libsoup’s WebSocket support with this configuration may be impacted.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/security/cve/CVE-2026-0716",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2427896",
                "https://gitlab.gnome.org/GNOME/libsoup/-/issues/476"
            ],
            "timeline": [
                {
                    "at": "2026-01-13T23:16:04.163",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0716"
                }
            ]
        },
        {
            "id": "CVE-2026-0636",
            "vendor": "Legion of the Bouncy Castle Inc.",
            "product": "BC-JAVA",
            "title": "BC-JAVA vulnerability",
            "summary": "Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).\n\n This vulnerability is associated with program files LDAPStoreHelper.\n\n\n\nThis issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.",
            "updated_at": "2026-09-11T13:17:03.680",
            "published_at": "2026-04-15T10:16:38.413",
            "cvss": 5.5,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:X/RE:M/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.74 through before 1.80.2 (maven); 1.81 through before 1.81.1 (maven); 1.82 through before 1.84 (maven)",
            "fixed": "See vendor advisory",
            "source_count": 29,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-90",
            "what_happened": "Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules).\n\n This vulnerability is associated with program files LDAPStoreHelper.\n\n\n\nThis issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/bcgit/bc-java/commit/d20cdb8430e09224114fec0179a71859929fcbde",
                "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%900636",
                "https://access.redhat.com/errata/RHSA-2026:11720",
                "https://access.redhat.com/errata/RHSA-2026:11721",
                "https://access.redhat.com/errata/RHSA-2026:13631",
                "https://access.redhat.com/errata/RHSA-2026:14272",
                "https://access.redhat.com/errata/RHSA-2026:14276",
                "https://access.redhat.com/errata/RHSA-2026:17668",
                "https://access.redhat.com/errata/RHSA-2026:18054",
                "https://access.redhat.com/errata/RHSA-2026:18055",
                "https://access.redhat.com/errata/RHSA-2026:18059",
                "https://access.redhat.com/errata/RHSA-2026:21772",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/errata/RHSA-2026:60239",
                "https://access.redhat.com/errata/RHSA-2026:60246",
                "https://access.redhat.com/errata/RHSA-2026:60247",
                "https://access.redhat.com/errata/RHSA-2026:60248",
                "https://access.redhat.com/errata/RHSA-2026:60249",
                "https://access.redhat.com/errata/RHSA-2026:60250",
                "https://access.redhat.com/errata/RHSA-2026:60251",
                "https://access.redhat.com/errata/RHSA-2026:60252",
                "https://access.redhat.com/errata/RHSA-2026:60254",
                "https://access.redhat.com/errata/RHSA-2026:60256",
                "https://access.redhat.com/errata/RHSA-2026:60259",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/security/cve/CVE-2026-0636",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2458641",
                "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0636.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-15T10:16:38.413",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0636"
                }
            ]
        },
        {
            "id": "CVE-2026-0310",
            "vendor": "Palo Alto Networks",
            "product": "Cloud NGFW",
            "title": "Cloud NGFW vulnerability",
            "summary": "A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls.\n\nThe security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . \n\nPanorama is impacted by this vulnerability.",
            "updated_at": "2026-09-11T04:17:13.060",
            "published_at": "2026-09-10T06:17:04.450",
            "cvss": 7.2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Red",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "All (custom); 12.2.0 through before 12.2.3 (custom); 12.1.0 through before 12.1.4-h10 (custom); 11.2.0 through before 11.2.4-h21 (custom); 11.1.0 through before 11.1.4-h36 (custom); 10.2.0 through before 10.2.7-h37 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-787",
            "what_happened": "A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root privileges on the PA-Series firewalls.\n\nThe security risk posed by this issue is minimized when the management interface is restricted to only trusted internal IP addresses according to our recommended  best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . \n\nPanorama is impacted by this vulnerability.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security.paloaltonetworks.com/CVE-2026-0310"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T06:17:04.450",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0310"
                }
            ]
        },
        {
            "id": "CVE-2026-0309",
            "vendor": "Palo Alto Networks",
            "product": "Cloud NGFW",
            "title": "Cloud NGFW vulnerability",
            "summary": "A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware Security Module (HSM). \n\nThe security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.\n\nPanorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.",
            "updated_at": "2026-09-11T04:17:10.937",
            "published_at": "2026-09-10T06:17:03.813",
            "cvss": 4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "12.2.0 through before 12.2.3 (custom); 12.1.0 through before 12.1.4-h10 (custom); 11.2.0 through before 11.2.4-h21 (custom); 11.1.0 through before 11.1.4-h36 (custom); 10.2.0 through before 10.2.7-h37 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI and the device must be configured with a Luna Hardware Security Module (HSM). \n\nThe security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators.\n\nPanorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security.paloaltonetworks.com/CVE-2026-0309"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T06:17:03.813",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0309"
                }
            ]
        },
        {
            "id": "CVE-2026-0307",
            "vendor": "Palo Alto Networks",
            "product": "GlobalProtect App",
            "title": "GlobalProtect App vulnerability",
            "summary": "Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.\n\n\n\nThis GlobalProtect app on iOS, Android and ChromeOS is not impacted.",
            "updated_at": "2026-09-11T04:17:10.160",
            "published_at": "2026-09-10T06:17:03.170",
            "cvss": 5.9,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.3.0 through before 6.3.3-h15 (custom); 6.0.0 through before 6.0.15 (custom); 6.2.0 through before 6.2.8-h14 (custom); All (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-426",
            "what_happened": "Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.\n\n\n\nThis GlobalProtect app on iOS, Android and ChromeOS is not impacted.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security.paloaltonetworks.com/CVE-2026-0307"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T06:17:03.170",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0307"
                }
            ]
        },
        {
            "id": "CVE-2026-0304",
            "vendor": "Palo Alto Networks",
            "product": "Cortex XDR Broker VM",
            "title": "Cortex XDR Broker VM vulnerability",
            "summary": "A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.",
            "updated_at": "2026-09-11T04:17:06.707",
            "published_at": "2026-09-10T07:17:02.470",
            "cvss": 4.8,
            "cvss_vector": "CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "20.0.96 through before 32.0.52 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-88",
            "what_happened": "A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security.paloaltonetworks.com/CVE-2026-0304"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T07:17:02.470",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0304"
                }
            ]
        },
        {
            "id": "CVE-2026-0303",
            "vendor": "Palo Alto Networks",
            "product": "Checkov by Prisma Cloud",
            "title": "Exploit for CVE-2026-0303",
            "summary": "A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.",
            "updated_at": "2026-09-10T14:50:07.813",
            "published_at": "2026-09-10T07:17:02.140",
            "cvss": 2.4,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "3.2.0 through before 3.2.532 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 53,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-829",
            "what_happened": "A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-0303",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 6.3,
                    "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/SC:H/VI:L/SI:H/VA:N/SA:H/E:U/AU:N/U:Amber/R:U/V:D/RE:M",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=B59C1874-80AC-51C7-9BE6-7148A177FC33",
                        "https://github.com/YonLiud/CVE-2026-0303"
                    ],
                    "repository": "Sploitus",
                    "author": "YonLiud",
                    "first_seen": "2026-09-10T12:54:32",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=B59C1874-80AC-51C7-9BE6-7148A177FC33"
                },
                {
                    "title": "Exploit for CVE-2026-0303",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 6.3,
                    "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/SC:H/VI:L/SI:H/VA:N/SA:H/E:U/AU:N/U:Amber/R:U/V:D/RE:M",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=B59C1874-80AC-51C7-9BE6-7148A177FC33",
                        "https://github.com/YonLiud/CVE-2026-0303"
                    ],
                    "repository": "YonLiud/CVE-2026-0303",
                    "author": "YonLiud",
                    "first_seen": "2026-09-10T12:54:32",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://github.com/YonLiud/CVE-2026-0303"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=B59C1874-80AC-51C7-9BE6-7148A177FC33",
                "https://github.com/YonLiud/CVE-2026-0303",
                "https://security.paloaltonetworks.com/CVE-2026-0303"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T10:54:32Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=B59C1874-80AC-51C7-9BE6-7148A177FC33"
                },
                {
                    "at": "2026-09-10T07:17:02.140",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0303"
                }
            ],
            "enrichment_checked_at": "2026-09-10T16:06:04Z",
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber"
        },
        {
            "id": "CVE-2026-0200",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T04:17:51.887",
            "published_at": "2026-09-15T19:17:15.133",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:15.133",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0200"
                }
            ]
        },
        {
            "id": "CVE-2026-0199",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T04:17:51.667",
            "published_at": "2026-09-15T19:17:15.033",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:15.033",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0199"
                }
            ]
        },
        {
            "id": "CVE-2026-0171",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T04:17:51.460",
            "published_at": "2026-09-15T19:17:14.057",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:14.057",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0171"
                }
            ]
        },
        {
            "id": "CVE-2026-0170",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T04:17:51.260",
            "published_at": "2026-09-15T19:17:13.960",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:13.960",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0170"
                }
            ]
        },
        {
            "id": "CVE-2026-0165",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
            "updated_at": "2026-09-16T17:17:14.950",
            "published_at": "2026-06-16T20:16:26.877",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:26.877",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0165"
                }
            ]
        },
        {
            "id": "CVE-2026-0159",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T04:17:38.370",
            "published_at": "2026-09-15T19:17:13.830",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T19:17:13.830",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0159"
                }
            ]
        },
        {
            "id": "CVE-2026-0158",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T17:17:14.793",
            "published_at": "2026-06-16T20:16:26.420",
            "cvss": 4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:26.420",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0158"
                }
            ]
        },
        {
            "id": "CVE-2026-0157",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T17:17:14.493",
            "published_at": "2026-06-16T20:16:26.327",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:26.327",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0157"
                }
            ]
        },
        {
            "id": "CVE-2026-0156",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T17:17:14.313",
            "published_at": "2026-06-16T20:16:26.240",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:26.240",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0156"
                }
            ]
        },
        {
            "id": "CVE-2026-0155",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T17:17:14.117",
            "published_at": "2026-06-16T20:16:26.150",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:26.150",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0155"
                }
            ]
        },
        {
            "id": "CVE-2026-0145",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T17:17:13.970",
            "published_at": "2026-06-16T20:16:25.260",
            "cvss": 4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:25.260",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0145"
                }
            ]
        },
        {
            "id": "CVE-2026-0144",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T17:17:13.817",
            "published_at": "2026-06-16T20:16:25.170",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:25.170",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0144"
                }
            ]
        },
        {
            "id": "CVE-2026-0142",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T17:17:13.670",
            "published_at": "2026-06-16T20:16:24.997",
            "cvss": 4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:24.997",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0142"
                }
            ]
        },
        {
            "id": "CVE-2026-0141",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T17:17:13.520",
            "published_at": "2026-06-16T20:16:24.907",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:24.907",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0141"
                }
            ]
        },
        {
            "id": "CVE-2026-0140",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
            "updated_at": "2026-09-16T17:17:13.370",
            "published_at": "2026-06-16T20:16:24.817",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:24.817",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0140"
                }
            ]
        },
        {
            "id": "CVE-2026-0136",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T17:17:13.213",
            "published_at": "2026-06-16T20:16:24.440",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:24.440",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0136"
                }
            ]
        },
        {
            "id": "CVE-2026-0134",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-16T17:17:13.060",
            "published_at": "2026-06-16T20:16:24.260",
            "cvss": 4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1188",
            "what_happened": "In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:24.260",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0134"
                }
            ]
        },
        {
            "id": "CVE-2026-0130",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
            "updated_at": "2026-09-16T17:17:12.907",
            "published_at": "2026-06-16T20:16:23.900",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-122",
            "what_happened": "In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:23.900",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0130"
                }
            ]
        },
        {
            "id": "CVE-2026-0129",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In RtcpByePacket::decodeByePacket, there is a possible  due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
            "updated_at": "2026-09-16T17:17:12.750",
            "published_at": "2026-06-16T20:16:23.813",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-120",
            "what_happened": "In RtcpByePacket::decodeByePacket, there is a possible  due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:23.813",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0129"
                }
            ]
        },
        {
            "id": "CVE-2026-0128",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
            "updated_at": "2026-09-16T17:17:12.580",
            "published_at": "2026-06-16T20:16:23.723",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android kernel",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/pixel/2026/2026-06-01"
            ],
            "timeline": [
                {
                    "at": "2026-06-16T20:16:23.723",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0128"
                }
            ]
        },
        {
            "id": "CVE-2026-0084",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple functions of HostEmulationManager.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:45.240",
            "published_at": "2026-09-08T19:17:50.067",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16-qpr2; 16",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In multiple functions of HostEmulationManager.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:50.067",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0084"
                }
            ]
        },
        {
            "id": "CVE-2026-0073",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-0073",
            "summary": "Authentication bypass in Android Wireless ADB (adbd) TLS handler grants same-network shell access.",
            "updated_at": "2026-08-27T01:52:48Z",
            "published_at": "2026-08-27T01:52:48Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 415,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Authentication bypass in Android Wireless ADB (adbd) TLS handler grants same-network shell access.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-0073",
                    "summary": "Authentication bypass in Android Wireless ADB (adbd) TLS handler grants same-network shell access.",
                    "what_happened": "Authentication bypass in Android Wireless ADB (adbd) TLS handler grants same-network shell access.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XBLACKASH-CVE-2026-0073",
                        "https://kitploit.com/ru/tools/github/0xblackash/cve-2026-0073/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-27T03:52:48",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XBLACKASH-CVE-2026-0073"
                },
                {
                    "title": "Exploit for CVE-2026-0073",
                    "summary": "Authentication bypass in Android Wireless ADB (adbd) TLS handler grants same-network shell access.",
                    "what_happened": "Authentication bypass in Android Wireless ADB (adbd) TLS handler grants same-network shell access.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XBLACKASH-CVE-2026-0073",
                        "https://kitploit.com/ru/tools/github/0xblackash/cve-2026-0073/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-27T03:52:48",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/0xblackash/cve-2026-0073/"
                },
                {
                    "title": "Exploit for CVE-2026-0073-Android-ADBD-bypass-POC_zh_CN",
                    "summary": "Type confusion in adbd TLS auth via EVP_PKEY_cmp gives unauthenticated shell on Android 14+.",
                    "what_happened": "Type confusion in adbd TLS auth via EVP_PKEY_cmp gives unauthenticated shell on Android 14+.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CTN-QVO-CVE-2026-0073-ANDROID-ADBD-BYPASS-POC_ZH_CN",
                        "https://kitploit.com/ru/tools/github/ctn-qvo/cve-2026-0073-android-adbd-bypass-poc_zh_cn/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-27T03:58:19",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CTN-QVO-CVE-2026-0073-ANDROID-ADBD-BYPASS-POC_ZH_CN"
                },
                {
                    "title": "Exploit for CVE-2026-0073-Android-ADBD-bypass-POC_zh_CN",
                    "summary": "Type confusion in adbd TLS auth via EVP_PKEY_cmp gives unauthenticated shell on Android 14+.",
                    "what_happened": "Type confusion in adbd TLS auth via EVP_PKEY_cmp gives unauthenticated shell on Android 14+.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CTN-QVO-CVE-2026-0073-ANDROID-ADBD-BYPASS-POC_ZH_CN",
                        "https://kitploit.com/ru/tools/github/ctn-qvo/cve-2026-0073-android-adbd-bypass-poc_zh_cn/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-27T03:58:19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/ctn-qvo/cve-2026-0073-android-adbd-bypass-poc_zh_cn/"
                },
                {
                    "repository": "PoC-in-GitHub · novaek/CVE-2026-0073-Research",
                    "author": "novaek",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2026-0073 is an RCE with a CVSS severity score of 8.3, and here we will explain how it works.",
                    "summary": "CVE-2026-0073 is an RCE with a CVSS severity score of 8.3, and here we will explain how it works.",
                    "url": "https://github.com/novaek/CVE-2026-0073-Research"
                },
                {
                    "repository": "PoC-in-GitHub · SecTestAnnaQuinn/CVE-2026-0073-Android-adbd-authentication-bypass-POC",
                    "author": "SecTestAnnaQuinn",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 82,
                    "title": "CVE-2026-0073 repository",
                    "summary": "",
                    "url": "https://github.com/SecTestAnnaQuinn/CVE-2026-0073-Android-adbd-authentication-bypass-POC"
                },
                {
                    "repository": "PoC-in-GitHub · devtint/CVE-2026-0073",
                    "author": "devtint",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "https://devtint.github.io/CVE-2026-0073/",
                    "summary": "https://devtint.github.io/CVE-2026-0073/",
                    "url": "https://github.com/devtint/CVE-2026-0073"
                },
                {
                    "repository": "PoC-in-GitHub · adityatelange/poc-CVE-2026-0073",
                    "author": "adityatelange",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 66,
                    "title": "CVE-2026-0073 - ADB Wireless Mutual Authentication Bypass PoC",
                    "summary": "CVE-2026-0073 - ADB Wireless Mutual Authentication Bypass PoC",
                    "url": "https://github.com/adityatelange/poc-CVE-2026-0073"
                },
                {
                    "repository": "PoC-in-GitHub · MartinPSDev/CVE-2026-0073-Android-ADBD-bypass-POC",
                    "author": "MartinPSDev",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 22,
                    "title": "CVE-2026-0073 — Android ADB daemon (adbd) TLS authentication bypass via EVP_PKEY_cmp type confusion. Gain unauthorized shell access over WiFi using EC/Ed25519 key mismatch. PoC exploit for Android 14+.",
                    "summary": "CVE-2026-0073 — Android ADB daemon (adbd) TLS authentication bypass via EVP_PKEY_cmp type confusion. Gain unauthorized shell access over WiFi using EC/Ed25519 key mismatch. PoC exploit for Android 14+.",
                    "url": "https://github.com/MartinPSDev/CVE-2026-0073-Android-ADBD-bypass-POC"
                },
                {
                    "repository": "PoC-in-GitHub · unnaim/adbHijacker",
                    "author": "unnaim",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "A PoC tool for the CVE-2026-0073 on android 11+ devices which allows instant zero click RCE on any unpatched device with adb over tcp enabled",
                    "summary": "A PoC tool for the CVE-2026-0073 on android 11+ devices which allows instant zero click RCE on any unpatched device with adb over tcp enabled",
                    "url": "https://github.com/unnaim/adbHijacker"
                },
                {
                    "repository": "PoC-in-GitHub · 0xBlackash/CVE-2026-0073",
                    "author": "0xBlackash",
                    "first_seen": "2026-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2026-0073",
                    "summary": "CVE-2026-0073",
                    "url": "https://github.com/0xBlackash/CVE-2026-0073"
                },
                {
                    "repository": "PoC-in-GitHub · xqi1337/poc-CVE-2026-0073",
                    "author": "xqi1337",
                    "first_seen": "2026-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-0073 - ADB Wireless Mutual Authentication Bypass PoC",
                    "summary": "CVE-2026-0073 - ADB Wireless Mutual Authentication Bypass PoC",
                    "url": "https://github.com/xqi1337/poc-CVE-2026-0073"
                },
                {
                    "repository": "PoC-in-GitHub · tc4dy/CVE-2026-0073-PoC-Exploit",
                    "author": "tc4dy",
                    "first_seen": "2026-05-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "🚀 CVE-2026-0073 - Android ADB Wireless Debugging Exploit (CVSS 8.8) 🔓 Zero-click authentication bypass via TLS type confusion. Gain interactive shell, execute commands, scan networks. Educational red-team tool. 🐚⚡",
                    "summary": "🚀 CVE-2026-0073 - Android ADB Wireless Debugging Exploit (CVSS 8.8) 🔓 Zero-click authentication bypass via TLS type confusion. Gain interactive shell, execute commands, scan networks. Educational red-team tool. 🐚⚡",
                    "url": "https://github.com/tc4dy/CVE-2026-0073-PoC-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · 0xbinder/CVE-2026-0073",
                    "author": "0xbinder",
                    "first_seen": "2026-05-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 27,
                    "title": "An automated exploit for CVE-2026-0073 (Android ADB TLS Auth Bypass). Features a built-in mDNS/Zeroconf scanner to instantly discover randomized Wireless Debugging ports on Android 13+ and establishes a fully interactive raw PTY shell.",
                    "summary": "An automated exploit for CVE-2026-0073 (Android ADB TLS Auth Bypass). Features a built-in mDNS/Zeroconf scanner to instantly discover randomized Wireless Debugging ports on Android 13+ and establishes a fully interactive raw PTY shell.",
                    "url": "https://github.com/0xbinder/CVE-2026-0073"
                },
                {
                    "repository": "PoC-in-GitHub · m00ddy/CVE-2026-0073-Android-client-TLS-auth-bypass",
                    "author": "m00ddy",
                    "first_seen": "2026-05-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "translating original python exploit to C",
                    "summary": "translating original python exploit to C",
                    "url": "https://github.com/m00ddy/CVE-2026-0073-Android-client-TLS-auth-bypass"
                },
                {
                    "repository": "PoC-in-GitHub · fredevsec/CVE-2026-0073",
                    "author": "fredevsec",
                    "first_seen": "2026-06-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "0-Click RCE Android Adb TLS Wireless Debugging",
                    "summary": "0-Click RCE Android Adb TLS Wireless Debugging",
                    "url": "https://github.com/fredevsec/CVE-2026-0073"
                },
                {
                    "repository": "PoC-in-GitHub · ctn-Qvo/CVE-2026-0073-Android-ADBD-bypass-POC_zh_CN",
                    "author": "ctn-Qvo",
                    "first_seen": "2026-06-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2026-0073-Android-ADBD-bypass-POC汉化版",
                    "summary": "CVE-2026-0073-Android-ADBD-bypass-POC汉化版",
                    "url": "https://github.com/ctn-Qvo/CVE-2026-0073-Android-ADBD-bypass-POC_zh_CN"
                },
                {
                    "repository": "PoC-in-GitHub · aye468448-eng/CVE-2026-0073-Android-adbd-authentication-bypass",
                    "author": "aye468448-eng",
                    "first_seen": "2026-08-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Research on CVE-2026-0073. An auth bypass allowing any attacker with local network access to connect to an Android device with dev tools and wireless debugging or ADB-over-TCP enabled. Device needs to have been paired before.  This has been tested working on Android 14 in Android Studio. Should work on others as well but exploitability may vary.",
                    "summary": "Research on CVE-2026-0073. An auth bypass allowing any attacker with local network access to connect to an Android device with dev tools and wireless debugging or ADB-over-TCP enabled. Device needs to have been paired before.  This has been tested working on Android 14 in Android Studio. Should work on others as well but exploitability may vary.",
                    "url": "https://github.com/aye468448-eng/CVE-2026-0073-Android-adbd-authentication-bypass"
                },
                {
                    "repository": "PoC-in-GitHub · naheeju/POC-CVE-2026-0073",
                    "author": "naheeju",
                    "first_seen": "2026-08-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Security research PoC for CVE-2026-0073: ADB authentication bypass verification",
                    "summary": "Security research PoC for CVE-2026-0073: ADB authentication bypass verification",
                    "url": "https://github.com/naheeju/POC-CVE-2026-0073"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XBLACKASH-CVE-2026-0073",
                "https://kitploit.com/ru/tools/github/0xblackash/cve-2026-0073/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CTN-QVO-CVE-2026-0073-ANDROID-ADBD-BYPASS-POC_ZH_CN",
                "https://kitploit.com/ru/tools/github/ctn-qvo/cve-2026-0073-android-adbd-bypass-poc_zh_cn/",
                "https://github.com/novaek/CVE-2026-0073-Research",
                "https://github.com/SecTestAnnaQuinn/CVE-2026-0073-Android-adbd-authentication-bypass-POC",
                "https://github.com/devtint/CVE-2026-0073",
                "https://github.com/adityatelange/poc-CVE-2026-0073",
                "https://github.com/MartinPSDev/CVE-2026-0073-Android-ADBD-bypass-POC",
                "https://github.com/unnaim/adbHijacker",
                "https://github.com/0xBlackash/CVE-2026-0073",
                "https://github.com/xqi1337/poc-CVE-2026-0073",
                "https://github.com/tc4dy/CVE-2026-0073-PoC-Exploit",
                "https://github.com/0xbinder/CVE-2026-0073",
                "https://github.com/m00ddy/CVE-2026-0073-Android-client-TLS-auth-bypass",
                "https://github.com/fredevsec/CVE-2026-0073",
                "https://github.com/ctn-Qvo/CVE-2026-0073-Android-ADBD-bypass-POC_zh_CN",
                "https://github.com/aye468448-eng/CVE-2026-0073-Android-adbd-authentication-bypass",
                "https://github.com/naheeju/POC-CVE-2026-0073"
            ],
            "timeline": [
                {
                    "at": "2026-08-27T01:52:48Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XBLACKASH-CVE-2026-0073"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-0065",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java, there is a possible unintended way to launch activities in the background due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-10T04:17:44.787",
            "published_at": "2026-09-08T19:17:49.970",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessController.java, there is a possible unintended way to launch activities in the background due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T19:17:49.970",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0065"
                }
            ]
        },
        {
            "id": "CVE-2026-0013",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for PoC-in-GitHub CVE-2026-0009 CVE-2026-0013",
            "summary": "Tapjacking and confused deputy in Android DocumentsUI leading to local privilege escalation.",
            "updated_at": "2026-09-06T10:27:01Z",
            "published_at": "2026-09-06T10:27:01Z",
            "cvss": 8.4,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 51,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Tapjacking and confused deputy in Android DocumentsUI leading to local privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for PoC-in-GitHub CVE-2026-0009 CVE-2026-0013",
                    "summary": "Tapjacking and confused deputy in Android DocumentsUI leading to local privilege escalation.",
                    "what_happened": "Tapjacking and confused deputy in Android DocumentsUI leading to local privilege escalation.",
                    "cvss": 8.4,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NOMI-SEC-POC-IN-GITHUB",
                        "https://kitploit.com/ru/tools/github/nomi-sec/poc-in-github/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T12:27:01",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NOMI-SEC-POC-IN-GITHUB"
                },
                {
                    "title": "Exploit for PoC-in-GitHub CVE-2026-0009 CVE-2026-0013",
                    "summary": "Tapjacking and confused deputy in Android DocumentsUI leading to local privilege escalation.",
                    "what_happened": "Tapjacking and confused deputy in Android DocumentsUI leading to local privilege escalation.",
                    "cvss": 8.4,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NOMI-SEC-POC-IN-GITHUB",
                        "https://kitploit.com/ru/tools/github/nomi-sec/poc-in-github/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-06T12:27:01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/nomi-sec/poc-in-github/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NOMI-SEC-POC-IN-GITHUB",
                "https://kitploit.com/ru/tools/github/nomi-sec/poc-in-github/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T10:27:01Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NOMI-SEC-POC-IN-GITHUB"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-0010",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-08T19:17:49.710",
            "published_at": "2026-03-02T19:16:29.470",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "In onTransact of IDrmManagerService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01",
                "http://seclists.org/fulldisclosure/2026/Aug/111",
                "http://www.openwall.com/lists/oss-security/2026/07/28/4"
            ],
            "timeline": [
                {
                    "at": "2026-03-02T19:16:29.470",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0010"
                }
            ]
        },
        {
            "id": "CVE-2026-0009",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for PoC-in-GitHub CVE-2026-0009 CVE-2026-0013",
            "summary": "Tapjacking and confused deputy in Android DocumentsUI leading to local privilege escalation.",
            "updated_at": "2026-09-06T10:27:01Z",
            "published_at": "2026-09-06T10:27:01Z",
            "cvss": 8.4,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 51,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Tapjacking and confused deputy in Android DocumentsUI leading to local privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for PoC-in-GitHub CVE-2026-0009 CVE-2026-0013",
                    "summary": "Tapjacking and confused deputy in Android DocumentsUI leading to local privilege escalation.",
                    "what_happened": "Tapjacking and confused deputy in Android DocumentsUI leading to local privilege escalation.",
                    "cvss": 8.4,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NOMI-SEC-POC-IN-GITHUB",
                        "https://kitploit.com/ru/tools/github/nomi-sec/poc-in-github/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T12:27:01",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NOMI-SEC-POC-IN-GITHUB"
                },
                {
                    "title": "Exploit for PoC-in-GitHub CVE-2026-0009 CVE-2026-0013",
                    "summary": "Tapjacking and confused deputy in Android DocumentsUI leading to local privilege escalation.",
                    "what_happened": "Tapjacking and confused deputy in Android DocumentsUI leading to local privilege escalation.",
                    "cvss": 8.4,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NOMI-SEC-POC-IN-GITHUB",
                        "https://kitploit.com/ru/tools/github/nomi-sec/poc-in-github/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-06T12:27:01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/nomi-sec/poc-in-github/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NOMI-SEC-POC-IN-GITHUB",
                "https://kitploit.com/ru/tools/github/nomi-sec/poc-in-github/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T10:27:01Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NOMI-SEC-POC-IN-GITHUB"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2026-0008",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-08T19:17:49.500",
            "published_at": "2026-03-02T19:16:29.360",
            "cvss": 8.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16-qpr2; 16",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-441",
            "what_happened": "In multiple functions of FaceEnroll.kt, there is a possible privilege escalation due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-03-02T19:16:29.360",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-0008"
                }
            ]
        },
        {
            "id": "CVE-2026-0001",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "threat = {  \"id\": \"CVE-2026-0001\",  \"title\": \"Apache HTTP Server Remote Code Execution\",  \"vendor\": \"Apache\",  \"product\": \"HTTP Server\",  \"description\": \"A vulnerability in Apache HTTP Server allows remote attackers to execute arbitrary code.\",  \"cvss\": 9.8,  \"kev\": True,  \"published\": \"2026-06-30\"  }",
            "summary": "threat = {  \"id\": \"CVE-2026-0001\",  \"title\": \"Apache HTTP Server Remote Code Execution\",  \"vendor\": \"Apache\",  \"product\": \"HTTP Server\",  \"description\": \"A vulnerability in Apache HTTP Server allows remote attackers to execute arbitrary code.\",  \"cvss\": 9.8,  \"kev\": True,  \"published\": \"2026-06-30\"  }",
            "updated_at": "2026-09-04T22:00:00Z",
            "published_at": "2026-09-04T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 43,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · sohanbhowmik/cyberthreat_DBSproject",
                    "author": "sohanbhowmik",
                    "first_seen": "2026-09-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "threat = {  \"id\": \"CVE-2026-0001\",  \"title\": \"Apache HTTP Server Remote Code Execution\",  \"vendor\": \"Apache\",  \"product\": \"HTTP Server\",  \"description\": \"A vulnerability in Apache HTTP Server allows remote attackers to execute arbitrary code.\",  \"cvss\": 9.8,  \"kev\": True,  \"published\": \"2026-06-30\"  }",
                    "summary": "threat = {  \"id\": \"CVE-2026-0001\",  \"title\": \"Apache HTTP Server Remote Code Execution\",  \"vendor\": \"Apache\",  \"product\": \"HTTP Server\",  \"description\": \"A vulnerability in Apache HTTP Server allows remote attackers to execute arbitrary code.\",  \"cvss\": 9.8,  \"kev\": True,  \"published\": \"2026-06-30\"  }",
                    "url": "https://github.com/sohanbhowmik/cyberthreat_DBSproject"
                }
            ],
            "references": [
                "https://github.com/sohanbhowmik/cyberthreat_DBSproject"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/sohanbhowmik/cyberthreat_DBSproject"
                }
            ]
        },
        {
            "id": "CVE-2025-71399",
            "vendor": "better-auth",
            "product": "better-auth",
            "title": "better-auth vulnerability",
            "summary": "Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extra slashes in the URL path. The issue does not apply in deployments where the proxy or platform normalizes URLs by collapsing multiple slashes.",
            "updated_at": "2026-09-16T20:32:21.400",
            "published_at": "2026-08-02T13:16:52.210",
            "cvss": 8.8,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.4.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3), this can allow attackers to bypass disabledPaths configuration and path-based rate limits by submitting requests with extra slashes in the URL path. The issue does not apply in deployments where the proxy or platform normalizes URLs by collapsing multiple slashes.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/better-auth/better-auth/commit/f60b43fa648399534507c9ac7db36d705b8874c3",
                "https://github.com/better-auth/better-auth/security/advisories/GHSA-x732-6j76-qmhm",
                "https://www.vulncheck.com/advisories/better-auth-before-path-normalization-bypass-via-rou3"
            ],
            "timeline": [
                {
                    "at": "2026-08-02T13:16:52.210",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-71399"
                }
            ]
        },
        {
            "id": "CVE-2025-71142",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpuset: fix warning when disabling remote partition\n\nA warning was triggered as follows:\n\nWARNING: kernel/cgroup/cpuset.c:1651 at remote_partition_disable+0xf7/0x110\nRIP: 0010:remote_partition_disable+0xf7/0x110\nRSP: 0018:ffffc90001947d88 EFLAGS: 00000206\nRAX: 0000000000007fff RBX: ffff888103b6e000 RCX: 0000000000006f40\nRDX: 0000000000006f00 RSI: ffffc90001947da8 RDI: ffff888103b6e000\nRBP: ffff888103b6e000 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000001 R11: ffff88810b2e2728 R12: ffffc90001947da8\nR13: 0000000000000000 R14: ffffc90001947da8 R15: ffff8881081f1c00\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f55c8bbe0b2 CR3: 000000010b14c000 CR4: 00000000000006f0\nCall Trace:\n <TASK>\n update_prstate+0x2d3/0x580\n cpuset_partition_write+0x94/0xf0\n kernfs_fop_write_iter+0x147/0x200\n vfs_write+0x35d/0x500\n ksys_write+0x66/0xe0\n do_syscall_64+0x6b/0x390\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\nRIP: 0033:0x7f55c8cd4887\n\nReproduction steps (on a 16-CPU machine):\n\n        # cd /sys/fs/cgroup/\n        # mkdir A1\n        # echo +cpuset > A1/cgroup.subtree_control\n        # echo \"0-14\" > A1/cpuset.cpus.exclusive\n        # mkdir A1/A2\n        # echo \"0-14\" > A1/A2/cpuset.cpus.exclusive\n        # echo \"root\" > A1/A2/cpuset.cpus.partition\n        # echo 0 > /sys/devices/system/cpu/cpu15/online\n        # echo member > A1/A2/cpuset.cpus.partition\n\nWhen CPU 15 is offlined, subpartitions_cpus gets cleared because no CPUs\nremain available for the top_cpuset, forcing partitions to share CPUs with\nthe top_cpuset. In this scenario, disabling the remote partition triggers\na warning stating that effective_xcpus is not a subset of\nsubpartitions_cpus. Partitions should be invalidated in this case to\ninform users that the partition is now invalid(cpus are shared with\ntop_cpuset).\n\nTo fix this issue:\n1. Only emit the warning only if subpartitions_cpus is not empty and the\n   effective_xcpus is not a subset of subpartitions_cpus.\n2. During the CPU hotplug process, invalidate partitions if\n   subpartitions_cpus is empty.",
            "updated_at": "2026-09-14T12:17:37.650",
            "published_at": "2026-01-14T15:16:04.010",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "93f045741dac64facf90c2216f9a1d0876d122c4 through before 71953da7c979983917a4597bcad2c1ea6b8cc226 (git); f62a5d39368e34a966c8df63e1f05eed7fe9c5de through before 5d8b9d38a7676be7bb5e7d57f92156a98dab39fb (git); f62a5d39368e34a966c8df63e1f05eed7fe9c5de through before aa7d3a56a20f07978d9f401e13637a6479b13bd0 (git); 6.15",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpuset: fix warning when disabling remote partition\n\nA warning was triggered as follows:\n\nWARNING: kernel/cgroup/cpuset.c:1651 at remote_partition_disable+0xf7/0x110\nRIP: 0010:remote_partition_disable+0xf7/0x110\nRSP: 0018:ffffc90001947d88 EFLAGS: 00000206\nRAX: 0000000000007fff RBX: ffff888103b6e000 RCX: 0000000000006f40\nRDX: 0000000000006f00 RSI: ffffc90001947da8 RDI: ffff888103b6e000\nRBP: ffff888103b6e000 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000001 R11: ffff88810b2e2728 R12: ffffc90001947da8\nR13: 0000000000000000 R14: ffffc90001947da8 R15: ffff8881081f1c00\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f55c8bbe0b2 CR3: 000000010b14c000 CR4: 00000000000006f0\nCall Trace:\n <TASK>\n update_prstate+0x2d3/0x580\n cpuset_partition_write+0x94/0xf0\n kernfs_fop_write_iter+0x147/0x200\n vfs_write+0x35d/0x500\n ksys_write+0x66/0xe0\n do_syscall_64+0x6b/0x390\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\nRIP: 0033:0x7f55c8cd4887\n\nReproduction steps (on a 16-CPU machine):\n\n        # cd /sys/fs/cgroup/\n        # mkdir A1\n        # echo +cpuset > A1/cgroup.subtree_control\n        # echo \"0-14\" > A1/cpuset.cpus.exclusive\n        # mkdir A1/A2\n        # echo \"0-14\" > A1/A2/cpuset.cpus.exclusive\n        # echo \"root\" > A1/A2/cpuset.cpus.partition\n        # echo 0 > /sys/devices/system/cpu/cpu15/online\n        # echo member > A1/A2/cpuset.cpus.partition\n\nWhen CPU 15 is offlined, subpartitions_cpus gets cleared because no CPUs\nremain available for the top_cpuset, forcing partitions to share CPUs with\nthe top_cpuset. In this scenario, disabling the remote partition triggers\na warning stating that effective_xcpus is not a subset of\nsubpartitions_cpus. Partitions should be invalidated in this case to\ninform users that the partition is now invalid(cpus are shared with\ntop_cpuset).\n\nTo fix this issue:\n1. Only emit the warning only if subpartitions_cpus is not empty and the\n   effective_xcpus is not a subset of subpartitions_cpus.\n2. During the CPU hotplug process, invalidate partitions if\n   subpartitions_cpus is empty.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/5d8b9d38a7676be7bb5e7d57f92156a98dab39fb",
                "https://git.kernel.org/stable/c/71953da7c979983917a4597bcad2c1ea6b8cc226",
                "https://git.kernel.org/stable/c/aa7d3a56a20f07978d9f401e13637a6479b13bd0"
            ],
            "timeline": [
                {
                    "at": "2026-01-14T15:16:04.010",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-71142"
                }
            ]
        },
        {
            "id": "CVE-2025-70820",
            "vendor": "Zettlab",
            "product": "D6 Ultra",
            "title": "D6 Ultra vulnerability",
            "summary": "Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.",
            "updated_at": "2026-09-13T20:16:50.727",
            "published_at": "2026-09-13T20:16:50.727",
            "cvss": 3.5,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.7.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-36",
            "what_happened": "Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.xda-developers.com/nas-wouldnt-give-ssh-access-hacked-into/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T20:16:50.727",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70820"
                }
            ]
        },
        {
            "id": "CVE-2025-70819",
            "vendor": "Zettlab",
            "product": "D6 Ultra",
            "title": "D6 Ultra vulnerability",
            "summary": "Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via \"..\" manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.",
            "updated_at": "2026-09-13T20:16:50.593",
            "published_at": "2026-09-13T19:16:52.850",
            "cvss": 6.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.7.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-24",
            "what_happened": "Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via \"..\" manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.xda-developers.com/nas-wouldnt-give-ssh-access-hacked-into/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T19:16:52.850",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70819"
                }
            ]
        },
        {
            "id": "CVE-2025-70336",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "PodcastGenerator 3.2.9 - Stored XSS",
            "summary": "PodcastGenerator 3.2.9 - Stored XSS",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 98,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52677",
                    "author": "Sahil Arya",
                    "first_seen": "2026-09-02",
                    "confidence": "High",
                    "title": "PodcastGenerator 3.2.9 - Stored XSS",
                    "summary": "PodcastGenerator 3.2.9 - Stored XSS",
                    "url": "https://www.exploit-db.com/exploits/52677",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52677"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52677"
                }
            ]
        },
        {
            "id": "CVE-2025-70152",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, username, password, user_id) into SQL queries without validation or parameterization.",
            "updated_at": "2026-09-08T20:17:28.533",
            "published_at": "2026-02-18T18:24:21.530",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 32,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, username, password, user_id) into SQL queries without validation or parameterization.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "youngkevinn.github.io",
                    "author": "NVD reference",
                    "first_seen": "2026-02-18",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://youngkevinn.github.io/posts/CVE-2025-70152-Scholars-SQLi-Missing-Auth/"
                }
            ],
            "references": [
                "https://0x0bito.github.io/posts/CVE-2025-70152-Scholars-SQLi-Missing-Auth/",
                "https://code-projects.org/scholars-tracking-system-in-php-with-source-code/",
                "https://youngkevinn.github.io/posts/CVE-2025-70152-Scholars-SQLi-Missing-Auth/"
            ],
            "timeline": [
                {
                    "at": "2026-02-18T18:24:21.530",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70152"
                }
            ]
        },
        {
            "id": "CVE-2025-70151",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the original, user-supplied filename without validating the file type or extension. By uploading a PHP file and then requesting it from /uploads/, an attacker can execute arbitrary PHP code as the web server user.",
            "updated_at": "2026-09-08T20:17:28.360",
            "published_at": "2026-02-18T18:24:20.757",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 32,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the original, user-supplied filename without validating the file type or extension. By uploading a PHP file and then requesting it from /uploads/, an attacker can execute arbitrary PHP code as the web server user.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "youngkevinn.github.io",
                    "author": "NVD reference",
                    "first_seen": "2026-02-18",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://youngkevinn.github.io/posts/CVE-2025-70151-Scholars-FileUpload-RCE/"
                }
            ],
            "references": [
                "https://0x0bito.github.io/posts/CVE-2025-70151-Scholars-FileUpload-RCE/",
                "https://code-projects.org/scholars-tracking-system-in-php-with-source-code/",
                "https://youngkevinn.github.io/posts/CVE-2025-70151-Scholars-FileUpload-RCE/"
            ],
            "timeline": [
                {
                    "at": "2026-02-18T18:24:20.757",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70151"
                }
            ]
        },
        {
            "id": "CVE-2025-70150",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.",
            "updated_at": "2026-09-08T20:17:28.220",
            "published_at": "2026-02-18T18:24:20.040",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 33,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that allows unauthenticated attackers to delete arbitrary member records via the id parameter.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "youngkevinn.github.io",
                    "author": "NVD reference",
                    "first_seen": "2026-02-18",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://youngkevinn.github.io/posts/CVE-2025-70150-Membership-Unauth-Delete/"
                }
            ],
            "references": [
                "https://0x0bito.github.io/posts/CVE-2025-70150-Membership-Unauth-Delete/",
                "https://www.phpscriptsonline.com/product/membership-management-software",
                "https://youngkevinn.github.io/posts/CVE-2025-70150-Membership-Unauth-Delete/"
            ],
            "timeline": [
                {
                    "at": "2026-02-18T18:24:20.040",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70150"
                }
            ]
        },
        {
            "id": "CVE-2025-70149",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.",
            "updated_at": "2026-09-08T20:17:28.017",
            "published_at": "2026-02-18T17:21:36.160",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 32,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parameter.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "youngkevinn.github.io",
                    "author": "NVD reference",
                    "first_seen": "2026-02-18",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://youngkevinn.github.io/posts/CVE-2025-70149-Membership-SQLi/"
                }
            ],
            "references": [
                "https://0x0bito.github.io/posts/CVE-2025-70149-Membership-SQLi/",
                "https://www.phpscriptsonline.com/product/membership-management-software",
                "https://youngkevinn.github.io/posts/CVE-2025-70149-Membership-SQLi/"
            ],
            "timeline": [
                {
                    "at": "2026-02-18T17:21:36.160",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70149"
                }
            ]
        },
        {
            "id": "CVE-2025-70148",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR).",
            "updated_at": "2026-09-08T20:17:27.867",
            "published_at": "2026-02-18T18:24:19.790",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 33,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allows unauthenticated attackers to access membership card data of arbitrary users via direct requests with a manipulated id parameter, resulting in insecure direct object reference (IDOR).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "youngkevinn.github.io",
                    "author": "NVD reference",
                    "first_seen": "2026-02-18",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://youngkevinn.github.io/posts/CVE-2025-70148-Membership-IDOR/"
                }
            ],
            "references": [
                "https://0x0bito.github.io/posts/CVE-2025-70148-Membership-IDOR/",
                "https://www.phpscriptsonline.com/product/membership-management-software",
                "https://youngkevinn.github.io/posts/CVE-2025-70148-Membership-IDOR/"
            ],
            "timeline": [
                {
                    "at": "2026-02-18T18:24:19.790",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70148"
                }
            ]
        },
        {
            "id": "CVE-2025-70147",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a valid session.",
            "updated_at": "2026-09-08T20:17:27.663",
            "published_at": "2026-02-18T17:21:36.007",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 32,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a valid session.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "youngkevinn.github.io",
                    "author": "NVD reference",
                    "first_seen": "2026-02-18",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://youngkevinn.github.io/posts/CVE-2025-70147-OTTTG-Info-Disclosure/"
                }
            ],
            "references": [
                "https://0x0bito.github.io/posts/CVE-2025-70147-OTTTG-Info-Disclosure/",
                "https://projectworlds.com/online-time-table-generator-php-mysql/",
                "https://youngkevinn.github.io/posts/CVE-2025-70147-OTTTG-Info-Disclosure/"
            ],
            "timeline": [
                {
                    "at": "2026-02-18T17:21:36.007",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70147"
                }
            ]
        },
        {
            "id": "CVE-2025-70146",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a valid session.",
            "updated_at": "2026-09-08T20:17:27.477",
            "published_at": "2026-02-18T17:21:35.853",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 32,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a valid session.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "youngkevinn.github.io",
                    "author": "NVD reference",
                    "first_seen": "2026-02-18",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://youngkevinn.github.io/posts/CVE-2025-70146-OTTTG-Unauth-Deletion/"
                }
            ],
            "references": [
                "https://0x0bito.github.io/posts/CVE-2025-70146-OTTTG-Unauth-Deletion/",
                "https://projectworlds.com/online-time-table-generator-php-mysql/",
                "https://youngkevinn.github.io/posts/CVE-2025-70146-OTTTG-Unauth-Deletion/"
            ],
            "timeline": [
                {
                    "at": "2026-02-18T17:21:35.853",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70146"
                }
            ]
        },
        {
            "id": "CVE-2025-70141",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An unauthenticated remote attacker can perform sensitive operations such as creating customers and deleting users (including the admin account), as well as modifying or deleting other application records (tickets, departments, comments), resulting in unauthorized data modification.",
            "updated_at": "2026-09-08T20:17:27.277",
            "published_at": "2026-02-18T17:21:35.700",
            "cvss": 9.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 32,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-306",
            "what_happened": "SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An unauthenticated remote attacker can perform sensitive operations such as creating customers and deleting users (including the admin account), as well as modifying or deleting other application records (tickets, departments, comments), resulting in unauthorized data modification.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "youngkevinn.github.io",
                    "author": "NVD reference",
                    "first_seen": "2026-02-18",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://youngkevinn.github.io/posts/CVE-2025-70141-Customer-Support-BAC/"
                }
            ],
            "references": [
                "https://0x0bito.github.io/posts/CVE-2025-70141-Customer-Support-BAC/",
                "https://www.sourcecodester.com/download-code?nid=14587&title=Customer+Support+System+using+PHP%2FMySQLi+with+Source+Code",
                "https://youngkevinn.github.io/posts/CVE-2025-70141-Customer-Support-BAC/"
            ],
            "timeline": [
                {
                    "at": "2026-02-18T17:21:35.700",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-70141"
                }
            ]
        },
        {
            "id": "CVE-2025-69873",
            "vendor": "ajv.js",
            "product": "ajv",
            "title": "ajv vulnerability",
            "summary": "ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., \"^(a|a)*$\") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation. This issue is also fixed in version 6.14.0.",
            "updated_at": "2026-09-10T13:17:29.420",
            "published_at": "2026-02-11T19:15:50.467",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 6.14.0 (semver); 7.0.0 through before 8.17.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 37,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-1333",
            "what_happened": "ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which is passed directly to the JavaScript RegExp() constructor without validation. An attacker can inject a malicious regex pattern (e.g., \"^(a|a)*$\") combined with crafted input to cause catastrophic backtracking. A 31-character payload causes approximately 44 seconds of CPU blocking, with each additional character doubling execution time. This enables complete denial of service with a single HTTP request against any API using ajv with $data: true for dynamic schema validation. This issue is also fixed in version 6.14.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md",
                "https://github.com/advisories/GHSA-2g4f-4pwh-qvx6",
                "https://github.com/ajv-validator/ajv/pull/2588",
                "https://github.com/ajv-validator/ajv/pull/2590",
                "https://github.com/ajv-validator/ajv/releases/tag/v6.14.0",
                "https://github.com/github/advisory-database/pull/6991",
                "https://access.redhat.com/errata/RHSA-2026:10093",
                "https://access.redhat.com/errata/RHSA-2026:13512",
                "https://access.redhat.com/errata/RHSA-2026:14774",
                "https://access.redhat.com/errata/RHSA-2026:15091",
                "https://access.redhat.com/errata/RHSA-2026:16874",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:26211",
                "https://access.redhat.com/errata/RHSA-2026:26214",
                "https://access.redhat.com/errata/RHSA-2026:33371",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:40984",
                "https://access.redhat.com/errata/RHSA-2026:41941",
                "https://access.redhat.com/errata/RHSA-2026:41944",
                "https://access.redhat.com/errata/RHSA-2026:5168",
                "https://access.redhat.com/errata/RHSA-2026:5807",
                "https://access.redhat.com/errata/RHSA-2026:5907",
                "https://access.redhat.com/errata/RHSA-2026:5910",
                "https://access.redhat.com/errata/RHSA-2026:6192",
                "https://access.redhat.com/errata/RHSA-2026:6277",
                "https://access.redhat.com/errata/RHSA-2026:6309",
                "https://access.redhat.com/errata/RHSA-2026:6497",
                "https://access.redhat.com/errata/RHSA-2026:6567",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/errata/RHSA-2026:6802",
                "https://access.redhat.com/errata/RHSA-2026:7314",
                "https://access.redhat.com/errata/RHSA-2026:9742",
                "https://access.redhat.com/security/cve/CVE-2025-69873",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2439070",
                "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69873.json"
            ],
            "timeline": [
                {
                    "at": "2026-02-11T19:15:50.467",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69873"
                }
            ]
        },
        {
            "id": "CVE-2025-69534",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.",
            "updated_at": "2026-09-07T13:17:57.517",
            "published_at": "2026-03-05T15:16:11.243",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 54,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-03-05",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/Python-Markdown/markdown/issues/1534"
                }
            ],
            "references": [
                "https://github.com/Python-Markdown/markdown",
                "https://github.com/Python-Markdown/markdown/actions/runs/15736122892",
                "https://github.com/Python-Markdown/markdown/issues/1534",
                "http://www.openwall.com/lists/oss-security/2026/03/06/4",
                "https://access.redhat.com/errata/RHSA-2026:10184",
                "https://access.redhat.com/errata/RHSA-2026:13508",
                "https://access.redhat.com/errata/RHSA-2026:13512",
                "https://access.redhat.com/errata/RHSA-2026:13826",
                "https://access.redhat.com/errata/RHSA-2026:14835",
                "https://access.redhat.com/errata/RHSA-2026:14873",
                "https://access.redhat.com/errata/RHSA-2026:14874",
                "https://access.redhat.com/errata/RHSA-2026:19155",
                "https://access.redhat.com/errata/RHSA-2026:19366",
                "https://access.redhat.com/errata/RHSA-2026:20674",
                "https://access.redhat.com/errata/RHSA-2026:20676",
                "https://access.redhat.com/errata/RHSA-2026:20677",
                "https://access.redhat.com/errata/RHSA-2026:9742",
                "https://access.redhat.com/security/cve/CVE-2025-69534",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2444839",
                "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69534.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-05T15:16:11.243",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-69534"
                }
            ]
        },
        {
            "id": "CVE-2025-69212",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing",
            "summary": "CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing",
            "updated_at": "2026-08-20T22:00:00Z",
            "published_at": "2026-08-20T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 131,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · lukasz-rybak/CVE-2025-69212",
                    "author": "lukasz-rybak",
                    "first_seen": "2026-04-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing",
                    "summary": "CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing",
                    "url": "https://github.com/lukasz-rybak/CVE-2025-69212"
                },
                {
                    "repository": "PoC-in-GitHub · tohib09/CVE-2025-69212-PoC",
                    "author": "tohib09",
                    "first_seen": "2026-06-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2025-69212 repository",
                    "summary": "",
                    "url": "https://github.com/tohib09/CVE-2025-69212-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · c0gnit00/CVE-2026-69212",
                    "author": "c0gnit00",
                    "first_seen": "2026-06-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Python poc, exploit for CVE-2025-69212",
                    "summary": "Python poc, exploit for CVE-2025-69212",
                    "url": "https://github.com/c0gnit00/CVE-2026-69212"
                },
                {
                    "repository": "PoC-in-GitHub · w3nch/CVE-2025-69212",
                    "author": "w3nch",
                    "first_seen": "2026-06-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-69212 repository",
                    "summary": "",
                    "url": "https://github.com/w3nch/CVE-2025-69212"
                },
                {
                    "repository": "PoC-in-GitHub · xorandd/CVE-2025-69212-PoC",
                    "author": "xorandd",
                    "first_seen": "2026-06-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-69212 repository",
                    "summary": "",
                    "url": "https://github.com/xorandd/CVE-2025-69212-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · BridgerAlderson/CVE-2025-69212-PoC",
                    "author": "BridgerAlderson",
                    "first_seen": "2026-06-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.",
                    "summary": "OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.",
                    "url": "https://github.com/BridgerAlderson/CVE-2025-69212-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · alaeddine03/CVE-2025-69212-PoC",
                    "author": "alaeddine03",
                    "first_seen": "2026-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-69212 - OpenSTAManager OS Command Injection PoC",
                    "summary": "CVE-2025-69212 - OpenSTAManager OS Command Injection PoC",
                    "url": "https://github.com/alaeddine03/CVE-2025-69212-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · m2sousa/CVE-2025-69212",
                    "author": "m2sousa",
                    "first_seen": "2026-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-69212 Proof-of-concept. Authenticated RCE in OpenSTAManager ≤2.9.8 via malicious ZIP uploads containing crafted .p7m filenames.",
                    "summary": "CVE-2025-69212 Proof-of-concept. Authenticated RCE in OpenSTAManager ≤2.9.8 via malicious ZIP uploads containing crafted .p7m filenames.",
                    "url": "https://github.com/m2sousa/CVE-2025-69212"
                },
                {
                    "repository": "PoC-in-GitHub · 0Zetrium0/CVE-2025-69212_PoC",
                    "author": "0Zetrium0",
                    "first_seen": "2026-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository contains a PoC exploit for CVE-2025-69212.",
                    "summary": "This repository contains a PoC exploit for CVE-2025-69212.",
                    "url": "https://github.com/0Zetrium0/CVE-2025-69212_PoC"
                },
                {
                    "repository": "PoC-in-GitHub · mmoobbeeiidat-design/Hack-The-Box-Enigma-Findings-Report",
                    "author": "mmoobbeeiidat-design",
                    "first_seen": "2026-07-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "HTB_Enigma Security Assessment – Full pentest completed, chaining NFS disclosure, IMAPS password reuse, and OS Command Injection in OpenSTAManager (CVE-2025-69212) through to root via a misconfigured OliveTin service. Full report and evidence appendix to be published once permitted by HTB's active-machine policy.",
                    "summary": "HTB_Enigma Security Assessment – Full pentest completed, chaining NFS disclosure, IMAPS password reuse, and OS Command Injection in OpenSTAManager (CVE-2025-69212) through to root via a misconfigured OliveTin service. Full report and evidence appendix to be published once permitted by HTB's active-machine policy.",
                    "url": "https://github.com/mmoobbeeiidat-design/Hack-The-Box-Enigma-Findings-Report"
                },
                {
                    "repository": "PoC-in-GitHub · liaomilk/CVE-2025-69212-for-myself",
                    "author": "liaomilk",
                    "first_seen": "2026-08-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "just record for myself",
                    "summary": "just record for myself",
                    "url": "https://github.com/liaomilk/CVE-2025-69212-for-myself"
                },
                {
                    "repository": "PoC-in-GitHub · lolw0/OpenSTA-Exploit",
                    "author": "lolw0",
                    "first_seen": "2026-08-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Proof of Concept (PoC) of CVE-2025-69212 related with P7M File Processing",
                    "summary": "Proof of Concept (PoC) of CVE-2025-69212 related with P7M File Processing",
                    "url": "https://github.com/lolw0/OpenSTA-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Pasindu-sd/CVE-2025-69212-Exploit",
                    "author": "Pasindu-sd",
                    "first_seen": "2026-08-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A fully automated exploit script for **CVE-2025-69212**, a command injection vulnerability in OpenSTAManager. This script authenticates with admin credentials, deploys a malicious PHP web shell via a crafted P7M file in a ZIP archive, and provides command execution or a reverse shell.",
                    "summary": "A fully automated exploit script for **CVE-2025-69212**, a command injection vulnerability in OpenSTAManager. This script authenticates with admin credentials, deploys a malicious PHP web shell via a crafted P7M file in a ZIP archive, and provides command execution or a reverse shell.",
                    "url": "https://github.com/Pasindu-sd/CVE-2025-69212-Exploit"
                }
            ],
            "references": [
                "https://github.com/lukasz-rybak/CVE-2025-69212",
                "https://github.com/tohib09/CVE-2025-69212-PoC",
                "https://github.com/c0gnit00/CVE-2026-69212",
                "https://github.com/w3nch/CVE-2025-69212",
                "https://github.com/xorandd/CVE-2025-69212-PoC",
                "https://github.com/BridgerAlderson/CVE-2025-69212-PoC",
                "https://github.com/alaeddine03/CVE-2025-69212-PoC",
                "https://github.com/m2sousa/CVE-2025-69212",
                "https://github.com/0Zetrium0/CVE-2025-69212_PoC",
                "https://github.com/mmoobbeeiidat-design/Hack-The-Box-Enigma-Findings-Report",
                "https://github.com/liaomilk/CVE-2025-69212-for-myself",
                "https://github.com/lolw0/OpenSTA-Exploit",
                "https://github.com/Pasindu-sd/CVE-2025-69212-Exploit"
            ],
            "timeline": [
                {
                    "at": "2026-08-20T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/lukasz-rybak/CVE-2025-69212"
                }
            ]
        },
        {
            "id": "CVE-2025-68686",
            "vendor": "Fortinet",
            "product": "FortiOS",
            "title": "Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability",
            "summary": "Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.",
            "updated_at": "2026-07-26T22:00:00Z",
            "published_at": "2026-07-26T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-07-26T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-68624",
            "vendor": "N-able",
            "product": "Mail Assure",
            "title": "Mail Assure vulnerability",
            "summary": "N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants. When connecting to the SMTP TCP port and performing SMTP AUTH with valid credentials, the server accepts arbitrary sender domains without enforcing any domain-to-account binding. As a result, an attacker from any tenant can impersonate other tenant domains, producing messages that pass SPF and DMARC validation. NOTE: N-able's position is that the behavior is intended functionality of its shared SMTP relay architecture and that the service does not represent that it enforces per-tenant sender-domain binding.",
            "updated_at": "2026-09-14T01:16:27.220",
            "published_at": "2026-09-14T01:16:27.220",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through April 2026 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-290",
            "what_happened": "N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants. When connecting to the SMTP TCP port and performing SMTP AUTH with valid credentials, the server accepts arbitrary sender domains without enforcing any domain-to-account binding. As a result, an attacker from any tenant can impersonate other tenant domains, producing messages that pass SPF and DMARC validation. NOTE: N-able's position is that the behavior is intended functionality of its shared SMTP relay architecture and that the service does not represent that it enforces per-tenant sender-domain binding.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://deepsec.net/speaker.html#PSLOT782",
                "https://gist.github.com/alessandrobertoldi/1ebe0f48aa0119d787ac0ff710057d92",
                "https://www.n-able.com/products/mail-assure",
                "http://seclists.org/fulldisclosure/2026/Jun/10"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T01:16:27.220",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-68624"
                }
            ]
        },
        {
            "id": "CVE-2025-68613",
            "vendor": "n8n",
            "product": "n8n",
            "title": "n8n Improper Control of Dynamically-Managed Code Resources Vulnerability",
            "summary": "n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.",
            "updated_at": "2026-09-11T22:10:10Z",
            "published_at": "2026-09-11T22:10:10Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 584,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Improper Input Validation in N8N CVE-2025-68613 CVE-2026-20805 CVE-2026-21858 CVE-2026-24291 CVE-2",
                    "summary": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "what_happened": "Unauthenticated RCE in n8n via file read and expression injection sandbox bypass.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-200",
                    "references": [
                        "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                        "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                    ],
                    "repository": "Sploitus",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12T00:10:10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA"
                },
                {
                    "repository": "PoC-in-GitHub · ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                    "author": "ZeroDayEvil",
                    "first_seen": "2026-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n \"Ni8mare\" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chain).",
                    "summary": "🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n \"Ni8mare\" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chain).",
                    "url": "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain"
                },
                {
                    "repository": "PoC-in-GitHub · rxerium/CVE-2025-68613",
                    "author": "rxerium",
                    "first_seen": "2025-12-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 28,
                    "title": "Detection for CVE-2025-68613",
                    "summary": "Detection for CVE-2025-68613",
                    "url": "https://github.com/rxerium/CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · TheStingR/CVE-2025-68613-POC",
                    "author": "TheStingR",
                    "first_seen": "2025-12-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 29,
                    "title": "Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes detection tools, full exploit, and remediation guidance.",
                    "summary": "Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes detection tools, full exploit, and remediation guidance.",
                    "url": "https://github.com/TheStingR/CVE-2025-68613-POC"
                },
                {
                    "repository": "PoC-in-GitHub · sahilccras/Blackash-CVE-2025-68613",
                    "author": "sahilccras",
                    "first_seen": "2025-12-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-68613",
                    "summary": "CVE-2025-68613",
                    "url": "https://github.com/sahilccras/Blackash-CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · wioui/n8n-CVE-2025-68613-exploit",
                    "author": "wioui",
                    "first_seen": "2025-12-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 106,
                    "title": "CVE-2025-68613: n8n RCE vulnerability exploit and documentation",
                    "summary": "CVE-2025-68613: n8n RCE vulnerability exploit and documentation",
                    "url": "https://github.com/wioui/n8n-CVE-2025-68613-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · reem-012/poc_CVE-2025-68613",
                    "author": "reem-012",
                    "first_seen": "2025-12-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "POC for CVE-2025-68613",
                    "summary": "POC for CVE-2025-68613",
                    "url": "https://github.com/reem-012/poc_CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · intbjw/CVE-2025-68613-poc-via-copilot",
                    "author": "intbjw",
                    "first_seen": "2025-12-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "通过GitHub Copilot 辅助分析CVE-2025-68613漏洞",
                    "summary": "通过GitHub Copilot 辅助分析CVE-2025-68613漏洞",
                    "url": "https://github.com/intbjw/CVE-2025-68613-poc-via-copilot"
                },
                {
                    "repository": "PoC-in-GitHub · ali-py3/Exploit-CVE-2025-68613",
                    "author": "ali-py3",
                    "first_seen": "2025-12-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-68613 repository",
                    "summary": "",
                    "url": "https://github.com/ali-py3/Exploit-CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · nehkark/CVE-2025-68613",
                    "author": "nehkark",
                    "first_seen": "2025-12-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository contains a laboratory-grade analysis and a **safe Proof-of-Concept** for the vulnerability **CVE-2025-68613**, affecting the workflow automation platform **n8n**.",
                    "summary": "This repository contains a laboratory-grade analysis and a **safe Proof-of-Concept** for the vulnerability **CVE-2025-68613**, affecting the workflow automation platform **n8n**.",
                    "url": "https://github.com/nehkark/CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · GnuTLam/POC-CVE-2025-68613",
                    "author": "GnuTLam",
                    "first_seen": "2025-12-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "My poc to exploit this vuln :D",
                    "summary": "My poc to exploit this vuln :D",
                    "url": "https://github.com/GnuTLam/POC-CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · secjoker/CVE-2025-68613",
                    "author": "secjoker",
                    "first_seen": "2025-12-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "基于Pocsuite3 框架编写的漏洞验证与利用脚本，用于检测 n8n工作流自动化工具中的认证后远程代码执行漏洞（RCE）",
                    "summary": "基于Pocsuite3 框架编写的漏洞验证与利用脚本，用于检测 n8n工作流自动化工具中的认证后远程代码执行漏洞（RCE）",
                    "url": "https://github.com/secjoker/CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · r4j3sh-com/CVE-2025-68613-n8n-lab",
                    "author": "r4j3sh-com",
                    "first_seen": "2025-12-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Analysis of CVE-2025-68613",
                    "summary": "Analysis of CVE-2025-68613",
                    "url": "https://github.com/r4j3sh-com/CVE-2025-68613-n8n-lab"
                },
                {
                    "repository": "PoC-in-GitHub · intelligent-ears/CVE-2025-68613",
                    "author": "intelligent-ears",
                    "first_seen": "2025-12-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-68613 repository",
                    "summary": "",
                    "url": "https://github.com/intelligent-ears/CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · manyaigdtuw/CVE-2025-68613_Scanner",
                    "author": "manyaigdtuw",
                    "first_seen": "2025-12-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "GUI Shodan-powered scanner to identify n8n instances exposed to CVE-2025-68613 (version range 0.211.0–1.122.0)",
                    "summary": "GUI Shodan-powered scanner to identify n8n instances exposed to CVE-2025-68613 (version range 0.211.0–1.122.0)",
                    "url": "https://github.com/manyaigdtuw/CVE-2025-68613_Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · AbdulRKB/n8n-RCE",
                    "author": "AbdulRKB",
                    "first_seen": "2025-12-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Proof of Concept (PoC) Script for Remote Code Execution via n8n Workflows (Based on CVE-2025-68613)",
                    "summary": "Proof of Concept (PoC) Script for Remote Code Execution via n8n Workflows (Based on CVE-2025-68613)",
                    "url": "https://github.com/AbdulRKB/n8n-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · JohannesLks/CVE-2025-68613-Python-Exploit",
                    "author": "JohannesLks",
                    "first_seen": "2025-12-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Python Exploit for CVE-2025-68613.",
                    "summary": "Python Exploit for CVE-2025-68613.",
                    "url": "https://github.com/JohannesLks/CVE-2025-68613-Python-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · hackersatyamrastogi/n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimate",
                    "author": "hackersatyamrastogi",
                    "first_seen": "2025-12-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "n8n God Mode Ultimate - CVE-2025-68613 Scanner v1.0.0         ║ ║           Workflow Automation Remote Code Execution",
                    "summary": "n8n God Mode Ultimate - CVE-2025-68613 Scanner v1.0.0         ║ ║           Workflow Automation Remote Code Execution",
                    "url": "https://github.com/hackersatyamrastogi/n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimate"
                },
                {
                    "repository": "PoC-in-GitHub · mbanyamer/n8n-Authenticated-Expression-Injection-RCE-CVE-2025-68613",
                    "author": "mbanyamer",
                    "first_seen": "2025-12-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Proof-of-Concept exploit for CVE-2025-68613: Authenticated Remote Code Execution in n8n via Expression Injection",
                    "summary": "Proof-of-Concept exploit for CVE-2025-68613: Authenticated Remote Code Execution in n8n via Expression Injection",
                    "url": "https://github.com/mbanyamer/n8n-Authenticated-Expression-Injection-RCE-CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · releaseown/analysis-and-poc-n8n-CVE-2025-68613",
                    "author": "releaseown",
                    "first_seen": "2025-12-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Technical study of the CVE-2025-68613 vulnerability in n8n, covering affected versions, laboratory exploration scenario, offensive and defensive analysis, and mitigation strategies.",
                    "summary": "Technical study of the CVE-2025-68613 vulnerability in n8n, covering affected versions, laboratory exploration scenario, offensive and defensive analysis, and mitigation strategies.",
                    "url": "https://github.com/releaseown/analysis-and-poc-n8n-CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · Dlanang/homelab-CVE-2025-68613",
                    "author": "Dlanang",
                    "first_seen": "2025-12-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-68613 repository",
                    "summary": "",
                    "url": "https://github.com/Dlanang/homelab-CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · Khin-96/n8n-cve-2025-68613-thm",
                    "author": "Khin-96",
                    "first_seen": "2025-12-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-68613 repository",
                    "summary": "",
                    "url": "https://github.com/Khin-96/n8n-cve-2025-68613-thm"
                },
                {
                    "repository": "PoC-in-GitHub · J4ck3LSyN-Gen2/n8n-CVE-2025-68613-TryHackMe",
                    "author": "J4ck3LSyN-Gen2",
                    "first_seen": "2025-12-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "The minor methodology for room: https://tryhackme.com/room/n8ncve202568613",
                    "summary": "The minor methodology for room: https://tryhackme.com/room/n8ncve202568613",
                    "url": "https://github.com/J4ck3LSyN-Gen2/n8n-CVE-2025-68613-TryHackMe"
                },
                {
                    "repository": "PoC-in-GitHub · Ak-cybe/CVE-2025-68613-n8n-rce-analysis",
                    "author": "Ak-cybe",
                    "first_seen": "2025-12-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-68613 (n8n) Critical RCE analysis + defensive recommendations (patch validation, detection ideas, and hardening tips)",
                    "summary": "CVE-2025-68613 (n8n) Critical RCE analysis + defensive recommendations (patch validation, detection ideas, and hardening tips)",
                    "url": "https://github.com/Ak-cybe/CVE-2025-68613-n8n-rce-analysis"
                },
                {
                    "repository": "PoC-in-GitHub · LingerANR/n8n-CVE-2025-68613",
                    "author": "LingerANR",
                    "first_seen": "2025-12-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "This laboratory provides a controlled environment to analyze and reproduce CVE-2025-68613 in a vulnerable n8n instance.",
                    "summary": "This laboratory provides a controlled environment to analyze and reproduce CVE-2025-68613 in a vulnerable n8n instance.",
                    "url": "https://github.com/LingerANR/n8n-CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · gagaltotal/n8n-cve-2025-68613",
                    "author": "gagaltotal",
                    "first_seen": "2025-12-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "n8n CVE-2025-68613",
                    "summary": "n8n CVE-2025-68613",
                    "url": "https://github.com/gagaltotal/n8n-cve-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · cv-sai-kamesh/n8n-CVE-2025-68613",
                    "author": "cv-sai-kamesh",
                    "first_seen": "2025-12-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-68613 repository",
                    "summary": "",
                    "url": "https://github.com/cv-sai-kamesh/n8n-CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · Rishi-kaul/n8n-CVE-2025-68613",
                    "author": "Rishi-kaul",
                    "first_seen": "2025-12-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-68613 repository",
                    "summary": "",
                    "url": "https://github.com/Rishi-kaul/n8n-CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · ahmedshamsddin/n8n-RCE-CVE-2025-68613",
                    "author": "ahmedshamsddin",
                    "first_seen": "2026-01-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "n8n RCE (CVE-2025-68613)",
                    "summary": "n8n RCE (CVE-2025-68613)",
                    "url": "https://github.com/ahmedshamsddin/n8n-RCE-CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · TheInterception/n8n_CVE-2025-68613_exploit_payloads",
                    "author": "TheInterception",
                    "first_seen": "2026-01-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Expression injection payloads for n8n CVE-2025-68613 RCE",
                    "summary": "Expression injection payloads for n8n CVE-2025-68613 RCE",
                    "url": "https://github.com/TheInterception/n8n_CVE-2025-68613_exploit_payloads"
                },
                {
                    "repository": "PoC-in-GitHub · Victorhugofariasvieir66/relatorio-n8n.md",
                    "author": "Victorhugofariasvieir66",
                    "first_seen": "2026-01-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Relatório TryHackMe — n8n CVE-2025-68613 (CVSS 9.9)",
                    "summary": "Relatório TryHackMe — n8n CVE-2025-68613 (CVSS 9.9)",
                    "url": "https://github.com/Victorhugofariasvieir66/relatorio-n8n.md"
                },
                {
                    "repository": "PoC-in-GitHub · h3raklez/CVE-2025-68613",
                    "author": "h3raklez",
                    "first_seen": "2026-03-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-68613 — n8n RCE via Expression Injection",
                    "summary": "CVE-2025-68613 — n8n RCE via Expression Injection",
                    "url": "https://github.com/h3raklez/CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · canpilayda/n8n-RCE-CVE-2025-68613",
                    "author": "canpilayda",
                    "first_seen": "2026-04-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-68613 repository",
                    "summary": "",
                    "url": "https://github.com/canpilayda/n8n-RCE-CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · azilRababe/CVE-2025-68613",
                    "author": "azilRababe",
                    "first_seen": "2026-06-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Technical analysis of CVE-2025-68613, a critical Expression Injection vulnerability in n8n that allows authenticated attackers to achieve Remote Code Execution (RCE)",
                    "summary": "Technical analysis of CVE-2025-68613, a critical Expression Injection vulnerability in n8n that allows authenticated attackers to achieve Remote Code Execution (RCE)",
                    "url": "https://github.com/azilRababe/CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · qianlijaingshan/n8n-cve-2026-21858",
                    "author": "qianlijaingshan",
                    "first_seen": "2026-07-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2026-21858 + CVE-2025-68613 — n8n unauthenticated file read to RCE exploit",
                    "summary": "CVE-2026-21858 + CVE-2025-68613 — n8n unauthenticated file read to RCE exploit",
                    "url": "https://github.com/qianlijaingshan/n8n-cve-2026-21858"
                },
                {
                    "repository": "PoC-in-GitHub · Giangdurian/CVE-2026-21858-and-CVE-2025-68613",
                    "author": "Giangdurian",
                    "first_seen": "2026-07-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-68613 repository",
                    "summary": "",
                    "url": "https://github.com/Giangdurian/CVE-2026-21858-and-CVE-2025-68613"
                },
                {
                    "repository": "PoC-in-GitHub · rmhowe425/POC-CVE-2025-68613",
                    "author": "rmhowe425",
                    "first_seen": "2026-09-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-68613 repository",
                    "summary": "",
                    "url": "https://github.com/rmhowe425/POC-CVE-2025-68613"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=B8999BFA-BF67-513C-AA37-7ADE8D43C0DA",
                "https://github.com/ZeroDayEvil/CVE-2026-21858-n8n-FullChain",
                "https://github.com/rxerium/CVE-2025-68613",
                "https://github.com/TheStingR/CVE-2025-68613-POC",
                "https://github.com/sahilccras/Blackash-CVE-2025-68613",
                "https://github.com/wioui/n8n-CVE-2025-68613-exploit",
                "https://github.com/reem-012/poc_CVE-2025-68613",
                "https://github.com/intbjw/CVE-2025-68613-poc-via-copilot",
                "https://github.com/ali-py3/Exploit-CVE-2025-68613",
                "https://github.com/nehkark/CVE-2025-68613",
                "https://github.com/GnuTLam/POC-CVE-2025-68613",
                "https://github.com/secjoker/CVE-2025-68613",
                "https://github.com/r4j3sh-com/CVE-2025-68613-n8n-lab",
                "https://github.com/intelligent-ears/CVE-2025-68613",
                "https://github.com/manyaigdtuw/CVE-2025-68613_Scanner",
                "https://github.com/AbdulRKB/n8n-RCE",
                "https://github.com/JohannesLks/CVE-2025-68613-Python-Exploit",
                "https://github.com/hackersatyamrastogi/n8n-exploit-CVE-2025-68613-n8n-God-Mode-Ultimate",
                "https://github.com/mbanyamer/n8n-Authenticated-Expression-Injection-RCE-CVE-2025-68613",
                "https://github.com/releaseown/analysis-and-poc-n8n-CVE-2025-68613",
                "https://github.com/Dlanang/homelab-CVE-2025-68613",
                "https://github.com/Khin-96/n8n-cve-2025-68613-thm",
                "https://github.com/J4ck3LSyN-Gen2/n8n-CVE-2025-68613-TryHackMe",
                "https://github.com/Ak-cybe/CVE-2025-68613-n8n-rce-analysis",
                "https://github.com/LingerANR/n8n-CVE-2025-68613",
                "https://github.com/gagaltotal/n8n-cve-2025-68613",
                "https://github.com/cv-sai-kamesh/n8n-CVE-2025-68613",
                "https://github.com/Rishi-kaul/n8n-CVE-2025-68613",
                "https://github.com/ahmedshamsddin/n8n-RCE-CVE-2025-68613",
                "https://github.com/TheInterception/n8n_CVE-2025-68613_exploit_payloads",
                "https://github.com/Victorhugofariasvieir66/relatorio-n8n.md",
                "https://github.com/h3raklez/CVE-2025-68613",
                "https://github.com/canpilayda/n8n-RCE-CVE-2025-68613",
                "https://github.com/azilRababe/CVE-2025-68613",
                "https://github.com/qianlijaingshan/n8n-cve-2026-21858",
                "https://github.com/Giangdurian/CVE-2026-21858-and-CVE-2025-68613",
                "https://github.com/rmhowe425/POC-CVE-2025-68613"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:10:10Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2025-68137",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "EVerest 2025.9.0 - DoS",
            "summary": "EVerest 2025.9.0 - DoS",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 171,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "EVerest 2025.9.0 DoS",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52679",
                    "author": "Ranjit Kumar Singh",
                    "first_seen": "2026-09-02",
                    "confidence": "High",
                    "title": "EVerest 2025.9.0 - DoS",
                    "summary": "EVerest 2025.9.0 - DoS",
                    "url": "https://www.exploit-db.com/exploits/52679",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "CXSecurity WLB-2026090003",
                    "author": "[Ranjit Kumar Singh]",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "EVerest 2025.9.0 DoS",
                    "summary": "EVerest 2025.9.0 DoS",
                    "what_happened": "EVerest 2025.9.0 DoS",
                    "cvss": 0,
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "url": "https://cxsecurity.com/issue/WLB-2026090003",
                    "cwe": "Unknown"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52679",
                "https://cxsecurity.com/issue/WLB-2026090003"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52679"
                }
            ]
        },
        {
            "id": "CVE-2025-67366",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of filesystem-mcp contains a critical path traversal vulnerability in its \"read_content\" tool. This vulnerability arises from improper symlink handling in the path validation mechanism: the resolvePath function checks path validity before resolving symlinks, while fs.readFile resolves symlinks automatically during file access. This allows attackers to bypass directory restrictions by leveraging symlinks within the allowed directory that point to external files, enabling unauthorized access to files outside the intended operational scope.",
            "updated_at": "2026-09-16T18:21:52.127",
            "published_at": "2026-01-07T17:16:01.893",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-23",
            "what_happened": "@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of filesystem-mcp contains a critical path traversal vulnerability in its \"read_content\" tool. This vulnerability arises from improper symlink handling in the path validation mechanism: the resolvePath function checks path validity before resolving symlinks, while fs.readFile resolves symlinks automatically during file access. This allows attackers to bypass directory restrictions by leveraging symlinks within the allowed directory that point to external files, enabling unauthorized access to files outside the intended operational scope.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-01-07",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/sylphxltd/filesystem-mcp/issues/134"
                }
            ],
            "references": [
                "https://github.com/sylphxltd/filesystem-mcp",
                "https://github.com/sylphxltd/filesystem-mcp/issues/134"
            ],
            "timeline": [
                {
                    "at": "2026-01-07T17:16:01.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67366"
                }
            ]
        },
        {
            "id": "CVE-2025-67038",
            "vendor": "Lantronix",
            "product": "EDS5000 series",
            "title": "EDS5000 series vulnerability",
            "summary": "An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.",
            "updated_at": "2026-09-08T19:00:57.803",
            "published_at": "2026-03-11T17:16:52.010",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "0 through 2.1.0.0R3 (custom); before 2.6.0.4R6 (custom); before 3.21.0.0R1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 33,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-069-02.json",
                "https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02",
                "https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038"
            ],
            "timeline": [
                {
                    "at": "2026-03-11T17:16:52.010",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67038"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-06-23",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-67030",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code",
            "updated_at": "2026-09-16T13:17:17.453",
            "published_at": "2026-03-25T18:16:25.880",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 37,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gist.github.com/weaver4VD/3216dac645220f8c9b488362f61241ec",
                "https://github.com/codehaus-plexus/plexus-utils/commit/6d780b3378829318ba5c2d29547e0012d5b29642",
                "https://github.com/codehaus-plexus/plexus-utils/issues/294",
                "https://github.com/codehaus-plexus/plexus-utils/pull/295",
                "https://github.com/codehaus-plexus/plexus-utils/pull/296",
                "https://access.redhat.com/errata/RHSA-2026:17668",
                "https://access.redhat.com/errata/RHSA-2026:18054",
                "https://access.redhat.com/errata/RHSA-2026:18055",
                "https://access.redhat.com/errata/RHSA-2026:18059",
                "https://access.redhat.com/errata/RHSA-2026:35990",
                "https://access.redhat.com/errata/RHSA-2026:35991",
                "https://access.redhat.com/errata/RHSA-2026:35992",
                "https://access.redhat.com/errata/RHSA-2026:35996",
                "https://access.redhat.com/errata/RHSA-2026:35997",
                "https://access.redhat.com/errata/RHSA-2026:36012",
                "https://access.redhat.com/errata/RHSA-2026:38500",
                "https://access.redhat.com/errata/RHSA-2026:38514",
                "https://access.redhat.com/errata/RHSA-2026:38796",
                "https://access.redhat.com/errata/RHSA-2026:40841",
                "https://access.redhat.com/errata/RHSA-2026:41948",
                "https://access.redhat.com/errata/RHSA-2026:60239",
                "https://access.redhat.com/errata/RHSA-2026:60246",
                "https://access.redhat.com/errata/RHSA-2026:60247",
                "https://access.redhat.com/errata/RHSA-2026:60248",
                "https://access.redhat.com/errata/RHSA-2026:60249",
                "https://access.redhat.com/errata/RHSA-2026:60250",
                "https://access.redhat.com/errata/RHSA-2026:60251",
                "https://access.redhat.com/errata/RHSA-2026:60252",
                "https://access.redhat.com/errata/RHSA-2026:60254",
                "https://access.redhat.com/errata/RHSA-2026:60256",
                "https://access.redhat.com/errata/RHSA-2026:60259",
                "https://access.redhat.com/errata/RHSA-2026:65126",
                "https://access.redhat.com/errata/RHSA-2026:7109",
                "https://access.redhat.com/errata/RHSA-2026:7380",
                "https://access.redhat.com/security/cve/CVE-2025-67030",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2451409",
                "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-67030.json"
            ],
            "timeline": [
                {
                    "at": "2026-03-25T18:16:25.880",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67030"
                }
            ]
        },
        {
            "id": "CVE-2025-66516",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2025-66516-POC",
            "summary": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
            "updated_at": "2026-09-07T19:12:13Z",
            "published_at": "2026-09-07T19:12:13Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 25,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-66516-POC",
                    "summary": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
                    "what_happened": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SID6224-CVE-2025-66516-POC",
                        "https://kitploit.com/ja/tools/github/sid6224/cve-2025-66516-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-07T21:12:13",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SID6224-CVE-2025-66516-POC"
                },
                {
                    "title": "Exploit for CVE-2025-66516-POC",
                    "summary": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
                    "what_happened": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SID6224-CVE-2025-66516-POC",
                        "https://kitploit.com/ja/tools/github/sid6224/cve-2025-66516-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-07T21:12:13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/sid6224/cve-2025-66516-poc/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SID6224-CVE-2025-66516-POC",
                "https://kitploit.com/ja/tools/github/sid6224/cve-2025-66516-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:12:13Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SID6224-CVE-2025-66516-POC"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-66478",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "🔧 Fix vulnerable versions in Next.js and React RSC apps with one command to secure against CVE-2025-66478. Improve your app's safety effortlessly.",
            "summary": "🔧 Fix vulnerable versions in Next.js and React RSC apps with one command to secure against CVE-2025-66478. Improve your app's safety effortlessly.",
            "updated_at": "2026-08-29T22:00:00Z",
            "published_at": "2026-08-29T22:00:00Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1116,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Unauthenticated RCE in React Server Components via insecure Server Function deserialization.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · Saied25/fix-react2shell-next",
                    "author": "Saied25",
                    "first_seen": "2025-10-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "🔧 Fix vulnerable versions in Next.js and React RSC apps with one command to secure against CVE-2025-66478. Improve your app's safety effortlessly.",
                    "summary": "🔧 Fix vulnerable versions in Next.js and React RSC apps with one command to secure against CVE-2025-66478. Improve your app's safety effortlessly.",
                    "url": "https://github.com/Saied25/fix-react2shell-next"
                },
                {
                    "repository": "PoC-in-GitHub · abtonc/next-cve-2025-66478",
                    "author": "abtonc",
                    "first_seen": "2025-12-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "CVE-2025-66478 repository",
                    "summary": "",
                    "url": "https://github.com/abtonc/next-cve-2025-66478"
                },
                {
                    "repository": "PoC-in-GitHub · wangxso/CVE-2025-66478-POC",
                    "author": "wangxso",
                    "first_seen": "2025-12-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2025-66478 Proof of Concept",
                    "summary": "CVE-2025-66478 Proof of Concept",
                    "url": "https://github.com/wangxso/CVE-2025-66478-POC"
                },
                {
                    "repository": "PoC-in-GitHub · Malayke/Next.js-RSC-RCE-Scanner-CVE-2025-66478",
                    "author": "Malayke",
                    "first_seen": "2025-12-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 433,
                    "title": "A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.",
                    "summary": "A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.",
                    "url": "https://github.com/Malayke/Next.js-RSC-RCE-Scanner-CVE-2025-66478"
                },
                {
                    "repository": "PoC-in-GitHub · mattcbarrett/check-cve-2025-66478",
                    "author": "mattcbarrett",
                    "first_seen": "2025-12-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Checks if your NextJS server is vulnerable to CVE-2025-66478",
                    "summary": "Checks if your NextJS server is vulnerable to CVE-2025-66478",
                    "url": "https://github.com/mattcbarrett/check-cve-2025-66478"
                },
                {
                    "repository": "PoC-in-GitHub · hackersatyamrastogi/react2shell-ultimate",
                    "author": "hackersatyamrastogi",
                    "first_seen": "2025-12-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 155,
                    "title": "React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local scanning.",
                    "summary": "React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local scanning.",
                    "url": "https://github.com/hackersatyamrastogi/react2shell-ultimate"
                },
                {
                    "repository": "PoC-in-GitHub · vercel-labs/fix-react2shell-next",
                    "author": "vercel-labs",
                    "first_seen": "2025-12-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 402,
                    "title": "One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.",
                    "summary": "One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.",
                    "url": "https://github.com/vercel-labs/fix-react2shell-next"
                },
                {
                    "repository": "PoC-in-GitHub · namest504/CVE-2025-66478-Exploit-Poc",
                    "author": "namest504",
                    "first_seen": "2025-12-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2025-66478 repository",
                    "summary": "",
                    "url": "https://github.com/namest504/CVE-2025-66478-Exploit-Poc"
                },
                {
                    "repository": "PoC-in-GitHub · aiexz/CVE-2025-66478-kinda-waf",
                    "author": "aiexz",
                    "first_seen": "2025-12-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Let's help websites stay safe until they are properly patched!",
                    "summary": "Let's help websites stay safe until they are properly patched!",
                    "url": "https://github.com/aiexz/CVE-2025-66478-kinda-waf"
                },
                {
                    "repository": "PoC-in-GitHub · Rhyru9/CVE-2025-66478",
                    "author": "Rhyru9",
                    "first_seen": "2025-12-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-66478 repository",
                    "summary": "",
                    "url": "https://github.com/Rhyru9/CVE-2025-66478"
                },
                {
                    "repository": "PoC-in-GitHub · Jibaru/CVE-2025-66478-github-patcher",
                    "author": "Jibaru",
                    "first_seen": "2025-12-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-66478 repository",
                    "summary": "",
                    "url": "https://github.com/Jibaru/CVE-2025-66478-github-patcher"
                },
                {
                    "repository": "PoC-in-GitHub · ExpTechTW/CVE-2025-66478",
                    "author": "ExpTechTW",
                    "first_seen": "2025-12-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-66478 repository",
                    "summary": "",
                    "url": "https://github.com/ExpTechTW/CVE-2025-66478"
                },
                {
                    "repository": "PoC-in-GitHub · abhirajranjan/cve-2025-66478",
                    "author": "abhirajranjan",
                    "first_seen": "2025-12-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-66478 repository",
                    "summary": "",
                    "url": "https://github.com/abhirajranjan/cve-2025-66478"
                },
                {
                    "repository": "PoC-in-GitHub · Letalandroid/cve-2025-66478_rce_vulnerable",
                    "author": "Letalandroid",
                    "first_seen": "2025-12-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "IMPORTANTE: Proyecto de Next JS VULNERABLE creado solo para fines educativos, de pruebas y explotación, NO SE RECOMIENDA INSTALACIÓN EN PRODUCCION, SÓLO PARA ÁMBITO LOCAL O ENTORNO CONTROLADO",
                    "summary": "IMPORTANTE: Proyecto de Next JS VULNERABLE creado solo para fines educativos, de pruebas y explotación, NO SE RECOMIENDA INSTALACIÓN EN PRODUCCION, SÓLO PARA ÁMBITO LOCAL O ENTORNO CONTROLADO",
                    "url": "https://github.com/Letalandroid/cve-2025-66478_rce_vulnerable"
                },
                {
                    "repository": "PoC-in-GitHub · strainxx/react2shell-honeypot",
                    "author": "strainxx",
                    "first_seen": "2025-12-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)",
                    "summary": "My attempt to make honeypot for React2Shell vulnerability (CVE-2025-66478)",
                    "url": "https://github.com/strainxx/react2shell-honeypot"
                },
                {
                    "repository": "PoC-in-GitHub · changgun-lee/Next.js-RSC-RCE-Scanner-CVE-2025-66478",
                    "author": "changgun-lee",
                    "first_seen": "2025-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-66478 repository",
                    "summary": "",
                    "url": "https://github.com/changgun-lee/Next.js-RSC-RCE-Scanner-CVE-2025-66478"
                },
                {
                    "repository": "PoC-in-GitHub · Code42Cate/nexts-cve-2025-66478-exploit",
                    "author": "Code42Cate",
                    "first_seen": "2025-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-66478 repository",
                    "summary": "",
                    "url": "https://github.com/Code42Cate/nexts-cve-2025-66478-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · viperh/poc-cve-next",
                    "author": "viperh",
                    "first_seen": "2025-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC for Next.js RCE Vulnerability  CVE-2025-66478",
                    "summary": "PoC for Next.js RCE Vulnerability  CVE-2025-66478",
                    "url": "https://github.com/viperh/poc-cve-next"
                },
                {
                    "repository": "PoC-in-GitHub · abdozkaya/rsc-security-auditor",
                    "author": "abdozkaya",
                    "first_seen": "2025-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "🛡️ Audit your Next.js & React Server Components stack for critical vulnerabilities (CVE-2025-66478, CVE-2025-55184). Detects risks & generates fix commands. 100% Client-side.",
                    "summary": "🛡️ Audit your Next.js & React Server Components stack for critical vulnerabilities (CVE-2025-66478, CVE-2025-55184). Detects risks & generates fix commands. 100% Client-side.",
                    "url": "https://github.com/abdozkaya/rsc-security-auditor"
                },
                {
                    "repository": "PoC-in-GitHub · DavionGowie/-vercel-prod.yml-application-is-vulnerable-to-CVE-2025-66478.",
                    "author": "DavionGowie",
                    "first_seen": "2025-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "bug bounty",
                    "summary": "bug bounty",
                    "url": "https://github.com/DavionGowie/-vercel-prod.yml-application-is-vulnerable-to-CVE-2025-66478."
                },
                {
                    "repository": "PoC-in-GitHub · DavionGowie/-vercel-application-is-vulnerable-to-CVE-2025-66478.",
                    "author": "DavionGowie",
                    "first_seen": "2025-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "bug bounty",
                    "summary": "bug bounty",
                    "url": "https://github.com/DavionGowie/-vercel-application-is-vulnerable-to-CVE-2025-66478."
                },
                {
                    "repository": "PoC-in-GitHub · zhixiangyao/CVE-2025-66478-Exploit-PoC",
                    "author": "zhixiangyao",
                    "first_seen": "2025-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Proof-of-concept exploit demo for CVE-2025-66478 using Node.js",
                    "summary": "Proof-of-concept exploit demo for CVE-2025-66478 using Node.js",
                    "url": "https://github.com/zhixiangyao/CVE-2025-66478-Exploit-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · khadafigans/React2Shell",
                    "author": "khadafigans",
                    "first_seen": "2025-12-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "React2Shell - CVE-2025-66478 RCE Exploit",
                    "summary": "React2Shell - CVE-2025-66478 RCE Exploit",
                    "url": "https://github.com/khadafigans/React2Shell"
                },
                {
                    "repository": "PoC-in-GitHub · Z3ROROOT3R/CVE-2025-66478",
                    "author": "Z3ROROOT3R",
                    "first_seen": "2025-12-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-66478 repository",
                    "summary": "",
                    "url": "https://github.com/Z3ROROOT3R/CVE-2025-66478"
                },
                {
                    "repository": "PoC-in-GitHub · imad457/NextJS-RCE-Root-Takeover",
                    "author": "imad457",
                    "first_seen": "2026-01-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Pentest Report: Next.js 16.0.6 RCE (CVE-2025-66478)",
                    "summary": "Pentest Report: Next.js 16.0.6 RCE (CVE-2025-66478)",
                    "url": "https://github.com/imad457/NextJS-RCE-Root-Takeover"
                },
                {
                    "repository": "PoC-in-GitHub · nilfredb/CVE-2025-66478-Research-Proof-of-Concept",
                    "author": "nilfredb",
                    "first_seen": "2026-05-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-66478 repository",
                    "summary": "",
                    "url": "https://github.com/nilfredb/CVE-2025-66478-Research-Proof-of-Concept"
                },
                {
                    "repository": "PoC-in-GitHub · JotaEspig/CVE-2025-66478-PoC-Reverse-Shell",
                    "author": "JotaEspig",
                    "first_seen": "2026-08-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-66478 PoC",
                    "summary": "CVE-2025-66478 PoC",
                    "url": "https://github.com/JotaEspig/CVE-2025-66478-PoC-Reverse-Shell"
                },
                {
                    "title": "MassExploit-CVE-2025-55182",
                    "summary": "Unauthenticated RCE in React Server Components via insecure Server Function deserialization.",
                    "what_happened": "Unauthenticated RCE in React Server Components via insecure Server Function deserialization.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CIRQUEIRADEV-MASSEXPLOIT-CVE-2025-55182",
                        "https://kitploit.com/hi/tools/github/cirqueiradev/massexploit-cve-2025-55182/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T11:18:48",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CIRQUEIRADEV-MASSEXPLOIT-CVE-2025-55182"
                },
                {
                    "title": "MassExploit-CVE-2025-55182",
                    "summary": "Unauthenticated RCE in React Server Components via insecure Server Function deserialization.",
                    "what_happened": "Unauthenticated RCE in React Server Components via insecure Server Function deserialization.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CIRQUEIRADEV-MASSEXPLOIT-CVE-2025-55182",
                        "https://kitploit.com/hi/tools/github/cirqueiradev/massexploit-cve-2025-55182/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T11:18:48",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/cirqueiradev/massexploit-cve-2025-55182/"
                }
            ],
            "references": [
                "https://github.com/Saied25/fix-react2shell-next",
                "https://github.com/abtonc/next-cve-2025-66478",
                "https://github.com/wangxso/CVE-2025-66478-POC",
                "https://github.com/Malayke/Next.js-RSC-RCE-Scanner-CVE-2025-66478",
                "https://github.com/mattcbarrett/check-cve-2025-66478",
                "https://github.com/hackersatyamrastogi/react2shell-ultimate",
                "https://github.com/vercel-labs/fix-react2shell-next",
                "https://github.com/namest504/CVE-2025-66478-Exploit-Poc",
                "https://github.com/aiexz/CVE-2025-66478-kinda-waf",
                "https://github.com/Rhyru9/CVE-2025-66478",
                "https://github.com/Jibaru/CVE-2025-66478-github-patcher",
                "https://github.com/ExpTechTW/CVE-2025-66478",
                "https://github.com/abhirajranjan/cve-2025-66478",
                "https://github.com/Letalandroid/cve-2025-66478_rce_vulnerable",
                "https://github.com/strainxx/react2shell-honeypot",
                "https://github.com/changgun-lee/Next.js-RSC-RCE-Scanner-CVE-2025-66478",
                "https://github.com/Code42Cate/nexts-cve-2025-66478-exploit",
                "https://github.com/viperh/poc-cve-next",
                "https://github.com/abdozkaya/rsc-security-auditor",
                "https://github.com/DavionGowie/-vercel-prod.yml-application-is-vulnerable-to-CVE-2025-66478.",
                "https://github.com/DavionGowie/-vercel-application-is-vulnerable-to-CVE-2025-66478.",
                "https://github.com/zhixiangyao/CVE-2025-66478-Exploit-PoC",
                "https://github.com/khadafigans/React2Shell",
                "https://github.com/Z3ROROOT3R/CVE-2025-66478",
                "https://github.com/imad457/NextJS-RCE-Root-Takeover",
                "https://github.com/nilfredb/CVE-2025-66478-Research-Proof-of-Concept",
                "https://github.com/JotaEspig/CVE-2025-66478-PoC-Reverse-Shell",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CIRQUEIRADEV-MASSEXPLOIT-CVE-2025-55182",
                "https://kitploit.com/hi/tools/github/cirqueiradev/massexploit-cve-2025-55182/"
            ],
            "timeline": [
                {
                    "at": "2026-08-29T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/Saied25/fix-react2shell-next"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-65856",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2025-65856",
            "summary": "Tools repository vulnerability identified as CVE-2025-65856.",
            "updated_at": "2026-08-28T09:34:00Z",
            "published_at": "2026-08-28T09:34:00Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 85,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Tools repository vulnerability identified as CVE-2025-65856.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-65856",
                    "summary": "Tools repository vulnerability identified as CVE-2025-65856.",
                    "what_happened": "Tools repository vulnerability identified as CVE-2025-65856.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LUISMIRANDAACEBEDO-CVE-2025-65856",
                        "https://kitploit.com/hi/tools/github/luismirandaacebedo/cve-2025-65856/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-28T11:34:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LUISMIRANDAACEBEDO-CVE-2025-65856"
                },
                {
                    "title": "Exploit for CVE-2025-65856",
                    "summary": "Tools repository vulnerability identified as CVE-2025-65856.",
                    "what_happened": "Tools repository vulnerability identified as CVE-2025-65856.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LUISMIRANDAACEBEDO-CVE-2025-65856",
                        "https://kitploit.com/hi/tools/github/luismirandaacebedo/cve-2025-65856/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-08-28T11:34:00",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/luismirandaacebedo/cve-2025-65856/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LUISMIRANDAACEBEDO-CVE-2025-65856",
                "https://kitploit.com/hi/tools/github/luismirandaacebedo/cve-2025-65856/"
            ],
            "timeline": [
                {
                    "at": "2026-08-28T09:34:00Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LUISMIRANDAACEBEDO-CVE-2025-65856"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-65835",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter. The onReceive implementation accesses Intent.EXTRA_CHOSEN_COMPONENT without checking for null. If a broadcast is sent with extras present but without EXTRA_CHOSEN_COMPONENT, the code dereferences a null value and throws a NullPointerException. Because the receiver is exported and performs no permission or caller validation, any local application on the device can send crafted ACTION_SEND broadcasts to this component and repeatedly crash the host application, resulting in a local, unauthenticated application-level denial of service for any app that includes the plugin.",
            "updated_at": "2026-09-15T20:17:58.250",
            "published_at": "2025-12-15T19:16:05.373",
            "cvss": 6.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter. The onReceive implementation accesses Intent.EXTRA_CHOSEN_COMPONENT without checking for null. If a broadcast is sent with extras present but without EXTRA_CHOSEN_COMPONENT, the code dereferences a null value and throws a NullPointerException. Because the receiver is exported and performs no permission or caller validation, any local application on the device can send crafted ACTION_SEND broadcasts to this component and repeatedly crash the host application, resulting in a local, unauthenticated application-level denial of service for any app that includes the plugin.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "medium.com",
                    "author": "NVD reference",
                    "first_seen": "2025-12-15",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://medium.com/@lcrawfqrd/local-dos-via-exported-receivers-f6b1da10d3b7"
                }
            ],
            "references": [
                "https://github.com/EddyVerbruggen/SocialSharing-PhoneGap-Plugin",
                "https://medium.com/@lcrawfqrd/local-dos-via-exported-receivers-f6b1da10d3b7",
                "https://www.npmjs.com/package/cordova-plugin-x-socialsharing"
            ],
            "timeline": [
                {
                    "at": "2025-12-15T19:16:05.373",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-65835"
                }
            ]
        },
        {
            "id": "CVE-2025-65271",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2025-65271 exploit",
            "summary": "Exploit for CVE-2025-65271. CVSS 8.8.",
            "updated_at": "2026-09-14T04:52:23Z",
            "published_at": "2026-09-14T04:52:23Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 23,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "CSTI in Azuriom CMS admin dashboard allows low-privilege user privilege escalation. Fixed in 1.2.7",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-65271",
                    "summary": "CSTI in Azuriom CMS admin dashboard allows low-privilege user privilege escalation. Fixed in 1.2.7",
                    "what_happened": "CSTI in Azuriom CMS admin dashboard allows low-privilege user privilege escalation. Fixed in 1.2.7",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-1337SKID-CVE-2025-65271",
                        "https://kitploit.com/ru/tools/github/1337skid/cve-2025-65271/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-07T04:52:11",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-1337SKID-CVE-2025-65271"
                },
                {
                    "title": "Exploit for CVE-2025-65271",
                    "summary": "CSTI in Azuriom CMS admin dashboard allows low-privilege user privilege escalation. Fixed in 1.2.7",
                    "what_happened": "CSTI in Azuriom CMS admin dashboard allows low-privilege user privilege escalation. Fixed in 1.2.7",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-1337SKID-CVE-2025-65271",
                        "https://kitploit.com/ru/tools/github/1337skid/cve-2025-65271/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-07T04:52:11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/1337skid/cve-2025-65271/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-1337SKID-CVE-2025-65271",
                "https://kitploit.com/ru/tools/github/1337skid/cve-2025-65271/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:52:23Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-1337SKID-CVE-2025-65271"
                }
            ]
        },
        {
            "id": "CVE-2025-64059",
            "vendor": "getgrav",
            "product": "Grav",
            "title": "Grav vulnerability",
            "summary": "Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.",
            "updated_at": "2026-09-13T19:16:52.707",
            "published_at": "2026-09-13T19:16:52.707",
            "cvss": 1.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.7.50.2 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-79",
            "what_happened": "Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://drive.google.com/file/d/1gbzdiaZEGTPwUPKLengVRO2Nijc6OVuy/view?usp=sharing"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T19:16:52.707",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64059"
                }
            ]
        },
        {
            "id": "CVE-2025-64031",
            "vendor": "libarchive",
            "product": "libarchive",
            "title": "libarchive vulnerability",
            "summary": "libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar. Exploitation envisions a marginally plausible scenario in which original-filename is obtained from an untrusted party. (original-filename is not derived from the input data.)",
            "updated_at": "2026-09-14T01:16:26.190",
            "published_at": "2026-09-14T01:16:26.190",
            "cvss": 2.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3.8.0 through before 3.8.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-122",
            "what_happened": "libarchive 3.8.x before 3.8.2 has a strcpy heap-based buffer overflow in the gzip writer via the original-filename field to archive_compressor_gzip_open in archive_write_add_filter_gzip.c, aka GHSA-92wx-p669-8gr9. This relates to bsdtar. Exploitation envisions a marginally plausible scenario in which original-filename is obtained from an untrusted party. (original-filename is not derived from the input data.)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gist.github.com/ttuurrnn/1365a4a9b1c3d5826a3a9bbe111f26b8",
                "https://github.com/libarchive/libarchive/blob/master/libarchive/archive_write_add_filter_gzip.c",
                "https://github.com/libarchive/libarchive/pull/2734",
                "https://github.com/libarchive/libarchive/pull/2734/commits",
                "https://github.com/libarchive/libarchive/pull/2734/files"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T01:16:26.190",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-64031"
                }
            ]
        },
        {
            "id": "CVE-2025-63913",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension.",
            "updated_at": "2026-09-09T16:04:24.933",
            "published_at": "2026-07-27T23:16:39.717",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/luojia65/opensbi-pmu2-crash"
            ],
            "timeline": [
                {
                    "at": "2026-07-27T23:16:39.717",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-63913"
                }
            ]
        },
        {
            "id": "CVE-2025-63842",
            "vendor": "Repetico",
            "product": "web backend",
            "title": "web backend vulnerability",
            "summary": "A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice question text field.",
            "updated_at": "2026-09-14T00:16:56.040",
            "published_at": "2026-09-14T00:16:56.040",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2026-06-30 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in the multiple-choice question text field.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/ciernyvlk/CVE/blob/main/CVE-2025-63842.md"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T00:16:56.040",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-63842"
                }
            ]
        },
        {
            "id": "CVE-2025-62718",
            "vendor": "axios",
            "product": "axios",
            "title": "axios vulnerability",
            "summary": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This issue leads to the possibility of proxy bypass and SSRF vulnerabilities allowing attackers to reach sensitive loopback or internal services despite the configured protections. This vulnerability is fixed in 1.15.0 and 0.31.0.",
            "updated_at": "2026-09-10T13:17:26.047",
            "published_at": "2026-04-09T15:16:08.650",
            "cvss": 6.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": ">= 1.0.0, < 1.15.0; < 0.31.0",
            "fixed": "See vendor advisory",
            "source_count": 70,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-441",
            "what_happened": "Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_PROXY matching and go through the configured proxy. This goes against what developers expect and lets attackers force requests through a proxy, even if NO_PROXY is set up to protect loopback or internal services. This issue leads to the possibility of proxy bypass and SSRF vulnerabilities allowing attackers to reach sensitive loopback or internal services despite the configured protections. This vulnerability is fixed in 1.15.0 and 0.31.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-04-09",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/axios/axios/security/advisories/GHSA-3p68-rc4w-qgx5"
                }
            ],
            "references": [
                "https://datatracker.ietf.org/doc/html/rfc1034#section-3.1",
                "https://datatracker.ietf.org/doc/html/rfc3986#section-3.2.2",
                "https://github.com/axios/axios/commit/03cdfc99e8db32a390e12128208b6778492cee9c",
                "https://github.com/axios/axios/commit/fb3befb6daac6cad26b2e54094d0f2d9e47f24df",
                "https://github.com/axios/axios/pull/10661",
                "https://github.com/axios/axios/pull/10688",
                "https://github.com/axios/axios/releases/tag/v0.31.0",
                "https://github.com/axios/axios/releases/tag/v1.15.0",
                "https://github.com/axios/axios/security/advisories/GHSA-3p68-rc4w-qgx5",
                "https://access.redhat.com/errata/RHSA-2026:10175",
                "https://access.redhat.com/errata/RHSA-2026:13571",
                "https://access.redhat.com/errata/RHSA-2026:13826",
                "https://access.redhat.com/errata/RHSA-2026:14937",
                "https://access.redhat.com/errata/RHSA-2026:16874",
                "https://access.redhat.com/errata/RHSA-2026:17657",
                "https://access.redhat.com/errata/RHSA-2026:17699",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:20889",
                "https://access.redhat.com/errata/RHSA-2026:20938",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:22465",
                "https://access.redhat.com/errata/RHSA-2026:22629",
                "https://access.redhat.com/errata/RHSA-2026:22840",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24471",
                "https://access.redhat.com/errata/RHSA-2026:24761",
                "https://access.redhat.com/errata/RHSA-2026:24766",
                "https://access.redhat.com/errata/RHSA-2026:24853",
                "https://access.redhat.com/errata/RHSA-2026:24866",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:26010",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:59155",
                "https://access.redhat.com/errata/RHSA-2026:8483",
                "https://access.redhat.com/errata/RHSA-2026:8484",
                "https://access.redhat.com/errata/RHSA-2026:8490",
                "https://access.redhat.com/errata/RHSA-2026:8491",
                "https://access.redhat.com/errata/RHSA-2026:8493",
                "https://access.redhat.com/errata/RHSA-2026:9742",
                "https://access.redhat.com/security/cve/CVE-2025-62718",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2456913",
                "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-62718.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-09T15:16:08.650",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-62718"
                }
            ]
        },
        {
            "id": "CVE-2025-62593",
            "vendor": "Ray-Project",
            "product": "Ray",
            "title": "Ray-Project Ray Code Injection Vulnerability",
            "summary": "Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.",
            "updated_at": "2026-08-16T22:00:00Z",
            "published_at": "2026-08-16T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-16T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-61732",
            "vendor": "Go toolchain",
            "product": "cmd/cgo",
            "title": "cmd/cgo vulnerability",
            "summary": "A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.",
            "updated_at": "2026-09-10T13:17:16.423",
            "published_at": "2026-02-05T04:15:50.873",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.24.13 (semver); 1.25.0-0 through before 1.25.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 38,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/734220",
                "https://go.dev/issue/76697",
                "https://groups.google.com/g/golang-announce/c/K09ubi9FQFk",
                "https://pkg.go.dev/vuln/GO-2026-4433",
                "https://access.redhat.com/errata/RHSA-2026:10104",
                "https://access.redhat.com/errata/RHSA-2026:12282",
                "https://access.redhat.com/errata/RHSA-2026:14100",
                "https://access.redhat.com/errata/RHSA-2026:14774",
                "https://access.redhat.com/errata/RHSA-2026:15091",
                "https://access.redhat.com/errata/RHSA-2026:17598",
                "https://access.redhat.com/errata/RHSA-2026:21691",
                "https://access.redhat.com/errata/RHSA-2026:2706",
                "https://access.redhat.com/errata/RHSA-2026:2708",
                "https://access.redhat.com/errata/RHSA-2026:2709",
                "https://access.redhat.com/errata/RHSA-2026:2844",
                "https://access.redhat.com/errata/RHSA-2026:3192",
                "https://access.redhat.com/errata/RHSA-2026:3193",
                "https://access.redhat.com/errata/RHSA-2026:3468",
                "https://access.redhat.com/errata/RHSA-2026:3469",
                "https://access.redhat.com/errata/RHSA-2026:3470",
                "https://access.redhat.com/errata/RHSA-2026:3471",
                "https://access.redhat.com/errata/RHSA-2026:3472",
                "https://access.redhat.com/errata/RHSA-2026:3473",
                "https://access.redhat.com/errata/RHSA-2026:3489",
                "https://access.redhat.com/errata/RHSA-2026:3556",
                "https://access.redhat.com/errata/RHSA-2026:3559",
                "https://access.redhat.com/errata/RHSA-2026:3855",
                "https://access.redhat.com/errata/RHSA-2026:4434",
                "https://access.redhat.com/errata/RHSA-2026:5878",
                "https://access.redhat.com/errata/RHSA-2026:5948",
                "https://access.redhat.com/errata/RHSA-2026:5950",
                "https://access.redhat.com/errata/RHSA-2026:5952",
                "https://access.redhat.com/errata/RHSA-2026:7291",
                "https://access.redhat.com/errata/RHSA-2026:7385",
                "https://access.redhat.com/errata/RHSA-2026:8448",
                "https://access.redhat.com/security/cve/CVE-2025-61732",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2437016",
                "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61732.json"
            ],
            "timeline": [
                {
                    "at": "2026-02-05T04:15:50.873",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61732"
                }
            ]
        },
        {
            "id": "CVE-2025-61731",
            "vendor": "Go toolchain",
            "product": "cmd/go",
            "title": "cmd/go vulnerability",
            "summary": "Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The \"#cgo pkg-config:\" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a \"--log-file\" argument to this directive, causing pkg-config to write to an attacker-controlled location.",
            "updated_at": "2026-09-10T13:17:10.037",
            "published_at": "2026-01-28T20:16:10.073",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.24.12 (semver); 1.25.0 through before 1.25.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 38,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-88",
            "what_happened": "Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The \"#cgo pkg-config:\" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker can provide a \"--log-file\" argument to this directive, causing pkg-config to write to an attacker-controlled location.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/736711",
                "https://go.dev/issue/77100",
                "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc",
                "https://pkg.go.dev/vuln/GO-2026-4339",
                "https://access.redhat.com/errata/RHSA-2026:12118",
                "https://access.redhat.com/errata/RHSA-2026:12282",
                "https://access.redhat.com/errata/RHSA-2026:13736",
                "https://access.redhat.com/errata/RHSA-2026:14100",
                "https://access.redhat.com/errata/RHSA-2026:14774",
                "https://access.redhat.com/errata/RHSA-2026:15091",
                "https://access.redhat.com/errata/RHSA-2026:17598",
                "https://access.redhat.com/errata/RHSA-2026:20088",
                "https://access.redhat.com/errata/RHSA-2026:21691",
                "https://access.redhat.com/errata/RHSA-2026:3556",
                "https://access.redhat.com/errata/RHSA-2026:3559",
                "https://access.redhat.com/errata/RHSA-2026:3855",
                "https://access.redhat.com/errata/RHSA-2026:4434",
                "https://access.redhat.com/errata/RHSA-2026:5941",
                "https://access.redhat.com/errata/RHSA-2026:5942",
                "https://access.redhat.com/errata/RHSA-2026:5943",
                "https://access.redhat.com/errata/RHSA-2026:5944",
                "https://access.redhat.com/errata/RHSA-2026:5948",
                "https://access.redhat.com/errata/RHSA-2026:5950",
                "https://access.redhat.com/errata/RHSA-2026:5952",
                "https://access.redhat.com/errata/RHSA-2026:6949",
                "https://access.redhat.com/errata/RHSA-2026:7291",
                "https://access.redhat.com/errata/RHSA-2026:7385",
                "https://access.redhat.com/errata/RHSA-2026:7833",
                "https://access.redhat.com/errata/RHSA-2026:7834",
                "https://access.redhat.com/errata/RHSA-2026:7876",
                "https://access.redhat.com/errata/RHSA-2026:7877",
                "https://access.redhat.com/errata/RHSA-2026:7878",
                "https://access.redhat.com/errata/RHSA-2026:7879",
                "https://access.redhat.com/errata/RHSA-2026:7883",
                "https://access.redhat.com/errata/RHSA-2026:8448",
                "https://access.redhat.com/security/cve/CVE-2025-61731",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2434433",
                "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61731.json"
            ],
            "timeline": [
                {
                    "at": "2026-01-28T20:16:10.073",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61731"
                }
            ]
        },
        {
            "id": "CVE-2025-61726",
            "vendor": "Go standard library",
            "product": "net/url",
            "title": "net/url vulnerability",
            "summary": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.",
            "updated_at": "2026-09-15T12:16:42.297",
            "published_at": "2026-01-28T20:16:09.713",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.24.12 (semver); 1.25.0 through before 1.25.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 288,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://go.dev/cl/736712",
                "https://go.dev/issue/77101",
                "https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc",
                "https://pkg.go.dev/vuln/GO-2026-4341",
                "https://access.redhat.com/errata/RHSA-2026:10096",
                "https://access.redhat.com/errata/RHSA-2026:10104",
                "https://access.redhat.com/errata/RHSA-2026:10184",
                "https://access.redhat.com/errata/RHSA-2026:10225",
                "https://access.redhat.com/errata/RHSA-2026:10250",
                "https://access.redhat.com/errata/RHSA-2026:11408",
                "https://access.redhat.com/errata/RHSA-2026:11414",
                "https://access.redhat.com/errata/RHSA-2026:11747",
                "https://access.redhat.com/errata/RHSA-2026:11749",
                "https://access.redhat.com/errata/RHSA-2026:12028",
                "https://access.redhat.com/errata/RHSA-2026:12029",
                "https://access.redhat.com/errata/RHSA-2026:12030",
                "https://access.redhat.com/errata/RHSA-2026:12031",
                "https://access.redhat.com/errata/RHSA-2026:12032",
                "https://access.redhat.com/errata/RHSA-2026:12033",
                "https://access.redhat.com/errata/RHSA-2026:12279",
                "https://access.redhat.com/errata/RHSA-2026:12282",
                "https://access.redhat.com/errata/RHSA-2026:13542",
                "https://access.redhat.com/errata/RHSA-2026:13548",
                "https://access.redhat.com/errata/RHSA-2026:13571",
                "https://access.redhat.com/errata/RHSA-2026:14100",
                "https://access.redhat.com/errata/RHSA-2026:14774",
                "https://access.redhat.com/errata/RHSA-2026:14868",
                "https://access.redhat.com/errata/RHSA-2026:14879",
                "https://access.redhat.com/errata/RHSA-2026:15091",
                "https://access.redhat.com/errata/RHSA-2026:15984",
                "https://access.redhat.com/errata/RHSA-2026:16102",
                "https://access.redhat.com/errata/RHSA-2026:16696",
                "https://access.redhat.com/errata/RHSA-2026:17040",
                "https://access.redhat.com/errata/RHSA-2026:17084",
                "https://access.redhat.com/errata/RHSA-2026:17446",
                "https://access.redhat.com/errata/RHSA-2026:17460",
                "https://access.redhat.com/errata/RHSA-2026:17463",
                "https://access.redhat.com/errata/RHSA-2026:17468",
                "https://access.redhat.com/errata/RHSA-2026:17595",
                "https://access.redhat.com/errata/RHSA-2026:17598",
                "https://access.redhat.com/errata/RHSA-2026:18913",
                "https://access.redhat.com/errata/RHSA-2026:19013",
                "https://access.redhat.com/errata/RHSA-2026:19132",
                "https://access.redhat.com/errata/RHSA-2026:19375",
                "https://access.redhat.com/errata/RHSA-2026:19634",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:20041",
                "https://access.redhat.com/errata/RHSA-2026:21017",
                "https://access.redhat.com/errata/RHSA-2026:21657",
                "https://access.redhat.com/errata/RHSA-2026:21691",
                "https://access.redhat.com/errata/RHSA-2026:22450",
                "https://access.redhat.com/errata/RHSA-2026:22627",
                "https://access.redhat.com/errata/RHSA-2026:22714",
                "https://access.redhat.com/errata/RHSA-2026:22937",
                "https://access.redhat.com/errata/RHSA-2026:23228",
                "https://access.redhat.com/errata/RHSA-2026:23361",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:25089",
                "https://access.redhat.com/errata/RHSA-2026:25127",
                "https://access.redhat.com/errata/RHSA-2026:25248",
                "https://access.redhat.com/errata/RHSA-2026:25250",
                "https://access.redhat.com/errata/RHSA-2026:25251",
                "https://access.redhat.com/errata/RHSA-2026:25252",
                "https://access.redhat.com/errata/RHSA-2026:25253",
                "https://access.redhat.com/errata/RHSA-2026:26420",
                "https://access.redhat.com/errata/RHSA-2026:26527",
                "https://access.redhat.com/errata/RHSA-2026:26541",
                "https://access.redhat.com/errata/RHSA-2026:26636",
                "https://access.redhat.com/errata/RHSA-2026:2681",
                "https://access.redhat.com/errata/RHSA-2026:2706",
                "https://access.redhat.com/errata/RHSA-2026:2708",
                "https://access.redhat.com/errata/RHSA-2026:2709",
                "https://access.redhat.com/errata/RHSA-2026:2754",
                "https://access.redhat.com/errata/RHSA-2026:28047",
                "https://access.redhat.com/errata/RHSA-2026:2844",
                "https://access.redhat.com/errata/RHSA-2026:28441",
                "https://access.redhat.com/errata/RHSA-2026:28886",
                "https://access.redhat.com/errata/RHSA-2026:28961",
                "https://access.redhat.com/errata/RHSA-2026:2914",
                "https://access.redhat.com/errata/RHSA-2026:2920",
                "https://access.redhat.com/errata/RHSA-2026:3035",
                "https://access.redhat.com/errata/RHSA-2026:3040",
                "https://access.redhat.com/errata/RHSA-2026:3089",
                "https://access.redhat.com/errata/RHSA-2026:3092",
                "https://access.redhat.com/errata/RHSA-2026:3184",
                "https://access.redhat.com/errata/RHSA-2026:3186",
                "https://access.redhat.com/errata/RHSA-2026:3187",
                "https://access.redhat.com/errata/RHSA-2026:3188",
                "https://access.redhat.com/errata/RHSA-2026:3192",
                "https://access.redhat.com/errata/RHSA-2026:3193",
                "https://access.redhat.com/errata/RHSA-2026:3291",
                "https://access.redhat.com/errata/RHSA-2026:3296",
                "https://access.redhat.com/errata/RHSA-2026:3297",
                "https://access.redhat.com/errata/RHSA-2026:3298",
                "https://access.redhat.com/errata/RHSA-2026:3336",
                "https://access.redhat.com/errata/RHSA-2026:3337",
                "https://access.redhat.com/errata/RHSA-2026:3340",
                "https://access.redhat.com/errata/RHSA-2026:3341",
                "https://access.redhat.com/errata/RHSA-2026:3343",
                "https://access.redhat.com/errata/RHSA-2026:3391",
                "https://access.redhat.com/errata/RHSA-2026:3416",
                "https://access.redhat.com/errata/RHSA-2026:3427",
                "https://access.redhat.com/errata/RHSA-2026:3459",
                "https://access.redhat.com/errata/RHSA-2026:3468",
                "https://access.redhat.com/errata/RHSA-2026:3469",
                "https://access.redhat.com/errata/RHSA-2026:3470",
                "https://access.redhat.com/errata/RHSA-2026:3471",
                "https://access.redhat.com/errata/RHSA-2026:3472",
                "https://access.redhat.com/errata/RHSA-2026:3473",
                "https://access.redhat.com/errata/RHSA-2026:3489",
                "https://access.redhat.com/errata/RHSA-2026:3506",
                "https://access.redhat.com/errata/RHSA-2026:3556",
                "https://access.redhat.com/errata/RHSA-2026:3559",
                "https://access.redhat.com/errata/RHSA-2026:3668",
                "https://access.redhat.com/errata/RHSA-2026:3669",
                "https://access.redhat.com/errata/RHSA-2026:36873",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:3699",
                "https://access.redhat.com/errata/RHSA-2026:3713",
                "https://access.redhat.com/errata/RHSA-2026:37275",
                "https://access.redhat.com/errata/RHSA-2026:3752",
                "https://access.redhat.com/errata/RHSA-2026:3753",
                "https://access.redhat.com/errata/RHSA-2026:3782",
                "https://access.redhat.com/errata/RHSA-2026:3812",
                "https://access.redhat.com/errata/RHSA-2026:3813",
                "https://access.redhat.com/errata/RHSA-2026:3814",
                "https://access.redhat.com/errata/RHSA-2026:3815",
                "https://access.redhat.com/errata/RHSA-2026:3816",
                "https://access.redhat.com/errata/RHSA-2026:3817",
                "https://access.redhat.com/errata/RHSA-2026:3818",
                "https://access.redhat.com/errata/RHSA-2026:3820",
                "https://access.redhat.com/errata/RHSA-2026:3821",
                "https://access.redhat.com/errata/RHSA-2026:3822",
                "https://access.redhat.com/errata/RHSA-2026:3831",
                "https://access.redhat.com/errata/RHSA-2026:3833",
                "https://access.redhat.com/errata/RHSA-2026:3835",
                "https://access.redhat.com/errata/RHSA-2026:3836",
                "https://access.redhat.com/errata/RHSA-2026:3838",
                "https://access.redhat.com/errata/RHSA-2026:3839",
                "https://access.redhat.com/errata/RHSA-2026:3840",
                "https://access.redhat.com/errata/RHSA-2026:3841",
                "https://access.redhat.com/errata/RHSA-2026:3843",
                "https://access.redhat.com/errata/RHSA-2026:3854",
                "https://access.redhat.com/errata/RHSA-2026:3855",
                "https://access.redhat.com/errata/RHSA-2026:3856",
                "https://access.redhat.com/errata/RHSA-2026:3864",
                "https://access.redhat.com/errata/RHSA-2026:3869",
                "https://access.redhat.com/errata/RHSA-2026:3874",
                "https://access.redhat.com/errata/RHSA-2026:3875",
                "https://access.redhat.com/errata/RHSA-2026:3879",
                "https://access.redhat.com/errata/RHSA-2026:3880",
                "https://access.redhat.com/errata/RHSA-2026:3884",
                "https://access.redhat.com/errata/RHSA-2026:3898",
                "https://access.redhat.com/errata/RHSA-2026:3905",
                "https://access.redhat.com/errata/RHSA-2026:3906",
                "https://access.redhat.com/errata/RHSA-2026:3928",
                "https://access.redhat.com/errata/RHSA-2026:3929",
                "https://access.redhat.com/errata/RHSA-2026:3930",
                "https://access.redhat.com/errata/RHSA-2026:3931",
                "https://access.redhat.com/errata/RHSA-2026:3932",
                "https://access.redhat.com/errata/RHSA-2026:3958",
                "https://access.redhat.com/errata/RHSA-2026:3959",
                "https://access.redhat.com/errata/RHSA-2026:3960",
                "https://access.redhat.com/errata/RHSA-2026:3970",
                "https://access.redhat.com/errata/RHSA-2026:3971",
                "https://access.redhat.com/errata/RHSA-2026:3972",
                "https://access.redhat.com/errata/RHSA-2026:3973",
                "https://access.redhat.com/errata/RHSA-2026:3974",
                "https://access.redhat.com/errata/RHSA-2026:3977",
                "https://access.redhat.com/errata/RHSA-2026:39810",
                "https://access.redhat.com/errata/RHSA-2026:3985",
                "https://access.redhat.com/errata/RHSA-2026:40924",
                "https://access.redhat.com/errata/RHSA-2026:4164",
                "https://access.redhat.com/errata/RHSA-2026:4166",
                "https://access.redhat.com/errata/RHSA-2026:4170",
                "https://access.redhat.com/errata/RHSA-2026:4174",
                "https://access.redhat.com/errata/RHSA-2026:4177",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41941",
                "https://access.redhat.com/errata/RHSA-2026:4211",
                "https://access.redhat.com/errata/RHSA-2026:4220",
                "https://access.redhat.com/errata/RHSA-2026:4256",
                "https://access.redhat.com/errata/RHSA-2026:4264",
                "https://access.redhat.com/errata/RHSA-2026:4267",
                "https://access.redhat.com/errata/RHSA-2026:4270",
                "https://access.redhat.com/errata/RHSA-2026:4276",
                "https://access.redhat.com/errata/RHSA-2026:4434",
                "https://access.redhat.com/errata/RHSA-2026:4435",
                "https://access.redhat.com/errata/RHSA-2026:4460",
                "https://access.redhat.com/errata/RHSA-2026:4466",
                "https://access.redhat.com/errata/RHSA-2026:4467",
                "https://access.redhat.com/errata/RHSA-2026:4498",
                "https://access.redhat.com/errata/RHSA-2026:4500",
                "https://access.redhat.com/errata/RHSA-2026:4510",
                "https://access.redhat.com/errata/RHSA-2026:4511",
                "https://access.redhat.com/errata/RHSA-2026:4672",
                "https://access.redhat.com/errata/RHSA-2026:46903",
                "https://access.redhat.com/errata/RHSA-2026:4753",
                "https://access.redhat.com/errata/RHSA-2026:4892",
                "https://access.redhat.com/errata/RHSA-2026:4901",
                "https://access.redhat.com/errata/RHSA-2026:4907",
                "https://access.redhat.com/errata/RHSA-2026:4939",
                "https://access.redhat.com/errata/RHSA-2026:4942",
                "https://access.redhat.com/errata/RHSA-2026:4943",
                "https://access.redhat.com/errata/RHSA-2026:4952",
                "https://access.redhat.com/errata/RHSA-2026:49944",
                "https://access.redhat.com/errata/RHSA-2026:5022",
                "https://access.redhat.com/errata/RHSA-2026:5030",
                "https://access.redhat.com/errata/RHSA-2026:5031",
                "https://access.redhat.com/errata/RHSA-2026:5076",
                "https://access.redhat.com/errata/RHSA-2026:5077",
                "https://access.redhat.com/errata/RHSA-2026:5078",
                "https://access.redhat.com/errata/RHSA-2026:5079",
                "https://access.redhat.com/errata/RHSA-2026:51033",
                "https://access.redhat.com/errata/RHSA-2026:5110",
                "https://access.redhat.com/errata/RHSA-2026:51288",
                "https://access.redhat.com/errata/RHSA-2026:5129",
                "https://access.redhat.com/errata/RHSA-2026:5130",
                "https://access.redhat.com/errata/RHSA-2026:5131",
                "https://access.redhat.com/errata/RHSA-2026:5132",
                "https://access.redhat.com/errata/RHSA-2026:5145",
                "https://access.redhat.com/errata/RHSA-2026:5146",
                "https://access.redhat.com/errata/RHSA-2026:5168",
                "https://access.redhat.com/errata/RHSA-2026:5327",
                "https://access.redhat.com/errata/RHSA-2026:5394",
                "https://access.redhat.com/errata/RHSA-2026:5439",
                "https://access.redhat.com/errata/RHSA-2026:5444",
                "https://access.redhat.com/errata/RHSA-2026:5447",
                "https://access.redhat.com/errata/RHSA-2026:5452",
                "https://access.redhat.com/errata/RHSA-2026:5461",
                "https://access.redhat.com/errata/RHSA-2026:5463",
                "https://access.redhat.com/errata/RHSA-2026:54757",
                "https://access.redhat.com/errata/RHSA-2026:5533",
                "https://access.redhat.com/errata/RHSA-2026:5544",
                "https://access.redhat.com/errata/RHSA-2026:5549",
                "https://access.redhat.com/errata/RHSA-2026:5636",
                "https://access.redhat.com/errata/RHSA-2026:56366",
                "https://access.redhat.com/errata/RHSA-2026:56431",
                "https://access.redhat.com/errata/RHSA-2026:5645",
                "https://access.redhat.com/errata/RHSA-2026:5649",
                "https://access.redhat.com/errata/RHSA-2026:5665",
                "https://access.redhat.com/errata/RHSA-2026:57013",
                "https://access.redhat.com/errata/RHSA-2026:5807",
                "https://access.redhat.com/errata/RHSA-2026:5851",
                "https://access.redhat.com/errata/RHSA-2026:5852",
                "https://access.redhat.com/errata/RHSA-2026:5853",
                "https://access.redhat.com/errata/RHSA-2026:5948",
                "https://access.redhat.com/errata/RHSA-2026:5950",
                "https://access.redhat.com/errata/RHSA-2026:5952",
                "https://access.redhat.com/errata/RHSA-2026:5968",
                "https://access.redhat.com/errata/RHSA-2026:6184",
                "https://access.redhat.com/errata/RHSA-2026:6192",
                "https://access.redhat.com/errata/RHSA-2026:6226",
                "https://access.redhat.com/errata/RHSA-2026:6251",
                "https://access.redhat.com/errata/RHSA-2026:6277",
                "https://access.redhat.com/errata/RHSA-2026:6278",
                "https://access.redhat.com/errata/RHSA-2026:6428",
                "https://access.redhat.com/errata/RHSA-2026:6429",
                "https://access.redhat.com/errata/RHSA-2026:6497",
                "https://access.redhat.com/errata/RHSA-2026:6554",
                "https://access.redhat.com/errata/RHSA-2026:6564",
                "https://access.redhat.com/errata/RHSA-2026:6567",
                "https://access.redhat.com/errata/RHSA-2026:6568",
                "https://access.redhat.com/errata/RHSA-2026:7052",
                "https://access.redhat.com/errata/RHSA-2026:7249",
                "https://access.redhat.com/errata/RHSA-2026:7291",
                "https://access.redhat.com/errata/RHSA-2026:7385",
                "https://access.redhat.com/errata/RHSA-2026:7676",
                "https://access.redhat.com/errata/RHSA-2026:7854",
                "https://access.redhat.com/errata/RHSA-2026:7942",
                "https://access.redhat.com/errata/RHSA-2026:8151",
                "https://access.redhat.com/errata/RHSA-2026:8167",
                "https://access.redhat.com/errata/RHSA-2026:8218",
                "https://access.redhat.com/errata/RHSA-2026:8229",
                "https://access.redhat.com/errata/RHSA-2026:8337",
                "https://access.redhat.com/errata/RHSA-2026:8338",
                "https://access.redhat.com/errata/RHSA-2026:8431",
                "https://access.redhat.com/errata/RHSA-2026:8433",
                "https://access.redhat.com/errata/RHSA-2026:8483",
                "https://access.redhat.com/errata/RHSA-2026:9097",
                "https://access.redhat.com/errata/RHSA-2026:9098",
                "https://access.redhat.com/errata/RHSA-2026:9108",
                "https://access.redhat.com/errata/RHSA-2026:9109",
                "https://access.redhat.com/errata/RHSA-2026:9848",
                "https://access.redhat.com/security/cve/CVE-2025-61726",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2434432",
                "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61726.json",
                "https://access.redhat.com/errata/RHSA-2026:66401"
            ],
            "timeline": [
                {
                    "at": "2026-01-28T20:16:09.713",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61726"
                }
            ]
        },
        {
            "id": "CVE-2025-61140",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.",
            "updated_at": "2026-09-07T13:17:29.797",
            "published_at": "2026-01-28T16:16:13.547",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1321",
            "what_happened": "The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://gist.github.com/Dremig/8105c189774217222a8ebea3ed4d341d",
                "https://github.com/dchester/jsonpath",
                "https://access.redhat.com/errata/RHSA-2026:2180",
                "https://access.redhat.com/errata/RHSA-2026:2181",
                "https://access.redhat.com/errata/RHSA-2026:3960",
                "https://access.redhat.com/errata/RHSA-2026:3962",
                "https://access.redhat.com/errata/RHSA-2026:6174",
                "https://access.redhat.com/errata/RHSA-2026:6802",
                "https://access.redhat.com/security/cve/CVE-2025-61140",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2433946",
                "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-61140.json"
            ],
            "timeline": [
                {
                    "at": "2026-01-28T16:16:13.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61140"
                }
            ]
        },
        {
            "id": "CVE-2025-60689",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Linksys E1200_2.0.04 - Unauthenticated OS Command Injection",
            "summary": "Linksys E1200_2.0.04 - Unauthenticated OS Command Injection",
            "updated_at": "2026-08-30T22:00:00Z",
            "published_at": "2026-08-30T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 96,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52660",
                    "author": "jarrett",
                    "first_seen": "2026-08-31",
                    "confidence": "High",
                    "title": "Linksys E1200_2.0.04 - Unauthenticated OS Command Injection",
                    "summary": "Linksys E1200_2.0.04 - Unauthenticated OS Command Injection",
                    "url": "https://www.exploit-db.com/exploits/52660",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52660"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52660"
                }
            ]
        },
        {
            "id": "CVE-2025-59713",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2025-59712_CVE-2025-59713 exploit",
            "summary": "Exploit for CVE-2025-59712 and CVE-2025-59713. CVSS 8.1.",
            "updated_at": "2026-09-05T08:13:00Z",
            "published_at": "2026-09-05T08:13:00Z",
            "cvss": 8.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 155,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "XSS and unsafe deserialization in Snipe-IT enable JavaScript injection and remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-59712_CVE-2025-59713 CVE-2025-59712 CVE-2025-59713",
                    "summary": "XSS and unsafe deserialization in Snipe-IT enable JavaScript injection and remote code execution.",
                    "what_happened": "XSS and unsafe deserialization in Snipe-IT enable JavaScript injection and remote code execution.",
                    "cvss": 8.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SYNACKTIV-CVE-2025-59712_CVE-2025-59713",
                        "https://kitploit.com/ru/tools/github/synacktiv/cve-2025-59712_cve-2025-59713/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T19:50:40",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SYNACKTIV-CVE-2025-59712_CVE-2025-59713"
                },
                {
                    "repository": "synacktiv/CVE-2025-59712_CVE-2025-59713",
                    "author": "synacktiv",
                    "first_seen": "2025-10-02",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 2,
                    "title": "Snipe-IT PoC exploit for CVE-2025-59712 and CVE-2025-59713",
                    "summary": "Snipe-IT PoC exploit for CVE-2025-59712 and CVE-2025-59713",
                    "url": "https://github.com/synacktiv/CVE-2025-59712_CVE-2025-59713"
                },
                {
                    "title": "Exploit for CVE-2025-59712_CVE-2025-59713 CVE-2025-59712 CVE-2025-59713",
                    "summary": "XSS and unsafe deserialization in Snipe-IT enable JavaScript injection and remote code execution.",
                    "what_happened": "XSS and unsafe deserialization in Snipe-IT enable JavaScript injection and remote code execution.",
                    "cvss": 8.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SYNACKTIV-CVE-2025-59712_CVE-2025-59713",
                        "https://kitploit.com/ru/tools/github/synacktiv/cve-2025-59712_cve-2025-59713/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-03T19:50:40",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/synacktiv/cve-2025-59712_cve-2025-59713/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SYNACKTIV-CVE-2025-59712_CVE-2025-59713",
                "https://github.com/synacktiv/CVE-2025-59712_CVE-2025-59713",
                "https://kitploit.com/ru/tools/github/synacktiv/cve-2025-59712_cve-2025-59713/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:13:00Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SYNACKTIV-CVE-2025-59712_CVE-2025-59713"
                }
            ]
        },
        {
            "id": "CVE-2025-59712",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2025-59712_CVE-2025-59713 exploit",
            "summary": "Exploit for CVE-2025-59712 and CVE-2025-59713. CVSS 8.1.",
            "updated_at": "2026-09-05T08:13:00Z",
            "published_at": "2026-09-05T08:13:00Z",
            "cvss": 8.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 155,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "XSS and unsafe deserialization in Snipe-IT enable JavaScript injection and remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-59712_CVE-2025-59713 CVE-2025-59712 CVE-2025-59713",
                    "summary": "XSS and unsafe deserialization in Snipe-IT enable JavaScript injection and remote code execution.",
                    "what_happened": "XSS and unsafe deserialization in Snipe-IT enable JavaScript injection and remote code execution.",
                    "cvss": 8.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SYNACKTIV-CVE-2025-59712_CVE-2025-59713",
                        "https://kitploit.com/ru/tools/github/synacktiv/cve-2025-59712_cve-2025-59713/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T19:50:40",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SYNACKTIV-CVE-2025-59712_CVE-2025-59713"
                },
                {
                    "repository": "synacktiv/CVE-2025-59712_CVE-2025-59713",
                    "author": "synacktiv",
                    "first_seen": "2025-10-02",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 2,
                    "title": "Snipe-IT PoC exploit for CVE-2025-59712 and CVE-2025-59713",
                    "summary": "Snipe-IT PoC exploit for CVE-2025-59712 and CVE-2025-59713",
                    "url": "https://github.com/synacktiv/CVE-2025-59712_CVE-2025-59713"
                },
                {
                    "title": "Exploit for CVE-2025-59712_CVE-2025-59713 CVE-2025-59712 CVE-2025-59713",
                    "summary": "XSS and unsafe deserialization in Snipe-IT enable JavaScript injection and remote code execution.",
                    "what_happened": "XSS and unsafe deserialization in Snipe-IT enable JavaScript injection and remote code execution.",
                    "cvss": 8.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SYNACKTIV-CVE-2025-59712_CVE-2025-59713",
                        "https://kitploit.com/ru/tools/github/synacktiv/cve-2025-59712_cve-2025-59713/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-03T19:50:40",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/synacktiv/cve-2025-59712_cve-2025-59713/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SYNACKTIV-CVE-2025-59712_CVE-2025-59713",
                "https://github.com/synacktiv/CVE-2025-59712_CVE-2025-59713",
                "https://kitploit.com/ru/tools/github/synacktiv/cve-2025-59712_cve-2025-59713/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:13:00Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SYNACKTIV-CVE-2025-59712_CVE-2025-59713"
                }
            ]
        },
        {
            "id": "CVE-2025-59214",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2025-50154 CVE-2025-50154 CVE-2025-59214",
            "summary": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
            "updated_at": "2026-09-02T21:38:26Z",
            "published_at": "2026-09-02T21:38:26Z",
            "cvss": 6.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 81,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-50154 CVE-2025-50154 CVE-2025-59214",
                    "summary": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
                    "what_happened": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUBENFORMATION-CVE-2025-50154",
                        "https://kitploit.com/ru/tools/github/rubenformation/cve-2025-50154/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-02T23:38:26",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUBENFORMATION-CVE-2025-50154"
                },
                {
                    "title": "Exploit for CVE-2025-50154 CVE-2025-50154 CVE-2025-59214",
                    "summary": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
                    "what_happened": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUBENFORMATION-CVE-2025-50154",
                        "https://kitploit.com/ru/tools/github/rubenformation/cve-2025-50154/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-02T23:38:26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/rubenformation/cve-2025-50154/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUBENFORMATION-CVE-2025-50154",
                "https://kitploit.com/ru/tools/github/rubenformation/cve-2025-50154/"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T21:38:26Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUBENFORMATION-CVE-2025-50154"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2025-58375",
            "vendor": "frappe",
            "product": "frappe",
            "title": "frappe vulnerability",
            "summary": "Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0.",
            "updated_at": "2026-09-08T20:51:43.490",
            "published_at": "2025-09-06T00:15:35.047",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "< 14.96.10; >= 15.0.0, < 15.72.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive information such as versioning can be retrieved. This issue is fixed in versions 14.96.10 and 15.72.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/frappe/frappe/commit/2dab009c8b15e29aa14bcd421eee8c6b2dc0fce6",
                "https://github.com/frappe/frappe/commit/ec70383ef0196d7b64fcf51b230483dac095a68b",
                "https://github.com/frappe/frappe/security/advisories/GHSA-mggw-6xqj-rphj"
            ],
            "timeline": [
                {
                    "at": "2025-09-06T00:15:35.047",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-58375"
                }
            ]
        },
        {
            "id": "CVE-2025-57847",
            "vendor": "Red Hat",
            "product": "Red Hat Ansible Automation Platform 2.16",
            "title": "Red Hat Ansible Automation Platform 2.16 vulnerability",
            "summary": "A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID 0, gaining full root privileges within the container.",
            "updated_at": "2026-09-10T22:16:54.607",
            "published_at": "2026-04-08T14:16:25.577",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "up to 2.6",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-276",
            "what_happened": "A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID 0, gaining full root privileges within the container.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:42141",
                "https://access.redhat.com/errata/RHSA-2026:42144",
                "https://access.redhat.com/errata/RHSA-2026:66482",
                "https://access.redhat.com/errata/RHSA-2026:66487",
                "https://access.redhat.com/security/cve/CVE-2025-57847",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2391092",
                "https://access.redhat.com/errata/RHSA-2026:66485",
                "https://access.redhat.com/errata/RHSA-2026:66486"
            ],
            "timeline": [
                {
                    "at": "2026-04-08T14:16:25.577",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-57847"
                }
            ]
        },
        {
            "id": "CVE-2025-57819",
            "vendor": "Sangoma",
            "product": "FreePBX",
            "title": "Sangoma FreePBX Authentication Bypass Vulnerability",
            "summary": "Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution.",
            "updated_at": "2026-09-02T22:00:00Z",
            "published_at": "2026-09-02T22:00:00Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 609,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52681",
                    "author": "Jared Brits",
                    "first_seen": "2026-09-03",
                    "confidence": "High",
                    "title": "FreePBX  17.0.2 - Remote Code Execution (RCE)",
                    "summary": "FreePBX  17.0.2 - Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/52681",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "CXSecurity WLB-2026090002",
                    "author": "K3ysTr0K3R",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "FreePBX 17.0.2 Remote Code Execution (RCE)",
                    "summary": "FreePBX 17.0.2 Remote Code Execution (RCE)",
                    "what_happened": "FreePBX 17.0.2 Remote Code Execution (RCE)",
                    "cvss": 0,
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "url": "https://cxsecurity.com/issue/WLB-2026090002",
                    "cwe": "Unknown"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-06T20:32:40+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Exploit for SQL Injection in Sangoma Freepbx",
                    "summary": "Proof-of-concept exploit for CVE-2025-57819. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=2E1494D5-4077-5CA3-AD82-8F9BDCB27DA4"
                },
                {
                    "repository": "PoC-in-GitHub · rxerium/CVE-2025-57819",
                    "author": "rxerium",
                    "first_seen": "2025-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Detection for CVE-2025-57819",
                    "summary": "Detection for CVE-2025-57819",
                    "url": "https://github.com/rxerium/CVE-2025-57819"
                },
                {
                    "repository": "PoC-in-GitHub · Sucuri-Labs/CVE-2025-57819-ioc-check",
                    "author": "Sucuri-Labs",
                    "first_seen": "2025-08-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819",
                    "summary": "This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819",
                    "url": "https://github.com/Sucuri-Labs/CVE-2025-57819-ioc-check"
                },
                {
                    "repository": "PoC-in-GitHub · cybertechajju/cve-2025-57819",
                    "author": "cybertechajju",
                    "first_seen": "2025-08-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Detects vulnerable FreePBX versions affected by CVE-2025-57819.",
                    "summary": "Detects vulnerable FreePBX versions affected by CVE-2025-57819.",
                    "url": "https://github.com/cybertechajju/cve-2025-57819"
                },
                {
                    "repository": "PoC-in-GitHub · blueisbeautiful/CVE-2025-57819",
                    "author": "blueisbeautiful",
                    "first_seen": "2025-09-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "FreePBX SQL Injection Exploit",
                    "summary": "FreePBX SQL Injection Exploit",
                    "url": "https://github.com/blueisbeautiful/CVE-2025-57819"
                },
                {
                    "repository": "PoC-in-GitHub · ImBIOS/lab-cve-2025-57819",
                    "author": "ImBIOS",
                    "first_seen": "2025-09-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "FreePBX CVE-2025-57819 lab (Docker) + Nuclei POC for unauth SQLi (time-based).",
                    "summary": "FreePBX CVE-2025-57819 lab (Docker) + Nuclei POC for unauth SQLi (time-based).",
                    "url": "https://github.com/ImBIOS/lab-cve-2025-57819"
                },
                {
                    "repository": "PoC-in-GitHub · watchtowrlabs/watchTowr-vs-FreePBX-CVE-2025-57819",
                    "author": "watchtowrlabs",
                    "first_seen": "2025-09-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 29,
                    "title": "CVE-2025-57819 repository",
                    "summary": "",
                    "url": "https://github.com/watchtowrlabs/watchTowr-vs-FreePBX-CVE-2025-57819"
                },
                {
                    "repository": "PoC-in-GitHub · MuhammadWaseem29/SQL-Injection-and-RCE_CVE-2025-57819",
                    "author": "MuhammadWaseem29",
                    "first_seen": "2025-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "FreePBX versions 15, 16, and 17 contain a Remote Code Execution (RCE) vulnerability caused by insufficient sanitization of user-supplied data in endpoints.",
                    "summary": "FreePBX versions 15, 16, and 17 contain a Remote Code Execution (RCE) vulnerability caused by insufficient sanitization of user-supplied data in endpoints.",
                    "url": "https://github.com/MuhammadWaseem29/SQL-Injection-and-RCE_CVE-2025-57819"
                },
                {
                    "repository": "PoC-in-GitHub · xV4nd3Rx/CVE-2025-57819_FreePBX-PoC",
                    "author": "xV4nd3Rx",
                    "first_seen": "2025-09-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Safe, read-only SQL Injection checker for FreePBX (CVE-2025-57819), using error/boolean/time-based techniques with per-parameter verdicts and JSON reporting.",
                    "summary": "Safe, read-only SQL Injection checker for FreePBX (CVE-2025-57819), using error/boolean/time-based techniques with per-parameter verdicts and JSON reporting.",
                    "url": "https://github.com/xV4nd3Rx/CVE-2025-57819_FreePBX-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · orange0Mint/CVE-2025-57819_FreePBX",
                    "author": "orange0Mint",
                    "first_seen": "2025-09-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract credentials using sqlmap (poc_auto_get_username_pass.py). For educational and authorized use only.",
                    "summary": "This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract credentials using sqlmap (poc_auto_get_username_pass.py). For educational and authorized use only.",
                    "url": "https://github.com/orange0Mint/CVE-2025-57819_FreePBX"
                },
                {
                    "repository": "PoC-in-GitHub · b4sh2/CVE-2025-57819-poc",
                    "author": "b4sh2",
                    "first_seen": "2026-06-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2025-57819 -> rce",
                    "summary": "CVE-2025-57819 -> rce",
                    "url": "https://github.com/b4sh2/CVE-2025-57819-poc"
                },
                {
                    "repository": "PoC-in-GitHub · 0xEhab/FreePBX-CVE-2025-57819-RCE",
                    "author": "0xEhab",
                    "first_seen": "2026-06-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 15,
                    "title": "CVE-2025-57819 repository",
                    "summary": "",
                    "url": "https://github.com/0xEhab/FreePBX-CVE-2025-57819-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · Jeanback1/CVE-2025-57819-exploit",
                    "author": "Jeanback1",
                    "first_seen": "2026-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit",
                    "summary": "FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit",
                    "url": "https://github.com/Jeanback1/CVE-2025-57819-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · jf-gondim/freepbx-endpoint-sqli-rce",
                    "author": "jf-gondim",
                    "first_seen": "2026-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Unauthenticated SQL injection in FreePBX Endpoint Manager (CVE-2025-57819) that injects a cron-scheduled PHP webshell for remote code execution.",
                    "summary": "Unauthenticated SQL injection in FreePBX Endpoint Manager (CVE-2025-57819) that injects a cron-scheduled PHP webshell for remote code execution.",
                    "url": "https://github.com/jf-gondim/freepbx-endpoint-sqli-rce"
                },
                {
                    "repository": "PoC-in-GitHub · YuvrajSHAD/FreePBX-CVE-2025-57819",
                    "author": "YuvrajSHAD",
                    "first_seen": "2026-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819",
                    "summary": "Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819",
                    "url": "https://github.com/YuvrajSHAD/FreePBX-CVE-2025-57819"
                },
                {
                    "repository": "PoC-in-GitHub · 0xyngtg/FreePBX-CVE-2025-57819-CVE-2025-61678",
                    "author": "0xyngtg",
                    "first_seen": "2026-06-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Chains CVE-2025-57819 (stacked query SQL injection) and CVE-2025-61678 (authenticated file upload in FreePBX Endpoint Manager) to achieve Remote Code Execution (RCE). For educational use only.",
                    "summary": "Chains CVE-2025-57819 (stacked query SQL injection) and CVE-2025-61678 (authenticated file upload in FreePBX Endpoint Manager) to achieve Remote Code Execution (RCE). For educational use only.",
                    "url": "https://github.com/0xyngtg/FreePBX-CVE-2025-57819-CVE-2025-61678"
                },
                {
                    "repository": "PoC-in-GitHub · ozcanpng/CVE-2025-57819-FreePBX-RCE2Root",
                    "author": "ozcanpng",
                    "first_seen": "2026-06-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.",
                    "summary": "Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.",
                    "url": "https://github.com/ozcanpng/CVE-2025-57819-FreePBX-RCE2Root"
                },
                {
                    "repository": "PoC-in-GitHub · JazzTheRabbit/FreePBX-SQLi-RCE",
                    "author": "JazzTheRabbit",
                    "first_seen": "2026-06-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-57819 FreePBX SQLi RCE PoC",
                    "summary": "CVE-2025-57819 FreePBX SQLi RCE PoC",
                    "url": "https://github.com/JazzTheRabbit/FreePBX-SQLi-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · Its1Zero/cve-2025-57819-exploit",
                    "author": "Its1Zero",
                    "first_seen": "2026-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-57819 repository",
                    "summary": "",
                    "url": "https://github.com/Its1Zero/cve-2025-57819-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · K3ysTr0K3R/CVE-2025-57819",
                    "author": "K3ysTr0K3R",
                    "first_seen": "2026-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2025-57819 - FreePBX Unauthenticated Remote Code Execution (RCE)",
                    "summary": "CVE-2025-57819 - FreePBX Unauthenticated Remote Code Execution (RCE)",
                    "url": "https://github.com/K3ysTr0K3R/CVE-2025-57819"
                },
                {
                    "repository": "PoC-in-GitHub · Neobee714/CVE-2025-57819-POC",
                    "author": "Neobee714",
                    "first_seen": "2026-07-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "FreePBX 未认证SQL注入导致远程代码执行，FreePBX 15 (低于 15.0.66)、16 (低于 16.0.89)、17 (低于 17.0.3)。该漏洞位于商业化“endpoint”模块中，因对用户输入过滤不严，允许未认证的攻击者绕过管理员权限，执行SQL注入，并最终实现远程代码执行",
                    "summary": "FreePBX 未认证SQL注入导致远程代码执行，FreePBX 15 (低于 15.0.66)、16 (低于 16.0.89)、17 (低于 17.0.3)。该漏洞位于商业化“endpoint”模块中，因对用户输入过滤不严，允许未认证的攻击者绕过管理员权限，执行SQL注入，并最终实现远程代码执行",
                    "url": "https://github.com/Neobee714/CVE-2025-57819-POC"
                },
                {
                    "repository": "PoC-in-GitHub · TeteREN/CVE-2025-57819-RCE",
                    "author": "TeteREN",
                    "first_seen": "2026-08-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-57819-RCE_PoC",
                    "summary": "CVE-2025-57819-RCE_PoC",
                    "url": "https://github.com/TeteREN/CVE-2025-57819-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · r3vpwnx/CVE-2025-57819",
                    "author": "r3vpwnx",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-57819 - FreePBX 16 Endpoint Manager unauthenticated SQL injection to RCE (PoC)",
                    "summary": "CVE-2025-57819 - FreePBX 16 Endpoint Manager unauthenticated SQL injection to RCE (PoC)",
                    "url": "https://github.com/r3vpwnx/CVE-2025-57819"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52681",
                "https://cxsecurity.com/issue/WLB-2026090002",
                "https://sploitus.com/exploit?id=2E1494D5-4077-5CA3-AD82-8F9BDCB27DA4",
                "https://github.com/rxerium/CVE-2025-57819",
                "https://github.com/Sucuri-Labs/CVE-2025-57819-ioc-check",
                "https://github.com/cybertechajju/cve-2025-57819",
                "https://github.com/blueisbeautiful/CVE-2025-57819",
                "https://github.com/ImBIOS/lab-cve-2025-57819",
                "https://github.com/watchtowrlabs/watchTowr-vs-FreePBX-CVE-2025-57819",
                "https://github.com/MuhammadWaseem29/SQL-Injection-and-RCE_CVE-2025-57819",
                "https://github.com/xV4nd3Rx/CVE-2025-57819_FreePBX-PoC",
                "https://github.com/orange0Mint/CVE-2025-57819_FreePBX",
                "https://github.com/b4sh2/CVE-2025-57819-poc",
                "https://github.com/0xEhab/FreePBX-CVE-2025-57819-RCE",
                "https://github.com/Jeanback1/CVE-2025-57819-exploit",
                "https://github.com/jf-gondim/freepbx-endpoint-sqli-rce",
                "https://github.com/YuvrajSHAD/FreePBX-CVE-2025-57819",
                "https://github.com/0xyngtg/FreePBX-CVE-2025-57819-CVE-2025-61678",
                "https://github.com/ozcanpng/CVE-2025-57819-FreePBX-RCE2Root",
                "https://github.com/JazzTheRabbit/FreePBX-SQLi-RCE",
                "https://github.com/Its1Zero/cve-2025-57819-exploit",
                "https://github.com/K3ysTr0K3R/CVE-2025-57819",
                "https://github.com/Neobee714/CVE-2025-57819-POC",
                "https://github.com/TeteREN/CVE-2025-57819-RCE",
                "https://github.com/r3vpwnx/CVE-2025-57819"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-55183",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2025-55183_POC exploit",
            "summary": "Exploit for CVE-2025-55183. CVSS 5.3.",
            "updated_at": "2026-09-15T08:37:15Z",
            "published_at": "2026-09-15T08:37:15Z",
            "cvss": 5.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Source code disclosure in Next.js RSC via stringified Server Function argument returning source.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-55183_POC",
                    "summary": "Source code disclosure in Next.js RSC via stringified Server Function argument returning source.",
                    "what_happened": "Source code disclosure in Next.js RSC via stringified Server Function argument returning source.",
                    "cvss": 5.3,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-COTANG-CVE-2025-55183_POC",
                        "https://kitploit.com/ru/tools/github/x-cotang/cve-2025-55183_poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-31T00:05:49",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-COTANG-CVE-2025-55183_POC"
                },
                {
                    "title": "Exploit for CVE-2025-55183_POC",
                    "summary": "Source code disclosure in Next.js RSC via stringified Server Function argument returning source.",
                    "what_happened": "Source code disclosure in Next.js RSC via stringified Server Function argument returning source.",
                    "cvss": 5.3,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-COTANG-CVE-2025-55183_POC",
                        "https://kitploit.com/ru/tools/github/x-cotang/cve-2025-55183_poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-31T00:05:49",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/x-cotang/cve-2025-55183_poc/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-COTANG-CVE-2025-55183_POC",
                "https://kitploit.com/ru/tools/github/x-cotang/cve-2025-55183_poc/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:37:15Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-COTANG-CVE-2025-55183_POC"
                }
            ]
        },
        {
            "id": "CVE-2025-54988",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2025-66516-POC",
            "summary": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
            "updated_at": "2026-09-07T19:12:13Z",
            "published_at": "2026-09-07T19:12:13Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 25,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-66516-POC",
                    "summary": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
                    "what_happened": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SID6224-CVE-2025-66516-POC",
                        "https://kitploit.com/ja/tools/github/sid6224/cve-2025-66516-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-07T21:12:13",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SID6224-CVE-2025-66516-POC"
                },
                {
                    "title": "Exploit for CVE-2025-66516-POC",
                    "summary": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
                    "what_happened": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SID6224-CVE-2025-66516-POC",
                        "https://kitploit.com/ja/tools/github/sid6224/cve-2025-66516-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-07T21:12:13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/sid6224/cve-2025-66516-poc/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SID6224-CVE-2025-66516-POC",
                "https://kitploit.com/ja/tools/github/sid6224/cve-2025-66516-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:12:13Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SID6224-CVE-2025-66516-POC"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-54918",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2025-54918-POC exploit",
            "summary": "Exploit for CVE-2025-54918. CVSS 8.8.",
            "updated_at": "2026-09-08T14:31:45Z",
            "published_at": "2026-09-08T14:31:45Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 61,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "NTLM reflection and coercion in Windows Server 2025 lets a domain user escalate to Domain Admin.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-54918-POC CVE-2025-33073 CVE-2025-54918",
                    "summary": "NTLM reflection and coercion in Windows Server 2025 lets a domain user escalate to Domain Admin.",
                    "what_happened": "NTLM reflection and coercion in Windows Server 2025 lets a domain user escalate to Domain Admin.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH0AM123-CVE-2025-54918-POC",
                        "https://kitploit.com/ru/tools/github/wh0am123/cve-2025-54918-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-24T23:01:33",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH0AM123-CVE-2025-54918-POC"
                },
                {
                    "title": "Exploit for CVE-2025-54918-POC CVE-2025-33073 CVE-2025-54918",
                    "summary": "NTLM reflection and coercion in Windows Server 2025 lets a domain user escalate to Domain Admin.",
                    "what_happened": "NTLM reflection and coercion in Windows Server 2025 lets a domain user escalate to Domain Admin.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH0AM123-CVE-2025-54918-POC",
                        "https://kitploit.com/ru/tools/github/wh0am123/cve-2025-54918-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-24T23:01:33",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/wh0am123/cve-2025-54918-poc/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH0AM123-CVE-2025-54918-POC",
                "https://kitploit.com/ru/tools/github/wh0am123/cve-2025-54918-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T14:31:45Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH0AM123-CVE-2025-54918-POC"
                }
            ]
        },
        {
            "id": "CVE-2025-54603",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.",
            "updated_at": "2026-09-08T17:17:31.227",
            "published_at": "2025-10-14T17:15:44.307",
            "cvss": 9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-284",
            "what_happened": "An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://claroty.com",
                "https://claroty.com/product-security/oidc-configurations-in-claroty-secure-access"
            ],
            "timeline": [
                {
                    "at": "2025-10-14T17:15:44.307",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-54603"
                }
            ]
        },
        {
            "id": "CVE-2025-54518",
            "vendor": "AMD",
            "product": "AMD EPYC™ 7002 Series Processors",
            "title": "AMD EPYC™ 7002 Series Processors vulnerability",
            "summary": "Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.",
            "updated_at": "2026-09-10T13:16:59.227",
            "published_at": "2026-05-15T05:16:33.013",
            "cvss": 7.3,
            "cvss_vector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-1189",
            "what_happened": "Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-7052.html",
                "http://www.openwall.com/lists/oss-security/2026/05/12/15",
                "http://xenbits.xen.org/xsa/advisory-490.html",
                "https://access.redhat.com/errata/RHSA-2026:50978",
                "https://access.redhat.com/errata/RHSA-2026:50979",
                "https://access.redhat.com/errata/RHSA-2026:53329",
                "https://access.redhat.com/errata/RHSA-2026:53989",
                "https://access.redhat.com/errata/RHSA-2026:53990",
                "https://access.redhat.com/errata/RHSA-2026:54769",
                "https://access.redhat.com/errata/RHSA-2026:55444",
                "https://access.redhat.com/errata/RHSA-2026:56573",
                "https://access.redhat.com/errata/RHSA-2026:57402",
                "https://access.redhat.com/errata/RHSA-2026:57457",
                "https://access.redhat.com/errata/RHSA-2026:57543",
                "https://access.redhat.com/errata/RHSA-2026:59091",
                "https://access.redhat.com/errata/RHSA-2026:59831",
                "https://access.redhat.com/errata/RHSA-2026:60019",
                "https://access.redhat.com/errata/RHSA-2026:62549",
                "https://access.redhat.com/security/cve/CVE-2025-54518",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2477784",
                "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-54518.json"
            ],
            "timeline": [
                {
                    "at": "2026-05-15T05:16:33.013",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-54518"
                }
            ]
        },
        {
            "id": "CVE-2025-54100",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2025-54100 exploit",
            "summary": "Exploit for CVE-2025-54100. CVSS 7.8.",
            "updated_at": "2026-09-11T18:31:26Z",
            "published_at": "2026-09-11T18:31:26Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 41,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Command injection in PowerShell 5.1 Invoke-WebRequest via MSHTML parsing enables RCE.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-54100",
                    "summary": "Command injection in PowerShell 5.1 Invoke-WebRequest via MSHTML parsing enables RCE.",
                    "what_happened": "Command injection in PowerShell 5.1 Invoke-WebRequest via MSHTML parsing enables RCE.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THEMEHACKERS-CVE-2025-54100",
                        "https://kitploit.com/zh/tools/github/themehackers/cve-2025-54100/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-07T17:03:40",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THEMEHACKERS-CVE-2025-54100"
                },
                {
                    "title": "Exploit for CVE-2025-54100",
                    "summary": "Command injection in PowerShell 5.1 Invoke-WebRequest via MSHTML parsing enables RCE.",
                    "what_happened": "Command injection in PowerShell 5.1 Invoke-WebRequest via MSHTML parsing enables RCE.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THEMEHACKERS-CVE-2025-54100",
                        "https://kitploit.com/zh/tools/github/themehackers/cve-2025-54100/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-07T17:03:40",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/themehackers/cve-2025-54100/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THEMEHACKERS-CVE-2025-54100",
                "https://kitploit.com/zh/tools/github/themehackers/cve-2025-54100/"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T18:31:26Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THEMEHACKERS-CVE-2025-54100"
                }
            ]
        },
        {
            "id": "CVE-2025-53772",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2025-53772",
            "summary": "RCE in Microsoft Web Deploy via unsafe deserialization of HTTP header data.",
            "updated_at": "2026-09-04T22:56:00Z",
            "published_at": "2026-09-04T22:56:00Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 81,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-502",
            "what_happened": "RCE in Microsoft Web Deploy via unsafe deserialization of HTTP header data.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-53772",
                    "summary": "RCE in Microsoft Web Deploy via unsafe deserialization of HTTP header data.",
                    "what_happened": "RCE in Microsoft Web Deploy via unsafe deserialization of HTTP header data.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-502",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SAILAY1996-CVE-2025-53772",
                        "https://kitploit.com/zh/tools/github/sailay1996/cve-2025-53772/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T00:56:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SAILAY1996-CVE-2025-53772"
                },
                {
                    "title": "Exploit for CVE-2025-53772",
                    "summary": "RCE in Microsoft Web Deploy via unsafe deserialization of HTTP header data.",
                    "what_happened": "RCE in Microsoft Web Deploy via unsafe deserialization of HTTP header data.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-502",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SAILAY1996-CVE-2025-53772",
                        "https://kitploit.com/zh/tools/github/sailay1996/cve-2025-53772/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-05T00:56:00",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/sailay1996/cve-2025-53772/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SAILAY1996-CVE-2025-53772",
                "https://kitploit.com/zh/tools/github/sailay1996/cve-2025-53772/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T22:56:00Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SAILAY1996-CVE-2025-53772"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-53341",
            "vendor": "Pixel Makers Creative INC.",
            "product": "App, SaaS & Software Startup Tech Theme - Stratus",
            "title": "App, SaaS & Software Startup Tech Theme - Stratus vulnerability",
            "summary": "Missing Authorization vulnerability in Pixel Makers Creative INC. App, SaaS & Software Startup Tech Theme - Stratus allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects App, SaaS & Software Startup Tech Theme - Stratus: from n/a before 4.2.11.",
            "updated_at": "2026-09-14T11:17:01.463",
            "published_at": "2025-08-14T19:15:35.597",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a through before 4.2.11 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "Missing Authorization vulnerability in Pixel Makers Creative INC. App, SaaS & Software Startup Tech Theme - Stratus allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects App, SaaS & Software Startup Tech Theme - Stratus: from n/a before 4.2.11.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://patchstack.com/database/wordpress/theme/stratusx/vulnerability/wordpress-stratus-theme-theme-4-2-5-broken-access-control-vulnerability?_s_id=cve"
            ],
            "timeline": [
                {
                    "at": "2025-08-14T19:15:35.597",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53341"
                }
            ]
        },
        {
            "id": "CVE-2025-51684",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessage before injecting it into the page DOM. An attacker can craft a malicious message that, when processed by renderCustomHtml, results in execution of arbitrary JavaScript in the context of the hosting site.",
            "updated_at": "2026-09-09T16:04:24.933",
            "published_at": "2026-07-30T20:16:51.793",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessage before injecting it into the page DOM. An attacker can craft a malicious message that, when processed by renderCustomHtml, results in execution of arbitrary JavaScript in the context of the hosting site.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/CleverTap/clevertap-web-sdk/issues/416"
            ],
            "timeline": [
                {
                    "at": "2026-07-30T20:16:51.793",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-51684"
                }
            ]
        },
        {
            "id": "CVE-2025-50505",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2025-50505",
            "summary": "Unauthenticated API in Clash Verge Rev <=2.2.3 allows command execution and privilege escalation.",
            "updated_at": "2026-09-03T18:34:36Z",
            "published_at": "2026-09-03T18:34:36Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Unauthenticated API in Clash Verge Rev <=2.2.3 allows command execution and privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-50505",
                    "summary": "Unauthenticated API in Clash Verge Rev <=2.2.3 allows command execution and privilege escalation.",
                    "what_happened": "Unauthenticated API in Clash Verge Rev <=2.2.3 allows command execution and privilege escalation.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-A0YAMI-CVE-2025-50505",
                        "https://kitploit.com/ru/tools/github/a0yami/cve-2025-50505/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T20:34:36",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-A0YAMI-CVE-2025-50505"
                },
                {
                    "title": "Exploit for CVE-2025-50505",
                    "summary": "Unauthenticated API in Clash Verge Rev <=2.2.3 allows command execution and privilege escalation.",
                    "what_happened": "Unauthenticated API in Clash Verge Rev <=2.2.3 allows command execution and privilege escalation.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-A0YAMI-CVE-2025-50505",
                        "https://kitploit.com/ru/tools/github/a0yami/cve-2025-50505/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-03T20:34:36",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/a0yami/cve-2025-50505/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-A0YAMI-CVE-2025-50505",
                "https://kitploit.com/ru/tools/github/a0yami/cve-2025-50505/"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T18:34:36Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-A0YAMI-CVE-2025-50505"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-50455",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "EasyAppointments  1.5.1 - Blind SQL Injection",
            "summary": "EasyAppointments  1.5.1 - Blind SQL Injection",
            "updated_at": "2026-08-31T22:00:00Z",
            "published_at": "2026-08-31T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 98,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52667",
                    "author": "Michael Chesang",
                    "first_seen": "2026-09-01",
                    "confidence": "High",
                    "title": "EasyAppointments  1.5.1 - Blind SQL Injection",
                    "summary": "EasyAppointments  1.5.1 - Blind SQL Injection",
                    "url": "https://www.exploit-db.com/exploits/52667",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52667"
            ],
            "timeline": [
                {
                    "at": "2026-08-31T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52667"
                }
            ]
        },
        {
            "id": "CVE-2025-50154",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Microsoft Windows 10.0.19045 - NTLMv2 Hash Disclosure",
            "summary": "Microsoft Windows 10.0.19045 - NTLMv2 Hash Disclosure",
            "updated_at": "2026-09-02T21:38:26Z",
            "published_at": "2026-09-02T21:38:26Z",
            "cvss": 6.5,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 190,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52415",
                    "author": "Ruben Enkaoua",
                    "first_seen": "2025-08-18",
                    "confidence": "High",
                    "title": "Microsoft Windows 10.0.19045 - NTLMv2 Hash Disclosure",
                    "summary": "Microsoft Windows 10.0.19045 - NTLMv2 Hash Disclosure",
                    "url": "https://www.exploit-db.com/exploits/52415",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2025-50154 CVE-2025-50154 CVE-2025-59214",
                    "summary": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
                    "what_happened": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUBENFORMATION-CVE-2025-50154",
                        "https://kitploit.com/ru/tools/github/rubenformation/cve-2025-50154/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-02T23:38:26",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUBENFORMATION-CVE-2025-50154"
                },
                {
                    "title": "Exploit for CVE-2025-50154 CVE-2025-50154 CVE-2025-59214",
                    "summary": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
                    "what_happened": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUBENFORMATION-CVE-2025-50154",
                        "https://kitploit.com/ru/tools/github/rubenformation/cve-2025-50154/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-02T23:38:26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/rubenformation/cve-2025-50154/"
                },
                {
                    "repository": "PoC-in-GitHub · zenzue/CVE-2025-50154",
                    "author": "zenzue",
                    "first_seen": "2025-08-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2025-50154 repository",
                    "summary": "",
                    "url": "https://github.com/zenzue/CVE-2025-50154"
                },
                {
                    "repository": "PoC-in-GitHub · rubenformation/CVE-2025-50154",
                    "author": "rubenformation",
                    "first_seen": "2025-08-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 56,
                    "title": "POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a bypass for the CVE-2025-24054 Security Patch",
                    "summary": "POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a bypass for the CVE-2025-24054 Security Patch",
                    "url": "https://github.com/rubenformation/CVE-2025-50154"
                },
                {
                    "repository": "PoC-in-GitHub · Ash1996x/CVE-2025-50154-Aggressor-Script",
                    "author": "Ash1996x",
                    "first_seen": "2025-08-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-50154 repository",
                    "summary": "",
                    "url": "https://github.com/Ash1996x/CVE-2025-50154-Aggressor-Script"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52415",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUBENFORMATION-CVE-2025-50154",
                "https://kitploit.com/ru/tools/github/rubenformation/cve-2025-50154/",
                "https://github.com/zenzue/CVE-2025-50154",
                "https://github.com/rubenformation/CVE-2025-50154",
                "https://github.com/Ash1996x/CVE-2025-50154-Aggressor-Script"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T21:38:26Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52415"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2025-49796",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.",
            "updated_at": "2026-09-10T10:17:28.800",
            "published_at": "2025-06-16T16:15:19.370",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.15.0 (semver); before V2.17.1 (custom); before V4.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 34,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input file that can lead libxml to crash, resulting in a denial of service or other possible undefined behavior due to sensitive data being corrupted in memory.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2025:10630",
                "https://access.redhat.com/errata/RHSA-2025:10698",
                "https://access.redhat.com/errata/RHSA-2025:10699",
                "https://access.redhat.com/errata/RHSA-2025:11580",
                "https://access.redhat.com/errata/RHSA-2025:12098",
                "https://access.redhat.com/errata/RHSA-2025:12099",
                "https://access.redhat.com/errata/RHSA-2025:12199",
                "https://access.redhat.com/errata/RHSA-2025:12237",
                "https://access.redhat.com/errata/RHSA-2025:12239",
                "https://access.redhat.com/errata/RHSA-2025:12240",
                "https://access.redhat.com/errata/RHSA-2025:12241",
                "https://access.redhat.com/errata/RHSA-2025:13267",
                "https://access.redhat.com/errata/RHSA-2025:13335",
                "https://access.redhat.com/errata/RHSA-2025:15397",
                "https://access.redhat.com/errata/RHSA-2025:15827",
                "https://access.redhat.com/errata/RHSA-2025:15828",
                "https://access.redhat.com/errata/RHSA-2025:18217",
                "https://access.redhat.com/errata/RHSA-2025:18218",
                "https://access.redhat.com/errata/RHSA-2025:18219",
                "https://access.redhat.com/errata/RHSA-2025:18240",
                "https://access.redhat.com/errata/RHSA-2025:19020",
                "https://access.redhat.com/errata/RHSA-2025:19041",
                "https://access.redhat.com/errata/RHSA-2025:19046",
                "https://access.redhat.com/errata/RHSA-2025:19894",
                "https://access.redhat.com/errata/RHSA-2025:21913",
                "https://access.redhat.com/errata/RHSA-2026:0934",
                "https://access.redhat.com/errata/RHSA-2026:7519",
                "https://access.redhat.com/security/cve/CVE-2025-49796",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2372385",
                "https://gitlab.gnome.org/GNOME/libxml2/-/issues/933",
                "https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-253495.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-577017.html",
                "https://access.redhat.com/errata/RHSA-2026:62549"
            ],
            "timeline": [
                {
                    "at": "2025-06-16T16:15:19.370",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49796"
                }
            ]
        },
        {
            "id": "CVE-2025-49794",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path=\"...\"/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.",
            "updated_at": "2026-09-10T10:17:26.977",
            "published_at": "2025-06-16T16:15:18.997",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.15.0 (semver); before V2.17.1 (custom); before V4.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 33,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-825",
            "what_happened": "A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path=\"...\"/> schema elements. This flaw allows a malicious actor to craft a malicious XML document used as input for libxml, resulting in the program's crash using libxml or other possible undefined behaviors.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2025:10630",
                "https://access.redhat.com/errata/RHSA-2025:10698",
                "https://access.redhat.com/errata/RHSA-2025:10699",
                "https://access.redhat.com/errata/RHSA-2025:11580",
                "https://access.redhat.com/errata/RHSA-2025:12098",
                "https://access.redhat.com/errata/RHSA-2025:12099",
                "https://access.redhat.com/errata/RHSA-2025:12199",
                "https://access.redhat.com/errata/RHSA-2025:12237",
                "https://access.redhat.com/errata/RHSA-2025:12239",
                "https://access.redhat.com/errata/RHSA-2025:12240",
                "https://access.redhat.com/errata/RHSA-2025:12241",
                "https://access.redhat.com/errata/RHSA-2025:13335",
                "https://access.redhat.com/errata/RHSA-2025:15397",
                "https://access.redhat.com/errata/RHSA-2025:15827",
                "https://access.redhat.com/errata/RHSA-2025:15828",
                "https://access.redhat.com/errata/RHSA-2025:18217",
                "https://access.redhat.com/errata/RHSA-2025:18218",
                "https://access.redhat.com/errata/RHSA-2025:18219",
                "https://access.redhat.com/errata/RHSA-2025:18240",
                "https://access.redhat.com/errata/RHSA-2025:19020",
                "https://access.redhat.com/errata/RHSA-2025:19041",
                "https://access.redhat.com/errata/RHSA-2025:19046",
                "https://access.redhat.com/errata/RHSA-2025:19894",
                "https://access.redhat.com/errata/RHSA-2025:21913",
                "https://access.redhat.com/errata/RHSA-2026:0934",
                "https://access.redhat.com/errata/RHSA-2026:7519",
                "https://access.redhat.com/security/cve/CVE-2025-49794",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2372373",
                "https://gitlab.gnome.org/GNOME/libxml2/-/issues/931",
                "https://lists.debian.org/debian-lts-announce/2025/07/msg00014.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-253495.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-577017.html",
                "https://access.redhat.com/errata/RHSA-2026:62549"
            ],
            "timeline": [
                {
                    "at": "2025-06-16T16:15:18.997",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-49794"
                }
            ]
        },
        {
            "id": "CVE-2025-49113",
            "vendor": "Roundcube",
            "product": "Webmail",
            "title": "RoundCube Webmail Deserialization of Untrusted Data Vulnerability",
            "summary": "RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.",
            "updated_at": "2026-09-11T18:32:00Z",
            "published_at": "2026-09-11T18:32:00Z",
            "cvss": 9.9,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 100,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52324",
                    "author": "Maksim Rogov",
                    "first_seen": "2025-06-13",
                    "confidence": "High",
                    "title": "Roundcube 1.6.10 - Remote Code Execution (RCE)",
                    "summary": "Roundcube 1.6.10 - Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/52324",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2025-49113-Roundcube_1.6.10",
                    "summary": "Authenticated RCE in Roundcube 1.6.10 via PHP payload enabling system-level command execution.",
                    "what_happened": "Authenticated RCE in Roundcube 1.6.10 via PHP payload enabling system-level command execution.",
                    "cvss": 9.9,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CYBERQUESTOR-INFOSEC-CVE-2025-49113-ROUNDCUBE_1.6.10",
                        "https://kitploit.com/ru/tools/github/cyberquestor-infosec/cve-2025-49113-roundcube_1.6.10/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T15:40:20",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CYBERQUESTOR-INFOSEC-CVE-2025-49113-ROUNDCUBE_1.6.10"
                },
                {
                    "title": "Exploit for CVE-2025-49113-Roundcube_1.6.10",
                    "summary": "Authenticated RCE in Roundcube 1.6.10 via PHP payload enabling system-level command execution.",
                    "what_happened": "Authenticated RCE in Roundcube 1.6.10 via PHP payload enabling system-level command execution.",
                    "cvss": 9.9,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CYBERQUESTOR-INFOSEC-CVE-2025-49113-ROUNDCUBE_1.6.10",
                        "https://kitploit.com/ru/tools/github/cyberquestor-infosec/cve-2025-49113-roundcube_1.6.10/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T15:40:20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/cyberquestor-infosec/cve-2025-49113-roundcube_1.6.10/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52324",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CYBERQUESTOR-INFOSEC-CVE-2025-49113-ROUNDCUBE_1.6.10",
                "https://kitploit.com/ru/tools/github/cyberquestor-infosec/cve-2025-49113-roundcube_1.6.10/"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T18:32:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-02-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-48651",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-08T19:17:49.300",
            "published_at": "2026-04-06T19:16:25.867",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Android SoC",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2026-04-06T19:16:25.867",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48651"
                }
            ]
        },
        {
            "id": "CVE-2025-48566",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-08T19:17:46.907",
            "published_at": "2025-12-08T17:16:14.893",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2025-12-08T17:16:14.893",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48566"
                }
            ]
        },
        {
            "id": "CVE-2025-48565",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-08T19:17:46.753",
            "published_at": "2025-12-08T17:16:14.777",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In multiple locations, there is a possible way to bypass the cross profile intent filter due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2025-12-08T17:16:14.777",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48565"
                }
            ]
        },
        {
            "id": "CVE-2025-48564",
            "vendor": "Google",
            "product": "Android",
            "title": "Android vulnerability",
            "summary": "In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-08T19:17:46.237",
            "published_at": "2025-12-08T17:16:14.660",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "17; 16-qpr2; 16; 15; 14",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "In multiple locations, there is a possible intent filter bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://source.android.com/docs/security/bulletin/2026/2026-09-01"
            ],
            "timeline": [
                {
                    "at": "2025-12-08T17:16:14.660",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48564"
                }
            ]
        },
        {
            "id": "CVE-2025-48431",
            "vendor": "Apache Software Foundation",
            "product": "Apache Thrift",
            "title": "Apache Thrift vulnerability",
            "summary": "Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.\n\nDescription: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal \"free(): invalid pointer\" error message.",
            "updated_at": "2026-09-10T13:16:58.930",
            "published_at": "2026-04-28T10:16:02.153",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.23.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-762",
            "what_happened": "Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.\n\nThis issue affects Apache Thrift: before 0.23.0.\n\nUsers are recommended to upgrade to version 0.23.0, which fixes the issue.\n\nDescription: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal \"free(): invalid pointer\" error message.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://lists.apache.org/thread/lb4j0zyd5f3g36cos0wql925przpnwql",
                "http://www.openwall.com/lists/oss-security/2026/04/28/8",
                "https://access.redhat.com/errata/RHSA-2026:24539",
                "https://access.redhat.com/errata/RHSA-2026:25273",
                "https://access.redhat.com/errata/RHSA-2026:27126",
                "https://access.redhat.com/errata/RHSA-2026:28010",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/security/cve/CVE-2025-48431",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2463410",
                "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-48431.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-28T10:16:02.153",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-48431"
                }
            ]
        },
        {
            "id": "CVE-2025-48384",
            "vendor": "Git",
            "product": "Git",
            "title": "Git Link Following Vulnerability",
            "summary": "Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.",
            "updated_at": "2026-09-06T22:00:00Z",
            "published_at": "2026-09-06T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1504,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · acheong08/CVE-2025-48384",
                    "author": "acheong08",
                    "first_seen": "2025-07-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 53,
                    "title": "Breaking git with a carriage return and cloning RCE",
                    "summary": "Breaking git with a carriage return and cloning RCE",
                    "url": "https://github.com/acheong08/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · fishyyh/CVE-2025-48384",
                    "author": "fishyyh",
                    "first_seen": "2025-07-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "for CVE-2025-48384 test",
                    "summary": "for CVE-2025-48384 test",
                    "url": "https://github.com/fishyyh/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · kallydev/cve-2025-48384-hook",
                    "author": "kallydev",
                    "first_seen": "2025-07-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/kallydev/cve-2025-48384-hook"
                },
                {
                    "repository": "PoC-in-GitHub · fishyyh/CVE-2025-48384-POC",
                    "author": "fishyyh",
                    "first_seen": "2025-07-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/fishyyh/CVE-2025-48384-POC"
                },
                {
                    "repository": "PoC-in-GitHub · liamg/CVE-2025-48384-submodule",
                    "author": "liamg",
                    "first_seen": "2025-07-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/liamg/CVE-2025-48384-submodule"
                },
                {
                    "repository": "PoC-in-GitHub · liamg/CVE-2025-48384",
                    "author": "liamg",
                    "first_seen": "2025-07-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 20,
                    "title": "PoC for CVE-2025-48384",
                    "summary": "PoC for CVE-2025-48384",
                    "url": "https://github.com/liamg/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · ppd520/CVE-2025-48384",
                    "author": "ppd520",
                    "first_seen": "2025-07-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/ppd520/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · NigelX/CVE-2025-48384",
                    "author": "NigelX",
                    "first_seen": "2025-07-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "漏洞测试",
                    "summary": "漏洞测试",
                    "url": "https://github.com/NigelX/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · greatyy/CVE-2025-48384-p",
                    "author": "greatyy",
                    "first_seen": "2025-07-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/greatyy/CVE-2025-48384-p"
                },
                {
                    "repository": "PoC-in-GitHub · testdjshan/CVE-2025-48384",
                    "author": "testdjshan",
                    "first_seen": "2025-07-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384",
                    "summary": "CVE-2025-48384",
                    "url": "https://github.com/testdjshan/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · altm4n/cve-2025-48384",
                    "author": "altm4n",
                    "first_seen": "2025-07-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/altm4n/cve-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · altm4n/cve-2025-48384-hub",
                    "author": "altm4n",
                    "first_seen": "2025-07-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/altm4n/cve-2025-48384-hub"
                },
                {
                    "repository": "PoC-in-GitHub · vinieger/vinieger-CVE-2025-48384-Dockerfile",
                    "author": "vinieger",
                    "first_seen": "2025-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC dockerfile image for CVE-2025-48384",
                    "summary": "PoC dockerfile image for CVE-2025-48384",
                    "url": "https://github.com/vinieger/vinieger-CVE-2025-48384-Dockerfile"
                },
                {
                    "repository": "PoC-in-GitHub · ECHO6789/CVE-2025-48384-submodule",
                    "author": "ECHO6789",
                    "first_seen": "2025-07-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/ECHO6789/CVE-2025-48384-submodule"
                },
                {
                    "repository": "PoC-in-GitHub · nguyentranbaotran/cve-2025-48384-poc",
                    "author": "nguyentranbaotran",
                    "first_seen": "2025-07-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/nguyentranbaotran/cve-2025-48384-poc"
                },
                {
                    "repository": "PoC-in-GitHub · admin-ping/CVE-2025-48384-RCE",
                    "author": "admin-ping",
                    "first_seen": "2025-07-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/admin-ping/CVE-2025-48384-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · Anezatraa/CVE-2025-48384-submodule",
                    "author": "Anezatraa",
                    "first_seen": "2025-07-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/Anezatraa/CVE-2025-48384-submodule"
                },
                {
                    "repository": "PoC-in-GitHub · IK-20211125/CVE-2025-48384",
                    "author": "IK-20211125",
                    "first_seen": "2025-07-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-48384 PoC",
                    "summary": "CVE-2025-48384 PoC",
                    "url": "https://github.com/IK-20211125/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · elprogramadorgt/CVE-2025-48384",
                    "author": "elprogramadorgt",
                    "first_seen": "2025-07-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/elprogramadorgt/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · fluoworite/CVE-2025-48384",
                    "author": "fluoworite",
                    "first_seen": "2025-08-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC for CVE-2025-48384",
                    "summary": "PoC for CVE-2025-48384",
                    "url": "https://github.com/fluoworite/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · fluoworite/CVE-2025-48384-sub",
                    "author": "fluoworite",
                    "first_seen": "2025-08-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/fluoworite/CVE-2025-48384-sub"
                },
                {
                    "repository": "PoC-in-GitHub · beishanxueyuan/CVE-2025-48384",
                    "author": "beishanxueyuan",
                    "first_seen": "2025-08-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/beishanxueyuan/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · beishanxueyuan/CVE-2025-48384-test",
                    "author": "beishanxueyuan",
                    "first_seen": "2025-08-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/beishanxueyuan/CVE-2025-48384-test"
                },
                {
                    "repository": "PoC-in-GitHub · replicatorbot/CVE-2025-48384",
                    "author": "replicatorbot",
                    "first_seen": "2025-08-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/replicatorbot/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · replicatorbot/CVE-2025-48384-POC",
                    "author": "replicatorbot",
                    "first_seen": "2025-08-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/replicatorbot/CVE-2025-48384-POC"
                },
                {
                    "repository": "PoC-in-GitHub · eliox01/CVE-2025-48384",
                    "author": "eliox01",
                    "first_seen": "2025-08-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC",
                    "summary": "PoC",
                    "url": "https://github.com/eliox01/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · jacobholtz/CVE-2025-48384-poc",
                    "author": "jacobholtz",
                    "first_seen": "2025-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC for CVE-2025-48384",
                    "summary": "PoC for CVE-2025-48384",
                    "url": "https://github.com/jacobholtz/CVE-2025-48384-poc"
                },
                {
                    "repository": "PoC-in-GitHub · jacobholtz/CVE-2025-48384-submodule",
                    "author": "jacobholtz",
                    "first_seen": "2025-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/jacobholtz/CVE-2025-48384-submodule"
                },
                {
                    "repository": "PoC-in-GitHub · butyraldehyde/CVE-2025-48384-PoC-Part2",
                    "author": "butyraldehyde",
                    "first_seen": "2025-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "RCE hook",
                    "summary": "RCE hook",
                    "url": "https://github.com/butyraldehyde/CVE-2025-48384-PoC-Part2"
                },
                {
                    "repository": "PoC-in-GitHub · butyraldehyde/CVE-2025-48384-PoC",
                    "author": "butyraldehyde",
                    "first_seen": "2025-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Built to call on CVE-2025-48384-PoC-Part2 for RCE",
                    "summary": "Built to call on CVE-2025-48384-PoC-Part2 for RCE",
                    "url": "https://github.com/butyraldehyde/CVE-2025-48384-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · arun1033/CVE-2025-48384",
                    "author": "arun1033",
                    "first_seen": "2025-08-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/arun1033/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · s41r4j/CVE-2025-48384",
                    "author": "s41r4j",
                    "first_seen": "2025-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "GIT vulnerability | Carriage Return and RCE on cloning",
                    "summary": "GIT vulnerability | Carriage Return and RCE on cloning",
                    "url": "https://github.com/s41r4j/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · s41r4j/CVE-2025-48384-submodule",
                    "author": "s41r4j",
                    "first_seen": "2025-09-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384-submodule",
                    "summary": "CVE-2025-48384-submodule",
                    "url": "https://github.com/s41r4j/CVE-2025-48384-submodule"
                },
                {
                    "repository": "PoC-in-GitHub · mukesh-610/cve-2025-48384-exploit",
                    "author": "mukesh-610",
                    "first_seen": "2025-10-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/mukesh-610/cve-2025-48384-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · mukesh-610/cve-2025-48384",
                    "author": "mukesh-610",
                    "first_seen": "2025-10-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/mukesh-610/cve-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · MarcoTondolo/cve-2025-48384-poc",
                    "author": "MarcoTondolo",
                    "first_seen": "2025-10-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/MarcoTondolo/cve-2025-48384-poc"
                },
                {
                    "repository": "PoC-in-GitHub · zr0n/CVE-2025-48384-sub",
                    "author": "zr0n",
                    "first_seen": "2025-12-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/zr0n/CVE-2025-48384-sub"
                },
                {
                    "repository": "PoC-in-GitHub · zr0n/CVE-2025-48384-main",
                    "author": "zr0n",
                    "first_seen": "2025-12-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A proof of concept of remote code execution",
                    "summary": "A proof of concept of remote code execution",
                    "url": "https://github.com/zr0n/CVE-2025-48384-main"
                },
                {
                    "repository": "PoC-in-GitHub · vignesh21-git/CVE-2025-48384",
                    "author": "vignesh21-git",
                    "first_seen": "2025-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "GIT vulnerability | Carriage Return and RCE on cloning",
                    "summary": "GIT vulnerability | Carriage Return and RCE on cloning",
                    "url": "https://github.com/vignesh21-git/CVE-2025-48384"
                },
                {
                    "repository": "PoC-in-GitHub · vignesh21-git/CVE-2025-48384-submodule",
                    "author": "vignesh21-git",
                    "first_seen": "2025-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Test",
                    "summary": "Test",
                    "url": "https://github.com/vignesh21-git/CVE-2025-48384-submodule"
                },
                {
                    "repository": "PoC-in-GitHub · sathish46-lab/CVE-2025-48384-submodule",
                    "author": "sathish46-lab",
                    "first_seen": "2026-04-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-48384 repository",
                    "summary": "",
                    "url": "https://github.com/sathish46-lab/CVE-2025-48384-submodule"
                },
                {
                    "repository": "PoC-in-GitHub · iustin24/gitssrf-gim-cve-parent",
                    "author": "iustin24",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "gitssrf-gim CVE-2025-48384 parent",
                    "summary": "gitssrf-gim CVE-2025-48384 parent",
                    "url": "https://github.com/iustin24/gitssrf-gim-cve-parent"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/acheong08/CVE-2025-48384",
                "https://github.com/fishyyh/CVE-2025-48384",
                "https://github.com/kallydev/cve-2025-48384-hook",
                "https://github.com/fishyyh/CVE-2025-48384-POC",
                "https://github.com/liamg/CVE-2025-48384-submodule",
                "https://github.com/liamg/CVE-2025-48384",
                "https://github.com/ppd520/CVE-2025-48384",
                "https://github.com/NigelX/CVE-2025-48384",
                "https://github.com/greatyy/CVE-2025-48384-p",
                "https://github.com/testdjshan/CVE-2025-48384",
                "https://github.com/altm4n/cve-2025-48384",
                "https://github.com/altm4n/cve-2025-48384-hub",
                "https://github.com/vinieger/vinieger-CVE-2025-48384-Dockerfile",
                "https://github.com/ECHO6789/CVE-2025-48384-submodule",
                "https://github.com/nguyentranbaotran/cve-2025-48384-poc",
                "https://github.com/admin-ping/CVE-2025-48384-RCE",
                "https://github.com/Anezatraa/CVE-2025-48384-submodule",
                "https://github.com/IK-20211125/CVE-2025-48384",
                "https://github.com/elprogramadorgt/CVE-2025-48384",
                "https://github.com/fluoworite/CVE-2025-48384",
                "https://github.com/fluoworite/CVE-2025-48384-sub",
                "https://github.com/beishanxueyuan/CVE-2025-48384",
                "https://github.com/beishanxueyuan/CVE-2025-48384-test",
                "https://github.com/replicatorbot/CVE-2025-48384",
                "https://github.com/replicatorbot/CVE-2025-48384-POC",
                "https://github.com/eliox01/CVE-2025-48384",
                "https://github.com/jacobholtz/CVE-2025-48384-poc",
                "https://github.com/jacobholtz/CVE-2025-48384-submodule",
                "https://github.com/butyraldehyde/CVE-2025-48384-PoC-Part2",
                "https://github.com/butyraldehyde/CVE-2025-48384-PoC",
                "https://github.com/arun1033/CVE-2025-48384",
                "https://github.com/s41r4j/CVE-2025-48384",
                "https://github.com/s41r4j/CVE-2025-48384-submodule",
                "https://github.com/mukesh-610/cve-2025-48384-exploit",
                "https://github.com/mukesh-610/cve-2025-48384",
                "https://github.com/MarcoTondolo/cve-2025-48384-poc",
                "https://github.com/zr0n/CVE-2025-48384-sub",
                "https://github.com/zr0n/CVE-2025-48384-main",
                "https://github.com/vignesh21-git/CVE-2025-48384",
                "https://github.com/vignesh21-git/CVE-2025-48384-submodule",
                "https://github.com/sathish46-lab/CVE-2025-48384-submodule",
                "https://github.com/iustin24/gitssrf-gim-cve-parent"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-47981",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2025-47981 repository",
            "summary": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "updated_at": "2026-09-07T22:00:00Z",
            "published_at": "2026-09-07T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 32,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · HKenzoKimura/CVE-2025-47981",
                    "author": "HKenzoKimura",
                    "first_seen": "2026-09-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-47981 repository",
                    "summary": "",
                    "url": "https://github.com/HKenzoKimura/CVE-2025-47981"
                }
            ],
            "references": [
                "https://github.com/HKenzoKimura/CVE-2025-47981"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/HKenzoKimura/CVE-2025-47981"
                }
            ]
        },
        {
            "id": "CVE-2025-47809",
            "vendor": "Wibu",
            "product": "CodeMeter",
            "title": "CodeMeter vulnerability",
            "summary": "Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer.",
            "updated_at": "2026-09-08T09:17:37.580",
            "published_at": "2025-05-16T01:15:51.827",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 8.30a (custom); before * (custom); before V8.0 QU2 (custom); before V5.0 SP2 (custom); before V3.18 P032 (custom); before V3.19 P020 (custom); before V3.20 P008 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-272",
            "what_happened": "Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center component must be installed, and the CodeMeter Control Center component must not have been restarted. In this scenario, the local user can navigate from Import License to a privileged instance of Windows Explorer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.wibu.com/support/security-advisories/wibu-100120.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-201595.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-331739.html"
            ],
            "timeline": [
                {
                    "at": "2025-05-16T01:15:51.827",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47809"
                }
            ]
        },
        {
            "id": "CVE-2025-45480",
            "vendor": "projectfloodlight",
            "product": "Floodlight",
            "title": "Floodlight vulnerability",
            "summary": "Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.",
            "updated_at": "2026-09-13T19:16:52.553",
            "published_at": "2026-09-13T19:16:52.553",
            "cvss": 3,
            "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "71fe8a7e72096eb0fd96c1d814a04e3b7b782830 (git)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-669",
            "what_happened": "Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/floodlight/floodlight/issues/873"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T19:16:52.553",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45480"
                }
            ]
        },
        {
            "id": "CVE-2025-43426",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2025-43426",
            "summary": "Vulnerability in tools component with video and report available for CVE-2025-43426.",
            "updated_at": "2026-09-06T11:54:39Z",
            "published_at": "2026-09-06T11:54:39Z",
            "cvss": 5.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Vulnerability in tools component with video and report available for CVE-2025-43426.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-43426",
                    "summary": "Vulnerability in tools component with video and report available for CVE-2025-43426.",
                    "what_happened": "Vulnerability in tools component with video and report available for CVE-2025-43426.",
                    "cvss": 5.5,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CSRXAMFI-CVE-2025-43426",
                        "https://kitploit.com/hi/tools/github/csrxamfi/cve-2025-43426/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T13:54:39",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CSRXAMFI-CVE-2025-43426"
                },
                {
                    "title": "Exploit for CVE-2025-43426",
                    "summary": "Vulnerability in tools component with video and report available for CVE-2025-43426.",
                    "what_happened": "Vulnerability in tools component with video and report available for CVE-2025-43426.",
                    "cvss": 5.5,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CSRXAMFI-CVE-2025-43426",
                        "https://kitploit.com/hi/tools/github/csrxamfi/cve-2025-43426/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T13:54:39",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/csrxamfi/cve-2025-43426/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CSRXAMFI-CVE-2025-43426",
                "https://kitploit.com/hi/tools/github/csrxamfi/cve-2025-43426/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T11:54:39Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CSRXAMFI-CVE-2025-43426"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2025-41236",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2026-59346",
            "summary": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "updated_at": "2026-09-15T09:13:48Z",
            "published_at": "2026-09-15T09:13:48Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2026-59346",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 0,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=0F791A8F-6EAD-5EAB-8510-775EC1066789",
                        "https://github.com/0xCyberstan/CVE-2026-59346-POC"
                    ],
                    "repository": "Sploitus",
                    "author": "0xCyberstan",
                    "first_seen": "2026-09-15T11:13:48",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=0F791A8F-6EAD-5EAB-8510-775EC1066789"
                },
                {
                    "title": "Exploit for CVE-2026-59346",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 0,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=0F791A8F-6EAD-5EAB-8510-775EC1066789",
                        "https://github.com/0xCyberstan/CVE-2026-59346-POC"
                    ],
                    "repository": "0xCyberstan/CVE-2026-59346-POC",
                    "author": "0xCyberstan",
                    "first_seen": "2026-09-15T11:13:48",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/0xCyberstan/CVE-2026-59346-POC"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=0F791A8F-6EAD-5EAB-8510-775EC1066789",
                "https://github.com/0xCyberstan/CVE-2026-59346-POC"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T09:13:48Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=0F791A8F-6EAD-5EAB-8510-775EC1066789"
                }
            ]
        },
        {
            "id": "CVE-2025-40910",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Net::IP::LPM version 1.10 for Perl does not properly consider leading zero characters in IP CIDR address strings, which could allow attac...",
            "summary": "Net::IP::LPM version 1.10 for Perl does not properly consider leading zero characters in IP CIDR address strings, which could allow attackers to bypass access control that is based on IP addresses.\n\nLeading zeros are used to indicate octal numbers, which can confuse users who are intentionally using octal notation, as well as users who believe they are using decimal notation.",
            "updated_at": "2026-09-07T19:17:24.773",
            "published_at": "2025-06-27T13:15:24.667",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.10 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1287",
            "what_happened": "Net::IP::LPM version 1.10 for Perl does not properly consider leading zero characters in IP CIDR address strings, which could allow attackers to bypass access control that is based on IP addresses.\n\nLeading zeros are used to indicate octal numbers, which can confuse users who are intentionally using octal notation, as well as users who believe they are using decimal notation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/",
                "https://metacpan.org/release/RRWO/Net-IP-LPM-1.11/changes",
                "https://metacpan.org/release/TPODER/Net-IP-LPM-1.10/diff/TPODER/Net-IP-LPM-1.09/lib/Net/IP/LPM.pm",
                "https://rt.cpan.org/Ticket/Display.html?id=179855",
                "https://security.metacpan.org/patches/N/Net-IP-LPM/1.10/CVE-2025-40910-r1.patch"
            ],
            "timeline": [
                {
                    "at": "2025-06-27T13:15:24.667",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40910"
                }
            ]
        },
        {
            "id": "CVE-2025-40583",
            "vendor": "Siemens",
            "product": "SCALANCE LPE9403",
            "title": "SCALANCE LPE9403 vulnerability",
            "summary": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do transmit sensitive information in cleartext.\r\nThis could allow a privileged local attacker to retrieve this sensitive information.",
            "updated_at": "2026-09-08T09:17:37.253",
            "published_at": "2025-05-13T10:15:28.723",
            "cvss": 6.7,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before V2.1 HF0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-319",
            "what_happened": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do transmit sensitive information in cleartext.\r\nThis could allow a privileged local attacker to retrieve this sensitive information.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cert-portal.siemens.com/productcert/html/ssa-327438.html"
            ],
            "timeline": [
                {
                    "at": "2025-05-13T10:15:28.723",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40583"
                }
            ]
        },
        {
            "id": "CVE-2025-40582",
            "vendor": "Siemens",
            "product": "SCALANCE LPE9403",
            "title": "SCALANCE LPE9403 vulnerability",
            "summary": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters.\r\nThis could allow a non-privileged local attacker to execute root commands on the device.",
            "updated_at": "2026-09-08T09:17:36.933",
            "published_at": "2025-05-13T10:15:28.537",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before V2.1 HF0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters.\r\nThis could allow a non-privileged local attacker to execute root commands on the device.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cert-portal.siemens.com/productcert/html/ssa-327438.html"
            ],
            "timeline": [
                {
                    "at": "2025-05-13T10:15:28.537",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40582"
                }
            ]
        },
        {
            "id": "CVE-2025-40581",
            "vendor": "Siemens",
            "product": "SCALANCE LPE9403",
            "title": "SCALANCE LPE9403 vulnerability",
            "summary": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass.\r\nThis could allow a non-privileged local attacker to bypass the authentication of the SINEMA Remote Connect Edge Client, and to read and modify the configuration parameters.",
            "updated_at": "2026-09-08T09:17:36.583",
            "published_at": "2025-05-13T10:15:28.333",
            "cvss": 8.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before V2.1 HF0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-288",
            "what_happened": "A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass.\r\nThis could allow a non-privileged local attacker to bypass the authentication of the SINEMA Remote Connect Edge Client, and to read and modify the configuration parameters.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cert-portal.siemens.com/productcert/html/ssa-327438.html"
            ],
            "timeline": [
                {
                    "at": "2025-05-13T10:15:28.333",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40581"
                }
            ]
        },
        {
            "id": "CVE-2025-40196",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs: quota: create dedicated workqueue for quota_release_work\n\nThere is a kernel panic due to WARN_ONCE when panic_on_warn is set.\n\nThis issue occurs when writeback is triggered due to sync call for an\nopened file(ie, writeback reason is WB_REASON_SYNC). When f2fs balance\nis needed at sync path, flush for quota_release_work is triggered.\nBy default quota_release_work is queued to \"events_unbound\" queue which\ndoes not have WQ_MEM_RECLAIM flag. During f2fs balance \"writeback\"\nworkqueue tries to flush quota_release_work causing kernel panic due to\nMEM_RECLAIM flag mismatch errors.\n\nThis patch creates dedicated workqueue with WQ_MEM_RECLAIM flag\nfor work quota_release_work.\n\n------------[ cut here ]------------\nWARNING: CPU: 4 PID: 14867 at kernel/workqueue.c:3721 check_flush_dependency+0x13c/0x148\nCall trace:\n check_flush_dependency+0x13c/0x148\n __flush_work+0xd0/0x398\n flush_delayed_work+0x44/0x5c\n dquot_writeback_dquots+0x54/0x318\n f2fs_do_quota_sync+0xb8/0x1a8\n f2fs_write_checkpoint+0x3cc/0x99c\n f2fs_gc+0x190/0x750\n f2fs_balance_fs+0x110/0x168\n f2fs_write_single_data_page+0x474/0x7dc\n f2fs_write_data_pages+0x7d0/0xd0c\n do_writepages+0xe0/0x2f4\n __writeback_single_inode+0x44/0x4ac\n writeback_sb_inodes+0x30c/0x538\n wb_writeback+0xf4/0x440\n wb_workfn+0x128/0x5d4\n process_scheduled_works+0x1c4/0x45c\n worker_thread+0x32c/0x3e8\n kthread+0x11c/0x1b0\n ret_from_fork+0x10/0x20\nKernel panic - not syncing: kernel: panic_on_warn set ...",
            "updated_at": "2026-09-08T09:17:36.077",
            "published_at": "2025-11-12T22:15:46.673",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3e6ff207cd5bd924ad94cd1a7c633bcdac0ba1cb through before 8df2eedd371a1c24ecc4283581299d7737dfcd06 (git); bcacb52a985f1b6d280f698a470b873dfe52728a through before f846eacde280ecc3daedfe001580e3033565179e (git); 8ea87e34792258825d290f4dc5216276e91cb224 through before f12039df1515d5daf7d92e586ece5cefeb39561b (git); ac6f420291b3fee1113f21d612fa88b628afab5b through before 8a09a62f0c8c6123c2f1864ed6d5f9eb144afaf0 (git); ac6f420291b3fee1113f21d612fa88b628afab5b through before 72b7ceca857f38a8ca7c5629feffc63769638974 (git); a5abba5e0e586e258ded3e798fe5f69c66fec198 (git); 6f3821acd7c3143145999248087de5fb4b48cf26 (git); ab6cfcf8ed2c7496f55d020b65b1d8cd55d9a2cb (git); 6.1.120 through before 6.1.178 (semver); 6.6.64 through before 6.6.114 (semver); 6.12.4 through before 6.12.54 (semver); 5.4.287 through before 5.5 (semver); 5.10.231 through before 5.11 (semver); 5.15.174 through before 5.16 (semver); 6.13; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs: quota: create dedicated workqueue for quota_release_work\n\nThere is a kernel panic due to WARN_ONCE when panic_on_warn is set.\n\nThis issue occurs when writeback is triggered due to sync call for an\nopened file(ie, writeback reason is WB_REASON_SYNC). When f2fs balance\nis needed at sync path, flush for quota_release_work is triggered.\nBy default quota_release_work is queued to \"events_unbound\" queue which\ndoes not have WQ_MEM_RECLAIM flag. During f2fs balance \"writeback\"\nworkqueue tries to flush quota_release_work causing kernel panic due to\nMEM_RECLAIM flag mismatch errors.\n\nThis patch creates dedicated workqueue with WQ_MEM_RECLAIM flag\nfor work quota_release_work.\n\n------------[ cut here ]------------\nWARNING: CPU: 4 PID: 14867 at kernel/workqueue.c:3721 check_flush_dependency+0x13c/0x148\nCall trace:\n check_flush_dependency+0x13c/0x148\n __flush_work+0xd0/0x398\n flush_delayed_work+0x44/0x5c\n dquot_writeback_dquots+0x54/0x318\n f2fs_do_quota_sync+0xb8/0x1a8\n f2fs_write_checkpoint+0x3cc/0x99c\n f2fs_gc+0x190/0x750\n f2fs_balance_fs+0x110/0x168\n f2fs_write_single_data_page+0x474/0x7dc\n f2fs_write_data_pages+0x7d0/0xd0c\n do_writepages+0xe0/0x2f4\n __writeback_single_inode+0x44/0x4ac\n writeback_sb_inodes+0x30c/0x538\n wb_writeback+0xf4/0x440\n wb_workfn+0x128/0x5d4\n process_scheduled_works+0x1c4/0x45c\n worker_thread+0x32c/0x3e8\n kthread+0x11c/0x1b0\n ret_from_fork+0x10/0x20\nKernel panic - not syncing: kernel: panic_on_warn set ...",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/72b7ceca857f38a8ca7c5629feffc63769638974",
                "https://git.kernel.org/stable/c/8a09a62f0c8c6123c2f1864ed6d5f9eb144afaf0",
                "https://git.kernel.org/stable/c/8df2eedd371a1c24ecc4283581299d7737dfcd06",
                "https://git.kernel.org/stable/c/f12039df1515d5daf7d92e586ece5cefeb39561b",
                "https://git.kernel.org/stable/c/f846eacde280ecc3daedfe001580e3033565179e",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2025-11-12T22:15:46.673",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40196"
                }
            ]
        },
        {
            "id": "CVE-2025-40123",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Enforce expected_attach_type for tailcall compatibility\n\nYinhao et al. recently reported:\n\n  Our fuzzer tool discovered an uninitialized pointer issue in the\n  bpf_prog_test_run_xdp() function within the Linux kernel's BPF subsystem.\n  This leads to a NULL pointer dereference when a BPF program attempts to\n  deference the txq member of struct xdp_buff object.\n\nThe test initializes two programs of BPF_PROG_TYPE_XDP: progA acts as the\nentry point for bpf_prog_test_run_xdp() and its expected_attach_type can\nneither be of be BPF_XDP_DEVMAP nor BPF_XDP_CPUMAP. progA calls into a slot\nof a tailcall map it owns. progB's expected_attach_type must be BPF_XDP_DEVMAP\nto pass xdp_is_valid_access() validation. The program returns struct xdp_md's\negress_ifindex, and the latter is only allowed to be accessed under mentioned\nexpected_attach_type. progB is then inserted into the tailcall which progA\ncalls.\n\nThe underlying issue goes beyond XDP though. Another example are programs\nof type BPF_PROG_TYPE_CGROUP_SOCK_ADDR. sock_addr_is_valid_access() as well\nas sock_addr_func_proto() have different logic depending on the programs'\nexpected_attach_type. Similarly, a program attached to BPF_CGROUP_INET4_GETPEERNAME\nshould not be allowed doing a tailcall into a program which calls bpf_bind()\nout of BPF which is only enabled for BPF_CGROUP_INET4_CONNECT.\n\nIn short, specifying expected_attach_type allows to open up additional\nfunctionality or restrictions beyond what the basic bpf_prog_type enables.\nThe use of tailcalls must not violate these constraints. Fix it by enforcing\nexpected_attach_type in __bpf_prog_map_compatible().\n\nNote that we only enforce this for tailcall maps, but not for BPF devmaps or\ncpumaps: There, the programs are invoked through dev_map_bpf_prog_run*() and\ncpu_map_bpf_prog_run*() which set up a new environment / context and therefore\nthese situations are not prone to this issue.",
            "updated_at": "2026-09-14T12:17:37.453",
            "published_at": "2025-11-12T11:15:41.807",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5e43f899b03a3492ce5fc44e8900becb04dae9c0 through before e53a59e7cee5c1605d1ed595933098c2b69108f9 (git); 5e43f899b03a3492ce5fc44e8900becb04dae9c0 through before dc4f348952173beb8ceb15be30b249276eccb605 (git); 5e43f899b03a3492ce5fc44e8900becb04dae9c0 through before a99de19128aec0913f3d529f529fbbff5edfaff8 (git); 5e43f899b03a3492ce5fc44e8900becb04dae9c0 through before 08cb3dc9d2b44f153d0bcf2cb966e4a94b5d0f32 (git); 5e43f899b03a3492ce5fc44e8900becb04dae9c0 through before f856c598080ba7ce1252867b8ecd6ad5bdaf9a6a (git); 5e43f899b03a3492ce5fc44e8900becb04dae9c0 through before c1ad19b5d8e23123503dcaf2d4342e1b90b923ad (git); 5e43f899b03a3492ce5fc44e8900becb04dae9c0 through before 4540aed51b12bc13364149bf95f6ecef013197c0 (git); 4.17",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Enforce expected_attach_type for tailcall compatibility\n\nYinhao et al. recently reported:\n\n  Our fuzzer tool discovered an uninitialized pointer issue in the\n  bpf_prog_test_run_xdp() function within the Linux kernel's BPF subsystem.\n  This leads to a NULL pointer dereference when a BPF program attempts to\n  deference the txq member of struct xdp_buff object.\n\nThe test initializes two programs of BPF_PROG_TYPE_XDP: progA acts as the\nentry point for bpf_prog_test_run_xdp() and its expected_attach_type can\nneither be of be BPF_XDP_DEVMAP nor BPF_XDP_CPUMAP. progA calls into a slot\nof a tailcall map it owns. progB's expected_attach_type must be BPF_XDP_DEVMAP\nto pass xdp_is_valid_access() validation. The program returns struct xdp_md's\negress_ifindex, and the latter is only allowed to be accessed under mentioned\nexpected_attach_type. progB is then inserted into the tailcall which progA\ncalls.\n\nThe underlying issue goes beyond XDP though. Another example are programs\nof type BPF_PROG_TYPE_CGROUP_SOCK_ADDR. sock_addr_is_valid_access() as well\nas sock_addr_func_proto() have different logic depending on the programs'\nexpected_attach_type. Similarly, a program attached to BPF_CGROUP_INET4_GETPEERNAME\nshould not be allowed doing a tailcall into a program which calls bpf_bind()\nout of BPF which is only enabled for BPF_CGROUP_INET4_CONNECT.\n\nIn short, specifying expected_attach_type allows to open up additional\nfunctionality or restrictions beyond what the basic bpf_prog_type enables.\nThe use of tailcalls must not violate these constraints. Fix it by enforcing\nexpected_attach_type in __bpf_prog_map_compatible().\n\nNote that we only enforce this for tailcall maps, but not for BPF devmaps or\ncpumaps: There, the programs are invoked through dev_map_bpf_prog_run*() and\ncpu_map_bpf_prog_run*() which set up a new environment / context and therefore\nthese situations are not prone to this issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/08cb3dc9d2b44f153d0bcf2cb966e4a94b5d0f32",
                "https://git.kernel.org/stable/c/4540aed51b12bc13364149bf95f6ecef013197c0",
                "https://git.kernel.org/stable/c/a99de19128aec0913f3d529f529fbbff5edfaff8",
                "https://git.kernel.org/stable/c/c1ad19b5d8e23123503dcaf2d4342e1b90b923ad",
                "https://git.kernel.org/stable/c/dc4f348952173beb8ceb15be30b249276eccb605",
                "https://git.kernel.org/stable/c/e53a59e7cee5c1605d1ed595933098c2b69108f9",
                "https://git.kernel.org/stable/c/f856c598080ba7ce1252867b8ecd6ad5bdaf9a6a"
            ],
            "timeline": [
                {
                    "at": "2025-11-12T11:15:41.807",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40123"
                }
            ]
        },
        {
            "id": "CVE-2025-40074",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: start using dst_dev_rcu()\n\nChange icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF.\n\nChange ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(),\nipv4_neigh_lookup() to use lockdep enabled dst_dev_rcu().",
            "updated_at": "2026-09-14T12:17:37.307",
            "published_at": "2025-10-28T12:15:41.943",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36 through before e150f273cd8ed34ebc6d03758aad95c12fc58337 (git); 4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36 through before 684efb2c86c887685f9aa65e1a21b3df6c1f822d (git); 4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36 through before 923e0734c386984d45de508528a7a7ad91d791cc (git); 4a6ce2b6f2ecabbddcfe47e7cf61dd0f00b10e36 through before 6ad8de3cefdb6ffa6708b21c567df0dbf82c43a8 (git); 4.13",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: start using dst_dev_rcu()\n\nChange icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF.\n\nChange ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(),\nipv4_neigh_lookup() to use lockdep enabled dst_dev_rcu().",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/684efb2c86c887685f9aa65e1a21b3df6c1f822d",
                "https://git.kernel.org/stable/c/6ad8de3cefdb6ffa6708b21c567df0dbf82c43a8",
                "https://git.kernel.org/stable/c/923e0734c386984d45de508528a7a7ad91d791cc",
                "https://git.kernel.org/stable/c/e150f273cd8ed34ebc6d03758aad95c12fc58337"
            ],
            "timeline": [
                {
                    "at": "2025-10-28T12:15:41.943",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40074"
                }
            ]
        },
        {
            "id": "CVE-2025-39991",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load()\n\nIf ab->fw.m3_data points to data, then fw pointer remains null.\nFurther, if m3_mem is not allocated, then fw is dereferenced to be\npassed to ath11k_err function.\n\nReplace fw->size by m3_len.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.",
            "updated_at": "2026-09-14T12:17:37.187",
            "published_at": "2025-10-15T08:15:37.197",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "98e373dc08187c3f1cd97342b369fa2b0f24005e through before 7554d498e4283c3b4559795abd175eb24a84f47f (git); 7db88b962f06a52af5e9a32971012e8f3427cec0 through before 1f52119809b76d43759fc47da1cf708690b740a1 (git); 7db88b962f06a52af5e9a32971012e8f3427cec0 through before 888830b2cbc035838bebefe94502976da94332a5 (git); 7db88b962f06a52af5e9a32971012e8f3427cec0 through before 500fcc31e488d798937a23dbb1f62db46820c5b2 (git); 7db88b962f06a52af5e9a32971012e8f3427cec0 through before 3fd2ef2ae2b5c955584a3bee8e83ae7d7a98f782 (git); 6.7",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load()\n\nIf ab->fw.m3_data points to data, then fw pointer remains null.\nFurther, if m3_mem is not allocated, then fw is dereferenced to be\npassed to ath11k_err function.\n\nReplace fw->size by m3_len.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1f52119809b76d43759fc47da1cf708690b740a1",
                "https://git.kernel.org/stable/c/3fd2ef2ae2b5c955584a3bee8e83ae7d7a98f782",
                "https://git.kernel.org/stable/c/500fcc31e488d798937a23dbb1f62db46820c5b2",
                "https://git.kernel.org/stable/c/7554d498e4283c3b4559795abd175eb24a84f47f",
                "https://git.kernel.org/stable/c/888830b2cbc035838bebefe94502976da94332a5"
            ],
            "timeline": [
                {
                    "at": "2025-10-15T08:15:37.197",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39991"
                }
            ]
        },
        {
            "id": "CVE-2025-39862",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: fix list corruption after hardware restart\n\nSince stations are recreated from scratch, all lists that wcids are added\nto must be cleared before calling ieee80211_restart_hw.\nSet wcid->sta = 0 for each wcid entry in order to ensure that they are\nnot added again before they are ready.",
            "updated_at": "2026-09-14T12:17:36.960",
            "published_at": "2025-09-19T16:15:45.203",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8a55712d124fd8a919e8a69b70643e1a97280b4b through before 8fa8eb52bc2eb08d93202863b5fc478e0bebc00c (git); 8a55712d124fd8a919e8a69b70643e1a97280b4b through before 065c79df595af21d6d1b27d642860faa1d938774 (git); 3a931ebf67b89316c3b5bed2dca4479dd6f85803 (git); 6.1.188 through before 6.2 (semver); 6.2",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7915: fix list corruption after hardware restart\n\nSince stations are recreated from scratch, all lists that wcids are added\nto must be cleared before calling ieee80211_restart_hw.\nSet wcid->sta = 0 for each wcid entry in order to ensure that they are\nnot added again before they are ready.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/065c79df595af21d6d1b27d642860faa1d938774",
                "https://git.kernel.org/stable/c/8fa8eb52bc2eb08d93202863b5fc478e0bebc00c"
            ],
            "timeline": [
                {
                    "at": "2025-09-19T16:15:45.203",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-39862"
                }
            ]
        },
        {
            "id": "CVE-2025-38660",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\n[ceph] parse_longname(): strrchr() expects NUL-terminated string\n\n... and parse_longname() is not guaranteed that.  That's the reason\nwhy it uses kmemdup_nul() to build the argument for kstrtou64();\nthe problem is, kstrtou64() is not the only thing that need it.\n\nJust get a NUL-terminated copy of the entire thing and be done\nwith that...",
            "updated_at": "2026-09-14T12:17:36.787",
            "published_at": "2025-08-22T16:15:41.193",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "dd66df0053ef84add5e684df517aa9b498342381 through before 4b9aee707c4580511983a0998547f3b28514e6a6 (git); dd66df0053ef84add5e684df517aa9b498342381 through before bb80f7618832d26f7e395f52f82b1dac76223e5f (git); dd66df0053ef84add5e684df517aa9b498342381 through before 3145b2b11492d61c512bbc59660bb823bc757f48 (git); dd66df0053ef84add5e684df517aa9b498342381 through before 493479af8af3ab907f49e99323777d498a4fbd2b (git); dd66df0053ef84add5e684df517aa9b498342381 through before 101841c38346f4ca41dc1802c867da990ffb32eb (git); 6.6",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\n[ceph] parse_longname(): strrchr() expects NUL-terminated string\n\n... and parse_longname() is not guaranteed that.  That's the reason\nwhy it uses kmemdup_nul() to build the argument for kstrtou64();\nthe problem is, kstrtou64() is not the only thing that need it.\n\nJust get a NUL-terminated copy of the entire thing and be done\nwith that...",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/101841c38346f4ca41dc1802c867da990ffb32eb",
                "https://git.kernel.org/stable/c/3145b2b11492d61c512bbc59660bb823bc757f48",
                "https://git.kernel.org/stable/c/493479af8af3ab907f49e99323777d498a4fbd2b",
                "https://git.kernel.org/stable/c/4b9aee707c4580511983a0998547f3b28514e6a6",
                "https://git.kernel.org/stable/c/bb80f7618832d26f7e395f52f82b1dac76223e5f"
            ],
            "timeline": [
                {
                    "at": "2025-08-22T16:15:41.193",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38660"
                }
            ]
        },
        {
            "id": "CVE-2025-38621",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd: make rdev_addable usable for rcu mode\n\nOur testcase trigger panic:\n\nBUG: kernel NULL pointer dereference, address: 00000000000000e0\n...\nOops: Oops: 0000 [#1] SMP NOPTI\nCPU: 2 UID: 0 PID: 85 Comm: kworker/2:1 Not tainted 6.16.0+ #94\nPREEMPT(none)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n1.16.1-2.fc37 04/01/2014\nWorkqueue: md_misc md_start_sync\nRIP: 0010:rdev_addable+0x4d/0xf0\n...\nCall Trace:\n <TASK>\n md_start_sync+0x329/0x480\n process_one_work+0x226/0x6d0\n worker_thread+0x19e/0x340\n kthread+0x10f/0x250\n ret_from_fork+0x14d/0x180\n ret_from_fork_asm+0x1a/0x30\n </TASK>\nModules linked in: raid10\nCR2: 00000000000000e0\n---[ end trace 0000000000000000 ]---\nRIP: 0010:rdev_addable+0x4d/0xf0\n\nmd_spares_need_change in md_start_sync will call rdev_addable which\nprotected by rcu_read_lock/rcu_read_unlock. This rcu context will help\nprotect rdev won't be released, but rdev->mddev will be set to NULL\nbefore we call synchronize_rcu in md_kick_rdev_from_array. Fix this by\nusing READ_ONCE and check does rdev->mddev still alive.",
            "updated_at": "2026-09-07T16:17:27.777",
            "published_at": "2025-08-22T16:15:35.460",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "bc08041b32abe6c9824f78735bac22018eabfc06 through before d713e105a6137d3f54f09d4d9e2273482057ca17 (git); bc08041b32abe6c9824f78735bac22018eabfc06 through before b5fbe940862339cdcc34dea7a057ad18d18fa137 (git); bc08041b32abe6c9824f78735bac22018eabfc06 through before 13017b427118f4311471ee47df74872372ca8482 (git); 6.7",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd: make rdev_addable usable for rcu mode\n\nOur testcase trigger panic:\n\nBUG: kernel NULL pointer dereference, address: 00000000000000e0\n...\nOops: Oops: 0000 [#1] SMP NOPTI\nCPU: 2 UID: 0 PID: 85 Comm: kworker/2:1 Not tainted 6.16.0+ #94\nPREEMPT(none)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n1.16.1-2.fc37 04/01/2014\nWorkqueue: md_misc md_start_sync\nRIP: 0010:rdev_addable+0x4d/0xf0\n...\nCall Trace:\n <TASK>\n md_start_sync+0x329/0x480\n process_one_work+0x226/0x6d0\n worker_thread+0x19e/0x340\n kthread+0x10f/0x250\n ret_from_fork+0x14d/0x180\n ret_from_fork_asm+0x1a/0x30\n </TASK>\nModules linked in: raid10\nCR2: 00000000000000e0\n---[ end trace 0000000000000000 ]---\nRIP: 0010:rdev_addable+0x4d/0xf0\n\nmd_spares_need_change in md_start_sync will call rdev_addable which\nprotected by rcu_read_lock/rcu_read_unlock. This rcu context will help\nprotect rdev won't be released, but rdev->mddev will be set to NULL\nbefore we call synchronize_rcu in md_kick_rdev_from_array. Fix this by\nusing READ_ONCE and check does rdev->mddev still alive.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/13017b427118f4311471ee47df74872372ca8482",
                "https://git.kernel.org/stable/c/b5fbe940862339cdcc34dea7a057ad18d18fa137",
                "https://git.kernel.org/stable/c/d713e105a6137d3f54f09d4d9e2273482057ca17"
            ],
            "timeline": [
                {
                    "at": "2025-08-22T16:15:35.460",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38621"
                }
            ]
        },
        {
            "id": "CVE-2025-38591",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject narrower access to pointer ctx fields\n\nThe following BPF program, simplified from a syzkaller repro, causes a\nkernel warning:\n\n    r0 = *(u8 *)(r1 + 169);\n    exit;\n\nWith pointer field sk being at offset 168 in __sk_buff. This access is\ndetected as a narrower read in bpf_skb_is_valid_access because it\ndoesn't match offsetof(struct __sk_buff, sk). It is therefore allowed\nand later proceeds to bpf_convert_ctx_access. Note that for the\n\"is_narrower_load\" case in the convert_ctx_accesses(), the insn->off\nis aligned, so the cnt may not be 0 because it matches the\noffsetof(struct __sk_buff, sk) in the bpf_convert_ctx_access. However,\nthe target_size stays 0 and the verifier errors with a kernel warning:\n\n    verifier bug: error during ctx access conversion(1)\n\nThis patch fixes that to return a proper \"invalid bpf_context access\noff=X size=Y\" error on the load instruction.\n\nThe same issue affects multiple other fields in context structures that\nallow narrow access. Some other non-affected fields (for sk_msg,\nsk_lookup, and sockopt) were also changed to use bpf_ctx_range_ptr for\nconsistency.\n\nNote this syzkaller crash was reported in the \"Closes\" link below, which\nused to be about a different bug, fixed in\ncommit fce7bd8e385a (\"bpf/verifier: Handle BPF_LOAD_ACQ instructions\nin insn_def_regno()\"). Because syzbot somehow confused the two bugs,\nthe new crash and repro didn't get reported to the mailing list.",
            "updated_at": "2026-09-14T12:17:36.590",
            "published_at": "2025-08-19T17:15:36.790",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f96da09473b52c09125cc9bf7d7d4576ae8229e0 through before 7847c4140e06f6e87229faae22cc38525334c156 (git); f96da09473b52c09125cc9bf7d7d4576ae8229e0 through before feae34c992eb7191862fb1594c704fbbf650fef8 (git); f96da09473b52c09125cc9bf7d7d4576ae8229e0 through before 33660d44e789edb4f303210c813fc56d56377a90 (git); f96da09473b52c09125cc9bf7d7d4576ae8229e0 through before e2e9599f3503df7cf3569d2b6c50d5488fb59435 (git); f96da09473b52c09125cc9bf7d7d4576ae8229e0 through before 058a0da4f6d916a79b693384111bb80a90d73763 (git); f96da09473b52c09125cc9bf7d7d4576ae8229e0 through before 202900ceeef67458c964c2af6e1427c8e533ea7c (git); f96da09473b52c09125cc9bf7d7d4576ae8229e0 through before e09299225d5ba3916c91ef70565f7d2187e4cca0 (git); 4.13; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject narrower access to pointer ctx fields\n\nThe following BPF program, simplified from a syzkaller repro, causes a\nkernel warning:\n\n    r0 = *(u8 *)(r1 + 169);\n    exit;\n\nWith pointer field sk being at offset 168 in __sk_buff. This access is\ndetected as a narrower read in bpf_skb_is_valid_access because it\ndoesn't match offsetof(struct __sk_buff, sk). It is therefore allowed\nand later proceeds to bpf_convert_ctx_access. Note that for the\n\"is_narrower_load\" case in the convert_ctx_accesses(), the insn->off\nis aligned, so the cnt may not be 0 because it matches the\noffsetof(struct __sk_buff, sk) in the bpf_convert_ctx_access. However,\nthe target_size stays 0 and the verifier errors with a kernel warning:\n\n    verifier bug: error during ctx access conversion(1)\n\nThis patch fixes that to return a proper \"invalid bpf_context access\noff=X size=Y\" error on the load instruction.\n\nThe same issue affects multiple other fields in context structures that\nallow narrow access. Some other non-affected fields (for sk_msg,\nsk_lookup, and sockopt) were also changed to use bpf_ctx_range_ptr for\nconsistency.\n\nNote this syzkaller crash was reported in the \"Closes\" link below, which\nused to be about a different bug, fixed in\ncommit fce7bd8e385a (\"bpf/verifier: Handle BPF_LOAD_ACQ instructions\nin insn_def_regno()\"). Because syzbot somehow confused the two bugs,\nthe new crash and repro didn't get reported to the mailing list.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/058a0da4f6d916a79b693384111bb80a90d73763",
                "https://git.kernel.org/stable/c/202900ceeef67458c964c2af6e1427c8e533ea7c",
                "https://git.kernel.org/stable/c/33660d44e789edb4f303210c813fc56d56377a90",
                "https://git.kernel.org/stable/c/7847c4140e06f6e87229faae22cc38525334c156",
                "https://git.kernel.org/stable/c/e09299225d5ba3916c91ef70565f7d2187e4cca0",
                "https://git.kernel.org/stable/c/e2e9599f3503df7cf3569d2b6c50d5488fb59435",
                "https://git.kernel.org/stable/c/feae34c992eb7191862fb1594c704fbbf650fef8",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2025-08-19T17:15:36.790",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38591"
                }
            ]
        },
        {
            "id": "CVE-2025-38502",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Out-of-bounds Read in Linux Linux_Kernel CVE-2025-3850 CVE-2025-38502",
            "summary": "Out-of-bounds read in Linux kernel BPF cgroup storage via tail calls enabling privilege escalation.",
            "updated_at": "2026-09-11T17:12:46Z",
            "published_at": "2026-09-11T17:12:46Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 42,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "Out-of-bounds read in Linux kernel BPF cgroup storage via tail calls enabling privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Out-of-bounds Read in Linux Linux_Kernel CVE-2025-3850 CVE-2025-38502",
                    "summary": "Out-of-bounds read in Linux kernel BPF cgroup storage via tail calls enabling privilege escalation.",
                    "what_happened": "Out-of-bounds read in Linux kernel BPF cgroup storage via tail calls enabling privilege escalation.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-125",
                    "references": [
                        "https://sploitus.com/exploit?id=8FF551F8-DFC3-5F10-95CB-6ECABBDF76C7",
                        "https://github.com/abraxas/CVE-2025-38502-Linux-LPE"
                    ],
                    "repository": "abraxas/CVE-2025-38502-Linux-LPE",
                    "author": "abraxas",
                    "first_seen": "2026-09-11T19:12:46",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/abraxas/CVE-2025-38502-Linux-LPE"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-11T18:56:40+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Exploit for Out-of-bounds Read in Linux Linux_Kernel",
                    "summary": "Proof-of-concept exploit for CVE-2025-3850 and CVE-2025-38502. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=8FF551F8-DFC3-5F10-95CB-6ECABBDF76C7"
                }
            ],
            "references": [
                "https://github.com/abraxas/CVE-2025-38502-Linux-LPE",
                "https://sploitus.com/exploit?id=8FF551F8-DFC3-5F10-95CB-6ECABBDF76C7"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T17:12:46Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://github.com/abraxas/CVE-2025-38502-Linux-LPE"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-38352",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nposix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()\n\nIf an exiting non-autoreaping task has already passed exit_notify() and\ncalls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent\nor debugger right after unlock_task_sighand().\n\nIf a concurrent posix_cpu_timer_del() runs at that moment, it won't be\nable to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or\nlock_task_sighand() will fail.\n\nAdd the tsk->exit_state check into run_posix_cpu_timers() to fix this.\n\nThis fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because\nexit_task_work() is called before exit_notify(). But the check still\nmakes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail\nanyway in this case.",
            "updated_at": "2026-09-08T18:17:32.447",
            "published_at": "2025-07-22T08:15:23.577",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 78a4b8e3795b31dae58762bc091bb0f4f74a2200 (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before c076635b3a42771ace7d276de8dc3bc76ee2ba1b (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 2f3daa04a9328220de46f0d5c919a6c0073a9f0b (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 764a7a5dfda23f69919441f2eac2a83e7db6e5bb (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 2c72fe18cc5f9f1750f5bc148cf1c94c29e106ff (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before c29d5318708e67ac13c1b6fc1007d179fb65b4d7 (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before 460188bc042a3f40f72d34b9f7fc6ee66b0b757b (git); 0bdd2ed4138ec04e09b4f8165981efc99e439f55 through before f90fff1e152dedf52b932240ebbd670d83330eca (git); 2.6.36",
            "fixed": "See vendor advisory",
            "source_count": 190,
            "kev": true,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-367",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nposix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del()\n\nIf an exiting non-autoreaping task has already passed exit_notify() and\ncalls handle_posix_cpu_timers() from IRQ, it can be reaped by its parent\nor debugger right after unlock_task_sighand().\n\nIf a concurrent posix_cpu_timer_del() runs at that moment, it won't be\nable to detect timer->it.cpu.firing != 0: cpu_timer_task_rcu() and/or\nlock_task_sighand() will fail.\n\nAdd the tsk->exit_state check into run_posix_cpu_timers() to fix this.\n\nThis fix is not needed if CONFIG_POSIX_CPU_TIMERS_TASK_WORK=y, because\nexit_task_work() is called before exit_notify(). But the check still\nmakes sense, task_work_add(&tsk->posix_cputimers_work.work) will fail\nanyway in this case.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · farazsth98/chronomaly",
                    "author": "farazsth98",
                    "first_seen": "2026-01-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 313,
                    "title": "Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.",
                    "summary": "Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.",
                    "url": "https://github.com/farazsth98/chronomaly"
                },
                {
                    "repository": "PoC-in-GitHub · farazsth98/poc-CVE-2025-38352",
                    "author": "farazsth98",
                    "first_seen": "2025-12-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 117,
                    "title": "This is a proof of concept for CVE-2025-38352, a vulnerability in the Linux kernel's POSIX CPU timers implementation. The September 2025 Android Bulletin mentions that this vulnerability has been used in limited, targeted exploitation in the wild.",
                    "summary": "This is a proof of concept for CVE-2025-38352, a vulnerability in the Linux kernel's POSIX CPU timers implementation. The September 2025 Android Bulletin mentions that this vulnerability has been used in limited, targeted exploitation in the wild.",
                    "url": "https://github.com/farazsth98/poc-CVE-2025-38352"
                },
                {
                    "repository": "PoC-in-GitHub · Crime2/poc-CVE-2025-38352",
                    "author": "Crime2",
                    "first_seen": "2026-01-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-38352 repository",
                    "summary": "",
                    "url": "https://github.com/Crime2/poc-CVE-2025-38352"
                },
                {
                    "repository": "PoC-in-GitHub · jordelmir/Elysium-Vanguard-Sentinel-Audit",
                    "author": "jordelmir",
                    "first_seen": "2026-02-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "The official Sentinel Edition v7.11 - Hypervisor Detection & Kernel Memory Audit Suite for Honor Magic V2. Investigating CVE-2025-38352 and EL2 RKP defenses.",
                    "summary": "The official Sentinel Edition v7.11 - Hypervisor Detection & Kernel Memory Audit Suite for Honor Magic V2. Investigating CVE-2025-38352 and EL2 RKP defenses.",
                    "url": "https://github.com/jordelmir/Elysium-Vanguard-Sentinel-Audit"
                },
                {
                    "repository": "PoC-in-GitHub · AnalyticETH/chronomaly-webos",
                    "author": "AnalyticETH",
                    "first_seen": "2026-05-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 15,
                    "title": "CVE-2025-38352 kernel exploit for LG webOS Smart TVs (ARM64). Achieves persistent root on real consumer hardware with novel exploitation techniques. Responsibly disclosed to LG.",
                    "summary": "CVE-2025-38352 kernel exploit for LG webOS Smart TVs (ARM64). Achieves persistent root on real consumer hardware with novel exploitation techniques. Responsibly disclosed to LG.",
                    "url": "https://github.com/AnalyticETH/chronomaly-webos"
                },
                {
                    "title": "Exploit for Time-of-check Time-of-use (TOCTOU) Race Condition in Linux Linux_Kernel CVE-2025-38352",
                    "summary": "TOCTOU race in Linux kernel POSIX CPU timers causing UAF and kernel crash.",
                    "what_happened": "TOCTOU race in Linux kernel POSIX CPU timers causing UAF and kernel crash.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=7CC97944-9FC4-50A6-9166-E0341C45386E",
                        "https://github.com/longwasu/CVE-2025-38352-PoC"
                    ],
                    "repository": "longwasu/CVE-2025-38352-PoC",
                    "author": "longwasu",
                    "first_seen": "2026-09-13T10:13:59",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/longwasu/CVE-2025-38352-PoC"
                },
                {
                    "title": "Exploit for Time-of-check Time-of-use (TOCTOU) Race Condition in Linux Linux_Kernel CVE-2025-38352",
                    "summary": "TOCTOU race in Linux kernel POSIX CPU timers causing UAF and kernel crash.",
                    "what_happened": "TOCTOU race in Linux kernel POSIX CPU timers causing UAF and kernel crash.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=7CC97944-9FC4-50A6-9166-E0341C45386E",
                        "https://github.com/longwasu/CVE-2025-38352-PoC"
                    ],
                    "repository": "Sploitus",
                    "author": "longwasu",
                    "first_seen": "2026-09-13T10:13:59",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=7CC97944-9FC4-50A6-9166-E0341C45386E"
                }
            ],
            "references": [
                "https://git.kernel.org/stable/c/2c72fe18cc5f9f1750f5bc148cf1c94c29e106ff",
                "https://git.kernel.org/stable/c/2f3daa04a9328220de46f0d5c919a6c0073a9f0b",
                "https://git.kernel.org/stable/c/460188bc042a3f40f72d34b9f7fc6ee66b0b757b",
                "https://git.kernel.org/stable/c/764a7a5dfda23f69919441f2eac2a83e7db6e5bb",
                "https://git.kernel.org/stable/c/78a4b8e3795b31dae58762bc091bb0f4f74a2200",
                "https://git.kernel.org/stable/c/c076635b3a42771ace7d276de8dc3bc76ee2ba1b",
                "https://git.kernel.org/stable/c/c29d5318708e67ac13c1b6fc1007d179fb65b4d7",
                "https://git.kernel.org/stable/c/f90fff1e152dedf52b932240ebbd670d83330eca",
                "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html",
                "https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html",
                "https://github.com/farazsth98/chronomaly",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-38352",
                "https://github.com/farazsth98/poc-CVE-2025-38352",
                "https://github.com/Crime2/poc-CVE-2025-38352",
                "https://github.com/jordelmir/Elysium-Vanguard-Sentinel-Audit",
                "https://github.com/AnalyticETH/chronomaly-webos",
                "https://github.com/longwasu/CVE-2025-38352-PoC",
                "https://sploitus.com/exploit?id=7CC97944-9FC4-50A6-9166-E0341C45386E"
            ],
            "timeline": [
                {
                    "at": "2025-07-22T08:15:23.577",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38352"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-38266",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: mediatek: eint: Fix invalid pointer dereference for v1 platforms\n\nCommit 3ef9f710efcb (\"pinctrl: mediatek: Add EINT support for multiple\naddresses\") introduced an access to the 'soc' field of struct\nmtk_pinctrl in mtk_eint_do_init() and for that an include of\npinctrl-mtk-common-v2.h.\n\nHowever, pinctrl drivers relying on the v1 common driver include\npinctrl-mtk-common.h instead, which provides another definition of\nstruct mtk_pinctrl that does not contain an 'soc' field.\n\nSince mtk_eint_do_init() can be called both by v1 and v2 drivers, it\nwill now try to dereference an invalid pointer when called on v1\nplatforms. This has been observed on Genio 350 EVK (MT8365), which\ncrashes very early in boot (the kernel trace can only be seen with\nearlycon).\n\nIn order to fix this, since 'struct mtk_pinctrl' was only needed to get\na 'struct mtk_eint_pin', make 'struct mtk_eint_pin' a parameter\nof mtk_eint_do_init() so that callers need to supply it, removing\nmtk_eint_do_init()'s dependency on any particular 'struct mtk_pinctrl'.",
            "updated_at": "2026-09-14T12:17:36.437",
            "published_at": "2025-07-10T08:15:24.727",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3cc64c13deb38080afc6b37060e825d4fe0a4737 through before eae2b12df3aac874566f7025799ca4219572e44c (git); 7586766229354983cf5572f81295e69bf5abccf5 through before e578bbff985822573a27d4b7c9ec858e6014d033 (git); 00f864b4b5ce3c50f3217626c8de97fbda1b2ea6 through before abe8ad6a1a00c5c7be28b038d0ede0bdcacd8610 (git); 3ef9f710efcb5cc1335b5b09c16c757f703d7e5f through before 9ebe21ede792cef851847648962c363cac67d17f (git); 3ef9f710efcb5cc1335b5b09c16c757f703d7e5f through before 1c9977b263475373b31bbf86af94a5c9ae2be42c (git); 6.15",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: mediatek: eint: Fix invalid pointer dereference for v1 platforms\n\nCommit 3ef9f710efcb (\"pinctrl: mediatek: Add EINT support for multiple\naddresses\") introduced an access to the 'soc' field of struct\nmtk_pinctrl in mtk_eint_do_init() and for that an include of\npinctrl-mtk-common-v2.h.\n\nHowever, pinctrl drivers relying on the v1 common driver include\npinctrl-mtk-common.h instead, which provides another definition of\nstruct mtk_pinctrl that does not contain an 'soc' field.\n\nSince mtk_eint_do_init() can be called both by v1 and v2 drivers, it\nwill now try to dereference an invalid pointer when called on v1\nplatforms. This has been observed on Genio 350 EVK (MT8365), which\ncrashes very early in boot (the kernel trace can only be seen with\nearlycon).\n\nIn order to fix this, since 'struct mtk_pinctrl' was only needed to get\na 'struct mtk_eint_pin', make 'struct mtk_eint_pin' a parameter\nof mtk_eint_do_init() so that callers need to supply it, removing\nmtk_eint_do_init()'s dependency on any particular 'struct mtk_pinctrl'.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1c9977b263475373b31bbf86af94a5c9ae2be42c",
                "https://git.kernel.org/stable/c/9ebe21ede792cef851847648962c363cac67d17f",
                "https://git.kernel.org/stable/c/abe8ad6a1a00c5c7be28b038d0ede0bdcacd8610",
                "https://git.kernel.org/stable/c/e578bbff985822573a27d4b7c9ec858e6014d033",
                "https://git.kernel.org/stable/c/eae2b12df3aac874566f7025799ca4219572e44c"
            ],
            "timeline": [
                {
                    "at": "2025-07-10T08:15:24.727",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38266"
                }
            ]
        },
        {
            "id": "CVE-2025-38205",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid divide by zero by initializing dummy pitch to 1\n\n[Why]\nIf the dummy values in `populate_dummy_dml_surface_cfg()` aren't updated\nthen they can lead to a divide by zero in downstream callers like\nCalculateVMAndRowBytes()\n\n[How]\nInitialize dummy value to a value to avoid divide by zero.",
            "updated_at": "2026-09-07T16:17:27.650",
            "published_at": "2025-07-04T14:15:28.540",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7966f319c66d9468623c6a6a017ecbc0dd79be75 through before 03a3dbca3b8e55b88958ce1f54aaf678ded11c79 (git); 7966f319c66d9468623c6a6a017ecbc0dd79be75 through before 8044f981b2cf8c32fe1bd5d1fc991552cdf7ffe0 (git); 7966f319c66d9468623c6a6a017ecbc0dd79be75 through before 7e40f64896e8e3dca471e287672db5ace12ea0be (git); 6.7",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-369",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Avoid divide by zero by initializing dummy pitch to 1\n\n[Why]\nIf the dummy values in `populate_dummy_dml_surface_cfg()` aren't updated\nthen they can lead to a divide by zero in downstream callers like\nCalculateVMAndRowBytes()\n\n[How]\nInitialize dummy value to a value to avoid divide by zero.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/03a3dbca3b8e55b88958ce1f54aaf678ded11c79",
                "https://git.kernel.org/stable/c/7e40f64896e8e3dca471e287672db5ace12ea0be",
                "https://git.kernel.org/stable/c/8044f981b2cf8c32fe1bd5d1fc991552cdf7ffe0"
            ],
            "timeline": [
                {
                    "at": "2025-07-04T14:15:28.540",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38205"
                }
            ]
        },
        {
            "id": "CVE-2025-38097",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nespintcp: remove encap socket caching to avoid reference leak\n\nThe current scheme for caching the encap socket can lead to reference\nleaks when we try to delete the netns.\n\nThe reference chain is: xfrm_state -> enacp_sk -> netns\n\nSince the encap socket is a userspace socket, it holds a reference on\nthe netns. If we delete the espintcp state (through flush or\nindividual delete) before removing the netns, the reference on the\nsocket is dropped and the netns is correctly deleted. Otherwise, the\nnetns may not be reachable anymore (if all processes within the ns\nhave terminated), so we cannot delete the xfrm state to drop its\nreference on the socket.\n\nThis patch results in a small (~2% in my tests) performance\nregression.\n\nA GC-type mechanism could be added for the socket cache, to clear\nreferences if the state hasn't been used \"recently\", but it's a lot\nmore complex than just not caching the socket.",
            "updated_at": "2026-09-14T12:17:36.207",
            "published_at": "2025-07-03T09:15:23.030",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 through before e32bafd08ee35feacd47b05cc5bfe9cd9659cd25 (git); e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 through before 9673ca00e6c5503069dc98780e2e89db0e663c16 (git); e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 through before e4cde54b46a87231c77256a633be1bef62687d69 (git); e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 through before b58a295d10065960bcb9d60cb8ca6ead9837cd27 (git); e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 through before 9cbca30102028f9ad3d2098f935c4368f581fd07 (git); e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 through before 74fd327767fb784c5875cf7c4ba1217f26020943 (git); e27cca96cd68fa2c6814c90f9a1cfd36bb68c593 through before 028363685bd0b7a19b4a820f82dd905b1dc83999 (git); 5.6",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nespintcp: remove encap socket caching to avoid reference leak\n\nThe current scheme for caching the encap socket can lead to reference\nleaks when we try to delete the netns.\n\nThe reference chain is: xfrm_state -> enacp_sk -> netns\n\nSince the encap socket is a userspace socket, it holds a reference on\nthe netns. If we delete the espintcp state (through flush or\nindividual delete) before removing the netns, the reference on the\nsocket is dropped and the netns is correctly deleted. Otherwise, the\nnetns may not be reachable anymore (if all processes within the ns\nhave terminated), so we cannot delete the xfrm state to drop its\nreference on the socket.\n\nThis patch results in a small (~2% in my tests) performance\nregression.\n\nA GC-type mechanism could be added for the socket cache, to clear\nreferences if the state hasn't been used \"recently\", but it's a lot\nmore complex than just not caching the socket.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/028363685bd0b7a19b4a820f82dd905b1dc83999",
                "https://git.kernel.org/stable/c/74fd327767fb784c5875cf7c4ba1217f26020943",
                "https://git.kernel.org/stable/c/9673ca00e6c5503069dc98780e2e89db0e663c16",
                "https://git.kernel.org/stable/c/9cbca30102028f9ad3d2098f935c4368f581fd07",
                "https://git.kernel.org/stable/c/b58a295d10065960bcb9d60cb8ca6ead9837cd27",
                "https://git.kernel.org/stable/c/e32bafd08ee35feacd47b05cc5bfe9cd9659cd25",
                "https://git.kernel.org/stable/c/e4cde54b46a87231c77256a633be1bef62687d69",
                "https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html"
            ],
            "timeline": [
                {
                    "at": "2025-07-03T09:15:23.030",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-38097"
                }
            ]
        },
        {
            "id": "CVE-2025-37833",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads\n\nFix niu_try_msix() to not cause a fatal trap on sparc systems.\n\nSet PCI_DEV_FLAGS_MSIX_TOUCH_ENTRY_DATA_FIRST on the struct pci_dev to\nwork around a bug in the hardware or firmware.\n\nFor each vector entry in the msix table, niu chips will cause a fatal\ntrap if any registers in that entry are read before that entries'\nENTRY_DATA register is written to. Testing indicates writes to other\nregisters are not sufficient to prevent the fatal trap, however the value\ndoes not appear to matter. This only needs to happen once after power up,\nso simply rebooting into a kernel lacking this fix will NOT cause the\ntrap.\n\nNON-RESUMABLE ERROR: Reporting on cpu 64\nNON-RESUMABLE ERROR: TPC [0x00000000005f6900] <msix_prepare_msi_desc+0x90/0xa0>\nNON-RESUMABLE ERROR: RAW [4010000000000016:00000e37f93e32ff:0000000202000080:ffffffffffffffff\nNON-RESUMABLE ERROR:      0000000800000000:0000000000000000:0000000000000000:0000000000000000]\nNON-RESUMABLE ERROR: handle [0x4010000000000016] stick [0x00000e37f93e32ff]\nNON-RESUMABLE ERROR: type [precise nonresumable]\nNON-RESUMABLE ERROR: attrs [0x02000080] < ASI sp-faulted priv >\nNON-RESUMABLE ERROR: raddr [0xffffffffffffffff]\nNON-RESUMABLE ERROR: insn effective address [0x000000c50020000c]\nNON-RESUMABLE ERROR: size [0x8]\nNON-RESUMABLE ERROR: asi [0x00]\nCPU: 64 UID: 0 PID: 745 Comm: kworker/64:1 Not tainted 6.11.5 #63\nWorkqueue: events work_for_cpu_fn\nTSTATE: 0000000011001602 TPC: 00000000005f6900 TNPC: 00000000005f6904 Y: 00000000    Not tainted\nTPC: <msix_prepare_msi_desc+0x90/0xa0>\ng0: 00000000000002e9 g1: 000000000000000c g2: 000000c50020000c g3: 0000000000000100\ng4: ffff8000470307c0 g5: ffff800fec5be000 g6: ffff800047a08000 g7: 0000000000000000\no0: ffff800014feb000 o1: ffff800047a0b620 o2: 0000000000000011 o3: ffff800047a0b620\no4: 0000000000000080 o5: 0000000000000011 sp: ffff800047a0ad51 ret_pc: 00000000005f7128\nRPC: <__pci_enable_msix_range+0x3cc/0x460>\nl0: 000000000000000d l1: 000000000000c01f l2: ffff800014feb0a8 l3: 0000000000000020\nl4: 000000000000c000 l5: 0000000000000001 l6: 0000000020000000 l7: ffff800047a0b734\ni0: ffff800014feb000 i1: ffff800047a0b730 i2: 0000000000000001 i3: 000000000000000d\ni4: 0000000000000000 i5: 0000000000000000 i6: ffff800047a0ae81 i7: 00000000101888b0\nI7: <niu_try_msix.constprop.0+0xc0/0x130 [niu]>\nCall Trace:\n[<00000000101888b0>] niu_try_msix.constprop.0+0xc0/0x130 [niu]\n[<000000001018f840>] niu_get_invariants+0x183c/0x207c [niu]\n[<00000000101902fc>] niu_pci_init_one+0x27c/0x2fc [niu]\n[<00000000005ef3e4>] local_pci_probe+0x28/0x74\n[<0000000000469240>] work_for_cpu_fn+0x8/0x1c\n[<000000000046b008>] process_scheduled_works+0x144/0x210\n[<000000000046b518>] worker_thread+0x13c/0x1c0\n[<00000000004710e0>] kthread+0xb8/0xc8\n[<00000000004060c8>] ret_from_fork+0x1c/0x2c\n[<0000000000000000>] 0x0\nKernel panic - not syncing: Non-resumable error.",
            "updated_at": "2026-09-14T12:17:36.000",
            "published_at": "2025-05-08T07:15:54.533",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7d5ec3d3612396dc6d4b76366d20ab9fc06f399f through before 52a266008a9450e4222994666b4510c026fbb03c (git); 7d5ec3d3612396dc6d4b76366d20ab9fc06f399f through before 0afd48b173bebd6d94769ba2c91bd7404b9eb3c9 (git); 7d5ec3d3612396dc6d4b76366d20ab9fc06f399f through before c187aaa9e79b4b6d86ac7ba941e579ad33df5538 (git); 7d5ec3d3612396dc6d4b76366d20ab9fc06f399f through before 64903e4849a71cf7f7c7e5d45225ccefc1280929 (git); 7d5ec3d3612396dc6d4b76366d20ab9fc06f399f through before fbb429ddff5c8e479edcc7dde5a542c9295944e6 (git); e6454fd429b0ba6513ac1de27a0bd6ccac021a40 (git); 3590d16b47ac561a4f2504befe43def10ed1814c (git); e1d5e8a561baaafed6e35d72a6ad53d248580d6c (git); 3b570884c868c12e3184627ce4b4a167e9d6f018 (git); 1866c8f6d43c3c6ffa2bfe086b65392b3a3fafb1 (git); aa8092c1d1f142f797995d0448afb73a5148f4ae (git); 6c971252f09040af40d20851cf4e14018e6710d9 (git); 4.4.282 through before 4.5 (semver); 4.9.281 through before 4.10 (semver); 4.14.245 through before 4.15 (semver); 4.19.205 through before 4.20 (semver); 5.4.142 through before 5.5 (semver); 5.10.60 through before 5.11 (semver); 5.13.12 through before 5.14 (semver); 5.14",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads\n\nFix niu_try_msix() to not cause a fatal trap on sparc systems.\n\nSet PCI_DEV_FLAGS_MSIX_TOUCH_ENTRY_DATA_FIRST on the struct pci_dev to\nwork around a bug in the hardware or firmware.\n\nFor each vector entry in the msix table, niu chips will cause a fatal\ntrap if any registers in that entry are read before that entries'\nENTRY_DATA register is written to. Testing indicates writes to other\nregisters are not sufficient to prevent the fatal trap, however the value\ndoes not appear to matter. This only needs to happen once after power up,\nso simply rebooting into a kernel lacking this fix will NOT cause the\ntrap.\n\nNON-RESUMABLE ERROR: Reporting on cpu 64\nNON-RESUMABLE ERROR: TPC [0x00000000005f6900] <msix_prepare_msi_desc+0x90/0xa0>\nNON-RESUMABLE ERROR: RAW [4010000000000016:00000e37f93e32ff:0000000202000080:ffffffffffffffff\nNON-RESUMABLE ERROR:      0000000800000000:0000000000000000:0000000000000000:0000000000000000]\nNON-RESUMABLE ERROR: handle [0x4010000000000016] stick [0x00000e37f93e32ff]\nNON-RESUMABLE ERROR: type [precise nonresumable]\nNON-RESUMABLE ERROR: attrs [0x02000080] < ASI sp-faulted priv >\nNON-RESUMABLE ERROR: raddr [0xffffffffffffffff]\nNON-RESUMABLE ERROR: insn effective address [0x000000c50020000c]\nNON-RESUMABLE ERROR: size [0x8]\nNON-RESUMABLE ERROR: asi [0x00]\nCPU: 64 UID: 0 PID: 745 Comm: kworker/64:1 Not tainted 6.11.5 #63\nWorkqueue: events work_for_cpu_fn\nTSTATE: 0000000011001602 TPC: 00000000005f6900 TNPC: 00000000005f6904 Y: 00000000    Not tainted\nTPC: <msix_prepare_msi_desc+0x90/0xa0>\ng0: 00000000000002e9 g1: 000000000000000c g2: 000000c50020000c g3: 0000000000000100\ng4: ffff8000470307c0 g5: ffff800fec5be000 g6: ffff800047a08000 g7: 0000000000000000\no0: ffff800014feb000 o1: ffff800047a0b620 o2: 0000000000000011 o3: ffff800047a0b620\no4: 0000000000000080 o5: 0000000000000011 sp: ffff800047a0ad51 ret_pc: 00000000005f7128\nRPC: <__pci_enable_msix_range+0x3cc/0x460>\nl0: 000000000000000d l1: 000000000000c01f l2: ffff800014feb0a8 l3: 0000000000000020\nl4: 000000000000c000 l5: 0000000000000001 l6: 0000000020000000 l7: ffff800047a0b734\ni0: ffff800014feb000 i1: ffff800047a0b730 i2: 0000000000000001 i3: 000000000000000d\ni4: 0000000000000000 i5: 0000000000000000 i6: ffff800047a0ae81 i7: 00000000101888b0\nI7: <niu_try_msix.constprop.0+0xc0/0x130 [niu]>\nCall Trace:\n[<00000000101888b0>] niu_try_msix.constprop.0+0xc0/0x130 [niu]\n[<000000001018f840>] niu_get_invariants+0x183c/0x207c [niu]\n[<00000000101902fc>] niu_pci_init_one+0x27c/0x2fc [niu]\n[<00000000005ef3e4>] local_pci_probe+0x28/0x74\n[<0000000000469240>] work_for_cpu_fn+0x8/0x1c\n[<000000000046b008>] process_scheduled_works+0x144/0x210\n[<000000000046b518>] worker_thread+0x13c/0x1c0\n[<00000000004710e0>] kthread+0xb8/0xc8\n[<00000000004060c8>] ret_from_fork+0x1c/0x2c\n[<0000000000000000>] 0x0\nKernel panic - not syncing: Non-resumable error.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0afd48b173bebd6d94769ba2c91bd7404b9eb3c9",
                "https://git.kernel.org/stable/c/52a266008a9450e4222994666b4510c026fbb03c",
                "https://git.kernel.org/stable/c/64903e4849a71cf7f7c7e5d45225ccefc1280929",
                "https://git.kernel.org/stable/c/c187aaa9e79b4b6d86ac7ba941e579ad33df5538",
                "https://git.kernel.org/stable/c/fbb429ddff5c8e479edcc7dde5a542c9295944e6"
            ],
            "timeline": [
                {
                    "at": "2025-05-08T07:15:54.533",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37833"
                }
            ]
        },
        {
            "id": "CVE-2025-37802",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix WARNING \"do not call blocking ops when !TASK_RUNNING\"\n\nwait_event_timeout() will set the state of the current\ntask to TASK_UNINTERRUPTIBLE, before doing the condition check. This\nmeans that ksmbd_durable_scavenger_alive() will try to acquire the mutex\nwhile already in a sleeping state. The scheduler warns us by giving\nthe following warning:\n\ndo not call blocking ops when !TASK_RUNNING; state=2 set at\n [<0000000061515a6f>] prepare_to_wait_event+0x9f/0x6c0\nWARNING: CPU: 2 PID: 4147 at kernel/sched/core.c:10099 __might_sleep+0x12f/0x160\n\nmutex lock is not needed in ksmbd_durable_scavenger_alive().",
            "updated_at": "2026-09-14T12:17:35.833",
            "published_at": "2025-05-08T07:15:51.363",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0626e6641f6b467447c81dd7678a69c66f7746cf through before 97aabdbf7ba82da20e698f0e62917fb206d42941 (git); 0626e6641f6b467447c81dd7678a69c66f7746cf through before 8f805b3746d2f41702c77cba22f94f8415fadd1a (git); 0626e6641f6b467447c81dd7678a69c66f7746cf through before cd161198e091e8a62b9bd631be970ea9a87d2d6a (git); 0626e6641f6b467447c81dd7678a69c66f7746cf through before 1df0d4c616138784e033ad337961b6e1a6bcd999 (git); 5.15",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-667",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix WARNING \"do not call blocking ops when !TASK_RUNNING\"\n\nwait_event_timeout() will set the state of the current\ntask to TASK_UNINTERRUPTIBLE, before doing the condition check. This\nmeans that ksmbd_durable_scavenger_alive() will try to acquire the mutex\nwhile already in a sleeping state. The scheduler warns us by giving\nthe following warning:\n\ndo not call blocking ops when !TASK_RUNNING; state=2 set at\n [<0000000061515a6f>] prepare_to_wait_event+0x9f/0x6c0\nWARNING: CPU: 2 PID: 4147 at kernel/sched/core.c:10099 __might_sleep+0x12f/0x160\n\nmutex lock is not needed in ksmbd_durable_scavenger_alive().",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1df0d4c616138784e033ad337961b6e1a6bcd999",
                "https://git.kernel.org/stable/c/8f805b3746d2f41702c77cba22f94f8415fadd1a",
                "https://git.kernel.org/stable/c/97aabdbf7ba82da20e698f0e62917fb206d42941",
                "https://git.kernel.org/stable/c/cd161198e091e8a62b9bd631be970ea9a87d2d6a"
            ],
            "timeline": [
                {
                    "at": "2025-05-08T07:15:51.363",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37802"
                }
            ]
        },
        {
            "id": "CVE-2025-36572",
            "vendor": "Dell",
            "product": "PowerStore",
            "title": "PowerStore vulnerability",
            "summary": "Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded account's privileges.",
            "updated_at": "2026-09-11T13:31:10.763",
            "published_at": "2025-05-28T17:15:24.093",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "N/A through before 4.0.1.3-2494147 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-798",
            "what_happened": "Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentially exploit this vulnerability to gain unauthorized access based on the hardcoded account's privileges.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-us/000325205/dsa-2025-223-dell-powerstore-t-security-update-for-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2025-05-28T17:15:24.093",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36572"
                }
            ]
        },
        {
            "id": "CVE-2025-34300",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2025-34300POC exploit",
            "summary": "Exploit for CVE-2025-34300. CVSS 10.",
            "updated_at": "2026-09-13T18:33:57Z",
            "published_at": "2026-09-13T18:33:57Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:33:57+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2025-34300POC exploit",
                    "summary": "Exploit for CVE-2025-34300. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JISI-001-CVE-2025-34300POC"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JISI-001-CVE-2025-34300POC"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:33:57Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JISI-001-CVE-2025-34300POC"
                }
            ]
        },
        {
            "id": "CVE-2025-34115",
            "vendor": "ITRS Group",
            "product": "OP5 Monitor",
            "title": "OP5 Monitor vulnerability",
            "summary": "An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' feature to execute arbitrary shell commands as the unprivileged web application user. The vulnerability resides in the configuration section of the application and requires valid login credentials with access to the command testing functionality. This issue is fixed in version 7.2.0.",
            "updated_at": "2026-09-08T20:17:25.700",
            "published_at": "2025-07-15T13:15:31.437",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 7.1.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' feature to execute arbitrary shell commands as the unprivileged web application user. The vulnerability resides in the configuration section of the application and requires valid login credentials with access to the command testing functionality. This issue is fixed in version 7.2.0.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/op5_config_exec.rb",
                "https://www.exploit-db.com/exploits/39676",
                "https://www.itrsgroup.com/products/network-monitoring-op5-monitor",
                "https://www.vulncheck.com/advisories/op5-monitor-authenticated-command-execution",
                "http://seclists.org/fulldisclosure/2026/Sep/38"
            ],
            "timeline": [
                {
                    "at": "2025-07-15T13:15:31.437",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-34115"
                }
            ]
        },
        {
            "id": "CVE-2025-33073",
            "vendor": "Microsoft",
            "product": "Windows",
            "title": "Microsoft Windows SMB Client Improper Access Control Vulnerability",
            "summary": "Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.",
            "updated_at": "2026-08-24T21:01:33Z",
            "published_at": "2026-08-24T21:01:33Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 332,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52330",
                    "author": "Mohammed Idrees Banyamer",
                    "first_seen": "2025-06-15",
                    "confidence": "High",
                    "title": "Windows 11 SMB Client - Privilege Escalation & Remote Code Execution (RCE)",
                    "summary": "Windows 11 SMB Client - Privilege Escalation & Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/52330",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2025-54918-POC CVE-2025-33073 CVE-2025-54918",
                    "summary": "NTLM reflection and coercion in Windows Server 2025 lets a domain user escalate to Domain Admin.",
                    "what_happened": "NTLM reflection and coercion in Windows Server 2025 lets a domain user escalate to Domain Admin.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH0AM123-CVE-2025-54918-POC",
                        "https://kitploit.com/ru/tools/github/wh0am123/cve-2025-54918-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-24T23:01:33",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH0AM123-CVE-2025-54918-POC"
                },
                {
                    "title": "Exploit for CVE-2025-54918-POC CVE-2025-33073 CVE-2025-54918",
                    "summary": "NTLM reflection and coercion in Windows Server 2025 lets a domain user escalate to Domain Admin.",
                    "what_happened": "NTLM reflection and coercion in Windows Server 2025 lets a domain user escalate to Domain Admin.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH0AM123-CVE-2025-54918-POC",
                        "https://kitploit.com/ru/tools/github/wh0am123/cve-2025-54918-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-24T23:01:33",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/wh0am123/cve-2025-54918-poc/"
                },
                {
                    "repository": "PoC-in-GitHub · mverschu/CVE-2025-33073",
                    "author": "mverschu",
                    "first_seen": "2025-06-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 717,
                    "title": "PoC Exploit for the NTLM reflection SMB flaw.",
                    "summary": "PoC Exploit for the NTLM reflection SMB flaw.",
                    "url": "https://github.com/mverschu/CVE-2025-33073"
                },
                {
                    "repository": "PoC-in-GitHub · starscow/CVE-2025-33073",
                    "author": "starscow",
                    "first_seen": "2025-06-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC Exploit for the NTLM reflection SMB flaw.",
                    "summary": "PoC Exploit for the NTLM reflection SMB flaw.",
                    "url": "https://github.com/starscow/CVE-2025-33073"
                },
                {
                    "repository": "PoC-in-GitHub · obscura-cert/CVE-2025-33073",
                    "author": "obscura-cert",
                    "first_seen": "2025-06-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-33073 repository",
                    "summary": "",
                    "url": "https://github.com/obscura-cert/CVE-2025-33073"
                },
                {
                    "repository": "PoC-in-GitHub · matejsmycka/CVE-2025-33073-checker",
                    "author": "matejsmycka",
                    "first_seen": "2025-07-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth coercion via samba RPC, to do this you need to have account with access to the samba.",
                    "summary": "This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth coercion via samba RPC, to do this you need to have account with access to the samba.",
                    "url": "https://github.com/matejsmycka/CVE-2025-33073-checker"
                },
                {
                    "repository": "PoC-in-GitHub · cve-2025-33073/cve-2025-33073",
                    "author": "cve-2025-33073",
                    "first_seen": "2025-09-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-33073 repository",
                    "summary": "",
                    "url": "https://github.com/cve-2025-33073/cve-2025-33073"
                },
                {
                    "repository": "PoC-in-GitHub · SFRDevelopment/windows-smb-vulnerability-framework-cve-2025-33073",
                    "author": "SFRDevelopment",
                    "first_seen": "2025-10-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Proof-of-Concept",
                    "summary": "Proof-of-Concept",
                    "url": "https://github.com/SFRDevelopment/windows-smb-vulnerability-framework-cve-2025-33073"
                },
                {
                    "repository": "PoC-in-GitHub · uziii2208/CVE-2025-33073",
                    "author": "uziii2208",
                    "first_seen": "2025-11-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 67,
                    "title": "Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.",
                    "summary": "Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.",
                    "url": "https://github.com/uziii2208/CVE-2025-33073"
                },
                {
                    "repository": "PoC-in-GitHub · irjfifndn-prog/Blackash-CVE-2025-33073",
                    "author": "irjfifndn-prog",
                    "first_seen": "2025-11-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-33073",
                    "summary": "CVE-2025-33073",
                    "url": "https://github.com/irjfifndn-prog/Blackash-CVE-2025-33073"
                },
                {
                    "repository": "PoC-in-GitHub · EgCupCake/cupntlm-Automated-Exploit-For-CVE-2025-33073-",
                    "author": "EgCupCake",
                    "first_seen": "2026-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "cupntlm",
                    "summary": "cupntlm",
                    "url": "https://github.com/EgCupCake/cupntlm-Automated-Exploit-For-CVE-2025-33073-"
                },
                {
                    "repository": "PoC-in-GitHub · IyarGross/SMB-CVE-2025-33073",
                    "author": "IyarGross",
                    "first_seen": "2026-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Advanced SMB Honeypot: CVE-2025-33073 Research & Implementation",
                    "summary": "Advanced SMB Honeypot: CVE-2025-33073 Research & Implementation",
                    "url": "https://github.com/IyarGross/SMB-CVE-2025-33073"
                },
                {
                    "repository": "PoC-in-GitHub · sentinel-aidefense/CVE-2025-33073",
                    "author": "sentinel-aidefense",
                    "first_seen": "2026-07-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-33073 Research writeup",
                    "summary": "CVE-2025-33073 Research writeup",
                    "url": "https://github.com/sentinel-aidefense/CVE-2025-33073"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52330",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH0AM123-CVE-2025-54918-POC",
                "https://kitploit.com/ru/tools/github/wh0am123/cve-2025-54918-poc/",
                "https://github.com/mverschu/CVE-2025-33073",
                "https://github.com/starscow/CVE-2025-33073",
                "https://github.com/obscura-cert/CVE-2025-33073",
                "https://github.com/matejsmycka/CVE-2025-33073-checker",
                "https://github.com/cve-2025-33073/cve-2025-33073",
                "https://github.com/SFRDevelopment/windows-smb-vulnerability-framework-cve-2025-33073",
                "https://github.com/uziii2208/CVE-2025-33073",
                "https://github.com/irjfifndn-prog/Blackash-CVE-2025-33073",
                "https://github.com/EgCupCake/cupntlm-Automated-Exploit-For-CVE-2025-33073-",
                "https://github.com/IyarGross/SMB-CVE-2025-33073",
                "https://github.com/sentinel-aidefense/CVE-2025-33073"
            ],
            "timeline": [
                {
                    "at": "2026-08-24T21:01:33Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-32958",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Authorized security-research lab: reproduction of CVE-2025-32958 (GHSA-8c7v-vccv-cx4q) — GITHUB_TOKEN leaked into workflow artifacts by Adept's remoteBuild.yml (snapshot of AdeptLanguage/Adept @ 6a64554)",
            "summary": "Authorized security-research lab: reproduction of CVE-2025-32958 (GHSA-8c7v-vccv-cx4q) — GITHUB_TOKEN leaked into workflow artifacts by Adept's remoteBuild.yml (snapshot of AdeptLanguage/Adept @ 6a64554)",
            "updated_at": "2026-09-02T22:00:00Z",
            "published_at": "2026-09-02T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 38,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · pvharmo2/gha-lab-b1fe4918c0",
                    "author": "pvharmo2",
                    "first_seen": "2026-09-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Authorized security-research lab: reproduction of CVE-2025-32958 (GHSA-8c7v-vccv-cx4q) — GITHUB_TOKEN leaked into workflow artifacts by Adept's remoteBuild.yml (snapshot of AdeptLanguage/Adept @ 6a64554)",
                    "summary": "Authorized security-research lab: reproduction of CVE-2025-32958 (GHSA-8c7v-vccv-cx4q) — GITHUB_TOKEN leaked into workflow artifacts by Adept's remoteBuild.yml (snapshot of AdeptLanguage/Adept @ 6a64554)",
                    "url": "https://github.com/pvharmo2/gha-lab-b1fe4918c0"
                }
            ],
            "references": [
                "https://github.com/pvharmo2/gha-lab-b1fe4918c0"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/pvharmo2/gha-lab-b1fe4918c0"
                }
            ]
        },
        {
            "id": "CVE-2025-32910",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8",
            "title": "Red Hat Enterprise Linux 8 vulnerability",
            "summary": "A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.",
            "updated_at": "2026-09-15T18:17:11.890",
            "published_at": "2025-04-14T15:15:25.307",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.6.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This issue may cause the libsoup client to crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2025:8292",
                "https://access.redhat.com/security/cve/CVE-2025-32910",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2359354",
                "https://gitlab.gnome.org/GNOME/libsoup/-/issues/432",
                "https://lists.debian.org/debian-lts-announce/2025/04/msg00036.html"
            ],
            "timeline": [
                {
                    "at": "2025-04-14T15:15:25.307",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32910"
                }
            ]
        },
        {
            "id": "CVE-2025-32909",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 8",
            "title": "Red Hat Enterprise Linux 8 vulnerability",
            "summary": "A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.",
            "updated_at": "2026-09-15T18:17:11.720",
            "published_at": "2025-04-14T15:15:25.140",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.6.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 function. The HTTP server may cause the libsoup client to crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2025:8292",
                "https://access.redhat.com/security/cve/CVE-2025-32909",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2359353",
                "https://gitlab.gnome.org/GNOME/libsoup/-/issues/431",
                "https://lists.debian.org/debian-lts-announce/2025/04/msg00036.html"
            ],
            "timeline": [
                {
                    "at": "2025-04-14T15:15:25.140",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32909"
                }
            ]
        },
        {
            "id": "CVE-2025-32756",
            "vendor": "Fortinet",
            "product": "Multiple Products",
            "title": "Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability",
            "summary": "Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.",
            "updated_at": "2026-09-05T12:39:10Z",
            "published_at": "2026-09-05T12:39:10Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 85,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-05T12:39:10+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "cve-2025-32756 exploit",
                    "summary": "Exploit for CVE-2025-32756. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAN0AR-CVE-2025-32756"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAN0AR-CVE-2025-32756"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:39:10Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-32711",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "exfil-scan exploit",
            "summary": "Exploit for CVE-2025-32711. CVSS 9.3.",
            "updated_at": "2026-09-08T01:13:05Z",
            "published_at": "2026-09-08T01:13:05Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 33,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-08T01:13:05+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "exfil-scan exploit",
                    "summary": "Exploit for CVE-2025-32711. CVSS 9.3.",
                    "cvss": 9.3,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-VIKASUDASI-EXFIL-SCAN"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-VIKASUDASI-EXFIL-SCAN"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:13:05Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-VIKASUDASI-EXFIL-SCAN"
                }
            ]
        },
        {
            "id": "CVE-2025-32463",
            "vendor": "Sudo",
            "product": "Sudo",
            "title": "Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability",
            "summary": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
            "updated_at": "2026-09-04T16:04:12Z",
            "published_at": "2026-09-04T16:04:12Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 3083,
            "kev": true,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52352",
                    "author": "Stratascale",
                    "first_seen": "2025-07-08",
                    "confidence": "High",
                    "title": "Sudo chroot 1.9.17 - Local Privilege Escalation",
                    "summary": "Sudo chroot 1.9.17 - Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/52352",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · pr0v3rbs/CVE-2025-32463_chwoot",
                    "author": "pr0v3rbs",
                    "first_seen": "2025-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 529,
                    "title": "Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463",
                    "summary": "Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463",
                    "url": "https://github.com/pr0v3rbs/CVE-2025-32463_chwoot"
                },
                {
                    "repository": "PoC-in-GitHub · 4f-kira/CVE-2025-32463",
                    "author": "4f-kira",
                    "first_seen": "2025-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/4f-kira/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · K1tt3h/CVE-2025-32463-POC",
                    "author": "K1tt3h",
                    "first_seen": "2025-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 30,
                    "title": "CVE-2025-32463 Proof of concept",
                    "summary": "CVE-2025-32463 Proof of concept",
                    "url": "https://github.com/K1tt3h/CVE-2025-32463-POC"
                },
                {
                    "repository": "PoC-in-GitHub · IC3-512/linux-root-kit",
                    "author": "IC3-512",
                    "first_seen": "2025-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full memory and network forensic analysis.",
                    "summary": "End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full memory and network forensic analysis.",
                    "url": "https://github.com/IC3-512/linux-root-kit"
                },
                {
                    "repository": "PoC-in-GitHub · 7r00t/cve-2025-32463-lab",
                    "author": "7r00t",
                    "first_seen": "2025-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/7r00t/cve-2025-32463-lab"
                },
                {
                    "repository": "PoC-in-GitHub · SysMancer/CVE-2025-32463",
                    "author": "SysMancer",
                    "first_seen": "2025-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/SysMancer/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · kh4sh3i/CVE-2025-32463",
                    "author": "kh4sh3i",
                    "first_seen": "2025-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 476,
                    "title": "Local Privilege Escalation to Root via Sudo chroot in Linux",
                    "summary": "Local Privilege Escalation to Root via Sudo chroot in Linux",
                    "url": "https://github.com/kh4sh3i/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · neko205-mx/CVE-2025-32463_Exploit",
                    "author": "neko205-mx",
                    "first_seen": "2025-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/neko205-mx/CVE-2025-32463_Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · pevinkumar10/CVE-2025-32463",
                    "author": "pevinkumar10",
                    "first_seen": "2025-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Exploit for Local Privilege Escalation in Sudo via Malicious nsswitch.conf with sudo -R. (CVE-2025-32463)",
                    "summary": "Exploit for Local Privilege Escalation in Sudo via Malicious nsswitch.conf with sudo -R. (CVE-2025-32463)",
                    "url": "https://github.com/pevinkumar10/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · zhaduchanhzz/CVE-2025-32463_POC",
                    "author": "zhaduchanhzz",
                    "first_seen": "2025-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/zhaduchanhzz/CVE-2025-32463_POC"
                },
                {
                    "repository": "PoC-in-GitHub · robbert1978/CVE-2025-32463_POC",
                    "author": "robbert1978",
                    "first_seen": "2025-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/robbert1978/CVE-2025-32463_POC"
                },
                {
                    "repository": "PoC-in-GitHub · Mikivirus0/sudoinjection",
                    "author": "Mikivirus0",
                    "first_seen": "2025-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Sudo Local Privilege Escalation CVE-2025-32463 (Best For Cases Where the shell is not stable to spawn a new root shell)",
                    "summary": "Sudo Local Privilege Escalation CVE-2025-32463 (Best For Cases Where the shell is not stable to spawn a new root shell)",
                    "url": "https://github.com/Mikivirus0/sudoinjection"
                },
                {
                    "repository": "PoC-in-GitHub · san8383/CVE-2025-32463",
                    "author": "san8383",
                    "first_seen": "2025-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/san8383/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · 0xAkarii/CVE-2025-32463",
                    "author": "0xAkarii",
                    "first_seen": "2025-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/0xAkarii/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · CIA911/sudo_patch_CVE-2025-32463",
                    "author": "CIA911",
                    "first_seen": "2025-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Mr.CIA's manual patching guide for CVE-2025-32463 (Sudo local privilege escalation) on Kali Linux and Ubuntu WSL.",
                    "summary": "Mr.CIA's manual patching guide for CVE-2025-32463 (Sudo local privilege escalation) on Kali Linux and Ubuntu WSL.",
                    "url": "https://github.com/CIA911/sudo_patch_CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · mirchr/CVE-2025-32463-sudo-chwoot",
                    "author": "mirchr",
                    "first_seen": "2025-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "PoC for CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability",
                    "summary": "PoC for CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability",
                    "url": "https://github.com/mirchr/CVE-2025-32463-sudo-chwoot"
                },
                {
                    "repository": "PoC-in-GitHub · ill-deed/CVE-2025-32463_illdeed",
                    "author": "ill-deed",
                    "first_seen": "2025-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Privilege escalation exploit for CVE-2025-32463 using a malicious NSS module injected via sudo -R. This version creates a stealth payload called illdeed, granting root access through a controlled chroot environment.",
                    "summary": "Privilege escalation exploit for CVE-2025-32463 using a malicious NSS module injected via sudo -R. This version creates a stealth payload called illdeed, granting root access through a controlled chroot environment.",
                    "url": "https://github.com/ill-deed/CVE-2025-32463_illdeed"
                },
                {
                    "repository": "PoC-in-GitHub · zinzloun/CVE-2025-32463",
                    "author": "zinzloun",
                    "first_seen": "2025-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "# CVE-2025-32463 – Sudo EoP Exploit (PoC) with precompiled .so",
                    "summary": "# CVE-2025-32463 – Sudo EoP Exploit (PoC) with precompiled .so",
                    "url": "https://github.com/zinzloun/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · 0p5cur/CVE-2025-32463-POC",
                    "author": "0p5cur",
                    "first_seen": "2025-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "🛡️ Proof of Concept (PoC) for CVE-2025-32463 - Local privilege escalation in sudo (versions 1.9.14 to 1.9.17). This exploit abuses the --chroot option and a malicious nsswitch.conf to execute arbitrary code as root. ⚠️ For educational and authorized testing only.",
                    "summary": "🛡️ Proof of Concept (PoC) for CVE-2025-32463 - Local privilege escalation in sudo (versions 1.9.14 to 1.9.17). This exploit abuses the --chroot option and a malicious nsswitch.conf to execute arbitrary code as root. ⚠️ For educational and authorized testing only.",
                    "url": "https://github.com/0p5cur/CVE-2025-32463-POC"
                },
                {
                    "repository": "PoC-in-GitHub · gmh5225/Blackash-CVE-2025-32463",
                    "author": "gmh5225",
                    "first_seen": "2025-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463",
                    "summary": "CVE-2025-32463",
                    "url": "https://github.com/gmh5225/Blackash-CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · FreeDurok/CVE-2025-32463-PoC",
                    "author": "FreeDurok",
                    "first_seen": "2025-07-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Proof of Concept for CVE-2025-32463 Local privilege escalation exploit targeting sudo -R on vulnerable Linux systems. For educational and authorized security testing only.",
                    "summary": "Proof of Concept for CVE-2025-32463 Local privilege escalation exploit targeting sudo -R on vulnerable Linux systems. For educational and authorized security testing only.",
                    "url": "https://github.com/FreeDurok/CVE-2025-32463-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · Chocapikk/CVE-2025-32463-lab",
                    "author": "Chocapikk",
                    "first_seen": "2025-07-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/Chocapikk/CVE-2025-32463-lab"
                },
                {
                    "repository": "PoC-in-GitHub · K3ysTr0K3R/CVE-2025-32463-EXPLOIT",
                    "author": "K3ysTr0K3R",
                    "first_seen": "2025-07-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "A PoC exploit for CVE-2025-32463 - Sudo Privilege Escalation",
                    "summary": "A PoC exploit for CVE-2025-32463 - Sudo Privilege Escalation",
                    "url": "https://github.com/K3ysTr0K3R/CVE-2025-32463-EXPLOIT"
                },
                {
                    "repository": "PoC-in-GitHub · SpongeBob-369/cve-2025-32463",
                    "author": "SpongeBob-369",
                    "first_seen": "2025-07-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "# cve-2025-32463 - Local Privilege Escalation to Root via Sudo chroot in Linux",
                    "summary": "# cve-2025-32463 - Local Privilege Escalation to Root via Sudo chroot in Linux",
                    "url": "https://github.com/SpongeBob-369/cve-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · lowercasenumbers/CVE-2025-32463_sudo_chroot",
                    "author": "lowercasenumbers",
                    "first_seen": "2025-07-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/lowercasenumbers/CVE-2025-32463_sudo_chroot"
                },
                {
                    "repository": "PoC-in-GitHub · abrewer251/CVE-2025-32463_Sudo_PoC",
                    "author": "abrewer251",
                    "first_seen": "2025-07-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC for CVE-2025-32463: Local privilege escalation in sudo via --chroot. Exploits NSS module injection through crafted chroot environments. Designed for security researchers and lab-only environments.",
                    "summary": "PoC for CVE-2025-32463: Local privilege escalation in sudo via --chroot. Exploits NSS module injection through crafted chroot environments. Designed for security researchers and lab-only environments.",
                    "url": "https://github.com/abrewer251/CVE-2025-32463_Sudo_PoC"
                },
                {
                    "repository": "PoC-in-GitHub · morgenm/sudo-chroot-CVE-2025-32463",
                    "author": "morgenm",
                    "first_seen": "2025-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Rust PoC for CVE-2025-32463 (sudo chroot \"chwoot\" Local PrivEsc)",
                    "summary": "Rust PoC for CVE-2025-32463 (sudo chroot \"chwoot\" Local PrivEsc)",
                    "url": "https://github.com/morgenm/sudo-chroot-CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · MohamedKarrab/CVE-2025-32463",
                    "author": "MohamedKarrab",
                    "first_seen": "2025-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 48,
                    "title": "Privilege escalation to root using sudo chroot, NO NEED for gcc installed.",
                    "summary": "Privilege escalation to root using sudo chroot, NO NEED for gcc installed.",
                    "url": "https://github.com/MohamedKarrab/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · krypton-0x00/CVE-2025-32463-Chwoot-POC",
                    "author": "krypton-0x00",
                    "first_seen": "2025-07-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/krypton-0x00/CVE-2025-32463-Chwoot-POC"
                },
                {
                    "repository": "PoC-in-GitHub · Rajneeshkarya/CVE-2025-32463",
                    "author": "Rajneeshkarya",
                    "first_seen": "2025-07-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is the exploit for the CVE-2025-32463",
                    "summary": "This is the exploit for the CVE-2025-32463",
                    "url": "https://github.com/Rajneeshkarya/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · MGunturG/CVE-2025-32463",
                    "author": "MGunturG",
                    "first_seen": "2025-07-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Local Privilege Escalation to Root via Sudo chroot in Linux",
                    "summary": "Local Privilege Escalation to Root via Sudo chroot in Linux",
                    "url": "https://github.com/MGunturG/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · Maalfer/Sudo-CVE-2021-3156",
                    "author": "Maalfer",
                    "first_seen": "2025-07-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "Exploit para explotar la vulnerabilidad CVE-2025-32463",
                    "summary": "Exploit para explotar la vulnerabilidad CVE-2025-32463",
                    "url": "https://github.com/Maalfer/Sudo-CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · daryllundy/CVE-2025-32463",
                    "author": "daryllundy",
                    "first_seen": "2025-07-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Proof-of-concept and analysis for CVE-2025-32463",
                    "summary": "Proof-of-concept and analysis for CVE-2025-32463",
                    "url": "https://github.com/daryllundy/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · AdityaBhatt3010/Sudo-Privilege-Escalation-Linux-CVE-2025-32463-and-CVE-2025-32462",
                    "author": "AdityaBhatt3010",
                    "first_seen": "2025-07-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "A deep dive into two critical Sudo vulnerabilities (CVE‑2025‑32463 & CVE‑2025‑32462) that enable local privilege escalation across major Linux distributions.",
                    "summary": "A deep dive into two critical Sudo vulnerabilities (CVE‑2025‑32463 & CVE‑2025‑32462) that enable local privilege escalation across major Linux distributions.",
                    "url": "https://github.com/AdityaBhatt3010/Sudo-Privilege-Escalation-Linux-CVE-2025-32463-and-CVE-2025-32462"
                },
                {
                    "repository": "PoC-in-GitHub · ChetanKomal/sudo_exploit",
                    "author": "ChetanKomal",
                    "first_seen": "2025-07-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463",
                    "summary": "CVE-2025-32463",
                    "url": "https://github.com/ChetanKomal/sudo_exploit"
                },
                {
                    "repository": "PoC-in-GitHub · KaiHT-Ladiant/CVE-2025-32463",
                    "author": "KaiHT-Ladiant",
                    "first_seen": "2025-07-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-32463 - Sudo Chroot Privilege Escalation Exploit",
                    "summary": "CVE-2025-32463 - Sudo Chroot Privilege Escalation Exploit",
                    "url": "https://github.com/KaiHT-Ladiant/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · y4ney/CVE-2025-32463-lab",
                    "author": "y4ney",
                    "first_seen": "2025-07-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "本项目基于 Docker 搭建了一个用于复现和测试 sudo 本地权限提升漏洞 CVE-2025-32463 的实验环境。",
                    "summary": "本项目基于 Docker 搭建了一个用于复现和测试 sudo 本地权限提升漏洞 CVE-2025-32463 的实验环境。",
                    "url": "https://github.com/y4ney/CVE-2025-32463-lab"
                },
                {
                    "repository": "PoC-in-GitHub · aldoClau98/CVE-2025-32463",
                    "author": "aldoClau98",
                    "first_seen": "2025-08-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Questo script è un proof of concept (PoC) che dimostra una tecnica di privilege escalation (Elevazione di privilegi) sfruttando una vulnerabilità teorica di sudo (es. CVE-2025-32463). Il PoC forza sudo a caricare una libreria .so manipolata sfruttando la funzionalità -R (chroot) e la configurazione personalizzata di NSS (nsswitch.conf).",
                    "summary": "Questo script è un proof of concept (PoC) che dimostra una tecnica di privilege escalation (Elevazione di privilegi) sfruttando una vulnerabilità teorica di sudo (es. CVE-2025-32463). Il PoC forza sudo a caricare una libreria .so manipolata sfruttando la funzionalità -R (chroot) e la configurazione personalizzata di NSS (nsswitch.conf).",
                    "url": "https://github.com/aldoClau98/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · painoob/CVE-2025-32463",
                    "author": "painoob",
                    "first_seen": "2025-08-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/painoob/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · 1xPwn/CVE-2025-32463",
                    "author": "1xPwn",
                    "first_seen": "2025-08-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 26,
                    "title": "This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.",
                    "summary": "This CVE addresses a vulnerability in sudo versions 1.9.14 to 1.9.17, enabling unauthorized local privilege escalation to root access.",
                    "url": "https://github.com/1xPwn/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · Yuy0ung/CVE-2025-32463_chwoot",
                    "author": "Yuy0ung",
                    "first_seen": "2025-08-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "用于CVE-2025-32463 sudo_chwoot的权限提升POC，适配了有gcc编译环境和无gcc编译环境的两种情况，下载运行即可一把梭哈",
                    "summary": "用于CVE-2025-32463 sudo_chwoot的权限提升POC，适配了有gcc编译环境和无gcc编译环境的两种情况，下载运行即可一把梭哈",
                    "url": "https://github.com/Yuy0ung/CVE-2025-32463_chwoot"
                },
                {
                    "repository": "PoC-in-GitHub · blackcat4347/CVE-2025-32463_PoC",
                    "author": "blackcat4347",
                    "first_seen": "2025-09-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/blackcat4347/CVE-2025-32463_PoC"
                },
                {
                    "repository": "PoC-in-GitHub · ashardev002/CVE-2025-32463_chwoot",
                    "author": "ashardev002",
                    "first_seen": "2025-09-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "🔍 Demonstrate the CVE-2025-32463 privilege-escalation flaw in sudo's chroot feature with this minimal, reproducible proof of concept environment.",
                    "summary": "🔍 Demonstrate the CVE-2025-32463 privilege-escalation flaw in sudo's chroot feature with this minimal, reproducible proof of concept environment.",
                    "url": "https://github.com/ashardev002/CVE-2025-32463_chwoot"
                },
                {
                    "repository": "PoC-in-GitHub · D3ltaFormation/CVE-2025-32463-Sudo-Chroot-Escape",
                    "author": "D3ltaFormation",
                    "first_seen": "2025-09-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository contains a Proof of Concept (PoC) for CVE-2025-32463, a vulnerability in sudo allowing a chroot escape to achieve local privilege escalation.",
                    "summary": "This repository contains a Proof of Concept (PoC) for CVE-2025-32463, a vulnerability in sudo allowing a chroot escape to achieve local privilege escalation.",
                    "url": "https://github.com/D3ltaFormation/CVE-2025-32463-Sudo-Chroot-Escape"
                },
                {
                    "repository": "PoC-in-GitHub · AC8999/CVE-2025-32463",
                    "author": "AC8999",
                    "first_seen": "2025-09-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A Python exploit for CVE-2025-32463, a critical local privilege escalation vulnerability in the Sudo binary on Linux systems. This flaw allows local users to obtain root access by exploiting the --chroot option, which incorrectly uses /etc/nsswitch.conf from a user-controlled directory.",
                    "summary": "A Python exploit for CVE-2025-32463, a critical local privilege escalation vulnerability in the Sudo binary on Linux systems. This flaw allows local users to obtain root access by exploiting the --chroot option, which incorrectly uses /etc/nsswitch.conf from a user-controlled directory.",
                    "url": "https://github.com/AC8999/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · onniio/CVE-2025-32463",
                    "author": "onniio",
                    "first_seen": "2025-10-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/onniio/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · khoazero123/CVE-2025-32463",
                    "author": "khoazero123",
                    "first_seen": "2025-10-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "# CVE-2025-32463 – Sudo EoP Exploit (PoC) with precompiled .so",
                    "summary": "# CVE-2025-32463 – Sudo EoP Exploit (PoC) with precompiled .so",
                    "url": "https://github.com/khoazero123/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · r3dBust3r/CVE-2025-32463",
                    "author": "r3dBust3r",
                    "first_seen": "2025-10-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This repository contains an exploit script for CVE-2025-32463, a local privilege escalation involving `chroot` behavior in affected `sudo` versions (1.9.14 through 1.9.17)",
                    "summary": "This repository contains an exploit script for CVE-2025-32463, a local privilege escalation involving `chroot` behavior in affected `sudo` versions (1.9.14 through 1.9.17)",
                    "url": "https://github.com/r3dBust3r/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · 0x3c4dfa1/CVE-2025-32463",
                    "author": "0x3c4dfa1",
                    "first_seen": "2025-10-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "sudo --chroot exploit",
                    "summary": "sudo --chroot exploit",
                    "url": "https://github.com/0x3c4dfa1/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · ricardomaia/CVE-2025-32463",
                    "author": "ricardomaia",
                    "first_seen": "2025-10-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Enviroment and Nuclei template to test CVE-2025-32463",
                    "summary": "Enviroment and Nuclei template to test CVE-2025-32463",
                    "url": "https://github.com/ricardomaia/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · shazed-x/CVE-2025-32463",
                    "author": "shazed-x",
                    "first_seen": "2025-10-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "- Vulnerable: sudo 1.9.14, 1.9.15, 1.9.16, 1.9.17 - Patched in: sudo 1.9.17p1 and later - Legacy versions older than 1.9.14 are not affected, as they don't support the --chroot option.",
                    "summary": "- Vulnerable: sudo 1.9.14, 1.9.15, 1.9.16, 1.9.17 - Patched in: sudo 1.9.17p1 and later - Legacy versions older than 1.9.14 are not affected, as they don't support the --chroot option.",
                    "url": "https://github.com/shazed-x/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · cybertechajju/CVE-2025-32463",
                    "author": "cybertechajju",
                    "first_seen": "2025-10-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Privilege escalation to root using sudo chroot, NO NEED for gcc installed.",
                    "summary": "Privilege escalation to root using sudo chroot, NO NEED for gcc installed.",
                    "url": "https://github.com/cybertechajju/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · secvulnhub/CVE-2025-32463-EXPLOIT",
                    "author": "secvulnhub",
                    "first_seen": "2025-10-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/secvulnhub/CVE-2025-32463-EXPLOIT"
                },
                {
                    "repository": "PoC-in-GitHub · dr4x-c0d3r/sudo-chroot",
                    "author": "dr4x-c0d3r",
                    "first_seen": "2025-10-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Sudo Vulnerability Local PrivEsc (CVE-2025-32463) POC with Python",
                    "summary": "Sudo Vulnerability Local PrivEsc (CVE-2025-32463) POC with Python",
                    "url": "https://github.com/dr4x-c0d3r/sudo-chroot"
                },
                {
                    "repository": "PoC-in-GitHub · dr4xp/sudo-chroot",
                    "author": "dr4xp",
                    "first_seen": "2025-10-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Sudo Vulnerability Local PrivEsc (CVE-2025-32463) POC with Python",
                    "summary": "Sudo Vulnerability Local PrivEsc (CVE-2025-32463) POC with Python",
                    "url": "https://github.com/dr4xp/sudo-chroot"
                },
                {
                    "repository": "PoC-in-GitHub · robbin0919/CVE-2025-32463",
                    "author": "robbin0919",
                    "first_seen": "2025-10-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/robbin0919/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · 12bijaya/CVE-2025-32463",
                    "author": "12bijaya",
                    "first_seen": "2025-10-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Sudo chroot privileged escalation PoC",
                    "summary": "Sudo chroot privileged escalation PoC",
                    "url": "https://github.com/12bijaya/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · muhammedkayag/CVE-2025-32463",
                    "author": "muhammedkayag",
                    "first_seen": "2025-10-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Technical examination of CVE-2025-32463 by Muhammed Kaya.",
                    "summary": "Technical examination of CVE-2025-32463 by Muhammed Kaya.",
                    "url": "https://github.com/muhammedkayag/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · NewComrade12211/CVE-2025-32463",
                    "author": "NewComrade12211",
                    "first_seen": "2025-11-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "exploit",
                    "summary": "exploit",
                    "url": "https://github.com/NewComrade12211/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · ankitpandey383/CVE-2025-32463-Sudo-Privilege-Escalation",
                    "author": "ankitpandey383",
                    "first_seen": "2025-11-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Practical security research project exploiting CVE-2025-32463 to gain root access on a vulnerable sudo version. Includes write-up, PoC, and mitigation steps.",
                    "summary": "Practical security research project exploiting CVE-2025-32463 to gain root access on a vulnerable sudo version. Includes write-up, PoC, and mitigation steps.",
                    "url": "https://github.com/ankitpandey383/CVE-2025-32463-Sudo-Privilege-Escalation"
                },
                {
                    "repository": "PoC-in-GitHub · justjoeyking/CVE-2025-32463",
                    "author": "justjoeyking",
                    "first_seen": "2025-11-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Chroot Privilege Escalation",
                    "summary": "Chroot Privilege Escalation",
                    "url": "https://github.com/justjoeyking/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · Mr-Alperen/CVE-2025-32463",
                    "author": "Mr-Alperen",
                    "first_seen": "2025-12-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/Mr-Alperen/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · SpycioKon/CVE-2025-32463",
                    "author": "SpycioKon",
                    "first_seen": "2026-02-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463",
                    "summary": "CVE-2025-32463",
                    "url": "https://github.com/SpycioKon/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · vpr-labs/CVE-2025-32463",
                    "author": "vpr-labs",
                    "first_seen": "2026-02-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "C reimplementation of chwoot PoC",
                    "summary": "C reimplementation of chwoot PoC",
                    "url": "https://github.com/vpr-labs/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · danilo1992-sys/CVE-2025-32463",
                    "author": "danilo1992-sys",
                    "first_seen": "2026-02-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/danilo1992-sys/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · 0xBlackash/CVE-2025-32463",
                    "author": "0xBlackash",
                    "first_seen": "2026-03-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463",
                    "summary": "CVE-2025-32463",
                    "url": "https://github.com/0xBlackash/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · EthanEvans92/CVE-2025-32463",
                    "author": "EthanEvans92",
                    "first_seen": "2026-05-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/EthanEvans92/CVE-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · Fomovet/cve-2025-32463",
                    "author": "Fomovet",
                    "first_seen": "2026-06-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "POC for CVE-2025-32463",
                    "summary": "POC for CVE-2025-32463",
                    "url": "https://github.com/Fomovet/cve-2025-32463"
                },
                {
                    "repository": "PoC-in-GitHub · 0xdak/CVE-2025-32463_exploit",
                    "author": "0xdak",
                    "first_seen": "2026-08-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32463 repository",
                    "summary": "",
                    "url": "https://github.com/0xdak/CVE-2025-32463_exploit"
                },
                {
                    "title": "Exploit for CVE-2025-32463",
                    "summary": "Privilege escalation in sudo via -R chroot with custom nsswitch.conf loading malicious .so library.",
                    "what_happened": "Privilege escalation in sudo via -R chroot with custom nsswitch.conf loading malicious .so library.",
                    "cvss": 9.3,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALDOCLAU98-CVE-2025-32463",
                        "https://kitploit.com/ru/tools/github/aldoclau98/cve-2025-32463/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T18:04:12",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALDOCLAU98-CVE-2025-32463"
                },
                {
                    "title": "Exploit for CVE-2025-32463",
                    "summary": "Privilege escalation in sudo via -R chroot with custom nsswitch.conf loading malicious .so library.",
                    "what_happened": "Privilege escalation in sudo via -R chroot with custom nsswitch.conf loading malicious .so library.",
                    "cvss": 9.3,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALDOCLAU98-CVE-2025-32463",
                        "https://kitploit.com/ru/tools/github/aldoclau98/cve-2025-32463/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T18:04:12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/aldoclau98/cve-2025-32463/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52352",
                "https://github.com/pr0v3rbs/CVE-2025-32463_chwoot",
                "https://github.com/4f-kira/CVE-2025-32463",
                "https://github.com/K1tt3h/CVE-2025-32463-POC",
                "https://github.com/IC3-512/linux-root-kit",
                "https://github.com/7r00t/cve-2025-32463-lab",
                "https://github.com/SysMancer/CVE-2025-32463",
                "https://github.com/kh4sh3i/CVE-2025-32463",
                "https://github.com/neko205-mx/CVE-2025-32463_Exploit",
                "https://github.com/pevinkumar10/CVE-2025-32463",
                "https://github.com/zhaduchanhzz/CVE-2025-32463_POC",
                "https://github.com/robbert1978/CVE-2025-32463_POC",
                "https://github.com/Mikivirus0/sudoinjection",
                "https://github.com/san8383/CVE-2025-32463",
                "https://github.com/0xAkarii/CVE-2025-32463",
                "https://github.com/CIA911/sudo_patch_CVE-2025-32463",
                "https://github.com/mirchr/CVE-2025-32463-sudo-chwoot",
                "https://github.com/ill-deed/CVE-2025-32463_illdeed",
                "https://github.com/zinzloun/CVE-2025-32463",
                "https://github.com/0p5cur/CVE-2025-32463-POC",
                "https://github.com/gmh5225/Blackash-CVE-2025-32463",
                "https://github.com/FreeDurok/CVE-2025-32463-PoC",
                "https://github.com/Chocapikk/CVE-2025-32463-lab",
                "https://github.com/K3ysTr0K3R/CVE-2025-32463-EXPLOIT",
                "https://github.com/SpongeBob-369/cve-2025-32463",
                "https://github.com/lowercasenumbers/CVE-2025-32463_sudo_chroot",
                "https://github.com/abrewer251/CVE-2025-32463_Sudo_PoC",
                "https://github.com/morgenm/sudo-chroot-CVE-2025-32463",
                "https://github.com/MohamedKarrab/CVE-2025-32463",
                "https://github.com/krypton-0x00/CVE-2025-32463-Chwoot-POC",
                "https://github.com/Rajneeshkarya/CVE-2025-32463",
                "https://github.com/MGunturG/CVE-2025-32463",
                "https://github.com/Maalfer/Sudo-CVE-2021-3156",
                "https://github.com/daryllundy/CVE-2025-32463",
                "https://github.com/AdityaBhatt3010/Sudo-Privilege-Escalation-Linux-CVE-2025-32463-and-CVE-2025-32462",
                "https://github.com/ChetanKomal/sudo_exploit",
                "https://github.com/KaiHT-Ladiant/CVE-2025-32463",
                "https://github.com/y4ney/CVE-2025-32463-lab",
                "https://github.com/aldoClau98/CVE-2025-32463",
                "https://github.com/painoob/CVE-2025-32463",
                "https://github.com/1xPwn/CVE-2025-32463",
                "https://github.com/Yuy0ung/CVE-2025-32463_chwoot",
                "https://github.com/blackcat4347/CVE-2025-32463_PoC",
                "https://github.com/ashardev002/CVE-2025-32463_chwoot",
                "https://github.com/D3ltaFormation/CVE-2025-32463-Sudo-Chroot-Escape",
                "https://github.com/AC8999/CVE-2025-32463",
                "https://github.com/onniio/CVE-2025-32463",
                "https://github.com/khoazero123/CVE-2025-32463",
                "https://github.com/r3dBust3r/CVE-2025-32463",
                "https://github.com/0x3c4dfa1/CVE-2025-32463",
                "https://github.com/ricardomaia/CVE-2025-32463",
                "https://github.com/shazed-x/CVE-2025-32463",
                "https://github.com/cybertechajju/CVE-2025-32463",
                "https://github.com/secvulnhub/CVE-2025-32463-EXPLOIT",
                "https://github.com/dr4x-c0d3r/sudo-chroot",
                "https://github.com/dr4xp/sudo-chroot",
                "https://github.com/robbin0919/CVE-2025-32463",
                "https://github.com/12bijaya/CVE-2025-32463",
                "https://github.com/muhammedkayag/CVE-2025-32463",
                "https://github.com/NewComrade12211/CVE-2025-32463",
                "https://github.com/ankitpandey383/CVE-2025-32463-Sudo-Privilege-Escalation",
                "https://github.com/justjoeyking/CVE-2025-32463",
                "https://github.com/Mr-Alperen/CVE-2025-32463",
                "https://github.com/SpycioKon/CVE-2025-32463",
                "https://github.com/vpr-labs/CVE-2025-32463",
                "https://github.com/danilo1992-sys/CVE-2025-32463",
                "https://github.com/0xBlackash/CVE-2025-32463",
                "https://github.com/EthanEvans92/CVE-2025-32463",
                "https://github.com/Fomovet/cve-2025-32463",
                "https://github.com/0xdak/CVE-2025-32463_exploit",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALDOCLAU98-CVE-2025-32463",
                "https://kitploit.com/ru/tools/github/aldoclau98/cve-2025-32463/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:04:12Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-09-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-32433",
            "vendor": "Erlang",
            "product": "Erlang/OTP",
            "title": "Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability",
            "summary": "Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE.",
            "updated_at": "2026-09-05T04:27:35Z",
            "published_at": "2026-09-05T04:27:35Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 304,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially leading to unauthenticated remote code execution (RCE). By exploiting a flaw in how SSH protocol messages are handled, a malicious actor could gain unauthorized access to affected systems. This vulnerability could affect various products that implement Erlang/OTP SSH server, including—but not limited to—Cisco, NetApp, and SUSE.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-32433_Erlang-OTP_PoC",
                    "summary": "Pre-auth RCE in Erlang-OTP SSH servers during handshake allows unauthenticated command execution.",
                    "what_happened": "Pre-auth RCE in Erlang-OTP SSH servers during handshake allows unauthenticated command execution.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ABREWER251-CVE-2025-32433_ERLANG-OTP_POC",
                        "https://kitploit.com/ru/tools/github/abrewer251/cve-2025-32433_erlang-otp_poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T06:27:35",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ABREWER251-CVE-2025-32433_ERLANG-OTP_POC"
                },
                {
                    "title": "Exploit for CVE-2025-32433_Erlang-OTP_PoC",
                    "summary": "Pre-auth RCE in Erlang-OTP SSH servers during handshake allows unauthenticated command execution.",
                    "what_happened": "Pre-auth RCE in Erlang-OTP SSH servers during handshake allows unauthenticated command execution.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ABREWER251-CVE-2025-32433_ERLANG-OTP_POC",
                        "https://kitploit.com/ru/tools/github/abrewer251/cve-2025-32433_erlang-otp_poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T06:27:35",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/abrewer251/cve-2025-32433_erlang-otp_poc/"
                },
                {
                    "repository": "PoC-in-GitHub · ProDefense/CVE-2025-32433",
                    "author": "ProDefense",
                    "first_seen": "2025-04-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 142,
                    "title": "CVE-2025-32433 https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2",
                    "summary": "CVE-2025-32433 https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2",
                    "url": "https://github.com/ProDefense/CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · ekomsSavior/POC_CVE-2025-32433",
                    "author": "ekomsSavior",
                    "first_seen": "2025-04-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2025-32433 repository",
                    "summary": "",
                    "url": "https://github.com/ekomsSavior/POC_CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · darses/CVE-2025-32433",
                    "author": "darses",
                    "first_seen": "2025-04-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Security research on Erlang/OTP SSH CVE-2025-32433.",
                    "summary": "Security research on Erlang/OTP SSH CVE-2025-32433.",
                    "url": "https://github.com/darses/CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · LemieOne/CVE-2025-32433",
                    "author": "LemieOne",
                    "first_seen": "2025-04-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Missing Authentication for Critical Function (CWE-306)-Exploit",
                    "summary": "Missing Authentication for Critical Function (CWE-306)-Exploit",
                    "url": "https://github.com/LemieOne/CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · teamtopkarl/CVE-2025-32433",
                    "author": "teamtopkarl",
                    "first_seen": "2025-04-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Erlang/OTP SSH 远程代码执行漏洞",
                    "summary": "Erlang/OTP SSH 远程代码执行漏洞",
                    "url": "https://github.com/teamtopkarl/CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · m0usem0use/erl_mouse",
                    "author": "m0usem0use",
                    "first_seen": "2025-04-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "python script to find vulnerable targets of CVE-2025-32433",
                    "summary": "python script to find vulnerable targets of CVE-2025-32433",
                    "url": "https://github.com/m0usem0use/erl_mouse"
                },
                {
                    "repository": "PoC-in-GitHub · exa-offsec/ssh_erlangotp_rce",
                    "author": "exa-offsec",
                    "first_seen": "2025-04-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Exploitation module for CVE-2025-32433 (Erlang/OTP)",
                    "summary": "Exploitation module for CVE-2025-32433 (Erlang/OTP)",
                    "url": "https://github.com/exa-offsec/ssh_erlangotp_rce"
                },
                {
                    "repository": "PoC-in-GitHub · omer-efe-curkus/CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC",
                    "author": "omer-efe-curkus",
                    "first_seen": "2025-04-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 16,
                    "title": "The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.",
                    "summary": "The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.",
                    "url": "https://github.com/omer-efe-curkus/CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · 0xPThree/cve-2025-32433",
                    "author": "0xPThree",
                    "first_seen": "2025-04-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2025-32433 repository",
                    "summary": "",
                    "url": "https://github.com/0xPThree/cve-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · meloppeitreet/CVE-2025-32433-Remote-Shell",
                    "author": "meloppeitreet",
                    "first_seen": "2025-04-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Go-based exploit for CVE-2025-32433",
                    "summary": "Go-based exploit for CVE-2025-32433",
                    "url": "https://github.com/meloppeitreet/CVE-2025-32433-Remote-Shell"
                },
                {
                    "repository": "PoC-in-GitHub · ps-interactive/lab_CVE-2025-32433",
                    "author": "ps-interactive",
                    "first_seen": "2025-04-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE lab to accompany CVE course for CVE-2025-32433",
                    "summary": "CVE lab to accompany CVE course for CVE-2025-32433",
                    "url": "https://github.com/ps-interactive/lab_CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · 0x7556/CVE-2025-32433",
                    "author": "0x7556",
                    "first_seen": "2025-04-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2025-32433 Erlang/OTP SSH RCE Exploit  SSH远程代码执行漏洞EXP",
                    "summary": "CVE-2025-32433 Erlang/OTP SSH RCE Exploit  SSH远程代码执行漏洞EXP",
                    "url": "https://github.com/0x7556/CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · becrevex/CVE-2025-32433",
                    "author": "becrevex",
                    "first_seen": "2025-04-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Erlang OTP SSH NSE Discovery Script",
                    "summary": "Erlang OTP SSH NSE Discovery Script",
                    "url": "https://github.com/becrevex/CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · MrDreamReal/CVE-2025-32433",
                    "author": "MrDreamReal",
                    "first_seen": "2025-04-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32433 Summary and Attack Overview",
                    "summary": "CVE-2025-32433 Summary and Attack Overview",
                    "url": "https://github.com/MrDreamReal/CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · Know56/CVE-2025-32433",
                    "author": "Know56",
                    "first_seen": "2025-04-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-32433 is a vuln of ssh",
                    "summary": "CVE-2025-32433 is a vuln of ssh",
                    "url": "https://github.com/Know56/CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · abrewer251/CVE-2025-32433_Erlang-OTP_PoC",
                    "author": "abrewer251",
                    "first_seen": "2025-04-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems running Erlang-based SSH servers",
                    "summary": "This script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems running Erlang-based SSH servers",
                    "url": "https://github.com/abrewer251/CVE-2025-32433_Erlang-OTP_PoC"
                },
                {
                    "repository": "PoC-in-GitHub · ODST-Forge/CVE-2025-32433_PoC",
                    "author": "ODST-Forge",
                    "first_seen": "2025-04-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems running Erlang-based SSH servers",
                    "summary": "This script is a custom security tool designed to test for a critical pre-authentication vulnerability in systems running Erlang-based SSH servers",
                    "url": "https://github.com/ODST-Forge/CVE-2025-32433_PoC"
                },
                {
                    "repository": "PoC-in-GitHub · bilalz5-github/Erlang-OTP-SSH-CVE-2025-32433",
                    "author": "bilalz5-github",
                    "first_seen": "2025-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-32433 – Erlang/OTP SSH vulnerability allowing pre-auth RCE",
                    "summary": "CVE-2025-32433 – Erlang/OTP SSH vulnerability allowing pre-auth RCE",
                    "url": "https://github.com/bilalz5-github/Erlang-OTP-SSH-CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · vigilante-1337/CVE-2025-32433",
                    "author": "vigilante-1337",
                    "first_seen": "2025-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A critical flaw has been discovered in Erlang/OTP's SSH server allows unauthenticated attackers to gain remote code execution. One malformed SSH handshake bypasses authentication and exploits improper handling of SSH protocol messages.",
                    "summary": "A critical flaw has been discovered in Erlang/OTP's SSH server allows unauthenticated attackers to gain remote code execution. One malformed SSH handshake bypasses authentication and exploits improper handling of SSH protocol messages.",
                    "url": "https://github.com/vigilante-1337/CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · NiteeshPujari/CVE-2025-32433-PoC",
                    "author": "NiteeshPujari",
                    "first_seen": "2025-08-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2025-32433 PoC: Unauthenticated Remote Code Execution (RCE) in Erlang/OTP SSH. A proof-of-concept exploit for CVE-2025-32433",
                    "summary": "CVE-2025-32433 PoC: Unauthenticated Remote Code Execution (RCE) in Erlang/OTP SSH. A proof-of-concept exploit for CVE-2025-32433",
                    "url": "https://github.com/NiteeshPujari/CVE-2025-32433-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · te0rwx/CVE-2025-32433-Detection",
                    "author": "te0rwx",
                    "first_seen": "2025-08-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32433 repository",
                    "summary": "",
                    "url": "https://github.com/te0rwx/CVE-2025-32433-Detection"
                },
                {
                    "repository": "PoC-in-GitHub · Mdusmandasthaheer/CVE-2025-32433",
                    "author": "Mdusmandasthaheer",
                    "first_seen": "2025-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32433 repository",
                    "summary": "",
                    "url": "https://github.com/Mdusmandasthaheer/CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · dollarboysushil/CVE-2025-32433-Erlang-OTP-SSH-Unauthenticated-RCE",
                    "author": "dollarboysushil",
                    "first_seen": "2025-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "PoC showing unauthenticated remote code execution in Erlang/OTP SSH server. By exploiting a flaw in SSH protocol message handling, an attacker can execute arbitrary commands on the target without valid credentials.",
                    "summary": "PoC showing unauthenticated remote code execution in Erlang/OTP SSH server. By exploiting a flaw in SSH protocol message handling, an attacker can execute arbitrary commands on the target without valid credentials.",
                    "url": "https://github.com/dollarboysushil/CVE-2025-32433-Erlang-OTP-SSH-Unauthenticated-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · iteride/CVE-2025-32433",
                    "author": "iteride",
                    "first_seen": "2025-09-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "test",
                    "summary": "test",
                    "url": "https://github.com/iteride/CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · mirmeweu/cve-2025-32433",
                    "author": "mirmeweu",
                    "first_seen": "2025-09-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "the task from C*****k",
                    "summary": "the task from C*****k",
                    "url": "https://github.com/mirmeweu/cve-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · Batman529/PoC-CVE-2025-32433",
                    "author": "Batman529",
                    "first_seen": "2025-10-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "These is a PoC for the CVE-2025-32433 vulnerability, do NOT test on systems that you dont own!!!",
                    "summary": "These is a PoC for the CVE-2025-32433 vulnerability, do NOT test on systems that you dont own!!!",
                    "url": "https://github.com/Batman529/PoC-CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · toshithh/CVE-2025-32433",
                    "author": "toshithh",
                    "first_seen": "2025-10-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-32433 repository",
                    "summary": "",
                    "url": "https://github.com/toshithh/CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · l1nuxkid/CVE-2025-32433-exploit",
                    "author": "l1nuxkid",
                    "first_seen": "2025-11-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32433 repository",
                    "summary": "",
                    "url": "https://github.com/l1nuxkid/CVE-2025-32433-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · soltanali0/CVE-2025-32433-Eploit",
                    "author": "soltanali0",
                    "first_seen": "2025-11-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Erlang/OTP SSH Vulnerable to Pre-Authentication RCE",
                    "summary": "Erlang/OTP SSH Vulnerable to Pre-Authentication RCE",
                    "url": "https://github.com/soltanali0/CVE-2025-32433-Eploit"
                },
                {
                    "repository": "PoC-in-GitHub · AntonieSoga/Erlang-OTP-PoC_CVE-2025-32433",
                    "author": "AntonieSoga",
                    "first_seen": "2025-12-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-32433 repository",
                    "summary": "",
                    "url": "https://github.com/AntonieSoga/Erlang-OTP-PoC_CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · blackcat4347/CVE-2025-32433-available-for-windows",
                    "author": "blackcat4347",
                    "first_seen": "2026-02-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32433-available-for-windows-victims",
                    "summary": "CVE-2025-32433-available-for-windows-victims",
                    "url": "https://github.com/blackcat4347/CVE-2025-32433-available-for-windows"
                },
                {
                    "repository": "PoC-in-GitHub · carlosalbertotuma/CVE-2025-32433",
                    "author": "carlosalbertotuma",
                    "first_seen": "2026-02-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32433 repository",
                    "summary": "",
                    "url": "https://github.com/carlosalbertotuma/CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · yonathanpy/CVE-2025-32433.py",
                    "author": "yonathanpy",
                    "first_seen": "2026-02-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2025-32433 PoC – SSH Protocol Python-based PoC for controlled lab testing of SSH message handling, channel operations, and pre-auth interactions. Designed for safe security research and analysis.",
                    "summary": "CVE-2025-32433 PoC – SSH Protocol Python-based PoC for controlled lab testing of SSH message handling, channel operations, and pre-auth interactions. Designed for safe security research and analysis.",
                    "url": "https://github.com/yonathanpy/CVE-2025-32433.py"
                },
                {
                    "repository": "PoC-in-GitHub · joshuavanderpoll/cve-2025-32433",
                    "author": "joshuavanderpoll",
                    "first_seen": "2026-03-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Go PoC for CVE-2025-32433 — unauthenticated RCE in Erlang/OTP SSH.",
                    "summary": "Go PoC for CVE-2025-32433 — unauthenticated RCE in Erlang/OTP SSH.",
                    "url": "https://github.com/joshuavanderpoll/cve-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · 0xBlackash/CVE-2025-32433",
                    "author": "0xBlackash",
                    "first_seen": "2026-04-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32433",
                    "summary": "CVE-2025-32433",
                    "url": "https://github.com/0xBlackash/CVE-2025-32433"
                },
                {
                    "repository": "PoC-in-GitHub · chuzouX/CVE-2025-32433-Exploit-edited",
                    "author": "chuzouX",
                    "first_seen": "2026-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Based on the original version:https://github.com/vulhub/vulhub/blob/master/erlang/CVE-2025-32433/exploit.py Replace Unicode checkmark with ASCII character for Windows compatibility",
                    "summary": "Based on the original version:https://github.com/vulhub/vulhub/blob/master/erlang/CVE-2025-32433/exploit.py Replace Unicode checkmark with ASCII character for Windows compatibility",
                    "url": "https://github.com/chuzouX/CVE-2025-32433-Exploit-edited"
                },
                {
                    "repository": "PoC-in-GitHub · dampedcoast/Exploiting-a-vulnerability-using-reverse-shell",
                    "author": "dampedcoast",
                    "first_seen": "2026-06-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE vulnerability (CVE-2025-32433) in an Erlang/OTP SSH server, crack extracted password hashes, and then harden the victim machine with firewall rules and patching.",
                    "summary": "This project simulates a real-world attack-and-defend scenario across two virtual machines. You will exploit a critical pre-authentication RCE vulnerability (CVE-2025-32433) in an Erlang/OTP SSH server, crack extracted password hashes, and then harden the victim machine with firewall rules and patching.",
                    "url": "https://github.com/dampedcoast/Exploiting-a-vulnerability-using-reverse-shell"
                },
                {
                    "repository": "PoC-in-GitHub · razureink/cve-2025-32433-erlang_ssh_rce_reproduction",
                    "author": "razureink",
                    "first_seen": "2026-07-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Reproduction of cve-2025-32433-erlang_ssh_rce_reproduction",
                    "summary": "Reproduction of cve-2025-32433-erlang_ssh_rce_reproduction",
                    "url": "https://github.com/razureink/cve-2025-32433-erlang_ssh_rce_reproduction"
                },
                {
                    "repository": "PoC-in-GitHub · Liam-Worsley/CVE-2025-32433-PoC-Analysis",
                    "author": "Liam-Worsley",
                    "first_seen": "2026-08-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the code does and instructions for setting up the server to perform the exploit yourself.",
                    "summary": "This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the code does and instructions for setting up the server to perform the exploit yourself.",
                    "url": "https://github.com/Liam-Worsley/CVE-2025-32433-PoC-Analysis"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ABREWER251-CVE-2025-32433_ERLANG-OTP_POC",
                "https://kitploit.com/ru/tools/github/abrewer251/cve-2025-32433_erlang-otp_poc/",
                "https://github.com/ProDefense/CVE-2025-32433",
                "https://github.com/ekomsSavior/POC_CVE-2025-32433",
                "https://github.com/darses/CVE-2025-32433",
                "https://github.com/LemieOne/CVE-2025-32433",
                "https://github.com/teamtopkarl/CVE-2025-32433",
                "https://github.com/m0usem0use/erl_mouse",
                "https://github.com/exa-offsec/ssh_erlangotp_rce",
                "https://github.com/omer-efe-curkus/CVE-2025-32433-Erlang-OTP-SSH-RCE-PoC",
                "https://github.com/0xPThree/cve-2025-32433",
                "https://github.com/meloppeitreet/CVE-2025-32433-Remote-Shell",
                "https://github.com/ps-interactive/lab_CVE-2025-32433",
                "https://github.com/0x7556/CVE-2025-32433",
                "https://github.com/becrevex/CVE-2025-32433",
                "https://github.com/MrDreamReal/CVE-2025-32433",
                "https://github.com/Know56/CVE-2025-32433",
                "https://github.com/abrewer251/CVE-2025-32433_Erlang-OTP_PoC",
                "https://github.com/ODST-Forge/CVE-2025-32433_PoC",
                "https://github.com/bilalz5-github/Erlang-OTP-SSH-CVE-2025-32433",
                "https://github.com/vigilante-1337/CVE-2025-32433",
                "https://github.com/NiteeshPujari/CVE-2025-32433-PoC",
                "https://github.com/te0rwx/CVE-2025-32433-Detection",
                "https://github.com/Mdusmandasthaheer/CVE-2025-32433",
                "https://github.com/dollarboysushil/CVE-2025-32433-Erlang-OTP-SSH-Unauthenticated-RCE",
                "https://github.com/iteride/CVE-2025-32433",
                "https://github.com/mirmeweu/cve-2025-32433",
                "https://github.com/Batman529/PoC-CVE-2025-32433",
                "https://github.com/toshithh/CVE-2025-32433",
                "https://github.com/l1nuxkid/CVE-2025-32433-exploit",
                "https://github.com/soltanali0/CVE-2025-32433-Eploit",
                "https://github.com/AntonieSoga/Erlang-OTP-PoC_CVE-2025-32433",
                "https://github.com/blackcat4347/CVE-2025-32433-available-for-windows",
                "https://github.com/carlosalbertotuma/CVE-2025-32433",
                "https://github.com/yonathanpy/CVE-2025-32433.py",
                "https://github.com/joshuavanderpoll/cve-2025-32433",
                "https://github.com/0xBlackash/CVE-2025-32433",
                "https://github.com/chuzouX/CVE-2025-32433-Exploit-edited",
                "https://github.com/dampedcoast/Exploiting-a-vulnerability-using-reverse-shell",
                "https://github.com/razureink/cve-2025-32433-erlang_ssh_rce_reproduction",
                "https://github.com/Liam-Worsley/CVE-2025-32433-PoC-Analysis"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T04:27:35Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-32432",
            "vendor": "Craft CMS",
            "product": "Craft CMS",
            "title": "Craft CMS Code Injection Vulnerability",
            "summary": "Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.",
            "updated_at": "2026-09-13T22:00:00Z",
            "published_at": "2026-09-13T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 144,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52525",
                    "author": "banyamer",
                    "first_seen": "2026-04-29",
                    "confidence": "High",
                    "title": "Craft CMS 5.6.16 - RCE",
                    "summary": "Craft CMS 5.6.16 - RCE",
                    "url": "https://www.exploit-db.com/exploits/52525",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · Chocapikk/CVE-2025-32432",
                    "author": "Chocapikk",
                    "first_seen": "2025-04-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "CraftCMS RCE Checker (CVE-2025-32432)",
                    "summary": "CraftCMS RCE Checker (CVE-2025-32432)",
                    "url": "https://github.com/Chocapikk/CVE-2025-32432"
                },
                {
                    "repository": "PoC-in-GitHub · Sachinart/CVE-2025-32432",
                    "author": "Sachinart",
                    "first_seen": "2025-04-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 27,
                    "title": "This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCMS versions 4.x and 5.x. The vulnerability exists in the asset transform generation feature of CraftCMS.",
                    "summary": "This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCMS versions 4.x and 5.x. The vulnerability exists in the asset transform generation feature of CraftCMS.",
                    "url": "https://github.com/Sachinart/CVE-2025-32432"
                },
                {
                    "repository": "PoC-in-GitHub · CTY-Research-1/CVE-2025-32432-PoC",
                    "author": "CTY-Research-1",
                    "first_seen": "2025-06-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "CVE-2025-32432 repository",
                    "summary": "",
                    "url": "https://github.com/CTY-Research-1/CVE-2025-32432-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · bambooqj/CVE-2025-32432",
                    "author": "bambooqj",
                    "first_seen": "2025-09-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "AI修复生成的CVE-2025-32432的poc",
                    "summary": "AI修复生成的CVE-2025-32432的poc",
                    "url": "https://github.com/bambooqj/CVE-2025-32432"
                },
                {
                    "repository": "PoC-in-GitHub · TheMursalin/CVE-2025-32432",
                    "author": "TheMursalin",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32432 repository",
                    "summary": "",
                    "url": "https://github.com/TheMursalin/CVE-2025-32432"
                },
                {
                    "repository": "PoC-in-GitHub · cd-ratel/CVE-2025-32432",
                    "author": "cd-ratel",
                    "first_seen": "2026-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning",
                    "summary": "Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning",
                    "url": "https://github.com/cd-ratel/CVE-2025-32432"
                },
                {
                    "repository": "PoC-in-GitHub · n40y/PoC_CVE-2025-32432",
                    "author": "n40y",
                    "first_seen": "2026-06-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CraftCMS CVE-2025-32432 - Clean PoC",
                    "summary": "CraftCMS CVE-2025-32432 - Clean PoC",
                    "url": "https://github.com/n40y/PoC_CVE-2025-32432"
                },
                {
                    "repository": "PoC-in-GitHub · c0gnit00/CVE-2025-32432",
                    "author": "c0gnit00",
                    "first_seen": "2026-07-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Exploit, POC for CVE-2025-32432, CraftCMS2Shell",
                    "summary": "Exploit, POC for CVE-2025-32432, CraftCMS2Shell",
                    "url": "https://github.com/c0gnit00/CVE-2025-32432"
                },
                {
                    "repository": "PoC-in-GitHub · theeomega/CVE-2025-32432-POC",
                    "author": "theeomega",
                    "first_seen": "2026-07-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32432 repository",
                    "summary": "",
                    "url": "https://github.com/theeomega/CVE-2025-32432-POC"
                },
                {
                    "repository": "PoC-in-GitHub · HeltonPojo/CVE-2025-32432",
                    "author": "HeltonPojo",
                    "first_seen": "2026-07-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32432 repository",
                    "summary": "",
                    "url": "https://github.com/HeltonPojo/CVE-2025-32432"
                },
                {
                    "repository": "PoC-in-GitHub · PsyGuy007-sys/craftcms-cve-2025-32432-rce",
                    "author": "PsyGuy007-sys",
                    "first_seen": "2026-08-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research",
                    "summary": "Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research",
                    "url": "https://github.com/PsyGuy007-sys/craftcms-cve-2025-32432-rce"
                },
                {
                    "repository": "PoC-in-GitHub · EzraMansor/CVE-2025-32432-PoC",
                    "author": "EzraMansor",
                    "first_seen": "2026-08-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go",
                    "summary": "A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go",
                    "url": "https://github.com/EzraMansor/CVE-2025-32432-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · e5dfdd568a75282b712b6d93a7a18e12/CVE-2025-32432",
                    "author": "e5dfdd568a75282b712b6d93a7a18e12",
                    "first_seen": "2026-09-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-32432 repository",
                    "summary": "",
                    "url": "https://github.com/e5dfdd568a75282b712b6d93a7a18e12/CVE-2025-32432"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52525",
                "https://github.com/Chocapikk/CVE-2025-32432",
                "https://github.com/Sachinart/CVE-2025-32432",
                "https://github.com/CTY-Research-1/CVE-2025-32432-PoC",
                "https://github.com/bambooqj/CVE-2025-32432",
                "https://github.com/TheMursalin/CVE-2025-32432",
                "https://github.com/cd-ratel/CVE-2025-32432",
                "https://github.com/n40y/PoC_CVE-2025-32432",
                "https://github.com/c0gnit00/CVE-2025-32432",
                "https://github.com/theeomega/CVE-2025-32432-POC",
                "https://github.com/HeltonPojo/CVE-2025-32432",
                "https://github.com/PsyGuy007-sys/craftcms-cve-2025-32432-rce",
                "https://github.com/EzraMansor/CVE-2025-32432-PoC",
                "https://github.com/e5dfdd568a75282b712b6d93a7a18e12/CVE-2025-32432"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-32370",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Kentico Xperience 13.0.178 - Cross Site Scripting (XSS)",
            "summary": "Kentico Xperience 13.0.178 - Cross Site Scripting (XSS)",
            "updated_at": "2026-09-07T19:12:13Z",
            "published_at": "2026-09-07T19:12:13Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 48,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52290",
                    "author": "Alex Messham",
                    "first_seen": "2025-05-13",
                    "confidence": "High",
                    "title": "Kentico Xperience 13.0.178 - Cross Site Scripting (XSS)",
                    "summary": "Kentico Xperience 13.0.178 - Cross Site Scripting (XSS)",
                    "url": "https://www.exploit-db.com/exploits/52290",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2025-66516-POC",
                    "summary": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
                    "what_happened": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SID6224-CVE-2025-66516-POC",
                        "https://kitploit.com/ja/tools/github/sid6224/cve-2025-66516-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-07T21:12:13",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SID6224-CVE-2025-66516-POC"
                },
                {
                    "title": "Exploit for CVE-2025-66516-POC",
                    "summary": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
                    "what_happened": "XXE in Apache Tika <3.2.2 tika-parser-pdf-module XFA parser enables file read and SSRF.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SID6224-CVE-2025-66516-POC",
                        "https://kitploit.com/ja/tools/github/sid6224/cve-2025-66516-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-07T21:12:13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/sid6224/cve-2025-66516-poc/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52290",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SID6224-CVE-2025-66516-POC",
                "https://kitploit.com/ja/tools/github/sid6224/cve-2025-66516-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:12:13Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52290"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-31324",
            "vendor": "SAP",
            "product": "NetWeaver",
            "title": "SAP NetWeaver Unrestricted File Upload Vulnerability",
            "summary": "SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.",
            "updated_at": "2026-09-05T22:00:00Z",
            "published_at": "2026-09-05T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 814,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · rxerium/CVE-2025-31324",
                    "author": "rxerium",
                    "first_seen": "2025-04-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.",
                    "summary": "SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.",
                    "url": "https://github.com/rxerium/CVE-2025-31324"
                },
                {
                    "repository": "PoC-in-GitHub · redrays-io/CVE-2025-31324",
                    "author": "redrays-io",
                    "first_seen": "2025-04-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "CVE-2025-31324, SAP Exploit",
                    "summary": "CVE-2025-31324, SAP Exploit",
                    "url": "https://github.com/redrays-io/CVE-2025-31324"
                },
                {
                    "repository": "PoC-in-GitHub · Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools",
                    "author": "Onapsis",
                    "first_seen": "2025-04-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "CVE-2025-31324 repository",
                    "summary": "",
                    "url": "https://github.com/Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools"
                },
                {
                    "repository": "PoC-in-GitHub · moften/CVE-2025-31324",
                    "author": "moften",
                    "first_seen": "2025-04-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "SAP PoC para CVE-2025-31324",
                    "summary": "SAP PoC para CVE-2025-31324",
                    "url": "https://github.com/moften/CVE-2025-31324"
                },
                {
                    "repository": "PoC-in-GitHub · moften/CVE-2025-31324-NUCLEI",
                    "author": "moften",
                    "first_seen": "2025-04-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Nuclei template for cve-2025-31324 (SAP)",
                    "summary": "Nuclei template for cve-2025-31324 (SAP)",
                    "url": "https://github.com/moften/CVE-2025-31324-NUCLEI"
                },
                {
                    "repository": "PoC-in-GitHub · Alizngnc/SAP-CVE-2025-31324",
                    "author": "Alizngnc",
                    "first_seen": "2025-04-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "SAP NetWeaver Unauthenticated Remote Code Execution",
                    "summary": "SAP NetWeaver Unauthenticated Remote Code Execution",
                    "url": "https://github.com/Alizngnc/SAP-CVE-2025-31324"
                },
                {
                    "repository": "PoC-in-GitHub · ODST-Forge/CVE-2025-31324_PoC",
                    "author": "ODST-Forge",
                    "first_seen": "2025-04-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader",
                    "summary": "Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader",
                    "url": "https://github.com/ODST-Forge/CVE-2025-31324_PoC"
                },
                {
                    "repository": "PoC-in-GitHub · abrewer251/CVE-2025-31324_PoC_SAP",
                    "author": "abrewer251",
                    "first_seen": "2025-04-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader",
                    "summary": "Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader",
                    "url": "https://github.com/abrewer251/CVE-2025-31324_PoC_SAP"
                },
                {
                    "repository": "PoC-in-GitHub · BlueOWL-overlord/Burp_CVE-2025-31324",
                    "author": "BlueOWL-overlord",
                    "first_seen": "2025-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324",
                    "summary": "Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324",
                    "url": "https://github.com/BlueOWL-overlord/Burp_CVE-2025-31324"
                },
                {
                    "repository": "PoC-in-GitHub · nullcult/CVE-2025-31324-File-Upload",
                    "author": "nullcult",
                    "first_seen": "2025-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A totally unauthenticated file-upload endpoint in Visual Composer lets anyone drop arbitrary files (e.g., a JSP web-shell) onto the server.",
                    "summary": "A totally unauthenticated file-upload endpoint in Visual Composer lets anyone drop arbitrary files (e.g., a JSP web-shell) onto the server.",
                    "url": "https://github.com/nullcult/CVE-2025-31324-File-Upload"
                },
                {
                    "repository": "PoC-in-GitHub · respondiq/jsp-webshell-scanner",
                    "author": "respondiq",
                    "first_seen": "2025-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.",
                    "summary": "🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.",
                    "url": "https://github.com/respondiq/jsp-webshell-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · JonathanStross/CVE-2025-31324",
                    "author": "JonathanStross",
                    "first_seen": "2025-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A Python-based security scanner for identifying the CVE-2025-31324 vulnerability in SAP Visual Composer systems, and detecting known Indicators of Compromise (IOCs) such as malicious .jsp.",
                    "summary": "A Python-based security scanner for identifying the CVE-2025-31324 vulnerability in SAP Visual Composer systems, and detecting known Indicators of Compromise (IOCs) such as malicious .jsp.",
                    "url": "https://github.com/JonathanStross/CVE-2025-31324"
                },
                {
                    "repository": "PoC-in-GitHub · Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment",
                    "author": "Onapsis",
                    "first_seen": "2025-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool",
                    "summary": "CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool",
                    "url": "https://github.com/Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment"
                },
                {
                    "repository": "PoC-in-GitHub · rf-peixoto/sap_netweaver_cve-2025-31324-",
                    "author": "rf-peixoto",
                    "first_seen": "2025-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Research Purposes only",
                    "summary": "Research Purposes only",
                    "url": "https://github.com/rf-peixoto/sap_netweaver_cve-2025-31324-"
                },
                {
                    "repository": "PoC-in-GitHub · NULLTRACE0X/CVE-2025-31324",
                    "author": "NULLTRACE0X",
                    "first_seen": "2025-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2025-31324 repository",
                    "summary": "",
                    "url": "https://github.com/NULLTRACE0X/CVE-2025-31324"
                },
                {
                    "repository": "PoC-in-GitHub · nairuzabulhul/nuclei-template-cve-2025-31324-check",
                    "author": "nairuzabulhul",
                    "first_seen": "2025-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "sap-netweaver-cve-2025-31324-check",
                    "summary": "sap-netweaver-cve-2025-31324-check",
                    "url": "https://github.com/nairuzabulhul/nuclei-template-cve-2025-31324-check"
                },
                {
                    "repository": "PoC-in-GitHub · sug4r-wr41th/CVE-2025-31324",
                    "author": "sug4r-wr41th",
                    "first_seen": "2025-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "SAP NetWeaver Visual Composer Metadata Uploader <= 7.50 CVE-2025-31324 PoC",
                    "summary": "SAP NetWeaver Visual Composer Metadata Uploader <= 7.50 CVE-2025-31324 PoC",
                    "url": "https://github.com/sug4r-wr41th/CVE-2025-31324"
                },
                {
                    "repository": "PoC-in-GitHub · antichainalysis/sap-netweaver-0day-CVE-2025-31324",
                    "author": "antichainalysis",
                    "first_seen": "2025-08-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 22,
                    "title": "sap netweaver 0day poc by shinyhunters (scattered lapsus$ hunters) affecting all 7.x CVE-2025-31324",
                    "summary": "sap netweaver 0day poc by shinyhunters (scattered lapsus$ hunters) affecting all 7.x CVE-2025-31324",
                    "url": "https://github.com/antichainalysis/sap-netweaver-0day-CVE-2025-31324"
                },
                {
                    "repository": "PoC-in-GitHub · harshitvarma05/CVE-2025-31324-Exploits",
                    "author": "harshitvarma05",
                    "first_seen": "2025-08-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-31324 repository",
                    "summary": "",
                    "url": "https://github.com/harshitvarma05/CVE-2025-31324-Exploits"
                },
                {
                    "repository": "PoC-in-GitHub · aristois913/CVE-2025-31324",
                    "author": "aristois913",
                    "first_seen": "2026-01-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Proof-of-Concept 0day for SAP NetWeaver created by ShinyHunters",
                    "summary": "Proof-of-Concept 0day for SAP NetWeaver created by ShinyHunters",
                    "url": "https://github.com/aristois913/CVE-2025-31324"
                },
                {
                    "repository": "PoC-in-GitHub · HKenzoKimura/CVE-2025-31324",
                    "author": "HKenzoKimura",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC — SAP NetWeaver Visual Composer unauthenticated file upload (CVSS 10.0). Benign JSP payload. CISA KEV May 2025 · Patched April/May 2025 · T1190 ·",
                    "summary": "PoC — SAP NetWeaver Visual Composer unauthenticated file upload (CVSS 10.0). Benign JSP payload. CISA KEV May 2025 · Patched April/May 2025 · T1190 ·",
                    "url": "https://github.com/HKenzoKimura/CVE-2025-31324"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/rxerium/CVE-2025-31324",
                "https://github.com/redrays-io/CVE-2025-31324",
                "https://github.com/Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools",
                "https://github.com/moften/CVE-2025-31324",
                "https://github.com/moften/CVE-2025-31324-NUCLEI",
                "https://github.com/Alizngnc/SAP-CVE-2025-31324",
                "https://github.com/ODST-Forge/CVE-2025-31324_PoC",
                "https://github.com/abrewer251/CVE-2025-31324_PoC_SAP",
                "https://github.com/BlueOWL-overlord/Burp_CVE-2025-31324",
                "https://github.com/nullcult/CVE-2025-31324-File-Upload",
                "https://github.com/respondiq/jsp-webshell-scanner",
                "https://github.com/JonathanStross/CVE-2025-31324",
                "https://github.com/Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment",
                "https://github.com/rf-peixoto/sap_netweaver_cve-2025-31324-",
                "https://github.com/NULLTRACE0X/CVE-2025-31324",
                "https://github.com/nairuzabulhul/nuclei-template-cve-2025-31324-check",
                "https://github.com/sug4r-wr41th/CVE-2025-31324",
                "https://github.com/antichainalysis/sap-netweaver-0day-CVE-2025-31324",
                "https://github.com/harshitvarma05/CVE-2025-31324-Exploits",
                "https://github.com/aristois913/CVE-2025-31324",
                "https://github.com/HKenzoKimura/CVE-2025-31324"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-29",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-31161",
            "vendor": "CrushFTP",
            "product": "CrushFTP",
            "title": "CrushFTP Authentication Bypass Vulnerability",
            "summary": "CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.",
            "updated_at": "2026-08-25T02:25:29Z",
            "published_at": "2026-08-25T02:25:29Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 243,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52295",
                    "author": "İbrahimsql",
                    "first_seen": "2025-05-18",
                    "confidence": "High",
                    "title": "CrushFTP 11.3.1 - Authentication Bypass",
                    "summary": "CrushFTP 11.3.1 - Authentication Bypass",
                    "url": "https://www.exploit-db.com/exploits/52295",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for ludus_crushftp_cve-2025-31161_sim CVE-2025-31161",
                    "summary": "Authentication bypass in CrushFTP 10.8.0 on Windows (CVE-2025-31161).",
                    "what_happened": "Authentication bypass in CrushFTP 10.8.0 on Windows (CVE-2025-31161).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUFFLABS-LUDUS_CRUSHFTP_CVE-2025-31161_SIM",
                        "https://kitploit.com/hi/tools/github/rufflabs/ludus_crushftp_cve-2025-31161_sim/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T04:25:29",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUFFLABS-LUDUS_CRUSHFTP_CVE-2025-31161_SIM"
                },
                {
                    "title": "Exploit for ludus_crushftp_cve-2025-31161_sim CVE-2025-31161",
                    "summary": "Authentication bypass in CrushFTP 10.8.0 on Windows (CVE-2025-31161).",
                    "what_happened": "Authentication bypass in CrushFTP 10.8.0 on Windows (CVE-2025-31161).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUFFLABS-LUDUS_CRUSHFTP_CVE-2025-31161_SIM",
                        "https://kitploit.com/hi/tools/github/rufflabs/ludus_crushftp_cve-2025-31161_sim/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-08-25T04:25:29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/rufflabs/ludus_crushftp_cve-2025-31161_sim/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52295",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUFFLABS-LUDUS_CRUSHFTP_CVE-2025-31161_SIM",
                "https://kitploit.com/hi/tools/github/rufflabs/ludus_crushftp_cve-2025-31161_sim/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T02:25:29Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-31125",
            "vendor": "Vite",
            "product": "Vitejs",
            "title": "Vite Vitejs Improper Access Control Vulnerability",
            "summary": "Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.",
            "updated_at": "2026-09-08T14:40:11Z",
            "published_at": "2026-09-08T14:40:11Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 91,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Path-Transversal-CVE-2025-31125-",
                    "summary": "Path traversal in Vite Development Server's @fs endpoint exposes sensitive files via crafted URLs.",
                    "what_happened": "Path traversal in Vite Development Server's @fs endpoint exposes sensitive files via crafted URLs.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HARSHGUPPTAA-PATH-TRANSVERSAL-CVE-2025-31125-",
                        "https://kitploit.com/ru/tools/github/harshgupptaa/path-transversal-cve-2025-31125-/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T17:39:30",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HARSHGUPPTAA-PATH-TRANSVERSAL-CVE-2025-31125-"
                },
                {
                    "title": "Exploit for Path-Transversal-CVE-2025-31125-",
                    "summary": "Path traversal in Vite Development Server's @fs endpoint exposes sensitive files via crafted URLs.",
                    "what_happened": "Path traversal in Vite Development Server's @fs endpoint exposes sensitive files via crafted URLs.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HARSHGUPPTAA-PATH-TRANSVERSAL-CVE-2025-31125-",
                        "https://kitploit.com/ru/tools/github/harshgupptaa/path-transversal-cve-2025-31125-/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T17:39:30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/harshgupptaa/path-transversal-cve-2025-31125-/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HARSHGUPPTAA-PATH-TRANSVERSAL-CVE-2025-31125-",
                "https://kitploit.com/ru/tools/github/harshgupptaa/path-transversal-cve-2025-31125-/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T14:40:11Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-01-22",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-30208",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Vite 6.2.2 - Arbitrary File Read",
            "summary": "Vite 6.2.2 - Arbitrary File Read",
            "updated_at": "2026-09-03T10:01:14Z",
            "published_at": "2026-09-03T10:01:14Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 260,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Arbitrary file read in Vite via @fs endpoint with raw or import&raw parameters.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52111",
                    "author": "4m3rr0r",
                    "first_seen": "2025-04-03",
                    "confidence": "High",
                    "title": "Vite 6.2.2 - Arbitrary File Read",
                    "summary": "Vite 6.2.2 - Arbitrary File Read",
                    "url": "https://www.exploit-db.com/exploits/52111",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-05T08:15:24+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2025-30208-ViteVulnScanner exploit",
                    "summary": "Exploit for CVE-2025-30208. CVSS 7.5.",
                    "cvss": 7.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KEKLICK1337-CVE-2025-30208-VITEVULNSCANNER"
                },
                {
                    "title": "Exploit for CVE-2025-30208-ViteVulnScanner",
                    "summary": "Arbitrary file read in Vite via @fs endpoint with raw or import&raw parameters.",
                    "what_happened": "Arbitrary file read in Vite via @fs endpoint with raw or import&raw parameters.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KEKLICK1337-CVE-2025-30208-VITEVULNSCANNER",
                        "https://kitploit.com/hi/tools/github/keklick1337/cve-2025-30208-vitevulnscanner/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-03T12:01:14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/keklick1337/cve-2025-30208-vitevulnscanner/"
                },
                {
                    "title": "Exploit for Path-Transversal-CVE-2025-31125-",
                    "summary": "Path traversal in Vite Development Server's @fs endpoint exposes sensitive files via crafted URLs.",
                    "what_happened": "Path traversal in Vite Development Server's @fs endpoint exposes sensitive files via crafted URLs.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HARSHGUPPTAA-PATH-TRANSVERSAL-CVE-2025-31125-",
                        "https://kitploit.com/ru/tools/github/harshgupptaa/path-transversal-cve-2025-31125-/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T17:39:30",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HARSHGUPPTAA-PATH-TRANSVERSAL-CVE-2025-31125-"
                },
                {
                    "title": "Exploit for Path-Transversal-CVE-2025-31125-",
                    "summary": "Path traversal in Vite Development Server's @fs endpoint exposes sensitive files via crafted URLs.",
                    "what_happened": "Path traversal in Vite Development Server's @fs endpoint exposes sensitive files via crafted URLs.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HARSHGUPPTAA-PATH-TRANSVERSAL-CVE-2025-31125-",
                        "https://kitploit.com/ru/tools/github/harshgupptaa/path-transversal-cve-2025-31125-/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T17:39:30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/harshgupptaa/path-transversal-cve-2025-31125-/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52111",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KEKLICK1337-CVE-2025-30208-VITEVULNSCANNER",
                "https://kitploit.com/hi/tools/github/keklick1337/cve-2025-30208-vitevulnscanner/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HARSHGUPPTAA-PATH-TRANSVERSAL-CVE-2025-31125-",
                "https://kitploit.com/ru/tools/github/harshgupptaa/path-transversal-cve-2025-31125-/"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T10:01:14Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52111"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2025-30033",
            "vendor": "Siemens",
            "product": "Automation License Manager V6.0",
            "title": "Automation License Manager V6.0 vulnerability",
            "summary": "The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.",
            "updated_at": "2026-09-08T09:17:30.320",
            "published_at": "2025-08-12T12:15:34.733",
            "cvss": 8.5,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before * (custom); before V6.2 Upd3 (custom); before V6.9 (custom); before V1.5.5.0 (custom); before V2.0 SP2 (custom); before V5.0 SP4 (custom); before V3.1.0.2 (custom); before V4.1 (custom); before V10.0 SP1 (custom); before V19 Update 4 (custom); before V2.0 Upd3 (custom); before V9.1 SP1 Upd8 (custom); before V2.1 (custom); before V4.1.0.1 (custom); before V5.0.0.1 (custom); before V20.0 Update 1 (custom); before V9.1 SP2 Upd4 (custom); before V9.1 SP2 Upd6 (custom); before V9.1 SP2 Upd2 (custom); before V10.0 SP1 Upd2 (custom); before V9.1 SP2 Upd8 (custom); before V9.1 Upd8 (custom); before V10.0 SP1 UC01 (custom); before V9.1 SP1 UC08 (custom); before V6.0 SP1 (custom); before V9.3 SP1 Upd2 (custom); before V2024 SP1 Upd2 (custom); before V17 Update 9 (custom); before V31.1.5 (custom); before V4.0.1 (custom); before V3.5 SP4 Update 1 (custom); before V7.0 Update 1 (custom); before V20 Update 1 (custom); before V6.0 SP3 (custom); before V21 (custom); before V20 (custom); before V7.5 SP2 Update 20 (custom); before V8.0 Update 8 (custom); before V8.1 Update 3 (custom); before V20 Update 3 (custom); before V4.0 (custom); before V3.1.2.2 (custom); before V3.0.6 (custom); before V2.3 (custom); before V2.2 (custom); before V18 Update 6 (custom); before V20 Update 4 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-427",
            "what_happened": "The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs an application that uses the affected setup component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cert-portal.siemens.com/productcert/html/ssa-282044.html"
            ],
            "timeline": [
                {
                    "at": "2025-08-12T12:15:34.733",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30033"
                }
            ]
        },
        {
            "id": "CVE-2025-29972",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2025-29972 exploit",
            "summary": "Exploit for CVE-2025-29927 and CVE-2025-29972. CVSS 9.9.",
            "updated_at": "2026-09-07T19:20:01Z",
            "published_at": "2026-09-07T19:20:01Z",
            "cvss": 9.9,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 34,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-07T19:20:01+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2025-29972 exploit",
                    "summary": "Exploit for CVE-2025-29927 and CVE-2025-29972. CVSS 9.9.",
                    "cvss": 9.9,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THEMEHACKERS-CVE-2025-29972"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THEMEHACKERS-CVE-2025-29972"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:20:01Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THEMEHACKERS-CVE-2025-29972"
                }
            ]
        },
        {
            "id": "CVE-2025-29927",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Next.js Middleware 15.2.2 -  Authorization Bypass",
            "summary": "Next.js Middleware 15.2.2 -  Authorization Bypass",
            "updated_at": "2026-09-05T12:41:19Z",
            "published_at": "2026-09-05T12:41:19Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 5546,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Next.js CVE-2025-29927 improper input handling or access control flaw with JWT and MySQL.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52124",
                    "author": "kOaDT",
                    "first_seen": "2025-04-05",
                    "confidence": "High",
                    "title": "Next.js Middleware 15.2.2 -  Authorization Bypass",
                    "summary": "Next.js Middleware 15.2.2 -  Authorization Bypass",
                    "url": "https://www.exploit-db.com/exploits/52124",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · serhalp/test-cve-2025-29927",
                    "author": "serhalp",
                    "first_seen": "2025-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Verify Next.js CVE-2025-29927 on Netlify not vulnerable",
                    "summary": "Verify Next.js CVE-2025-29927 on Netlify not vulnerable",
                    "url": "https://github.com/serhalp/test-cve-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · Ademking/CVE-2025-29927",
                    "author": "Ademking",
                    "first_seen": "2025-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Next.js Middleware Authorization Bypass",
                    "summary": "Next.js Middleware Authorization Bypass",
                    "url": "https://github.com/Ademking/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · 6mile/nextjs-CVE-2025-29927",
                    "author": "6mile",
                    "first_seen": "2025-03-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": "A Nuclei template to detect CVE-2025-29927 the Next.js authentication bypass vulnerability",
                    "summary": "A Nuclei template to detect CVE-2025-29927 the Next.js authentication bypass vulnerability",
                    "url": "https://github.com/6mile/nextjs-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · azu/nextjs-cve-2025-29927-poc",
                    "author": "azu",
                    "first_seen": "2025-03-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 15,
                    "title": "Next.js PoC for CVE-2025-29927",
                    "summary": "Next.js PoC for CVE-2025-29927",
                    "url": "https://github.com/azu/nextjs-cve-2025-29927-poc"
                },
                {
                    "repository": "PoC-in-GitHub · lirantal/vulnerable-nextjs-14-CVE-2025-29927",
                    "author": "lirantal",
                    "first_seen": "2025-03-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/lirantal/vulnerable-nextjs-14-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · aydinnyunus/CVE-2025-29927",
                    "author": "aydinnyunus",
                    "first_seen": "2025-03-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 103,
                    "title": "CVE-2025-29927 Proof of Concept",
                    "summary": "CVE-2025-29927 Proof of Concept",
                    "url": "https://github.com/aydinnyunus/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · ticofookfook/poc-nextjs-CVE-2025-29927",
                    "author": "ticofookfook",
                    "first_seen": "2025-03-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/ticofookfook/poc-nextjs-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · t3tra-dev/cve-2025-29927-demo",
                    "author": "t3tra-dev",
                    "first_seen": "2025-03-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Next.js における認可バイパスの脆弱性 CVE-2025-29927 を再現するデモです。",
                    "summary": "Next.js における認可バイパスの脆弱性 CVE-2025-29927 を再現するデモです。",
                    "url": "https://github.com/t3tra-dev/cve-2025-29927-demo"
                },
                {
                    "repository": "PoC-in-GitHub · websecnl/CVE-2025-29927-PoC-Exploit",
                    "author": "websecnl",
                    "first_seen": "2025-03-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 20,
                    "title": "Proof-of-Concept for Authorization Bypass in Next.js Middleware",
                    "summary": "Proof-of-Concept for Authorization Bypass in Next.js Middleware",
                    "url": "https://github.com/websecnl/CVE-2025-29927-PoC-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · MuhammadWaseem29/CVE-2025-29927-POC",
                    "author": "MuhammadWaseem29",
                    "first_seen": "2025-03-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "Authorization Bypass in Next.js Middleware",
                    "summary": "Authorization Bypass in Next.js Middleware",
                    "url": "https://github.com/MuhammadWaseem29/CVE-2025-29927-POC"
                },
                {
                    "repository": "PoC-in-GitHub · strobes-security/nextjs-vulnerable-app",
                    "author": "strobes-security",
                    "first_seen": "2025-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2025-29927 lab",
                    "summary": "CVE-2025-29927 lab",
                    "url": "https://github.com/strobes-security/nextjs-vulnerable-app"
                },
                {
                    "repository": "PoC-in-GitHub · RoyCampos/CVE-2025-29927",
                    "author": "RoyCampos",
                    "first_seen": "2025-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-29927 Exploit Checker",
                    "summary": "CVE-2025-29927 Exploit Checker",
                    "url": "https://github.com/RoyCampos/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · fourcube/nextjs-middleware-bypass-demo",
                    "author": "fourcube",
                    "first_seen": "2025-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Demo for Next.js middleware bypass - CVE-2025-29927",
                    "summary": "Demo for Next.js middleware bypass - CVE-2025-29927",
                    "url": "https://github.com/fourcube/nextjs-middleware-bypass-demo"
                },
                {
                    "repository": "PoC-in-GitHub · iSee857/CVE-2025-29927",
                    "author": "iSee857",
                    "first_seen": "2025-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Next.Js 权限绕过漏洞(CVE-2025-29927)",
                    "summary": "Next.Js 权限绕过漏洞(CVE-2025-29927)",
                    "url": "https://github.com/iSee857/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · Eve-SatOrU/POC-CVE-2025-29927",
                    "author": "Eve-SatOrU",
                    "first_seen": "2025-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2025-29927 Proof of Concept",
                    "summary": "CVE-2025-29927 Proof of Concept",
                    "url": "https://github.com/Eve-SatOrU/POC-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · arvion-agent/next-CVE-2025-29927",
                    "author": "arvion-agent",
                    "first_seen": "2025-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-29927 Authorization Bypass in Next.js Middleware",
                    "summary": "CVE-2025-29927 Authorization Bypass in Next.js Middleware",
                    "url": "https://github.com/arvion-agent/next-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · Oyst3r1ng/CVE-2025-29927",
                    "author": "Oyst3r1ng",
                    "first_seen": "2025-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Next.js Middleware Auth Bypass",
                    "summary": "Next.js Middleware Auth Bypass",
                    "url": "https://github.com/Oyst3r1ng/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · lem0n817/CVE-2025-29927",
                    "author": "lem0n817",
                    "first_seen": "2025-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Next.js 中间件授权绕过漏洞测试环境 (CVE-2025-29927)",
                    "summary": "Next.js 中间件授权绕过漏洞测试环境 (CVE-2025-29927)",
                    "url": "https://github.com/lem0n817/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · kuzushiki/CVE-2025-29927-test",
                    "author": "kuzushiki",
                    "first_seen": "2025-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-29927の検証",
                    "summary": "CVE-2025-29927の検証",
                    "url": "https://github.com/kuzushiki/CVE-2025-29927-test"
                },
                {
                    "repository": "PoC-in-GitHub · ricsirigu/CVE-2025-29927",
                    "author": "ricsirigu",
                    "first_seen": "2025-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass",
                    "summary": "A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass",
                    "url": "https://github.com/ricsirigu/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · 0xWhoknows/CVE-2025-29927",
                    "author": "0xWhoknows",
                    "first_seen": "2025-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Async Python scanner for Next.js CVE-2025-29927. Uses aiohttp & aiofiles to efficiently process large URL lists, detect vulnerabilities, and save results. Features connection pooling, caching, and chunked processing for fast performance",
                    "summary": "Async Python scanner for Next.js CVE-2025-29927. Uses aiohttp & aiofiles to efficiently process large URL lists, detect vulnerabilities, and save results. Features connection pooling, caching, and chunked processing for fast performance",
                    "url": "https://github.com/0xWhoknows/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · elshaheedy/CVE-2025-29927-Sigma-Rule",
                    "author": "elshaheedy",
                    "first_seen": "2025-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Sigma Rule for CVE-2025–29927 Detection",
                    "summary": "Sigma Rule for CVE-2025–29927 Detection",
                    "url": "https://github.com/elshaheedy/CVE-2025-29927-Sigma-Rule"
                },
                {
                    "repository": "PoC-in-GitHub · furmak331/CVE-2025-29927",
                    "author": "furmak331",
                    "first_seen": "2025-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Critical vulnerability in next.js : Bypass middleware authentication",
                    "summary": "Critical vulnerability in next.js : Bypass middleware authentication",
                    "url": "https://github.com/furmak331/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · phoscoder/ghost-route",
                    "author": "phoscoder",
                    "first_seen": "2025-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "Ghost Route detects if a Next JS site is vulnerable to the corrupt middleware bypass bug (CVE-2025-29927)",
                    "summary": "Ghost Route detects if a Next JS site is vulnerable to the corrupt middleware bypass bug (CVE-2025-29927)",
                    "url": "https://github.com/phoscoder/ghost-route"
                },
                {
                    "repository": "PoC-in-GitHub · 0xPb1/Next.js-CVE-2025-29927",
                    "author": "0xPb1",
                    "first_seen": "2025-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/0xPb1/Next.js-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · jeymo092/cve-2025-29927",
                    "author": "jeymo092",
                    "first_seen": "2025-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/jeymo092/cve-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · alihussainzada/CVE-2025-29927-PoC",
                    "author": "alihussainzada",
                    "first_seen": "2025-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes Docker setup for testing.",
                    "summary": "PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes Docker setup for testing.",
                    "url": "https://github.com/alihussainzada/CVE-2025-29927-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · TheresAFewConors/CVE-2025-29927-Testing",
                    "author": "TheresAFewConors",
                    "first_seen": "2025-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "PowerShell script to test if a web app is vulnerable to CVE-2025-29927",
                    "summary": "PowerShell script to test if a web app is vulnerable to CVE-2025-29927",
                    "url": "https://github.com/TheresAFewConors/CVE-2025-29927-Testing"
                },
                {
                    "repository": "PoC-in-GitHub · 0xPThree/next.js_cve-2025-29927",
                    "author": "0xPThree",
                    "first_seen": "2025-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/0xPThree/next.js_cve-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · 0xcucumbersalad/cve-2025-29927",
                    "author": "0xcucumbersalad",
                    "first_seen": "2025-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/0xcucumbersalad/cve-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · c0dejump/CVE-2025-29927-check",
                    "author": "c0dejump",
                    "first_seen": "2025-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "script to check cve \"CVE-2025-29927\" while waiting to add it to HExHTTP",
                    "summary": "script to check cve \"CVE-2025-29927\" while waiting to add it to HExHTTP",
                    "url": "https://github.com/c0dejump/CVE-2025-29927-check"
                },
                {
                    "repository": "PoC-in-GitHub · maronnjapan/claude-create-CVE-2025-29927",
                    "author": "maronnjapan",
                    "first_seen": "2025-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/maronnjapan/claude-create-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · kOaDT/poc-cve-2025-29927",
                    "author": "kOaDT",
                    "first_seen": "2025-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "This repository contains a proof of concept (POC) and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware.",
                    "summary": "This repository contains a proof of concept (POC) and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers to bypass authorization checks implemented in middleware.",
                    "url": "https://github.com/kOaDT/poc-cve-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · yugo-eliatrope/test-cve-2025-29927",
                    "author": "yugo-eliatrope",
                    "first_seen": "2025-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/yugo-eliatrope/test-cve-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · emadshanab/CVE-2025-29927",
                    "author": "emadshanab",
                    "first_seen": "2025-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "New nuclei CVE",
                    "summary": "New nuclei CVE",
                    "url": "https://github.com/emadshanab/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · w3shinew/CVE-2025-29927",
                    "author": "w3shinew",
                    "first_seen": "2025-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A touch of security",
                    "summary": "A touch of security",
                    "url": "https://github.com/w3shinew/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · aleongx/CVE-2025-29927",
                    "author": "aleongx",
                    "first_seen": "2025-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Next.js Acceso no autorizado CVE-2025-29927",
                    "summary": "Next.js Acceso no autorizado CVE-2025-29927",
                    "url": "https://github.com/aleongx/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · nicknisi/next-attack",
                    "author": "nicknisi",
                    "first_seen": "2025-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk",
                    "summary": "A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk",
                    "url": "https://github.com/nicknisi/next-attack"
                },
                {
                    "repository": "PoC-in-GitHub · jmbowes/NextSecureScan",
                    "author": "jmbowes",
                    "first_seen": "2025-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Next.js CVE-2025-29927 Vulnerability Scanner",
                    "summary": "Next.js CVE-2025-29927 Vulnerability Scanner",
                    "url": "https://github.com/jmbowes/NextSecureScan"
                },
                {
                    "repository": "PoC-in-GitHub · aleongx/CVE-2025-29927_Scanner",
                    "author": "aleongx",
                    "first_seen": "2025-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Este script verifica la vulnerabilidad CVE-2025-29927 en servidores Next.js, probando múltiples cargas en la cabecera x-middleware-subrequest para detectar accesos no autorizados.",
                    "summary": "Este script verifica la vulnerabilidad CVE-2025-29927 en servidores Next.js, probando múltiples cargas en la cabecera x-middleware-subrequest para detectar accesos no autorizados.",
                    "url": "https://github.com/aleongx/CVE-2025-29927_Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · Nekicj/CVE-2025-29927-exploit",
                    "author": "Nekicj",
                    "first_seen": "2025-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "next.js CVE-2025-29927 vulnerability exploit",
                    "summary": "next.js CVE-2025-29927 vulnerability exploit",
                    "url": "https://github.com/Nekicj/CVE-2025-29927-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Heimd411/CVE-2025-29927-PoC",
                    "author": "Heimd411",
                    "first_seen": "2025-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/Heimd411/CVE-2025-29927-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · m2hcz/PoC-for-Next.js-Middleware",
                    "author": "m2hcz",
                    "first_seen": "2025-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "> 🔓 Proof-of-Concept for a fictional Next.js middleware bypass (CVE-2025-29927) — craft sub-requests to test protected routes.",
                    "summary": "> 🔓 Proof-of-Concept for a fictional Next.js middleware bypass (CVE-2025-29927) — craft sub-requests to test protected routes.",
                    "url": "https://github.com/m2hcz/PoC-for-Next.js-Middleware"
                },
                {
                    "repository": "PoC-in-GitHub · nocomp/CVE-2025-29927-scanner",
                    "author": "nocomp",
                    "first_seen": "2025-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "python script for evaluate if you are vulnerable or not to next.js CVE-2025-29927",
                    "summary": "python script for evaluate if you are vulnerable or not to next.js CVE-2025-29927",
                    "url": "https://github.com/nocomp/CVE-2025-29927-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · yuzu-juice/CVE-2025-29927_demo",
                    "author": "yuzu-juice",
                    "first_seen": "2025-03-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository is for educational and research purposes.",
                    "summary": "This repository is for educational and research purposes.",
                    "url": "https://github.com/yuzu-juice/CVE-2025-29927_demo"
                },
                {
                    "repository": "PoC-in-GitHub · AnonKryptiQuz/NextSploit",
                    "author": "AnonKryptiQuz",
                    "first_seen": "2025-03-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 92,
                    "title": "NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js",
                    "summary": "NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js",
                    "url": "https://github.com/AnonKryptiQuz/NextSploit"
                },
                {
                    "repository": "PoC-in-GitHub · w2hcorp/CVE-2025-29927-PoC",
                    "author": "w2hcorp",
                    "first_seen": "2025-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Here is a simple but effective exploit for CVE-2025-29927.",
                    "summary": "Here is a simple but effective exploit for CVE-2025-29927.",
                    "url": "https://github.com/w2hcorp/CVE-2025-29927-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · ferpalma21/Automated-Next.js-Security-Scanner-for-CVE-2025-29927",
                    "author": "ferpalma21",
                    "first_seen": "2025-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist.",
                    "summary": "This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It optionally attempts exploitation using a wordlist.",
                    "url": "https://github.com/ferpalma21/Automated-Next.js-Security-Scanner-for-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · dante01yoon/CVE-2025-29927",
                    "author": "dante01yoon",
                    "first_seen": "2025-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Next.js CVE-2025-29927 demonstration",
                    "summary": "Next.js CVE-2025-29927 demonstration",
                    "url": "https://github.com/dante01yoon/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · ayato-shitomi/WebLab_CVE-2025-29927",
                    "author": "ayato-shitomi",
                    "first_seen": "2025-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Next.js Auth Bypass Lab ‐ CVE-2025-29927",
                    "summary": "Next.js Auth Bypass Lab ‐ CVE-2025-29927",
                    "url": "https://github.com/ayato-shitomi/WebLab_CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · Kamal-418/Vulnerable-Lab-NextJS-CVE-2025-29927",
                    "author": "Kamal-418",
                    "first_seen": "2025-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/Kamal-418/Vulnerable-Lab-NextJS-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · Ev3rPalestine/0xMiddleware",
                    "author": "Ev3rPalestine",
                    "first_seen": "2025-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927: Next.js Middleware Exploit",
                    "summary": "CVE-2025-29927: Next.js Middleware Exploit",
                    "url": "https://github.com/Ev3rPalestine/0xMiddleware"
                },
                {
                    "repository": "PoC-in-GitHub · dedibagus/cve-2025-29927-poc",
                    "author": "dedibagus",
                    "first_seen": "2025-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Authorization Bypass in Next.js Middleware",
                    "summary": "Authorization Bypass in Next.js Middleware",
                    "url": "https://github.com/dedibagus/cve-2025-29927-poc"
                },
                {
                    "repository": "PoC-in-GitHub · alastair66/CVE-2025-29927",
                    "author": "alastair66",
                    "first_seen": "2025-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Next.js Middleware Bypass Vulnerability",
                    "summary": "Next.js Middleware Bypass Vulnerability",
                    "url": "https://github.com/alastair66/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · 0xb1lal/CVE-2025-29927",
                    "author": "0xb1lal",
                    "first_seen": "2025-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Next.js CVE-2025-29927 güvenlik açığı hakkında",
                    "summary": "Next.js CVE-2025-29927 güvenlik açığı hakkında",
                    "url": "https://github.com/0xb1lal/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · JOOJIII/CVE-2025-29927",
                    "author": "JOOJIII",
                    "first_seen": "2025-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/JOOJIII/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · Naveen-005/Next.Js-middleware-bypass-vulnerability-CVE-2025-29927",
                    "author": "Naveen-005",
                    "first_seen": "2025-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A basic proof of concept of the CVE-2025-29927 vulnerability that allows to bypass the middleware scripts.",
                    "summary": "A basic proof of concept of the CVE-2025-29927 vulnerability that allows to bypass the middleware scripts.",
                    "url": "https://github.com/Naveen-005/Next.Js-middleware-bypass-vulnerability-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · Gokul-Krishnan-V-R/cve-2025-29927",
                    "author": "Gokul-Krishnan-V-R",
                    "first_seen": "2025-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Next.js and the corrupt middleware...TRY TO HACK IT..!",
                    "summary": "Next.js and the corrupt middleware...TRY TO HACK IT..!",
                    "url": "https://github.com/Gokul-Krishnan-V-R/cve-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · fahimalshihab/NextBypass",
                    "author": "fahimalshihab",
                    "first_seen": "2025-04-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Next.js Middleware Authorization Bypass Tool (CVE-2025-29927)",
                    "summary": "Next.js Middleware Authorization Bypass Tool (CVE-2025-29927)",
                    "url": "https://github.com/fahimalshihab/NextBypass"
                },
                {
                    "repository": "PoC-in-GitHub · all3njk/NextJS_CVE-2025-29927",
                    "author": "all3njk",
                    "first_seen": "2025-04-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/all3njk/NextJS_CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · Balajih4kr/cve-2025-29927",
                    "author": "Balajih4kr",
                    "first_seen": "2025-04-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles certain internal headers — specifically, the x-middleware-subrequest header",
                    "summary": "CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles certain internal headers — specifically, the x-middleware-subrequest header",
                    "url": "https://github.com/Balajih4kr/cve-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · YEONDG/nextjs-cve-2025-29927",
                    "author": "YEONDG",
                    "first_seen": "2025-04-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "vulnerable-nextjs-14-CVE-2025-29927",
                    "summary": "vulnerable-nextjs-14-CVE-2025-29927",
                    "url": "https://github.com/YEONDG/nextjs-cve-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · gotr00t0day/CVE-2025-29927",
                    "author": "gotr00t0day",
                    "first_seen": "2025-04-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "Next.js Middleware Bypass Scanne",
                    "summary": "Next.js Middleware Bypass Scanne",
                    "url": "https://github.com/gotr00t0day/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · pixilated730/NextJS-Exploit-",
                    "author": "pixilated730",
                    "first_seen": "2025-04-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-29927",
                    "summary": "CVE-2025-29927",
                    "url": "https://github.com/pixilated730/NextJS-Exploit-"
                },
                {
                    "repository": "PoC-in-GitHub · ValGrace/middleware-auth-bypass",
                    "author": "ValGrace",
                    "first_seen": "2025-04-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 ~ a poc of the next.js middleware authentication bypass",
                    "summary": "CVE-2025-29927 ~ a poc of the next.js middleware authentication bypass",
                    "url": "https://github.com/ValGrace/middleware-auth-bypass"
                },
                {
                    "repository": "PoC-in-GitHub · 0xnxt1me/CVE-2025-29927",
                    "author": "0xnxt1me",
                    "first_seen": "2025-04-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/0xnxt1me/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · pickovven/vulnerable-nextjs-14-CVE-2025-29927",
                    "author": "pickovven",
                    "first_seen": "2025-04-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/pickovven/vulnerable-nextjs-14-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · l1uk/nextjs-middleware-exploit",
                    "author": "l1uk",
                    "first_seen": "2025-04-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Research on Next.js middleware vulnerability (CVE-2025-29927) allowing authorization bypass and potential exploits.",
                    "summary": "Research on Next.js middleware vulnerability (CVE-2025-29927) allowing authorization bypass and potential exploits.",
                    "url": "https://github.com/l1uk/nextjs-middleware-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · darklotuskdb/nextjs-CVE-2025-29927-hunter",
                    "author": "darklotuskdb",
                    "first_seen": "2025-04-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Next.js CVE-2025-29927 Hunter",
                    "summary": "Next.js CVE-2025-29927 Hunter",
                    "url": "https://github.com/darklotuskdb/nextjs-CVE-2025-29927-hunter"
                },
                {
                    "repository": "PoC-in-GitHub · ethanol1310/POC-CVE-2025-29927-",
                    "author": "ethanol1310",
                    "first_seen": "2025-04-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "POC CVE-2025-29927",
                    "summary": "POC CVE-2025-29927",
                    "url": "https://github.com/ethanol1310/POC-CVE-2025-29927-"
                },
                {
                    "repository": "PoC-in-GitHub · UNICORDev/exploit-CVE-2025-29927",
                    "author": "UNICORDev",
                    "first_seen": "2025-04-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "Exploit for CVE-2025-29927 (Next.js) - Authorization Bypass",
                    "summary": "Exploit for CVE-2025-29927 (Next.js) - Authorization Bypass",
                    "url": "https://github.com/UNICORDev/exploit-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · Knotsecurity/CVE-2025-29927-NextJs-Middleware-Simulation",
                    "author": "Knotsecurity",
                    "first_seen": "2025-04-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal x-middleware-subrequest HTTP header. Demonstrates unauthorized access to protected routes and provides mitigation strategies.",
                    "summary": "Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal x-middleware-subrequest HTTP header. Demonstrates unauthorized access to protected routes and provides mitigation strategies.",
                    "url": "https://github.com/Knotsecurity/CVE-2025-29927-NextJs-Middleware-Simulation"
                },
                {
                    "repository": "PoC-in-GitHub · mhamzakhattak/CVE-2025-29927",
                    "author": "mhamzakhattak",
                    "first_seen": "2025-04-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/mhamzakhattak/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · enochgitgamefied/NextJS-CVE-2025-29927",
                    "author": "enochgitgamefied",
                    "first_seen": "2025-04-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/enochgitgamefied/NextJS-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · Grand-Moomin/Vuln-Next.js-CVE-2025-29927",
                    "author": "Grand-Moomin",
                    "first_seen": "2025-04-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/Grand-Moomin/Vuln-Next.js-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · pouriam23/Next.js-Middleware-Bypass-CVE-2025-29927-",
                    "author": "pouriam23",
                    "first_seen": "2025-04-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/pouriam23/Next.js-Middleware-Bypass-CVE-2025-29927-"
                },
                {
                    "repository": "PoC-in-GitHub · kh4sh3i/CVE-2025-29927",
                    "author": "kh4sh3i",
                    "first_seen": "2025-04-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-29927: Next.js Middleware Bypass Vulnerability",
                    "summary": "CVE-2025-29927: Next.js Middleware Bypass Vulnerability",
                    "url": "https://github.com/kh4sh3i/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · EQSTLab/CVE-2025-29927",
                    "author": "EQSTLab",
                    "first_seen": "2025-04-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Next.js middleware bypass exploit",
                    "summary": "Next.js middleware bypass exploit",
                    "url": "https://github.com/EQSTLab/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · Hirainsingadia/CVE-2025-29927",
                    "author": "Hirainsingadia",
                    "first_seen": "2025-04-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Next js middlewareauth Bypass",
                    "summary": "Next js middlewareauth Bypass",
                    "url": "https://github.com/Hirainsingadia/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · HoumanPashaei/CVE-2025-29927",
                    "author": "HoumanPashaei",
                    "first_seen": "2025-04-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "This is a CVE-2025-29927 Scanner.",
                    "summary": "This is a CVE-2025-29927 Scanner.",
                    "url": "https://github.com/HoumanPashaei/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · rubbxalc/CVE-2025-29927",
                    "author": "rubbxalc",
                    "first_seen": "2025-04-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/rubbxalc/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · olimpiofreitas/CVE-2025-29927-scanner",
                    "author": "olimpiofreitas",
                    "first_seen": "2025-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/olimpiofreitas/CVE-2025-29927-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · moften/CVE-2025-29927_Next.js_Auth_Bypass",
                    "author": "moften",
                    "first_seen": "2025-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Next.js Auth Bypass PoC Edge Runtime Env Leak via Middleware Bug",
                    "summary": "Next.js Auth Bypass PoC Edge Runtime Env Leak via Middleware Bug",
                    "url": "https://github.com/moften/CVE-2025-29927_Next.js_Auth_Bypass"
                },
                {
                    "repository": "PoC-in-GitHub · EarthAngel666/x-middleware-exploit",
                    "author": "EarthAngel666",
                    "first_seen": "2025-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "x-middleware exploit for next.js CVE-2023–46298 cache poisoning and CVE-2025-29927 bypass",
                    "summary": "x-middleware exploit for next.js CVE-2023–46298 cache poisoning and CVE-2025-29927 bypass",
                    "url": "https://github.com/EarthAngel666/x-middleware-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · lstudlo/nextjs-cve-demo",
                    "author": "lstudlo",
                    "first_seen": "2025-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。",
                    "summary": "演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。",
                    "url": "https://github.com/lstudlo/nextjs-cve-demo"
                },
                {
                    "repository": "PoC-in-GitHub · enochgitgamefied/NextJS-CVE-2025-29927-Docker-Lab",
                    "author": "enochgitgamefied",
                    "first_seen": "2025-05-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/enochgitgamefied/NextJS-CVE-2025-29927-Docker-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · sagsooz/CVE-2025-29927",
                    "author": "sagsooz",
                    "first_seen": "2025-05-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "🔐 Python-based smart scanner for CVE-2025-29927 — Next.js middleware authentication bypass vulnerability. Detects meta refresh, keyword-based redirects, and more.",
                    "summary": "🔐 Python-based smart scanner for CVE-2025-29927 — Next.js middleware authentication bypass vulnerability. Detects meta refresh, keyword-based redirects, and more.",
                    "url": "https://github.com/sagsooz/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · SugiB3o/vulnerable-nextjs-14-CVE-2025-29927",
                    "author": "SugiB3o",
                    "first_seen": "2025-05-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "vulnerable-nextjs-14-CVE-2025-29927",
                    "summary": "vulnerable-nextjs-14-CVE-2025-29927",
                    "url": "https://github.com/SugiB3o/vulnerable-nextjs-14-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · amitlttwo/Next.JS-CVE-2025-29927",
                    "author": "amitlttwo",
                    "first_seen": "2025-06-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/amitlttwo/Next.JS-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · kazuya256/next-js-auth-bypass",
                    "author": "kazuya256",
                    "first_seen": "2025-07-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "🔓 Next.js Auth Bypass Demo - Educational application demonstrating CVE-2025-29927 middleware authentication bypass vulnerability . ⚠️ For educational use only.[Made using Ai]",
                    "summary": "🔓 Next.js Auth Bypass Demo - Educational application demonstrating CVE-2025-29927 middleware authentication bypass vulnerability . ⚠️ For educational use only.[Made using Ai]",
                    "url": "https://github.com/kazuya256/next-js-auth-bypass"
                },
                {
                    "repository": "PoC-in-GitHub · mickhacking/Thank-u-Next",
                    "author": "mickhacking",
                    "first_seen": "2025-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 PoC | Auth Bypass Exploit | Python Tool using httpx | Middleware Vulnerability | Ethical Hacking Toolkit",
                    "summary": "CVE-2025-29927 PoC | Auth Bypass Exploit | Python Tool using httpx | Middleware Vulnerability | Ethical Hacking Toolkit",
                    "url": "https://github.com/mickhacking/Thank-u-Next"
                },
                {
                    "repository": "PoC-in-GitHub · b4sh0xf/PoC-CVE-2025-29927",
                    "author": "b4sh0xf",
                    "first_seen": "2025-07-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "→ poc for CVE-2025-29927",
                    "summary": "→ poc for CVE-2025-29927",
                    "url": "https://github.com/b4sh0xf/PoC-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · rgvillanueva28/vulnbox-easy-CVE-2025-29927",
                    "author": "rgvillanueva28",
                    "first_seen": "2025-07-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/rgvillanueva28/vulnbox-easy-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · s11s11/CVE-2025-29927",
                    "author": "s11s11",
                    "first_seen": "2025-08-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Demo of CVE-2025-29927 for secure programming class",
                    "summary": "Demo of CVE-2025-29927 for secure programming class",
                    "url": "https://github.com/s11s11/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · R3verseIN/Nextjs-middleware-vulnerable-appdemo-CVE-2025-29927",
                    "author": "R3verseIN",
                    "first_seen": "2025-08-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/R3verseIN/Nextjs-middleware-vulnerable-appdemo-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · zs1n/CVE-2025-29927",
                    "author": "zs1n",
                    "first_seen": "2025-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC | NextJS Middleware 15.2.2 - Authorization Bypass",
                    "summary": "PoC | NextJS Middleware 15.2.2 - Authorization Bypass",
                    "url": "https://github.com/zs1n/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · MKIRAHMET/CVE-2025-29927-PoC",
                    "author": "MKIRAHMET",
                    "first_seen": "2025-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository contains **research and analysis** related to CVE-2025-29927.   It demonstrates safe, controlled testing approaches for a path traversal/middleware misconfiguration vulnerability in web applications.",
                    "summary": "This repository contains **research and analysis** related to CVE-2025-29927.   It demonstrates safe, controlled testing approaches for a path traversal/middleware misconfiguration vulnerability in web applications.",
                    "url": "https://github.com/MKIRAHMET/CVE-2025-29927-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · adjscent/vulnerable-nextjs-14-CVE-2025-29927",
                    "author": "adjscent",
                    "first_seen": "2025-09-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "do not use. vulnerable",
                    "summary": "do not use. vulnerable",
                    "url": "https://github.com/adjscent/vulnerable-nextjs-14-CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · sdrtba/CVE-2025-29927",
                    "author": "sdrtba",
                    "first_seen": "2025-09-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/sdrtba/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · iteride/CVE-2025-29927",
                    "author": "iteride",
                    "first_seen": "2025-09-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/iteride/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · sermikr0/nextjs-middleware-auth-bypass",
                    "author": "sermikr0",
                    "first_seen": "2025-09-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-29927",
                    "summary": "CVE-2025-29927",
                    "url": "https://github.com/sermikr0/nextjs-middleware-auth-bypass"
                },
                {
                    "repository": "PoC-in-GitHub · amalpvatayam67/day10-nextjs-middleware-lab",
                    "author": "amalpvatayam67",
                    "first_seen": "2025-09-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Next.js middleware auth-bypass lab (CVE-2025-29927 simulation)",
                    "summary": "Next.js middleware auth-bypass lab (CVE-2025-29927 simulation)",
                    "url": "https://github.com/amalpvatayam67/day10-nextjs-middleware-lab"
                },
                {
                    "repository": "PoC-in-GitHub · diogolourencodev/middleforce",
                    "author": "diogolourencodev",
                    "first_seen": "2025-10-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Simple script to attempt a Bypass on a server possibly vulnerable to CVE-2025-29927 (Next.js Middleware)",
                    "summary": "Simple script to attempt a Bypass on a server possibly vulnerable to CVE-2025-29927 (Next.js Middleware)",
                    "url": "https://github.com/diogolourencodev/middleforce"
                },
                {
                    "repository": "PoC-in-GitHub · Bongni/CVE-2025-29927",
                    "author": "Bongni",
                    "first_seen": "2025-10-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Reproduction and fix of the CVE-2025-29927 vulnerability.",
                    "summary": "Reproduction and fix of the CVE-2025-29927 vulnerability.",
                    "url": "https://github.com/Bongni/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · NS-Projects-Unina/CTF_CVE_DSP_1",
                    "author": "NS-Projects-Unina",
                    "first_seen": "2025-10-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Una CTF, in formato DSP-compliant, basata sulla CVE-2025-29927 di nextjs.",
                    "summary": "Una CTF, in formato DSP-compliant, basata sulla CVE-2025-29927 di nextjs.",
                    "url": "https://github.com/NS-Projects-Unina/CTF_CVE_DSP_1"
                },
                {
                    "repository": "PoC-in-GitHub · lucaschanzx/CVE-2025-29927-PoC",
                    "author": "lucaschanzx",
                    "first_seen": "2025-10-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/lucaschanzx/CVE-2025-29927-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · liamromanis101/CVE-2025-29927-NextJS",
                    "author": "liamromanis101",
                    "first_seen": "2025-12-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC for testing CVE-2025-29927 for Next.js versions 11.x, 12.x <= 12.3.5, 13.x <= 13.5.9, 14.x <=14.2.25, 15.x <= 15.2.3",
                    "summary": "PoC for testing CVE-2025-29927 for Next.js versions 11.x, 12.x <= 12.3.5, 13.x <= 13.5.9, 14.x <=14.2.25, 15.x <= 15.2.3",
                    "url": "https://github.com/liamromanis101/CVE-2025-29927-NextJS"
                },
                {
                    "repository": "PoC-in-GitHub · DanielHallbro/CVE-2025-29927-Nextjs-Bypass-PoC",
                    "author": "DanielHallbro",
                    "first_seen": "2026-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9",
                    "summary": "A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9",
                    "url": "https://github.com/DanielHallbro/CVE-2025-29927-Nextjs-Bypass-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · Si-Ni/CVE-2025-29927-Proof-of-Concept",
                    "author": "Si-Ni",
                    "first_seen": "2026-02-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Capture the Flag challenge: CVE-2025-29927 in combination with a command injection vulnerability",
                    "summary": "Capture the Flag challenge: CVE-2025-29927 in combination with a command injection vulnerability",
                    "url": "https://github.com/Si-Ni/CVE-2025-29927-Proof-of-Concept"
                },
                {
                    "repository": "PoC-in-GitHub · sangrok-jeon/CVE-2025-29927-Nextjs-Analysis",
                    "author": "sangrok-jeon",
                    "first_seen": "2026-03-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-29927-Nextjs 분석 보고서",
                    "summary": "CVE-2025-29927-Nextjs 분석 보고서",
                    "url": "https://github.com/sangrok-jeon/CVE-2025-29927-Nextjs-Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · Toddkk02/CVE-2025-29927",
                    "author": "Toddkk02",
                    "first_seen": "2026-03-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/Toddkk02/CVE-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · hujiaozhuzhu/CVE-2025-29927__Next.js",
                    "author": "hujiaozhuzhu",
                    "first_seen": "2026-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 - Next.js漏洞测试工具",
                    "summary": "CVE-2025-29927 - Next.js漏洞测试工具",
                    "url": "https://github.com/hujiaozhuzhu/CVE-2025-29927__Next.js"
                },
                {
                    "repository": "PoC-in-GitHub · metasploit403/cve-2025-29927-lab",
                    "author": "metasploit403",
                    "first_seen": "2026-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Deliberately vulnerable Next.js application demonstrating CVE-2025-29927 (middleware-based auth bypass) for learning and bug bounty practice.",
                    "summary": "Deliberately vulnerable Next.js application demonstrating CVE-2025-29927 (middleware-based auth bypass) for learning and bug bounty practice.",
                    "url": "https://github.com/metasploit403/cve-2025-29927-lab"
                },
                {
                    "repository": "PoC-in-GitHub · shahin-shadow/nextjs-auth-bypass",
                    "author": "shahin-shadow",
                    "first_seen": "2026-04-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Analysis and exploitation of a Next.js authorization bypass vulnerability (CVE-2025-29927)",
                    "summary": "Analysis and exploitation of a Next.js authorization bypass vulnerability (CVE-2025-29927)",
                    "url": "https://github.com/shahin-shadow/nextjs-auth-bypass"
                },
                {
                    "repository": "PoC-in-GitHub · TheWaterbug/alpr-dashboard-patches",
                    "author": "TheWaterbug",
                    "first_seen": "2026-04-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Runtime patches for algertc/alpr-dashboard: async logger fix and CVE-2025-29927 nginx mitigation",
                    "summary": "Runtime patches for algertc/alpr-dashboard: async logger fix and CVE-2025-29927 nginx mitigation",
                    "url": "https://github.com/TheWaterbug/alpr-dashboard-patches"
                },
                {
                    "repository": "PoC-in-GitHub · Nayekah/Next.js-Proof-of-Concept",
                    "author": "Nayekah",
                    "first_seen": "2026-04-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Some Proof-of-Concept (POCs) for CVE-2025-29927, CVE-2026-27978, and CVE-2026-29057 in Next.js.",
                    "summary": "Some Proof-of-Concept (POCs) for CVE-2025-29927, CVE-2026-27978, and CVE-2026-29057 in Next.js.",
                    "url": "https://github.com/Nayekah/Next.js-Proof-of-Concept"
                },
                {
                    "repository": "PoC-in-GitHub · bk-security/auth-header-trust-rules",
                    "author": "bk-security",
                    "first_seen": "2026-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.",
                    "summary": "Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.",
                    "url": "https://github.com/bk-security/auth-header-trust-rules"
                },
                {
                    "repository": "PoC-in-GitHub · gitgudKrish/cve-2025-29927-nextjs",
                    "author": "gitgudKrish",
                    "first_seen": "2026-05-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/gitgudKrish/cve-2025-29927-nextjs"
                },
                {
                    "repository": "PoC-in-GitHub · SwapnilDeshpande/cve-2025-29927-lab",
                    "author": "SwapnilDeshpande",
                    "first_seen": "2026-06-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Reproduction lab for CVE-2025-29927 — Next.js middleware authorization bypass (CVSS 9.1)",
                    "summary": "Reproduction lab for CVE-2025-29927 — Next.js middleware authorization bypass (CVSS 9.1)",
                    "url": "https://github.com/SwapnilDeshpande/cve-2025-29927-lab"
                },
                {
                    "repository": "PoC-in-GitHub · Fomovet/cve-2025-29927",
                    "author": "Fomovet",
                    "first_seen": "2026-06-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "POC for CVE-2025-29927",
                    "summary": "POC for CVE-2025-29927",
                    "url": "https://github.com/Fomovet/cve-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · berraesen/nextjs-middleware-auth-bypass-lab",
                    "author": "berraesen",
                    "first_seen": "2026-08-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile yetkilendirme mekanizmasını kurduktan sonra Burp Suite kullanarak CVE-2025-29927 zafiyetini kontrollü ortamda gösterdim.",
                    "summary": "Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile yetkilendirme mekanizmasını kurduktan sonra Burp Suite kullanarak CVE-2025-29927 zafiyetini kontrollü ortamda gösterdim.",
                    "url": "https://github.com/berraesen/nextjs-middleware-auth-bypass-lab"
                },
                {
                    "repository": "PoC-in-GitHub · kuyrathdaro/cve-2025-29927",
                    "author": "kuyrathdaro",
                    "first_seen": "2026-08-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/kuyrathdaro/cve-2025-29927"
                },
                {
                    "repository": "PoC-in-GitHub · Ritinify/CVE-2025-29927-PoC",
                    "author": "Ritinify",
                    "first_seen": "2026-09-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-29927 repository",
                    "summary": "",
                    "url": "https://github.com/Ritinify/CVE-2025-29927-PoC"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-05T12:41:19+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Exploit for Improper Authorization in Vercel Next.Js",
                    "summary": "Proof-of-concept exploit for CVE-2025-29927. CVSS 9.1.",
                    "cvss": 9.1,
                    "url": "https://sploitus.com/exploit?id=DD629C00-2E2D-5D29-B5B7-1E74EAF37DBF"
                },
                {
                    "title": "Exploit for NextJS-CVE-2025-29927",
                    "summary": "Next.js CVE-2025-29927 improper input handling or access control flaw with JWT and MySQL.",
                    "what_happened": "Next.js CVE-2025-29927 improper input handling or access control flaw with JWT and MySQL.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ENOCHGITGAMEFIED-NEXTJS-CVE-2025-29927",
                        "https://kitploit.com/ru/tools/github/enochgitgamefied/nextjs-cve-2025-29927/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-30T08:54:09",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ENOCHGITGAMEFIED-NEXTJS-CVE-2025-29927"
                },
                {
                    "title": "Exploit for NextJS-CVE-2025-29927",
                    "summary": "Next.js CVE-2025-29927 improper input handling or access control flaw with JWT and MySQL.",
                    "what_happened": "Next.js CVE-2025-29927 improper input handling or access control flaw with JWT and MySQL.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ENOCHGITGAMEFIED-NEXTJS-CVE-2025-29927",
                        "https://kitploit.com/ru/tools/github/enochgitgamefied/nextjs-cve-2025-29927/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-30T08:54:09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/enochgitgamefied/nextjs-cve-2025-29927/"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-07T19:20:01+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2025-29972 exploit",
                    "summary": "Exploit for CVE-2025-29927 and CVE-2025-29972. CVSS 9.9.",
                    "cvss": 9.9,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THEMEHACKERS-CVE-2025-29972"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-11T18:31:19+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2025-29927 exploit",
                    "summary": "Exploit for CVE-2025-29927. CVSS 9.1.",
                    "cvss": 9.1,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AYDINNYUNUS-CVE-2025-29927"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52124",
                "https://github.com/serhalp/test-cve-2025-29927",
                "https://github.com/Ademking/CVE-2025-29927",
                "https://github.com/6mile/nextjs-CVE-2025-29927",
                "https://github.com/azu/nextjs-cve-2025-29927-poc",
                "https://github.com/lirantal/vulnerable-nextjs-14-CVE-2025-29927",
                "https://github.com/aydinnyunus/CVE-2025-29927",
                "https://github.com/ticofookfook/poc-nextjs-CVE-2025-29927",
                "https://github.com/t3tra-dev/cve-2025-29927-demo",
                "https://github.com/websecnl/CVE-2025-29927-PoC-Exploit",
                "https://github.com/MuhammadWaseem29/CVE-2025-29927-POC",
                "https://github.com/strobes-security/nextjs-vulnerable-app",
                "https://github.com/RoyCampos/CVE-2025-29927",
                "https://github.com/fourcube/nextjs-middleware-bypass-demo",
                "https://github.com/iSee857/CVE-2025-29927",
                "https://github.com/Eve-SatOrU/POC-CVE-2025-29927",
                "https://github.com/arvion-agent/next-CVE-2025-29927",
                "https://github.com/Oyst3r1ng/CVE-2025-29927",
                "https://github.com/lem0n817/CVE-2025-29927",
                "https://github.com/kuzushiki/CVE-2025-29927-test",
                "https://github.com/ricsirigu/CVE-2025-29927",
                "https://github.com/0xWhoknows/CVE-2025-29927",
                "https://github.com/elshaheedy/CVE-2025-29927-Sigma-Rule",
                "https://github.com/furmak331/CVE-2025-29927",
                "https://github.com/phoscoder/ghost-route",
                "https://github.com/0xPb1/Next.js-CVE-2025-29927",
                "https://github.com/jeymo092/cve-2025-29927",
                "https://github.com/alihussainzada/CVE-2025-29927-PoC",
                "https://github.com/TheresAFewConors/CVE-2025-29927-Testing",
                "https://github.com/0xPThree/next.js_cve-2025-29927",
                "https://github.com/0xcucumbersalad/cve-2025-29927",
                "https://github.com/c0dejump/CVE-2025-29927-check",
                "https://github.com/maronnjapan/claude-create-CVE-2025-29927",
                "https://github.com/kOaDT/poc-cve-2025-29927",
                "https://github.com/yugo-eliatrope/test-cve-2025-29927",
                "https://github.com/emadshanab/CVE-2025-29927",
                "https://github.com/w3shinew/CVE-2025-29927",
                "https://github.com/aleongx/CVE-2025-29927",
                "https://github.com/nicknisi/next-attack",
                "https://github.com/jmbowes/NextSecureScan",
                "https://github.com/aleongx/CVE-2025-29927_Scanner",
                "https://github.com/Nekicj/CVE-2025-29927-exploit",
                "https://github.com/Heimd411/CVE-2025-29927-PoC",
                "https://github.com/m2hcz/PoC-for-Next.js-Middleware",
                "https://github.com/nocomp/CVE-2025-29927-scanner",
                "https://github.com/yuzu-juice/CVE-2025-29927_demo",
                "https://github.com/AnonKryptiQuz/NextSploit",
                "https://github.com/w2hcorp/CVE-2025-29927-PoC",
                "https://github.com/ferpalma21/Automated-Next.js-Security-Scanner-for-CVE-2025-29927",
                "https://github.com/dante01yoon/CVE-2025-29927",
                "https://github.com/ayato-shitomi/WebLab_CVE-2025-29927",
                "https://github.com/Kamal-418/Vulnerable-Lab-NextJS-CVE-2025-29927",
                "https://github.com/Ev3rPalestine/0xMiddleware",
                "https://github.com/dedibagus/cve-2025-29927-poc",
                "https://github.com/alastair66/CVE-2025-29927",
                "https://github.com/0xb1lal/CVE-2025-29927",
                "https://github.com/JOOJIII/CVE-2025-29927",
                "https://github.com/Naveen-005/Next.Js-middleware-bypass-vulnerability-CVE-2025-29927",
                "https://github.com/Gokul-Krishnan-V-R/cve-2025-29927",
                "https://github.com/fahimalshihab/NextBypass",
                "https://github.com/all3njk/NextJS_CVE-2025-29927",
                "https://github.com/Balajih4kr/cve-2025-29927",
                "https://github.com/YEONDG/nextjs-cve-2025-29927",
                "https://github.com/gotr00t0day/CVE-2025-29927",
                "https://github.com/pixilated730/NextJS-Exploit-",
                "https://github.com/ValGrace/middleware-auth-bypass",
                "https://github.com/0xnxt1me/CVE-2025-29927",
                "https://github.com/pickovven/vulnerable-nextjs-14-CVE-2025-29927",
                "https://github.com/l1uk/nextjs-middleware-exploit",
                "https://github.com/darklotuskdb/nextjs-CVE-2025-29927-hunter",
                "https://github.com/ethanol1310/POC-CVE-2025-29927-",
                "https://github.com/UNICORDev/exploit-CVE-2025-29927",
                "https://github.com/Knotsecurity/CVE-2025-29927-NextJs-Middleware-Simulation",
                "https://github.com/mhamzakhattak/CVE-2025-29927",
                "https://github.com/enochgitgamefied/NextJS-CVE-2025-29927",
                "https://github.com/Grand-Moomin/Vuln-Next.js-CVE-2025-29927",
                "https://github.com/pouriam23/Next.js-Middleware-Bypass-CVE-2025-29927-",
                "https://github.com/kh4sh3i/CVE-2025-29927",
                "https://github.com/EQSTLab/CVE-2025-29927",
                "https://github.com/Hirainsingadia/CVE-2025-29927",
                "https://github.com/HoumanPashaei/CVE-2025-29927",
                "https://github.com/rubbxalc/CVE-2025-29927",
                "https://github.com/olimpiofreitas/CVE-2025-29927-scanner",
                "https://github.com/moften/CVE-2025-29927_Next.js_Auth_Bypass",
                "https://github.com/EarthAngel666/x-middleware-exploit",
                "https://github.com/lstudlo/nextjs-cve-demo",
                "https://github.com/enochgitgamefied/NextJS-CVE-2025-29927-Docker-Lab",
                "https://github.com/sagsooz/CVE-2025-29927",
                "https://github.com/SugiB3o/vulnerable-nextjs-14-CVE-2025-29927",
                "https://github.com/amitlttwo/Next.JS-CVE-2025-29927",
                "https://github.com/kazuya256/next-js-auth-bypass",
                "https://github.com/mickhacking/Thank-u-Next",
                "https://github.com/b4sh0xf/PoC-CVE-2025-29927",
                "https://github.com/rgvillanueva28/vulnbox-easy-CVE-2025-29927",
                "https://github.com/s11s11/CVE-2025-29927",
                "https://github.com/R3verseIN/Nextjs-middleware-vulnerable-appdemo-CVE-2025-29927",
                "https://github.com/zs1n/CVE-2025-29927",
                "https://github.com/MKIRAHMET/CVE-2025-29927-PoC",
                "https://github.com/adjscent/vulnerable-nextjs-14-CVE-2025-29927",
                "https://github.com/sdrtba/CVE-2025-29927",
                "https://github.com/iteride/CVE-2025-29927",
                "https://github.com/sermikr0/nextjs-middleware-auth-bypass",
                "https://github.com/amalpvatayam67/day10-nextjs-middleware-lab",
                "https://github.com/diogolourencodev/middleforce",
                "https://github.com/Bongni/CVE-2025-29927",
                "https://github.com/NS-Projects-Unina/CTF_CVE_DSP_1",
                "https://github.com/lucaschanzx/CVE-2025-29927-PoC",
                "https://github.com/liamromanis101/CVE-2025-29927-NextJS",
                "https://github.com/DanielHallbro/CVE-2025-29927-Nextjs-Bypass-PoC",
                "https://github.com/Si-Ni/CVE-2025-29927-Proof-of-Concept",
                "https://github.com/sangrok-jeon/CVE-2025-29927-Nextjs-Analysis",
                "https://github.com/Toddkk02/CVE-2025-29927",
                "https://github.com/hujiaozhuzhu/CVE-2025-29927__Next.js",
                "https://github.com/metasploit403/cve-2025-29927-lab",
                "https://github.com/shahin-shadow/nextjs-auth-bypass",
                "https://github.com/TheWaterbug/alpr-dashboard-patches",
                "https://github.com/Nayekah/Next.js-Proof-of-Concept",
                "https://github.com/bk-security/auth-header-trust-rules",
                "https://github.com/gitgudKrish/cve-2025-29927-nextjs",
                "https://github.com/SwapnilDeshpande/cve-2025-29927-lab",
                "https://github.com/Fomovet/cve-2025-29927",
                "https://github.com/berraesen/nextjs-middleware-auth-bypass-lab",
                "https://github.com/kuyrathdaro/cve-2025-29927",
                "https://github.com/Ritinify/CVE-2025-29927-PoC",
                "https://sploitus.com/exploit?id=DD629C00-2E2D-5D29-B5B7-1E74EAF37DBF",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ENOCHGITGAMEFIED-NEXTJS-CVE-2025-29927",
                "https://kitploit.com/ru/tools/github/enochgitgamefied/nextjs-cve-2025-29927/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THEMEHACKERS-CVE-2025-29972",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AYDINNYUNUS-CVE-2025-29927"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:41:19Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52124"
                }
            ]
        },
        {
            "id": "CVE-2025-26790",
            "vendor": "WithSecure",
            "product": "Atlant",
            "title": "Atlant vulnerability",
            "summary": "Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.",
            "updated_at": "2026-09-14T07:17:16.267",
            "published_at": "2026-09-14T07:17:16.267",
            "cvss": 3.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before Capricorn 2025-01-20_02 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-125",
            "what_happened": "Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://Withsecure.com",
                "https://support.withsecure.com/en/security-advisories/cve-2025-26790/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T07:17:16.267",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26790"
                }
            ]
        },
        {
            "id": "CVE-2025-25257",
            "vendor": "Fortinet",
            "product": "FortiWeb",
            "title": "Fortinet FortiWeb SQL Injection Vulnerability",
            "summary": "Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.",
            "updated_at": "2026-09-04T06:47:50Z",
            "published_at": "2026-09-04T06:47:50Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 317,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52473",
                    "author": "Milad Karimi (Ex3ptionaL)",
                    "first_seen": "2026-02-04",
                    "confidence": "High",
                    "title": "FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution",
                    "summary": "FortiWeb Fabric Connector 7.6.x - SQL Injection to Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/52473",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2025-25257",
                    "summary": "Pre-auth SQL injection to RCE in FortiWeb Fabric Connector enabling arbitrary command execution.",
                    "what_happened": "Pre-auth SQL injection to RCE in FortiWeb Fabric Connector enabling arbitrary command execution.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-89",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THESTINGR-CVE-2025-25257",
                        "https://kitploit.com/ja/tools/github/thestingr/cve-2025-25257/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T08:47:50",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THESTINGR-CVE-2025-25257"
                },
                {
                    "title": "Exploit for CVE-2025-25257",
                    "summary": "Pre-auth SQL injection to RCE in FortiWeb Fabric Connector enabling arbitrary command execution.",
                    "what_happened": "Pre-auth SQL injection to RCE in FortiWeb Fabric Connector enabling arbitrary command execution.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-89",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THESTINGR-CVE-2025-25257",
                        "https://kitploit.com/ja/tools/github/thestingr/cve-2025-25257/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-04T08:47:50",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/thestingr/cve-2025-25257/"
                },
                {
                    "title": "Exploit for CVE-2025-25257",
                    "summary": "SQL injection in FortiWeb Authorization header enables RCE via webshell upload.",
                    "what_happened": "SQL injection in FortiWeb Authorization header enables RCE via webshell upload.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IMBAS007-CVE-2025-25257",
                        "https://kitploit.com/ru/tools/github/imbas007/cve-2025-25257/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T11:22:55",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IMBAS007-CVE-2025-25257"
                },
                {
                    "title": "Exploit for CVE-2025-25257",
                    "summary": "SQL injection in FortiWeb Authorization header enables RCE via webshell upload.",
                    "what_happened": "SQL injection in FortiWeb Authorization header enables RCE via webshell upload.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IMBAS007-CVE-2025-25257",
                        "https://kitploit.com/ru/tools/github/imbas007/cve-2025-25257/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T11:22:55",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/imbas007/cve-2025-25257/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52473",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THESTINGR-CVE-2025-25257",
                "https://kitploit.com/ja/tools/github/thestingr/cve-2025-25257/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IMBAS007-CVE-2025-25257",
                "https://kitploit.com/ru/tools/github/imbas007/cve-2025-25257/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T06:47:50Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-25252",
            "vendor": "Fortinet",
            "product": "FortiOS",
            "title": "FortiOS vulnerability",
            "summary": "An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the SAML record of a user session to access or re-open that session via re-use of SAML record.",
            "updated_at": "2026-09-13T04:17:02.730",
            "published_at": "2025-10-14T16:15:36.683",
            "cvss": 4.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.6.0 through 7.6.2 (semver); 7.4.0 through 7.4.6 (semver); 7.2.0 through 7.2.10 (semver); 7.0.0 through 7.0.16 (semver); 6.4.0 through 6.4.16 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-613",
            "what_happened": "An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4 all versions may allow a remote attacker (e.g. a former admin whose account was removed and whose session was terminated) in possession of the SAML record of a user session to access or re-open that session via re-use of SAML record.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://fortiguard.fortinet.com/psirt/FG-IR-24-487"
            ],
            "timeline": [
                {
                    "at": "2025-10-14T16:15:36.683",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25252"
                }
            ]
        },
        {
            "id": "CVE-2025-25249",
            "vendor": "Fortinet",
            "product": "FortiSwitchManager",
            "title": "FortiSwitchManager vulnerability",
            "summary": "A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets",
            "updated_at": "2026-09-10T12:47:59.933",
            "published_at": "2026-01-13T17:15:56.910",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.2.2 through 7.2.5 (semver); 7.6.0 through 7.6.2 (semver); 7.4.0 through 7.4.7 (semver); 7.2.4 through 7.2.11 (semver); before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 54,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-122",
            "what_happened": "A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "socradar.io",
                    "author": "NVD reference",
                    "first_seen": "2026-01-13",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/"
                }
            ],
            "references": [
                "https://fortiguard.fortinet.com/psirt/FG-IR-25-084",
                "https://cert-portal.siemens.com/productcert/html/ssa-864900.html",
                "https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25249"
            ],
            "timeline": [
                {
                    "at": "2026-01-13T17:15:56.910",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25249"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-09-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-24893",
            "vendor": "XWiki",
            "product": "Platform",
            "title": "XWiki Platform Eval Injection Vulnerability",
            "summary": "XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.",
            "updated_at": "2026-09-13T18:34:22Z",
            "published_at": "2026-09-13T18:34:22Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 79,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52429",
                    "author": "Maksim Rogov",
                    "first_seen": "2025-09-16",
                    "confidence": "High",
                    "title": "XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)",
                    "summary": "XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/52429",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 52136",
                    "author": "Al Baradi Joy",
                    "first_seen": "2025-04-07",
                    "confidence": "High",
                    "title": "XWiki Platform 15.10.10 - Remote Code Execution",
                    "summary": "XWiki Platform 15.10.10 - Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/52136",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:34:22+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2025-24893-XWiki-SSTI-RCE exploit",
                    "summary": "Exploit for CVE-2025-24893. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RIPPSEC-CVE-2025-24893-XWIKI-SSTI-RCE"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-14T18:32:33+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2025-24893 exploit",
                    "summary": "Exploit for CVE-2025-24893. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GOTR00T0DAY-CVE-2025-24893"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52429",
                "https://www.exploit-db.com/exploits/52136",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RIPPSEC-CVE-2025-24893-XWIKI-SSTI-RCE",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GOTR00T0DAY-CVE-2025-24893"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:34:22Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-24813",
            "vendor": "Apache",
            "product": "Tomcat",
            "title": "Apache Tomcat Path Equivalence Vulnerability",
            "summary": "Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.",
            "updated_at": "2026-09-11T22:00:00Z",
            "published_at": "2026-09-11T22:00:00Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 963,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‑2026‑34486.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52134",
                    "author": "Al Baradi Joy",
                    "first_seen": "2025-04-07",
                    "confidence": "High",
                    "title": "Apache Tomcat 11.0.3 - Remote Code Execution",
                    "summary": "Apache Tomcat 11.0.3 - Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/52134",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · iSee857/CVE-2025-24813-PoC",
                    "author": "iSee857",
                    "first_seen": "2025-03-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 97,
                    "title": "Apache Tomcat 远程代码执行漏洞批量检测脚本(CVE-2025-24813)",
                    "summary": "Apache Tomcat 远程代码执行漏洞批量检测脚本(CVE-2025-24813)",
                    "url": "https://github.com/iSee857/CVE-2025-24813-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · N0c1or/CVE-2025-24813_POC",
                    "author": "N0c1or",
                    "first_seen": "2025-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2025-24813_POC",
                    "summary": "CVE-2025-24813_POC",
                    "url": "https://github.com/N0c1or/CVE-2025-24813_POC"
                },
                {
                    "repository": "PoC-in-GitHub · gregk4sec/CVE-2025-24813",
                    "author": "gregk4sec",
                    "first_seen": "2025-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Security Researcher",
                    "summary": "Security Researcher",
                    "url": "https://github.com/gregk4sec/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · absholi7ly/POC-CVE-2025-24813",
                    "author": "absholi7ly",
                    "first_seen": "2025-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 198,
                    "title": "his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tomcat. The vulnerability allows an attacker to upload a malicious serialized payload to the server, leading to arbitrary code execution via deserialization when specific conditions are met.",
                    "summary": "his repository contains an automated Proof of Concept (PoC) script for exploiting **CVE-2025-24813**, a Remote Code Execution (RCE) vulnerability in Apache Tomcat. The vulnerability allows an attacker to upload a malicious serialized payload to the server, leading to arbitrary code execution via deserialization when specific conditions are met.",
                    "url": "https://github.com/absholi7ly/POC-CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · qzy0x/cve-2025-24813_poc",
                    "author": "qzy0x",
                    "first_seen": "2025-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "cve-2025-24813验证脚本",
                    "summary": "cve-2025-24813验证脚本",
                    "url": "https://github.com/qzy0x/cve-2025-24813_poc"
                },
                {
                    "repository": "PoC-in-GitHub · charis3306/CVE-2025-24813",
                    "author": "charis3306",
                    "first_seen": "2025-03-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 16,
                    "title": "CVE-2025-24813利用工具",
                    "summary": "CVE-2025-24813利用工具",
                    "url": "https://github.com/charis3306/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · imbas007/CVE-2025-24813-apache-tomcat",
                    "author": "imbas007",
                    "first_seen": "2025-03-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Nuclei Template CVE-2025–24813",
                    "summary": "Nuclei Template CVE-2025–24813",
                    "url": "https://github.com/imbas007/CVE-2025-24813-apache-tomcat"
                },
                {
                    "repository": "PoC-in-GitHub · msadeghkarimi/CVE-2025-24813-Exploit",
                    "author": "msadeghkarimi",
                    "first_seen": "2025-03-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Apache Tomcat Remote Code Execution (RCE) Exploit - CVE-2025-24813",
                    "summary": "Apache Tomcat Remote Code Execution (RCE) Exploit - CVE-2025-24813",
                    "url": "https://github.com/msadeghkarimi/CVE-2025-24813-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · michael-david-fry/Apache-Tomcat-Vulnerability-POC-CVE-2025-24813",
                    "author": "michael-david-fry",
                    "first_seen": "2025-03-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Apache Tomcat Vulnerability POC (CVE-2025-24813)",
                    "summary": "Apache Tomcat Vulnerability POC (CVE-2025-24813)",
                    "url": "https://github.com/michael-david-fry/Apache-Tomcat-Vulnerability-POC-CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · ps-interactive/lab-cve-2025-24813",
                    "author": "ps-interactive",
                    "first_seen": "2025-03-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Resources for teh Apache Tomcat CVE lab",
                    "summary": "Resources for teh Apache Tomcat CVE lab",
                    "url": "https://github.com/ps-interactive/lab-cve-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · n0n-zer0/Spring-Boot-Tomcat-CVE-2025-24813",
                    "author": "n0n-zer0",
                    "first_seen": "2025-03-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "POC for CVE-2025-24813 using Spring-Boot",
                    "summary": "POC for CVE-2025-24813 using Spring-Boot",
                    "url": "https://github.com/n0n-zer0/Spring-Boot-Tomcat-CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · Alaatk/CVE-2025-24813-POC",
                    "author": "Alaatk",
                    "first_seen": "2025-03-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2025-24813 Apache Tomcat RCE Proof of Concept (PoC)",
                    "summary": "CVE-2025-24813 Apache Tomcat RCE Proof of Concept (PoC)",
                    "url": "https://github.com/Alaatk/CVE-2025-24813-POC"
                },
                {
                    "repository": "PoC-in-GitHub · tonyarris/CVE-2025-24813-PoC",
                    "author": "tonyarris",
                    "first_seen": "2025-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A PoC for CVE-2025-24813",
                    "summary": "A PoC for CVE-2025-24813",
                    "url": "https://github.com/tonyarris/CVE-2025-24813-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · u238/Tomcat-CVE_2025_24813",
                    "author": "u238",
                    "first_seen": "2025-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "A playground to test the RCE exploit for tomcat CVE-2025-24813",
                    "summary": "A playground to test the RCE exploit for tomcat CVE-2025-24813",
                    "url": "https://github.com/u238/Tomcat-CVE_2025_24813"
                },
                {
                    "repository": "PoC-in-GitHub · AlperenY-cs/CVE-2025-24813",
                    "author": "AlperenY-cs",
                    "first_seen": "2025-03-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Create lab for CVE-2025-24813",
                    "summary": "Create lab for CVE-2025-24813",
                    "url": "https://github.com/AlperenY-cs/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · manjula-aw/CVE-2025-24813",
                    "author": "manjula-aw",
                    "first_seen": "2025-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This repository contains a shell script based POC on Apache Tomcat CVE-2025-24813.  It allow you to easily test the vulnerability on any version of Apache Tomcat",
                    "summary": "This repository contains a shell script based POC on Apache Tomcat CVE-2025-24813.  It allow you to easily test the vulnerability on any version of Apache Tomcat",
                    "url": "https://github.com/manjula-aw/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · B1gN0Se/Tomcat-CVE-2025-24813",
                    "author": "B1gN0Se",
                    "first_seen": "2025-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24813 repository",
                    "summary": "",
                    "url": "https://github.com/B1gN0Se/Tomcat-CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · AsaL1n/CVE-2025-24813",
                    "author": "AsaL1n",
                    "first_seen": "2025-04-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "simple exp for CVE-2025-24813",
                    "summary": "simple exp for CVE-2025-24813",
                    "url": "https://github.com/AsaL1n/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · MuhammadWaseem29/CVE-2025-24813",
                    "author": "MuhammadWaseem29",
                    "first_seen": "2025-04-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Apache Tomcat is vulnerable to a Path Equivalence / Path Traversal issue due to improper handling of ../ sequences in paths.",
                    "summary": "Apache Tomcat is vulnerable to a Path Equivalence / Path Traversal issue due to improper handling of ../ sequences in paths.",
                    "url": "https://github.com/MuhammadWaseem29/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · La3B0z/CVE-2025-24813-POC",
                    "author": "La3B0z",
                    "first_seen": "2025-04-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-24813-POC JSP Web Shell Uploader",
                    "summary": "CVE-2025-24813-POC JSP Web Shell Uploader",
                    "url": "https://github.com/La3B0z/CVE-2025-24813-POC"
                },
                {
                    "repository": "PoC-in-GitHub · Heimd411/CVE-2025-24813-noPoC",
                    "author": "Heimd411",
                    "first_seen": "2025-04-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24813 repository",
                    "summary": "",
                    "url": "https://github.com/Heimd411/CVE-2025-24813-noPoC"
                },
                {
                    "repository": "PoC-in-GitHub · horsehacks/CVE-2025-24813-checker",
                    "author": "horsehacks",
                    "first_seen": "2025-04-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Hello researchers, I have a checker for the recent vulnerability  CVE-2025-24813-checker.",
                    "summary": "Hello researchers, I have a checker for the recent vulnerability  CVE-2025-24813-checker.",
                    "url": "https://github.com/horsehacks/CVE-2025-24813-checker"
                },
                {
                    "repository": "PoC-in-GitHub · NamelessSaint8/CVE-2025-24813-POC",
                    "author": "NamelessSaint8",
                    "first_seen": "2025-04-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A simple, easy-to-use POC for CVE-2025-42813 (Apache Tomcat versions below 9.0.99).",
                    "summary": "A simple, easy-to-use POC for CVE-2025-42813 (Apache Tomcat versions below 9.0.99).",
                    "url": "https://github.com/NamelessSaint8/CVE-2025-24813-POC"
                },
                {
                    "repository": "PoC-in-GitHub · Franconyu/Poc_for_CVE-2025-24813",
                    "author": "Franconyu",
                    "first_seen": "2025-04-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2025-24813 poc",
                    "summary": "CVE-2025-24813 poc",
                    "url": "https://github.com/Franconyu/Poc_for_CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · cchopin/CVE-Arsenal-Lab",
                    "author": "cchopin",
                    "first_seen": "2025-04-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "TomcatScanner is a comprehensive security tool designed for detecting and exploiting the CVE-2025-24813 vulnerability in Apache Tomcat servers.",
                    "summary": "TomcatScanner is a comprehensive security tool designed for detecting and exploiting the CVE-2025-24813 vulnerability in Apache Tomcat servers.",
                    "url": "https://github.com/cchopin/CVE-Arsenal-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · Mattb709/CVE-2025-24813-PoC-Apache-Tomcat-RCE",
                    "author": "Mattb709",
                    "first_seen": "2025-04-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A Python proof-of-concept exploit for CVE-2025-24813 - Unauthenticated RCE in Apache Tomcat (v9.0.0-9.0.98/10.1.0-10.1.34/11.0.0-11.0.2) via malicious Java object deserialization. Includes safe detection mode and custom payload support.",
                    "summary": "A Python proof-of-concept exploit for CVE-2025-24813 - Unauthenticated RCE in Apache Tomcat (v9.0.0-9.0.98/10.1.0-10.1.34/11.0.0-11.0.2) via malicious Java object deserialization. Includes safe detection mode and custom payload support.",
                    "url": "https://github.com/Mattb709/CVE-2025-24813-PoC-Apache-Tomcat-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · Mattb709/CVE-2025-24813-Scanner",
                    "author": "Mattb709",
                    "first_seen": "2025-04-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2025-24813-Scanner is a Python-based vulnerability scanner that detects Apache Tomcat servers vulnerable to CVE-2025-24813, an arbitrary file upload vulnerability leading to remote code execution (RCE) via insecure PUT method handling and jsessionid exploitation.",
                    "summary": "CVE-2025-24813-Scanner is a Python-based vulnerability scanner that detects Apache Tomcat servers vulnerable to CVE-2025-24813, an arbitrary file upload vulnerability leading to remote code execution (RCE) via insecure PUT method handling and jsessionid exploitation.",
                    "url": "https://github.com/Mattb709/CVE-2025-24813-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · Erosion2020/CVE-2025-24813-vulhub",
                    "author": "Erosion2020",
                    "first_seen": "2025-04-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2025-24813的vulhub环境的POC脚本",
                    "summary": "CVE-2025-24813的vulhub环境的POC脚本",
                    "url": "https://github.com/Erosion2020/CVE-2025-24813-vulhub"
                },
                {
                    "repository": "PoC-in-GitHub · hakankarabacak/CVE-2025-24813",
                    "author": "hakankarabacak",
                    "first_seen": "2025-04-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Proof of Concept (PoC) script for CVE-2025-24813, vulnerability in Apache Tomcat.",
                    "summary": "Proof of Concept (PoC) script for CVE-2025-24813, vulnerability in Apache Tomcat.",
                    "url": "https://github.com/hakankarabacak/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · ThHardvester/CVE-2025-24813",
                    "author": "ThHardvester",
                    "first_seen": "2025-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Remote Code Execution (RCE) vulnerability in Apache Tomcat.",
                    "summary": "Remote Code Execution (RCE) vulnerability in Apache Tomcat.",
                    "url": "https://github.com/ThHardvester/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · fatkz/CVE-2025-24813",
                    "author": "fatkz",
                    "first_seen": "2025-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-24813 repository",
                    "summary": "",
                    "url": "https://github.com/fatkz/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · mbanyamer/Apache-Tomcat---Remote-Code-Execution-via-Session-Deserialization-CVE-2025-24813-",
                    "author": "mbanyamer",
                    "first_seen": "2025-05-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": "Apache Tomcat - Remote Code Execution via Session Deserialization (CVE-2025-24813)",
                    "summary": "Apache Tomcat - Remote Code Execution via Session Deserialization (CVE-2025-24813)",
                    "url": "https://github.com/mbanyamer/Apache-Tomcat---Remote-Code-Execution-via-Session-Deserialization-CVE-2025-24813-"
                },
                {
                    "repository": "PoC-in-GitHub · x1ongsec/CVE-2025-24813",
                    "author": "x1ongsec",
                    "first_seen": "2025-06-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "tomcat CVE-2025-24813 反序列化RCE环境",
                    "summary": "tomcat CVE-2025-24813 反序列化RCE环境",
                    "url": "https://github.com/x1ongsec/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · yaleman/cve-2025-24813-poc",
                    "author": "yaleman",
                    "first_seen": "2025-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24813 repository",
                    "summary": "",
                    "url": "https://github.com/yaleman/cve-2025-24813-poc"
                },
                {
                    "repository": "PoC-in-GitHub · GongWook/CVE-2025-24813",
                    "author": "GongWook",
                    "first_seen": "2025-07-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "POC",
                    "summary": "POC",
                    "url": "https://github.com/GongWook/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · sentilaso1/CVE-2025-24813-Apache-Tomcat-RCE-PoC",
                    "author": "sentilaso1",
                    "first_seen": "2025-07-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Proof of Concept for CVE-2025-24813, a Remote Code Execution vulnerability in Apache Tomcat. This PoC exploits unsafe deserialization via crafted session files uploaded through HTTP PUT requests, allowing attackers to execute arbitrary code remotely on vulnerable Tomcat servers.",
                    "summary": "Proof of Concept for CVE-2025-24813, a Remote Code Execution vulnerability in Apache Tomcat. This PoC exploits unsafe deserialization via crafted session files uploaded through HTTP PUT requests, allowing attackers to execute arbitrary code remotely on vulnerable Tomcat servers.",
                    "url": "https://github.com/sentilaso1/CVE-2025-24813-Apache-Tomcat-RCE-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · x00byte/PutScanner",
                    "author": "x00byte",
                    "first_seen": "2025-07-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]",
                    "summary": "A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]",
                    "url": "https://github.com/x00byte/PutScanner"
                },
                {
                    "repository": "PoC-in-GitHub · Shivshantp/CVE-2025-24813",
                    "author": "Shivshantp",
                    "first_seen": "2025-07-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Apache Tomcat PUT JSP RCE - CVE-2025-24813 - Exploit & PoC",
                    "summary": "Apache Tomcat PUT JSP RCE - CVE-2025-24813 - Exploit & PoC",
                    "url": "https://github.com/Shivshantp/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · cyglegit/CVE-2025-24813",
                    "author": "cyglegit",
                    "first_seen": "2025-08-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Automated scanner + exploit for CVE-2025-24813",
                    "summary": "Automated scanner + exploit for CVE-2025-24813",
                    "url": "https://github.com/cyglegit/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · CEAlbez/CVE-2025-24813-PoC",
                    "author": "CEAlbez",
                    "first_seen": "2025-09-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is a PoC for the CVE-2025-24813 and tested in different environments.",
                    "summary": "This is a PoC for the CVE-2025-24813 and tested in different environments.",
                    "url": "https://github.com/CEAlbez/CVE-2025-24813-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · Makavellik/POC-CVE-2025-24813-Apache-Tomcat-Remote-Code-Execution",
                    "author": "Makavellik",
                    "first_seen": "2025-09-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Este repositorio contiene un exploit automatizado desarrollado con fines educativos y de investigación en ciberseguridad, dirigido a demostrar una potencial vulnerabilidad de ejecución remota de código (RCE) en Apache Tomcat (CVE-2025-24813).",
                    "summary": "Este repositorio contiene un exploit automatizado desarrollado con fines educativos y de investigación en ciberseguridad, dirigido a demostrar una potencial vulnerabilidad de ejecución remota de código (RCE) en Apache Tomcat (CVE-2025-24813).",
                    "url": "https://github.com/Makavellik/POC-CVE-2025-24813-Apache-Tomcat-Remote-Code-Execution"
                },
                {
                    "repository": "PoC-in-GitHub · pirenga/CVE-2025-24813",
                    "author": "pirenga",
                    "first_seen": "2025-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Example PoC for CVE-2025-24813 (Tomcat RCE)",
                    "summary": "Example PoC for CVE-2025-24813 (Tomcat RCE)",
                    "url": "https://github.com/pirenga/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · Arthurabriel/POC-CVE-2025-24813",
                    "author": "Arthurabriel",
                    "first_seen": "2025-12-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24813 repository",
                    "summary": "",
                    "url": "https://github.com/Arthurabriel/POC-CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · gunyakit/CVE-2025-24813-PoC-exploit",
                    "author": "gunyakit",
                    "first_seen": "2025-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Apache Tomcat Deserialization RCE",
                    "summary": "Apache Tomcat Deserialization RCE",
                    "url": "https://github.com/gunyakit/CVE-2025-24813-PoC-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · seahcy/CVE-2025-24813",
                    "author": "seahcy",
                    "first_seen": "2025-12-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Instructions for rapid deployment of Tomcat v9.0.90 with java 25.0.1 2025-10-21 LTS on Windows Server 2019 Standard for lazy researchers.",
                    "summary": "Instructions for rapid deployment of Tomcat v9.0.90 with java 25.0.1 2025-10-21 LTS on Windows Server 2019 Standard for lazy researchers.",
                    "url": "https://github.com/seahcy/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · EQSTLab/CVE-2025-24813",
                    "author": "EQSTLab",
                    "first_seen": "2026-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Apache Tomcat RCE",
                    "summary": "Apache Tomcat RCE",
                    "url": "https://github.com/EQSTLab/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · suil12/CVE-2025-24813_presentation",
                    "author": "suil12",
                    "first_seen": "2026-05-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24813 repository",
                    "summary": "",
                    "url": "https://github.com/suil12/CVE-2025-24813_presentation"
                },
                {
                    "repository": "PoC-in-GitHub · JTMH37/Apache-Tomcat-CVE-2025-24813-Lab",
                    "author": "JTMH37",
                    "first_seen": "2026-06-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "ICT279 Vulnerability Detection and Mitigation Project using CVE-2025-24813 in an Internet Banking Environment",
                    "summary": "ICT279 Vulnerability Detection and Mitigation Project using CVE-2025-24813 in an Internet Banking Environment",
                    "url": "https://github.com/JTMH37/Apache-Tomcat-CVE-2025-24813-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · Dhananjayasj/CVE-2025-24813-Apache-Tomcat-Partial-PUT-Deserialization-RCE-",
                    "author": "Dhananjayasj",
                    "first_seen": "2026-06-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24813 repository",
                    "summary": "",
                    "url": "https://github.com/Dhananjayasj/CVE-2025-24813-Apache-Tomcat-Partial-PUT-Deserialization-RCE-"
                },
                {
                    "repository": "PoC-in-GitHub · Loufa0/CVE-2025-24813",
                    "author": "Loufa0",
                    "first_seen": "2026-06-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "right payload for java CVE",
                    "summary": "right payload for java CVE",
                    "url": "https://github.com/Loufa0/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · yuzuki-ayanami/CVE-2025-24813",
                    "author": "yuzuki-ayanami",
                    "first_seen": "2026-07-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-24813 - Apache Tomcat RCE via Session Deserialization - PoC Exploit",
                    "summary": "CVE-2025-24813 - Apache Tomcat RCE via Session Deserialization - PoC Exploit",
                    "url": "https://github.com/yuzuki-ayanami/CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · Mega-Starmie/tomcat-cve-2025-24813-lab",
                    "author": "Mega-Starmie",
                    "first_seen": "2026-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Apache Tomcat CVE-2025-24813 本地复现、利用条件分析与 AI 辅助验证记录",
                    "summary": "Apache Tomcat CVE-2025-24813 本地复现、利用条件分析与 AI 辅助验证记录",
                    "url": "https://github.com/Mega-Starmie/tomcat-cve-2025-24813-lab"
                },
                {
                    "repository": "PoC-in-GitHub · SebastianMautner/nuclei-CVE-2025-24813",
                    "author": "SebastianMautner",
                    "first_seen": "2026-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "University Project of developing a template for safely testing for the CVE 2025-24813 on a server. It is intentionally made to not leave any lasting artifacts on the server and does not disrupt its activities.",
                    "summary": "University Project of developing a template for safely testing for the CVE 2025-24813 on a server. It is intentionally made to not leave any lasting artifacts on the server and does not disrupt its activities.",
                    "url": "https://github.com/SebastianMautner/nuclei-CVE-2025-24813"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-14T04:52:01+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2025-24813 exploit",
                    "summary": "Exploit for CVE-2025-24813. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FATKZ-CVE-2025-24813"
                },
                {
                    "repository": "PoC-in-GitHub · e5dfdd568a75282b712b6d93a7a18e12/CVE-2025-24813",
                    "author": "e5dfdd568a75282b712b6d93a7a18e12",
                    "first_seen": "2026-09-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24813 repository",
                    "summary": "",
                    "url": "https://github.com/e5dfdd568a75282b712b6d93a7a18e12/CVE-2025-24813"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52134",
                "https://github.com/iSee857/CVE-2025-24813-PoC",
                "https://github.com/N0c1or/CVE-2025-24813_POC",
                "https://github.com/gregk4sec/CVE-2025-24813",
                "https://github.com/absholi7ly/POC-CVE-2025-24813",
                "https://github.com/qzy0x/cve-2025-24813_poc",
                "https://github.com/charis3306/CVE-2025-24813",
                "https://github.com/imbas007/CVE-2025-24813-apache-tomcat",
                "https://github.com/msadeghkarimi/CVE-2025-24813-Exploit",
                "https://github.com/michael-david-fry/Apache-Tomcat-Vulnerability-POC-CVE-2025-24813",
                "https://github.com/ps-interactive/lab-cve-2025-24813",
                "https://github.com/n0n-zer0/Spring-Boot-Tomcat-CVE-2025-24813",
                "https://github.com/Alaatk/CVE-2025-24813-POC",
                "https://github.com/tonyarris/CVE-2025-24813-PoC",
                "https://github.com/u238/Tomcat-CVE_2025_24813",
                "https://github.com/AlperenY-cs/CVE-2025-24813",
                "https://github.com/manjula-aw/CVE-2025-24813",
                "https://github.com/B1gN0Se/Tomcat-CVE-2025-24813",
                "https://github.com/AsaL1n/CVE-2025-24813",
                "https://github.com/MuhammadWaseem29/CVE-2025-24813",
                "https://github.com/La3B0z/CVE-2025-24813-POC",
                "https://github.com/Heimd411/CVE-2025-24813-noPoC",
                "https://github.com/horsehacks/CVE-2025-24813-checker",
                "https://github.com/NamelessSaint8/CVE-2025-24813-POC",
                "https://github.com/Franconyu/Poc_for_CVE-2025-24813",
                "https://github.com/cchopin/CVE-Arsenal-Lab",
                "https://github.com/Mattb709/CVE-2025-24813-PoC-Apache-Tomcat-RCE",
                "https://github.com/Mattb709/CVE-2025-24813-Scanner",
                "https://github.com/Erosion2020/CVE-2025-24813-vulhub",
                "https://github.com/hakankarabacak/CVE-2025-24813",
                "https://github.com/ThHardvester/CVE-2025-24813",
                "https://github.com/fatkz/CVE-2025-24813",
                "https://github.com/mbanyamer/Apache-Tomcat---Remote-Code-Execution-via-Session-Deserialization-CVE-2025-24813-",
                "https://github.com/x1ongsec/CVE-2025-24813",
                "https://github.com/yaleman/cve-2025-24813-poc",
                "https://github.com/GongWook/CVE-2025-24813",
                "https://github.com/sentilaso1/CVE-2025-24813-Apache-Tomcat-RCE-PoC",
                "https://github.com/x00byte/PutScanner",
                "https://github.com/Shivshantp/CVE-2025-24813",
                "https://github.com/cyglegit/CVE-2025-24813",
                "https://github.com/CEAlbez/CVE-2025-24813-PoC",
                "https://github.com/Makavellik/POC-CVE-2025-24813-Apache-Tomcat-Remote-Code-Execution",
                "https://github.com/pirenga/CVE-2025-24813",
                "https://github.com/Arthurabriel/POC-CVE-2025-24813",
                "https://github.com/gunyakit/CVE-2025-24813-PoC-exploit",
                "https://github.com/seahcy/CVE-2025-24813",
                "https://github.com/EQSTLab/CVE-2025-24813",
                "https://github.com/suil12/CVE-2025-24813_presentation",
                "https://github.com/JTMH37/Apache-Tomcat-CVE-2025-24813-Lab",
                "https://github.com/Dhananjayasj/CVE-2025-24813-Apache-Tomcat-Partial-PUT-Deserialization-RCE-",
                "https://github.com/Loufa0/CVE-2025-24813",
                "https://github.com/yuzuki-ayanami/CVE-2025-24813",
                "https://github.com/Mega-Starmie/tomcat-cve-2025-24813-lab",
                "https://github.com/SebastianMautner/nuclei-CVE-2025-24813",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FATKZ-CVE-2025-24813",
                "https://github.com/e5dfdd568a75282b712b6d93a7a18e12/CVE-2025-24813"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-24799",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2025-24799 SQLi Scanner",
            "summary": "CVE-2025-24799 SQLi Scanner",
            "updated_at": "2026-09-05T22:00:00Z",
            "published_at": "2026-09-05T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 96,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · MuhammadWaseem29/CVE-2025-24799",
                    "author": "MuhammadWaseem29",
                    "first_seen": "2025-04-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2025-24799 SQLi Scanner",
                    "summary": "CVE-2025-24799 SQLi Scanner",
                    "url": "https://github.com/MuhammadWaseem29/CVE-2025-24799"
                },
                {
                    "repository": "PoC-in-GitHub · MatheuZSecurity/Exploit-CVE-2025-24799",
                    "author": "MatheuZSecurity",
                    "first_seen": "2025-04-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 34,
                    "title": "CVE-2025-24799 Exploit: GLPI - Unauthenticated SQL Injection",
                    "summary": "CVE-2025-24799 Exploit: GLPI - Unauthenticated SQL Injection",
                    "url": "https://github.com/MatheuZSecurity/Exploit-CVE-2025-24799"
                },
                {
                    "repository": "PoC-in-GitHub · Rosemary1337/CVE-2025-24799",
                    "author": "Rosemary1337",
                    "first_seen": "2025-09-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24799 Exploit: GLPI - Unauthenticated SQL Injection",
                    "summary": "CVE-2025-24799 Exploit: GLPI - Unauthenticated SQL Injection",
                    "url": "https://github.com/Rosemary1337/CVE-2025-24799"
                },
                {
                    "repository": "PoC-in-GitHub · airbus-cert/CVE-2025-24799-scanner",
                    "author": "airbus-cert",
                    "first_seen": "2025-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Scanner for GLPI CVE-2025-24799 vulnerability",
                    "summary": "Scanner for GLPI CVE-2025-24799 vulnerability",
                    "url": "https://github.com/airbus-cert/CVE-2025-24799-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · galisko/CVE-2025-24799",
                    "author": "galisko",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24799 repository",
                    "summary": "",
                    "url": "https://github.com/galisko/CVE-2025-24799"
                }
            ],
            "references": [
                "https://github.com/MuhammadWaseem29/CVE-2025-24799",
                "https://github.com/MatheuZSecurity/Exploit-CVE-2025-24799",
                "https://github.com/Rosemary1337/CVE-2025-24799",
                "https://github.com/airbus-cert/CVE-2025-24799-scanner",
                "https://github.com/galisko/CVE-2025-24799"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/MuhammadWaseem29/CVE-2025-24799"
                }
            ]
        },
        {
            "id": "CVE-2025-24291",
            "vendor": "Versa",
            "product": "Director",
            "title": "Director vulnerability",
            "summary": "The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME type validation, allowing the upload of arbitrary file types. This flaw can be exploited to place a malicious file on disk. \r\n\r\nVersa Networks is not aware of any reported instance where this vulnerability was exploited. Proof of concept for this vulnerability has been disclosed by third party security researchers.  \r\n\r\nThere are no workarounds to disable the GUI option. Versa recommends that Director be upgraded to one of the remediated software versions.",
            "updated_at": "2026-09-08T19:29:43.510",
            "published_at": "2025-06-19T00:15:22.437",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "21.2.2 through 21.2.2 (semver); 21.2.3 through 21.2.3 (semver); 22.1.1 through 22.1.1 (semver); 22.1.2 through 22.1.2 (semver); 22.1.3 through 22.1.3 (semver); 22.1.4 through 22.1.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME type validation, allowing the upload of arbitrary file types. This flaw can be exploited to place a malicious file on disk. \r\n\r\nVersa Networks is not aware of any reported instance where this vulnerability was exploited. Proof of concept for this vulnerability has been disclosed by third party security researchers.  \r\n\r\nThere are no workarounds to disable the GUI option. Versa recommends that Director be upgraded to one of the remediated software versions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security-portal.versa-networks.com/emailbulletins/68526fc6dc94d6b9f2faf71d",
                "https://support.versa-networks.com/support/solutions/articles/23000024323-release-21-2-3",
                "https://support.versa-networks.com/support/solutions/articles/23000025680-release-22-1-2",
                "https://support.versa-networks.com/support/solutions/articles/23000026033-release-22-1-3",
                "https://support.versa-networks.com/support/solutions/articles/23000026708-release-22-1-4"
            ],
            "timeline": [
                {
                    "at": "2025-06-19T00:15:22.437",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24291"
                }
            ]
        },
        {
            "id": "CVE-2025-24252",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for AirBorne-PoC CVE-2025-24132 CVE-2025-24252",
            "summary": "Apple AirPlay mDNS crash and heap overflow in AirPlayReceiver daemon enable DoS and RCE.",
            "updated_at": "2026-08-25T12:42:36Z",
            "published_at": "2026-08-25T12:42:36Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 139,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Apple AirPlay mDNS crash and heap overflow in AirPlayReceiver daemon enable DoS and RCE.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for AirBorne-PoC CVE-2025-24132 CVE-2025-24252",
                    "summary": "Apple AirPlay mDNS crash and heap overflow in AirPlayReceiver daemon enable DoS and RCE.",
                    "what_happened": "Apple AirPlay mDNS crash and heap overflow in AirPlayReceiver daemon enable DoS and RCE.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EKOMSSAVIOR-AIRBORNE-POC",
                        "https://kitploit.com/ru/tools/github/ekomssavior/airborne-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T14:42:36",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EKOMSSAVIOR-AIRBORNE-POC"
                },
                {
                    "title": "Exploit for AirBorne-PoC CVE-2025-24132 CVE-2025-24252",
                    "summary": "Apple AirPlay mDNS crash and heap overflow in AirPlayReceiver daemon enable DoS and RCE.",
                    "what_happened": "Apple AirPlay mDNS crash and heap overflow in AirPlayReceiver daemon enable DoS and RCE.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EKOMSSAVIOR-AIRBORNE-POC",
                        "https://kitploit.com/ru/tools/github/ekomssavior/airborne-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-25T14:42:36",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/ekomssavior/airborne-poc/"
                },
                {
                    "repository": "PoC-in-GitHub · ekomsSavior/AirBorne-PoC",
                    "author": "ekomsSavior",
                    "first_seen": "2025-04-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 165,
                    "title": "poc for CVE-2025-24252 & CVE-2025-24132",
                    "summary": "poc for CVE-2025-24252 & CVE-2025-24132",
                    "url": "https://github.com/ekomsSavior/AirBorne-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · cakescats/airborn-IOS-CVE-2025-24252",
                    "author": "cakescats",
                    "first_seen": "2025-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252",
                    "summary": "iOS Airborne vulnerabilities log artifact extractor from LogArchive CVE-2025-24252",
                    "url": "https://github.com/cakescats/airborn-IOS-CVE-2025-24252"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EKOMSSAVIOR-AIRBORNE-POC",
                "https://kitploit.com/ru/tools/github/ekomssavior/airborne-poc/",
                "https://github.com/ekomsSavior/AirBorne-PoC",
                "https://github.com/cakescats/airborn-IOS-CVE-2025-24252"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T12:42:36Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EKOMSSAVIOR-AIRBORNE-POC"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-24132",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for AirBorne-PoC CVE-2025-24132 CVE-2025-24252",
            "summary": "Apple AirPlay mDNS crash and heap overflow in AirPlayReceiver daemon enable DoS and RCE.",
            "updated_at": "2026-08-25T12:42:36Z",
            "published_at": "2026-08-25T12:42:36Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 105,
            "kev": false,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Apple AirPlay mDNS crash and heap overflow in AirPlayReceiver daemon enable DoS and RCE.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for AirBorne-PoC CVE-2025-24132 CVE-2025-24252",
                    "summary": "Apple AirPlay mDNS crash and heap overflow in AirPlayReceiver daemon enable DoS and RCE.",
                    "what_happened": "Apple AirPlay mDNS crash and heap overflow in AirPlayReceiver daemon enable DoS and RCE.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EKOMSSAVIOR-AIRBORNE-POC",
                        "https://kitploit.com/ru/tools/github/ekomssavior/airborne-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T14:42:36",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EKOMSSAVIOR-AIRBORNE-POC"
                },
                {
                    "title": "Exploit for AirBorne-PoC CVE-2025-24132 CVE-2025-24252",
                    "summary": "Apple AirPlay mDNS crash and heap overflow in AirPlayReceiver daemon enable DoS and RCE.",
                    "what_happened": "Apple AirPlay mDNS crash and heap overflow in AirPlayReceiver daemon enable DoS and RCE.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EKOMSSAVIOR-AIRBORNE-POC",
                        "https://kitploit.com/ru/tools/github/ekomssavior/airborne-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-25T14:42:36",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/ekomssavior/airborne-poc/"
                },
                {
                    "repository": "PoC-in-GitHub · Feralthedogg/CVE-2025-24132-Scanner",
                    "author": "Feralthedogg",
                    "first_seen": "2025-05-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2025-24132 repository",
                    "summary": "",
                    "url": "https://github.com/Feralthedogg/CVE-2025-24132-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · TheGamingGallifreyan/LiberationPlay-CVE-2025-24132-AirBourne-POC",
                    "author": "TheGamingGallifreyan",
                    "first_seen": "2026-02-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "POC for CVE-2025-24132 (AirBourne). Currently just triggers the overflow and causes a crash",
                    "summary": "POC for CVE-2025-24132 (AirBourne). Currently just triggers the overflow and causes a crash",
                    "url": "https://github.com/TheGamingGallifreyan/LiberationPlay-CVE-2025-24132-AirBourne-POC"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EKOMSSAVIOR-AIRBORNE-POC",
                "https://kitploit.com/ru/tools/github/ekomssavior/airborne-poc/",
                "https://github.com/Feralthedogg/CVE-2025-24132-Scanner",
                "https://github.com/TheGamingGallifreyan/LiberationPlay-CVE-2025-24132-AirBourne-POC"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T12:42:36Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EKOMSSAVIOR-AIRBORNE-POC"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-24071",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Windows File Explorer Windows 10 Pro x64 - TAR Extraction",
            "summary": "Windows File Explorer Windows 10 Pro x64 - TAR Extraction",
            "updated_at": "2026-09-05T08:16:29Z",
            "published_at": "2026-09-05T08:16:29Z",
            "cvss": 6.5,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1077,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "NetNTLMv2 hash capture in Windows explorer.exe via crafted ZIP file extraction.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52325",
                    "author": "Daniel Miranda",
                    "first_seen": "2025-06-13",
                    "confidence": "High",
                    "title": "Windows File Explorer Windows 10 Pro x64 - TAR Extraction",
                    "summary": "Windows File Explorer Windows 10 Pro x64 - TAR Extraction",
                    "url": "https://www.exploit-db.com/exploits/52325",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 52310",
                    "author": "Mohammed Idrees Banyamer",
                    "first_seen": "2025-05-29",
                    "confidence": "High",
                    "title": "Windows File Explorer Windows 11 (23H2) - NTLM Hash Disclosure",
                    "summary": "Windows File Explorer Windows 11 (23H2) - NTLM Hash Disclosure",
                    "url": "https://www.exploit-db.com/exploits/52310",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2025-24071_PoC CVE-2025-24054 CVE-2025-24071",
                    "summary": "NetNTLMv2 hash capture in Windows explorer.exe via crafted ZIP file extraction.",
                    "what_happened": "NetNTLMv2 hash capture in Windows explorer.exe via crafted ZIP file extraction.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MARCEJR117-CVE-2025-24071_POC",
                        "https://kitploit.com/ru/tools/github/marcejr117/cve-2025-24071_poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T11:03:12",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MARCEJR117-CVE-2025-24071_POC"
                },
                {
                    "repository": "PoC-in-GitHub · Fomovet/cve-2025-24071",
                    "author": "Fomovet",
                    "first_seen": "2026-06-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "POC for CVE-2025-24071",
                    "summary": "POC for CVE-2025-24071",
                    "url": "https://github.com/Fomovet/cve-2025-24071"
                },
                {
                    "repository": "PoC-in-GitHub · buffertrychar/CVE-2025-24071-POC",
                    "author": "buffertrychar",
                    "first_seen": "2026-05-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24071 repository",
                    "summary": "",
                    "url": "https://github.com/buffertrychar/CVE-2025-24071-POC"
                },
                {
                    "repository": "SecurityLayer404/CVE-2025-24054-24071---Metasploit-Module",
                    "author": "SecurityLayer404",
                    "first_seen": "2026-04-01",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 0,
                    "title": "Módulo de Metasploit para explotar CVE-2025-24054 (ex 24071). Exploit de filtración NTLM integrado en Metasploit para vectores de ataque basados en bibliotecas de Windows.",
                    "summary": "Módulo de Metasploit para explotar CVE-2025-24054 (ex 24071). Exploit de filtración NTLM integrado en Metasploit para vectores de ataque basados en bibliotecas de Windows.",
                    "url": "https://github.com/SecurityLayer404/CVE-2025-24054-24071---Metasploit-Module"
                },
                {
                    "repository": "PoC-in-GitHub · Abdelrahman0Sayed/CVE-2025-24071",
                    "author": "Abdelrahman0Sayed",
                    "first_seen": "2025-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This is a python PoC scripts for CVE-2025-24071 which is a vulnerability in Windows File Explorer that allows unauthorized access to sensitive information like NTLM Exposure.",
                    "summary": "This is a python PoC scripts for CVE-2025-24071 which is a vulnerability in Windows File Explorer that allows unauthorized access to sensitive information like NTLM Exposure.",
                    "url": "https://github.com/Abdelrahman0Sayed/CVE-2025-24071"
                },
                {
                    "repository": "Wind010/CVE-2025-24054_PoC",
                    "author": "Wind010",
                    "first_seen": "2025-11-09",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "A proof of concept for CVE-2025-24054/CVE-2025-24071",
                    "summary": "A proof of concept for CVE-2025-24054/CVE-2025-24071",
                    "url": "https://github.com/Wind010/CVE-2025-24054_PoC"
                },
                {
                    "repository": "helidem/CVE-2025-24054_CVE-2025-24071-PoC",
                    "author": "helidem",
                    "first_seen": "2025-04-22",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 21,
                    "title": "Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071",
                    "summary": "Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071",
                    "url": "https://github.com/helidem/CVE-2025-24054_CVE-2025-24071-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · AC8999/CVE-2025-24071",
                    "author": "AC8999",
                    "first_seen": "2025-09-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Python script to execute CVE-2025-24071",
                    "summary": "Python script to execute CVE-2025-24071",
                    "url": "https://github.com/AC8999/CVE-2025-24071"
                },
                {
                    "repository": "PoC-in-GitHub · ctabango/CVE-2025-24071_PoCExtra",
                    "author": "ctabango",
                    "first_seen": "2025-03-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Alternativa CVE-2025-24071_PoC",
                    "summary": "Alternativa CVE-2025-24071_PoC",
                    "url": "https://github.com/ctabango/CVE-2025-24071_PoCExtra"
                },
                {
                    "repository": "PoC-in-GitHub · Royall-Researchers/CVE-2025-24071",
                    "author": "Royall-Researchers",
                    "first_seen": "2025-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24071 repository",
                    "summary": "",
                    "url": "https://github.com/Royall-Researchers/CVE-2025-24071"
                },
                {
                    "repository": "PoC-in-GitHub · f4dee-backup/CVE-2025-24071",
                    "author": "f4dee-backup",
                    "first_seen": "2025-05-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Windows File Explorer Spoofing Vulnerability - CVE-2025-24071",
                    "summary": "Windows File Explorer Spoofing Vulnerability - CVE-2025-24071",
                    "url": "https://github.com/f4dee-backup/CVE-2025-24071"
                },
                {
                    "title": "Exploit for CVE-2025-24071_PoC CVE-2025-24054 CVE-2025-24071",
                    "summary": "NetNTLMv2 hash capture in Windows explorer.exe via crafted ZIP file extraction.",
                    "what_happened": "NetNTLMv2 hash capture in Windows explorer.exe via crafted ZIP file extraction.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MARCEJR117-CVE-2025-24071_POC",
                        "https://kitploit.com/ru/tools/github/marcejr117/cve-2025-24071_poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T11:03:12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/marcejr117/cve-2025-24071_poc/"
                },
                {
                    "repository": "PoC-in-GitHub · 0x6rss/CVE-2025-24071_PoC",
                    "author": "0x6rss",
                    "first_seen": "2025-03-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 408,
                    "title": "CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File",
                    "summary": "CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File",
                    "url": "https://github.com/0x6rss/CVE-2025-24071_PoC"
                },
                {
                    "repository": "PoC-in-GitHub · kaIIsyms/CVE-2025-24071",
                    "author": "kaIIsyms",
                    "first_seen": "2025-03-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Microsoft Windows File Explorer Spoofing Vulnerability / NTLM Hash Leak",
                    "summary": "Microsoft Windows File Explorer Spoofing Vulnerability / NTLM Hash Leak",
                    "url": "https://github.com/kaIIsyms/CVE-2025-24071"
                },
                {
                    "repository": "PoC-in-GitHub · FOLKS-iwd/CVE-2025-24071-msfvenom",
                    "author": "FOLKS-iwd",
                    "first_seen": "2025-03-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms",
                    "summary": "Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms",
                    "url": "https://github.com/FOLKS-iwd/CVE-2025-24071-msfvenom"
                },
                {
                    "repository": "PoC-in-GitHub · aleongx/CVE-2025-24071",
                    "author": "aleongx",
                    "first_seen": "2025-03-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)",
                    "summary": "Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)",
                    "url": "https://github.com/aleongx/CVE-2025-24071"
                },
                {
                    "repository": "PoC-in-GitHub · ThemeHackers/CVE-2025-24071",
                    "author": "ThemeHackers",
                    "first_seen": "2025-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 34,
                    "title": "Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)",
                    "summary": "Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)",
                    "url": "https://github.com/ThemeHackers/CVE-2025-24071"
                },
                {
                    "repository": "PoC-in-GitHub · rubbxalc/CVE-2025-24071",
                    "author": "rubbxalc",
                    "first_seen": "2025-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-24071 repository",
                    "summary": "",
                    "url": "https://github.com/rubbxalc/CVE-2025-24071"
                },
                {
                    "repository": "PoC-in-GitHub · Marcejr117/CVE-2025-24071_PoC",
                    "author": "Marcejr117",
                    "first_seen": "2025-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 24,
                    "title": "A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes",
                    "summary": "A PoC of CVE-2025-24071 / CVE-2025-24054, A windows vulnerability that allow get NTMLv2 hashes",
                    "url": "https://github.com/Marcejr117/CVE-2025-24071_PoC"
                },
                {
                    "repository": "PoC-in-GitHub · cesarbtakeda/Windows-Explorer-CVE-2025-24071",
                    "author": "cesarbtakeda",
                    "first_seen": "2025-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-24071 repository",
                    "summary": "",
                    "url": "https://github.com/cesarbtakeda/Windows-Explorer-CVE-2025-24071"
                },
                {
                    "repository": "PoC-in-GitHub · pswalia2u/CVE-2025-24071_POC",
                    "author": "pswalia2u",
                    "first_seen": "2025-04-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24071 repository",
                    "summary": "",
                    "url": "https://github.com/pswalia2u/CVE-2025-24071_POC"
                },
                {
                    "repository": "PoC-in-GitHub · LOOKY243/CVE-2025-24071-PoC",
                    "author": "LOOKY243",
                    "first_seen": "2025-05-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2025-24071 Proof Of Concept",
                    "summary": "CVE-2025-24071 Proof Of Concept",
                    "url": "https://github.com/LOOKY243/CVE-2025-24071-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · ex-cal1bur/SMB_CVE-2025-24071",
                    "author": "ex-cal1bur",
                    "first_seen": "2025-05-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted server-side without user interaction. Responder captures the NTLM hash once the target accesses the library.",
                    "summary": "Exploited CVE-2025-24071 via SMB by hosting a .library-ms file inside a .tar archive. Using tar x from smbclient, the payload is extracted server-side without user interaction. Responder captures the NTLM hash once the target accesses the library.",
                    "url": "https://github.com/ex-cal1bur/SMB_CVE-2025-24071"
                },
                {
                    "repository": "PoC-in-GitHub · TH-SecForge/CVE-2025-24071",
                    "author": "TH-SecForge",
                    "first_seen": "2025-06-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability",
                    "summary": "Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability",
                    "url": "https://github.com/TH-SecForge/CVE-2025-24071"
                },
                {
                    "repository": "PoC-in-GitHub · zbs54/Blackash-CVE-2025-24071",
                    "author": "zbs54",
                    "first_seen": "2025-06-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24071",
                    "summary": "CVE-2025-24071",
                    "url": "https://github.com/zbs54/Blackash-CVE-2025-24071"
                },
                {
                    "repository": "PoC-in-GitHub · DeshanFer94/CVE-2025-24071-POC-NTLMHashDisclosure-",
                    "author": "DeshanFer94",
                    "first_seen": "2025-06-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-24071: NTLMv2 Hash Disclosure via .library-ms File",
                    "summary": "CVE-2025-24071: NTLMv2 Hash Disclosure via .library-ms File",
                    "url": "https://github.com/DeshanFer94/CVE-2025-24071-POC-NTLMHashDisclosure-"
                },
                {
                    "repository": "PoC-in-GitHub · ephunter/CVE-2025-24071-Exploit",
                    "author": "ephunter",
                    "first_seen": "2025-07-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit CVE-2025-24071",
                    "summary": "Exploit CVE-2025-24071",
                    "url": "https://github.com/ephunter/CVE-2025-24071-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · DAEMON-404/PoC-CVE-2025-24071",
                    "author": "DAEMON-404",
                    "first_seen": "2026-09-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24071 repository",
                    "summary": "",
                    "url": "https://github.com/DAEMON-404/PoC-CVE-2025-24071"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:30:55+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Microsoft",
                    "summary": "Proof-of-concept exploit for CVE-2025-24071. CVSS 6.5.",
                    "cvss": 6.5,
                    "url": "https://sploitus.com/exploit?id=3B3221D2-B862-5A6A-A30D-C2E42334D44F"
                },
                {
                    "repository": "PoC-in-GitHub · BardLaudian/CVE-2025-24071",
                    "author": "BardLaudian",
                    "first_seen": "2026-09-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Dependency-free PoC generator for CVE-2025-24071 — Windows File Explorer .library-ms NTLM hash disclosure via crafted ZIP",
                    "summary": "Dependency-free PoC generator for CVE-2025-24071 — Windows File Explorer .library-ms NTLM hash disclosure via crafted ZIP",
                    "url": "https://github.com/BardLaudian/CVE-2025-24071"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52325",
                "https://www.exploit-db.com/exploits/52310",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MARCEJR117-CVE-2025-24071_POC",
                "https://github.com/Fomovet/cve-2025-24071",
                "https://github.com/buffertrychar/CVE-2025-24071-POC",
                "https://github.com/SecurityLayer404/CVE-2025-24054-24071---Metasploit-Module",
                "https://github.com/Abdelrahman0Sayed/CVE-2025-24071",
                "https://github.com/Wind010/CVE-2025-24054_PoC",
                "https://github.com/helidem/CVE-2025-24054_CVE-2025-24071-PoC",
                "https://github.com/AC8999/CVE-2025-24071",
                "https://github.com/ctabango/CVE-2025-24071_PoCExtra",
                "https://github.com/Royall-Researchers/CVE-2025-24071",
                "https://github.com/f4dee-backup/CVE-2025-24071",
                "https://kitploit.com/ru/tools/github/marcejr117/cve-2025-24071_poc/",
                "https://github.com/0x6rss/CVE-2025-24071_PoC",
                "https://github.com/kaIIsyms/CVE-2025-24071",
                "https://github.com/FOLKS-iwd/CVE-2025-24071-msfvenom",
                "https://github.com/aleongx/CVE-2025-24071",
                "https://github.com/ThemeHackers/CVE-2025-24071",
                "https://github.com/rubbxalc/CVE-2025-24071",
                "https://github.com/Marcejr117/CVE-2025-24071_PoC",
                "https://github.com/cesarbtakeda/Windows-Explorer-CVE-2025-24071",
                "https://github.com/pswalia2u/CVE-2025-24071_POC",
                "https://github.com/LOOKY243/CVE-2025-24071-PoC",
                "https://github.com/ex-cal1bur/SMB_CVE-2025-24071",
                "https://github.com/TH-SecForge/CVE-2025-24071",
                "https://github.com/zbs54/Blackash-CVE-2025-24071",
                "https://github.com/DeshanFer94/CVE-2025-24071-POC-NTLMHashDisclosure-",
                "https://github.com/ephunter/CVE-2025-24071-Exploit",
                "https://github.com/DAEMON-404/PoC-CVE-2025-24071",
                "https://sploitus.com/exploit?id=3B3221D2-B862-5A6A-A30D-C2E42334D44F",
                "https://github.com/BardLaudian/CVE-2025-24071"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:16:29Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52325"
                }
            ]
        },
        {
            "id": "CVE-2025-24054",
            "vendor": "Microsoft",
            "product": "Windows",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "updated_at": "2026-09-05T08:16:29Z",
            "published_at": "2026-09-05T08:16:29Z",
            "cvss": 6.5,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1000,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52280",
                    "author": "hyp3rlinx",
                    "first_seen": "2025-05-01",
                    "confidence": "High",
                    "title": "Microsoft - NTLM Hash Disclosure Spoofing (library-ms)",
                    "summary": "Microsoft - NTLM Hash Disclosure Spoofing (library-ms)",
                    "url": "https://www.exploit-db.com/exploits/52280",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 52480",
                    "author": "beatrizfn",
                    "first_seen": "2026-02-11",
                    "confidence": "High",
                    "title": "Windows 10.0.17763.7009 - spoofing vulnerability",
                    "summary": "Windows 10.0.17763.7009 - spoofing vulnerability",
                    "url": "https://www.exploit-db.com/exploits/52480",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 52478",
                    "author": "beatrizfn",
                    "first_seen": "2026-02-04",
                    "confidence": "High",
                    "title": "windows 10/11 - NTLM Hash Disclosure Spoofing",
                    "summary": "windows 10/11 - NTLM Hash Disclosure Spoofing",
                    "url": "https://www.exploit-db.com/exploits/52478",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2025-24071_PoC CVE-2025-24054 CVE-2025-24071",
                    "summary": "NetNTLMv2 hash capture in Windows explorer.exe via crafted ZIP file extraction.",
                    "what_happened": "NetNTLMv2 hash capture in Windows explorer.exe via crafted ZIP file extraction.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MARCEJR117-CVE-2025-24071_POC",
                        "https://kitploit.com/ru/tools/github/marcejr117/cve-2025-24071_poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T11:03:12",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MARCEJR117-CVE-2025-24071_POC"
                },
                {
                    "repository": "T0tooro/cve-2025-24054-lab",
                    "author": "T0tooro",
                    "first_seen": "2026-07-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy",
                    "summary": "Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy",
                    "url": "https://github.com/T0tooro/cve-2025-24054-lab"
                },
                {
                    "repository": "Fomovet/cve-2025-24054",
                    "author": "Fomovet",
                    "first_seen": "2026-06-21",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "POC for CVE-2025-24054",
                    "summary": "POC for CVE-2025-24054",
                    "url": "https://github.com/Fomovet/cve-2025-24054"
                },
                {
                    "repository": "simantchaudhari/CVE-2025-24054-PoC",
                    "author": "simantchaudhari",
                    "first_seen": "2026-05-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2025-24054 repository",
                    "summary": "",
                    "url": "https://github.com/simantchaudhari/CVE-2025-24054-PoC"
                },
                {
                    "repository": "kaleth4/CVE--2025-24054",
                    "author": "kaleth4",
                    "first_seen": "2026-04-03",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-24054 repository",
                    "summary": "",
                    "url": "https://github.com/kaleth4/CVE--2025-24054"
                },
                {
                    "repository": "SecurityLayer404/CVE-2025-24054-24071---Metasploit-Module",
                    "author": "SecurityLayer404",
                    "first_seen": "2026-04-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "Módulo de Metasploit para explotar CVE-2025-24054 (ex 24071). Exploit de filtración NTLM integrado en Metasploit para vectores de ataque basados en bibliotecas de Windows.",
                    "summary": "Módulo de Metasploit para explotar CVE-2025-24054 (ex 24071). Exploit de filtración NTLM integrado en Metasploit para vectores de ataque basados en bibliotecas de Windows.",
                    "url": "https://github.com/SecurityLayer404/CVE-2025-24054-24071---Metasploit-Module"
                },
                {
                    "repository": "Untouchable17/CVE-2025-24054",
                    "author": "Untouchable17",
                    "first_seen": "2025-11-23",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 2,
                    "title": "Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure",
                    "summary": "Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure",
                    "url": "https://github.com/Untouchable17/CVE-2025-24054"
                },
                {
                    "repository": "Wind010/CVE-2025-24054_PoC",
                    "author": "Wind010",
                    "first_seen": "2025-11-09",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "A proof of concept for CVE-2025-24054/CVE-2025-24071",
                    "summary": "A proof of concept for CVE-2025-24054/CVE-2025-24071",
                    "url": "https://github.com/Wind010/CVE-2025-24054_PoC"
                },
                {
                    "repository": "helidem/CVE-2025-24054_CVE-2025-24071-PoC",
                    "author": "helidem",
                    "first_seen": "2025-04-22",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 21,
                    "title": "Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071",
                    "summary": "Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071",
                    "url": "https://github.com/helidem/CVE-2025-24054_CVE-2025-24071-PoC"
                },
                {
                    "repository": "rubenformation/CVE-2025-50154",
                    "author": "rubenformation",
                    "first_seen": "2025-08-13",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 55,
                    "title": "POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a bypass for the CVE-2025-24054 Security Patch",
                    "summary": "POCs for CVE-2025-50154 and CVE-2025-59214, zero day vulnerabilities on windows file explorer disclosing NTLMv2-SSP without user interaction. It is a bypass for the CVE-2025-24054 Security Patch",
                    "url": "https://github.com/rubenformation/CVE-2025-50154"
                },
                {
                    "repository": "moften/CVE-2025-24054",
                    "author": "moften",
                    "first_seen": "2025-05-19",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": "Vulnerabilidad NTLM (CVE-2025-24054) explotada para robo de hashes",
                    "summary": "Vulnerabilidad NTLM (CVE-2025-24054) explotada para robo de hashes",
                    "url": "https://github.com/moften/CVE-2025-24054"
                },
                {
                    "title": "Exploit for CVE-2025-24071_PoC CVE-2025-24054 CVE-2025-24071",
                    "summary": "NetNTLMv2 hash capture in Windows explorer.exe via crafted ZIP file extraction.",
                    "what_happened": "NetNTLMv2 hash capture in Windows explorer.exe via crafted ZIP file extraction.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MARCEJR117-CVE-2025-24071_POC",
                        "https://kitploit.com/ru/tools/github/marcejr117/cve-2025-24071_poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T11:03:12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/marcejr117/cve-2025-24071_poc/"
                },
                {
                    "title": "Exploit for CVE-2025-50154 CVE-2025-50154 CVE-2025-59214",
                    "summary": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
                    "what_happened": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUBENFORMATION-CVE-2025-50154",
                        "https://kitploit.com/ru/tools/github/rubenformation/cve-2025-50154/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-02T23:38:26",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUBENFORMATION-CVE-2025-50154"
                },
                {
                    "title": "Exploit for CVE-2025-50154 CVE-2025-50154 CVE-2025-59214",
                    "summary": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
                    "what_happened": "Zero-click NTLMv2-SSP hash disclosure in Windows File Explorer via .LNK with remote SMB target.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUBENFORMATION-CVE-2025-50154",
                        "https://kitploit.com/ru/tools/github/rubenformation/cve-2025-50154/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-02T23:38:26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/rubenformation/cve-2025-50154/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52280",
                "https://www.exploit-db.com/exploits/52480",
                "https://www.exploit-db.com/exploits/52478",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MARCEJR117-CVE-2025-24071_POC",
                "https://github.com/T0tooro/cve-2025-24054-lab",
                "https://github.com/Fomovet/cve-2025-24054",
                "https://github.com/simantchaudhari/CVE-2025-24054-PoC",
                "https://github.com/kaleth4/CVE--2025-24054",
                "https://github.com/SecurityLayer404/CVE-2025-24054-24071---Metasploit-Module",
                "https://github.com/Untouchable17/CVE-2025-24054",
                "https://github.com/Wind010/CVE-2025-24054_PoC",
                "https://github.com/helidem/CVE-2025-24054_CVE-2025-24071-PoC",
                "https://github.com/rubenformation/CVE-2025-50154",
                "https://github.com/moften/CVE-2025-24054",
                "https://kitploit.com/ru/tools/github/marcejr117/cve-2025-24071_poc/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUBENFORMATION-CVE-2025-50154",
                "https://kitploit.com/ru/tools/github/rubenformation/cve-2025-50154/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:16:29Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-04-17",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-23368",
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7",
            "title": "Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 vulnerability",
            "summary": "A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.",
            "updated_at": "2026-09-14T22:16:55.233",
            "published_at": "2025-03-04T16:15:39.270",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "0 through * (semver)",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-307",
            "what_happened": "A flaw was found in Wildfly Elytron integration. The component does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it more susceptible to brute force attacks via CLI.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "www.gruppotim.it",
                    "author": "NVD reference",
                    "first_seen": "2025-03-04",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://www.gruppotim.it/it/footer/red-team.html"
                }
            ],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:18054",
                "https://access.redhat.com/errata/RHSA-2026:18055",
                "https://access.redhat.com/errata/RHSA-2026:18059",
                "https://access.redhat.com/errata/RHSA-2026:33371",
                "https://access.redhat.com/security/cve/CVE-2025-23368",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2337621",
                "https://www.gruppotim.it/it/footer/red-team.html"
            ],
            "timeline": [
                {
                    "at": "2025-03-04T16:15:39.270",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23368"
                }
            ]
        },
        {
            "id": "CVE-2025-23367",
            "vendor": "Red Hat",
            "product": "Red Hat JBoss Enterprise Application Platform",
            "title": "Red Hat JBoss Enterprise Application Platform vulnerability",
            "summary": "A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. \nThe vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.",
            "updated_at": "2026-09-14T15:17:03.750",
            "published_at": "2025-01-30T15:15:18.610",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 27.0.1.Final (semver); 28.0.0.Beta1 through before 28.0.0.Beta2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-284",
            "what_happened": "A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server. \nThe vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2025:3465",
                "https://access.redhat.com/errata/RHSA-2025:3467",
                "https://access.redhat.com/errata/RHSA-2025:3989",
                "https://access.redhat.com/errata/RHSA-2025:3990",
                "https://access.redhat.com/errata/RHSA-2025:3992",
                "https://access.redhat.com/security/cve/CVE-2025-23367",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2337620",
                "https://github.com/advisories/GHSA-qr6x-62gq-4ccp"
            ],
            "timeline": [
                {
                    "at": "2025-01-30T15:15:18.610",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23367"
                }
            ]
        },
        {
            "id": "CVE-2025-23173",
            "vendor": "Versa",
            "product": "Director",
            "title": "Director vulnerability",
            "summary": "The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and accessible from the internet. This exposure introduces significant risk, as websockify has known weaknesses that can be exploited, potentially leading to remote code execution. \r\n\r\nVersa Networks is not aware of any reported instance where this vulnerability was exploited. Proof of concept for this vulnerability has been disclosed by third party security researchers.  \r\n\r\nWorkarounds or Mitigation: \r\n\r\nRestrict access to TCP port 6080 if uCPE console access is not necessary. Versa recommends that Director be upgraded to one of the remediated software versions.",
            "updated_at": "2026-09-08T19:29:38.863",
            "published_at": "2025-06-19T00:15:21.977",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "21.2.2 through 21.2.2 (semver); 21.2.3 through 21.2.3 (semver); 22.1.1 through 22.1.1 (semver); 22.1.2 through 22.1.2 (semver); 22.1.3 through 22.1.3 (semver); 22.1.4 through 22.1.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and accessible from the internet. This exposure introduces significant risk, as websockify has known weaknesses that can be exploited, potentially leading to remote code execution. \r\n\r\nVersa Networks is not aware of any reported instance where this vulnerability was exploited. Proof of concept for this vulnerability has been disclosed by third party security researchers.  \r\n\r\nWorkarounds or Mitigation: \r\n\r\nRestrict access to TCP port 6080 if uCPE console access is not necessary. Versa recommends that Director be upgraded to one of the remediated software versions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security-portal.versa-networks.com/emailbulletins/68526ee0dc94d6b9f2faf71c",
                "https://support.versa-networks.com/support/solutions/articles/23000024323-release-21-2-3",
                "https://support.versa-networks.com/support/solutions/articles/23000025680-release-22-1-2",
                "https://support.versa-networks.com/support/solutions/articles/23000026033-release-22-1-3",
                "https://support.versa-networks.com/support/solutions/articles/23000026708-release-22-1-4"
            ],
            "timeline": [
                {
                    "at": "2025-06-19T00:15:21.977",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23173"
                }
            ]
        },
        {
            "id": "CVE-2025-23129",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: Clear affinity hint before calling ath11k_pcic_free_irq() in error path\n\nIf a shared IRQ is used by the driver due to platform limitation, then the\nIRQ affinity hint is set right after the allocation of IRQ vectors in\nath11k_pci_alloc_msi(). This does no harm unless one of the functions\nrequesting the IRQ fails and attempt to free the IRQ. This results in the\nbelow warning:\n\nWARNING: CPU: 7 PID: 349 at kernel/irq/manage.c:1929 free_irq+0x278/0x29c\nCall trace:\n free_irq+0x278/0x29c\n ath11k_pcic_free_irq+0x70/0x10c [ath11k]\n ath11k_pci_probe+0x800/0x820 [ath11k_pci]\n local_pci_probe+0x40/0xbc\n\nThe warning is due to not clearing the affinity hint before freeing the\nIRQs.\n\nSo to fix this issue, clear the IRQ affinity hint before calling\nath11k_pcic_free_irq() in the error path. The affinity will be cleared once\nagain further down the error path due to code organization, but that does\nno harm.\n\nTested-on: QCA6390 hw2.0 PCI WLAN.HST.1.0.1-05266-QCAHSTSWPLZ_V2_TO_X86-1",
            "updated_at": "2026-09-14T12:17:35.680",
            "published_at": "2025-04-16T15:16:07.373",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "e01b3400d641cb290742849331f0d22e1202538a through before 8d0519f511d93d675f61d6bfb45ffcc945af4b14 (git); d412d0ef300f28d698648cc7c19147ab413251fe through before 7493b9baf0e54b44caae46715aaa409a84bd9f4b (git); 39564b475ac5a589e6c22c43a08cbd283c295d2c through before 80dc5a2ce5b75d648e08549617f5c555d07ae43c (git); 39564b475ac5a589e6c22c43a08cbd283c295d2c through before 3fc42cfcc6e336f25dee79b34e57c4a63cd652a5 (git); 39564b475ac5a589e6c22c43a08cbd283c295d2c through before 68410c5bd381a81bcc92b808e7dc4e6b9ed25d11 (git); 5a9f55efa9333e3edb4826d945cfdd8356f6e269 (git); 6.1.63 through before 6.1.188 (semver); 6.6.2 through before 6.6.157 (semver); 6.5.12 through before 6.6 (semver); 6.7",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: Clear affinity hint before calling ath11k_pcic_free_irq() in error path\n\nIf a shared IRQ is used by the driver due to platform limitation, then the\nIRQ affinity hint is set right after the allocation of IRQ vectors in\nath11k_pci_alloc_msi(). This does no harm unless one of the functions\nrequesting the IRQ fails and attempt to free the IRQ. This results in the\nbelow warning:\n\nWARNING: CPU: 7 PID: 349 at kernel/irq/manage.c:1929 free_irq+0x278/0x29c\nCall trace:\n free_irq+0x278/0x29c\n ath11k_pcic_free_irq+0x70/0x10c [ath11k]\n ath11k_pci_probe+0x800/0x820 [ath11k_pci]\n local_pci_probe+0x40/0xbc\n\nThe warning is due to not clearing the affinity hint before freeing the\nIRQs.\n\nSo to fix this issue, clear the IRQ affinity hint before calling\nath11k_pcic_free_irq() in the error path. The affinity will be cleared once\nagain further down the error path due to code organization, but that does\nno harm.\n\nTested-on: QCA6390 hw2.0 PCI WLAN.HST.1.0.1-05266-QCAHSTSWPLZ_V2_TO_X86-1",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/3fc42cfcc6e336f25dee79b34e57c4a63cd652a5",
                "https://git.kernel.org/stable/c/68410c5bd381a81bcc92b808e7dc4e6b9ed25d11",
                "https://git.kernel.org/stable/c/7493b9baf0e54b44caae46715aaa409a84bd9f4b",
                "https://git.kernel.org/stable/c/80dc5a2ce5b75d648e08549617f5c555d07ae43c",
                "https://git.kernel.org/stable/c/8d0519f511d93d675f61d6bfb45ffcc945af4b14"
            ],
            "timeline": [
                {
                    "at": "2025-04-16T15:16:07.373",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23129"
                }
            ]
        },
        {
            "id": "CVE-2025-22652",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2025-22652",
            "summary": "SQL injection in Payment Forms for Paystack WordPress plugin up to 4.0.1.",
            "updated_at": "2026-09-06T03:59:44Z",
            "published_at": "2026-09-06T03:59:44Z",
            "cvss": 7.6,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 57,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "SQL injection in Payment Forms for Paystack WordPress plugin up to 4.0.1.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-22652",
                    "summary": "SQL injection in Payment Forms for Paystack WordPress plugin up to 4.0.1.",
                    "what_happened": "SQL injection in Payment Forms for Paystack WordPress plugin up to 4.0.1.",
                    "cvss": 7.6,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DOTTAK-CVE-2025-22652",
                        "https://kitploit.com/ja/tools/github/dottak/cve-2025-22652/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T05:59:44",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DOTTAK-CVE-2025-22652"
                },
                {
                    "title": "Exploit for CVE-2025-22652",
                    "summary": "SQL injection in Payment Forms for Paystack WordPress plugin up to 4.0.1.",
                    "what_happened": "SQL injection in Payment Forms for Paystack WordPress plugin up to 4.0.1.",
                    "cvss": 7.6,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DOTTAK-CVE-2025-22652",
                        "https://kitploit.com/ja/tools/github/dottak/cve-2025-22652/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-06T05:59:44",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/dottak/cve-2025-22652/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DOTTAK-CVE-2025-22652",
                "https://kitploit.com/ja/tools/github/dottak/cve-2025-22652/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T03:59:44Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DOTTAK-CVE-2025-22652"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L"
        },
        {
            "id": "CVE-2025-22127",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix potential deadloop in prepare_compress_overwrite()\n\nJan Prusakowski reported a kernel hang issue as below:\n\nWhen running xfstests on linux-next kernel (6.14.0-rc3, 6.12) I\nencountered a problem in generic/475 test where fsstress process\ngets blocked in __f2fs_write_data_pages() and the test hangs.\nThe options I used are:\n\nMKFS_OPTIONS  -- -O compression -O extra_attr -O project_quota -O quota /dev/vdc\nMOUNT_OPTIONS -- -o acl,user_xattr -o discard,compress_extension=* /dev/vdc /vdc\n\nINFO: task kworker/u8:0:11 blocked for more than 122 seconds.\n      Not tainted 6.14.0-rc3-xfstests-lockdep #1\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:kworker/u8:0    state:D stack:0     pid:11    tgid:11    ppid:2      task_flags:0x4208160 flags:0x00004000\nWorkqueue: writeback wb_workfn (flush-253:0)\nCall Trace:\n <TASK>\n __schedule+0x309/0x8e0\n schedule+0x3a/0x100\n schedule_preempt_disabled+0x15/0x30\n __mutex_lock+0x59a/0xdb0\n __f2fs_write_data_pages+0x3ac/0x400\n do_writepages+0xe8/0x290\n __writeback_single_inode+0x5c/0x360\n writeback_sb_inodes+0x22f/0x570\n wb_writeback+0xb0/0x410\n wb_do_writeback+0x47/0x2f0\n wb_workfn+0x5a/0x1c0\n process_one_work+0x223/0x5b0\n worker_thread+0x1d5/0x3c0\n kthread+0xfd/0x230\n ret_from_fork+0x31/0x50\n ret_from_fork_asm+0x1a/0x30\n </TASK>\n\nThe root cause is: once generic/475 starts toload error table to dm\ndevice, f2fs_prepare_compress_overwrite() will loop reading compressed\ncluster pages due to IO error, meanwhile it has held .writepages lock,\nit can block all other writeback tasks.\n\nLet's fix this issue w/ below changes:\n- add f2fs_handle_page_eio() in prepare_compress_overwrite() to\ndetect IO error.\n- detect cp_error earler in f2fs_read_multi_pages().",
            "updated_at": "2026-09-07T16:17:27.510",
            "published_at": "2025-04-16T15:16:06.813",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4c8ff7095bef64fc47e996a938f7d57f9e077da3 through before 7cd460bd9e7c6e6c30a33982603f65fb5deab1e4 (git); 4c8ff7095bef64fc47e996a938f7d57f9e077da3 through before 7215cf8ef54bdc9082dffac4662416d54961e258 (git); 4c8ff7095bef64fc47e996a938f7d57f9e077da3 through before 3147ee567dd9004a49826ddeaf0a4b12865d4409 (git); 5.6",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-667",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix potential deadloop in prepare_compress_overwrite()\n\nJan Prusakowski reported a kernel hang issue as below:\n\nWhen running xfstests on linux-next kernel (6.14.0-rc3, 6.12) I\nencountered a problem in generic/475 test where fsstress process\ngets blocked in __f2fs_write_data_pages() and the test hangs.\nThe options I used are:\n\nMKFS_OPTIONS  -- -O compression -O extra_attr -O project_quota -O quota /dev/vdc\nMOUNT_OPTIONS -- -o acl,user_xattr -o discard,compress_extension=* /dev/vdc /vdc\n\nINFO: task kworker/u8:0:11 blocked for more than 122 seconds.\n      Not tainted 6.14.0-rc3-xfstests-lockdep #1\n\"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\ntask:kworker/u8:0    state:D stack:0     pid:11    tgid:11    ppid:2      task_flags:0x4208160 flags:0x00004000\nWorkqueue: writeback wb_workfn (flush-253:0)\nCall Trace:\n <TASK>\n __schedule+0x309/0x8e0\n schedule+0x3a/0x100\n schedule_preempt_disabled+0x15/0x30\n __mutex_lock+0x59a/0xdb0\n __f2fs_write_data_pages+0x3ac/0x400\n do_writepages+0xe8/0x290\n __writeback_single_inode+0x5c/0x360\n writeback_sb_inodes+0x22f/0x570\n wb_writeback+0xb0/0x410\n wb_do_writeback+0x47/0x2f0\n wb_workfn+0x5a/0x1c0\n process_one_work+0x223/0x5b0\n worker_thread+0x1d5/0x3c0\n kthread+0xfd/0x230\n ret_from_fork+0x31/0x50\n ret_from_fork_asm+0x1a/0x30\n </TASK>\n\nThe root cause is: once generic/475 starts toload error table to dm\ndevice, f2fs_prepare_compress_overwrite() will loop reading compressed\ncluster pages due to IO error, meanwhile it has held .writepages lock,\nit can block all other writeback tasks.\n\nLet's fix this issue w/ below changes:\n- add f2fs_handle_page_eio() in prepare_compress_overwrite() to\ndetect IO error.\n- detect cp_error earler in f2fs_read_multi_pages().",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/3147ee567dd9004a49826ddeaf0a4b12865d4409",
                "https://git.kernel.org/stable/c/7215cf8ef54bdc9082dffac4662416d54961e258",
                "https://git.kernel.org/stable/c/7cd460bd9e7c6e6c30a33982603f65fb5deab1e4"
            ],
            "timeline": [
                {
                    "at": "2025-04-16T15:16:06.813",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22127"
                }
            ]
        },
        {
            "id": "CVE-2025-22124",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/md-bitmap: fix wrong bitmap_limit for clustermd when write sb\n\nIn clustermd, separate write-intent-bitmaps are used for each cluster\nnode:\n\n0                    4k                     8k                    12k\n-------------------------------------------------------------------\n| idle                | md super            | bm super [0] + bits |\n| bm bits[0, contd]   | bm super[1] + bits  | bm bits[1, contd]   |\n| bm super[2] + bits  | bm bits [2, contd]  | bm super[3] + bits  |\n| bm bits [3, contd]  |                     |                     |\n\nSo in node 1, pg_index in __write_sb_page() could equal to\nbitmap->storage.file_pages. Then bitmap_limit will be calculated to\n0. md_super_write() will be called with 0 size.\nThat means the first 4k sb area of node 1 will never be updated\nthrough filemap_write_page().\nThis bug causes hang of mdadm/clustermd_tests/01r1_Grow_resize.\n\nHere use (pg_index % bitmap->storage.file_pages) to make calculation\nof bitmap_limit correct.",
            "updated_at": "2026-09-14T12:17:35.497",
            "published_at": "2025-04-16T15:16:06.540",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "655cc01889fa9b65441922565cddee64af49e6d6 through before 5eaf57fdfa37c869e61e9908e03edd707f9145b8 (git); ab99a87542f194f28e2364a42afbf9fb48b1c724 through before 60196f92bbc7901eb5cfa5d456651b87ea50a4a3 (git); ab99a87542f194f28e2364a42afbf9fb48b1c724 through before bc3a9788961631359527763d7e1fcf26554c7cb1 (git); ab99a87542f194f28e2364a42afbf9fb48b1c724 through before 6130825f34d41718c98a9b1504a79a23e379701e (git); 5600d6013c634c2b6b6c6c55c8ecb50c3a6211f2 (git); 6.6.44 through before 6.6.157 (semver); 6.10.3 through before 6.11 (semver); 6.11",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/md-bitmap: fix wrong bitmap_limit for clustermd when write sb\n\nIn clustermd, separate write-intent-bitmaps are used for each cluster\nnode:\n\n0                    4k                     8k                    12k\n-------------------------------------------------------------------\n| idle                | md super            | bm super [0] + bits |\n| bm bits[0, contd]   | bm super[1] + bits  | bm bits[1, contd]   |\n| bm super[2] + bits  | bm bits [2, contd]  | bm super[3] + bits  |\n| bm bits [3, contd]  |                     |                     |\n\nSo in node 1, pg_index in __write_sb_page() could equal to\nbitmap->storage.file_pages. Then bitmap_limit will be calculated to\n0. md_super_write() will be called with 0 size.\nThat means the first 4k sb area of node 1 will never be updated\nthrough filemap_write_page().\nThis bug causes hang of mdadm/clustermd_tests/01r1_Grow_resize.\n\nHere use (pg_index % bitmap->storage.file_pages) to make calculation\nof bitmap_limit correct.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/5eaf57fdfa37c869e61e9908e03edd707f9145b8",
                "https://git.kernel.org/stable/c/60196f92bbc7901eb5cfa5d456651b87ea50a4a3",
                "https://git.kernel.org/stable/c/6130825f34d41718c98a9b1504a79a23e379701e",
                "https://git.kernel.org/stable/c/bc3a9788961631359527763d7e1fcf26554c7cb1"
            ],
            "timeline": [
                {
                    "at": "2025-04-16T15:16:06.540",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22124"
                }
            ]
        },
        {
            "id": "CVE-2025-22108",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Mask the bd_cnt field in the TX BD properly\n\nThe bd_cnt field in the TX BD specifies the total number of BDs for\nthe TX packet.  The bd_cnt field has 5 bits and the maximum number\nsupported is 32 with the value 0.\n\nCONFIG_MAX_SKB_FRAGS can be modified and the total number of SKB\nfragments can approach or exceed the maximum supported by the chip.\nAdd a macro to properly mask the bd_cnt field so that the value 32\nwill be properly masked and set to 0 in the bd_cnd field.\n\nWithout this patch, the out-of-range bd_cnt value will corrupt the\nTX BD and may cause TX timeout.\n\nThe next patch will check for values exceeding 32.",
            "updated_at": "2026-09-07T16:17:27.353",
            "published_at": "2025-04-16T15:16:05.083",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3948b05950fdd64002a5f182c65ba5cf2d53cf71 through before 9ee185e0f15594017a6f1a191ebe6630cfea5f74 (git); 3948b05950fdd64002a5f182c65ba5cf2d53cf71 through before f60b41b815826f15c4d0323f923f398c423178d0 (git); 3948b05950fdd64002a5f182c65ba5cf2d53cf71 through before 107b25db61122d8f990987895c2912927b8b6e3f (git); 6.4",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Mask the bd_cnt field in the TX BD properly\n\nThe bd_cnt field in the TX BD specifies the total number of BDs for\nthe TX packet.  The bd_cnt field has 5 bits and the maximum number\nsupported is 32 with the value 0.\n\nCONFIG_MAX_SKB_FRAGS can be modified and the total number of SKB\nfragments can approach or exceed the maximum supported by the chip.\nAdd a macro to properly mask the bd_cnt field so that the value 32\nwill be properly masked and set to 0 in the bd_cnd field.\n\nWithout this patch, the out-of-range bd_cnt value will corrupt the\nTX BD and may cause TX timeout.\n\nThe next patch will check for values exceeding 32.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/107b25db61122d8f990987895c2912927b8b6e3f",
                "https://git.kernel.org/stable/c/9ee185e0f15594017a6f1a191ebe6630cfea5f74",
                "https://git.kernel.org/stable/c/f60b41b815826f15c4d0323f923f398c423178d0"
            ],
            "timeline": [
                {
                    "at": "2025-04-16T15:16:05.083",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22108"
                }
            ]
        },
        {
            "id": "CVE-2025-22103",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix NULL pointer dereference in l3mdev_l3_rcv\n\nWhen delete l3s ipvlan:\n\n    ip link del link eth0 ipvlan1 type ipvlan mode l3s\n\nThis may cause a null pointer dereference:\n\n    Call trace:\n     ip_rcv_finish+0x48/0xd0\n     ip_rcv+0x5c/0x100\n     __netif_receive_skb_one_core+0x64/0xb0\n     __netif_receive_skb+0x20/0x80\n     process_backlog+0xb4/0x204\n     napi_poll+0xe8/0x294\n     net_rx_action+0xd8/0x22c\n     __do_softirq+0x12c/0x354\n\nThis is because l3mdev_l3_rcv() visit dev->l3mdev_ops after\nipvlan_l3s_unregister() assign the dev->l3mdev_ops to NULL. The process\nlike this:\n\n    (CPU1)                     | (CPU2)\n    l3mdev_l3_rcv()            |\n      check dev->priv_flags:   |\n        master = skb->dev;     |\n                               |\n                               | ipvlan_l3s_unregister()\n                               |   set dev->priv_flags\n                               |   dev->l3mdev_ops = NULL;\n                               |\n      visit master->l3mdev_ops |\n\nTo avoid this by do not set dev->l3mdev_ops when unregister l3s ipvlan.",
            "updated_at": "2026-09-14T12:17:35.353",
            "published_at": "2025-04-16T15:16:04.650",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "c675e06a98a474f7ad0af32ce467613da818da52 through before 1da52878f7fb74ace304f74325bb89e3e5546b55 (git); c675e06a98a474f7ad0af32ce467613da818da52 through before d97d6b1bd2b7f2a188d261d44c4519a13b8c406a (git); c675e06a98a474f7ad0af32ce467613da818da52 through before 8da4d7f9141e8dbd3ece2f0e6930a0ea8812c862 (git); c675e06a98a474f7ad0af32ce467613da818da52 through before 52b44d8c653459c658b733d13658afdde45f6836 (git); c675e06a98a474f7ad0af32ce467613da818da52 through before 59599bce44af3df7a215ebc81cb166426e1c9204 (git); c675e06a98a474f7ad0af32ce467613da818da52 through before f9dff65140efc289f01bcf39c3ca66a8806b6132 (git); c675e06a98a474f7ad0af32ce467613da818da52 through before 0032c99e83b9ce6d5995d65900aa4b6ffb501cce (git); 5.1",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix NULL pointer dereference in l3mdev_l3_rcv\n\nWhen delete l3s ipvlan:\n\n    ip link del link eth0 ipvlan1 type ipvlan mode l3s\n\nThis may cause a null pointer dereference:\n\n    Call trace:\n     ip_rcv_finish+0x48/0xd0\n     ip_rcv+0x5c/0x100\n     __netif_receive_skb_one_core+0x64/0xb0\n     __netif_receive_skb+0x20/0x80\n     process_backlog+0xb4/0x204\n     napi_poll+0xe8/0x294\n     net_rx_action+0xd8/0x22c\n     __do_softirq+0x12c/0x354\n\nThis is because l3mdev_l3_rcv() visit dev->l3mdev_ops after\nipvlan_l3s_unregister() assign the dev->l3mdev_ops to NULL. The process\nlike this:\n\n    (CPU1)                     | (CPU2)\n    l3mdev_l3_rcv()            |\n      check dev->priv_flags:   |\n        master = skb->dev;     |\n                               |\n                               | ipvlan_l3s_unregister()\n                               |   set dev->priv_flags\n                               |   dev->l3mdev_ops = NULL;\n                               |\n      visit master->l3mdev_ops |\n\nTo avoid this by do not set dev->l3mdev_ops when unregister l3s ipvlan.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0032c99e83b9ce6d5995d65900aa4b6ffb501cce",
                "https://git.kernel.org/stable/c/1da52878f7fb74ace304f74325bb89e3e5546b55",
                "https://git.kernel.org/stable/c/52b44d8c653459c658b733d13658afdde45f6836",
                "https://git.kernel.org/stable/c/59599bce44af3df7a215ebc81cb166426e1c9204",
                "https://git.kernel.org/stable/c/8da4d7f9141e8dbd3ece2f0e6930a0ea8812c862",
                "https://git.kernel.org/stable/c/d97d6b1bd2b7f2a188d261d44c4519a13b8c406a",
                "https://git.kernel.org/stable/c/f9dff65140efc289f01bcf39c3ca66a8806b6132"
            ],
            "timeline": [
                {
                    "at": "2025-04-16T15:16:04.650",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22103"
                }
            ]
        },
        {
            "id": "CVE-2025-22101",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: libwx: fix Tx L4 checksum\n\nThe hardware only supports L4 checksum offload for TCP/UDP/SCTP protocol.\nThere was a bug to set Tx checksum flag for the other protocol that results\nin Tx ring hang. Fix to compute software checksum for these packets.",
            "updated_at": "2026-09-14T12:17:35.210",
            "published_at": "2025-04-16T15:16:04.460",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "3403960cdf86c967442dccc2bec981e0093f716e through before 9c6c85ae77efbe29420883082b3a7b9fd2c57602 (git); 3403960cdf86c967442dccc2bec981e0093f716e through before 6d56ea133adf0389b216ba6e47f7f35e95776713 (git); 3403960cdf86c967442dccc2bec981e0093f716e through before 5f583e059eced1857f41e221ef5951e029e632bd (git); 3403960cdf86c967442dccc2bec981e0093f716e through before c7d82913d5f9e97860772ee4051eaa66b56a6273 (git); 6.5",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: libwx: fix Tx L4 checksum\n\nThe hardware only supports L4 checksum offload for TCP/UDP/SCTP protocol.\nThere was a bug to set Tx checksum flag for the other protocol that results\nin Tx ring hang. Fix to compute software checksum for these packets.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/5f583e059eced1857f41e221ef5951e029e632bd",
                "https://git.kernel.org/stable/c/6d56ea133adf0389b216ba6e47f7f35e95776713",
                "https://git.kernel.org/stable/c/9c6c85ae77efbe29420883082b3a7b9fd2c57602",
                "https://git.kernel.org/stable/c/c7d82913d5f9e97860772ee4051eaa66b56a6273"
            ],
            "timeline": [
                {
                    "at": "2025-04-16T15:16:04.460",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22101"
                }
            ]
        },
        {
            "id": "CVE-2025-22039",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix overflow in dacloffset bounds check\n\nThe dacloffset field was originally typed as int and used in an\nunchecked addition, which could overflow and bypass the existing\nbounds check in both smb_check_perm_dacl() and smb_inherit_dacl().\n\nThis could result in out-of-bounds memory access and a kernel crash\nwhen dereferencing the DACL pointer.\n\nThis patch converts dacloffset to unsigned int and uses\ncheck_add_overflow() to validate access to the DACL.",
            "updated_at": "2026-09-14T12:17:35.030",
            "published_at": "2025-04-16T15:15:56.500",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0626e6641f6b467447c81dd7678a69c66f7746cf through before abbb4ec41867f2cd1c971258e493893bf43bcbd3 (git); 0626e6641f6b467447c81dd7678a69c66f7746cf through before 8483d7b532be1d1bc149556a2fedf903868c6303 (git); 0626e6641f6b467447c81dd7678a69c66f7746cf through before 73f074fb5e139cd42ad75089abe4e28a49a30003 (git); 0626e6641f6b467447c81dd7678a69c66f7746cf through before 6a9cd9ff0fa2bcc30b2bfb8bdb161eb20e44b9dc (git); 0626e6641f6b467447c81dd7678a69c66f7746cf through before 6b8d379048b168a0dff5ab1acb975b933f368514 (git); 0626e6641f6b467447c81dd7678a69c66f7746cf through before 443b373a4df5a2cb9f7b8c4658b2afedeb16397f (git); 0626e6641f6b467447c81dd7678a69c66f7746cf through before beff0bc9d69bc8e733f9bca28e2d3df5b3e10e42 (git); 5.15",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix overflow in dacloffset bounds check\n\nThe dacloffset field was originally typed as int and used in an\nunchecked addition, which could overflow and bypass the existing\nbounds check in both smb_check_perm_dacl() and smb_inherit_dacl().\n\nThis could result in out-of-bounds memory access and a kernel crash\nwhen dereferencing the DACL pointer.\n\nThis patch converts dacloffset to unsigned int and uses\ncheck_add_overflow() to validate access to the DACL.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/443b373a4df5a2cb9f7b8c4658b2afedeb16397f",
                "https://git.kernel.org/stable/c/6a9cd9ff0fa2bcc30b2bfb8bdb161eb20e44b9dc",
                "https://git.kernel.org/stable/c/6b8d379048b168a0dff5ab1acb975b933f368514",
                "https://git.kernel.org/stable/c/73f074fb5e139cd42ad75089abe4e28a49a30003",
                "https://git.kernel.org/stable/c/8483d7b532be1d1bc149556a2fedf903868c6303",
                "https://git.kernel.org/stable/c/abbb4ec41867f2cd1c971258e493893bf43bcbd3",
                "https://git.kernel.org/stable/c/beff0bc9d69bc8e733f9bca28e2d3df5b3e10e42"
            ],
            "timeline": [
                {
                    "at": "2025-04-16T15:15:56.500",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22039"
                }
            ]
        },
        {
            "id": "CVE-2025-21863",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: prevent opcode speculation\n\nsqe->opcode is used for different tables, make sure we santitise it\nagainst speculations.",
            "updated_at": "2026-09-08T09:17:26.527",
            "published_at": "2025-03-12T10:15:19.387",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "d3656344fea0339fb0365c8df4d2beba4e0089cd through before 87e9eef43c758da267f6332678058a79764c7eba (git); d3656344fea0339fb0365c8df4d2beba4e0089cd through before 18eae8420081ef8e043ad455937bfb470ef08607 (git); d3656344fea0339fb0365c8df4d2beba4e0089cd through before d261ead565a080e3411b0dd04e6d58a52471cac8 (git); d3656344fea0339fb0365c8df4d2beba4e0089cd through before b9826e3b26ec031e9063f64a7c735449c43955e4 (git); d3656344fea0339fb0365c8df4d2beba4e0089cd through before 506b9b5e8c2d2a411ea8fe361333f5081c56d23a (git); d3656344fea0339fb0365c8df4d2beba4e0089cd through before fdbfd52bd8b85ed6783365ff54c82ab7067bd61b (git); d3656344fea0339fb0365c8df4d2beba4e0089cd through before 1e988c3fe1264708f4f92109203ac5b1d65de50b (git); 5.6; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: prevent opcode speculation\n\nsqe->opcode is used for different tables, make sure we santitise it\nagainst speculations.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/18eae8420081ef8e043ad455937bfb470ef08607",
                "https://git.kernel.org/stable/c/1e988c3fe1264708f4f92109203ac5b1d65de50b",
                "https://git.kernel.org/stable/c/506b9b5e8c2d2a411ea8fe361333f5081c56d23a",
                "https://git.kernel.org/stable/c/87e9eef43c758da267f6332678058a79764c7eba",
                "https://git.kernel.org/stable/c/b9826e3b26ec031e9063f64a7c735449c43955e4",
                "https://git.kernel.org/stable/c/d261ead565a080e3411b0dd04e6d58a52471cac8",
                "https://git.kernel.org/stable/c/fdbfd52bd8b85ed6783365ff54c82ab7067bd61b",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2025-03-12T10:15:19.387",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21863"
                }
            ]
        },
        {
            "id": "CVE-2025-21817",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: mark GFP_NOIO around sysfs ->store()\n\nsysfs ->store is called with queue freezed, meantime we have several\n->store() callbacks(update_nr_requests, wbt, scheduler) to allocate\nmemory with GFP_KERNEL which may run into direct reclaim code path,\nthen potential deadlock can be caused.\n\nFix the issue by marking NOIO around sysfs ->store()",
            "updated_at": "2026-09-07T16:17:27.213",
            "published_at": "2025-02-27T20:16:04.243",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1645cd7fd42c236c952e9228badcac4fea1829ea through before a09280c39ea54080daf19cfaf4a3121a8d17d5cd (git); 8985da5481562e96b95e94ed8e5cc9b6565eb82b through before 2566ce907e5d5db8a039647208e029ce559baa31 (git); c99f66e4084a62a2cc401c4704a84328aeddc9ec through before 7c0be4ead1f8f5f8be0803f347de0de81e3b8e1c (git); 6.12.96 through before 6.12.109 (semver); 6.13.2 through before 6.13.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-667",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: mark GFP_NOIO around sysfs ->store()\n\nsysfs ->store is called with queue freezed, meantime we have several\n->store() callbacks(update_nr_requests, wbt, scheduler) to allocate\nmemory with GFP_KERNEL which may run into direct reclaim code path,\nthen potential deadlock can be caused.\n\nFix the issue by marking NOIO around sysfs ->store()",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2566ce907e5d5db8a039647208e029ce559baa31",
                "https://git.kernel.org/stable/c/7c0be4ead1f8f5f8be0803f347de0de81e3b8e1c",
                "https://git.kernel.org/stable/c/a09280c39ea54080daf19cfaf4a3121a8d17d5cd"
            ],
            "timeline": [
                {
                    "at": "2025-02-27T20:16:04.243",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21817"
                }
            ]
        },
        {
            "id": "CVE-2025-21651",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: don't auto enable misc vector\n\nCurrently, there is a time window between misc irq enabled\nand service task inited. If an interrupte is reported at\nthis time, it will cause warning like below:\n\n[   16.324639] Call trace:\n[   16.324641]  __queue_delayed_work+0xb8/0xe0\n[   16.324643]  mod_delayed_work_on+0x78/0xd0\n[   16.324655]  hclge_errhand_task_schedule+0x58/0x90 [hclge]\n[   16.324662]  hclge_misc_irq_handle+0x168/0x240 [hclge]\n[   16.324666]  __handle_irq_event_percpu+0x64/0x1e0\n[   16.324667]  handle_irq_event+0x80/0x170\n[   16.324670]  handle_fasteoi_edge_irq+0x110/0x2bc\n[   16.324671]  __handle_domain_irq+0x84/0xfc\n[   16.324673]  gic_handle_irq+0x88/0x2c0\n[   16.324674]  el1_irq+0xb8/0x140\n[   16.324677]  arch_cpu_idle+0x18/0x40\n[   16.324679]  default_idle_call+0x5c/0x1bc\n[   16.324682]  cpuidle_idle_call+0x18c/0x1c4\n[   16.324684]  do_idle+0x174/0x17c\n[   16.324685]  cpu_startup_entry+0x30/0x6c\n[   16.324687]  secondary_start_kernel+0x1a4/0x280\n[   16.324688] ---[ end trace 6aa0bff672a964aa ]---\n\nSo don't auto enable misc vector when request irq..",
            "updated_at": "2026-09-14T12:17:34.877",
            "published_at": "2025-01-19T11:15:10.733",
            "cvss": 4.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7be1b9f3e99f6213d053d16ed2438126931d8351 through before 800a6dfcf570c4a7e168a6fe515904de56e97148 (git); 7be1b9f3e99f6213d053d16ed2438126931d8351 through before ee2861fce5f66c6901a014f68598e94666b23455 (git); 7be1b9f3e99f6213d053d16ed2438126931d8351 through before 41b84c5a603ffe987ec094e163d7da73aaf1841d (git); 7be1b9f3e99f6213d053d16ed2438126931d8351 through before 7f1fe43907a6339a41364f4f7915fbf3ab2775a8 (git); 7be1b9f3e99f6213d053d16ed2438126931d8351 through before bcf430d3bb5525fc89a92a0c451c725ba1aa4306 (git); 7be1b9f3e99f6213d053d16ed2438126931d8351 through before 98b1e3b27734139c76295754b6c317aa4df6d32e (git); 5.4",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-362",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: don't auto enable misc vector\n\nCurrently, there is a time window between misc irq enabled\nand service task inited. If an interrupte is reported at\nthis time, it will cause warning like below:\n\n[   16.324639] Call trace:\n[   16.324641]  __queue_delayed_work+0xb8/0xe0\n[   16.324643]  mod_delayed_work_on+0x78/0xd0\n[   16.324655]  hclge_errhand_task_schedule+0x58/0x90 [hclge]\n[   16.324662]  hclge_misc_irq_handle+0x168/0x240 [hclge]\n[   16.324666]  __handle_irq_event_percpu+0x64/0x1e0\n[   16.324667]  handle_irq_event+0x80/0x170\n[   16.324670]  handle_fasteoi_edge_irq+0x110/0x2bc\n[   16.324671]  __handle_domain_irq+0x84/0xfc\n[   16.324673]  gic_handle_irq+0x88/0x2c0\n[   16.324674]  el1_irq+0xb8/0x140\n[   16.324677]  arch_cpu_idle+0x18/0x40\n[   16.324679]  default_idle_call+0x5c/0x1bc\n[   16.324682]  cpuidle_idle_call+0x18c/0x1c4\n[   16.324684]  do_idle+0x174/0x17c\n[   16.324685]  cpu_startup_entry+0x30/0x6c\n[   16.324687]  secondary_start_kernel+0x1a4/0x280\n[   16.324688] ---[ end trace 6aa0bff672a964aa ]---\n\nSo don't auto enable misc vector when request irq..",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/41b84c5a603ffe987ec094e163d7da73aaf1841d",
                "https://git.kernel.org/stable/c/7f1fe43907a6339a41364f4f7915fbf3ab2775a8",
                "https://git.kernel.org/stable/c/800a6dfcf570c4a7e168a6fe515904de56e97148",
                "https://git.kernel.org/stable/c/98b1e3b27734139c76295754b6c317aa4df6d32e",
                "https://git.kernel.org/stable/c/bcf430d3bb5525fc89a92a0c451c725ba1aa4306",
                "https://git.kernel.org/stable/c/ee2861fce5f66c6901a014f68598e94666b23455"
            ],
            "timeline": [
                {
                    "at": "2025-01-19T11:15:10.733",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21651"
                }
            ]
        },
        {
            "id": "CVE-2025-21649",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix kernel crash when 1588 is sent on HIP08 devices\n\nCurrently, HIP08 devices does not register the ptp devices, so the\nhdev->ptp is NULL. But the tx process would still try to set hardware time\nstamp info with SKBTX_HW_TSTAMP flag and cause a kernel crash.\n\n[  128.087798] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000018\n...\n[  128.280251] pc : hclge_ptp_set_tx_info+0x2c/0x140 [hclge]\n[  128.286600] lr : hclge_ptp_set_tx_info+0x20/0x140 [hclge]\n[  128.292938] sp : ffff800059b93140\n[  128.297200] x29: ffff800059b93140 x28: 0000000000003280\n[  128.303455] x27: ffff800020d48280 x26: ffff0cb9dc814080\n[  128.309715] x25: ffff0cb9cde93fa0 x24: 0000000000000001\n[  128.315969] x23: 0000000000000000 x22: 0000000000000194\n[  128.322219] x21: ffff0cd94f986000 x20: 0000000000000000\n[  128.328462] x19: ffff0cb9d2a166c0 x18: 0000000000000000\n[  128.334698] x17: 0000000000000000 x16: ffffcf1fc523ed24\n[  128.340934] x15: 0000ffffd530a518 x14: 0000000000000000\n[  128.347162] x13: ffff0cd6bdb31310 x12: 0000000000000368\n[  128.353388] x11: ffff0cb9cfbc7070 x10: ffff2cf55dd11e02\n[  128.359606] x9 : ffffcf1f85a212b4 x8 : ffff0cd7cf27dab0\n[  128.365831] x7 : 0000000000000a20 x6 : ffff0cd7cf27d000\n[  128.372040] x5 : 0000000000000000 x4 : 000000000000ffff\n[  128.378243] x3 : 0000000000000400 x2 : ffffcf1f85a21294\n[  128.384437] x1 : ffff0cb9db520080 x0 : ffff0cb9db500080\n[  128.390626] Call trace:\n[  128.393964]  hclge_ptp_set_tx_info+0x2c/0x140 [hclge]\n[  128.399893]  hns3_nic_net_xmit+0x39c/0x4c4 [hns3]\n[  128.405468]  xmit_one.constprop.0+0xc4/0x200\n[  128.410600]  dev_hard_start_xmit+0x54/0xf0\n[  128.415556]  sch_direct_xmit+0xe8/0x634\n[  128.420246]  __dev_queue_xmit+0x224/0xc70\n[  128.425101]  dev_queue_xmit+0x1c/0x40\n[  128.429608]  ovs_vport_send+0xac/0x1a0 [openvswitch]\n[  128.435409]  do_output+0x60/0x17c [openvswitch]\n[  128.440770]  do_execute_actions+0x898/0x8c4 [openvswitch]\n[  128.446993]  ovs_execute_actions+0x64/0xf0 [openvswitch]\n[  128.453129]  ovs_dp_process_packet+0xa0/0x224 [openvswitch]\n[  128.459530]  ovs_vport_receive+0x7c/0xfc [openvswitch]\n[  128.465497]  internal_dev_xmit+0x34/0xb0 [openvswitch]\n[  128.471460]  xmit_one.constprop.0+0xc4/0x200\n[  128.476561]  dev_hard_start_xmit+0x54/0xf0\n[  128.481489]  __dev_queue_xmit+0x968/0xc70\n[  128.486330]  dev_queue_xmit+0x1c/0x40\n[  128.490856]  ip_finish_output2+0x250/0x570\n[  128.495810]  __ip_finish_output+0x170/0x1e0\n[  128.500832]  ip_finish_output+0x3c/0xf0\n[  128.505504]  ip_output+0xbc/0x160\n[  128.509654]  ip_send_skb+0x58/0xd4\n[  128.513892]  udp_send_skb+0x12c/0x354\n[  128.518387]  udp_sendmsg+0x7a8/0x9c0\n[  128.522793]  inet_sendmsg+0x4c/0x8c\n[  128.527116]  __sock_sendmsg+0x48/0x80\n[  128.531609]  __sys_sendto+0x124/0x164\n[  128.536099]  __arm64_sys_sendto+0x30/0x5c\n[  128.540935]  invoke_syscall+0x50/0x130\n[  128.545508]  el0_svc_common.constprop.0+0x10c/0x124\n[  128.551205]  do_el0_svc+0x34/0xdc\n[  128.555347]  el0_svc+0x20/0x30\n[  128.559227]  el0_sync_handler+0xb8/0xc0\n[  128.563883]  el0_sync+0x160/0x180",
            "updated_at": "2026-09-14T12:17:34.633",
            "published_at": "2025-01-19T11:15:10.517",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0bf5eb788512187b744ef7f79de835e6cbe85b9c through before 4cfa9624d6bf2d68c3831e22b49ccffe3f0b556a (git); 0bf5eb788512187b744ef7f79de835e6cbe85b9c through before 7b1b15058b177b0457ebf34b6664763cf2bbf712 (git); 0bf5eb788512187b744ef7f79de835e6cbe85b9c through before 9d213ca0cb49e2d829f8338baf776f32cc8d9efa (git); 0bf5eb788512187b744ef7f79de835e6cbe85b9c through before f19ab3ef96d9626e5f1bdc56d3574c355e83d623 (git); 0bf5eb788512187b744ef7f79de835e6cbe85b9c through before 9741e72b2286de8b38de9db685588ac421a95c87 (git); 5.14",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix kernel crash when 1588 is sent on HIP08 devices\n\nCurrently, HIP08 devices does not register the ptp devices, so the\nhdev->ptp is NULL. But the tx process would still try to set hardware time\nstamp info with SKBTX_HW_TSTAMP flag and cause a kernel crash.\n\n[  128.087798] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000018\n...\n[  128.280251] pc : hclge_ptp_set_tx_info+0x2c/0x140 [hclge]\n[  128.286600] lr : hclge_ptp_set_tx_info+0x20/0x140 [hclge]\n[  128.292938] sp : ffff800059b93140\n[  128.297200] x29: ffff800059b93140 x28: 0000000000003280\n[  128.303455] x27: ffff800020d48280 x26: ffff0cb9dc814080\n[  128.309715] x25: ffff0cb9cde93fa0 x24: 0000000000000001\n[  128.315969] x23: 0000000000000000 x22: 0000000000000194\n[  128.322219] x21: ffff0cd94f986000 x20: 0000000000000000\n[  128.328462] x19: ffff0cb9d2a166c0 x18: 0000000000000000\n[  128.334698] x17: 0000000000000000 x16: ffffcf1fc523ed24\n[  128.340934] x15: 0000ffffd530a518 x14: 0000000000000000\n[  128.347162] x13: ffff0cd6bdb31310 x12: 0000000000000368\n[  128.353388] x11: ffff0cb9cfbc7070 x10: ffff2cf55dd11e02\n[  128.359606] x9 : ffffcf1f85a212b4 x8 : ffff0cd7cf27dab0\n[  128.365831] x7 : 0000000000000a20 x6 : ffff0cd7cf27d000\n[  128.372040] x5 : 0000000000000000 x4 : 000000000000ffff\n[  128.378243] x3 : 0000000000000400 x2 : ffffcf1f85a21294\n[  128.384437] x1 : ffff0cb9db520080 x0 : ffff0cb9db500080\n[  128.390626] Call trace:\n[  128.393964]  hclge_ptp_set_tx_info+0x2c/0x140 [hclge]\n[  128.399893]  hns3_nic_net_xmit+0x39c/0x4c4 [hns3]\n[  128.405468]  xmit_one.constprop.0+0xc4/0x200\n[  128.410600]  dev_hard_start_xmit+0x54/0xf0\n[  128.415556]  sch_direct_xmit+0xe8/0x634\n[  128.420246]  __dev_queue_xmit+0x224/0xc70\n[  128.425101]  dev_queue_xmit+0x1c/0x40\n[  128.429608]  ovs_vport_send+0xac/0x1a0 [openvswitch]\n[  128.435409]  do_output+0x60/0x17c [openvswitch]\n[  128.440770]  do_execute_actions+0x898/0x8c4 [openvswitch]\n[  128.446993]  ovs_execute_actions+0x64/0xf0 [openvswitch]\n[  128.453129]  ovs_dp_process_packet+0xa0/0x224 [openvswitch]\n[  128.459530]  ovs_vport_receive+0x7c/0xfc [openvswitch]\n[  128.465497]  internal_dev_xmit+0x34/0xb0 [openvswitch]\n[  128.471460]  xmit_one.constprop.0+0xc4/0x200\n[  128.476561]  dev_hard_start_xmit+0x54/0xf0\n[  128.481489]  __dev_queue_xmit+0x968/0xc70\n[  128.486330]  dev_queue_xmit+0x1c/0x40\n[  128.490856]  ip_finish_output2+0x250/0x570\n[  128.495810]  __ip_finish_output+0x170/0x1e0\n[  128.500832]  ip_finish_output+0x3c/0xf0\n[  128.505504]  ip_output+0xbc/0x160\n[  128.509654]  ip_send_skb+0x58/0xd4\n[  128.513892]  udp_send_skb+0x12c/0x354\n[  128.518387]  udp_sendmsg+0x7a8/0x9c0\n[  128.522793]  inet_sendmsg+0x4c/0x8c\n[  128.527116]  __sock_sendmsg+0x48/0x80\n[  128.531609]  __sys_sendto+0x124/0x164\n[  128.536099]  __arm64_sys_sendto+0x30/0x5c\n[  128.540935]  invoke_syscall+0x50/0x130\n[  128.545508]  el0_svc_common.constprop.0+0x10c/0x124\n[  128.551205]  do_el0_svc+0x34/0xdc\n[  128.555347]  el0_svc+0x20/0x30\n[  128.559227]  el0_sync_handler+0xb8/0xc0\n[  128.563883]  el0_sync+0x160/0x180",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/4cfa9624d6bf2d68c3831e22b49ccffe3f0b556a",
                "https://git.kernel.org/stable/c/7b1b15058b177b0457ebf34b6664763cf2bbf712",
                "https://git.kernel.org/stable/c/9741e72b2286de8b38de9db685588ac421a95c87",
                "https://git.kernel.org/stable/c/9d213ca0cb49e2d829f8338baf776f32cc8d9efa",
                "https://git.kernel.org/stable/c/f19ab3ef96d9626e5f1bdc56d3574c355e83d623"
            ],
            "timeline": [
                {
                    "at": "2025-01-19T11:15:10.517",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21649"
                }
            ]
        },
        {
            "id": "CVE-2025-21479",
            "vendor": "Qualcomm",
            "product": "Multiple Chipsets",
            "title": "Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability",
            "summary": "Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.",
            "updated_at": "2026-06-17T08:43:33.660",
            "published_at": "2025-06-03T07:15:20.933",
            "cvss": 8.6,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "AQT1000; FastConnect 6200; FastConnect 6700; FastConnect 6800; FastConnect 6900; FastConnect 7800; QCA6391; QCM4490; QCS4490; SD855; SM4635; SM6250; SM6650; SM6650P; SM7325P; SM7635; SM7675; SM7675P; SM8550P; SM8635; SM8635P; SM8650Q; Snapdragon 4 Gen 1 Mobile Platform; Snapdragon 460 Mobile Platform; Snapdragon 480 5G Mobile Platform; Snapdragon 480+ 5G Mobile Platform (SM4350-AC); Snapdragon 662 Mobile Platform; Snapdragon 680 4G Mobile Platform; Snapdragon 685 4G Mobile Platform (SM6225-AD); Snapdragon 690 5G Mobile Platform; Snapdragon 695 5G Mobile Platform; Snapdragon 720G Mobile Platform; Snapdragon 778G 5G Mobile Platform; Snapdragon 778G+ 5G Mobile Platform (SM7325-AE); Snapdragon 782G Mobile Platform (SM7325-AF); Snapdragon 7c+ Gen 3 Compute; Snapdragon 8 Gen 2 Mobile Platform; Snapdragon 8 Gen 3 Mobile Platform; Snapdragon 8+ Gen 2 Mobile Platform; Snapdragon 855 Mobile Platform; Snapdragon 855+/860 Mobile Platform (SM8150-AC); Snapdragon 865 5G Mobile Platform; Snapdragon 865+ 5G Mobile Platform (SM8250-AB); Snapdragon 870 5G Mobile Platform (SM8250-AC); Snapdragon 888 5G Mobile Platform; Snapdragon 888+ 5G Mobile Platform (SM8350-AC); Snapdragon AR1 Gen 1 Platform; Snapdragon AR1 Gen 1 Platform \"Luna1\"; Snapdragon X55 5G Modem-RF System; SXR2230P; SXR2250P; SXR2330P; WCD9341; WCD9370; WCD9375; WCD9378; WCD9380; WCD9385; WCD9390; WCD9395; WCN3950; WCN3988; WCN6450; WCN6650; WCN6755; WCN7861; WCN7881; WSA8810; WSA8815; WSA8830; WSA8832; WSA8835; WSA8840; WSA8845; WSA8845H",
            "fixed": "See vendor advisory",
            "source_count": 376,
            "kev": true,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · zhuowei/cheese",
                    "author": "zhuowei",
                    "first_seen": "2025-06-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 276,
                    "title": "CVE-2025-21479 proof-of-concept, I think",
                    "summary": "CVE-2025-21479 proof-of-concept, I think",
                    "url": "https://github.com/zhuowei/cheese"
                },
                {
                    "repository": "PoC-in-GitHub · sarabpal-dev/cheese-cake",
                    "author": "sarabpal-dev",
                    "first_seen": "2025-11-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 35,
                    "title": "A proof-of-concept for CVE-2025-21479, chained with a Dirty Pagetable technique.",
                    "summary": "A proof-of-concept for CVE-2025-21479, chained with a Dirty Pagetable technique.",
                    "url": "https://github.com/sarabpal-dev/cheese-cake"
                },
                {
                    "repository": "PoC-in-GitHub · ma4the/omae-wa-cheese-da",
                    "author": "ma4the",
                    "first_seen": "2026-06-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "CVE-2025-21479 PoC for ZFlip5 with Knox in the way!(˶˃ ᵕ ˂˶)",
                    "summary": "CVE-2025-21479 PoC for ZFlip5 with Knox in the way!(˶˃ ᵕ ˂˶)",
                    "url": "https://github.com/ma4the/omae-wa-cheese-da"
                },
                {
                    "repository": "PoC-in-GitHub · CamsShaft/SELinux-Permissive-Only-CVE-2025-21479",
                    "author": "CamsShaft",
                    "first_seen": "2026-07-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "This is an SELinux permissive version of the Cheese exploit also known as CVE-2025-21479 which affected the adreno kgsl on many devices including Samsung snapdragon devices",
                    "summary": "This is an SELinux permissive version of the Cheese exploit also known as CVE-2025-21479 which affected the adreno kgsl on many devices including Samsung snapdragon devices",
                    "url": "https://github.com/CamsShaft/SELinux-Permissive-Only-CVE-2025-21479"
                },
                {
                    "repository": "PoC-in-GitHub · Type010/cve-2025-21479-iqoo11pro",
                    "author": "Type010",
                    "first_seen": "2026-08-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "CVE-2025-21479 repository",
                    "summary": "",
                    "url": "https://github.com/Type010/cve-2025-21479-iqoo11pro"
                },
                {
                    "repository": "PoC-in-GitHub · reaizuguo/vivo_iqoo_neo_9_root_research_on_CVE-2025-21479",
                    "author": "reaizuguo",
                    "first_seen": "2026-08-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "iQOO Neo9 (PD2338C) 免解锁 Caps-Root 工具** — 基于 CVE-2025-21479 (Adreno GPU SDS) 的任意物理写提权方案",
                    "summary": "iQOO Neo9 (PD2338C) 免解锁 Caps-Root 工具** — 基于 CVE-2025-21479 (Adreno GPU SDS) 的任意物理写提权方案",
                    "url": "https://github.com/reaizuguo/vivo_iqoo_neo_9_root_research_on_CVE-2025-21479"
                },
                {
                    "repository": "PoC-in-GitHub · linux-tools/vivo_iqoo_neo_9_root_research_on_CVE-2025-21479",
                    "author": "linux-tools",
                    "first_seen": "2026-08-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2025-21479 repository",
                    "summary": "",
                    "url": "https://github.com/linux-tools/vivo_iqoo_neo_9_root_research_on_CVE-2025-21479"
                },
                {
                    "repository": "PoC-in-GitHub · Qingizi7/cve-2025-21479_iqooneo8",
                    "author": "Qingizi7",
                    "first_seen": "2026-08-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical memory r/w, disables SELinux, spawns root shell",
                    "summary": "Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical memory r/w, disables SELinux, spawns root shell",
                    "url": "https://github.com/Qingizi7/cve-2025-21479_iqooneo8"
                },
                {
                    "repository": "PoC-in-GitHub · xjoker/lenovo_y700_tb320fc_on_CVE-2025-21479",
                    "author": "xjoker",
                    "first_seen": "2026-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-21479 repository",
                    "summary": "",
                    "url": "https://github.com/xjoker/lenovo_y700_tb320fc_on_CVE-2025-21479"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/zhuowei/cheese",
                "https://github.com/sarabpal-dev/cheese-cake",
                "https://github.com/ma4the/omae-wa-cheese-da",
                "https://github.com/CamsShaft/SELinux-Permissive-Only-CVE-2025-21479",
                "https://github.com/Type010/cve-2025-21479-iqoo11pro",
                "https://github.com/reaizuguo/vivo_iqoo_neo_9_root_research_on_CVE-2025-21479",
                "https://github.com/linux-tools/vivo_iqoo_neo_9_root_research_on_CVE-2025-21479",
                "https://github.com/Qingizi7/cve-2025-21479_iqooneo8",
                "https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-21479",
                "https://github.com/xjoker/lenovo_y700_tb320fc_on_CVE-2025-21479"
            ],
            "timeline": [
                {
                    "at": "2026-08-19T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-03T07:15:20.933",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21479"
                },
                {
                    "at": "2025-06-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "enrichment_checked_at": "2026-09-16T22:05:33Z",
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-20701",
            "vendor": "Airoha Technology Corp.",
            "product": "AB156x, AB157x, AB158x, AB159x series",
            "title": "AB156x, AB157x, AB158x, AB159x series vulnerability",
            "summary": "In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "updated_at": "2026-09-08T16:17:48.883",
            "published_at": "2025-08-04T07:15:28.027",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Airoha IoT SDK for BT audio v5.5.0 and earlier; Airoha AB1561x/AB1562x/AB1563x SDK v3.3.1 and earlier",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.airoha.com/product-security-bulletin/2025",
                "http://seclists.org/fulldisclosure/2026/Aug/7",
                "http://seclists.org/fulldisclosure/2026/Jun/18",
                "https://www.kb.cert.org/vuls/id/859658"
            ],
            "timeline": [
                {
                    "at": "2025-08-04T07:15:28.027",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20701"
                }
            ]
        },
        {
            "id": "CVE-2025-20260",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2025-20260-POC exploit",
            "summary": "Exploit for CVE-2025-20260. CVSS 9.8.",
            "updated_at": "2026-09-05T12:45:16Z",
            "published_at": "2026-09-05T12:45:16Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 89,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Buffer overflow in ClamAV PDF scanning via crafted PDF causing DoS or arbitrary code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-20260-POC",
                    "summary": "Buffer overflow in ClamAV PDF scanning via crafted PDF causing DoS or arbitrary code execution.",
                    "what_happened": "Buffer overflow in ClamAV PDF scanning via crafted PDF causing DoS or arbitrary code execution.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEX-ACERO-SECURITY-CVE-2025-20260-POC",
                        "https://kitploit.com/ru/tools/github/alex-acero-security/cve-2025-20260-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T12:45:16",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEX-ACERO-SECURITY-CVE-2025-20260-POC"
                },
                {
                    "title": "Exploit for CVE-2025-20260-POC",
                    "summary": "Buffer overflow in ClamAV PDF scanning via crafted PDF causing DoS or arbitrary code execution.",
                    "what_happened": "Buffer overflow in ClamAV PDF scanning via crafted PDF causing DoS or arbitrary code execution.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEX-ACERO-SECURITY-CVE-2025-20260-POC",
                        "https://kitploit.com/ru/tools/github/alex-acero-security/cve-2025-20260-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T12:45:16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/alex-acero-security/cve-2025-20260-poc/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEX-ACERO-SECURITY-CVE-2025-20260-POC",
                "https://kitploit.com/ru/tools/github/alex-acero-security/cve-2025-20260-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:45:16Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEX-ACERO-SECURITY-CVE-2025-20260-POC"
                }
            ]
        },
        {
            "id": "CVE-2025-15694",
            "vendor": "Unknown",
            "product": "Joli Table Of Contents",
            "title": "Joli Table Of Contents vulnerability",
            "summary": "The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed, for example in a multisite setup.",
            "updated_at": "2026-09-06T11:18:00.190",
            "published_at": "2026-09-05T07:17:10.447",
            "cvss": 3.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.0.0 through before 2.8.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-privilege users such as administrators to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed, for example in a multisite setup.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/9ebaf1aa-eb8b-4c62-bbd0-07918503fbf1/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:10.447",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15694"
                }
            ]
        },
        {
            "id": "CVE-2025-15693",
            "vendor": "Unknown",
            "product": "JCH Optimize",
            "title": "JCH Optimize vulnerability",
            "summary": "The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names outside the web root.",
            "updated_at": "2026-09-06T11:17:59.430",
            "published_at": "2026-09-05T07:17:10.343",
            "cvss": 2.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.2.1 through before 5.0.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site, allowing high-privilege users, administrators on single-site and sub-site administrators on multisite, to enumerate directories and file names outside the web root.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://wpscan.com/vulnerability/73e664a8-9075-4fe6-9af4-b6f5d2ccfe3c/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T07:17:10.343",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15693"
                }
            ]
        },
        {
            "id": "CVE-2025-15647",
            "vendor": "artem-ogre",
            "product": "CDT",
            "title": "CDT vulnerability",
            "summary": "CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent triangles. Attackers can supply nearly-degenerate constraint edges through geometry data to trigger an out-of-bounds array access that crashes the calling process.",
            "updated_at": "2026-09-05T12:16:46.490",
            "published_at": "2026-09-05T12:16:46.490",
            "cvss": 6.8,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.4.5 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent triangles. Attackers can supply nearly-degenerate constraint edges through geometry data to trigger an out-of-bounds array access that crashes the calling process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/artem-ogre/CDT",
                "https://github.com/artem-ogre/CDT/blob/1.4.4/CDT/include/CDTUtils.hpp#L175",
                "https://github.com/artem-ogre/CDT/commit/bf0d11ebfe3da0da72aed91816f665aef1b447cc",
                "https://github.com/artem-ogre/CDT/issues/212",
                "https://github.com/artem-ogre/CDT/releases/tag/1.4.5",
                "https://www.vulncheck.com/advisories/cdt-before-1.4.5-out-of-bounds-read-via-opposedvertexind"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:16:46.490",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15647"
                }
            ]
        },
        {
            "id": "CVE-2025-15614",
            "vendor": "Genivia",
            "product": "ugrep",
            "title": "ugrep vulnerability",
            "summary": "ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the process.",
            "updated_at": "2026-09-05T12:16:45.450",
            "published_at": "2026-09-05T12:16:45.450",
            "cvss": 4.8,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 7.6.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the process.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/Genivia/ugrep",
                "https://github.com/Genivia/ugrep/blob/v7.5.0/src/zopen.c#L673",
                "https://github.com/Genivia/ugrep/commit/c12849a11264e2c81c860bf78ee9039772f307a4",
                "https://github.com/Genivia/ugrep/issues/511",
                "https://github.com/Genivia/ugrep/releases/tag/v7.6.0",
                "https://www.vulncheck.com/advisories/ugrep-before-7.6.0-heap-buffer-over-read-via-z-decompression"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:16:45.450",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15614"
                }
            ]
        },
        {
            "id": "CVE-2025-15467",
            "vendor": "OpenSSL",
            "product": "OpenSSL",
            "title": "OpenSSL vulnerability",
            "summary": "Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with\nmaliciously crafted AEAD parameters can trigger a stack buffer overflow.\n\nImpact summary: A stack buffer overflow may lead to a crash, causing Denial\nof Service, or potentially remote code execution.\n\nWhen parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as\nAES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is\ncopied into a fixed-size stack buffer without verifying that its length fits\nthe destination. An attacker can supply a crafted CMS message with an\noversized IV, causing a stack-based out-of-bounds write before any\nauthentication or tag verification occurs.\n\nApplications and services that parse untrusted CMS or PKCS#7 content using\nAEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable.\nBecause the overflow occurs prior to authentication, no valid key material\nis required to trigger it. While exploitability to remote code execution\ndepends on platform and toolchain mitigations, the stack-based write\nprimitive represents a severe risk.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.\n\nOpenSSL 1.1.1 and 1.0.2 are not affected by this issue.",
            "updated_at": "2026-09-07T13:17:27.740",
            "published_at": "2026-01-27T16:16:14.257",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "3.6.0 through before 3.6.1 (semver); 3.5.0 through before 3.5.5 (semver); 3.4.0 through before 3.4.4 (semver); 3.3.0 through before 3.3.6 (semver); 3.0.0 through before 3.0.19 (semver); before * (custom); before V1.8.0 (custom); before V3.3.2 (custom); before V9.0 QU1 (custom); V4.0.700 through before * (custom); before V9.3 SP2 (custom); before V5.7 SP4 (custom); before V3.19 P024 (custom); before V3.20 P012 (custom); before V3.21 P02 (custom); before V17 Update 9 (custom); before V21 (custom); before V3.1.13 (custom); before V3.2.4 (custom); V6.3 through before * (custom); before V1.0 SP2 Update 5 (custom); before V4.2 SP3 (custom); before V2.15.3.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 98,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with\nmaliciously crafted AEAD parameters can trigger a stack buffer overflow.\n\nImpact summary: A stack buffer overflow may lead to a crash, causing Denial\nof Service, or potentially remote code execution.\n\nWhen parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as\nAES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is\ncopied into a fixed-size stack buffer without verifying that its length fits\nthe destination. An attacker can supply a crafted CMS message with an\noversized IV, causing a stack-based out-of-bounds write before any\nauthentication or tag verification occurs.\n\nApplications and services that parse untrusted CMS or PKCS#7 content using\nAEAD ciphers (e.g., S/MIME (Auth)EnvelopedData with AES-GCM) are vulnerable.\nBecause the overflow occurs prior to authentication, no valid key material\nis required to trigger it. While exploitability to remote code execution\ndepends on platform and toolchain mitigations, the stack-based write\nprimitive represents a severe risk.\n\nThe FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this\nissue, as the CMS implementation is outside the OpenSSL FIPS module\nboundary.\n\nOpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.\n\nOpenSSL 1.1.1 and 1.0.2 are not affected by this issue.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2026-01-27",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/guiimoraes/CVE-2025-15467"
                },
                {
                    "title": "Exploit for cve-2025-15467 CVE-2025-15467",
                    "summary": "Exploit script for CVE-2025-15467.",
                    "what_happened": "Exploit script for CVE-2025-15467.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MATERAJ2-CVE-2025-15467",
                        "https://kitploit.com/en/tools/github/materaj2/cve-2025-15467/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T18:42:11",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MATERAJ2-CVE-2025-15467"
                },
                {
                    "title": "Exploit for cve-2025-15467 CVE-2025-15467",
                    "summary": "Exploit script for CVE-2025-15467.",
                    "what_happened": "Exploit script for CVE-2025-15467.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MATERAJ2-CVE-2025-15467",
                        "https://kitploit.com/en/tools/github/materaj2/cve-2025-15467/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-06T18:42:11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/materaj2/cve-2025-15467/"
                }
            ],
            "references": [
                "https://github.com/openssl/openssl/commit/2c8f0e5fa9b6ee5508a0349e4572ddb74db5a703",
                "https://github.com/openssl/openssl/commit/5f26d4202f5b89664c5c3f3c62086276026ba9a9",
                "https://github.com/openssl/openssl/commit/6ced0fe6b10faa560e410e3ee8d6c82f06c65ea3",
                "https://github.com/openssl/openssl/commit/ce39170276daec87f55c39dad1f629b56344429e",
                "https://github.com/openssl/openssl/commit/d0071a0799f20cc8101730145349ed4487c268dc",
                "https://openssl-library.org/news/secadv/20260127.txt",
                "http://www.openwall.com/lists/oss-security/2026/01/27/10",
                "http://www.openwall.com/lists/oss-security/2026/02/25/6",
                "https://access.redhat.com/errata/RHSA-2026:1472",
                "https://access.redhat.com/errata/RHSA-2026:1473",
                "https://access.redhat.com/errata/RHSA-2026:1496",
                "https://access.redhat.com/errata/RHSA-2026:1503",
                "https://access.redhat.com/errata/RHSA-2026:1519",
                "https://access.redhat.com/errata/RHSA-2026:1594",
                "https://access.redhat.com/errata/RHSA-2026:1733",
                "https://access.redhat.com/errata/RHSA-2026:1736",
                "https://access.redhat.com/errata/RHSA-2026:2072",
                "https://access.redhat.com/errata/RHSA-2026:2077",
                "https://access.redhat.com/errata/RHSA-2026:2485",
                "https://access.redhat.com/errata/RHSA-2026:2563",
                "https://access.redhat.com/errata/RHSA-2026:2633",
                "https://access.redhat.com/errata/RHSA-2026:2659",
                "https://access.redhat.com/errata/RHSA-2026:2671",
                "https://access.redhat.com/errata/RHSA-2026:2844",
                "https://access.redhat.com/errata/RHSA-2026:2974",
                "https://access.redhat.com/errata/RHSA-2026:2995",
                "https://access.redhat.com/errata/RHSA-2026:3228",
                "https://access.redhat.com/errata/RHSA-2026:3415",
                "https://access.redhat.com/errata/RHSA-2026:3461",
                "https://access.redhat.com/errata/RHSA-2026:3462",
                "https://access.redhat.com/errata/RHSA-2026:4419",
                "https://access.redhat.com/errata/RHSA-2026:4943",
                "https://access.redhat.com/errata/RHSA-2026:6481",
                "https://access.redhat.com/errata/RHSA-2026:7261",
                "https://access.redhat.com/security/cve/CVE-2025-15467",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2430376",
                "https://cert-portal.siemens.com/productcert/html/ssa-434797.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-734552.html",
                "https://github.com/guiimoraes/CVE-2025-15467",
                "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-15467.json",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MATERAJ2-CVE-2025-15467",
                "https://kitploit.com/en/tools/github/materaj2/cve-2025-15467/"
            ],
            "timeline": [
                {
                    "at": "2026-01-27T16:16:14.257",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15467"
                }
            ]
        },
        {
            "id": "CVE-2025-15267",
            "vendor": "boldthemes",
            "product": "Bold Page Builder",
            "title": "Bold Page Builder vulnerability",
            "summary": "The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion_item shortcode in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
            "updated_at": "2026-09-15T16:17:07.547",
            "published_at": "2026-02-07T06:16:03.847",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 5.6.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion_item shortcode in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/bold-page-builder/tags/5.5.7/content_elements/bt_bb_accordion_item/bt_bb_accordion_item.php?marks=28#L28",
                "https://plugins.trac.wordpress.org/changeset/3449791/bold-page-builder/trunk/content_elements/bt_bb_accordion_item/bt_bb_accordion_item.php",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/38a3b3bf-9538-4ae8-9da4-d4b48805763b?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-02-07T06:16:03.847",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15267"
                }
            ]
        },
        {
            "id": "CVE-2025-15224",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
            "updated_at": "2026-09-15T07:16:24.690",
            "published_at": "2026-01-08T10:15:47.207",
            "cvss": 3.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.58.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.18.0 (semver); c92d2e14cfb0db662f958effd2ac86f995cf1b5a through before 16d5f2a5660c61cc27bd5f1c7f512391d1c927aa (git); 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-287",
            "what_happened": "When doing SSH-based transfers using either SCP or SFTP, and asked to do\npublic key authentication, curl would wrongly still ask and authenticate using\na locally running SSH agent.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-01-08",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3480925"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2025-15224.html",
                "https://curl.se/docs/CVE-2025-15224.json",
                "https://hackerone.com/reports/3480925",
                "http://www.openwall.com/lists/oss-security/2026/01/07/7"
            ],
            "timeline": [
                {
                    "at": "2026-01-08T10:15:47.207",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15224"
                }
            ]
        },
        {
            "id": "CVE-2025-15079",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.",
            "updated_at": "2026-09-15T07:16:24.467",
            "published_at": "2026-01-08T10:15:47.100",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.58.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.18.0 (semver); c92d2e14cfb0db662f958effd2ac86f995cf1b5a through before adca486c125d9a6d9565b9607a19dce803a8b479 (git); 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-297",
            "what_happened": "When doing SSH-based transfers using either SCP or SFTP, and setting the\nknown_hosts file, libcurl could still mistakenly accept connecting to hosts\n*not present* in the specified file if they were added as recognized in the\nlibssh *global* known_hosts file.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-01-08",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3477116"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2025-15079.html",
                "https://curl.se/docs/CVE-2025-15079.json",
                "https://hackerone.com/reports/3477116",
                "http://www.openwall.com/lists/oss-security/2026/01/07/6"
            ],
            "timeline": [
                {
                    "at": "2026-01-08T10:15:47.100",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15079"
                }
            ]
        },
        {
            "id": "CVE-2025-14945",
            "vendor": "netweblogic",
            "product": "Events Manager – Calendar, Bookings, Tickets, and more!",
            "title": "Events Manager – Calendar, Bookings, Tickets, and more! vulnerability",
            "summary": "The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions up to, and including, 7.3.3. This is due to insufficient input sanitization when storing attribute values (using only `wp_unslash()` without sanitization) and lack of output escaping when rendering the '#_ATT{key}' placeholder. This makes it possible for authenticated attackers, with Author-level access and above, or unauthenticated attackers when anonymous event submissions are enabled, to inject arbitrary web scripts that execute when any user views the affected event page.",
            "updated_at": "2026-09-05T06:17:09.017",
            "published_at": "2026-09-05T06:17:09.017",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 7.3.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-79",
            "what_happened": "The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions up to, and including, 7.3.3. This is due to insufficient input sanitization when storing attribute values (using only `wp_unslash()` without sanitization) and lack of output escaping when rendering the '#_ATT{key}' placeholder. This makes it possible for authenticated attackers, with Author-level access and above, or unauthenticated attackers when anonymous event submissions are enabled, to inject arbitrary web scripts that execute when any user views the affected event page.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/events-manager/trunk/classes/em-event.php#L1206",
                "https://plugins.trac.wordpress.org/browser/events-manager/trunk/classes/em-event.php#L2608",
                "https://plugins.trac.wordpress.org/changeset/3567065/",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/a1985eb5-bfb5-4220-a4f8-fcfa84beae6a?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T06:17:09.017",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14945"
                }
            ]
        },
        {
            "id": "CVE-2025-14819",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When doing TLS related transfers with reused easy or multi handles and\naltering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally\nreuse a CA store cached in memory for which the partial chain option was\nreversed. Contrary to the user's wishes and expectations. This could make\nlibcurl find and accept a trust chain that it otherwise would not.",
            "updated_at": "2026-09-15T07:16:24.260",
            "published_at": "2026-01-08T10:15:46.730",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.87.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.18.0 (semver); 3c16697ebd796f799227be293e8689aec5f8190d through before cd046f6c93b39d673a58c18648d8906e954c4f5d (git); 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "When doing TLS related transfers with reused easy or multi handles and\naltering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally\nreuse a CA store cached in memory for which the partial chain option was\nreversed. Contrary to the user's wishes and expectations. This could make\nlibcurl find and accept a trust chain that it otherwise would not.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://curl.se/docs/CVE-2025-14819.html",
                "https://curl.se/docs/CVE-2025-14819.json",
                "http://www.openwall.com/lists/oss-security/2026/01/07/5"
            ],
            "timeline": [
                {
                    "at": "2026-01-08T10:15:46.730",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14819"
                }
            ]
        },
        {
            "id": "CVE-2025-14813",
            "vendor": "Legion of the Bouncy Castle Inc.",
            "product": "BC-JAVA",
            "title": "BC-JAVA vulnerability",
            "summary": ": Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).\n\n This vulnerability is associated with program files G3413CTRBlockCipher.\n\n\n\nThis issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.",
            "updated_at": "2026-09-11T13:16:48.273",
            "published_at": "2026-04-15T10:16:38.243",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:Red",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.59 through before 1.80.2 (maven); 1.81 through before 1.81.1 (maven); 1.82 through before 1.84 (maven)",
            "fixed": "See vendor advisory",
            "source_count": 31,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-327",
            "what_happened": ": Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules).\n\n This vulnerability is associated with program files G3413CTRBlockCipher.\n\n\n\nThis issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/bcgit/bc-java/commit/701686cb0184cd9ae103c801b3581fdf95c6d4f3",
                "https://github.com/bcgit/bc-java/commit/b42574345414e4b7c8051b16fa1fafe01c29871f",
                "https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9014813",
                "https://access.redhat.com/errata/RHSA-2026:11720",
                "https://access.redhat.com/errata/RHSA-2026:11721",
                "https://access.redhat.com/errata/RHSA-2026:13631",
                "https://access.redhat.com/errata/RHSA-2026:14272",
                "https://access.redhat.com/errata/RHSA-2026:14276",
                "https://access.redhat.com/errata/RHSA-2026:17668",
                "https://access.redhat.com/errata/RHSA-2026:18054",
                "https://access.redhat.com/errata/RHSA-2026:18055",
                "https://access.redhat.com/errata/RHSA-2026:18059",
                "https://access.redhat.com/errata/RHSA-2026:21772",
                "https://access.redhat.com/errata/RHSA-2026:24977",
                "https://access.redhat.com/errata/RHSA-2026:53644",
                "https://access.redhat.com/errata/RHSA-2026:53806",
                "https://access.redhat.com/errata/RHSA-2026:60239",
                "https://access.redhat.com/errata/RHSA-2026:60246",
                "https://access.redhat.com/errata/RHSA-2026:60247",
                "https://access.redhat.com/errata/RHSA-2026:60248",
                "https://access.redhat.com/errata/RHSA-2026:60249",
                "https://access.redhat.com/errata/RHSA-2026:60250",
                "https://access.redhat.com/errata/RHSA-2026:60251",
                "https://access.redhat.com/errata/RHSA-2026:60252",
                "https://access.redhat.com/errata/RHSA-2026:60254",
                "https://access.redhat.com/errata/RHSA-2026:60256",
                "https://access.redhat.com/errata/RHSA-2026:60259",
                "https://access.redhat.com/errata/RHSA-2026:66488",
                "https://access.redhat.com/security/cve/CVE-2025-14813",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2458640",
                "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-14813.json"
            ],
            "timeline": [
                {
                    "at": "2026-04-15T10:16:38.243",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14813"
                }
            ]
        },
        {
            "id": "CVE-2025-14733",
            "vendor": "WatchGuard",
            "product": "Fireware OS",
            "title": "Fireware OS vulnerability",
            "summary": "An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.\n\nIf the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.",
            "updated_at": "2026-09-09T04:17:52.700",
            "published_at": "2025-12-19T01:16:05.530",
            "cvss": 9.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red",
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "2025.1 through before 2025.1.4 (custom); 12.0 through before 12.11.6 (custom); 11.10.2 through 11.12.4+541730 (custom); 12.0 through before 12.3.1+728352 (custom); 12.0 through before 12.5.15 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 31,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.\n\nIf the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://psirt.watchguard.com/CVE-2025-14733",
                "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00027",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-14733"
            ],
            "timeline": [
                {
                    "at": "2025-12-19T01:16:05.530",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14733"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-14659",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Static analysis (Ghidra) and custom packet-crafting (Scapy) demonstrating a root-level DHCP command injection vulnerability (CVE-2025-14659) in D-Link firmware",
            "summary": "Static analysis (Ghidra) and custom packet-crafting (Scapy) demonstrating a root-level DHCP command injection vulnerability (CVE-2025-14659) in D-Link firmware",
            "updated_at": "2026-09-12T22:00:00Z",
            "published_at": "2026-09-12T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · PeterLinccl/Vulnerability-DLink-CVE-2025-14659",
                    "author": "PeterLinccl",
                    "first_seen": "2026-09-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Static analysis (Ghidra) and custom packet-crafting (Scapy) demonstrating a root-level DHCP command injection vulnerability (CVE-2025-14659) in D-Link firmware",
                    "summary": "Static analysis (Ghidra) and custom packet-crafting (Scapy) demonstrating a root-level DHCP command injection vulnerability (CVE-2025-14659) in D-Link firmware",
                    "url": "https://github.com/PeterLinccl/Vulnerability-DLink-CVE-2025-14659"
                }
            ],
            "references": [
                "https://github.com/PeterLinccl/Vulnerability-DLink-CVE-2025-14659"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/PeterLinccl/Vulnerability-DLink-CVE-2025-14659"
                }
            ]
        },
        {
            "id": "CVE-2025-14524",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.",
            "updated_at": "2026-09-15T07:16:24.020",
            "published_at": "2026-01-08T10:15:46.607",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.33.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.18.0 (semver); 06c1bea72faabb6fad4b7ef818aafaa336c9a7aa through before 1a822275d333dc6da6043497160fd04c8fa48640 (git); 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-522",
            "what_happened": "When an OAuth2 bearer token is used for an HTTP(S) transfer, and that transfer\nperforms a cross-protocol redirect to a second URL that uses an IMAP, LDAP,\nPOP3 or SMTP scheme, curl might wrongly pass on the bearer token to the new\ntarget host.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2026-01-08",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3459417"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2025-14524.html",
                "https://curl.se/docs/CVE-2025-14524.json",
                "https://hackerone.com/reports/3459417",
                "http://www.openwall.com/lists/oss-security/2026/01/07/4"
            ],
            "timeline": [
                {
                    "at": "2026-01-08T10:15:46.607",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14524"
                }
            ]
        },
        {
            "id": "CVE-2025-14017",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.",
            "updated_at": "2026-09-15T07:16:23.753",
            "published_at": "2026-01-08T10:15:45.667",
            "cvss": 6.3,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.17.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.18.0 (semver); ccba0d10b6baf5c73cae8cf4fb3f29f0f55c5a34 through before 39d1976b7f709a516e3243338ebc0443bdd8d56d (git); 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; 7.68.0; 7.67.0; 7.66.0; 7.65.3; 7.65.2; 7.65.1; 7.65.0; 7.64.1; 7.64.0; 7.63.0; 7.62.0; 7.61.1; 7.61.0; 7.60.0; 7.59.0; 7.58.0; 7.57.0; 7.56.1; 7.56.0; 7.55.1; 7.55.0; 7.54.1; 7.54.0; 7.53.1; 7.53.0; 7.52.1; 7.52.0; 7.51.0; 7.50.3; 7.50.2; 7.50.1; 7.50.0; 7.49.1; 7.49.0; 7.48.0; 7.47.1; 7.47.0; 7.46.0; 7.45.0; 7.44.0; 7.43.0; 7.42.1; 7.42.0; 7.41.0; 7.40.0; 7.39.0; 7.38.0; 7.37.1; 7.37.0; 7.36.0; 7.35.0; 7.34.0; 7.33.0; 7.32.0; 7.31.0; 7.30.0; 7.29.0; 7.28.1; 7.28.0; 7.27.0; 7.26.0; 7.25.0; 7.24.0; 7.23.1; 7.23.0; 7.22.0; 7.21.7; 7.21.6; 7.21.5; 7.21.4; 7.21.3; 7.21.2; 7.21.1; 7.21.0; 7.20.1; 7.20.0; 7.19.7; 7.19.6; 7.19.5; 7.19.4; 7.19.3; 7.19.2; 7.19.1; 7.19.0; 7.18.2; 7.18.1; 7.18.0; 7.17.1; 7.17.0",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-567",
            "what_happened": "When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,\nchanging TLS options in one thread would inadvertently change them globally\nand therefore possibly also affect other concurrently setup transfers.\n\nDisabling certificate verification for a specific transfer could\nunintentionally disable the feature for other threads as well.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://curl.se/docs/CVE-2025-14017.html",
                "https://curl.se/docs/CVE-2025-14017.json",
                "http://www.openwall.com/lists/oss-security/2026/01/07/3"
            ],
            "timeline": [
                {
                    "at": "2026-01-08T10:15:45.667",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14017"
                }
            ]
        },
        {
            "id": "CVE-2025-13465",
            "vendor": "Lodash",
            "product": "Lodash",
            "title": "Lodash vulnerability",
            "summary": "Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23",
            "updated_at": "2026-09-10T13:16:56.537",
            "published_at": "2026-01-21T20:16:05.250",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through 4.17.22 (semver); 4.0.0; before V4.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 88,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-1321",
            "what_happened": "Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes.\n\nThe issue permits deletion of properties but does not allow overwriting their original behavior.\n\nThis issue is patched on 4.17.23",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg",
                "https://access.redhat.com/errata/RHSA-2026:11414",
                "https://access.redhat.com/errata/RHSA-2026:13542",
                "https://access.redhat.com/errata/RHSA-2026:13548",
                "https://access.redhat.com/errata/RHSA-2026:13829",
                "https://access.redhat.com/errata/RHSA-2026:14774",
                "https://access.redhat.com/errata/RHSA-2026:14870",
                "https://access.redhat.com/errata/RHSA-2026:14871",
                "https://access.redhat.com/errata/RHSA-2026:15091",
                "https://access.redhat.com/errata/RHSA-2026:17469",
                "https://access.redhat.com/errata/RHSA-2026:1845",
                "https://access.redhat.com/errata/RHSA-2026:18480",
                "https://access.redhat.com/errata/RHSA-2026:18868",
                "https://access.redhat.com/errata/RHSA-2026:19712",
                "https://access.redhat.com/errata/RHSA-2026:20042",
                "https://access.redhat.com/errata/RHSA-2026:20088",
                "https://access.redhat.com/errata/RHSA-2026:2078",
                "https://access.redhat.com/errata/RHSA-2026:2119",
                "https://access.redhat.com/errata/RHSA-2026:2145",
                "https://access.redhat.com/errata/RHSA-2026:2147",
                "https://access.redhat.com/errata/RHSA-2026:2148",
                "https://access.redhat.com/errata/RHSA-2026:2149",
                "https://access.redhat.com/errata/RHSA-2026:21658",
                "https://access.redhat.com/errata/RHSA-2026:24331",
                "https://access.redhat.com/errata/RHSA-2026:2438",
                "https://access.redhat.com/errata/RHSA-2026:2452",
                "https://access.redhat.com/errata/RHSA-2026:2462",
                "https://access.redhat.com/errata/RHSA-2026:2465",
                "https://access.redhat.com/errata/RHSA-2026:2469",
                "https://access.redhat.com/errata/RHSA-2026:2484",
                "https://access.redhat.com/errata/RHSA-2026:25089",
                "https://access.redhat.com/errata/RHSA-2026:2651",
                "https://access.redhat.com/errata/RHSA-2026:2661",
                "https://access.redhat.com/errata/RHSA-2026:2672",
                "https://access.redhat.com/errata/RHSA-2026:2675",
                "https://access.redhat.com/errata/RHSA-2026:2694",
                "https://access.redhat.com/errata/RHSA-2026:2816",
                "https://access.redhat.com/errata/RHSA-2026:2817",
                "https://access.redhat.com/errata/RHSA-2026:2818",
                "https://access.redhat.com/errata/RHSA-2026:2819",
                "https://access.redhat.com/errata/RHSA-2026:2900",
                "https://access.redhat.com/errata/RHSA-2026:2926",
                "https://access.redhat.com/errata/RHSA-2026:2984",
                "https://access.redhat.com/errata/RHSA-2026:2990",
                "https://access.redhat.com/errata/RHSA-2026:3087",
                "https://access.redhat.com/errata/RHSA-2026:33154",
                "https://access.redhat.com/errata/RHSA-2026:33371",
                "https://access.redhat.com/errata/RHSA-2026:34100",
                "https://access.redhat.com/errata/RHSA-2026:3422",
                "https://access.redhat.com/errata/RHSA-2026:34608",
                "https://access.redhat.com/errata/RHSA-2026:36651",
                "https://access.redhat.com/errata/RHSA-2026:36882",
                "https://access.redhat.com/errata/RHSA-2026:3710",
                "https://access.redhat.com/errata/RHSA-2026:3782",
                "https://access.redhat.com/errata/RHSA-2026:3825",
                "https://access.redhat.com/errata/RHSA-2026:3869",
                "https://access.redhat.com/errata/RHSA-2026:3870",
                "https://access.redhat.com/errata/RHSA-2026:3874",
                "https://access.redhat.com/errata/RHSA-2026:3884",
                "https://access.redhat.com/errata/RHSA-2026:3958",
                "https://access.redhat.com/errata/RHSA-2026:3960",
                "https://access.redhat.com/errata/RHSA-2026:3962",
                "https://access.redhat.com/errata/RHSA-2026:40118",
                "https://access.redhat.com/errata/RHSA-2026:40945",
                "https://access.redhat.com/errata/RHSA-2026:40984",
                "https://access.redhat.com/errata/RHSA-2026:41064",
                "https://access.redhat.com/errata/RHSA-2026:41928",
                "https://access.redhat.com/errata/RHSA-2026:41941",
                "https://access.redhat.com/errata/RHSA-2026:41944",
                "https://access.redhat.com/errata/RHSA-2026:4423",
                "https://access.redhat.com/errata/RHSA-2026:4466",
                "https://access.redhat.com/errata/RHSA-2026:4467",
                "https://access.redhat.com/errata/RHSA-2026:4630",
                "https://access.redhat.com/errata/RHSA-2026:4782",
                "https://access.redhat.com/errata/RHSA-2026:5633",
                "https://access.redhat.com/errata/RHSA-2026:5636",
                "https://access.redhat.com/errata/RHSA-2026:57487",
                "https://access.redhat.com/errata/RHSA-2026:6192",
                "https://access.redhat.com/errata/RHSA-2026:6288",
                "https://access.redhat.com/errata/RHSA-2026:6497",
                "https://access.redhat.com/errata/RHSA-2026:6567",
                "https://access.redhat.com/errata/RHSA-2026:8218",
                "https://access.redhat.com/errata/RHSA-2026:8229",
                "https://access.redhat.com/errata/RHSA-2026:9848",
                "https://access.redhat.com/security/cve/CVE-2025-13465",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2431740",
                "https://cert-portal.siemens.com/productcert/html/ssa-253495.html",
                "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13465.json"
            ],
            "timeline": [
                {
                    "at": "2026-01-21T20:16:05.250",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13465"
                }
            ]
        },
        {
            "id": "CVE-2025-13146",
            "vendor": "sevenspark",
            "product": "DTX – Dynamic Text Extension for Contact Form 7",
            "title": "DTX – Dynamic Text Extension for Contact Form 7 vulnerability",
            "summary": "The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The vulnerability was partially patched in version 5.0.4.",
            "updated_at": "2026-09-14T23:17:14.463",
            "published_at": "2026-07-22T12:16:54.763",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 5.0.7 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The vulnerability was partially patched in version 5.0.4.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/trunk/contact-form-7-dynamic-text-extension.php#L765",
                "https://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/trunk/contact-form-7-dynamic-text-extension.php#L782",
                "https://plugins.trac.wordpress.org/browser/contact-form-7-dynamic-text-extension/trunk/includes/utilities.php#L265",
                "https://plugins.trac.wordpress.org/changeset/3430784/",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/3e5ad3a7-03c5-4085-b330-bc77e7e46cea?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-07-22T12:16:54.763",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13146"
                }
            ]
        },
        {
            "id": "CVE-2025-13034",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool, curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.",
            "updated_at": "2026-09-15T07:16:23.550",
            "published_at": "2026-01-08T10:15:45.407",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.8.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.18.0 (semver); 3210101088dfa3d6a125d213226b092f2f866722 through before 3d91ca8cdb3b434226e743946d428b4dd3acf2c9 (git); 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-295",
            "what_happened": "When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool, curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://curl.se/docs/CVE-2025-13034.html",
                "https://curl.se/docs/CVE-2025-13034.json"
            ],
            "timeline": [
                {
                    "at": "2026-01-08T10:15:45.407",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-13034"
                }
            ]
        },
        {
            "id": "CVE-2025-12821",
            "vendor": "spicethemes",
            "product": "NewsBlogger",
            "title": "NewsBlogger vulnerability",
            "summary": "The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6  to 0.2.5.9. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This is due to a reverted fix of CVE-2025-1305.",
            "updated_at": "2026-09-14T23:17:14.290",
            "published_at": "2026-02-19T07:17:28.770",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0.2.5.6 through 0.2.5.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-352",
            "what_happened": "The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6  to 0.2.5.9. This is due to missing or incorrect nonce validation on the newsblogger_install_and_activate_plugin() function. This makes it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This is due to a reverted fix of CVE-2025-1305.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://themes.trac.wordpress.org/browser/newsblogger/0.2.5.8/functions.php#L499",
                "https://themes.trac.wordpress.org/changeset?old=302341&old_path=%2Fnewsblogger%2F0.2.5.9%2Ffunctions.php&new=304663&new_path=%2Fnewsblogger%2F0.2.6%2Ffunctions.php",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/9f33096a-dfd5-48c1-84d8-30a0faa2a7f5?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-02-19T07:17:28.770",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-12821"
                }
            ]
        },
        {
            "id": "CVE-2025-12543",
            "vendor": "Red Hat",
            "product": "Red Hat build of Apache Camel 4.14.4 for Spring Boot 3.5.11",
            "title": "Red Hat build of Apache Camel 4.14.4 for Spring Boot 3.5.11 vulnerability",
            "summary": "A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.",
            "updated_at": "2026-09-07T13:17:24.093",
            "published_at": "2026-01-07T17:15:55.093",
            "cvss": 9.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.14.4; 8.0 through before 8.0.12; 8.1.0 through before 8.1.3; before 2.2.39; 2.3.0 through before 2.3.21",
            "fixed": "See vendor advisory",
            "source_count": 31,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:0383",
                "https://access.redhat.com/errata/RHSA-2026:0384",
                "https://access.redhat.com/errata/RHSA-2026:0386",
                "https://access.redhat.com/errata/RHSA-2026:33371",
                "https://access.redhat.com/errata/RHSA-2026:33372",
                "https://access.redhat.com/errata/RHSA-2026:3889",
                "https://access.redhat.com/errata/RHSA-2026:3890",
                "https://access.redhat.com/errata/RHSA-2026:3891",
                "https://access.redhat.com/errata/RHSA-2026:3892",
                "https://access.redhat.com/errata/RHSA-2026:4915",
                "https://access.redhat.com/errata/RHSA-2026:4916",
                "https://access.redhat.com/errata/RHSA-2026:4917",
                "https://access.redhat.com/errata/RHSA-2026:4924",
                "https://access.redhat.com/security/cve/CVE-2025-12543",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2408784",
                "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-12543.json"
            ],
            "timeline": [
                {
                    "at": "2026-01-07T17:15:55.093",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-12543"
                }
            ]
        },
        {
            "id": "CVE-2025-12449",
            "vendor": "kodezen",
            "product": "aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder",
            "title": "aBlocks – Gutenberg Blocks, User Dashboard Builder, Popup Builder, Form Builder & Animation Builder vulnerability",
            "summary": "The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and including, 2.4.0. This makes it possible for authenticated attackers, with subscriber level access and above, to read plugin settings including block visibility, maintenance mode configuration, and third-party email marketing API keys, as well as read sensitive configuration data including API keys for email marketing services.",
            "updated_at": "2026-09-15T16:17:07.203",
            "published_at": "2026-01-07T12:16:46.710",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2.4.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and including, 2.4.0. This makes it possible for authenticated attackers, with subscriber level access and above, to read plugin settings including block visibility, maintenance mode configuration, and third-party email marketing API keys, as well as read sensitive configuration data including API keys for email marketing services.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/ablocks/tags/2.4.0/includes/ajax/settings.php#L16",
                "https://plugins.trac.wordpress.org/browser/ablocks/tags/2.4.0/includes/assets.php#L353",
                "https://plugins.trac.wordpress.org/browser/ablocks/tags/2.4.0/includes/classes/abstract-request-handler.php#L486",
                "https://plugins.trac.wordpress.org/changeset?old_path=/ablocks/trunk/includes/classes/abstract-request-handler.php&old=3269886&new_path=/ablocks/trunk/includes/classes/abstract-request-handler.php&new=3401920",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/c10600ae-1ff0-4f12-ae53-39d9342640f4?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-01-07T12:16:46.710",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-12449"
                }
            ]
        },
        {
            "id": "CVE-2025-11003",
            "vendor": "admintwentytwenty",
            "product": "UiPress lite | Effortless custom dashboards, admin themes and pages",
            "title": "UiPress lite | Effortless custom dashboards, admin themes and pages vulnerability",
            "summary": "The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_ui_template' function in all versions up to, and including, 3.5.09. This makes it possible for authenticated attackers, with Subscriber-level access and above, to save templates that contain custom JavaScript.",
            "updated_at": "2026-09-14T20:16:37.493",
            "published_at": "2025-11-21T08:15:48.400",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.5.09 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_ui_template' function in all versions up to, and including, 3.5.09. This makes it possible for authenticated attackers, with Subscriber-level access and above, to save templates that contain custom JavaScript.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/uipress-lite/tags/3.5.08/admin/classes/PostTypes/UiTemplates.php#L416",
                "https://plugins.trac.wordpress.org/browser/uipress-lite/tags/3.5.08/admin/core/uiBuilder.php#L613",
                "https://plugins.trac.wordpress.org/changeset/3654103/",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/b2a01ccc-c98e-4fcc-8eaf-721ec46584fc?source=cve"
            ],
            "timeline": [
                {
                    "at": "2025-11-21T08:15:48.400",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-11003"
                }
            ]
        },
        {
            "id": "CVE-2025-10966",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "curl's code for managing SSH connections when SFTP was done using the wolfSSH\npowered backend was flawed and missed host verification mechanisms.\n\nThis prevents curl from detecting MITM attackers and more.",
            "updated_at": "2026-09-15T07:16:23.317",
            "published_at": "2025-11-07T08:15:39.617",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "7.69.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 6773c7ca65cf2183295e56603f9b86a5ce816a06 through before b011e3fcfb06d6c0278595ee2ee297036fbe9793 (git); 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; before V4.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 11,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-322",
            "what_happened": "curl's code for managing SSH connections when SFTP was done using the wolfSSH\npowered backend was flawed and missed host verification mechanisms.\n\nThis prevents curl from detecting MITM attackers and more.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2025-11-07",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3355218"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2025-10966.html",
                "https://curl.se/docs/CVE-2025-10966.json",
                "https://hackerone.com/reports/3355218",
                "http://www.openwall.com/lists/oss-security/2025/11/05/2",
                "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
            ],
            "timeline": [
                {
                    "at": "2025-11-07T08:15:39.617",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-10966"
                }
            ]
        },
        {
            "id": "CVE-2025-10938",
            "vendor": "admintwentytwenty",
            "product": "UiPress lite | Effortless custom dashboards, admin themes and pages",
            "title": "UiPress lite | Effortless custom dashboards, admin themes and pages vulnerability",
            "summary": "The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user data including password hashes, emails, and other user information that could be used for account takeover attacks.",
            "updated_at": "2026-09-14T20:16:37.167",
            "published_at": "2025-11-21T08:15:48.083",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 3.5.09 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user data including password hashes, emails, and other user information that could be used for account takeover attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/changeset/3654103/",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/d8aa06eb-774a-4cd9-bd35-2d6409475696?source=cve"
            ],
            "timeline": [
                {
                    "at": "2025-11-21T08:15:48.083",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-10938"
                }
            ]
        },
        {
            "id": "CVE-2025-10148",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "curl's WebSocket code did not update the 32-bit mask pattern for each new\noutgoing frame as the specification says. Instead it used a fixed mask that\npersisted and was used throughout the entire connection.\n\nA predictable mask pattern allows for a malicious server to induce traffic\nbetween the two communicating parties that could be interpreted by an involved\nproxy (configured or transparent) as genuine, real, HTTP traffic with content\nand thereby poison its cache. That cached poisoned content could then be\nserved to all users of that proxy.",
            "updated_at": "2026-09-15T07:16:21.967",
            "published_at": "2025-09-12T06:15:40.020",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "8.11.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.0 (semver); d78e129d50b2d190f1c1bde2ad1f62f02f152db0 through before 84db7a9eae8468c0445b15aa806fa7fa806fa0f2 (git); 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-340",
            "what_happened": "curl's WebSocket code did not update the 32-bit mask pattern for each new\noutgoing frame as the specification says. Instead it used a fixed mask that\npersisted and was used throughout the entire connection.\n\nA predictable mask pattern allows for a malicious server to induce traffic\nbetween the two communicating parties that could be interpreted by an involved\nproxy (configured or transparent) as genuine, real, HTTP traffic with content\nand thereby poison its cache. That cached poisoned content could then be\nserved to all users of that proxy.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://curl.se/docs/CVE-2025-10148.html",
                "https://curl.se/docs/CVE-2025-10148.json",
                "https://hackerone.com/reports/3330839",
                "http://www.openwall.com/lists/oss-security/2025/09/10/2",
                "http://www.openwall.com/lists/oss-security/2025/09/10/3",
                "http://www.openwall.com/lists/oss-security/2025/09/10/4"
            ],
            "timeline": [
                {
                    "at": "2025-09-12T06:15:40.020",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-10148"
                }
            ]
        },
        {
            "id": "CVE-2025-10012",
            "vendor": "Portabilis",
            "product": "i-Educar",
            "title": "i-Educar vulnerability",
            "summary": "A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file educar_historico_escolar_lst.php. Such manipulation of the argument ref_cod_aluno leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.12 is sufficient to resolve this issue. It is advisable to upgrade the affected component. The vendor confirms, that \"[t]he reported attack vector was tested against the corrected code, and the previously described SQL Injection behavior could no longer be reproduced\".",
            "updated_at": "2026-09-15T09:16:43.287",
            "published_at": "2025-09-05T15:15:32.603",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "2.0; 2.1; 2.2; 2.3; 2.4; 2.5; 2.6; 2.7; 2.8; 2.9; 2.10",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file educar_historico_escolar_lst.php. Such manipulation of the argument ref_cod_aluno leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.12 is sufficient to resolve this issue. It is advisable to upgrade the affected component. The vendor confirms, that \"[t]he reported attack vector was tested against the corrected code, and the previously described SQL Injection behavior could no longer be reproduced\".",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2025-09-05",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-10012.md"
                }
            ],
            "references": [
                "https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-10012.md",
                "https://github.com/marcelomulder/CVE/blob/main/i-educar/SQL%20Injection%20(Blind%20Time-Based)%20Vulnerability%20in%20ref_cod_aluno%20Parameter%20on%20educar_historico_escolar_lst.php%20Endpoint.md",
                "https://github.com/portabilis/i-educar/tree/2.12",
                "https://vuldb.com/cve/CVE-2025-10012",
                "https://vuldb.com/submit/643549",
                "https://vuldb.com/vuln/322737",
                "https://vuldb.com/vuln/322737/cti"
            ],
            "timeline": [
                {
                    "at": "2025-09-05T15:15:32.603",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-10012"
                }
            ]
        },
        {
            "id": "CVE-2025-9606",
            "vendor": "Portabilis",
            "product": "i-Educar",
            "title": "i-Educar vulnerability",
            "summary": "A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_preferencias.php. Performing a manipulation of the argument cod_agenda results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.12 addresses this issue. Upgrading the affected component is advised. The vendor confirms: \"The reported attack vector was tested against the corrected code, and the previously described SQL Injection behavior could no longer be reproduced.\"",
            "updated_at": "2026-09-15T14:16:46.373",
            "published_at": "2025-08-29T03:15:40.403",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "2.0; 2.1; 2.2; 2.3; 2.4; 2.5; 2.6; 2.7; 2.8; 2.9; 2.10",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_preferencias.php. Performing a manipulation of the argument cod_agenda results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.12 addresses this issue. Upgrading the affected component is advised. The vendor confirms: \"The reported attack vector was tested against the corrected code, and the previously described SQL Injection behavior could no longer be reproduced.\"",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2025-08-29",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9606.md"
                }
            ],
            "references": [
                "https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9606.md",
                "https://github.com/marcelomulder/CVE/blob/main/i-educar/SQL%20Injection%20(Blind%20Time-Based)%20Vulnerability%20in%20cod_agenda%20Parameter%20on%20agenda_preferencias.php%20Endpoint.md#poc",
                "https://github.com/portabilis/i-educar/tree/2.12",
                "https://vuldb.com/cve/CVE-2025-9606",
                "https://vuldb.com/submit/636577",
                "https://vuldb.com/vuln/321784",
                "https://vuldb.com/vuln/321784/cti",
                "https://vuldb.com/?submit.636577"
            ],
            "timeline": [
                {
                    "at": "2025-08-29T03:15:40.403",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-9606"
                }
            ]
        },
        {
            "id": "CVE-2025-9566",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file.\n\nBinary-Affected: podman\nUpstream-version-introduced: v4.0.0\nUpstream-version-fixed: v5.6.1",
            "updated_at": "2026-09-10T10:17:29.233",
            "published_at": "2025-09-05T20:15:36.727",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 5.6.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 33,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file.\n\nBinary-Affected: podman\nUpstream-version-introduced: v4.0.0\nUpstream-version-fixed: v5.6.1",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHBA-2025:15692",
                "https://access.redhat.com/errata/RHBA-2025:15712",
                "https://access.redhat.com/errata/RHBA-2025:16158",
                "https://access.redhat.com/errata/RHBA-2025:16163",
                "https://access.redhat.com/errata/RHEA-2025:4782",
                "https://access.redhat.com/errata/RHSA-2025:15900",
                "https://access.redhat.com/errata/RHSA-2025:15901",
                "https://access.redhat.com/errata/RHSA-2025:15904",
                "https://access.redhat.com/errata/RHSA-2025:16480",
                "https://access.redhat.com/errata/RHSA-2025:16481",
                "https://access.redhat.com/errata/RHSA-2025:16482",
                "https://access.redhat.com/errata/RHSA-2025:16488",
                "https://access.redhat.com/errata/RHSA-2025:16515",
                "https://access.redhat.com/errata/RHSA-2025:16724",
                "https://access.redhat.com/errata/RHSA-2025:17669",
                "https://access.redhat.com/errata/RHSA-2025:18217",
                "https://access.redhat.com/errata/RHSA-2025:18218",
                "https://access.redhat.com/errata/RHSA-2025:18240",
                "https://access.redhat.com/errata/RHSA-2025:19002",
                "https://access.redhat.com/errata/RHSA-2025:19041",
                "https://access.redhat.com/errata/RHSA-2025:19046",
                "https://access.redhat.com/errata/RHSA-2025:19094",
                "https://access.redhat.com/errata/RHSA-2025:19894",
                "https://access.redhat.com/errata/RHSA-2025:20909",
                "https://access.redhat.com/errata/RHSA-2025:20983",
                "https://access.redhat.com/errata/RHSA-2026:18289",
                "https://access.redhat.com/errata/RHSA-2026:18722",
                "https://access.redhat.com/errata/RHSA-2026:62549",
                "https://access.redhat.com/errata/RHSA-2026:8211",
                "https://access.redhat.com/security/cve/CVE-2025-9566",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2393152",
                "https://github.com/containers/podman/commit/43fbde4e665fe6cee6921868f04b7ccd3de5ad89",
                "https://github.com/containers/podman/security/advisories/GHSA-wp3j-xq48-xpjw"
            ],
            "timeline": [
                {
                    "at": "2025-09-05T20:15:36.727",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-9566"
                }
            ]
        },
        {
            "id": "CVE-2025-9531",
            "vendor": "Portabilis",
            "product": "i-Educar",
            "title": "i-Educar vulnerability",
            "summary": "A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/agenda.php of the component Agenda Module. Performing a manipulation of the argument cod_agenda results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 2.12 mitigates this issue. It is suggested to upgrade the affected component. The vendor confirms: \"The reported attack vector was tested against the corrected code, and the previously described SQL Injection behavior could no longer be reproduced.\"",
            "updated_at": "2026-09-15T14:16:45.230",
            "published_at": "2025-08-27T14:15:56.570",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "2.0; 2.1; 2.2; 2.3; 2.4; 2.5; 2.6; 2.7; 2.8; 2.9; 2.10",
            "fixed": "See vendor advisory",
            "source_count": 16,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/agenda.php of the component Agenda Module. Performing a manipulation of the argument cod_agenda results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 2.12 mitigates this issue. It is suggested to upgrade the affected component. The vendor confirms: \"The reported attack vector was tested against the corrected code, and the previously described SQL Injection behavior could no longer be reproduced.\"",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "karinagante.github.io",
                    "author": "NVD reference",
                    "first_seen": "2025-08-27",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://karinagante.github.io/cve-2025-9531/"
                },
                {
                    "repository": "karinagante.github.io",
                    "author": "NVD reference",
                    "first_seen": "2025-08-27",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://karinagante.github.io/cve-2025-9531/#proof-of-concept-poc"
                }
            ],
            "references": [
                "https://github.com/portabilis/i-educar/tree/2.12",
                "https://karinagante.github.io/cve-2025-9531/",
                "https://karinagante.github.io/cve-2025-9531/#proof-of-concept-poc",
                "https://vuldb.com/cve/CVE-2025-9531",
                "https://vuldb.com/submit/635752",
                "https://vuldb.com/submit/748849",
                "https://vuldb.com/vuln/321550",
                "https://vuldb.com/vuln/321550/cti"
            ],
            "timeline": [
                {
                    "at": "2025-08-27T14:15:56.570",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-9531"
                }
            ]
        },
        {
            "id": "CVE-2025-9467",
            "vendor": "vaadin",
            "product": "vaadin",
            "title": "vaadin vulnerability",
            "summary": "When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. \n\n\nUsers of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:\n\nProduct version\nVaadin 7.0.0 - 7.7.47\nVaadin 8.0.0 - 8.28.1\nVaadin 14.0.0 - 14.13.0\nVaadin 23.0.0 - 23.6.1\nVaadin 24.0.0 - 24.7.6\n\nMitigation\nUpgrade to 7.7.48\nUpgrade to 8.28.2\nUpgrade to 14.13.1\nUpgrade to 23.6.2\nUpgrade to 24.7.7 or newer\n\nPlease note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 14, 23, 24 version.\n\nArtifacts     Maven coordinatesVulnerable versionsFixed versioncom.vaadin:vaadin-server\n7.0.0 - 7.7.47\n≥7.7.48\ncom.vaadin:vaadin-server\n8.0.0 - 8.28.1\n≥8.28.2\ncom.vaadin:vaadin\n14.0.0 - 14.13.0\n≥14.13.1\ncom.vaadin:vaadin23.0.0 - 23.6.1\n≥23.6.2\ncom.vaadin:vaadin24.0.0 - 24.7.6\n≥24.7.7com.vaadin:vaadin-upload-flow\n2.0.0 - 14.13.0\n≥14.13.1\ncom.vaadin:vaadin-upload-flow\n23.0.0 - 23.6.1\n≥23.6.2\ncom.vaadin:vaadin-upload-flow\n24.0.0 - 24.7.6\n≥24.7.7",
            "updated_at": "2026-09-14T14:17:07.200",
            "published_at": "2025-09-04T10:42:34.793",
            "cvss": 5.3,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:D/RE:L/U:Green",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.0.0 through 14.13.0 (maven); 23.0.0 through 23.6.1 (maven); 24.0.0 through 24.7.6 (maven); 7.0.0 through 7.7.47 (maven); 8.0.0 through 8.28.1 (maven); 2.0.0 through 14.13.0 (maven)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass the upload validation. \n\n\nUsers of affected versions should apply the following mitigation or upgrade. Releases that have fixed this issue include:\n\nProduct version\nVaadin 7.0.0 - 7.7.47\nVaadin 8.0.0 - 8.28.1\nVaadin 14.0.0 - 14.13.0\nVaadin 23.0.0 - 23.6.1\nVaadin 24.0.0 - 24.7.6\n\nMitigation\nUpgrade to 7.7.48\nUpgrade to 8.28.2\nUpgrade to 14.13.1\nUpgrade to 23.6.2\nUpgrade to 24.7.7 or newer\n\nPlease note that Vaadin versions 10-13 and 15-22 are no longer supported and you should update either to the latest 14, 23, 24 version.\n\nArtifacts     Maven coordinatesVulnerable versionsFixed versioncom.vaadin:vaadin-server\n7.0.0 - 7.7.47\n≥7.7.48\ncom.vaadin:vaadin-server\n8.0.0 - 8.28.1\n≥8.28.2\ncom.vaadin:vaadin\n14.0.0 - 14.13.0\n≥14.13.1\ncom.vaadin:vaadin23.0.0 - 23.6.1\n≥23.6.2\ncom.vaadin:vaadin24.0.0 - 24.7.6\n≥24.7.7com.vaadin:vaadin-upload-flow\n2.0.0 - 14.13.0\n≥14.13.1\ncom.vaadin:vaadin-upload-flow\n23.0.0 - 23.6.1\n≥23.6.2\ncom.vaadin:vaadin-upload-flow\n24.0.0 - 24.7.6\n≥24.7.7",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://vaadin.com/security/cve-2025-9467"
            ],
            "timeline": [
                {
                    "at": "2025-09-04T10:42:34.793",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-9467"
                }
            ]
        },
        {
            "id": "CVE-2025-9236",
            "vendor": "Portabilis",
            "product": "i-Educar",
            "title": "i-Educar vulnerability",
            "summary": "A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page. Such manipulation of the argument nm_tipo/descrição leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Upgrading to version 2.12 mitigates this issue. Upgrading the affected component is advised. The vendor confirms: \"The reported attack vector was tested against the corrected code, and the previously described SQL Injection behavior could no longer be reproduced.\"",
            "updated_at": "2026-09-15T16:17:07.910",
            "published_at": "2025-08-20T18:15:36.333",
            "cvss": 2.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "2.0; 2.1; 2.2; 2.3; 2.4; 2.5; 2.6; 2.7; 2.8; 2.9; 2.10",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-74",
            "what_happened": "A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page. Such manipulation of the argument nm_tipo/descrição leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Upgrading to version 2.12 mitigates this issue. Upgrading the affected component is advised. The vendor confirms: \"The reported attack vector was tested against the corrected code, and the previously described SQL Injection behavior could no longer be reproduced.\"",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2025-08-20",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9236.md"
                }
            ],
            "references": [
                "https://github.com/marcelomulder/CVE/blob/main/i-educar/CVE-2025-9236.md",
                "https://github.com/marcelomulder/CVE/blob/main/i-educar/SQL%20Injection%20(Blind%20Time-Based)%20Vulnerability%20in%20nm_tipo%20Parameter%20on%20educar_tipo_usuario_lst.php%20Endpoint.md#poc",
                "https://github.com/portabilis/i-educar/tree/2.12",
                "https://vuldb.com/cve/CVE-2025-9236",
                "https://vuldb.com/submit/631370",
                "https://vuldb.com/submit/638555",
                "https://vuldb.com/vuln/320769",
                "https://vuldb.com/vuln/320769/cti"
            ],
            "timeline": [
                {
                    "at": "2025-08-20T18:15:36.333",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-9236"
                }
            ]
        },
        {
            "id": "CVE-2025-9086",
            "vendor": "curl",
            "product": "curl",
            "title": "curl vulnerability",
            "summary": "1. A cookie is set using the `secure` keyword for `https://target`\n2. curl is redirected to or otherwise made to speak with `http://target` (same\n   hostname, but using clear text HTTP) using the same cookie set\n3. The same cookie name is set - but with only a slash as path (`path=\"/\"`).\n   Since this site is not secure, the cookie *should* be ignored.\n4. A bug in the path comparison logic makes curl read outside a heap buffer\n   boundary\n\nThe bug either causes a crash or it potentially makes the comparison come to\nthe wrong conclusion and lets the clear-text site override the contents of the\nsecure cookie, contrary to expectations and depending on the memory contents\nimmediately following the single-byte allocation that holds the path.\n\nThe presumed and correct behavior would be to plainly ignore the second set of\nthe cookie since it was already set as secure on a secure host so overriding\nit on an insecure host should not be okay.",
            "updated_at": "2026-09-14T21:16:59.523",
            "published_at": "2025-09-12T06:15:44.100",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.13.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.0 (semver); 1aea05a6c2699e80c75936d58569851555acd603 through before c6ae07c6a541e0e96d0040afb62b45dd37711300 (git); 8.15.0; 8.14.1; 8.14.0; 8.13.0; before V3.3 (custom); before V4.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "1. A cookie is set using the `secure` keyword for `https://target`\n2. curl is redirected to or otherwise made to speak with `http://target` (same\n   hostname, but using clear text HTTP) using the same cookie set\n3. The same cookie name is set - but with only a slash as path (`path=\"/\"`).\n   Since this site is not secure, the cookie *should* be ignored.\n4. A bug in the path comparison logic makes curl read outside a heap buffer\n   boundary\n\nThe bug either causes a crash or it potentially makes the comparison come to\nthe wrong conclusion and lets the clear-text site override the contents of the\nsecure cookie, contrary to expectations and depending on the memory contents\nimmediately following the single-byte allocation that holds the path.\n\nThe presumed and correct behavior would be to plainly ignore the second set of\nthe cookie since it was already set as secure on a secure host so overriding\nit on an insecure host should not be okay.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "hackerone.com",
                    "author": "NVD reference",
                    "first_seen": "2025-09-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://hackerone.com/reports/3294999"
                }
            ],
            "references": [
                "https://curl.se/docs/CVE-2025-9086.html",
                "https://curl.se/docs/CVE-2025-9086.json",
                "https://hackerone.com/reports/3294999",
                "http://www.openwall.com/lists/oss-security/2025/09/10/1",
                "https://lists.debian.org/debian-lts-announce/2026/01/msg00002.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-089022.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
            ],
            "timeline": [
                {
                    "at": "2025-09-12T06:15:44.100",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-9086"
                }
            ]
        },
        {
            "id": "CVE-2025-9049",
            "vendor": "scriptsbundle",
            "product": "Nokri – Job Board WordPress Theme",
            "title": "Nokri – Job Board WordPress Theme vulnerability",
            "summary": "The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add new Subscriber users with employer account member permissions, who in turn can escalate privileges by updating the email address of any user, including Administrator users.",
            "updated_at": "2026-09-05T12:16:46.653",
            "published_at": "2026-09-05T12:16:46.653",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.6.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-862",
            "what_happened": "The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add new Subscriber users with employer account member permissions, who in turn can escalate privileges by updating the email address of any user, including Administrator users.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://themeforest.net/item/nokri-job-board-wordpress-theme/22677241#item-description__nokri-theme-change-logs",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/e079e886-70a5-4188-ad99-96fc37651ed0?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:16:46.653",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-9049"
                }
            ]
        },
        {
            "id": "CVE-2025-8539",
            "vendor": "Portabilis",
            "product": "i-Educar",
            "title": "i-Educar vulnerability",
            "summary": "A weakness has been identified in Portabilis i-Educar 2.10. This affects an unknown function of the file /intranet/public_distrito_cad.php. This manipulation of the argument nome causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.12 mitigates this issue. It is recommended to upgrade the affected component. The vendor explains, that \"[t]he reported attack vector was tested against the corrected version, and the previously described XSS behavior could no longer be reproduced\".",
            "updated_at": "2026-09-15T03:17:05.247",
            "published_at": "2025-08-05T02:15:25.557",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "2.10",
            "fixed": "See vendor advisory",
            "source_count": 20,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A weakness has been identified in Portabilis i-Educar 2.10. This affects an unknown function of the file /intranet/public_distrito_cad.php. This manipulation of the argument nome causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.12 mitigates this issue. It is recommended to upgrade the affected component. The vendor explains, that \"[t]he reported attack vector was tested against the corrected version, and the previously described XSS behavior could no longer be reproduced\".",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "karinagante.github.io",
                    "author": "NVD reference",
                    "first_seen": "2025-08-05",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://karinagante.github.io/cve-2025-8539/"
                },
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2025-08-05",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/CVE-2025-8539.md"
                }
            ],
            "references": [
                "https://github.com/portabilis/i-educar/tree/2.12",
                "https://karinagante.github.io/cve-2025-8539/",
                "https://vuldb.com/cve/CVE-2025-8539",
                "https://vuldb.com/submit/620453",
                "https://vuldb.com/vuln/318668",
                "https://vuldb.com/vuln/318668/cti",
                "https://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/CVE-2025-8539.md",
                "https://vuldb.com/?submit.620453"
            ],
            "timeline": [
                {
                    "at": "2025-08-05T02:15:25.557",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-8539"
                }
            ]
        },
        {
            "id": "CVE-2025-8538",
            "vendor": "Portabilis",
            "product": "i-Educar",
            "title": "i-Educar vulnerability",
            "summary": "A security flaw has been discovered in Portabilis i-Educar 2.10. The impacted element is an unknown function of the file /usuarios/tipos/novo. The manipulation of the argument name/description results in cross site scripting. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.12 is sufficient to resolve this issue. Upgrading the affected component is recommended. The vendor explains, that \"[t]he reported attack vector was tested against the corrected version, and the previously described XSS behavior could no longer be reproduced\".",
            "updated_at": "2026-09-15T03:17:05.000",
            "published_at": "2025-08-05T01:15:43.567",
            "cvss": 1.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "2.10",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A security flaw has been discovered in Portabilis i-Educar 2.10. The impacted element is an unknown function of the file /usuarios/tipos/novo. The manipulation of the argument name/description results in cross site scripting. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 2.12 is sufficient to resolve this issue. Upgrading the affected component is recommended. The vendor explains, that \"[t]he reported attack vector was tested against the corrected version, and the previously described XSS behavior could no longer be reproduced\".",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "karinagante.github.io",
                    "author": "NVD reference",
                    "first_seen": "2025-08-05",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://karinagante.github.io/cve-2025-8538/"
                },
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2025-08-05",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/CVE-2025-8538.md"
                }
            ],
            "references": [
                "https://github.com/portabilis/i-educar/tree/2.12",
                "https://karinagante.github.io/cve-2025-8538/",
                "https://vuldb.com/cve/CVE-2025-8538",
                "https://vuldb.com/submit/620451",
                "https://vuldb.com/vuln/318667",
                "https://vuldb.com/vuln/318667/cti",
                "https://github.com/KarinaGante/KGSec/blob/main/CVEs/i-educar/CVE-2025-8538.md",
                "https://vuldb.com/?submit.620451"
            ],
            "timeline": [
                {
                    "at": "2025-08-05T01:15:43.567",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-8538"
                }
            ]
        },
        {
            "id": "CVE-2025-8517",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Session-Fixation-in-Vvveb-CMS-v1.0.6.1 exploit",
            "summary": "Exploit for CVE-2025-8517. CVSS 6.5.",
            "updated_at": "2026-09-07T19:20:43Z",
            "published_at": "2026-09-07T19:20:43Z",
            "cvss": 6.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 34,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-07T19:20:43+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Session-Fixation-in-Vvveb-CMS-v1.0.6.1 exploit",
                    "summary": "Exploit for CVE-2025-8517. CVSS 6.5.",
                    "cvss": 6.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HELLOANDREWPAUL-SESSION-FIXATION-IN-VVVEB-CMS-V1.0.6.1"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HELLOANDREWPAUL-SESSION-FIXATION-IN-VVVEB-CMS-V1.0.6.1"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:20:43Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HELLOANDREWPAUL-SESSION-FIXATION-IN-VVVEB-CMS-V1.0.6.1"
                }
            ]
        },
        {
            "id": "CVE-2025-7425",
            "vendor": "GNOME",
            "product": "libxml2",
            "title": "libxml2 vulnerability",
            "summary": "A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.",
            "updated_at": "2026-09-08T16:17:51.987",
            "published_at": "2025-07-10T14:15:27.877",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.15.2 (semver); before V2.17.1 (custom); before V5.0 (custom); V3.1.5 through before * (custom); before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 44,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the proper cleanup of ID attributes. As a result, the system may access freed memory, causing crashes or enabling attackers to trigger heap corruption.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHBA-2025:12345",
                "https://access.redhat.com/errata/RHSA-2025:12447",
                "https://access.redhat.com/errata/RHSA-2025:12450",
                "https://access.redhat.com/errata/RHSA-2025:13267",
                "https://access.redhat.com/errata/RHSA-2025:13308",
                "https://access.redhat.com/errata/RHSA-2025:13309",
                "https://access.redhat.com/errata/RHSA-2025:13310",
                "https://access.redhat.com/errata/RHSA-2025:13311",
                "https://access.redhat.com/errata/RHSA-2025:13312",
                "https://access.redhat.com/errata/RHSA-2025:13313",
                "https://access.redhat.com/errata/RHSA-2025:13314",
                "https://access.redhat.com/errata/RHSA-2025:13335",
                "https://access.redhat.com/errata/RHSA-2025:13464",
                "https://access.redhat.com/errata/RHSA-2025:13622",
                "https://access.redhat.com/errata/RHSA-2025:14059",
                "https://access.redhat.com/errata/RHSA-2025:14396",
                "https://access.redhat.com/errata/RHSA-2025:14818",
                "https://access.redhat.com/errata/RHSA-2025:14819",
                "https://access.redhat.com/errata/RHSA-2025:14853",
                "https://access.redhat.com/errata/RHSA-2025:14858",
                "https://access.redhat.com/errata/RHSA-2025:15308",
                "https://access.redhat.com/errata/RHSA-2025:15672",
                "https://access.redhat.com/errata/RHSA-2025:15827",
                "https://access.redhat.com/errata/RHSA-2025:15828",
                "https://access.redhat.com/errata/RHSA-2025:18219",
                "https://access.redhat.com/errata/RHSA-2025:21885",
                "https://access.redhat.com/errata/RHSA-2025:21913",
                "https://access.redhat.com/errata/RHSA-2026:0934",
                "https://access.redhat.com/errata/RHSA-2026:11503",
                "https://access.redhat.com/security/cve/CVE-2025-7425",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2379274",
                "https://gitlab.gnome.org/GNOME/libxslt/-/issues/140",
                "http://seclists.org/fulldisclosure/2025/Aug/0",
                "http://seclists.org/fulldisclosure/2025/Jul/30",
                "http://seclists.org/fulldisclosure/2025/Jul/32",
                "http://seclists.org/fulldisclosure/2025/Jul/35",
                "http://seclists.org/fulldisclosure/2025/Jul/37",
                "http://www.openwall.com/lists/oss-security/2025/07/11/2",
                "https://lists.debian.org/debian-lts-announce/2025/09/msg00035.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-265688.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-577017.html"
            ],
            "timeline": [
                {
                    "at": "2025-07-10T14:15:27.877",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-7425"
                }
            ]
        },
        {
            "id": "CVE-2025-7195",
            "vendor": "operator-framework",
            "product": "operator-sdk",
            "title": "operator-sdk vulnerability",
            "summary": "Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before 0.15.2 to scaffold their operator may still be impacted by this if the insecure user_setup script is still being used to build new container images. \n\nIn affected images, the /etc/passwd file is created during build time with group-writable permissions and a group ownership of root (gid=0). An attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.",
            "updated_at": "2026-09-08T13:17:15.633",
            "published_at": "2025-08-07T19:15:29.367",
            "cvss": 6.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.15.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 26,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-276",
            "what_happened": "Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before 0.15.2 to scaffold their operator may still be impacted by this if the insecure user_setup script is still being used to build new container images. \n\nIn affected images, the /etc/passwd file is created during build time with group-writable permissions and a group ownership of root (gid=0). An attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHEA-2025:23406",
                "https://access.redhat.com/errata/RHEA-2025:23478",
                "https://access.redhat.com/errata/RHEA-2026:0129",
                "https://access.redhat.com/errata/RHSA-2025:19332",
                "https://access.redhat.com/errata/RHSA-2025:19335",
                "https://access.redhat.com/errata/RHSA-2025:19958",
                "https://access.redhat.com/errata/RHSA-2025:19961",
                "https://access.redhat.com/errata/RHSA-2025:21368",
                "https://access.redhat.com/errata/RHSA-2025:21885",
                "https://access.redhat.com/errata/RHSA-2025:22415",
                "https://access.redhat.com/errata/RHSA-2025:22416",
                "https://access.redhat.com/errata/RHSA-2025:22418",
                "https://access.redhat.com/errata/RHSA-2025:22420",
                "https://access.redhat.com/errata/RHSA-2025:22683",
                "https://access.redhat.com/errata/RHSA-2025:22684",
                "https://access.redhat.com/errata/RHSA-2025:23528",
                "https://access.redhat.com/errata/RHSA-2025:23529",
                "https://access.redhat.com/errata/RHSA-2025:23542",
                "https://access.redhat.com/errata/RHSA-2026:0627",
                "https://access.redhat.com/errata/RHSA-2026:0718",
                "https://access.redhat.com/errata/RHSA-2026:0722",
                "https://access.redhat.com/errata/RHSA-2026:0737",
                "https://access.redhat.com/errata/RHSA-2026:2572",
                "https://access.redhat.com/errata/RHSA-2026:5633",
                "https://access.redhat.com/security/cve/CVE-2025-7195",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2376300"
            ],
            "timeline": [
                {
                    "at": "2025-08-07T19:15:29.367",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-7195"
                }
            ]
        },
        {
            "id": "CVE-2025-6220",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2025-6220 exploit",
            "summary": "Exploit for CVE-2025-6220. CVSS 7.2.",
            "updated_at": "2026-09-05T12:44:52Z",
            "published_at": "2026-09-05T12:44:52Z",
            "cvss": 7.2,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 89,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Arbitrary file upload in Ultimate Addons for Contact Form 7 <= 3.5.12 enabling code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-6220",
                    "summary": "Arbitrary file upload in Ultimate Addons for Contact Form 7 <= 3.5.12 enabling code execution.",
                    "what_happened": "Arbitrary file upload in Ultimate Addons for Contact Form 7 <= 3.5.12 enabling code execution.",
                    "cvss": 7.2,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D0N601-CVE-2025-6220",
                        "https://kitploit.com/ja/tools/github/d0n601/cve-2025-6220/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T14:18:22",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D0N601-CVE-2025-6220"
                },
                {
                    "title": "Exploit for CVE-2025-6220",
                    "summary": "Arbitrary file upload in Ultimate Addons for Contact Form 7 <= 3.5.12 enabling code execution.",
                    "what_happened": "Arbitrary file upload in Ultimate Addons for Contact Form 7 <= 3.5.12 enabling code execution.",
                    "cvss": 7.2,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D0N601-CVE-2025-6220",
                        "https://kitploit.com/ja/tools/github/d0n601/cve-2025-6220/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-04T14:18:22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/d0n601/cve-2025-6220/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D0N601-CVE-2025-6220",
                "https://kitploit.com/ja/tools/github/d0n601/cve-2025-6220/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:44:52Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D0N601-CVE-2025-6220"
                }
            ]
        },
        {
            "id": "CVE-2025-6020",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.",
            "updated_at": "2026-09-08T14:17:19.873",
            "published_at": "2025-06-17T13:15:21.660",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.7.1 (semver); before V2.17.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 32,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2025:10024",
                "https://access.redhat.com/errata/RHSA-2025:10027",
                "https://access.redhat.com/errata/RHSA-2025:10180",
                "https://access.redhat.com/errata/RHSA-2025:10354",
                "https://access.redhat.com/errata/RHSA-2025:10357",
                "https://access.redhat.com/errata/RHSA-2025:10358",
                "https://access.redhat.com/errata/RHSA-2025:10359",
                "https://access.redhat.com/errata/RHSA-2025:10361",
                "https://access.redhat.com/errata/RHSA-2025:10362",
                "https://access.redhat.com/errata/RHSA-2025:10735",
                "https://access.redhat.com/errata/RHSA-2025:10823",
                "https://access.redhat.com/errata/RHSA-2025:11386",
                "https://access.redhat.com/errata/RHSA-2025:11487",
                "https://access.redhat.com/errata/RHSA-2025:14557",
                "https://access.redhat.com/errata/RHSA-2025:15099",
                "https://access.redhat.com/errata/RHSA-2025:15709",
                "https://access.redhat.com/errata/RHSA-2025:15827",
                "https://access.redhat.com/errata/RHSA-2025:15828",
                "https://access.redhat.com/errata/RHSA-2025:16524",
                "https://access.redhat.com/errata/RHSA-2025:17181",
                "https://access.redhat.com/errata/RHSA-2025:18219",
                "https://access.redhat.com/errata/RHSA-2025:20181",
                "https://access.redhat.com/errata/RHSA-2025:21885",
                "https://access.redhat.com/errata/RHSA-2025:22019",
                "https://access.redhat.com/errata/RHSA-2025:9526",
                "https://access.redhat.com/errata/RHSA-2026:0934",
                "https://access.redhat.com/security/cve/CVE-2025-6020",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2372512",
                "https://github.com/linux-pam/linux-pam/security/advisories/GHSA-f9p8-gjr4-j9gx",
                "http://www.openwall.com/lists/oss-security/2025/06/17/1",
                "https://lists.debian.org/debian-lts-announce/2025/09/msg00021.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-577017.html"
            ],
            "timeline": [
                {
                    "at": "2025-06-17T13:15:21.660",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-6020"
                }
            ]
        },
        {
            "id": "CVE-2025-5914",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.",
            "updated_at": "2026-09-09T03:17:20.877",
            "published_at": "2025-06-09T20:15:26.123",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "before 3.8.0 (semver); before V7.26.0310 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 62,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a double-free vulnerability can result in memory corruption, enabling an attacker to execute arbitrary code or cause a denial-of-service condition.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2025-06-09",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/libarchive/libarchive/pull/2598"
                }
            ],
            "references": [
                "https://access.redhat.com/errata/RHSA-2025:14130",
                "https://access.redhat.com/errata/RHSA-2025:14135",
                "https://access.redhat.com/errata/RHSA-2025:14137",
                "https://access.redhat.com/errata/RHSA-2025:14141",
                "https://access.redhat.com/errata/RHSA-2025:14142",
                "https://access.redhat.com/errata/RHSA-2025:14525",
                "https://access.redhat.com/errata/RHSA-2025:14528",
                "https://access.redhat.com/errata/RHSA-2025:14594",
                "https://access.redhat.com/errata/RHSA-2025:14644",
                "https://access.redhat.com/errata/RHSA-2025:14808",
                "https://access.redhat.com/errata/RHSA-2025:14810",
                "https://access.redhat.com/errata/RHSA-2025:14828",
                "https://access.redhat.com/errata/RHSA-2025:15024",
                "https://access.redhat.com/errata/RHSA-2025:15397",
                "https://access.redhat.com/errata/RHSA-2025:15709",
                "https://access.redhat.com/errata/RHSA-2025:15827",
                "https://access.redhat.com/errata/RHSA-2025:15828",
                "https://access.redhat.com/errata/RHSA-2025:16524",
                "https://access.redhat.com/errata/RHSA-2025:18217",
                "https://access.redhat.com/errata/RHSA-2025:18218",
                "https://access.redhat.com/errata/RHSA-2025:18219",
                "https://access.redhat.com/errata/RHSA-2025:19041",
                "https://access.redhat.com/errata/RHSA-2025:19046",
                "https://access.redhat.com/errata/RHSA-2025:21885",
                "https://access.redhat.com/errata/RHSA-2025:21913",
                "https://access.redhat.com/errata/RHSA-2026:0326",
                "https://access.redhat.com/errata/RHSA-2026:0934",
                "https://access.redhat.com/errata/RHSA-2026:1541",
                "https://access.redhat.com/security/cve/CVE-2025-5914",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2370861",
                "https://github.com/libarchive/libarchive/pull/2598",
                "https://github.com/libarchive/libarchive/releases/tag/v3.8.0",
                "https://cert-portal.siemens.com/productcert/html/ssa-585531.html"
            ],
            "timeline": [
                {
                    "at": "2025-06-09T20:15:26.123",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5914"
                }
            ]
        },
        {
            "id": "CVE-2025-5777",
            "vendor": "Citrix",
            "product": "NetScaler ADC and Gateway",
            "title": "Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability",
            "summary": "Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.",
            "updated_at": "2026-09-03T21:14:58Z",
            "published_at": "2026-09-03T21:14:58Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 135,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52401",
                    "author": "Yesith Alvarez",
                    "first_seen": "2025-08-11",
                    "confidence": "High",
                    "title": "Citrix NetScaler ADC/Gateway 14.1 - Memory Disclosure",
                    "summary": "Citrix NetScaler ADC/Gateway 14.1 - Memory Disclosure",
                    "url": "https://www.exploit-db.com/exploits/52401",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2025-5777",
                    "summary": "Memory leak in Citrix NetScaler via doAuthentication endpoint exposes uninitialized memory.",
                    "what_happened": "Memory leak in Citrix NetScaler via doAuthentication endpoint exposes uninitialized memory.",
                    "cvss": 9.3,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:L/VI:H/SI:L/VA:H/SA:L",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XGH057R3C0N-CVE-2025-5777",
                        "https://kitploit.com/ko/tools/github/0xgh057r3c0n/cve-2025-5777/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T23:14:58",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XGH057R3C0N-CVE-2025-5777"
                },
                {
                    "title": "Exploit for CVE-2025-5777",
                    "summary": "Memory leak in Citrix NetScaler via doAuthentication endpoint exposes uninitialized memory.",
                    "what_happened": "Memory leak in Citrix NetScaler via doAuthentication endpoint exposes uninitialized memory.",
                    "cvss": 9.3,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:L/VI:H/SI:L/VA:H/SA:L",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XGH057R3C0N-CVE-2025-5777",
                        "https://kitploit.com/ko/tools/github/0xgh057r3c0n/cve-2025-5777/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ko",
                    "first_seen": "2026-09-03T23:14:58",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ko/tools/github/0xgh057r3c0n/cve-2025-5777/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52401",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XGH057R3C0N-CVE-2025-5777",
                "https://kitploit.com/ko/tools/github/0xgh057r3c0n/cve-2025-5777/"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T21:14:58Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-07-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:L/VI:H/SI:L/VA:H/SA:L"
        },
        {
            "id": "CVE-2025-5755",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2025-5777",
            "summary": "Memory leak in Citrix NetScaler via doAuthentication endpoint exposes uninitialized memory.",
            "updated_at": "2026-09-03T21:14:58Z",
            "published_at": "2026-09-03T21:14:58Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 55,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Memory leak in Citrix NetScaler via doAuthentication endpoint exposes uninitialized memory.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-5777",
                    "summary": "Memory leak in Citrix NetScaler via doAuthentication endpoint exposes uninitialized memory.",
                    "what_happened": "Memory leak in Citrix NetScaler via doAuthentication endpoint exposes uninitialized memory.",
                    "cvss": 9.3,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:L/VI:H/SI:L/VA:H/SA:L",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XGH057R3C0N-CVE-2025-5777",
                        "https://kitploit.com/ko/tools/github/0xgh057r3c0n/cve-2025-5777/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T23:14:58",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XGH057R3C0N-CVE-2025-5777"
                },
                {
                    "title": "Exploit for CVE-2025-5777",
                    "summary": "Memory leak in Citrix NetScaler via doAuthentication endpoint exposes uninitialized memory.",
                    "what_happened": "Memory leak in Citrix NetScaler via doAuthentication endpoint exposes uninitialized memory.",
                    "cvss": 9.3,
                    "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:L/VI:H/SI:L/VA:H/SA:L",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XGH057R3C0N-CVE-2025-5777",
                        "https://kitploit.com/ko/tools/github/0xgh057r3c0n/cve-2025-5777/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ko",
                    "first_seen": "2026-09-03T23:14:58",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ko/tools/github/0xgh057r3c0n/cve-2025-5777/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XGH057R3C0N-CVE-2025-5777",
                "https://kitploit.com/ko/tools/github/0xgh057r3c0n/cve-2025-5777/"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T21:14:58Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XGH057R3C0N-CVE-2025-5777"
                }
            ],
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/SC:L/VI:H/SI:L/VA:H/SA:L"
        },
        {
            "id": "CVE-2025-5318",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.",
            "updated_at": "2026-09-08T15:18:39.210",
            "published_at": "2025-06-24T14:15:30.523",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.11.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 30,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2025:18231",
                "https://access.redhat.com/errata/RHSA-2025:18275",
                "https://access.redhat.com/errata/RHSA-2025:18286",
                "https://access.redhat.com/errata/RHSA-2025:19012",
                "https://access.redhat.com/errata/RHSA-2025:19098",
                "https://access.redhat.com/errata/RHSA-2025:19101",
                "https://access.redhat.com/errata/RHSA-2025:19295",
                "https://access.redhat.com/errata/RHSA-2025:19300",
                "https://access.redhat.com/errata/RHSA-2025:19313",
                "https://access.redhat.com/errata/RHSA-2025:19400",
                "https://access.redhat.com/errata/RHSA-2025:19401",
                "https://access.redhat.com/errata/RHSA-2025:19470",
                "https://access.redhat.com/errata/RHSA-2025:19472",
                "https://access.redhat.com/errata/RHSA-2025:19807",
                "https://access.redhat.com/errata/RHSA-2025:19864",
                "https://access.redhat.com/errata/RHSA-2025:20943",
                "https://access.redhat.com/errata/RHSA-2025:21013",
                "https://access.redhat.com/errata/RHSA-2025:21329",
                "https://access.redhat.com/errata/RHSA-2025:21829",
                "https://access.redhat.com/errata/RHSA-2025:22275",
                "https://access.redhat.com/errata/RHSA-2025:23078",
                "https://access.redhat.com/errata/RHSA-2025:23079",
                "https://access.redhat.com/errata/RHSA-2025:23080",
                "https://access.redhat.com/errata/RHSA-2026:0326",
                "https://access.redhat.com/errata/RHSA-2026:1541",
                "https://access.redhat.com/errata/RHSA-2026:3461",
                "https://access.redhat.com/errata/RHSA-2026:3462",
                "https://access.redhat.com/security/cve/CVE-2025-5318",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2369131",
                "https://www.libssh.org/security/advisories/CVE-2025-5318.txt"
            ],
            "timeline": [
                {
                    "at": "2025-06-24T14:15:30.523",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5318"
                }
            ]
        },
        {
            "id": "CVE-2025-5278",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.",
            "updated_at": "2026-09-08T15:18:38.923",
            "published_at": "2025-05-27T21:15:23.197",
            "cvss": 4.4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.2 through before 9.8 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 20,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2026:28911",
                "https://access.redhat.com/errata/RHSA-2026:33124",
                "https://access.redhat.com/errata/RHSA-2026:33313",
                "https://access.redhat.com/errata/RHSA-2026:33612",
                "https://access.redhat.com/errata/RHSA-2026:34102",
                "https://access.redhat.com/errata/RHSA-2026:39981",
                "https://access.redhat.com/errata/RHSA-2026:44481",
                "https://access.redhat.com/errata/RHSA-2026:46836",
                "https://access.redhat.com/errata/RHSA-2026:50205",
                "https://access.redhat.com/errata/RHSA-2026:58981",
                "https://access.redhat.com/security/cve/CVE-2025-5278",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2368764",
                "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/commit/?id=8c9602e3a145e9596dc1a63c6ed67865814b6633",
                "https://debbugs.gnu.org/cgi/bugreport.cgi?bug=78507",
                "http://www.openwall.com/lists/oss-security/2025/05/27/2",
                "http://www.openwall.com/lists/oss-security/2025/05/29/1",
                "http://www.openwall.com/lists/oss-security/2025/05/29/2",
                "https://cgit.git.savannah.gnu.org/cgit/coreutils.git/tree/NEWS?id=8c9602e3a145e9596dc1a63c6ed67865814b6633#n14",
                "https://security-tracker.debian.org/tracker/CVE-2025-5278"
            ],
            "timeline": [
                {
                    "at": "2025-05-27T21:15:23.197",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5278"
                }
            ]
        },
        {
            "id": "CVE-2025-4871",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "PCMan 2.0.7 - Buffer Overflow",
            "summary": "PCMan 2.0.7 - Buffer Overflow",
            "updated_at": "2026-08-20T22:00:00Z",
            "published_at": "2026-08-20T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 187,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "PCMan 2.0.7 Buffer Overflow",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52657",
                    "author": "Thiago Cunha",
                    "first_seen": "2026-08-18",
                    "confidence": "High",
                    "title": "PCMan 2.0.7 - Buffer Overflow",
                    "summary": "PCMan 2.0.7 - Buffer Overflow",
                    "url": "https://www.exploit-db.com/exploits/52657",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "CXSecurity WLB-2026080010",
                    "author": "Thiago Cunha",
                    "first_seen": "2026-08-21",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "PCMan 2.0.7 Buffer Overflow",
                    "summary": "PCMan 2.0.7 Buffer Overflow",
                    "what_happened": "PCMan 2.0.7 Buffer Overflow",
                    "cvss": 0,
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "url": "https://cxsecurity.com/issue/WLB-2026080010",
                    "cwe": "Unknown"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52657",
                "https://cxsecurity.com/issue/WLB-2026080010"
            ],
            "timeline": [
                {
                    "at": "2026-08-20T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52657"
                }
            ]
        },
        {
            "id": "CVE-2025-4403",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2025-4403",
            "summary": "Unauthenticated file upload in Drag and Drop Multiple File Upload for WooCommerce up to 1.1.6.",
            "updated_at": "2026-09-04T03:55:22Z",
            "published_at": "2026-09-04T03:55:22Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 79,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "Unauthenticated file upload in Drag and Drop Multiple File Upload for WooCommerce up to 1.1.6.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-4403",
                    "summary": "Unauthenticated file upload in Drag and Drop Multiple File Upload for WooCommerce up to 1.1.6.",
                    "what_happened": "Unauthenticated file upload in Drag and Drop Multiple File Upload for WooCommerce up to 1.1.6.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YUCAERIN-CVE-2025-4403",
                        "https://kitploit.com/ru/tools/github/yucaerin/cve-2025-4403/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T05:55:22",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YUCAERIN-CVE-2025-4403"
                },
                {
                    "title": "Exploit for CVE-2025-4403",
                    "summary": "Unauthenticated file upload in Drag and Drop Multiple File Upload for WooCommerce up to 1.1.6.",
                    "what_happened": "Unauthenticated file upload in Drag and Drop Multiple File Upload for WooCommerce up to 1.1.6.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YUCAERIN-CVE-2025-4403",
                        "https://kitploit.com/ru/tools/github/yucaerin/cve-2025-4403/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T05:55:22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/yucaerin/cve-2025-4403/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YUCAERIN-CVE-2025-4403",
                "https://kitploit.com/ru/tools/github/yucaerin/cve-2025-4403/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T03:55:22Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YUCAERIN-CVE-2025-4403"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-4373",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 10",
            "title": "Red Hat Enterprise Linux 10 vulnerability",
            "summary": "A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.",
            "updated_at": "2026-09-07T21:17:27.187",
            "published_at": "2025-05-06T15:16:05.320",
            "cvss": 4.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2.84.2 (semver); before V3.3 (custom); V3.1.5 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-124",
            "what_happened": "A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2025:10855",
                "https://access.redhat.com/errata/RHSA-2025:11140",
                "https://access.redhat.com/errata/RHSA-2025:11327",
                "https://access.redhat.com/errata/RHSA-2025:11373",
                "https://access.redhat.com/errata/RHSA-2025:11374",
                "https://access.redhat.com/errata/RHSA-2025:11662",
                "https://access.redhat.com/errata/RHSA-2025:12275",
                "https://access.redhat.com/errata/RHSA-2025:13335",
                "https://access.redhat.com/errata/RHSA-2025:14988",
                "https://access.redhat.com/errata/RHSA-2025:14989",
                "https://access.redhat.com/errata/RHSA-2025:14990",
                "https://access.redhat.com/errata/RHSA-2025:14991",
                "https://access.redhat.com/security/cve/CVE-2025-4373",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2364265",
                "https://gitlab.gnome.org/GNOME/glib/-/issues/3677",
                "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-089022.html"
            ],
            "timeline": [
                {
                    "at": "2025-05-06T15:16:05.320",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4373"
                }
            ]
        },
        {
            "id": "CVE-2025-3850",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Out-of-bounds Read in Linux Linux_Kernel CVE-2025-3850 CVE-2025-38502",
            "summary": "Out-of-bounds read in Linux kernel BPF cgroup storage via tail calls enabling privilege escalation.",
            "updated_at": "2026-09-11T17:12:46Z",
            "published_at": "2026-09-11T17:12:46Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 42,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-125",
            "what_happened": "Out-of-bounds read in Linux kernel BPF cgroup storage via tail calls enabling privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-11T18:56:40+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Exploit for Out-of-bounds Read in Linux Linux_Kernel",
                    "summary": "Proof-of-concept exploit for CVE-2025-3850 and CVE-2025-38502. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=8FF551F8-DFC3-5F10-95CB-6ECABBDF76C7"
                },
                {
                    "title": "Exploit for Out-of-bounds Read in Linux Linux_Kernel CVE-2025-3850 CVE-2025-38502",
                    "summary": "Out-of-bounds read in Linux kernel BPF cgroup storage via tail calls enabling privilege escalation.",
                    "what_happened": "Out-of-bounds read in Linux kernel BPF cgroup storage via tail calls enabling privilege escalation.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "CWE-125",
                    "references": [
                        "https://sploitus.com/exploit?id=8FF551F8-DFC3-5F10-95CB-6ECABBDF76C7",
                        "https://github.com/abraxas/CVE-2025-38502-Linux-LPE"
                    ],
                    "repository": "abraxas/CVE-2025-38502-Linux-LPE",
                    "author": "abraxas",
                    "first_seen": "2026-09-11T19:12:46",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/abraxas/CVE-2025-38502-Linux-LPE"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=8FF551F8-DFC3-5F10-95CB-6ECABBDF76C7",
                "https://github.com/abraxas/CVE-2025-38502-Linux-LPE"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T17:12:46Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=8FF551F8-DFC3-5F10-95CB-6ECABBDF76C7"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-3248",
            "vendor": "Langflow",
            "product": "Langflow",
            "title": "Langflow Missing Authentication Vulnerability",
            "summary": "Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.",
            "updated_at": "2026-09-08T22:00:00Z",
            "published_at": "2026-09-08T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 725,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52262",
                    "author": "VeryLazyTech",
                    "first_seen": "2025-04-18",
                    "confidence": "High",
                    "title": "Langflow 1.3.0 -  Remote Code Execution (RCE)",
                    "summary": "Langflow 1.3.0 -  Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/52262",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 52364",
                    "author": "Raghad Abdallah Al-syouf",
                    "first_seen": "2025-07-16",
                    "confidence": "High",
                    "title": "Langflow 1.2.x - Remote Code Execution (RCE)",
                    "summary": "Langflow 1.2.x - Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/52364",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · xuemian168/CVE-2025-3248",
                    "author": "xuemian168",
                    "first_seen": "2025-04-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "A vulnerability scanner for CVE-2025-3248 in Langflow applications. 用于扫描 Langflow 应用中 CVE-2025-3248 漏洞的工具。",
                    "summary": "A vulnerability scanner for CVE-2025-3248 in Langflow applications. 用于扫描 Langflow 应用中 CVE-2025-3248 漏洞的工具。",
                    "url": "https://github.com/xuemian168/CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · PuddinCat/CVE-2025-3248-POC",
                    "author": "PuddinCat",
                    "first_seen": "2025-04-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "POC of CVE-2025-3248, RCE of LangFlow",
                    "summary": "POC of CVE-2025-3248, RCE of LangFlow",
                    "url": "https://github.com/PuddinCat/CVE-2025-3248-POC"
                },
                {
                    "repository": "PoC-in-GitHub · verylazytech/CVE-2025-3248",
                    "author": "verylazytech",
                    "first_seen": "2025-04-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "CVE-2025-3248 repository",
                    "summary": "",
                    "url": "https://github.com/verylazytech/CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · GraySignal/CVE-2025-3248",
                    "author": "GraySignal",
                    "first_seen": "2025-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Scanner and exploit for CVE-2025-3248",
                    "summary": "Scanner and exploit for CVE-2025-3248",
                    "url": "https://github.com/GraySignal/CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · vigilante-1337/CVE-2025-3248",
                    "author": "vigilante-1337",
                    "first_seen": "2025-05-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-3248: A critical flaw has been discovered in Langflow that allows malicious actors to execute arbitrary Python code on the target system. This can lead to full remote code execution without authentication, potentially giving attackers control over the server.",
                    "summary": "CVE-2025-3248: A critical flaw has been discovered in Langflow that allows malicious actors to execute arbitrary Python code on the target system. This can lead to full remote code execution without authentication, potentially giving attackers control over the server.",
                    "url": "https://github.com/vigilante-1337/CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · Vip3rLi0n/CVE-2025-3248",
                    "author": "Vip3rLi0n",
                    "first_seen": "2025-05-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Perform Remote Code Execution using vulnerable API endpoint.",
                    "summary": "Perform Remote Code Execution using vulnerable API endpoint.",
                    "url": "https://github.com/Vip3rLi0n/CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · tiemio/RCE-CVE-2025-3248",
                    "author": "tiemio",
                    "first_seen": "2025-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This Python script exploits CVE-2025-3248 to execute arbitrary commands or spawn a reverse shell on a vulnerable system. Authentication is required to use this exploit.",
                    "summary": "This Python script exploits CVE-2025-3248 to execute arbitrary commands or spawn a reverse shell on a vulnerable system. Authentication is required to use this exploit.",
                    "url": "https://github.com/tiemio/RCE-CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · ynsmroztas/CVE-2025-3248-Langflow-RCE",
                    "author": "ynsmroztas",
                    "first_seen": "2025-06-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "CVE-2025-3248 Langflow RCE Exploit",
                    "summary": "CVE-2025-3248 Langflow RCE Exploit",
                    "url": "https://github.com/ynsmroztas/CVE-2025-3248-Langflow-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · imbas007/CVE-2025-3248",
                    "author": "imbas007",
                    "first_seen": "2025-06-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-3248 repository",
                    "summary": "",
                    "url": "https://github.com/imbas007/CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · 0xgh057r3c0n/CVE-2025-3248",
                    "author": "0xgh057r3c0n",
                    "first_seen": "2025-06-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit for Langflow AI Remote Code Execution (Unauthenticated)",
                    "summary": "Exploit for Langflow AI Remote Code Execution (Unauthenticated)",
                    "url": "https://github.com/0xgh057r3c0n/CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · zapstiko/CVE-2025-3248",
                    "author": "zapstiko",
                    "first_seen": "2025-06-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-3248 — Langflow RCE Exploit",
                    "summary": "CVE-2025-3248 — Langflow RCE Exploit",
                    "url": "https://github.com/zapstiko/CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · 0-d3y/langflow-rce-exploit",
                    "author": "0-d3y",
                    "first_seen": "2025-06-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]",
                    "summary": "Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]",
                    "url": "https://github.com/0-d3y/langflow-rce-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · dennisec/Mass-CVE-2025-3248",
                    "author": "dennisec",
                    "first_seen": "2025-06-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Mass-CVE-2025-3248",
                    "summary": "Mass-CVE-2025-3248",
                    "url": "https://github.com/dennisec/Mass-CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · ill-deed/Langflow-CVE-2025-3248-Multi-target",
                    "author": "ill-deed",
                    "first_seen": "2025-06-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.",
                    "summary": "Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.",
                    "url": "https://github.com/ill-deed/Langflow-CVE-2025-3248-Multi-target"
                },
                {
                    "repository": "PoC-in-GitHub · r0otk3r/CVE-2025-3248",
                    "author": "r0otk3r",
                    "first_seen": "2025-07-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-3248 repository",
                    "summary": "",
                    "url": "https://github.com/r0otk3r/CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · min8282/CVE-2025-3248",
                    "author": "min8282",
                    "first_seen": "2025-09-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-3248",
                    "summary": "CVE-2025-3248",
                    "url": "https://github.com/min8282/CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · EQSTLab/CVE-2025-3248",
                    "author": "EQSTLab",
                    "first_seen": "2025-09-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Langflow Remote Code Execution",
                    "summary": "Langflow Remote Code Execution",
                    "url": "https://github.com/EQSTLab/CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · wand3rlust/CVE-2025-3248",
                    "author": "wand3rlust",
                    "first_seen": "2025-09-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC for achieving RCE in Langflow versions <1.3.0",
                    "summary": "PoC for achieving RCE in Langflow versions <1.3.0",
                    "url": "https://github.com/wand3rlust/CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · Kiraly07/Demo_CVE-2025-3248",
                    "author": "Kiraly07",
                    "first_seen": "2025-10-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-3248 repository",
                    "summary": "",
                    "url": "https://github.com/Kiraly07/Demo_CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · bambooqj/cve-2025-3248",
                    "author": "bambooqj",
                    "first_seen": "2025-10-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Langflow 在对用户提交的“验证代码”做 AST 解析和编译时，在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()（以及在编译阶段会评估函数默认参数与装饰器），攻击者可把恶意载荷放在参数默认值或装饰器里，借此在服务器上下文中执行任意语句（反弹 shell、下载器、横向移动等）",
                    "summary": "Langflow 在对用户提交的“验证代码”做 AST 解析和编译时，在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()（以及在编译阶段会评估函数默认参数与装饰器），攻击者可把恶意载荷放在参数默认值或装饰器里，借此在服务器上下文中执行任意语句（反弹 shell、下载器、横向移动等）",
                    "url": "https://github.com/bambooqj/cve-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · drackyjr/cve-2025-3248-exploit",
                    "author": "drackyjr",
                    "first_seen": "2025-11-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution vulnerability in Langflow versions ≤ 1.3.0.",
                    "summary": "A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution vulnerability in Langflow versions ≤ 1.3.0.",
                    "url": "https://github.com/drackyjr/cve-2025-3248-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · b0ySie7e/CVE-2025-3248-POC",
                    "author": "b0ySie7e",
                    "first_seen": "2025-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2025-3248 repository",
                    "summary": "",
                    "url": "https://github.com/b0ySie7e/CVE-2025-3248-POC"
                },
                {
                    "repository": "PoC-in-GitHub · 12-test-12/CVE-2025-3248",
                    "author": "12-test-12",
                    "first_seen": "2026-03-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-3248 repository",
                    "summary": "",
                    "url": "https://github.com/12-test-12/CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · Atomics-hub/exposecheck",
                    "author": "Atomics-hub",
                    "first_seen": "2026-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Defensive single-target self-check for Langflow CVE-2025-3248 exposure",
                    "summary": "Defensive single-target self-check for Langflow CVE-2025-3248 exposure",
                    "url": "https://github.com/Atomics-hub/exposecheck"
                },
                {
                    "repository": "PoC-in-GitHub · preemware/langflow-exploit",
                    "author": "preemware",
                    "first_seen": "2026-08-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC for CVE-2025-3248: unauthenticated RCE in Langflow < 1.3.0 via /api/v1/validate/code.",
                    "summary": "PoC for CVE-2025-3248: unauthenticated RCE in Langflow < 1.3.0 via /api/v1/validate/code.",
                    "url": "https://github.com/preemware/langflow-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · hideki233/CVE-2025-3248-Langflow-RCE",
                    "author": "hideki233",
                    "first_seen": "2026-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2025-3248 repository",
                    "summary": "",
                    "url": "https://github.com/hideki233/CVE-2025-3248-Langflow-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · LeotheGGman/Langflow-RCE-CVE-2025-3248",
                    "author": "LeotheGGman",
                    "first_seen": "2026-09-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-3248 repository",
                    "summary": "",
                    "url": "https://github.com/LeotheGGman/Langflow-RCE-CVE-2025-3248"
                },
                {
                    "repository": "PoC-in-GitHub · zoly-zoly/CVE-2025-3248",
                    "author": "zoly-zoly",
                    "first_seen": "2026-09-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "An educational reference and defensive analysis of CVE-2025-3248, a critical code injection vulnerability affecting Langflow.",
                    "summary": "An educational reference and defensive analysis of CVE-2025-3248, a critical code injection vulnerability affecting Langflow.",
                    "url": "https://github.com/zoly-zoly/CVE-2025-3248"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52262",
                "https://www.exploit-db.com/exploits/52364",
                "https://github.com/xuemian168/CVE-2025-3248",
                "https://github.com/PuddinCat/CVE-2025-3248-POC",
                "https://github.com/verylazytech/CVE-2025-3248",
                "https://github.com/GraySignal/CVE-2025-3248",
                "https://github.com/vigilante-1337/CVE-2025-3248",
                "https://github.com/Vip3rLi0n/CVE-2025-3248",
                "https://github.com/tiemio/RCE-CVE-2025-3248",
                "https://github.com/ynsmroztas/CVE-2025-3248-Langflow-RCE",
                "https://github.com/imbas007/CVE-2025-3248",
                "https://github.com/0xgh057r3c0n/CVE-2025-3248",
                "https://github.com/zapstiko/CVE-2025-3248",
                "https://github.com/0-d3y/langflow-rce-exploit",
                "https://github.com/dennisec/Mass-CVE-2025-3248",
                "https://github.com/ill-deed/Langflow-CVE-2025-3248-Multi-target",
                "https://github.com/r0otk3r/CVE-2025-3248",
                "https://github.com/min8282/CVE-2025-3248",
                "https://github.com/EQSTLab/CVE-2025-3248",
                "https://github.com/wand3rlust/CVE-2025-3248",
                "https://github.com/Kiraly07/Demo_CVE-2025-3248",
                "https://github.com/bambooqj/cve-2025-3248",
                "https://github.com/drackyjr/cve-2025-3248-exploit",
                "https://github.com/b0ySie7e/CVE-2025-3248-POC",
                "https://github.com/12-test-12/CVE-2025-3248",
                "https://github.com/Atomics-hub/exposecheck",
                "https://github.com/preemware/langflow-exploit",
                "https://github.com/hideki233/CVE-2025-3248-Langflow-RCE",
                "https://github.com/LeotheGGman/Langflow-RCE-CVE-2025-3248",
                "https://github.com/zoly-zoly/CVE-2025-3248"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-05-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2025-2842",
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift distributed tracing 3.5.2",
            "title": "Red Hat OpenShift distributed tracing 3.5.2 vulnerability",
            "summary": "A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole.\nThis can be exploited if a user has 'create' permissions on TempoStack and 'get' permissions on Secret in a namespace (for example, a user has ClusterAdmin permissions for a specific namespace), as the user can read the token of the Tempo service account and therefore has access to see all cluster metrics.",
            "updated_at": "2026-09-08T15:18:38.780",
            "published_at": "2025-04-02T12:15:14.677",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.15.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole.\nThis can be exploited if a user has 'create' permissions on TempoStack and 'get' permissions on Secret in a namespace (for example, a user has ClusterAdmin permissions for a specific namespace), as the user can read the token of the Tempo service account and therefore has access to see all cluster metrics.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2025:3607",
                "https://access.redhat.com/errata/RHSA-2025:3740",
                "https://access.redhat.com/security/cve/CVE-2025-2842",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2355219",
                "https://github.com/grafana/tempo-operator/pull/1144"
            ],
            "timeline": [
                {
                    "at": "2025-04-02T12:15:14.677",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2842"
                }
            ]
        },
        {
            "id": "CVE-2025-2825",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for ludus_crushftp_cve-2025-31161_sim CVE-2025-31161",
            "summary": "Authentication bypass in CrushFTP 10.8.0 on Windows (CVE-2025-31161).",
            "updated_at": "2026-08-25T02:25:29Z",
            "published_at": "2026-08-25T02:25:29Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 103,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Authentication bypass in CrushFTP 10.8.0 on Windows (CVE-2025-31161).",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for ludus_crushftp_cve-2025-31161_sim CVE-2025-31161",
                    "summary": "Authentication bypass in CrushFTP 10.8.0 on Windows (CVE-2025-31161).",
                    "what_happened": "Authentication bypass in CrushFTP 10.8.0 on Windows (CVE-2025-31161).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUFFLABS-LUDUS_CRUSHFTP_CVE-2025-31161_SIM",
                        "https://kitploit.com/hi/tools/github/rufflabs/ludus_crushftp_cve-2025-31161_sim/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T04:25:29",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUFFLABS-LUDUS_CRUSHFTP_CVE-2025-31161_SIM"
                },
                {
                    "title": "Exploit for ludus_crushftp_cve-2025-31161_sim CVE-2025-31161",
                    "summary": "Authentication bypass in CrushFTP 10.8.0 on Windows (CVE-2025-31161).",
                    "what_happened": "Authentication bypass in CrushFTP 10.8.0 on Windows (CVE-2025-31161).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUFFLABS-LUDUS_CRUSHFTP_CVE-2025-31161_SIM",
                        "https://kitploit.com/hi/tools/github/rufflabs/ludus_crushftp_cve-2025-31161_sim/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-08-25T04:25:29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/rufflabs/ludus_crushftp_cve-2025-31161_sim/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUFFLABS-LUDUS_CRUSHFTP_CVE-2025-31161_SIM",
                "https://kitploit.com/hi/tools/github/rufflabs/ludus_crushftp_cve-2025-31161_sim/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T02:25:29Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUFFLABS-LUDUS_CRUSHFTP_CVE-2025-31161_SIM"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-2786",
            "vendor": "Red Hat",
            "product": "Red Hat OpenShift distributed tracing 3.5.2",
            "title": "Red Hat OpenShift distributed tracing 3.5.2 vulnerability",
            "summary": "A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks.",
            "updated_at": "2026-09-08T15:18:38.630",
            "published_at": "2025-04-02T11:15:39.300",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.15.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2025:3607",
                "https://access.redhat.com/errata/RHSA-2025:3740",
                "https://access.redhat.com/security/cve/CVE-2025-2786",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2354811",
                "https://github.com/grafana/tempo-operator/pull/1145"
            ],
            "timeline": [
                {
                    "at": "2025-04-02T11:15:39.300",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2786"
                }
            ]
        },
        {
            "id": "CVE-2025-2294",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Kubio AI Page Builder 2.5.1 - Local File Inclusion (LFI)",
            "summary": "Kubio AI Page Builder 2.5.1 - Local File Inclusion (LFI)",
            "updated_at": "2026-09-04T03:55:22Z",
            "published_at": "2026-09-04T03:55:22Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 156,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "Unauthenticated file upload in Drag and Drop Multiple File Upload for WooCommerce up to 1.1.6.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52125",
                    "author": "4m3rr0r",
                    "first_seen": "2025-04-05",
                    "confidence": "High",
                    "title": "Kubio AI Page Builder 2.5.1 - Local File Inclusion (LFI)",
                    "summary": "Kubio AI Page Builder 2.5.1 - Local File Inclusion (LFI)",
                    "url": "https://www.exploit-db.com/exploits/52125",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2025-4403",
                    "summary": "Unauthenticated file upload in Drag and Drop Multiple File Upload for WooCommerce up to 1.1.6.",
                    "what_happened": "Unauthenticated file upload in Drag and Drop Multiple File Upload for WooCommerce up to 1.1.6.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YUCAERIN-CVE-2025-4403",
                        "https://kitploit.com/ru/tools/github/yucaerin/cve-2025-4403/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T05:55:22",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YUCAERIN-CVE-2025-4403"
                },
                {
                    "title": "Exploit for CVE-2025-4403",
                    "summary": "Unauthenticated file upload in Drag and Drop Multiple File Upload for WooCommerce up to 1.1.6.",
                    "what_happened": "Unauthenticated file upload in Drag and Drop Multiple File Upload for WooCommerce up to 1.1.6.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-434",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YUCAERIN-CVE-2025-4403",
                        "https://kitploit.com/ru/tools/github/yucaerin/cve-2025-4403/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T05:55:22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/yucaerin/cve-2025-4403/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52125",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YUCAERIN-CVE-2025-4403",
                "https://kitploit.com/ru/tools/github/yucaerin/cve-2025-4403/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T03:55:22Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52125"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2025-1244",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
            "title": "Red Hat Enterprise Linux 7 Extended Lifecycle Support vulnerability",
            "summary": "A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.",
            "updated_at": "2026-09-06T02:17:16.397",
            "published_at": "2025-02-12T15:15:18.430",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 29.4.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 18,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-78",
            "what_happened": "A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2025:1915",
                "https://access.redhat.com/errata/RHSA-2025:1917",
                "https://access.redhat.com/errata/RHSA-2025:1961",
                "https://access.redhat.com/errata/RHSA-2025:1962",
                "https://access.redhat.com/errata/RHSA-2025:1963",
                "https://access.redhat.com/errata/RHSA-2025:1964",
                "https://access.redhat.com/errata/RHSA-2025:2022",
                "https://access.redhat.com/errata/RHSA-2025:2130",
                "https://access.redhat.com/errata/RHSA-2025:2157",
                "https://access.redhat.com/errata/RHSA-2025:2195",
                "https://access.redhat.com/errata/RHSA-2025:2754",
                "https://access.redhat.com/security/cve/CVE-2025-1244",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2345150",
                "https://git.savannah.gnu.org/cgit/emacs.git/commit/?id=820f0793f0b46448928905552726c1f1b999062f",
                "http://www.openwall.com/lists/oss-security/2025/03/01/2",
                "https://debbugs.gnu.org/cgi/bugreport.cgi?bug=66390",
                "https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-30.1",
                "https://lists.debian.org/debian-lts-announce/2025/02/msg00033.html"
            ],
            "timeline": [
                {
                    "at": "2025-02-12T15:15:18.430",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1244"
                }
            ]
        },
        {
            "id": "CVE-2025-1094",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "WebSocket and SQL Injection Exploit Script",
            "summary": "WebSocket and SQL Injection Exploit Script",
            "updated_at": "2026-09-03T22:00:00Z",
            "published_at": "2026-09-03T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 247,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · soltanali0/CVE-2025-1094-Exploit",
                    "author": "soltanali0",
                    "first_seen": "2025-02-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 41,
                    "title": "WebSocket and SQL Injection Exploit Script",
                    "summary": "WebSocket and SQL Injection Exploit Script",
                    "url": "https://github.com/soltanali0/CVE-2025-1094-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · ishwardeepp/CVE-2025-1094-PoC-Postgre-SQLi",
                    "author": "ishwardeepp",
                    "first_seen": "2025-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2025-1094 repository",
                    "summary": "",
                    "url": "https://github.com/ishwardeepp/CVE-2025-1094-PoC-Postgre-SQLi"
                },
                {
                    "repository": "PoC-in-GitHub · aninfosec/CVE-2025-1094",
                    "author": "aninfosec",
                    "first_seen": "2025-06-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can inject malicious SQL that the backend executes.",
                    "summary": "It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can inject malicious SQL that the backend executes.",
                    "url": "https://github.com/aninfosec/CVE-2025-1094"
                },
                {
                    "repository": "PoC-in-GitHub · PinkArmor/CVE-2025-1094-Lab-Setup",
                    "author": "PinkArmor",
                    "first_seen": "2025-10-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-1094 repository",
                    "summary": "",
                    "url": "https://github.com/PinkArmor/CVE-2025-1094-Lab-Setup"
                },
                {
                    "repository": "PoC-in-GitHub · TranDongA3/POC-CVE-2025-1094",
                    "author": "TranDongA3",
                    "first_seen": "2026-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2025-1094 repository",
                    "summary": "",
                    "url": "https://github.com/TranDongA3/POC-CVE-2025-1094"
                },
                {
                    "repository": "PoC-in-GitHub · skraft9/CVE-2024-12356",
                    "author": "skraft9",
                    "first_seen": "2026-09-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Unauthenticated RCE detector + RCA for BeyondTrust Remote Support / PRA (CVE-2024-12356 + CVE-2025-1094)",
                    "summary": "Unauthenticated RCE detector + RCA for BeyondTrust Remote Support / PRA (CVE-2024-12356 + CVE-2025-1094)",
                    "url": "https://github.com/skraft9/CVE-2024-12356"
                }
            ],
            "references": [
                "https://github.com/soltanali0/CVE-2025-1094-Exploit",
                "https://github.com/ishwardeepp/CVE-2025-1094-PoC-Postgre-SQLi",
                "https://github.com/aninfosec/CVE-2025-1094",
                "https://github.com/PinkArmor/CVE-2025-1094-Lab-Setup",
                "https://github.com/TranDongA3/POC-CVE-2025-1094",
                "https://github.com/skraft9/CVE-2024-12356"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/soltanali0/CVE-2025-1094-Exploit"
                }
            ]
        },
        {
            "id": "CVE-2025-0411",
            "vendor": "7-Zip",
            "product": "7-Zip",
            "title": "7-Zip Mark of the Web Bypass Vulnerability",
            "summary": "7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.",
            "updated_at": "2026-09-13T18:06:11Z",
            "published_at": "2026-09-13T18:06:11Z",
            "cvss": 7,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 23,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:06:11+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2025-0411-7-Zip-Mark-of-the-Web-Bypass exploit",
                    "summary": "Exploit for CVE-2025-0411. CVSS 7.",
                    "cvss": 7,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BETULSSAHIN-CVE-2025-0411-7-ZIP-MARK-OF-THE-WEB-BYPASS"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BETULSSAHIN-CVE-2025-0411-7-ZIP-MARK-OF-THE-WEB-BYPASS"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:06:11Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2024-58097",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix RCU stall while reaping monitor destination ring\n\nWhile processing the monitor destination ring, MSDUs are reaped from the\nlink descriptor based on the corresponding buf_id.\n\nHowever, sometimes the driver cannot obtain a valid buffer corresponding\nto the buf_id received from the hardware. This causes an infinite loop\nin the destination processing, resulting in a kernel crash.\n\nkernel log:\nath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309\nath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed\nath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309\nath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed\n\nFix this by skipping the problematic buf_id and reaping the next entry,\nreplacing the break with the next MSDU processing.\n\nTested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30\nTested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1",
            "updated_at": "2026-09-14T12:17:34.377",
            "published_at": "2025-04-16T15:15:53.683",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "d5c65159f2895379e11ca13f62feabe93278985d through before cdb32923699932502b0573f818643aae72ce0cd5 (git); d5c65159f2895379e11ca13f62feabe93278985d through before 8db5de0cf02fccf4c759aa58edbe65659daf607c (git); d5c65159f2895379e11ca13f62feabe93278985d through before 9f1a002f0171d27f3554e529f3c70df438f05dfe (git); d5c65159f2895379e11ca13f62feabe93278985d through before b4991fc41745645f8050506f5a8578bd11e6b378 (git); d5c65159f2895379e11ca13f62feabe93278985d through before 16c6c35c03ea73054a1f6d3302a4ce4a331b427d (git); 5.6",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-835",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix RCU stall while reaping monitor destination ring\n\nWhile processing the monitor destination ring, MSDUs are reaped from the\nlink descriptor based on the corresponding buf_id.\n\nHowever, sometimes the driver cannot obtain a valid buffer corresponding\nto the buf_id received from the hardware. This causes an infinite loop\nin the destination processing, resulting in a kernel crash.\n\nkernel log:\nath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309\nath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed\nath11k_pci 0000:58:00.0: data msdu_pop: invalid buf_id 309\nath11k_pci 0000:58:00.0: data dp_rx_monitor_link_desc_return failed\n\nFix this by skipping the problematic buf_id and reaping the next entry,\nreplacing the break with the next MSDU processing.\n\nTested-on: WCN6855 hw2.0 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.30\nTested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/16c6c35c03ea73054a1f6d3302a4ce4a331b427d",
                "https://git.kernel.org/stable/c/8db5de0cf02fccf4c759aa58edbe65659daf607c",
                "https://git.kernel.org/stable/c/9f1a002f0171d27f3554e529f3c70df438f05dfe",
                "https://git.kernel.org/stable/c/b4991fc41745645f8050506f5a8578bd11e6b378",
                "https://git.kernel.org/stable/c/cdb32923699932502b0573f818643aae72ce0cd5"
            ],
            "timeline": [
                {
                    "at": "2025-04-16T15:15:53.683",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58097"
                }
            ]
        },
        {
            "id": "CVE-2024-56639",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: must allocate more bytes for RedBox support\n\nBlamed commit forgot to change hsr_init_skb() to allocate\nlarger skb for RedBox case.\n\nIndeed, send_hsr_supervision_frame() will add\ntwo additional components (struct hsr_sup_tlv\nand struct hsr_sup_payload)\n\nsyzbot reported the following crash:\nskbuff: skb_over_panic: text:ffffffff8afd4b0a len:34 put:6 head:ffff88802ad29e00 data:ffff88802ad29f22 tail:0x144 end:0x140 dev:gretap0\n------------[ cut here ]------------\n kernel BUG at net/core/skbuff.c:206 !\nOops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI\nCPU: 2 UID: 0 PID: 7611 Comm: syz-executor Not tainted 6.12.0-syzkaller #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\n RIP: 0010:skb_panic+0x157/0x1d0 net/core/skbuff.c:206\nCode: b6 04 01 84 c0 74 04 3c 03 7e 21 8b 4b 70 41 56 45 89 e8 48 c7 c7 a0 7d 9b 8c 41 57 56 48 89 ee 52 4c 89 e2 e8 9a 76 79 f8 90 <0f> 0b 4c 89 4c 24 10 48 89 54 24 08 48 89 34 24 e8 94 76 fb f8 4c\nRSP: 0018:ffffc90000858ab8 EFLAGS: 00010282\nRAX: 0000000000000087 RBX: ffff8880598c08c0 RCX: ffffffff816d3e69\nRDX: 0000000000000000 RSI: ffffffff816de786 RDI: 0000000000000005\nRBP: ffffffff8c9b91c0 R08: 0000000000000005 R09: 0000000000000000\nR10: 0000000000000302 R11: ffffffff961cc1d0 R12: ffffffff8afd4b0a\nR13: 0000000000000006 R14: ffff88804b938130 R15: 0000000000000140\nFS:  000055558a3d6500(0000) GS:ffff88806a800000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f1295974ff8 CR3: 000000002ab6e000 CR4: 0000000000352ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n <IRQ>\n  skb_over_panic net/core/skbuff.c:211 [inline]\n  skb_put+0x174/0x1b0 net/core/skbuff.c:2617\n  send_hsr_supervision_frame+0x6fa/0x9e0 net/hsr/hsr_device.c:342\n  hsr_proxy_announce+0x1a3/0x4a0 net/hsr/hsr_device.c:436\n  call_timer_fn+0x1a0/0x610 kernel/time/timer.c:1794\n  expire_timers kernel/time/timer.c:1845 [inline]\n  __run_timers+0x6e8/0x930 kernel/time/timer.c:2419\n  __run_timer_base kernel/time/timer.c:2430 [inline]\n  __run_timer_base kernel/time/timer.c:2423 [inline]\n  run_timer_base+0x111/0x190 kernel/time/timer.c:2439\n  run_timer_softirq+0x1a/0x40 kernel/time/timer.c:2449\n  handle_softirqs+0x213/0x8f0 kernel/softirq.c:554\n  __do_softirq kernel/softirq.c:588 [inline]\n  invoke_softirq kernel/softirq.c:428 [inline]\n  __irq_exit_rcu kernel/softirq.c:637 [inline]\n  irq_exit_rcu+0xbb/0x120 kernel/softirq.c:649\n  instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1049 [inline]\n  sysvec_apic_timer_interrupt+0xa4/0xc0 arch/x86/kernel/apic/apic.c:1049\n </IRQ>",
            "updated_at": "2026-09-14T12:17:34.223",
            "published_at": "2024-12-27T15:15:23.633",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "cb3a332662b7fbe9f20849473c1b2c59e7d5d617 through before e6773b7da5ecb11ef8e95b50145fd963e326e0f1 (git); d90e4f72e8d464577dac67a18e69eb4a26abd63b through before a77a45fbadd9c053e8cf3a9ce2e23bcd23819ea6 (git); 5055cccfc2d1cc1a7306f6bcdcd0ee9521d707f5 through before 688842f47ee9fb392d1c3a1ced1d21d505b14968 (git); 5055cccfc2d1cc1a7306f6bcdcd0ee9521d707f5 through before af8edaeddbc52e53207d859c912b017fd9a77629 (git); 6.10",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: must allocate more bytes for RedBox support\n\nBlamed commit forgot to change hsr_init_skb() to allocate\nlarger skb for RedBox case.\n\nIndeed, send_hsr_supervision_frame() will add\ntwo additional components (struct hsr_sup_tlv\nand struct hsr_sup_payload)\n\nsyzbot reported the following crash:\nskbuff: skb_over_panic: text:ffffffff8afd4b0a len:34 put:6 head:ffff88802ad29e00 data:ffff88802ad29f22 tail:0x144 end:0x140 dev:gretap0\n------------[ cut here ]------------\n kernel BUG at net/core/skbuff.c:206 !\nOops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI\nCPU: 2 UID: 0 PID: 7611 Comm: syz-executor Not tainted 6.12.0-syzkaller #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\n RIP: 0010:skb_panic+0x157/0x1d0 net/core/skbuff.c:206\nCode: b6 04 01 84 c0 74 04 3c 03 7e 21 8b 4b 70 41 56 45 89 e8 48 c7 c7 a0 7d 9b 8c 41 57 56 48 89 ee 52 4c 89 e2 e8 9a 76 79 f8 90 <0f> 0b 4c 89 4c 24 10 48 89 54 24 08 48 89 34 24 e8 94 76 fb f8 4c\nRSP: 0018:ffffc90000858ab8 EFLAGS: 00010282\nRAX: 0000000000000087 RBX: ffff8880598c08c0 RCX: ffffffff816d3e69\nRDX: 0000000000000000 RSI: ffffffff816de786 RDI: 0000000000000005\nRBP: ffffffff8c9b91c0 R08: 0000000000000005 R09: 0000000000000000\nR10: 0000000000000302 R11: ffffffff961cc1d0 R12: ffffffff8afd4b0a\nR13: 0000000000000006 R14: ffff88804b938130 R15: 0000000000000140\nFS:  000055558a3d6500(0000) GS:ffff88806a800000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f1295974ff8 CR3: 000000002ab6e000 CR4: 0000000000352ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n <IRQ>\n  skb_over_panic net/core/skbuff.c:211 [inline]\n  skb_put+0x174/0x1b0 net/core/skbuff.c:2617\n  send_hsr_supervision_frame+0x6fa/0x9e0 net/hsr/hsr_device.c:342\n  hsr_proxy_announce+0x1a3/0x4a0 net/hsr/hsr_device.c:436\n  call_timer_fn+0x1a0/0x610 kernel/time/timer.c:1794\n  expire_timers kernel/time/timer.c:1845 [inline]\n  __run_timers+0x6e8/0x930 kernel/time/timer.c:2419\n  __run_timer_base kernel/time/timer.c:2430 [inline]\n  __run_timer_base kernel/time/timer.c:2423 [inline]\n  run_timer_base+0x111/0x190 kernel/time/timer.c:2439\n  run_timer_softirq+0x1a/0x40 kernel/time/timer.c:2449\n  handle_softirqs+0x213/0x8f0 kernel/softirq.c:554\n  __do_softirq kernel/softirq.c:588 [inline]\n  invoke_softirq kernel/softirq.c:428 [inline]\n  __irq_exit_rcu kernel/softirq.c:637 [inline]\n  irq_exit_rcu+0xbb/0x120 kernel/softirq.c:649\n  instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1049 [inline]\n  sysvec_apic_timer_interrupt+0xa4/0xc0 arch/x86/kernel/apic/apic.c:1049\n </IRQ>",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/688842f47ee9fb392d1c3a1ced1d21d505b14968",
                "https://git.kernel.org/stable/c/a77a45fbadd9c053e8cf3a9ce2e23bcd23819ea6",
                "https://git.kernel.org/stable/c/af8edaeddbc52e53207d859c912b017fd9a77629",
                "https://git.kernel.org/stable/c/e6773b7da5ecb11ef8e95b50145fd963e326e0f1"
            ],
            "timeline": [
                {
                    "at": "2024-12-27T15:15:23.633",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56639"
                }
            ]
        },
        {
            "id": "CVE-2024-56545",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: hyperv: streamline driver probe to avoid devres issues\n\nIt was found that unloading 'hid_hyperv' module results in a devres\ncomplaint:\n\n ...\n hv_vmbus: unregistering driver hid_hyperv\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 3983 at drivers/base/devres.c:691 devres_release_group+0x1f2/0x2c0\n ...\n Call Trace:\n  <TASK>\n  ? devres_release_group+0x1f2/0x2c0\n  ? __warn+0xd1/0x1c0\n  ? devres_release_group+0x1f2/0x2c0\n  ? report_bug+0x32a/0x3c0\n  ? handle_bug+0x53/0xa0\n  ? exc_invalid_op+0x18/0x50\n  ? asm_exc_invalid_op+0x1a/0x20\n  ? devres_release_group+0x1f2/0x2c0\n  ? devres_release_group+0x90/0x2c0\n  ? rcu_is_watching+0x15/0xb0\n  ? __pfx_devres_release_group+0x10/0x10\n  hid_device_remove+0xf5/0x220\n  device_release_driver_internal+0x371/0x540\n  ? klist_put+0xf3/0x170\n  bus_remove_device+0x1f1/0x3f0\n  device_del+0x33f/0x8c0\n  ? __pfx_device_del+0x10/0x10\n  ? cleanup_srcu_struct+0x337/0x500\n  hid_destroy_device+0xc8/0x130\n  mousevsc_remove+0xd2/0x1d0 [hid_hyperv]\n  device_release_driver_internal+0x371/0x540\n  driver_detach+0xc5/0x180\n  bus_remove_driver+0x11e/0x2a0\n  ? __mutex_unlock_slowpath+0x160/0x5e0\n  vmbus_driver_unregister+0x62/0x2b0 [hv_vmbus]\n  ...\n\nAnd the issue seems to be that the corresponding devres group is not\nallocated. Normally, devres_open_group() is called from\n__hid_device_probe() but Hyper-V HID driver overrides 'hid_dev->driver'\nwith 'mousevsc_hid_driver' stub and basically re-implements\n__hid_device_probe() by calling hid_parse() and hid_hw_start() but not\ndevres_open_group(). hid_device_probe() does not call __hid_device_probe()\nfor it. Later, when the driver is removed, hid_device_remove() calls\ndevres_release_group() as it doesn't check whether hdev->driver was\ninitially overridden or not.\n\nThe issue seems to be related to the commit 62c68e7cee33 (\"HID: ensure\ntimely release of driver-allocated resources\") but the commit itself seems\nto be correct.\n\nFix the issue by dropping the 'hid_dev->driver' override and using\nhid_register_driver()/hid_unregister_driver() instead. Alternatively, it\nwould have been possible to rely on the default handling but\nHID_CONNECT_DEFAULT implies HID_CONNECT_HIDRAW and it doesn't seem to work\nfor mousevsc as-is.",
            "updated_at": "2026-09-14T12:17:34.047",
            "published_at": "2024-12-27T14:15:34.270",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "62c68e7cee332e08e625af3bca3318814086490d through before b03e713a400aeb5f969bab4daf47a7402d0df814 (git); 62c68e7cee332e08e625af3bca3318814086490d through before 19a9457e5e210e408c1f8865b5d93c5a2c90409d (git); 62c68e7cee332e08e625af3bca3318814086490d through before 3d48d0fbaaa74a04fb9092780a3f83dc4f3f8160 (git); 62c68e7cee332e08e625af3bca3318814086490d through before 66ef47faa90d838cda131fe1f7776456cc3b59f2 (git); e6ea3de7abef998aaab9f04a7a11a7c5f56bbe57 (git); ac0d8318082f549419104cfe9cb6a9deb2df9853 (git); 4d1617e40713a6202b6165ca137b09aaf35637f5 (git); 5.10.270 through before 5.11 (semver); 5.15.221 through before 5.16 (semver); 6.1.188 through before 6.2 (semver); 6.5",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: hyperv: streamline driver probe to avoid devres issues\n\nIt was found that unloading 'hid_hyperv' module results in a devres\ncomplaint:\n\n ...\n hv_vmbus: unregistering driver hid_hyperv\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 3983 at drivers/base/devres.c:691 devres_release_group+0x1f2/0x2c0\n ...\n Call Trace:\n  <TASK>\n  ? devres_release_group+0x1f2/0x2c0\n  ? __warn+0xd1/0x1c0\n  ? devres_release_group+0x1f2/0x2c0\n  ? report_bug+0x32a/0x3c0\n  ? handle_bug+0x53/0xa0\n  ? exc_invalid_op+0x18/0x50\n  ? asm_exc_invalid_op+0x1a/0x20\n  ? devres_release_group+0x1f2/0x2c0\n  ? devres_release_group+0x90/0x2c0\n  ? rcu_is_watching+0x15/0xb0\n  ? __pfx_devres_release_group+0x10/0x10\n  hid_device_remove+0xf5/0x220\n  device_release_driver_internal+0x371/0x540\n  ? klist_put+0xf3/0x170\n  bus_remove_device+0x1f1/0x3f0\n  device_del+0x33f/0x8c0\n  ? __pfx_device_del+0x10/0x10\n  ? cleanup_srcu_struct+0x337/0x500\n  hid_destroy_device+0xc8/0x130\n  mousevsc_remove+0xd2/0x1d0 [hid_hyperv]\n  device_release_driver_internal+0x371/0x540\n  driver_detach+0xc5/0x180\n  bus_remove_driver+0x11e/0x2a0\n  ? __mutex_unlock_slowpath+0x160/0x5e0\n  vmbus_driver_unregister+0x62/0x2b0 [hv_vmbus]\n  ...\n\nAnd the issue seems to be that the corresponding devres group is not\nallocated. Normally, devres_open_group() is called from\n__hid_device_probe() but Hyper-V HID driver overrides 'hid_dev->driver'\nwith 'mousevsc_hid_driver' stub and basically re-implements\n__hid_device_probe() by calling hid_parse() and hid_hw_start() but not\ndevres_open_group(). hid_device_probe() does not call __hid_device_probe()\nfor it. Later, when the driver is removed, hid_device_remove() calls\ndevres_release_group() as it doesn't check whether hdev->driver was\ninitially overridden or not.\n\nThe issue seems to be related to the commit 62c68e7cee33 (\"HID: ensure\ntimely release of driver-allocated resources\") but the commit itself seems\nto be correct.\n\nFix the issue by dropping the 'hid_dev->driver' override and using\nhid_register_driver()/hid_unregister_driver() instead. Alternatively, it\nwould have been possible to rely on the default handling but\nHID_CONNECT_DEFAULT implies HID_CONNECT_HIDRAW and it doesn't seem to work\nfor mousevsc as-is.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/19a9457e5e210e408c1f8865b5d93c5a2c90409d",
                "https://git.kernel.org/stable/c/3d48d0fbaaa74a04fb9092780a3f83dc4f3f8160",
                "https://git.kernel.org/stable/c/66ef47faa90d838cda131fe1f7776456cc3b59f2",
                "https://git.kernel.org/stable/c/b03e713a400aeb5f969bab4daf47a7402d0df814"
            ],
            "timeline": [
                {
                    "at": "2024-12-27T14:15:34.270",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56545"
                }
            ]
        },
        {
            "id": "CVE-2024-56182",
            "vendor": "Siemens",
            "product": "SIMATIC Field PG M5",
            "title": "SIMATIC Field PG M5 vulnerability",
            "summary": "A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (All versions < V29.01.07), SIMATIC IPC BX-59A (All versions < V32.01.04), SIMATIC IPC PX-32A (All versions < V29.01.07), SIMATIC IPC PX-39A (All versions < V29.01.07), SIMATIC IPC PX-39A PRO (All versions < V29.01.07), SIMATIC IPC RC-543A (All versions < V36.01.03), SIMATIC IPC RC-543B (All versions < V35.01.12), SIMATIC IPC RW-543A (All versions < V1.1.4), SIMATIC IPC RW-543B (All versions < V35.02.10), SIMATIC IPC127E (All versions < V27.01.11), SIMATIC IPC227E (All versions), SIMATIC IPC227G (All versions < V28.01.14), SIMATIC IPC277E (All versions), SIMATIC IPC277G (All versions < V28.01.14), SIMATIC IPC277G PRO (All versions < V28.01.14), SIMATIC IPC3000 SMART V3 (All versions), SIMATIC IPC327G (All versions < V28.01.14), SIMATIC IPC347G (All versions), SIMATIC IPC377G (All versions < V28.01.14), SIMATIC IPC427E (All versions < V21.01.21), SIMATIC IPC477E (All versions < V21.01.21), SIMATIC IPC477E PRO (All versions < V21.01.21), SIMATIC IPC527G (All versions), SIMATIC IPC627E (All versions < V25.02.15), SIMATIC IPC647E (All versions < V25.02.15), SIMATIC IPC677E (All versions < V25.02.15), SIMATIC IPC847E (All versions < V25.02.15), SIMATIC ITP1000 (All versions). The affected devices have insufficient protection mechanism for the EFI(Extensible Firmware Interface) variables stored on the device. This could allow an authenticated attacker to disable the BIOS password without proper authorization by directly communicate with the flash controller.",
            "updated_at": "2026-09-08T09:17:20.690",
            "published_at": "2025-03-11T10:15:15.823",
            "cvss": 8.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before * (custom); before V26.01.12 (custom); before V31.01.07 (custom); before V29.01.07 (custom); before V32.01.04 (custom); before V36.01.03 (custom); before V35.01.12 (custom); before V1.1.4 (custom); before V35.02.10 (custom); before V27.01.11 (custom); before V28.01.14 (custom); before V21.01.21 (custom); before V25.02.15 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-693",
            "what_happened": "A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC Field PG M6 (All versions < V26.01.12), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (All versions < V29.01.07), SIMATIC IPC BX-59A (All versions < V32.01.04), SIMATIC IPC PX-32A (All versions < V29.01.07), SIMATIC IPC PX-39A (All versions < V29.01.07), SIMATIC IPC PX-39A PRO (All versions < V29.01.07), SIMATIC IPC RC-543A (All versions < V36.01.03), SIMATIC IPC RC-543B (All versions < V35.01.12), SIMATIC IPC RW-543A (All versions < V1.1.4), SIMATIC IPC RW-543B (All versions < V35.02.10), SIMATIC IPC127E (All versions < V27.01.11), SIMATIC IPC227E (All versions), SIMATIC IPC227G (All versions < V28.01.14), SIMATIC IPC277E (All versions), SIMATIC IPC277G (All versions < V28.01.14), SIMATIC IPC277G PRO (All versions < V28.01.14), SIMATIC IPC3000 SMART V3 (All versions), SIMATIC IPC327G (All versions < V28.01.14), SIMATIC IPC347G (All versions), SIMATIC IPC377G (All versions < V28.01.14), SIMATIC IPC427E (All versions < V21.01.21), SIMATIC IPC477E (All versions < V21.01.21), SIMATIC IPC477E PRO (All versions < V21.01.21), SIMATIC IPC527G (All versions), SIMATIC IPC627E (All versions < V25.02.15), SIMATIC IPC647E (All versions < V25.02.15), SIMATIC IPC677E (All versions < V25.02.15), SIMATIC IPC847E (All versions < V25.02.15), SIMATIC ITP1000 (All versions). The affected devices have insufficient protection mechanism for the EFI(Extensible Firmware Interface) variables stored on the device. This could allow an authenticated attacker to disable the BIOS password without proper authorization by directly communicate with the flash controller.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cert-portal.siemens.com/productcert/html/ssa-216014.html"
            ],
            "timeline": [
                {
                    "at": "2025-03-11T10:15:15.823",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56182"
                }
            ]
        },
        {
            "id": "CVE-2024-56181",
            "vendor": "Siemens",
            "product": "SIMATIC Field PG M5",
            "title": "SIMATIC Field PG M5 vulnerability",
            "summary": "A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (All versions < V29.01.07), SIMATIC IPC BX-59A (All versions < V32.01.04), SIMATIC IPC PX-32A (All versions < V29.01.07), SIMATIC IPC PX-39A (All versions < V29.01.07), SIMATIC IPC PX-39A PRO (All versions < V29.01.07), SIMATIC IPC RC-543A (All versions < V36.01.03), SIMATIC IPC RC-543B (All versions < V35.01.12), SIMATIC IPC RW-543A (All versions < V1.1.4), SIMATIC IPC RW-543B (All versions < V35.02.10), SIMATIC IPC127E (All versions < V27.01.11), SIMATIC IPC227E (All versions), SIMATIC IPC227G (All versions < V28.01.14), SIMATIC IPC277E (All versions), SIMATIC IPC277G (All versions < V28.01.14), SIMATIC IPC277G PRO (All versions < V28.01.14), SIMATIC IPC3000 SMART V3 (All versions), SIMATIC IPC327G (All versions < V28.01.14), SIMATIC IPC347G (All versions), SIMATIC IPC377G (All versions < V28.01.14), SIMATIC IPC427E (All versions < V21.01.21), SIMATIC IPC477E (All versions < V21.01.21), SIMATIC IPC477E PRO (All versions < V21.01.21), SIMATIC IPC527G (All versions), SIMATIC IPC627E (All versions < V25.02.15), SIMATIC IPC647E (All versions < V25.02.15), SIMATIC IPC677E (All versions < V25.02.15), SIMATIC IPC847E (All versions < V25.02.15), SIMATIC ITP1000 (All versions). The affected devices have insufficient protection mechanism for the EFI(Extensible Firmware Interface) variables stored on the device. This could allow an authenticated attacker to alter the secure boot configuration without proper authorization by directly communicate with the flash controller.",
            "updated_at": "2026-09-08T09:17:20.340",
            "published_at": "2025-03-11T10:15:15.597",
            "cvss": 8.4,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before * (custom); before V31.01.07 (custom); before V29.01.07 (custom); before V32.01.04 (custom); before V36.01.03 (custom); before V35.01.12 (custom); before V1.1.4 (custom); before V35.02.10 (custom); before V27.01.11 (custom); before V28.01.14 (custom); before V21.01.21 (custom); before V25.02.15 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-693",
            "what_happened": "A vulnerability has been identified in SIMATIC Field PG M5 (All versions), SIMATIC IPC BX-21A (All versions < V31.01.07), SIMATIC IPC BX-32A (All versions < V29.01.07), SIMATIC IPC BX-39A (All versions < V29.01.07), SIMATIC IPC BX-59A (All versions < V32.01.04), SIMATIC IPC PX-32A (All versions < V29.01.07), SIMATIC IPC PX-39A (All versions < V29.01.07), SIMATIC IPC PX-39A PRO (All versions < V29.01.07), SIMATIC IPC RC-543A (All versions < V36.01.03), SIMATIC IPC RC-543B (All versions < V35.01.12), SIMATIC IPC RW-543A (All versions < V1.1.4), SIMATIC IPC RW-543B (All versions < V35.02.10), SIMATIC IPC127E (All versions < V27.01.11), SIMATIC IPC227E (All versions), SIMATIC IPC227G (All versions < V28.01.14), SIMATIC IPC277E (All versions), SIMATIC IPC277G (All versions < V28.01.14), SIMATIC IPC277G PRO (All versions < V28.01.14), SIMATIC IPC3000 SMART V3 (All versions), SIMATIC IPC327G (All versions < V28.01.14), SIMATIC IPC347G (All versions), SIMATIC IPC377G (All versions < V28.01.14), SIMATIC IPC427E (All versions < V21.01.21), SIMATIC IPC477E (All versions < V21.01.21), SIMATIC IPC477E PRO (All versions < V21.01.21), SIMATIC IPC527G (All versions), SIMATIC IPC627E (All versions < V25.02.15), SIMATIC IPC647E (All versions < V25.02.15), SIMATIC IPC677E (All versions < V25.02.15), SIMATIC IPC847E (All versions < V25.02.15), SIMATIC ITP1000 (All versions). The affected devices have insufficient protection mechanism for the EFI(Extensible Firmware Interface) variables stored on the device. This could allow an authenticated attacker to alter the secure boot configuration without proper authorization by directly communicate with the flash controller.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cert-portal.siemens.com/productcert/html/ssa-216014.html"
            ],
            "timeline": [
                {
                    "at": "2025-03-11T10:15:15.597",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56181"
                }
            ]
        },
        {
            "id": "CVE-2024-55591",
            "vendor": "Fortinet",
            "product": "FortiOS and FortiProxy",
            "title": "Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
            "summary": "Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.",
            "updated_at": "2026-09-14T04:53:05Z",
            "published_at": "2026-09-14T04:53:05Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 33,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-55591-POC",
                    "summary": "Authentication bypass in FortiOS 7.0 and FortiProxy 7.0/7.2 via WebSocket CLI interface.",
                    "what_happened": "Authentication bypass in FortiOS 7.0 and FortiProxy 7.0/7.2 via WebSocket CLI interface.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EXFIL0-CVE-2024-55591-POC",
                        "https://kitploit.com/ru/tools/github/exfil0/cve-2024-55591-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-12T01:20:33",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EXFIL0-CVE-2024-55591-POC"
                },
                {
                    "title": "Exploit for CVE-2024-55591-POC",
                    "summary": "Authentication bypass in FortiOS 7.0 and FortiProxy 7.0/7.2 via WebSocket CLI interface.",
                    "what_happened": "Authentication bypass in FortiOS 7.0 and FortiProxy 7.0/7.2 via WebSocket CLI interface.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EXFIL0-CVE-2024-55591-POC",
                        "https://kitploit.com/ru/tools/github/exfil0/cve-2024-55591-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-12T01:20:33",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/exfil0/cve-2024-55591-poc/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EXFIL0-CVE-2024-55591-POC",
                "https://kitploit.com/ru/tools/github/exfil0/cve-2024-55591-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:53:05Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-01-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-01-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-01-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-01-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-01-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-01-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-01-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-01-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-01-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-01-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2024-53922",
            "vendor": "Samsung",
            "product": "Exynos 8890 firmware",
            "title": "Exynos 8890 firmware vulnerability",
            "summary": "An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.",
            "updated_at": "2026-09-14T00:16:55.880",
            "published_at": "2026-09-14T00:16:55.880",
            "cvss": 5.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "V7 (custom); V9 (custom); V920 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-1284",
            "what_happened": "An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://diconium.com/de/blog/cybersecurity/hunting-bugs-in-linux-kernel-with-kasan",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-53922/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T00:16:55.880",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53922"
                }
            ]
        },
        {
            "id": "CVE-2024-53920",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)",
            "updated_at": "2026-09-14T17:17:42.293",
            "published_at": "2024-11-27T15:15:26.837",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a; 30.0.92",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://eshelyaron.com/posts/2024-11-27-emacs-aritrary-code-execution-and-how-to-avoid-it.html",
                "https://git.savannah.gnu.org/cgit/emacs.git/tag/?h=emacs-30.0.92",
                "https://git.savannah.gnu.org/cgit/emacs.git/tree/ChangeLog.4",
                "https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-30.1",
                "https://news.ycombinator.com/item?id=42256409",
                "https://yhetil.org/emacs/CAFXAjY5f4YfHAtZur1RAqH34UbYU56_t6t2Er0YEh1Sb7-W=hg@mail.gmail.com/",
                "http://www.openwall.com/lists/oss-security/2026/08/20/3",
                "http://www.openwall.com/lists/oss-security/2026/08/20/7",
                "http://www.openwall.com/lists/oss-security/2026/09/14/1",
                "https://lists.debian.org/debian-lts-announce/2025/02/msg00033.html"
            ],
            "timeline": [
                {
                    "at": "2024-11-27T15:15:26.837",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53920"
                }
            ]
        },
        {
            "id": "CVE-2024-53677",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for cve-2023-50164 CVE-2023-50164",
            "summary": "Simple app demonstrating Sysdig detection of CVE-2023-50164.",
            "updated_at": "2026-09-05T08:34:07Z",
            "published_at": "2026-09-05T08:34:07Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 113,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Simple app demonstrating Sysdig detection of CVE-2023-50164.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for cve-2023-50164 CVE-2023-50164",
                    "summary": "Simple app demonstrating Sysdig detection of CVE-2023-50164.",
                    "what_happened": "Simple app demonstrating Sysdig detection of CVE-2023-50164.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AARONM-SYSDIG-CVE-2023-50164",
                        "https://kitploit.com/hi/tools/github/aaronm-sysdig/cve-2023-50164/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T08:34:34",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AARONM-SYSDIG-CVE-2023-50164"
                },
                {
                    "title": "Exploit for cve-2023-50164 CVE-2023-50164",
                    "summary": "Simple app demonstrating Sysdig detection of CVE-2023-50164.",
                    "what_happened": "Simple app demonstrating Sysdig detection of CVE-2023-50164.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AARONM-SYSDIG-CVE-2023-50164",
                        "https://kitploit.com/hi/tools/github/aaronm-sysdig/cve-2023-50164/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T08:34:34",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/aaronm-sysdig/cve-2023-50164/"
                },
                {
                    "title": "Exploit for CVE-2024-53677",
                    "summary": "Path traversal in Apache Struts 2 file upload enables RCE via CVE-2024-53677.",
                    "what_happened": "Path traversal in Apache Struts 2 file upload enables RCE via CVE-2024-53677.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SEANRICKERD-CVE-2024-53677",
                        "https://kitploit.com/ru/tools/github/seanrickerd/cve-2024-53677/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-12T06:33:26",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SEANRICKERD-CVE-2024-53677"
                },
                {
                    "title": "Exploit for CVE-2024-53677",
                    "summary": "Path traversal in Apache Struts 2 file upload enables RCE via CVE-2024-53677.",
                    "what_happened": "Path traversal in Apache Struts 2 file upload enables RCE via CVE-2024-53677.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SEANRICKERD-CVE-2024-53677",
                        "https://kitploit.com/ru/tools/github/seanrickerd/cve-2024-53677/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-12T06:33:26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/seanrickerd/cve-2024-53677/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AARONM-SYSDIG-CVE-2023-50164",
                "https://kitploit.com/hi/tools/github/aaronm-sysdig/cve-2023-50164/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SEANRICKERD-CVE-2024-53677",
                "https://kitploit.com/ru/tools/github/seanrickerd/cve-2024-53677/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:34:07Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AARONM-SYSDIG-CVE-2023-50164"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2024-52940",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "abdal-anydesk-remote-ip-detector exploit",
            "summary": "Exploit for CVE-2024-52940. CVSS 7.5.",
            "updated_at": "2026-09-05T12:44:01Z",
            "published_at": "2026-09-05T12:44:01Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 101,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "IP leak vulnerability in AnyDesk (CVE-2024-52940) exposes the user's IP address.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for abdal-anydesk-remote-ip-detector CVE-2024-52940",
                    "summary": "IP leak vulnerability in AnyDesk (CVE-2024-52940) exposes the user's IP address.",
                    "what_happened": "IP leak vulnerability in AnyDesk (CVE-2024-52940) exposes the user's IP address.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EBRASHA-ABDAL-ANYDESK-REMOTE-IP-DETECTOR",
                        "https://kitploit.com/ja/tools/github/ebrasha/abdal-anydesk-remote-ip-detector/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T08:39:35",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EBRASHA-ABDAL-ANYDESK-REMOTE-IP-DETECTOR"
                },
                {
                    "title": "Exploit for abdal-anydesk-remote-ip-detector CVE-2024-52940",
                    "summary": "IP leak vulnerability in AnyDesk (CVE-2024-52940) exposes the user's IP address.",
                    "what_happened": "IP leak vulnerability in AnyDesk (CVE-2024-52940) exposes the user's IP address.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EBRASHA-ABDAL-ANYDESK-REMOTE-IP-DETECTOR",
                        "https://kitploit.com/ja/tools/github/ebrasha/abdal-anydesk-remote-ip-detector/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-03T08:39:35",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/ebrasha/abdal-anydesk-remote-ip-detector/"
                },
                {
                    "repository": "PoC-in-GitHub · ebrasha/abdal-anydesk-remote-ip-detector",
                    "author": "ebrasha",
                    "first_seen": "2024-10-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 37,
                    "title": "CVE-2024-52940 - A zero-day vulnerability in AnyDesk's \"Allow Direct Connections\" feature, discovered and registered by Ebrahim Shafiei (EbraSha), exposing public and private IP addresses. For details, visit the NVD, Tenable, or MITRE pages.",
                    "summary": "CVE-2024-52940 - A zero-day vulnerability in AnyDesk's \"Allow Direct Connections\" feature, discovered and registered by Ebrahim Shafiei (EbraSha), exposing public and private IP addresses. For details, visit the NVD, Tenable, or MITRE pages.",
                    "url": "https://github.com/ebrasha/abdal-anydesk-remote-ip-detector"
                },
                {
                    "repository": "PoC-in-GitHub · MKultra6969/AnySniff",
                    "author": "MKultra6969",
                    "first_seen": "2024-12-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "AnySniff is a tool for monitoring TCP connections of processes like AnyDesk on Windows. It uses the CVE-2024-52940 vulnerability to track open connections and log IPs, ports, and other details.",
                    "summary": "AnySniff is a tool for monitoring TCP connections of processes like AnyDesk on Windows. It uses the CVE-2024-52940 vulnerability to track open connections and log IPs, ports, and other details.",
                    "url": "https://github.com/MKultra6969/AnySniff"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EBRASHA-ABDAL-ANYDESK-REMOTE-IP-DETECTOR",
                "https://kitploit.com/ja/tools/github/ebrasha/abdal-anydesk-remote-ip-detector/",
                "https://github.com/ebrasha/abdal-anydesk-remote-ip-detector",
                "https://github.com/MKultra6969/AnySniff"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:44:01Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EBRASHA-ABDAL-ANYDESK-REMOTE-IP-DETECTOR"
                }
            ]
        },
        {
            "id": "CVE-2024-52560",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr()\n\nExtended the `mi_enum_attr()` function interface with an additional\nparameter, `struct ntfs_inode *ni`, to allow marking the inode\nas bad as soon as an error is detected.",
            "updated_at": "2026-09-14T12:17:33.867",
            "published_at": "2025-02-27T03:15:10.573",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4534a70b7056fd4b9a1c6db5a4ce3c98546b291e through before 4ff4b6b9e85cfe879773ca78d91b1090a3ce19ac (git); 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e through before acfb75eeb3304d08cbd5b5a8c77379459ec6a04e (git); 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e through before d9c699f2c4dc174940ffe8600b20c267897da155 (git); 4534a70b7056fd4b9a1c6db5a4ce3c98546b291e through before 2afd4d267e6dbaec8d3ccd4f5396cb84bc67aa2e (git); 5.15",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr()\n\nExtended the `mi_enum_attr()` function interface with an additional\nparameter, `struct ntfs_inode *ni`, to allow marking the inode\nas bad as soon as an error is detected.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2afd4d267e6dbaec8d3ccd4f5396cb84bc67aa2e",
                "https://git.kernel.org/stable/c/4ff4b6b9e85cfe879773ca78d91b1090a3ce19ac",
                "https://git.kernel.org/stable/c/acfb75eeb3304d08cbd5b5a8c77379459ec6a04e",
                "https://git.kernel.org/stable/c/d9c699f2c4dc174940ffe8600b20c267897da155"
            ],
            "timeline": [
                {
                    "at": "2025-02-27T03:15:10.573",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52560"
                }
            ]
        },
        {
            "id": "CVE-2024-52510",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-52510 exploit",
            "summary": "Exploit for CVE-2024-52510. CVSS 7.5.",
            "updated_at": "2026-09-05T08:10:11Z",
            "published_at": "2026-09-05T08:10:11Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 57,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-07T08:12:47+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2024-52510 exploit",
                    "summary": "Exploit for CVE-2024-52510. CVSS 7.5.",
                    "cvss": 7.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D-XUAN-CVE-2024-52510"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D-XUAN-CVE-2024-52510"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:10:11Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D-XUAN-CVE-2024-52510"
                }
            ]
        },
        {
            "id": "CVE-2024-51532",
            "vendor": "Dell",
            "product": "PowerStore",
            "title": "PowerStore vulnerability",
            "summary": "Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.",
            "updated_at": "2026-09-11T13:31:30.093",
            "published_at": "2024-12-19T02:15:23.000",
            "cvss": 7.1,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "N/A through before 4.0.1.0-2408234 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-88",
            "what_happened": "Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.dell.com/support/kbdoc/en-ie/000250483/dsa-2024-462-dell-powerstore-t-security-update-for-multiple-vulnerabilities"
            ],
            "timeline": [
                {
                    "at": "2024-12-19T02:15:23.000",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51532"
                }
            ]
        },
        {
            "id": "CVE-2024-51324",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Master's Thesis research on CVE-2024-51324 (BYOVD). Advanced exploit with 4 operational modes (SCANNER, LOADER, KILLER, CLEANUP), SHA-256 driver verification, and full academic documentation. Portfolio piece covers Windows kernel driver security, IOCTL reverse engineering, and Bring Your Own Vulnerable Driver exploitation.",
            "summary": "Master's Thesis research on CVE-2024-51324 (BYOVD). Advanced exploit with 4 operational modes (SCANNER, LOADER, KILLER, CLEANUP), SHA-256 driver verification, and full academic documentation. Portfolio piece covers Windows kernel driver security, IOCTL reverse engineering, and Bring Your Own Vulnerable Driver exploitation.",
            "updated_at": "2026-09-12T22:00:00Z",
            "published_at": "2026-09-12T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 23,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · devianntsec/CVE-2024-51324",
                    "author": "devianntsec",
                    "first_seen": "2026-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Master's Thesis research on CVE-2024-51324 (BYOVD). Advanced exploit with 4 operational modes (SCANNER, LOADER, KILLER, CLEANUP), SHA-256 driver verification, and full academic documentation. Portfolio piece covers Windows kernel driver security, IOCTL reverse engineering, and Bring Your Own Vulnerable Driver exploitation.",
                    "summary": "Master's Thesis research on CVE-2024-51324 (BYOVD). Advanced exploit with 4 operational modes (SCANNER, LOADER, KILLER, CLEANUP), SHA-256 driver verification, and full academic documentation. Portfolio piece covers Windows kernel driver security, IOCTL reverse engineering, and Bring Your Own Vulnerable Driver exploitation.",
                    "url": "https://github.com/devianntsec/CVE-2024-51324"
                },
                {
                    "repository": "PoC-in-GitHub · uLl0a/bdapiutil-bydov",
                    "author": "uLl0a",
                    "first_seen": "2026-09-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "C++ Windows research tool for studying the BdApiUtil64.sys vulnerable driver and CVE-2024-51324",
                    "summary": "C++ Windows research tool for studying the BdApiUtil64.sys vulnerable driver and CVE-2024-51324",
                    "url": "https://github.com/uLl0a/bdapiutil-bydov"
                }
            ],
            "references": [
                "https://github.com/devianntsec/CVE-2024-51324",
                "https://github.com/uLl0a/bdapiutil-bydov"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/devianntsec/CVE-2024-51324"
                }
            ]
        },
        {
            "id": "CVE-2024-50986",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-50986 exploit",
            "summary": "Exploit for CVE-2024-50986. CVSS 7.3.",
            "updated_at": "2026-09-13T18:37:17Z",
            "published_at": "2026-09-13T18:37:17Z",
            "cvss": 7.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 27,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "DLL hijacking in Clementine v.1.3.1 via QUSEREX.DLL enables local code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-50986",
                    "summary": "DLL hijacking in Clementine v.1.3.1 via QUSEREX.DLL enables local code execution.",
                    "what_happened": "DLL hijacking in Clementine v.1.3.1 via QUSEREX.DLL enables local code execution.",
                    "cvss": 7.3,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RIFTSANDROSES-CVE-2024-50986",
                        "https://kitploit.com/ja/tools/github/riftsandroses/cve-2024-50986/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-11T13:55:48",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RIFTSANDROSES-CVE-2024-50986"
                },
                {
                    "title": "Exploit for CVE-2024-50986",
                    "summary": "DLL hijacking in Clementine v.1.3.1 via QUSEREX.DLL enables local code execution.",
                    "what_happened": "DLL hijacking in Clementine v.1.3.1 via QUSEREX.DLL enables local code execution.",
                    "cvss": 7.3,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RIFTSANDROSES-CVE-2024-50986",
                        "https://kitploit.com/ja/tools/github/riftsandroses/cve-2024-50986/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-11T13:55:48",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/riftsandroses/cve-2024-50986/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RIFTSANDROSES-CVE-2024-50986",
                "https://kitploit.com/ja/tools/github/riftsandroses/cve-2024-50986/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:37:17Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RIFTSANDROSES-CVE-2024-50986"
                }
            ]
        },
        {
            "id": "CVE-2024-50971",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2024-50971",
            "summary": "SQL injection in Itsourcecode Construction Management System 1.0 via map_id parameter in print.php.",
            "updated_at": "2026-08-25T02:15:14Z",
            "published_at": "2026-08-25T02:15:14Z",
            "cvss": 7.2,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 31,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "SQL injection in Itsourcecode Construction Management System 1.0 via map_id parameter in print.php.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-50971",
                    "summary": "SQL injection in Itsourcecode Construction Management System 1.0 via map_id parameter in print.php.",
                    "what_happened": "SQL injection in Itsourcecode Construction Management System 1.0 via map_id parameter in print.php.",
                    "cvss": 7.2,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AKHLAK2511-CVE-2024-50971",
                        "https://kitploit.com/ar/tools/github/akhlak2511/cve-2024-50971/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T04:15:14",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AKHLAK2511-CVE-2024-50971"
                },
                {
                    "title": "Exploit for CVE-2024-50971",
                    "summary": "SQL injection in Itsourcecode Construction Management System 1.0 via map_id parameter in print.php.",
                    "what_happened": "SQL injection in Itsourcecode Construction Management System 1.0 via map_id parameter in print.php.",
                    "cvss": 7.2,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AKHLAK2511-CVE-2024-50971",
                        "https://kitploit.com/ar/tools/github/akhlak2511/cve-2024-50971/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-08-25T04:15:14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/akhlak2511/cve-2024-50971/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AKHLAK2511-CVE-2024-50971",
                "https://kitploit.com/ar/tools/github/akhlak2511/cve-2024-50971/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T02:15:14Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AKHLAK2511-CVE-2024-50971"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2024-50961",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-50961 exploit",
            "summary": "Exploit for CVE-2024-50961.",
            "updated_at": "2026-09-12T15:05:48Z",
            "published_at": "2026-09-12T15:05:48Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T15:05:48+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2024-50961 exploit",
                    "summary": "Exploit for CVE-2024-50961.",
                    "cvss": 0,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FDZDEV-CVE-2024-50961"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FDZDEV-CVE-2024-50961"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T15:05:48Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FDZDEV-CVE-2024-50961"
                }
            ]
        },
        {
            "id": "CVE-2024-50475",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-50475 exploit",
            "summary": "Exploit for CVE-2024-50475. CVSS 9.8.",
            "updated_at": "2026-09-05T12:40:41Z",
            "published_at": "2026-09-05T12:40:41Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 43,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-05T12:40:41+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2024-50475 exploit",
                    "summary": "Exploit for CVE-2024-50475. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RANDOMROBBIEBF-CVE-2024-50475"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RANDOMROBBIEBF-CVE-2024-50475"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:40:41Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RANDOMROBBIEBF-CVE-2024-50475"
                }
            ]
        },
        {
            "id": "CVE-2024-50029",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_conn: Fix UAF in hci_enhanced_setup_sync\n\nThis checks if the ACL connection remains valid as it could be destroyed\nwhile hci_enhanced_setup_sync is pending on cmd_sync leading to the\nfollowing trace:\n\nBUG: KASAN: slab-use-after-free in hci_enhanced_setup_sync+0x91b/0xa60\nRead of size 1 at addr ffff888002328ffd by task kworker/u5:2/37\n\nCPU: 0 UID: 0 PID: 37 Comm: kworker/u5:2 Not tainted 6.11.0-rc6-01300-g810be445d8d6 #7099\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014\nWorkqueue: hci0 hci_cmd_sync_work\nCall Trace:\n <TASK>\n dump_stack_lvl+0x5d/0x80\n ? hci_enhanced_setup_sync+0x91b/0xa60\n print_report+0x152/0x4c0\n ? hci_enhanced_setup_sync+0x91b/0xa60\n ? __virt_addr_valid+0x1fa/0x420\n ? hci_enhanced_setup_sync+0x91b/0xa60\n kasan_report+0xda/0x1b0\n ? hci_enhanced_setup_sync+0x91b/0xa60\n hci_enhanced_setup_sync+0x91b/0xa60\n ? __pfx_hci_enhanced_setup_sync+0x10/0x10\n ? __pfx___mutex_lock+0x10/0x10\n hci_cmd_sync_work+0x1c2/0x330\n process_one_work+0x7d9/0x1360\n ? __pfx_lock_acquire+0x10/0x10\n ? __pfx_process_one_work+0x10/0x10\n ? assign_work+0x167/0x240\n worker_thread+0x5b7/0xf60\n ? __kthread_parkme+0xac/0x1c0\n ? __pfx_worker_thread+0x10/0x10\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x293/0x360\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2f/0x70\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n </TASK>\n\nAllocated by task 34:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0x8f/0xa0\n __hci_conn_add+0x187/0x17d0\n hci_connect_sco+0x2e1/0xb90\n sco_sock_connect+0x2a2/0xb80\n __sys_connect+0x227/0x2a0\n __x64_sys_connect+0x6d/0xb0\n do_syscall_64+0x71/0x140\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nFreed by task 37:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x101/0x160\n kfree+0xd0/0x250\n device_release+0x9a/0x210\n kobject_put+0x151/0x280\n hci_conn_del+0x448/0xbf0\n hci_abort_conn_sync+0x46f/0x980\n hci_cmd_sync_work+0x1c2/0x330\n process_one_work+0x7d9/0x1360\n worker_thread+0x5b7/0xf60\n kthread+0x293/0x360\n ret_from_fork+0x2f/0x70\n ret_from_fork_asm+0x1a/0x30",
            "updated_at": "2026-09-14T12:17:33.670",
            "published_at": "2024-10-21T20:15:16.227",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "e07a06b4eb417f5271d33ce2240e93c62d98b7b4 through before 9b666a0490379c860eab380dec19a864c0bc256b (git); e07a06b4eb417f5271d33ce2240e93c62d98b7b4 through before 867639300759e3e1c5b1e1a5ff89231f263a32a7 (git); e07a06b4eb417f5271d33ce2240e93c62d98b7b4 through before 98ccd44002d88cbf4edfc4480df532a3da5a013e (git); e07a06b4eb417f5271d33ce2240e93c62d98b7b4 through before 18fd04ad856df07733f5bb07e7f7168e7443d393 (git); 6.1",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_conn: Fix UAF in hci_enhanced_setup_sync\n\nThis checks if the ACL connection remains valid as it could be destroyed\nwhile hci_enhanced_setup_sync is pending on cmd_sync leading to the\nfollowing trace:\n\nBUG: KASAN: slab-use-after-free in hci_enhanced_setup_sync+0x91b/0xa60\nRead of size 1 at addr ffff888002328ffd by task kworker/u5:2/37\n\nCPU: 0 UID: 0 PID: 37 Comm: kworker/u5:2 Not tainted 6.11.0-rc6-01300-g810be445d8d6 #7099\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-2.fc40 04/01/2014\nWorkqueue: hci0 hci_cmd_sync_work\nCall Trace:\n <TASK>\n dump_stack_lvl+0x5d/0x80\n ? hci_enhanced_setup_sync+0x91b/0xa60\n print_report+0x152/0x4c0\n ? hci_enhanced_setup_sync+0x91b/0xa60\n ? __virt_addr_valid+0x1fa/0x420\n ? hci_enhanced_setup_sync+0x91b/0xa60\n kasan_report+0xda/0x1b0\n ? hci_enhanced_setup_sync+0x91b/0xa60\n hci_enhanced_setup_sync+0x91b/0xa60\n ? __pfx_hci_enhanced_setup_sync+0x10/0x10\n ? __pfx___mutex_lock+0x10/0x10\n hci_cmd_sync_work+0x1c2/0x330\n process_one_work+0x7d9/0x1360\n ? __pfx_lock_acquire+0x10/0x10\n ? __pfx_process_one_work+0x10/0x10\n ? assign_work+0x167/0x240\n worker_thread+0x5b7/0xf60\n ? __kthread_parkme+0xac/0x1c0\n ? __pfx_worker_thread+0x10/0x10\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x293/0x360\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2f/0x70\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n </TASK>\n\nAllocated by task 34:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0x8f/0xa0\n __hci_conn_add+0x187/0x17d0\n hci_connect_sco+0x2e1/0xb90\n sco_sock_connect+0x2a2/0xb80\n __sys_connect+0x227/0x2a0\n __x64_sys_connect+0x6d/0xb0\n do_syscall_64+0x71/0x140\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nFreed by task 37:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x101/0x160\n kfree+0xd0/0x250\n device_release+0x9a/0x210\n kobject_put+0x151/0x280\n hci_conn_del+0x448/0xbf0\n hci_abort_conn_sync+0x46f/0x980\n hci_cmd_sync_work+0x1c2/0x330\n process_one_work+0x7d9/0x1360\n worker_thread+0x5b7/0xf60\n kthread+0x293/0x360\n ret_from_fork+0x2f/0x70\n ret_from_fork_asm+0x1a/0x30",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/18fd04ad856df07733f5bb07e7f7168e7443d393",
                "https://git.kernel.org/stable/c/867639300759e3e1c5b1e1a5ff89231f263a32a7",
                "https://git.kernel.org/stable/c/98ccd44002d88cbf4edfc4480df532a3da5a013e",
                "https://git.kernel.org/stable/c/9b666a0490379c860eab380dec19a864c0bc256b"
            ],
            "timeline": [
                {
                    "at": "2024-10-21T20:15:16.227",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50029"
                }
            ]
        },
        {
            "id": "CVE-2024-50017",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm/ident_map: Use gbpages only where full GB page should be mapped.\n\nWhen ident_pud_init() uses only GB pages to create identity maps, large\nranges of addresses not actually requested can be included in the resulting\ntable; a 4K request will map a full GB.  This can include a lot of extra\naddress space past that requested, including areas marked reserved by the\nBIOS.  That allows processor speculation into reserved regions, that on UV\nsystems can cause system halts.\n\nOnly use GB pages when map creation requests include the full GB page of\nspace.  Fall back to using smaller 2M pages when only portions of a GB page\nare included in the request.\n\nNo attempt is made to coalesce mapping requests. If a request requires a\nmap entry at the 2M (pmd) level, subsequent mapping requests within the\nsame 1G region will also be at the pmd level, even if adjacent or\noverlapping such requests could have been combined to map a full GB page.\nExisting usage starts with larger regions and then adds smaller regions, so\nthis should not have any great consequence.",
            "updated_at": "2026-09-14T12:17:33.497",
            "published_at": "2024-10-21T19:15:05.043",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "66aad4fdf2bf0af29c7decb4433dc5ec6c7c5451 through before cb2555fb0223edac9e7820f16de17ae04a39ad39 (git); 66aad4fdf2bf0af29c7decb4433dc5ec6c7c5451 through before fe9bab1d6441ed49dc3dd0acce4c2215e8d85447 (git); 66aad4fdf2bf0af29c7decb4433dc5ec6c7c5451 through before d113f9723f2bfd9c6feeb899b8ddbee6b8a6e01f (git); 66aad4fdf2bf0af29c7decb4433dc5ec6c7c5451 through before d80a99892f7a992d103138fa4636b2c33abd6740 (git); 66aad4fdf2bf0af29c7decb4433dc5ec6c7c5451 through before a23823098ab2c277c14fc110b97d8d5c83597195 (git); 66aad4fdf2bf0af29c7decb4433dc5ec6c7c5451 through before cc31744a294584a36bf764a0ffa3255a8e69f036 (git); 4.12",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/mm/ident_map: Use gbpages only where full GB page should be mapped.\n\nWhen ident_pud_init() uses only GB pages to create identity maps, large\nranges of addresses not actually requested can be included in the resulting\ntable; a 4K request will map a full GB.  This can include a lot of extra\naddress space past that requested, including areas marked reserved by the\nBIOS.  That allows processor speculation into reserved regions, that on UV\nsystems can cause system halts.\n\nOnly use GB pages when map creation requests include the full GB page of\nspace.  Fall back to using smaller 2M pages when only portions of a GB page\nare included in the request.\n\nNo attempt is made to coalesce mapping requests. If a request requires a\nmap entry at the 2M (pmd) level, subsequent mapping requests within the\nsame 1G region will also be at the pmd level, even if adjacent or\noverlapping such requests could have been combined to map a full GB page.\nExisting usage starts with larger regions and then adds smaller regions, so\nthis should not have any great consequence.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/a23823098ab2c277c14fc110b97d8d5c83597195",
                "https://git.kernel.org/stable/c/cb2555fb0223edac9e7820f16de17ae04a39ad39",
                "https://git.kernel.org/stable/c/cc31744a294584a36bf764a0ffa3255a8e69f036",
                "https://git.kernel.org/stable/c/d113f9723f2bfd9c6feeb899b8ddbee6b8a6e01f",
                "https://git.kernel.org/stable/c/d80a99892f7a992d103138fa4636b2c33abd6740",
                "https://git.kernel.org/stable/c/fe9bab1d6441ed49dc3dd0acce4c2215e8d85447"
            ],
            "timeline": [
                {
                    "at": "2024-10-21T19:15:05.043",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50017"
                }
            ]
        },
        {
            "id": "CVE-2024-49138",
            "vendor": "Microsoft",
            "product": "Windows",
            "title": "Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 476,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52270",
                    "author": "Milad karimi",
                    "first_seen": "2025-04-22",
                    "confidence": "High",
                    "title": "Microsoft Windows 11 23h2 - CLFS.sys Elevation of Privilege",
                    "summary": "Microsoft Windows 11 23h2 - CLFS.sys Elevation of Privilege",
                    "url": "https://www.exploit-db.com/exploits/52270",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · MrAle98/CVE-2024-49138-POC",
                    "author": "MrAle98",
                    "first_seen": "2025-01-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 271,
                    "title": "POC exploit for CVE-2024-49138",
                    "summary": "POC exploit for CVE-2024-49138",
                    "url": "https://github.com/MrAle98/CVE-2024-49138-POC"
                },
                {
                    "repository": "PoC-in-GitHub · bananoname/CVE-2024-49138-POC",
                    "author": "bananoname",
                    "first_seen": "2025-01-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-49138 repository",
                    "summary": "",
                    "url": "https://github.com/bananoname/CVE-2024-49138-POC"
                },
                {
                    "repository": "PoC-in-GitHub · DeividasTerechovas/SOC335-CVE-2024-49138-Exploitation-Detected",
                    "author": "DeividasTerechovas",
                    "first_seen": "2025-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-49138 repository",
                    "summary": "",
                    "url": "https://github.com/DeividasTerechovas/SOC335-CVE-2024-49138-Exploitation-Detected"
                },
                {
                    "repository": "PoC-in-GitHub · CyprianAtsyor/letsdefend-cve-2024-49138-investigation",
                    "author": "CyprianAtsyor",
                    "first_seen": "2025-04-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Hands-on SOC investigation of CVE-2024-49138 using LetsDefend, VirusTotal, Hybrid Analysis, TrueFort, and ChatGPT.",
                    "summary": "Hands-on SOC investigation of CVE-2024-49138 using LetsDefend, VirusTotal, Hybrid Analysis, TrueFort, and ChatGPT.",
                    "url": "https://github.com/CyprianAtsyor/letsdefend-cve-2024-49138-investigation"
                },
                {
                    "repository": "PoC-in-GitHub · Bridg3Ops/SOC335-CVE-2024-49138-Exploitation-Detected",
                    "author": "Bridg3Ops",
                    "first_seen": "2025-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-49138 repository",
                    "summary": "",
                    "url": "https://github.com/Bridg3Ops/SOC335-CVE-2024-49138-Exploitation-Detected"
                },
                {
                    "repository": "PoC-in-GitHub · onixgod/SOC335-Event-ID-313-CVE-2024-49138-Exploitation-Detected--Lest-Defend-Writeup",
                    "author": "onixgod",
                    "first_seen": "2025-06-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "In this lab I walked through an end-to-end intrusion that began with an external RDP break-in, used a brand-new CLFS privilege-escalation exploit (CVE-2024–49138), and ended with SYSTEM-level cloud credential harvesting. Below is the story, the evidence, and the lessons I drew from it.",
                    "summary": "In this lab I walked through an end-to-end intrusion that began with an external RDP break-in, used a brand-new CLFS privilege-escalation exploit (CVE-2024–49138), and ended with SYSTEM-level cloud credential harvesting. Below is the story, the evidence, and the lessons I drew from it.",
                    "url": "https://github.com/onixgod/SOC335-Event-ID-313-CVE-2024-49138-Exploitation-Detected--Lest-Defend-Writeup"
                },
                {
                    "repository": "PoC-in-GitHub · Zedocun/soc-investigation-powershell-edrfreeze",
                    "author": "Zedocun",
                    "first_seen": "2026-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated environment.",
                    "summary": "SOC investigation of CVE-2024-49138 exploitation alert involving PowerShell, EDRFreeze execution, and defense evasion behavior in a simulated environment.",
                    "url": "https://github.com/Zedocun/soc-investigation-powershell-edrfreeze"
                },
                {
                    "repository": "PoC-in-GitHub · vettrivel007/CVE-2024-49138",
                    "author": "vettrivel007",
                    "first_seen": "2026-04-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-49138 repository",
                    "summary": "",
                    "url": "https://github.com/vettrivel007/CVE-2024-49138"
                },
                {
                    "repository": "PoC-in-GitHub · basitsajidapply-stack/SOC-Investigation-CVE-2024-49138",
                    "author": "basitsajidapply-stack",
                    "first_seen": "2026-08-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)",
                    "summary": "Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)",
                    "url": "https://github.com/basitsajidapply-stack/SOC-Investigation-CVE-2024-49138"
                },
                {
                    "repository": "PoC-in-GitHub · NadineElliottCyber/SOC335-CVE-2024-49138-Investigation",
                    "author": "NadineElliottCyber",
                    "first_seen": "2026-08-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.",
                    "summary": "SOC investigation of a CVE-2024-49138 exploitation alert using log analysis, threat intelligence, and endpoint containment.",
                    "url": "https://github.com/NadineElliottCyber/SOC335-CVE-2024-49138-Investigation"
                },
                {
                    "repository": "PoC-in-GitHub · Adisasoc/CVE-2024-49138-SOC-Investigation",
                    "author": "Adisasoc",
                    "first_seen": "2026-09-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "SOC investigation of CVE-2024-49138 exploitation involving brute-force activity, PowerShell execution, malicious payload analysis, privilege escalation, and incident response.",
                    "summary": "SOC investigation of CVE-2024-49138 exploitation involving brute-force activity, PowerShell execution, malicious payload analysis, privilege escalation, and incident response.",
                    "url": "https://github.com/Adisasoc/CVE-2024-49138-SOC-Investigation"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52270",
                "https://github.com/MrAle98/CVE-2024-49138-POC",
                "https://github.com/bananoname/CVE-2024-49138-POC",
                "https://github.com/DeividasTerechovas/SOC335-CVE-2024-49138-Exploitation-Detected",
                "https://github.com/CyprianAtsyor/letsdefend-cve-2024-49138-investigation",
                "https://github.com/Bridg3Ops/SOC335-CVE-2024-49138-Exploitation-Detected",
                "https://github.com/onixgod/SOC335-Event-ID-313-CVE-2024-49138-Exploitation-Detected--Lest-Defend-Writeup",
                "https://github.com/Zedocun/soc-investigation-powershell-edrfreeze",
                "https://github.com/vettrivel007/CVE-2024-49138",
                "https://github.com/basitsajidapply-stack/SOC-Investigation-CVE-2024-49138",
                "https://github.com/NadineElliottCyber/SOC335-CVE-2024-49138-Investigation",
                "https://github.com/Adisasoc/CVE-2024-49138-SOC-Investigation"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2024-45163",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized username (such as root), or can send arbitrary data.",
            "updated_at": "2026-09-16T21:17:06.310",
            "published_at": "2024-08-22T04:15:20.247",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a; 0 through 2024-08-19 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized username (such as root), or can send arbitrary data.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://cypressthatkid.medium.com/remote-dos-exploit-found-in-mirai-botnet-source-code-27a1aad284f1",
                "https://flowtriq.com/blog/cve-2024-45163-mirai-botnet-kill-switch",
                "https://pastebin.com/6tqHnCva",
                "https://traztech.ca/research",
                "https://youtu.be/aJkvSr85ML8"
            ],
            "timeline": [
                {
                    "at": "2024-08-22T04:15:20.247",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45163"
                }
            ]
        },
        {
            "id": "CVE-2024-44258",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-44258 exploit",
            "summary": "Exploit for CVE-2024-44258. CVSS 7.1.",
            "updated_at": "2026-09-08T01:13:58Z",
            "published_at": "2026-09-08T01:13:58Z",
            "cvss": 7.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 67,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-08T01:13:58+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2024-44258 exploit",
                    "summary": "Exploit for CVE-2024-44258. CVSS 7.1.",
                    "cvss": 7.1,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IFPDZ-CVE-2024-44258"
                },
                {
                    "repository": "PoC-in-GitHub · ifpdz/CVE-2024-44258",
                    "author": "ifpdz",
                    "first_seen": "2024-10-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 91,
                    "title": "CVE-2024-44258",
                    "summary": "CVE-2024-44258",
                    "url": "https://github.com/ifpdz/CVE-2024-44258"
                },
                {
                    "repository": "PoC-in-GitHub · missaels235/POC-CVE-2024-44258-Py",
                    "author": "missaels235",
                    "first_seen": "2025-05-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2024-44258 repository",
                    "summary": "",
                    "url": "https://github.com/missaels235/POC-CVE-2024-44258-Py"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IFPDZ-CVE-2024-44258",
                "https://github.com/ifpdz/CVE-2024-44258",
                "https://github.com/missaels235/POC-CVE-2024-44258-Py"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:13:58Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IFPDZ-CVE-2024-44258"
                }
            ]
        },
        {
            "id": "CVE-2024-43570",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "KTM_POCS exploit",
            "summary": "Exploit for CVE-2024-43535 and CVE-2024-43570. CVSS 7.",
            "updated_at": "2026-09-13T18:21:12Z",
            "published_at": "2026-09-13T18:21:12Z",
            "cvss": 7,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:21:12+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "KTM_POCS exploit",
                    "summary": "Exploit for CVE-2024-43535 and CVE-2024-43570. CVSS 7.",
                    "cvss": 7,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAYESTHER-KTM_POCS"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAYESTHER-KTM_POCS"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:21:12Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAYESTHER-KTM_POCS"
                }
            ]
        },
        {
            "id": "CVE-2024-43535",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "KTM_POCS exploit",
            "summary": "Exploit for CVE-2024-43535 and CVE-2024-43570. CVSS 7.",
            "updated_at": "2026-09-13T18:21:12Z",
            "published_at": "2026-09-13T18:21:12Z",
            "cvss": 7,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:21:12+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "KTM_POCS exploit",
                    "summary": "Exploit for CVE-2024-43535 and CVE-2024-43570. CVSS 7.",
                    "cvss": 7,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAYESTHER-KTM_POCS"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAYESTHER-KTM_POCS"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:21:12Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAYESTHER-KTM_POCS"
                }
            ]
        },
        {
            "id": "CVE-2024-42461",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-42461 exploit",
            "summary": "Exploit for CVE-2024-42461. CVSS 9.1.",
            "updated_at": "2026-09-14T18:32:41Z",
            "published_at": "2026-09-14T18:32:41Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 19,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "ECDSA/EDDSA signature verification flaw in elliptic library allows zero-byte manipulation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-42461",
                    "summary": "ECDSA/EDDSA signature verification flaw in elliptic library allows zero-byte manipulation.",
                    "what_happened": "ECDSA/EDDSA signature verification flaw in elliptic library allows zero-byte manipulation.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FEVAR54-CVE-2024-42461",
                        "https://kitploit.com/ru/tools/github/fevar54/cve-2024-42461/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T00:24:53",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FEVAR54-CVE-2024-42461"
                },
                {
                    "title": "Exploit for CVE-2024-42461",
                    "summary": "ECDSA/EDDSA signature verification flaw in elliptic library allows zero-byte manipulation.",
                    "what_happened": "ECDSA/EDDSA signature verification flaw in elliptic library allows zero-byte manipulation.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FEVAR54-CVE-2024-42461",
                        "https://kitploit.com/ru/tools/github/fevar54/cve-2024-42461/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T00:24:53",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/fevar54/cve-2024-42461/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FEVAR54-CVE-2024-42461",
                "https://kitploit.com/ru/tools/github/fevar54/cve-2024-42461/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T18:32:41Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FEVAR54-CVE-2024-42461"
                }
            ]
        },
        {
            "id": "CVE-2024-42392",
            "vendor": "Cesanta",
            "product": "Mongoose Web Server",
            "title": "Mongoose Web Server vulnerability",
            "summary": "Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.",
            "updated_at": "2026-09-08T09:17:18.617",
            "published_at": "2024-11-18T10:15:08.753",
            "cvss": 4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 7.14 (semver); before V2.70 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-140",
            "what_happened": "Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42392",
                "https://cert-portal.siemens.com/productcert/html/ssa-142885.html"
            ],
            "timeline": [
                {
                    "at": "2024-11-18T10:15:08.753",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42392"
                }
            ]
        },
        {
            "id": "CVE-2024-42391",
            "vendor": "Cesanta",
            "product": "Mongoose Web Server",
            "title": "Mongoose Web Server vulnerability",
            "summary": "Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.",
            "updated_at": "2026-09-08T09:17:18.303",
            "published_at": "2024-11-18T10:15:08.540",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 7.14 (semver); before V2.70 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-823",
            "what_happened": "Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42391",
                "https://cert-portal.siemens.com/productcert/html/ssa-142885.html"
            ],
            "timeline": [
                {
                    "at": "2024-11-18T10:15:08.540",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42391"
                }
            ]
        },
        {
            "id": "CVE-2024-42386",
            "vendor": "Cesanta",
            "product": "Mongoose Web Server",
            "title": "Mongoose Web Server vulnerability",
            "summary": "Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.",
            "updated_at": "2026-09-08T09:17:18.023",
            "published_at": "2024-11-18T10:15:07.427",
            "cvss": 8.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 7.14 (semver); 0 through 7.1.4 (semver); before V2.70 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-823",
            "what_happened": "Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42386",
                "https://cert-portal.siemens.com/productcert/html/ssa-142885.html"
            ],
            "timeline": [
                {
                    "at": "2024-11-18T10:15:07.427",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42386"
                }
            ]
        },
        {
            "id": "CVE-2024-42385",
            "vendor": "Cesanta",
            "product": "Mongoose Web Server",
            "title": "Mongoose Web Server vulnerability",
            "summary": "Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.",
            "updated_at": "2026-09-08T09:17:17.737",
            "published_at": "2024-11-18T10:15:07.187",
            "cvss": 4,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 7.14 (semver); before V2.70 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-140",
            "what_happened": "Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-42385",
                "https://cert-portal.siemens.com/productcert/html/ssa-142885.html"
            ],
            "timeline": [
                {
                    "at": "2024-11-18T10:15:07.187",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42385"
                }
            ]
        },
        {
            "id": "CVE-2024-42384",
            "vendor": "Cesanta",
            "product": "Mongoose Web Server",
            "title": "Mongoose Web Server vulnerability",
            "summary": "Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.",
            "updated_at": "2026-09-08T09:17:17.430",
            "published_at": "2024-11-18T10:15:06.943",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 7.14 (semver); 0 through 7.1.4 (semver); before V2.70 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.nozominetworks.com/blog",
                "https://cert-portal.siemens.com/productcert/html/ssa-142885.html"
            ],
            "timeline": [
                {
                    "at": "2024-11-18T10:15:06.943",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42384"
                }
            ]
        },
        {
            "id": "CVE-2024-41062",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbluetooth/l2cap: sync sock recv cb and release\n\nThe problem occurs between the system call to close the sock and hci_rx_work,\nwhere the former releases the sock and the latter accesses it without lock protection.\n\n           CPU0                       CPU1\n           ----                       ----\n           sock_close                 hci_rx_work\n\t   l2cap_sock_release         hci_acldata_packet\n\t   l2cap_sock_kill            l2cap_recv_frame\n\t   sk_free                    l2cap_conless_channel\n\t                              l2cap_sock_recv_cb\n\nIf hci_rx_work processes the data that needs to be received before the sock is\nclosed, then everything is normal; Otherwise, the work thread may access the\nreleased sock when receiving data.\n\nAdd a chan mutex in the rx callback of the sock to achieve synchronization between\nthe sock release and recv cb.\n\nSock is dead, so set chan data to NULL, avoid others use invalid sock pointer.",
            "updated_at": "2026-09-14T12:17:33.270",
            "published_at": "2024-07-29T15:15:14.173",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5b4cedaa14bd1fe3ca1d59c684203a6ae7747faa through before 2243127db6ba20cbef90c6349a2b1000af401d2e (git); 5b4cedaa14bd1fe3ca1d59c684203a6ae7747faa through before 605572e64cd9cebb05ed609d96cff05b50d18cdf (git); 5b4cedaa14bd1fe3ca1d59c684203a6ae7747faa through before b803f30ea23e0968b6c8285c42adf0d862ab2bf6 (git); 5b4cedaa14bd1fe3ca1d59c684203a6ae7747faa through before 3b732449b78183d17178db40be3a4401cf3cd629 (git); 5b4cedaa14bd1fe3ca1d59c684203a6ae7747faa through before 89e856e124f9ae548572c56b1b70c2255705f8fe (git); 3.4",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nbluetooth/l2cap: sync sock recv cb and release\n\nThe problem occurs between the system call to close the sock and hci_rx_work,\nwhere the former releases the sock and the latter accesses it without lock protection.\n\n           CPU0                       CPU1\n           ----                       ----\n           sock_close                 hci_rx_work\n\t   l2cap_sock_release         hci_acldata_packet\n\t   l2cap_sock_kill            l2cap_recv_frame\n\t   sk_free                    l2cap_conless_channel\n\t                              l2cap_sock_recv_cb\n\nIf hci_rx_work processes the data that needs to be received before the sock is\nclosed, then everything is normal; Otherwise, the work thread may access the\nreleased sock when receiving data.\n\nAdd a chan mutex in the rx callback of the sock to achieve synchronization between\nthe sock release and recv cb.\n\nSock is dead, so set chan data to NULL, avoid others use invalid sock pointer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/2243127db6ba20cbef90c6349a2b1000af401d2e",
                "https://git.kernel.org/stable/c/3b732449b78183d17178db40be3a4401cf3cd629",
                "https://git.kernel.org/stable/c/605572e64cd9cebb05ed609d96cff05b50d18cdf",
                "https://git.kernel.org/stable/c/89e856e124f9ae548572c56b1b70c2255705f8fe",
                "https://git.kernel.org/stable/c/b803f30ea23e0968b6c8285c42adf0d862ab2bf6",
                "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
            ],
            "timeline": [
                {
                    "at": "2024-07-29T15:15:14.173",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41062"
                }
            ]
        },
        {
            "id": "CVE-2024-40443",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-40443 exploit",
            "summary": "Exploit for CVE-2024-40443. CVSS 4.3.",
            "updated_at": "2026-09-15T08:28:07Z",
            "published_at": "2026-09-15T08:28:07Z",
            "cvss": 4.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-15T08:28:07+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2024-40443 exploit",
                    "summary": "Exploit for CVE-2024-40443. CVSS 4.3.",
                    "cvss": 4.3,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YUMA-TSUSHIMA07-CVE-2024-40443"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YUMA-TSUSHIMA07-CVE-2024-40443"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:28:07Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YUMA-TSUSHIMA07-CVE-2024-40443"
                }
            ]
        },
        {
            "id": "CVE-2024-39700",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-39700 Proof of Concept",
            "summary": "CVE-2024-39700 Proof of Concept",
            "updated_at": "2026-08-31T22:00:00Z",
            "published_at": "2026-08-31T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 71,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · LOURC0D3/CVE-2024-39700-PoC",
                    "author": "LOURC0D3",
                    "first_seen": "2024-07-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-39700 Proof of Concept",
                    "summary": "CVE-2024-39700 Proof of Concept",
                    "url": "https://github.com/LOURC0D3/CVE-2024-39700-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · pvharmo2/gha-lab-0ba60e6456",
                    "author": "pvharmo2",
                    "first_seen": "2026-09-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Authorized security-research lab reproducing CVE-2024-39700 / GHSA-45gq-v5wm-82wg (JupyterLab extension-template update-integration-tests pwn request)",
                    "summary": "Authorized security-research lab reproducing CVE-2024-39700 / GHSA-45gq-v5wm-82wg (JupyterLab extension-template update-integration-tests pwn request)",
                    "url": "https://github.com/pvharmo2/gha-lab-0ba60e6456"
                }
            ],
            "references": [
                "https://github.com/LOURC0D3/CVE-2024-39700-PoC",
                "https://github.com/pvharmo2/gha-lab-0ba60e6456"
            ],
            "timeline": [
                {
                    "at": "2026-08-31T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/LOURC0D3/CVE-2024-39700-PoC"
                }
            ]
        },
        {
            "id": "CVE-2024-38821",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Forced Browsing in Vmware Spring_Security CVE-2026-22732",
            "summary": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "updated_at": "2026-09-11T11:16:21Z",
            "published_at": "2026-09-11T11:16:21Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-425",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Forced Browsing in Vmware Spring_Security CVE-2026-22732",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-425",
                    "references": [
                        "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE",
                        "https://github.com/dylan-chainguard/cve-2026-22732-poc"
                    ],
                    "repository": "Sploitus",
                    "author": "dylan-chainguard",
                    "first_seen": "2026-09-11T13:16:21",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE"
                },
                {
                    "title": "Exploit for Forced Browsing in Vmware Spring_Security CVE-2026-22732",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-425",
                    "references": [
                        "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE",
                        "https://github.com/dylan-chainguard/cve-2026-22732-poc"
                    ],
                    "repository": "dylan-chainguard/cve-2026-22732-poc",
                    "author": "dylan-chainguard",
                    "first_seen": "2026-09-11T13:16:21",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/dylan-chainguard/cve-2026-22732-poc"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE",
                "https://github.com/dylan-chainguard/cve-2026-22732-poc"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T11:16:21Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2024-38063",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "mitigation script by disabling ipv6 of all interfaces",
            "summary": "mitigation script by disabling ipv6 of all interfaces",
            "updated_at": "2026-09-05T22:00:00Z",
            "published_at": "2026-09-05T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 417,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · diegoalbuquerque/CVE-2024-38063",
                    "author": "diegoalbuquerque",
                    "first_seen": "2024-08-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "mitigation script by disabling ipv6 of all interfaces",
                    "summary": "mitigation script by disabling ipv6 of all interfaces",
                    "url": "https://github.com/diegoalbuquerque/CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · Sachinart/CVE-2024-38063-poc",
                    "author": "Sachinart",
                    "first_seen": "2024-08-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 86,
                    "title": "Note: I am not responsible for any bad act. This is written by Chirag Artani to demonstrate the vulnerability.",
                    "summary": "Note: I am not responsible for any bad act. This is written by Chirag Artani to demonstrate the vulnerability.",
                    "url": "https://github.com/Sachinart/CVE-2024-38063-poc"
                },
                {
                    "repository": "PoC-in-GitHub · dweger-scripts/CVE-2024-38063-Remediation",
                    "author": "dweger-scripts",
                    "first_seen": "2024-08-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-38063 repository",
                    "summary": "",
                    "url": "https://github.com/dweger-scripts/CVE-2024-38063-Remediation"
                },
                {
                    "repository": "PoC-in-GitHub · almogopp/Disable-IPv6-CVE-2024-38063-Fix",
                    "author": "almogopp",
                    "first_seen": "2024-08-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the registry to reduce the risk of exploitation without needing the immediate installation of the official Microsoft KB update. Intended as a temporary fix",
                    "summary": "A PowerShell script to temporarily mitigate the CVE-2024-38063 vulnerability by disabling IPv6 on Windows systems. This workaround modifies the registry to reduce the risk of exploitation without needing the immediate installation of the official Microsoft KB update. Intended as a temporary fix",
                    "url": "https://github.com/almogopp/Disable-IPv6-CVE-2024-38063-Fix"
                },
                {
                    "repository": "PoC-in-GitHub · Th3Tr1ckst3r/CVE-2024-38063",
                    "author": "Th3Tr1ckst3r",
                    "first_seen": "2024-08-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2024-38063 research so you don't have to.",
                    "summary": "CVE-2024-38063 research so you don't have to.",
                    "url": "https://github.com/Th3Tr1ckst3r/CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · ynwarcs/CVE-2024-38063",
                    "author": "ynwarcs",
                    "first_seen": "2024-08-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 691,
                    "title": "poc for CVE-2024-38063 (RCE in tcpip.sys)",
                    "summary": "poc for CVE-2024-38063 (RCE in tcpip.sys)",
                    "url": "https://github.com/ynwarcs/CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · patchpoint/CVE-2024-38063",
                    "author": "patchpoint",
                    "first_seen": "2024-08-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 20,
                    "title": "CVE-2024-38063 repository",
                    "summary": "",
                    "url": "https://github.com/patchpoint/CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · PumpkinBridge/Windows-CVE-2024-38063",
                    "author": "PumpkinBridge",
                    "first_seen": "2024-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Windows TCP/IP IPv6(CVE-2024-38063)",
                    "summary": "Windows TCP/IP IPv6(CVE-2024-38063)",
                    "url": "https://github.com/PumpkinBridge/Windows-CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · zenzue/CVE-2024-38063-POC",
                    "author": "zenzue",
                    "first_seen": "2024-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "potential memory corruption vulnerabilities in IPv6 networks.",
                    "summary": "potential memory corruption vulnerabilities in IPv6 networks.",
                    "url": "https://github.com/zenzue/CVE-2024-38063-POC"
                },
                {
                    "repository": "PoC-in-GitHub · AdminPentester/CVE-2024-38063-",
                    "author": "AdminPentester",
                    "first_seen": "2024-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Remotely Exploiting The Kernel Via IPv6",
                    "summary": "Remotely Exploiting The Kernel Via IPv6",
                    "url": "https://github.com/AdminPentester/CVE-2024-38063-"
                },
                {
                    "repository": "PoC-in-GitHub · ThemeHackers/CVE-2024-38063",
                    "author": "ThemeHackers",
                    "first_seen": "2024-08-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 44,
                    "title": "CVE-2024-38063 is a critical security vulnerability in the Windows TCP/IP stack that allows for remote code execution (RCE)",
                    "summary": "CVE-2024-38063 is a critical security vulnerability in the Windows TCP/IP stack that allows for remote code execution (RCE)",
                    "url": "https://github.com/ThemeHackers/CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · KernelKraze/CVE-2024-38063_PoC",
                    "author": "KernelKraze",
                    "first_seen": "2024-09-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "This is a C language program designed to test the Windows TCP/IP Remote Code Execution Vulnerability (CVE-2024-38063). It sends specially crafted IPv6 packets with embedded shellcode to exploit the vulnerability.",
                    "summary": "This is a C language program designed to test the Windows TCP/IP Remote Code Execution Vulnerability (CVE-2024-38063). It sends specially crafted IPv6 packets with embedded shellcode to exploit the vulnerability.",
                    "url": "https://github.com/KernelKraze/CVE-2024-38063_PoC"
                },
                {
                    "repository": "PoC-in-GitHub · ps-interactive/cve-2024-38063",
                    "author": "ps-interactive",
                    "first_seen": "2024-09-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-38063 repository",
                    "summary": "",
                    "url": "https://github.com/ps-interactive/cve-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · brownpanda29/Cve-2024-38063",
                    "author": "brownpanda29",
                    "first_seen": "2024-09-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-38063 repository",
                    "summary": "",
                    "url": "https://github.com/brownpanda29/Cve-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · FrancescoDiSalesGithub/quick-fix-cve-2024-38063",
                    "author": "FrancescoDiSalesGithub",
                    "first_seen": "2024-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "quick powershell script to fix cve-2024-38063",
                    "summary": "quick powershell script to fix cve-2024-38063",
                    "url": "https://github.com/FrancescoDiSalesGithub/quick-fix-cve-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · Faizan-Khanx/CVE-2024-38063",
                    "author": "Faizan-Khanx",
                    "first_seen": "2024-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6",
                    "summary": "CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6",
                    "url": "https://github.com/Faizan-Khanx/CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · ArenaldyP/CVE-2024-38063-Medium",
                    "author": "ArenaldyP",
                    "first_seen": "2024-09-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Kode Eksploitasi CVE-2024-38063",
                    "summary": "Kode Eksploitasi CVE-2024-38063",
                    "url": "https://github.com/ArenaldyP/CVE-2024-38063-Medium"
                },
                {
                    "repository": "PoC-in-GitHub · becrevex/CVE-2024-38063",
                    "author": "becrevex",
                    "first_seen": "2024-10-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Performs an IPv6 vulnerability scan and packet flood attack on specified targets. The script simulates a SYN flood and ICMP flood attack and optionally sends exploit packets.",
                    "summary": "Performs an IPv6 vulnerability scan and packet flood attack on specified targets. The script simulates a SYN flood and ICMP flood attack and optionally sends exploit packets.",
                    "url": "https://github.com/becrevex/CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · idkwastaken/CVE-2024-38063",
                    "author": "idkwastaken",
                    "first_seen": "2024-10-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-38063 repository",
                    "summary": "",
                    "url": "https://github.com/idkwastaken/CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · thanawee321/CVE-2024-38063",
                    "author": "thanawee321",
                    "first_seen": "2024-10-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Vulnerability CVE-2024-38063",
                    "summary": "Vulnerability CVE-2024-38063",
                    "url": "https://github.com/thanawee321/CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · AliHj98/cve-2024-38063-Anonyvader",
                    "author": "AliHj98",
                    "first_seen": "2024-11-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-38063 repository",
                    "summary": "",
                    "url": "https://github.com/AliHj98/cve-2024-38063-Anonyvader"
                },
                {
                    "repository": "PoC-in-GitHub · Dragkob/CVE-2024-38063",
                    "author": "Dragkob",
                    "first_seen": "2024-11-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "PoC for Windows' IPv6 CVE-2024-38063",
                    "summary": "PoC for Windows' IPv6 CVE-2024-38063",
                    "url": "https://github.com/Dragkob/CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · fredagsguf/Windows-CVE-2024-38063",
                    "author": "fredagsguf",
                    "first_seen": "2024-12-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-38063 repository",
                    "summary": "",
                    "url": "https://github.com/fredagsguf/Windows-CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · jip-0-0-0-0-0/CVE-2024-38063-scanner",
                    "author": "jip-0-0-0-0-0",
                    "first_seen": "2025-01-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A Python tool leveraging Shodan and Scapy to identify and exploit Windows systems vulnerable to CVE-2024-38063, enabling targeted Denial of Service attacks",
                    "summary": "A Python tool leveraging Shodan and Scapy to identify and exploit Windows systems vulnerable to CVE-2024-38063, enabling targeted Denial of Service attacks",
                    "url": "https://github.com/jip-0-0-0-0-0/CVE-2024-38063-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · Skac44/CVE-2024-38063",
                    "author": "Skac44",
                    "first_seen": "2025-07-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-38063 repository",
                    "summary": "",
                    "url": "https://github.com/Skac44/CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · thealice01/CVE-2024-38063",
                    "author": "thealice01",
                    "first_seen": "2026-01-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "SSP H3",
                    "summary": "SSP H3",
                    "url": "https://github.com/thealice01/CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · AvidanMaatuk/CVE-2024-38063",
                    "author": "AvidanMaatuk",
                    "first_seen": "2026-01-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC exploit and technical analysis for CVE-2024-38063 in the Windows IPv6 stack, built with Python and Scapy",
                    "summary": "PoC exploit and technical analysis for CVE-2024-38063 in the Windows IPv6 stack, built with Python and Scapy",
                    "url": "https://github.com/AvidanMaatuk/CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · arrhenius975/CVE-2024-38063-Exploit-Refactoring",
                    "author": "arrhenius975",
                    "first_seen": "2026-03-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-38063 repository",
                    "summary": "",
                    "url": "https://github.com/arrhenius975/CVE-2024-38063-Exploit-Refactoring"
                },
                {
                    "repository": "PoC-in-GitHub · SALMA-ESSAOUD/CVE-CVSS--CVE-2024-38063-IPv6-TCP-IP-Remote-Code-Execution-Analysis",
                    "author": "SALMA-ESSAOUD",
                    "first_seen": "2026-03-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-38063 repository",
                    "summary": "",
                    "url": "https://github.com/SALMA-ESSAOUD/CVE-CVSS--CVE-2024-38063-IPv6-TCP-IP-Remote-Code-Execution-Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · RohitMalik7/cve-2024-38063-detection-mitigation-system",
                    "author": "RohitMalik7",
                    "first_seen": "2026-04-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "End-to-end cybersecurity project demonstrating detection and mitigation of CVE-2024-38063 using IDS, host-based monitoring, and virtual lab attack simulation.",
                    "summary": "End-to-end cybersecurity project demonstrating detection and mitigation of CVE-2024-38063 using IDS, host-based monitoring, and virtual lab attack simulation.",
                    "url": "https://github.com/RohitMalik7/cve-2024-38063-detection-mitigation-system"
                },
                {
                    "repository": "PoC-in-GitHub · Mayank637-pixel/CVE-2024-38063",
                    "author": "Mayank637-pixel",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-38063 repository",
                    "summary": "",
                    "url": "https://github.com/Mayank637-pixel/CVE-2024-38063"
                },
                {
                    "repository": "PoC-in-GitHub · hibaNITT/CVE-2024-38063",
                    "author": "hibaNITT",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-38063 repository",
                    "summary": "",
                    "url": "https://github.com/hibaNITT/CVE-2024-38063"
                }
            ],
            "references": [
                "https://github.com/diegoalbuquerque/CVE-2024-38063",
                "https://github.com/Sachinart/CVE-2024-38063-poc",
                "https://github.com/dweger-scripts/CVE-2024-38063-Remediation",
                "https://github.com/almogopp/Disable-IPv6-CVE-2024-38063-Fix",
                "https://github.com/Th3Tr1ckst3r/CVE-2024-38063",
                "https://github.com/ynwarcs/CVE-2024-38063",
                "https://github.com/patchpoint/CVE-2024-38063",
                "https://github.com/PumpkinBridge/Windows-CVE-2024-38063",
                "https://github.com/zenzue/CVE-2024-38063-POC",
                "https://github.com/AdminPentester/CVE-2024-38063-",
                "https://github.com/ThemeHackers/CVE-2024-38063",
                "https://github.com/KernelKraze/CVE-2024-38063_PoC",
                "https://github.com/ps-interactive/cve-2024-38063",
                "https://github.com/brownpanda29/Cve-2024-38063",
                "https://github.com/FrancescoDiSalesGithub/quick-fix-cve-2024-38063",
                "https://github.com/Faizan-Khanx/CVE-2024-38063",
                "https://github.com/ArenaldyP/CVE-2024-38063-Medium",
                "https://github.com/becrevex/CVE-2024-38063",
                "https://github.com/idkwastaken/CVE-2024-38063",
                "https://github.com/thanawee321/CVE-2024-38063",
                "https://github.com/AliHj98/cve-2024-38063-Anonyvader",
                "https://github.com/Dragkob/CVE-2024-38063",
                "https://github.com/fredagsguf/Windows-CVE-2024-38063",
                "https://github.com/jip-0-0-0-0-0/CVE-2024-38063-scanner",
                "https://github.com/Skac44/CVE-2024-38063",
                "https://github.com/thealice01/CVE-2024-38063",
                "https://github.com/AvidanMaatuk/CVE-2024-38063",
                "https://github.com/arrhenius975/CVE-2024-38063-Exploit-Refactoring",
                "https://github.com/SALMA-ESSAOUD/CVE-CVSS--CVE-2024-38063-IPv6-TCP-IP-Remote-Code-Execution-Analysis",
                "https://github.com/RohitMalik7/cve-2024-38063-detection-mitigation-system",
                "https://github.com/Mayank637-pixel/CVE-2024-38063",
                "https://github.com/hibaNITT/CVE-2024-38063"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/diegoalbuquerque/CVE-2024-38063"
                }
            ]
        },
        {
            "id": "CVE-2024-37890",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Автоатакующий скрипт на базе эксплойтов CVE-2024-37890 и OOM 2026",
            "summary": "Автоатакующий скрипт на базе эксплойтов CVE-2024-37890 и OOM 2026",
            "updated_at": "2026-09-09T22:00:00Z",
            "published_at": "2026-09-09T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 24,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · RazdoruNET/OMG_KILLER",
                    "author": "RazdoruNET",
                    "first_seen": "2026-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Автоатакующий скрипт на базе эксплойтов CVE-2024-37890 и OOM 2026",
                    "summary": "Автоатакующий скрипт на базе эксплойтов CVE-2024-37890 и OOM 2026",
                    "url": "https://github.com/RazdoruNET/OMG_KILLER"
                }
            ],
            "references": [
                "https://github.com/RazdoruNET/OMG_KILLER"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/RazdoruNET/OMG_KILLER"
                }
            ]
        },
        {
            "id": "CVE-2024-37054",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-37054 exploit",
            "summary": "Exploit for CVE-2024-37054. CVSS 8.8.",
            "updated_at": "2026-09-15T08:32:46Z",
            "published_at": "2026-09-15T08:32:46Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-15T08:32:46+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2024-37054 exploit",
                    "summary": "Exploit for CVE-2024-37054. CVSS 8.8.",
                    "cvss": 8.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BEN-SLATES-CVE-2024-37054"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BEN-SLATES-CVE-2024-37054"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:32:46Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BEN-SLATES-CVE-2024-37054"
                }
            ]
        },
        {
            "id": "CVE-2024-36401",
            "vendor": "OSGeo",
            "product": "GeoServer",
            "title": "OSGeo GeoServer GeoTools Eval Injection Vulnerability",
            "summary": "OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input.",
            "updated_at": "2026-09-14T22:00:00Z",
            "published_at": "2026-09-14T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 97,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unauthenticated attackers to conduct remote code execution via specially crafted input.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · bigb0x/CVE-2024-36401",
                    "author": "bigb0x",
                    "first_seen": "2024-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 35,
                    "title": "POC for CVE-2024-36401. This POC will attempt to establish a reverse shell from the vlun targets.",
                    "summary": "POC for CVE-2024-36401. This POC will attempt to establish a reverse shell from the vlun targets.",
                    "url": "https://github.com/bigb0x/CVE-2024-36401"
                },
                {
                    "repository": "PoC-in-GitHub · Niuwoo/CVE-2024-36401",
                    "author": "Niuwoo",
                    "first_seen": "2024-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "POC",
                    "summary": "POC",
                    "url": "https://github.com/Niuwoo/CVE-2024-36401"
                },
                {
                    "repository": "PoC-in-GitHub · RevoltSecurities/CVE-2024-36401",
                    "author": "RevoltSecurities",
                    "first_seen": "2024-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Exploiter a Vulnerability detection and Exploitation tool for GeoServer Unauthenticated Remote Code Execution CVE-2024-36401.",
                    "summary": "Exploiter a Vulnerability detection and Exploitation tool for GeoServer Unauthenticated Remote Code Execution CVE-2024-36401.",
                    "url": "https://github.com/RevoltSecurities/CVE-2024-36401"
                },
                {
                    "repository": "PoC-in-GitHub · Mr-xn/CVE-2024-36401",
                    "author": "Mr-xn",
                    "first_seen": "2024-07-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 56,
                    "title": "Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions with multies ways to exploit",
                    "summary": "Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions with multies ways to exploit",
                    "url": "https://github.com/Mr-xn/CVE-2024-36401"
                },
                {
                    "repository": "PoC-in-GitHub · jakabakos/CVE-2024-36401-GeoServer-RCE",
                    "author": "jakabakos",
                    "first_seen": "2024-07-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-36401 repository",
                    "summary": "",
                    "url": "https://github.com/jakabakos/CVE-2024-36401-GeoServer-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · ahisec/geoserver-",
                    "author": "ahisec",
                    "first_seen": "2024-07-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 45,
                    "title": "geoserver CVE-2024-36401漏洞利用工具",
                    "summary": "geoserver CVE-2024-36401漏洞利用工具",
                    "url": "https://github.com/ahisec/geoserver-"
                },
                {
                    "repository": "PoC-in-GitHub · Chocapikk/CVE-2024-36401",
                    "author": "Chocapikk",
                    "first_seen": "2024-07-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 89,
                    "title": "GeoServer Remote Code Execution",
                    "summary": "GeoServer Remote Code Execution",
                    "url": "https://github.com/Chocapikk/CVE-2024-36401"
                },
                {
                    "repository": "PoC-in-GitHub · y1s4s/CVE-2024-36401-PoC",
                    "author": "y1s4s",
                    "first_seen": "2024-08-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-36401 repository",
                    "summary": "",
                    "url": "https://github.com/y1s4s/CVE-2024-36401-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · justin-p/geoexplorer",
                    "author": "justin-p",
                    "first_seen": "2024-08-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Mass scanner for CVE-2024-36401",
                    "summary": "Mass scanner for CVE-2024-36401",
                    "url": "https://github.com/justin-p/geoexplorer"
                },
                {
                    "repository": "PoC-in-GitHub · daniellowrie/CVE-2024-36401-PoC",
                    "author": "daniellowrie",
                    "first_seen": "2024-09-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Proof-of-Concept Exploit for CVE-2024-36401 GeoServer 2.25.1",
                    "summary": "Proof-of-Concept Exploit for CVE-2024-36401 GeoServer 2.25.1",
                    "url": "https://github.com/daniellowrie/CVE-2024-36401-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · punitdarji/GeoServer-CVE-2024-36401",
                    "author": "punitdarji",
                    "first_seen": "2024-09-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "GeoServer CVE-2024-36401: Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions",
                    "summary": "GeoServer CVE-2024-36401: Remote Code Execution (RCE) Vulnerability In Evaluating Property Name Expressions",
                    "url": "https://github.com/punitdarji/GeoServer-CVE-2024-36401"
                },
                {
                    "repository": "PoC-in-GitHub · kkhackz0013/CVE-2024-36401",
                    "author": "kkhackz0013",
                    "first_seen": "2024-10-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-36401 repository",
                    "summary": "",
                    "url": "https://github.com/kkhackz0013/CVE-2024-36401"
                },
                {
                    "repository": "PoC-in-GitHub · 0x0d3ad/CVE-2024-36401",
                    "author": "0x0d3ad",
                    "first_seen": "2024-11-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2024-36401 (GeoServer Remote Code Execution)",
                    "summary": "CVE-2024-36401 (GeoServer Remote Code Execution)",
                    "url": "https://github.com/0x0d3ad/CVE-2024-36401"
                },
                {
                    "repository": "PoC-in-GitHub · funnyDog896/CVE-2024-36401-WoodpeckerPlugin",
                    "author": "funnyDog896",
                    "first_seen": "2024-11-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-36401-GeoServer Property 表达式注入 Rce woodpecker-framework 插件",
                    "summary": "CVE-2024-36401-GeoServer Property 表达式注入 Rce woodpecker-framework 插件",
                    "url": "https://github.com/funnyDog896/CVE-2024-36401-WoodpeckerPlugin"
                },
                {
                    "repository": "PoC-in-GitHub · whitebear-ch/GeoServerExploit",
                    "author": "whitebear-ch",
                    "first_seen": "2025-01-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 122,
                    "title": "GeoServer（CVE-2024-36401/CVE-2024-36404）漏洞利用工具",
                    "summary": "GeoServer（CVE-2024-36401/CVE-2024-36404）漏洞利用工具",
                    "url": "https://github.com/whitebear-ch/GeoServerExploit"
                },
                {
                    "repository": "PoC-in-GitHub · bmth666/GeoServer-Tools-CVE-2024-36401",
                    "author": "bmth666",
                    "first_seen": "2025-04-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 43,
                    "title": "CVE-2024-36401 图形化利用工具，支持各个JDK版本利用以及回显、内存马实现",
                    "summary": "CVE-2024-36401 图形化利用工具，支持各个JDK版本利用以及回显、内存马实现",
                    "url": "https://github.com/bmth666/GeoServer-Tools-CVE-2024-36401"
                },
                {
                    "repository": "PoC-in-GitHub · amoy6228/CVE-2024-36401_Geoserver_RCE_POC",
                    "author": "amoy6228",
                    "first_seen": "2025-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "本脚本是针对 GeoServer 的远程代码执行漏洞（CVE-2024-36401）开发的 PoC（Proof of Concept）探测工具。该漏洞允许攻击者通过构造特定请求，在目标服务器上执行任意命令。",
                    "summary": "本脚本是针对 GeoServer 的远程代码执行漏洞（CVE-2024-36401）开发的 PoC（Proof of Concept）探测工具。该漏洞允许攻击者通过构造特定请求，在目标服务器上执行任意命令。",
                    "url": "https://github.com/amoy6228/CVE-2024-36401_Geoserver_RCE_POC"
                },
                {
                    "repository": "PoC-in-GitHub · URJACK2025/CVE-2024-36401",
                    "author": "URJACK2025",
                    "first_seen": "2025-10-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "An Python Exp For \"GeoServer\"",
                    "summary": "An Python Exp For \"GeoServer\"",
                    "url": "https://github.com/URJACK2025/CVE-2024-36401"
                },
                {
                    "repository": "PoC-in-GitHub · mantanhacker/CVE-2024-36401-MASS",
                    "author": "mantanhacker",
                    "first_seen": "2025-12-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Geoserver RCE",
                    "summary": "Geoserver RCE",
                    "url": "https://github.com/mantanhacker/CVE-2024-36401-MASS"
                },
                {
                    "repository": "PoC-in-GitHub · Delt-A/CVE-2024-36401-poc",
                    "author": "Delt-A",
                    "first_seen": "2026-05-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-36401 repository",
                    "summary": "",
                    "url": "https://github.com/Delt-A/CVE-2024-36401-poc"
                },
                {
                    "repository": "PoC-in-GitHub · DanieleGiovanardi2408/cve-2024-36401-geoserver-rce",
                    "author": "DanieleGiovanardi2408",
                    "first_seen": "2026-06-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-36401 repository",
                    "summary": "",
                    "url": "https://github.com/DanieleGiovanardi2408/cve-2024-36401-geoserver-rce"
                },
                {
                    "repository": "PoC-in-GitHub · keelanbrady1011/CVE-2024-36401",
                    "author": "keelanbrady1011",
                    "first_seen": "2026-07-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Remix of Chokapikk's CVE-2024-36401 to allow webshell-like behaviour on limited environments",
                    "summary": "Remix of Chokapikk's CVE-2024-36401 to allow webshell-like behaviour on limited environments",
                    "url": "https://github.com/keelanbrady1011/CVE-2024-36401"
                },
                {
                    "repository": "PoC-in-GitHub · raniaemran/cve-2024-36401-security-simulator",
                    "author": "raniaemran",
                    "first_seen": "2026-09-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-36401 repository",
                    "summary": "",
                    "url": "https://github.com/raniaemran/cve-2024-36401-security-simulator"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/bigb0x/CVE-2024-36401",
                "https://github.com/Niuwoo/CVE-2024-36401",
                "https://github.com/RevoltSecurities/CVE-2024-36401",
                "https://github.com/Mr-xn/CVE-2024-36401",
                "https://github.com/jakabakos/CVE-2024-36401-GeoServer-RCE",
                "https://github.com/ahisec/geoserver-",
                "https://github.com/Chocapikk/CVE-2024-36401",
                "https://github.com/y1s4s/CVE-2024-36401-PoC",
                "https://github.com/justin-p/geoexplorer",
                "https://github.com/daniellowrie/CVE-2024-36401-PoC",
                "https://github.com/punitdarji/GeoServer-CVE-2024-36401",
                "https://github.com/kkhackz0013/CVE-2024-36401",
                "https://github.com/0x0d3ad/CVE-2024-36401",
                "https://github.com/funnyDog896/CVE-2024-36401-WoodpeckerPlugin",
                "https://github.com/whitebear-ch/GeoServerExploit",
                "https://github.com/bmth666/GeoServer-Tools-CVE-2024-36401",
                "https://github.com/amoy6228/CVE-2024-36401_Geoserver_RCE_POC",
                "https://github.com/URJACK2025/CVE-2024-36401",
                "https://github.com/mantanhacker/CVE-2024-36401-MASS",
                "https://github.com/Delt-A/CVE-2024-36401-poc",
                "https://github.com/DanieleGiovanardi2408/cve-2024-36401-geoserver-rce",
                "https://github.com/keelanbrady1011/CVE-2024-36401",
                "https://github.com/raniaemran/cve-2024-36401-security-simulator"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-07-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-07-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-07-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-07-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2024-36114",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Serpstat fork of housepower/ClickHouse-Native-JDBC 2.7.1. Fixes the CityHash128 checksum defect behind \"Checksum doesn't match: corrupted data\" on INSERT, upgrades aircompressor to 0.27 (CVE-2024-36114). Drop-in: com.serpstat:clickhouse-native-jdbc-shaded:2.7.1-serpstat.1. Apache 2.0.",
            "summary": "Serpstat fork of housepower/ClickHouse-Native-JDBC 2.7.1. Fixes the CityHash128 checksum defect behind \"Checksum doesn't match: corrupted data\" on INSERT, upgrades aircompressor to 0.27 (CVE-2024-36114). Drop-in: com.serpstat:clickhouse-native-jdbc-shaded:2.7.1-serpstat.1. Apache 2.0.",
            "updated_at": "2026-09-07T22:00:00Z",
            "published_at": "2026-09-07T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · SerpstatGlobal/ClickHouse-Native-JDBC",
                    "author": "SerpstatGlobal",
                    "first_seen": "2026-09-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Serpstat fork of housepower/ClickHouse-Native-JDBC 2.7.1. Fixes the CityHash128 checksum defect behind \"Checksum doesn't match: corrupted data\" on INSERT, upgrades aircompressor to 0.27 (CVE-2024-36114). Drop-in: com.serpstat:clickhouse-native-jdbc-shaded:2.7.1-serpstat.1. Apache 2.0.",
                    "summary": "Serpstat fork of housepower/ClickHouse-Native-JDBC 2.7.1. Fixes the CityHash128 checksum defect behind \"Checksum doesn't match: corrupted data\" on INSERT, upgrades aircompressor to 0.27 (CVE-2024-36114). Drop-in: com.serpstat:clickhouse-native-jdbc-shaded:2.7.1-serpstat.1. Apache 2.0.",
                    "url": "https://github.com/SerpstatGlobal/ClickHouse-Native-JDBC"
                }
            ],
            "references": [
                "https://github.com/SerpstatGlobal/ClickHouse-Native-JDBC"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/SerpstatGlobal/ClickHouse-Native-JDBC"
                }
            ]
        },
        {
            "id": "CVE-2024-35887",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nax25: fix use-after-free bugs caused by ax25_ds_del_timer\n\nWhen the ax25 device is detaching, the ax25_dev_device_down()\ncalls ax25_ds_del_timer() to cleanup the slave_timer. When\nthe timer handler is running, the ax25_ds_del_timer() that\ncalls del_timer() in it will return directly. As a result,\nthe use-after-free bugs could happen, one of the scenarios\nis shown below:\n\n      (Thread 1)          |      (Thread 2)\n                          | ax25_ds_timeout()\nax25_dev_device_down()    |\n  ax25_ds_del_timer()     |\n    del_timer()           |\n  ax25_dev_put() //FREE   |\n                          |  ax25_dev-> //USE\n\nIn order to mitigate bugs, when the device is detaching, use\ntimer_shutdown_sync() to stop the timer.",
            "updated_at": "2026-09-14T12:17:33.070",
            "published_at": "2024-05-19T09:15:09.837",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 28f2d36ac52225a13e020c2589833f1816a0cfc6 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 8a912ef5b7c5d14fb41b9a7935d1df5bb87058bf (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before 74204bf9050f7627aead9875fe4e07ba125cb19b (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before c6a368f9c7af4c14b14d390c2543af8001c9bdb9 (git); 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 through before fd819ad3ecf6f3c232a06b27423ce9ed8c20da89 (git); 2.6.12",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nax25: fix use-after-free bugs caused by ax25_ds_del_timer\n\nWhen the ax25 device is detaching, the ax25_dev_device_down()\ncalls ax25_ds_del_timer() to cleanup the slave_timer. When\nthe timer handler is running, the ax25_ds_del_timer() that\ncalls del_timer() in it will return directly. As a result,\nthe use-after-free bugs could happen, one of the scenarios\nis shown below:\n\n      (Thread 1)          |      (Thread 2)\n                          | ax25_ds_timeout()\nax25_dev_device_down()    |\n  ax25_ds_del_timer()     |\n    del_timer()           |\n  ax25_dev_put() //FREE   |\n                          |  ax25_dev-> //USE\n\nIn order to mitigate bugs, when the device is detaching, use\ntimer_shutdown_sync() to stop the timer.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/28f2d36ac52225a13e020c2589833f1816a0cfc6",
                "https://git.kernel.org/stable/c/74204bf9050f7627aead9875fe4e07ba125cb19b",
                "https://git.kernel.org/stable/c/8a912ef5b7c5d14fb41b9a7935d1df5bb87058bf",
                "https://git.kernel.org/stable/c/c6a368f9c7af4c14b14d390c2543af8001c9bdb9",
                "https://git.kernel.org/stable/c/fd819ad3ecf6f3c232a06b27423ce9ed8c20da89"
            ],
            "timeline": [
                {
                    "at": "2024-05-19T09:15:09.837",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35887"
                }
            ]
        },
        {
            "id": "CVE-2024-33668",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.",
            "updated_at": "2026-09-16T20:17:20.507",
            "published_at": "2024-04-26T01:15:46.320",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a; 6.2.0 through before 6.3.0 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-639",
            "what_happened": "An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://a7.de/fue/advisories/cve-2024-33668/",
                "https://zammad.com/en/advisories/zaa-2024-02"
            ],
            "timeline": [
                {
                    "at": "2024-04-26T01:15:46.320",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33668"
                }
            ]
        },
        {
            "id": "CVE-2024-30350",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Research notes for CVE-2024-30350",
            "summary": "Research notes for CVE-2024-30350",
            "updated_at": "2026-09-10T22:00:00Z",
            "published_at": "2026-09-10T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · lmx-071028/cve-2024-30350-research-notes",
                    "author": "lmx-071028",
                    "first_seen": "2026-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Research notes for CVE-2024-30350",
                    "summary": "Research notes for CVE-2024-30350",
                    "url": "https://github.com/lmx-071028/cve-2024-30350-research-notes"
                }
            ],
            "references": [
                "https://github.com/lmx-071028/cve-2024-30350-research-notes"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/lmx-071028/cve-2024-30350-research-notes"
                }
            ]
        },
        {
            "id": "CVE-2024-28116",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Graver exploit",
            "summary": "Exploit for CVE-2024-28116. CVSS 8.8.",
            "updated_at": "2026-09-07T08:09:45Z",
            "published_at": "2026-09-07T08:09:45Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 103,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Authenticated SSTI to RCE in Grav CMS (CVE-2024-28116) via malicious page creation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Graver CVE-2024-28116",
                    "summary": "Authenticated SSTI to RCE in Grav CMS (CVE-2024-28116) via malicious page creation.",
                    "what_happened": "Authenticated SSTI to RCE in Grav CMS (CVE-2024-28116) via malicious page creation.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AKABE1-GRAVER",
                        "https://kitploit.com/ar/tools/github/akabe1/graver/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T12:08:06",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AKABE1-GRAVER"
                },
                {
                    "title": "Exploit for Graver CVE-2024-28116",
                    "summary": "Authenticated SSTI to RCE in Grav CMS (CVE-2024-28116) via malicious page creation.",
                    "what_happened": "Authenticated SSTI to RCE in Grav CMS (CVE-2024-28116) via malicious page creation.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AKABE1-GRAVER",
                        "https://kitploit.com/ar/tools/github/akabe1/graver/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-03T12:08:06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/akabe1/graver/"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-08T14:43:54+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "GenGravSSTIExploit",
                    "summary": "Exploit for CVE-2024-28116. CVSS 8.8.",
                    "cvss": 8.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GENIUSZLY-GENGRAVSSTIEXPLOIT"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AKABE1-GRAVER",
                "https://kitploit.com/ar/tools/github/akabe1/graver/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GENIUSZLY-GENGRAVSSTIEXPLOIT"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:09:45Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AKABE1-GRAVER"
                }
            ]
        },
        {
            "id": "CVE-2024-27564",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "SSRF-Exploit-CVE-2024-27564",
            "summary": "SSRF in pictureproxy.php via unvalidated url parameter passed to file_get_contents.",
            "updated_at": "2026-09-05T04:05:44Z",
            "published_at": "2026-09-05T04:05:44Z",
            "cvss": 6.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 79,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "SSRF in pictureproxy.php via unvalidated url parameter passed to file_get_contents.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "SSRF-Exploit-CVE-2024-27564",
                    "summary": "SSRF in pictureproxy.php via unvalidated url parameter passed to file_get_contents.",
                    "what_happened": "SSRF in pictureproxy.php via unvalidated url parameter passed to file_get_contents.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CHAUDHRYMUHAMMADTAYAB-SSRF-EXPLOIT-CVE-2024-27564",
                        "https://kitploit.com/ru/tools/github/chaudhrymuhammadtayab/ssrf-exploit-cve-2024-27564/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T06:05:44",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CHAUDHRYMUHAMMADTAYAB-SSRF-EXPLOIT-CVE-2024-27564"
                },
                {
                    "title": "SSRF-Exploit-CVE-2024-27564",
                    "summary": "SSRF in pictureproxy.php via unvalidated url parameter passed to file_get_contents.",
                    "what_happened": "SSRF in pictureproxy.php via unvalidated url parameter passed to file_get_contents.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CHAUDHRYMUHAMMADTAYAB-SSRF-EXPLOIT-CVE-2024-27564",
                        "https://kitploit.com/ru/tools/github/chaudhrymuhammadtayab/ssrf-exploit-cve-2024-27564/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T06:05:44",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/chaudhrymuhammadtayab/ssrf-exploit-cve-2024-27564/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CHAUDHRYMUHAMMADTAYAB-SSRF-EXPLOIT-CVE-2024-27564",
                "https://kitploit.com/ru/tools/github/chaudhrymuhammadtayab/ssrf-exploit-cve-2024-27564/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T04:05:44Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CHAUDHRYMUHAMMADTAYAB-SSRF-EXPLOIT-CVE-2024-27564"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
        },
        {
            "id": "CVE-2024-26304",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-26304-RCE-exploit",
            "summary": "Exploit for CVE-2024-26304. CVSS 9.8.",
            "updated_at": "2026-09-05T08:11:50Z",
            "published_at": "2026-09-05T08:11:50Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 111,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Buffer overflow in ArubaOS L2/L3 Management service via PAPI UDP port 8211 enables RCE.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "CVE-2024-26304-RCE-exploit",
                    "summary": "Buffer overflow in ArubaOS L2/L3 Management service via PAPI UDP port 8211 enables RCE.",
                    "what_happened": "Buffer overflow in ArubaOS L2/L3 Management service via PAPI UDP port 8211 enables RCE.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-PROJETION-CVE-2024-26304-RCE-EXPLOIT",
                        "https://kitploit.com/ja/tools/github/x-projetion/cve-2024-26304-rce-exploit/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-02T05:05:55",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-PROJETION-CVE-2024-26304-RCE-EXPLOIT"
                },
                {
                    "title": "CVE-2024-26304-RCE-exploit",
                    "summary": "Buffer overflow in ArubaOS L2/L3 Management service via PAPI UDP port 8211 enables RCE.",
                    "what_happened": "Buffer overflow in ArubaOS L2/L3 Management service via PAPI UDP port 8211 enables RCE.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-PROJETION-CVE-2024-26304-RCE-EXPLOIT",
                        "https://kitploit.com/ja/tools/github/x-projetion/cve-2024-26304-rce-exploit/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-02T05:05:55",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/x-projetion/cve-2024-26304-rce-exploit/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-PROJETION-CVE-2024-26304-RCE-EXPLOIT",
                "https://kitploit.com/ja/tools/github/x-projetion/cve-2024-26304-rce-exploit/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:11:50Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-PROJETION-CVE-2024-26304-RCE-EXPLOIT"
                }
            ]
        },
        {
            "id": "CVE-2024-24576",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2025-50505",
            "summary": "Unauthenticated API in Clash Verge Rev <=2.2.3 allows command execution and privilege escalation.",
            "updated_at": "2026-09-03T18:34:36Z",
            "published_at": "2026-09-03T18:34:36Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Unauthenticated API in Clash Verge Rev <=2.2.3 allows command execution and privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2025-50505",
                    "summary": "Unauthenticated API in Clash Verge Rev <=2.2.3 allows command execution and privilege escalation.",
                    "what_happened": "Unauthenticated API in Clash Verge Rev <=2.2.3 allows command execution and privilege escalation.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-A0YAMI-CVE-2025-50505",
                        "https://kitploit.com/ru/tools/github/a0yami/cve-2025-50505/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T20:34:36",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-A0YAMI-CVE-2025-50505"
                },
                {
                    "title": "Exploit for CVE-2025-50505",
                    "summary": "Unauthenticated API in Clash Verge Rev <=2.2.3 allows command execution and privilege escalation.",
                    "what_happened": "Unauthenticated API in Clash Verge Rev <=2.2.3 allows command execution and privilege escalation.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-A0YAMI-CVE-2025-50505",
                        "https://kitploit.com/ru/tools/github/a0yami/cve-2025-50505/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-03T20:34:36",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/a0yami/cve-2025-50505/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-A0YAMI-CVE-2025-50505",
                "https://kitploit.com/ru/tools/github/a0yami/cve-2025-50505/"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T18:34:36Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-A0YAMI-CVE-2025-50505"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2024-23897",
            "vendor": "Jenkins",
            "product": "Jenkins Command Line Interface (CLI)",
            "title": "Jenkins Command Line Interface (CLI) Path Traversal Vulnerability",
            "summary": "Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.",
            "updated_at": "2026-08-27T22:00:00Z",
            "published_at": "2026-08-27T22:00:00Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1185,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 51993",
                    "author": "Matisse Beckandt",
                    "first_seen": "2024-04-15",
                    "confidence": "High",
                    "title": "Jenkins 2.441 - Local File Inclusion",
                    "summary": "Jenkins 2.441 - Local File Inclusion",
                    "url": "https://www.exploit-db.com/exploits/51993",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · jenkinsci-cert/SECURITY-3314-3315",
                    "author": "jenkinsci-cert",
                    "first_seen": "2024-01-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Workaround for disabling the CLI to mitigate SECURITY-3314/CVE-2024-23897 and SECURITY-3315/CVE-2024-23898",
                    "summary": "Workaround for disabling the CLI to mitigate SECURITY-3314/CVE-2024-23897 and SECURITY-3315/CVE-2024-23898",
                    "url": "https://github.com/jenkinsci-cert/SECURITY-3314-3315"
                },
                {
                    "repository": "PoC-in-GitHub · binganao/CVE-2024-23897",
                    "author": "binganao",
                    "first_seen": "2024-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 100,
                    "title": "CVE-2024-23897 repository",
                    "summary": "",
                    "url": "https://github.com/binganao/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · h4x0r-dz/CVE-2024-23897",
                    "author": "h4x0r-dz",
                    "first_seen": "2024-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 209,
                    "title": "CVE-2024-23897",
                    "summary": "CVE-2024-23897",
                    "url": "https://github.com/h4x0r-dz/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · xaitax/CVE-2024-23897",
                    "author": "xaitax",
                    "first_seen": "2024-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 81,
                    "title": "CVE-2024-23897 | Jenkins <= 2.441 & <= LTS 2.426.2 PoC and scanner.",
                    "summary": "CVE-2024-23897 | Jenkins <= 2.441 & <= LTS 2.426.2 PoC and scanner.",
                    "url": "https://github.com/xaitax/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · vmtyan/poc-cve-2024-23897",
                    "author": "vmtyan",
                    "first_seen": "2024-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2024-23897 repository",
                    "summary": "",
                    "url": "https://github.com/vmtyan/poc-cve-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · yoryio/CVE-2024-23897",
                    "author": "yoryio",
                    "first_seen": "2024-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Scanner for CVE-2024-23897 - Jenkins",
                    "summary": "Scanner for CVE-2024-23897 - Jenkins",
                    "url": "https://github.com/yoryio/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · P4x1s/CVE-2024-23897",
                    "author": "P4x1s",
                    "first_seen": "2024-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 16,
                    "title": "CVE-2024-23897 jenkins-cli",
                    "summary": "CVE-2024-23897 jenkins-cli",
                    "url": "https://github.com/P4x1s/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · 10T4/PoC-Fix-jenkins-rce_CVE-2024-23897",
                    "author": "10T4",
                    "first_seen": "2024-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "on this git you can find all information on the CVE-2024-23897",
                    "summary": "on this git you can find all information on the CVE-2024-23897",
                    "url": "https://github.com/10T4/PoC-Fix-jenkins-rce_CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · wjlin0/CVE-2024-23897",
                    "author": "wjlin0",
                    "first_seen": "2024-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 88,
                    "title": "CVE-2024-23897 - Jenkins 任意文件读取 利用工具",
                    "summary": "CVE-2024-23897 - Jenkins 任意文件读取 利用工具",
                    "url": "https://github.com/wjlin0/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · Vozec/CVE-2024-23897",
                    "author": "Vozec",
                    "first_seen": "2024-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 18,
                    "title": "This repository presents a proof-of-concept of CVE-2024-23897",
                    "summary": "This repository presents a proof-of-concept of CVE-2024-23897",
                    "url": "https://github.com/Vozec/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · r0xDB/CVE-2024-23897",
                    "author": "r0xDB",
                    "first_seen": "2024-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.",
                    "summary": "Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.",
                    "url": "https://github.com/r0xDB/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · viszsec/CVE-2024-23897",
                    "author": "viszsec",
                    "first_seen": "2024-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Jenkins POC of Arbitrary file read vulnerability through the CLI can lead to RCE",
                    "summary": "Jenkins POC of Arbitrary file read vulnerability through the CLI can lead to RCE",
                    "url": "https://github.com/viszsec/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · jopraveen/CVE-2024-23897",
                    "author": "jopraveen",
                    "first_seen": "2024-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-23897 repository",
                    "summary": "",
                    "url": "https://github.com/jopraveen/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · AbraXa5/Jenkins-CVE-2024-23897",
                    "author": "AbraXa5",
                    "first_seen": "2024-02-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC for Jenkins CVE-2024-23897",
                    "summary": "PoC for Jenkins CVE-2024-23897",
                    "url": "https://github.com/AbraXa5/Jenkins-CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · WLXQqwer/Jenkins-CVE-2024-23897-",
                    "author": "WLXQqwer",
                    "first_seen": "2024-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-23897 repository",
                    "summary": "",
                    "url": "https://github.com/WLXQqwer/Jenkins-CVE-2024-23897-"
                },
                {
                    "repository": "PoC-in-GitHub · kaanatmacaa/CVE-2024-23897",
                    "author": "kaanatmacaa",
                    "first_seen": "2024-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 23,
                    "title": "Nuclei template for CVE-2024-23897 (Jenkins LFI Vulnerability)",
                    "summary": "Nuclei template for CVE-2024-23897 (Jenkins LFI Vulnerability)",
                    "url": "https://github.com/kaanatmacaa/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · GraySignal/CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability",
                    "author": "GraySignal",
                    "first_seen": "2024-02-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.",
                    "summary": "Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.",
                    "url": "https://github.com/GraySignal/CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · B4CK4TT4CK/CVE-2024-23897",
                    "author": "B4CK4TT4CK",
                    "first_seen": "2024-02-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-23897",
                    "summary": "CVE-2024-23897",
                    "url": "https://github.com/B4CK4TT4CK/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · godylockz/CVE-2024-23897",
                    "author": "godylockz",
                    "first_seen": "2024-02-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 45,
                    "title": "POC for CVE-2024-23897 Jenkins File-Read",
                    "summary": "POC for CVE-2024-23897 Jenkins File-Read",
                    "url": "https://github.com/godylockz/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · ifconfig-me/CVE-2024-23897",
                    "author": "ifconfig-me",
                    "first_seen": "2024-02-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Jenkins Arbitrary File Leak Vulnerability [CVE-2024-23897]",
                    "summary": "Jenkins Arbitrary File Leak Vulnerability [CVE-2024-23897]",
                    "url": "https://github.com/ifconfig-me/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · Ap0dexMe0/CVE-2024-23897",
                    "author": "Ap0dexMe0",
                    "first_seen": "2024-02-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Perform with massive Jenkins Reading-2-RCE",
                    "summary": "Perform with massive Jenkins Reading-2-RCE",
                    "url": "https://github.com/Ap0dexMe0/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · pulentoski/CVE-2024-23897-Arbitrary-file-read",
                    "author": "pulentoski",
                    "first_seen": "2024-02-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Un script realizado en python para atumatizar la vulnerabilidad CVE-2024-23897",
                    "summary": "Un script realizado en python para atumatizar la vulnerabilidad CVE-2024-23897",
                    "url": "https://github.com/pulentoski/CVE-2024-23897-Arbitrary-file-read"
                },
                {
                    "repository": "PoC-in-GitHub · Nebian/CVE-2024-23897",
                    "author": "Nebian",
                    "first_seen": "2024-02-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Scraping tool to ennumerate directories or files with the CVE-2024-23897 vulnerability in Jenkins.",
                    "summary": "Scraping tool to ennumerate directories or files with the CVE-2024-23897 vulnerability in Jenkins.",
                    "url": "https://github.com/Nebian/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · JAthulya/CVE-2024-23897",
                    "author": "JAthulya",
                    "first_seen": "2024-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Jenkins CVE-2024-23897: Arbitrary File Read Vulnerability",
                    "summary": "Jenkins CVE-2024-23897: Arbitrary File Read Vulnerability",
                    "url": "https://github.com/JAthulya/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · murataydemir/CVE-2024-23897",
                    "author": "murataydemir",
                    "first_seen": "2024-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "[CVE-2024-23897] Jenkins CI Authenticated Arbitrary File Read Through the CLI Leads to Remote Code Execution (RCE)",
                    "summary": "[CVE-2024-23897] Jenkins CI Authenticated Arbitrary File Read Through the CLI Leads to Remote Code Execution (RCE)",
                    "url": "https://github.com/murataydemir/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · Maalfer/CVE-2024-23897",
                    "author": "Maalfer",
                    "first_seen": "2024-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "Poc para explotar la vulnerabilidad CVE-2024-23897 en versiones 2.441 y anteriores de Jenkins, mediante la cual podremos leer archivos internos del sistema sin estar autenticados",
                    "summary": "Poc para explotar la vulnerabilidad CVE-2024-23897 en versiones 2.441 y anteriores de Jenkins, mediante la cual podremos leer archivos internos del sistema sin estar autenticados",
                    "url": "https://github.com/Maalfer/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · Surko888/Surko-Exploit-Jenkins-CVE-2024-23897",
                    "author": "Surko888",
                    "first_seen": "2024-05-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Un exploit con el que puedes aprovecharte de la vulnerabilidad (CVE-2024-23897)",
                    "summary": "Un exploit con el que puedes aprovecharte de la vulnerabilidad (CVE-2024-23897)",
                    "url": "https://github.com/Surko888/Surko-Exploit-Jenkins-CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · cc3305/CVE-2024-23897",
                    "author": "cc3305",
                    "first_seen": "2024-07-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-23897 exploit script",
                    "summary": "CVE-2024-23897 exploit script",
                    "url": "https://github.com/cc3305/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · verylazytech/CVE-2024-23897",
                    "author": "verylazytech",
                    "first_seen": "2024-09-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "POC - Jenkins File Read Vulnerability - CVE-2024-23897",
                    "summary": "POC - Jenkins File Read Vulnerability - CVE-2024-23897",
                    "url": "https://github.com/verylazytech/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · D1se0/CVE-2024-23897-Vulnerabilidad-Jenkins",
                    "author": "D1se0",
                    "first_seen": "2024-12-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2024-23897 repository",
                    "summary": "",
                    "url": "https://github.com/D1se0/CVE-2024-23897-Vulnerabilidad-Jenkins"
                },
                {
                    "repository": "PoC-in-GitHub · slytechroot/CVE-2024-23897",
                    "author": "slytechroot",
                    "first_seen": "2025-03-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Jenkins RCE Arbitrary File Read CVE-2024-23897",
                    "summary": "Jenkins RCE Arbitrary File Read CVE-2024-23897",
                    "url": "https://github.com/slytechroot/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo",
                    "author": "brandonhjh",
                    "first_seen": "2025-03-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-23897 repository",
                    "summary": "",
                    "url": "https://github.com/brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo"
                },
                {
                    "repository": "PoC-in-GitHub · tvasari/CVE-2024-23897",
                    "author": "tvasari",
                    "first_seen": "2025-04-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Jenkins CLI arbitrary read (CVE-2024-23897 applies to versions below 2.442 and LTS 2.426.3)",
                    "summary": "Jenkins CLI arbitrary read (CVE-2024-23897 applies to versions below 2.442 and LTS 2.426.3)",
                    "url": "https://github.com/tvasari/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · Fineken/Jenkins-CVE-2024-23897-Lab",
                    "author": "Fineken",
                    "first_seen": "2025-07-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2024-23897 repository",
                    "summary": "",
                    "url": "https://github.com/Fineken/Jenkins-CVE-2024-23897-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · classic130/CVE-2024-23897-Jenkins-4.441",
                    "author": "classic130",
                    "first_seen": "2025-07-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-23897 repository",
                    "summary": "",
                    "url": "https://github.com/classic130/CVE-2024-23897-Jenkins-4.441"
                },
                {
                    "repository": "PoC-in-GitHub · amalpvatayam67/day03-jenkins-23897",
                    "author": "amalpvatayam67",
                    "first_seen": "2025-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Jenkins CLI arbitrary file read (CVE-2024-23897)",
                    "summary": "Jenkins CLI arbitrary file read (CVE-2024-23897)",
                    "url": "https://github.com/amalpvatayam67/day03-jenkins-23897"
                },
                {
                    "repository": "PoC-in-GitHub · hybinn/CVE-2024-23897",
                    "author": "hybinn",
                    "first_seen": "2025-10-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-23897 repository",
                    "summary": "",
                    "url": "https://github.com/hybinn/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · aadi0258/Exploit-CVE-2024-23897",
                    "author": "aadi0258",
                    "first_seen": "2025-10-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-23897 repository",
                    "summary": "",
                    "url": "https://github.com/aadi0258/Exploit-CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · harekrishnarai/CVE-2024-23897-test-windows",
                    "author": "harekrishnarai",
                    "first_seen": "2025-11-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-23897 repository",
                    "summary": "",
                    "url": "https://github.com/harekrishnarai/CVE-2024-23897-test-windows"
                },
                {
                    "repository": "PoC-in-GitHub · vmc8ll/poc-CVE-2024-23897",
                    "author": "vmc8ll",
                    "first_seen": "2026-03-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-23897: Jenkins Arbitrary File Read Lead to RCE",
                    "summary": "CVE-2024-23897: Jenkins Arbitrary File Read Lead to RCE",
                    "url": "https://github.com/vmc8ll/poc-CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · w41l3r/jenkins_scan",
                    "author": "w41l3r",
                    "first_seen": "2026-04-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Find jenkins environment and checks for CVE-2024-23897",
                    "summary": "Find jenkins environment and checks for CVE-2024-23897",
                    "url": "https://github.com/w41l3r/jenkins_scan"
                },
                {
                    "repository": "PoC-in-GitHub · rivaedoardo62-boop/cve-2024-23897-jenkins-poc",
                    "author": "rivaedoardo62-boop",
                    "first_seen": "2026-06-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Self-contained Docker reproduction and analysis of CVE-2024-23897, the Jenkins CLI arbitrary file read via the args4j @-syntax argument expansion.",
                    "summary": "Self-contained Docker reproduction and analysis of CVE-2024-23897, the Jenkins CLI arbitrary file read via the args4j @-syntax argument expansion.",
                    "url": "https://github.com/rivaedoardo62-boop/cve-2024-23897-jenkins-poc"
                },
                {
                    "repository": "PoC-in-GitHub · Dungsocool/CVE-2024-23897",
                    "author": "Dungsocool",
                    "first_seen": "2026-07-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-23897 repository",
                    "summary": "",
                    "url": "https://github.com/Dungsocool/CVE-2024-23897"
                },
                {
                    "repository": "PoC-in-GitHub · razureink/cve-2024-23897-jenkins_lfi_reproduction",
                    "author": "razureink",
                    "first_seen": "2026-07-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Reproduction of cve-2024-23897-jenkins_lfi_reproduction",
                    "summary": "Reproduction of cve-2024-23897-jenkins_lfi_reproduction",
                    "url": "https://github.com/razureink/cve-2024-23897-jenkins_lfi_reproduction"
                },
                {
                    "repository": "PoC-in-GitHub · dheeraj-jayaswal/CICD-Goat-Vapt-Writeup",
                    "author": "dheeraj-jayaswal",
                    "first_seen": "2026-07-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries.",
                    "summary": "Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries.",
                    "url": "https://github.com/dheeraj-jayaswal/CICD-Goat-Vapt-Writeup"
                },
                {
                    "repository": "PoC-in-GitHub · MachiavelliII/CVE-2024-23897",
                    "author": "MachiavelliII",
                    "first_seen": "2026-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Jenkins CVE-2024-23897 — CSRF-crumb aware PoC",
                    "summary": "Jenkins CVE-2024-23897 — CSRF-crumb aware PoC",
                    "url": "https://github.com/MachiavelliII/CVE-2024-23897"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:32:19+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2024-23897 exploit",
                    "summary": "Exploit for CVE-2024-23897. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MURATAYDEMIR-CVE-2024-23897"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/51993",
                "https://github.com/jenkinsci-cert/SECURITY-3314-3315",
                "https://github.com/binganao/CVE-2024-23897",
                "https://github.com/h4x0r-dz/CVE-2024-23897",
                "https://github.com/xaitax/CVE-2024-23897",
                "https://github.com/vmtyan/poc-cve-2024-23897",
                "https://github.com/yoryio/CVE-2024-23897",
                "https://github.com/P4x1s/CVE-2024-23897",
                "https://github.com/10T4/PoC-Fix-jenkins-rce_CVE-2024-23897",
                "https://github.com/wjlin0/CVE-2024-23897",
                "https://github.com/Vozec/CVE-2024-23897",
                "https://github.com/r0xDB/CVE-2024-23897",
                "https://github.com/viszsec/CVE-2024-23897",
                "https://github.com/jopraveen/CVE-2024-23897",
                "https://github.com/AbraXa5/Jenkins-CVE-2024-23897",
                "https://github.com/WLXQqwer/Jenkins-CVE-2024-23897-",
                "https://github.com/kaanatmacaa/CVE-2024-23897",
                "https://github.com/GraySignal/CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability",
                "https://github.com/B4CK4TT4CK/CVE-2024-23897",
                "https://github.com/godylockz/CVE-2024-23897",
                "https://github.com/ifconfig-me/CVE-2024-23897",
                "https://github.com/Ap0dexMe0/CVE-2024-23897",
                "https://github.com/pulentoski/CVE-2024-23897-Arbitrary-file-read",
                "https://github.com/Nebian/CVE-2024-23897",
                "https://github.com/JAthulya/CVE-2024-23897",
                "https://github.com/murataydemir/CVE-2024-23897",
                "https://github.com/Maalfer/CVE-2024-23897",
                "https://github.com/Surko888/Surko-Exploit-Jenkins-CVE-2024-23897",
                "https://github.com/cc3305/CVE-2024-23897",
                "https://github.com/verylazytech/CVE-2024-23897",
                "https://github.com/D1se0/CVE-2024-23897-Vulnerabilidad-Jenkins",
                "https://github.com/slytechroot/CVE-2024-23897",
                "https://github.com/brandonhjh/Jenkins-CVE-2024-23897-Exploit-Demo",
                "https://github.com/tvasari/CVE-2024-23897",
                "https://github.com/Fineken/Jenkins-CVE-2024-23897-Lab",
                "https://github.com/classic130/CVE-2024-23897-Jenkins-4.441",
                "https://github.com/amalpvatayam67/day03-jenkins-23897",
                "https://github.com/hybinn/CVE-2024-23897",
                "https://github.com/aadi0258/Exploit-CVE-2024-23897",
                "https://github.com/harekrishnarai/CVE-2024-23897-test-windows",
                "https://github.com/vmc8ll/poc-CVE-2024-23897",
                "https://github.com/w41l3r/jenkins_scan",
                "https://github.com/rivaedoardo62-boop/cve-2024-23897-jenkins-poc",
                "https://github.com/Dungsocool/CVE-2024-23897",
                "https://github.com/razureink/cve-2024-23897-jenkins_lfi_reproduction",
                "https://github.com/dheeraj-jayaswal/CICD-Goat-Vapt-Writeup",
                "https://github.com/MachiavelliII/CVE-2024-23897",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MURATAYDEMIR-CVE-2024-23897"
            ],
            "timeline": [
                {
                    "at": "2026-08-27T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2024-23774",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-23774 exploit",
            "summary": "Exploit for CVE-2024-23774. CVSS 7.8.",
            "updated_at": "2026-09-08T14:30:04Z",
            "published_at": "2026-09-08T14:30:04Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 58,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Unquoted Windows service path vulnerability in tools.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-23774",
                    "summary": "Unquoted Windows service path vulnerability in tools.",
                    "what_happened": "Unquoted Windows service path vulnerability in tools.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-VERRIDEO-CVE-2024-23774",
                        "https://kitploit.com/ru/tools/github/verrideo/cve-2024-23774/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T12:14:54",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-VERRIDEO-CVE-2024-23774"
                },
                {
                    "title": "Exploit for CVE-2024-23774",
                    "summary": "Unquoted Windows service path vulnerability in tools.",
                    "what_happened": "Unquoted Windows service path vulnerability in tools.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-VERRIDEO-CVE-2024-23774",
                        "https://kitploit.com/ru/tools/github/verrideo/cve-2024-23774/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-06T12:14:54",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/verrideo/cve-2024-23774/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-VERRIDEO-CVE-2024-23774",
                "https://kitploit.com/ru/tools/github/verrideo/cve-2024-23774/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T14:30:04Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-VERRIDEO-CVE-2024-23774"
                }
            ]
        },
        {
            "id": "CVE-2024-23673",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "apache__sling-org-apache-sling-servlets-resolver_CVE-2024-23673_2-10-0 exploit",
            "summary": "Exploit for CVE-2024-23673. CVSS 8.5.",
            "updated_at": "2026-09-13T18:29:55Z",
            "published_at": "2026-09-13T18:29:55Z",
            "cvss": 8.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:29:55+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "apache__sling-org-apache-sling-servlets-resolver_CVE-2024-23673_2-10-0 exploit",
                    "summary": "Exploit for CVE-2024-23673. CVSS 8.5.",
                    "cvss": 8.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHOUCHENG3-APACHE__SLING-ORG-APACHE-SLING-SERVLETS-RESOLVER_CVE-2024-23673_2-10-0"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHOUCHENG3-APACHE__SLING-ORG-APACHE-SLING-SERVLETS-RESOLVER_CVE-2024-23673_2-10-0"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:29:55Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHOUCHENG3-APACHE__SLING-ORG-APACHE-SLING-SERVLETS-RESOLVER_CVE-2024-23673_2-10-0"
                }
            ]
        },
        {
            "id": "CVE-2024-23334",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "aiohttp 3.9.1 - directory traversal PoC",
            "summary": "aiohttp 3.9.1 - directory traversal PoC",
            "updated_at": "2026-09-07T08:10:20Z",
            "published_at": "2026-09-07T08:10:20Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 142,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "LFI in aiohttp static routes via directory traversal allows unauthorized file access.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52474",
                    "author": "Beatriz Fresno Naumova",
                    "first_seen": "2026-02-04",
                    "confidence": "High",
                    "title": "aiohttp 3.9.1 - directory traversal PoC",
                    "summary": "aiohttp 3.9.1 - directory traversal PoC",
                    "url": "https://www.exploit-db.com/exploits/52474",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for LFI-aiohttp-CVE-2024-23334-PoC",
                    "summary": "LFI in aiohttp static routes via directory traversal allows unauthorized file access.",
                    "what_happened": "LFI in aiohttp static routes via directory traversal allows unauthorized file access.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THEREDP4NTHER-LFI-AIOHTTP-CVE-2024-23334-POC",
                        "https://kitploit.com/zh/tools/github/theredp4nther/lfi-aiohttp-cve-2024-23334-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T07:02:39",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THEREDP4NTHER-LFI-AIOHTTP-CVE-2024-23334-POC"
                },
                {
                    "title": "Exploit for LFI-aiohttp-CVE-2024-23334-PoC",
                    "summary": "LFI in aiohttp static routes via directory traversal allows unauthorized file access.",
                    "what_happened": "LFI in aiohttp static routes via directory traversal allows unauthorized file access.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THEREDP4NTHER-LFI-AIOHTTP-CVE-2024-23334-POC",
                        "https://kitploit.com/zh/tools/github/theredp4nther/lfi-aiohttp-cve-2024-23334-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-06T07:02:39",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/theredp4nther/lfi-aiohttp-cve-2024-23334-poc/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52474",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THEREDP4NTHER-LFI-AIOHTTP-CVE-2024-23334-POC",
                "https://kitploit.com/zh/tools/github/theredp4nther/lfi-aiohttp-cve-2024-23334-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:10:20Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52474"
                }
            ]
        },
        {
            "id": "CVE-2024-23176",
            "vendor": "MediaWiki",
            "product": "MassMessage",
            "title": "MassMessage vulnerability",
            "summary": "An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.",
            "updated_at": "2026-09-14T07:17:16.097",
            "published_at": "2026-09-14T07:17:16.097",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.40.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://lists.wikimedia.org/hyperkitty/list/mediawiki-announce@lists.wikimedia.org/message/TDBUBCCOQJUT4SCHJNPHKQNPBUUETY52/",
                "https://phabricator.wikimedia.org/T347742"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T07:17:16.097",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23176"
                }
            ]
        },
        {
            "id": "CVE-2024-22891",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-22891 exploit",
            "summary": "Exploit for CVE-2024-22891. CVSS 9.8.",
            "updated_at": "2026-09-14T18:32:46Z",
            "published_at": "2026-09-14T18:32:46Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "RCE in nteract 0.28.0 via Electron webview through Markdown link with nodeIntegration enabled.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-22891",
                    "summary": "RCE in nteract 0.28.0 via Electron webview through Markdown link with nodeIntegration enabled.",
                    "what_happened": "RCE in nteract 0.28.0 via Electron webview through Markdown link with nodeIntegration enabled.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EQSTLAB-CVE-2024-22891",
                        "https://kitploit.com/ja/tools/github/eqstlab/cve-2024-22891/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T21:46:38",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EQSTLAB-CVE-2024-22891"
                },
                {
                    "title": "Exploit for CVE-2024-22891",
                    "summary": "RCE in nteract 0.28.0 via Electron webview through Markdown link with nodeIntegration enabled.",
                    "what_happened": "RCE in nteract 0.28.0 via Electron webview through Markdown link with nodeIntegration enabled.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EQSTLAB-CVE-2024-22891",
                        "https://kitploit.com/ja/tools/github/eqstlab/cve-2024-22891/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-03T21:46:38",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/eqstlab/cve-2024-22891/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EQSTLAB-CVE-2024-22891",
                "https://kitploit.com/ja/tools/github/eqstlab/cve-2024-22891/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T18:32:46Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EQSTLAB-CVE-2024-22891"
                }
            ]
        },
        {
            "id": "CVE-2024-22373",
            "vendor": "Grassroot DICOM",
            "product": "Grassroot DICOM",
            "title": "Grassroot DICOM vulnerability",
            "summary": "An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.",
            "updated_at": "2026-09-10T06:17:01.230",
            "published_at": "2024-04-25T15:16:03.590",
            "cvss": 8.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "3.0.23",
            "fixed": "See vendor advisory",
            "source_count": 36,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-119",
            "what_happened": "An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "talosintelligence.com",
                    "author": "NVD reference",
                    "first_seen": "2024-04-25",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1935"
                }
            ],
            "references": [
                "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BZJ4IG7EXMSMPHTK5ZFASCW6MHSOVZOE/",
                "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N5HXUKUJ7SG3TK456SGUWVZ4Z5D7JKOL/",
                "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WJA7QWWZWMY4AQFR35EA7S3CFVUTOQYG/",
                "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1935",
                "http://www.openwall.com/lists/oss-security/2026/09/10/13",
                "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1935"
            ],
            "timeline": [
                {
                    "at": "2024-04-25T15:16:03.590",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22373"
                }
            ]
        },
        {
            "id": "CVE-2024-21887",
            "vendor": "Ivanti",
            "product": "Connect Secure and Policy Secure",
            "title": "Ivanti Connect Secure and Policy Secure Command Injection Vulnerability",
            "summary": "Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.",
            "updated_at": "2026-09-05T09:04:57Z",
            "published_at": "2026-09-05T09:04:57Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Gideon CVE-2024-21887",
                    "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                        "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T11:04:57",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON"
                },
                {
                    "title": "Exploit for Gideon CVE-2024-21887",
                    "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                        "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T11:04:57",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                "https://kitploit.com/ru/tools/github/cogensec/gideon/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T09:04:57Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2024-21762",
            "vendor": "Fortinet",
            "product": "FortiOS",
            "title": "Fortinet FortiOS Out-of-Bound Write Vulnerability",
            "summary": "Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.",
            "updated_at": "2026-08-31T22:00:00Z",
            "published_at": "2026-08-31T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 57,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · BishopFox/cve-2024-21762-check",
                    "author": "BishopFox",
                    "first_seen": "2024-02-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 107,
                    "title": "Safely detect whether a FortiGate SSL VPN is vulnerable to CVE-2024-21762",
                    "summary": "Safely detect whether a FortiGate SSL VPN is vulnerable to CVE-2024-21762",
                    "url": "https://github.com/BishopFox/cve-2024-21762-check"
                },
                {
                    "repository": "PoC-in-GitHub · h4x0r-dz/CVE-2024-21762",
                    "author": "h4x0r-dz",
                    "first_seen": "2024-03-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 150,
                    "title": "out-of-bounds write in Fortinet FortiOS  CVE-2024-21762 vulnerability",
                    "summary": "out-of-bounds write in Fortinet FortiOS  CVE-2024-21762 vulnerability",
                    "url": "https://github.com/h4x0r-dz/CVE-2024-21762"
                },
                {
                    "repository": "PoC-in-GitHub · r4p3c4/CVE-2024-21762-Exploit-PoC-Fortinet-SSL-VPN-Check",
                    "author": "r4p3c4",
                    "first_seen": "2024-03-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 16,
                    "title": "Chequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación)",
                    "summary": "Chequea si tu firewall es vulnerable a CVE-2024-21762 (RCE sin autenticación)",
                    "url": "https://github.com/r4p3c4/CVE-2024-21762-Exploit-PoC-Fortinet-SSL-VPN-Check"
                },
                {
                    "repository": "PoC-in-GitHub · d0rb/CVE-2024-21762",
                    "author": "d0rb",
                    "first_seen": "2024-03-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw.",
                    "summary": "The PoC demonstrates the potential for remote code execution by exploiting the identified security flaw.",
                    "url": "https://github.com/d0rb/CVE-2024-21762"
                },
                {
                    "repository": "PoC-in-GitHub · rdoix/cve-2024-21762-checker",
                    "author": "rdoix",
                    "first_seen": "2024-06-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-21762 repository",
                    "summary": "",
                    "url": "https://github.com/rdoix/cve-2024-21762-checker"
                },
                {
                    "repository": "PoC-in-GitHub · deFr0ggy/CVE-2024-21762-Checker",
                    "author": "deFr0ggy",
                    "first_seen": "2024-10-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given server is vulnerable to this CVE by sending specific requests and analyzing the responses.",
                    "summary": "This script performs vulnerability scanning for CVE-2024-21762, a Fortinet SSL VPN remote code execution vulnerability. It checks whether a given server is vulnerable to this CVE by sending specific requests and analyzing the responses.",
                    "url": "https://github.com/deFr0ggy/CVE-2024-21762-Checker"
                },
                {
                    "repository": "PoC-in-GitHub · CrackerCat/cve-2024-21762-poc",
                    "author": "CrackerCat",
                    "first_seen": "2025-04-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21762 是 Fortinet 公司的 FortiOS 和 FortiProxy 产品中的一个严重漏洞，存在于其 SSL VPN 组件中。",
                    "summary": "CVE-2024-21762 是 Fortinet 公司的 FortiOS 和 FortiProxy 产品中的一个严重漏洞，存在于其 SSL VPN 组件中。",
                    "url": "https://github.com/CrackerCat/cve-2024-21762-poc"
                },
                {
                    "repository": "PoC-in-GitHub · abrewer251/CVE-2024-21762_FortiNet_PoC",
                    "author": "abrewer251",
                    "first_seen": "2025-05-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.",
                    "summary": "Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.",
                    "url": "https://github.com/abrewer251/CVE-2024-21762_FortiNet_PoC"
                },
                {
                    "repository": "PoC-in-GitHub · 0x13-ByteZer0/CVE-2024-21762",
                    "author": "0x13-ByteZer0",
                    "first_seen": "2026-01-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21762 repository",
                    "summary": "",
                    "url": "https://github.com/0x13-ByteZer0/CVE-2024-21762"
                },
                {
                    "repository": "PoC-in-GitHub · 0x0asif/CVE-2024-21762",
                    "author": "0x0asif",
                    "first_seen": "2026-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21762 repository",
                    "summary": "",
                    "url": "https://github.com/0x0asif/CVE-2024-21762"
                },
                {
                    "repository": "PoC-in-GitHub · Sxmpl3/CVE-2024-21762-Safe-Check",
                    "author": "Sxmpl3",
                    "first_seen": "2026-06-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21762 repository",
                    "summary": "",
                    "url": "https://github.com/Sxmpl3/CVE-2024-21762-Safe-Check"
                },
                {
                    "repository": "PoC-in-GitHub · Vampsecure-Labs/vamp-forticheck",
                    "author": "Vampsecure-Labs",
                    "first_seen": "2026-07-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)",
                    "summary": "VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)",
                    "url": "https://github.com/Vampsecure-Labs/vamp-forticheck"
                },
                {
                    "repository": "PoC-in-GitHub · abraxas/Fortigate-SSL-VPN-Exploit-Kit",
                    "author": "abraxas",
                    "first_seen": "2026-09-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997.  79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.",
                    "summary": "The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997.  79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.",
                    "url": "https://github.com/abraxas/Fortigate-SSL-VPN-Exploit-Kit"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/BishopFox/cve-2024-21762-check",
                "https://github.com/h4x0r-dz/CVE-2024-21762",
                "https://github.com/r4p3c4/CVE-2024-21762-Exploit-PoC-Fortinet-SSL-VPN-Check",
                "https://github.com/d0rb/CVE-2024-21762",
                "https://github.com/rdoix/cve-2024-21762-checker",
                "https://github.com/deFr0ggy/CVE-2024-21762-Checker",
                "https://github.com/CrackerCat/cve-2024-21762-poc",
                "https://github.com/abrewer251/CVE-2024-21762_FortiNet_PoC",
                "https://github.com/0x13-ByteZer0/CVE-2024-21762",
                "https://github.com/0x0asif/CVE-2024-21762",
                "https://github.com/Sxmpl3/CVE-2024-21762-Safe-Check",
                "https://github.com/Vampsecure-Labs/vamp-forticheck",
                "https://github.com/abraxas/Fortigate-SSL-VPN-Exploit-Kit"
            ],
            "timeline": [
                {
                    "at": "2026-08-31T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-02-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-02-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-02-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-02-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2024-21733",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Sn1per CVE-2024-21733",
            "summary": "Sn1per Professional 2026 is an offensive-security platform for recon, scan, exploit, and reporting.",
            "updated_at": "2026-09-04T10:27:03Z",
            "published_at": "2026-09-04T10:27:03Z",
            "cvss": 5.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 51,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Sn1per Professional 2026 is an offensive-security platform for recon, scan, exploit, and reporting.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Sn1per CVE-2024-21733",
                    "summary": "Sn1per Professional 2026 is an offensive-security platform for recon, scan, exploit, and reporting.",
                    "what_happened": "Sn1per Professional 2026 is an offensive-security platform for recon, scan, exploit, and reporting.",
                    "cvss": 5.3,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-1N3-SN1PER",
                        "https://kitploit.com/ru/tools/github/1n3/sn1per/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T12:27:03",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-1N3-SN1PER"
                },
                {
                    "title": "Exploit for Sn1per CVE-2024-21733",
                    "summary": "Sn1per Professional 2026 is an offensive-security platform for recon, scan, exploit, and reporting.",
                    "what_happened": "Sn1per Professional 2026 is an offensive-security platform for recon, scan, exploit, and reporting.",
                    "cvss": 5.3,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-1N3-SN1PER",
                        "https://kitploit.com/ru/tools/github/1n3/sn1per/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T12:27:03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/1n3/sn1per/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-1N3-SN1PER",
                "https://kitploit.com/ru/tools/github/1n3/sn1per/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T10:27:03Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-1N3-SN1PER"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
        },
        {
            "id": "CVE-2024-21413",
            "vendor": "Microsoft",
            "product": "Office Outlook",
            "title": "Microsoft Outlook Improper Input Validation Vulnerability",
            "summary": "Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.",
            "updated_at": "2026-09-13T22:00:00Z",
            "published_at": "2026-09-13T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 337,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · duy-31/CVE-2024-21413",
                    "author": "duy-31",
                    "first_seen": "2024-02-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 156,
                    "title": "Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC",
                    "summary": "Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC",
                    "url": "https://github.com/duy-31/CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · xaitax/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability",
                    "author": "xaitax",
                    "first_seen": "2024-02-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 772,
                    "title": "Microsoft-Outlook-Remote-Code-Execution-Vulnerability",
                    "summary": "Microsoft-Outlook-Remote-Code-Execution-Vulnerability",
                    "url": "https://github.com/xaitax/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · r00tb1t/CVE-2024-21413-POC",
                    "author": "r00tb1t",
                    "first_seen": "2024-02-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - CVE-2024-21413 POC",
                    "summary": "Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - CVE-2024-21413 POC",
                    "url": "https://github.com/r00tb1t/CVE-2024-21413-POC"
                },
                {
                    "repository": "PoC-in-GitHub · CMNatic/CVE-2024-21413",
                    "author": "CMNatic",
                    "first_seen": "2024-02-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 283,
                    "title": "CVE-2024-21413 PoC for THM Lab",
                    "summary": "CVE-2024-21413 PoC for THM Lab",
                    "url": "https://github.com/CMNatic/CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · MSeymenD/CVE-2024-21413",
                    "author": "MSeymenD",
                    "first_seen": "2024-02-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21413 Açığını Kullanarak Giriş Bilgilerini Alma",
                    "summary": "CVE-2024-21413 Açığını Kullanarak Giriş Bilgilerini Alma",
                    "url": "https://github.com/MSeymenD/CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · Mdusmandasthaheer/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability",
                    "author": "Mdusmandasthaheer",
                    "first_seen": "2024-02-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2024-21413 repository",
                    "summary": "",
                    "url": "https://github.com/Mdusmandasthaheer/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · ahmetkarakayaoffical/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability",
                    "author": "ahmetkarakayaoffical",
                    "first_seen": "2024-02-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Bu betik, Microsoft Outlook'ta keşfedilen ve CVSS değeri 9.8 olan önemli bir güvenlik açığı olan CVE-2024-21413 için bir kavram kanıtı (PoC) sunmaktadır. MonikerLink hatası olarak adlandırılan bu güvenlik açığı, yerel NTLM bilgilerinin potansiyel sızıntısı ve uzaktan kod çalıştırma olasılığı dahil olmak üzere geniş kapsamlı etkilere sahiptir.",
                    "summary": "Bu betik, Microsoft Outlook'ta keşfedilen ve CVSS değeri 9.8 olan önemli bir güvenlik açığı olan CVE-2024-21413 için bir kavram kanıtı (PoC) sunmaktadır. MonikerLink hatası olarak adlandırılan bu güvenlik açığı, yerel NTLM bilgilerinin potansiyel sızıntısı ve uzaktan kod çalıştırma olasılığı dahil olmak üzere geniş kapsamlı etkilere sahiptir.",
                    "url": "https://github.com/ahmetkarakayaoffical/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · dshabani96/CVE-2024-21413",
                    "author": "dshabani96",
                    "first_seen": "2024-02-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2024-21413 repository",
                    "summary": "",
                    "url": "https://github.com/dshabani96/CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · KartheekKandalam99/SVPT_CW_2",
                    "author": "KartheekKandalam99",
                    "first_seen": "2024-04-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21413 Setup for CW",
                    "summary": "CVE-2024-21413 Setup for CW",
                    "url": "https://github.com/KartheekKandalam99/SVPT_CW_2"
                },
                {
                    "repository": "PoC-in-GitHub · X-Projetion/CVE-2024-21413-Microsoft-Outlook-RCE-Exploit",
                    "author": "X-Projetion",
                    "first_seen": "2024-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2024-21413 Microsoft Outlook RCE Exploit",
                    "summary": "CVE-2024-21413 Microsoft Outlook RCE Exploit",
                    "url": "https://github.com/X-Projetion/CVE-2024-21413-Microsoft-Outlook-RCE-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · th3Hellion/CVE-2024-21413",
                    "author": "th3Hellion",
                    "first_seen": "2024-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21413 repository",
                    "summary": "",
                    "url": "https://github.com/th3Hellion/CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · ShubhamKanhere307/CVE-2024-21413",
                    "author": "ShubhamKanhere307",
                    "first_seen": "2024-06-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This script is the Proof of Concept (PoC) of the CVE-2024-21413, a significant security vulnerability discovered in the Microsoft Windows Outlook having a strong 9.8 critical CVSS score. Named as #MonikerLink Bug, this vulnerability allows the attacker to execute the arbitrary code remotely on the victim's machine, thus becomes a full-fledged RCE.",
                    "summary": "This script is the Proof of Concept (PoC) of the CVE-2024-21413, a significant security vulnerability discovered in the Microsoft Windows Outlook having a strong 9.8 critical CVSS score. Named as #MonikerLink Bug, this vulnerability allows the attacker to execute the arbitrary code remotely on the victim's machine, thus becomes a full-fledged RCE.",
                    "url": "https://github.com/ShubhamKanhere307/CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · olebris/CVE-2024-21413",
                    "author": "olebris",
                    "first_seen": "2024-06-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21413 PoC",
                    "summary": "CVE-2024-21413 PoC",
                    "url": "https://github.com/olebris/CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · Redfox-Security/Unveiling-Moniker-Link-CVE-2024-21413-Navigating-the-Latest-Cybersecurity-Landscape",
                    "author": "Redfox-Security",
                    "first_seen": "2024-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21413 repository",
                    "summary": "",
                    "url": "https://github.com/Redfox-Security/Unveiling-Moniker-Link-CVE-2024-21413-Navigating-the-Latest-Cybersecurity-Landscape"
                },
                {
                    "repository": "PoC-in-GitHub · ThemeHackers/CVE-2024-21413",
                    "author": "ThemeHackers",
                    "first_seen": "2024-08-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC",
                    "summary": "CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC",
                    "url": "https://github.com/ThemeHackers/CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · D1se0/CVE-2024-21413-Vulnerabilidad-Outlook-LAB",
                    "author": "D1se0",
                    "first_seen": "2024-12-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2024-21413 repository",
                    "summary": "",
                    "url": "https://github.com/D1se0/CVE-2024-21413-Vulnerabilidad-Outlook-LAB"
                },
                {
                    "repository": "PoC-in-GitHub · ArtemCyberLab/Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413",
                    "author": "ArtemCyberLab",
                    "first_seen": "2025-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks using email. This showcases how network authentication vulnerabilities and phishing methods can be exploited to compromise systems.",
                    "summary": "The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks using email. This showcases how network authentication vulnerabilities and phishing methods can be exploited to compromise systems.",
                    "url": "https://github.com/ArtemCyberLab/Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · PolarisXSec/CVE-2024-21413",
                    "author": "PolarisXSec",
                    "first_seen": "2025-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-21413 repository",
                    "summary": "",
                    "url": "https://github.com/PolarisXSec/CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · MQKGitHub/Moniker-Link-CVE-2024-21413",
                    "author": "MQKGitHub",
                    "first_seen": "2025-05-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21413 repository",
                    "summary": "",
                    "url": "https://github.com/MQKGitHub/Moniker-Link-CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · yass2400012/Email-exploit-Moniker-Link-CVE-2024-21413-",
                    "author": "yass2400012",
                    "first_seen": "2025-09-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21413 repository",
                    "summary": "",
                    "url": "https://github.com/yass2400012/Email-exploit-Moniker-Link-CVE-2024-21413-"
                },
                {
                    "repository": "PoC-in-GitHub · gurleen-147/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability-PoC",
                    "author": "gurleen-147",
                    "first_seen": "2025-11-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "This repository contains research notes and a high-level proof-of-concept (PoC) for CVE-2024-21413, a vulnerability observed in certain mail clients when handling SMB/moniker-style links embedded in messages. The PoC and experiments documented here were performed in a controlled lab environment on systems.",
                    "summary": "This repository contains research notes and a high-level proof-of-concept (PoC) for CVE-2024-21413, a vulnerability observed in certain mail clients when handling SMB/moniker-style links embedded in messages. The PoC and experiments documented here were performed in a controlled lab environment on systems.",
                    "url": "https://github.com/gurleen-147/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · hau2212/Moniker-Link-CVE-2024-21413-",
                    "author": "hau2212",
                    "first_seen": "2025-11-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "On February 13th, 2024, Microsoft announced a Microsoft Outlook RCE & credential leak vulnerability with the assigned CVE of CVE-2024-21413 (Moniker Link). Haifei Li of Check Point Research is credited with discovering the vulnerability.  The vulnerability bypasses Outlook's security mechanisms when handing a specific type of hyperlink .",
                    "summary": "On February 13th, 2024, Microsoft announced a Microsoft Outlook RCE & credential leak vulnerability with the assigned CVE of CVE-2024-21413 (Moniker Link). Haifei Li of Check Point Research is credited with discovering the vulnerability.  The vulnerability bypasses Outlook's security mechanisms when handing a specific type of hyperlink .",
                    "url": "https://github.com/hau2212/Moniker-Link-CVE-2024-21413-"
                },
                {
                    "repository": "PoC-in-GitHub · mmathivanan17/CVE-2024-21413",
                    "author": "mmathivanan17",
                    "first_seen": "2025-11-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "Outlook exploitation",
                    "summary": "Outlook exploitation",
                    "url": "https://github.com/mmathivanan17/CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · eylommaayan/THM---CVE-2024-21413-Moniker-Link-Microsoft-Outlook-",
                    "author": "eylommaayan",
                    "first_seen": "2026-01-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "ב־13 בפברואר 2024 פרסמה Microsoft חולשת אבטחה חמורה ב־Microsoft Outlook, אשר קיבלה את הזיהוי CVE-2024-21413, ומוכרת בשם Moniker Link Vulnerability.  החולשה מאפשרת לתוקף לעקוף את מנגנון Protected View של Outlook",
                    "summary": "ב־13 בפברואר 2024 פרסמה Microsoft חולשת אבטחה חמורה ב־Microsoft Outlook, אשר קיבלה את הזיהוי CVE-2024-21413, ומוכרת בשם Moniker Link Vulnerability.  החולשה מאפשרת לתוקף לעקוף את מנגנון Protected View של Outlook",
                    "url": "https://github.com/eylommaayan/THM---CVE-2024-21413-Moniker-Link-Microsoft-Outlook-"
                },
                {
                    "repository": "PoC-in-GitHub · ViniciusFariasDev/cve-2024-21413-outlook-monikerlink-lab",
                    "author": "ViniciusFariasDev",
                    "first_seen": "2026-01-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21413 repository",
                    "summary": "",
                    "url": "https://github.com/ViniciusFariasDev/cve-2024-21413-outlook-monikerlink-lab"
                },
                {
                    "repository": "PoC-in-GitHub · dionissh/CVE-2024-21413",
                    "author": "dionissh",
                    "first_seen": "2026-01-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21413 repository",
                    "summary": "",
                    "url": "https://github.com/dionissh/CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · securenetexpert/CVE-2024-21413-Moniker-Link-Writeup",
                    "author": "securenetexpert",
                    "first_seen": "2026-02-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Technical write-up on CVE-2024-21413 (Moniker Link vulnerability)",
                    "summary": "Technical write-up on CVE-2024-21413 (Moniker Link vulnerability)",
                    "url": "https://github.com/securenetexpert/CVE-2024-21413-Moniker-Link-Writeup"
                },
                {
                    "repository": "PoC-in-GitHub · SallocinAvalcante/lab-SMB-responder-CVE-2024-21413",
                    "author": "SallocinAvalcante",
                    "first_seen": "2026-02-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Laboratorio criado para PenTest da Vuln CVE 2024-214113(MONIKER LINK).",
                    "summary": "Laboratorio criado para PenTest da Vuln CVE 2024-214113(MONIKER LINK).",
                    "url": "https://github.com/SallocinAvalcante/lab-SMB-responder-CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · E-m-e-k-a/Moniker-Link-Lab-Setup",
                    "author": "E-m-e-k-a",
                    "first_seen": "2026-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking, and defensive countermeasures",
                    "summary": "Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking, and defensive countermeasures",
                    "url": "https://github.com/E-m-e-k-a/Moniker-Link-Lab-Setup"
                },
                {
                    "repository": "PoC-in-GitHub · TheMursalin/HTB-Mailing-A-Complete-Walkthrough",
                    "author": "TheMursalin",
                    "first_seen": "2026-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "If you've been grinding through HackTheBox machines, Mailing is one of those boxes that genuinely teaches you something. It's rated Easy, runs on Windows, and chains together a few real-world vulnerabilities — a directory traversal, a credential leak, CVE-2024-21413, and a LibreOffice macro exploit. Let's walk through it step by step.",
                    "summary": "If you've been grinding through HackTheBox machines, Mailing is one of those boxes that genuinely teaches you something. It's rated Easy, runs on Windows, and chains together a few real-world vulnerabilities — a directory traversal, a credential leak, CVE-2024-21413, and a LibreOffice macro exploit. Let's walk through it step by step.",
                    "url": "https://github.com/TheMursalin/HTB-Mailing-A-Complete-Walkthrough"
                },
                {
                    "repository": "PoC-in-GitHub · pedro-lucas-melo/Estudo-de-Caso-CVE-2024-21413",
                    "author": "pedro-lucas-melo",
                    "first_seen": "2026-04-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Um estudo de caso do CVE-2024-21413. Usado como parâmetro a sala do TryHackMe Moniker Link (CVE-2024-21413). Feito edições com claude code no exploit.",
                    "summary": "Um estudo de caso do CVE-2024-21413. Usado como parâmetro a sala do TryHackMe Moniker Link (CVE-2024-21413). Feito edições com claude code no exploit.",
                    "url": "https://github.com/pedro-lucas-melo/Estudo-de-Caso-CVE-2024-21413"
                },
                {
                    "repository": "PoC-in-GitHub · FathanahHidayati/https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability",
                    "author": "FathanahHidayati",
                    "first_seen": "2026-04-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21413 repository",
                    "summary": "",
                    "url": "https://github.com/FathanahHidayati/https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · bhatbhupendra/Moniker-Link--CVE-2024-21413-",
                    "author": "bhatbhupendra",
                    "first_seen": "2026-04-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21413 repository",
                    "summary": "",
                    "url": "https://github.com/bhatbhupendra/Moniker-Link--CVE-2024-21413-"
                },
                {
                    "repository": "PoC-in-GitHub · KaiHaoChen04/monikerlinktest",
                    "author": "KaiHaoChen04",
                    "first_seen": "2026-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "cve-2024-21413",
                    "summary": "cve-2024-21413",
                    "url": "https://github.com/KaiHaoChen04/monikerlinktest"
                },
                {
                    "repository": "PoC-in-GitHub · Dhananjayasj/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability",
                    "author": "Dhananjayasj",
                    "first_seen": "2026-05-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21413 repository",
                    "summary": "",
                    "url": "https://github.com/Dhananjayasj/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · H1ssBl1tz/Blind-Trust-CVE-2024-21413-Research",
                    "author": "H1ssBl1tz",
                    "first_seen": "2026-06-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A security research tool for simulating targeted phishing campaigns  using CVE-2024-21413 (Moniker Link).",
                    "summary": "A security research tool for simulating targeted phishing campaigns  using CVE-2024-21413 (Moniker Link).",
                    "url": "https://github.com/H1ssBl1tz/Blind-Trust-CVE-2024-21413-Research"
                },
                {
                    "repository": "PoC-in-GitHub · YoguiCR/CVE-2024-21413-Outlook-Assessment",
                    "author": "YoguiCR",
                    "first_seen": "2026-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-21413 repository",
                    "summary": "",
                    "url": "https://github.com/YoguiCR/CVE-2024-21413-Outlook-Assessment"
                },
                {
                    "repository": "PoC-in-GitHub · h4cknain/CVE-2024-21413-Microsoft-Outlook-Moniker-Link-Vulnerability",
                    "author": "h4cknain",
                    "first_seen": "2026-08-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository documents my hands-on analysis of **CVE-2024-21413 (Moniker Link)**, a critical Microsoft Outlook vulnerability that bypasses Protected View to leak Windows NetNTLMv2 credentials via SMB authentication.  > **Severity:** Critical (CVSS 9.8)",
                    "summary": "This repository documents my hands-on analysis of **CVE-2024-21413 (Moniker Link)**, a critical Microsoft Outlook vulnerability that bypasses Protected View to leak Windows NetNTLMv2 credentials via SMB authentication.  > **Severity:** Critical (CVSS 9.8)",
                    "url": "https://github.com/h4cknain/CVE-2024-21413-Microsoft-Outlook-Moniker-Link-Vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · OmarMahmoud1024/tryhackme-monikerlink-writeup",
                    "author": "OmarMahmoud1024",
                    "first_seen": "2026-08-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "TryHackMe Moniker Link (CVE-2024-21413) walkthrough: Outlook Protected View bypass leading to NTLMv2 hash capture via a crafted moniker link.",
                    "summary": "TryHackMe Moniker Link (CVE-2024-21413) walkthrough: Outlook Protected View bypass leading to NTLMv2 hash capture via a crafted moniker link.",
                    "url": "https://github.com/OmarMahmoud1024/tryhackme-monikerlink-writeup"
                },
                {
                    "repository": "PoC-in-GitHub · yfelipecruvinel/tryhackme-moniker-link",
                    "author": "yfelipecruvinel",
                    "first_seen": "2026-08-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Documentation of my  hands-on lab Moniker Link (CVE-2024-21413) completed on TryHackMe.",
                    "summary": "Documentation of my  hands-on lab Moniker Link (CVE-2024-21413) completed on TryHackMe.",
                    "url": "https://github.com/yfelipecruvinel/tryhackme-moniker-link"
                },
                {
                    "repository": "PoC-in-GitHub · shauryarathore357-hub/thm-Moniker-Link-cve-2024-21413-writeup",
                    "author": "shauryarathore357-hub",
                    "first_seen": "2026-09-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "TRYHACKME \"Moniker Link (CVE-2024-21413)\" room walkthrough ~",
                    "summary": "TRYHACKME \"Moniker Link (CVE-2024-21413)\" room walkthrough ~",
                    "url": "https://github.com/shauryarathore357-hub/thm-Moniker-Link-cve-2024-21413-writeup"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/duy-31/CVE-2024-21413",
                "https://github.com/xaitax/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability",
                "https://github.com/r00tb1t/CVE-2024-21413-POC",
                "https://github.com/CMNatic/CVE-2024-21413",
                "https://github.com/MSeymenD/CVE-2024-21413",
                "https://github.com/Mdusmandasthaheer/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability",
                "https://github.com/ahmetkarakayaoffical/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability",
                "https://github.com/dshabani96/CVE-2024-21413",
                "https://github.com/KartheekKandalam99/SVPT_CW_2",
                "https://github.com/X-Projetion/CVE-2024-21413-Microsoft-Outlook-RCE-Exploit",
                "https://github.com/th3Hellion/CVE-2024-21413",
                "https://github.com/ShubhamKanhere307/CVE-2024-21413",
                "https://github.com/olebris/CVE-2024-21413",
                "https://github.com/Redfox-Security/Unveiling-Moniker-Link-CVE-2024-21413-Navigating-the-Latest-Cybersecurity-Landscape",
                "https://github.com/ThemeHackers/CVE-2024-21413",
                "https://github.com/D1se0/CVE-2024-21413-Vulnerabilidad-Outlook-LAB",
                "https://github.com/ArtemCyberLab/Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413",
                "https://github.com/PolarisXSec/CVE-2024-21413",
                "https://github.com/MQKGitHub/Moniker-Link-CVE-2024-21413",
                "https://github.com/yass2400012/Email-exploit-Moniker-Link-CVE-2024-21413-",
                "https://github.com/gurleen-147/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability-PoC",
                "https://github.com/hau2212/Moniker-Link-CVE-2024-21413-",
                "https://github.com/mmathivanan17/CVE-2024-21413",
                "https://github.com/eylommaayan/THM---CVE-2024-21413-Moniker-Link-Microsoft-Outlook-",
                "https://github.com/ViniciusFariasDev/cve-2024-21413-outlook-monikerlink-lab",
                "https://github.com/dionissh/CVE-2024-21413",
                "https://github.com/securenetexpert/CVE-2024-21413-Moniker-Link-Writeup",
                "https://github.com/SallocinAvalcante/lab-SMB-responder-CVE-2024-21413",
                "https://github.com/E-m-e-k-a/Moniker-Link-Lab-Setup",
                "https://github.com/TheMursalin/HTB-Mailing-A-Complete-Walkthrough",
                "https://github.com/pedro-lucas-melo/Estudo-de-Caso-CVE-2024-21413",
                "https://github.com/FathanahHidayati/https-github.com-xaitax-CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability",
                "https://github.com/bhatbhupendra/Moniker-Link--CVE-2024-21413-",
                "https://github.com/KaiHaoChen04/monikerlinktest",
                "https://github.com/Dhananjayasj/CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability",
                "https://github.com/H1ssBl1tz/Blind-Trust-CVE-2024-21413-Research",
                "https://github.com/YoguiCR/CVE-2024-21413-Outlook-Assessment",
                "https://github.com/h4cknain/CVE-2024-21413-Microsoft-Outlook-Moniker-Link-Vulnerability",
                "https://github.com/OmarMahmoud1024/tryhackme-monikerlink-writeup",
                "https://github.com/yfelipecruvinel/tryhackme-moniker-link",
                "https://github.com/shauryarathore357-hub/thm-Moniker-Link-cve-2024-21413-writeup"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2024-21400",
            "vendor": "Microsoft",
            "product": "Azure Kubernetes Service",
            "title": "Azure Kubernetes Service vulnerability",
            "summary": "Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability",
            "updated_at": "2026-09-14T13:44:43.017",
            "published_at": "2024-03-12T17:15:49.797",
            "cvss": 9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1.0.0 through before 0.3.3 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-22",
            "what_happened": "Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21400"
            ],
            "timeline": [
                {
                    "at": "2024-03-12T17:15:49.797",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21400"
                }
            ]
        },
        {
            "id": "CVE-2024-20931",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2024-20931_weblogic",
            "summary": "Vulnerability CVE-2024-20931 in WebLogic tools component.",
            "updated_at": "2026-09-05T16:22:20Z",
            "published_at": "2026-09-05T16:22:20Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 55,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Vulnerability CVE-2024-20931 in WebLogic tools component.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-20931_weblogic",
                    "summary": "Vulnerability CVE-2024-20931 in WebLogic tools component.",
                    "what_happened": "Vulnerability CVE-2024-20931 in WebLogic tools component.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ATONYSAN-CVE-2024-20931_WEBLOGIC",
                        "https://kitploit.com/ar/tools/github/atonysan/cve-2024-20931_weblogic/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T18:22:20",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ATONYSAN-CVE-2024-20931_WEBLOGIC"
                },
                {
                    "title": "Exploit for CVE-2024-20931_weblogic",
                    "summary": "Vulnerability CVE-2024-20931 in WebLogic tools component.",
                    "what_happened": "Vulnerability CVE-2024-20931 in WebLogic tools component.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ATONYSAN-CVE-2024-20931_WEBLOGIC",
                        "https://kitploit.com/ar/tools/github/atonysan/cve-2024-20931_weblogic/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-05T18:22:20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/atonysan/cve-2024-20931_weblogic/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ATONYSAN-CVE-2024-20931_WEBLOGIC",
                "https://kitploit.com/ar/tools/github/atonysan/cve-2024-20931_weblogic/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T16:22:20Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ATONYSAN-CVE-2024-20931_WEBLOGIC"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2024-20260",
            "vendor": "Cisco",
            "product": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software",
            "title": "Cisco Secure Firewall Adaptive Security Appliance (ASA) Software vulnerability",
            "summary": "Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software platforms.\r\n\r\nA vulnerability in the VPN and management web servers of the Cisco Secure Firewall ASA Software and Cisco Secure FTD Software platforms could allow an unauthenticated, remote attacker to cause an affected device to run out of system memory or buffer blocks, which in turn could cause SSL VPN connection processing to slow down and eventually cease altogether.\r\nThis vulnerability is due to a lack of proper memory management for new incoming SSL/TLS connections. An attacker could exploit this vulnerability by sending a large number of new incoming SSL/TLS connections to the targeted device. A successful exploit could allow the attacker to deplete system memory or buffers, resulting in a denial of service (DoS) condition. The memory or buffers could be reclaimed slowly if the attack traffic is stopped, but a manual reload may be required to restore operations quickly.",
            "updated_at": "2026-09-16T21:17:05.947",
            "published_at": "2024-10-23T17:15:13.950",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "9.16.1; 9.16.1.28; 9.16.2; 9.16.2.3; 9.16.2.7; 9.16.2.11; 9.16.2.13; 9.16.2.14; 9.16.3.3; 9.16.3; 9.16.3.14; 9.18.1; 9.16.3.15; 9.18.1.3; 9.18.2; 9.16.3.19; 9.16.3.23; 9.18.2.5; 9.16.4; 9.18.2.7; 9.19.1; 9.16.4.9; 9.18.2.8; 9.16.4.14; 9.18.3; 9.19.1.5; 9.16.4.18; 9.19.1.9; 9.18.3.39; 9.16.4.19; 9.19.1.12; 9.18.3.46; 9.16.4.27; 9.19.1.18; 9.18.3.53; 9.18.3.55; 9.16.4.38; 9.16.4.39; 9.18.3.56; 9.20.1; 9.16.4.42; 9.19.1.22; 9.18.4; 9.20.1.5; 9.18.4.5; 9.19.1.24; 9.16.4.48; 9.18.4.8; 9.20.2; 9.19.1.27; 9.16.4.55; 9.18.4.22; 9.20.2.10; 9.16.4.57; 9.19.1.28; 9.18.4.24; 9.20.2.21; 9.16.4.61; 9.19.1.31; 9.18.4.29; 9.20.2.22; 9.16.4.62; 9.18.4.34; 9.20.3; 9.16.4.67; 9.16.4.70; 9.18.4.40; 9.23.1; 9.22.1.1; 9.16.4.71; 9.20.3.4; 9.18.4.47; 9.20.3.7; 9.19.1.37; 9.16.4.76; 9.20.3.9; 9.19.1.38; 9.18.4.50; 9.22.1.3; 9.20.3.10; 9.22.1.2; 9.18.4.52; 9.20.3.13; 9.22.1.6; 9.18.4.53; 9.16.4.82; 9.22.2; 9.20.3.16; 9.19.1.42; 9.18.4.57; 9.16.4.84; 9.23.1.3; 9.20.3.20; 9.22.2.4; 9.23.1.7; 9.20.4; 9.22.2.9; 9.23.1.13; 9.20.4.7; 9.22.2.13; 9.18.4.66; 9.20.4.10; 9.23.1.19; 9.16.4.85; 9.22.2.14; 9.18.4.67; 9.18.4.68; 9.23.1.22; 9.20.4.14; 9.22.2.20; 9.20.4.19; 9.16.4.89; 9.16.4.92; 7.0.0; 7.0.0.1; 7.0.1; 7.0.1.1; 7.0.2; 7.2.0; 7.0.2.1; 7.0.3; 7.2.0.1; 7.0.4; 7.2.1; 7.0.5; 7.3.0; 7.2.2; 7.2.3; 7.3.1; 7.2.4; 7.0.6; 7.2.5; 7.2.4.1; 7.3.1.1; 7.4.0; 7.0.6.1; 7.2.5.1; 7.4.1; 7.2.6; 7.0.6.2; 7.4.1.1; 7.2.7; 7.2.5.2; 7.3.1.2; 7.2.8; 7.6.0; 7.4.2; 7.2.8.1; 7.0.6.3; 7.4.2.1; 7.2.9; 7.0.7; 7.7.0; 7.4.2.2; 7.2.10; 7.6.1; 7.4.2.3; 7.0.8; 7.6.2; 7.7.10; 7.7.11; 7.0.8.1; 7.6.2.1; 7.7.10.1; 7.4.2.4; 7.2.10.2; 7.4.3; 7.6.4; 7.0.9; 6.2.3 through 6.2.3.18 (custom); 7.4.1 through 7.4.1.1 (custom); 7.3.0 through 7.3.1.2 (custom); 7.2.0 through 7.2.8.1 (custom); 7.1.0 through 7.1.0.3 (custom); 7.0.0 through 7.0.6.2 (custom); 6.7.0 through 6.7.0.3 (custom); 6.6.0 through 6.6.7.2 (custom); 6.4.0 through 6.4.0.18 (custom); 9.8.1 through 9.8.4.48 (custom); 9.20.2 through 9.20.2.21 (custom); 9.19.1 through 9.19.1.31 (custom); 9.18.1 through 9.18.4.29 (custom); 9.17.1 through 19.17.1.39 (custom); 9.16.1 through 9.16.4.61 (custom); 9.15.1 through 9.15.1.21 (custom); 9.14.1 through 9.14.4.24 (custom); 9.12.1 through 9.12.4.67 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-789",
            "what_happened": "Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software platforms.\r\n\r\nA vulnerability in the VPN and management web servers of the Cisco Secure Firewall ASA Software and Cisco Secure FTD Software platforms could allow an unauthenticated, remote attacker to cause an affected device to run out of system memory or buffer blocks, which in turn could cause SSL VPN connection processing to slow down and eventually cease altogether.\r\nThis vulnerability is due to a lack of proper memory management for new incoming SSL/TLS connections. An attacker could exploit this vulnerability by sending a large number of new incoming SSL/TLS connections to the targeted device. A successful exploit could allow the attacker to deplete system memory or buffers, resulting in a denial of service (DoS) condition. The memory or buffers could be reclaimed slowly if the attack traffic is stopped, but a manual reload may be required to restore operations quickly.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftdvirtual-dos-MuenGnYR"
            ],
            "timeline": [
                {
                    "at": "2024-10-23T17:15:13.950",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20260"
                }
            ]
        },
        {
            "id": "CVE-2024-13869",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-13869 exploit",
            "summary": "Exploit for CVE-2024-13869. CVSS 7.2.",
            "updated_at": "2026-09-15T08:38:24Z",
            "published_at": "2026-09-15T08:38:24Z",
            "cvss": 7.2,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Authenticated arbitrary file upload in WPvivid <= 0.9.112 enabling code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-13869",
                    "summary": "Authenticated arbitrary file upload in WPvivid <= 0.9.112 enabling code execution.",
                    "what_happened": "Authenticated arbitrary file upload in WPvivid <= 0.9.112 enabling code execution.",
                    "cvss": 7.2,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D0N601-CVE-2024-13869",
                        "https://kitploit.com/ja/tools/github/d0n601/cve-2024-13869/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T08:45:34",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D0N601-CVE-2024-13869"
                },
                {
                    "title": "Exploit for CVE-2024-13869",
                    "summary": "Authenticated arbitrary file upload in WPvivid <= 0.9.112 enabling code execution.",
                    "what_happened": "Authenticated arbitrary file upload in WPvivid <= 0.9.112 enabling code execution.",
                    "cvss": 7.2,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D0N601-CVE-2024-13869",
                        "https://kitploit.com/ja/tools/github/d0n601/cve-2024-13869/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-03T08:45:34",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/d0n601/cve-2024-13869/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D0N601-CVE-2024-13869",
                "https://kitploit.com/ja/tools/github/d0n601/cve-2024-13869/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:38:24Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D0N601-CVE-2024-13869"
                }
            ]
        },
        {
            "id": "CVE-2024-13159",
            "vendor": "Ivanti",
            "product": "Endpoint Manager (EPM)",
            "title": "Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability",
            "summary": "Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.",
            "updated_at": "2026-09-11T18:30:39Z",
            "published_at": "2026-09-11T18:30:39Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 61,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Ivanti-EPM-Coercion-Vulnerabilities CVE-2024-13159",
                    "summary": "Unauthenticated coercion of Ivanti EPM machine credential enabling relay attacks (CVE-2024-13159).",
                    "what_happened": "Unauthenticated coercion of Ivanti EPM machine credential enabling relay attacks (CVE-2024-13159).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HORIZON3AI-IVANTI-EPM-COERCION-VULNERABILITIES",
                        "https://kitploit.com/ru/tools/github/horizon3ai/ivanti-epm-coercion-vulnerabilities/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T09:07:08",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HORIZON3AI-IVANTI-EPM-COERCION-VULNERABILITIES"
                },
                {
                    "title": "Exploit for Ivanti-EPM-Coercion-Vulnerabilities CVE-2024-13159",
                    "summary": "Unauthenticated coercion of Ivanti EPM machine credential enabling relay attacks (CVE-2024-13159).",
                    "what_happened": "Unauthenticated coercion of Ivanti EPM machine credential enabling relay attacks (CVE-2024-13159).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HORIZON3AI-IVANTI-EPM-COERCION-VULNERABILITIES",
                        "https://kitploit.com/ru/tools/github/horizon3ai/ivanti-epm-coercion-vulnerabilities/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T09:07:08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/horizon3ai/ivanti-epm-coercion-vulnerabilities/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HORIZON3AI-IVANTI-EPM-COERCION-VULNERABILITIES",
                "https://kitploit.com/ru/tools/github/horizon3ai/ivanti-epm-coercion-vulnerabilities/"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T18:30:39Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2024-12381",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2024-12381-PoC",
            "summary": "Proof of concept repository for CVE-2024-12381 containing exploit tools.",
            "updated_at": "2026-08-29T06:34:26Z",
            "published_at": "2026-08-29T06:34:26Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 107,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Proof of concept repository for CVE-2024-12381 containing exploit tools.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-12381-PoC",
                    "summary": "Proof of concept repository for CVE-2024-12381 containing exploit tools.",
                    "what_happened": "Proof of concept repository for CVE-2024-12381 containing exploit tools.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FATFISHIO-CVE-2024-12381-POC",
                        "https://kitploit.com/it/tools/github/fatfishio/cve-2024-12381-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-29T08:34:26",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FATFISHIO-CVE-2024-12381-POC"
                },
                {
                    "title": "Exploit for CVE-2024-12381-PoC",
                    "summary": "Proof of concept repository for CVE-2024-12381 containing exploit tools.",
                    "what_happened": "Proof of concept repository for CVE-2024-12381 containing exploit tools.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FATFISHIO-CVE-2024-12381-POC",
                        "https://kitploit.com/it/tools/github/fatfishio/cve-2024-12381-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "it",
                    "first_seen": "2026-08-29T08:34:26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/it/tools/github/fatfishio/cve-2024-12381-poc/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FATFISHIO-CVE-2024-12381-POC",
                "https://kitploit.com/it/tools/github/fatfishio/cve-2024-12381-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-08-29T06:34:26Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FATFISHIO-CVE-2024-12381-POC"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2024-12356",
            "vendor": "BeyondTrust",
            "product": "Privileged Remote Access (PRA) and Remote Support (RS)",
            "title": "BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability",
            "summary": "BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.",
            "updated_at": "2026-09-03T22:00:00Z",
            "published_at": "2026-09-03T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 83,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · skraft9/CVE-2024-12356",
                    "author": "skraft9",
                    "first_seen": "2026-09-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Unauthenticated RCE detector + RCA for BeyondTrust Remote Support / PRA (CVE-2024-12356 + CVE-2025-1094)",
                    "summary": "Unauthenticated RCE detector + RCA for BeyondTrust Remote Support / PRA (CVE-2024-12356 + CVE-2025-1094)",
                    "url": "https://github.com/skraft9/CVE-2024-12356"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/skraft9/CVE-2024-12356"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-12-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2024-11831",
            "vendor": "Red Hat",
            "product": "Red Hat Advanced Cluster Security 4.4",
            "title": "Red Hat Advanced Cluster Security 4.4 vulnerability",
            "summary": "A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.",
            "updated_at": "2026-09-08T16:17:47.957",
            "published_at": "2025-02-10T16:15:37.080",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.0 through before 6.0.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 25,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHBA-2025:0304",
                "https://access.redhat.com/errata/RHSA-2025:0381",
                "https://access.redhat.com/errata/RHSA-2025:10853",
                "https://access.redhat.com/errata/RHSA-2025:1334",
                "https://access.redhat.com/errata/RHSA-2025:1468",
                "https://access.redhat.com/errata/RHSA-2025:21068",
                "https://access.redhat.com/errata/RHSA-2025:21203",
                "https://access.redhat.com/errata/RHSA-2025:3870",
                "https://access.redhat.com/errata/RHSA-2025:4511",
                "https://access.redhat.com/errata/RHSA-2025:8059",
                "https://access.redhat.com/errata/RHSA-2025:8078",
                "https://access.redhat.com/errata/RHSA-2025:8233",
                "https://access.redhat.com/errata/RHSA-2025:8479",
                "https://access.redhat.com/errata/RHSA-2025:8512",
                "https://access.redhat.com/errata/RHSA-2025:8544",
                "https://access.redhat.com/errata/RHSA-2025:8551",
                "https://access.redhat.com/errata/RHSA-2025:9294",
                "https://access.redhat.com/errata/RHSA-2026:1536",
                "https://access.redhat.com/errata/RHSA-2026:2769",
                "https://access.redhat.com/errata/RHSA-2026:62115",
                "https://access.redhat.com/errata/RHSA-2026:8568",
                "https://access.redhat.com/security/cve/CVE-2024-11831",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2312579",
                "https://github.com/yahoo/serialize-javascript/commit/f27d65d3de42affe2aac14607066c293891cec4e",
                "https://github.com/yahoo/serialize-javascript/pull/173"
            ],
            "timeline": [
                {
                    "at": "2025-02-10T16:15:37.080",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11831"
                }
            ]
        },
        {
            "id": "CVE-2024-11616",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-11616 exploit",
            "summary": "Exploit for CVE-2024-11616. CVSS 5.6.",
            "updated_at": "2026-09-08T01:15:14Z",
            "published_at": "2026-09-08T01:15:14Z",
            "cvss": 5.6,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 64,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Vulnerability in the tools repository, which lacks a README.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-11616",
                    "summary": "Vulnerability in the tools repository, which lacks a README.",
                    "what_happened": "Vulnerability in the tools repository, which lacks a README.",
                    "cvss": 5.6,
                    "cvss_vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/SC:N/VI:N/SI:L/VA:H/SA:N",
                    "attack_vector": "Local",
                    "authentication": "High",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-INB1TS-CVE-2024-11616",
                        "https://kitploit.com/ar/tools/github/inb1ts/cve-2024-11616/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T03:26:34",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-INB1TS-CVE-2024-11616"
                },
                {
                    "title": "Exploit for CVE-2024-11616",
                    "summary": "Vulnerability in the tools repository, which lacks a README.",
                    "what_happened": "Vulnerability in the tools repository, which lacks a README.",
                    "cvss": 5.6,
                    "cvss_vector": "CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/SC:N/VI:N/SI:L/VA:H/SA:N",
                    "attack_vector": "Local",
                    "authentication": "High",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-INB1TS-CVE-2024-11616",
                        "https://kitploit.com/ar/tools/github/inb1ts/cve-2024-11616/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-04T03:26:34",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/inb1ts/cve-2024-11616/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-INB1TS-CVE-2024-11616",
                "https://kitploit.com/ar/tools/github/inb1ts/cve-2024-11616/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:15:14Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-INB1TS-CVE-2024-11616"
                }
            ]
        },
        {
            "id": "CVE-2024-11080",
            "vendor": "pickplugins",
            "product": "Post Grid",
            "title": "Post Grid vulnerability",
            "summary": "The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress, granted no other security controls are present in the function.",
            "updated_at": "2026-09-05T09:16:48.880",
            "published_at": "2026-09-05T09:16:48.880",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.2.85 through 2.3.32 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress, granted no other security controls are present in the function.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://plugins.trac.wordpress.org/browser/post-grid/trunk/includes/blocks/form-wrap/functions.php#L116",
                "https://plugins.trac.wordpress.org/browser/post-grid/trunk/includes/blocks/form-wrap/functions.php#L262",
                "https://plugins.trac.wordpress.org/browser/post-grid/trunk/includes/blocks/form-wrap/functions.php#L3249",
                "https://www.wordfence.com/threat-intel/vulnerabilities/id/ec8666d4-042e-4cf4-86f5-474a69d90ff6?source=cve"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T09:16:48.880",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11080"
                }
            ]
        },
        {
            "id": "CVE-2024-10914",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "D-Link DNS_340L - OS Command Injection",
            "summary": "D-Link DNS_340L - OS Command Injection",
            "updated_at": "2026-08-16T22:00:00Z",
            "published_at": "2026-08-16T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52643",
                    "author": "Jared Brits",
                    "first_seen": "2026-08-17",
                    "confidence": "High",
                    "title": "D-Link DNS_340L - OS Command Injection",
                    "summary": "D-Link DNS_340L - OS Command Injection",
                    "url": "https://www.exploit-db.com/exploits/52643",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52643"
            ],
            "timeline": [
                {
                    "at": "2026-08-16T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52643"
                }
            ]
        },
        {
            "id": "CVE-2024-10220",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for cve-2024-10220 CVE-2024-10220",
            "summary": "Vulnerability in the tools repository identified as CVE-2024-10220.",
            "updated_at": "2026-09-10T09:03:22Z",
            "published_at": "2026-09-10T09:03:22Z",
            "cvss": 8.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Vulnerability in the tools repository identified as CVE-2024-10220.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for cve-2024-10220 CVE-2024-10220",
                    "summary": "Vulnerability in the tools repository identified as CVE-2024-10220.",
                    "what_happened": "Vulnerability in the tools repository identified as CVE-2024-10220.",
                    "cvss": 8.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANY2SEC-CVE-2024-10220",
                        "https://kitploit.com/ru/tools/github/any2sec/cve-2024-10220/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-10T11:03:22",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANY2SEC-CVE-2024-10220"
                },
                {
                    "title": "Exploit for cve-2024-10220 CVE-2024-10220",
                    "summary": "Vulnerability in the tools repository identified as CVE-2024-10220.",
                    "what_happened": "Vulnerability in the tools repository identified as CVE-2024-10220.",
                    "cvss": 8.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANY2SEC-CVE-2024-10220",
                        "https://kitploit.com/ru/tools/github/any2sec/cve-2024-10220/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-10T11:03:22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/any2sec/cve-2024-10220/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANY2SEC-CVE-2024-10220",
                "https://kitploit.com/ru/tools/github/any2sec/cve-2024-10220/"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T09:03:22Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANY2SEC-CVE-2024-10220"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2024-9680",
            "vendor": "Mozilla",
            "product": "Firefox",
            "title": "Mozilla Firefox Use-After-Free Vulnerability",
            "summary": "Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.",
            "updated_at": "2026-09-11T12:40:53Z",
            "published_at": "2026-09-11T12:40:53Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 39,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Firefox-CVE-2024-9680",
                    "summary": "Use-after-free in Firefox Animation timelines enabling content process code execution.",
                    "what_happened": "Use-after-free in Firefox Animation timelines enabling content process code execution.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TDONAWORTH-FIREFOX-CVE-2024-9680",
                        "https://kitploit.com/zh/tools/github/tdonaworth/firefox-cve-2024-9680/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-11T14:40:53",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TDONAWORTH-FIREFOX-CVE-2024-9680"
                },
                {
                    "title": "Exploit for Firefox-CVE-2024-9680",
                    "summary": "Use-after-free in Firefox Animation timelines enabling content process code execution.",
                    "what_happened": "Use-after-free in Firefox Animation timelines enabling content process code execution.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TDONAWORTH-FIREFOX-CVE-2024-9680",
                        "https://kitploit.com/zh/tools/github/tdonaworth/firefox-cve-2024-9680/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-11T14:40:53",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/tdonaworth/firefox-cve-2024-9680/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TDONAWORTH-FIREFOX-CVE-2024-9680",
                "https://kitploit.com/zh/tools/github/tdonaworth/firefox-cve-2024-9680/"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T12:40:53Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-10-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-10-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-10-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-10-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-10-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-10-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-10-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-10-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-10-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-10-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-10-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-10-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2024-9355",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
            "title": "Red Hat Enterprise Linux 7 Extended Lifecycle Support vulnerability",
            "summary": "A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.",
            "updated_at": "2026-09-09T17:17:10.500",
            "published_at": "2024-10-01T19:15:09.793",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 18,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-457",
            "what_happened": "A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2024:10133",
                "https://access.redhat.com/errata/RHSA-2024:7502",
                "https://access.redhat.com/errata/RHSA-2024:7550",
                "https://access.redhat.com/errata/RHSA-2024:8327",
                "https://access.redhat.com/errata/RHSA-2024:8678",
                "https://access.redhat.com/errata/RHSA-2024:8847",
                "https://access.redhat.com/errata/RHSA-2024:9551",
                "https://access.redhat.com/errata/RHSA-2025:2416",
                "https://access.redhat.com/errata/RHSA-2025:7118",
                "https://access.redhat.com/errata/RHSA-2025:7256",
                "https://access.redhat.com/errata/RHSA-2025:7624",
                "https://access.redhat.com/errata/RHSA-2026:55520",
                "https://access.redhat.com/errata/RHSA-2026:55525",
                "https://access.redhat.com/errata/RHSA-2026:59439",
                "https://access.redhat.com/errata/RHSA-2026:66016",
                "https://access.redhat.com/security/cve/CVE-2024-9355",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2315719",
                "https://github.com/golang-fips/openssl/pull/198"
            ],
            "timeline": [
                {
                    "at": "2024-10-01T19:15:09.793",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9355"
                }
            ]
        },
        {
            "id": "CVE-2024-8447",
            "vendor": "Red Hat",
            "product": "Red Hat JBoss EAP XP 5.0 Update 2.0",
            "title": "Red Hat JBoss EAP XP 5.0 Update 2.0 vulnerability",
            "summary": "A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.",
            "updated_at": "2026-09-07T15:17:29.960",
            "published_at": "2025-01-02T21:15:10.303",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 7.1.0.Final (semver)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-833",
            "what_happened": "A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2025:3357",
                "https://access.redhat.com/errata/RHSA-2025:3358",
                "https://access.redhat.com/errata/RHSA-2025:7620",
                "https://access.redhat.com/security/cve/CVE-2024-8447",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2335206",
                "https://github.com/jbosstm/narayana/pull/2293"
            ],
            "timeline": [
                {
                    "at": "2025-01-02T21:15:10.303",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8447"
                }
            ]
        },
        {
            "id": "CVE-2024-7804",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Docker lab + Python exploit for CVE-2024-7804 (PyTorch torch.distributed.rpc unsafe pickle deserialization RCE, CWE-502, torch <= 2.3.1)",
            "summary": "Docker lab + Python exploit for CVE-2024-7804 (PyTorch torch.distributed.rpc unsafe pickle deserialization RCE, CWE-502, torch <= 2.3.1)",
            "updated_at": "2026-09-05T22:00:00Z",
            "published_at": "2026-09-05T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 37,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · joaovicdev/CVE-2024-7804",
                    "author": "joaovicdev",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Docker lab + Python exploit for CVE-2024-7804 (PyTorch torch.distributed.rpc unsafe pickle deserialization RCE, CWE-502, torch <= 2.3.1)",
                    "summary": "Docker lab + Python exploit for CVE-2024-7804 (PyTorch torch.distributed.rpc unsafe pickle deserialization RCE, CWE-502, torch <= 2.3.1)",
                    "url": "https://github.com/joaovicdev/CVE-2024-7804"
                }
            ],
            "references": [
                "https://github.com/joaovicdev/CVE-2024-7804"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/joaovicdev/CVE-2024-7804"
                }
            ]
        },
        {
            "id": "CVE-2024-7344",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Research on CVE-2024-7344, a Secure Boot bypass affecting Howyar SysReturn through an untrusted EFI payload loading mechanism.",
            "summary": "Research on CVE-2024-7344, a Secure Boot bypass affecting Howyar SysReturn through an untrusted EFI payload loading mechanism.",
            "updated_at": "2026-09-10T22:00:00Z",
            "published_at": "2026-09-10T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 64,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · TheMalwareGuardian/CVE-2024-7344",
                    "author": "TheMalwareGuardian",
                    "first_seen": "2026-02-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Research on CVE-2024-7344, a Secure Boot bypass affecting Howyar SysReturn through an untrusted EFI payload loading mechanism.",
                    "summary": "Research on CVE-2024-7344, a Secure Boot bypass affecting Howyar SysReturn through an untrusted EFI payload loading mechanism.",
                    "url": "https://github.com/TheMalwareGuardian/CVE-2024-7344"
                },
                {
                    "repository": "PoC-in-GitHub · TheMalwareGuardian/UEFI-Security-Research-Howyar-SysReturn-NetCopy",
                    "author": "TheMalwareGuardian",
                    "first_seen": "2026-06-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Post CVE-2024-7344 analysis of Howyar SysReturn NetCopy - reverse engineering notes, vulnerable binaries, vendor correspondence, and proof-of-concept tooling for CVE-2026-79298 (IA-32 Secure Boot bypass via the RxPE custom PE loader in BOOTia32.efi).",
                    "summary": "Post CVE-2024-7344 analysis of Howyar SysReturn NetCopy - reverse engineering notes, vulnerable binaries, vendor correspondence, and proof-of-concept tooling for CVE-2026-79298 (IA-32 Secure Boot bypass via the RxPE custom PE loader in BOOTia32.efi).",
                    "url": "https://github.com/TheMalwareGuardian/UEFI-Security-Research-Howyar-SysReturn-NetCopy"
                },
                {
                    "repository": "PoC-in-GitHub · TheMalwareGuardian/CVE-2026-79298",
                    "author": "TheMalwareGuardian",
                    "first_seen": "2026-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2026-79298 - Incomplete remediation of UEFI Secure Boot bypass in Howyar SysReturn. The IA-32 boot path (BOOTia32.efi) was never patched after CVE-2024-7344, shipping the same revoked custom PE loader until July 2026.",
                    "summary": "CVE-2026-79298 - Incomplete remediation of UEFI Secure Boot bypass in Howyar SysReturn. The IA-32 boot path (BOOTia32.efi) was never patched after CVE-2024-7344, shipping the same revoked custom PE loader until July 2026.",
                    "url": "https://github.com/TheMalwareGuardian/CVE-2026-79298"
                }
            ],
            "references": [
                "https://github.com/TheMalwareGuardian/CVE-2024-7344",
                "https://github.com/TheMalwareGuardian/UEFI-Security-Research-Howyar-SysReturn-NetCopy",
                "https://github.com/TheMalwareGuardian/CVE-2026-79298"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/TheMalwareGuardian/CVE-2024-7344"
                }
            ]
        },
        {
            "id": "CVE-2024-7049",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "summary": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "updated_at": "2026-09-11T10:16:49.593",
            "published_at": "2024-10-10T08:15:03.910",
            "cvss": 0,
            "cvss_vector": "",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "See CVSS vector",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [],
            "timeline": [
                {
                    "at": "2024-10-10T08:15:03.910",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7049"
                }
            ]
        },
        {
            "id": "CVE-2024-6387",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 9",
            "title": "OpenSSH server (sshd) 9.8p1 - Race Condition",
            "summary": "OpenSSH server (sshd) 9.8p1 - Race Condition",
            "updated_at": "2026-09-01T12:17:13.423",
            "published_at": "2024-07-01T13:15:06.467",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "8.5p1 through 9.7p1 (custom); before * (custom); V3.1.5 through before * (custom); before V1.0 HF1 (custom); before V3.2 SP2 (custom); before V6.24 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2965,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-364",
            "what_happened": "Multi-target OpenSSH version checker script for CVE-2024-6387 using nmap banner scanning.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52269",
                    "author": "Milad karimi",
                    "first_seen": "2025-04-22",
                    "confidence": "High",
                    "title": "OpenSSH server (sshd) 9.8p1 - Race Condition",
                    "summary": "OpenSSH server (sshd) 9.8p1 - Race Condition",
                    "url": "https://www.exploit-db.com/exploits/52269",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2023-4596-OpenSSH-Multi-Checker CVE-2023-4596 CVE-2024-6387",
                    "summary": "Multi-target OpenSSH version checker script for CVE-2024-6387 using nmap banner scanning.",
                    "what_happened": "Multi-target OpenSSH version checker script for CVE-2024-6387 using nmap banner scanning.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-PROJETION-CVE-2023-4596-OPENSSH-MULTI-CHECKER",
                        "https://kitploit.com/ru/tools/github/x-projetion/cve-2023-4596-openssh-multi-checker/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-02T13:01:51",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-PROJETION-CVE-2023-4596-OPENSSH-MULTI-CHECKER"
                },
                {
                    "title": "Exploit for CVE-2023-4596-OpenSSH-Multi-Checker CVE-2023-4596 CVE-2024-6387",
                    "summary": "Multi-target OpenSSH version checker script for CVE-2024-6387 using nmap banner scanning.",
                    "what_happened": "Multi-target OpenSSH version checker script for CVE-2024-6387 using nmap banner scanning.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-PROJETION-CVE-2023-4596-OPENSSH-MULTI-CHECKER",
                        "https://kitploit.com/ru/tools/github/x-projetion/cve-2023-4596-openssh-multi-checker/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-02T13:01:51",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/x-projetion/cve-2023-4596-openssh-multi-checker/"
                },
                {
                    "title": "Exploit for CVE-2024-6387-OpenSSH-Analysis",
                    "summary": "Race condition in OpenSSH sshd allowing unauthorised remote attacker to execute code.",
                    "what_happened": "Race condition in OpenSSH sshd allowing unauthorised remote attacker to execute code.",
                    "cvss": 8.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AL7ARAZIRUBY-JPG-CVE-2024-6387-OPENSSH-ANALYSIS",
                        "https://kitploit.com/ru/tools/github/al7araziruby-jpg/cve-2024-6387-openssh-analysis/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-01T13:59:43",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AL7ARAZIRUBY-JPG-CVE-2024-6387-OPENSSH-ANALYSIS"
                },
                {
                    "title": "Exploit for CVE-2024-6387-OpenSSH-Analysis",
                    "summary": "Race condition in OpenSSH sshd allowing unauthorised remote attacker to execute code.",
                    "what_happened": "Race condition in OpenSSH sshd allowing unauthorised remote attacker to execute code.",
                    "cvss": 8.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AL7ARAZIRUBY-JPG-CVE-2024-6387-OPENSSH-ANALYSIS",
                        "https://kitploit.com/ru/tools/github/al7araziruby-jpg/cve-2024-6387-openssh-analysis/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-01T13:59:43",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/al7araziruby-jpg/cve-2024-6387-openssh-analysis/"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-08T01:20:02+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2024-6387-Check exploit",
                    "summary": "Exploit for CVE-2024-6387. CVSS 8.1.",
                    "cvss": 8.1,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DEVARSHISHIMPI-CVE-2024-6387-CHECK"
                },
                {
                    "repository": "santandersecurityresearch.github.io",
                    "author": "NVD reference",
                    "first_seen": "2024-07-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://santandersecurityresearch.github.io/blog/sshing_the_masses.html"
                },
                {
                    "repository": "www.qualys.com",
                    "author": "NVD reference",
                    "first_seen": "2024-07-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt"
                },
                {
                    "repository": "www.openwall.com",
                    "author": "NVD reference",
                    "first_seen": "2024-07-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://www.openwall.com/lists/oss-security/2024/07/03/11"
                },
                {
                    "repository": "www.openwall.com",
                    "author": "NVD reference",
                    "first_seen": "2024-07-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://www.openwall.com/lists/oss-security/2024/07/04/2"
                },
                {
                    "repository": "www.openwall.com",
                    "author": "NVD reference",
                    "first_seen": "2024-07-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://www.openwall.com/lists/oss-security/2024/07/08/2"
                },
                {
                    "repository": "www.openwall.com",
                    "author": "NVD reference",
                    "first_seen": "2024-07-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://www.openwall.com/lists/oss-security/2024/07/09/5"
                },
                {
                    "repository": "www.openwall.com",
                    "author": "NVD reference",
                    "first_seen": "2024-07-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://www.openwall.com/lists/oss-security/2024/07/10/1"
                },
                {
                    "repository": "www.vicarius.io",
                    "author": "NVD reference",
                    "first_seen": "2024-07-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://www.vicarius.io/vsociety/posts/regresshion-an-openssh-regression-error-cve-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · 7etsuo/cve-2024-6387-poc",
                    "author": "7etsuo",
                    "first_seen": "2024-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "a signal handler race condition in OpenSSH's server (sshd)",
                    "summary": "a signal handler race condition in OpenSSH's server (sshd)",
                    "url": "https://github.com/7etsuo/cve-2024-6387-poc"
                },
                {
                    "repository": "PoC-in-GitHub · zgzhang/cve-2024-6387-poc",
                    "author": "zgzhang",
                    "first_seen": "2024-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 497,
                    "title": "a signal handler race condition in OpenSSH's server (sshd)",
                    "summary": "a signal handler race condition in OpenSSH's server (sshd)",
                    "url": "https://github.com/zgzhang/cve-2024-6387-poc"
                },
                {
                    "repository": "PoC-in-GitHub · acrono/cve-2024-6387-poc",
                    "author": "acrono",
                    "first_seen": "2024-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 378,
                    "title": "32-bit PoC for CVE-2024-6387 — mirror of the original 7etsuo/cve-2024-6387-poc",
                    "summary": "32-bit PoC for CVE-2024-6387 — mirror of the original 7etsuo/cve-2024-6387-poc",
                    "url": "https://github.com/acrono/cve-2024-6387-poc"
                },
                {
                    "repository": "PoC-in-GitHub · lflare/cve-2024-6387-poc",
                    "author": "lflare",
                    "first_seen": "2024-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 129,
                    "title": "MIRROR of the original 32-bit PoC for CVE-2024-6387 \"regreSSHion\" by 7etsuo/cve-2024-6387-poc",
                    "summary": "MIRROR of the original 32-bit PoC for CVE-2024-6387 \"regreSSHion\" by 7etsuo/cve-2024-6387-poc",
                    "url": "https://github.com/lflare/cve-2024-6387-poc"
                },
                {
                    "repository": "PoC-in-GitHub · getdrive/CVE-2024-6387-PoC",
                    "author": "getdrive",
                    "first_seen": "2024-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "PoC RCE in OpenSSH",
                    "summary": "PoC RCE in OpenSSH",
                    "url": "https://github.com/getdrive/CVE-2024-6387-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · FerasAlrimali/CVE-2024-6387-POC",
                    "author": "FerasAlrimali",
                    "first_seen": "2024-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "SSHd cve-2024-6387-poc",
                    "summary": "SSHd cve-2024-6387-poc",
                    "url": "https://github.com/FerasAlrimali/CVE-2024-6387-POC"
                },
                {
                    "repository": "PoC-in-GitHub · passwa11/cve-2024-6387-poc",
                    "author": "passwa11",
                    "first_seen": "2024-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/passwa11/cve-2024-6387-poc"
                },
                {
                    "repository": "PoC-in-GitHub · jack0we/CVE-2024-6387",
                    "author": "jack0we",
                    "first_seen": "2024-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/jack0we/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · xaitax/CVE-2024-6387_Check",
                    "author": "xaitax",
                    "first_seen": "2024-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 528,
                    "title": "CVE-2024-6387_Check is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH",
                    "summary": "CVE-2024-6387_Check is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH",
                    "url": "https://github.com/xaitax/CVE-2024-6387_Check"
                },
                {
                    "repository": "PoC-in-GitHub · bigb0x/CVE-2024-6387",
                    "author": "bigb0x",
                    "first_seen": "2024-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 35,
                    "title": "Bulk Scanning Tool for OpenSSH  CVE-2024-6387, CVE-2006-5051 , CVE-2008-4109 and others.",
                    "summary": "Bulk Scanning Tool for OpenSSH  CVE-2024-6387, CVE-2006-5051 , CVE-2008-4109 and others.",
                    "url": "https://github.com/bigb0x/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · wiggels/regresshion-check",
                    "author": "wiggels",
                    "first_seen": "2024-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CLI Tool to Check SSH Servers for Vulnerability to CVE-2024-6387",
                    "summary": "CLI Tool to Check SSH Servers for Vulnerability to CVE-2024-6387",
                    "url": "https://github.com/wiggels/regresshion-check"
                },
                {
                    "repository": "PoC-in-GitHub · P4x1s/CVE-2024-6387",
                    "author": "P4x1s",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "SSH RCE PoC CVE-2024-6387",
                    "summary": "SSH RCE PoC CVE-2024-6387",
                    "url": "https://github.com/P4x1s/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · betancour/OpenSSH-Vulnerability-test",
                    "author": "betancour",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "OpenSSH CVE-2024-6387 Vulnerability Checker",
                    "summary": "OpenSSH CVE-2024-6387 Vulnerability Checker",
                    "url": "https://github.com/betancour/OpenSSH-Vulnerability-test"
                },
                {
                    "repository": "PoC-in-GitHub · muyuanlove/CVE-2024-6387fixshell",
                    "author": "muyuanlove",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/muyuanlove/CVE-2024-6387fixshell"
                },
                {
                    "repository": "PoC-in-GitHub · TAM-K592/CVE-2024-6387",
                    "author": "TAM-K592",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "Recently, the OpenSSH maintainers released security updates to fix a critical vulnerability that could lead to unauthenticated remote code execution (RCE) with root privileges. This vulnerability, identified as CVE-2024-6387, resides in the OpenSSH server component (sshd), which is designed to listen for connections from client applications.",
                    "summary": "Recently, the OpenSSH maintainers released security updates to fix a critical vulnerability that could lead to unauthenticated remote code execution (RCE) with root privileges. This vulnerability, identified as CVE-2024-6387, resides in the OpenSSH server component (sshd), which is designed to listen for connections from client applications.",
                    "url": "https://github.com/TAM-K592/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · teamos-hub/regreSSHion",
                    "author": "teamos-hub",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This is a POC I wrote for CVE-2024-6387",
                    "summary": "This is a POC I wrote for CVE-2024-6387",
                    "url": "https://github.com/teamos-hub/regreSSHion"
                },
                {
                    "repository": "PoC-in-GitHub · ahlfors/CVE-2024-6387",
                    "author": "ahlfors",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/ahlfors/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · Mufti22/CVE-2024-6387-checkher",
                    "author": "Mufti22",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/Mufti22/CVE-2024-6387-checkher"
                },
                {
                    "repository": "PoC-in-GitHub · thegenetic/CVE-2024-6387-exploit",
                    "author": "thegenetic",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "CVE-2024-6387 exploit",
                    "summary": "CVE-2024-6387 exploit",
                    "url": "https://github.com/thegenetic/CVE-2024-6387-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · R4Tw1z/CVE-2024-6387",
                    "author": "R4Tw1z",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This script, created by R4Tw1z, is designed to scan IP addresses to check if they are running a potentially vulnerable version of OpenSSH. The tool leverages multi-threading to optimize scanning performance and handle multiple IP addresses concurrently.",
                    "summary": "This script, created by R4Tw1z, is designed to scan IP addresses to check if they are running a potentially vulnerable version of OpenSSH. The tool leverages multi-threading to optimize scanning performance and handle multiple IP addresses concurrently.",
                    "url": "https://github.com/R4Tw1z/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · d0rb/CVE-2024-6387",
                    "author": "d0rb",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 52,
                    "title": "This Python script exploits a remote code execution vulnerability (CVE-2024-6387) in OpenSSH.",
                    "summary": "This Python script exploits a remote code execution vulnerability (CVE-2024-6387) in OpenSSH.",
                    "url": "https://github.com/d0rb/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · CiderAndWhisky/regression-scanner",
                    "author": "CiderAndWhisky",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Used to detect ssh servers vulnerable to CVE-2024-6387. Shameless robbery from https://github.com/bigb0x/CVE-2024-6387 using ChatGPT to translate the code to PHP.",
                    "summary": "Used to detect ssh servers vulnerable to CVE-2024-6387. Shameless robbery from https://github.com/bigb0x/CVE-2024-6387 using ChatGPT to translate the code to PHP.",
                    "url": "https://github.com/CiderAndWhisky/regression-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · shamo0/CVE-2024-6387_PoC",
                    "author": "shamo0",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Script for checking CVE-2024-6387 (regreSSHion)",
                    "summary": "Script for checking CVE-2024-6387 (regreSSHion)",
                    "url": "https://github.com/shamo0/CVE-2024-6387_PoC"
                },
                {
                    "repository": "PoC-in-GitHub · paradessia/CVE-2024-6387-nmap",
                    "author": "paradessia",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2024-6387-nmap",
                    "summary": "CVE-2024-6387-nmap",
                    "url": "https://github.com/paradessia/CVE-2024-6387-nmap"
                },
                {
                    "repository": "PoC-in-GitHub · PrincipalAnthony/CVE-2024-6387-Updated-x64bit",
                    "author": "PrincipalAnthony",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Private x64 RCE exploit for CVE-2024-6387 [02.07.2024] from exploit.in",
                    "summary": "Private x64 RCE exploit for CVE-2024-6387 [02.07.2024] from exploit.in",
                    "url": "https://github.com/PrincipalAnthony/CVE-2024-6387-Updated-x64bit"
                },
                {
                    "repository": "PoC-in-GitHub · daniel-odrinski/CVE-2024-6387-Mitigation-Ansible-Playbook",
                    "author": "daniel-odrinski",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "An Ansible Playbook to mitigate the risk of RCE (CVE-2024-6387) until platforms update OpenSSH to a non-vulnerable version.",
                    "summary": "An Ansible Playbook to mitigate the risk of RCE (CVE-2024-6387) until platforms update OpenSSH to a non-vulnerable version.",
                    "url": "https://github.com/daniel-odrinski/CVE-2024-6387-Mitigation-Ansible-Playbook"
                },
                {
                    "repository": "PoC-in-GitHub · rumochnaya/openssh-cve-2024-6387.sh",
                    "author": "rumochnaya",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "openssh-cve-2024-6387.sh",
                    "summary": "openssh-cve-2024-6387.sh",
                    "url": "https://github.com/rumochnaya/openssh-cve-2024-6387.sh"
                },
                {
                    "repository": "PoC-in-GitHub · zenzue/CVE-2024-6387-Mitigation",
                    "author": "zenzue",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Mitigation Guide for CVE-2024-6387 in OpenSSH",
                    "summary": "Mitigation Guide for CVE-2024-6387 in OpenSSH",
                    "url": "https://github.com/zenzue/CVE-2024-6387-Mitigation"
                },
                {
                    "repository": "PoC-in-GitHub · devarshishimpi/CVE-2024-6387-Check",
                    "author": "devarshishimpi",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "Fast, efficient, and reliable detection for the regreSSHion exploit. Scan multiple targets in seconds with zero dependencies.",
                    "summary": "Fast, efficient, and reliable detection for the regreSSHion exploit. Scan multiple targets in seconds with zero dependencies.",
                    "url": "https://github.com/devarshishimpi/CVE-2024-6387-Check"
                },
                {
                    "repository": "PoC-in-GitHub · hssmo/cve-2024-6387_AImade",
                    "author": "hssmo",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "cve-2024-6387_AImade",
                    "summary": "cve-2024-6387_AImade",
                    "url": "https://github.com/hssmo/cve-2024-6387_AImade"
                },
                {
                    "repository": "PoC-in-GitHub · ACHUX21/checker-CVE-2024-6387",
                    "author": "ACHUX21",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Python scanner that checks hosts for the OpenSSH regreSSHion vulnerability (CVE-2024-6387)",
                    "summary": "Python scanner that checks hosts for the OpenSSH regreSSHion vulnerability (CVE-2024-6387)",
                    "url": "https://github.com/ACHUX21/checker-CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · AiGptCode/ssh_exploiter_CVE-2024-6387",
                    "author": "AiGptCode",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "CVE-2024-6387 with auto ip scanner and auto expliot",
                    "summary": "CVE-2024-6387 with auto ip scanner and auto expliot",
                    "url": "https://github.com/AiGptCode/ssh_exploiter_CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · xristos8574/regreSSHion-nmap-scanner",
                    "author": "xristos8574",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A bash script for nmap to scan for vulnerable machines in regards to the latest CVE-2024-6387",
                    "summary": "A bash script for nmap to scan for vulnerable machines in regards to the latest CVE-2024-6387",
                    "url": "https://github.com/xristos8574/regreSSHion-nmap-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · particle99/CVE-2024-6387-POC",
                    "author": "particle99",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "fork for proof of concept of the regresshion vulnerability",
                    "summary": "fork for proof of concept of the regresshion vulnerability",
                    "url": "https://github.com/particle99/CVE-2024-6387-POC"
                },
                {
                    "repository": "PoC-in-GitHub · xonoxitron/regreSSHion",
                    "author": "xonoxitron",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 69,
                    "title": "CVE-2024-6387 (regreSSHion) Exploit (PoC), a vulnerability in OpenSSH's server (sshd) on glibc-based Linux systems.",
                    "summary": "CVE-2024-6387 (regreSSHion) Exploit (PoC), a vulnerability in OpenSSH's server (sshd) on glibc-based Linux systems.",
                    "url": "https://github.com/xonoxitron/regreSSHion"
                },
                {
                    "repository": "PoC-in-GitHub · no-one-sec/CVE-2024-6387",
                    "author": "no-one-sec",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "开箱即用的AK47",
                    "summary": "开箱即用的AK47",
                    "url": "https://github.com/no-one-sec/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · dawnl3ss/CVE-2024-6387",
                    "author": "dawnl3ss",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/dawnl3ss/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · MrR0b0t19/CVE-2024-6387-Exploit-POC",
                    "author": "MrR0b0t19",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/MrR0b0t19/CVE-2024-6387-Exploit-POC"
                },
                {
                    "repository": "PoC-in-GitHub · th3gokul/CVE-2024-6387",
                    "author": "th3gokul",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2024-6387 : Vulnerability Detection tool  for regreSSHion Remote Unauthenticated Code Execution in OpenSSH Server",
                    "summary": "CVE-2024-6387 : Vulnerability Detection tool  for regreSSHion Remote Unauthenticated Code Execution in OpenSSH Server",
                    "url": "https://github.com/th3gokul/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · n1cks0n/Test_CVE-2024-6387",
                    "author": "n1cks0n",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Test_CVE-2024-6387 is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH",
                    "summary": "Test_CVE-2024-6387 is a lightweight, efficient tool designed to identify servers running vulnerable versions of OpenSSH",
                    "url": "https://github.com/n1cks0n/Test_CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · l0n3m4n/CVE-2024-6387",
                    "author": "l0n3m4n",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 113,
                    "title": "PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)",
                    "summary": "PoC - Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (Scanner and Exploit)",
                    "url": "https://github.com/l0n3m4n/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · RickGeex/CVE-2024-6387-Checker",
                    "author": "RickGeex",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2024-6387-Check is a streamlined and efficient tool created to detect servers operating on vulnerable versions of OpenSSH.",
                    "summary": "CVE-2024-6387-Check is a streamlined and efficient tool created to detect servers operating on vulnerable versions of OpenSSH.",
                    "url": "https://github.com/RickGeex/CVE-2024-6387-Checker"
                },
                {
                    "repository": "PoC-in-GitHub · xonoxitron/regreSSHion-checker",
                    "author": "xonoxitron",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "Quickly identifies servers vulnerable to OpenSSH 'regreSSHion' (CVE-2024-6387).",
                    "summary": "Quickly identifies servers vulnerable to OpenSSH 'regreSSHion' (CVE-2024-6387).",
                    "url": "https://github.com/xonoxitron/regreSSHion-checker"
                },
                {
                    "repository": "PoC-in-GitHub · BrandonLynch2402/cve-2024-6387-nuclei-template",
                    "author": "BrandonLynch2402",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/BrandonLynch2402/cve-2024-6387-nuclei-template"
                },
                {
                    "repository": "PoC-in-GitHub · edsonjt81/CVE-2024-6387_Check",
                    "author": "edsonjt81",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/edsonjt81/CVE-2024-6387_Check"
                },
                {
                    "repository": "PoC-in-GitHub · grupooruss/CVE-2024-6387",
                    "author": "grupooruss",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "regreSSHion vulnerability in OpenSSH CVE-2024-6387 Testing Script",
                    "summary": "regreSSHion vulnerability in OpenSSH CVE-2024-6387 Testing Script",
                    "url": "https://github.com/grupooruss/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · CognisysGroup/CVE-2024-6387-Checker",
                    "author": "CognisysGroup",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/CognisysGroup/CVE-2024-6387-Checker"
                },
                {
                    "repository": "PoC-in-GitHub · sxlmnwb/CVE-2024-6387",
                    "author": "sxlmnwb",
                    "first_seen": "2024-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 21,
                    "title": "Targeting a signal handler race condition in OpenSSH's server (sshd) on glibc-based Linux systems.",
                    "summary": "Targeting a signal handler race condition in OpenSSH's server (sshd) on glibc-based Linux systems.",
                    "url": "https://github.com/sxlmnwb/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · Symbolexe/CVE-2024-6387",
                    "author": "Symbolexe",
                    "first_seen": "2024-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "SSH Exploit for CVE-2024-6387 : RCE in OpenSSH's server, on glibc-based Linux systems",
                    "summary": "SSH Exploit for CVE-2024-6387 : RCE in OpenSSH's server, on glibc-based Linux systems",
                    "url": "https://github.com/Symbolexe/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · harshinsecurity/sentinelssh",
                    "author": "harshinsecurity",
                    "first_seen": "2024-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "SentinelSSH is an advanced, high-performance SSH vulnerability scanner written in Go. It's specifically designed to detect the CVE-2024-6387 vulnerability in OpenSSH servers across various network environments.",
                    "summary": "SentinelSSH is an advanced, high-performance SSH vulnerability scanner written in Go. It's specifically designed to detect the CVE-2024-6387 vulnerability in OpenSSH servers across various network environments.",
                    "url": "https://github.com/harshinsecurity/sentinelssh"
                },
                {
                    "repository": "PoC-in-GitHub · t3rry327/cve-2024-6387-poc",
                    "author": "t3rry327",
                    "first_seen": "2024-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/t3rry327/cve-2024-6387-poc"
                },
                {
                    "repository": "PoC-in-GitHub · jocker2410/CVE-2024-6387_poc",
                    "author": "jocker2410",
                    "first_seen": "2024-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/jocker2410/CVE-2024-6387_poc"
                },
                {
                    "repository": "PoC-in-GitHub · turbobit/CVE-2024-6387-OpenSSH-Vulnerability-Checker",
                    "author": "turbobit",
                    "first_seen": "2024-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Welcome to the CVE-2024-6387 OpenSSH Vulnerability Checker repository!  This project offers multiple scripts to check the installed version of OpenSSH on your system and determine if it is vulnerable to CVE-2024-6387. It supports various environments, including Ubuntu, Mac, and Windows.",
                    "summary": "Welcome to the CVE-2024-6387 OpenSSH Vulnerability Checker repository!  This project offers multiple scripts to check the installed version of OpenSSH on your system and determine if it is vulnerable to CVE-2024-6387. It supports various environments, including Ubuntu, Mac, and Windows.",
                    "url": "https://github.com/turbobit/CVE-2024-6387-OpenSSH-Vulnerability-Checker"
                },
                {
                    "repository": "PoC-in-GitHub · sms2056/CVE-2024-6387",
                    "author": "sms2056",
                    "first_seen": "2024-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/sms2056/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · invaderslabs/regreSSHion-CVE-2024-6387-",
                    "author": "invaderslabs",
                    "first_seen": "2024-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Provides instructions for using the script to check if your OpenSSH installation is vulnerable to CVE-2024-6387",
                    "summary": "Provides instructions for using the script to check if your OpenSSH installation is vulnerable to CVE-2024-6387",
                    "url": "https://github.com/invaderslabs/regreSSHion-CVE-2024-6387-"
                },
                {
                    "repository": "PoC-in-GitHub · lala-amber/CVE-2024-6387",
                    "author": "lala-amber",
                    "first_seen": "2024-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/lala-amber/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · 4lxprime/regreSSHive",
                    "author": "4lxprime",
                    "first_seen": "2024-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "rewrited SSH Exploit for CVE-2024-6387 (regreSSHion)",
                    "summary": "rewrited SSH Exploit for CVE-2024-6387 (regreSSHion)",
                    "url": "https://github.com/4lxprime/regreSSHive"
                },
                {
                    "repository": "PoC-in-GitHub · sardine-web/CVE-2024-6387_Check",
                    "author": "sardine-web",
                    "first_seen": "2024-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.",
                    "summary": "A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead to sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.",
                    "url": "https://github.com/sardine-web/CVE-2024-6387_Check"
                },
                {
                    "repository": "PoC-in-GitHub · 0x4D31/cve-2024-6387_hassh",
                    "author": "0x4D31",
                    "first_seen": "2024-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "HASSH fingerprints for identifying OpenSSH servers potentially vulnerable to CVE-2024-6387 (regreSSHion).",
                    "summary": "HASSH fingerprints for identifying OpenSSH servers potentially vulnerable to CVE-2024-6387 (regreSSHion).",
                    "url": "https://github.com/0x4D31/cve-2024-6387_hassh"
                },
                {
                    "repository": "PoC-in-GitHub · sardine-web/CVE-2024-6387-template",
                    "author": "sardine-web",
                    "first_seen": "2024-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Quick regreSSHion checker (based on software version) for nuclei CVE-2024-6387",
                    "summary": "Quick regreSSHion checker (based on software version) for nuclei CVE-2024-6387",
                    "url": "https://github.com/sardine-web/CVE-2024-6387-template"
                },
                {
                    "repository": "PoC-in-GitHub · imv7/CVE-2024-6387",
                    "author": "imv7",
                    "first_seen": "2024-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/imv7/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · azurejoga/CVE-2024-6387-how-to-fix",
                    "author": "azurejoga",
                    "first_seen": "2024-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Vulnerability remediation and mitigationCVE-2024-6387",
                    "summary": "Vulnerability remediation and mitigationCVE-2024-6387",
                    "url": "https://github.com/azurejoga/CVE-2024-6387-how-to-fix"
                },
                {
                    "repository": "PoC-in-GitHub · Karmakstylez/CVE-2024-6387",
                    "author": "Karmakstylez",
                    "first_seen": "2024-07-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 196,
                    "title": "Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (CVE-2024-6387)",
                    "summary": "Remote Unauthenticated Code Execution Vulnerability in OpenSSH server (CVE-2024-6387)",
                    "url": "https://github.com/Karmakstylez/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · vkaushik-chef/regreSSHion",
                    "author": "vkaushik-chef",
                    "first_seen": "2024-07-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Chef Inspec profile for checking regreSSHion vulnerability CVE-2024-6387",
                    "summary": "Chef Inspec profile for checking regreSSHion vulnerability CVE-2024-6387",
                    "url": "https://github.com/vkaushik-chef/regreSSHion"
                },
                {
                    "repository": "PoC-in-GitHub · dgourillon/mitigate-CVE-2024-6387",
                    "author": "dgourillon",
                    "first_seen": "2024-07-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/dgourillon/mitigate-CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · mrmtwoj/CVE-2024-6387",
                    "author": "mrmtwoj",
                    "first_seen": "2024-07-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "regreSSHion is a security tool designed to test for vulnerabilities related to CVE-2024-6387, specifically focusing on SSH and remote access exploitation.",
                    "summary": "regreSSHion is a security tool designed to test for vulnerabilities related to CVE-2024-6387, specifically focusing on SSH and remote access exploitation.",
                    "url": "https://github.com/mrmtwoj/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · filipi86/CVE-2024-6387-Vulnerability-Checker",
                    "author": "filipi86",
                    "first_seen": "2024-07-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 102,
                    "title": "This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.",
                    "summary": "This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.",
                    "url": "https://github.com/filipi86/CVE-2024-6387-Vulnerability-Checker"
                },
                {
                    "repository": "PoC-in-GitHub · kubota/CVE-2024-6387-Vulnerability-Checker",
                    "author": "kubota",
                    "first_seen": "2024-07-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This Rust Code is designed to check SSH servers for the CVE-2024-6387 vulnerability",
                    "summary": "This Rust Code is designed to check SSH servers for the CVE-2024-6387 vulnerability",
                    "url": "https://github.com/kubota/CVE-2024-6387-Vulnerability-Checker"
                },
                {
                    "repository": "PoC-in-GitHub · DimaMend/cve-2024-6387-poc",
                    "author": "DimaMend",
                    "first_seen": "2024-07-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/DimaMend/cve-2024-6387-poc"
                },
                {
                    "repository": "PoC-in-GitHub · redux-sibi-jose/mitigate_ssh",
                    "author": "redux-sibi-jose",
                    "first_seen": "2024-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "OpenSSH vulnerability CVE-2024-6387",
                    "summary": "OpenSSH vulnerability CVE-2024-6387",
                    "url": "https://github.com/redux-sibi-jose/mitigate_ssh"
                },
                {
                    "repository": "PoC-in-GitHub · dream434/CVE-2024-6387",
                    "author": "dream434",
                    "first_seen": "2024-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "OpenSSH a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-6387. Cette vulnérabilité permet à un attaquant non authentifié d'exécuter du  code arbitraire",
                    "summary": "OpenSSH a publié un avis de sécurité concernant la vulnérabilité critique CVE-2024-6387. Cette vulnérabilité permet à un attaquant non authentifié d'exécuter du  code arbitraire",
                    "url": "https://github.com/dream434/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · Ap0dexMe0/CVE-2024-6387",
                    "author": "Ap0dexMe0",
                    "first_seen": "2024-07-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "OpenSSH RCE Massive Vulnerable Scanner",
                    "summary": "OpenSSH RCE Massive Vulnerable Scanner",
                    "url": "https://github.com/Ap0dexMe0/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · prelearn-code/CVE-2024-6387",
                    "author": "prelearn-code",
                    "first_seen": "2024-07-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/prelearn-code/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · l-urk/CVE-2024-6387",
                    "author": "l-urk",
                    "first_seen": "2024-07-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "Proof of concept python script for regreSSHion exploit.",
                    "summary": "Proof of concept python script for regreSSHion exploit.",
                    "url": "https://github.com/l-urk/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · alex14324/ssh_poc2024",
                    "author": "alex14324",
                    "first_seen": "2024-07-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "An exploit for CVE-2024-6387, targeting a signal handler race condition in OpenSSH's server",
                    "summary": "An exploit for CVE-2024-6387, targeting a signal handler race condition in OpenSSH's server",
                    "url": "https://github.com/alex14324/ssh_poc2024"
                },
                {
                    "repository": "PoC-in-GitHub · X-Projetion/CVE-2023-4596-OpenSSH-Multi-Checker",
                    "author": "X-Projetion",
                    "first_seen": "2024-08-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.",
                    "summary": "CVE-2024-6387-checker is a tool or script designed to detect the security vulnerability known as CVE-2024-6387 OpenSSH. CVE-2024-6387 OpenSSH is an entry in the Common Vulnerabilities and Exposures (CVE) that documents security weaknesses discovered in certain software or systems.",
                    "url": "https://github.com/X-Projetion/CVE-2023-4596-OpenSSH-Multi-Checker"
                },
                {
                    "repository": "PoC-in-GitHub · s1d6point7bugcrowd/CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH",
                    "author": "s1d6point7bugcrowd",
                    "first_seen": "2024-08-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/s1d6point7bugcrowd/CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH"
                },
                {
                    "repository": "PoC-in-GitHub · almogopp/OpenSSH-CVE-2024-6387-Fix",
                    "author": "almogopp",
                    "first_seen": "2024-08-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A Bash script to mitigate the CVE-2024-6387 vulnerability in OpenSSH by providing an option to upgrade to a secure version or apply a temporary workaround. This repository helps secure systems against potential remote code execution risks associated with affected OpenSSH versions.",
                    "summary": "A Bash script to mitigate the CVE-2024-6387 vulnerability in OpenSSH by providing an option to upgrade to a secure version or apply a temporary workaround. This repository helps secure systems against potential remote code execution risks associated with affected OpenSSH versions.",
                    "url": "https://github.com/almogopp/OpenSSH-CVE-2024-6387-Fix"
                },
                {
                    "repository": "PoC-in-GitHub · HadesNull123/CVE-2024-6387_Check",
                    "author": "HadesNull123",
                    "first_seen": "2024-08-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "RCE OpenSSH CVE-2024-6387 Check and Exploit",
                    "summary": "RCE OpenSSH CVE-2024-6387 Check and Exploit",
                    "url": "https://github.com/HadesNull123/CVE-2024-6387_Check"
                },
                {
                    "repository": "PoC-in-GitHub · identity-threat-labs/CVE-2024-6387-Vulnerability-Checker",
                    "author": "identity-threat-labs",
                    "first_seen": "2024-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.",
                    "summary": "This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.",
                    "url": "https://github.com/identity-threat-labs/CVE-2024-6387-Vulnerability-Checker"
                },
                {
                    "repository": "PoC-in-GitHub · identity-threat-labs/Article-RegreSSHion-CVE-2024-6387",
                    "author": "identity-threat-labs",
                    "first_seen": "2024-08-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "In an era where digital security is crucial, a new vulnerability in OpenSSH, identified as CVE-2024-6387, has drawn the attention of system administrators and security professionals worldwide. Named \"regreSSHion,\" this severe security flaw allows remote code execution (RCE) and could significant threat to the integrity of vulnerable systems.",
                    "summary": "In an era where digital security is crucial, a new vulnerability in OpenSSH, identified as CVE-2024-6387, has drawn the attention of system administrators and security professionals worldwide. Named \"regreSSHion,\" this severe security flaw allows remote code execution (RCE) and could significant threat to the integrity of vulnerable systems.",
                    "url": "https://github.com/identity-threat-labs/Article-RegreSSHion-CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · anhvutuan/CVE-2024-6387-poc-1",
                    "author": "anhvutuan",
                    "first_seen": "2024-10-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2024-6387, also known as RegreSSHion, is a high-severity vulnerability found in OpenSSH servers (sshd) running on glibc-based Linux systems. It is a regression of a previously fixed vulnerability (CVE-2006-5051), which means the issue was reintroduced in newer versions of OpenSSH.",
                    "summary": "CVE-2024-6387, also known as RegreSSHion, is a high-severity vulnerability found in OpenSSH servers (sshd) running on glibc-based Linux systems. It is a regression of a previously fixed vulnerability (CVE-2006-5051), which means the issue was reintroduced in newer versions of OpenSSH.",
                    "url": "https://github.com/anhvutuan/CVE-2024-6387-poc-1"
                },
                {
                    "repository": "PoC-in-GitHub · YassDEV221608/CVE-2024-6387",
                    "author": "YassDEV221608",
                    "first_seen": "2024-11-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/YassDEV221608/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · awusan125/test_for6387",
                    "author": "awusan125",
                    "first_seen": "2024-12-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "test code for cve-2024-6387",
                    "summary": "test code for cve-2024-6387",
                    "url": "https://github.com/awusan125/test_for6387"
                },
                {
                    "repository": "PoC-in-GitHub · YassDEV221608/CVE-2024-6387_PoC",
                    "author": "YassDEV221608",
                    "first_seen": "2025-01-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/YassDEV221608/CVE-2024-6387_PoC"
                },
                {
                    "repository": "PoC-in-GitHub · kinu404/CVE-2024-6387",
                    "author": "kinu404",
                    "first_seen": "2025-01-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "This is an altered PoC for d0rb/CVE-2024-6387. This takes glibc addresses and trys to exploit the CVE through them.",
                    "summary": "This is an altered PoC for d0rb/CVE-2024-6387. This takes glibc addresses and trys to exploit the CVE through them.",
                    "url": "https://github.com/kinu404/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · xiw1ll/CVE-2024-6387_Checker",
                    "author": "xiw1ll",
                    "first_seen": "2025-07-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Nuclei template to detect CVE-2024-6387. All latest patched versions are excluded.",
                    "summary": "Nuclei template to detect CVE-2024-6387. All latest patched versions are excluded.",
                    "url": "https://github.com/xiw1ll/CVE-2024-6387_Checker"
                },
                {
                    "repository": "PoC-in-GitHub · moften/regreSSHion-CVE-2024-6387",
                    "author": "moften",
                    "first_seen": "2025-09-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387",
                    "summary": "CVE-2024-6387",
                    "url": "https://github.com/moften/regreSSHion-CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · OHHDamnBRO/Noregressh",
                    "author": "OHHDamnBRO",
                    "first_seen": "2025-09-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2024-6387 and more Checker and Exploiter  - Reverse/Bind-Shell Support. education only",
                    "summary": "CVE-2024-6387 and more Checker and Exploiter  - Reverse/Bind-Shell Support. education only",
                    "url": "https://github.com/OHHDamnBRO/Noregressh"
                },
                {
                    "repository": "PoC-in-GitHub · Doux-x/CVE-2024-6387-analysis",
                    "author": "Doux-x",
                    "first_seen": "2026-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 OpenSSH 信号竞争漏洞（regreSSHion）分析报告及检测脚本",
                    "summary": "CVE-2024-6387 OpenSSH 信号竞争漏洞（regreSSHion）分析报告及检测脚本",
                    "url": "https://github.com/Doux-x/CVE-2024-6387-analysis"
                },
                {
                    "repository": "PoC-in-GitHub · kaleth4/CVE-2024-6387",
                    "author": "kaleth4",
                    "first_seen": "2026-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/kaleth4/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · oseasfr/Scanner_CVE_OpenSSH",
                    "author": "oseasfr",
                    "first_seen": "2026-05-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Scanner para identificação de servidores com softwares SSH possivelmente vulnerável às CVEs CVE-2024-6387 e CVE-2023-48795.",
                    "summary": "Scanner para identificação de servidores com softwares SSH possivelmente vulnerável às CVEs CVE-2024-6387 e CVE-2023-48795.",
                    "url": "https://github.com/oseasfr/Scanner_CVE_OpenSSH"
                },
                {
                    "repository": "PoC-in-GitHub · vuducmanhno100-cloud/CVE-2024-6387",
                    "author": "vuducmanhno100-cloud",
                    "first_seen": "2026-05-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 POC (Currently being edited)",
                    "summary": "CVE-2024-6387 POC (Currently being edited)",
                    "url": "https://github.com/vuducmanhno100-cloud/CVE-2024-6387"
                },
                {
                    "repository": "PoC-in-GitHub · m0n3ef/regreSSHion-Checker",
                    "author": "m0n3ef",
                    "first_seen": "2026-07-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A lightweight, fast tool to scan and detect the \"regreSSHion\" OpenSSH remote code execution vulnerability (CVE-2024-6387).",
                    "summary": "A lightweight, fast tool to scan and detect the \"regreSSHion\" OpenSSH remote code execution vulnerability (CVE-2024-6387).",
                    "url": "https://github.com/m0n3ef/regreSSHion-Checker"
                },
                {
                    "repository": "PoC-in-GitHub · al7araziruby-jpg/CVE-2024-6387-OpenSSH-Analysis",
                    "author": "al7araziruby-jpg",
                    "first_seen": "2026-07-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Security analysis and report of CVE-2024-6387 OpenSSH vulnerability, including vulnerability details, CVSS evaluation, and mitigation recommendations.",
                    "summary": "Security analysis and report of CVE-2024-6387 OpenSSH vulnerability, including vulnerability details, CVSS evaluation, and mitigation recommendations.",
                    "url": "https://github.com/al7araziruby-jpg/CVE-2024-6387-OpenSSH-Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · hasan8babiker/CVE-2024-6387",
                    "author": "hasan8babiker",
                    "first_seen": "2026-08-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-6387 repository",
                    "summary": "",
                    "url": "https://github.com/hasan8babiker/CVE-2024-6387"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52269",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-PROJETION-CVE-2023-4596-OPENSSH-MULTI-CHECKER",
                "https://kitploit.com/ru/tools/github/x-projetion/cve-2023-4596-openssh-multi-checker/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AL7ARAZIRUBY-JPG-CVE-2024-6387-OPENSSH-ANALYSIS",
                "https://kitploit.com/ru/tools/github/al7araziruby-jpg/cve-2024-6387-openssh-analysis/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DEVARSHISHIMPI-CVE-2024-6387-CHECK",
                "https://access.redhat.com/errata/RHSA-2024:4312",
                "https://access.redhat.com/errata/RHSA-2024:4340",
                "https://access.redhat.com/errata/RHSA-2024:4389",
                "https://access.redhat.com/errata/RHSA-2024:4469",
                "https://access.redhat.com/errata/RHSA-2024:4474",
                "https://access.redhat.com/errata/RHSA-2024:4479",
                "https://access.redhat.com/errata/RHSA-2024:4484",
                "https://access.redhat.com/security/cve/CVE-2024-6387",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2294604",
                "https://santandersecurityresearch.github.io/blog/sshing_the_masses.html",
                "https://www.openssh.com/txt/release-9.8",
                "https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt",
                "http://seclists.org/fulldisclosure/2024/Jul/18",
                "http://seclists.org/fulldisclosure/2024/Jul/19",
                "http://seclists.org/fulldisclosure/2024/Jul/20",
                "http://www.openwall.com/lists/oss-security/2024/07/01/12",
                "http://www.openwall.com/lists/oss-security/2024/07/01/13",
                "http://www.openwall.com/lists/oss-security/2024/07/02/1",
                "http://www.openwall.com/lists/oss-security/2024/07/03/1",
                "http://www.openwall.com/lists/oss-security/2024/07/03/11",
                "http://www.openwall.com/lists/oss-security/2024/07/03/2",
                "http://www.openwall.com/lists/oss-security/2024/07/03/3",
                "http://www.openwall.com/lists/oss-security/2024/07/03/4",
                "http://www.openwall.com/lists/oss-security/2024/07/03/5",
                "http://www.openwall.com/lists/oss-security/2024/07/04/1",
                "http://www.openwall.com/lists/oss-security/2024/07/04/2",
                "http://www.openwall.com/lists/oss-security/2024/07/08/2",
                "http://www.openwall.com/lists/oss-security/2024/07/08/3",
                "http://www.openwall.com/lists/oss-security/2024/07/09/2",
                "http://www.openwall.com/lists/oss-security/2024/07/09/5",
                "http://www.openwall.com/lists/oss-security/2024/07/10/1",
                "http://www.openwall.com/lists/oss-security/2024/07/10/2",
                "http://www.openwall.com/lists/oss-security/2024/07/10/3",
                "http://www.openwall.com/lists/oss-security/2024/07/10/4",
                "http://www.openwall.com/lists/oss-security/2024/07/10/6",
                "http://www.openwall.com/lists/oss-security/2024/07/11/1",
                "http://www.openwall.com/lists/oss-security/2024/07/11/3",
                "http://www.openwall.com/lists/oss-security/2024/07/23/4",
                "http://www.openwall.com/lists/oss-security/2024/07/23/6",
                "http://www.openwall.com/lists/oss-security/2024/07/28/2",
                "http://www.openwall.com/lists/oss-security/2024/07/28/3",
                "https://archlinux.org/news/the-sshd-service-needs-to-be-restarted-after-upgrading-to-openssh-98p1/",
                "https://arstechnica.com/security/2024/07/regresshion-vulnerability-in-openssh-gives-attackers-root-on-linux/",
                "https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server",
                "https://explore.alas.aws.amazon.com/CVE-2024-6387.html",
                "https://forum.vmssoftware.com/viewtopic.php?f=8&t=9132",
                "https://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2024-002.txt.asc",
                "https://github.com/AlmaLinux/updates/issues/629",
                "https://github.com/Azure/AKS/issues/4379",
                "https://github.com/PowerShell/Win32-OpenSSH/discussions/2248",
                "https://github.com/PowerShell/Win32-OpenSSH/issues/2249",
                "https://github.com/microsoft/azurelinux/issues/9555",
                "https://github.com/openela-main/openssh/commit/e1f438970e5a337a17070a637c1b9e19697cad09",
                "https://github.com/oracle/oracle-linux/issues/149",
                "https://github.com/rapier1/hpn-ssh/issues/87",
                "https://github.com/zgzhang/cve-2024-6387-poc",
                "https://lists.almalinux.org/archives/list/announce@lists.almalinux.org/thread/23BF5BMGFVEVUI2WNVAGMLKT557EU7VY/",
                "https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-July/000158.html",
                "https://lists.mindrot.org/pipermail/openssh-unix-dev/2024-July/041431.html",
                "https://news.ycombinator.com/item?id=40843778",
                "https://packetstorm.news/files/id/190587/",
                "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0010",
                "https://security-tracker.debian.org/tracker/CVE-2024-6387",
                "https://security.netapp.com/advisory/ntap-20240701-0001/",
                "https://sig-security.rocky.page/issues/CVE-2024-6387/",
                "https://stackdiary.com/openssh-race-condition-in-sshd-allows-remote-code-execution/",
                "https://support.apple.com/kb/HT214118",
                "https://support.apple.com/kb/HT214119",
                "https://support.apple.com/kb/HT214120",
                "https://ubuntu.com/security/CVE-2024-6387",
                "https://ubuntu.com/security/notices/USN-6859-1",
                "https://www.akamai.com/blog/security-research/2024-openssh-vulnerability-regression-what-to-know-and-do",
                "https://www.arista.com/en/support/advisories-notices/security-advisory/19904-security-advisory-0100",
                "https://www.freebsd.org/security/advisories/FreeBSD-SA-24:04.openssh.asc",
                "https://www.splunk.com/en_us/blog/security/cve-2024-6387-regresshion-vulnerability.html",
                "https://www.suse.com/security/cve/CVE-2024-6387.html",
                "https://www.theregister.com/2024/07/01/regresshion_openssh/",
                "https://www.vicarius.io/vsociety/posts/regresshion-an-openssh-regression-error-cve-2024-6387",
                "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
                "https://cert-portal.siemens.com/productcert/html/ssa-446545.html",
                "https://github.com/7etsuo/cve-2024-6387-poc",
                "https://github.com/acrono/cve-2024-6387-poc",
                "https://github.com/lflare/cve-2024-6387-poc",
                "https://github.com/getdrive/CVE-2024-6387-PoC",
                "https://github.com/FerasAlrimali/CVE-2024-6387-POC",
                "https://github.com/passwa11/cve-2024-6387-poc",
                "https://github.com/jack0we/CVE-2024-6387",
                "https://github.com/xaitax/CVE-2024-6387_Check",
                "https://github.com/bigb0x/CVE-2024-6387",
                "https://github.com/wiggels/regresshion-check",
                "https://github.com/P4x1s/CVE-2024-6387",
                "https://github.com/betancour/OpenSSH-Vulnerability-test",
                "https://github.com/muyuanlove/CVE-2024-6387fixshell",
                "https://github.com/TAM-K592/CVE-2024-6387",
                "https://github.com/teamos-hub/regreSSHion",
                "https://github.com/ahlfors/CVE-2024-6387",
                "https://github.com/Mufti22/CVE-2024-6387-checkher",
                "https://github.com/thegenetic/CVE-2024-6387-exploit",
                "https://github.com/R4Tw1z/CVE-2024-6387",
                "https://github.com/d0rb/CVE-2024-6387",
                "https://github.com/CiderAndWhisky/regression-scanner",
                "https://github.com/shamo0/CVE-2024-6387_PoC",
                "https://github.com/paradessia/CVE-2024-6387-nmap",
                "https://github.com/PrincipalAnthony/CVE-2024-6387-Updated-x64bit",
                "https://github.com/daniel-odrinski/CVE-2024-6387-Mitigation-Ansible-Playbook",
                "https://github.com/rumochnaya/openssh-cve-2024-6387.sh",
                "https://github.com/zenzue/CVE-2024-6387-Mitigation",
                "https://github.com/devarshishimpi/CVE-2024-6387-Check",
                "https://github.com/hssmo/cve-2024-6387_AImade",
                "https://github.com/ACHUX21/checker-CVE-2024-6387",
                "https://github.com/AiGptCode/ssh_exploiter_CVE-2024-6387",
                "https://github.com/xristos8574/regreSSHion-nmap-scanner",
                "https://github.com/particle99/CVE-2024-6387-POC",
                "https://github.com/xonoxitron/regreSSHion",
                "https://github.com/no-one-sec/CVE-2024-6387",
                "https://github.com/dawnl3ss/CVE-2024-6387",
                "https://github.com/MrR0b0t19/CVE-2024-6387-Exploit-POC",
                "https://github.com/th3gokul/CVE-2024-6387",
                "https://github.com/n1cks0n/Test_CVE-2024-6387",
                "https://github.com/l0n3m4n/CVE-2024-6387",
                "https://github.com/RickGeex/CVE-2024-6387-Checker",
                "https://github.com/xonoxitron/regreSSHion-checker",
                "https://github.com/BrandonLynch2402/cve-2024-6387-nuclei-template",
                "https://github.com/edsonjt81/CVE-2024-6387_Check",
                "https://github.com/grupooruss/CVE-2024-6387",
                "https://github.com/CognisysGroup/CVE-2024-6387-Checker",
                "https://github.com/sxlmnwb/CVE-2024-6387",
                "https://github.com/Symbolexe/CVE-2024-6387",
                "https://github.com/harshinsecurity/sentinelssh",
                "https://github.com/t3rry327/cve-2024-6387-poc",
                "https://github.com/jocker2410/CVE-2024-6387_poc",
                "https://github.com/turbobit/CVE-2024-6387-OpenSSH-Vulnerability-Checker",
                "https://github.com/sms2056/CVE-2024-6387",
                "https://github.com/invaderslabs/regreSSHion-CVE-2024-6387-",
                "https://github.com/lala-amber/CVE-2024-6387",
                "https://github.com/4lxprime/regreSSHive",
                "https://github.com/sardine-web/CVE-2024-6387_Check",
                "https://github.com/0x4D31/cve-2024-6387_hassh",
                "https://github.com/sardine-web/CVE-2024-6387-template",
                "https://github.com/imv7/CVE-2024-6387",
                "https://github.com/azurejoga/CVE-2024-6387-how-to-fix",
                "https://github.com/Karmakstylez/CVE-2024-6387",
                "https://github.com/vkaushik-chef/regreSSHion",
                "https://github.com/dgourillon/mitigate-CVE-2024-6387",
                "https://github.com/mrmtwoj/CVE-2024-6387",
                "https://github.com/filipi86/CVE-2024-6387-Vulnerability-Checker",
                "https://github.com/kubota/CVE-2024-6387-Vulnerability-Checker",
                "https://github.com/DimaMend/cve-2024-6387-poc",
                "https://github.com/redux-sibi-jose/mitigate_ssh",
                "https://github.com/dream434/CVE-2024-6387",
                "https://github.com/Ap0dexMe0/CVE-2024-6387",
                "https://github.com/prelearn-code/CVE-2024-6387",
                "https://github.com/l-urk/CVE-2024-6387",
                "https://github.com/alex14324/ssh_poc2024",
                "https://github.com/X-Projetion/CVE-2023-4596-OpenSSH-Multi-Checker",
                "https://github.com/s1d6point7bugcrowd/CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH",
                "https://github.com/almogopp/OpenSSH-CVE-2024-6387-Fix",
                "https://github.com/HadesNull123/CVE-2024-6387_Check",
                "https://github.com/identity-threat-labs/CVE-2024-6387-Vulnerability-Checker",
                "https://github.com/identity-threat-labs/Article-RegreSSHion-CVE-2024-6387",
                "https://github.com/anhvutuan/CVE-2024-6387-poc-1",
                "https://github.com/YassDEV221608/CVE-2024-6387",
                "https://github.com/awusan125/test_for6387",
                "https://github.com/YassDEV221608/CVE-2024-6387_PoC",
                "https://github.com/kinu404/CVE-2024-6387",
                "https://github.com/xiw1ll/CVE-2024-6387_Checker",
                "https://github.com/moften/regreSSHion-CVE-2024-6387",
                "https://github.com/OHHDamnBRO/Noregressh",
                "https://github.com/Doux-x/CVE-2024-6387-analysis",
                "https://github.com/kaleth4/CVE-2024-6387",
                "https://github.com/oseasfr/Scanner_CVE_OpenSSH",
                "https://github.com/vuducmanhno100-cloud/CVE-2024-6387",
                "https://github.com/m0n3ef/regreSSHion-Checker",
                "https://github.com/al7araziruby-jpg/CVE-2024-6387-OpenSSH-Analysis",
                "https://github.com/hasan8babiker/CVE-2024-6387"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:32:51Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52269"
                },
                {
                    "at": "2024-07-01T13:15:06.467",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6387"
                }
            ],
            "enrichment_checked_at": "2026-09-08T10:05:29Z",
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2024-4885",
            "vendor": "Progress",
            "product": "WhatsUp Gold",
            "title": "Progress WhatsUp Gold Path Traversal Vulnerability",
            "summary": "Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.",
            "updated_at": "2026-09-15T10:56:32Z",
            "published_at": "2026-09-15T10:56:32Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-4885",
                    "summary": "Unauthenticated RCE in Progress WhatsUp Gold via GetFileWithoutZip endpoint.",
                    "what_happened": "Unauthenticated RCE in Progress WhatsUp Gold via GetFileWithoutZip endpoint.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SINSINOLOGY-CVE-2024-4885",
                        "https://kitploit.com/ja/tools/github/sinsinology/cve-2024-4885/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-02T07:32:40",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SINSINOLOGY-CVE-2024-4885"
                },
                {
                    "title": "Exploit for CVE-2024-4885",
                    "summary": "Unauthenticated RCE in Progress WhatsUp Gold via GetFileWithoutZip endpoint.",
                    "what_happened": "Unauthenticated RCE in Progress WhatsUp Gold via GetFileWithoutZip endpoint.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SINSINOLOGY-CVE-2024-4885",
                        "https://kitploit.com/ja/tools/github/sinsinology/cve-2024-4885/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-02T07:32:40",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/sinsinology/cve-2024-4885/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SINSINOLOGY-CVE-2024-4885",
                "https://kitploit.com/ja/tools/github/sinsinology/cve-2024-4885/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T10:56:32Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2024-4577",
            "vendor": "PHP Group",
            "product": "PHP",
            "title": "PHP-CGI OS Command Injection Vulnerability",
            "summary": "PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.",
            "updated_at": "2026-09-04T07:30:11Z",
            "published_at": "2026-09-04T07:30:11Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1357,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52331",
                    "author": "İbrahimsql",
                    "first_seen": "2025-06-15",
                    "confidence": "High",
                    "title": "PHP CGI Module 8.3.4 - Remote Code Execution (RCE)",
                    "summary": "PHP CGI Module 8.3.4 - Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/52331",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2024-4577-RCE",
                    "summary": "PHP CGI argument injection on Windows via Best-Fit character replacement enabling RCE in XAMPP.",
                    "what_happened": "PHP CGI argument injection on Windows via Best-Fit character replacement enabling RCE in XAMPP.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GH-OST00-CVE-2024-4577-RCE",
                        "https://kitploit.com/zh/tools/github/gh-ost00/cve-2024-4577-rce/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T09:30:11",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GH-OST00-CVE-2024-4577-RCE"
                },
                {
                    "title": "Exploit for CVE-2024-4577-RCE",
                    "summary": "PHP CGI argument injection on Windows via Best-Fit character replacement enabling RCE in XAMPP.",
                    "what_happened": "PHP CGI argument injection on Windows via Best-Fit character replacement enabling RCE in XAMPP.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GH-OST00-CVE-2024-4577-RCE",
                        "https://kitploit.com/zh/tools/github/gh-ost00/cve-2024-4577-rce/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-04T09:30:11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/gh-ost00/cve-2024-4577-rce/"
                },
                {
                    "repository": "PoC-in-GitHub · TAM-K592/CVE-2024-4577",
                    "author": "TAM-K592",
                    "first_seen": "2024-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 75,
                    "title": "CVE-2024-4577 is a critical vulnerability in PHP affecting CGI configurations, allowing attackers to execute arbitrary commands via crafted URL parameters.",
                    "summary": "CVE-2024-4577 is a critical vulnerability in PHP affecting CGI configurations, allowing attackers to execute arbitrary commands via crafted URL parameters.",
                    "url": "https://github.com/TAM-K592/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · Ra1n-60W/CVE-2024-4577",
                    "author": "Ra1n-60W",
                    "first_seen": "2024-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577",
                    "summary": "CVE-2024-4577",
                    "url": "https://github.com/Ra1n-60W/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · princew88/CVE-2024-4577",
                    "author": "princew88",
                    "first_seen": "2024-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/princew88/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · 11whoami99/CVE-2024-4577",
                    "author": "11whoami99",
                    "first_seen": "2024-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 43,
                    "title": "POC & $BASH script for CVE-2024-4577",
                    "summary": "POC & $BASH script for CVE-2024-4577",
                    "url": "https://github.com/11whoami99/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · watchtowrlabs/CVE-2024-4577",
                    "author": "watchtowrlabs",
                    "first_seen": "2024-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 322,
                    "title": "PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC",
                    "summary": "PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC",
                    "url": "https://github.com/watchtowrlabs/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · huseyinstif/CVE-2024-4577-Nuclei-Template",
                    "author": "huseyinstif",
                    "first_seen": "2024-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 21,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/huseyinstif/CVE-2024-4577-Nuclei-Template"
                },
                {
                    "repository": "PoC-in-GitHub · taida957789/CVE-2024-4577",
                    "author": "taida957789",
                    "first_seen": "2024-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/taida957789/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · Wh02m1/CVE-2024-4577",
                    "author": "Wh02m1",
                    "first_seen": "2024-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/Wh02m1/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · Sysc4ll3r/CVE-2024-4577",
                    "author": "Sysc4ll3r",
                    "first_seen": "2024-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Nuclei Template for CVE-2024-4577",
                    "summary": "Nuclei Template for CVE-2024-4577",
                    "url": "https://github.com/Sysc4ll3r/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · WanLiChangChengWanLiChang/CVE-2024-4577-RCE-EXP",
                    "author": "WanLiChangChengWanLiChang",
                    "first_seen": "2024-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/WanLiChangChengWanLiChang/CVE-2024-4577-RCE-EXP"
                },
                {
                    "repository": "PoC-in-GitHub · graphite-org/CVE-2024-4577",
                    "author": "graphite-org",
                    "first_seen": "2024-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/graphite-org/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · 0x20c/CVE-2024-4577-nuclei",
                    "author": "0x20c",
                    "first_seen": "2024-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2024-4577 nuclei-templates",
                    "summary": "CVE-2024-4577 nuclei-templates",
                    "url": "https://github.com/0x20c/CVE-2024-4577-nuclei"
                },
                {
                    "repository": "PoC-in-GitHub · manuelinfosec/CVE-2024-4577",
                    "author": "manuelinfosec",
                    "first_seen": "2024-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "Proof Of Concept RCE exploit for critical vulnerability in PHP <8.2.15 (Windows), allowing attackers to execute arbitrary commands.",
                    "summary": "Proof Of Concept RCE exploit for critical vulnerability in PHP <8.2.15 (Windows), allowing attackers to execute arbitrary commands.",
                    "url": "https://github.com/manuelinfosec/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · zomasec/CVE-2024-4577",
                    "author": "zomasec",
                    "first_seen": "2024-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2024-4577 Exploit POC",
                    "summary": "CVE-2024-4577 Exploit POC",
                    "url": "https://github.com/zomasec/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · ZephrFish/CVE-2024-4577-PHP-RCE",
                    "author": "ZephrFish",
                    "first_seen": "2024-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 33,
                    "title": "PHP RCE PoC for CVE-2024-4577 written in bash, go, python and a nuclei template",
                    "summary": "PHP RCE PoC for CVE-2024-4577 written in bash, go, python and a nuclei template",
                    "url": "https://github.com/ZephrFish/CVE-2024-4577-PHP-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · xcanwin/CVE-2024-4577-PHP-RCE",
                    "author": "xcanwin",
                    "first_seen": "2024-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 162,
                    "title": "[漏洞复现] 全球首款利用PHP默认环境（XAMPP）的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP。",
                    "summary": "[漏洞复现] 全球首款利用PHP默认环境（XAMPP）的CVE-2024-4577 PHP-CGI RCE 漏洞 EXP。",
                    "url": "https://github.com/xcanwin/CVE-2024-4577-PHP-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · dbyMelina/CVE-2024-4577",
                    "author": "dbyMelina",
                    "first_seen": "2024-06-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "python poc编写练手，可以对单个目标或批量检测",
                    "summary": "python poc编写练手，可以对单个目标或批量检测",
                    "url": "https://github.com/dbyMelina/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · Chocapikk/CVE-2024-4577",
                    "author": "Chocapikk",
                    "first_seen": "2024-06-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 35,
                    "title": "PHP CGI Argument Injection vulnerability",
                    "summary": "PHP CGI Argument Injection vulnerability",
                    "url": "https://github.com/Chocapikk/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · K3ysTr0K3R/CVE-2024-4577-EXPLOIT",
                    "author": "K3ysTr0K3R",
                    "first_seen": "2024-06-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "A PoC exploit for CVE-2024-4577 - PHP CGI Argument Injection Remote Code Execution (RCE)",
                    "summary": "A PoC exploit for CVE-2024-4577 - PHP CGI Argument Injection Remote Code Execution (RCE)",
                    "url": "https://github.com/K3ysTr0K3R/CVE-2024-4577-EXPLOIT"
                },
                {
                    "repository": "PoC-in-GitHub · BLACK-ARCHIVERS/CVE-2024-4577",
                    "author": "BLACK-ARCHIVERS",
                    "first_seen": "2024-06-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC",
                    "summary": "PHP CGI Argument Injection (CVE-2024-4577) Remote Code Execution PoC",
                    "url": "https://github.com/BLACK-ARCHIVERS/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · bl4cksku11/CVE-2024-4577",
                    "author": "bl4cksku11",
                    "first_seen": "2024-06-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is a PoC for PHP CVE-2024-4577.",
                    "summary": "This is a PoC for PHP CVE-2024-4577.",
                    "url": "https://github.com/bl4cksku11/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · aavamin/cve-2024-4577",
                    "author": "aavamin",
                    "first_seen": "2024-06-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2024-4577",
                    "summary": "CVE-2024-4577",
                    "url": "https://github.com/aavamin/cve-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · d3ck4/Shodan-CVE-2024-4577",
                    "author": "d3ck4",
                    "first_seen": "2024-06-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "POC for CVE-2024-4577 with Shodan integration",
                    "summary": "POC for CVE-2024-4577 with Shodan integration",
                    "url": "https://github.com/d3ck4/Shodan-CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · Entropt/CVE-2024-4577_Analysis",
                    "author": "Entropt",
                    "first_seen": "2024-06-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Vietnam National Cyber Security (NCS)'s Internship - 2nd Test",
                    "summary": "Vietnam National Cyber Security (NCS)'s Internship - 2nd Test",
                    "url": "https://github.com/Entropt/CVE-2024-4577_Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · 0XFFFF-XD/CVE-2024-4577-PHP-CGI-RCE",
                    "author": "0XFFFF-XD",
                    "first_seen": "2024-06-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/0XFFFF-XD/CVE-2024-4577-PHP-CGI-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · Sh0ckFR/CVE-2024-4577",
                    "author": "Sh0ckFR",
                    "first_seen": "2024-06-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Fixed and minimalist PoC of the CVE-2024-4577",
                    "summary": "Fixed and minimalist PoC of the CVE-2024-4577",
                    "url": "https://github.com/Sh0ckFR/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · gotr00t0day/CVE-2024-4577",
                    "author": "gotr00t0day",
                    "first_seen": "2024-06-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "Argument injection vulnerability in PHP",
                    "summary": "Argument injection vulnerability in PHP",
                    "url": "https://github.com/gotr00t0day/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · VictorShem/CVE-2024-4577",
                    "author": "VictorShem",
                    "first_seen": "2024-06-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2024-4577 POC",
                    "summary": "CVE-2024-4577 POC",
                    "url": "https://github.com/VictorShem/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · jakabakos/CVE-2024-4577-PHP-CGI-argument-injection-RCE",
                    "author": "jakabakos",
                    "first_seen": "2024-06-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/jakabakos/CVE-2024-4577-PHP-CGI-argument-injection-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · PhinehasNarh/CVE-2024-4577-LetsDefend-walkthrough",
                    "author": "PhinehasNarh",
                    "first_seen": "2024-06-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This is an Incident Response Walkthrough: Mitigating a Zero-Day Attack (CVE-2024-4577)",
                    "summary": "This is an Incident Response Walkthrough: Mitigating a Zero-Day Attack (CVE-2024-4577)",
                    "url": "https://github.com/PhinehasNarh/CVE-2024-4577-LetsDefend-walkthrough"
                },
                {
                    "repository": "PoC-in-GitHub · ggfzx/CVE-2024-4577",
                    "author": "ggfzx",
                    "first_seen": "2024-06-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/ggfzx/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · olebris/CVE-2024-4577",
                    "author": "olebris",
                    "first_seen": "2024-06-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577",
                    "summary": "CVE-2024-4577",
                    "url": "https://github.com/olebris/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · AlperenY-cs/CVE-2024-4577",
                    "author": "AlperenY-cs",
                    "first_seen": "2024-06-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Create lab for CVE-2024-4577",
                    "summary": "Create lab for CVE-2024-4577",
                    "url": "https://github.com/AlperenY-cs/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · charis3306/CVE-2024-4577",
                    "author": "charis3306",
                    "first_seen": "2024-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 EXP",
                    "summary": "CVE-2024-4577 EXP",
                    "url": "https://github.com/charis3306/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · l0n3m4n/CVE-2024-4577-RCE",
                    "author": "l0n3m4n",
                    "first_seen": "2024-07-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "PoC - PHP CGI Argument Injection CVE-2024-4577 (Scanner and Exploit)",
                    "summary": "PoC - PHP CGI Argument Injection CVE-2024-4577 (Scanner and Exploit)",
                    "url": "https://github.com/l0n3m4n/CVE-2024-4577-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · bibo318/CVE-2024-4577-RCE-ATTACK",
                    "author": "bibo318",
                    "first_seen": "2024-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "ATTACK PoC - PHP CVE-2024-4577",
                    "summary": "ATTACK PoC - PHP CVE-2024-4577",
                    "url": "https://github.com/bibo318/CVE-2024-4577-RCE-ATTACK"
                },
                {
                    "repository": "PoC-in-GitHub · gmh5225/CVE-2024-4577-PHP-RCE",
                    "author": "gmh5225",
                    "first_seen": "2024-07-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Automated PHP remote code execution scanner for CVE-2024-4577",
                    "summary": "Automated PHP remote code execution scanner for CVE-2024-4577",
                    "url": "https://github.com/gmh5225/CVE-2024-4577-PHP-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · a-roshbaik/CVE-2024-4577-PHP-RCE",
                    "author": "a-roshbaik",
                    "first_seen": "2024-07-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/a-roshbaik/CVE-2024-4577-PHP-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · Jcccccx/CVE-2024-4577",
                    "author": "Jcccccx",
                    "first_seen": "2024-07-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "批量验证POC和EXP",
                    "summary": "批量验证POC和EXP",
                    "url": "https://github.com/Jcccccx/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · bughuntar/CVE-2024-4577",
                    "author": "bughuntar",
                    "first_seen": "2024-08-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 Exploits",
                    "summary": "CVE-2024-4577 Exploits",
                    "url": "https://github.com/bughuntar/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · gh-ost00/CVE-2024-4577-RCE",
                    "author": "gh-ost00",
                    "first_seen": "2024-08-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "PHP CGI Argument Injection (CVE-2024-4577) RCE",
                    "summary": "PHP CGI Argument Injection (CVE-2024-4577) RCE",
                    "url": "https://github.com/gh-ost00/CVE-2024-4577-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · ywChen-NTUST/PHP-CGI-RCE-Scanner",
                    "author": "ywChen-NTUST",
                    "first_seen": "2024-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Scanning CVE-2024-4577 vulnerability with a url list.",
                    "summary": "Scanning CVE-2024-4577 vulnerability with a url list.",
                    "url": "https://github.com/ywChen-NTUST/PHP-CGI-RCE-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · AhmedMansour93/Event-ID-268-Rule-Name-SOC292-Possible-PHP-Injection-Detected-CVE-2024-4577-",
                    "author": "AhmedMansour93",
                    "first_seen": "2024-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "🚨 New Incident Report Completed! 🚨 Just wrapped up \"Event ID 268: SOC292 - Possible PHP Injection Detected (CVE-2024-4577)\" on LetsDefend.io. This analysis involved investigating an attempted Command Injection targeting our PHP server. Staying ahead of these threats with continuous monitoring and swift containment! 🛡️",
                    "summary": "🚨 New Incident Report Completed! 🚨 Just wrapped up \"Event ID 268: SOC292 - Possible PHP Injection Detected (CVE-2024-4577)\" on LetsDefend.io. This analysis involved investigating an attempted Command Injection targeting our PHP server. Staying ahead of these threats with continuous monitoring and swift containment! 🛡️",
                    "url": "https://github.com/AhmedMansour93/Event-ID-268-Rule-Name-SOC292-Possible-PHP-Injection-Detected-CVE-2024-4577-"
                },
                {
                    "repository": "PoC-in-GitHub · phirojshah/CVE-2024-4577",
                    "author": "phirojshah",
                    "first_seen": "2024-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/phirojshah/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · JeninSutradhar/CVE-2024-4577-checker",
                    "author": "JeninSutradhar",
                    "first_seen": "2024-10-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A Bash script designed to scan multiple domains for the CVE-2024-4577 vulnerability in PHP-CGI.",
                    "summary": "A Bash script designed to scan multiple domains for the CVE-2024-4577 vulnerability in PHP-CGI.",
                    "url": "https://github.com/JeninSutradhar/CVE-2024-4577-checker"
                },
                {
                    "repository": "PoC-in-GitHub · longhoangth18/CVE-2024-4577",
                    "author": "longhoangth18",
                    "first_seen": "2024-10-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/longhoangth18/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · ahmetramazank/CVE-2024-4577",
                    "author": "ahmetramazank",
                    "first_seen": "2024-11-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/ahmetramazank/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · BTtea/CVE-2024-4577-RCE-PoC",
                    "author": "BTtea",
                    "first_seen": "2024-11-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "CVE-2024-4577 RCE PoC",
                    "summary": "CVE-2024-4577 RCE PoC",
                    "url": "https://github.com/BTtea/CVE-2024-4577-RCE-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · Dejavu666/CVE-2024-4577",
                    "author": "Dejavu666",
                    "first_seen": "2025-01-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 POC",
                    "summary": "CVE-2024-4577 POC",
                    "url": "https://github.com/Dejavu666/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · tpdlshdmlrkfmcla/php-cgi-cve-2024-4577",
                    "author": "tpdlshdmlrkfmcla",
                    "first_seen": "2025-02-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "php-cgi-cve-2024-4577",
                    "summary": "php-cgi-cve-2024-4577",
                    "url": "https://github.com/tpdlshdmlrkfmcla/php-cgi-cve-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · Didarul342/CVE-2024-4577",
                    "author": "Didarul342",
                    "first_seen": "2025-02-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/Didarul342/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · Night-have-dreams/php-cgi-Injector",
                    "author": "Night-have-dreams",
                    "first_seen": "2025-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 52,
                    "title": "一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具",
                    "summary": "一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具",
                    "url": "https://github.com/Night-have-dreams/php-cgi-Injector"
                },
                {
                    "repository": "PoC-in-GitHub · wilss0n/CVE-2024-4577",
                    "author": "wilss0n",
                    "first_seen": "2025-03-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/wilss0n/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · sug4r-wr41th/CVE-2024-4577",
                    "author": "sug4r-wr41th",
                    "first_seen": "2025-04-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PHP CGI CVE-2024-4577 PoC",
                    "summary": "PHP CGI CVE-2024-4577 PoC",
                    "url": "https://github.com/sug4r-wr41th/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · Gill-Singh-A/CVE-2024-4577-Exploit",
                    "author": "Gill-Singh-A",
                    "first_seen": "2025-04-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PHP CGI Parameter Injection Vulnerability (RCE: Remote Code Execution)",
                    "summary": "PHP CGI Parameter Injection Vulnerability (RCE: Remote Code Execution)",
                    "url": "https://github.com/Gill-Singh-A/CVE-2024-4577-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · tntrock/CVE-2024-4577_PowerShell",
                    "author": "tntrock",
                    "first_seen": "2025-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "使用PowsrShell掃描CVE-2024-4577",
                    "summary": "使用PowsrShell掃描CVE-2024-4577",
                    "url": "https://github.com/tntrock/CVE-2024-4577_PowerShell"
                },
                {
                    "repository": "PoC-in-GitHub · KimJuhyeong95/cve-2024-4577",
                    "author": "KimJuhyeong95",
                    "first_seen": "2025-05-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/KimJuhyeong95/cve-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · byteReaper77/CVE-2024-4577",
                    "author": "byteReaper77",
                    "first_seen": "2025-06-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Exploit (C) CVE-2024-4577 on PHP CGI",
                    "summary": "Exploit (C) CVE-2024-4577 on PHP CGI",
                    "url": "https://github.com/byteReaper77/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · r0otk3r/CVE-2024-4577",
                    "author": "r0otk3r",
                    "first_seen": "2025-07-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/r0otk3r/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · mananjain61/PHP-CGI-INTERNAL-RCE",
                    "author": "mananjain61",
                    "first_seen": "2025-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers",
                    "summary": "Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers",
                    "url": "https://github.com/mananjain61/PHP-CGI-INTERNAL-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · Skycritch/CVE-2024-4577",
                    "author": "Skycritch",
                    "first_seen": "2025-07-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit for php-cgi",
                    "summary": "Exploit for php-cgi",
                    "url": "https://github.com/Skycritch/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · CirqueiraDev/MassExploit-CVE-2024-4577",
                    "author": "CirqueiraDev",
                    "first_seen": "2025-07-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2024-4577 Mass Scanner & Exploit Tool",
                    "summary": "CVE-2024-4577 Mass Scanner & Exploit Tool",
                    "url": "https://github.com/CirqueiraDev/MassExploit-CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · Ianthinus/CVE-2024-4577",
                    "author": "Ianthinus",
                    "first_seen": "2025-08-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/Ianthinus/CVE-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · a1ex-var1amov/ctf-cve-2024-4577",
                    "author": "a1ex-var1amov",
                    "first_seen": "2025-08-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/a1ex-var1amov/ctf-cve-2024-4577"
                },
                {
                    "repository": "PoC-in-GitHub · rayngnpc/CVE-2024-4577-rayng",
                    "author": "rayngnpc",
                    "first_seen": "2025-12-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 PHP CGI Argument Injection - Detection Lab with Vagrant VMs and Wazuh SIEM rules",
                    "summary": "CVE-2024-4577 PHP CGI Argument Injection - Detection Lab with Vagrant VMs and Wazuh SIEM rules",
                    "url": "https://github.com/rayngnpc/CVE-2024-4577-rayng"
                },
                {
                    "repository": "PoC-in-GitHub · gl1tch0x1/PHP_8.1.x_Exploit",
                    "author": "gl1tch0x1",
                    "first_seen": "2026-04-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Automated detection & exploitation of critical PHP vulnerabilities (CVE-2024-4577 bypass, CVE-2025-14177, CVE-2025-14180, CVE-2025-14178)",
                    "summary": "Automated detection & exploitation of critical PHP vulnerabilities (CVE-2024-4577 bypass, CVE-2025-14177, CVE-2025-14180, CVE-2025-14178)",
                    "url": "https://github.com/gl1tch0x1/PHP_8.1.x_Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Kanak-CypherX/cve-2024-4577-lab",
                    "author": "Kanak-CypherX",
                    "first_seen": "2026-07-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/Kanak-CypherX/cve-2024-4577-lab"
                },
                {
                    "repository": "PoC-in-GitHub · razureink/cve-2024-4577-phpcgi_rce_reproduction",
                    "author": "razureink",
                    "first_seen": "2026-07-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE Reproduction: cve-2024-4577-phpcgi_rce_reproduction",
                    "summary": "CVE Reproduction: cve-2024-4577-phpcgi_rce_reproduction",
                    "url": "https://github.com/razureink/cve-2024-4577-phpcgi_rce_reproduction"
                },
                {
                    "repository": "PoC-in-GitHub · DuyDuongDuyDuong/CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigation",
                    "author": "DuyDuongDuyDuong",
                    "first_seen": "2026-08-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/DuyDuongDuyDuong/CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigation"
                },
                {
                    "repository": "PoC-in-GitHub · khwajasaad267-coder/cve-2024-4577-lab",
                    "author": "khwajasaad267-coder",
                    "first_seen": "2026-08-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4577 repository",
                    "summary": "",
                    "url": "https://github.com/khwajasaad267-coder/cve-2024-4577-lab"
                },
                {
                    "repository": "PoC-in-GitHub · yeee3642/edu-recon",
                    "author": "yeee3642",
                    "first_seen": "2026-08-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Authorized education-sector recon & triage orchestrator (nmap/dirsearch/sqlmap/hydra + CVE-2024-4577, secret/API-key leak, XSS, wp2shell) with a web control panel",
                    "summary": "Authorized education-sector recon & triage orchestrator (nmap/dirsearch/sqlmap/hydra + CVE-2024-4577, secret/API-key leak, XSS, wp2shell) with a web control panel",
                    "url": "https://github.com/yeee3642/edu-recon"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/52331",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GH-OST00-CVE-2024-4577-RCE",
                "https://kitploit.com/zh/tools/github/gh-ost00/cve-2024-4577-rce/",
                "https://github.com/TAM-K592/CVE-2024-4577",
                "https://github.com/Ra1n-60W/CVE-2024-4577",
                "https://github.com/princew88/CVE-2024-4577",
                "https://github.com/11whoami99/CVE-2024-4577",
                "https://github.com/watchtowrlabs/CVE-2024-4577",
                "https://github.com/huseyinstif/CVE-2024-4577-Nuclei-Template",
                "https://github.com/taida957789/CVE-2024-4577",
                "https://github.com/Wh02m1/CVE-2024-4577",
                "https://github.com/Sysc4ll3r/CVE-2024-4577",
                "https://github.com/WanLiChangChengWanLiChang/CVE-2024-4577-RCE-EXP",
                "https://github.com/graphite-org/CVE-2024-4577",
                "https://github.com/0x20c/CVE-2024-4577-nuclei",
                "https://github.com/manuelinfosec/CVE-2024-4577",
                "https://github.com/zomasec/CVE-2024-4577",
                "https://github.com/ZephrFish/CVE-2024-4577-PHP-RCE",
                "https://github.com/xcanwin/CVE-2024-4577-PHP-RCE",
                "https://github.com/dbyMelina/CVE-2024-4577",
                "https://github.com/Chocapikk/CVE-2024-4577",
                "https://github.com/K3ysTr0K3R/CVE-2024-4577-EXPLOIT",
                "https://github.com/BLACK-ARCHIVERS/CVE-2024-4577",
                "https://github.com/bl4cksku11/CVE-2024-4577",
                "https://github.com/aavamin/cve-2024-4577",
                "https://github.com/d3ck4/Shodan-CVE-2024-4577",
                "https://github.com/Entropt/CVE-2024-4577_Analysis",
                "https://github.com/0XFFFF-XD/CVE-2024-4577-PHP-CGI-RCE",
                "https://github.com/Sh0ckFR/CVE-2024-4577",
                "https://github.com/gotr00t0day/CVE-2024-4577",
                "https://github.com/VictorShem/CVE-2024-4577",
                "https://github.com/jakabakos/CVE-2024-4577-PHP-CGI-argument-injection-RCE",
                "https://github.com/PhinehasNarh/CVE-2024-4577-LetsDefend-walkthrough",
                "https://github.com/ggfzx/CVE-2024-4577",
                "https://github.com/olebris/CVE-2024-4577",
                "https://github.com/AlperenY-cs/CVE-2024-4577",
                "https://github.com/charis3306/CVE-2024-4577",
                "https://github.com/l0n3m4n/CVE-2024-4577-RCE",
                "https://github.com/bibo318/CVE-2024-4577-RCE-ATTACK",
                "https://github.com/gmh5225/CVE-2024-4577-PHP-RCE",
                "https://github.com/a-roshbaik/CVE-2024-4577-PHP-RCE",
                "https://github.com/Jcccccx/CVE-2024-4577",
                "https://github.com/bughuntar/CVE-2024-4577",
                "https://github.com/gh-ost00/CVE-2024-4577-RCE",
                "https://github.com/ywChen-NTUST/PHP-CGI-RCE-Scanner",
                "https://github.com/AhmedMansour93/Event-ID-268-Rule-Name-SOC292-Possible-PHP-Injection-Detected-CVE-2024-4577-",
                "https://github.com/phirojshah/CVE-2024-4577",
                "https://github.com/JeninSutradhar/CVE-2024-4577-checker",
                "https://github.com/longhoangth18/CVE-2024-4577",
                "https://github.com/ahmetramazank/CVE-2024-4577",
                "https://github.com/BTtea/CVE-2024-4577-RCE-PoC",
                "https://github.com/Dejavu666/CVE-2024-4577",
                "https://github.com/tpdlshdmlrkfmcla/php-cgi-cve-2024-4577",
                "https://github.com/Didarul342/CVE-2024-4577",
                "https://github.com/Night-have-dreams/php-cgi-Injector",
                "https://github.com/wilss0n/CVE-2024-4577",
                "https://github.com/sug4r-wr41th/CVE-2024-4577",
                "https://github.com/Gill-Singh-A/CVE-2024-4577-Exploit",
                "https://github.com/tntrock/CVE-2024-4577_PowerShell",
                "https://github.com/KimJuhyeong95/cve-2024-4577",
                "https://github.com/byteReaper77/CVE-2024-4577",
                "https://github.com/r0otk3r/CVE-2024-4577",
                "https://github.com/mananjain61/PHP-CGI-INTERNAL-RCE",
                "https://github.com/Skycritch/CVE-2024-4577",
                "https://github.com/CirqueiraDev/MassExploit-CVE-2024-4577",
                "https://github.com/Ianthinus/CVE-2024-4577",
                "https://github.com/a1ex-var1amov/ctf-cve-2024-4577",
                "https://github.com/rayngnpc/CVE-2024-4577-rayng",
                "https://github.com/gl1tch0x1/PHP_8.1.x_Exploit",
                "https://github.com/Kanak-CypherX/cve-2024-4577-lab",
                "https://github.com/razureink/cve-2024-4577-phpcgi_rce_reproduction",
                "https://github.com/DuyDuongDuyDuong/CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigation",
                "https://github.com/khwajasaad267-coder/cve-2024-4577-lab",
                "https://github.com/yeee3642/edu-recon"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T07:30:11Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-06-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2024-4367",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Firefox ESR 115.11 - PDF.js Arbitrary JavaScript execution",
            "summary": "Firefox ESR 115.11 - PDF.js Arbitrary JavaScript execution",
            "updated_at": "2026-09-14T22:00:00Z",
            "published_at": "2026-09-14T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 112,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52273",
                    "author": "Milad karimi",
                    "first_seen": "2025-04-22",
                    "confidence": "High",
                    "title": "Firefox ESR 115.11 - PDF.js Arbitrary JavaScript execution",
                    "summary": "Firefox ESR 115.11 - PDF.js Arbitrary JavaScript execution",
                    "url": "https://www.exploit-db.com/exploits/52273",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · LOURC0D3/CVE-2024-4367-PoC",
                    "author": "LOURC0D3",
                    "first_seen": "2024-05-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 202,
                    "title": "CVE-2024-4367 & CVE-2024-34342 Proof of Concept",
                    "summary": "CVE-2024-4367 & CVE-2024-34342 Proof of Concept",
                    "url": "https://github.com/LOURC0D3/CVE-2024-4367-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · s4vvysec/CVE-2024-4367-POC",
                    "author": "s4vvysec",
                    "first_seen": "2024-05-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 57,
                    "title": "CVE-2024-4367 arbitrary js execution in pdf js",
                    "summary": "CVE-2024-4367 arbitrary js execution in pdf js",
                    "url": "https://github.com/s4vvysec/CVE-2024-4367-POC"
                },
                {
                    "repository": "PoC-in-GitHub · spaceraccoon/detect-cve-2024-4367",
                    "author": "spaceraccoon",
                    "first_seen": "2024-05-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js",
                    "summary": "YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js",
                    "url": "https://github.com/spaceraccoon/detect-cve-2024-4367"
                },
                {
                    "repository": "PoC-in-GitHub · clarkio/pdfjs-vuln-demo",
                    "author": "clarkio",
                    "first_seen": "2024-05-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367",
                    "summary": "This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367",
                    "url": "https://github.com/clarkio/pdfjs-vuln-demo"
                },
                {
                    "repository": "PoC-in-GitHub · avalahEE/pdfjs_disable_eval",
                    "author": "avalahEE",
                    "first_seen": "2024-05-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-4367 mitigation for Odoo 14.0",
                    "summary": "CVE-2024-4367 mitigation for Odoo 14.0",
                    "url": "https://github.com/avalahEE/pdfjs_disable_eval"
                },
                {
                    "repository": "PoC-in-GitHub · Zombie-Kaiser/cve-2024-4367-PoC-fixed",
                    "author": "Zombie-Kaiser",
                    "first_seen": "2024-06-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "PDF.js是由Mozilla维护的基于JavaScript的PDF查看器。此漏洞允许攻击者在打开恶意 PDF 文件后立即执行任意 JavaScript 代码。这会影响所有 Firefox 用户 （<126），因为 Firefox 使用 PDF.js 来显示 PDF 文件，但也严重影响了许多基于 Web 和 Electron 的应用程序，这些应用程序（间接）使用 PDF.js 进行预览功能。",
                    "summary": "PDF.js是由Mozilla维护的基于JavaScript的PDF查看器。此漏洞允许攻击者在打开恶意 PDF 文件后立即执行任意 JavaScript 代码。这会影响所有 Firefox 用户 （<126），因为 Firefox 使用 PDF.js 来显示 PDF 文件，但也严重影响了许多基于 Web 和 Electron 的应用程序，这些应用程序（间接）使用 PDF.js 进行预览功能。",
                    "url": "https://github.com/Zombie-Kaiser/cve-2024-4367-PoC-fixed"
                },
                {
                    "repository": "PoC-in-GitHub · snyk-labs/pdfjs-vuln-demo",
                    "author": "snyk-labs",
                    "first_seen": "2024-06-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367",
                    "summary": "This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in CVE-2024-4367",
                    "url": "https://github.com/snyk-labs/pdfjs-vuln-demo"
                },
                {
                    "repository": "PoC-in-GitHub · UnHackerEnCapital/PDFernetRemotelo",
                    "author": "UnHackerEnCapital",
                    "first_seen": "2024-06-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script",
                    "summary": "PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script",
                    "url": "https://github.com/UnHackerEnCapital/PDFernetRemotelo"
                },
                {
                    "repository": "PoC-in-GitHub · Masamuneee/CVE-2024-4367-Analysis",
                    "author": "Masamuneee",
                    "first_seen": "2024-09-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js",
                    "summary": "Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js",
                    "url": "https://github.com/Masamuneee/CVE-2024-4367-Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · m0d0ri205/PDFJS",
                    "author": "m0d0ri205",
                    "first_seen": "2024-10-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "wargame, CVE-2024-4367",
                    "summary": "wargame, CVE-2024-4367",
                    "url": "https://github.com/m0d0ri205/PDFJS"
                },
                {
                    "repository": "PoC-in-GitHub · pedrochalegre7/CVE-2024-4367-pdf-sample",
                    "author": "pedrochalegre7",
                    "first_seen": "2024-11-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4367 repository",
                    "summary": "",
                    "url": "https://github.com/pedrochalegre7/CVE-2024-4367-pdf-sample"
                },
                {
                    "repository": "PoC-in-GitHub · exfil0/WEAPONIZING-CVE-2024-4367",
                    "author": "exfil0",
                    "first_seen": "2025-01-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the FontMatrix object within PDF files.",
                    "summary": "CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the FontMatrix object within PDF files.",
                    "url": "https://github.com/exfil0/WEAPONIZING-CVE-2024-4367"
                },
                {
                    "repository": "PoC-in-GitHub · kabiri-labs/CVE-2024-4367-PoC",
                    "author": "kabiri-labs",
                    "first_seen": "2025-02-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This Proof of Concept (PoC) demonstrates the exploitation of the CVE-2024-4367 vulnerability, which involves Cross-Site Scripting (XSS) attacks.",
                    "summary": "This Proof of Concept (PoC) demonstrates the exploitation of the CVE-2024-4367 vulnerability, which involves Cross-Site Scripting (XSS) attacks.",
                    "url": "https://github.com/kabiri-labs/CVE-2024-4367-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · elamani-drawing/CVE-2024-4367-POC-PDFJS",
                    "author": "elamani-drawing",
                    "first_seen": "2025-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC (Proof of Concept) de la CVE-2024-4367 - Vulnérabilité RCE dans libwebp.  Démonstration complète incluant : création de payloads, scénarios d'attaque, analyse des risques et serveur Express.js de test.",
                    "summary": "PoC (Proof of Concept) de la CVE-2024-4367 - Vulnérabilité RCE dans libwebp.  Démonstration complète incluant : création de payloads, scénarios d'attaque, analyse des risques et serveur Express.js de test.",
                    "url": "https://github.com/elamani-drawing/CVE-2024-4367-POC-PDFJS"
                },
                {
                    "repository": "PoC-in-GitHub · VVeakee/CVE-2024-4367",
                    "author": "VVeakee",
                    "first_seen": "2025-04-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4367 repository",
                    "summary": "",
                    "url": "https://github.com/VVeakee/CVE-2024-4367"
                },
                {
                    "repository": "PoC-in-GitHub · BektiHandoyo/cve-pdf-host",
                    "author": "BektiHandoyo",
                    "first_seen": "2025-04-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PDF host for CVE-2024-4367",
                    "summary": "PDF host for CVE-2024-4367",
                    "url": "https://github.com/BektiHandoyo/cve-pdf-host"
                },
                {
                    "repository": "PoC-in-GitHub · Bhavyakcwestern/Hacking-pdf.js-vulnerability",
                    "author": "Bhavyakcwestern",
                    "first_seen": "2025-04-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4367",
                    "summary": "CVE-2024-4367",
                    "url": "https://github.com/Bhavyakcwestern/Hacking-pdf.js-vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · PenguinCabinet/CVE-2024-4367-hands-on",
                    "author": "PenguinCabinet",
                    "first_seen": "2025-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4367 repository",
                    "summary": "",
                    "url": "https://github.com/PenguinCabinet/CVE-2024-4367-hands-on"
                },
                {
                    "repository": "PoC-in-GitHub · AnomalousVectors/cve-2024-4367-poc",
                    "author": "AnomalousVectors",
                    "first_seen": "2025-06-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "POC for PDF JS' CVE-2024-4367 vuln",
                    "summary": "POC for PDF JS' CVE-2024-4367 vuln",
                    "url": "https://github.com/AnomalousVectors/cve-2024-4367-poc"
                },
                {
                    "repository": "PoC-in-GitHub · 0xr2r/CVE-2024-4367",
                    "author": "0xr2r",
                    "first_seen": "2025-08-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4367 repository",
                    "summary": "",
                    "url": "https://github.com/0xr2r/CVE-2024-4367"
                },
                {
                    "repository": "PoC-in-GitHub · 1337rokudenashi/Odoo_PDFjs_CVE-2024-4367.pdf",
                    "author": "1337rokudenashi",
                    "first_seen": "2025-08-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Odoo ≤17 is vulnerable to CVE-2024-4367, allowing arbitrary JavaScript execution via PDF.js.",
                    "summary": "Odoo ≤17 is vulnerable to CVE-2024-4367, allowing arbitrary JavaScript execution via PDF.js.",
                    "url": "https://github.com/1337rokudenashi/Odoo_PDFjs_CVE-2024-4367.pdf"
                },
                {
                    "repository": "PoC-in-GitHub · xiaoqiesec0x1/CVE-2024-4367-PDF.js-xss",
                    "author": "xiaoqiesec0x1",
                    "first_seen": "2026-05-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4367–PDF.js-xss",
                    "summary": "CVE-2024-4367–PDF.js-xss",
                    "url": "https://github.com/xiaoqiesec0x1/CVE-2024-4367-PDF.js-xss"
                },
                {
                    "repository": "PoC-in-GitHub · J1nKsC/CVE-2024-4367_test",
                    "author": "J1nKsC",
                    "first_seen": "2026-06-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4367 repository",
                    "summary": "",
                    "url": "https://github.com/J1nKsC/CVE-2024-4367_test"
                },
                {
                    "repository": "PoC-in-GitHub · veronimo669/pdf.js-CVE-2024-4367",
                    "author": "veronimo669",
                    "first_seen": "2026-06-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "SCAN END POC THE CVE-2024-4367",
                    "summary": "SCAN END POC THE CVE-2024-4367",
                    "url": "https://github.com/veronimo669/pdf.js-CVE-2024-4367"
                },
                {
                    "repository": "PoC-in-GitHub · yuimamur/CVE-2024-4367-hands-on-01",
                    "author": "yuimamur",
                    "first_seen": "2026-07-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-4367 repository",
                    "summary": "",
                    "url": "https://github.com/yuimamur/CVE-2024-4367-hands-on-01"
                },
                {
                    "repository": "PoC-in-GitHub · Qq1111111111/pentest-i021-poc-1789486727",
                    "author": "Qq1111111111",
                    "first_seen": "2026-09-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "temporary CVE-2024-4367 verification artifacts",
                    "summary": "temporary CVE-2024-4367 verification artifacts",
                    "url": "https://github.com/Qq1111111111/pentest-i021-poc-1789486727"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52273",
                "https://github.com/LOURC0D3/CVE-2024-4367-PoC",
                "https://github.com/s4vvysec/CVE-2024-4367-POC",
                "https://github.com/spaceraccoon/detect-cve-2024-4367",
                "https://github.com/clarkio/pdfjs-vuln-demo",
                "https://github.com/avalahEE/pdfjs_disable_eval",
                "https://github.com/Zombie-Kaiser/cve-2024-4367-PoC-fixed",
                "https://github.com/snyk-labs/pdfjs-vuln-demo",
                "https://github.com/UnHackerEnCapital/PDFernetRemotelo",
                "https://github.com/Masamuneee/CVE-2024-4367-Analysis",
                "https://github.com/m0d0ri205/PDFJS",
                "https://github.com/pedrochalegre7/CVE-2024-4367-pdf-sample",
                "https://github.com/exfil0/WEAPONIZING-CVE-2024-4367",
                "https://github.com/kabiri-labs/CVE-2024-4367-PoC",
                "https://github.com/elamani-drawing/CVE-2024-4367-POC-PDFJS",
                "https://github.com/VVeakee/CVE-2024-4367",
                "https://github.com/BektiHandoyo/cve-pdf-host",
                "https://github.com/Bhavyakcwestern/Hacking-pdf.js-vulnerability",
                "https://github.com/PenguinCabinet/CVE-2024-4367-hands-on",
                "https://github.com/AnomalousVectors/cve-2024-4367-poc",
                "https://github.com/0xr2r/CVE-2024-4367",
                "https://github.com/1337rokudenashi/Odoo_PDFjs_CVE-2024-4367.pdf",
                "https://github.com/xiaoqiesec0x1/CVE-2024-4367-PDF.js-xss",
                "https://github.com/J1nKsC/CVE-2024-4367_test",
                "https://github.com/veronimo669/pdf.js-CVE-2024-4367",
                "https://github.com/yuimamur/CVE-2024-4367-hands-on-01",
                "https://github.com/Qq1111111111/pentest-i021-poc-1789486727"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52273"
                }
            ]
        },
        {
            "id": "CVE-2024-4040",
            "vendor": "CrushFTP",
            "product": "CrushFTP",
            "title": "CrushFTP VFS Sandbox Escape Vulnerability",
            "summary": "CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).",
            "updated_at": "2026-09-12T15:07:16Z",
            "published_at": "2026-09-12T15:07:16Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 50,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CrushFTP-cve-2024-4040-poc CVE-2024-4040",
                    "summary": "PoC for CVE-2024-4040 in CrushFTP tools component.",
                    "what_happened": "PoC for CVE-2024-4040 in CrushFTP tools component.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SAFEER-ACCUKNOX-CRUSHFTP-CVE-2024-4040-POC",
                        "https://kitploit.com/it/tools/github/safeer-accuknox/crushftp-cve-2024-4040-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-29T15:06:54",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SAFEER-ACCUKNOX-CRUSHFTP-CVE-2024-4040-POC"
                },
                {
                    "title": "Exploit for CrushFTP-cve-2024-4040-poc CVE-2024-4040",
                    "summary": "PoC for CVE-2024-4040 in CrushFTP tools component.",
                    "what_happened": "PoC for CVE-2024-4040 in CrushFTP tools component.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SAFEER-ACCUKNOX-CRUSHFTP-CVE-2024-4040-POC",
                        "https://kitploit.com/it/tools/github/safeer-accuknox/crushftp-cve-2024-4040-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "it",
                    "first_seen": "2026-08-29T15:06:54",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/it/tools/github/safeer-accuknox/crushftp-cve-2024-4040-poc/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SAFEER-ACCUKNOX-CRUSHFTP-CVE-2024-4040-POC",
                "https://kitploit.com/it/tools/github/safeer-accuknox/crushftp-cve-2024-4040-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T15:07:16Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-04-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2024-3094",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Information for CVE-2024-3094",
            "summary": "Information for CVE-2024-3094",
            "updated_at": "2026-09-06T22:00:00Z",
            "published_at": "2026-09-06T22:00:00Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 3083,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Kong is an LLM orchestration tool for reverse engineering obfuscated stripped binaries into Ghidra.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · byinarie/CVE-2024-3094-info",
                    "author": "byinarie",
                    "first_seen": "2024-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 54,
                    "title": "Information for CVE-2024-3094",
                    "summary": "Information for CVE-2024-3094",
                    "url": "https://github.com/byinarie/CVE-2024-3094-info"
                },
                {
                    "repository": "PoC-in-GitHub · FabioBaroni/CVE-2024-3094-checker",
                    "author": "FabioBaroni",
                    "first_seen": "2024-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 72,
                    "title": "Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)",
                    "summary": "Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)",
                    "url": "https://github.com/FabioBaroni/CVE-2024-3094-checker"
                },
                {
                    "repository": "PoC-in-GitHub · lypd0/CVE-2024-3094-Vulnerabity-Checker",
                    "author": "lypd0",
                    "first_seen": "2024-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Verify that your XZ Utils version is not vulnerable to CVE-2024-3094",
                    "summary": "Verify that your XZ Utils version is not vulnerable to CVE-2024-3094",
                    "url": "https://github.com/lypd0/CVE-2024-3094-Vulnerabity-Checker"
                },
                {
                    "repository": "PoC-in-GitHub · OpensourceICTSolutions/xz_utils-CVE-2024-3094",
                    "author": "OpensourceICTSolutions",
                    "first_seen": "2024-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/OpensourceICTSolutions/xz_utils-CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · bioless/xz_cve-2024-3094_detection",
                    "author": "bioless",
                    "first_seen": "2024-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Script to detect CVE-2024-3094.",
                    "summary": "Script to detect CVE-2024-3094.",
                    "url": "https://github.com/bioless/xz_cve-2024-3094_detection"
                },
                {
                    "repository": "PoC-in-GitHub · HackerHermanos/CVE-2024-3094_xz_check",
                    "author": "HackerHermanos",
                    "first_seen": "2024-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "This repository contains a Bash script and a one-liner command to verify if a system is running a vulnerable version of the \"xz\" utility, as specified by CVE-2024-3094.",
                    "summary": "This repository contains a Bash script and a one-liner command to verify if a system is running a vulnerable version of the \"xz\" utility, as specified by CVE-2024-3094.",
                    "url": "https://github.com/HackerHermanos/CVE-2024-3094_xz_check"
                },
                {
                    "repository": "PoC-in-GitHub · Fractal-Tess/CVE-2024-3094",
                    "author": "Fractal-Tess",
                    "first_seen": "2024-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/Fractal-Tess/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · wgetnz/CVE-2024-3094-check",
                    "author": "wgetnz",
                    "first_seen": "2024-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/wgetnz/CVE-2024-3094-check"
                },
                {
                    "repository": "PoC-in-GitHub · emirkmo/xz-backdoor-github",
                    "author": "emirkmo",
                    "first_seen": "2024-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "History of commits related to the xz backdoor Discovered On March 29, 2024: CVE-2024-3094.",
                    "summary": "History of commits related to the xz backdoor Discovered On March 29, 2024: CVE-2024-3094.",
                    "url": "https://github.com/emirkmo/xz-backdoor-github"
                },
                {
                    "repository": "PoC-in-GitHub · ashwani95/CVE-2024-3094",
                    "author": "ashwani95",
                    "first_seen": "2024-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/ashwani95/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · harekrishnarai/xz-utils-vuln-checker",
                    "author": "harekrishnarai",
                    "first_seen": "2024-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Checker for CVE-2024-3094 where malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code.",
                    "summary": "Checker for CVE-2024-3094 where malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code.",
                    "url": "https://github.com/harekrishnarai/xz-utils-vuln-checker"
                },
                {
                    "repository": "PoC-in-GitHub · teyhouse/CVE-2024-3094",
                    "author": "teyhouse",
                    "first_seen": "2024-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "K8S and Docker Vulnerability Check for CVE-2024-3094",
                    "summary": "K8S and Docker Vulnerability Check for CVE-2024-3094",
                    "url": "https://github.com/teyhouse/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer",
                    "author": "gensecaihq",
                    "first_seen": "2024-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 26,
                    "title": "Shell scripts to identify and fix installations of xz-utils affected by the CVE-2024-3094 vulnerability. Versions 5.6.0 and 5.6.1 of xz-utils are known to be vulnerable, and this script aids in detecting them and optionally downgrading to a stable, un-compromised version (5.4.6) or upgrading to latest version.  Added Ansible Playbook",
                    "summary": "Shell scripts to identify and fix installations of xz-utils affected by the CVE-2024-3094 vulnerability. Versions 5.6.0 and 5.6.1 of xz-utils are known to be vulnerable, and this script aids in detecting them and optionally downgrading to a stable, un-compromised version (5.4.6) or upgrading to latest version.  Added Ansible Playbook",
                    "url": "https://github.com/gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer"
                },
                {
                    "repository": "PoC-in-GitHub · Horizon-Software-Development/CVE-2024-3094",
                    "author": "Horizon-Software-Development",
                    "first_seen": "2024-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/Horizon-Software-Development/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · hazemkya/CVE-2024-3094-checker",
                    "author": "hazemkya",
                    "first_seen": "2024-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/hazemkya/CVE-2024-3094-checker"
                },
                {
                    "repository": "PoC-in-GitHub · lockness-Ko/xz-vulnerable-honeypot",
                    "author": "lockness-Ko",
                    "first_seen": "2024-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 146,
                    "title": "An ssh honeypot with the XZ backdoor. CVE-2024-3094",
                    "summary": "An ssh honeypot with the XZ backdoor. CVE-2024-3094",
                    "url": "https://github.com/lockness-Ko/xz-vulnerable-honeypot"
                },
                {
                    "repository": "PoC-in-GitHub · brinhosa/CVE-2024-3094-One-Liner",
                    "author": "brinhosa",
                    "first_seen": "2024-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/brinhosa/CVE-2024-3094-One-Liner"
                },
                {
                    "repository": "PoC-in-GitHub · isuruwa/CVE-2024-3094",
                    "author": "isuruwa",
                    "first_seen": "2024-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094",
                    "summary": "CVE-2024-3094",
                    "url": "https://github.com/isuruwa/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · Yuma-Tsushima07/CVE-2024-3094",
                    "author": "Yuma-Tsushima07",
                    "first_seen": "2024-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "A script to detect if xz is vulnerable - CVE-2024-3094",
                    "summary": "A script to detect if xz is vulnerable - CVE-2024-3094",
                    "url": "https://github.com/Yuma-Tsushima07/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · jfrog/cve-2024-3094-tools",
                    "author": "jfrog",
                    "first_seen": "2024-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 45,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/jfrog/cve-2024-3094-tools"
                },
                {
                    "repository": "PoC-in-GitHub · Simplifi-ED/CVE-2024-3094-patcher",
                    "author": "Simplifi-ED",
                    "first_seen": "2024-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Ansible playbook for patching CVE-2024-3094",
                    "summary": "Ansible playbook for patching CVE-2024-3094",
                    "url": "https://github.com/Simplifi-ED/CVE-2024-3094-patcher"
                },
                {
                    "repository": "PoC-in-GitHub · spidygal/CVE-2024-3094-Nmap-NSE-script",
                    "author": "spidygal",
                    "first_seen": "2024-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/spidygal/CVE-2024-3094-Nmap-NSE-script"
                },
                {
                    "repository": "PoC-in-GitHub · Mustafa1986/CVE-2024-3094",
                    "author": "Mustafa1986",
                    "first_seen": "2024-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/Mustafa1986/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · MrBUGLF/XZ-Utils_CVE-2024-3094",
                    "author": "MrBUGLF",
                    "first_seen": "2024-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "XZ-Utils工具库恶意后门植入漏洞(CVE-2024-3094)",
                    "summary": "XZ-Utils工具库恶意后门植入漏洞(CVE-2024-3094)",
                    "url": "https://github.com/MrBUGLF/XZ-Utils_CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · galacticquest/cve-2024-3094-detect",
                    "author": "galacticquest",
                    "first_seen": "2024-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/galacticquest/cve-2024-3094-detect"
                },
                {
                    "repository": "PoC-in-GitHub · mightysai1997/CVE-2024-3094-info",
                    "author": "mightysai1997",
                    "first_seen": "2024-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/mightysai1997/CVE-2024-3094-info"
                },
                {
                    "repository": "PoC-in-GitHub · mightysai1997/CVE-2024-3094",
                    "author": "mightysai1997",
                    "first_seen": "2024-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/mightysai1997/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · mesutgungor/xz-backdoor-vulnerability",
                    "author": "mesutgungor",
                    "first_seen": "2024-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094",
                    "summary": "CVE-2024-3094",
                    "url": "https://github.com/mesutgungor/xz-backdoor-vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · jbnetwork-git/CVE-2024-3094-XZ-Utils-Check",
                    "author": "jbnetwork-git",
                    "first_seen": "2024-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Herramientas de linux para diferentes funciones.",
                    "summary": "Herramientas de linux para diferentes funciones.",
                    "url": "https://github.com/jbnetwork-git/CVE-2024-3094-XZ-Utils-Check"
                },
                {
                    "repository": "PoC-in-GitHub · amlweems/xzbot",
                    "author": "amlweems",
                    "first_seen": "2024-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3553,
                    "title": "notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)",
                    "summary": "notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)",
                    "url": "https://github.com/amlweems/xzbot"
                },
                {
                    "repository": "PoC-in-GitHub · zpxlz/CVE-2024-3094",
                    "author": "zpxlz",
                    "first_seen": "2024-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Obsidian notes about CVE-2024-3094",
                    "summary": "Obsidian notes about CVE-2024-3094",
                    "url": "https://github.com/zpxlz/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · gustavorobertux/CVE-2024-3094",
                    "author": "gustavorobertux",
                    "first_seen": "2024-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Checker - CVE-2024-3094",
                    "summary": "Checker - CVE-2024-3094",
                    "url": "https://github.com/gustavorobertux/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · ackemed/detectar_cve-2024-3094",
                    "author": "ackemed",
                    "first_seen": "2024-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/ackemed/detectar_cve-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · 0xlane/xz-cve-2024-3094",
                    "author": "0xlane",
                    "first_seen": "2024-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "XZ Backdoor Extract(Test on Ubuntu 23.10)",
                    "summary": "XZ Backdoor Extract(Test on Ubuntu 23.10)",
                    "url": "https://github.com/0xlane/xz-cve-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · dah4k/CVE-2024-3094",
                    "author": "dah4k",
                    "first_seen": "2024-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/dah4k/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · hackingetico21/revisaxzutils",
                    "author": "hackingetico21",
                    "first_seen": "2024-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Script en bash para revisar si tienes la vulnerabilidad CVE-2024-3094.",
                    "summary": "Script en bash para revisar si tienes la vulnerabilidad CVE-2024-3094.",
                    "url": "https://github.com/hackingetico21/revisaxzutils"
                },
                {
                    "repository": "PoC-in-GitHub · devjanger/CVE-2024-3094-XZ-Backdoor-Detector",
                    "author": "devjanger",
                    "first_seen": "2024-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 XZ Backdoor Detector",
                    "summary": "CVE-2024-3094 XZ Backdoor Detector",
                    "url": "https://github.com/devjanger/CVE-2024-3094-XZ-Backdoor-Detector"
                },
                {
                    "repository": "PoC-in-GitHub · ScrimForever/CVE-2024-3094",
                    "author": "ScrimForever",
                    "first_seen": "2024-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Detectar CVE-2024-3094",
                    "summary": "Detectar CVE-2024-3094",
                    "url": "https://github.com/ScrimForever/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · pentestfunctions/CVE-2024-3094",
                    "author": "pentestfunctions",
                    "first_seen": "2024-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2024-3094 - Checker (fix for arch etc)",
                    "summary": "CVE-2024-3094 - Checker (fix for arch etc)",
                    "url": "https://github.com/pentestfunctions/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · r0binak/xzk8s",
                    "author": "r0binak",
                    "first_seen": "2024-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094",
                    "summary": "Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094",
                    "url": "https://github.com/r0binak/xzk8s"
                },
                {
                    "repository": "PoC-in-GitHub · przemoc/xz-backdoor-links",
                    "author": "przemoc",
                    "first_seen": "2024-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "apocalypxze: xz backdoor (2024) AKA CVE-2024-3094 related links",
                    "summary": "apocalypxze: xz backdoor (2024) AKA CVE-2024-3094 related links",
                    "url": "https://github.com/przemoc/xz-backdoor-links"
                },
                {
                    "repository": "PoC-in-GitHub · Security-Phoenix-demo/CVE-2024-3094-fix-exploits",
                    "author": "Security-Phoenix-demo",
                    "first_seen": "2024-04-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Collection of Detection, Fix, and exploit for CVE-2024-3094",
                    "summary": "Collection of Detection, Fix, and exploit for CVE-2024-3094",
                    "url": "https://github.com/Security-Phoenix-demo/CVE-2024-3094-fix-exploits"
                },
                {
                    "repository": "PoC-in-GitHub · MagpieRYL/CVE-2024-3094-backdoor-env-container",
                    "author": "MagpieRYL",
                    "first_seen": "2024-04-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is a container environment running CVE-2024-3094 sshd backdoor instance, working with https://github.com/amlweems/xzbot project. IT IS NOT Docker, just implemented by chroot.",
                    "summary": "This is a container environment running CVE-2024-3094 sshd backdoor instance, working with https://github.com/amlweems/xzbot project. IT IS NOT Docker, just implemented by chroot.",
                    "url": "https://github.com/MagpieRYL/CVE-2024-3094-backdoor-env-container"
                },
                {
                    "repository": "PoC-in-GitHub · Bella-Bc/xz-backdoor-CVE-2024-3094-Check",
                    "author": "Bella-Bc",
                    "first_seen": "2024-04-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Verify if your installed version of xz-utils is vulnerable to CVE-2024-3094 backdoor",
                    "summary": "Verify if your installed version of xz-utils is vulnerable to CVE-2024-3094 backdoor",
                    "url": "https://github.com/Bella-Bc/xz-backdoor-CVE-2024-3094-Check"
                },
                {
                    "repository": "PoC-in-GitHub · TheTorjanCaptain/CVE-2024-3094-Checker",
                    "author": "TheTorjanCaptain",
                    "first_seen": "2024-04-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "The repository consists of a checker file that confirms if your xz version and xz-utils package is vulnerable to CVE-2024-3094.",
                    "summary": "The repository consists of a checker file that confirms if your xz version and xz-utils package is vulnerable to CVE-2024-3094.",
                    "url": "https://github.com/TheTorjanCaptain/CVE-2024-3094-Checker"
                },
                {
                    "repository": "PoC-in-GitHub · iheb2b/CVE-2024-3094-Checker",
                    "author": "iheb2b",
                    "first_seen": "2024-04-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "The CVE-2024-3094 Checker is a Bash tool for identifying if Linux systems are at risk from the CVE-2024-3094 flaw in XZ/LZMA utilities. It checks XZ versions, SSHD's LZMA linkage, and scans for specific byte patterns, delivering results in a concise table format.",
                    "summary": "The CVE-2024-3094 Checker is a Bash tool for identifying if Linux systems are at risk from the CVE-2024-3094 flaw in XZ/LZMA utilities. It checks XZ versions, SSHD's LZMA linkage, and scans for specific byte patterns, delivering results in a concise table format.",
                    "url": "https://github.com/iheb2b/CVE-2024-3094-Checker"
                },
                {
                    "repository": "PoC-in-GitHub · felipecosta09/cve-2024-3094",
                    "author": "felipecosta09",
                    "first_seen": "2024-04-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "A tutorial on how to detect the CVE 2024-3094",
                    "summary": "A tutorial on how to detect the CVE 2024-3094",
                    "url": "https://github.com/felipecosta09/cve-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · weltregie/liblzma-scan",
                    "author": "weltregie",
                    "first_seen": "2024-04-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Scans liblzma from xu-utils for backdoor (CVE-2024-3094)",
                    "summary": "Scans liblzma from xu-utils for backdoor (CVE-2024-3094)",
                    "url": "https://github.com/weltregie/liblzma-scan"
                },
                {
                    "repository": "PoC-in-GitHub · KaminaDuck/ansible-CVE-2024-3094",
                    "author": "KaminaDuck",
                    "first_seen": "2024-04-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Ansible playbooks designed to check and remediate CVE-2024-3094 (XZ Backdoor)",
                    "summary": "Ansible playbooks designed to check and remediate CVE-2024-3094 (XZ Backdoor)",
                    "url": "https://github.com/KaminaDuck/ansible-CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · robertdebock/ansible-playbook-cve-2024-3094",
                    "author": "robertdebock",
                    "first_seen": "2024-04-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A small repo with a single playbook.",
                    "summary": "A small repo with a single playbook.",
                    "url": "https://github.com/robertdebock/ansible-playbook-cve-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · badsectorlabs/ludus_xz_backdoor",
                    "author": "badsectorlabs",
                    "first_seen": "2024-04-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "An Ansible Role that installs the xz backdoor (CVE-2024-3094) on a Debian host and optionally installs the xzbot tool.",
                    "summary": "An Ansible Role that installs the xz backdoor (CVE-2024-3094) on a Debian host and optionally installs the xzbot tool.",
                    "url": "https://github.com/badsectorlabs/ludus_xz_backdoor"
                },
                {
                    "repository": "PoC-in-GitHub · Juul/xz-backdoor-scan",
                    "author": "Juul",
                    "first_seen": "2024-04-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Scan for files containing the signature from the `xz` backdoor (CVE-2024-3094)",
                    "summary": "Scan for files containing the signature from the `xz` backdoor (CVE-2024-3094)",
                    "url": "https://github.com/Juul/xz-backdoor-scan"
                },
                {
                    "repository": "PoC-in-GitHub · fevar54/Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-",
                    "author": "fevar54",
                    "first_seen": "2024-04-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Regla YARA para detectar el backdoor de liblzma en XZ Utils 5.6.0/5.6.1 (CVE-2024-3094).",
                    "summary": "Regla YARA para detectar el backdoor de liblzma en XZ Utils 5.6.0/5.6.1 (CVE-2024-3094).",
                    "url": "https://github.com/fevar54/Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-"
                },
                {
                    "repository": "PoC-in-GitHub · neuralinhibitor/xzwhy",
                    "author": "neuralinhibitor",
                    "first_seen": "2024-04-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "XZ Utils CVE-2024-3094 POC for Kubernetes",
                    "summary": "XZ Utils CVE-2024-3094 POC for Kubernetes",
                    "url": "https://github.com/neuralinhibitor/xzwhy"
                },
                {
                    "repository": "PoC-in-GitHub · AndreaCicca/Sicurezza-Informatica-Presentazione",
                    "author": "AndreaCicca",
                    "first_seen": "2024-05-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Presentazione per il corsi di sicurezza Informatica sulla vulnerabilità CVE-2024-3094",
                    "summary": "Presentazione per il corsi di sicurezza Informatica sulla vulnerabilità CVE-2024-3094",
                    "url": "https://github.com/AndreaCicca/Sicurezza-Informatica-Presentazione"
                },
                {
                    "repository": "PoC-in-GitHub · shefirot/CVE-2024-3094",
                    "author": "shefirot",
                    "first_seen": "2024-06-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Basic POC to test CVE-2024-3094 vulnerability inside K8s cluster",
                    "summary": "Basic POC to test CVE-2024-3094 vulnerability inside K8s cluster",
                    "url": "https://github.com/shefirot/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · robertdfrench/ifuncd-up",
                    "author": "robertdfrench",
                    "first_seen": "2024-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 61,
                    "title": "GNU IFUNC is the real culprit behind CVE-2024-3094",
                    "summary": "GNU IFUNC is the real culprit behind CVE-2024-3094",
                    "url": "https://github.com/robertdfrench/ifuncd-up"
                },
                {
                    "repository": "PoC-in-GitHub · been22426/CVE-2024-3094",
                    "author": "been22426",
                    "first_seen": "2025-04-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 실습 환경 구축 및 보고",
                    "summary": "CVE-2024-3094 실습 환경 구축 및 보고",
                    "url": "https://github.com/been22426/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094",
                    "author": "laxmikumari615",
                    "first_seen": "2025-05-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "It was determined that malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. #    It was determined that only certain operating systems and operating system versions were affected by this vulnerability.",
                    "summary": "It was determined that malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. #    It was determined that only certain operating systems and operating system versions were affected by this vulnerability.",
                    "url": "https://github.com/laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · valeriot30/cve-2024-3094",
                    "author": "valeriot30",
                    "first_seen": "2025-06-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A XZ backdoor vulnerability explained in details",
                    "summary": "A XZ backdoor vulnerability explained in details",
                    "url": "https://github.com/valeriot30/cve-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · 24Owais/threat-intel-cve-2024-3094",
                    "author": "24Owais",
                    "first_seen": "2025-06-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Threat intelligence report analyzing the xz-utils backdoor vulnerability (CVE-2024-3094)",
                    "summary": "Threat intelligence report analyzing the xz-utils backdoor vulnerability (CVE-2024-3094)",
                    "url": "https://github.com/24Owais/threat-intel-cve-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · Ikram124/CVE-2024-3094-analysis",
                    "author": "Ikram124",
                    "first_seen": "2025-06-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Security analysis project: Real-world CVE breakdown",
                    "summary": "Security analysis project: Real-world CVE breakdown",
                    "url": "https://github.com/Ikram124/CVE-2024-3094-analysis"
                },
                {
                    "repository": "PoC-in-GitHub · mrk336/CVE-2024-3094",
                    "author": "mrk336",
                    "first_seen": "2025-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-3094 exposed a backdoor in the XZ compression library, allowing remote SSH access by bypassing authentication. It’s a major supply chain attack affecting Linux systems, highlighting risks in trusted open-source components.",
                    "summary": "CVE-2024-3094 exposed a backdoor in the XZ compression library, allowing remote SSH access by bypassing authentication. It’s a major supply chain attack affecting Linux systems, highlighting risks in trusted open-source components.",
                    "url": "https://github.com/mrk336/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public",
                    "author": "Titus-soc",
                    "first_seen": "2025-09-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A lightweight utility designed to detect and remediate systems affected by CVE-2024-3094, a critical vulnerability impacting [insert affected software/library here if known]. This tool provides automated scanning, reporting, and optional mitigation steps to help administrators and security teams secure their environments quickly.",
                    "summary": "A lightweight utility designed to detect and remediate systems affected by CVE-2024-3094, a critical vulnerability impacting [insert affected software/library here if known]. This tool provides automated scanning, reporting, and optional mitigation steps to help administrators and security teams secure their environments quickly.",
                    "url": "https://github.com/Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public"
                },
                {
                    "repository": "PoC-in-GitHub · M1lo25/CS50FinalProject",
                    "author": "M1lo25",
                    "first_seen": "2025-10-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Investigation into the XZ Utils backdoor (CVE-2024-3094): chronology, attack chain, risk to SSH, and supply-chain insights. Includes slides, sources, and mitigations (parity checks, attestations, or SBOMs, as well as SLSA)",
                    "summary": "Investigation into the XZ Utils backdoor (CVE-2024-3094): chronology, attack chain, risk to SSH, and supply-chain insights. Includes slides, sources, and mitigations (parity checks, attestations, or SBOMs, as well as SLSA)",
                    "url": "https://github.com/M1lo25/CS50FinalProject"
                },
                {
                    "repository": "PoC-in-GitHub · ThomRgn/xzutils_backdoor_obfuscation",
                    "author": "ThomRgn",
                    "first_seen": "2025-10-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)",
                    "summary": "Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)",
                    "url": "https://github.com/ThomRgn/xzutils_backdoor_obfuscation"
                },
                {
                    "repository": "PoC-in-GitHub · encikayelwhitehat-glitch/CVE-2024-3094",
                    "author": "encikayelwhitehat-glitch",
                    "first_seen": "2026-01-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/encikayelwhitehat-glitch/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · BOSE122/CVE-2024-3094",
                    "author": "BOSE122",
                    "first_seen": "2026-01-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/BOSE122/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · hackura/xz-cve-2024-3094",
                    "author": "hackura",
                    "first_seen": "2026-01-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.",
                    "summary": "Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.",
                    "url": "https://github.com/hackura/xz-cve-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · michalAshurov/writeup-CVE-2024-3094",
                    "author": "michalAshurov",
                    "first_seen": "2026-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/michalAshurov/writeup-CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · extracoding-dozen/CVE-2024-3094",
                    "author": "extracoding-dozen",
                    "first_seen": "2026-03-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Research of CVE-2024-3094 vulnerability.",
                    "summary": "Research of CVE-2024-3094 vulnerability.",
                    "url": "https://github.com/extracoding-dozen/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · ElinaNotElina/cve-2024-3094-analysis",
                    "author": "ElinaNotElina",
                    "first_seen": "2026-04-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/ElinaNotElina/cve-2024-3094-analysis"
                },
                {
                    "repository": "PoC-in-GitHub · vnchk1/sec_review_cve-2024-3094",
                    "author": "vnchk1",
                    "first_seen": "2026-04-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Security review уязвимости CVE-2024-3094 с открытым исходным кодом",
                    "summary": "Security review уязвимости CVE-2024-3094 с открытым исходным кодом",
                    "url": "https://github.com/vnchk1/sec_review_cve-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · h3raklez/CVE-2024-3094",
                    "author": "h3raklez",
                    "first_seen": "2026-04-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 - XZ Utils Backdoor",
                    "summary": "CVE-2024-3094 - XZ Utils Backdoor",
                    "url": "https://github.com/h3raklez/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · Ava-Vispilio/CVE-2024-3094",
                    "author": "Ava-Vispilio",
                    "first_seen": "2026-04-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/Ava-Vispilio/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · 0xBlackash/CVE-2024-3094",
                    "author": "0xBlackash",
                    "first_seen": "2026-04-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094",
                    "summary": "CVE-2024-3094",
                    "url": "https://github.com/0xBlackash/CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · vesjolyjd/Kaspersky_CVE-2024-3094",
                    "author": "vesjolyjd",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2024-3094 repository",
                    "summary": "",
                    "url": "https://github.com/vesjolyjd/Kaspersky_CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · stevehenderson/lab_xz_backdoor",
                    "author": "stevehenderson",
                    "first_seen": "2026-06-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)",
                    "summary": "Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)",
                    "url": "https://github.com/stevehenderson/lab_xz_backdoor"
                },
                {
                    "repository": "PoC-in-GitHub · nnatsopoulos/xz-backdoor-research",
                    "author": "nnatsopoulos",
                    "first_seen": "2026-06-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool",
                    "summary": "CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool",
                    "url": "https://github.com/nnatsopoulos/xz-backdoor-research"
                },
                {
                    "repository": "PoC-in-GitHub · x-cmd-build/xz",
                    "author": "x-cmd-build",
                    "first_seen": "2026-07-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Vendored xz-utils @ 5.8.3 (post-CVE-2024-3094) — portable binary distribution for x-cmd, musl-static + macOS + Windows MSYS",
                    "summary": "Vendored xz-utils @ 5.8.3 (post-CVE-2024-3094) — portable binary distribution for x-cmd, musl-static + macOS + Windows MSYS",
                    "url": "https://github.com/x-cmd-build/xz"
                },
                {
                    "repository": "PoC-in-GitHub · Preacher98/Report-XZ-Utils-CVE-2024-3094",
                    "author": "Preacher98",
                    "first_seen": "2026-07-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Hello,",
                    "summary": "Hello,",
                    "url": "https://github.com/Preacher98/Report-XZ-Utils-CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · namegabevictoire01-sys/cs50-cybersecurity-final-project",
                    "author": "namegabevictoire01-sys",
                    "first_seen": "2026-08-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CS50 Cybersecurity Final Project - Analysis of CVE-2024-3094",
                    "summary": "CS50 Cybersecurity Final Project - Analysis of CVE-2024-3094",
                    "url": "https://github.com/namegabevictoire01-sys/cs50-cybersecurity-final-project"
                },
                {
                    "repository": "PoC-in-GitHub · mhicairo-hue/cs50-cybersecurity-final-project",
                    "author": "mhicairo-hue",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CS50 Cybersecurity Final Project: Technical Analysis of the XZ Utils Backdoor (CVE-2024-3094)",
                    "summary": "CS50 Cybersecurity Final Project: Technical Analysis of the XZ Utils Backdoor (CVE-2024-3094)",
                    "url": "https://github.com/mhicairo-hue/cs50-cybersecurity-final-project"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-15T10:56:40+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2024-3094 exploit",
                    "summary": "Exploit for CVE-2024-3094. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ASHWANI95-CVE-2024-3094"
                },
                {
                    "repository": "PoC-in-GitHub · Michel-DV/xz-utils-backdoor-case-study",
                    "author": "Michel-DV",
                    "first_seen": "2026-09-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Technical case study of the XZ Utils backdoor (CVE-2024-3094), covering supply-chain trust abuse, malicious release artifacts, build-stage injection, sshd dependency abuse, detection engineering and Red Team lessons.",
                    "summary": "Technical case study of the XZ Utils backdoor (CVE-2024-3094), covering supply-chain trust abuse, malicious release artifacts, build-stage injection, sshd dependency abuse, detection engineering and Red Team lessons.",
                    "url": "https://github.com/Michel-DV/xz-utils-backdoor-case-study"
                },
                {
                    "title": "Exploit for kong CVE-2024-3094",
                    "summary": "Kong is an LLM orchestration tool for reverse engineering obfuscated stripped binaries into Ghidra.",
                    "what_happened": "Kong is an LLM orchestration tool for reverse engineering obfuscated stripped binaries into Ghidra.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AMRUTH-SN-KONG",
                        "https://kitploit.com/hi/tools/github/amruth-sn/kong/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T16:37:51",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AMRUTH-SN-KONG"
                },
                {
                    "title": "Exploit for kong CVE-2024-3094",
                    "summary": "Kong is an LLM orchestration tool for reverse engineering obfuscated stripped binaries into Ghidra.",
                    "what_happened": "Kong is an LLM orchestration tool for reverse engineering obfuscated stripped binaries into Ghidra.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AMRUTH-SN-KONG",
                        "https://kitploit.com/hi/tools/github/amruth-sn/kong/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-05T16:37:51",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/amruth-sn/kong/"
                }
            ],
            "references": [
                "https://github.com/byinarie/CVE-2024-3094-info",
                "https://github.com/FabioBaroni/CVE-2024-3094-checker",
                "https://github.com/lypd0/CVE-2024-3094-Vulnerabity-Checker",
                "https://github.com/OpensourceICTSolutions/xz_utils-CVE-2024-3094",
                "https://github.com/bioless/xz_cve-2024-3094_detection",
                "https://github.com/HackerHermanos/CVE-2024-3094_xz_check",
                "https://github.com/Fractal-Tess/CVE-2024-3094",
                "https://github.com/wgetnz/CVE-2024-3094-check",
                "https://github.com/emirkmo/xz-backdoor-github",
                "https://github.com/ashwani95/CVE-2024-3094",
                "https://github.com/harekrishnarai/xz-utils-vuln-checker",
                "https://github.com/teyhouse/CVE-2024-3094",
                "https://github.com/gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer",
                "https://github.com/Horizon-Software-Development/CVE-2024-3094",
                "https://github.com/hazemkya/CVE-2024-3094-checker",
                "https://github.com/lockness-Ko/xz-vulnerable-honeypot",
                "https://github.com/brinhosa/CVE-2024-3094-One-Liner",
                "https://github.com/isuruwa/CVE-2024-3094",
                "https://github.com/Yuma-Tsushima07/CVE-2024-3094",
                "https://github.com/jfrog/cve-2024-3094-tools",
                "https://github.com/Simplifi-ED/CVE-2024-3094-patcher",
                "https://github.com/spidygal/CVE-2024-3094-Nmap-NSE-script",
                "https://github.com/Mustafa1986/CVE-2024-3094",
                "https://github.com/MrBUGLF/XZ-Utils_CVE-2024-3094",
                "https://github.com/galacticquest/cve-2024-3094-detect",
                "https://github.com/mightysai1997/CVE-2024-3094-info",
                "https://github.com/mightysai1997/CVE-2024-3094",
                "https://github.com/mesutgungor/xz-backdoor-vulnerability",
                "https://github.com/jbnetwork-git/CVE-2024-3094-XZ-Utils-Check",
                "https://github.com/amlweems/xzbot",
                "https://github.com/zpxlz/CVE-2024-3094",
                "https://github.com/gustavorobertux/CVE-2024-3094",
                "https://github.com/ackemed/detectar_cve-2024-3094",
                "https://github.com/0xlane/xz-cve-2024-3094",
                "https://github.com/dah4k/CVE-2024-3094",
                "https://github.com/hackingetico21/revisaxzutils",
                "https://github.com/devjanger/CVE-2024-3094-XZ-Backdoor-Detector",
                "https://github.com/ScrimForever/CVE-2024-3094",
                "https://github.com/pentestfunctions/CVE-2024-3094",
                "https://github.com/r0binak/xzk8s",
                "https://github.com/przemoc/xz-backdoor-links",
                "https://github.com/Security-Phoenix-demo/CVE-2024-3094-fix-exploits",
                "https://github.com/MagpieRYL/CVE-2024-3094-backdoor-env-container",
                "https://github.com/Bella-Bc/xz-backdoor-CVE-2024-3094-Check",
                "https://github.com/TheTorjanCaptain/CVE-2024-3094-Checker",
                "https://github.com/iheb2b/CVE-2024-3094-Checker",
                "https://github.com/felipecosta09/cve-2024-3094",
                "https://github.com/weltregie/liblzma-scan",
                "https://github.com/KaminaDuck/ansible-CVE-2024-3094",
                "https://github.com/robertdebock/ansible-playbook-cve-2024-3094",
                "https://github.com/badsectorlabs/ludus_xz_backdoor",
                "https://github.com/Juul/xz-backdoor-scan",
                "https://github.com/fevar54/Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-",
                "https://github.com/neuralinhibitor/xzwhy",
                "https://github.com/AndreaCicca/Sicurezza-Informatica-Presentazione",
                "https://github.com/shefirot/CVE-2024-3094",
                "https://github.com/robertdfrench/ifuncd-up",
                "https://github.com/been22426/CVE-2024-3094",
                "https://github.com/laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094",
                "https://github.com/valeriot30/cve-2024-3094",
                "https://github.com/24Owais/threat-intel-cve-2024-3094",
                "https://github.com/Ikram124/CVE-2024-3094-analysis",
                "https://github.com/mrk336/CVE-2024-3094",
                "https://github.com/Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public",
                "https://github.com/M1lo25/CS50FinalProject",
                "https://github.com/ThomRgn/xzutils_backdoor_obfuscation",
                "https://github.com/encikayelwhitehat-glitch/CVE-2024-3094",
                "https://github.com/BOSE122/CVE-2024-3094",
                "https://github.com/hackura/xz-cve-2024-3094",
                "https://github.com/michalAshurov/writeup-CVE-2024-3094",
                "https://github.com/extracoding-dozen/CVE-2024-3094",
                "https://github.com/ElinaNotElina/cve-2024-3094-analysis",
                "https://github.com/vnchk1/sec_review_cve-2024-3094",
                "https://github.com/h3raklez/CVE-2024-3094",
                "https://github.com/Ava-Vispilio/CVE-2024-3094",
                "https://github.com/0xBlackash/CVE-2024-3094",
                "https://github.com/vesjolyjd/Kaspersky_CVE-2024-3094",
                "https://github.com/stevehenderson/lab_xz_backdoor",
                "https://github.com/nnatsopoulos/xz-backdoor-research",
                "https://github.com/x-cmd-build/xz",
                "https://github.com/Preacher98/Report-XZ-Utils-CVE-2024-3094",
                "https://github.com/namegabevictoire01-sys/cs50-cybersecurity-final-project",
                "https://github.com/mhicairo-hue/cs50-cybersecurity-final-project",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ASHWANI95-CVE-2024-3094",
                "https://github.com/Michel-DV/xz-utils-backdoor-case-study",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AMRUTH-SN-KONG",
                "https://kitploit.com/hi/tools/github/amruth-sn/kong/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/byinarie/CVE-2024-3094-info"
                }
            ]
        },
        {
            "id": "CVE-2024-2389",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-2389 exploit",
            "summary": "Exploit for CVE-2024-2389. CVSS 10.",
            "updated_at": "2026-09-12T06:32:58Z",
            "published_at": "2026-09-12T06:32:58Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 35,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Arbitrary command execution in Progress Kemp Flowmon via confluence endpoint yields reverse shell.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-2389",
                    "summary": "Arbitrary command execution in Progress Kemp Flowmon via confluence endpoint yields reverse shell.",
                    "what_happened": "Arbitrary command execution in Progress Kemp Flowmon via confluence endpoint yields reverse shell.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ADHIKARA13-CVE-2024-2389",
                        "https://kitploit.com/hi/tools/github/adhikara13/cve-2024-2389/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T02:14:50",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ADHIKARA13-CVE-2024-2389"
                },
                {
                    "title": "Exploit for CVE-2024-2389",
                    "summary": "Arbitrary command execution in Progress Kemp Flowmon via confluence endpoint yields reverse shell.",
                    "what_happened": "Arbitrary command execution in Progress Kemp Flowmon via confluence endpoint yields reverse shell.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ADHIKARA13-CVE-2024-2389",
                        "https://kitploit.com/hi/tools/github/adhikara13/cve-2024-2389/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T02:14:50",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/adhikara13/cve-2024-2389/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ADHIKARA13-CVE-2024-2389",
                "https://kitploit.com/hi/tools/github/adhikara13/cve-2024-2389/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:32:58Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ADHIKARA13-CVE-2024-2389"
                }
            ]
        },
        {
            "id": "CVE-2024-1540",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Controlled security-research lab reproducing CVE-2024-1540 (GitHub Actions command injection in gradio-app/gradio deploy+test-visual.yml) — flattened snapshot of gradio-app/gradio @ f35f615e33a5dd90bfeb106b6f5dca689849fcef",
            "summary": "Controlled security-research lab reproducing CVE-2024-1540 (GitHub Actions command injection in gradio-app/gradio deploy+test-visual.yml) — flattened snapshot of gradio-app/gradio @ f35f615e33a5dd90bfeb106b6f5dca689849fcef",
            "updated_at": "2026-08-31T22:00:00Z",
            "published_at": "2026-08-31T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 36,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · pvharmo2/gha-lab-8e9316151c",
                    "author": "pvharmo2",
                    "first_seen": "2026-09-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Controlled security-research lab reproducing CVE-2024-1540 (GitHub Actions command injection in gradio-app/gradio deploy+test-visual.yml) — flattened snapshot of gradio-app/gradio @ f35f615e33a5dd90bfeb106b6f5dca689849fcef",
                    "summary": "Controlled security-research lab reproducing CVE-2024-1540 (GitHub Actions command injection in gradio-app/gradio deploy+test-visual.yml) — flattened snapshot of gradio-app/gradio @ f35f615e33a5dd90bfeb106b6f5dca689849fcef",
                    "url": "https://github.com/pvharmo2/gha-lab-8e9316151c"
                }
            ],
            "references": [
                "https://github.com/pvharmo2/gha-lab-8e9316151c"
            ],
            "timeline": [
                {
                    "at": "2026-08-31T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/pvharmo2/gha-lab-8e9316151c"
                }
            ]
        },
        {
            "id": "CVE-2024-1403",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-1403 exploit",
            "summary": "Exploit for CVE-2024-1403. CVSS 10.",
            "updated_at": "2026-09-14T18:33:12Z",
            "published_at": "2026-09-14T18:33:12Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Authentication bypass in Progress OpenEdge AdminServer RMI via NT AUTHORITY\\SYSTEM credential.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-1403",
                    "summary": "Authentication bypass in Progress OpenEdge AdminServer RMI via NT AUTHORITY\\SYSTEM credential.",
                    "what_happened": "Authentication bypass in Progress OpenEdge AdminServer RMI via NT AUTHORITY\\SYSTEM credential.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HORIZON3AI-CVE-2024-1403",
                        "https://kitploit.com/ru/tools/github/horizon3ai/cve-2024-1403/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T08:51:07",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HORIZON3AI-CVE-2024-1403"
                },
                {
                    "title": "Exploit for CVE-2024-1403",
                    "summary": "Authentication bypass in Progress OpenEdge AdminServer RMI via NT AUTHORITY\\SYSTEM credential.",
                    "what_happened": "Authentication bypass in Progress OpenEdge AdminServer RMI via NT AUTHORITY\\SYSTEM credential.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HORIZON3AI-CVE-2024-1403",
                        "https://kitploit.com/ru/tools/github/horizon3ai/cve-2024-1403/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T08:51:07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/horizon3ai/cve-2024-1403/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HORIZON3AI-CVE-2024-1403",
                "https://kitploit.com/ru/tools/github/horizon3ai/cve-2024-1403/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T18:33:12Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HORIZON3AI-CVE-2024-1403"
                }
            ]
        },
        {
            "id": "CVE-2024-1249",
            "vendor": "Red Hat",
            "product": "Red Hat AMQ Broker 7",
            "title": "Red Hat AMQ Broker 7 vulnerability",
            "summary": "A flaw was found in Keycloak's OIDC component in the \"checkLoginIframe,\" which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.",
            "updated_at": "2026-09-08T20:17:25.350",
            "published_at": "2024-04-17T14:15:08.160",
            "cvss": 7.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "21.1.0 through before 22.0.10 (semver); 23.0.0 through before 24.0.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-346",
            "what_happened": "A flaw was found in Keycloak's OIDC component in the \"checkLoginIframe,\" which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2024:1860",
                "https://access.redhat.com/errata/RHSA-2024:1861",
                "https://access.redhat.com/errata/RHSA-2024:1862",
                "https://access.redhat.com/errata/RHSA-2024:1864",
                "https://access.redhat.com/errata/RHSA-2024:1866",
                "https://access.redhat.com/errata/RHSA-2024:1867",
                "https://access.redhat.com/errata/RHSA-2024:1868",
                "https://access.redhat.com/errata/RHSA-2024:2945",
                "https://access.redhat.com/errata/RHSA-2024:4057",
                "https://access.redhat.com/security/cve/CVE-2024-1249",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2262918"
            ],
            "timeline": [
                {
                    "at": "2024-04-17T14:15:08.160",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1249"
                }
            ]
        },
        {
            "id": "CVE-2024-0520",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-0520_try exploit",
            "summary": "Exploit for CVE-2024-0520. CVSS 10.",
            "updated_at": "2026-09-11T18:30:44Z",
            "published_at": "2026-09-11T18:30:44Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 41,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Repository CVE-2024-0520_try for tools has no README.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-0520_try",
                    "summary": "Repository CVE-2024-0520_try for tools has no README.",
                    "what_happened": "Repository CVE-2024-0520_try for tools has no README.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CHAN-068-CVE-2024-0520_TRY",
                        "https://kitploit.com/ar/tools/github/chan-068/cve-2024-0520_try/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T18:30:11",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CHAN-068-CVE-2024-0520_TRY"
                },
                {
                    "title": "Exploit for CVE-2024-0520_try",
                    "summary": "Repository CVE-2024-0520_try for tools has no README.",
                    "what_happened": "Repository CVE-2024-0520_try for tools has no README.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CHAN-068-CVE-2024-0520_TRY",
                        "https://kitploit.com/ar/tools/github/chan-068/cve-2024-0520_try/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-06T18:30:11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/chan-068/cve-2024-0520_try/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CHAN-068-CVE-2024-0520_TRY",
                "https://kitploit.com/ar/tools/github/chan-068/cve-2024-0520_try/"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T18:30:44Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CHAN-068-CVE-2024-0520_TRY"
                }
            ]
        },
        {
            "id": "CVE-2024-0015",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2024-0015 exploit",
            "summary": "Exploit for CVE-2024-0015. CVSS 7.8.",
            "updated_at": "2026-09-05T08:12:58Z",
            "published_at": "2026-09-05T08:12:58Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 111,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "PoC and EXP demonstration of CVE-2024-0015 for tools by DubheCTF.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2024-0015",
                    "summary": "PoC and EXP demonstration of CVE-2024-0015 for tools by DubheCTF.",
                    "what_happened": "PoC and EXP demonstration of CVE-2024-0015 for tools by DubheCTF.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-UMVFX1BVAW50-CVE-2024-0015",
                        "https://kitploit.com/ru/tools/github/umvfx1bvaw50/cve-2024-0015/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T10:58:07",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-UMVFX1BVAW50-CVE-2024-0015"
                },
                {
                    "title": "Exploit for CVE-2024-0015",
                    "summary": "PoC and EXP demonstration of CVE-2024-0015 for tools by DubheCTF.",
                    "what_happened": "PoC and EXP demonstration of CVE-2024-0015 for tools by DubheCTF.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-UMVFX1BVAW50-CVE-2024-0015",
                        "https://kitploit.com/ru/tools/github/umvfx1bvaw50/cve-2024-0015/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T10:58:07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/umvfx1bvaw50/cve-2024-0015/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-UMVFX1BVAW50-CVE-2024-0015",
                "https://kitploit.com/ru/tools/github/umvfx1bvaw50/cve-2024-0015/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:12:58Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-UMVFX1BVAW50-CVE-2024-0015"
                }
            ]
        },
        {
            "id": "CVE-2023-54237",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix potential panic dues to unprotected smc_llc_srv_add_link()\n\nThere is a certain chance to trigger the following panic:\n\nPID: 5900   TASK: ffff88c1c8af4100  CPU: 1   COMMAND: \"kworker/1:48\"\n #0 [ffff9456c1cc79a0] machine_kexec at ffffffff870665b7\n #1 [ffff9456c1cc79f0] __crash_kexec at ffffffff871b4c7a\n #2 [ffff9456c1cc7ab0] crash_kexec at ffffffff871b5b60\n #3 [ffff9456c1cc7ac0] oops_end at ffffffff87026ce7\n #4 [ffff9456c1cc7ae0] page_fault_oops at ffffffff87075715\n #5 [ffff9456c1cc7b58] exc_page_fault at ffffffff87ad0654\n #6 [ffff9456c1cc7b80] asm_exc_page_fault at ffffffff87c00b62\n    [exception RIP: ib_alloc_mr+19]\n    RIP: ffffffffc0c9cce3  RSP: ffff9456c1cc7c38  RFLAGS: 00010202\n    RAX: 0000000000000000  RBX: 0000000000000002  RCX: 0000000000000004\n    RDX: 0000000000000010  RSI: 0000000000000000  RDI: 0000000000000000\n    RBP: ffff88c1ea281d00   R8: 000000020a34ffff   R9: ffff88c1350bbb20\n    R10: 0000000000000000  R11: 0000000000000001  R12: 0000000000000000\n    R13: 0000000000000010  R14: ffff88c1ab040a50  R15: ffff88c1ea281d00\n    ORIG_RAX: ffffffffffffffff  CS: 0010  SS: 0018\n #7 [ffff9456c1cc7c60] smc_ib_get_memory_region at ffffffffc0aff6df [smc]\n #8 [ffff9456c1cc7c88] smcr_buf_map_link at ffffffffc0b0278c [smc]\n #9 [ffff9456c1cc7ce0] __smc_buf_create at ffffffffc0b03586 [smc]\n\nThe reason here is that when the server tries to create a second link,\nsmc_llc_srv_add_link() has no protection and may add a new link to\nlink group. This breaks the security environment protected by\nllc_conf_mutex.",
            "updated_at": "2026-09-14T12:17:32.890",
            "published_at": "2025-12-30T13:16:12.193",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2d2209f2018943d4152a21eff5b76f1952e0b435 through before fe35c24b730d38b421da93ac5d493cb4495e8e54 (git); 2d2209f2018943d4152a21eff5b76f1952e0b435 through before f2f46de98c11d41ac8d22765f47ba54ce5480a5b (git); 2d2209f2018943d4152a21eff5b76f1952e0b435 through before 0c764cc271d3aa6528ae1b3394babf34ac01f775 (git); 2d2209f2018943d4152a21eff5b76f1952e0b435 through before e40b801b3603a8f90b46acbacdea3505c27f01c0 (git); 5.8",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix potential panic dues to unprotected smc_llc_srv_add_link()\n\nThere is a certain chance to trigger the following panic:\n\nPID: 5900   TASK: ffff88c1c8af4100  CPU: 1   COMMAND: \"kworker/1:48\"\n #0 [ffff9456c1cc79a0] machine_kexec at ffffffff870665b7\n #1 [ffff9456c1cc79f0] __crash_kexec at ffffffff871b4c7a\n #2 [ffff9456c1cc7ab0] crash_kexec at ffffffff871b5b60\n #3 [ffff9456c1cc7ac0] oops_end at ffffffff87026ce7\n #4 [ffff9456c1cc7ae0] page_fault_oops at ffffffff87075715\n #5 [ffff9456c1cc7b58] exc_page_fault at ffffffff87ad0654\n #6 [ffff9456c1cc7b80] asm_exc_page_fault at ffffffff87c00b62\n    [exception RIP: ib_alloc_mr+19]\n    RIP: ffffffffc0c9cce3  RSP: ffff9456c1cc7c38  RFLAGS: 00010202\n    RAX: 0000000000000000  RBX: 0000000000000002  RCX: 0000000000000004\n    RDX: 0000000000000010  RSI: 0000000000000000  RDI: 0000000000000000\n    RBP: ffff88c1ea281d00   R8: 000000020a34ffff   R9: ffff88c1350bbb20\n    R10: 0000000000000000  R11: 0000000000000001  R12: 0000000000000000\n    R13: 0000000000000010  R14: ffff88c1ab040a50  R15: ffff88c1ea281d00\n    ORIG_RAX: ffffffffffffffff  CS: 0010  SS: 0018\n #7 [ffff9456c1cc7c60] smc_ib_get_memory_region at ffffffffc0aff6df [smc]\n #8 [ffff9456c1cc7c88] smcr_buf_map_link at ffffffffc0b0278c [smc]\n #9 [ffff9456c1cc7ce0] __smc_buf_create at ffffffffc0b03586 [smc]\n\nThe reason here is that when the server tries to create a second link,\nsmc_llc_srv_add_link() has no protection and may add a new link to\nlink group. This breaks the security environment protected by\nllc_conf_mutex.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/0c764cc271d3aa6528ae1b3394babf34ac01f775",
                "https://git.kernel.org/stable/c/e40b801b3603a8f90b46acbacdea3505c27f01c0",
                "https://git.kernel.org/stable/c/f2f46de98c11d41ac8d22765f47ba54ce5480a5b",
                "https://git.kernel.org/stable/c/fe35c24b730d38b421da93ac5d493cb4495e8e54"
            ],
            "timeline": [
                {
                    "at": "2025-12-30T13:16:12.193",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-54237"
                }
            ]
        },
        {
            "id": "CVE-2023-53292",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_none\n\nAfter grabbing q->sysfs_lock, q->elevator may become NULL because of\nelevator switch.\n\nFix the NULL dereference on q->elevator by checking it with lock.",
            "updated_at": "2026-09-08T09:17:16.520",
            "published_at": "2025-09-16T08:15:38.457",
            "cvss": 5.5,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "5fd7a84a09e640016fe106dd3e992f5210e23dc7 through before 988ddb77218d3975dd13dee7bb0e1fae098a9fdb (git); 5fd7a84a09e640016fe106dd3e992f5210e23dc7 through before 3e977386521b71471e66ec2ba82efdfcc456adf2 (git); 5fd7a84a09e640016fe106dd3e992f5210e23dc7 through before 245165658e1c9f95c0fecfe02b9b1ebd30a1198a (git); 5.19; V3.1.6 through before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_none\n\nAfter grabbing q->sysfs_lock, q->elevator may become NULL because of\nelevator switch.\n\nFix the NULL dereference on q->elevator by checking it with lock.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/245165658e1c9f95c0fecfe02b9b1ebd30a1198a",
                "https://git.kernel.org/stable/c/3e977386521b71471e66ec2ba82efdfcc456adf2",
                "https://git.kernel.org/stable/c/988ddb77218d3975dd13dee7bb0e1fae098a9fdb",
                "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
            ],
            "timeline": [
                {
                    "at": "2025-09-16T08:15:38.457",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53292"
                }
            ]
        },
        {
            "id": "CVE-2023-52676",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Guard stack limits against 32bit overflow\n\nThis patch promotes the arithmetic around checking stack bounds to be\ndone in the 64-bit domain, instead of the current 32bit. The arithmetic\nimplies adding together a 64-bit register with a int offset. The\nregister was checked to be below 1<<29 when it was variable, but not\nwhen it was fixed. The offset either comes from an instruction (in which\ncase it is 16 bit), from another register (in which case the caller\nchecked it to be below 1<<29 [1]), or from the size of an argument to a\nkfunc (in which case it can be a u32 [2]). Between the register being\ninconsistently checked to be below 1<<29, and the offset being up to an\nu32, it appears that we were open to overflowing the `int`s which were\ncurrently used for arithmetic.\n\n[1] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L7494-L7498\n[2] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L11904",
            "updated_at": "2026-09-14T12:17:32.653",
            "published_at": "2024-05-17T15:15:18.633",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "f3c4b01689d392373301e6e60d1b02c5b4020afc through before ad1754f86a87fe74912fb542b23ff24ada4e3307 (git); 01f810ace9ed37255f27608a0864abebccf0aab3 through before 4ba97610399e83d29d1086a0827d33172539b49b (git); 01f810ace9ed37255f27608a0864abebccf0aab3 through before e160b2ed94a20fa940369ebd914277f88005e70d (git); 01f810ace9ed37255f27608a0864abebccf0aab3 through before ad140fc856f0b1d5e2215bcb6d0cc247a86805a2 (git); 01f810ace9ed37255f27608a0864abebccf0aab3 through before e5ad9ecb84405637df82732ee02ad741a5f782a6 (git); 01f810ace9ed37255f27608a0864abebccf0aab3 through before 1d38a9ee81570c4bd61f557832dead4d6f816760 (git); d1b725ea5d104caea250427899f4e2e3ab15b4fc (git); 5.10.33 through before 5.10.270 (semver); 5.11.17 through before 5.12 (semver); 5.12",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-190",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Guard stack limits against 32bit overflow\n\nThis patch promotes the arithmetic around checking stack bounds to be\ndone in the 64-bit domain, instead of the current 32bit. The arithmetic\nimplies adding together a 64-bit register with a int offset. The\nregister was checked to be below 1<<29 when it was variable, but not\nwhen it was fixed. The offset either comes from an instruction (in which\ncase it is 16 bit), from another register (in which case the caller\nchecked it to be below 1<<29 [1]), or from the size of an argument to a\nkfunc (in which case it can be a u32 [2]). Between the register being\ninconsistently checked to be below 1<<29, and the offset being up to an\nu32, it appears that we were open to overflowing the `int`s which were\ncurrently used for arithmetic.\n\n[1] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L7494-L7498\n[2] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L11904",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/1d38a9ee81570c4bd61f557832dead4d6f816760",
                "https://git.kernel.org/stable/c/4ba97610399e83d29d1086a0827d33172539b49b",
                "https://git.kernel.org/stable/c/ad140fc856f0b1d5e2215bcb6d0cc247a86805a2",
                "https://git.kernel.org/stable/c/ad1754f86a87fe74912fb542b23ff24ada4e3307",
                "https://git.kernel.org/stable/c/e160b2ed94a20fa940369ebd914277f88005e70d",
                "https://git.kernel.org/stable/c/e5ad9ecb84405637df82732ee02ad741a5f782a6"
            ],
            "timeline": [
                {
                    "at": "2024-05-17T15:15:18.633",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52676"
                }
            ]
        },
        {
            "id": "CVE-2023-52251",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages. No fixed release is available; the project has had no commit since 2024-04-08.",
            "updated_at": "2026-09-08T19:17:43.673",
            "published_at": "2024-01-25T21:15:08.787",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 37,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-94",
            "what_happened": "An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages. No fixed release is available; the project has had no commit since 2024-04-08.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2024-01-25",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/BobTheShoplifter/CVE-2023-52251-POC"
                }
            ],
            "references": [
                "http://packetstormsecurity.com/files/177214/Kafka-UI-0.7.1-Command-Injection.html",
                "https://github.com/BobTheShoplifter/CVE-2023-52251-POC",
                "https://github.com/github/advisory-database/issues/9400",
                "https://github.com/google/osv.dev/issues/5988",
                "https://github.com/kafbat/kafka-ui/commit/11a57d14",
                "https://github.com/provectus/kafka-ui/blob/v0.7.2/kafka-ui-api/src/main/java/com/provectus/kafka/ui/emitter/MessageFilters.java"
            ],
            "timeline": [
                {
                    "at": "2024-01-25T21:15:08.787",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52251"
                }
            ]
        },
        {
            "id": "CVE-2023-51769",
            "vendor": "Frappe",
            "product": "Frappe",
            "title": "Frappe vulnerability",
            "summary": "Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.",
            "updated_at": "2026-09-14T07:17:15.933",
            "published_at": "2026-09-14T07:17:15.933",
            "cvss": 6.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 14.49.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/frappe/frappe/compare/v14.48.1...v14.49.0",
                "https://github.com/frappe/frappe/security/advisories/GHSA-439c-3956-r8q7"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T07:17:15.933",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51769"
                }
            ]
        },
        {
            "id": "CVE-2023-50781",
            "vendor": "Red Hat",
            "product": "Red Hat Enterprise Linux 6",
            "title": "Red Hat Enterprise Linux 6 vulnerability",
            "summary": "A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.",
            "updated_at": "2026-09-16T20:16:07.447",
            "published_at": "2024-02-05T21:15:10.970",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before * (custom)",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-203",
            "what_happened": "A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/security/cve/CVE-2023-50781",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2254426",
                "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
            ],
            "timeline": [
                {
                    "at": "2024-02-05T21:15:10.970",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50781"
                }
            ]
        },
        {
            "id": "CVE-2023-50462",
            "vendor": "TYPO3",
            "product": "content_consent",
            "title": "content_consent vulnerability",
            "summary": "An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to display various content elements, leading to an insecure direct object reference (IDOR) issue with the potential to expose internal content elements.",
            "updated_at": "2026-09-14T07:17:15.793",
            "published_at": "2026-09-14T07:17:15.793",
            "cvss": 5.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.0.3 (semver); 2.0.0 through before 2.0.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to display various content elements, leading to an insecure direct object reference (IDOR) issue with the potential to expose internal content elements.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://typo3.org/security/advisory/typo3-ext-sa-2023-009"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T07:17:15.793",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50462"
                }
            ]
        },
        {
            "id": "CVE-2023-50461",
            "vendor": "TYPO3",
            "product": "direct_mail",
            "title": "direct_mail vulnerability",
            "summary": "An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4 and above) and to Arbitrary Code Execution (TYPO3 9.5 and below). A valid backend user account, with access to the Direct Mail Configuration backend module, is needed to exploit this.",
            "updated_at": "2026-09-14T07:17:15.653",
            "published_at": "2026-09-14T07:17:15.653",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 6.0.3 (semver); 7.0.0 through before 7.0.3 (semver); 8.0.0 through before 9.5.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4 and above) and to Arbitrary Code Execution (TYPO3 9.5 and below). A valid backend user account, with access to the Direct Mail Configuration backend module, is needed to exploit this.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://typo3.org/security/advisory/typo3-ext-sa-2023-011"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T07:17:15.653",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50461"
                }
            ]
        },
        {
            "id": "CVE-2023-50460",
            "vendor": "TYPO3",
            "product": "femanager",
            "title": "femanager vulnerability",
            "summary": "An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system.",
            "updated_at": "2026-09-14T07:17:15.510",
            "published_at": "2026-09-14T07:17:15.510",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.0.0 through before 7.2.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://typo3.org/security/advisory/typo3-ext-sa-2023-010"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T07:17:15.510",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50460"
                }
            ]
        },
        {
            "id": "CVE-2023-50459",
            "vendor": "TYPO3",
            "product": "femanager",
            "title": "femanager vulnerability",
            "summary": "An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.",
            "updated_at": "2026-09-14T07:17:15.353",
            "published_at": "2026-09-14T07:17:15.353",
            "cvss": 5.4,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.0.0 through before 7.2.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-863",
            "what_happened": "An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://typo3.org/security/advisory/typo3-ext-sa-2023-010"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T07:17:15.353",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50459"
                }
            ]
        },
        {
            "id": "CVE-2023-50164",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "cve-2023-50164 exploit",
            "summary": "Exploit for CVE-2023-50164. CVSS 9.8.",
            "updated_at": "2026-09-06T08:34:34Z",
            "published_at": "2026-09-06T08:34:34Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 87,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Simple app demonstrating Sysdig detection of CVE-2023-50164.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for cve-2023-50164 CVE-2023-50164",
                    "summary": "Simple app demonstrating Sysdig detection of CVE-2023-50164.",
                    "what_happened": "Simple app demonstrating Sysdig detection of CVE-2023-50164.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AARONM-SYSDIG-CVE-2023-50164",
                        "https://kitploit.com/hi/tools/github/aaronm-sysdig/cve-2023-50164/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T08:34:34",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AARONM-SYSDIG-CVE-2023-50164"
                },
                {
                    "title": "Exploit for cve-2023-50164 CVE-2023-50164",
                    "summary": "Simple app demonstrating Sysdig detection of CVE-2023-50164.",
                    "what_happened": "Simple app demonstrating Sysdig detection of CVE-2023-50164.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AARONM-SYSDIG-CVE-2023-50164",
                        "https://kitploit.com/hi/tools/github/aaronm-sysdig/cve-2023-50164/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T08:34:34",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/aaronm-sysdig/cve-2023-50164/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AARONM-SYSDIG-CVE-2023-50164",
                "https://kitploit.com/hi/tools/github/aaronm-sysdig/cve-2023-50164/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:34:34Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AARONM-SYSDIG-CVE-2023-50164"
                }
            ]
        },
        {
            "id": "CVE-2023-49982",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2023-49982 exploit",
            "summary": "Exploit for CVE-2023-49982. CVSS 8.8.",
            "updated_at": "2026-09-13T18:37:53Z",
            "published_at": "2026-09-13T18:37:53Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 27,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Broken access control in School Fees Management System v1.0 allows privilege escalation to admin.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-49982",
                    "summary": "Broken access control in School Fees Management System v1.0 allows privilege escalation to admin.",
                    "what_happened": "Broken access control in School Fees Management System v1.0 allows privilege escalation to admin.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERALDOALCANTARA-CVE-2023-49982",
                        "https://kitploit.com/ru/tools/github/geraldoalcantara/cve-2023-49982/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T15:57:01",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERALDOALCANTARA-CVE-2023-49982"
                },
                {
                    "title": "Exploit for CVE-2023-49982",
                    "summary": "Broken access control in School Fees Management System v1.0 allows privilege escalation to admin.",
                    "what_happened": "Broken access control in School Fees Management System v1.0 allows privilege escalation to admin.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERALDOALCANTARA-CVE-2023-49982",
                        "https://kitploit.com/ru/tools/github/geraldoalcantara/cve-2023-49982/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T15:57:01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/geraldoalcantara/cve-2023-49982/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERALDOALCANTARA-CVE-2023-49982",
                "https://kitploit.com/ru/tools/github/geraldoalcantara/cve-2023-49982/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:37:53Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERALDOALCANTARA-CVE-2023-49982"
                }
            ]
        },
        {
            "id": "CVE-2023-49543",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2023-49543",
            "summary": "Unauthenticated access control flaw in Book Store Management System v1.0 enables account takeover.",
            "updated_at": "2026-09-04T06:42:05Z",
            "published_at": "2026-09-04T06:42:05Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 61,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Unauthenticated access control flaw in Book Store Management System v1.0 enables account takeover.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-49543",
                    "summary": "Unauthenticated access control flaw in Book Store Management System v1.0 enables account takeover.",
                    "what_happened": "Unauthenticated access control flaw in Book Store Management System v1.0 enables account takeover.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERALDOALCANTARA-CVE-2023-49543",
                        "https://kitploit.com/ru/tools/github/geraldoalcantara/cve-2023-49543/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T08:42:05",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERALDOALCANTARA-CVE-2023-49543"
                },
                {
                    "title": "Exploit for CVE-2023-49543",
                    "summary": "Unauthenticated access control flaw in Book Store Management System v1.0 enables account takeover.",
                    "what_happened": "Unauthenticated access control flaw in Book Store Management System v1.0 enables account takeover.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERALDOALCANTARA-CVE-2023-49543",
                        "https://kitploit.com/ru/tools/github/geraldoalcantara/cve-2023-49543/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T08:42:05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/geraldoalcantara/cve-2023-49543/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERALDOALCANTARA-CVE-2023-49543",
                "https://kitploit.com/ru/tools/github/geraldoalcantara/cve-2023-49543/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T06:42:05Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERALDOALCANTARA-CVE-2023-49543"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2023-49105",
            "vendor": "ownCloud",
            "product": "ownCloud",
            "title": "ownCloud Improper Authentication Vulnerability",
            "summary": "ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.",
            "updated_at": "2026-08-26T22:00:00Z",
            "published_at": "2026-08-26T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 49,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2023-46805",
            "vendor": "Ivanti",
            "product": "Connect Secure and Policy Secure",
            "title": "Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
            "summary": "Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.",
            "updated_at": "2026-09-05T09:04:57Z",
            "published_at": "2026-09-05T09:04:57Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Gideon CVE-2024-21887",
                    "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                        "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T11:04:57",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON"
                },
                {
                    "title": "Exploit for Gideon CVE-2024-21887",
                    "summary": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "what_happened": "Autonomous AI red teaming and security operations agent with CVE research and IOC analysis.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                        "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T11:04:57",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/cogensec/gideon/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COGENSEC-GIDEON",
                "https://kitploit.com/ru/tools/github/cogensec/gideon/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T09:04:57Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2023-46604",
            "vendor": "Apache",
            "product": "ActiveMQ",
            "title": "Apache ActiveMQ Deserialization of Untrusted Data Vulnerability",
            "summary": "Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.",
            "updated_at": "2026-08-31T22:00:00Z",
            "published_at": "2026-08-31T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 81,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · trganda/ActiveMQ-RCE",
                    "author": "trganda",
                    "first_seen": "2023-10-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 28,
                    "title": "CVE-2023-46604",
                    "summary": "CVE-2023-46604",
                    "url": "https://github.com/trganda/ActiveMQ-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · SaumyajeetDas/CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ",
                    "author": "SaumyajeetDas",
                    "first_seen": "2023-11-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 126,
                    "title": "Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)",
                    "summary": "Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)",
                    "url": "https://github.com/SaumyajeetDas/CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ"
                },
                {
                    "repository": "PoC-in-GitHub · evkl1d/CVE-2023-46604",
                    "author": "evkl1d",
                    "first_seen": "2023-11-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 41,
                    "title": "CVE-2023-46604 repository",
                    "summary": "",
                    "url": "https://github.com/evkl1d/CVE-2023-46604"
                },
                {
                    "repository": "PoC-in-GitHub · justdoit-cai/CVE-2023-46604-Apache-ActiveMQ-RCE-exp",
                    "author": "justdoit-cai",
                    "first_seen": "2023-11-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2023-46604 Apache ActiveMQ RCE exp 基于python",
                    "summary": "CVE-2023-46604 Apache ActiveMQ RCE exp 基于python",
                    "url": "https://github.com/justdoit-cai/CVE-2023-46604-Apache-ActiveMQ-RCE-exp"
                },
                {
                    "repository": "PoC-in-GitHub · h3x3h0g/ActiveMQ-RCE-CVE-2023-46604-Write-up",
                    "author": "h3x3h0g",
                    "first_seen": "2023-11-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2023-46604 repository",
                    "summary": "",
                    "url": "https://github.com/h3x3h0g/ActiveMQ-RCE-CVE-2023-46604-Write-up"
                },
                {
                    "repository": "PoC-in-GitHub · duck-sec/CVE-2023-46604-ActiveMQ-RCE-pseudoshell",
                    "author": "duck-sec",
                    "first_seen": "2023-11-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": "This script leverages CVE-2023046604 (Apache ActiveMQ) to generate a pseudo shell. The vulnerability allows for remote code execution due to unsafe deserialization within the OpenWire protocol.",
                    "summary": "This script leverages CVE-2023046604 (Apache ActiveMQ) to generate a pseudo shell. The vulnerability allows for remote code execution due to unsafe deserialization within the OpenWire protocol.",
                    "url": "https://github.com/duck-sec/CVE-2023-46604-ActiveMQ-RCE-pseudoshell"
                },
                {
                    "repository": "PoC-in-GitHub · vjayant93/CVE-2023-46604-POC",
                    "author": "vjayant93",
                    "first_seen": "2023-11-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "POC repo for CVE-2023-46604",
                    "summary": "POC repo for CVE-2023-46604",
                    "url": "https://github.com/vjayant93/CVE-2023-46604-POC"
                },
                {
                    "repository": "PoC-in-GitHub · LiritoShawshark/CVE-2023-46604_ActiveMQ_RCE_Recurrence",
                    "author": "LiritoShawshark",
                    "first_seen": "2023-11-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2023-46604环境复现包",
                    "summary": "CVE-2023-46604环境复现包",
                    "url": "https://github.com/LiritoShawshark/CVE-2023-46604_ActiveMQ_RCE_Recurrence"
                },
                {
                    "repository": "PoC-in-GitHub · NKeshawarz/CVE-2023-46604-RCE",
                    "author": "NKeshawarz",
                    "first_seen": "2023-11-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2023-46604 repository",
                    "summary": "",
                    "url": "https://github.com/NKeshawarz/CVE-2023-46604-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · minhangxiaohui/ActiveMQ_CVE-2023-46604",
                    "author": "minhangxiaohui",
                    "first_seen": "2023-11-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PY",
                    "summary": "PY",
                    "url": "https://github.com/minhangxiaohui/ActiveMQ_CVE-2023-46604"
                },
                {
                    "repository": "PoC-in-GitHub · CrackerCat/ActiveMQ_RCE_Pro_Max",
                    "author": "CrackerCat",
                    "first_seen": "2023-11-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-46604",
                    "summary": "CVE-2023-46604",
                    "url": "https://github.com/CrackerCat/ActiveMQ_RCE_Pro_Max"
                },
                {
                    "repository": "PoC-in-GitHub · nitzanoligo/CVE-2023-46604-demo",
                    "author": "nitzanoligo",
                    "first_seen": "2023-11-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-46604 repository",
                    "summary": "",
                    "url": "https://github.com/nitzanoligo/CVE-2023-46604-demo"
                },
                {
                    "repository": "PoC-in-GitHub · dcm2406/CVE-Lab",
                    "author": "dcm2406",
                    "first_seen": "2023-12-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Instructions for exploiting vulnerabilities CVE-2021-44228 and CVE-2023-46604",
                    "summary": "Instructions for exploiting vulnerabilities CVE-2021-44228 and CVE-2023-46604",
                    "url": "https://github.com/dcm2406/CVE-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · mrpentst/CVE-2023-46604",
                    "author": "mrpentst",
                    "first_seen": "2023-12-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Exploit for CVE-2023-46604",
                    "summary": "Exploit for CVE-2023-46604",
                    "url": "https://github.com/mrpentst/CVE-2023-46604"
                },
                {
                    "repository": "PoC-in-GitHub · dcm2406/CVE-2023-46604",
                    "author": "dcm2406",
                    "first_seen": "2023-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-46604 repository",
                    "summary": "",
                    "url": "https://github.com/dcm2406/CVE-2023-46604"
                },
                {
                    "repository": "PoC-in-GitHub · Mudoleto/Broker_ApacheMQ",
                    "author": "Mudoleto",
                    "first_seen": "2023-12-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-46604 - ApacheMQ Version 5.15.5 Vulnerability  Machine: Broker",
                    "summary": "CVE-2023-46604 - ApacheMQ Version 5.15.5 Vulnerability  Machine: Broker",
                    "url": "https://github.com/Mudoleto/Broker_ApacheMQ"
                },
                {
                    "repository": "PoC-in-GitHub · tomasmussi/activemq-cve-2023-46604",
                    "author": "tomasmussi",
                    "first_seen": "2023-12-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Repository to exploit CVE-2023-46604 reported for ActiveMQ",
                    "summary": "Repository to exploit CVE-2023-46604 reported for ActiveMQ",
                    "url": "https://github.com/tomasmussi/activemq-cve-2023-46604"
                },
                {
                    "repository": "PoC-in-GitHub · stegano5/ExploitScript-CVE-2023-46604",
                    "author": "stegano5",
                    "first_seen": "2024-02-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2023-46604 repository",
                    "summary": "",
                    "url": "https://github.com/stegano5/ExploitScript-CVE-2023-46604"
                },
                {
                    "repository": "PoC-in-GitHub · Arlenhiack/ActiveMQ-RCE-Exploit",
                    "author": "Arlenhiack",
                    "first_seen": "2024-03-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 45,
                    "title": "ActiveMQ RCE (CVE-2023-46604) 回显利用工具",
                    "summary": "ActiveMQ RCE (CVE-2023-46604) 回显利用工具",
                    "url": "https://github.com/Arlenhiack/ActiveMQ-RCE-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · vulncheck-oss/cve-2023-46604",
                    "author": "vulncheck-oss",
                    "first_seen": "2024-04-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "A go-exploit for Apache ActiveMQ CVE-2023-46604",
                    "summary": "A go-exploit for Apache ActiveMQ CVE-2023-46604",
                    "url": "https://github.com/vulncheck-oss/cve-2023-46604"
                },
                {
                    "repository": "PoC-in-GitHub · thinkycx/activemq-rce-cve-2023-46604",
                    "author": "thinkycx",
                    "first_seen": "2024-04-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "activemq-rce-cve-2023-46604",
                    "summary": "activemq-rce-cve-2023-46604",
                    "url": "https://github.com/thinkycx/activemq-rce-cve-2023-46604"
                },
                {
                    "repository": "PoC-in-GitHub · mranv/honeypot.rs",
                    "author": "mranv",
                    "first_seen": "2024-05-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-46604 (Apache ActiveMQ RCE Vulnerability) and focused on getting Indicators of Compromise.",
                    "summary": "CVE-2023-46604 (Apache ActiveMQ RCE Vulnerability) and focused on getting Indicators of Compromise.",
                    "url": "https://github.com/mranv/honeypot.rs"
                },
                {
                    "repository": "PoC-in-GitHub · pulentoski/CVE-2023-46604",
                    "author": "pulentoski",
                    "first_seen": "2024-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "El script explota una vulnerabilidad de deserialización insegura en Apache ActiveMQ (CVE-2023-46604)",
                    "summary": "El script explota una vulnerabilidad de deserialización insegura en Apache ActiveMQ (CVE-2023-46604)",
                    "url": "https://github.com/pulentoski/CVE-2023-46604"
                },
                {
                    "repository": "PoC-in-GitHub · cuanh2333/CVE-2023-46604",
                    "author": "cuanh2333",
                    "first_seen": "2024-10-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-46604 repository",
                    "summary": "",
                    "url": "https://github.com/cuanh2333/CVE-2023-46604"
                },
                {
                    "repository": "PoC-in-GitHub · skrkcb2/CVE-2023-46604",
                    "author": "skrkcb2",
                    "first_seen": "2025-02-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2023-46604 repository",
                    "summary": "",
                    "url": "https://github.com/skrkcb2/CVE-2023-46604"
                },
                {
                    "repository": "PoC-in-GitHub · CCIEVoice2009/CVE-2023-46604",
                    "author": "CCIEVoice2009",
                    "first_seen": "2025-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-46604 repository",
                    "summary": "",
                    "url": "https://github.com/CCIEVoice2009/CVE-2023-46604"
                },
                {
                    "repository": "PoC-in-GitHub · vaishnavucv/Project-Vuln-Detection-N-Mitigation_101",
                    "author": "vaishnavucv",
                    "first_seen": "2025-09-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Vulnerability Detection and Mitigation Apache ActiveMQ | Security Architectures and Systems Administration - on - Apache ActiveMQ Deserialization Remote Code Execution (RCE) – CVE-2023-46604",
                    "summary": "Vulnerability Detection and Mitigation Apache ActiveMQ | Security Architectures and Systems Administration - on - Apache ActiveMQ Deserialization Remote Code Execution (RCE) – CVE-2023-46604",
                    "url": "https://github.com/vaishnavucv/Project-Vuln-Detection-N-Mitigation_101"
                },
                {
                    "repository": "PoC-in-GitHub · pavanaa4k/CVE-2023-46604-LAB",
                    "author": "pavanaa4k",
                    "first_seen": "2025-11-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Detection, Exploit and Mitigation for CVE 2023 46604.",
                    "summary": "Detection, Exploit and Mitigation for CVE 2023 46604.",
                    "url": "https://github.com/pavanaa4k/CVE-2023-46604-LAB"
                },
                {
                    "repository": "PoC-in-GitHub · RockyDesigne/SSP-Assignment-3-RCEYouLater",
                    "author": "RockyDesigne",
                    "first_seen": "2026-01-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A PoC for CVE-2023-46604 written as part of SPS class for the Advanced Cyber Security master's at UPB.",
                    "summary": "A PoC for CVE-2023-46604 written as part of SPS class for the Advanced Cyber Security master's at UPB.",
                    "url": "https://github.com/RockyDesigne/SSP-Assignment-3-RCEYouLater"
                },
                {
                    "repository": "PoC-in-GitHub · sangrok-jeon/CVE-2023-46604-Analysis",
                    "author": "sangrok-jeon",
                    "first_seen": "2026-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Apache ActiveMQ OpenWire 역직렬화 RCE 취약점 기술 분석",
                    "summary": "Apache ActiveMQ OpenWire 역직렬화 RCE 취약점 기술 분석",
                    "url": "https://github.com/sangrok-jeon/CVE-2023-46604-Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · mkdemir/activemq-lockbit-analysis",
                    "author": "mkdemir",
                    "first_seen": "2026-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Apache ActiveMQ (CVE-2023-46604) zafiyetinden LockBit ransomware aşamasına uzanan 419 saatlik sızma vakasının uçtan uca analizi, SIEM korelasyon kuralları ve IOC listesi.",
                    "summary": "Apache ActiveMQ (CVE-2023-46604) zafiyetinden LockBit ransomware aşamasına uzanan 419 saatlik sızma vakasının uçtan uca analizi, SIEM korelasyon kuralları ve IOC listesi.",
                    "url": "https://github.com/mkdemir/activemq-lockbit-analysis"
                },
                {
                    "repository": "PoC-in-GitHub · Catherines77/ActiveMQ-EXPtools",
                    "author": "Catherines77",
                    "first_seen": "2026-04-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 83,
                    "title": "Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254，CVE-2016-3088，CVE-2022-41678，CVE-2023-46604，CVE-2024-32114，CVE-2026-34197，CVE-2026-40466， CVE-2026-42588)",
                    "summary": "Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254，CVE-2016-3088，CVE-2022-41678，CVE-2023-46604，CVE-2024-32114，CVE-2026-34197，CVE-2026-40466， CVE-2026-42588)",
                    "url": "https://github.com/Catherines77/ActiveMQ-EXPtools"
                },
                {
                    "repository": "PoC-in-GitHub · Navya240/intel471-threat-hunting-cve-2023-46604",
                    "author": "Navya240",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "My first hands-on Intel 471 threat hunting workshop experience investigating CVE-2023-46604 using Elastic SIEM, vulnerability intelligence, and post-exploitation detection.",
                    "summary": "My first hands-on Intel 471 threat hunting workshop experience investigating CVE-2023-46604 using Elastic SIEM, vulnerability intelligence, and post-exploitation detection.",
                    "url": "https://github.com/Navya240/intel471-threat-hunting-cve-2023-46604"
                },
                {
                    "repository": "PoC-in-GitHub · KlaasStessens/CVE-2023-46604",
                    "author": "KlaasStessens",
                    "first_seen": "2026-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploitation of CVE-2023-44604. Using a Kali Linux VM (attacker) and a Debian 11 server VM (victim)",
                    "summary": "Exploitation of CVE-2023-44604. Using a Kali Linux VM (attacker) and a Debian 11 server VM (victim)",
                    "url": "https://github.com/KlaasStessens/CVE-2023-46604"
                },
                {
                    "repository": "PoC-in-GitHub · trnguyen03/activemq-ids-ips-lab",
                    "author": "trnguyen03",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "IDS/IPS lab for detecting and preventing Apache ActiveMQ RCE (CVE-2023-46604) using GVM, Nmap, Snort, iptables, and UFW.",
                    "summary": "IDS/IPS lab for detecting and preventing Apache ActiveMQ RCE (CVE-2023-46604) using GVM, Nmap, Snort, iptables, and UFW.",
                    "url": "https://github.com/trnguyen03/activemq-ids-ips-lab"
                },
                {
                    "repository": "PoC-in-GitHub · REGGYRAIDER/CVE-2023-46604-RCE",
                    "author": "REGGYRAIDER",
                    "first_seen": "2026-06-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-46604-RCE exploit with Linux reverse shell payload",
                    "summary": "CVE-2023-46604-RCE exploit with Linux reverse shell payload",
                    "url": "https://github.com/REGGYRAIDER/CVE-2023-46604-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · aelshimony-cloud/OpenWire-CVE-2023-46604-Investigation",
                    "author": "aelshimony-cloud",
                    "first_seen": "2026-06-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-46604 repository",
                    "summary": "",
                    "url": "https://github.com/aelshimony-cloud/OpenWire-CVE-2023-46604-Investigation"
                },
                {
                    "repository": "PoC-in-GitHub · stefanotractor/activemq-cve-2023-46604-lab",
                    "author": "stefanotractor",
                    "first_seen": "2026-08-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-46604 repository",
                    "summary": "",
                    "url": "https://github.com/stefanotractor/activemq-cve-2023-46604-lab"
                },
                {
                    "repository": "PoC-in-GitHub · Bhanunamikaze/ActiveMQ-CVE-2023-46604",
                    "author": "Bhanunamikaze",
                    "first_seen": "2026-09-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit POC for Apache ActiveMQ CVE-2023-46604",
                    "summary": "Exploit POC for Apache ActiveMQ CVE-2023-46604",
                    "url": "https://github.com/Bhanunamikaze/ActiveMQ-CVE-2023-46604"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/trganda/ActiveMQ-RCE",
                "https://github.com/SaumyajeetDas/CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ",
                "https://github.com/evkl1d/CVE-2023-46604",
                "https://github.com/justdoit-cai/CVE-2023-46604-Apache-ActiveMQ-RCE-exp",
                "https://github.com/h3x3h0g/ActiveMQ-RCE-CVE-2023-46604-Write-up",
                "https://github.com/duck-sec/CVE-2023-46604-ActiveMQ-RCE-pseudoshell",
                "https://github.com/vjayant93/CVE-2023-46604-POC",
                "https://github.com/LiritoShawshark/CVE-2023-46604_ActiveMQ_RCE_Recurrence",
                "https://github.com/NKeshawarz/CVE-2023-46604-RCE",
                "https://github.com/minhangxiaohui/ActiveMQ_CVE-2023-46604",
                "https://github.com/CrackerCat/ActiveMQ_RCE_Pro_Max",
                "https://github.com/nitzanoligo/CVE-2023-46604-demo",
                "https://github.com/dcm2406/CVE-Lab",
                "https://github.com/mrpentst/CVE-2023-46604",
                "https://github.com/dcm2406/CVE-2023-46604",
                "https://github.com/Mudoleto/Broker_ApacheMQ",
                "https://github.com/tomasmussi/activemq-cve-2023-46604",
                "https://github.com/stegano5/ExploitScript-CVE-2023-46604",
                "https://github.com/Arlenhiack/ActiveMQ-RCE-Exploit",
                "https://github.com/vulncheck-oss/cve-2023-46604",
                "https://github.com/thinkycx/activemq-rce-cve-2023-46604",
                "https://github.com/mranv/honeypot.rs",
                "https://github.com/pulentoski/CVE-2023-46604",
                "https://github.com/cuanh2333/CVE-2023-46604",
                "https://github.com/skrkcb2/CVE-2023-46604",
                "https://github.com/CCIEVoice2009/CVE-2023-46604",
                "https://github.com/vaishnavucv/Project-Vuln-Detection-N-Mitigation_101",
                "https://github.com/pavanaa4k/CVE-2023-46604-LAB",
                "https://github.com/RockyDesigne/SSP-Assignment-3-RCEYouLater",
                "https://github.com/sangrok-jeon/CVE-2023-46604-Analysis",
                "https://github.com/mkdemir/activemq-lockbit-analysis",
                "https://github.com/Catherines77/ActiveMQ-EXPtools",
                "https://github.com/Navya240/intel471-threat-hunting-cve-2023-46604",
                "https://github.com/KlaasStessens/CVE-2023-46604",
                "https://github.com/trnguyen03/activemq-ids-ips-lab",
                "https://github.com/REGGYRAIDER/CVE-2023-46604-RCE",
                "https://github.com/aelshimony-cloud/OpenWire-CVE-2023-46604-Investigation",
                "https://github.com/stefanotractor/activemq-cve-2023-46604-lab",
                "https://github.com/Bhanunamikaze/ActiveMQ-CVE-2023-46604"
            ],
            "timeline": [
                {
                    "at": "2026-08-31T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2023-46273",
            "vendor": "extremenetworks",
            "product": "IQ Engine",
            "title": "IQ Engine vulnerability",
            "summary": "Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.",
            "updated_at": "2026-09-14T07:17:14.543",
            "published_at": "2026-09-14T06:16:54.647",
            "cvss": 8.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 10.6r1a (custom); 10.6r2 through before 10.6r5 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://extreme-networks.my.site.com/ExtrArticleDetail?an=000115356",
                "https://extremenetworks.com"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T06:16:54.647",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46273"
                }
            ]
        },
        {
            "id": "CVE-2023-46035",
            "vendor": "fnando",
            "product": "svg_optimizer",
            "title": "svg_optimizer vulnerability",
            "summary": "The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.",
            "updated_at": "2026-09-14T06:16:54.500",
            "published_at": "2026-09-14T06:16:54.500",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 0.3.0 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-776",
            "what_happened": "The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/fnando/svg_optimizer/pull/17",
                "https://github.com/rubysec/ruby-advisory-db/pull/713"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T06:16:54.500",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46035"
                }
            ]
        },
        {
            "id": "CVE-2023-45858",
            "vendor": "Paessler",
            "product": "PRTG Network Monitor",
            "title": "PRTG Network Monitor vulnerability",
            "summary": "A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.",
            "updated_at": "2026-09-14T06:16:54.357",
            "published_at": "2026-09-14T06:16:54.357",
            "cvss": 8.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 23.4.88.1429 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-23",
            "what_happened": "A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://helpdesk.paessler.com/en/support/solutions/articles/76000076525-what-is-the-vulnerability-fixed-in-prtg-23-4-88-1429-about-",
                "https://www.paessler.com/prtg/history/stable"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T06:16:54.357",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45858"
                }
            ]
        },
        {
            "id": "CVE-2023-45023",
            "vendor": "TYPO3",
            "product": "femanager",
            "title": "femanager vulnerability",
            "summary": "The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.",
            "updated_at": "2026-09-14T06:16:54.207",
            "published_at": "2026-09-14T06:16:54.207",
            "cvss": 4.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "7.0.0 through before 7.2.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-863",
            "what_happened": "The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://typo3.org/security/advisory/typo3-ext-sa-2023-008"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T06:16:54.207",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45023"
                }
            ]
        },
        {
            "id": "CVE-2023-43344",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2023-43344-Quick-CMS-Stored-XSS---SEO-Meta-description exploit",
            "summary": "Exploit for CVE-2023-43344. CVSS 5.4.",
            "updated_at": "2026-09-13T18:38:30Z",
            "published_at": "2026-09-13T18:38:30Z",
            "cvss": 5.4,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 27,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Stored XSS in Quick CMS v6.7 via SEO Meta description field allows code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-43344-Quick-CMS-Stored-XSS---SEO-Meta-description",
                    "summary": "Stored XSS in Quick CMS v6.7 via SEO Meta description field allows code execution.",
                    "what_happened": "Stored XSS in Quick CMS v6.7 via SEO Meta description field allows code execution.",
                    "cvss": 5.4,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SROMANHU-CVE-2023-43344-QUICK-CMS-STORED-XSS---SEO-META-DESCRIPTION",
                        "https://kitploit.com/ru/tools/github/sromanhu/cve-2023-43344-quick-cms-stored-xss---seo-meta-description/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T17:53:09",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SROMANHU-CVE-2023-43344-QUICK-CMS-STORED-XSS---SEO-META-DESCRIPTION"
                },
                {
                    "title": "Exploit for CVE-2023-43344-Quick-CMS-Stored-XSS---SEO-Meta-description",
                    "summary": "Stored XSS in Quick CMS v6.7 via SEO Meta description field allows code execution.",
                    "what_happened": "Stored XSS in Quick CMS v6.7 via SEO Meta description field allows code execution.",
                    "cvss": 5.4,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SROMANHU-CVE-2023-43344-QUICK-CMS-STORED-XSS---SEO-META-DESCRIPTION",
                        "https://kitploit.com/ru/tools/github/sromanhu/cve-2023-43344-quick-cms-stored-xss---seo-meta-description/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T17:53:09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/sromanhu/cve-2023-43344-quick-cms-stored-xss---seo-meta-description/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SROMANHU-CVE-2023-43344-QUICK-CMS-STORED-XSS---SEO-META-DESCRIPTION",
                "https://kitploit.com/ru/tools/github/sromanhu/cve-2023-43344-quick-cms-stored-xss---seo-meta-description/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:38:30Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SROMANHU-CVE-2023-43344-QUICK-CMS-STORED-XSS---SEO-META-DESCRIPTION"
                }
            ]
        },
        {
            "id": "CVE-2023-42793",
            "vendor": "JetBrains",
            "product": "TeamCity",
            "title": "JetBrains TeamCity Authentication Bypass Vulnerability",
            "summary": "JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.",
            "updated_at": "2026-09-04T22:00:00Z",
            "published_at": "2026-09-04T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1099,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 51884",
                    "author": "ByteHunter",
                    "first_seen": "2024-03-14",
                    "confidence": "High",
                    "title": "JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE)",
                    "summary": "JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/51884",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · H454NSec/CVE-2023-42793",
                    "author": "H454NSec",
                    "first_seen": "2023-09-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 45,
                    "title": "JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit",
                    "summary": "JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit",
                    "url": "https://github.com/H454NSec/CVE-2023-42793"
                },
                {
                    "repository": "PoC-in-GitHub · whoamins/CVE-2023-42793",
                    "author": "whoamins",
                    "first_seen": "2023-10-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-42793 repository",
                    "summary": "",
                    "url": "https://github.com/whoamins/CVE-2023-42793"
                },
                {
                    "repository": "PoC-in-GitHub · Zenmovie/CVE-2023-42793",
                    "author": "Zenmovie",
                    "first_seen": "2023-10-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "PoC of CVE-2023-42793",
                    "summary": "PoC of CVE-2023-42793",
                    "url": "https://github.com/Zenmovie/CVE-2023-42793"
                },
                {
                    "repository": "PoC-in-GitHub · johnossawy/CVE-2023-42793_POC",
                    "author": "johnossawy",
                    "first_seen": "2024-01-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-42793 repository",
                    "summary": "",
                    "url": "https://github.com/johnossawy/CVE-2023-42793_POC"
                },
                {
                    "repository": "PoC-in-GitHub · StanleyJobsonAU/GhostTown",
                    "author": "StanleyJobsonAU",
                    "first_seen": "2024-01-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Proof of Concept script to exploit CVE-2023-42793 (TeamCity)",
                    "summary": "Proof of Concept script to exploit CVE-2023-42793 (TeamCity)",
                    "url": "https://github.com/StanleyJobsonAU/GhostTown"
                },
                {
                    "repository": "PoC-in-GitHub · hotplugin0x01/CVE-2023-42793",
                    "author": "hotplugin0x01",
                    "first_seen": "2024-04-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "JetBrains TeamCity Unauthenticated Remote Code Execution - Python3 POC",
                    "summary": "JetBrains TeamCity Unauthenticated Remote Code Execution - Python3 POC",
                    "url": "https://github.com/hotplugin0x01/CVE-2023-42793"
                },
                {
                    "repository": "PoC-in-GitHub · B4l3rI0n/CVE-2023-42793",
                    "author": "B4l3rI0n",
                    "first_seen": "2024-04-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE), CVE-2023-42793",
                    "summary": "JetBrains TeamCity 2023.05.3 - Remote Code Execution (RCE), CVE-2023-42793",
                    "url": "https://github.com/B4l3rI0n/CVE-2023-42793"
                },
                {
                    "repository": "PoC-in-GitHub · junnythemarksman/CVE-2023-42793",
                    "author": "junnythemarksman",
                    "first_seen": "2024-05-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "TeamCity CVE-2023-42793 exploit written in Rust",
                    "summary": "TeamCity CVE-2023-42793 exploit written in Rust",
                    "url": "https://github.com/junnythemarksman/CVE-2023-42793"
                },
                {
                    "repository": "PoC-in-GitHub · HusenjanDev/CVE-2023-42793",
                    "author": "HusenjanDev",
                    "first_seen": "2024-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "TeamCity RCE for Linux (CVE-2023-42793)",
                    "summary": "TeamCity RCE for Linux (CVE-2023-42793)",
                    "url": "https://github.com/HusenjanDev/CVE-2023-42793"
                },
                {
                    "repository": "PoC-in-GitHub · FlojBoj/CVE-2023-42793",
                    "author": "FlojBoj",
                    "first_seen": "2024-08-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "TeamCity CVE-2023-42793 RCE (Remote Code Execution)",
                    "summary": "TeamCity CVE-2023-42793 RCE (Remote Code Execution)",
                    "url": "https://github.com/FlojBoj/CVE-2023-42793"
                },
                {
                    "repository": "PoC-in-GitHub · SwiftSecur/teamcity-exploit-cve-2023-42793",
                    "author": "SwiftSecur",
                    "first_seen": "2024-09-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "teamcity-exploit-cve-2023-42793",
                    "summary": "teamcity-exploit-cve-2023-42793",
                    "url": "https://github.com/SwiftSecur/teamcity-exploit-cve-2023-42793"
                },
                {
                    "repository": "PoC-in-GitHub · becrevex/CVE-2023-42793",
                    "author": "becrevex",
                    "first_seen": "2024-10-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "TeamCity server scanner to detect CVE-2023-42793",
                    "summary": "TeamCity server scanner to detect CVE-2023-42793",
                    "url": "https://github.com/becrevex/CVE-2023-42793"
                },
                {
                    "repository": "PoC-in-GitHub · jakehomb/cve-2023-42793",
                    "author": "jakehomb",
                    "first_seen": "2025-04-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-42793 repository",
                    "summary": "",
                    "url": "https://github.com/jakehomb/cve-2023-42793"
                },
                {
                    "repository": "PoC-in-GitHub · syaifulandy/Nuclei-Template-CVE-2023-42793.yaml",
                    "author": "syaifulandy",
                    "first_seen": "2025-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Windows & linux support",
                    "summary": "Windows & linux support",
                    "url": "https://github.com/syaifulandy/Nuclei-Template-CVE-2023-42793.yaml"
                },
                {
                    "repository": "PoC-in-GitHub · cxdxnt/CVE-2023-42793",
                    "author": "cxdxnt",
                    "first_seen": "2025-11-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "TeamCity 2023.05.3 - CVE-2023-42793 - Create username administrator.",
                    "summary": "TeamCity 2023.05.3 - CVE-2023-42793 - Create username administrator.",
                    "url": "https://github.com/cxdxnt/CVE-2023-42793"
                },
                {
                    "repository": "PoC-in-GitHub · DDestinys/CVE-2023-42793",
                    "author": "DDestinys",
                    "first_seen": "2026-01-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-42793 repository",
                    "summary": "",
                    "url": "https://github.com/DDestinys/CVE-2023-42793"
                },
                {
                    "repository": "PoC-in-GitHub · burakacar6/CVE-2023-42793-TeamCity-Unauthenticated-RCE",
                    "author": "burakacar6",
                    "first_seen": "2026-09-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A PoC and automated version detection/exploit tool for JetBrains TeamCity Authentication Bypass & RCE (CVE-2023-42793).",
                    "summary": "A PoC and automated version detection/exploit tool for JetBrains TeamCity Authentication Bypass & RCE (CVE-2023-42793).",
                    "url": "https://github.com/burakacar6/CVE-2023-42793-TeamCity-Unauthenticated-RCE"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/51884",
                "https://github.com/H454NSec/CVE-2023-42793",
                "https://github.com/whoamins/CVE-2023-42793",
                "https://github.com/Zenmovie/CVE-2023-42793",
                "https://github.com/johnossawy/CVE-2023-42793_POC",
                "https://github.com/StanleyJobsonAU/GhostTown",
                "https://github.com/hotplugin0x01/CVE-2023-42793",
                "https://github.com/B4l3rI0n/CVE-2023-42793",
                "https://github.com/junnythemarksman/CVE-2023-42793",
                "https://github.com/HusenjanDev/CVE-2023-42793",
                "https://github.com/FlojBoj/CVE-2023-42793",
                "https://github.com/SwiftSecur/teamcity-exploit-cve-2023-42793",
                "https://github.com/becrevex/CVE-2023-42793",
                "https://github.com/jakehomb/cve-2023-42793",
                "https://github.com/syaifulandy/Nuclei-Template-CVE-2023-42793.yaml",
                "https://github.com/cxdxnt/CVE-2023-42793",
                "https://github.com/DDestinys/CVE-2023-42793",
                "https://github.com/burakacar6/CVE-2023-42793-TeamCity-Unauthenticated-RCE"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2023-42326",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2023-42326 exploit",
            "summary": "Exploit for CVE-2023-42326. CVSS 8.8.",
            "updated_at": "2026-09-08T01:12:21Z",
            "published_at": "2026-09-08T01:12:21Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 34,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-14T04:51:21+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2023-42326 exploit",
                    "summary": "Exploit for CVE-2023-42326. CVSS 8.8.",
                    "cvss": 8.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BL4CKARCH-CVE-2023-42326"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BL4CKARCH-CVE-2023-42326"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:12:21Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BL4CKARCH-CVE-2023-42326"
                }
            ]
        },
        {
            "id": "CVE-2023-40772",
            "vendor": "DataEase",
            "product": "DataEase",
            "title": "DataEase vulnerability",
            "summary": "A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.",
            "updated_at": "2026-09-14T06:16:54.053",
            "published_at": "2026-09-14T06:16:54.053",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.18.10 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-23",
            "what_happened": "A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/dataease/dataease/issues/5864"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T06:16:54.053",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40772"
                }
            ]
        },
        {
            "id": "CVE-2023-40355",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2023-40355 exploit",
            "summary": "Exploit for CVE-2023-40355. CVSS 5.4.",
            "updated_at": "2026-09-15T08:30:59Z",
            "published_at": "2026-09-15T08:30:59Z",
            "cvss": 5.4,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-15T08:30:59+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2023-40355 exploit",
                    "summary": "Exploit for CVE-2023-40355. CVSS 5.4.",
                    "cvss": 5.4,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ACE-83-CVE-2023-40355"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ACE-83-CVE-2023-40355"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:30:59Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ACE-83-CVE-2023-40355"
                }
            ]
        },
        {
            "id": "CVE-2023-40028",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Ghost CMS 5.59.1 - Arbitrary File Read",
            "summary": "Ghost CMS 5.59.1 - Arbitrary File Read",
            "updated_at": "2026-09-07T19:21:40Z",
            "published_at": "2026-09-07T19:21:40Z",
            "cvss": 6.5,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 132,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Authenticated arbitrary file read in Ghost CMS prior to 5.59.1 via symlink file upload.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52409",
                    "author": "İbrahimsql",
                    "first_seen": "2025-08-11",
                    "confidence": "High",
                    "title": "Ghost CMS 5.59.1 - Arbitrary File Read",
                    "summary": "Ghost CMS 5.59.1 - Arbitrary File Read",
                    "url": "https://www.exploit-db.com/exploits/52409",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2023-40028",
                    "summary": "Authenticated arbitrary file read in Ghost CMS prior to 5.59.1 via symlink file upload.",
                    "what_happened": "Authenticated arbitrary file read in Ghost CMS prior to 5.59.1 via symlink file upload.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BUUTT3RF1Y-CVE-2023-40028",
                        "https://kitploit.com/ru/tools/github/buutt3rf1y/cve-2023-40028/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T15:20:31",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BUUTT3RF1Y-CVE-2023-40028"
                },
                {
                    "title": "Exploit for CVE-2023-40028",
                    "summary": "Authenticated arbitrary file read in Ghost CMS prior to 5.59.1 via symlink file upload.",
                    "what_happened": "Authenticated arbitrary file read in Ghost CMS prior to 5.59.1 via symlink file upload.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BUUTT3RF1Y-CVE-2023-40028",
                        "https://kitploit.com/ru/tools/github/buutt3rf1y/cve-2023-40028/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T15:20:31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/buutt3rf1y/cve-2023-40028/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52409",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BUUTT3RF1Y-CVE-2023-40028",
                "https://kitploit.com/ru/tools/github/buutt3rf1y/cve-2023-40028/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:21:40Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52409"
                }
            ]
        },
        {
            "id": "CVE-2023-39725",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2023-39725",
            "summary": "CVE-2023-39725 in tools component; repository has no README.",
            "updated_at": "2026-09-06T02:25:17Z",
            "published_at": "2026-09-06T02:25:17Z",
            "cvss": 5.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "CVE-2023-39725 in tools component; repository has no README.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-39725",
                    "summary": "CVE-2023-39725 in tools component; repository has no README.",
                    "what_happened": "CVE-2023-39725 in tools component; repository has no README.",
                    "cvss": 5.8,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANKY-123-CVE-2023-39725",
                        "https://kitploit.com/hi/tools/github/anky-123/cve-2023-39725/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T04:25:17",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANKY-123-CVE-2023-39725"
                },
                {
                    "title": "Exploit for CVE-2023-39725",
                    "summary": "CVE-2023-39725 in tools component; repository has no README.",
                    "what_happened": "CVE-2023-39725 in tools component; repository has no README.",
                    "cvss": 5.8,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANKY-123-CVE-2023-39725",
                        "https://kitploit.com/hi/tools/github/anky-123/cve-2023-39725/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T04:25:17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/anky-123/cve-2023-39725/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANKY-123-CVE-2023-39725",
                "https://kitploit.com/hi/tools/github/anky-123/cve-2023-39725/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T02:25:17Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANKY-123-CVE-2023-39725"
                }
            ],
            "cvss_vector": "NONE"
        },
        {
            "id": "CVE-2023-38831",
            "vendor": "RARLAB",
            "product": "WinRAR",
            "title": "RARLAB WinRAR Code Execution Vulnerability",
            "summary": "RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.",
            "updated_at": "2026-09-04T05:37:23Z",
            "published_at": "2026-09-04T05:37:23Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2052,
            "kev": true,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file within a ZIP archive.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-38831",
                    "summary": "PoC exploit for CVE-2023-38831 that achieves shell access.",
                    "what_happened": "PoC exploit for CVE-2023-38831 that achieves shell access.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUYCR4FT-CVE-2023-38831",
                        "https://kitploit.com/ru/tools/github/ruycr4ft/cve-2023-38831/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T07:37:23",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUYCR4FT-CVE-2023-38831"
                },
                {
                    "title": "Exploit for Windows-X64-RAT CVE-2023-38831",
                    "summary": "WinRAR < 6.23 CVE-2023-38831 exploited to deliver encrypted x64 RAT via reverse shell.",
                    "what_happened": "WinRAR < 6.23 CVE-2023-38831 exploited to deliver encrypted x64 RAT via reverse shell.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MAORBUSKILA-WINDOWS-X64-RAT",
                        "https://kitploit.com/ru/tools/github/maorbuskila/windows-x64-rat/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T07:25:30",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MAORBUSKILA-WINDOWS-X64-RAT"
                },
                {
                    "title": "Exploit for CVE-2023-38831",
                    "summary": "PoC exploit for CVE-2023-38831 that achieves shell access.",
                    "what_happened": "PoC exploit for CVE-2023-38831 that achieves shell access.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUYCR4FT-CVE-2023-38831",
                        "https://kitploit.com/ru/tools/github/ruycr4ft/cve-2023-38831/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T07:37:23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/ruycr4ft/cve-2023-38831/"
                },
                {
                    "title": "Exploit for Windows-X64-RAT CVE-2023-38831",
                    "summary": "WinRAR < 6.23 CVE-2023-38831 exploited to deliver encrypted x64 RAT via reverse shell.",
                    "what_happened": "WinRAR < 6.23 CVE-2023-38831 exploited to deliver encrypted x64 RAT via reverse shell.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MAORBUSKILA-WINDOWS-X64-RAT",
                        "https://kitploit.com/ru/tools/github/maorbuskila/windows-x64-rat/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T07:25:30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/maorbuskila/windows-x64-rat/"
                },
                {
                    "repository": "PoC-in-GitHub · BoredHackerBlog/winrar_CVE-2023-38831_lazy_poc",
                    "author": "BoredHackerBlog",
                    "first_seen": "2023-08-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 91,
                    "title": "lazy way to create CVE-2023-38831 winrar file for testing",
                    "summary": "lazy way to create CVE-2023-38831 winrar file for testing",
                    "url": "https://github.com/BoredHackerBlog/winrar_CVE-2023-38831_lazy_poc"
                },
                {
                    "repository": "PoC-in-GitHub · b1tg/CVE-2023-38831-winrar-exploit",
                    "author": "b1tg",
                    "first_seen": "2023-08-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 784,
                    "title": "CVE-2023-38831 winrar exploit generator",
                    "summary": "CVE-2023-38831 winrar exploit generator",
                    "url": "https://github.com/b1tg/CVE-2023-38831-winrar-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · IR-HuntGuardians/CVE-2023-38831-HUNT",
                    "author": "IR-HuntGuardians",
                    "first_seen": "2023-08-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2023-38831 repository",
                    "summary": "",
                    "url": "https://github.com/IR-HuntGuardians/CVE-2023-38831-HUNT"
                },
                {
                    "repository": "PoC-in-GitHub · Garck3h/cve-2023-38831",
                    "author": "Garck3h",
                    "first_seen": "2023-08-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 127,
                    "title": "一款用于生成winrar程序RCE（即cve-2023-38831）的POC的工具。",
                    "summary": "一款用于生成winrar程序RCE（即cve-2023-38831）的POC的工具。",
                    "url": "https://github.com/Garck3h/cve-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · ignis-sec/CVE-2023-38831-RaRCE",
                    "author": "ignis-sec",
                    "first_seen": "2023-08-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 113,
                    "title": "An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23",
                    "summary": "An easy to install and easy to run tool for generating exploit payloads for CVE-2023-38831, WinRAR RCE before versions 6.23",
                    "url": "https://github.com/ignis-sec/CVE-2023-38831-RaRCE"
                },
                {
                    "repository": "PoC-in-GitHub · HDCE-inc/CVE-2023-38831",
                    "author": "HDCE-inc",
                    "first_seen": "2023-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 92,
                    "title": "CVE-2023-38831 PoC (Proof Of Concept)",
                    "summary": "CVE-2023-38831 PoC (Proof Of Concept)",
                    "url": "https://github.com/HDCE-inc/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · Maalfer/CVE-2023-38831_ReverseShell_Winrar-RCE",
                    "author": "Maalfer",
                    "first_seen": "2023-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 22,
                    "title": "Pasos necesarios para obtener una reverse shell explotando la vulnerabilidad de winrar CVE-2023-38831 en versiones anteriores a 6.23.",
                    "summary": "Pasos necesarios para obtener una reverse shell explotando la vulnerabilidad de winrar CVE-2023-38831 en versiones anteriores a 6.23.",
                    "url": "https://github.com/Maalfer/CVE-2023-38831_ReverseShell_Winrar-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · knight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831",
                    "author": "knight0x07",
                    "first_seen": "2023-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 40,
                    "title": "Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)",
                    "summary": "Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)",
                    "url": "https://github.com/knight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · akhomlyuk/cve-2023-38831",
                    "author": "akhomlyuk",
                    "first_seen": "2023-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2023-38831 WinRAR",
                    "summary": "CVE-2023-38831 WinRAR",
                    "url": "https://github.com/akhomlyuk/cve-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · PascalAsch/CVE-2023-38831-KQL",
                    "author": "PascalAsch",
                    "first_seen": "2023-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "KQL Hunting for WinRAR CVE-2023-38831",
                    "summary": "KQL Hunting for WinRAR CVE-2023-38831",
                    "url": "https://github.com/PascalAsch/CVE-2023-38831-KQL"
                },
                {
                    "repository": "PoC-in-GitHub · ahmed-fa7im/CVE-2023-38831-winrar-expoit-simple-Poc",
                    "author": "ahmed-fa7im",
                    "first_seen": "2023-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "CVE-2023-38831 winrar exploit generator and get reverse shell",
                    "summary": "CVE-2023-38831 winrar exploit generator and get reverse shell",
                    "url": "https://github.com/ahmed-fa7im/CVE-2023-38831-winrar-expoit-simple-Poc"
                },
                {
                    "repository": "PoC-in-GitHub · thegr1ffyn/CVE-2023-38831",
                    "author": "thegr1ffyn",
                    "first_seen": "2023-08-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Proof of Concept (POC) for CVE-2023-38831 WinRAR",
                    "summary": "Proof of Concept (POC) for CVE-2023-38831 WinRAR",
                    "url": "https://github.com/thegr1ffyn/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · ML-K-eng/CVE-2023-38831-Exploit-and-Detection",
                    "author": "ML-K-eng",
                    "first_seen": "2023-08-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository has both an attack detection tool and a Proof-of-Concept (PoC) Python script for the WinRAR CVE-2023-38831 vulnerability.",
                    "summary": "This repository has both an attack detection tool and a Proof-of-Concept (PoC) Python script for the WinRAR CVE-2023-38831 vulnerability.",
                    "url": "https://github.com/ML-K-eng/CVE-2023-38831-Exploit-and-Detection"
                },
                {
                    "repository": "PoC-in-GitHub · sudo-py-dev/CVE-2023-38831",
                    "author": "sudo-py-dev",
                    "first_seen": "2023-08-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "winrar exploit 6.22 <=",
                    "summary": "winrar exploit 6.22 <=",
                    "url": "https://github.com/sudo-py-dev/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · z3r0sw0rd/CVE-2023-38831-PoC",
                    "author": "z3r0sw0rd",
                    "first_seen": "2023-08-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Proof-of-Concept for CVE-2023-38831 Zero-Day vulnerability in WinRAR",
                    "summary": "Proof-of-Concept for CVE-2023-38831 Zero-Day vulnerability in WinRAR",
                    "url": "https://github.com/z3r0sw0rd/CVE-2023-38831-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · sh770/CVE-2023-38831",
                    "author": "sh770",
                    "first_seen": "2023-08-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "winrar exploit 6.22 <=",
                    "summary": "winrar exploit 6.22 <=",
                    "url": "https://github.com/sh770/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · Ben1B3astt/CVE-2023-38831_ReverseShell_Winrar",
                    "author": "Ben1B3astt",
                    "first_seen": "2023-08-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2023-38831 repository",
                    "summary": "",
                    "url": "https://github.com/Ben1B3astt/CVE-2023-38831_ReverseShell_Winrar"
                },
                {
                    "repository": "PoC-in-GitHub · MorDavid/CVE-2023-38831-Winrar-Exploit-Generator-POC",
                    "author": "MorDavid",
                    "first_seen": "2023-08-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "This is a POC for the CVE-2023-3883 exploit targeting WinRAR up to 6.22. Modified some existing internet-sourced POCs by introducing greater dynamism and incorporated additional try-except blocks within the code.",
                    "summary": "This is a POC for the CVE-2023-3883 exploit targeting WinRAR up to 6.22. Modified some existing internet-sourced POCs by introducing greater dynamism and incorporated additional try-except blocks within the code.",
                    "url": "https://github.com/MorDavid/CVE-2023-38831-Winrar-Exploit-Generator-POC"
                },
                {
                    "repository": "PoC-in-GitHub · Mich-ele/CVE-2023-38831-winrar",
                    "author": "Mich-ele",
                    "first_seen": "2023-09-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2023-38831 winrar exploit builder",
                    "summary": "CVE-2023-38831 winrar exploit builder",
                    "url": "https://github.com/Mich-ele/CVE-2023-38831-winrar"
                },
                {
                    "repository": "PoC-in-GitHub · asepsaepdin/CVE-2023-38831",
                    "author": "asepsaepdin",
                    "first_seen": "2023-09-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-38831 repository",
                    "summary": "",
                    "url": "https://github.com/asepsaepdin/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · Fa1c0n35/CVE-2023-38831-winrar-exploit",
                    "author": "Fa1c0n35",
                    "first_seen": "2023-09-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-38831 repository",
                    "summary": "",
                    "url": "https://github.com/Fa1c0n35/CVE-2023-38831-winrar-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · xaitax/WinRAR-CVE-2023-38831",
                    "author": "xaitax",
                    "first_seen": "2023-09-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is executed, leading to code execution.",
                    "summary": "This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is executed, leading to code execution.",
                    "url": "https://github.com/xaitax/WinRAR-CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · GOTonyGO/CVE-2023-38831-winrar",
                    "author": "GOTonyGO",
                    "first_seen": "2023-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Quick exploit builder for CVE-2023-38831, a vulnerability that affects WinRAR versions before 6.23.",
                    "summary": "Quick exploit builder for CVE-2023-38831, a vulnerability that affects WinRAR versions before 6.23.",
                    "url": "https://github.com/GOTonyGO/CVE-2023-38831-winrar"
                },
                {
                    "repository": "PoC-in-GitHub · Malwareman007/CVE-2023-38831",
                    "author": "Malwareman007",
                    "first_seen": "2023-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2023-38831 WinRaR Exploit Generator",
                    "summary": "CVE-2023-38831 WinRaR Exploit Generator",
                    "url": "https://github.com/Malwareman007/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · ameerpornillos/CVE-2023-38831-WinRAR-Exploit",
                    "author": "ameerpornillos",
                    "first_seen": "2023-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Proof of concept (PoC) exploit for WinRAR vulnerability (CVE-2023-38831) vulnerability",
                    "summary": "Proof of concept (PoC) exploit for WinRAR vulnerability (CVE-2023-38831) vulnerability",
                    "url": "https://github.com/ameerpornillos/CVE-2023-38831-WinRAR-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · ngothienan/CVE-2023-38831",
                    "author": "ngothienan",
                    "first_seen": "2023-09-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-38831 repository",
                    "summary": "",
                    "url": "https://github.com/ngothienan/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · malvika-thakur/CVE-2023-38831",
                    "author": "malvika-thakur",
                    "first_seen": "2023-09-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Proof-of-Concept (POC) of CVE-2023-38831 Zero-Day vulnerability in WinRAR",
                    "summary": "Proof-of-Concept (POC) of CVE-2023-38831 Zero-Day vulnerability in WinRAR",
                    "url": "https://github.com/malvika-thakur/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · ruycr4ft/CVE-2023-38831",
                    "author": "ruycr4ft",
                    "first_seen": "2023-10-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2023-38831 repository",
                    "summary": "",
                    "url": "https://github.com/ruycr4ft/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · Nielk74/CVE-2023-38831",
                    "author": "Nielk74",
                    "first_seen": "2023-10-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-38831 repository",
                    "summary": "",
                    "url": "https://github.com/Nielk74/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · kehrijksen/CVE-2023-38831",
                    "author": "kehrijksen",
                    "first_seen": "2023-10-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-38831 is an RCE in WinRAR (<6.23)",
                    "summary": "CVE-2023-38831 is an RCE in WinRAR (<6.23)",
                    "url": "https://github.com/kehrijksen/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · h3xecute/SideCopy-Exploits-CVE-2023-38831",
                    "author": "h3xecute",
                    "first_seen": "2023-11-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "SideCopy APT Group exploits CVE-2023-38831",
                    "summary": "SideCopy APT Group exploits CVE-2023-38831",
                    "url": "https://github.com/h3xecute/SideCopy-Exploits-CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · s4m98/winrar-cve-2023-38831-poc-gen",
                    "author": "s4m98",
                    "first_seen": "2023-11-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "WinRAR cve-2023-38831-poc-generator",
                    "summary": "WinRAR cve-2023-38831-poc-generator",
                    "url": "https://github.com/s4m98/winrar-cve-2023-38831-poc-gen"
                },
                {
                    "repository": "PoC-in-GitHub · xk-mt/WinRAR-Vulnerability-recurrence-tutorial",
                    "author": "xk-mt",
                    "first_seen": "2023-11-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "WinRAR-6.22、CVE-2023-38831、CNNVD-202308-1943、DM-202307-003730、QVD-2023-19572漏洞复现",
                    "summary": "WinRAR-6.22、CVE-2023-38831、CNNVD-202308-1943、DM-202307-003730、QVD-2023-19572漏洞复现",
                    "url": "https://github.com/xk-mt/WinRAR-Vulnerability-recurrence-tutorial"
                },
                {
                    "repository": "PoC-in-GitHub · MyStuffYT/CVE-2023-38831-POC",
                    "author": "MyStuffYT",
                    "first_seen": "2023-12-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Proof-of-concept of CVE-2023-38831",
                    "summary": "Proof-of-concept of CVE-2023-38831",
                    "url": "https://github.com/MyStuffYT/CVE-2023-38831-POC"
                },
                {
                    "repository": "PoC-in-GitHub · SpamixOfficial/CVE-2023-38831",
                    "author": "SpamixOfficial",
                    "first_seen": "2023-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2023-38831 Proof-of-concept code",
                    "summary": "CVE-2023-38831 Proof-of-concept code",
                    "url": "https://github.com/SpamixOfficial/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · r1yaz/winDED",
                    "author": "r1yaz",
                    "first_seen": "2023-12-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Exploit Development using python for CVE-2023-38831 (POC)",
                    "summary": "Exploit Development using python for CVE-2023-38831 (POC)",
                    "url": "https://github.com/r1yaz/winDED"
                },
                {
                    "repository": "PoC-in-GitHub · youmulijiang/evil-winrar",
                    "author": "youmulijiang",
                    "first_seen": "2024-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "evil-winrar,CVE-2023-38831漏洞利用和社会工程学攻击框架 (evil-winrar, CVE-2023-38831 Vulnerability Exploitation and Social Engineering Attack Framework)",
                    "summary": "evil-winrar,CVE-2023-38831漏洞利用和社会工程学攻击框架 (evil-winrar, CVE-2023-38831 Vulnerability Exploitation and Social Engineering Attack Framework)",
                    "url": "https://github.com/youmulijiang/evil-winrar"
                },
                {
                    "repository": "PoC-in-GitHub · solomon12354/VolleyballSquid-----CVE-2023-38831-and-Bypass-UAC",
                    "author": "solomon12354",
                    "first_seen": "2024-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is my malware",
                    "summary": "This is my malware",
                    "url": "https://github.com/solomon12354/VolleyballSquid-----CVE-2023-38831-and-Bypass-UAC"
                },
                {
                    "repository": "PoC-in-GitHub · RomainBayle08/CVE-2023-38831",
                    "author": "RomainBayle08",
                    "first_seen": "2024-04-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-38831 repository",
                    "summary": "",
                    "url": "https://github.com/RomainBayle08/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · imbyter/imbyter-WinRAR_CVE-2023-38831",
                    "author": "imbyter",
                    "first_seen": "2024-06-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "WinRAR漏洞测试复现。详参：https://flowus.cn/share/a3b35db0-ab5e-4abc-b8d3-5ff284e82e7b",
                    "summary": "WinRAR漏洞测试复现。详参：https://flowus.cn/share/a3b35db0-ab5e-4abc-b8d3-5ff284e82e7b",
                    "url": "https://github.com/imbyter/imbyter-WinRAR_CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · UnHackerEnCapital/PDFernetRemotelo",
                    "author": "UnHackerEnCapital",
                    "first_seen": "2024-06-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script",
                    "summary": "PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script",
                    "url": "https://github.com/UnHackerEnCapital/PDFernetRemotelo"
                },
                {
                    "repository": "PoC-in-GitHub · Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784",
                    "author": "Hirusha-N",
                    "first_seen": "2024-06-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-38831 repository",
                    "summary": "",
                    "url": "https://github.com/Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784"
                },
                {
                    "repository": "PoC-in-GitHub · khanhtranngoccva/cve-2023-38831-poc",
                    "author": "khanhtranngoccva",
                    "first_seen": "2024-07-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-38831 repository",
                    "summary": "",
                    "url": "https://github.com/khanhtranngoccva/cve-2023-38831-poc"
                },
                {
                    "repository": "PoC-in-GitHub · MaorBuskila/Windows-X64-RAT",
                    "author": "MaorBuskila",
                    "first_seen": "2024-07-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Remote Access Trojan (RAT) for Windows x64 using a combination of vulnerability CVE-2023-38831 (WinRAR < 6.23 vulnerability) and Shellcode exploitation technique.",
                    "summary": "Remote Access Trojan (RAT) for Windows x64 using a combination of vulnerability CVE-2023-38831 (WinRAR < 6.23 vulnerability) and Shellcode exploitation technique.",
                    "url": "https://github.com/MaorBuskila/Windows-X64-RAT"
                },
                {
                    "repository": "PoC-in-GitHub · yezzfusl/cve_2023_38831_scanner",
                    "author": "yezzfusl",
                    "first_seen": "2024-08-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.",
                    "summary": "This Python application scans for the CVE-2023-38831 vulnerability in WinRAR.",
                    "url": "https://github.com/yezzfusl/cve_2023_38831_scanner"
                },
                {
                    "repository": "PoC-in-GitHub · FirFirdaus/CVE-2023-38831",
                    "author": "FirFirdaus",
                    "first_seen": "2024-08-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A POC demo on CVE-2023-38831",
                    "summary": "A POC demo on CVE-2023-38831",
                    "url": "https://github.com/FirFirdaus/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · ra3edAJ/LAB-DFIR-cve-2023-38831",
                    "author": "ra3edAJ",
                    "first_seen": "2024-09-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "d",
                    "summary": "d",
                    "url": "https://github.com/ra3edAJ/LAB-DFIR-cve-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · technicalcorp0/CVE-2023-38831-Exploit",
                    "author": "technicalcorp0",
                    "first_seen": "2024-09-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This project contains a Python script that exploits **CVE-2023-38831**, a vulnerability in **WinRAR** versions prior to 6.23. The exploit generates a **malicious RAR archive** that triggers the execution of arbitrary code when the victim opens a benign-looking file within the archive (such as a PDF).",
                    "summary": "This project contains a Python script that exploits **CVE-2023-38831**, a vulnerability in **WinRAR** versions prior to 6.23. The exploit generates a **malicious RAR archive** that triggers the execution of arbitrary code when the victim opens a benign-looking file within the archive (such as a PDF).",
                    "url": "https://github.com/technicalcorp0/CVE-2023-38831-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · idkwastaken/CVE-2023-38831",
                    "author": "idkwastaken",
                    "first_seen": "2024-10-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-38831 repository",
                    "summary": "",
                    "url": "https://github.com/idkwastaken/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · VictoriousKnight/CVE-2023-38831_Exploit",
                    "author": "VictoriousKnight",
                    "first_seen": "2024-12-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-38831 repository",
                    "summary": "",
                    "url": "https://github.com/VictoriousKnight/CVE-2023-38831_Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · kuyrathdaro/cve-2023-38831",
                    "author": "kuyrathdaro",
                    "first_seen": "2024-12-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2023-38831 (PoC) - WinRAR Exploit",
                    "summary": "CVE-2023-38831 (PoC) - WinRAR Exploit",
                    "url": "https://github.com/kuyrathdaro/cve-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · Tolu12wani/Demonstration-of-CVE-2023-38831-via-Reverse-Shell-Execution",
                    "author": "Tolu12wani",
                    "first_seen": "2025-08-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This project demonstrates a simulated exploitation of the WinRAR vulnerability CVE-2023-38831 to execute a reverse shell. The purpose of this task was to showcase how attackers can weaponize compressed archive files to gain remote access to a target machine.",
                    "summary": "This project demonstrates a simulated exploitation of the WinRAR vulnerability CVE-2023-38831 to execute a reverse shell. The purpose of this task was to showcase how attackers can weaponize compressed archive files to gain remote access to a target machine.",
                    "url": "https://github.com/Tolu12wani/Demonstration-of-CVE-2023-38831-via-Reverse-Shell-Execution"
                },
                {
                    "repository": "PoC-in-GitHub · anelya0333/Exploiting-CVE-2023-38831",
                    "author": "anelya0333",
                    "first_seen": "2025-11-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-38831 repository",
                    "summary": "",
                    "url": "https://github.com/anelya0333/Exploiting-CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · mishra0230/CVE-2023-38831",
                    "author": "mishra0230",
                    "first_seen": "2026-01-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-38831 - WinRAR",
                    "summary": "CVE-2023-38831 - WinRAR",
                    "url": "https://github.com/mishra0230/CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · RonF98/CVE-2023-38831-POC",
                    "author": "RonF98",
                    "first_seen": "2026-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2023-38831 is a Zero-day WinRAR vulnerability that lets attackers disguise malicious files in archives, tricking users into executing harmful content.",
                    "summary": "CVE-2023-38831 is a Zero-day WinRAR vulnerability that lets attackers disguise malicious files in archives, tricking users into executing harmful content.",
                    "url": "https://github.com/RonF98/CVE-2023-38831-POC"
                },
                {
                    "repository": "PoC-in-GitHub · lightningspeed221/Winrar-Exploit-CVE-2023-38831",
                    "author": "lightningspeed221",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Winrar Exploit CVE-2023-38831",
                    "summary": "Winrar Exploit CVE-2023-38831",
                    "url": "https://github.com/lightningspeed221/Winrar-Exploit-CVE-2023-38831"
                },
                {
                    "repository": "PoC-in-GitHub · olowostandard1/CVE-2023-38831-WinRAR-Vulnerability-Analysis",
                    "author": "olowostandard1",
                    "first_seen": "2026-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This project is a cybersecurity research and analysis project focused on CVE-2023-38831, a critical WinRAR vulnerability that allows attackers to execute malicious code through specially crafted archive files.  The project was conducted in a controlled lab environment for educational and defensive security purposes only.",
                    "summary": "This project is a cybersecurity research and analysis project focused on CVE-2023-38831, a critical WinRAR vulnerability that allows attackers to execute malicious code through specially crafted archive files.  The project was conducted in a controlled lab environment for educational and defensive security purposes only.",
                    "url": "https://github.com/olowostandard1/CVE-2023-38831-WinRAR-Vulnerability-Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · cristhiansm0/TXDXCristhian_2023-CVE-38831",
                    "author": "cristhiansm0",
                    "first_seen": "2026-08-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-38831 WinRAR lab: detection with Sysmon/Wazuh, reverse engineering with Ghidra, patch analysis, and remediation.",
                    "summary": "CVE-2023-38831 WinRAR lab: detection with Sysmon/Wazuh, reverse engineering with Ghidra, patch analysis, and remediation.",
                    "url": "https://github.com/cristhiansm0/TXDXCristhian_2023-CVE-38831"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RUYCR4FT-CVE-2023-38831",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MAORBUSKILA-WINDOWS-X64-RAT",
                "https://kitploit.com/ru/tools/github/ruycr4ft/cve-2023-38831/",
                "https://kitploit.com/ru/tools/github/maorbuskila/windows-x64-rat/",
                "https://github.com/BoredHackerBlog/winrar_CVE-2023-38831_lazy_poc",
                "https://github.com/b1tg/CVE-2023-38831-winrar-exploit",
                "https://github.com/IR-HuntGuardians/CVE-2023-38831-HUNT",
                "https://github.com/Garck3h/cve-2023-38831",
                "https://github.com/ignis-sec/CVE-2023-38831-RaRCE",
                "https://github.com/HDCE-inc/CVE-2023-38831",
                "https://github.com/Maalfer/CVE-2023-38831_ReverseShell_Winrar-RCE",
                "https://github.com/knight0x07/WinRAR-Code-Execution-Vulnerability-CVE-2023-38831",
                "https://github.com/akhomlyuk/cve-2023-38831",
                "https://github.com/PascalAsch/CVE-2023-38831-KQL",
                "https://github.com/ahmed-fa7im/CVE-2023-38831-winrar-expoit-simple-Poc",
                "https://github.com/thegr1ffyn/CVE-2023-38831",
                "https://github.com/ML-K-eng/CVE-2023-38831-Exploit-and-Detection",
                "https://github.com/sudo-py-dev/CVE-2023-38831",
                "https://github.com/z3r0sw0rd/CVE-2023-38831-PoC",
                "https://github.com/sh770/CVE-2023-38831",
                "https://github.com/Ben1B3astt/CVE-2023-38831_ReverseShell_Winrar",
                "https://github.com/MorDavid/CVE-2023-38831-Winrar-Exploit-Generator-POC",
                "https://github.com/Mich-ele/CVE-2023-38831-winrar",
                "https://github.com/asepsaepdin/CVE-2023-38831",
                "https://github.com/Fa1c0n35/CVE-2023-38831-winrar-exploit",
                "https://github.com/xaitax/WinRAR-CVE-2023-38831",
                "https://github.com/GOTonyGO/CVE-2023-38831-winrar",
                "https://github.com/Malwareman007/CVE-2023-38831",
                "https://github.com/ameerpornillos/CVE-2023-38831-WinRAR-Exploit",
                "https://github.com/ngothienan/CVE-2023-38831",
                "https://github.com/malvika-thakur/CVE-2023-38831",
                "https://github.com/ruycr4ft/CVE-2023-38831",
                "https://github.com/Nielk74/CVE-2023-38831",
                "https://github.com/kehrijksen/CVE-2023-38831",
                "https://github.com/h3xecute/SideCopy-Exploits-CVE-2023-38831",
                "https://github.com/s4m98/winrar-cve-2023-38831-poc-gen",
                "https://github.com/xk-mt/WinRAR-Vulnerability-recurrence-tutorial",
                "https://github.com/MyStuffYT/CVE-2023-38831-POC",
                "https://github.com/SpamixOfficial/CVE-2023-38831",
                "https://github.com/r1yaz/winDED",
                "https://github.com/youmulijiang/evil-winrar",
                "https://github.com/solomon12354/VolleyballSquid-----CVE-2023-38831-and-Bypass-UAC",
                "https://github.com/RomainBayle08/CVE-2023-38831",
                "https://github.com/imbyter/imbyter-WinRAR_CVE-2023-38831",
                "https://github.com/UnHackerEnCapital/PDFernetRemotelo",
                "https://github.com/Hirusha-N/CVE-2021-34527-CVE-2023-38831-and-CVE-2023-32784",
                "https://github.com/khanhtranngoccva/cve-2023-38831-poc",
                "https://github.com/MaorBuskila/Windows-X64-RAT",
                "https://github.com/yezzfusl/cve_2023_38831_scanner",
                "https://github.com/FirFirdaus/CVE-2023-38831",
                "https://github.com/ra3edAJ/LAB-DFIR-cve-2023-38831",
                "https://github.com/technicalcorp0/CVE-2023-38831-Exploit",
                "https://github.com/idkwastaken/CVE-2023-38831",
                "https://github.com/VictoriousKnight/CVE-2023-38831_Exploit",
                "https://github.com/kuyrathdaro/cve-2023-38831",
                "https://github.com/Tolu12wani/Demonstration-of-CVE-2023-38831-via-Reverse-Shell-Execution",
                "https://github.com/anelya0333/Exploiting-CVE-2023-38831",
                "https://github.com/mishra0230/CVE-2023-38831",
                "https://github.com/RonF98/CVE-2023-38831-POC",
                "https://github.com/lightningspeed221/Winrar-Exploit-CVE-2023-38831",
                "https://github.com/olowostandard1/CVE-2023-38831-WinRAR-Vulnerability-Analysis",
                "https://github.com/cristhiansm0/TXDXCristhian_2023-CVE-38831"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T05:37:23Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-08-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2023-38817",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": ":pager: a tiny code that performs kernel-mode read/write using CVE-2023-38817.",
            "summary": ":pager: a tiny code that performs kernel-mode read/write using CVE-2023-38817.",
            "updated_at": "2026-09-11T22:00:00Z",
            "published_at": "2026-09-11T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 57,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · vxcall/kur",
                    "author": "vxcall",
                    "first_seen": "2023-11-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": ":pager: a tiny code that performs kernel-mode read/write using CVE-2023-38817.",
                    "summary": ":pager: a tiny code that performs kernel-mode read/write using CVE-2023-38817.",
                    "url": "https://github.com/vxcall/kur"
                },
                {
                    "repository": "PoC-in-GitHub · SecSecBurger/CVE-2023-38817",
                    "author": "SecSecBurger",
                    "first_seen": "2026-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit Code for CVE-2023-38817",
                    "summary": "Exploit Code for CVE-2023-38817",
                    "url": "https://github.com/SecSecBurger/CVE-2023-38817"
                },
                {
                    "repository": "PoC-in-GitHub · T-thanha/echoac-poc",
                    "author": "T-thanha",
                    "first_seen": "2026-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-38817 echo.ac echo_driver.sys PoC (token stealing -> SYSTEM, silent RDP user creation)",
                    "summary": "CVE-2023-38817 echo.ac echo_driver.sys PoC (token stealing -> SYSTEM, silent RDP user creation)",
                    "url": "https://github.com/T-thanha/echoac-poc"
                }
            ],
            "references": [
                "https://github.com/vxcall/kur",
                "https://github.com/SecSecBurger/CVE-2023-38817",
                "https://github.com/T-thanha/echoac-poc"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/vxcall/kur"
                }
            ]
        },
        {
            "id": "CVE-2023-37771",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2023-37771 exploit",
            "summary": "Exploit for CVE-2023-37771. CVSS 9.8.",
            "updated_at": "2026-09-13T06:35:00Z",
            "published_at": "2026-09-13T06:35:00Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 31,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Vulnerability in tools repository with no README or further details.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-37771",
                    "summary": "Vulnerability in tools repository with no README or further details.",
                    "what_happened": "Vulnerability in tools repository with no README or further details.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANKY-123-CVE-2023-37771",
                        "https://kitploit.com/ar/tools/github/anky-123/cve-2023-37771/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T02:18:54",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANKY-123-CVE-2023-37771"
                },
                {
                    "title": "Exploit for CVE-2023-37771",
                    "summary": "Vulnerability in tools repository with no README or further details.",
                    "what_happened": "Vulnerability in tools repository with no README or further details.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANKY-123-CVE-2023-37771",
                        "https://kitploit.com/ar/tools/github/anky-123/cve-2023-37771/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-06T02:18:54",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/anky-123/cve-2023-37771/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANKY-123-CVE-2023-37771",
                "https://kitploit.com/ar/tools/github/anky-123/cve-2023-37771/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T06:35:00Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANKY-123-CVE-2023-37771"
                }
            ]
        },
        {
            "id": "CVE-2023-37366",
            "vendor": "Samsung",
            "product": "Exynos 850 firmware",
            "title": "Exynos 850 firmware vulnerability",
            "summary": "An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, an Exynos Auto T5123. In the Shannon SM Task, improper handling of a loop with an unreachable exit condition cannot guarantee the termination of a required service via a malformed SM message.",
            "updated_at": "2026-09-14T06:16:53.907",
            "published_at": "2026-09-14T06:16:53.907",
            "cvss": 2.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 2023-04-28 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-835",
            "what_happened": "An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300, an Exynos Auto T5123. In the Shannon SM Task, improper handling of a loop with an unreachable exit condition cannot guarantee the termination of a required service via a malformed SM message.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/",
                "https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2023-37366/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T06:16:53.907",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37366"
                }
            ]
        },
        {
            "id": "CVE-2023-37253",
            "vendor": "MediaWiki",
            "product": "ProofreadPage",
            "title": "ProofreadPage vulnerability",
            "summary": "An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.",
            "updated_at": "2026-09-14T06:16:53.740",
            "published_at": "2026-09-14T06:16:53.740",
            "cvss": 3.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.35.11 (semver); 1.36.0 through before 1.38.7 (semver); 1.39.0 through before 1.39.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-669",
            "what_happened": "An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://phabricator.wikimedia.org/T326952"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T06:16:53.740",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37253"
                }
            ]
        },
        {
            "id": "CVE-2023-37252",
            "vendor": "MediaWiki",
            "product": "CheckUser",
            "title": "CheckUser vulnerability",
            "summary": "An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.",
            "updated_at": "2026-09-14T06:16:52.380",
            "published_at": "2026-09-14T05:16:57.580",
            "cvss": 3.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.35.11 (semver); 1.36.0 through before 1.38.7 (semver); 1.39.0 through before 1.39.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-669",
            "what_happened": "An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://phabricator.wikimedia.org/T330968"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:57.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37252"
                }
            ]
        },
        {
            "id": "CVE-2023-36025",
            "vendor": "Microsoft",
            "product": "Windows",
            "title": "Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
            "summary": "Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.",
            "updated_at": "2026-09-07T19:19:53Z",
            "published_at": "2026-09-07T19:19:53Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 67,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-07T19:19:53+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "-EXPLOIT-CVE-2023-36025",
                    "summary": "Exploit for CVE-2023-36025. CVSS 8.8.",
                    "cvss": 8.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COOLMAN6942O--EXPLOIT-CVE-2023-36025"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COOLMAN6942O--EXPLOIT-CVE-2023-36025"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:19:53Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2023-35086",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2023-35086-POC",
            "summary": "Format string in ASUS RT-AX56U V2 and RT-AC86U detwan.cgi httpd service enabling RCE.",
            "updated_at": "2026-09-03T08:43:04Z",
            "published_at": "2026-09-03T08:43:04Z",
            "cvss": 7.2,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Format string in ASUS RT-AX56U V2 and RT-AC86U detwan.cgi httpd service enabling RCE.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-35086-POC",
                    "summary": "Format string in ASUS RT-AX56U V2 and RT-AC86U detwan.cgi httpd service enabling RCE.",
                    "what_happened": "Format string in ASUS RT-AX56U V2 and RT-AC86U detwan.cgi httpd service enabling RCE.",
                    "cvss": 7.2,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TIN-Z-CVE-2023-35086-POC",
                        "https://kitploit.com/ru/tools/github/tin-z/cve-2023-35086-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T10:43:04",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TIN-Z-CVE-2023-35086-POC"
                },
                {
                    "title": "Exploit for CVE-2023-35086-POC",
                    "summary": "Format string in ASUS RT-AX56U V2 and RT-AC86U detwan.cgi httpd service enabling RCE.",
                    "what_happened": "Format string in ASUS RT-AX56U V2 and RT-AC86U detwan.cgi httpd service enabling RCE.",
                    "cvss": 7.2,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TIN-Z-CVE-2023-35086-POC",
                        "https://kitploit.com/ru/tools/github/tin-z/cve-2023-35086-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-03T10:43:04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/tin-z/cve-2023-35086-poc/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TIN-Z-CVE-2023-35086-POC",
                "https://kitploit.com/ru/tools/github/tin-z/cve-2023-35086-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T08:43:04Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TIN-Z-CVE-2023-35086-POC"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2023-34854",
            "vendor": "digitaldruid",
            "product": "HotelDruid",
            "title": "HotelDruid vulnerability",
            "summary": "HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.",
            "updated_at": "2026-09-14T05:16:57.437",
            "published_at": "2026-09-14T05:16:57.437",
            "cvss": 6.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.0.6 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-434",
            "what_happened": "HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://security-tracker.debian.org/tracker/CVE-2023-34854"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:57.437",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-34854"
                }
            ]
        },
        {
            "id": "CVE-2023-34598",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2023-34598 exploit",
            "summary": "Exploit for CVE-2023-34598. CVSS 9.8.",
            "updated_at": "2026-09-14T18:32:38Z",
            "published_at": "2026-09-14T18:32:38Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Local file inclusion in Gibbon v25.0.0 allowing extraction of SQL database dumps.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-34598",
                    "summary": "Local file inclusion in Gibbon v25.0.0 allowing extraction of SQL database dumps.",
                    "what_happened": "Local file inclusion in Gibbon v25.0.0 allowing extraction of SQL database dumps.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZER0F8TH-CVE-2023-34598",
                        "https://kitploit.com/zh/tools/github/zer0f8th/cve-2023-34598/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-12T18:48:57",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZER0F8TH-CVE-2023-34598"
                },
                {
                    "title": "Exploit for CVE-2023-34598",
                    "summary": "Local file inclusion in Gibbon v25.0.0 allowing extraction of SQL database dumps.",
                    "what_happened": "Local file inclusion in Gibbon v25.0.0 allowing extraction of SQL database dumps.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZER0F8TH-CVE-2023-34598",
                        "https://kitploit.com/zh/tools/github/zer0f8th/cve-2023-34598/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-12T18:48:57",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/zer0f8th/cve-2023-34598/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZER0F8TH-CVE-2023-34598",
                "https://kitploit.com/zh/tools/github/zer0f8th/cve-2023-34598/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T18:32:38Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZER0F8TH-CVE-2023-34598"
                }
            ]
        },
        {
            "id": "CVE-2023-33107",
            "vendor": "Qualcomm",
            "product": "Multiple Chipsets",
            "title": "Qualcomm Multiple Chipsets Integer Overflow Vulnerability",
            "summary": "Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.",
            "updated_at": "2026-09-08T14:39:34Z",
            "published_at": "2026-09-08T14:39:34Z",
            "cvss": 8.4,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 115,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Multiple Qualcomm chipsets contain an integer overflow vulnerability due to memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-33107",
                    "summary": "CVE-2023-33107 vulnerability with available writeup and test video demonstrating the issue.",
                    "what_happened": "CVE-2023-33107 vulnerability with available writeup and test video demonstrating the issue.",
                    "cvss": 8.4,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KETO0422-CVE-2023-33107",
                        "https://kitploit.com/hi/tools/github/keto0422/cve-2023-33107/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-26T00:07:13",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KETO0422-CVE-2023-33107"
                },
                {
                    "title": "Exploit for CVE-2023-33107",
                    "summary": "CVE-2023-33107 vulnerability with available writeup and test video demonstrating the issue.",
                    "what_happened": "CVE-2023-33107 vulnerability with available writeup and test video demonstrating the issue.",
                    "cvss": 8.4,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KETO0422-CVE-2023-33107",
                        "https://kitploit.com/hi/tools/github/keto0422/cve-2023-33107/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-08-26T00:07:13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/keto0422/cve-2023-33107/"
                },
                {
                    "repository": "PoC-in-GitHub · keto0422/CVE-2023-33107",
                    "author": "keto0422",
                    "first_seen": "2026-02-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "full exploit code",
                    "summary": "full exploit code",
                    "url": "https://github.com/keto0422/CVE-2023-33107"
                },
                {
                    "repository": "PoC-in-GitHub · 264312431/picohaxx",
                    "author": "264312431",
                    "first_seen": "2026-07-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "A kernel exploit for Pico 4 devices based on cve-2023-33107",
                    "summary": "A kernel exploit for Pico 4 devices based on cve-2023-33107",
                    "url": "https://github.com/264312431/picohaxx"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KETO0422-CVE-2023-33107",
                "https://kitploit.com/hi/tools/github/keto0422/cve-2023-33107/",
                "https://github.com/keto0422/CVE-2023-33107",
                "https://github.com/264312431/picohaxx"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T14:39:34Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-12-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2023-32803",
            "vendor": "Amazon",
            "product": "ca-certificates",
            "title": "ca-certificates vulnerability",
            "summary": "The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.",
            "updated_at": "2026-09-14T05:16:57.290",
            "published_at": "2026-09-14T05:16:57.290",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 2021.2.50-72 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-669",
            "what_happened": "The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://alas.aws.amazon.com/AL2/ALAS-2023-1957.html",
                "https://explore.alas.aws.amazon.com/CVE-2023-32803.html"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:57.290",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32803"
                }
            ]
        },
        {
            "id": "CVE-2023-32778",
            "vendor": "ILIAS",
            "product": "ILIAS",
            "title": "ILIAS vulnerability",
            "summary": "An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.",
            "updated_at": "2026-09-14T05:16:57.137",
            "published_at": "2026-09-14T05:16:57.137",
            "cvss": 3.3,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.23 (custom); 7 through before 7.22 (custom); 8.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-23",
            "what_happened": "An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://docu.ilias.de/goto.php?target=wiki_5307&client_id=docu#secissues",
                "https://docu.ilias.de/goto_docu_pg_141704_35.html"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:57.137",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32778"
                }
            ]
        },
        {
            "id": "CVE-2023-32629",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for PHP-CVE-2023-2023-2640-POC-Escalation CVE-2023-2023 CVE-2023-2640 CVE-2023-32629",
            "summary": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
            "updated_at": "2026-09-06T18:11:35Z",
            "published_at": "2026-09-06T18:11:35Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 65,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for PHP-CVE-2023-2023-2640-POC-Escalation CVE-2023-2023 CVE-2023-2640 CVE-2023-32629",
                    "summary": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
                    "what_happened": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION",
                        "https://kitploit.com/hi/tools/github/druxter-x/php-cve-2023-2023-2640-poc-escalation/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T20:11:35",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION"
                },
                {
                    "title": "Exploit for PHP-CVE-2023-2023-2640-POC-Escalation CVE-2023-2023 CVE-2023-2640 CVE-2023-32629",
                    "summary": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
                    "what_happened": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION",
                        "https://kitploit.com/hi/tools/github/druxter-x/php-cve-2023-2023-2640-poc-escalation/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T20:11:35",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/druxter-x/php-cve-2023-2023-2640-poc-escalation/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION",
                "https://kitploit.com/hi/tools/github/druxter-x/php-cve-2023-2023-2640-poc-escalation/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T18:11:35Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2023-32407",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2023-32407-a-macOS-TCC-bypass-in-Metal",
            "summary": "macOS TCC bypass in Metal.",
            "updated_at": "2026-09-05T20:48:42Z",
            "published_at": "2026-09-05T20:48:42Z",
            "cvss": 5.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 31,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "macOS TCC bypass in Metal.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-32407-a-macOS-TCC-bypass-in-Metal",
                    "summary": "macOS TCC bypass in Metal.",
                    "what_happened": "macOS TCC bypass in Metal.",
                    "cvss": 5.5,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERGELYKALMAN-CVE-2023-32407-A-MACOS-TCC-BYPASS-IN-METAL",
                        "https://kitploit.com/hi/tools/github/gergelykalman/cve-2023-32407-a-macos-tcc-bypass-in-metal/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T22:48:42",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERGELYKALMAN-CVE-2023-32407-A-MACOS-TCC-BYPASS-IN-METAL"
                },
                {
                    "title": "Exploit for CVE-2023-32407-a-macOS-TCC-bypass-in-Metal",
                    "summary": "macOS TCC bypass in Metal.",
                    "what_happened": "macOS TCC bypass in Metal.",
                    "cvss": 5.5,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERGELYKALMAN-CVE-2023-32407-A-MACOS-TCC-BYPASS-IN-METAL",
                        "https://kitploit.com/hi/tools/github/gergelykalman/cve-2023-32407-a-macos-tcc-bypass-in-metal/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-05T22:48:42",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/gergelykalman/cve-2023-32407-a-macos-tcc-bypass-in-metal/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERGELYKALMAN-CVE-2023-32407-A-MACOS-TCC-BYPASS-IN-METAL",
                "https://kitploit.com/hi/tools/github/gergelykalman/cve-2023-32407-a-macos-tcc-bypass-in-metal/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T20:48:42Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GERGELYKALMAN-CVE-2023-32407-A-MACOS-TCC-BYPASS-IN-METAL"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"
        },
        {
            "id": "CVE-2023-30258",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "MagnusSolution magnusbilling 7.3.0 - Command Injection",
            "summary": "MagnusSolution magnusbilling 7.3.0 - Command Injection",
            "updated_at": "2026-09-15T08:32:02Z",
            "published_at": "2026-09-15T08:32:02Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 18,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52170",
                    "author": "CodeSecLab",
                    "first_seen": "2025-04-11",
                    "confidence": "High",
                    "title": "MagnusSolution magnusbilling 7.3.0 - Command Injection",
                    "summary": "MagnusSolution magnusbilling 7.3.0 - Command Injection",
                    "url": "https://www.exploit-db.com/exploits/52170",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-15T08:32:02+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "THM-MagnusBilling-CVE-2023-30258-Exploit",
                    "summary": "Exploit for CVE-2023-30258. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CYB3RK0ALA-THM-MAGNUSBILLING-CVE-2023-30258-EXPLOIT"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52170",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CYB3RK0ALA-THM-MAGNUSBILLING-CVE-2023-30258-EXPLOIT"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:32:02Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52170"
                }
            ]
        },
        {
            "id": "CVE-2023-30212",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2023-30212-OURPHP-Vulnerability exploit",
            "summary": "Exploit for CVE-2023-30212. CVSS 6.1.",
            "updated_at": "2026-09-13T18:36:13Z",
            "published_at": "2026-09-13T18:36:13Z",
            "cvss": 6.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:36:13+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2023-30212-OURPHP-Vulnerability exploit",
                    "summary": "Exploit for CVE-2023-30212. CVSS 6.1.",
                    "cvss": 6.1,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IMATHEWVINCENT-CVE-2023-30212-OURPHP-VULNERABILITY"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IMATHEWVINCENT-CVE-2023-30212-OURPHP-VULNERABILITY"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:36:13Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IMATHEWVINCENT-CVE-2023-30212-OURPHP-VULNERABILITY"
                }
            ]
        },
        {
            "id": "CVE-2023-29489",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2023-29489.py",
            "summary": "Python tool for CVE-2023-29489 in a tools directory; repository lacks a README.",
            "updated_at": "2026-09-04T09:55:15Z",
            "published_at": "2026-09-04T09:55:15Z",
            "cvss": 6.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 61,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Python tool for CVE-2023-29489 in a tools directory; repository lacks a README.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-29489.py",
                    "summary": "Python tool for CVE-2023-29489 in a tools directory; repository lacks a README.",
                    "what_happened": "Python tool for CVE-2023-29489 in a tools directory; repository lacks a README.",
                    "cvss": 6.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IPK1-CVE-2023-29489.PY",
                        "https://kitploit.com/ar/tools/github/ipk1/cve-2023-29489.py/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T11:55:15",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IPK1-CVE-2023-29489.PY"
                },
                {
                    "title": "Exploit for CVE-2023-29489.py",
                    "summary": "Python tool for CVE-2023-29489 in a tools directory; repository lacks a README.",
                    "what_happened": "Python tool for CVE-2023-29489 in a tools directory; repository lacks a README.",
                    "cvss": 6.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IPK1-CVE-2023-29489.PY",
                        "https://kitploit.com/ar/tools/github/ipk1/cve-2023-29489.py/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-04T11:55:15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/ipk1/cve-2023-29489.py/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IPK1-CVE-2023-29489.PY",
                "https://kitploit.com/ar/tools/github/ipk1/cve-2023-29489.py/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T09:55:15Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IPK1-CVE-2023-29489.PY"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
            "id": "CVE-2023-29377",
            "vendor": "Softing",
            "product": "Secure Integration Server",
            "title": "Secure Integration Server vulnerability",
            "summary": "An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA objects.",
            "updated_at": "2026-09-14T05:16:56.987",
            "published_at": "2026-09-14T05:16:56.987",
            "cvss": 6.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 1.22 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-23",
            "what_happened": "An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA objects.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://industrial.softing.com/fileadmin/psirt/downloads/syt-2023-02.html",
                "https://industrial.softing.com/fileadmin/psirt/downloads/syt-2023-02.json",
                "https://www.zerodayinitiative.com/advisories/ZDI-23-1055/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:56.987",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29377"
                }
            ]
        },
        {
            "id": "CVE-2023-29343",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2023-29343 CVE-2020-0668 CVE-2023-28222 CVE-2023-29343",
            "summary": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
            "updated_at": "2026-08-25T18:44:18Z",
            "published_at": "2026-08-25T18:44:18Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 67,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-29343 CVE-2020-0668 CVE-2023-28222 CVE-2023-29343",
                    "summary": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
                    "what_happened": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343",
                        "https://kitploit.com/ar/tools/github/wh04m1001/cve-2023-29343/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T20:44:18",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343"
                },
                {
                    "title": "Exploit for CVE-2023-29343 CVE-2020-0668 CVE-2023-28222 CVE-2023-29343",
                    "summary": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
                    "what_happened": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343",
                        "https://kitploit.com/ar/tools/github/wh04m1001/cve-2023-29343/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-08-25T20:44:18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/wh04m1001/cve-2023-29343/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343",
                "https://kitploit.com/ar/tools/github/wh04m1001/cve-2023-29343/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T18:44:18Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2023-28343",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Altenergy Power Control Software C1.2.5 - OS command injection",
            "summary": "Altenergy Power Control Software C1.2.5 - OS command injection",
            "updated_at": "2026-09-14T04:53:10Z",
            "published_at": "2026-09-14T04:53:10Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 42,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "OS command injection in Altenergy Power System Control Software C1.2.5 /set_timezone enables RCE.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 51325",
                    "author": "Ahmed Alroky",
                    "first_seen": "2023-04-08",
                    "confidence": "High",
                    "title": "Altenergy Power Control Software C1.2.5 - OS command injection",
                    "summary": "Altenergy Power Control Software C1.2.5 - OS command injection",
                    "url": "https://www.exploit-db.com/exploits/51325",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2023-28343",
                    "summary": "OS command injection in Altenergy Power System Control Software C1.2.5 /set_timezone enables RCE.",
                    "what_happened": "OS command injection in Altenergy Power System Control Software C1.2.5 /set_timezone enables RCE.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GOBYSEC-CVE-2023-28343",
                        "https://kitploit.com/ru/tools/github/gobysec/cve-2023-28343/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T03:15:13",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GOBYSEC-CVE-2023-28343"
                },
                {
                    "title": "Exploit for CVE-2023-28343",
                    "summary": "OS command injection in Altenergy Power System Control Software C1.2.5 /set_timezone enables RCE.",
                    "what_happened": "OS command injection in Altenergy Power System Control Software C1.2.5 /set_timezone enables RCE.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GOBYSEC-CVE-2023-28343",
                        "https://kitploit.com/ru/tools/github/gobysec/cve-2023-28343/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T03:15:13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/gobysec/cve-2023-28343/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/51325",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GOBYSEC-CVE-2023-28343",
                "https://kitploit.com/ru/tools/github/gobysec/cve-2023-28343/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:53:10Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/51325"
                }
            ]
        },
        {
            "id": "CVE-2023-28222",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2023-29343 CVE-2020-0668 CVE-2023-28222 CVE-2023-29343",
            "summary": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
            "updated_at": "2026-08-25T18:44:18Z",
            "published_at": "2026-08-25T18:44:18Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 67,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-29343 CVE-2020-0668 CVE-2023-28222 CVE-2023-29343",
                    "summary": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
                    "what_happened": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343",
                        "https://kitploit.com/ar/tools/github/wh04m1001/cve-2023-29343/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T20:44:18",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343"
                },
                {
                    "title": "Exploit for CVE-2023-29343 CVE-2020-0668 CVE-2023-28222 CVE-2023-29343",
                    "summary": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
                    "what_happened": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343",
                        "https://kitploit.com/ar/tools/github/wh04m1001/cve-2023-29343/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-08-25T20:44:18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/wh04m1001/cve-2023-29343/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343",
                "https://kitploit.com/ar/tools/github/wh04m1001/cve-2023-29343/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T18:44:18Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2023-28148",
            "vendor": "Paessler",
            "product": "PRTG Network Monitor",
            "title": "PRTG Network Monitor vulnerability",
            "summary": "A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.",
            "updated_at": "2026-09-14T05:16:56.837",
            "published_at": "2026-09-14T05:16:56.837",
            "cvss": 7.2,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 23.3.86.1520 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.paessler.com/prtg/history/prtg-23",
                "https://www.paessler.com/prtg/history/stable"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:56.837",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28148"
                }
            ]
        },
        {
            "id": "CVE-2023-27997",
            "vendor": "Fortinet",
            "product": "FortiOS and FortiProxy SSL-VPN",
            "title": "Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability",
            "summary": "Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.",
            "updated_at": "2026-08-31T22:00:00Z",
            "published_at": "2026-08-31T22:00:00Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 426,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · rio128128/CVE-2023-27997-POC",
                    "author": "rio128128",
                    "first_seen": "2023-06-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 27,
                    "title": "POC FortiOS SSL-VPN buffer overflow vulnerability",
                    "summary": "POC FortiOS SSL-VPN buffer overflow vulnerability",
                    "url": "https://github.com/rio128128/CVE-2023-27997-POC"
                },
                {
                    "repository": "PoC-in-GitHub · BishopFox/CVE-2023-27997-check",
                    "author": "BishopFox",
                    "first_seen": "2023-06-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 135,
                    "title": "Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing",
                    "summary": "Safely detect whether a FortiGate SSL VPN instance is vulnerable to CVE-2023-27997 based on response timing",
                    "url": "https://github.com/BishopFox/CVE-2023-27997-check"
                },
                {
                    "repository": "PoC-in-GitHub · imbas007/CVE-2023-27997-Check",
                    "author": "imbas007",
                    "first_seen": "2023-06-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2023-27997 repository",
                    "summary": "",
                    "url": "https://github.com/imbas007/CVE-2023-27997-Check"
                },
                {
                    "repository": "PoC-in-GitHub · puckiestyle/cve-2023-27997",
                    "author": "puckiestyle",
                    "first_seen": "2023-06-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-27997 repository",
                    "summary": "",
                    "url": "https://github.com/puckiestyle/cve-2023-27997"
                },
                {
                    "repository": "PoC-in-GitHub · TechinsightsPro/ShodanFortiOS",
                    "author": "TechinsightsPro",
                    "first_seen": "2023-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Search vulnerable FortiOS devices via Shodan (CVE-2023-27997)",
                    "summary": "Search vulnerable FortiOS devices via Shodan (CVE-2023-27997)",
                    "url": "https://github.com/TechinsightsPro/ShodanFortiOS"
                },
                {
                    "repository": "PoC-in-GitHub · Cyb3rEnthusiast/CVE-2023-27997",
                    "author": "Cyb3rEnthusiast",
                    "first_seen": "2023-09-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "How to get access via CVE-2022-27997",
                    "summary": "How to get access via CVE-2022-27997",
                    "url": "https://github.com/Cyb3rEnthusiast/CVE-2023-27997"
                },
                {
                    "repository": "PoC-in-GitHub · lexfo/xortigate-cve-2023-27997",
                    "author": "lexfo",
                    "first_seen": "2023-10-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 63,
                    "title": "xortigate-cve-2023-27997",
                    "summary": "xortigate-cve-2023-27997",
                    "url": "https://github.com/lexfo/xortigate-cve-2023-27997"
                },
                {
                    "repository": "PoC-in-GitHub · delsploit/CVE-2023-27997",
                    "author": "delsploit",
                    "first_seen": "2023-10-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2023-27997 repository",
                    "summary": "",
                    "url": "https://github.com/delsploit/CVE-2023-27997"
                },
                {
                    "repository": "PoC-in-GitHub · node011/CVE-2023-27997-POC",
                    "author": "node011",
                    "first_seen": "2024-11-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Fortigate SSL VPN buffer overflow exploit",
                    "summary": "Fortigate SSL VPN buffer overflow exploit",
                    "url": "https://github.com/node011/CVE-2023-27997-POC"
                },
                {
                    "repository": "PoC-in-GitHub · onurkerembozkurt/fgt-cve-2023-27997-exploit",
                    "author": "onurkerembozkurt",
                    "first_seen": "2025-04-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "FortiGate SSL-VPN CVE-2023-27997 Exploit PoC Script with ROP Chain",
                    "summary": "FortiGate SSL-VPN CVE-2023-27997 Exploit PoC Script with ROP Chain",
                    "url": "https://github.com/onurkerembozkurt/fgt-cve-2023-27997-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Vampsecure-Labs/vamp-forticheck",
                    "author": "Vampsecure-Labs",
                    "first_seen": "2026-07-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)",
                    "summary": "VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)",
                    "url": "https://github.com/Vampsecure-Labs/vamp-forticheck"
                },
                {
                    "repository": "PoC-in-GitHub · abraxas/Fortigate-SSL-VPN-Exploit-Kit",
                    "author": "abraxas",
                    "first_seen": "2026-09-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997.  79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.",
                    "summary": "The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997.  79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.",
                    "url": "https://github.com/abraxas/Fortigate-SSL-VPN-Exploit-Kit"
                },
                {
                    "title": "Exploit for xortigate-cve-2023-27997 CVE-2023-27997",
                    "summary": "POC exploit for xortigate (CVE-2023-27997) demonstrating a bug for educational purposes.",
                    "what_happened": "POC exploit for xortigate (CVE-2023-27997) demonstrating a bug for educational purposes.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LEXFO-XORTIGATE-CVE-2023-27997",
                        "https://kitploit.com/ru/tools/github/lexfo/xortigate-cve-2023-27997/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-26T01:06:40",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LEXFO-XORTIGATE-CVE-2023-27997"
                },
                {
                    "title": "Exploit for xortigate-cve-2023-27997 CVE-2023-27997",
                    "summary": "POC exploit for xortigate (CVE-2023-27997) demonstrating a bug for educational purposes.",
                    "what_happened": "POC exploit for xortigate (CVE-2023-27997) demonstrating a bug for educational purposes.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LEXFO-XORTIGATE-CVE-2023-27997",
                        "https://kitploit.com/ru/tools/github/lexfo/xortigate-cve-2023-27997/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-26T01:06:40",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/lexfo/xortigate-cve-2023-27997/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/rio128128/CVE-2023-27997-POC",
                "https://github.com/BishopFox/CVE-2023-27997-check",
                "https://github.com/imbas007/CVE-2023-27997-Check",
                "https://github.com/puckiestyle/cve-2023-27997",
                "https://github.com/TechinsightsPro/ShodanFortiOS",
                "https://github.com/Cyb3rEnthusiast/CVE-2023-27997",
                "https://github.com/lexfo/xortigate-cve-2023-27997",
                "https://github.com/delsploit/CVE-2023-27997",
                "https://github.com/node011/CVE-2023-27997-POC",
                "https://github.com/onurkerembozkurt/fgt-cve-2023-27997-exploit",
                "https://github.com/Vampsecure-Labs/vamp-forticheck",
                "https://github.com/abraxas/Fortigate-SSL-VPN-Exploit-Kit",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LEXFO-XORTIGATE-CVE-2023-27997",
                "https://kitploit.com/ru/tools/github/lexfo/xortigate-cve-2023-27997/"
            ],
            "timeline": [
                {
                    "at": "2026-08-31T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-06-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2023-27842",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2023-27842 exploit",
            "summary": "Exploit for CVE-2023-27842. CVSS 8.8.",
            "updated_at": "2026-09-08T01:13:39Z",
            "published_at": "2026-09-08T01:13:39Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 33,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-08T01:13:39+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2023-27842 exploit",
                    "summary": "Exploit for CVE-2023-27842. CVSS 8.8.",
                    "cvss": 8.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COWSECURITY-CVE-2023-27842"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COWSECURITY-CVE-2023-27842"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:13:39Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-COWSECURITY-CVE-2023-27842"
                }
            ]
        },
        {
            "id": "CVE-2023-27172",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.",
            "updated_at": "2026-09-16T20:17:20.303",
            "published_at": "2023-12-20T01:15:07.233",
            "cvss": 9.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-307",
            "what_happened": "Xpand IT Write-back Manager v2.3.1 uses weak secret keys to sign JWT tokens. This allows attackers to easily obtain the secret key used to sign JWT tokens via a bruteforce attack.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "balwurk.github.io",
                    "author": "NVD reference",
                    "first_seen": "2023-12-20",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://balwurk.github.io/CVE-2023-27172/"
                }
            ],
            "references": [
                "https://balwurk.github.io/CVE-2023-27172/",
                "https://ghostline.neocities.org/CVE-2023-27172/"
            ],
            "timeline": [
                {
                    "at": "2023-12-20T01:15:07.233",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27172"
                }
            ]
        },
        {
            "id": "CVE-2023-27170",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.",
            "updated_at": "2026-09-16T20:17:20.100",
            "published_at": "2023-10-26T23:15:09.253",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-22",
            "what_happened": "Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "balwurk.com",
                    "author": "NVD reference",
                    "first_seen": "2023-10-26",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://balwurk.com/cve-2023-27170-improper-limitation-of-a-pathname-to-a-restricted-directory/"
                }
            ],
            "references": [
                "https://balwurk.com/cve-2023-27170-improper-limitation-of-a-pathname-to-a-restricted-directory/",
                "https://ghostline.neocities.org/CVE-2023-27170/"
            ],
            "timeline": [
                {
                    "at": "2023-10-26T23:15:09.253",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27170"
                }
            ]
        },
        {
            "id": "CVE-2023-27169",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.",
            "updated_at": "2026-09-16T20:17:19.963",
            "published_at": "2023-09-12T12:15:07.580",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 9,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-798",
            "what_happened": "Xpand IT Write-back manager v2.3.1 uses a hardcoded salt in license class configuration which leads to the generation of a hardcoded and predictable symmetric encryption keys for license generation and validation.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://balwurk.com",
                "https://balwurk.com/cve-use-of-hard-coded-cryptographic-key/",
                "https://ghostline.neocities.org/CVE-2023-27169/",
                "https://writeback4t.com",
                "https://www.xpand-it.com"
            ],
            "timeline": [
                {
                    "at": "2023-09-12T12:15:07.580",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27169"
                }
            ]
        },
        {
            "id": "CVE-2023-27168",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.",
            "updated_at": "2026-09-16T20:17:19.743",
            "published_at": "2024-01-19T14:15:12.247",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 10,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-434",
            "what_happened": "An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "balwurk.github.io",
                    "author": "NVD reference",
                    "first_seen": "2024-01-19",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://balwurk.github.io/CVE-2023-27168/"
                }
            ],
            "references": [
                "https://balwurk.com",
                "https://balwurk.github.io/CVE-2023-27168/",
                "https://ghostline.neocities.org/CVE-2023-27168/",
                "https://writeback4t.com",
                "https://www.xpand-it.com"
            ],
            "timeline": [
                {
                    "at": "2024-01-19T14:15:12.247",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27168"
                }
            ]
        },
        {
            "id": "CVE-2023-26493",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Authorized lab reproduction of CVE-2023-26493 (GHSL-2023-027): command injection via github.head_ref in cocos-engine's <Web> Interface check pull_request_target workflow",
            "summary": "Authorized lab reproduction of CVE-2023-26493 (GHSL-2023-027): command injection via github.head_ref in cocos-engine's <Web> Interface check pull_request_target workflow",
            "updated_at": "2026-08-30T22:00:00Z",
            "published_at": "2026-08-30T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 36,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · pvharmo2/gha-lab-fb32aba4a3",
                    "author": "pvharmo2",
                    "first_seen": "2026-08-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Authorized lab reproduction of CVE-2023-26493 (GHSL-2023-027): command injection via github.head_ref in cocos-engine's <Web> Interface check pull_request_target workflow",
                    "summary": "Authorized lab reproduction of CVE-2023-26493 (GHSL-2023-027): command injection via github.head_ref in cocos-engine's <Web> Interface check pull_request_target workflow",
                    "url": "https://github.com/pvharmo2/gha-lab-fb32aba4a3"
                }
            ],
            "references": [
                "https://github.com/pvharmo2/gha-lab-fb32aba4a3"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/pvharmo2/gha-lab-fb32aba4a3"
                }
            ]
        },
        {
            "id": "CVE-2023-25690",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2023-25690_lab exploit",
            "summary": "Exploit for CVE-2023-25690. CVSS 9.8.",
            "updated_at": "2026-09-14T18:31:28Z",
            "published_at": "2026-09-14T18:31:28Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-444",
            "what_happened": "HTTP Request Smuggling vulnerability via Apache proxy (CVE-2023-25690).",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-25690_lab",
                    "summary": "HTTP Request Smuggling vulnerability via Apache proxy (CVE-2023-25690).",
                    "what_happened": "HTTP Request Smuggling vulnerability via Apache proxy (CVE-2023-25690).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-444",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GIORDY0424-CVE-2023-25690_LAB",
                        "https://kitploit.com/zh/tools/github/giordy0424/cve-2023-25690_lab/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-13T17:43:34",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GIORDY0424-CVE-2023-25690_LAB"
                },
                {
                    "title": "Exploit for CVE-2023-25690_lab",
                    "summary": "HTTP Request Smuggling vulnerability via Apache proxy (CVE-2023-25690).",
                    "what_happened": "HTTP Request Smuggling vulnerability via Apache proxy (CVE-2023-25690).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-444",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GIORDY0424-CVE-2023-25690_LAB",
                        "https://kitploit.com/zh/tools/github/giordy0424/cve-2023-25690_lab/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-13T17:43:34",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/giordy0424/cve-2023-25690_lab/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GIORDY0424-CVE-2023-25690_LAB",
                "https://kitploit.com/zh/tools/github/giordy0424/cve-2023-25690_lab/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T18:31:28Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GIORDY0424-CVE-2023-25690_LAB"
                }
            ]
        },
        {
            "id": "CVE-2023-25500",
            "vendor": "vaadin",
            "product": "vaadin",
            "title": "vaadin vulnerability",
            "summary": "Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in RPC responses by sending modified requests.",
            "updated_at": "2026-09-14T17:17:41.473",
            "published_at": "2023-06-22T13:15:09.737",
            "cvss": 3.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.0 through 10.0.23 (maven); 11.0.0 through 14.10.1 (maven); 15.0.0 through 22.0.28 (maven); 23.0.0 through 23.3.13 (maven); 24.0.0 through 24.0.6 (maven); 24.1.0.alpha1 through 24.1.0.rc2 (maven); 1.0.0 through 1.0.20 (maven); 1.1.0 through 2.9.2 (maven); 3.0.0 through 9.1.1 (maven); 23.0.0 through 23.3.12 (maven); 24.0.0 through 24.0.8 (maven); 24.1.0.alpha1 through 24.1.0.rc3 (maven)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "Possible information disclosure in Vaadin 10.0.0 to 10.0.23, 11.0.0 to 14.10.1, 15.0.0 to 22.0.28, 23.0.0 to 23.3.13, 24.0.0 to 24.0.6, 24.1.0.alpha1 to 24.1.0.rc2, resulting in potential information disclosure of class and method names in RPC responses by sending modified requests.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/vaadin/flow/pull/16935",
                "https://vaadin.com/security/cve-2023-25500"
            ],
            "timeline": [
                {
                    "at": "2023-06-22T13:15:09.737",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25500"
                }
            ]
        },
        {
            "id": "CVE-2023-25499",
            "vendor": "vaadin",
            "product": "vaadin",
            "title": "vaadin vulnerability",
            "summary": "When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1 to 24.1.0.beta1, resulting in potential information disclosure.",
            "updated_at": "2026-09-14T16:17:04.217",
            "published_at": "2023-06-22T13:15:09.660",
            "cvss": 5.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "10.0.0 through 10.0.22 (maven); 11.0.0 through 14.10.0 (maven); 15.0.0 through 22.0.28 (maven); 23.0.0 through 23.3.12 (maven); 24.0.0 through 24.0.5 (maven); 24.1.0.alpha1 through 24.1.0.beta1 (maven); 1.0.0 through 1.0.19 (maven); 1.1.0 through 2.8.9 (maven); 2.9.0 through before 2.9.1 (maven); 3.0.0 through 9.1.0 (maven); 23.0.0 through 23.3.10 (maven); 24.0.0 through 24.0.7 (maven)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "When adding non-visible components to the UI in server side, content is sent to the browser in Vaadin 10.0.0 through 10.0.22, 11.0.0 through 14.10.0, 15.0.0 through 22.0.28, 23.0.0 through 23.3.12, 24.0.0 through 24.0.5 and 24.1.0.alpha1 to 24.1.0.beta1, resulting in potential information disclosure.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/vaadin/flow/pull/15885",
                "https://vaadin.com/security/CVE-2023-25499"
            ],
            "timeline": [
                {
                    "at": "2023-06-22T13:15:09.660",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25499"
                }
            ]
        },
        {
            "id": "CVE-2023-25157",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2023-25157 - GeoServer SQL Injection - PoC",
            "summary": "CVE-2023-25157 - GeoServer SQL Injection - PoC",
            "updated_at": "2026-09-09T22:00:00Z",
            "published_at": "2026-09-09T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 251,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · win3zz/CVE-2023-25157",
                    "author": "win3zz",
                    "first_seen": "2023-06-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 167,
                    "title": "CVE-2023-25157 - GeoServer SQL Injection - PoC",
                    "summary": "CVE-2023-25157 - GeoServer SQL Injection - PoC",
                    "url": "https://github.com/win3zz/CVE-2023-25157"
                },
                {
                    "repository": "PoC-in-GitHub · 0x2458bughunt/CVE-2023-25157",
                    "author": "0x2458bughunt",
                    "first_seen": "2023-06-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "CVE-2023-25157 repository",
                    "summary": "",
                    "url": "https://github.com/0x2458bughunt/CVE-2023-25157"
                },
                {
                    "repository": "PoC-in-GitHub · murataydemir/CVE-2023-25157-and-CVE-2023-25158",
                    "author": "murataydemir",
                    "first_seen": "2023-06-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "GeoServer & GeoTools SQL Injection (CVE-2023-25157 & CVE-2023-25158)",
                    "summary": "GeoServer & GeoTools SQL Injection (CVE-2023-25157 & CVE-2023-25158)",
                    "url": "https://github.com/murataydemir/CVE-2023-25157-and-CVE-2023-25158"
                },
                {
                    "repository": "PoC-in-GitHub · 7imbitz/CVE-2023-25157-checker",
                    "author": "7imbitz",
                    "first_seen": "2023-06-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A script, written in golang. POC for CVE-2023-25157",
                    "summary": "A script, written in golang. POC for CVE-2023-25157",
                    "url": "https://github.com/7imbitz/CVE-2023-25157-checker"
                },
                {
                    "repository": "PoC-in-GitHub · Rubikcuv5/CVE-2023-25157",
                    "author": "Rubikcuv5",
                    "first_seen": "2023-07-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "GeoServer OGC Filter SQL Injection Vulnerabilities",
                    "summary": "GeoServer OGC Filter SQL Injection Vulnerabilities",
                    "url": "https://github.com/Rubikcuv5/CVE-2023-25157"
                },
                {
                    "repository": "PoC-in-GitHub · dr-cable-tv/Geoserver-CVE-2023-25157",
                    "author": "dr-cable-tv",
                    "first_seen": "2023-11-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Geoserver SQL Injection Exploit",
                    "summary": "Geoserver SQL Injection Exploit",
                    "url": "https://github.com/dr-cable-tv/Geoserver-CVE-2023-25157"
                },
                {
                    "repository": "PoC-in-GitHub · custiya/geoserver-CVE-2023-25157",
                    "author": "custiya",
                    "first_seen": "2025-04-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-25157 repository",
                    "summary": "",
                    "url": "https://github.com/custiya/geoserver-CVE-2023-25157"
                },
                {
                    "repository": "PoC-in-GitHub · charis3306/CVE-2023-25157",
                    "author": "charis3306",
                    "first_seen": "2025-04-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2023-25157 exp",
                    "summary": "CVE-2023-25157 exp",
                    "url": "https://github.com/charis3306/CVE-2023-25157"
                },
                {
                    "repository": "PoC-in-GitHub · Giangdurian/CVE-2023-25157-GeoServer-SQLi-Lab",
                    "author": "Giangdurian",
                    "first_seen": "2026-07-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-25157 repository",
                    "summary": "",
                    "url": "https://github.com/Giangdurian/CVE-2023-25157-GeoServer-SQLi-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · ivanesk315/CVE-2023-25157",
                    "author": "ivanesk315",
                    "first_seen": "2026-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-25157 repository",
                    "summary": "",
                    "url": "https://github.com/ivanesk315/CVE-2023-25157"
                }
            ],
            "references": [
                "https://github.com/win3zz/CVE-2023-25157",
                "https://github.com/0x2458bughunt/CVE-2023-25157",
                "https://github.com/murataydemir/CVE-2023-25157-and-CVE-2023-25158",
                "https://github.com/7imbitz/CVE-2023-25157-checker",
                "https://github.com/Rubikcuv5/CVE-2023-25157",
                "https://github.com/dr-cable-tv/Geoserver-CVE-2023-25157",
                "https://github.com/custiya/geoserver-CVE-2023-25157",
                "https://github.com/charis3306/CVE-2023-25157",
                "https://github.com/Giangdurian/CVE-2023-25157-GeoServer-SQLi-Lab",
                "https://github.com/ivanesk315/CVE-2023-25157"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/win3zz/CVE-2023-25157"
                }
            ]
        },
        {
            "id": "CVE-2023-24291",
            "vendor": "Simon Tatham",
            "product": "Portable Puzzle Collection",
            "title": "Portable Puzzle Collection vulnerability",
            "summary": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.",
            "updated_at": "2026-09-14T05:16:56.700",
            "published_at": "2026-09-14T05:16:56.700",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 20230116.5782e29 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-120",
            "what_happened": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1028986",
                "https://git.tartarus.org/?p=simon/puzzles.git;a=commit;h=e5717d1ba2184eb6e38b4e2a9d29dc4704aeef30"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:56.700",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24291"
                }
            ]
        },
        {
            "id": "CVE-2023-24288",
            "vendor": "Simon Tatham",
            "product": "Portable Puzzle Collection",
            "title": "Portable Puzzle Collection vulnerability",
            "summary": "An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.",
            "updated_at": "2026-09-14T05:16:56.560",
            "published_at": "2026-09-14T05:16:56.560",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 20230116.5782e29 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-190",
            "what_happened": "An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1028986",
                "https://git.tartarus.org/?p=simon/puzzles.git;a=commit;h=b3d4a4197954c21ac78b68c58dff8f84fe743ea2"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:56.560",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24288"
                }
            ]
        },
        {
            "id": "CVE-2023-24287",
            "vendor": "Simon Tatham",
            "product": "Portable Puzzle Collection",
            "title": "Portable Puzzle Collection vulnerability",
            "summary": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the \"M\" command.",
            "updated_at": "2026-09-14T05:16:56.410",
            "published_at": "2026-09-14T05:16:56.410",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 20230116.5782e29 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-120",
            "what_happened": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the \"M\" command.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1028986",
                "https://git.tartarus.org/?p=simon/puzzles.git;a=commit;h=952ef8ca565d803da1134466358bd85683a489a3"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:56.410",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24287"
                }
            ]
        },
        {
            "id": "CVE-2023-24286",
            "vendor": "Simon Tatham",
            "product": "Portable Puzzle Collection",
            "title": "Portable Puzzle Collection vulnerability",
            "summary": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.",
            "updated_at": "2026-09-14T05:16:56.277",
            "published_at": "2026-09-14T05:16:56.277",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 20230116.5782e29 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 1,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-120",
            "what_happened": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.tartarus.org/?p=simon/puzzles.git;a=commit;h=a539f38efd0d821c8325846fc879a3e46d6412bf"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:56.277",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24286"
                }
            ]
        },
        {
            "id": "CVE-2023-24285",
            "vendor": "Simon Tatham",
            "product": "Portable Puzzle Collection",
            "title": "Portable Puzzle Collection vulnerability",
            "summary": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.",
            "updated_at": "2026-09-14T05:16:56.140",
            "published_at": "2026-09-14T05:16:56.140",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 20230116.5782e29 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-120",
            "what_happened": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1028986",
                "https://git.tartarus.org/?p=simon/puzzles.git;a=commit;h=1aded127eb3fb7194a1752d96bfba95a5b7fa4dc"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:56.140",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24285"
                }
            ]
        },
        {
            "id": "CVE-2023-24284",
            "vendor": "Simon Tatham",
            "product": "Portable Puzzle Collection",
            "title": "Portable Puzzle Collection vulnerability",
            "summary": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.",
            "updated_at": "2026-09-14T05:16:55.173",
            "published_at": "2026-09-14T05:16:55.173",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 20230116.5782e29 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-120",
            "what_happened": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1028986",
                "https://git.tartarus.org/?p=simon/puzzles.git;a=commit;h=5279fd24b2f4a51e760bfde873fe1d29547220a6"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T05:16:55.173",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24284"
                }
            ]
        },
        {
            "id": "CVE-2023-24283",
            "vendor": "Simon Tatham",
            "product": "Portable Puzzle Collection",
            "title": "Portable Puzzle Collection vulnerability",
            "summary": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of Service (DoS) via a crafted save file.",
            "updated_at": "2026-09-14T04:16:35.440",
            "published_at": "2026-09-14T04:16:35.440",
            "cvss": 2.9,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 20230116.5782e29 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-120",
            "what_happened": "Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of Service (DoS) via a crafted save file.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1028986",
                "https://git.tartarus.org/?p=simon/puzzles.git;a=commit;h=c84af670b52f09e9e47587584c0559c508d4a37d"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:16:35.440",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24283"
                }
            ]
        },
        {
            "id": "CVE-2023-24100",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2023-24100 exploit",
            "summary": "Exploit for CVE-2023-24100.",
            "updated_at": "2026-09-15T08:39:27Z",
            "published_at": "2026-09-15T08:39:27Z",
            "cvss": 5.4,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "IoT RCE vulnerability with Nuclei detection templates for CVE-2023-24100.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-24100",
                    "summary": "IoT RCE vulnerability with Nuclei detection templates for CVE-2023-24100.",
                    "what_happened": "IoT RCE vulnerability with Nuclei detection templates for CVE-2023-24100.",
                    "cvss": 5.4,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BADBOYCXCC-CVE-2023-24100",
                        "https://kitploit.com/ru/tools/github/badboycxcc/cve-2023-24100/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T12:58:35",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BADBOYCXCC-CVE-2023-24100"
                },
                {
                    "title": "Exploit for CVE-2023-24100",
                    "summary": "IoT RCE vulnerability with Nuclei detection templates for CVE-2023-24100.",
                    "what_happened": "IoT RCE vulnerability with Nuclei detection templates for CVE-2023-24100.",
                    "cvss": 5.4,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BADBOYCXCC-CVE-2023-24100",
                        "https://kitploit.com/ru/tools/github/badboycxcc/cve-2023-24100/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T12:58:35",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/badboycxcc/cve-2023-24100/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BADBOYCXCC-CVE-2023-24100",
                "https://kitploit.com/ru/tools/github/badboycxcc/cve-2023-24100/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:39:27Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BADBOYCXCC-CVE-2023-24100"
                }
            ],
            "enrichment_checked_at": "2026-09-15T10:05:44Z",
            "cvss_vector": "NONE"
        },
        {
            "id": "CVE-2023-24035",
            "vendor": "Nagios",
            "product": "Nagios XI",
            "title": "Nagios XI vulnerability",
            "summary": "An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in the comparison.",
            "updated_at": "2026-09-14T04:16:35.293",
            "published_at": "2026-09-14T04:16:35.293",
            "cvss": 3.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.9.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-208",
            "what_happened": "An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in the comparison.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.nagios.com/downloads/nagios-xi/change-log/",
                "https://www.nagios.com/security-disclosures/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:16:35.293",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24035"
                }
            ]
        },
        {
            "id": "CVE-2023-24034",
            "vendor": "Nagios",
            "product": "Nagios XI",
            "title": "Nagios XI vulnerability",
            "summary": "An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.",
            "updated_at": "2026-09-14T04:16:35.107",
            "published_at": "2026-09-14T04:16:35.107",
            "cvss": 3.1,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 5.9.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-601",
            "what_happened": "An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.nagios.com/downloads/nagios-xi/change-log/",
                "https://www.nagios.com/security-disclosures/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:16:35.107",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24034"
                }
            ]
        },
        {
            "id": "CVE-2023-23397",
            "vendor": "Microsoft",
            "product": "Office",
            "title": "Microsoft Office Outlook Privilege Escalation Vulnerability",
            "summary": "Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.",
            "updated_at": "2026-08-27T22:00:00Z",
            "published_at": "2026-08-27T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1315,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the user.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAY",
                    "author": "sqrtZeroKnowledge",
                    "first_seen": "2023-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 158,
                    "title": "Exploit for the CVE-2023-23397",
                    "summary": "Exploit for the CVE-2023-23397",
                    "url": "https://github.com/sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAY"
                },
                {
                    "repository": "PoC-in-GitHub · j0eyv/CVE-2023-23397",
                    "author": "j0eyv",
                    "first_seen": "2023-03-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2023-23397 repository",
                    "summary": "",
                    "url": "https://github.com/j0eyv/CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · alicangnll/CVE-2023-23397",
                    "author": "alicangnll",
                    "first_seen": "2023-03-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2023-23397 - Microsoft Outlook Vulnerability",
                    "summary": "CVE-2023-23397 - Microsoft Outlook Vulnerability",
                    "url": "https://github.com/alicangnll/CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · grn-bogo/CVE-2023-23397",
                    "author": "grn-bogo",
                    "first_seen": "2023-03-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Python script to create a message with the vulenrability properties set",
                    "summary": "Python script to create a message with the vulenrability properties set",
                    "url": "https://github.com/grn-bogo/CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · ka7ana/CVE-2023-23397",
                    "author": "ka7ana",
                    "first_seen": "2023-03-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 40,
                    "title": "Simple PoC in PowerShell for CVE-2023-23397",
                    "summary": "Simple PoC in PowerShell for CVE-2023-23397",
                    "url": "https://github.com/ka7ana/CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · api0cradle/CVE-2023-23397-POC-Powershell",
                    "author": "api0cradle",
                    "first_seen": "2023-03-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 345,
                    "title": "CVE-2023-23397 repository",
                    "summary": "",
                    "url": "https://github.com/api0cradle/CVE-2023-23397-POC-Powershell"
                },
                {
                    "repository": "PoC-in-GitHub · im007/CVE-2023-23397",
                    "author": "im007",
                    "first_seen": "2023-03-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-23397 Remediation Script (Powershell)",
                    "summary": "CVE-2023-23397 Remediation Script (Powershell)",
                    "url": "https://github.com/im007/CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · ahmedkhlief/CVE-2023-23397-POC",
                    "author": "ahmedkhlief",
                    "first_seen": "2023-03-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Exploit POC for CVE-2023-23397",
                    "summary": "Exploit POC for CVE-2023-23397",
                    "url": "https://github.com/ahmedkhlief/CVE-2023-23397-POC"
                },
                {
                    "repository": "PoC-in-GitHub · BillSkiCO/CVE-2023-23397_EXPLOIT",
                    "author": "BillSkiCO",
                    "first_seen": "2023-03-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Generates meeting requests taking advantage of CVE-2023-23397. This requires the outlook thick client to send.",
                    "summary": "Generates meeting requests taking advantage of CVE-2023-23397. This requires the outlook thick client to send.",
                    "url": "https://github.com/BillSkiCO/CVE-2023-23397_EXPLOIT"
                },
                {
                    "repository": "PoC-in-GitHub · djackreuter/CVE-2023-23397-PoC",
                    "author": "djackreuter",
                    "first_seen": "2023-03-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2023-23397 repository",
                    "summary": "",
                    "url": "https://github.com/djackreuter/CVE-2023-23397-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · moneertv/CVE-2023-23397",
                    "author": "moneertv",
                    "first_seen": "2023-03-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2023-23397 C# PoC",
                    "summary": "CVE-2023-23397 C# PoC",
                    "url": "https://github.com/moneertv/CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · ahmedkhlief/CVE-2023-23397-POC-Using-Interop-Outlook",
                    "author": "ahmedkhlief",
                    "first_seen": "2023-03-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2023-23397 repository",
                    "summary": "",
                    "url": "https://github.com/ahmedkhlief/CVE-2023-23397-POC-Using-Interop-Outlook"
                },
                {
                    "repository": "PoC-in-GitHub · Trackflaw/CVE-2023-23397",
                    "author": "Trackflaw",
                    "first_seen": "2023-03-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 132,
                    "title": "Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.",
                    "summary": "Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.",
                    "url": "https://github.com/Trackflaw/CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · SecCTechs/CVE-2023-23397",
                    "author": "SecCTechs",
                    "first_seen": "2023-03-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Patch for MS Outlook Critical Vulnerability - CVSS 9.8",
                    "summary": "Patch for MS Outlook Critical Vulnerability - CVSS 9.8",
                    "url": "https://github.com/SecCTechs/CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · tiepologian/CVE-2023-23397",
                    "author": "tiepologian",
                    "first_seen": "2023-03-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "Proof of Concept for CVE-2023-23397 in Python",
                    "summary": "Proof of Concept for CVE-2023-23397 in Python",
                    "url": "https://github.com/tiepologian/CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · BronzeBee/cve-2023-23397",
                    "author": "BronzeBee",
                    "first_seen": "2023-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "Python script for sending e-mails with CVE-2023-23397 payload using SMTP",
                    "summary": "Python script for sending e-mails with CVE-2023-23397 payload using SMTP",
                    "url": "https://github.com/BronzeBee/cve-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · Cyb3rMaddy/CVE-2023-23397-Report",
                    "author": "Cyb3rMaddy",
                    "first_seen": "2023-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "An exploitation demo of Outlook Elevation of Privilege Vulnerability",
                    "summary": "An exploitation demo of Outlook Elevation of Privilege Vulnerability",
                    "url": "https://github.com/Cyb3rMaddy/CVE-2023-23397-Report"
                },
                {
                    "repository": "PoC-in-GitHub · Zeppperoni/CVE-2023-23397-Patch",
                    "author": "Zeppperoni",
                    "first_seen": "2023-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-23397 powershell patch script for Windows 10 and 11",
                    "summary": "CVE-2023-23397 powershell patch script for Windows 10 and 11",
                    "url": "https://github.com/Zeppperoni/CVE-2023-23397-Patch"
                },
                {
                    "repository": "PoC-in-GitHub · jacquesquail/CVE-2023-23397",
                    "author": "jacquesquail",
                    "first_seen": "2023-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-23397 repository",
                    "summary": "",
                    "url": "https://github.com/jacquesquail/CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · P4x1s/CVE-2023-23397-POC",
                    "author": "P4x1s",
                    "first_seen": "2023-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2023-23397漏洞的简单PoC，有效载荷通过电子邮件发送。",
                    "summary": "CVE-2023-23397漏洞的简单PoC，有效载荷通过电子邮件发送。",
                    "url": "https://github.com/P4x1s/CVE-2023-23397-POC"
                },
                {
                    "repository": "PoC-in-GitHub · vlad-a-man/CVE-2023-23397",
                    "author": "vlad-a-man",
                    "first_seen": "2023-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "CVE-2023-23397 PoC",
                    "summary": "CVE-2023-23397 PoC",
                    "url": "https://github.com/vlad-a-man/CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · Muhammad-Ali007/OutlookNTLM_CVE-2023-23397",
                    "author": "Muhammad-Ali007",
                    "first_seen": "2023-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 22,
                    "title": "CVE-2023-23397 repository",
                    "summary": "",
                    "url": "https://github.com/Muhammad-Ali007/OutlookNTLM_CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · Pushkarup/CVE-2023-23397",
                    "author": "Pushkarup",
                    "first_seen": "2023-10-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "This script exploits CVE-2023-23397, a Zero-Day vulnerability in Microsoft Outlook, allowing the generation of malicious emails for testing and educational purposes.",
                    "summary": "This script exploits CVE-2023-23397, a Zero-Day vulnerability in Microsoft Outlook, allowing the generation of malicious emails for testing and educational purposes.",
                    "url": "https://github.com/Pushkarup/CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · TheUnknownSoul/CVE-2023-23397-PoW",
                    "author": "TheUnknownSoul",
                    "first_seen": "2024-03-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Proof of Work of CVE-2023-23397 for vulnerable Microsoft Outlook client application.",
                    "summary": "Proof of Work of CVE-2023-23397 for vulnerable Microsoft Outlook client application.",
                    "url": "https://github.com/TheUnknownSoul/CVE-2023-23397-PoW"
                },
                {
                    "repository": "PoC-in-GitHub · Symbolexe/CVE-2023-23397",
                    "author": "Symbolexe",
                    "first_seen": "2024-06-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-23397: Remote Code Execution Vulnerability in Microsoft Outlook",
                    "summary": "CVE-2023-23397: Remote Code Execution Vulnerability in Microsoft Outlook",
                    "url": "https://github.com/Symbolexe/CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · Gilospy/CVE-2023-23397",
                    "author": "Gilospy",
                    "first_seen": "2025-04-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Demonstration of CVE-2023-23397 Outlook Privellege Escalation vulnerability",
                    "summary": "Demonstration of CVE-2023-23397 Outlook Privellege Escalation vulnerability",
                    "url": "https://github.com/Gilospy/CVE-2023-23397"
                },
                {
                    "repository": "PoC-in-GitHub · Phaedrik/CVE-2023-23397-POC",
                    "author": "Phaedrik",
                    "first_seen": "2026-01-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.",
                    "summary": "Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.",
                    "url": "https://github.com/Phaedrik/CVE-2023-23397-POC"
                },
                {
                    "repository": "PoC-in-GitHub · praneethnaidu1910-cmd/cve-2023-23397-purple-team",
                    "author": "praneethnaidu1910-cmd",
                    "first_seen": "2026-08-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-23397 repository",
                    "summary": "",
                    "url": "https://github.com/praneethnaidu1910-cmd/cve-2023-23397-purple-team"
                },
                {
                    "repository": "PoC-in-GitHub · ZHOUCC-CPU/cve-2023-23397-detection-lab",
                    "author": "ZHOUCC-CPU",
                    "first_seen": "2026-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.",
                    "summary": "Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.",
                    "url": "https://github.com/ZHOUCC-CPU/cve-2023-23397-detection-lab"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/sqrtZeroKnowledge/CVE-2023-23397_EXPLOIT_0DAY",
                "https://github.com/j0eyv/CVE-2023-23397",
                "https://github.com/alicangnll/CVE-2023-23397",
                "https://github.com/grn-bogo/CVE-2023-23397",
                "https://github.com/ka7ana/CVE-2023-23397",
                "https://github.com/api0cradle/CVE-2023-23397-POC-Powershell",
                "https://github.com/im007/CVE-2023-23397",
                "https://github.com/ahmedkhlief/CVE-2023-23397-POC",
                "https://github.com/BillSkiCO/CVE-2023-23397_EXPLOIT",
                "https://github.com/djackreuter/CVE-2023-23397-PoC",
                "https://github.com/moneertv/CVE-2023-23397",
                "https://github.com/ahmedkhlief/CVE-2023-23397-POC-Using-Interop-Outlook",
                "https://github.com/Trackflaw/CVE-2023-23397",
                "https://github.com/SecCTechs/CVE-2023-23397",
                "https://github.com/tiepologian/CVE-2023-23397",
                "https://github.com/BronzeBee/cve-2023-23397",
                "https://github.com/Cyb3rMaddy/CVE-2023-23397-Report",
                "https://github.com/Zeppperoni/CVE-2023-23397-Patch",
                "https://github.com/jacquesquail/CVE-2023-23397",
                "https://github.com/P4x1s/CVE-2023-23397-POC",
                "https://github.com/vlad-a-man/CVE-2023-23397",
                "https://github.com/Muhammad-Ali007/OutlookNTLM_CVE-2023-23397",
                "https://github.com/Pushkarup/CVE-2023-23397",
                "https://github.com/TheUnknownSoul/CVE-2023-23397-PoW",
                "https://github.com/Symbolexe/CVE-2023-23397",
                "https://github.com/Gilospy/CVE-2023-23397",
                "https://github.com/Phaedrik/CVE-2023-23397-POC",
                "https://github.com/praneethnaidu1910-cmd/cve-2023-23397-purple-team",
                "https://github.com/ZHOUCC-CPU/cve-2023-23397-detection-lab"
            ],
            "timeline": [
                {
                    "at": "2026-08-27T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2023-23169",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2023-23169",
            "summary": "LFI and SSRF in PDFocus triggered by uploading and viewing a docx file.",
            "updated_at": "2026-09-05T13:06:57Z",
            "published_at": "2026-09-05T13:06:57Z",
            "cvss": 6.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 34,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "LFI and SSRF in PDFocus triggered by uploading and viewing a docx file.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T15:07:11+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2023-23169 exploit",
                    "summary": "Exploit for CVE-2023-23169. CVSS 6.5.",
                    "cvss": 6.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-S4NSHINE-CVE-2023-23169"
                },
                {
                    "title": "Exploit for CVE-2023-23169",
                    "summary": "LFI and SSRF in PDFocus triggered by uploading and viewing a docx file.",
                    "what_happened": "LFI and SSRF in PDFocus triggered by uploading and viewing a docx file.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-S4NSHINE-CVE-2023-23169",
                        "https://kitploit.com/ru/tools/github/s4nshine/cve-2023-23169/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T15:06:57",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/s4nshine/cve-2023-23169/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-S4NSHINE-CVE-2023-23169",
                "https://kitploit.com/ru/tools/github/s4nshine/cve-2023-23169/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T13:06:57Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-S4NSHINE-CVE-2023-23169"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2023-22960",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2023-22960",
            "summary": "Brute-force prevention bypass in Lexmark Embedded Web Server before 01/2023 firmware on all models.",
            "updated_at": "2026-09-04T09:35:50Z",
            "published_at": "2026-09-04T09:35:50Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Brute-force prevention bypass in Lexmark Embedded Web Server before 01/2023 firmware on all models.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-22960",
                    "summary": "Brute-force prevention bypass in Lexmark Embedded Web Server before 01/2023 firmware on all models.",
                    "what_happened": "Brute-force prevention bypass in Lexmark Embedded Web Server before 01/2023 firmware on all models.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-T3L3MACHUS-CVE-2023-22960",
                        "https://kitploit.com/ru/tools/github/t3l3machus/cve-2023-22960/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T11:35:50",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-T3L3MACHUS-CVE-2023-22960"
                },
                {
                    "title": "Exploit for CVE-2023-22960",
                    "summary": "Brute-force prevention bypass in Lexmark Embedded Web Server before 01/2023 firmware on all models.",
                    "what_happened": "Brute-force prevention bypass in Lexmark Embedded Web Server before 01/2023 firmware on all models.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-T3L3MACHUS-CVE-2023-22960",
                        "https://kitploit.com/ru/tools/github/t3l3machus/cve-2023-22960/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T11:35:50",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/t3l3machus/cve-2023-22960/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-T3L3MACHUS-CVE-2023-22960",
                "https://kitploit.com/ru/tools/github/t3l3machus/cve-2023-22960/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T09:35:50Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-T3L3MACHUS-CVE-2023-22960"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2023-22632",
            "vendor": "Paessler",
            "product": "PRTG Network Monitor",
            "title": "PRTG Network Monitor vulnerability",
            "summary": "PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.",
            "updated_at": "2026-09-14T04:16:34.960",
            "published_at": "2026-09-14T04:16:34.960",
            "cvss": 2.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 23.1.82 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-88",
            "what_happened": "PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://helpdesk.paessler.com/en/support/solutions/articles/76000076688-is-prtg-affected-by-cve-2023-22631-or-cve-2023-22632-",
                "https://www.paessler.com/prtg"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:16:34.960",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22632"
                }
            ]
        },
        {
            "id": "CVE-2023-22631",
            "vendor": "Paessler",
            "product": "PRTG Network Monitor",
            "title": "PRTG Network Monitor vulnerability",
            "summary": "PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.",
            "updated_at": "2026-09-14T04:16:33.853",
            "published_at": "2026-09-14T04:16:33.853",
            "cvss": 2.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 23.1.82 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "CWE-88",
            "what_happened": "PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://helpdesk.paessler.com/en/support/solutions/articles/76000076688-is-prtg-affected-by-cve-2023-22631-or-cve-2023-22632-",
                "https://www.paessler.com/prtg"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:16:33.853",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-22631"
                }
            ]
        },
        {
            "id": "CVE-2023-22518",
            "vendor": "Atlassian",
            "product": "Confluence Data Center and Server",
            "title": "Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
            "summary": "Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.",
            "updated_at": "2026-08-28T08:02:13Z",
            "published_at": "2026-08-28T08:02:13Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 118,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-22518 CVE-2023-22515 CVE-2023-22518",
                    "summary": "Critical vulnerability in Atlassian Confluence (CVE-2023-22518) allowing admin account creation.",
                    "what_happened": "Critical vulnerability in Atlassian Confluence (CVE-2023-22518) allowing admin account creation.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DAVIDFORTYTWO-CVE-2023-22518",
                        "https://kitploit.com/hi/tools/github/davidfortytwo/cve-2023-22518/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-28T10:02:13",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DAVIDFORTYTWO-CVE-2023-22518"
                },
                {
                    "title": "Exploit for CVE-2023-22518 CVE-2023-22515 CVE-2023-22518",
                    "summary": "Critical vulnerability in Atlassian Confluence (CVE-2023-22518) allowing admin account creation.",
                    "what_happened": "Critical vulnerability in Atlassian Confluence (CVE-2023-22518) allowing admin account creation.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DAVIDFORTYTWO-CVE-2023-22518",
                        "https://kitploit.com/hi/tools/github/davidfortytwo/cve-2023-22518/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-08-28T10:02:13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/davidfortytwo/cve-2023-22518/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DAVIDFORTYTWO-CVE-2023-22518",
                "https://kitploit.com/hi/tools/github/davidfortytwo/cve-2023-22518/"
            ],
            "timeline": [
                {
                    "at": "2026-08-28T08:02:13Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-11-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2023-22515",
            "vendor": "Atlassian",
            "product": "Confluence Data Center and Server",
            "title": "Atlassian Confluence Data Center and Server Broken Access Control Vulnerability",
            "summary": "Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.",
            "updated_at": "2026-08-28T08:02:13Z",
            "published_at": "2026-08-28T08:02:13Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1233,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-22518 CVE-2023-22515 CVE-2023-22518",
                    "summary": "Critical vulnerability in Atlassian Confluence (CVE-2023-22518) allowing admin account creation.",
                    "what_happened": "Critical vulnerability in Atlassian Confluence (CVE-2023-22518) allowing admin account creation.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DAVIDFORTYTWO-CVE-2023-22518",
                        "https://kitploit.com/hi/tools/github/davidfortytwo/cve-2023-22518/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-28T10:02:13",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DAVIDFORTYTWO-CVE-2023-22518"
                },
                {
                    "title": "Exploit for CVE-2023-22518 CVE-2023-22515 CVE-2023-22518",
                    "summary": "Critical vulnerability in Atlassian Confluence (CVE-2023-22518) allowing admin account creation.",
                    "what_happened": "Critical vulnerability in Atlassian Confluence (CVE-2023-22518) allowing admin account creation.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DAVIDFORTYTWO-CVE-2023-22518",
                        "https://kitploit.com/hi/tools/github/davidfortytwo/cve-2023-22518/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-08-28T10:02:13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/davidfortytwo/cve-2023-22518/"
                },
                {
                    "repository": "PoC-in-GitHub · ErikWynter/CVE-2023-22515-Scan",
                    "author": "ErikWynter",
                    "first_seen": "2023-10-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 80,
                    "title": "Scanner for CVE-2023-22515 - Broken Access Control Vulnerability in Atlassian Confluence",
                    "summary": "Scanner for CVE-2023-22515 - Broken Access Control Vulnerability in Atlassian Confluence",
                    "url": "https://github.com/ErikWynter/CVE-2023-22515-Scan"
                },
                {
                    "repository": "PoC-in-GitHub · j3seer/CVE-2023-22515-POC",
                    "author": "j3seer",
                    "first_seen": "2023-10-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "Poc for CVE-2023-22515",
                    "summary": "Poc for CVE-2023-22515",
                    "url": "https://github.com/j3seer/CVE-2023-22515-POC"
                },
                {
                    "repository": "PoC-in-GitHub · Chocapikk/CVE-2023-22515",
                    "author": "Chocapikk",
                    "first_seen": "2023-10-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 155,
                    "title": "CVE-2023-22515: Confluence Broken Access Control Exploit",
                    "summary": "CVE-2023-22515: Confluence Broken Access Control Exploit",
                    "url": "https://github.com/Chocapikk/CVE-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · ad-calcium/CVE-2023-22515",
                    "author": "ad-calcium",
                    "first_seen": "2023-10-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 110,
                    "title": "Confluence未授权添加管理员用户(CVE-2023-22515)漏洞利用工具",
                    "summary": "Confluence未授权添加管理员用户(CVE-2023-22515)漏洞利用工具",
                    "url": "https://github.com/ad-calcium/CVE-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · kh4sh3i/CVE-2023-22515",
                    "author": "kh4sh3i",
                    "first_seen": "2023-10-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server",
                    "summary": "CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server",
                    "url": "https://github.com/kh4sh3i/CVE-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · s1incere/CVE-2023-22515",
                    "author": "s1incere",
                    "first_seen": "2023-10-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "Confluence Unauthorized Administrator User Addition Exploitation Script",
                    "summary": "Confluence Unauthorized Administrator User Addition Exploitation Script",
                    "url": "https://github.com/s1incere/CVE-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · Le1a/CVE-2023-22515",
                    "author": "Le1a",
                    "first_seen": "2023-10-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Confluence Data Center & Server 权限提升漏洞 Exploit",
                    "summary": "Confluence Data Center & Server 权限提升漏洞 Exploit",
                    "url": "https://github.com/Le1a/CVE-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · Vulnmachines/confluence-cve-2023-22515",
                    "author": "Vulnmachines",
                    "first_seen": "2023-10-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Confluence Broken Access Control",
                    "summary": "Confluence Broken Access Control",
                    "url": "https://github.com/Vulnmachines/confluence-cve-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · iveresk/CVE-2023-22515",
                    "author": "iveresk",
                    "first_seen": "2023-10-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "iveresk-CVE-2023-22515",
                    "summary": "iveresk-CVE-2023-22515",
                    "url": "https://github.com/iveresk/CVE-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · youcannotseemeagain/CVE-2023-22515_RCE",
                    "author": "youcannotseemeagain",
                    "first_seen": "2023-10-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 20,
                    "title": "Confluence后台rce",
                    "summary": "Confluence后台rce",
                    "url": "https://github.com/youcannotseemeagain/CVE-2023-22515_RCE"
                },
                {
                    "repository": "PoC-in-GitHub · DsaHen/cve-2023-22515-exp",
                    "author": "DsaHen",
                    "first_seen": "2023-10-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "cve-2023-22515的python利用脚本",
                    "summary": "cve-2023-22515的python利用脚本",
                    "url": "https://github.com/DsaHen/cve-2023-22515-exp"
                },
                {
                    "repository": "PoC-in-GitHub · C1ph3rX13/CVE-2023-22515",
                    "author": "C1ph3rX13",
                    "first_seen": "2023-10-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2023-22515",
                    "summary": "CVE-2023-22515",
                    "url": "https://github.com/C1ph3rX13/CVE-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · AIex-3/confluence-hack",
                    "author": "AIex-3",
                    "first_seen": "2023-10-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 52,
                    "title": "CVE-2023-22515",
                    "summary": "CVE-2023-22515",
                    "url": "https://github.com/AIex-3/confluence-hack"
                },
                {
                    "repository": "PoC-in-GitHub · LucasPDiniz/CVE-2023-22515",
                    "author": "LucasPDiniz",
                    "first_seen": "2023-11-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Server Broken Access Control in Confluence - CVE-2023-22515",
                    "summary": "Server Broken Access Control in Confluence - CVE-2023-22515",
                    "url": "https://github.com/LucasPDiniz/CVE-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · aaaademo/Confluence-EvilJar",
                    "author": "aaaademo",
                    "first_seen": "2023-11-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 23,
                    "title": "配合 CVE-2023-22515 后台上传jar包实现RCE",
                    "summary": "配合 CVE-2023-22515 后台上传jar包实现RCE",
                    "url": "https://github.com/aaaademo/Confluence-EvilJar"
                },
                {
                    "repository": "PoC-in-GitHub · edsonjt81/CVE-2023-22515-Scan.",
                    "author": "edsonjt81",
                    "first_seen": "2023-11-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-22515 repository",
                    "summary": "",
                    "url": "https://github.com/edsonjt81/CVE-2023-22515-Scan."
                },
                {
                    "repository": "PoC-in-GitHub · INTfinityConsulting/cve-2023-22515",
                    "author": "INTfinityConsulting",
                    "first_seen": "2023-11-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Confluence broken access control to code execution",
                    "summary": "Confluence broken access control to code execution",
                    "url": "https://github.com/INTfinityConsulting/cve-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · CalegariMindSec/Exploit-CVE-2023-22515",
                    "author": "CalegariMindSec",
                    "first_seen": "2024-01-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A simple exploit for CVE-2023-22515",
                    "summary": "A simple exploit for CVE-2023-22515",
                    "url": "https://github.com/CalegariMindSec/Exploit-CVE-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · rxerium/CVE-2023-22515",
                    "author": "rxerium",
                    "first_seen": "2024-02-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Atlassian Confluence Data Center and Server Broken Access Control Vulnerability",
                    "summary": "Atlassian Confluence Data Center and Server Broken Access Control Vulnerability",
                    "url": "https://github.com/rxerium/CVE-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · fyx1t/NSE--CVE-2023-22515",
                    "author": "fyx1t",
                    "first_seen": "2024-04-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "NSE script for checking the presence of CVE-2023-22515",
                    "summary": "NSE script for checking the presence of CVE-2023-22515",
                    "url": "https://github.com/fyx1t/NSE--CVE-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · s1d6point7bugcrowd/CVE-2023-22515-check",
                    "author": "s1d6point7bugcrowd",
                    "first_seen": "2024-06-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This script will inform the user if the Confluence instance is vulnerable, but it will not proceed with the exploitation steps.",
                    "summary": "This script will inform the user if the Confluence instance is vulnerable, but it will not proceed with the exploitation steps.",
                    "url": "https://github.com/s1d6point7bugcrowd/CVE-2023-22515-check"
                },
                {
                    "repository": "PoC-in-GitHub · xorbbo/cve-2023-22515",
                    "author": "xorbbo",
                    "first_seen": "2024-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "NSE script to check if app is vulnerable to cve-2023-22515",
                    "summary": "NSE script to check if app is vulnerable to cve-2023-22515",
                    "url": "https://github.com/xorbbo/cve-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · spareack/CVE-2023-22515-NSE",
                    "author": "spareack",
                    "first_seen": "2024-07-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Vulnerability checking tool via Nmap Scripting Engine",
                    "summary": "Vulnerability checking tool via Nmap Scripting Engine",
                    "url": "https://github.com/spareack/CVE-2023-22515-NSE"
                },
                {
                    "repository": "PoC-in-GitHub · Onedy1703/CVE-2023-22515-Confluence",
                    "author": "Onedy1703",
                    "first_seen": "2024-07-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE 2023-22515",
                    "summary": "CVE 2023-22515",
                    "url": "https://github.com/Onedy1703/CVE-2023-22515-Confluence"
                },
                {
                    "repository": "PoC-in-GitHub · killvxk/CVE-2023-22515-joaoviictorti",
                    "author": "killvxk",
                    "first_seen": "2024-11-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-22515 (Confluence Broken Access Control Exploit)",
                    "summary": "CVE-2023-22515 (Confluence Broken Access Control Exploit)",
                    "url": "https://github.com/killvxk/CVE-2023-22515-joaoviictorti"
                },
                {
                    "repository": "PoC-in-GitHub · vivigotnotime/CVE-2023-22515-Exploit-Script",
                    "author": "vivigotnotime",
                    "first_seen": "2025-02-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-22515 repository",
                    "summary": "",
                    "url": "https://github.com/vivigotnotime/CVE-2023-22515-Exploit-Script"
                },
                {
                    "repository": "PoC-in-GitHub · tranphuc2005/CVE-2023-22515",
                    "author": "tranphuc2005",
                    "first_seen": "2025-09-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-22515 repository",
                    "summary": "",
                    "url": "https://github.com/tranphuc2005/CVE-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · Arkha-Corvus/LetsDefend-SOC235-Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515-EventID-197",
                    "author": "Arkha-Corvus",
                    "first_seen": "2025-10-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "I was presented with a high-severity alert indicating a potential exploit attempt of CVE-2023-22515, a zero-day vulnerability in Atlassian Confluence. The alert showed a suspicious GET request from an external IP targeting the Confluence server, suggesting an attempt to gain unauthorised admin access.",
                    "summary": "I was presented with a high-severity alert indicating a potential exploit attempt of CVE-2023-22515, a zero-day vulnerability in Atlassian Confluence. The alert showed a suspicious GET request from an external IP targeting the Confluence server, suggesting an attempt to gain unauthorised admin access.",
                    "url": "https://github.com/Arkha-Corvus/LetsDefend-SOC235-Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515-EventID-197"
                },
                {
                    "repository": "PoC-in-GitHub · CyberSentinel321/cve-2023-22515-lab",
                    "author": "CyberSentinel321",
                    "first_seen": "2025-11-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Hands-on security lab demonstrating CVE-2023-22515 — Atlassian Confluence Authentication Bypass using a simulated vulnerable environment.",
                    "summary": "Hands-on security lab demonstrating CVE-2023-22515 — Atlassian Confluence Authentication Bypass using a simulated vulnerable environment.",
                    "url": "https://github.com/CyberSentinel321/cve-2023-22515-lab"
                },
                {
                    "repository": "PoC-in-GitHub · dkq-k/CVE-2023-22515",
                    "author": "dkq-k",
                    "first_seen": "2026-01-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-22515 repository",
                    "summary": "",
                    "url": "https://github.com/dkq-k/CVE-2023-22515"
                },
                {
                    "repository": "PoC-in-GitHub · dkq-k/cve-2023-22515-1",
                    "author": "dkq-k",
                    "first_seen": "2026-01-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-22515 repository",
                    "summary": "",
                    "url": "https://github.com/dkq-k/cve-2023-22515-1"
                },
                {
                    "repository": "PoC-in-GitHub · Borsch-Appreciator/SOC235---Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515",
                    "author": "Borsch-Appreciator",
                    "first_seen": "2026-07-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-22515 repository",
                    "summary": "",
                    "url": "https://github.com/Borsch-Appreciator/SOC235---Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-14T04:51:24+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "NSE--CVE-2023-22515 exploit",
                    "summary": "Exploit for CVE-2023-22515. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FYX1T-NSE--CVE-2023-22515"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DAVIDFORTYTWO-CVE-2023-22518",
                "https://kitploit.com/hi/tools/github/davidfortytwo/cve-2023-22518/",
                "https://github.com/ErikWynter/CVE-2023-22515-Scan",
                "https://github.com/j3seer/CVE-2023-22515-POC",
                "https://github.com/Chocapikk/CVE-2023-22515",
                "https://github.com/ad-calcium/CVE-2023-22515",
                "https://github.com/kh4sh3i/CVE-2023-22515",
                "https://github.com/s1incere/CVE-2023-22515",
                "https://github.com/Le1a/CVE-2023-22515",
                "https://github.com/Vulnmachines/confluence-cve-2023-22515",
                "https://github.com/iveresk/CVE-2023-22515",
                "https://github.com/youcannotseemeagain/CVE-2023-22515_RCE",
                "https://github.com/DsaHen/cve-2023-22515-exp",
                "https://github.com/C1ph3rX13/CVE-2023-22515",
                "https://github.com/AIex-3/confluence-hack",
                "https://github.com/LucasPDiniz/CVE-2023-22515",
                "https://github.com/aaaademo/Confluence-EvilJar",
                "https://github.com/edsonjt81/CVE-2023-22515-Scan.",
                "https://github.com/INTfinityConsulting/cve-2023-22515",
                "https://github.com/CalegariMindSec/Exploit-CVE-2023-22515",
                "https://github.com/rxerium/CVE-2023-22515",
                "https://github.com/fyx1t/NSE--CVE-2023-22515",
                "https://github.com/s1d6point7bugcrowd/CVE-2023-22515-check",
                "https://github.com/xorbbo/cve-2023-22515",
                "https://github.com/spareack/CVE-2023-22515-NSE",
                "https://github.com/Onedy1703/CVE-2023-22515-Confluence",
                "https://github.com/killvxk/CVE-2023-22515-joaoviictorti",
                "https://github.com/vivigotnotime/CVE-2023-22515-Exploit-Script",
                "https://github.com/tranphuc2005/CVE-2023-22515",
                "https://github.com/Arkha-Corvus/LetsDefend-SOC235-Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515-EventID-197",
                "https://github.com/CyberSentinel321/cve-2023-22515-lab",
                "https://github.com/dkq-k/CVE-2023-22515",
                "https://github.com/dkq-k/cve-2023-22515-1",
                "https://github.com/Borsch-Appreciator/SOC235---Atlassian-Confluence-Broken-Access-Control-0-Day-CVE-2023-22515",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FYX1T-NSE--CVE-2023-22515"
            ],
            "timeline": [
                {
                    "at": "2026-08-28T08:02:13Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2023-21768",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2023-21768",
            "summary": "CVE-2023-21768 vulnerability in tools with available proof of concept.",
            "updated_at": "2026-09-05T04:59:26Z",
            "published_at": "2026-09-05T04:59:26Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 495,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "CVE-2023-21768 vulnerability in tools with available proof of concept.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-21768",
                    "summary": "CVE-2023-21768 vulnerability in tools with available proof of concept.",
                    "what_happened": "CVE-2023-21768 vulnerability in tools with available proof of concept.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LEANDROFLEURY-CVE-2023-21768",
                        "https://kitploit.com/ar/tools/github/leandrofleury/cve-2023-21768/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T06:59:26",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LEANDROFLEURY-CVE-2023-21768"
                },
                {
                    "title": "Exploit for CVE-2023-21768",
                    "summary": "CVE-2023-21768 vulnerability in tools with available proof of concept.",
                    "what_happened": "CVE-2023-21768 vulnerability in tools with available proof of concept.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LEANDROFLEURY-CVE-2023-21768",
                        "https://kitploit.com/ar/tools/github/leandrofleury/cve-2023-21768/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-05T06:59:26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/leandrofleury/cve-2023-21768/"
                },
                {
                    "repository": "PoC-in-GitHub · chompie1337/Windows_LPE_AFD_CVE-2023-21768",
                    "author": "chompie1337",
                    "first_seen": "2023-03-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 505,
                    "title": "LPE exploit for CVE-2023-21768",
                    "summary": "LPE exploit for CVE-2023-21768",
                    "url": "https://github.com/chompie1337/Windows_LPE_AFD_CVE-2023-21768"
                },
                {
                    "repository": "PoC-in-GitHub · cl4ym0re/cve-2023-21768-compiled",
                    "author": "cl4ym0re",
                    "first_seen": "2023-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 27,
                    "title": "cve-2023-21768",
                    "summary": "cve-2023-21768",
                    "url": "https://github.com/cl4ym0re/cve-2023-21768-compiled"
                },
                {
                    "repository": "PoC-in-GitHub · SamuelTulach/nullmap",
                    "author": "SamuelTulach",
                    "first_seen": "2023-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 202,
                    "title": "Using CVE-2023-21768 to manual map kernel mode driver",
                    "summary": "Using CVE-2023-21768 to manual map kernel mode driver",
                    "url": "https://github.com/SamuelTulach/nullmap"
                },
                {
                    "repository": "PoC-in-GitHub · Malwareman007/CVE-2023-21768",
                    "author": "Malwareman007",
                    "first_seen": "2023-03-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 65,
                    "title": "Windows_AFD_LPE_CVE-2023-21768",
                    "summary": "Windows_AFD_LPE_CVE-2023-21768",
                    "url": "https://github.com/Malwareman007/CVE-2023-21768"
                },
                {
                    "repository": "PoC-in-GitHub · P4x1s/CVE-2023-21768-POC",
                    "author": "P4x1s",
                    "first_seen": "2023-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 23,
                    "title": "CVE-2023-21768 Windows 11 22H2 系统本地提权 POC",
                    "summary": "CVE-2023-21768 Windows 11 22H2 系统本地提权 POC",
                    "url": "https://github.com/P4x1s/CVE-2023-21768-POC"
                },
                {
                    "repository": "PoC-in-GitHub · h1bAna/CVE-2023-21768",
                    "author": "h1bAna",
                    "first_seen": "2023-04-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2023-21768 repository",
                    "summary": "",
                    "url": "https://github.com/h1bAna/CVE-2023-21768"
                },
                {
                    "repository": "PoC-in-GitHub · zoemurmure/CVE-2023-21768-AFD-for-WinSock-EoP-exploit",
                    "author": "zoemurmure",
                    "first_seen": "2023-04-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 15,
                    "title": "CVE-2023-21768 repository",
                    "summary": "",
                    "url": "https://github.com/zoemurmure/CVE-2023-21768-AFD-for-WinSock-EoP-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · ivanovick1/Windows_AFD_LPE_CVE-2023-21768",
                    "author": "ivanovick1",
                    "first_seen": "2023-08-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Windows 11 System Permission Elevation",
                    "summary": "Windows 11 System Permission Elevation",
                    "url": "https://github.com/ivanovick1/Windows_AFD_LPE_CVE-2023-21768"
                },
                {
                    "repository": "PoC-in-GitHub · Rosayxy/Recreate-cve-2023-21768",
                    "author": "Rosayxy",
                    "first_seen": "2023-10-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "recreating exp for cve-2023-21768.",
                    "summary": "recreating exp for cve-2023-21768.",
                    "url": "https://github.com/Rosayxy/Recreate-cve-2023-21768"
                },
                {
                    "repository": "PoC-in-GitHub · ldrx30/CVE-2023-21768",
                    "author": "ldrx30",
                    "first_seen": "2024-04-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-21768 Proof of Concept",
                    "summary": "CVE-2023-21768 Proof of Concept",
                    "url": "https://github.com/ldrx30/CVE-2023-21768"
                },
                {
                    "repository": "PoC-in-GitHub · xboxoneresearch/CVE-2023-21768-dotnet",
                    "author": "xboxoneresearch",
                    "first_seen": "2024-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 15,
                    "title": "C# / .NET version of CVE-2023-21768",
                    "summary": "C# / .NET version of CVE-2023-21768",
                    "url": "https://github.com/xboxoneresearch/CVE-2023-21768-dotnet"
                },
                {
                    "repository": "PoC-in-GitHub · IlanDudnik/CVE-2023-21768",
                    "author": "IlanDudnik",
                    "first_seen": "2024-12-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Exploit implementation with IO Rings for CVE-2023-21768",
                    "summary": "Exploit implementation with IO Rings for CVE-2023-21768",
                    "url": "https://github.com/IlanDudnik/CVE-2023-21768"
                },
                {
                    "repository": "PoC-in-GitHub · radoi-teodor/CVE-2023-21768-DSE-Bypass",
                    "author": "radoi-teodor",
                    "first_seen": "2025-08-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-21768 repository",
                    "summary": "",
                    "url": "https://github.com/radoi-teodor/CVE-2023-21768-DSE-Bypass"
                },
                {
                    "repository": "PoC-in-GitHub · leandrofleury/CVE-2023-21768",
                    "author": "leandrofleury",
                    "first_seen": "2026-06-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-21768 repository",
                    "summary": "",
                    "url": "https://github.com/leandrofleury/CVE-2023-21768"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LEANDROFLEURY-CVE-2023-21768",
                "https://kitploit.com/ar/tools/github/leandrofleury/cve-2023-21768/",
                "https://github.com/chompie1337/Windows_LPE_AFD_CVE-2023-21768",
                "https://github.com/cl4ym0re/cve-2023-21768-compiled",
                "https://github.com/SamuelTulach/nullmap",
                "https://github.com/Malwareman007/CVE-2023-21768",
                "https://github.com/P4x1s/CVE-2023-21768-POC",
                "https://github.com/h1bAna/CVE-2023-21768",
                "https://github.com/zoemurmure/CVE-2023-21768-AFD-for-WinSock-EoP-exploit",
                "https://github.com/ivanovick1/Windows_AFD_LPE_CVE-2023-21768",
                "https://github.com/Rosayxy/Recreate-cve-2023-21768",
                "https://github.com/ldrx30/CVE-2023-21768",
                "https://github.com/xboxoneresearch/CVE-2023-21768-dotnet",
                "https://github.com/IlanDudnik/CVE-2023-21768",
                "https://github.com/radoi-teodor/CVE-2023-21768-DSE-Bypass",
                "https://github.com/leandrofleury/CVE-2023-21768"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T04:59:26Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LEANDROFLEURY-CVE-2023-21768"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2023-20944",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "frameworks_base_CVE-2023-20944 exploit",
            "summary": "Exploit for CVE-2023-20944. CVSS 7.8.",
            "updated_at": "2026-09-07T19:21:17Z",
            "published_at": "2026-09-07T19:21:17Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 67,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "CVE-2023-20944 in frameworks_base tools component.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for frameworks_base_CVE-2023-20944",
                    "summary": "CVE-2023-20944 in frameworks_base tools component.",
                    "what_happened": "CVE-2023-20944 in frameworks_base tools component.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TRINADH465-FRAMEWORKS_BASE_CVE-2023-20944",
                        "https://kitploit.com/ar/tools/github/trinadh465/frameworks_base_cve-2023-20944/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T23:46:58",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TRINADH465-FRAMEWORKS_BASE_CVE-2023-20944"
                },
                {
                    "title": "Exploit for frameworks_base_CVE-2023-20944",
                    "summary": "CVE-2023-20944 in frameworks_base tools component.",
                    "what_happened": "CVE-2023-20944 in frameworks_base tools component.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TRINADH465-FRAMEWORKS_BASE_CVE-2023-20944",
                        "https://kitploit.com/ar/tools/github/trinadh465/frameworks_base_cve-2023-20944/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-05T23:46:58",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/trinadh465/frameworks_base_cve-2023-20944/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TRINADH465-FRAMEWORKS_BASE_CVE-2023-20944",
                "https://kitploit.com/ar/tools/github/trinadh465/frameworks_base_cve-2023-20944/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:21:17Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TRINADH465-FRAMEWORKS_BASE_CVE-2023-20944"
                }
            ]
        },
        {
            "id": "CVE-2023-7028",
            "vendor": "GitLab",
            "product": "GitLab CE/EE",
            "title": "GitLab Community and Enterprise Editions Improper Access Control Vulnerability",
            "summary": "GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.",
            "updated_at": "2026-09-05T22:00:00Z",
            "published_at": "2026-09-05T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 837,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 51889",
                    "author": "0xB455",
                    "first_seen": "2024-03-14",
                    "confidence": "High",
                    "title": "GitLab CE/EE < 16.7.2 - Password Reset",
                    "summary": "GitLab CE/EE < 16.7.2 - Password Reset",
                    "url": "https://www.exploit-db.com/exploits/51889",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · RandomRobbieBF/CVE-2023-7028",
                    "author": "RandomRobbieBF",
                    "first_seen": "2024-01-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 58,
                    "title": "CVE-2023-7028",
                    "summary": "CVE-2023-7028",
                    "url": "https://github.com/RandomRobbieBF/CVE-2023-7028"
                },
                {
                    "repository": "PoC-in-GitHub · googlei1996/CVE-2023-7028",
                    "author": "googlei1996",
                    "first_seen": "2024-01-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-7028 poc",
                    "summary": "CVE-2023-7028 poc",
                    "url": "https://github.com/googlei1996/CVE-2023-7028"
                },
                {
                    "repository": "PoC-in-GitHub · duy-31/CVE-2023-7028",
                    "author": "duy-31",
                    "first_seen": "2024-01-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.",
                    "summary": "An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.",
                    "url": "https://github.com/duy-31/CVE-2023-7028"
                },
                {
                    "repository": "PoC-in-GitHub · Vozec/CVE-2023-7028",
                    "author": "Vozec",
                    "first_seen": "2024-01-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 245,
                    "title": "This repository presents a proof-of-concept of CVE-2023-7028",
                    "summary": "This repository presents a proof-of-concept of CVE-2023-7028",
                    "url": "https://github.com/Vozec/CVE-2023-7028"
                },
                {
                    "repository": "PoC-in-GitHub · yoryio/CVE-2023-7028",
                    "author": "yoryio",
                    "first_seen": "2024-01-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit for CVE-2023-7028 - GitLab CE/EE",
                    "summary": "Exploit for CVE-2023-7028 - GitLab CE/EE",
                    "url": "https://github.com/yoryio/CVE-2023-7028"
                },
                {
                    "repository": "PoC-in-GitHub · Esonhugh/gitlab_honeypot",
                    "author": "Esonhugh",
                    "first_seen": "2024-01-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2023-7028 killer",
                    "summary": "CVE-2023-7028 killer",
                    "url": "https://github.com/Esonhugh/gitlab_honeypot"
                },
                {
                    "repository": "PoC-in-GitHub · Shimon03/CVE-2023-7028-Account-Take-Over-Gitlab",
                    "author": "Shimon03",
                    "first_seen": "2024-01-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-7028 repository",
                    "summary": "",
                    "url": "https://github.com/Shimon03/CVE-2023-7028-Account-Take-Over-Gitlab"
                },
                {
                    "repository": "PoC-in-GitHub · thanhlam-attt/CVE-2023-7028",
                    "author": "thanhlam-attt",
                    "first_seen": "2024-01-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2023-7028 repository",
                    "summary": "",
                    "url": "https://github.com/thanhlam-attt/CVE-2023-7028"
                },
                {
                    "repository": "PoC-in-GitHub · Trackflaw/CVE-2023-7028-Docker",
                    "author": "Trackflaw",
                    "first_seen": "2024-01-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Repository to install CVE-2023-7028 vulnerable Gitlab instance",
                    "summary": "Repository to install CVE-2023-7028 vulnerable Gitlab instance",
                    "url": "https://github.com/Trackflaw/CVE-2023-7028-Docker"
                },
                {
                    "repository": "PoC-in-GitHub · mochammadrafi/CVE-2023-7028",
                    "author": "mochammadrafi",
                    "first_seen": "2024-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Python Code for Exploit Automation CVE-2023-7028",
                    "summary": "Python Code for Exploit Automation CVE-2023-7028",
                    "url": "https://github.com/mochammadrafi/CVE-2023-7028"
                },
                {
                    "repository": "PoC-in-GitHub · hackeremmen/gitlab-exploit",
                    "author": "hackeremmen",
                    "first_seen": "2024-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "GitLab CVE-2023-7028",
                    "summary": "GitLab CVE-2023-7028",
                    "url": "https://github.com/hackeremmen/gitlab-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · soltanali0/CVE-2023-7028",
                    "author": "soltanali0",
                    "first_seen": "2024-07-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Implementation and exploitation of CVE-2023-7028 account takeover vulnerability related to GO-TO CVE weekly articles of the 11th week.",
                    "summary": "Implementation and exploitation of CVE-2023-7028 account takeover vulnerability related to GO-TO CVE weekly articles of the 11th week.",
                    "url": "https://github.com/soltanali0/CVE-2023-7028"
                },
                {
                    "repository": "PoC-in-GitHub · gh-ost00/CVE-2023-7028",
                    "author": "gh-ost00",
                    "first_seen": "2024-08-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2023-7028 POC && Exploit",
                    "summary": "CVE-2023-7028 POC && Exploit",
                    "url": "https://github.com/gh-ost00/CVE-2023-7028"
                },
                {
                    "repository": "PoC-in-GitHub · sariamubeen/CVE-2023-7028",
                    "author": "sariamubeen",
                    "first_seen": "2025-02-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2023-7028 repository",
                    "summary": "",
                    "url": "https://github.com/sariamubeen/CVE-2023-7028"
                },
                {
                    "repository": "PoC-in-GitHub · Sornphut/CVE-2023-7028-GitLab",
                    "author": "Sornphut",
                    "first_seen": "2025-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-7028 repository",
                    "summary": "",
                    "url": "https://github.com/Sornphut/CVE-2023-7028-GitLab"
                },
                {
                    "repository": "PoC-in-GitHub · szybnev/CVE-2023-7028",
                    "author": "szybnev",
                    "first_seen": "2025-07-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This FORK of repository presents a proof-of-concept of CVE-2023-7028. I am only improve exploit usage",
                    "summary": "This FORK of repository presents a proof-of-concept of CVE-2023-7028. I am only improve exploit usage",
                    "url": "https://github.com/szybnev/CVE-2023-7028"
                },
                {
                    "repository": "PoC-in-GitHub · KameliaZaman/Exploiting-GitLab-CVE-2023-7028",
                    "author": "KameliaZaman",
                    "first_seen": "2025-08-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Penetration test targeting CVE-2023-7028",
                    "summary": "Penetration test targeting CVE-2023-7028",
                    "url": "https://github.com/KameliaZaman/Exploiting-GitLab-CVE-2023-7028"
                },
                {
                    "repository": "PoC-in-GitHub · FearThePLOTO/GitLab-CVE-2023-7028",
                    "author": "FearThePLOTO",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A mock app for the GitLab CVE-2023-7028, which allow multile email adresses when ordering a password reset.",
                    "summary": "A mock app for the GitLab CVE-2023-7028, which allow multile email adresses when ordering a password reset.",
                    "url": "https://github.com/FearThePLOTO/GitLab-CVE-2023-7028"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/51889",
                "https://github.com/RandomRobbieBF/CVE-2023-7028",
                "https://github.com/googlei1996/CVE-2023-7028",
                "https://github.com/duy-31/CVE-2023-7028",
                "https://github.com/Vozec/CVE-2023-7028",
                "https://github.com/yoryio/CVE-2023-7028",
                "https://github.com/Esonhugh/gitlab_honeypot",
                "https://github.com/Shimon03/CVE-2023-7028-Account-Take-Over-Gitlab",
                "https://github.com/thanhlam-attt/CVE-2023-7028",
                "https://github.com/Trackflaw/CVE-2023-7028-Docker",
                "https://github.com/mochammadrafi/CVE-2023-7028",
                "https://github.com/hackeremmen/gitlab-exploit",
                "https://github.com/soltanali0/CVE-2023-7028",
                "https://github.com/gh-ost00/CVE-2023-7028",
                "https://github.com/sariamubeen/CVE-2023-7028",
                "https://github.com/Sornphut/CVE-2023-7028-GitLab",
                "https://github.com/szybnev/CVE-2023-7028",
                "https://github.com/KameliaZaman/Exploiting-GitLab-CVE-2023-7028",
                "https://github.com/FearThePLOTO/GitLab-CVE-2023-7028"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2023-6717",
            "vendor": "Red Hat",
            "product": "Red Hat AMQ Broker 7",
            "title": "Red Hat AMQ Broker 7 vulnerability",
            "summary": "A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This issue may allow a malicious admin in one realm or a client with registration access to target users in different realms or applications, executing arbitrary JavaScript in their contexts upon form submission. This can enable unauthorized access and harmful actions, compromising the confidentiality, integrity, and availability of the complete KC instance.",
            "updated_at": "2026-09-11T02:18:31.073",
            "published_at": "2024-04-25T16:15:10.653",
            "cvss": 6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 22.0.10 (maven); 24.0.0 through before 24.0.3 (maven)",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "High",
            "cwe": "CWE-79",
            "what_happened": "A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This issue may allow a malicious admin in one realm or a client with registration access to target users in different realms or applications, executing arbitrary JavaScript in their contexts upon form submission. This can enable unauthorized access and harmful actions, compromising the confidentiality, integrity, and availability of the complete KC instance.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2024:1353",
                "https://access.redhat.com/errata/RHSA-2024:1867",
                "https://access.redhat.com/errata/RHSA-2024:1868",
                "https://access.redhat.com/errata/RHSA-2024:2945",
                "https://access.redhat.com/errata/RHSA-2024:4057",
                "https://access.redhat.com/security/cve/CVE-2023-6717",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2253952"
            ],
            "timeline": [
                {
                    "at": "2024-04-25T16:15:10.653",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6717"
                }
            ]
        },
        {
            "id": "CVE-2023-6572",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Security-research lab reproducing CVE-2023-6572 (GHSA-gqvf-3hgp-5hxv): command injection in gradio-app/gradio's workflow_run handling of generate-changeset.yml",
            "summary": "Security-research lab reproducing CVE-2023-6572 (GHSA-gqvf-3hgp-5hxv): command injection in gradio-app/gradio's workflow_run handling of generate-changeset.yml",
            "updated_at": "2026-08-30T22:00:00Z",
            "published_at": "2026-08-30T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 36,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · pvharmo2/gha-lab-6255f5fc33",
                    "author": "pvharmo2",
                    "first_seen": "2026-08-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Security-research lab reproducing CVE-2023-6572 (GHSA-gqvf-3hgp-5hxv): command injection in gradio-app/gradio's workflow_run handling of generate-changeset.yml",
                    "summary": "Security-research lab reproducing CVE-2023-6572 (GHSA-gqvf-3hgp-5hxv): command injection in gradio-app/gradio's workflow_run handling of generate-changeset.yml",
                    "url": "https://github.com/pvharmo2/gha-lab-6255f5fc33"
                }
            ],
            "references": [
                "https://github.com/pvharmo2/gha-lab-6255f5fc33"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/pvharmo2/gha-lab-6255f5fc33"
                }
            ]
        },
        {
            "id": "CVE-2023-5685",
            "vendor": "Red Hat",
            "product": "Red Hat build of Apache Camel 4.4.0 for Spring Boot",
            "title": "Red Hat build of Apache Camel 4.4.0 for Spring Boot vulnerability",
            "summary": "A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).",
            "updated_at": "2026-09-14T20:16:36.733",
            "published_at": "2024-03-22T19:15:07.983",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "See vendor advisory",
            "fixed": "See vendor advisory",
            "source_count": 16,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large can lead to uncontrolled resource management and a possible denial of service (DoS).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/errata/RHSA-2023:7637",
                "https://access.redhat.com/errata/RHSA-2023:7638",
                "https://access.redhat.com/errata/RHSA-2023:7639",
                "https://access.redhat.com/errata/RHSA-2023:7641",
                "https://access.redhat.com/errata/RHSA-2024:10207",
                "https://access.redhat.com/errata/RHSA-2024:10208",
                "https://access.redhat.com/errata/RHSA-2024:2707",
                "https://access.redhat.com/security/cve/CVE-2023-5685",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2241822"
            ],
            "timeline": [
                {
                    "at": "2024-03-22T19:15:07.983",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5685"
                }
            ]
        },
        {
            "id": "CVE-2023-5578",
            "vendor": "Portábilis",
            "product": "i-Educar",
            "title": "i-Educar vulnerability",
            "summary": "A vulnerability was detected in Portábilis i-Educar up to 2.7.5. Affected is an unknown function of the file \\intranet\\agenda_imprimir.php of the component HTTP GET Request Handler. The manipulation of the argument cod_agenda with the input \");'> <script>alert(document.cookie)</script> results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading the affected component is recommended. The vendor explains: \"This endpoint and the associated functionality are no longer present in the current i-Educar codebase, as the affected area was removed from the product. As a result, the previously reported attack vector (...) is no longer applicable to versions in which this functionality has been removed.\"",
            "updated_at": "2026-09-15T03:17:03.637",
            "published_at": "2023-10-14T11:15:45.800",
            "cvss": 2,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "2.7.0; 2.7.1; 2.7.2; 2.7.3; 2.7.4; 2.7.5",
            "fixed": "See vendor advisory",
            "source_count": 8,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-79",
            "what_happened": "A vulnerability was detected in Portábilis i-Educar up to 2.7.5. Affected is an unknown function of the file \\intranet\\agenda_imprimir.php of the component HTTP GET Request Handler. The manipulation of the argument cod_agenda with the input \");'> <script>alert(document.cookie)</script> results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. Upgrading the affected component is recommended. The vendor explains: \"This endpoint and the associated functionality are no longer present in the current i-Educar codebase, as the affected area was removed from the product. As a result, the previously reported attack vector (...) is no longer applicable to versions in which this functionality has been removed.\"",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/portabilis/i-educar",
                "https://vuldb.com/cve/CVE-2023-5578",
                "https://vuldb.com/submit/217053",
                "https://vuldb.com/submit/649873",
                "https://vuldb.com/vuln/242143",
                "https://vuldb.com/vuln/242143/cti",
                "https://vuldb.com/?ctiid.242143",
                "https://vuldb.com/?id.242143"
            ],
            "timeline": [
                {
                    "at": "2023-10-14T11:15:45.800",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5578"
                }
            ]
        },
        {
            "id": "CVE-2023-4966",
            "vendor": "Citrix",
            "product": "NetScaler ADC and NetScaler Gateway",
            "title": "Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability",
            "summary": "Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.",
            "updated_at": "2026-09-04T21:50:58Z",
            "published_at": "2026-09-04T21:50:58Z",
            "cvss": 9.4,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 100,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for citrix-logchecker CVE-2023-4966",
                    "summary": "Perl script to parse Citrix Netscaler logs for signs of CVE-2023-4966 exploitation.",
                    "what_happened": "Perl script to parse Citrix Netscaler logs for signs of CVE-2023-4966 exploitation.",
                    "cvss": 9.4,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CERTAT-CITRIX-LOGCHECKER",
                        "https://kitploit.com/zh/tools/github/certat/citrix-logchecker/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T23:50:58",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CERTAT-CITRIX-LOGCHECKER"
                },
                {
                    "title": "Exploit for citrix-logchecker CVE-2023-4966",
                    "summary": "Perl script to parse Citrix Netscaler logs for signs of CVE-2023-4966 exploitation.",
                    "what_happened": "Perl script to parse Citrix Netscaler logs for signs of CVE-2023-4966 exploitation.",
                    "cvss": 9.4,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CERTAT-CITRIX-LOGCHECKER",
                        "https://kitploit.com/zh/tools/github/certat/citrix-logchecker/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-04T23:50:58",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/certat/citrix-logchecker/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CERTAT-CITRIX-LOGCHECKER",
                "https://kitploit.com/zh/tools/github/certat/citrix-logchecker/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T21:50:58Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-10-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"
        },
        {
            "id": "CVE-2023-4622",
            "vendor": "Linux",
            "product": "Kernel",
            "title": "Kernel vulnerability",
            "summary": "A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation.\n\nThe unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collection, resulting in use-after-free.\n\nWe recommend upgrading past commit 790c2f9d15b594350ae9bca7b236f2b1859de02c.",
            "updated_at": "2026-09-11T16:12:18.457",
            "published_at": "2023-09-06T14:15:12.193",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.2 through before 6.1.47 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation.\n\nThe unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there is a race where unix_stream_sendpage() could access an skb locklessly that is being released by garbage collection, resulting in use-after-free.\n\nWe recommend upgrading past commit 790c2f9d15b594350ae9bca7b236f2b1859de02c.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "http://packetstormsecurity.com/files/175963/Kernel-Live-Patch-Security-Notice-LSN-0099-1.html",
                "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=linux-6.1.y&id=790c2f9d15b594350ae9bca7b236f2b1859de02c",
                "https://kernel.dance/790c2f9d15b594350ae9bca7b236f2b1859de02c",
                "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html",
                "https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html",
                "https://www.debian.org/security/2023/dsa-5492"
            ],
            "timeline": [
                {
                    "at": "2023-09-06T14:15:12.193",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4622"
                }
            ]
        },
        {
            "id": "CVE-2023-4611",
            "vendor": "n/a",
            "product": "Kernel",
            "title": "Kernel vulnerability",
            "summary": "A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel information leak.",
            "updated_at": "2026-09-11T16:15:24.103",
            "published_at": "2023-08-29T22:15:09.397",
            "cvss": 7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "6.4 through before 6.4.8",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-416",
            "what_happened": "A use-after-free flaw was found in mm/mempolicy.c in the memory management subsystem in the Linux Kernel. This issue is caused by a race between mbind() and VMA-locked page fault, and may allow a local attacker to crash the system or lead to a kernel information leak.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/security/cve/CVE-2023-4611",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2227244",
                "https://www.spinics.net/lists/stable-commits/msg310136.html"
            ],
            "timeline": [
                {
                    "at": "2023-08-29T22:15:09.397",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-4611"
                }
            ]
        },
        {
            "id": "CVE-2023-4596",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2023-4596-OpenSSH-Multi-Checker exploit",
            "summary": "Exploit for CVE-2023-4596 and CVE-2024-6387. CVSS 9.8.",
            "updated_at": "2026-09-06T08:32:51Z",
            "published_at": "2026-09-06T08:32:51Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 85,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Multi-target OpenSSH version checker script for CVE-2024-6387 using nmap banner scanning.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-4596-OpenSSH-Multi-Checker CVE-2023-4596 CVE-2024-6387",
                    "summary": "Multi-target OpenSSH version checker script for CVE-2024-6387 using nmap banner scanning.",
                    "what_happened": "Multi-target OpenSSH version checker script for CVE-2024-6387 using nmap banner scanning.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-PROJETION-CVE-2023-4596-OPENSSH-MULTI-CHECKER",
                        "https://kitploit.com/ru/tools/github/x-projetion/cve-2023-4596-openssh-multi-checker/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-02T13:01:51",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-PROJETION-CVE-2023-4596-OPENSSH-MULTI-CHECKER"
                },
                {
                    "title": "Exploit for CVE-2023-4596-OpenSSH-Multi-Checker CVE-2023-4596 CVE-2024-6387",
                    "summary": "Multi-target OpenSSH version checker script for CVE-2024-6387 using nmap banner scanning.",
                    "what_happened": "Multi-target OpenSSH version checker script for CVE-2024-6387 using nmap banner scanning.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-PROJETION-CVE-2023-4596-OPENSSH-MULTI-CHECKER",
                        "https://kitploit.com/ru/tools/github/x-projetion/cve-2023-4596-openssh-multi-checker/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-02T13:01:51",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/x-projetion/cve-2023-4596-openssh-multi-checker/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-PROJETION-CVE-2023-4596-OPENSSH-MULTI-CHECKER",
                "https://kitploit.com/ru/tools/github/x-projetion/cve-2023-4596-openssh-multi-checker/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:32:51Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X-PROJETION-CVE-2023-4596-OPENSSH-MULTI-CHECKER"
                }
            ]
        },
        {
            "id": "CVE-2023-4346",
            "vendor": "KNX Association",
            "product": "KNX Protocol Connection Authorization Option 1",
            "title": "KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability",
            "summary": "KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.",
            "updated_at": "2026-07-14T22:00:00Z",
            "published_at": "2026-07-14T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-07-14T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2023-3635",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2023-3635 repository",
            "summary": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "updated_at": "2026-08-24T22:00:00Z",
            "published_at": "2026-08-24T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 25,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · JoshuaASmith/reproducer-okio-cve-2023-3635",
                    "author": "JoshuaASmith",
                    "first_seen": "2026-08-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-3635 repository",
                    "summary": "",
                    "url": "https://github.com/JoshuaASmith/reproducer-okio-cve-2023-3635"
                }
            ],
            "references": [
                "https://github.com/JoshuaASmith/reproducer-okio-cve-2023-3635"
            ],
            "timeline": [
                {
                    "at": "2026-08-24T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/JoshuaASmith/reproducer-okio-cve-2023-3635"
                }
            ]
        },
        {
            "id": "CVE-2023-3609",
            "vendor": "Linux",
            "product": "Kernel",
            "title": "Kernel vulnerability",
            "summary": "A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation.\n\n\n\nIf tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.\n\n\n\nWe recommend upgrading past commit 04c55383fa5689357bcdd2c8036725a55ed632bc.",
            "updated_at": "2026-09-11T16:16:30.007",
            "published_at": "2023-07-21T21:15:11.743",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.14.0 through before 4.14.322 (semver); 4.15.0 through before 4.19.291 (semver); 4.20.0 through before 5.4.248 (semver); 5.5.0 through before 5.10.185 (semver); 5.11.0 through before 5.15.118 (semver); 5.16.0 through before 6.1.35 (semver); 6.2.0 through before 6.3.9 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 16,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation.\n\n\n\nIf tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability.\n\n\n\nWe recommend upgrading past commit 04c55383fa5689357bcdd2c8036725a55ed632bc.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "http://packetstormsecurity.com/files/175072/Kernel-Live-Patch-Security-Notice-LSN-0098-1.html",
                "http://packetstormsecurity.com/files/175963/Kernel-Live-Patch-Security-Notice-LSN-0099-1.html",
                "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=04c55383fa5689357bcdd2c8036725a55ed632bc",
                "https://kernel.dance/04c55383fa5689357bcdd2c8036725a55ed632bc",
                "https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html",
                "https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html",
                "https://security.netapp.com/advisory/ntap-20230818-0005/",
                "https://www.debian.org/security/2023/dsa-5480"
            ],
            "timeline": [
                {
                    "at": "2023-07-21T21:15:11.743",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3609"
                }
            ]
        },
        {
            "id": "CVE-2023-2822",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2023-2822-demo exploit",
            "summary": "Exploit for CVE-2023-2822. CVSS 6.1.",
            "updated_at": "2026-09-11T18:33:44Z",
            "published_at": "2026-09-11T18:33:44Z",
            "cvss": 6.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 39,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Reflected XSS in Ellucian Ethos Identity CAS logout page via crafted input.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-2822-demo",
                    "summary": "Reflected XSS in Ellucian Ethos Identity CAS logout page via crafted input.",
                    "what_happened": "Reflected XSS in Ellucian Ethos Identity CAS logout page via crafted input.",
                    "cvss": 6.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CBERMAN-CVE-2023-2822-DEMO",
                        "https://kitploit.com/ru/tools/github/cberman/cve-2023-2822-demo/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T14:58:16",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CBERMAN-CVE-2023-2822-DEMO"
                },
                {
                    "title": "Exploit for CVE-2023-2822-demo",
                    "summary": "Reflected XSS in Ellucian Ethos Identity CAS logout page via crafted input.",
                    "what_happened": "Reflected XSS in Ellucian Ethos Identity CAS logout page via crafted input.",
                    "cvss": 6.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CBERMAN-CVE-2023-2822-DEMO",
                        "https://kitploit.com/ru/tools/github/cberman/cve-2023-2822-demo/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T14:58:16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/cberman/cve-2023-2822-demo/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CBERMAN-CVE-2023-2822-DEMO",
                "https://kitploit.com/ru/tools/github/cberman/cve-2023-2822-demo/"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T18:33:44Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CBERMAN-CVE-2023-2822-DEMO"
                }
            ]
        },
        {
            "id": "CVE-2023-2640",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for PHP-CVE-2023-2023-2640-POC-Escalation CVE-2023-2023 CVE-2023-2640 CVE-2023-32629",
            "summary": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
            "updated_at": "2026-09-06T18:11:35Z",
            "published_at": "2026-09-06T18:11:35Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 65,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for PHP-CVE-2023-2023-2640-POC-Escalation CVE-2023-2023 CVE-2023-2640 CVE-2023-32629",
                    "summary": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
                    "what_happened": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION",
                        "https://kitploit.com/hi/tools/github/druxter-x/php-cve-2023-2023-2640-poc-escalation/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T20:11:35",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION"
                },
                {
                    "title": "Exploit for PHP-CVE-2023-2023-2640-POC-Escalation CVE-2023-2023 CVE-2023-2640 CVE-2023-32629",
                    "summary": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
                    "what_happened": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION",
                        "https://kitploit.com/hi/tools/github/druxter-x/php-cve-2023-2023-2640-poc-escalation/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T20:11:35",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/druxter-x/php-cve-2023-2023-2640-poc-escalation/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION",
                "https://kitploit.com/hi/tools/github/druxter-x/php-cve-2023-2023-2640-poc-escalation/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T18:11:35Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2023-2023",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for PHP-CVE-2023-2023-2640-POC-Escalation CVE-2023-2023 CVE-2023-2640 CVE-2023-32629",
            "summary": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
            "updated_at": "2026-09-06T18:11:35Z",
            "published_at": "2026-09-06T18:11:35Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 65,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for PHP-CVE-2023-2023-2640-POC-Escalation CVE-2023-2023 CVE-2023-2640 CVE-2023-32629",
                    "summary": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
                    "what_happened": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION",
                        "https://kitploit.com/hi/tools/github/druxter-x/php-cve-2023-2023-2640-poc-escalation/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T20:11:35",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION"
                },
                {
                    "title": "Exploit for PHP-CVE-2023-2023-2640-POC-Escalation CVE-2023-2023 CVE-2023-2640 CVE-2023-32629",
                    "summary": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
                    "what_happened": "PHP privilege escalation POC combining CVE-2023-2640 and CVE-2023-32629 in a single script.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION",
                        "https://kitploit.com/hi/tools/github/druxter-x/php-cve-2023-2023-2640-poc-escalation/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T20:11:35",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/druxter-x/php-cve-2023-2023-2640-poc-escalation/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION",
                "https://kitploit.com/hi/tools/github/druxter-x/php-cve-2023-2023-2640-poc-escalation/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T18:11:35Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRUXTER-X-PHP-CVE-2023-2023-2640-POC-ESCALATION"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2023-1326",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "A proof of concept for CVE-2023–1326 in apport-cli 2.26.0",
            "summary": "A proof of concept for CVE-2023–1326 in apport-cli 2.26.0",
            "updated_at": "2026-09-11T22:00:00Z",
            "published_at": "2026-09-11T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 91,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · diego-tella/CVE-2023-1326-PoC",
                    "author": "diego-tella",
                    "first_seen": "2023-12-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 21,
                    "title": "A proof of concept for CVE-2023–1326 in apport-cli 2.26.0",
                    "summary": "A proof of concept for CVE-2023–1326 in apport-cli 2.26.0",
                    "url": "https://github.com/diego-tella/CVE-2023-1326-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · Pol-Ruiz/CVE-2023-1326",
                    "author": "Pol-Ruiz",
                    "first_seen": "2024-01-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Esto es una prueba de concepto propia i basica de la vulneravilidad CVE-2023-1326",
                    "summary": "Esto es una prueba de concepto propia i basica de la vulneravilidad CVE-2023-1326",
                    "url": "https://github.com/Pol-Ruiz/CVE-2023-1326"
                },
                {
                    "repository": "PoC-in-GitHub · h3x0v3rl0rd/CVE-2023-1326",
                    "author": "h3x0v3rl0rd",
                    "first_seen": "2024-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2023-1326 repository",
                    "summary": "",
                    "url": "https://github.com/h3x0v3rl0rd/CVE-2023-1326"
                },
                {
                    "repository": "PoC-in-GitHub · cve-2024/CVE-2023-1326-PoC",
                    "author": "cve-2024",
                    "first_seen": "2024-06-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2023-1326 repository",
                    "summary": "",
                    "url": "https://github.com/cve-2024/CVE-2023-1326-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · R3fr4kt/DEVVORTEX",
                    "author": "R3fr4kt",
                    "first_seen": "2026-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A comprehensive technical walkthrough detailing the compromise of the Devvortex machine on HackTheBox. This path demonstrates Subdomain Fuzzing, Joomla API Enumeration, Template Modification for initial access, Database Hash Extraction & Cracking for lateral movement, and exploitation of Apport-CLI (CVE-2023-1326) for privilege escalation to root.",
                    "summary": "A comprehensive technical walkthrough detailing the compromise of the Devvortex machine on HackTheBox. This path demonstrates Subdomain Fuzzing, Joomla API Enumeration, Template Modification for initial access, Database Hash Extraction & Cracking for lateral movement, and exploitation of Apport-CLI (CVE-2023-1326) for privilege escalation to root.",
                    "url": "https://github.com/R3fr4kt/DEVVORTEX"
                }
            ],
            "references": [
                "https://github.com/diego-tella/CVE-2023-1326-PoC",
                "https://github.com/Pol-Ruiz/CVE-2023-1326",
                "https://github.com/h3x0v3rl0rd/CVE-2023-1326",
                "https://github.com/cve-2024/CVE-2023-1326-PoC",
                "https://github.com/R3fr4kt/DEVVORTEX"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/diego-tella/CVE-2023-1326-PoC"
                }
            ]
        },
        {
            "id": "CVE-2022-51009",
            "vendor": "pmmp",
            "product": "PocketMine-MP",
            "title": "PocketMine-MP vulnerability",
            "summary": "PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash.",
            "updated_at": "2026-09-06T13:17:10.307",
            "published_at": "2026-09-06T12:17:15.073",
            "cvss": 8.7,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.7.2 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-248",
            "what_happened": "PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pmmp/PocketMine-MP/commit/c9626c610b8f6810c8c987559c9197b2a291f0bb",
                "https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-8cwq-4cmf-px73",
                "https://www.vulncheck.com/advisories/pocketmine-mp-before-4.7.2-denial-of-service-via-skin-geometry"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:15.073",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-51009"
                }
            ]
        },
        {
            "id": "CVE-2022-51008",
            "vendor": "pmmp",
            "product": "PocketMine-MP",
            "title": "PocketMine-MP vulnerability",
            "summary": "PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers can flood the server with unauthenticated connections that occupy max-player slots, preventing legitimate players from joining.",
            "updated_at": "2026-09-06T13:17:10.203",
            "published_at": "2026-09-06T12:17:14.930",
            "cvss": 6.9,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "4.0.0 through before 4.12.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-770",
            "what_happened": "PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers can flood the server with unauthenticated connections that occupy max-player slots, preventing legitimate players from joining.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pmmp/PocketMine-MP/commit/59be901efe6b7833e69e638e0e1497051ce96fa7",
                "https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-474q-9hgp-hcvx",
                "https://www.vulncheck.com/advisories/pocketmine-mp-before-4.12.3-denial-of-service-via-unauthenticated-sessions"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:14.930",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-51008"
                }
            ]
        },
        {
            "id": "CVE-2022-48650",
            "vendor": "Linux",
            "product": "Linux",
            "title": "Linux vulnerability",
            "summary": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix memory leak in __qlt_24xx_handle_abts()\n\nCommit 8f394da36a36 (\"scsi: qla2xxx: Drop TARGET_SCF_LOOKUP_LUN_FROM_TAG\")\nmade the __qlt_24xx_handle_abts() function return early if\ntcm_qla2xxx_find_cmd_by_tag() didn't find a command, but it missed to clean\nup the allocated memory for the management command.",
            "updated_at": "2026-09-14T12:17:31.540",
            "published_at": "2024-04-28T13:15:07.380",
            "cvss": 4.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "1c5bf7c529d95755f32b8ef449d10df2d50aaf5a through before 29a22a3d495c147117137719d2c39045c44ccebf (git); 8f394da36a361cbe0e1e8b1d4213e5598c8095ac through before 89df49e561b4a8948521fc3f8a013012eaa08f82 (git); 8f394da36a361cbe0e1e8b1d4213e5598c8095ac through before 6a4236ed47f5b0a57eb6b8fb1c351b15b3d341d7 (git); 8f394da36a361cbe0e1e8b1d4213e5598c8095ac through before 601be20fc6a1b762044d2398befffd6bf236cebf (git); 5.11",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-401",
            "what_happened": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix memory leak in __qlt_24xx_handle_abts()\n\nCommit 8f394da36a36 (\"scsi: qla2xxx: Drop TARGET_SCF_LOOKUP_LUN_FROM_TAG\")\nmade the __qlt_24xx_handle_abts() function return early if\ntcm_qla2xxx_find_cmd_by_tag() didn't find a command, but it missed to clean\nup the allocated memory for the management command.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/stable/c/29a22a3d495c147117137719d2c39045c44ccebf",
                "https://git.kernel.org/stable/c/601be20fc6a1b762044d2398befffd6bf236cebf",
                "https://git.kernel.org/stable/c/6a4236ed47f5b0a57eb6b8fb1c351b15b3d341d7",
                "https://git.kernel.org/stable/c/89df49e561b4a8948521fc3f8a013012eaa08f82"
            ],
            "timeline": [
                {
                    "at": "2024-04-28T13:15:07.380",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48650"
                }
            ]
        },
        {
            "id": "CVE-2022-46505",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "details-for-CVE-2022-46505 exploit",
            "summary": "Exploit for CVE-2022-46505. CVSS 7.5.",
            "updated_at": "2026-09-06T08:25:51Z",
            "published_at": "2026-09-06T08:25:51Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-06T08:25:51+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "details-for-CVE-2022-46505 exploit",
                    "summary": "Exploit for CVE-2022-46505. CVSS 7.5.",
                    "cvss": 7.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SMALLTOWN123-DETAILS-FOR-CVE-2022-46505"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SMALLTOWN123-DETAILS-FOR-CVE-2022-46505"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:25:51Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SMALLTOWN123-DETAILS-FOR-CVE-2022-46505"
                }
            ]
        },
        {
            "id": "CVE-2022-42917",
            "vendor": "FRRouting",
            "product": "FRRouting",
            "title": "FRRouting vulnerability",
            "summary": "In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the ownership of arbitrary files. This is a TOCTOU Race Condition caused by a combination of touch and chown.",
            "updated_at": "2026-09-14T00:16:55.700",
            "published_at": "2026-09-14T00:16:55.700",
            "cvss": 6.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.5 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-367",
            "what_happened": "In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the ownership of arbitrary files. This is a TOCTOU Race Condition caused by a combination of touch and chown.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://bugzilla.suse.com/show_bug.cgi?id=1204124",
                "https://frrouting.org/security/cve-2022-42917/",
                "https://github.com/FRRouting/frr/commit/972cdc560e339d70c0ee5fb70ec636ab78f00bca",
                "https://github.com/FRRouting/frr/compare/frr-8.4...frr-8.5"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T00:16:55.700",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-42917"
                }
            ]
        },
        {
            "id": "CVE-2022-42899",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2022-42899 exploit",
            "summary": "Exploit for CVE-2022-42899. CVSS 7.8.",
            "updated_at": "2026-09-13T18:05:33Z",
            "published_at": "2026-09-13T18:05:33Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:05:33+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2022-42899 exploit",
                    "summary": "Exploit for CVE-2022-42899. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IAMSANJAY-CVE-2022-42899"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IAMSANJAY-CVE-2022-42899"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:05:33Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IAMSANJAY-CVE-2022-42899"
                }
            ]
        },
        {
            "id": "CVE-2022-41404",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Windows Apache Tomcat resource limits implementation guide for CVE-2022-41404 DoS vulnerability protection",
            "summary": "Windows Apache Tomcat resource limits implementation guide for CVE-2022-41404 DoS vulnerability protection",
            "updated_at": "2026-09-14T22:00:00Z",
            "published_at": "2026-09-14T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · fdjy1234/CVE-2022-41404-DoS-Protection",
                    "author": "fdjy1234",
                    "first_seen": "2026-09-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Windows Apache Tomcat resource limits implementation guide for CVE-2022-41404 DoS vulnerability protection",
                    "summary": "Windows Apache Tomcat resource limits implementation guide for CVE-2022-41404 DoS vulnerability protection",
                    "url": "https://github.com/fdjy1234/CVE-2022-41404-DoS-Protection"
                }
            ],
            "references": [
                "https://github.com/fdjy1234/CVE-2022-41404-DoS-Protection"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/fdjy1234/CVE-2022-41404-DoS-Protection"
                }
            ]
        },
        {
            "id": "CVE-2022-41401",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2022-41401 exploit",
            "summary": "Exploit for CVE-2022-41401. CVSS 6.5.",
            "updated_at": "2026-09-11T18:33:11Z",
            "published_at": "2026-09-11T18:33:11Z",
            "cvss": 6.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 20,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-11T18:33:11+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2022-41401 exploit",
                    "summary": "Exploit for CVE-2022-41401. CVSS 6.5.",
                    "cvss": 6.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IXSLY-CVE-2022-41401"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IXSLY-CVE-2022-41401"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T18:33:11Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IXSLY-CVE-2022-41401"
                }
            ]
        },
        {
            "id": "CVE-2022-41352",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.",
            "updated_at": "2026-09-10T04:17:37.410",
            "published_at": "2022-09-26T02:15:10.733",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 63,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "packetstormsecurity.com",
                    "author": "NVD reference",
                    "first_seen": "2022-09-26",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://packetstormsecurity.com/files/169458/Zimbra-Collaboration-Suite-TAR-Path-Traversal.html"
                }
            ],
            "references": [
                "http://packetstormsecurity.com/files/169458/Zimbra-Collaboration-Suite-TAR-Path-Traversal.html",
                "https://forums.zimbra.org/viewtopic.php?t=71153&p=306532",
                "https://wiki.zimbra.com/wiki/Security_Center",
                "https://wiki.zimbra.com/wiki/Zimbra_Security_Advisories",
                "https://www.secpod.com/blog/unpatched-rce-bug-in-zimbra-collaboration-suite-exploited-in-wild/",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-41352"
            ],
            "timeline": [
                {
                    "at": "2022-09-26T02:15:10.733",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41352"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2022-38266",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.",
            "updated_at": "2026-09-14T14:10:44.773",
            "published_at": "2022-09-09T22:15:08.830",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 16,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-369",
            "what_happened": "An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2022-09-09",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/tesseract-ocr/tesseract/issues/3498"
                }
            ],
            "references": [
                "https://github.com/DanBloomberg/leptonica/commit/f062b42c0ea8dddebdc6a152fd16152de215d614",
                "https://github.com/tesseract-ocr/tesseract/issues/3498",
                "https://lists.debian.org/debian-lts-announce/2022/12/msg00018.html",
                "https://security.gentoo.org/glsa/202312-01"
            ],
            "timeline": [
                {
                    "at": "2022-09-09T22:15:08.830",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38266"
                }
            ]
        },
        {
            "id": "CVE-2022-38181",
            "vendor": "Arm",
            "product": "Mali Graphics Processing Unit (GPU)",
            "title": "Arm Mali GPU Kernel Driver Use-After-Free Vulnerability",
            "summary": "Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.",
            "updated_at": "2026-09-11T21:04:59Z",
            "published_at": "2026-09-11T21:04:59Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 161,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · Pro-me3us/CVE_2022_38181_Raven",
                    "author": "Pro-me3us",
                    "first_seen": "2023-04-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2022-38181 POC for FireTV 2nd gen Cube (raven)",
                    "summary": "CVE-2022-38181 POC for FireTV 2nd gen Cube (raven)",
                    "url": "https://github.com/Pro-me3us/CVE_2022_38181_Raven"
                },
                {
                    "repository": "PoC-in-GitHub · Pro-me3us/CVE_2022_38181_Gazelle",
                    "author": "Pro-me3us",
                    "first_seen": "2023-04-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2022-38181 POC for FireTV 3rd gen Cube (gazelle)",
                    "summary": "CVE-2022-38181 POC for FireTV 3rd gen Cube (gazelle)",
                    "url": "https://github.com/Pro-me3us/CVE_2022_38181_Gazelle"
                },
                {
                    "repository": "PoC-in-GitHub · R0rt1z2/CVE-2022-38181",
                    "author": "R0rt1z2",
                    "first_seen": "2023-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2022-38181 repository",
                    "summary": "",
                    "url": "https://github.com/R0rt1z2/CVE-2022-38181"
                },
                {
                    "repository": "PoC-in-GitHub · soralis0912/CVE-2022-38181-aristotle",
                    "author": "soralis0912",
                    "first_seen": "2026-07-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-38181 repository",
                    "summary": "",
                    "url": "https://github.com/soralis0912/CVE-2022-38181-aristotle"
                },
                {
                    "repository": "PoC-in-GitHub · ericpardee/fire-hd-ownership",
                    "author": "ericpardee",
                    "first_seen": "2026-08-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Owning a tablet Amazon kept shutting down — CVE-2022-38181 write-up, four AI models, and a blog",
                    "summary": "Owning a tablet Amazon kept shutting down — CVE-2022-38181 write-up, four AI models, and a blog",
                    "url": "https://github.com/ericpardee/fire-hd-ownership"
                },
                {
                    "repository": "PoC-in-GitHub · artur9010/amazon-mustang-hack",
                    "author": "artur9010",
                    "first_seen": "2026-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "FireOS 7.3.3.1 temp root by CVE-2022-38181",
                    "summary": "FireOS 7.3.3.1 temp root by CVE-2022-38181",
                    "url": "https://github.com/artur9010/amazon-mustang-hack"
                },
                {
                    "title": "Exploit for Use After Free in Arm Bifrost_Gpu_Kernel_Driver CVE-2022-38181 CVE-2026-43499",
                    "summary": "Use After Free in Arm Bifrost kbase JIT driver (CVE-2022-38181) enabling kernel root exploit.",
                    "what_happened": "Use After Free in Arm Bifrost kbase JIT driver (CVE-2022-38181) enabling kernel root exploit.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=B7F4C122-DCF4-5F88-B125-FCF4479408A9",
                        "https://github.com/artur9010/amazon-mustang-hack"
                    ],
                    "repository": "Sploitus",
                    "author": "artur9010",
                    "first_seen": "2026-09-11T21:05:23",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B7F4C122-DCF4-5F88-B125-FCF4479408A9"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/Pro-me3us/CVE_2022_38181_Raven",
                "https://github.com/Pro-me3us/CVE_2022_38181_Gazelle",
                "https://github.com/R0rt1z2/CVE-2022-38181",
                "https://github.com/soralis0912/CVE-2022-38181-aristotle",
                "https://github.com/ericpardee/fire-hd-ownership",
                "https://github.com/artur9010/amazon-mustang-hack",
                "https://sploitus.com/exploit?id=B7F4C122-DCF4-5F88-B125-FCF4479408A9"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T21:04:59Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2022-37969",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809",
            "title": "Windows 10 Version 1809 vulnerability",
            "summary": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "updated_at": "2026-09-10T04:17:35.097",
            "published_at": "2022-09-13T19:15:12.323",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "10.0.17763.0 through before 10.0.17763.3406 (custom); 10.0.0 through before 10.0.17763.3406 (custom); 10.0.0 through before 10.0.19043.2006 (custom); 10.0.20348.0 through before 10.0.20348.1006 (custom); 10.0.0 through before 10.0.19042.2006 (custom); 10.0.0 through before 10.0.22000.978 (custom); 10.0.19043.0 through before 10.0.19044.2006 (custom); 10.0.10240.0 through before 10.0.10240.19444 (custom); 10.0.14393.0 through before 10.0.14393.5356 (custom); 6.1.0 through before 6.1.7601.26115 (custom); 6.3.0 through before 6.3.9600.20571 (custom); 6.0.6003.0 through before 6.0.6003.21666 (custom); 6.1.7601.0 through before 6.1.7601.26115 (custom); 6.2.9200.0 through before 6.2.9200.23865 (custom); 6.3.9600.0 through before 6.3.9600.20571 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 29,
            "kev": true,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-787",
            "what_happened": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-37969",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-37969"
            ],
            "timeline": [
                {
                    "at": "2022-09-13T19:15:12.323",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37969"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2022-37305",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "rollback_car_attack_proverif exploit",
            "summary": "Exploit for CVE-2022-36945 and CVE-2022-37305. CVSS 6.4.",
            "updated_at": "2026-09-13T18:09:34Z",
            "published_at": "2026-09-13T18:09:34Z",
            "cvss": 6.4,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:09:34+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "rollback_car_attack_proverif exploit",
                    "summary": "Exploit for CVE-2022-36945 and CVE-2022-37305. CVSS 6.4.",
                    "cvss": 6.4,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THOMASARMEL-ROLLBACK_CAR_ATTACK_PROVERIF"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THOMASARMEL-ROLLBACK_CAR_ATTACK_PROVERIF"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:09:34Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THOMASARMEL-ROLLBACK_CAR_ATTACK_PROVERIF"
                }
            ]
        },
        {
            "id": "CVE-2022-36945",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "rollback_car_attack_proverif exploit",
            "summary": "Exploit for CVE-2022-36945 and CVE-2022-37305. CVSS 6.4.",
            "updated_at": "2026-09-13T18:09:34Z",
            "published_at": "2026-09-13T18:09:34Z",
            "cvss": 6.4,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:09:34+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "rollback_car_attack_proverif exploit",
                    "summary": "Exploit for CVE-2022-36945 and CVE-2022-37305. CVSS 6.4.",
                    "cvss": 6.4,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THOMASARMEL-ROLLBACK_CAR_ATTACK_PROVERIF"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THOMASARMEL-ROLLBACK_CAR_ATTACK_PROVERIF"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:09:34Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-THOMASARMEL-ROLLBACK_CAR_ATTACK_PROVERIF"
                }
            ]
        },
        {
            "id": "CVE-2022-36804",
            "vendor": "Atlassian",
            "product": "Bitbucket Server and Data Center",
            "title": "Atlassian Bitbucket Server and Data Center Command Injection Vulnerability",
            "summary": "Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.",
            "updated_at": "2026-08-20T22:00:00Z",
            "published_at": "2026-08-20T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 770,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 51040",
                    "author": "khal4n1",
                    "first_seen": "2023-03-23",
                    "confidence": "High",
                    "title": "Bitbucket v7.0.0 -  RCE",
                    "summary": "Bitbucket v7.0.0 -  RCE",
                    "url": "https://www.exploit-db.com/exploits/51040",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · notdls/CVE-2022-36804",
                    "author": "notdls",
                    "first_seen": "2022-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 35,
                    "title": "A real exploit for BitBucket RCE CVE-2022-36804",
                    "summary": "A real exploit for BitBucket RCE CVE-2022-36804",
                    "url": "https://github.com/notdls/CVE-2022-36804"
                },
                {
                    "repository": "PoC-in-GitHub · notxesh/CVE-2022-36804-PoC",
                    "author": "notxesh",
                    "first_seen": "2022-09-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 18,
                    "title": "Multithreaded exploit script for CVE-2022-36804 affecting BitBucket versions <8.3.1",
                    "summary": "Multithreaded exploit script for CVE-2022-36804 affecting BitBucket versions <8.3.1",
                    "url": "https://github.com/notxesh/CVE-2022-36804-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · JRandomSage/CVE-2022-36804-MASS-RCE",
                    "author": "JRandomSage",
                    "first_seen": "2022-09-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A critical vulnerability (CVE-2022-36804) in Atlassian Bitbucket Server and Data Center could be exploited by unauthorized attackers to execute malicious code on vulnerable instances.",
                    "summary": "A critical vulnerability (CVE-2022-36804) in Atlassian Bitbucket Server and Data Center could be exploited by unauthorized attackers to execute malicious code on vulnerable instances.",
                    "url": "https://github.com/JRandomSage/CVE-2022-36804-MASS-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · benjaminhays/CVE-2022-36804-PoC-Exploit",
                    "author": "benjaminhays",
                    "first_seen": "2022-09-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 16,
                    "title": "Somewhat Reliable PoC Exploit for CVE-2022-36804 (BitBucket Critical Command Injection)",
                    "summary": "Somewhat Reliable PoC Exploit for CVE-2022-36804 (BitBucket Critical Command Injection)",
                    "url": "https://github.com/benjaminhays/CVE-2022-36804-PoC-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Vulnmachines/bitbucket-cve-2022-36804",
                    "author": "Vulnmachines",
                    "first_seen": "2022-09-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2022-36804 Atlassian Bitbucket Command Injection Vulnerability",
                    "summary": "CVE-2022-36804 Atlassian Bitbucket Command Injection Vulnerability",
                    "url": "https://github.com/Vulnmachines/bitbucket-cve-2022-36804"
                },
                {
                    "repository": "PoC-in-GitHub · kljunowsky/CVE-2022-36804-POC",
                    "author": "kljunowsky",
                    "first_seen": "2022-09-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Bitbucket CVE-2022-36804 unauthenticated remote command execution",
                    "summary": "Bitbucket CVE-2022-36804 unauthenticated remote command execution",
                    "url": "https://github.com/kljunowsky/CVE-2022-36804-POC"
                },
                {
                    "repository": "PoC-in-GitHub · Chocapikk/CVE-2022-36804-ReverseShell",
                    "author": "Chocapikk",
                    "first_seen": "2022-09-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)",
                    "summary": "PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)",
                    "url": "https://github.com/Chocapikk/CVE-2022-36804-ReverseShell"
                },
                {
                    "repository": "PoC-in-GitHub · khal4n1/CVE-2022-36804",
                    "author": "khal4n1",
                    "first_seen": "2022-09-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "You can find a python script to exploit the vulnerability on Bitbucket related CVE-2022-36804.",
                    "summary": "You can find a python script to exploit the vulnerability on Bitbucket related CVE-2022-36804.",
                    "url": "https://github.com/khal4n1/CVE-2022-36804"
                },
                {
                    "repository": "PoC-in-GitHub · 0xEleven/CVE-2022-36804-ReverseShell",
                    "author": "0xEleven",
                    "first_seen": "2022-09-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)",
                    "summary": "PoC exploit for CVE-2022-36804 (BitBucket Critical Command Injection)",
                    "url": "https://github.com/0xEleven/CVE-2022-36804-ReverseShell"
                },
                {
                    "repository": "PoC-in-GitHub · tahtaciburak/cve-2022-36804",
                    "author": "tahtaciburak",
                    "first_seen": "2022-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "A simple PoC for Atlassian Bitbucket RCE [CVE-2022-36804]",
                    "summary": "A simple PoC for Atlassian Bitbucket RCE [CVE-2022-36804]",
                    "url": "https://github.com/tahtaciburak/cve-2022-36804"
                },
                {
                    "repository": "PoC-in-GitHub · sh4den/CVE-2022-36804",
                    "author": "sh4den",
                    "first_seen": "2022-09-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "A loader for bitbucket 2022 rce (cve-2022-36804)",
                    "summary": "A loader for bitbucket 2022 rce (cve-2022-36804)",
                    "url": "https://github.com/sh4den/CVE-2022-36804"
                },
                {
                    "repository": "PoC-in-GitHub · ColdFusionX/CVE-2022-36804",
                    "author": "ColdFusionX",
                    "first_seen": "2022-10-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Atlassian Bitbucket Server and Data Center - Command Injection Vulnerability (CVE-2022-36804)",
                    "summary": "Atlassian Bitbucket Server and Data Center - Command Injection Vulnerability (CVE-2022-36804)",
                    "url": "https://github.com/ColdFusionX/CVE-2022-36804"
                },
                {
                    "repository": "PoC-in-GitHub · devengpk/CVE-2022-36804",
                    "author": "devengpk",
                    "first_seen": "2022-12-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-36804 repository",
                    "summary": "",
                    "url": "https://github.com/devengpk/CVE-2022-36804"
                },
                {
                    "repository": "PoC-in-GitHub · walnutsecurity/cve-2022-36804",
                    "author": "walnutsecurity",
                    "first_seen": "2023-01-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "A critical command injection vulnerability was found in multiple API endpoints of the Atlassian Bit bucket Server and Data center. This vulnerability affects all versions of Bitbucket Server and Data Center released before versions <7.6.17, <7.17.10, <7.21.4, <8.0.3, <8.1.2, <8.2.2, and <8.3.1",
                    "summary": "A critical command injection vulnerability was found in multiple API endpoints of the Atlassian Bit bucket Server and Data center. This vulnerability affects all versions of Bitbucket Server and Data Center released before versions <7.6.17, <7.17.10, <7.21.4, <8.0.3, <8.1.2, <8.2.2, and <8.3.1",
                    "url": "https://github.com/walnutsecurity/cve-2022-36804"
                },
                {
                    "repository": "PoC-in-GitHub · imbas007/Atlassian-Bitbucket-CVE-2022-36804",
                    "author": "imbas007",
                    "first_seen": "2023-02-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-36804 repository",
                    "summary": "",
                    "url": "https://github.com/imbas007/Atlassian-Bitbucket-CVE-2022-36804"
                },
                {
                    "repository": "PoC-in-GitHub · asepsaepdin/CVE-2022-36804",
                    "author": "asepsaepdin",
                    "first_seen": "2025-01-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-36804 repository",
                    "summary": "",
                    "url": "https://github.com/asepsaepdin/CVE-2022-36804"
                },
                {
                    "repository": "PoC-in-GitHub · DanielHallbro/CVE-2022-36804-Bitbucket-RCE-Analysis",
                    "author": "DanielHallbro",
                    "first_seen": "2026-02-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Full-chain reproduction of CVE-2022-36804 (Bitbucket RCE). Includes a Dockerized laboratory, pspy64 monitoring for null-byte injection verification, and a custom Bash exploit script. Based on Assetnote research.",
                    "summary": "Full-chain reproduction of CVE-2022-36804 (Bitbucket RCE). Includes a Dockerized laboratory, pspy64 monitoring for null-byte injection verification, and a custom Bash exploit script. Based on Assetnote research.",
                    "url": "https://github.com/DanielHallbro/CVE-2022-36804-Bitbucket-RCE-Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · JohanGabrielson/bitbucket-test",
                    "author": "JohanGabrielson",
                    "first_seen": "2026-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Investigating CVE-2022-36804",
                    "summary": "Investigating CVE-2022-36804",
                    "url": "https://github.com/JohanGabrielson/bitbucket-test"
                },
                {
                    "repository": "PoC-in-GitHub · Junohea/cve-2022-36804",
                    "author": "Junohea",
                    "first_seen": "2026-08-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-36804 Bitbucket command execution and file transfer tool",
                    "summary": "CVE-2022-36804 Bitbucket command execution and file transfer tool",
                    "url": "https://github.com/Junohea/cve-2022-36804"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/51040",
                "https://github.com/notdls/CVE-2022-36804",
                "https://github.com/notxesh/CVE-2022-36804-PoC",
                "https://github.com/JRandomSage/CVE-2022-36804-MASS-RCE",
                "https://github.com/benjaminhays/CVE-2022-36804-PoC-Exploit",
                "https://github.com/Vulnmachines/bitbucket-cve-2022-36804",
                "https://github.com/kljunowsky/CVE-2022-36804-POC",
                "https://github.com/Chocapikk/CVE-2022-36804-ReverseShell",
                "https://github.com/khal4n1/CVE-2022-36804",
                "https://github.com/0xEleven/CVE-2022-36804-ReverseShell",
                "https://github.com/tahtaciburak/cve-2022-36804",
                "https://github.com/sh4den/CVE-2022-36804",
                "https://github.com/ColdFusionX/CVE-2022-36804",
                "https://github.com/devengpk/CVE-2022-36804",
                "https://github.com/walnutsecurity/cve-2022-36804",
                "https://github.com/imbas007/Atlassian-Bitbucket-CVE-2022-36804",
                "https://github.com/asepsaepdin/CVE-2022-36804",
                "https://github.com/DanielHallbro/CVE-2022-36804-Bitbucket-RCE-Analysis",
                "https://github.com/JohanGabrielson/bitbucket-test",
                "https://github.com/Junohea/cve-2022-36804"
            ],
            "timeline": [
                {
                    "at": "2026-08-20T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-09-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2022-34303",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2022-34303 - Secure Boot bypass via CryptoPro Secure Disk signed UEFI Shell (Shell_Full.efi) - BYOVUA technique exploiting mm command for gSecurity2 corruption to load unsigned UEFI applications.",
            "summary": "CVE-2022-34303 - Secure Boot bypass via CryptoPro Secure Disk signed UEFI Shell (Shell_Full.efi) - BYOVUA technique exploiting mm command for gSecurity2 corruption to load unsigned UEFI applications.",
            "updated_at": "2026-08-30T22:00:00Z",
            "published_at": "2026-08-30T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · TheMalwareGuardian/CVE-2022-34303",
                    "author": "TheMalwareGuardian",
                    "first_seen": "2026-08-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-34303 - Secure Boot bypass via CryptoPro Secure Disk signed UEFI Shell (Shell_Full.efi) - BYOVUA technique exploiting mm command for gSecurity2 corruption to load unsigned UEFI applications.",
                    "summary": "CVE-2022-34303 - Secure Boot bypass via CryptoPro Secure Disk signed UEFI Shell (Shell_Full.efi) - BYOVUA technique exploiting mm command for gSecurity2 corruption to load unsigned UEFI applications.",
                    "url": "https://github.com/TheMalwareGuardian/CVE-2022-34303"
                }
            ],
            "references": [
                "https://github.com/TheMalwareGuardian/CVE-2022-34303"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/TheMalwareGuardian/CVE-2022-34303"
                }
            ]
        },
        {
            "id": "CVE-2022-34302",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2022-34302 - Secure Boot bypass via New Horizon Datasys signed bootloader (shdloader.efi) - BYOVUA technique exploiting built-in custom PE/COFF loader to load unsigned UEFI applications without signature verification.",
            "summary": "CVE-2022-34302 - Secure Boot bypass via New Horizon Datasys signed bootloader (shdloader.efi) - BYOVUA technique exploiting built-in custom PE/COFF loader to load unsigned UEFI applications without signature verification.",
            "updated_at": "2026-09-06T22:00:00Z",
            "published_at": "2026-09-06T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · TheMalwareGuardian/CVE-2022-34302",
                    "author": "TheMalwareGuardian",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-34302 - Secure Boot bypass via New Horizon Datasys signed bootloader (shdloader.efi) - BYOVUA technique exploiting built-in custom PE/COFF loader to load unsigned UEFI applications without signature verification.",
                    "summary": "CVE-2022-34302 - Secure Boot bypass via New Horizon Datasys signed bootloader (shdloader.efi) - BYOVUA technique exploiting built-in custom PE/COFF loader to load unsigned UEFI applications without signature verification.",
                    "url": "https://github.com/TheMalwareGuardian/CVE-2022-34302"
                }
            ],
            "references": [
                "https://github.com/TheMalwareGuardian/CVE-2022-34302"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/TheMalwareGuardian/CVE-2022-34302"
                }
            ]
        },
        {
            "id": "CVE-2022-34301",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2022-34301 - Secure Boot bypass via Eurosoft signed UEFI Shell (esdiags.efi) - BYOVUA technique exploiting mm command for gSecurity2 corruption to load unsigned UEFI applications.",
            "summary": "CVE-2022-34301 - Secure Boot bypass via Eurosoft signed UEFI Shell (esdiags.efi) - BYOVUA technique exploiting mm command for gSecurity2 corruption to load unsigned UEFI applications.",
            "updated_at": "2026-09-06T22:00:00Z",
            "published_at": "2026-09-06T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · TheMalwareGuardian/CVE-2022-34301",
                    "author": "TheMalwareGuardian",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-34301 - Secure Boot bypass via Eurosoft signed UEFI Shell (esdiags.efi) - BYOVUA technique exploiting mm command for gSecurity2 corruption to load unsigned UEFI applications.",
                    "summary": "CVE-2022-34301 - Secure Boot bypass via Eurosoft signed UEFI Shell (esdiags.efi) - BYOVUA technique exploiting mm command for gSecurity2 corruption to load unsigned UEFI applications.",
                    "url": "https://github.com/TheMalwareGuardian/CVE-2022-34301"
                }
            ],
            "references": [
                "https://github.com/TheMalwareGuardian/CVE-2022-34301"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/TheMalwareGuardian/CVE-2022-34301"
                }
            ]
        },
        {
            "id": "CVE-2022-32073",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "project_BIT_nmap_script exploit",
            "summary": "Exploit for CVE-2022-32073. CVSS 9.8.",
            "updated_at": "2026-09-13T18:28:42Z",
            "published_at": "2026-09-13T18:28:42Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:28:42+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "project_BIT_nmap_script exploit",
                    "summary": "Exploit for CVE-2022-32073. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MGREGUS-PROJECT_BIT_NMAP_SCRIPT"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MGREGUS-PROJECT_BIT_NMAP_SCRIPT"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:28:42Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MGREGUS-PROJECT_BIT_NMAP_SCRIPT"
                }
            ]
        },
        {
            "id": "CVE-2022-31101",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Prestashop blockwishlist module 2.1.0 - SQLi",
            "summary": "Prestashop blockwishlist module 2.1.0 - SQLi",
            "updated_at": "2026-08-25T21:54:06Z",
            "published_at": "2026-08-25T21:54:06Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 120,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "SQL injection in PrestaShop blockwishlist module 2.1.0 via wishlist view parameter.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 51001",
                    "author": "Karthik UJ",
                    "first_seen": "2022-08-09",
                    "confidence": "High",
                    "title": "Prestashop blockwishlist module 2.1.0 - SQLi",
                    "summary": "Prestashop blockwishlist module 2.1.0 - SQLi",
                    "url": "https://www.exploit-db.com/exploits/51001",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2022-31101",
                    "summary": "SQL injection in PrestaShop blockwishlist module 2.1.0 via wishlist view parameter.",
                    "what_happened": "SQL injection in PrestaShop blockwishlist module 2.1.0 via wishlist view parameter.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KARTHIKUJ-CVE-2022-31101",
                        "https://kitploit.com/ru/tools/github/karthikuj/cve-2022-31101/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T23:54:06",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KARTHIKUJ-CVE-2022-31101"
                },
                {
                    "title": "Exploit for CVE-2022-31101",
                    "summary": "SQL injection in PrestaShop blockwishlist module 2.1.0 via wishlist view parameter.",
                    "what_happened": "SQL injection in PrestaShop blockwishlist module 2.1.0 via wishlist view parameter.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KARTHIKUJ-CVE-2022-31101",
                        "https://kitploit.com/ru/tools/github/karthikuj/cve-2022-31101/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-25T23:54:06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/karthikuj/cve-2022-31101/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/51001",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KARTHIKUJ-CVE-2022-31101",
                "https://kitploit.com/ru/tools/github/karthikuj/cve-2022-31101/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T21:54:06Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/51001"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2022-30526",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2022-30526 exploit",
            "summary": "Exploit for CVE-2022-30526. CVSS 7.8.",
            "updated_at": "2026-09-14T04:52:38Z",
            "published_at": "2026-09-14T04:52:38Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 23,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Missing README in the tools repository identified as CVE-2022-30526.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2022-30526",
                    "summary": "Missing README in the tools repository identified as CVE-2022-30526.",
                    "what_happened": "Missing README in the tools repository identified as CVE-2022-30526.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GREEK0X0-CVE-2022-30526",
                        "https://kitploit.com/ar/tools/github/greek0x0/cve-2022-30526/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T02:03:19",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GREEK0X0-CVE-2022-30526"
                },
                {
                    "title": "Exploit for CVE-2022-30526",
                    "summary": "Missing README in the tools repository identified as CVE-2022-30526.",
                    "what_happened": "Missing README in the tools repository identified as CVE-2022-30526.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GREEK0X0-CVE-2022-30526",
                        "https://kitploit.com/ar/tools/github/greek0x0/cve-2022-30526/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-05T02:03:19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/greek0x0/cve-2022-30526/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GREEK0X0-CVE-2022-30526",
                "https://kitploit.com/ar/tools/github/greek0x0/cve-2022-30526/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:52:38Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GREEK0X0-CVE-2022-30526"
                }
            ]
        },
        {
            "id": "CVE-2022-30190",
            "vendor": "Microsoft",
            "product": "Windows",
            "title": "Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability",
            "summary": "A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.",
            "updated_at": "2026-08-25T02:55:03Z",
            "published_at": "2026-08-25T02:55:03Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 113,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2021-40444 CVE-2021-40444 CVE-2022-30190",
                    "summary": "RCE in Microsoft Office Word via malicious docx loading arbitrary DLLs through IE preview.",
                    "what_happened": "RCE in Microsoft Office Word via malicious docx loading arbitrary DLLs through IE preview.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KLEZVIRUS-CVE-2021-40444",
                        "https://kitploit.com/ko/tools/github/klezvirus/cve-2021-40444/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T04:55:03",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KLEZVIRUS-CVE-2021-40444"
                },
                {
                    "title": "Exploit for CVE-2021-40444 CVE-2021-40444 CVE-2022-30190",
                    "summary": "RCE in Microsoft Office Word via malicious docx loading arbitrary DLLs through IE preview.",
                    "what_happened": "RCE in Microsoft Office Word via malicious docx loading arbitrary DLLs through IE preview.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KLEZVIRUS-CVE-2021-40444",
                        "https://kitploit.com/ko/tools/github/klezvirus/cve-2021-40444/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ko",
                    "first_seen": "2026-08-25T04:55:03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ko/tools/github/klezvirus/cve-2021-40444/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KLEZVIRUS-CVE-2021-40444",
                "https://kitploit.com/ko/tools/github/klezvirus/cve-2021-40444/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T02:55:03Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C"
        },
        {
            "id": "CVE-2022-29900",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Reproduction of the Retbleed (CVE-2022-29900/29901) micro-architectural attack in gem5. RSB underflow, Flush+Reload side-channel leak, and a verified lfence mitigation.",
            "summary": "Reproduction of the Retbleed (CVE-2022-29900/29901) micro-architectural attack in gem5. RSB underflow, Flush+Reload side-channel leak, and a verified lfence mitigation.",
            "updated_at": "2026-09-10T22:00:00Z",
            "published_at": "2026-09-10T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 23,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · abdul-kalam2000/retbleed-speculative-execution-poc",
                    "author": "abdul-kalam2000",
                    "first_seen": "2026-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Reproduction of the Retbleed (CVE-2022-29900/29901) micro-architectural attack in gem5. RSB underflow, Flush+Reload side-channel leak, and a verified lfence mitigation.",
                    "summary": "Reproduction of the Retbleed (CVE-2022-29900/29901) micro-architectural attack in gem5. RSB underflow, Flush+Reload side-channel leak, and a verified lfence mitigation.",
                    "url": "https://github.com/abdul-kalam2000/retbleed-speculative-execution-poc"
                }
            ],
            "references": [
                "https://github.com/abdul-kalam2000/retbleed-speculative-execution-poc"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/abdul-kalam2000/retbleed-speculative-execution-poc"
                }
            ]
        },
        {
            "id": "CVE-2022-29567",
            "vendor": "Vaadin",
            "product": "vaadin",
            "title": "vaadin vulnerability",
            "summary": "The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.",
            "updated_at": "2026-09-14T17:17:38.980",
            "published_at": "2022-05-24T15:15:08.220",
            "cvss": 5.7,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "14.8.5 through 14.8.9 (maven); 22.0.6 through 22.0.14 (maven); 23.0.0.beta2 through 23.0.8 (maven); 23.1.0.alpha1 through before 23.1.0.beta1 (maven)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-200",
            "what_happened": "The default configuration of a TreeGrid component uses Object::toString as a key on the client-side and server communication in Vaadin 14.8.5 through 14.8.9, 22.0.6 through 22.0.14, 23.0.0.beta2 through 23.0.8 and 23.1.0.alpha1 through 23.1.0.alpha4, resulting in potential information disclosure of values that should not be available on the client-side.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/vaadin/flow-components/pull/3046",
                "https://vaadin.com/security/cve-2022-29567"
            ],
            "timeline": [
                {
                    "at": "2022-05-24T15:15:08.220",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-29567"
                }
            ]
        },
        {
            "id": "CVE-2022-28368",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Dompdf 1.2.1 - Remote Code Execution (RCE)",
            "summary": "Dompdf 1.2.1 - Remote Code Execution (RCE)",
            "updated_at": "2026-09-13T18:32:43Z",
            "published_at": "2026-09-13T18:32:43Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 36,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 51270",
                    "author": "Ravindu Wickramasinghe",
                    "first_seen": "2023-04-06",
                    "confidence": "High",
                    "title": "Dompdf 1.2.1 - Remote Code Execution (RCE)",
                    "summary": "Dompdf 1.2.1 - Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/51270",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:32:43+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2022-28368 exploit",
                    "summary": "Exploit for CVE-2022-28368. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RVZSEC-CVE-2022-28368"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/51270",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RVZSEC-CVE-2022-28368"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:32:43Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/51270"
                }
            ]
        },
        {
            "id": "CVE-2022-26923",
            "vendor": "Microsoft",
            "product": "Active Directory",
            "title": "Microsoft Active Directory Domain Services Privilege Escalation Vulnerability",
            "summary": "An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.",
            "updated_at": "2026-09-12T15:06:29Z",
            "published_at": "2026-09-12T15:06:29Z",
            "cvss": 9,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 109,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2022-26923",
                    "summary": "AD CS elevation of privilege via Machine template DNS Name impersonating a Domain Controller.",
                    "what_happened": "AD CS elevation of privilege via Machine template DNS Name impersonating a Domain Controller.",
                    "cvss": 9,
                    "cvss_vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YOWISE-CVE-2022-26923",
                        "https://kitploit.com/ru/tools/github/yowise/cve-2022-26923/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-12T15:06:29",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YOWISE-CVE-2022-26923"
                },
                {
                    "title": "Exploit for CVE-2022-26923",
                    "summary": "AD CS elevation of privilege via Machine template DNS Name impersonating a Domain Controller.",
                    "what_happened": "AD CS elevation of privilege via Machine template DNS Name impersonating a Domain Controller.",
                    "cvss": 9,
                    "cvss_vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YOWISE-CVE-2022-26923",
                        "https://kitploit.com/ru/tools/github/yowise/cve-2022-26923/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-12T15:06:29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/yowise/cve-2022-26923/"
                },
                {
                    "repository": "PoC-in-GitHub · r1skkam/TryHackMe-CVE-2022-26923",
                    "author": "r1skkam",
                    "first_seen": "2022-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services",
                    "summary": "Walkthrough on the exploitation of CVE-2022-26923, a vulnerability in AD Certificate Services",
                    "url": "https://github.com/r1skkam/TryHackMe-CVE-2022-26923"
                },
                {
                    "repository": "PoC-in-GitHub · LudovicPatho/CVE-2022-26923_AD-Certificate-Services",
                    "author": "LudovicPatho",
                    "first_seen": "2022-05-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 41,
                    "title": "The vulnerability allowed a low-privileged user to escalate privileges to domain administrator in a default Active Directory environment with the Active Directory Certificate Services (AD CS) server role installed.",
                    "summary": "The vulnerability allowed a low-privileged user to escalate privileges to domain administrator in a default Active Directory environment with the Active Directory Certificate Services (AD CS) server role installed.",
                    "url": "https://github.com/LudovicPatho/CVE-2022-26923_AD-Certificate-Services"
                },
                {
                    "repository": "PoC-in-GitHub · lsecqt/CVE-2022-26923-Powershell-POC",
                    "author": "lsecqt",
                    "first_seen": "2022-08-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "A powershell poc to load and automatically run Certify and Rubeus from memory.",
                    "summary": "A powershell poc to load and automatically run Certify and Rubeus from memory.",
                    "url": "https://github.com/lsecqt/CVE-2022-26923-Powershell-POC"
                },
                {
                    "repository": "PoC-in-GitHub · evilashz/PIGADVulnScanner",
                    "author": "evilashz",
                    "first_seen": "2023-10-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 82,
                    "title": "检测域内常见一把梭漏洞，包括：NoPac、ZeroLogon、CVE-2022-26923、PrintNightMare",
                    "summary": "检测域内常见一把梭漏洞，包括：NoPac、ZeroLogon、CVE-2022-26923、PrintNightMare",
                    "url": "https://github.com/evilashz/PIGADVulnScanner"
                },
                {
                    "repository": "PoC-in-GitHub · Gh-Badr/CVE-2022-26923",
                    "author": "Gh-Badr",
                    "first_seen": "2023-11-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A proof of concept exploiting CVE-2022-26923.",
                    "summary": "A proof of concept exploiting CVE-2022-26923.",
                    "url": "https://github.com/Gh-Badr/CVE-2022-26923"
                },
                {
                    "repository": "PoC-in-GitHub · Yowise/CVE-2022-26923",
                    "author": "Yowise",
                    "first_seen": "2024-09-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26923 repository",
                    "summary": "",
                    "url": "https://github.com/Yowise/CVE-2022-26923"
                },
                {
                    "repository": "PoC-in-GitHub · rayngnpc/CVE-2022-26923-rayng",
                    "author": "rayngnpc",
                    "first_seen": "2025-03-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploitation for CVE-2022-26923",
                    "summary": "Exploitation for CVE-2022-26923",
                    "url": "https://github.com/rayngnpc/CVE-2022-26923-rayng"
                },
                {
                    "repository": "PoC-in-GitHub · Eliasdekiniweek/CVE-2022-26923",
                    "author": "Eliasdekiniweek",
                    "first_seen": "2026-02-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Exploitation de CVE-2022-26923",
                    "summary": "Exploitation de CVE-2022-26923",
                    "url": "https://github.com/Eliasdekiniweek/CVE-2022-26923"
                },
                {
                    "repository": "PoC-in-GitHub · Nefhara/CVE-2022-26923",
                    "author": "Nefhara",
                    "first_seen": "2026-05-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Automated CVE-2022-26923 Exploitation (Certifried)",
                    "summary": "Automated CVE-2022-26923 Exploitation (Certifried)",
                    "url": "https://github.com/Nefhara/CVE-2022-26923"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YOWISE-CVE-2022-26923",
                "https://kitploit.com/ru/tools/github/yowise/cve-2022-26923/",
                "https://github.com/r1skkam/TryHackMe-CVE-2022-26923",
                "https://github.com/LudovicPatho/CVE-2022-26923_AD-Certificate-Services",
                "https://github.com/lsecqt/CVE-2022-26923-Powershell-POC",
                "https://github.com/evilashz/PIGADVulnScanner",
                "https://github.com/Gh-Badr/CVE-2022-26923",
                "https://github.com/Yowise/CVE-2022-26923",
                "https://github.com/rayngnpc/CVE-2022-26923-rayng",
                "https://github.com/Eliasdekiniweek/CVE-2022-26923",
                "https://github.com/Nefhara/CVE-2022-26923"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T15:06:29Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2022-26134",
            "vendor": "Atlassian",
            "product": "Confluence Server/Data Center",
            "title": "Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
            "summary": "Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.",
            "updated_at": "2026-09-05T12:45:24Z",
            "published_at": "2026-09-05T12:45:24Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1726,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50952",
                    "author": "Fellipe Oliveira",
                    "first_seen": "2022-06-10",
                    "confidence": "High",
                    "title": "Confluence Data Center 7.18.0 - Remote Code Execution (RCE)",
                    "summary": "Confluence Data Center 7.18.0 - Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/50952",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2022-26134-OGNL-Injection",
                    "summary": "OGNL injection vulnerability in tools repository, CVE-2022-26134.",
                    "what_happened": "OGNL injection vulnerability in tools repository, CVE-2022-26134.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ROODHELIOS-CVE-2022-26134-OGNL-INJECTION",
                        "https://kitploit.com/ru/tools/github/roodhelios/cve-2022-26134-ognl-injection/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T04:25:14",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ROODHELIOS-CVE-2022-26134-OGNL-INJECTION"
                },
                {
                    "title": "Exploit for CVE-2022-26134-OGNL-Injection",
                    "summary": "OGNL injection vulnerability in tools repository, CVE-2022-26134.",
                    "what_happened": "OGNL injection vulnerability in tools repository, CVE-2022-26134.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ROODHELIOS-CVE-2022-26134-OGNL-INJECTION",
                        "https://kitploit.com/ru/tools/github/roodhelios/cve-2022-26134-ognl-injection/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-25T04:25:14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/roodhelios/cve-2022-26134-ognl-injection/"
                },
                {
                    "repository": "PoC-in-GitHub · W01fh4cker/Serein",
                    "author": "W01fh4cker",
                    "first_seen": "2022-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1249,
                    "title": "【懒人神器】一款图形化、批量采集url、批量对采集的url进行各种nday检测的工具。可用于src挖掘、cnvd挖掘、0day利用、打造自己的武器库等场景。可以批量利用Actively Exploited Atlassian Confluence 0Day CVE-2022-26134和DedeCMS v5.7.87 SQL注入 CVE-2022-23337。",
                    "summary": "【懒人神器】一款图形化、批量采集url、批量对采集的url进行各种nday检测的工具。可用于src挖掘、cnvd挖掘、0day利用、打造自己的武器库等场景。可以批量利用Actively Exploited Atlassian Confluence 0Day CVE-2022-26134和DedeCMS v5.7.87 SQL注入 CVE-2022-23337。",
                    "url": "https://github.com/W01fh4cker/Serein"
                },
                {
                    "repository": "PoC-in-GitHub · offlinehoster/CVE-2022-26134",
                    "author": "offlinehoster",
                    "first_seen": "2022-06-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "Information and scripts for the confluence CVE-2022-26134",
                    "summary": "Information and scripts for the confluence CVE-2022-26134",
                    "url": "https://github.com/offlinehoster/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · ma1am/CVE-2022-26134-Exploit-Detection",
                    "author": "ma1am",
                    "first_seen": "2022-06-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This repository contains Yara rule and the method that a security investigator may want to use for CVE-2022-26134 threat hunting on their Linux confluence servers.",
                    "summary": "This repository contains Yara rule and the method that a security investigator may want to use for CVE-2022-26134 threat hunting on their Linux confluence servers.",
                    "url": "https://github.com/ma1am/CVE-2022-26134-Exploit-Detection"
                },
                {
                    "repository": "PoC-in-GitHub · jbaines-r7/through_the_wire",
                    "author": "jbaines-r7",
                    "first_seen": "2022-06-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 173,
                    "title": "CVE-2022-26134 Proof of Concept",
                    "summary": "CVE-2022-26134 Proof of Concept",
                    "url": "https://github.com/jbaines-r7/through_the_wire"
                },
                {
                    "repository": "PoC-in-GitHub · crowsec-edtech/CVE-2022-26134",
                    "author": "crowsec-edtech",
                    "first_seen": "2022-06-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 31,
                    "title": "CVE-2022-26134 - Confluence Pre-Auth RCE | OGNL injection",
                    "summary": "CVE-2022-26134 - Confluence Pre-Auth RCE | OGNL injection",
                    "url": "https://github.com/crowsec-edtech/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · kyxiaxiang/CVE-2022-26134",
                    "author": "kyxiaxiang",
                    "first_seen": "2022-06-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/kyxiaxiang/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · Brucetg/CVE-2022-26134",
                    "author": "Brucetg",
                    "first_seen": "2022-06-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "（CVE-2022-26134）an unauthenticated and remote OGNL injection vulnerability resulting in code execution in the context of the Confluence server",
                    "summary": "（CVE-2022-26134）an unauthenticated and remote OGNL injection vulnerability resulting in code execution in the context of the Confluence server",
                    "url": "https://github.com/Brucetg/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · shamo0/CVE-2022-26134",
                    "author": "shamo0",
                    "first_seen": "2022-06-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Confluence Server and Data Center - CVE-2022-26134 - Critical severity unauthenticated remote code execution vulnerability PoC",
                    "summary": "Confluence Server and Data Center - CVE-2022-26134 - Critical severity unauthenticated remote code execution vulnerability PoC",
                    "url": "https://github.com/shamo0/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · SNCKER/CVE-2022-26134",
                    "author": "SNCKER",
                    "first_seen": "2022-06-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 26,
                    "title": "[CVE-2022-26134]Confluence OGNL expression injected RCE with sandbox bypass.",
                    "summary": "[CVE-2022-26134]Confluence OGNL expression injected RCE with sandbox bypass.",
                    "url": "https://github.com/SNCKER/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · Vulnmachines/Confluence-CVE-2022-26134",
                    "author": "Vulnmachines",
                    "first_seen": "2022-06-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/Vulnmachines/Confluence-CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · axingde/CVE-2022-26134",
                    "author": "axingde",
                    "first_seen": "2022-06-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Atlassian confluence poc",
                    "summary": "Atlassian confluence poc",
                    "url": "https://github.com/axingde/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · 0xAgun/CVE-2022-26134",
                    "author": "0xAgun",
                    "first_seen": "2022-06-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/0xAgun/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · abhishekmorla/CVE-2022-26134",
                    "author": "abhishekmorla",
                    "first_seen": "2022-06-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/abhishekmorla/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · hev0x/CVE-2022-26134",
                    "author": "hev0x",
                    "first_seen": "2022-06-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 44,
                    "title": "Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134)",
                    "summary": "Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134)",
                    "url": "https://github.com/hev0x/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · archanchoudhury/Confluence-CVE-2022-26134",
                    "author": "archanchoudhury",
                    "first_seen": "2022-06-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "This repository talks about Zero-Day Exploitation of Atlassian Confluence, it's defense and analysis point of view from a SecOps or Blue Team perspective",
                    "summary": "This repository talks about Zero-Day Exploitation of Atlassian Confluence, it's defense and analysis point of view from a SecOps or Blue Team perspective",
                    "url": "https://github.com/archanchoudhury/Confluence-CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · SIFalcon/confluencePot",
                    "author": "SIFalcon",
                    "first_seen": "2022-06-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 20,
                    "title": "Simple Honeypot for Atlassian Confluence (CVE-2022-26134)",
                    "summary": "Simple Honeypot for Atlassian Confluence (CVE-2022-26134)",
                    "url": "https://github.com/SIFalcon/confluencePot"
                },
                {
                    "repository": "PoC-in-GitHub · vesperp/CVE-2022-26134-Confluence",
                    "author": "vesperp",
                    "first_seen": "2022-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/vesperp/CVE-2022-26134-Confluence"
                },
                {
                    "repository": "PoC-in-GitHub · li8u99/CVE-2022-26134",
                    "author": "li8u99",
                    "first_seen": "2022-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Atlassian Confluence 远程代码执行漏洞（CVE-2022-26134）",
                    "summary": "Atlassian Confluence 远程代码执行漏洞（CVE-2022-26134）",
                    "url": "https://github.com/li8u99/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · reubensammut/cve-2022-26134",
                    "author": "reubensammut",
                    "first_seen": "2022-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Implementation of CVE-2022-26134",
                    "summary": "Implementation of CVE-2022-26134",
                    "url": "https://github.com/reubensammut/cve-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · BeichenDream/CVE-2022-26134-Godzilla-MEMSHELL",
                    "author": "BeichenDream",
                    "first_seen": "2022-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 340,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/BeichenDream/CVE-2022-26134-Godzilla-MEMSHELL"
                },
                {
                    "repository": "PoC-in-GitHub · alcaparra/CVE-2022-26134",
                    "author": "alcaparra",
                    "first_seen": "2022-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2022-26134 Confluence OGNL Injection POC",
                    "summary": "CVE-2022-26134 Confluence OGNL Injection POC",
                    "url": "https://github.com/alcaparra/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · whokilleddb/CVE-2022-26134-Confluence-RCE",
                    "author": "whokilleddb",
                    "first_seen": "2022-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "Exploit for CVE-2022-26134: Confluence Pre-Auth Remote Code Execution via OGNL Injection",
                    "summary": "Exploit for CVE-2022-26134: Confluence Pre-Auth Remote Code Execution via OGNL Injection",
                    "url": "https://github.com/whokilleddb/CVE-2022-26134-Confluence-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · Habib0x0/CVE-2022-26134",
                    "author": "Habib0x0",
                    "first_seen": "2022-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Atlassian Confluence- Unauthenticated OGNL injection vulnerability (RCE)",
                    "summary": "Atlassian Confluence- Unauthenticated OGNL injection vulnerability (RCE)",
                    "url": "https://github.com/Habib0x0/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · Y000o/Confluence-CVE-2022-26134",
                    "author": "Y000o",
                    "first_seen": "2022-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/Y000o/Confluence-CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · redhuntlabs/ConfluentPwn",
                    "author": "redhuntlabs",
                    "first_seen": "2022-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "Atlassian confluence unauthenticated ONGL injection remote code execution scanner (CVE-2022-26134).",
                    "summary": "Atlassian confluence unauthenticated ONGL injection remote code execution scanner (CVE-2022-26134).",
                    "url": "https://github.com/redhuntlabs/ConfluentPwn"
                },
                {
                    "repository": "PoC-in-GitHub · secjia/CVE-2022-26134",
                    "author": "secjia",
                    "first_seen": "2022-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/secjia/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · cai-niao98/CVE-2022-26134",
                    "author": "cai-niao98",
                    "first_seen": "2022-06-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2022-26134",
                    "summary": "CVE-2022-26134",
                    "url": "https://github.com/cai-niao98/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · sunny-kathuria/exploit_CVE-2022-26134",
                    "author": "sunny-kathuria",
                    "first_seen": "2022-06-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. This is CVE-2022-26134 expoitation script",
                    "summary": "CVE-2022-26134, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. This is CVE-2022-26134 expoitation script",
                    "url": "https://github.com/sunny-kathuria/exploit_CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · KeepWannabe/BotCon",
                    "author": "KeepWannabe",
                    "first_seen": "2022-06-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "[CVE-2022-26134] Attlasian Confluence RCE",
                    "summary": "[CVE-2022-26134] Attlasian Confluence RCE",
                    "url": "https://github.com/KeepWannabe/BotCon"
                },
                {
                    "repository": "PoC-in-GitHub · Chocapikk/CVE-2022-26134",
                    "author": "Chocapikk",
                    "first_seen": "2022-06-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2022-26134 - Pre-Auth Remote Code Execution via OGNL Injection",
                    "summary": "CVE-2022-26134 - Pre-Auth Remote Code Execution via OGNL Injection",
                    "url": "https://github.com/Chocapikk/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · AmoloHT/CVE-2022-26134",
                    "author": "AmoloHT",
                    "first_seen": "2022-06-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "「💥」CVE-2022-26134 - Confluence Pre-Auth RCE",
                    "summary": "「💥」CVE-2022-26134 - Confluence Pre-Auth RCE",
                    "url": "https://github.com/AmoloHT/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · kh4sh3i/CVE-2022-26134",
                    "author": "kh4sh3i",
                    "first_seen": "2022-06-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "[PoC] Atlassian Confluence (CVE-2022-26134) - Unauthenticated OGNL injection vulnerability (RCE)",
                    "summary": "[PoC] Atlassian Confluence (CVE-2022-26134) - Unauthenticated OGNL injection vulnerability (RCE)",
                    "url": "https://github.com/kh4sh3i/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · ColdFusionX/CVE-2022-26134",
                    "author": "ColdFusionX",
                    "first_seen": "2022-06-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Atlassian Confluence OGNL Injection Remote Code Execution (RCE) Vulnerability (CVE-2022-26134)",
                    "summary": "Atlassian Confluence OGNL Injection Remote Code Execution (RCE) Vulnerability (CVE-2022-26134)",
                    "url": "https://github.com/ColdFusionX/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · Luchoane/CVE-2022-26134_conFLU",
                    "author": "Luchoane",
                    "first_seen": "2022-06-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC for exploiting CVE-2022-26134 on Confluence",
                    "summary": "PoC for exploiting CVE-2022-26134 on Confluence",
                    "url": "https://github.com/Luchoane/CVE-2022-26134_conFLU"
                },
                {
                    "repository": "PoC-in-GitHub · r1skkam/TryHackMe-Atlassian-CVE-2022-26134",
                    "author": "r1skkam",
                    "first_seen": "2022-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Atlassian, CVE-2022-26134  An interactive lab showcasing the Confluence Server and Data Center un-authenticated RCE vulnerability.",
                    "summary": "Atlassian, CVE-2022-26134  An interactive lab showcasing the Confluence Server and Data Center un-authenticated RCE vulnerability.",
                    "url": "https://github.com/r1skkam/TryHackMe-Atlassian-CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · nxtexploit/CVE-2022-26134",
                    "author": "nxtexploit",
                    "first_seen": "2022-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 29,
                    "title": "Atlassian Confluence (CVE-2022-26134) - Unauthenticated Remote code execution (RCE)",
                    "summary": "Atlassian Confluence (CVE-2022-26134) - Unauthenticated Remote code execution (RCE)",
                    "url": "https://github.com/nxtexploit/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · Debajyoti0-0/CVE-2022-26134",
                    "author": "Debajyoti0-0",
                    "first_seen": "2022-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Atlassian Confluence (CVE-2022-26134) - Unauthenticated OGNL injection vulnerability (RCE).",
                    "summary": "Atlassian Confluence (CVE-2022-26134) - Unauthenticated OGNL injection vulnerability (RCE).",
                    "url": "https://github.com/Debajyoti0-0/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · f4yd4-s3c/cve-2022-26134",
                    "author": "f4yd4-s3c",
                    "first_seen": "2022-07-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/f4yd4-s3c/cve-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · coskper-papa/CVE-2022-26134",
                    "author": "coskper-papa",
                    "first_seen": "2022-07-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "confluence rce",
                    "summary": "confluence rce",
                    "url": "https://github.com/coskper-papa/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · p4b3l1t0/confusploit",
                    "author": "p4b3l1t0",
                    "first_seen": "2022-07-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "This is a python script that can be used with Shodan CLI to mass hunting Confluence Servers vulnerable to CVE-2022-26134",
                    "summary": "This is a python script that can be used with Shodan CLI to mass hunting Confluence Servers vulnerable to CVE-2022-26134",
                    "url": "https://github.com/p4b3l1t0/confusploit"
                },
                {
                    "repository": "PoC-in-GitHub · twoning/CVE-2022-26134-PoC",
                    "author": "twoning",
                    "first_seen": "2022-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2022-26134-PoC",
                    "summary": "CVE-2022-26134-PoC",
                    "url": "https://github.com/twoning/CVE-2022-26134-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · iveresk/cve-2022-26134",
                    "author": "iveresk",
                    "first_seen": "2022-07-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "Just simple PoC for the Atlassian Jira exploit. Provides code execution for unauthorised user on a server.",
                    "summary": "Just simple PoC for the Atlassian Jira exploit. Provides code execution for unauthorised user on a server.",
                    "url": "https://github.com/iveresk/cve-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · keven1z/CVE-2022-26134",
                    "author": "keven1z",
                    "first_seen": "2022-07-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "远程攻击者在Confluence未经身份验证的情况下，可构造OGNL表达式进行注入，实现在Confluence Server或Data Center上执行任意代码,在现有脚本上修改了poc，方便getshell。",
                    "summary": "远程攻击者在Confluence未经身份验证的情况下，可构造OGNL表达式进行注入，实现在Confluence Server或Data Center上执行任意代码,在现有脚本上修改了poc，方便getshell。",
                    "url": "https://github.com/keven1z/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · shiftsansan/CVE-2022-26134-Console",
                    "author": "shiftsansan",
                    "first_seen": "2022-08-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134-Console",
                    "summary": "CVE-2022-26134-Console",
                    "url": "https://github.com/shiftsansan/CVE-2022-26134-Console"
                },
                {
                    "repository": "PoC-in-GitHub · 1337in/CVE-2022-26134web",
                    "author": "1337in",
                    "first_seen": "2022-08-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-26134 web payload",
                    "summary": "CVE-2022-26134 web payload",
                    "url": "https://github.com/1337in/CVE-2022-26134web"
                },
                {
                    "repository": "PoC-in-GitHub · skhalsa-sigsci/CVE-2022-26134-LAB",
                    "author": "skhalsa-sigsci",
                    "first_seen": "2022-10-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Detecting CVE-2022-26134 using Nuclei",
                    "summary": "Detecting CVE-2022-26134 using Nuclei",
                    "url": "https://github.com/skhalsa-sigsci/CVE-2022-26134-LAB"
                },
                {
                    "repository": "PoC-in-GitHub · yigexioabai/CVE-2022-26134-cve1",
                    "author": "yigexioabai",
                    "first_seen": "2022-10-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/yigexioabai/CVE-2022-26134-cve1"
                },
                {
                    "repository": "PoC-in-GitHub · kailing0220/CVE-2022-26134",
                    "author": "kailing0220",
                    "first_seen": "2022-10-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "在受影响的Confluence Server 和Data Center 版本中，存在一个OGNL 注入漏洞，该漏洞允许未经身份验证的攻击者在Confluence Server 或Data Center 服务器上执行任意代码。",
                    "summary": "在受影响的Confluence Server 和Data Center 版本中，存在一个OGNL 注入漏洞，该漏洞允许未经身份验证的攻击者在Confluence Server 或Data Center 服务器上执行任意代码。",
                    "url": "https://github.com/kailing0220/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · xanszZZ/ATLASSIAN-Confluence_rce",
                    "author": "xanszZZ",
                    "first_seen": "2022-10-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "批量检测CVE-2022-26134 RCE漏洞",
                    "summary": "批量检测CVE-2022-26134 RCE漏洞",
                    "url": "https://github.com/xanszZZ/ATLASSIAN-Confluence_rce"
                },
                {
                    "repository": "PoC-in-GitHub · kelemaoya/CVE-2022-26134",
                    "author": "kelemaoya",
                    "first_seen": "2022-10-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Confluence Server and Data Center存在一个远程代码执行漏洞，未经身份验证的攻击者可以利用该漏洞向目标服务器注入恶意ONGL表达式，进而在目标服务器上执行任意代码。",
                    "summary": "Confluence Server and Data Center存在一个远程代码执行漏洞，未经身份验证的攻击者可以利用该漏洞向目标服务器注入恶意ONGL表达式，进而在目标服务器上执行任意代码。",
                    "url": "https://github.com/kelemaoya/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · CJ-0107/cve-2022-26134",
                    "author": "CJ-0107",
                    "first_seen": "2022-10-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "cve-2022-26134",
                    "summary": "cve-2022-26134",
                    "url": "https://github.com/CJ-0107/cve-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · latings/CVE-2022-26134",
                    "author": "latings",
                    "first_seen": "2022-10-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134",
                    "summary": "CVE-2022-26134",
                    "url": "https://github.com/latings/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · yyqxi/CVE-2022-26134",
                    "author": "yyqxi",
                    "first_seen": "2022-10-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134poc",
                    "summary": "CVE-2022-26134poc",
                    "url": "https://github.com/yyqxi/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · b4dboy17/CVE-2022-26134",
                    "author": "b4dboy17",
                    "first_seen": "2022-10-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/b4dboy17/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · wjlin0/CVE-2022-26134",
                    "author": "wjlin0",
                    "first_seen": "2022-12-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134 GO POC 练习",
                    "summary": "CVE-2022-26134 GO POC 练习",
                    "url": "https://github.com/wjlin0/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · cbk914/CVE-2022-26134_check",
                    "author": "cbk914",
                    "first_seen": "2023-01-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/cbk914/CVE-2022-26134_check"
                },
                {
                    "repository": "PoC-in-GitHub · MaskCyberSecurityTeam/CVE-2022-26134_Behinder_MemShell",
                    "author": "MaskCyberSecurityTeam",
                    "first_seen": "2023-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/MaskCyberSecurityTeam/CVE-2022-26134_Behinder_MemShell"
                },
                {
                    "repository": "PoC-in-GitHub · Muhammad-Ali007/Atlassian_CVE-2022-26134",
                    "author": "Muhammad-Ali007",
                    "first_seen": "2023-07-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134)",
                    "summary": "Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134)",
                    "url": "https://github.com/Muhammad-Ali007/Atlassian_CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · acfirthh/CVE-2022-26134",
                    "author": "acfirthh",
                    "first_seen": "2023-09-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A PoC for CVE-2022-26134 for Educational Purposes and Security Research",
                    "summary": "A PoC for CVE-2022-26134 for Educational Purposes and Security Research",
                    "url": "https://github.com/acfirthh/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · yTxZx/CVE-2022-26134",
                    "author": "yTxZx",
                    "first_seen": "2023-10-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/yTxZx/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · DARKSTUFF-LAB/-CVE-2022-26134",
                    "author": "DARKSTUFF-LAB",
                    "first_seen": "2023-12-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/DARKSTUFF-LAB/-CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · 404fu/CVE-2022-26134-POC",
                    "author": "404fu",
                    "first_seen": "2024-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/404fu/CVE-2022-26134-POC"
                },
                {
                    "repository": "PoC-in-GitHub · xsxtw/CVE-2022-26134",
                    "author": "xsxtw",
                    "first_seen": "2024-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/xsxtw/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · BBD-YZZ/Confluence-RCE",
                    "author": "BBD-YZZ",
                    "first_seen": "2024-05-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "confluence rce (CVE-2021-26084, CVE-2022-26134, CVE-2023-22527)",
                    "summary": "confluence rce (CVE-2021-26084, CVE-2022-26134, CVE-2023-22527)",
                    "url": "https://github.com/BBD-YZZ/Confluence-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · cc3305/CVE-2022-26134",
                    "author": "cc3305",
                    "first_seen": "2024-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134 exploit script",
                    "summary": "CVE-2022-26134 exploit script",
                    "url": "https://github.com/cc3305/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · Gilospy/CVE-2022-26134",
                    "author": "Gilospy",
                    "first_seen": "2024-10-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/Gilospy/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · Khalidhaimur/CVE-2022-26134",
                    "author": "Khalidhaimur",
                    "first_seen": "2025-02-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Active Exploitation of Atlassian’s Questions for Confluence App CVE-2022-26134",
                    "summary": "Active Exploitation of Atlassian’s Questions for Confluence App CVE-2022-26134",
                    "url": "https://github.com/Khalidhaimur/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · tpdlshdmlrkfmcla/cve-2022-26134",
                    "author": "tpdlshdmlrkfmcla",
                    "first_seen": "2025-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "cve-2022-26134 atlassia Confluence Data Center2016 server OGNL %[...}",
                    "summary": "cve-2022-26134 atlassia Confluence Data Center2016 server OGNL %[...}",
                    "url": "https://github.com/tpdlshdmlrkfmcla/cve-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · thetowsif/CVE-2022-26134",
                    "author": "thetowsif",
                    "first_seen": "2025-06-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Atlassian's Confluence Server and Data Center editions (Vulnerable Version > 7.18.1)",
                    "summary": "Atlassian's Confluence Server and Data Center editions (Vulnerable Version > 7.18.1)",
                    "url": "https://github.com/thetowsif/CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · MAHABUB122003/Atlassian-CVE-2022-26134",
                    "author": "MAHABUB122003",
                    "first_seen": "2025-06-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/MAHABUB122003/Atlassian-CVE-2022-26134"
                },
                {
                    "repository": "PoC-in-GitHub · crypt0lith/confluence-ognl-rce",
                    "author": "crypt0lith",
                    "first_seen": "2026-02-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Confluence Unauth RCE (CVE-2022-26134)",
                    "summary": "Confluence Unauth RCE (CVE-2022-26134)",
                    "url": "https://github.com/crypt0lith/confluence-ognl-rce"
                },
                {
                    "repository": "PoC-in-GitHub · roodhelios/CVE-2022-26134-OGNL-Injection",
                    "author": "roodhelios",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-26134 repository",
                    "summary": "",
                    "url": "https://github.com/roodhelios/CVE-2022-26134-OGNL-Injection"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/50952",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ROODHELIOS-CVE-2022-26134-OGNL-INJECTION",
                "https://kitploit.com/ru/tools/github/roodhelios/cve-2022-26134-ognl-injection/",
                "https://github.com/W01fh4cker/Serein",
                "https://github.com/offlinehoster/CVE-2022-26134",
                "https://github.com/ma1am/CVE-2022-26134-Exploit-Detection",
                "https://github.com/jbaines-r7/through_the_wire",
                "https://github.com/crowsec-edtech/CVE-2022-26134",
                "https://github.com/kyxiaxiang/CVE-2022-26134",
                "https://github.com/Brucetg/CVE-2022-26134",
                "https://github.com/shamo0/CVE-2022-26134",
                "https://github.com/SNCKER/CVE-2022-26134",
                "https://github.com/Vulnmachines/Confluence-CVE-2022-26134",
                "https://github.com/axingde/CVE-2022-26134",
                "https://github.com/0xAgun/CVE-2022-26134",
                "https://github.com/abhishekmorla/CVE-2022-26134",
                "https://github.com/hev0x/CVE-2022-26134",
                "https://github.com/archanchoudhury/Confluence-CVE-2022-26134",
                "https://github.com/SIFalcon/confluencePot",
                "https://github.com/vesperp/CVE-2022-26134-Confluence",
                "https://github.com/li8u99/CVE-2022-26134",
                "https://github.com/reubensammut/cve-2022-26134",
                "https://github.com/BeichenDream/CVE-2022-26134-Godzilla-MEMSHELL",
                "https://github.com/alcaparra/CVE-2022-26134",
                "https://github.com/whokilleddb/CVE-2022-26134-Confluence-RCE",
                "https://github.com/Habib0x0/CVE-2022-26134",
                "https://github.com/Y000o/Confluence-CVE-2022-26134",
                "https://github.com/redhuntlabs/ConfluentPwn",
                "https://github.com/secjia/CVE-2022-26134",
                "https://github.com/cai-niao98/CVE-2022-26134",
                "https://github.com/sunny-kathuria/exploit_CVE-2022-26134",
                "https://github.com/KeepWannabe/BotCon",
                "https://github.com/Chocapikk/CVE-2022-26134",
                "https://github.com/AmoloHT/CVE-2022-26134",
                "https://github.com/kh4sh3i/CVE-2022-26134",
                "https://github.com/ColdFusionX/CVE-2022-26134",
                "https://github.com/Luchoane/CVE-2022-26134_conFLU",
                "https://github.com/r1skkam/TryHackMe-Atlassian-CVE-2022-26134",
                "https://github.com/nxtexploit/CVE-2022-26134",
                "https://github.com/Debajyoti0-0/CVE-2022-26134",
                "https://github.com/f4yd4-s3c/cve-2022-26134",
                "https://github.com/coskper-papa/CVE-2022-26134",
                "https://github.com/p4b3l1t0/confusploit",
                "https://github.com/twoning/CVE-2022-26134-PoC",
                "https://github.com/iveresk/cve-2022-26134",
                "https://github.com/keven1z/CVE-2022-26134",
                "https://github.com/shiftsansan/CVE-2022-26134-Console",
                "https://github.com/1337in/CVE-2022-26134web",
                "https://github.com/skhalsa-sigsci/CVE-2022-26134-LAB",
                "https://github.com/yigexioabai/CVE-2022-26134-cve1",
                "https://github.com/kailing0220/CVE-2022-26134",
                "https://github.com/xanszZZ/ATLASSIAN-Confluence_rce",
                "https://github.com/kelemaoya/CVE-2022-26134",
                "https://github.com/CJ-0107/cve-2022-26134",
                "https://github.com/latings/CVE-2022-26134",
                "https://github.com/yyqxi/CVE-2022-26134",
                "https://github.com/b4dboy17/CVE-2022-26134",
                "https://github.com/wjlin0/CVE-2022-26134",
                "https://github.com/cbk914/CVE-2022-26134_check",
                "https://github.com/MaskCyberSecurityTeam/CVE-2022-26134_Behinder_MemShell",
                "https://github.com/Muhammad-Ali007/Atlassian_CVE-2022-26134",
                "https://github.com/acfirthh/CVE-2022-26134",
                "https://github.com/yTxZx/CVE-2022-26134",
                "https://github.com/DARKSTUFF-LAB/-CVE-2022-26134",
                "https://github.com/404fu/CVE-2022-26134-POC",
                "https://github.com/xsxtw/CVE-2022-26134",
                "https://github.com/BBD-YZZ/Confluence-RCE",
                "https://github.com/cc3305/CVE-2022-26134",
                "https://github.com/Gilospy/CVE-2022-26134",
                "https://github.com/Khalidhaimur/CVE-2022-26134",
                "https://github.com/tpdlshdmlrkfmcla/cve-2022-26134",
                "https://github.com/thetowsif/CVE-2022-26134",
                "https://github.com/MAHABUB122003/Atlassian-CVE-2022-26134",
                "https://github.com/crypt0lith/confluence-ognl-rce",
                "https://github.com/roodhelios/CVE-2022-26134-OGNL-Injection"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:45:24Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-02",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2022-25765",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "pdfkit <0.8.6 command injection shell. The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized. (Tested on ver 0.8.6) - CVE-2022-25765",
            "summary": "pdfkit <0.8.6 command injection shell. The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized. (Tested on ver 0.8.6) - CVE-2022-25765",
            "updated_at": "2026-09-01T22:00:00Z",
            "published_at": "2026-09-01T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 111,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · PurpleWaveIO/CVE-2022-25765-pdfkit-Exploit-Reverse-Shell",
                    "author": "PurpleWaveIO",
                    "first_seen": "2022-12-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 20,
                    "title": "pdfkit <0.8.6 command injection shell. The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized. (Tested on ver 0.8.6) - CVE-2022-25765",
                    "summary": "pdfkit <0.8.6 command injection shell. The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized. (Tested on ver 0.8.6) - CVE-2022-25765",
                    "url": "https://github.com/PurpleWaveIO/CVE-2022-25765-pdfkit-Exploit-Reverse-Shell"
                },
                {
                    "repository": "PoC-in-GitHub · Wai-Yan-Kyaw/PDFKitExploit",
                    "author": "Wai-Yan-Kyaw",
                    "first_seen": "2022-12-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A Shell exploit for CVE-2022-25765",
                    "summary": "A Shell exploit for CVE-2022-25765",
                    "url": "https://github.com/Wai-Yan-Kyaw/PDFKitExploit"
                },
                {
                    "repository": "PoC-in-GitHub · LordRNA/CVE-2022-25765",
                    "author": "LordRNA",
                    "first_seen": "2022-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "PoC for Blind RCE for CVE-2022-25765 (Tested in HTB - Precious Machine)",
                    "summary": "PoC for Blind RCE for CVE-2022-25765 (Tested in HTB - Precious Machine)",
                    "url": "https://github.com/LordRNA/CVE-2022-25765"
                },
                {
                    "repository": "PoC-in-GitHub · shamo0/PDFkit-CMD-Injection",
                    "author": "shamo0",
                    "first_seen": "2022-12-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 16,
                    "title": "CVE-2022-25765 pdfkit <0.8.6 command injection.",
                    "summary": "CVE-2022-25765 pdfkit <0.8.6 command injection.",
                    "url": "https://github.com/shamo0/PDFkit-CMD-Injection"
                },
                {
                    "repository": "PoC-in-GitHub · nikn0laty/PDFkit-CMD-Injection-CVE-2022-25765",
                    "author": "nikn0laty",
                    "first_seen": "2023-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "Exploit for CVE-2022-25765 command injection in pdfkit < 0.8.6",
                    "summary": "Exploit for CVE-2022-25765 command injection in pdfkit < 0.8.6",
                    "url": "https://github.com/nikn0laty/PDFkit-CMD-Injection-CVE-2022-25765"
                },
                {
                    "repository": "PoC-in-GitHub · UNICORDev/exploit-CVE-2022-25765",
                    "author": "UNICORDev",
                    "first_seen": "2023-02-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 31,
                    "title": "Exploit for CVE-2022–25765 (pdfkit) - Command Injection",
                    "summary": "Exploit for CVE-2022–25765 (pdfkit) - Command Injection",
                    "url": "https://github.com/UNICORDev/exploit-CVE-2022-25765"
                },
                {
                    "repository": "PoC-in-GitHub · lekosbelas/PDFkit-CMD-Injection",
                    "author": "lekosbelas",
                    "first_seen": "2023-02-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-25765 pdfkit 0.8.6 command injection.",
                    "summary": "CVE-2022-25765 pdfkit 0.8.6 command injection.",
                    "url": "https://github.com/lekosbelas/PDFkit-CMD-Injection"
                },
                {
                    "repository": "PoC-in-GitHub · lowercasenumbers/CVE-2022-25765",
                    "author": "lowercasenumbers",
                    "first_seen": "2024-01-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit for CVE-2022-25765",
                    "summary": "Exploit for CVE-2022-25765",
                    "url": "https://github.com/lowercasenumbers/CVE-2022-25765"
                },
                {
                    "repository": "PoC-in-GitHub · Jeanback1/CVE-2022-25765-exploit",
                    "author": "Jeanback1",
                    "first_seen": "2026-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-25765 repository",
                    "summary": "",
                    "url": "https://github.com/Jeanback1/CVE-2022-25765-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · innocentx0/CVE-2022-25765",
                    "author": "innocentx0",
                    "first_seen": "2026-09-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-25765 | pdfkit v0.8.6 Python PoC",
                    "summary": "CVE-2022-25765 | pdfkit v0.8.6 Python PoC",
                    "url": "https://github.com/innocentx0/CVE-2022-25765"
                }
            ],
            "references": [
                "https://github.com/PurpleWaveIO/CVE-2022-25765-pdfkit-Exploit-Reverse-Shell",
                "https://github.com/Wai-Yan-Kyaw/PDFKitExploit",
                "https://github.com/LordRNA/CVE-2022-25765",
                "https://github.com/shamo0/PDFkit-CMD-Injection",
                "https://github.com/nikn0laty/PDFkit-CMD-Injection-CVE-2022-25765",
                "https://github.com/UNICORDev/exploit-CVE-2022-25765",
                "https://github.com/lekosbelas/PDFkit-CMD-Injection",
                "https://github.com/lowercasenumbers/CVE-2022-25765",
                "https://github.com/Jeanback1/CVE-2022-25765-exploit",
                "https://github.com/innocentx0/CVE-2022-25765"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/PurpleWaveIO/CVE-2022-25765-pdfkit-Exploit-Reverse-Shell"
                }
            ]
        },
        {
            "id": "CVE-2022-24958",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.",
            "updated_at": "2026-09-11T16:17:32.383",
            "published_at": "2022-02-11T06:15:06.717",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-763",
            "what_happened": "drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=89f3594d0de58e8a57d92d497dea9fee3d4b9cda",
                "https://github.com/torvalds/linux/commit/501e38a5531efbd77d5c73c0ba838a889bfc1d74",
                "https://github.com/torvalds/linux/commit/89f3594d0de58e8a57d92d497dea9fee3d4b9cda",
                "https://lists.debian.org/debian-lts-announce/2022/07/msg00000.html",
                "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SUVZA2YVOQJBJTDIDQ5HF5TAU2C6WP6H/",
                "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TCW2KZYJ2H6BKZE3CVLHRIXYDGNYYC5P/",
                "https://security.netapp.com/advisory/ntap-20220225-0008/"
            ],
            "timeline": [
                {
                    "at": "2022-02-11T06:15:06.717",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24958"
                }
            ]
        },
        {
            "id": "CVE-2022-24715",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Icinga Web 2.10 - Authenticated Remote Code Execution",
            "summary": "Icinga Web 2.10 - Authenticated Remote Code Execution",
            "updated_at": "2026-09-08T01:15:21Z",
            "published_at": "2026-09-08T01:15:21Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 127,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "RCE in Icinga Web 2 2.10 with a Go-based exploit.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 51586",
                    "author": "Dante Corona",
                    "first_seen": "2023-07-15",
                    "confidence": "High",
                    "title": "Icinga Web 2.10 - Authenticated Remote Code Execution",
                    "summary": "Icinga Web 2.10 - Authenticated Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/51586",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2022-24715-go",
                    "summary": "RCE in Icinga Web 2 2.10 with a Go-based exploit.",
                    "what_happened": "RCE in Icinga Web 2 2.10 with a Go-based exploit.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D4RKB0N3-CVE-2022-24715-GO",
                        "https://kitploit.com/ru/tools/github/d4rkb0n3/cve-2022-24715-go/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T19:13:09",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D4RKB0N3-CVE-2022-24715-GO"
                },
                {
                    "title": "Exploit for CVE-2022-24715-go",
                    "summary": "RCE in Icinga Web 2 2.10 with a Go-based exploit.",
                    "what_happened": "RCE in Icinga Web 2 2.10 with a Go-based exploit.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D4RKB0N3-CVE-2022-24715-GO",
                        "https://kitploit.com/ru/tools/github/d4rkb0n3/cve-2022-24715-go/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T19:13:09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/d4rkb0n3/cve-2022-24715-go/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/51586",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-D4RKB0N3-CVE-2022-24715-GO",
                "https://kitploit.com/ru/tools/github/d4rkb0n3/cve-2022-24715-go/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:15:21Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/51586"
                }
            ]
        },
        {
            "id": "CVE-2022-24637",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Open Web Analytics 1.7.3 - Remote Code Execution",
            "summary": "Open Web Analytics 1.7.3 - Remote Code Execution",
            "updated_at": "2026-09-09T22:00:00Z",
            "published_at": "2026-09-09T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 225,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 51026",
                    "author": "Jacob Ebben",
                    "first_seen": "2022-11-11",
                    "confidence": "High",
                    "title": "Open Web Analytics 1.7.3 - Remote Code Execution",
                    "summary": "Open Web Analytics 1.7.3 - Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/51026",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · Lay0us/CVE-2022-24637",
                    "author": "Lay0us",
                    "first_seen": "2022-08-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Unauthenticated RCE in Open Web Analytics (OWA) 1.7.3",
                    "summary": "Unauthenticated RCE in Open Web Analytics (OWA) 1.7.3",
                    "url": "https://github.com/Lay0us/CVE-2022-24637"
                },
                {
                    "repository": "PoC-in-GitHub · hupe1980/CVE-2022-24637",
                    "author": "hupe1980",
                    "first_seen": "2022-10-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Open Web Analytics (OWA) - Unauthenticated Remote Code Execution",
                    "summary": "Open Web Analytics (OWA) - Unauthenticated Remote Code Execution",
                    "url": "https://github.com/hupe1980/CVE-2022-24637"
                },
                {
                    "repository": "PoC-in-GitHub · icebreack/CVE-2022-24637",
                    "author": "icebreack",
                    "first_seen": "2022-11-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "FIxed exploit for CVE-2022-24637 (original xplt: https://www.exploit-db.com/exploits/51026)",
                    "summary": "FIxed exploit for CVE-2022-24637 (original xplt: https://www.exploit-db.com/exploits/51026)",
                    "url": "https://github.com/icebreack/CVE-2022-24637"
                },
                {
                    "repository": "PoC-in-GitHub · Pflegusch/CVE-2022-24637",
                    "author": "Pflegusch",
                    "first_seen": "2023-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Open Web Analytics 1.7.3 - Remote Code Execution",
                    "summary": "Open Web Analytics 1.7.3 - Remote Code Execution",
                    "url": "https://github.com/Pflegusch/CVE-2022-24637"
                },
                {
                    "repository": "PoC-in-GitHub · 0xM4hm0ud/CVE-2022-24637",
                    "author": "0xM4hm0ud",
                    "first_seen": "2023-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Unauthenticated RCE in Open Web Analytics version <1.7.4",
                    "summary": "Unauthenticated RCE in Open Web Analytics version <1.7.4",
                    "url": "https://github.com/0xM4hm0ud/CVE-2022-24637"
                },
                {
                    "repository": "PoC-in-GitHub · 0xRyuk/CVE-2022-24637",
                    "author": "0xRyuk",
                    "first_seen": "2023-08-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2",
                    "summary": "Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2",
                    "url": "https://github.com/0xRyuk/CVE-2022-24637"
                },
                {
                    "repository": "PoC-in-GitHub · PrinceAikinsBaidoo/CVE-2022-24637",
                    "author": "PrinceAikinsBaidoo",
                    "first_seen": "2026-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-24637 repository",
                    "summary": "",
                    "url": "https://github.com/PrinceAikinsBaidoo/CVE-2022-24637"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/51026",
                "https://github.com/Lay0us/CVE-2022-24637",
                "https://github.com/hupe1980/CVE-2022-24637",
                "https://github.com/icebreack/CVE-2022-24637",
                "https://github.com/Pflegusch/CVE-2022-24637",
                "https://github.com/0xM4hm0ud/CVE-2022-24637",
                "https://github.com/0xRyuk/CVE-2022-24637",
                "https://github.com/PrinceAikinsBaidoo/CVE-2022-24637"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/51026"
                }
            ]
        },
        {
            "id": "CVE-2022-24521",
            "vendor": "Microsoft",
            "product": "Windows",
            "title": "Microsoft Windows CLFS Driver Privilege Escalation Vulnerability",
            "summary": "Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.",
            "updated_at": "2026-08-25T13:38:35Z",
            "published_at": "2026-08-25T13:38:35Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 97,
            "kev": true,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2022-24481-POC CVE-2022-24481 CVE-2022-24521",
                    "summary": "CLFS pContainer pointer corruption in CClfsContainer::Close enables arbitrary code execution.",
                    "what_happened": "CLFS pContainer pointer corruption in CClfsContainer::Close enables arbitrary code execution.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FR4NKXIXI-CVE-2022-24481-POC",
                        "https://kitploit.com/ru/tools/github/fr4nkxixi/cve-2022-24481-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T15:38:35",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FR4NKXIXI-CVE-2022-24481-POC"
                },
                {
                    "title": "Exploit for CVE-2022-24481-POC CVE-2022-24481 CVE-2022-24521",
                    "summary": "CLFS pContainer pointer corruption in CClfsContainer::Close enables arbitrary code execution.",
                    "what_happened": "CLFS pContainer pointer corruption in CClfsContainer::Close enables arbitrary code execution.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FR4NKXIXI-CVE-2022-24481-POC",
                        "https://kitploit.com/ru/tools/github/fr4nkxixi/cve-2022-24481-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-25T15:38:35",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/fr4nkxixi/cve-2022-24481-poc/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FR4NKXIXI-CVE-2022-24481-POC",
                "https://kitploit.com/ru/tools/github/fr4nkxixi/cve-2022-24481-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T13:38:35Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2022-24481",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2022-24481-POC CVE-2022-24481 CVE-2022-24521",
            "summary": "CLFS pContainer pointer corruption in CClfsContainer::Close enables arbitrary code execution.",
            "updated_at": "2026-08-25T13:38:35Z",
            "published_at": "2026-08-25T13:38:35Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 65,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "CLFS pContainer pointer corruption in CClfsContainer::Close enables arbitrary code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2022-24481-POC CVE-2022-24481 CVE-2022-24521",
                    "summary": "CLFS pContainer pointer corruption in CClfsContainer::Close enables arbitrary code execution.",
                    "what_happened": "CLFS pContainer pointer corruption in CClfsContainer::Close enables arbitrary code execution.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FR4NKXIXI-CVE-2022-24481-POC",
                        "https://kitploit.com/ru/tools/github/fr4nkxixi/cve-2022-24481-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T15:38:35",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FR4NKXIXI-CVE-2022-24481-POC"
                },
                {
                    "title": "Exploit for CVE-2022-24481-POC CVE-2022-24481 CVE-2022-24521",
                    "summary": "CLFS pContainer pointer corruption in CClfsContainer::Close enables arbitrary code execution.",
                    "what_happened": "CLFS pContainer pointer corruption in CClfsContainer::Close enables arbitrary code execution.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FR4NKXIXI-CVE-2022-24481-POC",
                        "https://kitploit.com/ru/tools/github/fr4nkxixi/cve-2022-24481-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-25T15:38:35",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/fr4nkxixi/cve-2022-24481-poc/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FR4NKXIXI-CVE-2022-24481-POC",
                "https://kitploit.com/ru/tools/github/fr4nkxixi/cve-2022-24481-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T13:38:35Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FR4NKXIXI-CVE-2022-24481-POC"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2022-23773",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2022-23773-Reproduce exploit",
            "summary": "Exploit for CVE-2022-23773. CVSS 7.5.",
            "updated_at": "2026-09-05T12:41:23Z",
            "published_at": "2026-09-05T12:41:23Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 43,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-05T12:41:23+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2022-23773-Reproduce exploit",
                    "summary": "Exploit for CVE-2022-23773. CVSS 7.5.",
                    "cvss": 7.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YOUSHENGLIU-CVE-2022-23773-REPRODUCE"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YOUSHENGLIU-CVE-2022-23773-REPRODUCE"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:41:23Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YOUSHENGLIU-CVE-2022-23773-REPRODUCE"
                }
            ]
        },
        {
            "id": "CVE-2022-22972",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2022-22972",
            "summary": "Auth bypass in VMware Workspace ONE, vIDM, and vRealize Automation 7.6 via Host header manipulation.",
            "updated_at": "2026-09-05T02:43:56Z",
            "published_at": "2026-09-05T02:43:56Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Auth bypass in VMware Workspace ONE, vIDM, and vRealize Automation 7.6 via Host header manipulation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2022-22972",
                    "summary": "Auth bypass in VMware Workspace ONE, vIDM, and vRealize Automation 7.6 via Host header manipulation.",
                    "what_happened": "Auth bypass in VMware Workspace ONE, vIDM, and vRealize Automation 7.6 via Host header manipulation.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HORIZON3AI-CVE-2022-22972",
                        "https://kitploit.com/ru/tools/github/horizon3ai/cve-2022-22972/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T04:43:56",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HORIZON3AI-CVE-2022-22972"
                },
                {
                    "title": "Exploit for CVE-2022-22972",
                    "summary": "Auth bypass in VMware Workspace ONE, vIDM, and vRealize Automation 7.6 via Host header manipulation.",
                    "what_happened": "Auth bypass in VMware Workspace ONE, vIDM, and vRealize Automation 7.6 via Host header manipulation.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HORIZON3AI-CVE-2022-22972",
                        "https://kitploit.com/ru/tools/github/horizon3ai/cve-2022-22972/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T04:43:56",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/horizon3ai/cve-2022-22972/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HORIZON3AI-CVE-2022-22972",
                "https://kitploit.com/ru/tools/github/horizon3ai/cve-2022-22972/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T02:43:56Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HORIZON3AI-CVE-2022-22972"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2022-22965",
            "vendor": "VMware",
            "product": "Spring Framework",
            "title": "Spring Framework JDK 9+ Remote Code Execution Vulnerability",
            "summary": "Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.",
            "updated_at": "2026-08-28T19:19:40Z",
            "published_at": "2026-08-28T19:19:40Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 85,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Spring4Shell-POC CVE-2022-22965",
                    "summary": "RCE in Spring framework (CVE-2022-22965) with POC and vulnerable Tomcat server.",
                    "what_happened": "RCE in Spring framework (CVE-2022-22965) with POC and vulnerable Tomcat server.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BOBTHESHOPLIFTER-SPRING4SHELL-POC",
                        "https://kitploit.com/ar/tools/github/bobtheshoplifter/spring4shell-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-28T21:19:40",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BOBTHESHOPLIFTER-SPRING4SHELL-POC"
                },
                {
                    "title": "Exploit for Spring4Shell-POC CVE-2022-22965",
                    "summary": "RCE in Spring framework (CVE-2022-22965) with POC and vulnerable Tomcat server.",
                    "what_happened": "RCE in Spring framework (CVE-2022-22965) with POC and vulnerable Tomcat server.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BOBTHESHOPLIFTER-SPRING4SHELL-POC",
                        "https://kitploit.com/ar/tools/github/bobtheshoplifter/spring4shell-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-08-28T21:19:40",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/bobtheshoplifter/spring4shell-poc/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BOBTHESHOPLIFTER-SPRING4SHELL-POC",
                "https://kitploit.com/ar/tools/github/bobtheshoplifter/spring4shell-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-08-28T19:19:40Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-04",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2022-22963",
            "vendor": "VMware Tanzu",
            "product": "Spring Cloud",
            "title": "VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability",
            "summary": "When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.",
            "updated_at": "2026-08-21T22:00:00Z",
            "published_at": "2026-08-21T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 925,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 51577",
                    "author": "GatoGamer1155",
                    "first_seen": "2023-07-11",
                    "confidence": "High",
                    "title": "Spring Cloud 3.2.2 - Remote Command Execution (RCE)",
                    "summary": "Spring Cloud 3.2.2 - Remote Command Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/51577",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · hktalent/spring-spel-0day-poc",
                    "author": "hktalent",
                    "first_seen": "2022-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 353,
                    "title": "spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963",
                    "summary": "spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963",
                    "url": "https://github.com/hktalent/spring-spel-0day-poc"
                },
                {
                    "repository": "PoC-in-GitHub · dinosn/CVE-2022-22963",
                    "author": "dinosn",
                    "first_seen": "2022-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 116,
                    "title": "CVE-2022-22963 PoC",
                    "summary": "CVE-2022-22963 PoC",
                    "url": "https://github.com/dinosn/CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · RanDengShiFu/CVE-2022-22963",
                    "author": "RanDengShiFu",
                    "first_seen": "2022-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 15,
                    "title": "CVE-2022-22963 Spring-Cloud-Function-SpEL_RCE_exploit",
                    "summary": "CVE-2022-22963 Spring-Cloud-Function-SpEL_RCE_exploit",
                    "url": "https://github.com/RanDengShiFu/CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · darryk10/CVE-2022-22963",
                    "author": "darryk10",
                    "first_seen": "2022-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 34,
                    "title": "CVE-2022-22963 repository",
                    "summary": "",
                    "url": "https://github.com/darryk10/CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · Kirill89/CVE-2022-22963-PoC",
                    "author": "Kirill89",
                    "first_seen": "2022-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2022-22963 repository",
                    "summary": "",
                    "url": "https://github.com/Kirill89/CVE-2022-22963-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · stevemats/Spring0DayCoreExploit",
                    "author": "stevemats",
                    "first_seen": "2022-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "{ Spring Core 0day CVE-2022-22963 }",
                    "summary": "{ Spring Core 0day CVE-2022-22963 }",
                    "url": "https://github.com/stevemats/Spring0DayCoreExploit"
                },
                {
                    "repository": "PoC-in-GitHub · puckiestyle/CVE-2022-22963",
                    "author": "puckiestyle",
                    "first_seen": "2022-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-22963 repository",
                    "summary": "",
                    "url": "https://github.com/puckiestyle/CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · me2nuk/CVE-2022-22963",
                    "author": "me2nuk",
                    "first_seen": "2022-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": "Spring Cloud Function Vulnerable Application / CVE-2022-22963",
                    "summary": "Spring Cloud Function Vulnerable Application / CVE-2022-22963",
                    "url": "https://github.com/me2nuk/CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · kh4sh3i/Spring-CVE",
                    "author": "kh4sh3i",
                    "first_seen": "2022-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux RCE termed \"SpringShell\".",
                    "summary": "This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux RCE termed \"SpringShell\".",
                    "url": "https://github.com/kh4sh3i/Spring-CVE"
                },
                {
                    "repository": "PoC-in-GitHub · AayushmanThapaMagar/CVE-2022-22963",
                    "author": "AayushmanThapaMagar",
                    "first_seen": "2022-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "POC for CVE-2022-22963",
                    "summary": "POC for CVE-2022-22963",
                    "url": "https://github.com/AayushmanThapaMagar/CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · twseptian/cve-2022-22963",
                    "author": "twseptian",
                    "first_seen": "2022-04-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Spring Cloud Function SpEL - cve-2022-22963",
                    "summary": "Spring Cloud Function SpEL - cve-2022-22963",
                    "url": "https://github.com/twseptian/cve-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · SealPaPaPa/SpringCloudFunction-Research",
                    "author": "SealPaPaPa",
                    "first_seen": "2022-04-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-22963 research",
                    "summary": "CVE-2022-22963 research",
                    "url": "https://github.com/SealPaPaPa/SpringCloudFunction-Research"
                },
                {
                    "repository": "PoC-in-GitHub · G01d3nW01f/CVE-2022-22963",
                    "author": "G01d3nW01f",
                    "first_seen": "2022-04-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-22963 repository",
                    "summary": "",
                    "url": "https://github.com/G01d3nW01f/CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · k3rwin/spring-cloud-function-rce",
                    "author": "k3rwin",
                    "first_seen": "2022-04-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "Spring Cloud Function SPEL表达式注入漏洞（CVE-2022-22963）",
                    "summary": "Spring Cloud Function SPEL表达式注入漏洞（CVE-2022-22963）",
                    "url": "https://github.com/k3rwin/spring-cloud-function-rce"
                },
                {
                    "repository": "PoC-in-GitHub · iliass-dahman/CVE-2022-22963-POC",
                    "author": "iliass-dahman",
                    "first_seen": "2023-01-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2022-22963 repository",
                    "summary": "",
                    "url": "https://github.com/iliass-dahman/CVE-2022-22963-POC"
                },
                {
                    "repository": "PoC-in-GitHub · charis3306/CVE-2022-22963",
                    "author": "charis3306",
                    "first_seen": "2023-03-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "spring cloud function 一键利用工具! by charis 博客https://charis3306.top/",
                    "summary": "spring cloud function 一键利用工具! by charis 博客https://charis3306.top/",
                    "url": "https://github.com/charis3306/CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · lemmyz4n3771/CVE-2022-22963-PoC",
                    "author": "lemmyz4n3771",
                    "first_seen": "2023-03-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2022-22963 RCE PoC in python",
                    "summary": "CVE-2022-22963 RCE PoC in python",
                    "url": "https://github.com/lemmyz4n3771/CVE-2022-22963-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · J0ey17/CVE-2022-22963_Reverse-Shell-Exploit",
                    "author": "J0ey17",
                    "first_seen": "2023-03-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 24,
                    "title": "CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify if the vulnerability exists, and if it does, will give you a reverse shell.",
                    "summary": "CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify if the vulnerability exists, and if it does, will give you a reverse shell.",
                    "url": "https://github.com/J0ey17/CVE-2022-22963_Reverse-Shell-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Mustafa1986/CVE-2022-22963",
                    "author": "Mustafa1986",
                    "first_seen": "2023-03-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-22963 repository",
                    "summary": "",
                    "url": "https://github.com/Mustafa1986/CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · SourM1lk/CVE-2022-22963-Exploit",
                    "author": "SourM1lk",
                    "first_seen": "2023-04-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Rust-based exploit for the CVE-2022-22963 vulnerability",
                    "summary": "Rust-based exploit for the CVE-2022-22963 vulnerability",
                    "url": "https://github.com/SourM1lk/CVE-2022-22963-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · randallbanner/Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE",
                    "author": "randallbanner",
                    "first_seen": "2023-04-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2022-22963 repository",
                    "summary": "",
                    "url": "https://github.com/randallbanner/Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · gunzf0x/CVE-2022-22963",
                    "author": "gunzf0x",
                    "first_seen": "2023-05-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Binaries for CVE-2022-22963",
                    "summary": "Binaries for CVE-2022-22963",
                    "url": "https://github.com/gunzf0x/CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · nikn0laty/RCE-in-Spring-Cloud-CVE-2022-22963",
                    "author": "nikn0laty",
                    "first_seen": "2023-05-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit for CVE-2022-22963 remote command execution in Spring Cloud Function",
                    "summary": "Exploit for CVE-2022-22963 remote command execution in Spring Cloud Function",
                    "url": "https://github.com/nikn0laty/RCE-in-Spring-Cloud-CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · BearClaw96/CVE-2022-22963-Poc-Bearcules",
                    "author": "BearClaw96",
                    "first_seen": "2023-10-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is a POC for CVE-2022-22963",
                    "summary": "This is a POC for CVE-2022-22963",
                    "url": "https://github.com/BearClaw96/CVE-2022-22963-Poc-Bearcules"
                },
                {
                    "repository": "PoC-in-GitHub · xmqaq/CVE-2022-22963",
                    "author": "xmqaq",
                    "first_seen": "2023-12-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-22963-poc",
                    "summary": "CVE-2022-22963-poc",
                    "url": "https://github.com/xmqaq/CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · jrbH4CK/CVE-2022-22963",
                    "author": "jrbH4CK",
                    "first_seen": "2024-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-22963 repository",
                    "summary": "",
                    "url": "https://github.com/jrbH4CK/CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · Shayz614/CVE-2022-22963",
                    "author": "Shayz614",
                    "first_seen": "2024-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE to CTF FP",
                    "summary": "CVE to CTF FP",
                    "url": "https://github.com/Shayz614/CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · 808rsec/CVE-2022-22963",
                    "author": "808rsec",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Simple exploit",
                    "summary": "Simple exploit",
                    "url": "https://github.com/808rsec/CVE-2022-22963"
                },
                {
                    "repository": "PoC-in-GitHub · r4y-br/CVE-2022-22963",
                    "author": "r4y-br",
                    "first_seen": "2026-08-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Educational proof-of-concept automation for CVE-2022-22963, demonstrated in an authorized Hack The Box lab environment.",
                    "summary": "Educational proof-of-concept automation for CVE-2022-22963, demonstrated in an authorized Hack The Box lab environment.",
                    "url": "https://github.com/r4y-br/CVE-2022-22963"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/51577",
                "https://github.com/hktalent/spring-spel-0day-poc",
                "https://github.com/dinosn/CVE-2022-22963",
                "https://github.com/RanDengShiFu/CVE-2022-22963",
                "https://github.com/darryk10/CVE-2022-22963",
                "https://github.com/Kirill89/CVE-2022-22963-PoC",
                "https://github.com/stevemats/Spring0DayCoreExploit",
                "https://github.com/puckiestyle/CVE-2022-22963",
                "https://github.com/me2nuk/CVE-2022-22963",
                "https://github.com/kh4sh3i/Spring-CVE",
                "https://github.com/AayushmanThapaMagar/CVE-2022-22963",
                "https://github.com/twseptian/cve-2022-22963",
                "https://github.com/SealPaPaPa/SpringCloudFunction-Research",
                "https://github.com/G01d3nW01f/CVE-2022-22963",
                "https://github.com/k3rwin/spring-cloud-function-rce",
                "https://github.com/iliass-dahman/CVE-2022-22963-POC",
                "https://github.com/charis3306/CVE-2022-22963",
                "https://github.com/lemmyz4n3771/CVE-2022-22963-PoC",
                "https://github.com/J0ey17/CVE-2022-22963_Reverse-Shell-Exploit",
                "https://github.com/Mustafa1986/CVE-2022-22963",
                "https://github.com/SourM1lk/CVE-2022-22963-Exploit",
                "https://github.com/randallbanner/Spring-Cloud-Function-Vulnerability-CVE-2022-22963-RCE",
                "https://github.com/gunzf0x/CVE-2022-22963",
                "https://github.com/nikn0laty/RCE-in-Spring-Cloud-CVE-2022-22963",
                "https://github.com/BearClaw96/CVE-2022-22963-Poc-Bearcules",
                "https://github.com/xmqaq/CVE-2022-22963",
                "https://github.com/jrbH4CK/CVE-2022-22963",
                "https://github.com/Shayz614/CVE-2022-22963",
                "https://github.com/808rsec/CVE-2022-22963",
                "https://github.com/r4y-br/CVE-2022-22963"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-08-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2022-22954",
            "vendor": "VMware",
            "product": "Workspace ONE Access and Identity Manager",
            "title": "VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability",
            "summary": "VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.",
            "updated_at": "2026-09-11T18:30:47Z",
            "published_at": "2026-09-11T18:30:47Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 61,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2022-22954-POC",
                    "summary": "Critical (CVSS 9.8) vulnerability in VMware Workspace ONE Access Appliance and Identity Manager.",
                    "what_happened": "Critical (CVSS 9.8) vulnerability in VMware Workspace ONE Access Appliance and Identity Manager.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MHURTS-CVE-2022-22954-POC",
                        "https://kitploit.com/ru/tools/github/mhurts/cve-2022-22954-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-02T23:43:13",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MHURTS-CVE-2022-22954-POC"
                },
                {
                    "title": "Exploit for CVE-2022-22954-POC",
                    "summary": "Critical (CVSS 9.8) vulnerability in VMware Workspace ONE Access Appliance and Identity Manager.",
                    "what_happened": "Critical (CVSS 9.8) vulnerability in VMware Workspace ONE Access Appliance and Identity Manager.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MHURTS-CVE-2022-22954-POC",
                        "https://kitploit.com/ru/tools/github/mhurts/cve-2022-22954-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-02T23:43:13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/mhurts/cve-2022-22954-poc/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MHURTS-CVE-2022-22954-POC",
                "https://kitploit.com/ru/tools/github/mhurts/cve-2022-22954-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T18:30:47Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-14",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2022-22718",
            "vendor": "Microsoft",
            "product": "Windows",
            "title": "Microsoft Windows Print Spooler Privilege Escalation Vulnerability",
            "summary": "Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation.",
            "updated_at": "2026-09-13T18:32:33Z",
            "published_at": "2026-09-13T18:32:33Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 25,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:32:33+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "SpoolFool exploit",
                    "summary": "Exploit for CVE-2022-21999 and CVE-2022-22718. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LY4K-SPOOLFOOL"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LY4K-SPOOLFOOL"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:32:33Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-19",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2022-22715",
            "vendor": "Microsoft",
            "product": "Windows 10 Version 1809",
            "title": "Blogpost: https://whereisk0shl.top/post/break-me-out-of-sandbox-in-old-pipe-cve-2022-22715-windows-dirty-pipe",
            "summary": "Named Pipe File System Elevation of Privilege Vulnerability",
            "updated_at": "2026-06-17T04:28:51.017",
            "published_at": "2022-02-09T17:15:10.117",
            "cvss": 7.8,
            "confidence": 55,
            "confidence_label": "review",
            "affected": "10.0.17763.0 through before 10.0.17763.2565 (custom); 10.0.0 through before 10.0.17763.2565 (custom); 10.0.0 through before 10.0.18363.2094 (custom); 10.0.0 through before 10.0.19043.1526 (custom); 10.0.20348.0 through before 10.0.20348.524 (custom); 10.0.0 through before 10.0.19042.1526 (custom); 10.0.0 through before 10.0.22000.493 (custom); 10.0.19043.0 through before 10.0.19044.1526 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-191",
            "what_happened": "Named Pipe File System Elevation of Privilege Vulnerability",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · vportal/CVE-2022-22715",
                    "author": "vportal",
                    "first_seen": "2026-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Blogpost: https://whereisk0shl.top/post/break-me-out-of-sandbox-in-old-pipe-cve-2022-22715-windows-dirty-pipe",
                    "summary": "Blogpost: https://whereisk0shl.top/post/break-me-out-of-sandbox-in-old-pipe-cve-2022-22715-windows-dirty-pipe",
                    "url": "https://github.com/vportal/CVE-2022-22715"
                }
            ],
            "references": [
                "https://github.com/vportal/CVE-2022-22715",
                "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22715"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/vportal/CVE-2022-22715"
                },
                {
                    "at": "2022-02-09T17:15:10.117",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-22715"
                }
            ],
            "enrichment_checked_at": "2026-09-16T22:05:33Z",
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2022-22706",
            "vendor": "Arm",
            "product": "Mali Graphics Processing Unit (GPU)",
            "title": "Arm Mali GPU Kernel Driver Unspecified Vulnerability",
            "summary": "Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages.",
            "updated_at": "2026-09-07T19:21:37Z",
            "published_at": "2026-09-07T19:21:37Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 100,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2022-22706-poc CVE-2021-39793 CVE-2022-22706",
                    "summary": "Page-cache write in Arm Mali GPU driver r35p0 via writable mapping of read-only file page cache.",
                    "what_happened": "Page-cache write in Arm Mali GPU driver r35p0 via writable mapping of read-only file page cache.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BYT3QUESTER-CVE-2022-22706-POC",
                        "https://kitploit.com/ru/tools/github/byt3quester/cve-2022-22706-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-24T12:00:02",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BYT3QUESTER-CVE-2022-22706-POC"
                },
                {
                    "title": "Exploit for CVE-2022-22706-poc CVE-2021-39793 CVE-2022-22706",
                    "summary": "Page-cache write in Arm Mali GPU driver r35p0 via writable mapping of read-only file page cache.",
                    "what_happened": "Page-cache write in Arm Mali GPU driver r35p0 via writable mapping of read-only file page cache.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BYT3QUESTER-CVE-2022-22706-POC",
                        "https://kitploit.com/ru/tools/github/byt3quester/cve-2022-22706-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-24T12:00:02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/byt3quester/cve-2022-22706-poc/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BYT3QUESTER-CVE-2022-22706-POC",
                "https://kitploit.com/ru/tools/github/byt3quester/cve-2022-22706-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:21:37Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-03-30",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2022-22639",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2022-22639 exploit",
            "summary": "Exploit for CVE-2022-22639. CVSS 7.8.",
            "updated_at": "2026-09-14T04:51:48Z",
            "published_at": "2026-09-14T04:51:48Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 23,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Root privilege escalation in macOS SUHelper via InstallAssistant.gz file.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2022-22639",
                    "summary": "Root privilege escalation in macOS SUHelper via InstallAssistant.gz file.",
                    "what_happened": "Root privilege escalation in macOS SUHelper via InstallAssistant.gz file.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JHFTSS-CVE-2022-22639",
                        "https://kitploit.com/ru/tools/github/jhftss/cve-2022-22639/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T21:23:53",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JHFTSS-CVE-2022-22639"
                },
                {
                    "title": "Exploit for CVE-2022-22639",
                    "summary": "Root privilege escalation in macOS SUHelper via InstallAssistant.gz file.",
                    "what_happened": "Root privilege escalation in macOS SUHelper via InstallAssistant.gz file.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JHFTSS-CVE-2022-22639",
                        "https://kitploit.com/ru/tools/github/jhftss/cve-2022-22639/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T21:23:53",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/jhftss/cve-2022-22639/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JHFTSS-CVE-2022-22639",
                "https://kitploit.com/ru/tools/github/jhftss/cve-2022-22639/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T04:51:48Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JHFTSS-CVE-2022-22639"
                }
            ]
        },
        {
            "id": "CVE-2022-21999",
            "vendor": "Microsoft",
            "product": "Windows",
            "title": "Microsoft Windows Print Spooler Privilege Escalation Vulnerability",
            "summary": "Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.",
            "updated_at": "2026-09-13T18:32:33Z",
            "published_at": "2026-09-13T18:32:33Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 37,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · ly4k/SpoolFool",
                    "author": "ly4k",
                    "first_seen": "2022-02-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 793,
                    "title": "Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)",
                    "summary": "Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)",
                    "url": "https://github.com/ly4k/SpoolFool"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:32:33+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "SpoolFool exploit",
                    "summary": "Exploit for CVE-2022-21999 and CVE-2022-22718. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LY4K-SPOOLFOOL"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/ly4k/SpoolFool",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LY4K-SPOOLFOOL"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:32:33Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2022-21907",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution",
            "summary": "Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution",
            "updated_at": "2026-09-05T08:10:53Z",
            "published_at": "2026-09-05T08:10:53Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 264,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "CVE-2022-21907: RCE in Windows http.sys IIS module causing DoS via payload upload.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 51575",
                    "author": "nu11secur1ty",
                    "first_seen": "2023-07-07",
                    "confidence": "High",
                    "title": "Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution",
                    "summary": "Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/51575",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-14T04:51:26+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "nmap-CVE-2022-21907 exploit",
                    "summary": "Exploit for CVE-2022-21907. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GPIECHNIK2-NMAP-CVE-2022-21907"
                },
                {
                    "title": "Exploit for nmap-CVE-2022-21907",
                    "summary": "CVE-2022-21907: RCE in Windows http.sys IIS module causing DoS via payload upload.",
                    "what_happened": "CVE-2022-21907: RCE in Windows http.sys IIS module causing DoS via payload upload.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GPIECHNIK2-NMAP-CVE-2022-21907",
                        "https://kitploit.com/ru/tools/github/gpiechnik2/nmap-cve-2022-21907/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T08:49:02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/gpiechnik2/nmap-cve-2022-21907/"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-08T14:45:13+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2022-21907 exploit",
                    "summary": "Exploit for CVE-2022-21907. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KAMAL-MAROUANE-CVE-2022-21907"
                },
                {
                    "title": "Exploit for CVE-2021-31166",
                    "summary": "DoS in IIS Web Server via malformed Accept-Encoding header with double commas causing BSOD.",
                    "what_happened": "DoS in IIS Web Server via malformed Accept-Encoding header with double commas causing BSOD.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MAURICELAMBERT-CVE-2021-31166",
                        "https://kitploit.com/en/tools/github/mauricelambert/cve-2021-31166/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-09T17:29:32",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MAURICELAMBERT-CVE-2021-31166"
                },
                {
                    "title": "Exploit for CVE-2021-31166",
                    "summary": "DoS in IIS Web Server via malformed Accept-Encoding header with double commas causing BSOD.",
                    "what_happened": "DoS in IIS Web Server via malformed Accept-Encoding header with double commas causing BSOD.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MAURICELAMBERT-CVE-2021-31166",
                        "https://kitploit.com/en/tools/github/mauricelambert/cve-2021-31166/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-09T17:29:32",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/mauricelambert/cve-2021-31166/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/51575",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GPIECHNIK2-NMAP-CVE-2022-21907",
                "https://kitploit.com/ru/tools/github/gpiechnik2/nmap-cve-2022-21907/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KAMAL-MAROUANE-CVE-2022-21907",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MAURICELAMBERT-CVE-2021-31166",
                "https://kitploit.com/en/tools/github/mauricelambert/cve-2021-31166/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:10:53Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/51575"
                }
            ]
        },
        {
            "id": "CVE-2022-21449",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2018-0114 CVE-2019-20933 CVE-2020-28042 CVE-2020-28637 C",
            "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
            "updated_at": "2026-09-10T05:59:46Z",
            "published_at": "2026-09-10T05:59:46Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 57,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2020-28042 CVE-2020-28637 CVE-2022-21449",
                    "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                        "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-10T07:59:46",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299"
                },
                {
                    "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2020-28042 CVE-2020-28637 CVE-2022-21449",
                    "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                        "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-10T07:59:46",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T05:59:46Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2022-20494",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2022-20494",
            "summary": "Memory exhaustion DoS in Android NotificationManagerService via addAutomaticZenRule API.",
            "updated_at": "2026-09-04T00:32:58Z",
            "published_at": "2026-09-04T00:32:58Z",
            "cvss": 5.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 29,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Memory exhaustion DoS in Android NotificationManagerService via addAutomaticZenRule API.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2022-20494",
                    "summary": "Memory exhaustion DoS in Android NotificationManagerService via addAutomaticZenRule API.",
                    "what_happened": "Memory exhaustion DoS in Android NotificationManagerService via addAutomaticZenRule API.",
                    "cvss": 5.5,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SUPERSONIC-CVE-2022-20494",
                        "https://kitploit.com/ru/tools/github/supersonic/cve-2022-20494/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T02:32:58",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SUPERSONIC-CVE-2022-20494"
                },
                {
                    "title": "Exploit for CVE-2022-20494",
                    "summary": "Memory exhaustion DoS in Android NotificationManagerService via addAutomaticZenRule API.",
                    "what_happened": "Memory exhaustion DoS in Android NotificationManagerService via addAutomaticZenRule API.",
                    "cvss": 5.5,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SUPERSONIC-CVE-2022-20494",
                        "https://kitploit.com/ru/tools/github/supersonic/cve-2022-20494/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T02:32:58",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/supersonic/cve-2022-20494/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SUPERSONIC-CVE-2022-20494",
                "https://kitploit.com/ru/tools/github/supersonic/cve-2022-20494/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T00:32:58Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SUPERSONIC-CVE-2022-20494"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
        },
        {
            "id": "CVE-2022-19052",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "cve-2018-19052 exploit",
            "summary": "Exploit for CVE-2018-19052 and CVE-2022-19052. CVSS 7.5.",
            "updated_at": "2026-09-08T14:47:08Z",
            "published_at": "2026-09-08T14:47:08Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 65,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Path traversal in mod_alias enabling directory listing one level above the alias destination.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for cve-2018-19052 CVE-2018-19052 CVE-2022-19052",
                    "summary": "Path traversal in mod_alias enabling directory listing one level above the alias destination.",
                    "what_happened": "Path traversal in mod_alias enabling directory listing one level above the alias destination.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IVERESK-CVE-2018-19052",
                        "https://kitploit.com/ru/tools/github/iveresk/cve-2018-19052/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T09:09:19",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IVERESK-CVE-2018-19052"
                },
                {
                    "title": "Exploit for cve-2018-19052 CVE-2018-19052 CVE-2022-19052",
                    "summary": "Path traversal in mod_alias enabling directory listing one level above the alias destination.",
                    "what_happened": "Path traversal in mod_alias enabling directory listing one level above the alias destination.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IVERESK-CVE-2018-19052",
                        "https://kitploit.com/ru/tools/github/iveresk/cve-2018-19052/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T09:09:19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/iveresk/cve-2018-19052/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IVERESK-CVE-2018-19052",
                "https://kitploit.com/ru/tools/github/iveresk/cve-2018-19052/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T14:47:08Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IVERESK-CVE-2018-19052"
                }
            ],
            "enrichment_checked_at": "2026-09-09T10:05:36Z"
        },
        {
            "id": "CVE-2022-4140",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "WordPress plugin Welcart e-Commerce < 2.8.5 - Arbitrary File Read",
            "summary": "WordPress plugin Welcart e-Commerce < 2.8.5 - Arbitrary File Read",
            "updated_at": "2026-09-06T22:00:00Z",
            "published_at": "2026-09-06T22:00:00Z",
            "cvss": 0,
            "confidence": 80,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · anirbala98/CVE-2022-4140",
                    "author": "anirbala98",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "WordPress plugin Welcart e-Commerce < 2.8.5 - Arbitrary File Read",
                    "summary": "WordPress plugin Welcart e-Commerce < 2.8.5 - Arbitrary File Read",
                    "url": "https://github.com/anirbala98/CVE-2022-4140"
                }
            ],
            "references": [
                "https://github.com/anirbala98/CVE-2022-4140"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/anirbala98/CVE-2022-4140"
                }
            ]
        },
        {
            "id": "CVE-2022-2869",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2022-2869 repository",
            "summary": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "updated_at": "2026-09-07T22:00:00Z",
            "published_at": "2026-09-07T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 30,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · halahajyahia/CVE-2022-2869-detector",
                    "author": "halahajyahia",
                    "first_seen": "2026-09-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-2869 repository",
                    "summary": "",
                    "url": "https://github.com/halahajyahia/CVE-2022-2869-detector"
                }
            ],
            "references": [
                "https://github.com/halahajyahia/CVE-2022-2869-detector"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/halahajyahia/CVE-2022-2869-detector"
                }
            ]
        },
        {
            "id": "CVE-2022-1471",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Forced Browsing in Vmware Spring_Security CVE-2026-22732",
            "summary": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "updated_at": "2026-09-11T11:16:21Z",
            "published_at": "2026-09-11T11:16:21Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-425",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Forced Browsing in Vmware Spring_Security CVE-2026-22732",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-425",
                    "references": [
                        "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE",
                        "https://github.com/dylan-chainguard/cve-2026-22732-poc"
                    ],
                    "repository": "Sploitus",
                    "author": "dylan-chainguard",
                    "first_seen": "2026-09-11T13:16:21",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE"
                },
                {
                    "title": "Exploit for Forced Browsing in Vmware Spring_Security CVE-2026-22732",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-425",
                    "references": [
                        "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE",
                        "https://github.com/dylan-chainguard/cve-2026-22732-poc"
                    ],
                    "repository": "dylan-chainguard/cve-2026-22732-poc",
                    "author": "dylan-chainguard",
                    "first_seen": "2026-09-11T13:16:21",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/dylan-chainguard/cve-2026-22732-poc"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE",
                "https://github.com/dylan-chainguard/cve-2026-22732-poc"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T11:16:21Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2022-1388",
            "vendor": "F5",
            "product": "BIG-IP",
            "title": "F5 BIG-IP Missing Authentication Vulnerability",
            "summary": "F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.",
            "updated_at": "2026-09-06T08:31:38Z",
            "published_at": "2026-09-06T08:31:38Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1187,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50932",
                    "author": "Yesith Alvarez",
                    "first_seen": "2022-05-12",
                    "confidence": "High",
                    "title": "F5 BIG-IP 16.0.x - Remote Code Execution (RCE)",
                    "summary": "F5 BIG-IP 16.0.x - Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/50932",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2022-1388",
                    "summary": "Unauthenticated command execution in BIG-IP iControl REST via /mgmt/tm/util/bash.",
                    "what_happened": "Unauthenticated command execution in BIG-IP iControl REST via /mgmt/tm/util/bash.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAMO0-CVE-2022-1388",
                        "https://kitploit.com/ru/tools/github/shamo0/cve-2022-1388/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T09:23:19",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAMO0-CVE-2022-1388"
                },
                {
                    "title": "Exploit for CVE-2022-1388",
                    "summary": "Unauthenticated command execution in BIG-IP iControl REST via /mgmt/tm/util/bash.",
                    "what_happened": "Unauthenticated command execution in BIG-IP iControl REST via /mgmt/tm/util/bash.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAMO0-CVE-2022-1388",
                        "https://kitploit.com/ru/tools/github/shamo0/cve-2022-1388/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T09:23:19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/shamo0/cve-2022-1388/"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T15:06:39+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2022-1388 exploit",
                    "summary": "Exploit for CVE-2022-1388. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-OMNIGODZ-CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · numanturle/CVE-2022-1388",
                    "author": "numanturle",
                    "first_seen": "2022-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 53,
                    "title": "K23605346: BIG-IP iControl REST vulnerability CVE-2022-1388",
                    "summary": "K23605346: BIG-IP iControl REST vulnerability CVE-2022-1388",
                    "url": "https://github.com/numanturle/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · jheeree/CVE-2022-1388-checker",
                    "author": "jheeree",
                    "first_seen": "2022-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "Simple script realizado en bash, para revisión de múltiples hosts para CVE-2022-1388 (F5)",
                    "summary": "Simple script realizado en bash, para revisión de múltiples hosts para CVE-2022-1388 (F5)",
                    "url": "https://github.com/jheeree/CVE-2022-1388-checker"
                },
                {
                    "repository": "PoC-in-GitHub · MrCl0wnLab/Nuclei-Template-CVE-2022-1388-BIG-IP-iControl-REST-Exposed",
                    "author": "MrCl0wnLab",
                    "first_seen": "2022-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 28,
                    "title": "This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.",
                    "summary": "This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.",
                    "url": "https://github.com/MrCl0wnLab/Nuclei-Template-CVE-2022-1388-BIG-IP-iControl-REST-Exposed"
                },
                {
                    "repository": "PoC-in-GitHub · Osyanina/westone-CVE-2022-1388-scanner",
                    "author": "Osyanina",
                    "first_seen": "2022-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A vulnerability scanner that detects CVE-2021-21980 vulnerabilities.",
                    "summary": "A vulnerability scanner that detects CVE-2021-21980 vulnerabilities.",
                    "url": "https://github.com/Osyanina/westone-CVE-2022-1388-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · doocop/CVE-2022-1388-EXP",
                    "author": "doocop",
                    "first_seen": "2022-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 92,
                    "title": "CVE-2022-1388 F5 BIG-IP RCE 批量检测",
                    "summary": "CVE-2022-1388 F5 BIG-IP RCE 批量检测",
                    "url": "https://github.com/doocop/CVE-2022-1388-EXP"
                },
                {
                    "repository": "PoC-in-GitHub · blind-intruder/CVE-2022-1388-RCE-checker-and-POC-Exploit",
                    "author": "blind-intruder",
                    "first_seen": "2022-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "CVE-2022-1388 repository",
                    "summary": "",
                    "url": "https://github.com/blind-intruder/CVE-2022-1388-RCE-checker-and-POC-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Hudi233/CVE-2022-1388",
                    "author": "Hudi233",
                    "first_seen": "2022-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-1388 repository",
                    "summary": "",
                    "url": "https://github.com/Hudi233/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · sherlocksecurity/CVE-2022-1388-Exploit-POC",
                    "author": "sherlocksecurity",
                    "first_seen": "2022-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 56,
                    "title": "PoC for CVE-2022-1388_F5_BIG-IP",
                    "summary": "PoC for CVE-2022-1388_F5_BIG-IP",
                    "url": "https://github.com/sherlocksecurity/CVE-2022-1388-Exploit-POC"
                },
                {
                    "repository": "PoC-in-GitHub · yukar1z0e/CVE-2022-1388",
                    "author": "yukar1z0e",
                    "first_seen": "2022-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "batch scan CVE-2022-1388",
                    "summary": "batch scan CVE-2022-1388",
                    "url": "https://github.com/yukar1z0e/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · 0xf4n9x/CVE-2022-1388",
                    "author": "0xf4n9x",
                    "first_seen": "2022-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 84,
                    "title": "CVE-2022-1388 F5 BIG-IP iControl REST Auth Bypass RCE",
                    "summary": "CVE-2022-1388 F5 BIG-IP iControl REST Auth Bypass RCE",
                    "url": "https://github.com/0xf4n9x/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · alt3kx/CVE-2022-1388_PoC",
                    "author": "alt3kx",
                    "first_seen": "2022-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 87,
                    "title": "F5 BIG-IP RCE exploitation (CVE-2022-1388)",
                    "summary": "F5 BIG-IP RCE exploitation (CVE-2022-1388)",
                    "url": "https://github.com/alt3kx/CVE-2022-1388_PoC"
                },
                {
                    "repository": "PoC-in-GitHub · Vulnmachines/F5-Big-IP-CVE-2022-1388",
                    "author": "Vulnmachines",
                    "first_seen": "2022-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2022-1388 F5 Big IP unauth remote code execution",
                    "summary": "CVE-2022-1388 F5 Big IP unauth remote code execution",
                    "url": "https://github.com/Vulnmachines/F5-Big-IP-CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · ZephrFish/F5-CVE-2022-1388-Exploit",
                    "author": "ZephrFish",
                    "first_seen": "2022-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 59,
                    "title": "Exploit and Check Script for CVE 2022-1388",
                    "summary": "Exploit and Check Script for CVE 2022-1388",
                    "url": "https://github.com/ZephrFish/F5-CVE-2022-1388-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · horizon3ai/CVE-2022-1388",
                    "author": "horizon3ai",
                    "first_seen": "2022-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 231,
                    "title": "POC for CVE-2022-1388",
                    "summary": "POC for CVE-2022-1388",
                    "url": "https://github.com/horizon3ai/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · Al1ex/CVE-2022-1388",
                    "author": "Al1ex",
                    "first_seen": "2022-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 37,
                    "title": "CVE-2022-1388 F5 BIG-IP iControl REST RCE",
                    "summary": "CVE-2022-1388 F5 BIG-IP iControl REST RCE",
                    "url": "https://github.com/Al1ex/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · Henry4E36/CVE-2022-1388",
                    "author": "Henry4E36",
                    "first_seen": "2022-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "F5 BIG-IP iControl REST身份验证绕过漏洞",
                    "summary": "F5 BIG-IP iControl REST身份验证绕过漏洞",
                    "url": "https://github.com/Henry4E36/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · savior-only/CVE-2022-1388",
                    "author": "savior-only",
                    "first_seen": "2022-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2022-1388 F5 BIG-IP iControl REST身份验证绕过漏洞",
                    "summary": "CVE-2022-1388 F5 BIG-IP iControl REST身份验证绕过漏洞",
                    "url": "https://github.com/savior-only/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · saucer-man/CVE-2022-1388",
                    "author": "saucer-man",
                    "first_seen": "2022-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2022-1388",
                    "summary": "CVE-2022-1388",
                    "url": "https://github.com/saucer-man/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · superzerosec/CVE-2022-1388",
                    "author": "superzerosec",
                    "first_seen": "2022-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2022-1388 POC exploit",
                    "summary": "CVE-2022-1388 POC exploit",
                    "url": "https://github.com/superzerosec/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · Stonzyy/Exploit-F5-CVE-2022-1388",
                    "author": "Stonzyy",
                    "first_seen": "2022-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "PoC For F5 BIG-IP - bash script Exploit one Liner",
                    "summary": "PoC For F5 BIG-IP - bash script Exploit one Liner",
                    "url": "https://github.com/Stonzyy/Exploit-F5-CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · MrCl0wnLab/Nuclei-Template-Exploit-F5-BIG-IP-iControl-REST-Auth-Bypass-RCE-Command-Parameter",
                    "author": "MrCl0wnLab",
                    "first_seen": "2022-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2022-1388 is an authentication bypass vulnerability in the REST      component of BIG-IP’s iControl API that was assigned a CVSSv3      score of 9.8. The iControl REST API is used for the management and      configuration of BIG-IP devices. CVE-2022-1388 could be exploited      by an unauthenticated attacker with network access to the management      port or self IP addresses of devices that use BIG-IP. Exploitation would      allow the attacker to execute arbitrary system commands, create and      delete files and disable services.",
                    "summary": "CVE-2022-1388 is an authentication bypass vulnerability in the REST      component of BIG-IP’s iControl API that was assigned a CVSSv3      score of 9.8. The iControl REST API is used for the management and      configuration of BIG-IP devices. CVE-2022-1388 could be exploited      by an unauthenticated attacker with network access to the management      port or self IP addresses of devices that use BIG-IP. Exploitation would      allow the attacker to execute arbitrary system commands, create and      delete files and disable services.",
                    "url": "https://github.com/MrCl0wnLab/Nuclei-Template-Exploit-F5-BIG-IP-iControl-REST-Auth-Bypass-RCE-Command-Parameter"
                },
                {
                    "repository": "PoC-in-GitHub · qusaialhaddad/F5-BigIP-CVE-2022-1388",
                    "author": "qusaialhaddad",
                    "first_seen": "2022-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Reverse Shell for CVE-2022-1388",
                    "summary": "Reverse Shell for CVE-2022-1388",
                    "url": "https://github.com/qusaialhaddad/F5-BigIP-CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · chesterblue/CVE-2022-1388",
                    "author": "chesterblue",
                    "first_seen": "2022-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "POC of CVE-2022-1388",
                    "summary": "POC of CVE-2022-1388",
                    "url": "https://github.com/chesterblue/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · Angus-Team/F5-BIG-IP-RCE-CVE-2022-1388",
                    "author": "Angus-Team",
                    "first_seen": "2022-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2022-1388 repository",
                    "summary": "",
                    "url": "https://github.com/Angus-Team/F5-BIG-IP-RCE-CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · LinJacck/CVE-2022-1388-EXP",
                    "author": "LinJacck",
                    "first_seen": "2022-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-1388-EXP可批量实现攻击",
                    "summary": "CVE-2022-1388-EXP可批量实现攻击",
                    "url": "https://github.com/LinJacck/CVE-2022-1388-EXP"
                },
                {
                    "repository": "PoC-in-GitHub · iveresk/cve-2022-1388-1veresk",
                    "author": "iveresk",
                    "first_seen": "2022-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Simple shell script for the exploit",
                    "summary": "Simple shell script for the exploit",
                    "url": "https://github.com/iveresk/cve-2022-1388-1veresk"
                },
                {
                    "repository": "PoC-in-GitHub · shamo0/CVE-2022-1388",
                    "author": "shamo0",
                    "first_seen": "2022-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "BIG-IP iControl REST vulnerability CVE-2022-1388 PoC",
                    "summary": "BIG-IP iControl REST vulnerability CVE-2022-1388 PoC",
                    "url": "https://github.com/shamo0/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · vesperp/CVE-2022-1388-F5-BIG-IP",
                    "author": "vesperp",
                    "first_seen": "2022-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-1388 repository",
                    "summary": "",
                    "url": "https://github.com/vesperp/CVE-2022-1388-F5-BIG-IP"
                },
                {
                    "repository": "PoC-in-GitHub · thatonesecguy/CVE-2022-1388-Exploit",
                    "author": "thatonesecguy",
                    "first_seen": "2022-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Test and Exploit Scripts for CVE 2022-1388 (F5 Big-IP)",
                    "summary": "Test and Exploit Scripts for CVE 2022-1388 (F5 Big-IP)",
                    "url": "https://github.com/thatonesecguy/CVE-2022-1388-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · bandit92/CVE2022-1388_TestAPI",
                    "author": "bandit92",
                    "first_seen": "2022-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "A Test API for testing the POC against CVE-2022-1388",
                    "summary": "A Test API for testing the POC against CVE-2022-1388",
                    "url": "https://github.com/bandit92/CVE2022-1388_TestAPI"
                },
                {
                    "repository": "PoC-in-GitHub · 0x7eTeam/CVE-2022-1388-PocExp",
                    "author": "0x7eTeam",
                    "first_seen": "2022-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2022-1388-PocExp,新增了多线程,F5 BIG-IP RCE exploitation",
                    "summary": "CVE-2022-1388-PocExp,新增了多线程,F5 BIG-IP RCE exploitation",
                    "url": "https://github.com/0x7eTeam/CVE-2022-1388-PocExp"
                },
                {
                    "repository": "PoC-in-GitHub · 0xAgun/CVE-2022-1388",
                    "author": "0xAgun",
                    "first_seen": "2022-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-1388 repository",
                    "summary": "",
                    "url": "https://github.com/0xAgun/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · AmirHoseinTangsiriNET/CVE-2022-1388-Scanner",
                    "author": "AmirHoseinTangsiriNET",
                    "first_seen": "2022-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2022-1388 repository",
                    "summary": "",
                    "url": "https://github.com/AmirHoseinTangsiriNET/CVE-2022-1388-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · EvilLizard666/CVE-2022-1388",
                    "author": "EvilLizard666",
                    "first_seen": "2022-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2022-1388 Scanner",
                    "summary": "CVE-2022-1388 Scanner",
                    "url": "https://github.com/EvilLizard666/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · mr-vill4in/CVE-2022-1388",
                    "author": "mr-vill4in",
                    "first_seen": "2022-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-1388",
                    "summary": "CVE-2022-1388",
                    "url": "https://github.com/mr-vill4in/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · omnigodz/CVE-2022-1388",
                    "author": "omnigodz",
                    "first_seen": "2022-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository consists of the python exploit for CVE-2022-1388 (F5's BIG-IP Authentication Bypass to RCE)",
                    "summary": "This repository consists of the python exploit for CVE-2022-1388 (F5's BIG-IP Authentication Bypass to RCE)",
                    "url": "https://github.com/omnigodz/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · pauloink/CVE-2022-1388",
                    "author": "pauloink",
                    "first_seen": "2022-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Research and proof of concept related to CVE-2022-1388.",
                    "summary": "Research and proof of concept related to CVE-2022-1388.",
                    "url": "https://github.com/pauloink/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · SecTheBit/CVE-2022-1388",
                    "author": "SecTheBit",
                    "first_seen": "2022-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Nuclei Template for CVE-2022-1388",
                    "summary": "Nuclei Template for CVE-2022-1388",
                    "url": "https://github.com/SecTheBit/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · Zeyad-Azima/CVE-2022-1388",
                    "author": "Zeyad-Azima",
                    "first_seen": "2022-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LAB",
                    "summary": "F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LAB",
                    "url": "https://github.com/Zeyad-Azima/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · justakazh/CVE-2022-1388",
                    "author": "justakazh",
                    "first_seen": "2022-05-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "Tool for CVE-2022-1388",
                    "summary": "Tool for CVE-2022-1388",
                    "url": "https://github.com/justakazh/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · PsychoSec2/CVE-2022-1388-POC",
                    "author": "PsychoSec2",
                    "first_seen": "2022-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "An Improved Proof of Concept for CVE-2022-1388 w/ an Interactive Shell",
                    "summary": "An Improved Proof of Concept for CVE-2022-1388 w/ an Interactive Shell",
                    "url": "https://github.com/PsychoSec2/CVE-2022-1388-POC"
                },
                {
                    "repository": "PoC-in-GitHub · iveresk/cve-2022-1388-iveresk-command-shell",
                    "author": "iveresk",
                    "first_seen": "2022-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Improved POC for CVE-2022-1388 that affects multiple F5 products.",
                    "summary": "Improved POC for CVE-2022-1388 that affects multiple F5 products.",
                    "url": "https://github.com/iveresk/cve-2022-1388-iveresk-command-shell"
                },
                {
                    "repository": "PoC-in-GitHub · Wrin9/CVE-2022-1388",
                    "author": "Wrin9",
                    "first_seen": "2022-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-1388 repository",
                    "summary": "",
                    "url": "https://github.com/Wrin9/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · aancw/CVE-2022-1388-rs",
                    "author": "aancw",
                    "first_seen": "2022-05-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2022-1388 F5 BIG-IP iControl REST Auth Bypass RCE written in Rust",
                    "summary": "CVE-2022-1388 F5 BIG-IP iControl REST Auth Bypass RCE written in Rust",
                    "url": "https://github.com/aancw/CVE-2022-1388-rs"
                },
                {
                    "repository": "PoC-in-GitHub · west9b/F5-BIG-IP-POC",
                    "author": "west9b",
                    "first_seen": "2022-05-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "CVE-2020-5902 CVE-2021-22986 CVE-2022-1388 POC集合",
                    "summary": "CVE-2020-5902 CVE-2021-22986 CVE-2022-1388 POC集合",
                    "url": "https://github.com/west9b/F5-BIG-IP-POC"
                },
                {
                    "repository": "PoC-in-GitHub · sashka3076/F5-BIG-IP-exploit",
                    "author": "sashka3076",
                    "first_seen": "2022-06-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-1388",
                    "summary": "CVE-2022-1388",
                    "url": "https://github.com/sashka3076/F5-BIG-IP-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Chocapikk/CVE-2022-1388",
                    "author": "Chocapikk",
                    "first_seen": "2022-06-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-1388 | F5 - Big IP Pre Auth RCE via '/mgmt/tm/util/bash' endpoint",
                    "summary": "CVE-2022-1388 | F5 - Big IP Pre Auth RCE via '/mgmt/tm/util/bash' endpoint",
                    "url": "https://github.com/Chocapikk/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · li8u99/CVE-2022-1388",
                    "author": "li8u99",
                    "first_seen": "2022-06-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-1388 | F5 - Big IP Pre Auth RCE via '/mgmt/tm/util/bash' endpoint",
                    "summary": "CVE-2022-1388 | F5 - Big IP Pre Auth RCE via '/mgmt/tm/util/bash' endpoint",
                    "url": "https://github.com/li8u99/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · Luchoane/CVE-2022-1388_refresh",
                    "author": "Luchoane",
                    "first_seen": "2022-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC for exploiting CVE-2022-1388 on BIG IP F5",
                    "summary": "PoC for exploiting CVE-2022-1388 on BIG IP F5",
                    "url": "https://github.com/Luchoane/CVE-2022-1388_refresh"
                },
                {
                    "repository": "PoC-in-GitHub · jbharucha05/CVE-2022-1388",
                    "author": "jbharucha05",
                    "first_seen": "2022-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-1388, bypassing iControl REST authentication",
                    "summary": "CVE-2022-1388, bypassing iControl REST authentication",
                    "url": "https://github.com/jbharucha05/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · On-Cyber-War/CVE-2022-1388",
                    "author": "On-Cyber-War",
                    "first_seen": "2022-10-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "cURL one-liner to test for CVE-2022-1388 BIG-IP iControl REST RCE",
                    "summary": "cURL one-liner to test for CVE-2022-1388 BIG-IP iControl REST RCE",
                    "url": "https://github.com/On-Cyber-War/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · ThinkingOffensively/CVE-2022-1388",
                    "author": "ThinkingOffensively",
                    "first_seen": "2022-10-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "cURL one-liner to test for CVE-2022-1388 BIG-IP iControl REST RCE",
                    "summary": "cURL one-liner to test for CVE-2022-1388 BIG-IP iControl REST RCE",
                    "url": "https://github.com/ThinkingOffensively/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · revanmalang/CVE-2022-1388",
                    "author": "revanmalang",
                    "first_seen": "2022-11-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2022-1388 repository",
                    "summary": "",
                    "url": "https://github.com/revanmalang/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · amitlttwo/CVE-2022-1388",
                    "author": "amitlttwo",
                    "first_seen": "2022-12-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-1388 repository",
                    "summary": "",
                    "url": "https://github.com/amitlttwo/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · M4fiaB0y/CVE-2022-1388",
                    "author": "M4fiaB0y",
                    "first_seen": "2022-12-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Scan IP ranges for IP's vulnerable to the F5 Big IP exploit (CVE-2022-1388)",
                    "summary": "Scan IP ranges for IP's vulnerable to the F5 Big IP exploit (CVE-2022-1388)",
                    "url": "https://github.com/M4fiaB0y/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · devengpk/CVE-2022-1388",
                    "author": "devengpk",
                    "first_seen": "2022-12-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2022-1388 repository",
                    "summary": "",
                    "url": "https://github.com/devengpk/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · vaelwolf/CVE-2022-1388",
                    "author": "vaelwolf",
                    "first_seen": "2022-12-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "-- FOR EDUCATIONAL USE ONLY -- Proof-of-Concept RCE for CVE-2022-1388, plus some added functionality for blue and red teams",
                    "summary": "-- FOR EDUCATIONAL USE ONLY -- Proof-of-Concept RCE for CVE-2022-1388, plus some added functionality for blue and red teams",
                    "url": "https://github.com/vaelwolf/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · j-baines/tippa-my-tongue",
                    "author": "j-baines",
                    "first_seen": "2023-04-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "F5 BIG-IP Exploit Using CVE-2022-1388 and CVE-2022-41800",
                    "summary": "F5 BIG-IP Exploit Using CVE-2022-1388 and CVE-2022-41800",
                    "url": "https://github.com/j-baines/tippa-my-tongue"
                },
                {
                    "repository": "PoC-in-GitHub · SudeepaShiranthaka/F5-BIG-IP-Remote-Code-Execution-Vulnerability-CVE-2022-1388-A-Case-Study",
                    "author": "SudeepaShiranthaka",
                    "first_seen": "2023-07-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "F5-BIG-IP Remote Code Execution Vulnerability CVE-2022-1388: A Case Study",
                    "summary": "F5-BIG-IP Remote Code Execution Vulnerability CVE-2022-1388: A Case Study",
                    "url": "https://github.com/SudeepaShiranthaka/F5-BIG-IP-Remote-Code-Execution-Vulnerability-CVE-2022-1388-A-Case-Study"
                },
                {
                    "repository": "PoC-in-GitHub · battleofthebots/refresh",
                    "author": "battleofthebots",
                    "first_seen": "2023-08-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-1388 - F5 Router RCE Replica",
                    "summary": "CVE-2022-1388 - F5 Router RCE Replica",
                    "url": "https://github.com/battleofthebots/refresh"
                },
                {
                    "repository": "PoC-in-GitHub · nvk0x/CVE-2022-1388-exploit",
                    "author": "nvk0x",
                    "first_seen": "2024-01-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "exploit poc",
                    "summary": "exploit poc",
                    "url": "https://github.com/nvk0x/CVE-2022-1388-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · nico989/CVE-2022-1388",
                    "author": "nico989",
                    "first_seen": "2024-01-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC for CVE-2022-1388 affecting F5 BIG-IP.",
                    "summary": "PoC for CVE-2022-1388 affecting F5 BIG-IP.",
                    "url": "https://github.com/nico989/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · gotr00t0day/CVE-2022-1388",
                    "author": "gotr00t0day",
                    "first_seen": "2024-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "A remote code execution vulnerability exists in the iControl REST API feature of F5's BIG-IP product. An unauthenticated, remote attacker can exploit this to bypass authentication and execute arbitrary commands with root privileges.",
                    "summary": "A remote code execution vulnerability exists in the iControl REST API feature of F5's BIG-IP product. An unauthenticated, remote attacker can exploit this to bypass authentication and execute arbitrary commands with root privileges.",
                    "url": "https://github.com/gotr00t0day/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · impost0r/CVE-2022-1388",
                    "author": "impost0r",
                    "first_seen": "2024-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Old weaponized CVE-2022-1388 exploit.",
                    "summary": "Old weaponized CVE-2022-1388 exploit.",
                    "url": "https://github.com/impost0r/CVE-2022-1388"
                },
                {
                    "repository": "PoC-in-GitHub · r0otk3r/CVE-2022-1388",
                    "author": "r0otk3r",
                    "first_seen": "2025-07-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-1388 repository",
                    "summary": "",
                    "url": "https://github.com/r0otk3r/CVE-2022-1388"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/50932",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAMO0-CVE-2022-1388",
                "https://kitploit.com/ru/tools/github/shamo0/cve-2022-1388/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-OMNIGODZ-CVE-2022-1388",
                "https://github.com/numanturle/CVE-2022-1388",
                "https://github.com/jheeree/CVE-2022-1388-checker",
                "https://github.com/MrCl0wnLab/Nuclei-Template-CVE-2022-1388-BIG-IP-iControl-REST-Exposed",
                "https://github.com/Osyanina/westone-CVE-2022-1388-scanner",
                "https://github.com/doocop/CVE-2022-1388-EXP",
                "https://github.com/blind-intruder/CVE-2022-1388-RCE-checker-and-POC-Exploit",
                "https://github.com/Hudi233/CVE-2022-1388",
                "https://github.com/sherlocksecurity/CVE-2022-1388-Exploit-POC",
                "https://github.com/yukar1z0e/CVE-2022-1388",
                "https://github.com/0xf4n9x/CVE-2022-1388",
                "https://github.com/alt3kx/CVE-2022-1388_PoC",
                "https://github.com/Vulnmachines/F5-Big-IP-CVE-2022-1388",
                "https://github.com/ZephrFish/F5-CVE-2022-1388-Exploit",
                "https://github.com/horizon3ai/CVE-2022-1388",
                "https://github.com/Al1ex/CVE-2022-1388",
                "https://github.com/Henry4E36/CVE-2022-1388",
                "https://github.com/savior-only/CVE-2022-1388",
                "https://github.com/saucer-man/CVE-2022-1388",
                "https://github.com/superzerosec/CVE-2022-1388",
                "https://github.com/Stonzyy/Exploit-F5-CVE-2022-1388",
                "https://github.com/MrCl0wnLab/Nuclei-Template-Exploit-F5-BIG-IP-iControl-REST-Auth-Bypass-RCE-Command-Parameter",
                "https://github.com/qusaialhaddad/F5-BigIP-CVE-2022-1388",
                "https://github.com/chesterblue/CVE-2022-1388",
                "https://github.com/Angus-Team/F5-BIG-IP-RCE-CVE-2022-1388",
                "https://github.com/LinJacck/CVE-2022-1388-EXP",
                "https://github.com/iveresk/cve-2022-1388-1veresk",
                "https://github.com/shamo0/CVE-2022-1388",
                "https://github.com/vesperp/CVE-2022-1388-F5-BIG-IP",
                "https://github.com/thatonesecguy/CVE-2022-1388-Exploit",
                "https://github.com/bandit92/CVE2022-1388_TestAPI",
                "https://github.com/0x7eTeam/CVE-2022-1388-PocExp",
                "https://github.com/0xAgun/CVE-2022-1388",
                "https://github.com/AmirHoseinTangsiriNET/CVE-2022-1388-Scanner",
                "https://github.com/EvilLizard666/CVE-2022-1388",
                "https://github.com/mr-vill4in/CVE-2022-1388",
                "https://github.com/omnigodz/CVE-2022-1388",
                "https://github.com/pauloink/CVE-2022-1388",
                "https://github.com/SecTheBit/CVE-2022-1388",
                "https://github.com/Zeyad-Azima/CVE-2022-1388",
                "https://github.com/justakazh/CVE-2022-1388",
                "https://github.com/PsychoSec2/CVE-2022-1388-POC",
                "https://github.com/iveresk/cve-2022-1388-iveresk-command-shell",
                "https://github.com/Wrin9/CVE-2022-1388",
                "https://github.com/aancw/CVE-2022-1388-rs",
                "https://github.com/west9b/F5-BIG-IP-POC",
                "https://github.com/sashka3076/F5-BIG-IP-exploit",
                "https://github.com/Chocapikk/CVE-2022-1388",
                "https://github.com/li8u99/CVE-2022-1388",
                "https://github.com/Luchoane/CVE-2022-1388_refresh",
                "https://github.com/jbharucha05/CVE-2022-1388",
                "https://github.com/On-Cyber-War/CVE-2022-1388",
                "https://github.com/ThinkingOffensively/CVE-2022-1388",
                "https://github.com/revanmalang/CVE-2022-1388",
                "https://github.com/amitlttwo/CVE-2022-1388",
                "https://github.com/M4fiaB0y/CVE-2022-1388",
                "https://github.com/devengpk/CVE-2022-1388",
                "https://github.com/vaelwolf/CVE-2022-1388",
                "https://github.com/j-baines/tippa-my-tongue",
                "https://github.com/SudeepaShiranthaka/F5-BIG-IP-Remote-Code-Execution-Vulnerability-CVE-2022-1388-A-Case-Study",
                "https://github.com/battleofthebots/refresh",
                "https://github.com/nvk0x/CVE-2022-1388-exploit",
                "https://github.com/nico989/CVE-2022-1388",
                "https://github.com/gotr00t0day/CVE-2022-1388",
                "https://github.com/impost0r/CVE-2022-1388",
                "https://github.com/r0otk3r/CVE-2022-1388"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:31:38Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-05-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2022-1199",
            "vendor": "n/a",
            "product": "Kernel",
            "title": "Kernel vulnerability",
            "summary": "A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability.",
            "updated_at": "2026-09-11T16:18:07.107",
            "published_at": "2022-08-29T15:15:10.527",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Fixed in kernel v5.18-rc4",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://access.redhat.com/security/cve/CVE-2022-1199",
                "https://bugzilla.redhat.com/show_bug.cgi?id=2070694",
                "https://github.com/torvalds/linux/commit/4e0f718daf97d47cf7dec122da1be970f145c809",
                "https://github.com/torvalds/linux/commit/71171ac8eb34ce7fe6b3267dce27c313ab3cb3ac",
                "https://github.com/torvalds/linux/commit/7ec02f5ac8a5be5a3f20611731243dc5e1d9ba10",
                "https://security.netapp.com/advisory/ntap-20221228-0006/",
                "https://www.openwall.com/lists/oss-security/2022/04/02/5"
            ],
            "timeline": [
                {
                    "at": "2022-08-29T15:15:10.527",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-1199"
                }
            ]
        },
        {
            "id": "CVE-2022-0995",
            "vendor": "Linux",
            "product": "Kernel",
            "title": "Linux Kernel Out-of-Bounds Write Vulnerability",
            "summary": "Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.",
            "updated_at": "2026-08-25T22:00:00Z",
            "published_at": "2026-08-25T22:00:00Z",
            "cvss": 8.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 108,
            "kev": true,
            "attack_vector": "Adjacent",
            "authentication": "None",
            "complexity": "High",
            "cwe": "Unknown",
            "what_happened": "Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2021-22555",
                    "summary": "Vulnerability in tools component identified as CVE-2021-22555.",
                    "what_happened": "Vulnerability in tools component identified as CVE-2021-22555.",
                    "cvss": 8.3,
                    "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "None",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WHATSWRONGANDWHY-CVE-2021-22555",
                        "https://kitploit.com/es/tools/github/whatswrongandwhy/cve-2021-22555/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T05:06:30",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WHATSWRONGANDWHY-CVE-2021-22555"
                },
                {
                    "title": "Exploit for CVE-2021-22555",
                    "summary": "Vulnerability in tools component identified as CVE-2021-22555.",
                    "what_happened": "Vulnerability in tools component identified as CVE-2021-22555.",
                    "cvss": 8.3,
                    "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "None",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WHATSWRONGANDWHY-CVE-2021-22555",
                        "https://kitploit.com/es/tools/github/whatswrongandwhy/cve-2021-22555/"
                    ],
                    "repository": "kitploit.com",
                    "author": "es",
                    "first_seen": "2026-09-03T05:06:30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/es/tools/github/whatswrongandwhy/cve-2021-22555/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WHATSWRONGANDWHY-CVE-2021-22555",
                "https://kitploit.com/es/tools/github/whatswrongandwhy/cve-2021-22555/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2022-0847",
            "vendor": "Linux",
            "product": "Kernel",
            "title": "Linux Kernel Privilege Escalation Vulnerability",
            "summary": "Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of \"Dirty Pipe.\"",
            "updated_at": "2026-09-09T22:00:00Z",
            "published_at": "2026-09-09T22:00:00Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 3325,
            "kev": true,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of \"Dirty Pipe.\"",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50808",
                    "author": "Lance Biggerstaff",
                    "first_seen": "2022-03-08",
                    "confidence": "High",
                    "title": "Linux Kernel 5.8 < 5.16.11 - Local Privilege Escalation (DirtyPipe)",
                    "summary": "Linux Kernel 5.8 < 5.16.11 - Local Privilege Escalation (DirtyPipe)",
                    "url": "https://www.exploit-db.com/exploits/50808",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · bbaranoff/CVE-2022-0847",
                    "author": "bbaranoff",
                    "first_seen": "2022-03-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 50,
                    "title": "CVE-2022-0847",
                    "summary": "CVE-2022-0847",
                    "url": "https://github.com/bbaranoff/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · xndpxs/CVE-2022-0847",
                    "author": "xndpxs",
                    "first_seen": "2022-03-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "Vulnerability in the Linux kernel since 5.8",
                    "summary": "Vulnerability in the Linux kernel since 5.8",
                    "url": "https://github.com/xndpxs/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · r1is/CVE-2022-0847",
                    "author": "r1is",
                    "first_seen": "2022-03-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 281,
                    "title": "CVE-2022-0847-DirtyPipe-Exploit   CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞，可覆盖重写任意可读文件中的数据，从而可将普通权限的用户提升到特权 root。    CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞（Dirty Cow），但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”",
                    "summary": "CVE-2022-0847-DirtyPipe-Exploit   CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞，可覆盖重写任意可读文件中的数据，从而可将普通权限的用户提升到特权 root。    CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞（Dirty Cow），但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”",
                    "url": "https://github.com/r1is/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · Arinerron/CVE-2022-0847-DirtyPipe-Exploit",
                    "author": "Arinerron",
                    "first_seen": "2022-03-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1132,
                    "title": "A root exploit for CVE-2022-0847 (Dirty Pipe)",
                    "summary": "A root exploit for CVE-2022-0847 (Dirty Pipe)",
                    "url": "https://github.com/Arinerron/CVE-2022-0847-DirtyPipe-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · crowsec-edtech/Dirty-Pipe",
                    "author": "crowsec-edtech",
                    "first_seen": "2022-03-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "CVE-2022-0847 exploit one liner",
                    "summary": "CVE-2022-0847 exploit one liner",
                    "url": "https://github.com/crowsec-edtech/Dirty-Pipe"
                },
                {
                    "repository": "PoC-in-GitHub · lucksec/CVE-2022-0847",
                    "author": "lucksec",
                    "first_seen": "2022-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/lucksec/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · si1ent-le/CVE-2022-0847",
                    "author": "si1ent-le",
                    "first_seen": "2022-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0487",
                    "summary": "CVE-2022-0487",
                    "url": "https://github.com/si1ent-le/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · bohr777/cve-2022-0847dirtypipe-exploit",
                    "author": "bohr777",
                    "first_seen": "2022-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/bohr777/cve-2022-0847dirtypipe-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · ZZ-SOCMAP/CVE-2022-0847",
                    "author": "ZZ-SOCMAP",
                    "first_seen": "2022-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 58,
                    "title": "Linux Kernel Local Privilege Escalation Vulnerability CVE-2022-0847.",
                    "summary": "Linux Kernel Local Privilege Escalation Vulnerability CVE-2022-0847.",
                    "url": "https://github.com/ZZ-SOCMAP/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · cspshivam/CVE-2022-0847-dirty-pipe-exploit",
                    "author": "cspshivam",
                    "first_seen": "2022-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "An exploit for CVE-2022-0847 dirty-pipe vulnerability",
                    "summary": "An exploit for CVE-2022-0847 dirty-pipe vulnerability",
                    "url": "https://github.com/cspshivam/CVE-2022-0847-dirty-pipe-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · febinrev/dirtypipez-exploit",
                    "author": "febinrev",
                    "first_seen": "2022-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 49,
                    "title": "CVE-2022-0847 DirtyPipe Exploit.",
                    "summary": "CVE-2022-0847 DirtyPipe Exploit.",
                    "url": "https://github.com/febinrev/dirtypipez-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · ahrixia/CVE_2022_0847",
                    "author": "ahrixia",
                    "first_seen": "2022-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 21,
                    "title": "CVE-2022-0847: Linux Kernel Privilege Escalation Vulnerability",
                    "summary": "CVE-2022-0847: Linux Kernel Privilege Escalation Vulnerability",
                    "url": "https://github.com/ahrixia/CVE_2022_0847"
                },
                {
                    "repository": "PoC-in-GitHub · knqyf263/CVE-2022-0847",
                    "author": "knqyf263",
                    "first_seen": "2022-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 46,
                    "title": "The Dirty Pipe Vulnerability",
                    "summary": "The Dirty Pipe Vulnerability",
                    "url": "https://github.com/knqyf263/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · puckiestyle/CVE-2022-0847",
                    "author": "puckiestyle",
                    "first_seen": "2022-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/puckiestyle/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · 0xIronGoat/dirty-pipe",
                    "author": "0xIronGoat",
                    "first_seen": "2022-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "Implementation of Max Kellermann's exploit for CVE-2022-0847",
                    "summary": "Implementation of Max Kellermann's exploit for CVE-2022-0847",
                    "url": "https://github.com/0xIronGoat/dirty-pipe"
                },
                {
                    "repository": "PoC-in-GitHub · ITMarcin2211/CVE-2022-0847-DirtyPipe-Exploit",
                    "author": "ITMarcin2211",
                    "first_seen": "2022-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/ITMarcin2211/CVE-2022-0847-DirtyPipe-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · mrchucu1/CVE-2022-0847-Docker",
                    "author": "mrchucu1",
                    "first_seen": "2022-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Docker exploit",
                    "summary": "Docker exploit",
                    "url": "https://github.com/mrchucu1/CVE-2022-0847-Docker"
                },
                {
                    "repository": "PoC-in-GitHub · basharkey/CVE-2022-0847-dirty-pipe-checker",
                    "author": "basharkey",
                    "first_seen": "2022-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 72,
                    "title": "Bash script to check for CVE-2022-0847 \"Dirty Pipe\"",
                    "summary": "Bash script to check for CVE-2022-0847 \"Dirty Pipe\"",
                    "url": "https://github.com/basharkey/CVE-2022-0847-dirty-pipe-checker"
                },
                {
                    "repository": "PoC-in-GitHub · 4luc4rdr5290/CVE-2022-0847",
                    "author": "4luc4rdr5290",
                    "first_seen": "2022-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2022-0847",
                    "summary": "CVE-2022-0847",
                    "url": "https://github.com/4luc4rdr5290/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · dadhee/CVE-2022-0847_DirtyPipeExploit",
                    "author": "dadhee",
                    "first_seen": "2022-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A “Dirty Pipe” vulnerability with CVE-2022-0847 and a CVSS score of 7.8 has been identified, affecting Linux Kernel 5.8 and higher. The vulnerability allows attackers to overwrite data in read-only files. Threat actors can exploit this vulnerability to privilege themselves with code injection.",
                    "summary": "A “Dirty Pipe” vulnerability with CVE-2022-0847 and a CVSS score of 7.8 has been identified, affecting Linux Kernel 5.8 and higher. The vulnerability allows attackers to overwrite data in read-only files. Threat actors can exploit this vulnerability to privilege themselves with code injection.",
                    "url": "https://github.com/dadhee/CVE-2022-0847_DirtyPipeExploit"
                },
                {
                    "repository": "PoC-in-GitHub · Greetdawn/CVE-2022-0847-DirtyPipe",
                    "author": "Greetdawn",
                    "first_seen": "2022-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/Greetdawn/CVE-2022-0847-DirtyPipe"
                },
                {
                    "repository": "PoC-in-GitHub · Al1ex/CVE-2022-0847",
                    "author": "Al1ex",
                    "first_seen": "2022-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 91,
                    "title": "CVE-2022-0847",
                    "summary": "CVE-2022-0847",
                    "url": "https://github.com/Al1ex/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · Mustafa1986/CVE-2022-0847-DirtyPipe-Exploit",
                    "author": "Mustafa1986",
                    "first_seen": "2022-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/Mustafa1986/CVE-2022-0847-DirtyPipe-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · nanaao/Dirtypipe-exploit",
                    "author": "nanaao",
                    "first_seen": "2022-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn. a root shell. (and attempts to restore the damaged binary as well)",
                    "summary": "Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn. a root shell. (and attempts to restore the damaged binary as well)",
                    "url": "https://github.com/nanaao/Dirtypipe-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · AyoubNajim/cve-2022-0847dirtypipe-exploit",
                    "author": "AyoubNajim",
                    "first_seen": "2022-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/AyoubNajim/cve-2022-0847dirtypipe-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · pentestblogin/pentestblog-CVE-2022-0847",
                    "author": "pentestblogin",
                    "first_seen": "2022-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/pentestblogin/pentestblog-CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · gyaansastra/CVE-2022-0847",
                    "author": "gyaansastra",
                    "first_seen": "2022-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Dirty Pipe POC",
                    "summary": "Dirty Pipe POC",
                    "url": "https://github.com/gyaansastra/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · DataDog/dirtypipe-container-breakout-poc",
                    "author": "DataDog",
                    "first_seen": "2022-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 77,
                    "title": "Container Excape PoC for CVE-2022-0847 \"DirtyPipe\"",
                    "summary": "Container Excape PoC for CVE-2022-0847 \"DirtyPipe\"",
                    "url": "https://github.com/DataDog/dirtypipe-container-breakout-poc"
                },
                {
                    "repository": "PoC-in-GitHub · babyshen/CVE-2022-0847",
                    "author": "babyshen",
                    "first_seen": "2022-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A root exploit for CVE-2022-0847 (Dirty Pipe)",
                    "summary": "A root exploit for CVE-2022-0847 (Dirty Pipe)",
                    "url": "https://github.com/babyshen/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · edsonjt81/CVE-2022-0847-Linux",
                    "author": "edsonjt81",
                    "first_seen": "2022-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/edsonjt81/CVE-2022-0847-Linux"
                },
                {
                    "repository": "PoC-in-GitHub · chenaotian/CVE-2022-0847",
                    "author": "chenaotian",
                    "first_seen": "2022-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "CVE-2022-0847 POC and Docker and Analysis write up",
                    "summary": "CVE-2022-0847 POC and Docker and Analysis write up",
                    "url": "https://github.com/chenaotian/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · V0WKeep3r/CVE-2022-0847-DirtyPipe-Exploit",
                    "author": "V0WKeep3r",
                    "first_seen": "2022-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847-DirtyPipe-Exploit",
                    "summary": "CVE-2022-0847-DirtyPipe-Exploit",
                    "url": "https://github.com/V0WKeep3r/CVE-2022-0847-DirtyPipe-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · osungjinwoo/CVE-2022-0847-Dirty-Pipe",
                    "author": "osungjinwoo",
                    "first_seen": "2022-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/osungjinwoo/CVE-2022-0847-Dirty-Pipe"
                },
                {
                    "repository": "PoC-in-GitHub · Greetdawn/CVE-2022-0847-DirtyPipe-",
                    "author": "Greetdawn",
                    "first_seen": "2022-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/Greetdawn/CVE-2022-0847-DirtyPipe-"
                },
                {
                    "repository": "PoC-in-GitHub · crusoe112/DirtyPipePython",
                    "author": "crusoe112",
                    "first_seen": "2022-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "A Python-based DirtyPipe (CVE-2022-0847) POC to pop a root shell",
                    "summary": "A Python-based DirtyPipe (CVE-2022-0847) POC to pop a root shell",
                    "url": "https://github.com/crusoe112/DirtyPipePython"
                },
                {
                    "repository": "PoC-in-GitHub · nanaao/dirtyPipe-automaticRoot",
                    "author": "nanaao",
                    "first_seen": "2022-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2022-0847 Python exploit to get root or write a no write permission, immutable or read-only mounted file.",
                    "summary": "CVE-2022-0847 Python exploit to get root or write a no write permission, immutable or read-only mounted file.",
                    "url": "https://github.com/nanaao/dirtyPipe-automaticRoot"
                },
                {
                    "repository": "PoC-in-GitHub · arttnba3/CVE-2022-0847",
                    "author": "arttnba3",
                    "first_seen": "2022-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "my personal exploit of CVE-2022-0847(dirty pipe)",
                    "summary": "my personal exploit of CVE-2022-0847(dirty pipe)",
                    "url": "https://github.com/arttnba3/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits",
                    "author": "AlexisAhmed",
                    "first_seen": "2022-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 735,
                    "title": "A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.",
                    "summary": "A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.",
                    "url": "https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits"
                },
                {
                    "repository": "PoC-in-GitHub · sa-infinity8888/Dirty-Pipe-CVE-2022-0847",
                    "author": "sa-infinity8888",
                    "first_seen": "2022-03-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2022-0847 (Dirty Pipe) is an arbitrary file overwrite vulnerability that allows escalation of privileges by modifying or overwriting arbitrary read-only files e.g. /etc/passwd, /etc/shadow.",
                    "summary": "CVE-2022-0847 (Dirty Pipe) is an arbitrary file overwrite vulnerability that allows escalation of privileges by modifying or overwriting arbitrary read-only files e.g. /etc/passwd, /etc/shadow.",
                    "url": "https://github.com/sa-infinity8888/Dirty-Pipe-CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · realbatuhan/dirtypipetester",
                    "author": "realbatuhan",
                    "first_seen": "2022-03-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Dirty Pipe (CVE-2022-0847) zafiyeti kontrolü",
                    "summary": "Dirty Pipe (CVE-2022-0847) zafiyeti kontrolü",
                    "url": "https://github.com/realbatuhan/dirtypipetester"
                },
                {
                    "repository": "PoC-in-GitHub · CYB3RK1D/CVE-2022-0847-POC",
                    "author": "CYB3RK1D",
                    "first_seen": "2022-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "dirtypipe",
                    "summary": "dirtypipe",
                    "url": "https://github.com/CYB3RK1D/CVE-2022-0847-POC"
                },
                {
                    "repository": "PoC-in-GitHub · breachnix/dirty-pipe-poc",
                    "author": "breachnix",
                    "first_seen": "2022-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 15,
                    "title": "CVE-2022-0847 POC",
                    "summary": "CVE-2022-0847 POC",
                    "url": "https://github.com/breachnix/dirty-pipe-poc"
                },
                {
                    "repository": "PoC-in-GitHub · Shotokhan/cve_2022_0847_shellcode",
                    "author": "Shotokhan",
                    "first_seen": "2022-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Implementation of CVE-2022-0847 as a shellcode",
                    "summary": "Implementation of CVE-2022-0847 as a shellcode",
                    "url": "https://github.com/Shotokhan/cve_2022_0847_shellcode"
                },
                {
                    "repository": "PoC-in-GitHub · githublihaha/DirtyPIPE-CVE-2022-0847",
                    "author": "githublihaha",
                    "first_seen": "2022-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/githublihaha/DirtyPIPE-CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · MrP1xel/CVE-2022-0847-dirty-pipe-kernel-checker",
                    "author": "MrP1xel",
                    "first_seen": "2022-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Python script to check if your kernel is vulnerable to Dirty pipe CVE-2022-0847",
                    "summary": "Python script to check if your kernel is vulnerable to Dirty pipe CVE-2022-0847",
                    "url": "https://github.com/MrP1xel/CVE-2022-0847-dirty-pipe-kernel-checker"
                },
                {
                    "repository": "PoC-in-GitHub · jpts/CVE-2022-0847-DirtyPipe-Container-Breakout",
                    "author": "jpts",
                    "first_seen": "2022-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "PoC Container Breakout for DirtyPipe Vulnerability CVE-2022-0847",
                    "summary": "PoC Container Breakout for DirtyPipe Vulnerability CVE-2022-0847",
                    "url": "https://github.com/jpts/CVE-2022-0847-DirtyPipe-Container-Breakout"
                },
                {
                    "repository": "PoC-in-GitHub · LudovicPatho/CVE-2022-0847_dirty-pipe",
                    "author": "LudovicPatho",
                    "first_seen": "2022-03-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "Hacked up Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn a root shell. (and attempts to restore the damaged binary as well)",
                    "summary": "Hacked up Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn a root shell. (and attempts to restore the damaged binary as well)",
                    "url": "https://github.com/LudovicPatho/CVE-2022-0847_dirty-pipe"
                },
                {
                    "repository": "PoC-in-GitHub · DanaEpp/pwncat_dirtypipe",
                    "author": "DanaEpp",
                    "first_seen": "2022-03-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "pwncat module that automatically exploits CVE-2022-0847 (dirtypipe)",
                    "summary": "pwncat module that automatically exploits CVE-2022-0847 (dirtypipe)",
                    "url": "https://github.com/DanaEpp/pwncat_dirtypipe"
                },
                {
                    "repository": "PoC-in-GitHub · tmoneypenny/CVE-2022-0847",
                    "author": "tmoneypenny",
                    "first_seen": "2022-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Dirty Pipe - CVE-2022-0847",
                    "summary": "Dirty Pipe - CVE-2022-0847",
                    "url": "https://github.com/tmoneypenny/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · scopion/dirty-pipe",
                    "author": "scopion",
                    "first_seen": "2022-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Exploit for Dirty-Pipe (CVE-2022-0847)",
                    "summary": "Exploit for Dirty-Pipe (CVE-2022-0847)",
                    "url": "https://github.com/scopion/dirty-pipe"
                },
                {
                    "repository": "PoC-in-GitHub · stfnw/Debugging_Dirty_Pipe_CVE-2022-0847",
                    "author": "stfnw",
                    "first_seen": "2022-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Presentation slides and supplementary material",
                    "summary": "Presentation slides and supplementary material",
                    "url": "https://github.com/stfnw/Debugging_Dirty_Pipe_CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · drapl0n/dirtypipe",
                    "author": "drapl0n",
                    "first_seen": "2022-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "DirtyPipe: Exploit for a new Linux vulnerability known as 'Dirty Pipe(CVE-2022-0847)' allows local users to gain root privileges. The vulnerability is tracked as CVE-2022-0847 and allows a non-privileged user to inject and overwrite data in read-only files, including SUID processes that run as root.",
                    "summary": "DirtyPipe: Exploit for a new Linux vulnerability known as 'Dirty Pipe(CVE-2022-0847)' allows local users to gain root privileges. The vulnerability is tracked as CVE-2022-0847 and allows a non-privileged user to inject and overwrite data in read-only files, including SUID processes that run as root.",
                    "url": "https://github.com/drapl0n/dirtypipe"
                },
                {
                    "repository": "PoC-in-GitHub · 0xr1l3s/CVE-2022-0847",
                    "author": "0xr1l3s",
                    "first_seen": "2022-04-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Linux “Dirty Pipe” vulnerability gives unprivileged users root access",
                    "summary": "Linux “Dirty Pipe” vulnerability gives unprivileged users root access",
                    "url": "https://github.com/0xr1l3s/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · mhanief/dirtypipe",
                    "author": "mhanief",
                    "first_seen": "2022-04-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Dirty Pipe Vulnerability Detection Script - RHSB-2022-002 Dirty Pipe - kernel arbitrary file manipulation - (CVE-2022-0847)",
                    "summary": "Dirty Pipe Vulnerability Detection Script - RHSB-2022-002 Dirty Pipe - kernel arbitrary file manipulation - (CVE-2022-0847)",
                    "url": "https://github.com/mhanief/dirtypipe"
                },
                {
                    "repository": "PoC-in-GitHub · tufanturhan/CVE-2022-0847-L-nux-PrivEsc",
                    "author": "tufanturhan",
                    "first_seen": "2022-04-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/tufanturhan/CVE-2022-0847-L-nux-PrivEsc"
                },
                {
                    "repository": "PoC-in-GitHub · rexpository/linux-privilege-escalation",
                    "author": "rexpository",
                    "first_seen": "2022-04-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "Scripted Linux Privilege Escalation for the CVE-2022-0847 \"Dirty Pipe\" vulnerability",
                    "summary": "Scripted Linux Privilege Escalation for the CVE-2022-0847 \"Dirty Pipe\" vulnerability",
                    "url": "https://github.com/rexpository/linux-privilege-escalation"
                },
                {
                    "repository": "PoC-in-GitHub · isaiahsimeone/COMP3320-VAPT",
                    "author": "isaiahsimeone",
                    "first_seen": "2022-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Files required to demonstrate CVE-2022-0847 vulnerability in Linux Kernel v5.8",
                    "summary": "Files required to demonstrate CVE-2022-0847 vulnerability in Linux Kernel v5.8",
                    "url": "https://github.com/isaiahsimeone/COMP3320-VAPT"
                },
                {
                    "repository": "PoC-in-GitHub · VinuKalana/DirtyPipe-CVE-2022-0847",
                    "author": "VinuKalana",
                    "first_seen": "2022-05-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "This repository is developed to analysis and understand DirtyPipe exploit CVE-2022-0847",
                    "summary": "This repository is developed to analysis and understand DirtyPipe exploit CVE-2022-0847",
                    "url": "https://github.com/VinuKalana/DirtyPipe-CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · ihenakaarachchi/debian11-dirty_pipe-patcher",
                    "author": "ihenakaarachchi",
                    "first_seen": "2022-05-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A Simple bash script that patches the CVE-2022-0847 (dirty pipe) kernel vulnerability on Debian 11",
                    "summary": "A Simple bash script that patches the CVE-2022-0847 (dirty pipe) kernel vulnerability on Debian 11",
                    "url": "https://github.com/ihenakaarachchi/debian11-dirty_pipe-patcher"
                },
                {
                    "repository": "PoC-in-GitHub · greenhandatsjtu/CVE-2022-0847-Container-Escape",
                    "author": "greenhandatsjtu",
                    "first_seen": "2022-06-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 37,
                    "title": "CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸",
                    "summary": "CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸",
                    "url": "https://github.com/greenhandatsjtu/CVE-2022-0847-Container-Escape"
                },
                {
                    "repository": "PoC-in-GitHub · jxpsx/CVE-2022-0847-DirtyPipe-Exploits",
                    "author": "jxpsx",
                    "first_seen": "2022-06-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.",
                    "summary": "A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.",
                    "url": "https://github.com/jxpsx/CVE-2022-0847-DirtyPipe-Exploits"
                },
                {
                    "repository": "PoC-in-GitHub · airbus-cert/dirtypipe-ebpf_detection",
                    "author": "airbus-cert",
                    "first_seen": "2022-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 29,
                    "title": "An eBPF detection program for CVE-2022-0847",
                    "summary": "An eBPF detection program for CVE-2022-0847",
                    "url": "https://github.com/airbus-cert/dirtypipe-ebpf_detection"
                },
                {
                    "repository": "PoC-in-GitHub · rabomen/Dirty-Pipe",
                    "author": "rabomen",
                    "first_seen": "2022-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "exp of CVE-2022-0847",
                    "summary": "exp of CVE-2022-0847",
                    "url": "https://github.com/rabomen/Dirty-Pipe"
                },
                {
                    "repository": "PoC-in-GitHub · eduquintanilha/CVE-2022-0847-DirtyPipe-Exploits",
                    "author": "eduquintanilha",
                    "first_seen": "2022-08-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "COMPILED",
                    "summary": "COMPILED",
                    "url": "https://github.com/eduquintanilha/CVE-2022-0847-DirtyPipe-Exploits"
                },
                {
                    "repository": "PoC-in-GitHub · EagleTube/CVE-2022-0847",
                    "author": "EagleTube",
                    "first_seen": "2022-08-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Modified dirtypipe script into auto root without have to search a file manually to hijack suid binary.",
                    "summary": "Modified dirtypipe script into auto root without have to search a file manually to hijack suid binary.",
                    "url": "https://github.com/EagleTube/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · KianaBin/CVE-2022-0847-Container-Escape",
                    "author": "KianaBin",
                    "first_seen": "2022-08-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸",
                    "summary": "CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸",
                    "url": "https://github.com/KianaBin/CVE-2022-0847-Container-Escape"
                },
                {
                    "repository": "PoC-in-GitHub · notl0cal/dpipe",
                    "author": "notl0cal",
                    "first_seen": "2022-08-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Proof-of-concept exploit for the Dirty Pipe vulnerability (CVE-2022-0847)",
                    "summary": "Proof-of-concept exploit for the Dirty Pipe vulnerability (CVE-2022-0847)",
                    "url": "https://github.com/notl0cal/dpipe"
                },
                {
                    "repository": "PoC-in-GitHub · Gustavo-Nogueira/Dirty-Pipe-Exploits",
                    "author": "Gustavo-Nogueira",
                    "first_seen": "2022-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2022-0847(Dirty Pipe) vulnerability exploits.",
                    "summary": "CVE-2022-0847(Dirty Pipe) vulnerability exploits.",
                    "url": "https://github.com/Gustavo-Nogueira/Dirty-Pipe-Exploits"
                },
                {
                    "repository": "PoC-in-GitHub · b4dboy17/Dirty-Pipe-Oneshot",
                    "author": "b4dboy17",
                    "first_seen": "2022-10-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Compled version of CVE-2022-0847 aka Dirty Pipe. Just one shot to root them all :D",
                    "summary": "Compled version of CVE-2022-0847 aka Dirty Pipe. Just one shot to root them all :D",
                    "url": "https://github.com/b4dboy17/Dirty-Pipe-Oneshot"
                },
                {
                    "repository": "PoC-in-GitHub · edsonjt81/CVE-2022-0847-DirtyPipe-",
                    "author": "edsonjt81",
                    "first_seen": "2022-10-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/edsonjt81/CVE-2022-0847-DirtyPipe-"
                },
                {
                    "repository": "PoC-in-GitHub · mattlloyddavies/ps-lab-cve-2022-0847",
                    "author": "mattlloyddavies",
                    "first_seen": "2022-11-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Resources required for building Pluralsight CVE-2022-0847 lab",
                    "summary": "Resources required for building Pluralsight CVE-2022-0847 lab",
                    "url": "https://github.com/mattlloyddavies/ps-lab-cve-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · qwert419/linux-",
                    "author": "qwert419",
                    "first_seen": "2022-11-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "修改版CVE-2022-0847",
                    "summary": "修改版CVE-2022-0847",
                    "url": "https://github.com/qwert419/linux-"
                },
                {
                    "repository": "PoC-in-GitHub · DataFox/CVE-2022-0847",
                    "author": "DataFox",
                    "first_seen": "2022-12-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847",
                    "summary": "CVE-2022-0847",
                    "url": "https://github.com/DataFox/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · pmihsan/Dirty-Pipe-CVE-2022-0847",
                    "author": "pmihsan",
                    "first_seen": "2022-12-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Dirty Pipe Kernel Vulnerability Exploit",
                    "summary": "Dirty Pipe Kernel Vulnerability Exploit",
                    "url": "https://github.com/pmihsan/Dirty-Pipe-CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · ajith737/Dirty-Pipe-CVE-2022-0847-POCs",
                    "author": "ajith737",
                    "first_seen": "2023-01-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/ajith737/Dirty-Pipe-CVE-2022-0847-POCs"
                },
                {
                    "repository": "PoC-in-GitHub · mutur4/CVE-2022-0847",
                    "author": "mutur4",
                    "first_seen": "2023-01-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Drity Pipe Linux Kernel 1-Day Exploit",
                    "summary": "Drity Pipe Linux Kernel 1-Day Exploit",
                    "url": "https://github.com/mutur4/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · orsuprasad/CVE-2022-0847-DirtyPipe-Exploits",
                    "author": "orsuprasad",
                    "first_seen": "2023-02-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/orsuprasad/CVE-2022-0847-DirtyPipe-Exploits"
                },
                {
                    "repository": "PoC-in-GitHub · JlSakuya/CVE-2022-0847-container-escape",
                    "author": "JlSakuya",
                    "first_seen": "2023-04-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.",
                    "summary": "A simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.",
                    "url": "https://github.com/JlSakuya/CVE-2022-0847-container-escape"
                },
                {
                    "repository": "PoC-in-GitHub · jonathanbest7/cve-2022-0847",
                    "author": "jonathanbest7",
                    "first_seen": "2023-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "check cve-2022-0847",
                    "summary": "check cve-2022-0847",
                    "url": "https://github.com/jonathanbest7/cve-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · 0xeremus/dirty-pipe-poc",
                    "author": "0xeremus",
                    "first_seen": "2023-06-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "POC Exploit to add user to Sudo for CVE-2022-0847 Dirty Pipe Vulnerability",
                    "summary": "POC Exploit to add user to Sudo for CVE-2022-0847 Dirty Pipe Vulnerability",
                    "url": "https://github.com/0xeremus/dirty-pipe-poc"
                },
                {
                    "repository": "PoC-in-GitHub · h4ckm310n/CVE-2022-0847-eBPF",
                    "author": "h4ckm310n",
                    "first_seen": "2023-07-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "An eBPF program to detect attacks on CVE-2022-0847",
                    "summary": "An eBPF program to detect attacks on CVE-2022-0847",
                    "url": "https://github.com/h4ckm310n/CVE-2022-0847-eBPF"
                },
                {
                    "repository": "PoC-in-GitHub · joeymeech/CVE-2022-0847-Exploit-Implementation",
                    "author": "joeymeech",
                    "first_seen": "2023-07-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Using CVE-2022-0847, \"Dirty Pipe Exploit\", to pop a reverse bash shell for arbitrary code execution on a foreign machine.",
                    "summary": "Using CVE-2022-0847, \"Dirty Pipe Exploit\", to pop a reverse bash shell for arbitrary code execution on a foreign machine.",
                    "url": "https://github.com/joeymeech/CVE-2022-0847-Exploit-Implementation"
                },
                {
                    "repository": "PoC-in-GitHub · pashayogi/DirtyPipe",
                    "author": "pashayogi",
                    "first_seen": "2023-09-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE: CVE-2022-0847",
                    "summary": "CVE: CVE-2022-0847",
                    "url": "https://github.com/pashayogi/DirtyPipe"
                },
                {
                    "repository": "PoC-in-GitHub · ayushx007/CVE-2022-0847-dirty-pipe-checker",
                    "author": "ayushx007",
                    "first_seen": "2023-10-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Bash script to check if kernel is vulnerable",
                    "summary": "Bash script to check if kernel is vulnerable",
                    "url": "https://github.com/ayushx007/CVE-2022-0847-dirty-pipe-checker"
                },
                {
                    "repository": "PoC-in-GitHub · ayushx007/CVE-2022-0847-DirtyPipe-Exploits",
                    "author": "ayushx007",
                    "first_seen": "2023-11-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/ayushx007/CVE-2022-0847-DirtyPipe-Exploits"
                },
                {
                    "repository": "PoC-in-GitHub · solomon12354/LockingGirl-----CVE-2022-0847-Dirty_Pipe_virus",
                    "author": "solomon12354",
                    "first_seen": "2023-12-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/solomon12354/LockingGirl-----CVE-2022-0847-Dirty_Pipe_virus"
                },
                {
                    "repository": "PoC-in-GitHub · letsr00t/CVE-2022-0847",
                    "author": "letsr00t",
                    "first_seen": "2024-02-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/letsr00t/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · karanlvm/DirtyPipe-Exploit",
                    "author": "karanlvm",
                    "first_seen": "2024-04-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Proof of concept for CVE-2022-0847",
                    "summary": "Proof of concept for CVE-2022-0847",
                    "url": "https://github.com/karanlvm/DirtyPipe-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · xsxtw/CVE-2022-0847",
                    "author": "xsxtw",
                    "first_seen": "2024-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/xsxtw/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · muhammad1596/CVE-2022-0847-dirty-pipe-checker",
                    "author": "muhammad1596",
                    "first_seen": "2024-06-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/muhammad1596/CVE-2022-0847-dirty-pipe-checker"
                },
                {
                    "repository": "PoC-in-GitHub · muhammad1596/CVE-2022-0847-DirtyPipe-Exploits",
                    "author": "muhammad1596",
                    "first_seen": "2024-06-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/muhammad1596/CVE-2022-0847-DirtyPipe-Exploits"
                },
                {
                    "repository": "PoC-in-GitHub · aswanepo/DirtyPipe",
                    "author": "aswanepo",
                    "first_seen": "2024-11-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Working Dirty Pipe (CVE-2022-0847) exploit tool with root access and file overwrites.",
                    "summary": "Working Dirty Pipe (CVE-2022-0847) exploit tool with root access and file overwrites.",
                    "url": "https://github.com/aswanepo/DirtyPipe"
                },
                {
                    "repository": "PoC-in-GitHub · JustinYe377/CTF-CVE-2022-0847",
                    "author": "JustinYe377",
                    "first_seen": "2025-01-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/JustinYe377/CTF-CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · mithunmadhukuttan/Dirty-Pipe-Exploit",
                    "author": "mithunmadhukuttan",
                    "first_seen": "2025-01-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "The **Dirty Pipe exploit (CVE-2022-0847)** is a Linux kernel vulnerability (v5.8+) allowing unprivileged attackers to overwrite arbitrary files via a flaw in the pipe mechanism. This leads to privilege escalation, granting root access. Similar to Dirty Cow but easier to exploit. Fix: Update to a patched kernel version.",
                    "summary": "The **Dirty Pipe exploit (CVE-2022-0847)** is a Linux kernel vulnerability (v5.8+) allowing unprivileged attackers to overwrite arbitrary files via a flaw in the pipe mechanism. This leads to privilege escalation, granting root access. Similar to Dirty Cow but easier to exploit. Fix: Update to a patched kernel version.",
                    "url": "https://github.com/mithunmadhukuttan/Dirty-Pipe-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Mephierr/DirtyPipe_exploit",
                    "author": "Mephierr",
                    "first_seen": "2025-01-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-0847",
                    "summary": "CVE-2022-0847",
                    "url": "https://github.com/Mephierr/DirtyPipe_exploit"
                },
                {
                    "repository": "PoC-in-GitHub · RogelioPumajulca/CVE-2022-0847",
                    "author": "RogelioPumajulca",
                    "first_seen": "2025-02-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/RogelioPumajulca/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · cypherlobo/DirtyPipe-BSI",
                    "author": "cypherlobo",
                    "first_seen": "2025-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A root exploit for CVE-2022-0847 (Dirty Pipe)",
                    "summary": "A root exploit for CVE-2022-0847 (Dirty Pipe)",
                    "url": "https://github.com/cypherlobo/DirtyPipe-BSI"
                },
                {
                    "repository": "PoC-in-GitHub · byteReaper77/Dirty-Pipe",
                    "author": "byteReaper77",
                    "first_seen": "2025-04-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Simple Exploit for Dirty Pipe Vulnerability (CVE-2022-0847) This repository contains a simple proof of concept (PoC) for the Dirty Pipe vulnerability (CVE-2022-0847), which affects Linux kernel versions 5.8 to 5.16. This exploit demonstrates local privilege escalation  by leveraging improper handling of pipe buffers in the kernel.",
                    "summary": "Simple Exploit for Dirty Pipe Vulnerability (CVE-2022-0847) This repository contains a simple proof of concept (PoC) for the Dirty Pipe vulnerability (CVE-2022-0847), which affects Linux kernel versions 5.8 to 5.16. This exploit demonstrates local privilege escalation  by leveraging improper handling of pipe buffers in the kernel.",
                    "url": "https://github.com/byteReaper77/Dirty-Pipe"
                },
                {
                    "repository": "PoC-in-GitHub · morgenm/dirtypipe",
                    "author": "morgenm",
                    "first_seen": "2025-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "DirtyPipe (CVE-2022-0847) exploit written in Rust",
                    "summary": "DirtyPipe (CVE-2022-0847) exploit written in Rust",
                    "url": "https://github.com/morgenm/dirtypipe"
                },
                {
                    "repository": "PoC-in-GitHub · Scouserr/cve-2022-0847-poc-dockerimage",
                    "author": "Scouserr",
                    "first_seen": "2025-08-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/Scouserr/cve-2022-0847-poc-dockerimage"
                },
                {
                    "repository": "PoC-in-GitHub · Shadow-Spinner/CVE-2022-0847",
                    "author": "Shadow-Spinner",
                    "first_seen": "2025-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "exploit of CVE-2022-0847 which directly remove password of the root account",
                    "summary": "exploit of CVE-2022-0847 which directly remove password of the root account",
                    "url": "https://github.com/Shadow-Spinner/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · xiaoLvChen/CVE-2022-0847",
                    "author": "xiaoLvChen",
                    "first_seen": "2026-01-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2022-0847（Linux 内核本地提权漏洞）",
                    "summary": "CVE-2022-0847（Linux 内核本地提权漏洞）",
                    "url": "https://github.com/xiaoLvChen/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · stfnw/reproducer-poc-CVE-2022-0847",
                    "author": "stfnw",
                    "first_seen": "2026-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Very rough PoC for detecting/reproducing CVE-2022-0847 (dirty pipe) through random generation of syscalls and differential fuzzing against a model.",
                    "summary": "Very rough PoC for detecting/reproducing CVE-2022-0847 (dirty pipe) through random generation of syscalls and differential fuzzing against a model.",
                    "url": "https://github.com/stfnw/reproducer-poc-CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · bluedragonsecurity/Linux-Kernel-Dirty-Pipe-Exploitation-Logic-Bug-",
                    "author": "bluedragonsecurity",
                    "first_seen": "2026-02-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Exploiting CVE-2022-0847 - written by : Antonius (w1sdom)",
                    "summary": "Exploiting CVE-2022-0847 - written by : Antonius (w1sdom)",
                    "url": "https://github.com/bluedragonsecurity/Linux-Kernel-Dirty-Pipe-Exploitation-Logic-Bug-"
                },
                {
                    "repository": "PoC-in-GitHub · SimoesCTT/Chrono-Drip-Temporal-Viscosity-Exploitation-Framework-CVE-2022-0847",
                    "author": "SimoesCTT",
                    "first_seen": "2026-02-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This tool demonstrates the application of fundamental physics discoveries to cybersecurity.",
                    "summary": "This tool demonstrates the application of fundamental physics discoveries to cybersecurity.",
                    "url": "https://github.com/SimoesCTT/Chrono-Drip-Temporal-Viscosity-Exploitation-Framework-CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · real-tim-johnston/megaquagga-pentest-report",
                    "author": "real-tim-johnston",
                    "first_seen": "2026-03-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Black box penetration test — WordPress exploitation, privilege escalation via CVE-2022-0847",
                    "summary": "Black box penetration test — WordPress exploitation, privilege escalation via CVE-2022-0847",
                    "url": "https://github.com/real-tim-johnston/megaquagga-pentest-report"
                },
                {
                    "repository": "PoC-in-GitHub · JeevanAnand1202/Penetration-Test",
                    "author": "JeevanAnand1202",
                    "first_seen": "2026-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Full penetration test report against `IP` (Ubuntu VM).   Attack chain: directory enumeration → backup file discovery → password cracking → CMS file upload → reverse shell → kernel privilege escalation (Dirty Pipe, CVE-2022-0847).",
                    "summary": "Full penetration test report against `IP` (Ubuntu VM).   Attack chain: directory enumeration → backup file discovery → password cracking → CMS file upload → reverse shell → kernel privilege escalation (Dirty Pipe, CVE-2022-0847).",
                    "url": "https://github.com/JeevanAnand1202/Penetration-Test"
                },
                {
                    "repository": "PoC-in-GitHub · gaganhm3018-art/CVE-2022-0847-Dirty-Pipe-",
                    "author": "gaganhm3018-art",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "this is  a repo who is facing a escalation issue in their linux system and a news regarding problem of \"Dirty pipeline\"",
                    "summary": "this is  a repo who is facing a escalation issue in their linux system and a news regarding problem of \"Dirty pipeline\"",
                    "url": "https://github.com/gaganhm3018-art/CVE-2022-0847-Dirty-Pipe-"
                },
                {
                    "repository": "PoC-in-GitHub · t1ckprivate/CVE-2022-0847-Dirty-Pipe",
                    "author": "t1ckprivate",
                    "first_seen": "2026-06-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/t1ckprivate/CVE-2022-0847-Dirty-Pipe"
                },
                {
                    "repository": "PoC-in-GitHub · vudangducminh/CVE-2022-0847",
                    "author": "vudangducminh",
                    "first_seen": "2026-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2022-0847 repository",
                    "summary": "",
                    "url": "https://github.com/vudangducminh/CVE-2022-0847"
                },
                {
                    "title": "Exploit for traitor CVE-2021-3560 CVE-2021-4034 CVE-2022-0847",
                    "summary": "Automatic Linux privilege escalation tool exploiting misconfigurations and GTFOBins vulnerabilities to gain root shel",
                    "what_happened": "Automatic Linux privilege escalation tool exploiting misconfigurations and GTFOBins vulnerabilities to gain root shel",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A2038172355644588718",
                        "https://kitploit.com/en/tools/github/liamg/traitor/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-02T21:29:33",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A2038172355644588718"
                },
                {
                    "title": "Exploit for traitor CVE-2021-3560 CVE-2021-4034 CVE-2022-0847",
                    "summary": "Automatic Linux privilege escalation tool exploiting misconfigurations and GTFOBins vulnerabilities to gain root shel",
                    "what_happened": "Automatic Linux privilege escalation tool exploiting misconfigurations and GTFOBins vulnerabilities to gain root shel",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A2038172355644588718",
                        "https://kitploit.com/en/tools/github/liamg/traitor/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-02T21:29:33",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/liamg/traitor/"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-14T04:52:35+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "cve-2022-0847dirtypipe-exploit",
                    "summary": "Exploit for CVE-2022-0847. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BOHR777-CVE-2022-0847DIRTYPIPE-EXPLOIT"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/50808",
                "https://github.com/bbaranoff/CVE-2022-0847",
                "https://github.com/xndpxs/CVE-2022-0847",
                "https://github.com/r1is/CVE-2022-0847",
                "https://github.com/Arinerron/CVE-2022-0847-DirtyPipe-Exploit",
                "https://github.com/crowsec-edtech/Dirty-Pipe",
                "https://github.com/lucksec/CVE-2022-0847",
                "https://github.com/si1ent-le/CVE-2022-0847",
                "https://github.com/bohr777/cve-2022-0847dirtypipe-exploit",
                "https://github.com/ZZ-SOCMAP/CVE-2022-0847",
                "https://github.com/cspshivam/CVE-2022-0847-dirty-pipe-exploit",
                "https://github.com/febinrev/dirtypipez-exploit",
                "https://github.com/ahrixia/CVE_2022_0847",
                "https://github.com/knqyf263/CVE-2022-0847",
                "https://github.com/puckiestyle/CVE-2022-0847",
                "https://github.com/0xIronGoat/dirty-pipe",
                "https://github.com/ITMarcin2211/CVE-2022-0847-DirtyPipe-Exploit",
                "https://github.com/mrchucu1/CVE-2022-0847-Docker",
                "https://github.com/basharkey/CVE-2022-0847-dirty-pipe-checker",
                "https://github.com/4luc4rdr5290/CVE-2022-0847",
                "https://github.com/dadhee/CVE-2022-0847_DirtyPipeExploit",
                "https://github.com/Greetdawn/CVE-2022-0847-DirtyPipe",
                "https://github.com/Al1ex/CVE-2022-0847",
                "https://github.com/Mustafa1986/CVE-2022-0847-DirtyPipe-Exploit",
                "https://github.com/nanaao/Dirtypipe-exploit",
                "https://github.com/AyoubNajim/cve-2022-0847dirtypipe-exploit",
                "https://github.com/pentestblogin/pentestblog-CVE-2022-0847",
                "https://github.com/gyaansastra/CVE-2022-0847",
                "https://github.com/DataDog/dirtypipe-container-breakout-poc",
                "https://github.com/babyshen/CVE-2022-0847",
                "https://github.com/edsonjt81/CVE-2022-0847-Linux",
                "https://github.com/chenaotian/CVE-2022-0847",
                "https://github.com/V0WKeep3r/CVE-2022-0847-DirtyPipe-Exploit",
                "https://github.com/osungjinwoo/CVE-2022-0847-Dirty-Pipe",
                "https://github.com/Greetdawn/CVE-2022-0847-DirtyPipe-",
                "https://github.com/crusoe112/DirtyPipePython",
                "https://github.com/nanaao/dirtyPipe-automaticRoot",
                "https://github.com/arttnba3/CVE-2022-0847",
                "https://github.com/AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits",
                "https://github.com/sa-infinity8888/Dirty-Pipe-CVE-2022-0847",
                "https://github.com/realbatuhan/dirtypipetester",
                "https://github.com/CYB3RK1D/CVE-2022-0847-POC",
                "https://github.com/breachnix/dirty-pipe-poc",
                "https://github.com/Shotokhan/cve_2022_0847_shellcode",
                "https://github.com/githublihaha/DirtyPIPE-CVE-2022-0847",
                "https://github.com/MrP1xel/CVE-2022-0847-dirty-pipe-kernel-checker",
                "https://github.com/jpts/CVE-2022-0847-DirtyPipe-Container-Breakout",
                "https://github.com/LudovicPatho/CVE-2022-0847_dirty-pipe",
                "https://github.com/DanaEpp/pwncat_dirtypipe",
                "https://github.com/tmoneypenny/CVE-2022-0847",
                "https://github.com/scopion/dirty-pipe",
                "https://github.com/stfnw/Debugging_Dirty_Pipe_CVE-2022-0847",
                "https://github.com/drapl0n/dirtypipe",
                "https://github.com/0xr1l3s/CVE-2022-0847",
                "https://github.com/mhanief/dirtypipe",
                "https://github.com/tufanturhan/CVE-2022-0847-L-nux-PrivEsc",
                "https://github.com/rexpository/linux-privilege-escalation",
                "https://github.com/isaiahsimeone/COMP3320-VAPT",
                "https://github.com/VinuKalana/DirtyPipe-CVE-2022-0847",
                "https://github.com/ihenakaarachchi/debian11-dirty_pipe-patcher",
                "https://github.com/greenhandatsjtu/CVE-2022-0847-Container-Escape",
                "https://github.com/jxpsx/CVE-2022-0847-DirtyPipe-Exploits",
                "https://github.com/airbus-cert/dirtypipe-ebpf_detection",
                "https://github.com/rabomen/Dirty-Pipe",
                "https://github.com/eduquintanilha/CVE-2022-0847-DirtyPipe-Exploits",
                "https://github.com/EagleTube/CVE-2022-0847",
                "https://github.com/KianaBin/CVE-2022-0847-Container-Escape",
                "https://github.com/notl0cal/dpipe",
                "https://github.com/Gustavo-Nogueira/Dirty-Pipe-Exploits",
                "https://github.com/b4dboy17/Dirty-Pipe-Oneshot",
                "https://github.com/edsonjt81/CVE-2022-0847-DirtyPipe-",
                "https://github.com/mattlloyddavies/ps-lab-cve-2022-0847",
                "https://github.com/qwert419/linux-",
                "https://github.com/DataFox/CVE-2022-0847",
                "https://github.com/pmihsan/Dirty-Pipe-CVE-2022-0847",
                "https://github.com/ajith737/Dirty-Pipe-CVE-2022-0847-POCs",
                "https://github.com/mutur4/CVE-2022-0847",
                "https://github.com/orsuprasad/CVE-2022-0847-DirtyPipe-Exploits",
                "https://github.com/JlSakuya/CVE-2022-0847-container-escape",
                "https://github.com/jonathanbest7/cve-2022-0847",
                "https://github.com/0xeremus/dirty-pipe-poc",
                "https://github.com/h4ckm310n/CVE-2022-0847-eBPF",
                "https://github.com/joeymeech/CVE-2022-0847-Exploit-Implementation",
                "https://github.com/pashayogi/DirtyPipe",
                "https://github.com/ayushx007/CVE-2022-0847-dirty-pipe-checker",
                "https://github.com/ayushx007/CVE-2022-0847-DirtyPipe-Exploits",
                "https://github.com/solomon12354/LockingGirl-----CVE-2022-0847-Dirty_Pipe_virus",
                "https://github.com/letsr00t/CVE-2022-0847",
                "https://github.com/karanlvm/DirtyPipe-Exploit",
                "https://github.com/xsxtw/CVE-2022-0847",
                "https://github.com/muhammad1596/CVE-2022-0847-dirty-pipe-checker",
                "https://github.com/muhammad1596/CVE-2022-0847-DirtyPipe-Exploits",
                "https://github.com/aswanepo/DirtyPipe",
                "https://github.com/JustinYe377/CTF-CVE-2022-0847",
                "https://github.com/mithunmadhukuttan/Dirty-Pipe-Exploit",
                "https://github.com/Mephierr/DirtyPipe_exploit",
                "https://github.com/RogelioPumajulca/CVE-2022-0847",
                "https://github.com/cypherlobo/DirtyPipe-BSI",
                "https://github.com/byteReaper77/Dirty-Pipe",
                "https://github.com/morgenm/dirtypipe",
                "https://github.com/Scouserr/cve-2022-0847-poc-dockerimage",
                "https://github.com/Shadow-Spinner/CVE-2022-0847",
                "https://github.com/xiaoLvChen/CVE-2022-0847",
                "https://github.com/stfnw/reproducer-poc-CVE-2022-0847",
                "https://github.com/bluedragonsecurity/Linux-Kernel-Dirty-Pipe-Exploitation-Logic-Bug-",
                "https://github.com/SimoesCTT/Chrono-Drip-Temporal-Viscosity-Exploitation-Framework-CVE-2022-0847",
                "https://github.com/real-tim-johnston/megaquagga-pentest-report",
                "https://github.com/JeevanAnand1202/Penetration-Test",
                "https://github.com/gaganhm3018-art/CVE-2022-0847-Dirty-Pipe-",
                "https://github.com/t1ckprivate/CVE-2022-0847-Dirty-Pipe",
                "https://github.com/vudangducminh/CVE-2022-0847",
                "https://sploitus.com/exploit?id=KITPLOIT%3A2038172355644588718",
                "https://kitploit.com/en/tools/github/liamg/traitor/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BOHR777-CVE-2022-0847DIRTYPIPE-EXPLOIT"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2022-0829",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Webmin-CVE-2022-0824-revshell exploit",
            "summary": "Exploit for CVE-2022-0824 and CVE-2022-0829. CVSS 9.",
            "updated_at": "2026-09-11T18:33:31Z",
            "published_at": "2026-09-11T18:33:31Z",
            "cvss": 9,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 20,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-11T18:33:31+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Webmin-CVE-2022-0824-revshell exploit",
                    "summary": "Exploit for CVE-2022-0824 and CVE-2022-0829. CVSS 9.",
                    "cvss": 9,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FAISALFS10X-WEBMIN-CVE-2022-0824-REVSHELL"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FAISALFS10X-WEBMIN-CVE-2022-0824-REVSHELL"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T18:33:31Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FAISALFS10X-WEBMIN-CVE-2022-0824-REVSHELL"
                }
            ]
        },
        {
            "id": "CVE-2022-0824",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Webmin 1.984 - Remote Code Execution (Authenticated)",
            "summary": "Webmin 1.984 - Remote Code Execution (Authenticated)",
            "updated_at": "2026-09-11T18:33:31Z",
            "published_at": "2026-09-11T18:33:31Z",
            "cvss": 9,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 57,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50809",
                    "author": "faisalfs10x",
                    "first_seen": "2022-03-09",
                    "confidence": "High",
                    "title": "Webmin 1.984 - Remote Code Execution (Authenticated)",
                    "summary": "Webmin 1.984 - Remote Code Execution (Authenticated)",
                    "url": "https://www.exploit-db.com/exploits/50809",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-11T18:33:31+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Webmin-CVE-2022-0824-revshell exploit",
                    "summary": "Exploit for CVE-2022-0824 and CVE-2022-0829. CVSS 9.",
                    "cvss": 9,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FAISALFS10X-WEBMIN-CVE-2022-0824-REVSHELL"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/50809",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FAISALFS10X-WEBMIN-CVE-2022-0824-REVSHELL"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T18:33:31Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/50809"
                }
            ]
        },
        {
            "id": "CVE-2022-0169",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2022-0169 exploit",
            "summary": "Exploit for CVE-2022-0169. CVSS 9.8.",
            "updated_at": "2026-09-06T08:27:30Z",
            "published_at": "2026-09-06T08:27:30Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-06T08:27:30+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2022-0169 exploit",
                    "summary": "Exploit for CVE-2022-0169. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X3RX3SSEC-CVE-2022-0169"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X3RX3SSEC-CVE-2022-0169"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:27:30Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-X3RX3SSEC-CVE-2022-0169"
                }
            ]
        },
        {
            "id": "CVE-2021-48007",
            "vendor": "pmmp",
            "product": "PocketMine-MP",
            "title": "PocketMine-MP vulnerability",
            "summary": "PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with invalid floating-point values to crash servers through unhandled mathematical operations or prevent clients from rendering other players.",
            "updated_at": "2026-09-06T13:17:10.077",
            "published_at": "2026-09-06T12:17:14.783",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.18.1 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with invalid floating-point values to crash servers through unhandled mathematical operations or prevent clients from rendering other players.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pmmp/PocketMine-MP/commit/fb20bb38327b4c08ee3976640cd0dd547388a638",
                "https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-fm35-jgg3-3grx",
                "https://www.vulncheck.com/advisories/pocketmine-mp-before-3.18.1-denial-of-service-via-moveplayerpacket"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:14.783",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-48007"
                }
            ]
        },
        {
            "id": "CVE-2021-48006",
            "vendor": "pmmp",
            "product": "PocketMine-MP",
            "title": "PocketMine-MP vulnerability",
            "summary": "PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an exactly matching entry, so an operator name stored with non-lowercase letters cannot be revoked using the deop command, leaving the player as an operator until the entry is removed from ops.txt manually.",
            "updated_at": "2026-09-06T13:17:09.963",
            "published_at": "2026-09-06T12:17:14.637",
            "cvss": 4.8,
            "cvss_vector": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 4.0.3 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-178",
            "what_happened": "PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an exactly matching entry, so an operator name stored with non-lowercase letters cannot be revoked using the deop command, leaving the player as an operator until the entry is removed from ops.txt manually.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pmmp/PocketMine-MP/commit/4d37b79ff7f9d9452e988387f97919a9a1c4954e",
                "https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-j5qg-w9jg-3wg3",
                "https://www.vulncheck.com/advisories/pocketmine-mp-before-4.0.3-operator-privilege-escalation-via-case-sensitivity"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:14.637",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-48006"
                }
            ]
        },
        {
            "id": "CVE-2021-45046",
            "vendor": "Apache",
            "product": "Log4j2",
            "title": "Apache Log4j2 Deserialization of Untrusted Data Vulnerability",
            "summary": "Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.",
            "updated_at": "2026-09-13T18:34:52Z",
            "published_at": "2026-09-13T18:34:52Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 25,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:34:52+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Log4j-JNDIServer exploit",
                    "summary": "Exploit for CVE-2021-44228 and CVE-2021-45046. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IMMUNITYINC-LOG4J-JNDISERVER"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IMMUNITYINC-LOG4J-JNDISERVER"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:34:52Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-44790",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Apache 2.4.x - Buffer Overflow",
            "summary": "Apache 2.4.x - Buffer Overflow",
            "updated_at": "2026-09-13T15:43:34Z",
            "published_at": "2026-09-13T15:43:34Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 28,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-444",
            "what_happened": "HTTP Request Smuggling vulnerability via Apache proxy (CVE-2023-25690).",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 51193",
                    "author": "Sunil Iyengar",
                    "first_seen": "2023-04-01",
                    "confidence": "High",
                    "title": "Apache 2.4.x - Buffer Overflow",
                    "summary": "Apache 2.4.x - Buffer Overflow",
                    "url": "https://www.exploit-db.com/exploits/51193",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2023-25690_lab",
                    "summary": "HTTP Request Smuggling vulnerability via Apache proxy (CVE-2023-25690).",
                    "what_happened": "HTTP Request Smuggling vulnerability via Apache proxy (CVE-2023-25690).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-444",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GIORDY0424-CVE-2023-25690_LAB",
                        "https://kitploit.com/zh/tools/github/giordy0424/cve-2023-25690_lab/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-13T17:43:34",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GIORDY0424-CVE-2023-25690_LAB"
                },
                {
                    "title": "Exploit for CVE-2023-25690_lab",
                    "summary": "HTTP Request Smuggling vulnerability via Apache proxy (CVE-2023-25690).",
                    "what_happened": "HTTP Request Smuggling vulnerability via Apache proxy (CVE-2023-25690).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-444",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GIORDY0424-CVE-2023-25690_LAB",
                        "https://kitploit.com/zh/tools/github/giordy0424/cve-2023-25690_lab/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-13T17:43:34",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/giordy0424/cve-2023-25690_lab/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/51193",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GIORDY0424-CVE-2023-25690_LAB",
                "https://kitploit.com/zh/tools/github/giordy0424/cve-2023-25690_lab/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T15:43:34Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/51193"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2021-44228",
            "vendor": "Apache",
            "product": "Log4j2",
            "title": "Apache Log4j2 Remote Code Execution Vulnerability",
            "summary": "Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.",
            "updated_at": "2026-09-14T18:31:54Z",
            "published_at": "2026-09-14T18:31:54Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 4590,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 51183",
                    "author": "Chan Nyein Wai",
                    "first_seen": "2023-04-01",
                    "confidence": "High",
                    "title": "AD Manager Plus 7122 - Remote Code Execution (RCE)",
                    "summary": "AD Manager Plus 7122 - Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/51183",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 50592",
                    "author": "kozmer",
                    "first_seen": "2021-12-14",
                    "confidence": "High",
                    "title": "Apache Log4j 2 - Remote Code Execution (RCE)",
                    "summary": "Apache Log4j 2 - Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/50592",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 50590",
                    "author": "leonjza",
                    "first_seen": "2021-12-14",
                    "confidence": "High",
                    "title": "Apache Log4j2 2.14.1 - Information Disclosure",
                    "summary": "Apache Log4j2 2.14.1 - Information Disclosure",
                    "url": "https://www.exploit-db.com/exploits/50590",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce",
                    "author": "tangxiaofeng7",
                    "first_seen": "2021-12-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 89,
                    "title": "Apache Log4j 远程代码执行",
                    "summary": "Apache Log4j 远程代码执行",
                    "url": "https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce"
                },
                {
                    "repository": "PoC-in-GitHub · Glease/Healer",
                    "author": "Glease",
                    "first_seen": "2021-12-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": "Patch up CVE-2021-44228 for minecraft forge 1.7.10 - 1.12.2",
                    "summary": "Patch up CVE-2021-44228 for minecraft forge 1.7.10 - 1.12.2",
                    "url": "https://github.com/Glease/Healer"
                },
                {
                    "repository": "PoC-in-GitHub · jacobtread/L4J-Vuln-Patch",
                    "author": "jacobtread",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or updating versions of minecraft as its not a perminent patch",
                    "summary": "This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or updating versions of minecraft as its not a perminent patch",
                    "url": "https://github.com/jacobtread/L4J-Vuln-Patch"
                },
                {
                    "repository": "PoC-in-GitHub · jas502n/Log4j2-CVE-2021-44228",
                    "author": "jas502n",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 469,
                    "title": "Remote Code Injection In Log4j",
                    "summary": "Remote Code Injection In Log4j",
                    "url": "https://github.com/jas502n/Log4j2-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · HyCraftHD/Log4J-RCE-Proof-Of-Concept",
                    "author": "HyCraftHD",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 182,
                    "title": "Log4j-RCE (CVE-2021-44228) Proof of Concept with additional information",
                    "summary": "Log4j-RCE (CVE-2021-44228) Proof of Concept with additional information",
                    "url": "https://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept"
                },
                {
                    "repository": "PoC-in-GitHub · boundaryx/cloudrasp-log4j2",
                    "author": "boundaryx",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 126,
                    "title": "一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.",
                    "summary": "一个针对防御 log4j2 CVE-2021-44228 漏洞的 RASP 工具。 A Runtime Application Self-Protection module specifically designed for log4j2 RCE (CVE-2021-44228) defense.",
                    "url": "https://github.com/boundaryx/cloudrasp-log4j2"
                },
                {
                    "repository": "PoC-in-GitHub · dbgee/CVE-2021-44228",
                    "author": "dbgee",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Apache Log4j 2   a remote code execution vulnerability via the ldap JNDI parser.",
                    "summary": "Apache Log4j 2   a remote code execution vulnerability via the ldap JNDI parser.",
                    "url": "https://github.com/dbgee/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · CreeperHost/Log4jPatcher",
                    "author": "CreeperHost",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 49,
                    "title": "A mitigation for CVE-2021-44228 (log4shell) that works by patching the vulnerability at runtime. (Works with any vulnerable java software, tested with java 6 and newer)",
                    "summary": "A mitigation for CVE-2021-44228 (log4shell) that works by patching the vulnerability at runtime. (Works with any vulnerable java software, tested with java 6 and newer)",
                    "url": "https://github.com/CreeperHost/Log4jPatcher"
                },
                {
                    "repository": "PoC-in-GitHub · DragonSurvivalEU/RCE",
                    "author": "DragonSurvivalEU",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2021-44228 fix",
                    "summary": "CVE-2021-44228 fix",
                    "url": "https://github.com/DragonSurvivalEU/RCE"
                },
                {
                    "repository": "PoC-in-GitHub · simonis/Log4jPatch",
                    "author": "simonis",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 108,
                    "title": "Deploys an agent to fix  CVE-2021-44228 (Log4j RCE vulnerability) in a running JVM process",
                    "summary": "Deploys an agent to fix  CVE-2021-44228 (Log4j RCE vulnerability) in a running JVM process",
                    "url": "https://github.com/simonis/Log4jPatch"
                },
                {
                    "repository": "PoC-in-GitHub · zlepper/CVE-2021-44228-Test-Server",
                    "author": "zlepper",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A small server for verifing if a given java program is succeptibel to CVE-2021-44228",
                    "summary": "A small server for verifing if a given java program is succeptibel to CVE-2021-44228",
                    "url": "https://github.com/zlepper/CVE-2021-44228-Test-Server"
                },
                {
                    "repository": "PoC-in-GitHub · christophetd/log4shell-vulnerable-app",
                    "author": "christophetd",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1140,
                    "title": "Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).",
                    "summary": "Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).",
                    "url": "https://github.com/christophetd/log4shell-vulnerable-app"
                },
                {
                    "repository": "PoC-in-GitHub · NorthwaveSecurity/log4jcheck",
                    "author": "NorthwaveSecurity",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 127,
                    "title": "A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.",
                    "summary": "A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.",
                    "url": "https://github.com/NorthwaveSecurity/log4jcheck"
                },
                {
                    "repository": "PoC-in-GitHub · nkoneko/VictimApp",
                    "author": "nkoneko",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Vulnerable to CVE-2021-44228. trustURLCodebase is not required.",
                    "summary": "Vulnerable to CVE-2021-44228. trustURLCodebase is not required.",
                    "url": "https://github.com/nkoneko/VictimApp"
                },
                {
                    "repository": "PoC-in-GitHub · lhotari/pulsar-docker-images-patch-CVE-2021-44228",
                    "author": "lhotari",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Patch Pulsar Docker images with Log4J 2.17.1 update to mitigate Apache Log4J Security Vulnerabilities including Log4Shell",
                    "summary": "Patch Pulsar Docker images with Log4J 2.17.1 update to mitigate Apache Log4J Security Vulnerabilities including Log4Shell",
                    "url": "https://github.com/lhotari/pulsar-docker-images-patch-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · 1in9e/Apache-Log4j2-RCE",
                    "author": "1in9e",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Apache Log4j2 RCE( CVE-2021-44228)验证环境",
                    "summary": "Apache Log4j2 RCE( CVE-2021-44228)验证环境",
                    "url": "https://github.com/1in9e/Apache-Log4j2-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · KosmX/CVE-2021-44228-example",
                    "author": "KosmX",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "vulnerability POC",
                    "summary": "vulnerability POC",
                    "url": "https://github.com/KosmX/CVE-2021-44228-example"
                },
                {
                    "repository": "PoC-in-GitHub · greymd/CVE-2021-44228",
                    "author": "greymd",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 35,
                    "title": "Vulnerability CVE-2021-44228 checker",
                    "summary": "Vulnerability CVE-2021-44228 checker",
                    "url": "https://github.com/greymd/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · mubix/CVE-2021-44228-Log4Shell-Hashes",
                    "author": "mubix",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 155,
                    "title": "Hashes for vulnerable LOG4J versions",
                    "summary": "Hashes for vulnerable LOG4J versions",
                    "url": "https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes"
                },
                {
                    "repository": "PoC-in-GitHub · OopsieWoopsie/mc-log4j-patcher",
                    "author": "OopsieWoopsie",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2021-44228 server-side fix for minecraft servers.",
                    "summary": "CVE-2021-44228 server-side fix for minecraft servers.",
                    "url": "https://github.com/OopsieWoopsie/mc-log4j-patcher"
                },
                {
                    "repository": "PoC-in-GitHub · wheezysec/CVE-2021-44228-kusto",
                    "author": "wheezysec",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/wheezysec/CVE-2021-44228-kusto"
                },
                {
                    "repository": "PoC-in-GitHub · izzyacademy/log4shell-mitigation",
                    "author": "izzyacademy",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Mitigation for Log4Shell Security Vulnerability CVE-2021-44228",
                    "summary": "Mitigation for Log4Shell Security Vulnerability CVE-2021-44228",
                    "url": "https://github.com/izzyacademy/log4shell-mitigation"
                },
                {
                    "repository": "PoC-in-GitHub · Kadantte/CVE-2021-44228-poc",
                    "author": "Kadantte",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "log4shell sample application (CVE-2021-44228)",
                    "summary": "log4shell sample application (CVE-2021-44228)",
                    "url": "https://github.com/Kadantte/CVE-2021-44228-poc"
                },
                {
                    "repository": "PoC-in-GitHub · takito1812/log4j-detect",
                    "author": "takito1812",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 195,
                    "title": "Simple Python 3 script to detect the \"Log4j\" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading",
                    "summary": "Simple Python 3 script to detect the \"Log4j\" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading",
                    "url": "https://github.com/takito1812/log4j-detect"
                },
                {
                    "repository": "PoC-in-GitHub · winnpixie/log4noshell",
                    "author": "winnpixie",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "A Java Agent that disables Apache Log4J's JNDI Lookup to mitigate CVE-2021-44228 (\"Log4Shell\").",
                    "summary": "A Java Agent that disables Apache Log4J's JNDI Lookup to mitigate CVE-2021-44228 (\"Log4Shell\").",
                    "url": "https://github.com/winnpixie/log4noshell"
                },
                {
                    "repository": "PoC-in-GitHub · Azeemering/CVE-2021-44228-DFIR-Notes",
                    "author": "Azeemering",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2021-44228 DFIR Notes",
                    "summary": "CVE-2021-44228 DFIR Notes",
                    "url": "https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes"
                },
                {
                    "repository": "PoC-in-GitHub · Puliczek/CVE-2021-44228-PoC-log4j-bypass-words",
                    "author": "Puliczek",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 948,
                    "title": "🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks",
                    "summary": "🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks",
                    "url": "https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words"
                },
                {
                    "repository": "PoC-in-GitHub · kozmer/log4j-shell-poc",
                    "author": "kozmer",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1847,
                    "title": "A Proof-Of-Concept for the CVE-2021-44228 vulnerability.",
                    "summary": "A Proof-Of-Concept for the CVE-2021-44228 vulnerability.",
                    "url": "https://github.com/kozmer/log4j-shell-poc"
                },
                {
                    "repository": "PoC-in-GitHub · alexandreroman/cve-2021-44228-workaround-buildpack",
                    "author": "alexandreroman",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)",
                    "summary": "Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)",
                    "url": "https://github.com/alexandreroman/cve-2021-44228-workaround-buildpack"
                },
                {
                    "repository": "PoC-in-GitHub · Adikso/minecraft-log4j-honeypot",
                    "author": "Adikso",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 106,
                    "title": "Minecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam",
                    "summary": "Minecraft Honeypot for Log4j exploit. CVE-2021-44228 Log4Shell LogJam",
                    "url": "https://github.com/Adikso/minecraft-log4j-honeypot"
                },
                {
                    "repository": "PoC-in-GitHub · racoon-rac/CVE-2021-44228",
                    "author": "racoon-rac",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/racoon-rac/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · TheArqsz/CVE-2021-44228-PoC",
                    "author": "TheArqsz",
                    "first_seen": "2021-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/TheArqsz/CVE-2021-44228-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · 1lann/log4shelldetect",
                    "author": "1lann",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 45,
                    "title": "Rapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or \"that Log4j JNDI exploit\" by inspecting the class paths inside files",
                    "summary": "Rapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or \"that Log4j JNDI exploit\" by inspecting the class paths inside files",
                    "url": "https://github.com/1lann/log4shelldetect"
                },
                {
                    "repository": "PoC-in-GitHub · binganao/Log4j2-RCE",
                    "author": "binganao",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Log4j2 CVE-2021-44228 复现和回显利用",
                    "summary": "Log4j2 CVE-2021-44228 复现和回显利用",
                    "url": "https://github.com/binganao/Log4j2-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · phoswald/sample-ldap-exploit",
                    "author": "phoswald",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "A short demo of CVE-2021-44228",
                    "summary": "A short demo of CVE-2021-44228",
                    "url": "https://github.com/phoswald/sample-ldap-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · rakutentech/jndi-ldap-test-server",
                    "author": "rakutentech",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "A minimalistic LDAP server that is meant for test vulnerability to JNDI+LDAP injection attacks in Java, especially CVE-2021-44228.",
                    "summary": "A minimalistic LDAP server that is meant for test vulnerability to JNDI+LDAP injection attacks in Java, especially CVE-2021-44228.",
                    "url": "https://github.com/rakutentech/jndi-ldap-test-server"
                },
                {
                    "repository": "PoC-in-GitHub · uint0/cve-2021-44228--spring-hibernate",
                    "author": "uint0",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228 POC - Spring / Hibernate",
                    "summary": "CVE-2021-44228 POC - Spring / Hibernate",
                    "url": "https://github.com/uint0/cve-2021-44228--spring-hibernate"
                },
                {
                    "repository": "PoC-in-GitHub · saharNooby/log4j-vulnerability-patcher-agent",
                    "author": "saharNooby",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Fixes CVE-2021-44228 in log4j by patching JndiLookup class",
                    "summary": "Fixes CVE-2021-44228 in log4j by patching JndiLookup class",
                    "url": "https://github.com/saharNooby/log4j-vulnerability-patcher-agent"
                },
                {
                    "repository": "PoC-in-GitHub · f0ng/log4j2burpscanner",
                    "author": "f0ng",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 841,
                    "title": "CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks",
                    "summary": "CVE-2021-44228 Log4j2 BurpSuite Scanner,Customize ceye.io api or other apis,including internal networks",
                    "url": "https://github.com/f0ng/log4j2burpscanner"
                },
                {
                    "repository": "PoC-in-GitHub · M1ngGod/CVE-2021-44228-Log4j-lookup-Rce",
                    "author": "M1ngGod",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/M1ngGod/CVE-2021-44228-Log4j-lookup-Rce"
                },
                {
                    "repository": "PoC-in-GitHub · byteboycn/CVE-2021-44228-Apache-Log4j-Rce",
                    "author": "byteboycn",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/byteboycn/CVE-2021-44228-Apache-Log4j-Rce"
                },
                {
                    "repository": "PoC-in-GitHub · lhotari/log4shell-mitigation-tester",
                    "author": "lhotari",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 16,
                    "title": "Log4Shell CVE-2021-44228 mitigation tester",
                    "summary": "Log4Shell CVE-2021-44228 mitigation tester",
                    "url": "https://github.com/lhotari/log4shell-mitigation-tester"
                },
                {
                    "repository": "PoC-in-GitHub · toramanemre/log4j-rce-detect-waf-bypass",
                    "author": "toramanemre",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 23,
                    "title": "A Nuclei Template for Apache Log4j RCE (CVE-2021-44228) Detection with WAF Bypass Payloads",
                    "summary": "A Nuclei Template for Apache Log4j RCE (CVE-2021-44228) Detection with WAF Bypass Payloads",
                    "url": "https://github.com/toramanemre/log4j-rce-detect-waf-bypass"
                },
                {
                    "repository": "PoC-in-GitHub · logpresso/CVE-2021-44228-Scanner",
                    "author": "logpresso",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 859,
                    "title": "Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228",
                    "summary": "Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228",
                    "url": "https://github.com/logpresso/CVE-2021-44228-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · vorburger/Log4j_CVE-2021-44228",
                    "author": "vorburger",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/vorburger/Log4j_CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · gauthamg/log4j2021_vul_test",
                    "author": "gauthamg",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Test the CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228",
                    "summary": "Test the CVE https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228",
                    "url": "https://github.com/gauthamg/log4j2021_vul_test"
                },
                {
                    "repository": "PoC-in-GitHub · b-abderrahmane/CVE-2021-44228-playground",
                    "author": "b-abderrahmane",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/b-abderrahmane/CVE-2021-44228-playground"
                },
                {
                    "repository": "PoC-in-GitHub · leetxyz/CVE-2021-44228-Advisories",
                    "author": "leetxyz",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "List of company advisories log4j",
                    "summary": "List of company advisories log4j",
                    "url": "https://github.com/leetxyz/CVE-2021-44228-Advisories"
                },
                {
                    "repository": "PoC-in-GitHub · cado-security/log4shell",
                    "author": "cado-security",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Content to help the community responding to the Log4j Vulnerability Log4Shell CVE-2021-44228",
                    "summary": "Content to help the community responding to the Log4j Vulnerability Log4Shell CVE-2021-44228",
                    "url": "https://github.com/cado-security/log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · WYSIIWYG/Log4J_0day_RCE",
                    "author": "WYSIIWYG",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4j-RCE (CVE-2021-44228) Proof of Concept",
                    "summary": "Log4j-RCE (CVE-2021-44228) Proof of Concept",
                    "url": "https://github.com/WYSIIWYG/Log4J_0day_RCE"
                },
                {
                    "repository": "PoC-in-GitHub · mkhazamipour/log4j-vulnerable-app-cve-2021-44228-terraform",
                    "author": "mkhazamipour",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A Terraform to deploy vulnerable app and a JDNIExploit to work with CVE-2021-44228",
                    "summary": "A Terraform to deploy vulnerable app and a JDNIExploit to work with CVE-2021-44228",
                    "url": "https://github.com/mkhazamipour/log4j-vulnerable-app-cve-2021-44228-terraform"
                },
                {
                    "repository": "PoC-in-GitHub · Sh0ckFR/log4j-CVE-2021-44228-Public-IoCs",
                    "author": "Sh0ckFR",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "Public IoCs about log4j CVE-2021-44228",
                    "summary": "Public IoCs about log4j CVE-2021-44228",
                    "url": "https://github.com/Sh0ckFR/log4j-CVE-2021-44228-Public-IoCs"
                },
                {
                    "repository": "PoC-in-GitHub · zzzz0317/log4j2-vulnerable-spring-app",
                    "author": "zzzz0317",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2021-44228",
                    "summary": "CVE-2021-44228",
                    "url": "https://github.com/zzzz0317/log4j2-vulnerable-spring-app"
                },
                {
                    "repository": "PoC-in-GitHub · datadavev/test-44228",
                    "author": "datadavev",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Simple demo of CVE-2021-44228",
                    "summary": "Simple demo of CVE-2021-44228",
                    "url": "https://github.com/datadavev/test-44228"
                },
                {
                    "repository": "PoC-in-GitHub · LemonCraftRu/JndiRemover",
                    "author": "LemonCraftRu",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Небольшой мод направленный на устранение уязвимости CVE-2021-44228",
                    "summary": "Небольшой мод направленный на устранение уязвимости CVE-2021-44228",
                    "url": "https://github.com/LemonCraftRu/JndiRemover"
                },
                {
                    "repository": "PoC-in-GitHub · zhangxvx/Log4j-Rec-CVE-2021-44228",
                    "author": "zhangxvx",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Apache Log4j CVE-2021-44228 漏洞复现",
                    "summary": "Apache Log4j CVE-2021-44228 漏洞复现",
                    "url": "https://github.com/zhangxvx/Log4j-Rec-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · darkarnium/Log4j-CVE-Detect",
                    "author": "darkarnium",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 35,
                    "title": "Detections for CVE-2021-44228 inside of nested binaries",
                    "summary": "Detections for CVE-2021-44228 inside of nested binaries",
                    "url": "https://github.com/darkarnium/Log4j-CVE-Detect"
                },
                {
                    "repository": "PoC-in-GitHub · chilliwebs/CVE-2021-44228_Example",
                    "author": "chilliwebs",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/chilliwebs/CVE-2021-44228_Example"
                },
                {
                    "repository": "PoC-in-GitHub · irgoncalves/f5-waf-enforce-sig-CVE-2021-44228",
                    "author": "irgoncalves",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "This enforces signatures for CVE-2021-44228 across all policies on a BIG-IP ASM device",
                    "summary": "This enforces signatures for CVE-2021-44228 across all policies on a BIG-IP ASM device",
                    "url": "https://github.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · jeffbryner/log4j-docker-vaccine",
                    "author": "jeffbryner",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "docker compose solution to run a vaccine environment for the log4j2 vulnerability CVE-2021-44228",
                    "summary": "docker compose solution to run a vaccine environment for the log4j2 vulnerability CVE-2021-44228",
                    "url": "https://github.com/jeffbryner/log4j-docker-vaccine"
                },
                {
                    "repository": "PoC-in-GitHub · mergebase/log4j-detector",
                    "author": "mergebase",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 640,
                    "title": "A public open sourced tool.  Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any application. It is able to even find Log4J instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too!  TAG_OS_TOOL, OWNER_KELLY, DC_PUBLIC",
                    "summary": "A public open sourced tool.  Log4J scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046, etc) on your file-system within any application. It is able to even find Log4J instances that are hidden several layers deep. Works on Linux, Windows, and Mac, and everywhere else Java runs, too!  TAG_OS_TOOL, OWNER_KELLY, DC_PUBLIC",
                    "url": "https://github.com/mergebase/log4j-detector"
                },
                {
                    "repository": "PoC-in-GitHub · unlimitedsola/log4j2-rce-poc",
                    "author": "unlimitedsola",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A bare minimum proof-of-concept for Log4j2 JNDI RCE vulnerability (CVE-2021-44228/Log4Shell).",
                    "summary": "A bare minimum proof-of-concept for Log4j2 JNDI RCE vulnerability (CVE-2021-44228/Log4Shell).",
                    "url": "https://github.com/unlimitedsola/log4j2-rce-poc"
                },
                {
                    "repository": "PoC-in-GitHub · Jeromeyoung/log4j2burpscanner",
                    "author": "Jeromeyoung",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 32,
                    "title": "CVE-2021-44228，log4j2 burp插件 Java版本，dnslog选取了非dnslog.cn域名",
                    "summary": "CVE-2021-44228，log4j2 burp插件 Java版本，dnslog选取了非dnslog.cn域名",
                    "url": "https://github.com/Jeromeyoung/log4j2burpscanner"
                },
                {
                    "repository": "PoC-in-GitHub · corretto/hotpatch-for-apache-log4j2",
                    "author": "corretto",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 497,
                    "title": "An  agent to hotpatch the log4j RCE from CVE-2021-44228.",
                    "summary": "An  agent to hotpatch the log4j RCE from CVE-2021-44228.",
                    "url": "https://github.com/corretto/hotpatch-for-apache-log4j2"
                },
                {
                    "repository": "PoC-in-GitHub · alexandre-lavoie/python-log4rce",
                    "author": "alexandre-lavoie",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 178,
                    "title": "An All-In-One Pure Python PoC for CVE-2021-44228",
                    "summary": "An All-In-One Pure Python PoC for CVE-2021-44228",
                    "url": "https://github.com/alexandre-lavoie/python-log4rce"
                },
                {
                    "repository": "PoC-in-GitHub · RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs",
                    "author": "RedDrip7",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 44,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs"
                },
                {
                    "repository": "PoC-in-GitHub · mzlogin/CVE-2021-44228-Demo",
                    "author": "mzlogin",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Apache Log4j2 CVE-2021-44228 RCE Demo with RMI and LDAP",
                    "summary": "Apache Log4j2 CVE-2021-44228 RCE Demo with RMI and LDAP",
                    "url": "https://github.com/mzlogin/CVE-2021-44228-Demo"
                },
                {
                    "repository": "PoC-in-GitHub · blake-fm/vcenter-log4j",
                    "author": "blake-fm",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 16,
                    "title": "Script to apply official workaround for VMware vCenter log4j vulnerability CVE-2021-44228",
                    "summary": "Script to apply official workaround for VMware vCenter log4j vulnerability CVE-2021-44228",
                    "url": "https://github.com/blake-fm/vcenter-log4j"
                },
                {
                    "repository": "PoC-in-GitHub · uint0/cve-2021-44228-helpers",
                    "author": "uint0",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/uint0/cve-2021-44228-helpers"
                },
                {
                    "repository": "PoC-in-GitHub · sud0x00/log4j-CVE-2021-44228",
                    "author": "sud0x00",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2021-44228",
                    "summary": "CVE-2021-44228",
                    "url": "https://github.com/sud0x00/log4j-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · DiCanio/CVE-2021-44228-docker-example",
                    "author": "DiCanio",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/DiCanio/CVE-2021-44228-docker-example"
                },
                {
                    "repository": "PoC-in-GitHub · mrlnstk/cve-2021-44228-minecraft-poc",
                    "author": "mrlnstk",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Log4J CVE-2021-44228 Minecraft PoC",
                    "summary": "Log4J CVE-2021-44228 Minecraft PoC",
                    "url": "https://github.com/mrlnstk/cve-2021-44228-minecraft-poc"
                },
                {
                    "repository": "PoC-in-GitHub · RrUZi/Awesome-CVE-2021-44228",
                    "author": "RrUZi",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "An awesome curated list of repos for CVE-2021-44228.     ``Apache Log4j 2``",
                    "summary": "An awesome curated list of repos for CVE-2021-44228.     ``Apache Log4j 2``",
                    "url": "https://github.com/RrUZi/Awesome-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · future-client/CVE-2021-44228",
                    "author": "future-client",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 66,
                    "title": "Abuse Log4J CVE-2021-44228 to patch CVE-2021-44228 in vulnerable Minecraft game sessions to prevent exploitation in the session :)",
                    "summary": "Abuse Log4J CVE-2021-44228 to patch CVE-2021-44228 in vulnerable Minecraft game sessions to prevent exploitation in the session :)",
                    "url": "https://github.com/future-client/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · CodeShield-Security/Log4JShell-Bytecode-Detector",
                    "author": "CodeShield-Security",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 49,
                    "title": "Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)",
                    "summary": "Local Bytecode Scanner for the Log4JShell Vulnerability (CVE-2021-44228)",
                    "url": "https://github.com/CodeShield-Security/Log4JShell-Bytecode-Detector"
                },
                {
                    "repository": "PoC-in-GitHub · Crane-Mocker/log4j-poc",
                    "author": "Crane-Mocker",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Poc of log4j2 (CVE-2021-44228)",
                    "summary": "Poc of log4j2 (CVE-2021-44228)",
                    "url": "https://github.com/Crane-Mocker/log4j-poc"
                },
                {
                    "repository": "PoC-in-GitHub · dtact/divd-2021-00038--log4j-scanner",
                    "author": "dtact",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 46,
                    "title": "Scan systems and docker images for potential log4j vulnerabilities. Able to patch (remove JndiLookup.class) from layered archives. Will detect in-depth (layered archives jar/zip/tar/war and scans for vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046 and CVE-2021-45105). Binaries for Windows, Linux and OsX, but can be build on each platform supported by supported Golang.",
                    "summary": "Scan systems and docker images for potential log4j vulnerabilities. Able to patch (remove JndiLookup.class) from layered archives. Will detect in-depth (layered archives jar/zip/tar/war and scans for vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046 and CVE-2021-45105). Binaries for Windows, Linux and OsX, but can be build on each platform supported by supported Golang.",
                    "url": "https://github.com/dtact/divd-2021-00038--log4j-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · kali-dass/CVE-2021-44228-log4Shell",
                    "author": "kali-dass",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Sample log4j shell exploit",
                    "summary": "Sample log4j shell exploit",
                    "url": "https://github.com/kali-dass/CVE-2021-44228-log4Shell"
                },
                {
                    "repository": "PoC-in-GitHub · pravin-pp/log4j2-CVE-2021-44228",
                    "author": "pravin-pp",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/pravin-pp/log4j2-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228",
                    "author": "Malwar3Ninja",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 15,
                    "title": "IP addresses exploiting recent log4j2 vulnerability CVE-2021-44228",
                    "summary": "IP addresses exploiting recent log4j2 vulnerability CVE-2021-44228",
                    "url": "https://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · urholaukkarinen/docker-log4shell",
                    "author": "urholaukkarinen",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Dockerized Go app for testing the CVE-2021-44228 vulnerability",
                    "summary": "Dockerized Go app for testing the CVE-2021-44228 vulnerability",
                    "url": "https://github.com/urholaukkarinen/docker-log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · ssl/scan4log4j",
                    "author": "ssl",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Python script that sends CVE-2021-44228 log4j payload requests to url list",
                    "summary": "Python script that sends CVE-2021-44228 log4j payload requests to url list",
                    "url": "https://github.com/ssl/scan4log4j"
                },
                {
                    "repository": "PoC-in-GitHub · infiniroot/nginx-mitigate-log4shell",
                    "author": "infiniroot",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 38,
                    "title": "Mitigate log4shell (CVE-2021-44228) vulnerability attacks using Nginx LUA script",
                    "summary": "Mitigate log4shell (CVE-2021-44228) vulnerability attacks using Nginx LUA script",
                    "url": "https://github.com/infiniroot/nginx-mitigate-log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · lohanichaten/log4j-cve-2021-44228",
                    "author": "lohanichaten",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/lohanichaten/log4j-cve-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · authomize/log4j-log4shell-affected",
                    "author": "authomize",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 52,
                    "title": "Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security responders to be able to find and address the vulnerability",
                    "summary": "Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security responders to be able to find and address the vulnerability",
                    "url": "https://github.com/authomize/log4j-log4shell-affected"
                },
                {
                    "repository": "PoC-in-GitHub · guardicode/CVE-2021-44228_IoCs",
                    "author": "guardicode",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Known IoCs for log4j framework vulnerability",
                    "summary": "Known IoCs for log4j framework vulnerability",
                    "url": "https://github.com/guardicode/CVE-2021-44228_IoCs"
                },
                {
                    "repository": "PoC-in-GitHub · fireflyingup/log4j-poc",
                    "author": "fireflyingup",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 test demo",
                    "summary": "CVE-2021-44228 test demo",
                    "url": "https://github.com/fireflyingup/log4j-poc"
                },
                {
                    "repository": "PoC-in-GitHub · qingtengyun/cve-2021-44228-qingteng-patch",
                    "author": "qingtengyun",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/qingtengyun/cve-2021-44228-qingteng-patch"
                },
                {
                    "repository": "PoC-in-GitHub · nccgroup/log4j-jndi-be-gone",
                    "author": "nccgroup",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 72,
                    "title": "A Byte Buddy Java agent-based fix for CVE-2021-44228, the log4j 2.x \"JNDI LDAP\" vulnerability.",
                    "summary": "A Byte Buddy Java agent-based fix for CVE-2021-44228, the log4j 2.x \"JNDI LDAP\" vulnerability.",
                    "url": "https://github.com/nccgroup/log4j-jndi-be-gone"
                },
                {
                    "repository": "PoC-in-GitHub · qingtengyun/cve-2021-44228-qingteng-online-patch",
                    "author": "qingtengyun",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "Hot-patch CVE-2021-44228 by exploiting the vulnerability itself.",
                    "summary": "Hot-patch CVE-2021-44228 by exploiting the vulnerability itself.",
                    "url": "https://github.com/qingtengyun/cve-2021-44228-qingteng-online-patch"
                },
                {
                    "repository": "PoC-in-GitHub · tasooshi/horrors-log4shell",
                    "author": "tasooshi",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A micro lab for CVE-2021-44228 (log4j)",
                    "summary": "A micro lab for CVE-2021-44228 (log4j)",
                    "url": "https://github.com/tasooshi/horrors-log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · Hydragyrum/evil-rmi-server",
                    "author": "Hydragyrum",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "An evil RMI server that can launch an arbitrary command. May be useful for CVE-2021-44228",
                    "summary": "An evil RMI server that can launch an arbitrary command. May be useful for CVE-2021-44228",
                    "url": "https://github.com/Hydragyrum/evil-rmi-server"
                },
                {
                    "repository": "PoC-in-GitHub · twseptian/spring-boot-log4j-cve-2021-44228-docker-lab",
                    "author": "twseptian",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 27,
                    "title": "Spring Boot Log4j - CVE-2021-44228 Docker Lab",
                    "summary": "Spring Boot Log4j - CVE-2021-44228 Docker Lab",
                    "url": "https://github.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-lab"
                },
                {
                    "repository": "PoC-in-GitHub · OlafHaalstra/log4jcheck",
                    "author": "OlafHaalstra",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Check list of URLs against Log4j vulnerability CVE-2021-44228",
                    "summary": "Check list of URLs against Log4j vulnerability CVE-2021-44228",
                    "url": "https://github.com/OlafHaalstra/log4jcheck"
                },
                {
                    "repository": "PoC-in-GitHub · Panyaprach/Prove-CVE-2021-44228",
                    "author": "Panyaprach",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/Panyaprach/Prove-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · momos1337/Log4j-RCE",
                    "author": "momos1337",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Log4j RCE - (CVE-2021-44228)",
                    "summary": "Log4j RCE - (CVE-2021-44228)",
                    "url": "https://github.com/momos1337/Log4j-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · cyberxml/log4j-poc",
                    "author": "cyberxml",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 72,
                    "title": "A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell",
                    "summary": "A Docker based LDAP RCE exploit demo for CVE-2021-44228 Log4Shell",
                    "url": "https://github.com/cyberxml/log4j-poc"
                },
                {
                    "repository": "PoC-in-GitHub · corneacristian/Log4J-CVE-2021-44228-RCE",
                    "author": "corneacristian",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Log4J (CVE-2021-44228) Exploit with Remote Command Execution (RCE)",
                    "summary": "Log4J (CVE-2021-44228) Exploit with Remote Command Execution (RCE)",
                    "url": "https://github.com/corneacristian/Log4J-CVE-2021-44228-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · Diverto/nse-log4shell",
                    "author": "Diverto",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 353,
                    "title": "Nmap NSE scripts to check against log4shell or LogJam vulnerabilities (CVE-2021-44228)",
                    "summary": "Nmap NSE scripts to check against log4shell or LogJam vulnerabilities (CVE-2021-44228)",
                    "url": "https://github.com/Diverto/nse-log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · dotPY-hax/log4py",
                    "author": "dotPY-hax",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "pythonic pure python RCE exploit for CVE-2021-44228 log4shell",
                    "summary": "pythonic pure python RCE exploit for CVE-2021-44228 log4shell",
                    "url": "https://github.com/dotPY-hax/log4py"
                },
                {
                    "repository": "PoC-in-GitHub · sunnyvale-it/CVE-2021-44228-PoC",
                    "author": "sunnyvale-it",
                    "first_seen": "2021-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "CVE-2021-44228 (Log4Shell) Proof of Concept",
                    "summary": "CVE-2021-44228 (Log4Shell) Proof of Concept",
                    "url": "https://github.com/sunnyvale-it/CVE-2021-44228-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · maxant/log4j2-CVE-2021-44228",
                    "author": "maxant",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/maxant/log4j2-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · atnetws/fail2ban-log4j",
                    "author": "atnetws",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "fail2ban filter that catches attacks againts log4j CVE-2021-44228",
                    "summary": "fail2ban filter that catches attacks againts log4j CVE-2021-44228",
                    "url": "https://github.com/atnetws/fail2ban-log4j"
                },
                {
                    "repository": "PoC-in-GitHub · kimobu/cve-2021-44228",
                    "author": "kimobu",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Some files for red team/blue team investigations into CVE-2021-44228",
                    "summary": "Some files for red team/blue team investigations into CVE-2021-44228",
                    "url": "https://github.com/kimobu/cve-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · ph0lk3r/anti-jndi",
                    "author": "ph0lk3r",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Fun things against the abuse of the recent CVE-2021-44228 (Log4Shell) vulnerability using common web servers.",
                    "summary": "Fun things against the abuse of the recent CVE-2021-44228 (Log4Shell) vulnerability using common web servers.",
                    "url": "https://github.com/ph0lk3r/anti-jndi"
                },
                {
                    "repository": "PoC-in-GitHub · bigsizeme/Log4j-check",
                    "author": "bigsizeme",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 71,
                    "title": "log4J burp被扫插件、CVE-2021-44228、支持dnclog.cn和burp内置DNS、可配合JNDIExploit生成payload",
                    "summary": "log4J burp被扫插件、CVE-2021-44228、支持dnclog.cn和burp内置DNS、可配合JNDIExploit生成payload",
                    "url": "https://github.com/bigsizeme/Log4j-check"
                },
                {
                    "repository": "PoC-in-GitHub · pedrohavay/exploit-CVE-2021-44228",
                    "author": "pedrohavay",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 20,
                    "title": "This is a proof-of-concept exploit for Log4j RCE Unauthenticated (CVE-2021-44228).",
                    "summary": "This is a proof-of-concept exploit for Log4j RCE Unauthenticated (CVE-2021-44228).",
                    "url": "https://github.com/pedrohavay/exploit-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · fireeye/CVE-2021-44228",
                    "author": "fireeye",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 37,
                    "title": "OpenIOC rules to facilitate hunting for indicators of compromise",
                    "summary": "OpenIOC rules to facilitate hunting for indicators of compromise",
                    "url": "https://github.com/fireeye/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · fullhunt/log4j-scan",
                    "author": "fullhunt",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3421,
                    "title": "A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228",
                    "summary": "A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228",
                    "url": "https://github.com/fullhunt/log4j-scan"
                },
                {
                    "repository": "PoC-in-GitHub · rubo77/log4j_checker_beta",
                    "author": "rubo77",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 247,
                    "title": "a fast check, if your server could be vulnerable to CVE-2021-44228",
                    "summary": "a fast check, if your server could be vulnerable to CVE-2021-44228",
                    "url": "https://github.com/rubo77/log4j_checker_beta"
                },
                {
                    "repository": "PoC-in-GitHub · thecyberneh/Log4j-RCE-Exploiter",
                    "author": "thecyberneh",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "Scanner for Log4j RCE CVE-2021-44228",
                    "summary": "Scanner for Log4j RCE CVE-2021-44228",
                    "url": "https://github.com/thecyberneh/Log4j-RCE-Exploiter"
                },
                {
                    "repository": "PoC-in-GitHub · halibobor/log4j2",
                    "author": "halibobor",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228",
                    "summary": "CVE-2021-44228",
                    "url": "https://github.com/halibobor/log4j2"
                },
                {
                    "repository": "PoC-in-GitHub · sourcegraph/log4j-cve-code-search-resources",
                    "author": "sourcegraph",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Using code search to help fix/mitigate log4j CVE-2021-44228",
                    "summary": "Using code search to help fix/mitigate log4j CVE-2021-44228",
                    "url": "https://github.com/sourcegraph/log4j-cve-code-search-resources"
                },
                {
                    "repository": "PoC-in-GitHub · thedevappsecguy/Log4J-Mitigation-CVE-2021-44228--CVE-2021-45046--CVE-2021-45105--CVE-2021-44832",
                    "author": "thedevappsecguy",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Log4J CVE-2021-44228 : Mitigation Cheat Sheet",
                    "summary": "Log4J CVE-2021-44228 : Mitigation Cheat Sheet",
                    "url": "https://github.com/thedevappsecguy/Log4J-Mitigation-CVE-2021-44228--CVE-2021-45046--CVE-2021-45105--CVE-2021-44832"
                },
                {
                    "repository": "PoC-in-GitHub · helsecert/CVE-2021-44228",
                    "author": "helsecert",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/helsecert/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · markuman/aws-log4j-mitigations",
                    "author": "markuman",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 log4j mitigation using aws wafv2 with ansible",
                    "summary": "CVE-2021-44228 log4j mitigation using aws wafv2 with ansible",
                    "url": "https://github.com/markuman/aws-log4j-mitigations"
                },
                {
                    "repository": "PoC-in-GitHub · tuyenee/Log4shell",
                    "author": "tuyenee",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A lab for playing around with the Log4J CVE-2021-44228",
                    "summary": "A lab for playing around with the Log4J CVE-2021-44228",
                    "url": "https://github.com/tuyenee/Log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · JiuBanSec/Log4j-CVE-2021-44228",
                    "author": "JiuBanSec",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Log4j Remote Code Injection (Apache Log4j 2.x < 2.15.0-rc2)",
                    "summary": "Log4j Remote Code Injection (Apache Log4j 2.x < 2.15.0-rc2)",
                    "url": "https://github.com/JiuBanSec/Log4j-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · ycdxsb/Log4Shell-CVE-2021-44228-ENV",
                    "author": "ycdxsb",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Log4Shell Docker Env",
                    "summary": "Log4Shell Docker Env",
                    "url": "https://github.com/ycdxsb/Log4Shell-CVE-2021-44228-ENV"
                },
                {
                    "repository": "PoC-in-GitHub · avwolferen/Sitecore.Solr-log4j-mitigation",
                    "author": "avwolferen",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "This repository contains a script that you can run on your (windows) machine to mitigate CVE-2021-44228",
                    "summary": "This repository contains a script that you can run on your (windows) machine to mitigate CVE-2021-44228",
                    "url": "https://github.com/avwolferen/Sitecore.Solr-log4j-mitigation"
                },
                {
                    "repository": "PoC-in-GitHub · george-petrakis/log4j-scanner-CVE-2021-44228",
                    "author": "george-petrakis",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Simple tool for scanning entire directories for attempts of CVE-2021-44228",
                    "summary": "Simple tool for scanning entire directories for attempts of CVE-2021-44228",
                    "url": "https://github.com/george-petrakis/log4j-scanner-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · Camphul/log4shell-spring-framework-research",
                    "author": "Camphul",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Research into the implications of CVE-2021-44228 in Spring based applications.",
                    "summary": "Research into the implications of CVE-2021-44228 in Spring based applications.",
                    "url": "https://github.com/Camphul/log4shell-spring-framework-research"
                },
                {
                    "repository": "PoC-in-GitHub · lov3r/cve-2021-44228-log4j-exploits",
                    "author": "lov3r",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4428 复现",
                    "summary": "CVE-2021-4428 复现",
                    "url": "https://github.com/lov3r/cve-2021-44228-log4j-exploits"
                },
                {
                    "repository": "PoC-in-GitHub · sinakeshmiri/log4jScan",
                    "author": "sinakeshmiri",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "simple python scanner to check if your network is vulnerable to CVE-2021-44228",
                    "summary": "simple python scanner to check if your network is vulnerable to CVE-2021-44228",
                    "url": "https://github.com/sinakeshmiri/log4jScan"
                },
                {
                    "repository": "PoC-in-GitHub · 0xDexter0us/Log4J-Scanner",
                    "author": "0xDexter0us",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 101,
                    "title": "Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.",
                    "summary": "Burp extension to scan Log4Shell (CVE-2021-44228) vulnerability pre and post auth.",
                    "url": "https://github.com/0xDexter0us/Log4J-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · LutziGoz/Log4J_Exploitation-Vulnerabiliy__CVE-2021-44228",
                    "author": "LutziGoz",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/LutziGoz/Log4J_Exploitation-Vulnerabiliy__CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · 0xsyr0/Log4Shell",
                    "author": "0xsyr0",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "This repository contains all gathered resources we used during our Incident Reponse on CVE-2021-44228 and CVE-2021-45046 aka Log4Shell.",
                    "summary": "This repository contains all gathered resources we used during our Incident Reponse on CVE-2021-44228 and CVE-2021-45046 aka Log4Shell.",
                    "url": "https://github.com/0xsyr0/Log4Shell"
                },
                {
                    "repository": "PoC-in-GitHub · 1hakusai1/log4j-rce-CVE-2021-44228",
                    "author": "1hakusai1",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "log4j2 CVE-2021-44228 POC",
                    "summary": "log4j2 CVE-2021-44228 POC",
                    "url": "https://github.com/1hakusai1/log4j-rce-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · jeffli1024/log4j-rce-test",
                    "author": "jeffli1024",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2021-44228 - Apache log4j RCE quick test",
                    "summary": "CVE-2021-44228 - Apache log4j RCE quick test",
                    "url": "https://github.com/jeffli1024/log4j-rce-test"
                },
                {
                    "repository": "PoC-in-GitHub · zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service",
                    "author": "zsolt-halo",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service"
                },
                {
                    "repository": "PoC-in-GitHub · manuel-alvarez-alvarez/log4j-cve-2021-44228",
                    "author": "manuel-alvarez-alvarez",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ...",
                    "summary": "Log4j CVE-2021-44228 examples: Remote Code Execution (through LDAP, RMI, ...), Forced DNS queries, ...",
                    "url": "https://github.com/manuel-alvarez-alvarez/log4j-cve-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · VNYui/CVE-2021-44228",
                    "author": "VNYui",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Mass recognition tool for CVE-2021-44228",
                    "summary": "Mass recognition tool for CVE-2021-44228",
                    "url": "https://github.com/VNYui/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · justakazh/Log4j-CVE-2021-44228",
                    "author": "justakazh",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Mass Check Vulnerable Log4j CVE-2021-44228",
                    "summary": "Mass Check Vulnerable Log4j CVE-2021-44228",
                    "url": "https://github.com/justakazh/Log4j-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · irgoncalves/f5-waf-quick-patch-cve-2021-44228",
                    "author": "irgoncalves",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode",
                    "summary": "This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode",
                    "url": "https://github.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · madCdan/JndiLookup",
                    "author": "madCdan",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Some tools to help mitigating Apache Log4j 2 CVE-2021-44228",
                    "summary": "Some tools to help mitigating Apache Log4j 2 CVE-2021-44228",
                    "url": "https://github.com/madCdan/JndiLookup"
                },
                {
                    "repository": "PoC-in-GitHub · Koupah/MC-Log4j-Patcher",
                    "author": "Koupah",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "A singular file to protect as many Minecraft servers and clients as possible from the Log4j exploit (CVE-2021-44228).",
                    "summary": "A singular file to protect as many Minecraft servers and clients as possible from the Log4j exploit (CVE-2021-44228).",
                    "url": "https://github.com/Koupah/MC-Log4j-Patcher"
                },
                {
                    "repository": "PoC-in-GitHub · AlexandreHeroux/Fix-CVE-2021-44228",
                    "author": "AlexandreHeroux",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Apply class remove process from ear/war/jar/zip archive, see https://logging.apache.org/log4j/2.x/",
                    "summary": "Apply class remove process from ear/war/jar/zip archive, see https://logging.apache.org/log4j/2.x/",
                    "url": "https://github.com/AlexandreHeroux/Fix-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · kossatzd/log4j-CVE-2021-44228-test",
                    "author": "kossatzd",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "demo project to highlight how to execute the log4j (CVE-2021-44228) vulnerability",
                    "summary": "demo project to highlight how to execute the log4j (CVE-2021-44228) vulnerability",
                    "url": "https://github.com/kossatzd/log4j-CVE-2021-44228-test"
                },
                {
                    "repository": "PoC-in-GitHub · tobiasoed/log4j-CVE-2021-44228",
                    "author": "tobiasoed",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/tobiasoed/log4j-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · hackinghippo/log4shell_ioc_ips",
                    "author": "hackinghippo",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 37,
                    "title": "log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon  (CVE-2021-44228)",
                    "summary": "log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon  (CVE-2021-44228)",
                    "url": "https://github.com/hackinghippo/log4shell_ioc_ips"
                },
                {
                    "repository": "PoC-in-GitHub · p3dr16k/log4j-1.2.15-mod",
                    "author": "p3dr16k",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "log4j version 1 with a patch for CVE-2021-44228 vulnerability",
                    "summary": "log4j version 1 with a patch for CVE-2021-44228 vulnerability",
                    "url": "https://github.com/p3dr16k/log4j-1.2.15-mod"
                },
                {
                    "repository": "PoC-in-GitHub · claranet/ansible-role-log4shell",
                    "author": "claranet",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "Find Log4Shell CVE-2021-44228 on your system",
                    "summary": "Find Log4Shell CVE-2021-44228 on your system",
                    "url": "https://github.com/claranet/ansible-role-log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · taurusxin/CVE-2021-44228",
                    "author": "taurusxin",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/taurusxin/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · corelight/cve-2021-44228",
                    "author": "corelight",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": "Log4j Exploit Detection Logic for Zeek",
                    "summary": "Log4j Exploit Detection Logic for Zeek",
                    "url": "https://github.com/corelight/cve-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · rodfer0x80/log4j2-prosecutor",
                    "author": "rodfer0x80",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228",
                    "summary": "CVE-2021-44228",
                    "url": "https://github.com/rodfer0x80/log4j2-prosecutor"
                },
                {
                    "repository": "PoC-in-GitHub · yanghaoi/CVE-2021-44228_Log4Shell",
                    "author": "yanghaoi",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell A test for CVE-2021-44228",
                    "summary": "Log4Shell A test for CVE-2021-44228",
                    "url": "https://github.com/yanghaoi/CVE-2021-44228_Log4Shell"
                },
                {
                    "repository": "PoC-in-GitHub · lfama/log4j_checker",
                    "author": "lfama",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "Python3 script for scanning CVE-2021-44228 (Log4shell) vulnerable machines.",
                    "summary": "Python3 script for scanning CVE-2021-44228 (Log4shell) vulnerable machines.",
                    "url": "https://github.com/lfama/log4j_checker"
                },
                {
                    "repository": "PoC-in-GitHub · threatmonit/Log4j-IOCs",
                    "author": "threatmonit",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Public IOCs about log4j CVE-2021-44228",
                    "summary": "Public IOCs about log4j CVE-2021-44228",
                    "url": "https://github.com/threatmonit/Log4j-IOCs"
                },
                {
                    "repository": "PoC-in-GitHub · ben-smash/l4j-info",
                    "author": "ben-smash",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Compiling links of value i find regarding CVE-2021-44228",
                    "summary": "Compiling links of value i find regarding CVE-2021-44228",
                    "url": "https://github.com/ben-smash/l4j-info"
                },
                {
                    "repository": "PoC-in-GitHub · strawhatasif/log4j-test",
                    "author": "strawhatasif",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Demonstration of CVE-2021-44228 with a possible strategic fix.",
                    "summary": "Demonstration of CVE-2021-44228 with a possible strategic fix.",
                    "url": "https://github.com/strawhatasif/log4j-test"
                },
                {
                    "repository": "PoC-in-GitHub · giterlizzi/nmap-log4shell",
                    "author": "giterlizzi",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 79,
                    "title": "Nmap Log4Shell NSE script for discovery Apache Log4j RCE (CVE-2021-44228)",
                    "summary": "Nmap Log4Shell NSE script for discovery Apache Log4j RCE (CVE-2021-44228)",
                    "url": "https://github.com/giterlizzi/nmap-log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · tica506/Siem-queries-for-CVE-2021-44228",
                    "author": "tica506",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/tica506/Siem-queries-for-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · chilit-nl/log4shell-example",
                    "author": "chilit-nl",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "The goal of this project is to demonstrate the log4j cve-2021-44228 exploit vulnerability in a spring-boot setup, and to show how to fix it.",
                    "summary": "The goal of this project is to demonstrate the log4j cve-2021-44228 exploit vulnerability in a spring-boot setup, and to show how to fix it.",
                    "url": "https://github.com/chilit-nl/log4shell-example"
                },
                {
                    "repository": "PoC-in-GitHub · Occamsec/log4j-checker",
                    "author": "Occamsec",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Bash and PowerShell scripts to scan a local filesystem for Log4j .jar files which could be vulnerable to CVE-2021-44228 aka Log4Shell.",
                    "summary": "Bash and PowerShell scripts to scan a local filesystem for Log4j .jar files which could be vulnerable to CVE-2021-44228 aka Log4Shell.",
                    "url": "https://github.com/Occamsec/log4j-checker"
                },
                {
                    "repository": "PoC-in-GitHub · snatalius/log4j2-CVE-2021-44228-poc-local",
                    "author": "snatalius",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Just a personal proof of concept of CVE-2021-44228 on log4j2",
                    "summary": "Just a personal proof of concept of CVE-2021-44228 on log4j2",
                    "url": "https://github.com/snatalius/log4j2-CVE-2021-44228-poc-local"
                },
                {
                    "repository": "PoC-in-GitHub · Contrast-Security-OSS/CVE-2021-44228",
                    "author": "Contrast-Security-OSS",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Professional Service scripts to aid in the identification of affected Java applications in TeamServer",
                    "summary": "Professional Service scripts to aid in the identification of affected Java applications in TeamServer",
                    "url": "https://github.com/Contrast-Security-OSS/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · back2root/log4shell-rex",
                    "author": "back2root",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 291,
                    "title": "PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs",
                    "summary": "PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs",
                    "url": "https://github.com/back2root/log4shell-rex"
                },
                {
                    "repository": "PoC-in-GitHub · alexbakker/log4shell-tools",
                    "author": "alexbakker",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 86,
                    "title": "Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046",
                    "summary": "Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046",
                    "url": "https://github.com/alexbakker/log4shell-tools"
                },
                {
                    "repository": "PoC-in-GitHub · perryflynn/find-log4j",
                    "author": "perryflynn",
                    "first_seen": "2021-12-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Find log4j for CVE-2021-44228 on some places * Log4Shell",
                    "summary": "Find log4j for CVE-2021-44228 on some places * Log4Shell",
                    "url": "https://github.com/perryflynn/find-log4j"
                },
                {
                    "repository": "PoC-in-GitHub · alpacamybags118/log4j-cve-2021-44228-sample",
                    "author": "alpacamybags118",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Sample docker-compose setup to show how this exploit works",
                    "summary": "Sample docker-compose setup to show how this exploit works",
                    "url": "https://github.com/alpacamybags118/log4j-cve-2021-44228-sample"
                },
                {
                    "repository": "PoC-in-GitHub · sandarenu/log4j2-issue-check",
                    "author": "sandarenu",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Demo project to evaluate Log4j2 Vulnerability | CVE-2021-44228",
                    "summary": "Demo project to evaluate Log4j2 Vulnerability | CVE-2021-44228",
                    "url": "https://github.com/sandarenu/log4j2-issue-check"
                },
                {
                    "repository": "PoC-in-GitHub · roticagas/CVE-2021-44228-Demo",
                    "author": "roticagas",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/roticagas/CVE-2021-44228-Demo"
                },
                {
                    "repository": "PoC-in-GitHub · Woahd/log4j-urlscanner",
                    "author": "Woahd",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Simple Python 3 script to detect the \"Log4j\" Java library vulnerability (CVE-2021-44228) for a list of URL with multithreading",
                    "summary": "Simple Python 3 script to detect the \"Log4j\" Java library vulnerability (CVE-2021-44228) for a list of URL with multithreading",
                    "url": "https://github.com/Woahd/log4j-urlscanner"
                },
                {
                    "repository": "PoC-in-GitHub · faisalfs10x/Log4j2-CVE-2021-44228-revshell",
                    "author": "faisalfs10x",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 18,
                    "title": "Log4j2 CVE-2021-44228 revshell, ofc it suck!!",
                    "summary": "Log4j2 CVE-2021-44228 revshell, ofc it suck!!",
                    "url": "https://github.com/faisalfs10x/Log4j2-CVE-2021-44228-revshell"
                },
                {
                    "repository": "PoC-in-GitHub · gcmurphy/chk_log4j",
                    "author": "gcmurphy",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Some siimple checks to see if JAR file is vulnerable to CVE-2021-44228",
                    "summary": "Some siimple checks to see if JAR file is vulnerable to CVE-2021-44228",
                    "url": "https://github.com/gcmurphy/chk_log4j"
                },
                {
                    "repository": "PoC-in-GitHub · 0xInfection/LogMePwn",
                    "author": "0xInfection",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 395,
                    "title": "A fully automated, reliable, super-fast, scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.",
                    "summary": "A fully automated, reliable, super-fast, scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.",
                    "url": "https://github.com/0xInfection/LogMePwn"
                },
                {
                    "repository": "PoC-in-GitHub · toramanemre/apache-solr-log4j-CVE-2021-44228",
                    "author": "toramanemre",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "A Nuclei template for Apache Solr affected by Apache Log4J CVE-2021-44228",
                    "summary": "A Nuclei template for Apache Solr affected by Apache Log4J CVE-2021-44228",
                    "url": "https://github.com/toramanemre/apache-solr-log4j-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · codiobert/log4j-scanner",
                    "author": "codiobert",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Check CVE-2021-44228 vulnerability",
                    "summary": "Check CVE-2021-44228 vulnerability",
                    "url": "https://github.com/codiobert/log4j-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · cbuschka/log4j2-rce-recap",
                    "author": "cbuschka",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Little recap of the log4j2 remote code execution (CVE-2021-44228)",
                    "summary": "Little recap of the log4j2 remote code execution (CVE-2021-44228)",
                    "url": "https://github.com/cbuschka/log4j2-rce-recap"
                },
                {
                    "repository": "PoC-in-GitHub · andrii-kovalenko-celonis/log4j-vulnerability-demo",
                    "author": "andrii-kovalenko-celonis",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Endpoint to test CVE-2021-44228 – Log4j 2",
                    "summary": "Endpoint to test CVE-2021-44228 – Log4j 2",
                    "url": "https://github.com/andrii-kovalenko-celonis/log4j-vulnerability-demo"
                },
                {
                    "repository": "PoC-in-GitHub · dark-ninja10/Log4j-CVE-2021-44228",
                    "author": "dark-ninja10",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code Execution (RCE) by logging a certain string.  Given how ubiquitous this library is, the impact of the exploit (full server control), and how easy it is to exploit, the impact of this vulnerability is quite severe. We're calling it \"Log4Shell\" for short.",
                    "summary": "On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code Execution (RCE) by logging a certain string.  Given how ubiquitous this library is, the impact of the exploit (full server control), and how easy it is to exploit, the impact of this vulnerability is quite severe. We're calling it \"Log4Shell\" for short.",
                    "url": "https://github.com/dark-ninja10/Log4j-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · fox-it/log4j-finder",
                    "author": "fox-it",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 439,
                    "title": "Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)",
                    "summary": "Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)",
                    "url": "https://github.com/fox-it/log4j-finder"
                },
                {
                    "repository": "PoC-in-GitHub · 34zY/JNDI-Exploit-1.2-log4shell",
                    "author": "34zY",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Details : CVE-2021-44228",
                    "summary": "Details : CVE-2021-44228",
                    "url": "https://github.com/34zY/JNDI-Exploit-1.2-log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · didoatanasov/cve-2021-44228",
                    "author": "didoatanasov",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/didoatanasov/cve-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · ShaneKingBlog/org.shaneking.demo.cve.y2021.s44228",
                    "author": "ShaneKingBlog",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228",
                    "summary": "CVE-2021-44228",
                    "url": "https://github.com/ShaneKingBlog/org.shaneking.demo.cve.y2021.s44228"
                },
                {
                    "repository": "PoC-in-GitHub · wortell/log4j",
                    "author": "wortell",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "Repo containing all info, scripts, etc. related to CVE-2021-44228",
                    "summary": "Repo containing all info, scripts, etc. related to CVE-2021-44228",
                    "url": "https://github.com/wortell/log4j"
                },
                {
                    "repository": "PoC-in-GitHub · municipalparkingservices/CVE-2021-44228-Scanner",
                    "author": "municipalparkingservices",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/municipalparkingservices/CVE-2021-44228-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · BinaryDefense/log4j-honeypot-flask",
                    "author": "BinaryDefense",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 149,
                    "title": "Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228",
                    "summary": "Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228",
                    "url": "https://github.com/BinaryDefense/log4j-honeypot-flask"
                },
                {
                    "repository": "PoC-in-GitHub · MalwareTech/Log4jTools",
                    "author": "MalwareTech",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 94,
                    "title": "Tools for investigating Log4j CVE-2021-44228",
                    "summary": "Tools for investigating Log4j CVE-2021-44228",
                    "url": "https://github.com/MalwareTech/Log4jTools"
                },
                {
                    "repository": "PoC-in-GitHub · mufeedvh/log4jail",
                    "author": "mufeedvh",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 21,
                    "title": "A firewall reverse proxy for preventing Log4J (Log4Shell aka CVE-2021-44228) attacks.",
                    "summary": "A firewall reverse proxy for preventing Log4J (Log4Shell aka CVE-2021-44228) attacks.",
                    "url": "https://github.com/mufeedvh/log4jail"
                },
                {
                    "repository": "PoC-in-GitHub · guerzon/log4shellpoc",
                    "author": "guerzon",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Simple Spring Boot application vulnerable to CVE-2021-44228 (a.k.a log4shell)",
                    "summary": "Simple Spring Boot application vulnerable to CVE-2021-44228 (a.k.a log4shell)",
                    "url": "https://github.com/guerzon/log4shellpoc"
                },
                {
                    "repository": "PoC-in-GitHub · ab0x90/CVE-2021-44228_PoC",
                    "author": "ab0x90",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 16,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/ab0x90/CVE-2021-44228_PoC"
                },
                {
                    "repository": "PoC-in-GitHub · stripe/log4j-remediation-tools",
                    "author": "stripe",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 40,
                    "title": "Tools for remediating the recent log4j2 RCE vulnerability (CVE-2021-44228)",
                    "summary": "Tools for remediating the recent log4j2 RCE vulnerability (CVE-2021-44228)",
                    "url": "https://github.com/stripe/log4j-remediation-tools"
                },
                {
                    "repository": "PoC-in-GitHub · xsultan/log4jshield",
                    "author": "xsultan",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "Log4j Shield - fast ⚡, scalable and easy to use Log4j vulnerability CVE-2021-44228 finder and patcher",
                    "summary": "Log4j Shield - fast ⚡, scalable and easy to use Log4j vulnerability CVE-2021-44228 finder and patcher",
                    "url": "https://github.com/xsultan/log4jshield"
                },
                {
                    "repository": "PoC-in-GitHub · HynekPetrak/log4shell-finder",
                    "author": "HynekPetrak",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 39,
                    "title": "Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) instances of log4j library. Excellent performance and low memory footprint.",
                    "summary": "Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) instances of log4j library. Excellent performance and low memory footprint.",
                    "url": "https://github.com/HynekPetrak/log4shell-finder"
                },
                {
                    "repository": "PoC-in-GitHub · 0xThiebaut/CVE-2021-44228",
                    "author": "0xThiebaut",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 Response Scripts",
                    "summary": "CVE-2021-44228 Response Scripts",
                    "url": "https://github.com/0xThiebaut/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · CERTCC/CVE-2021-44228_scanner",
                    "author": "CERTCC",
                    "first_seen": "2021-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 350,
                    "title": "Scanners for Jar files that may be vulnerable to CVE-2021-44228",
                    "summary": "Scanners for Jar files that may be vulnerable to CVE-2021-44228",
                    "url": "https://github.com/CERTCC/CVE-2021-44228_scanner"
                },
                {
                    "repository": "PoC-in-GitHub · CrackerCat/CVE-2021-44228-Log4j-Payloads",
                    "author": "CrackerCat",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/CrackerCat/CVE-2021-44228-Log4j-Payloads"
                },
                {
                    "repository": "PoC-in-GitHub · dbzoo/log4j_scanner",
                    "author": "dbzoo",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Fast filesystem scanner for CVE-2021-44228",
                    "summary": "Fast filesystem scanner for CVE-2021-44228",
                    "url": "https://github.com/dbzoo/log4j_scanner"
                },
                {
                    "repository": "PoC-in-GitHub · jeremyrsellars/CVE-2021-44228_scanner",
                    "author": "jeremyrsellars",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Aims to find JndiLookup.class in nearly any directory or zip, jar, ear, war file, even deeply nested.",
                    "summary": "Aims to find JndiLookup.class in nearly any directory or zip, jar, ear, war file, even deeply nested.",
                    "url": "https://github.com/jeremyrsellars/CVE-2021-44228_scanner"
                },
                {
                    "repository": "PoC-in-GitHub · VinniMarcon/Log4j-Updater",
                    "author": "VinniMarcon",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228",
                    "summary": "Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228",
                    "url": "https://github.com/VinniMarcon/Log4j-Updater"
                },
                {
                    "repository": "PoC-in-GitHub · bhprin/log4j-vul",
                    "author": "bhprin",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This project is just to show Apache Log4j2 Vulnerability - aka CVE-2021-44228",
                    "summary": "This project is just to show Apache Log4j2 Vulnerability - aka CVE-2021-44228",
                    "url": "https://github.com/bhprin/log4j-vul"
                },
                {
                    "repository": "PoC-in-GitHub · rgl/log4j-log4shell-playground",
                    "author": "rgl",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A playground for poking at the Log4Shell (CVE-2021-44228) vulnerability mitigations",
                    "summary": "A playground for poking at the Log4Shell (CVE-2021-44228) vulnerability mitigations",
                    "url": "https://github.com/rgl/log4j-log4shell-playground"
                },
                {
                    "repository": "PoC-in-GitHub · anuvindhs/how-to-check-patch-secure-log4j-CVE-2021-44228",
                    "author": "anuvindhs",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A one-stop repo/  information hub for all log4j vulnerability-related information.",
                    "summary": "A one-stop repo/  information hub for all log4j vulnerability-related information.",
                    "url": "https://github.com/anuvindhs/how-to-check-patch-secure-log4j-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · KeysAU/Get-log4j-Windows.ps1",
                    "author": "KeysAU",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Identifying all log4j components across all windows servers, entire domain, can be multi domain. CVE-2021-44228",
                    "summary": "Identifying all log4j components across all windows servers, entire domain, can be multi domain. CVE-2021-44228",
                    "url": "https://github.com/KeysAU/Get-log4j-Windows.ps1"
                },
                {
                    "repository": "PoC-in-GitHub · kubearmor/log4j-CVE-2021-44228",
                    "author": "kubearmor",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228",
                    "summary": "Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228",
                    "url": "https://github.com/kubearmor/log4j-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · redhuntlabs/Log4JHunt",
                    "author": "redhuntlabs",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 47,
                    "title": "An automated, reliable scanner for the Log4Shell (CVE-2021-44228) vulnerability.",
                    "summary": "An automated, reliable scanner for the Log4Shell (CVE-2021-44228) vulnerability.",
                    "url": "https://github.com/redhuntlabs/Log4JHunt"
                },
                {
                    "repository": "PoC-in-GitHub · mss/log4shell-hotfix-side-effect",
                    "author": "mss",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Test case to check if the Log4Shell/CVE-2021-44228 hotfix will raise any unexpected exceptions",
                    "summary": "Test case to check if the Log4Shell/CVE-2021-44228 hotfix will raise any unexpected exceptions",
                    "url": "https://github.com/mss/log4shell-hotfix-side-effect"
                },
                {
                    "repository": "PoC-in-GitHub · MeterianHQ/log4j-vuln-coverage-check",
                    "author": "MeterianHQ",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)",
                    "summary": "A simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)",
                    "url": "https://github.com/MeterianHQ/log4j-vuln-coverage-check"
                },
                {
                    "repository": "PoC-in-GitHub · mitiga/log4shell-cloud-scanner",
                    "author": "mitiga",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "we are providing DevOps and security teams script to identify cloud workloads that may be vulnerable to the Log4j vulnerability(CVE-2021-44228) in their AWS account. The script enables security teams to identify external-facing AWS assets by running the exploit on them, and thus be able to map them and quickly patch them",
                    "summary": "we are providing DevOps and security teams script to identify cloud workloads that may be vulnerable to the Log4j vulnerability(CVE-2021-44228) in their AWS account. The script enables security teams to identify external-facing AWS assets by running the exploit on them, and thus be able to map them and quickly patch them",
                    "url": "https://github.com/mitiga/log4shell-cloud-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · isuruwa/Log4j",
                    "author": "isuruwa",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "A scanner and a proof of sample exploit for  log4j RCE CVE-2021-44228",
                    "summary": "A scanner and a proof of sample exploit for  log4j RCE CVE-2021-44228",
                    "url": "https://github.com/isuruwa/Log4j"
                },
                {
                    "repository": "PoC-in-GitHub · honeynet/log4shell-data",
                    "author": "honeynet",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Data we are receiving from our honeypots about CVE-2021-44228",
                    "summary": "Data we are receiving from our honeypots about CVE-2021-44228",
                    "url": "https://github.com/honeynet/log4shell-data"
                },
                {
                    "repository": "PoC-in-GitHub · inettgmbh/checkmk-log4j-scanner",
                    "author": "inettgmbh",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Scans for Log4j versions effected by CVE-2021-44228",
                    "summary": "Scans for Log4j versions effected by CVE-2021-44228",
                    "url": "https://github.com/inettgmbh/checkmk-log4j-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · b1tm0n3r/CVE-2021-44228",
                    "author": "b1tm0n3r",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 demo webapp",
                    "summary": "CVE-2021-44228 demo webapp",
                    "url": "https://github.com/b1tm0n3r/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · VerveIndustrialProtection/CVE-2021-44228-Log4j",
                    "author": "VerveIndustrialProtection",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/VerveIndustrialProtection/CVE-2021-44228-Log4j"
                },
                {
                    "repository": "PoC-in-GitHub · alenazi90/log4j",
                    "author": "alenazi90",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "An automated header extensive scanner for detecting log4j RCE CVE-2021-44228",
                    "summary": "An automated header extensive scanner for detecting log4j RCE CVE-2021-44228",
                    "url": "https://github.com/alenazi90/log4j"
                },
                {
                    "repository": "PoC-in-GitHub · pmontesd/log4j-cve-2021-44228",
                    "author": "pmontesd",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Very simple Ansible playbook that scan filesystem for JAR files vulnerable to Log4Shell",
                    "summary": "Very simple Ansible playbook that scan filesystem for JAR files vulnerable to Log4Shell",
                    "url": "https://github.com/pmontesd/log4j-cve-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · LiveOverflow/log4shell",
                    "author": "LiveOverflow",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 72,
                    "title": "Small example repo for looking into log4j CVE-2021-44228",
                    "summary": "Small example repo for looking into log4j CVE-2021-44228",
                    "url": "https://github.com/LiveOverflow/log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · aws-samples/kubernetes-log4j-cve-2021-44228-node-agent",
                    "author": "aws-samples",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agent"
                },
                {
                    "repository": "PoC-in-GitHub · michaelsanford/Log4Shell-Honeypot",
                    "author": "michaelsanford",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Dockerized honeypot for CVE-2021-44228.",
                    "summary": "Dockerized honeypot for CVE-2021-44228.",
                    "url": "https://github.com/michaelsanford/Log4Shell-Honeypot"
                },
                {
                    "repository": "PoC-in-GitHub · thomaspatzke/Log4Pot",
                    "author": "thomaspatzke",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 94,
                    "title": "A honeypot for the Log4Shell vulnerability (CVE-2021-44228).",
                    "summary": "A honeypot for the Log4Shell vulnerability (CVE-2021-44228).",
                    "url": "https://github.com/thomaspatzke/Log4Pot"
                },
                {
                    "repository": "PoC-in-GitHub · ubitech/cve-2021-44228-rce-poc",
                    "author": "ubitech",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A Remote Code Execution PoC for Log4Shell (CVE-2021-44228)",
                    "summary": "A Remote Code Execution PoC for Log4Shell (CVE-2021-44228)",
                    "url": "https://github.com/ubitech/cve-2021-44228-rce-poc"
                },
                {
                    "repository": "PoC-in-GitHub · rv4l3r3/log4v-vuln-check",
                    "author": "rv4l3r3",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This script is used to perform a fast check if your server is possibly affected by CVE-2021-44228 (the log4j vulnerability).",
                    "summary": "This script is used to perform a fast check if your server is possibly affected by CVE-2021-44228 (the log4j vulnerability).",
                    "url": "https://github.com/rv4l3r3/log4v-vuln-check"
                },
                {
                    "repository": "PoC-in-GitHub · dpomnean/log4j_scanner_wrapper",
                    "author": "dpomnean",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "log4j vulnerability wrapper scanner for CVE-2021-44228",
                    "summary": "log4j vulnerability wrapper scanner for CVE-2021-44228",
                    "url": "https://github.com/dpomnean/log4j_scanner_wrapper"
                },
                {
                    "repository": "PoC-in-GitHub · roxas-tan/CVE-2021-44228",
                    "author": "roxas-tan",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "This Log4j RCE exploit originated from https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce",
                    "summary": "This Log4j RCE exploit originated from https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce",
                    "url": "https://github.com/roxas-tan/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · shamo0/CVE-2021-44228",
                    "author": "shamo0",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "log4shell (CVE-2021-44228) scanning tool",
                    "summary": "log4shell (CVE-2021-44228) scanning tool",
                    "url": "https://github.com/shamo0/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · snow0715/log4j-Scan-Burpsuite",
                    "author": "snow0715",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "Log4j漏洞（CVE-2021-44228）的Burpsuite检测插件",
                    "summary": "Log4j漏洞（CVE-2021-44228）的Burpsuite检测插件",
                    "url": "https://github.com/snow0715/log4j-Scan-Burpsuite"
                },
                {
                    "repository": "PoC-in-GitHub · Joefreedy/Log4j-Windows-Scanner",
                    "author": "Joefreedy",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2021-44228 vulnerability in Apache Log4j library | Log4j vulnerability scanner on Windows machines.",
                    "summary": "CVE-2021-44228 vulnerability in Apache Log4j library | Log4j vulnerability scanner on Windows machines.",
                    "url": "https://github.com/Joefreedy/Log4j-Windows-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · Nanitor/log4fix",
                    "author": "Nanitor",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "Detect and fix log4j log4shell vulnerability (CVE-2021-44228)",
                    "summary": "Detect and fix log4j log4shell vulnerability (CVE-2021-44228)",
                    "url": "https://github.com/Nanitor/log4fix"
                },
                {
                    "repository": "PoC-in-GitHub · korteke/log4shell-demo",
                    "author": "korteke",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Simple webapp that is vulnerable to Log4Shell (CVE-2021-44228)",
                    "summary": "Simple webapp that is vulnerable to Log4Shell (CVE-2021-44228)",
                    "url": "https://github.com/korteke/log4shell-demo"
                },
                {
                    "repository": "PoC-in-GitHub · recanavar/vuln_spring_log4j2",
                    "author": "recanavar",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Simple Vulnerable Spring Boot Application to Test the CVE-2021-44228",
                    "summary": "Simple Vulnerable Spring Boot Application to Test the CVE-2021-44228",
                    "url": "https://github.com/recanavar/vuln_spring_log4j2"
                },
                {
                    "repository": "PoC-in-GitHub · DXC-StrikeForce/Burp-Log4j-HammerTime",
                    "author": "DXC-StrikeForce",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "Burp Active Scan extension to identify Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046",
                    "summary": "Burp Active Scan extension to identify Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046",
                    "url": "https://github.com/DXC-StrikeForce/Burp-Log4j-HammerTime"
                },
                {
                    "repository": "PoC-in-GitHub · andalik/log4j-filescan",
                    "author": "andalik",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Scanner recursivo de arquivos desenvolvido em Python 3 para localização e varredura de versões vulneráveis do Log4j2, contemplando análise interna de arquivos JAR (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 e CVE-2021-44832)",
                    "summary": "Scanner recursivo de arquivos desenvolvido em Python 3 para localização e varredura de versões vulneráveis do Log4j2, contemplando análise interna de arquivos JAR (CVE-2021-44228, CVE-2021-45046, CVE-2021-45105 e CVE-2021-44832)",
                    "url": "https://github.com/andalik/log4j-filescan"
                },
                {
                    "repository": "PoC-in-GitHub · lonecloud/CVE-2021-44228-Apache-Log4j",
                    "author": "lonecloud",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228-Apache-Log4j",
                    "summary": "CVE-2021-44228-Apache-Log4j",
                    "url": "https://github.com/lonecloud/CVE-2021-44228-Apache-Log4j"
                },
                {
                    "repository": "PoC-in-GitHub · gyaansastra/CVE-2021-44228",
                    "author": "gyaansastra",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Log4Shell CVE-2021-44228 Vulnerability Scanner and POC",
                    "summary": "Log4Shell CVE-2021-44228 Vulnerability Scanner and POC",
                    "url": "https://github.com/gyaansastra/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · axisops/CVE-2021-44228",
                    "author": "axisops",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "log4j mitigation work",
                    "summary": "log4j mitigation work",
                    "url": "https://github.com/axisops/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · kal1gh0st/MyLog4Shell",
                    "author": "kal1gh0st",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Simple Python 3 script to detect the \"Log4j\" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading",
                    "summary": "Simple Python 3 script to detect the \"Log4j\" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading",
                    "url": "https://github.com/kal1gh0st/MyLog4Shell"
                },
                {
                    "repository": "PoC-in-GitHub · hozyx/log4shell",
                    "author": "hozyx",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the presence of JndiLookup.class.",
                    "summary": "Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the presence of JndiLookup.class.",
                    "url": "https://github.com/hozyx/log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · andypitcher/Log4J_checker",
                    "author": "andypitcher",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4J checker for Apache CVE-2021-44228",
                    "summary": "Log4J checker for Apache CVE-2021-44228",
                    "url": "https://github.com/andypitcher/Log4J_checker"
                },
                {
                    "repository": "PoC-in-GitHub · Vulnmachines/log4j-cve-2021-44228",
                    "author": "Vulnmachines",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/Vulnmachines/log4j-cve-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · kannthu/CVE-2021-44228-Apache-Log4j-Rce",
                    "author": "kannthu",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/kannthu/CVE-2021-44228-Apache-Log4j-Rce"
                },
                {
                    "repository": "PoC-in-GitHub · Kr0ff/CVE-2021-44228",
                    "author": "Kr0ff",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Log4Shell Proof of Concept (CVE-2021-44228)",
                    "summary": "Log4Shell Proof of Concept (CVE-2021-44228)",
                    "url": "https://github.com/Kr0ff/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · suuhm/log4shell4shell",
                    "author": "suuhm",
                    "first_seen": "2021-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Log4shell - Multi-Toolkit. Find, Fix & Test possible CVE-2021-44228 vulneraries - provides a complete LOG4SHELL test/attack environment on shell",
                    "summary": "Log4shell - Multi-Toolkit. Find, Fix & Test possible CVE-2021-44228 vulneraries - provides a complete LOG4SHELL test/attack environment on shell",
                    "url": "https://github.com/suuhm/log4shell4shell"
                },
                {
                    "repository": "PoC-in-GitHub · wajda/log4shell-test-exploit",
                    "author": "wajda",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Test exploit of CVE-2021-44228",
                    "summary": "Test exploit of CVE-2021-44228",
                    "url": "https://github.com/wajda/log4shell-test-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · obscuritylabs/log4shell-poc-lab",
                    "author": "obscuritylabs",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "A lab demonstration of the log4shell vulnerability: CVE-2021-44228",
                    "summary": "A lab demonstration of the log4shell vulnerability: CVE-2021-44228",
                    "url": "https://github.com/obscuritylabs/log4shell-poc-lab"
                },
                {
                    "repository": "PoC-in-GitHub · Fazmin/vCenter-Server-Workaround-Script-CVE-2021-44228",
                    "author": "Fazmin",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Script - Workaround instructions to address CVE-2021-44228 in vCenter Server",
                    "summary": "Script - Workaround instructions to address CVE-2021-44228 in vCenter Server",
                    "url": "https://github.com/Fazmin/vCenter-Server-Workaround-Script-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · Grupo-Kapa-7/CVE-2021-44228-Log4j-PoC-RCE",
                    "author": "Grupo-Kapa-7",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC RCE Log4j CVE-2021-4428 para pruebas",
                    "summary": "PoC RCE Log4j CVE-2021-4428 para pruebas",
                    "url": "https://github.com/Grupo-Kapa-7/CVE-2021-44228-Log4j-PoC-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · sysadmin0815/Fix-Log4j-PowershellScript",
                    "author": "sysadmin0815",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell mitigation (CVE-2021-44228) - search and remove JNDI class from *log4j*.jar files on the system with Powershell (Windows)",
                    "summary": "Log4Shell mitigation (CVE-2021-44228) - search and remove JNDI class from *log4j*.jar files on the system with Powershell (Windows)",
                    "url": "https://github.com/sysadmin0815/Fix-Log4j-PowershellScript"
                },
                {
                    "repository": "PoC-in-GitHub · RenYuH/log4j-lookups-vulnerability",
                    "author": "RenYuH",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4j2 Vulnerability (CVE-2021-44228)",
                    "summary": "Log4j2 Vulnerability (CVE-2021-44228)",
                    "url": "https://github.com/RenYuH/log4j-lookups-vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · scheibling/py-log4shellscanner",
                    "author": "scheibling",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)",
                    "summary": "Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)",
                    "url": "https://github.com/scheibling/py-log4shellscanner"
                },
                {
                    "repository": "PoC-in-GitHub · zaneef/CVE-2021-44228",
                    "author": "zaneef",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell (CVE-2021-44228): Descrizione, Exploitation e Mitigazione",
                    "summary": "Log4Shell (CVE-2021-44228): Descrizione, Exploitation e Mitigazione",
                    "url": "https://github.com/zaneef/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · metodidavidovic/log4j-quick-scan",
                    "author": "metodidavidovic",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Scan your IP network and determine hosts with possible CVE-2021-44228 vulnerability in log4j library.",
                    "summary": "Scan your IP network and determine hosts with possible CVE-2021-44228 vulnerability in log4j library.",
                    "url": "https://github.com/metodidavidovic/log4j-quick-scan"
                },
                {
                    "repository": "PoC-in-GitHub · WatchGuard-Threat-Lab/log4shell-iocs",
                    "author": "WatchGuard-Threat-Lab",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A collection of IOCs for CVE-2021-44228 also known as Log4Shell",
                    "summary": "A collection of IOCs for CVE-2021-44228 also known as Log4Shell",
                    "url": "https://github.com/WatchGuard-Threat-Lab/log4shell-iocs"
                },
                {
                    "repository": "PoC-in-GitHub · Aschen/log4j-patched",
                    "author": "Aschen",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Provide patched version of Log4J against CVE-2021-44228 and CVE-2021-45046 as well as a script to manually patch it yourself",
                    "summary": "Provide patched version of Log4J against CVE-2021-44228 and CVE-2021-45046 as well as a script to manually patch it yourself",
                    "url": "https://github.com/Aschen/log4j-patched"
                },
                {
                    "repository": "PoC-in-GitHub · nikolas-charalambidis/cve-2021-44228",
                    "author": "nikolas-charalambidis",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A simple simulation of the infamous CVE-2021-44228 issue.",
                    "summary": "A simple simulation of the infamous CVE-2021-44228 issue.",
                    "url": "https://github.com/nikolas-charalambidis/cve-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · m0rath/detect-log4j-exploitable",
                    "author": "m0rath",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228",
                    "summary": "CVE-2021-44228",
                    "url": "https://github.com/m0rath/detect-log4j-exploitable"
                },
                {
                    "repository": "PoC-in-GitHub · nu11secur1ty/CVE-2021-44228-VULN-APP",
                    "author": "nu11secur1ty",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/nu11secur1ty/CVE-2021-44228-VULN-APP"
                },
                {
                    "repository": "PoC-in-GitHub · ankur-katiyar/log4j-docker",
                    "author": "ankur-katiyar",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Docker images and k8s YAMLs for Log4j Vulnerability POC (Log4j (CVE-2021-44228 RCE Vulnerability)",
                    "summary": "Docker images and k8s YAMLs for Log4j Vulnerability POC (Log4j (CVE-2021-44228 RCE Vulnerability)",
                    "url": "https://github.com/ankur-katiyar/log4j-docker"
                },
                {
                    "repository": "PoC-in-GitHub · immunityinc/Log4j-JNDIServer",
                    "author": "immunityinc",
                    "first_seen": "2021-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "This project will help to test the Log4j CVE-2021-44228 vulnerability.",
                    "summary": "This project will help to test the Log4j CVE-2021-44228 vulnerability.",
                    "url": "https://github.com/immunityinc/Log4j-JNDIServer"
                },
                {
                    "repository": "PoC-in-GitHub · DANSI/PowerShell-Log4J-Scanner",
                    "author": "DANSI",
                    "first_seen": "2021-12-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "can find, analyse and patch Log4J files because of CVE-2021-44228, CVE-2021-45046",
                    "summary": "can find, analyse and patch Log4J files because of CVE-2021-44228, CVE-2021-45046",
                    "url": "https://github.com/DANSI/PowerShell-Log4J-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · suniastar/scan-log4shell",
                    "author": "suniastar",
                    "first_seen": "2021-12-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A scanning suite to find servers affected by the log4shell flaw (CVE-2021-44228) with example to test it",
                    "summary": "A scanning suite to find servers affected by the log4shell flaw (CVE-2021-44228) with example to test it",
                    "url": "https://github.com/suniastar/scan-log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · shivakumarjayaraman/log4jvulnerability-CVE-2021-44228",
                    "author": "shivakumarjayaraman",
                    "first_seen": "2021-12-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "An attempt to understand the log4j vulnerability by looking through the code",
                    "summary": "An attempt to understand the log4j vulnerability by looking through the code",
                    "url": "https://github.com/shivakumarjayaraman/log4jvulnerability-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · j3kz/CVE-2021-44228-PoC",
                    "author": "j3kz",
                    "first_seen": "2021-12-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Self-contained lab environment that runs the exploit safely, all from docker compose",
                    "summary": "Self-contained lab environment that runs the exploit safely, all from docker compose",
                    "url": "https://github.com/j3kz/CVE-2021-44228-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · Apipia/log4j-pcap-activity",
                    "author": "Apipia",
                    "first_seen": "2021-12-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A fun activity using a packet capture file from the log4j exploit (CVE-2021-44228)",
                    "summary": "A fun activity using a packet capture file from the log4j exploit (CVE-2021-44228)",
                    "url": "https://github.com/Apipia/log4j-pcap-activity"
                },
                {
                    "repository": "PoC-in-GitHub · axelcurmi/log4shell-docker-lab",
                    "author": "axelcurmi",
                    "first_seen": "2021-12-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell (CVE-2021-44228) docker lab",
                    "summary": "Log4Shell (CVE-2021-44228) docker lab",
                    "url": "https://github.com/axelcurmi/log4shell-docker-lab"
                },
                {
                    "repository": "PoC-in-GitHub · otaviokr/log4j-2021-vulnerability-study",
                    "author": "otaviokr",
                    "first_seen": "2021-12-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is a showcase how the Log4J vulnerability (CVE-2021-44228) could be explored. This code is safe to run, but understand what it does and how it works!",
                    "summary": "This is a showcase how the Log4J vulnerability (CVE-2021-44228) could be explored. This code is safe to run, but understand what it does and how it works!",
                    "url": "https://github.com/otaviokr/log4j-2021-vulnerability-study"
                },
                {
                    "repository": "PoC-in-GitHub · kkyehit/log4j_CVE-2021-44228",
                    "author": "kkyehit",
                    "first_seen": "2021-12-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/kkyehit/log4j_CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · trickyearlobe/inspec-log4j",
                    "author": "trickyearlobe",
                    "first_seen": "2021-12-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "An Inspec profile to check for Log4j CVE-2021-44228 and CVE-2021-45046",
                    "summary": "An Inspec profile to check for Log4j CVE-2021-44228 and CVE-2021-45046",
                    "url": "https://github.com/trickyearlobe/inspec-log4j"
                },
                {
                    "repository": "PoC-in-GitHub · TheInterception/Log4J-Simulation-Tool",
                    "author": "TheInterception",
                    "first_seen": "2021-12-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Vulnerability analysis, patch management and exploitation tool forCVE-2021-44228 / CVE-2021-45046 / CVE-2021-4104",
                    "summary": "Vulnerability analysis, patch management and exploitation tool forCVE-2021-44228 / CVE-2021-45046 / CVE-2021-4104",
                    "url": "https://github.com/TheInterception/Log4J-Simulation-Tool"
                },
                {
                    "repository": "PoC-in-GitHub · KeysAU/Get-log4j-Windows-local",
                    "author": "KeysAU",
                    "first_seen": "2021-12-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Identifying all log4j components across on local windows servers. CVE-2021-44228",
                    "summary": "Identifying all log4j components across on local windows servers. CVE-2021-44228",
                    "url": "https://github.com/KeysAU/Get-log4j-Windows-local"
                },
                {
                    "repository": "PoC-in-GitHub · mschmnet/Log4Shell-demo",
                    "author": "mschmnet",
                    "first_seen": "2021-12-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Demo to show how Log4Shell / CVE-2021-44228 vulnerability works",
                    "summary": "Demo to show how Log4Shell / CVE-2021-44228 vulnerability works",
                    "url": "https://github.com/mschmnet/Log4Shell-demo"
                },
                {
                    "repository": "PoC-in-GitHub · Rk-000/Log4j_scan_Advance",
                    "author": "Rk-000",
                    "first_seen": "2021-12-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228",
                    "summary": "A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228",
                    "url": "https://github.com/Rk-000/Log4j_scan_Advance"
                },
                {
                    "repository": "PoC-in-GitHub · puzzlepeaches/Log4jCenter",
                    "author": "puzzlepeaches",
                    "first_seen": "2021-12-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 103,
                    "title": "Exploiting CVE-2021-44228 in vCenter for remote code execution and more.",
                    "summary": "Exploiting CVE-2021-44228 in vCenter for remote code execution and more.",
                    "url": "https://github.com/puzzlepeaches/Log4jCenter"
                },
                {
                    "repository": "PoC-in-GitHub · Labout/log4shell-rmi-poc",
                    "author": "Labout",
                    "first_seen": "2021-12-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "A Proof of Concept of the Log4j vulnerabilities (CVE-2021-44228) over Java-RMI",
                    "summary": "A Proof of Concept of the Log4j vulnerabilities (CVE-2021-44228) over Java-RMI",
                    "url": "https://github.com/Labout/log4shell-rmi-poc"
                },
                {
                    "repository": "PoC-in-GitHub · TotallyNotAHaxxer/f-for-java",
                    "author": "TotallyNotAHaxxer",
                    "first_seen": "2021-12-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "a project written in go and java i abandoned for CVE-2021-44228 try to fix it if you can XD",
                    "summary": "a project written in go and java i abandoned for CVE-2021-44228 try to fix it if you can XD",
                    "url": "https://github.com/TotallyNotAHaxxer/f-for-java"
                },
                {
                    "repository": "PoC-in-GitHub · spasam/log4j2-exploit",
                    "author": "spasam",
                    "first_seen": "2021-12-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "log4j2 Log4Shell CVE-2021-44228 proof of concept",
                    "summary": "log4j2 Log4Shell CVE-2021-44228 proof of concept",
                    "url": "https://github.com/spasam/log4j2-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · bumheehan/cve-2021-44228-log4j-test",
                    "author": "bumheehan",
                    "first_seen": "2021-12-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/bumheehan/cve-2021-44228-log4j-test"
                },
                {
                    "repository": "PoC-in-GitHub · Y0-kan/Log4jShell-Scan",
                    "author": "Y0-kan",
                    "first_seen": "2021-12-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 38,
                    "title": "log4j2 RCE漏洞（CVE-2021-44228)内网扫描器，可用于在不出网的条件下进行漏洞扫描，帮助企业内部快速发现Log4jShell漏洞。",
                    "summary": "log4j2 RCE漏洞（CVE-2021-44228)内网扫描器，可用于在不出网的条件下进行漏洞扫描，帮助企业内部快速发现Log4jShell漏洞。",
                    "url": "https://github.com/Y0-kan/Log4jShell-Scan"
                },
                {
                    "repository": "PoC-in-GitHub · julian911015/Log4j-Scanner-Exploit",
                    "author": "julian911015",
                    "first_seen": "2021-12-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.",
                    "summary": "Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.",
                    "url": "https://github.com/julian911015/Log4j-Scanner-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · intel-xeon/CVE-2021-44228---detection-with-PowerShell",
                    "author": "intel-xeon",
                    "first_seen": "2021-12-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/intel-xeon/CVE-2021-44228---detection-with-PowerShell"
                },
                {
                    "repository": "PoC-in-GitHub · chandru-gunasekaran/log4j-fix-CVE-2021-44228",
                    "author": "chandru-gunasekaran",
                    "first_seen": "2021-12-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Windows Batch Scrip to Fix the log4j-issue-CVE-2021-44228",
                    "summary": "Windows Batch Scrip to Fix the log4j-issue-CVE-2021-44228",
                    "url": "https://github.com/chandru-gunasekaran/log4j-fix-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · snapattack/damn-vulnerable-log4j-app",
                    "author": "snapattack",
                    "first_seen": "2021-12-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack",
                    "summary": "Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack",
                    "url": "https://github.com/snapattack/damn-vulnerable-log4j-app"
                },
                {
                    "repository": "PoC-in-GitHub · r00thunter/Log4Shell-Scanner",
                    "author": "r00thunter",
                    "first_seen": "2021-12-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Python script to detect Log4Shell Vulnerability CVE-2021-44228",
                    "summary": "Python script to detect Log4Shell Vulnerability CVE-2021-44228",
                    "url": "https://github.com/r00thunter/Log4Shell-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · mn-io/log4j-spring-vuln-poc",
                    "author": "mn-io",
                    "first_seen": "2021-12-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "POC for CVE-2021-44228 within Springboot",
                    "summary": "POC for CVE-2021-44228 within Springboot",
                    "url": "https://github.com/mn-io/log4j-spring-vuln-poc"
                },
                {
                    "repository": "PoC-in-GitHub · rejupillai/log4j2-hack-springboot",
                    "author": "rejupillai",
                    "first_seen": "2021-12-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4j2 CVE-2021-44228 hack demo for a springboot app",
                    "summary": "Log4j2 CVE-2021-44228 hack demo for a springboot app",
                    "url": "https://github.com/rejupillai/log4j2-hack-springboot"
                },
                {
                    "repository": "PoC-in-GitHub · lucab85/log4j-cve-2021-44228",
                    "author": "lucab85",
                    "first_seen": "2021-12-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 57,
                    "title": "Ansible detector scanner playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 Remote Code Execution - log4j (CVE-2021-44228)",
                    "summary": "Ansible detector scanner playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 Remote Code Execution - log4j (CVE-2021-44228)",
                    "url": "https://github.com/lucab85/log4j-cve-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · BabooPan/Log4Shell-CVE-2021-44228-Demo",
                    "author": "BabooPan",
                    "first_seen": "2021-12-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Log4Shell Demo with AWS",
                    "summary": "Log4Shell Demo with AWS",
                    "url": "https://github.com/BabooPan/Log4Shell-CVE-2021-44228-Demo"
                },
                {
                    "repository": "PoC-in-GitHub · ossie-git/log4shell_sentinel",
                    "author": "ossie-git",
                    "first_seen": "2021-12-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner",
                    "summary": "A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner",
                    "url": "https://github.com/ossie-git/log4shell_sentinel"
                },
                {
                    "repository": "PoC-in-GitHub · r00thunter/Log4Shell",
                    "author": "r00thunter",
                    "first_seen": "2021-12-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Generic Scanner for Apache log4j RCE CVE-2021-44228",
                    "summary": "Generic Scanner for Apache log4j RCE CVE-2021-44228",
                    "url": "https://github.com/r00thunter/Log4Shell"
                },
                {
                    "repository": "PoC-in-GitHub · ssl-user-en/Log4j-Scanner-Exploit",
                    "author": "ssl-user-en",
                    "first_seen": "2021-12-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.",
                    "summary": "Script en bash que permite identificar la vulnerabilidad Log4j CVE-2021-44228 de forma remota.",
                    "url": "https://github.com/ssl-user-en/Log4j-Scanner-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · BJLIYANLIANG/log4j-scanner",
                    "author": "BJLIYANLIANG",
                    "first_seen": "2021-12-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4j 2 (CVE-2021-44228) vulnerability scanner for Windows OS",
                    "summary": "Log4j 2 (CVE-2021-44228) vulnerability scanner for Windows OS",
                    "url": "https://github.com/BJLIYANLIANG/log4j-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · badb33f/Apache-Log4j-POC",
                    "author": "badb33f",
                    "first_seen": "2021-12-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228",
                    "summary": "Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228",
                    "url": "https://github.com/badb33f/Apache-Log4j-POC"
                },
                {
                    "repository": "PoC-in-GitHub · TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit",
                    "author": "TaroballzChen",
                    "first_seen": "2021-12-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "open detection and scanning tool for discovering and fuzzing for Log4J RCE CVE-2021-44228 vulnerability",
                    "summary": "open detection and scanning tool for discovering and fuzzing for Log4J RCE CVE-2021-44228 vulnerability",
                    "url": "https://github.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit"
                },
                {
                    "repository": "PoC-in-GitHub · lucab85/ansible-role-log4shell",
                    "author": "lucab85",
                    "first_seen": "2021-12-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Ansible playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 for Log4Shell (CVE-2021-44228).",
                    "summary": "Ansible playbook to verify target Linux hosts using the official Red Hat Log4j detector script RHSB-2021-009 for Log4Shell (CVE-2021-44228).",
                    "url": "https://github.com/lucab85/ansible-role-log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · grimch/log4j-CVE-2021-44228-workaround",
                    "author": "grimch",
                    "first_seen": "2021-12-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "general purpose workaround for the log4j CVE-2021-44228 vulnerability",
                    "summary": "general purpose workaround for the log4j CVE-2021-44228 vulnerability",
                    "url": "https://github.com/grimch/log4j-CVE-2021-44228-workaround"
                },
                {
                    "repository": "PoC-in-GitHub · cybersecurityworks553/log4j-shell-csw",
                    "author": "cybersecurityworks553",
                    "first_seen": "2021-12-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.",
                    "summary": "A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.",
                    "url": "https://github.com/cybersecurityworks553/log4j-shell-csw"
                },
                {
                    "repository": "PoC-in-GitHub · Toolsec/log4j-scan",
                    "author": "Toolsec",
                    "first_seen": "2021-12-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 检查工具",
                    "summary": "CVE-2021-44228 检查工具",
                    "url": "https://github.com/Toolsec/log4j-scan"
                },
                {
                    "repository": "PoC-in-GitHub · puzzlepeaches/Log4jUnifi",
                    "author": "puzzlepeaches",
                    "first_seen": "2021-12-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 168,
                    "title": "Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.",
                    "summary": "Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.",
                    "url": "https://github.com/puzzlepeaches/Log4jUnifi"
                },
                {
                    "repository": "PoC-in-GitHub · many-fac3d-g0d/apache-tomcat-log4j",
                    "author": "many-fac3d-g0d",
                    "first_seen": "2021-12-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Log4j2 CVE-2021-44228 Vulnerability POC in Apache Tomcat",
                    "summary": "Log4j2 CVE-2021-44228 Vulnerability POC in Apache Tomcat",
                    "url": "https://github.com/many-fac3d-g0d/apache-tomcat-log4j"
                },
                {
                    "repository": "PoC-in-GitHub · marcourbano/CVE-2021-44228",
                    "author": "marcourbano",
                    "first_seen": "2021-12-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "PoC for CVE-2021-44228.",
                    "summary": "PoC for CVE-2021-44228.",
                    "url": "https://github.com/marcourbano/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · bsigouin/log4shell-vulnerable-app",
                    "author": "bsigouin",
                    "first_seen": "2021-12-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Spring Boot web application vulnerable to CVE-2021-44228, nicknamed Log4Shell.",
                    "summary": "Spring Boot web application vulnerable to CVE-2021-44228, nicknamed Log4Shell.",
                    "url": "https://github.com/bsigouin/log4shell-vulnerable-app"
                },
                {
                    "repository": "PoC-in-GitHub · ToxicEnvelope/XSYS-Log4J2Shell-Ex",
                    "author": "ToxicEnvelope",
                    "first_seen": "2021-12-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "this repository contains a POC of CVE-2021-44228 (log4j2shell) as part of a security research",
                    "summary": "this repository contains a POC of CVE-2021-44228 (log4j2shell) as part of a security research",
                    "url": "https://github.com/ToxicEnvelope/XSYS-Log4J2Shell-Ex"
                },
                {
                    "repository": "PoC-in-GitHub · felipe8398/ModSec-log4j2",
                    "author": "felipe8398",
                    "first_seen": "2021-12-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Regra ModSec para proteção log4j2 - CVE-2021-44228",
                    "summary": "Regra ModSec para proteção log4j2 - CVE-2021-44228",
                    "url": "https://github.com/felipe8398/ModSec-log4j2"
                },
                {
                    "repository": "PoC-in-GitHub · c3-h2/Log4j_Attacker_IPList",
                    "author": "c3-h2",
                    "first_seen": "2021-12-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228",
                    "summary": "CVE-2021-44228",
                    "url": "https://github.com/c3-h2/Log4j_Attacker_IPList"
                },
                {
                    "repository": "PoC-in-GitHub · mazhar-hassan/log4j-vulnerability",
                    "author": "mazhar-hassan",
                    "first_seen": "2021-12-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell (CVE-2021-44228) is a zero-day vulnerability in Log4j",
                    "summary": "Log4Shell (CVE-2021-44228) is a zero-day vulnerability in Log4j",
                    "url": "https://github.com/mazhar-hassan/log4j-vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · s-retlaw/l4s_poc",
                    "author": "s-retlaw",
                    "first_seen": "2021-12-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell (Cve-2021-44228) Proof Of Concept",
                    "summary": "Log4Shell (Cve-2021-44228) Proof Of Concept",
                    "url": "https://github.com/s-retlaw/l4s_poc"
                },
                {
                    "repository": "PoC-in-GitHub · Ravid-CheckMarx/CVE-2021-44228-Apache-Log4j-Rce-main",
                    "author": "Ravid-CheckMarx",
                    "first_seen": "2021-12-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/Ravid-CheckMarx/CVE-2021-44228-Apache-Log4j-Rce-main"
                },
                {
                    "repository": "PoC-in-GitHub · yesspider-hacker/log4j-payload-generator",
                    "author": "yesspider-hacker",
                    "first_seen": "2021-12-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "log4j-paylaod generator : A generic payload generator for Apache log4j RCE CVE-2021-44228",
                    "summary": "log4j-paylaod generator : A generic payload generator for Apache log4j RCE CVE-2021-44228",
                    "url": "https://github.com/yesspider-hacker/log4j-payload-generator"
                },
                {
                    "repository": "PoC-in-GitHub · LinkMJB/log4shell_scanner",
                    "author": "LinkMJB",
                    "first_seen": "2021-12-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Quick and dirty scanner, hitting common ports looking for Log4Shell (CVE-2021-44228) vulnerability",
                    "summary": "Quick and dirty scanner, hitting common ports looking for Log4Shell (CVE-2021-44228) vulnerability",
                    "url": "https://github.com/LinkMJB/log4shell_scanner"
                },
                {
                    "repository": "PoC-in-GitHub · NS-Sp4ce/Vm4J",
                    "author": "NS-Sp4ce",
                    "first_seen": "2021-12-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 207,
                    "title": "A tool for detect&exploit vmware product log4j(cve-2021-44228) vulnerability.Support VMware HCX/vCenter/NSX/Horizon/vRealize Operations Manager",
                    "summary": "A tool for detect&exploit vmware product log4j(cve-2021-44228) vulnerability.Support VMware HCX/vCenter/NSX/Horizon/vRealize Operations Manager",
                    "url": "https://github.com/NS-Sp4ce/Vm4J"
                },
                {
                    "repository": "PoC-in-GitHub · PoneyClairDeLune/LogJackFix",
                    "author": "PoneyClairDeLune",
                    "first_seen": "2021-12-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A spigot plugin to fix CVE-2021-44228 Log4j remote code execution vulnerability, to protect Minecraft clients.",
                    "summary": "A spigot plugin to fix CVE-2021-44228 Log4j remote code execution vulnerability, to protect Minecraft clients.",
                    "url": "https://github.com/PoneyClairDeLune/LogJackFix"
                },
                {
                    "repository": "PoC-in-GitHub · MarceloLeite2604/log4j-vulnerability",
                    "author": "MarceloLeite2604",
                    "first_seen": "2021-12-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Presents how to exploit CVE-2021-44228 vulnerability.",
                    "summary": "Presents how to exploit CVE-2021-44228 vulnerability.",
                    "url": "https://github.com/MarceloLeite2604/log4j-vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · romanutti/log4shell-vulnerable-app",
                    "author": "romanutti",
                    "first_seen": "2021-12-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository contains a Spring Boot web application vulnerable to CVE-2021-44228, known as log4shell.",
                    "summary": "This repository contains a Spring Boot web application vulnerable to CVE-2021-44228, known as log4shell.",
                    "url": "https://github.com/romanutti/log4shell-vulnerable-app"
                },
                {
                    "repository": "PoC-in-GitHub · marklindsey11/-CVE-2021-44228_scanner-Applications-that-are-vulnerable-to-the-log4j-CVE-2021-44228-https-nvd.",
                    "author": "marklindsey11",
                    "first_seen": "2022-01-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4j Vulnerability Scanner",
                    "summary": "Log4j Vulnerability Scanner",
                    "url": "https://github.com/marklindsey11/-CVE-2021-44228_scanner-Applications-that-are-vulnerable-to-the-log4j-CVE-2021-44228-https-nvd."
                },
                {
                    "repository": "PoC-in-GitHub · Timborin0/log4j-dork-scanner",
                    "author": "Timborin0",
                    "first_seen": "2022-01-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A script to search, scrape and scan for Apache Log4j CVE-2021-44228 affected files using Google dorks",
                    "summary": "A script to search, scrape and scan for Apache Log4j CVE-2021-44228 affected files using Google dorks",
                    "url": "https://github.com/Timborin0/log4j-dork-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · marklindsey11/gh-repo-clone-marklindsey11--CVE-2021-44228_scanner-Applications-that-are-vulnerable-to-the-log4j-CV",
                    "author": "marklindsey11",
                    "first_seen": "2022-01-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4j-Scanner",
                    "summary": "Log4j-Scanner",
                    "url": "https://github.com/marklindsey11/gh-repo-clone-marklindsey11--CVE-2021-44228_scanner-Applications-that-are-vulnerable-to-the-log4j-CV"
                },
                {
                    "repository": "PoC-in-GitHub · mklinkj/log4j2-test",
                    "author": "mklinkj",
                    "first_seen": "2022-01-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4j2 LDAP 취약점 테스트 (CVE-2021-44228)",
                    "summary": "Log4j2 LDAP 취약점 테스트 (CVE-2021-44228)",
                    "url": "https://github.com/mklinkj/log4j2-test"
                },
                {
                    "repository": "PoC-in-GitHub · 4jfinder/4jfinder.github.io",
                    "author": "4jfinder",
                    "first_seen": "2022-01-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Searchable page for CISA Log4j (CVE-2021-44228) Affected Vendor & Software List",
                    "summary": "Searchable page for CISA Log4j (CVE-2021-44228) Affected Vendor & Software List",
                    "url": "https://github.com/4jfinder/4jfinder.github.io"
                },
                {
                    "repository": "PoC-in-GitHub · alexpena5635/CVE-2021-44228_scanner-main-Modified-",
                    "author": "alexpena5635",
                    "first_seen": "2022-01-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/alexpena5635/CVE-2021-44228_scanner-main-Modified-"
                },
                {
                    "repository": "PoC-in-GitHub · kanitan/log4j2-web-vulnerable",
                    "author": "kanitan",
                    "first_seen": "2022-01-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A vulnerable web app for log4j2 RCE(CVE-2021-44228) exploit test.",
                    "summary": "A vulnerable web app for log4j2 RCE(CVE-2021-44228) exploit test.",
                    "url": "https://github.com/kanitan/log4j2-web-vulnerable"
                },
                {
                    "repository": "PoC-in-GitHub · mr-r3b00t/CVE-2021-44228",
                    "author": "mr-r3b00t",
                    "first_seen": "2022-01-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "Backdoor detection for VMware view",
                    "summary": "Backdoor detection for VMware view",
                    "url": "https://github.com/mr-r3b00t/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · ChandanShastri/Log4j_Vulnerability_Demo",
                    "author": "ChandanShastri",
                    "first_seen": "2022-01-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A simple program to demonstrate how Log4j vulnerability can be exploited ( CVE-2021-44228 )",
                    "summary": "A simple program to demonstrate how Log4j vulnerability can be exploited ( CVE-2021-44228 )",
                    "url": "https://github.com/ChandanShastri/Log4j_Vulnerability_Demo"
                },
                {
                    "repository": "PoC-in-GitHub · puzzlepeaches/Log4jHorizon",
                    "author": "puzzlepeaches",
                    "first_seen": "2022-01-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 120,
                    "title": "Exploiting CVE-2021-44228 in VMWare Horizon for remote code execution and more.",
                    "summary": "Exploiting CVE-2021-44228 in VMWare Horizon for remote code execution and more.",
                    "url": "https://github.com/puzzlepeaches/Log4jHorizon"
                },
                {
                    "repository": "PoC-in-GitHub · Vulnmachines/log4jshell_CVE-2021-44228",
                    "author": "Vulnmachines",
                    "first_seen": "2022-01-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Log4jshell - CVE-2021-44228",
                    "summary": "Log4jshell - CVE-2021-44228",
                    "url": "https://github.com/Vulnmachines/log4jshell_CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · mr-vill4in/log4j-fuzzer",
                    "author": "mr-vill4in",
                    "first_seen": "2022-01-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2021-44228",
                    "summary": "CVE-2021-44228",
                    "url": "https://github.com/mr-vill4in/log4j-fuzzer"
                },
                {
                    "repository": "PoC-in-GitHub · nix-xin/vuln4japi",
                    "author": "nix-xin",
                    "first_seen": "2022-01-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A vulnerable Java based REST API for demonstrating CVE-2021-44228 (log4shell).",
                    "summary": "A vulnerable Java based REST API for demonstrating CVE-2021-44228 (log4shell).",
                    "url": "https://github.com/nix-xin/vuln4japi"
                },
                {
                    "repository": "PoC-in-GitHub · maximofernandezriera/CVE-2021-44228",
                    "author": "maximofernandezriera",
                    "first_seen": "2022-01-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "This Log4j RCE exploit originated from https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce",
                    "summary": "This Log4j RCE exploit originated from https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce",
                    "url": "https://github.com/maximofernandezriera/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · mebibite/log4jhound",
                    "author": "mebibite",
                    "first_seen": "2022-01-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight on versions used. Unpacks JARs and analyses their Manifest files.",
                    "summary": "Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight on versions used. Unpacks JARs and analyses their Manifest files.",
                    "url": "https://github.com/mebibite/log4jhound"
                },
                {
                    "repository": "PoC-in-GitHub · 3pplus/loguccino",
                    "author": "3pplus",
                    "first_seen": "2022-01-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Scan and patch tool for CVE-2021-44228 and related log4j concerns.",
                    "summary": "Scan and patch tool for CVE-2021-44228 and related log4j concerns.",
                    "url": "https://github.com/3pplus/loguccino"
                },
                {
                    "repository": "PoC-in-GitHub · jxerome/log4shell",
                    "author": "jxerome",
                    "first_seen": "2022-01-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Démo du fonctionnement de log4shell (CVE-2021-44228)",
                    "summary": "Démo du fonctionnement de log4shell (CVE-2021-44228)",
                    "url": "https://github.com/jxerome/log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · solitarysp/Log4j-CVE-2021-44228",
                    "author": "solitarysp",
                    "first_seen": "2022-01-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/solitarysp/Log4j-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · atlassion/log4j-exploit-builder",
                    "author": "atlassion",
                    "first_seen": "2022-01-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Script to create a log4j (CVE-2021-44228) exploit with support for different methods of getting a reverse shell",
                    "summary": "Script to create a log4j (CVE-2021-44228) exploit with support for different methods of getting a reverse shell",
                    "url": "https://github.com/atlassion/log4j-exploit-builder"
                },
                {
                    "repository": "PoC-in-GitHub · atlassion/RS4LOGJ-CVE-2021-44228",
                    "author": "atlassion",
                    "first_seen": "2022-01-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Fix: CVE-2021-44228 4LOGJ",
                    "summary": "Fix: CVE-2021-44228 4LOGJ",
                    "url": "https://github.com/atlassion/RS4LOGJ-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · sdogancesur/log4j_github_repository",
                    "author": "sdogancesur",
                    "first_seen": "2022-01-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This work includes testing and improvement tools for CVE-2021-44228(log4j).",
                    "summary": "This work includes testing and improvement tools for CVE-2021-44228(log4j).",
                    "url": "https://github.com/sdogancesur/log4j_github_repository"
                },
                {
                    "repository": "PoC-in-GitHub · jrocia/Search-log4Jvuln-AppScanSTD",
                    "author": "jrocia",
                    "first_seen": "2022-01-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This Pwsh script run AppScan Standard scans against a list of web sites (URLs.txt) checking for Log4J (CVE-2021-44228) vulnerability",
                    "summary": "This Pwsh script run AppScan Standard scans against a list of web sites (URLs.txt) checking for Log4J (CVE-2021-44228) vulnerability",
                    "url": "https://github.com/jrocia/Search-log4Jvuln-AppScanSTD"
                },
                {
                    "repository": "PoC-in-GitHub · aajuvonen/log4stdin",
                    "author": "aajuvonen",
                    "first_seen": "2022-01-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A Java application intentionally vulnerable to CVE-2021-44228",
                    "summary": "A Java application intentionally vulnerable to CVE-2021-44228",
                    "url": "https://github.com/aajuvonen/log4stdin"
                },
                {
                    "repository": "PoC-in-GitHub · arnaudluti/PS-CVE-2021-44228",
                    "author": "arnaudluti",
                    "first_seen": "2022-01-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Static detection of vulnerable log4j librairies on Windows servers, members of an AD domain.",
                    "summary": "Static detection of vulnerable log4j librairies on Windows servers, members of an AD domain.",
                    "url": "https://github.com/arnaudluti/PS-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · ColdFusionX/CVE-2021-44228-Log4Shell-POC",
                    "author": "ColdFusionX",
                    "first_seen": "2022-01-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "POC for Infamous Log4j CVE-2021-44228",
                    "summary": "POC for Infamous Log4j CVE-2021-44228",
                    "url": "https://github.com/ColdFusionX/CVE-2021-44228-Log4Shell-POC"
                },
                {
                    "repository": "PoC-in-GitHub · robrankin/cve-2021-44228-waf-tests",
                    "author": "robrankin",
                    "first_seen": "2022-01-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Testing WAF protection against CVE-2021-44228 Log4Shell",
                    "summary": "Testing WAF protection against CVE-2021-44228 Log4Shell",
                    "url": "https://github.com/robrankin/cve-2021-44228-waf-tests"
                },
                {
                    "repository": "PoC-in-GitHub · 0xalwayslucky/log4j-polkit-poc",
                    "author": "0xalwayslucky",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "vulnerable setup to display an attack chain of log4j CVE-2021-44228 with privilege escalation to root using the polkit exploit CVE-2021-4034",
                    "summary": "vulnerable setup to display an attack chain of log4j CVE-2021-44228 with privilege escalation to root using the polkit exploit CVE-2021-4034",
                    "url": "https://github.com/0xalwayslucky/log4j-polkit-poc"
                },
                {
                    "repository": "PoC-in-GitHub · y-security/yLog4j",
                    "author": "y-security",
                    "first_seen": "2022-01-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "PortSwigger Burp Plugin for the Log4j  (CVE-2021-44228)",
                    "summary": "PortSwigger Burp Plugin for the Log4j  (CVE-2021-44228)",
                    "url": "https://github.com/y-security/yLog4j"
                },
                {
                    "repository": "PoC-in-GitHub · IAmNewbieZ/CVE-2021-44228",
                    "author": "IAmNewbieZ",
                    "first_seen": "2022-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/IAmNewbieZ/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · FeryaelJustice/Log4Shell",
                    "author": "FeryaelJustice",
                    "first_seen": "2022-02-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository is for Log4j 2021 (CVE-2021-44228) Vulnerability demonstration and mitigation.",
                    "summary": "This repository is for Log4j 2021 (CVE-2021-44228) Vulnerability demonstration and mitigation.",
                    "url": "https://github.com/FeryaelJustice/Log4Shell"
                },
                {
                    "repository": "PoC-in-GitHub · hotpotcookie/CVE-2021-44228-white-box",
                    "author": "hotpotcookie",
                    "first_seen": "2022-02-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Log4j vulner testing environment based on CVE-2021-44228. It provide guidance to build the sample infrastructure and the exploit scripts. Supporting cooki3 script as the main exploit tools & integration",
                    "summary": "Log4j vulner testing environment based on CVE-2021-44228. It provide guidance to build the sample infrastructure and the exploit scripts. Supporting cooki3 script as the main exploit tools & integration",
                    "url": "https://github.com/hotpotcookie/CVE-2021-44228-white-box"
                },
                {
                    "repository": "PoC-in-GitHub · s-retlaw/l4srs",
                    "author": "s-retlaw",
                    "first_seen": "2022-02-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Rust implementation of the Log 4 Shell (log 4 j - CVE-2021-44228)",
                    "summary": "Rust implementation of the Log 4 Shell (log 4 j - CVE-2021-44228)",
                    "url": "https://github.com/s-retlaw/l4srs"
                },
                {
                    "repository": "PoC-in-GitHub · Ananya-0306/Log-4j-scanner",
                    "author": "Ananya-0306",
                    "first_seen": "2022-02-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228",
                    "summary": "A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228",
                    "url": "https://github.com/Ananya-0306/Log-4j-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · paulvkitor/log4shellwithlog4j2_13_3",
                    "author": "paulvkitor",
                    "first_seen": "2022-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Springboot web application accepts a name get parameter and logs its value to log4j2.  Vulnerable to CVE-2021-44228.",
                    "summary": "Springboot web application accepts a name get parameter and logs its value to log4j2.  Vulnerable to CVE-2021-44228.",
                    "url": "https://github.com/paulvkitor/log4shellwithlog4j2_13_3"
                },
                {
                    "repository": "PoC-in-GitHub · MiguelM001/vulescanjndilookup",
                    "author": "MiguelM001",
                    "first_seen": "2022-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "HERRAMIENTA AUTOMATIZADA PARA LA DETECCION DE LA VULNERABILIDAD CVE-2021-44228",
                    "summary": "HERRAMIENTA AUTOMATIZADA PARA LA DETECCION DE LA VULNERABILIDAD CVE-2021-44228",
                    "url": "https://github.com/MiguelM001/vulescanjndilookup"
                },
                {
                    "repository": "PoC-in-GitHub · Jun-5heng/CVE-2021-44228",
                    "author": "Jun-5heng",
                    "first_seen": "2022-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4j2组件命令执行RCE / Code By:Jun_sheng",
                    "summary": "Log4j2组件命令执行RCE / Code By:Jun_sheng",
                    "url": "https://github.com/Jun-5heng/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · vulnerable-apps/log4shell-honeypot",
                    "author": "vulnerable-apps",
                    "first_seen": "2022-04-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Java application vulnerable to the CVE-2021-44228 (a.k.a log4shell) vulnerability",
                    "summary": "Java application vulnerable to the CVE-2021-44228 (a.k.a log4shell) vulnerability",
                    "url": "https://github.com/vulnerable-apps/log4shell-honeypot"
                },
                {
                    "repository": "PoC-in-GitHub · manishkanyal/log4j-scanner",
                    "author": "manishkanyal",
                    "first_seen": "2022-04-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A Log4j vulnerability scanner is used to identify the CVE-2021-44228 and CVE_2021_45046",
                    "summary": "A Log4j vulnerability scanner is used to identify the CVE-2021-44228 and CVE_2021_45046",
                    "url": "https://github.com/manishkanyal/log4j-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · TPower2112/Writing-Sample-1",
                    "author": "TPower2112",
                    "first_seen": "2022-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228 Log4j Summary",
                    "summary": "CVE-2021-44228 Log4j Summary",
                    "url": "https://github.com/TPower2112/Writing-Sample-1"
                },
                {
                    "repository": "PoC-in-GitHub · Willian-2-0-0-1/Log4j-Exploit-CVE-2021-44228",
                    "author": "Willian-2-0-0-1",
                    "first_seen": "2022-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/Willian-2-0-0-1/Log4j-Exploit-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · r3kind1e/Log4Shell-obfuscated-payloads-generator",
                    "author": "r3kind1e",
                    "first_seen": "2022-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "Generate primary obfuscated or secondary obfuscated CVE-2021-44228 or CVE-2021-45046 payloads to evade WAF detection.",
                    "summary": "Generate primary obfuscated or secondary obfuscated CVE-2021-44228 or CVE-2021-45046 payloads to evade WAF detection.",
                    "url": "https://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generator"
                },
                {
                    "repository": "PoC-in-GitHub · Phineas09/CVE-2021-44228",
                    "author": "Phineas09",
                    "first_seen": "2022-05-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell Proof-Of-Concept derived from https://github.com/kozmer/log4j-shell-poc",
                    "summary": "Log4Shell Proof-Of-Concept derived from https://github.com/kozmer/log4j-shell-poc",
                    "url": "https://github.com/Phineas09/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · hassaanahmad813/log4j",
                    "author": "hassaanahmad813",
                    "first_seen": "2022-05-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 vulnerability in Apache Log4j library",
                    "summary": "CVE-2021-44228 vulnerability in Apache Log4j library",
                    "url": "https://github.com/hassaanahmad813/log4j"
                },
                {
                    "repository": "PoC-in-GitHub · yuuki1967/CVE-2021-44228-Apache-Log4j-Rce",
                    "author": "yuuki1967",
                    "first_seen": "2022-05-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/yuuki1967/CVE-2021-44228-Apache-Log4j-Rce"
                },
                {
                    "repository": "PoC-in-GitHub · moshuum/tf-log4j-aws-poc",
                    "author": "moshuum",
                    "first_seen": "2022-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This project files demostrate a proof-of-concept of log4j vulnerability (CVE-2021-44228) on AWS using Terraform Infrastructure-as-a-code means.",
                    "summary": "This project files demostrate a proof-of-concept of log4j vulnerability (CVE-2021-44228) on AWS using Terraform Infrastructure-as-a-code means.",
                    "url": "https://github.com/moshuum/tf-log4j-aws-poc"
                },
                {
                    "repository": "PoC-in-GitHub · jaehnri/CVE-2021-44228",
                    "author": "jaehnri",
                    "first_seen": "2022-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Proof of concept of the Log4Shell vulnerability (CVE-2021-44228)",
                    "summary": "Proof of concept of the Log4Shell vulnerability (CVE-2021-44228)",
                    "url": "https://github.com/jaehnri/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · ra890927/Log4Shell-CVE-2021-44228-Demo",
                    "author": "ra890927",
                    "first_seen": "2022-06-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell CVE-2021-44228 Demo",
                    "summary": "Log4Shell CVE-2021-44228 Demo",
                    "url": "https://github.com/ra890927/Log4Shell-CVE-2021-44228-Demo"
                },
                {
                    "repository": "PoC-in-GitHub · vino-theva/CVE-2021-44228",
                    "author": "vino-theva",
                    "first_seen": "2022-08-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Apache Log4j is a logging tool written in Java. This paper focuses on what is Log4j and log4shell  vulnerability and how it works, how it affects the victim, and  how can this be mitigated",
                    "summary": "Apache Log4j is a logging tool written in Java. This paper focuses on what is Log4j and log4shell  vulnerability and how it works, how it affects the victim, and  how can this be mitigated",
                    "url": "https://github.com/vino-theva/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · tharindudh/tharindudh-Log4j-Vulnerability-in-Ghidra-tool-CVE-2021-44228",
                    "author": "tharindudh",
                    "first_seen": "2022-08-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/tharindudh/tharindudh-Log4j-Vulnerability-in-Ghidra-tool-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · eurogig/jankybank",
                    "author": "eurogig",
                    "first_seen": "2022-08-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Simple Java Front and Back end with bad log4j version featuring CVE-2021-44228",
                    "summary": "Simple Java Front and Back end with bad log4j version featuring CVE-2021-44228",
                    "url": "https://github.com/eurogig/jankybank"
                },
                {
                    "repository": "PoC-in-GitHub · digital-dev/Log4j-CVE-2021-44228-Remediation",
                    "author": "digital-dev",
                    "first_seen": "2022-09-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple machines and run remotely as a job on all or only affected devices.",
                    "summary": "This powershell script is intended to be used by anyone looking to remediate the Log4j Vulnerability within their environment. It can target multiple machines and run remotely as a job on all or only affected devices.",
                    "url": "https://github.com/digital-dev/Log4j-CVE-2021-44228-Remediation"
                },
                {
                    "repository": "PoC-in-GitHub · ocastel/log4j-shell-poc",
                    "author": "ocastel",
                    "first_seen": "2022-09-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A Proof-Of-Concept for the CVE-2021-44228 vulnerability.",
                    "summary": "A Proof-Of-Concept for the CVE-2021-44228 vulnerability.",
                    "url": "https://github.com/ocastel/log4j-shell-poc"
                },
                {
                    "repository": "PoC-in-GitHub · bcdunbar/CVE-2021-44228-poc",
                    "author": "bcdunbar",
                    "first_seen": "2022-09-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228 POC / Example",
                    "summary": "CVE-2021-44228 POC / Example",
                    "url": "https://github.com/bcdunbar/CVE-2021-44228-poc"
                },
                {
                    "repository": "PoC-in-GitHub · srcporter/CVE-2021-44228",
                    "author": "srcporter",
                    "first_seen": "2022-11-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "DO NOT USE FOR ANYTHING REAL. Simple springboot sample app with vulnerability CVE-2021-44228 aka \"Log4Shell\"",
                    "summary": "DO NOT USE FOR ANYTHING REAL. Simple springboot sample app with vulnerability CVE-2021-44228 aka \"Log4Shell\"",
                    "url": "https://github.com/srcporter/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · sqsec/log4j2_CVE-2021-44228",
                    "author": "sqsec",
                    "first_seen": "2022-12-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/sqsec/log4j2_CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · demining/Log4j-Vulnerability",
                    "author": "demining",
                    "first_seen": "2023-01-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Vulnerability CVE-2021-44228 allows remote code execution without authentication for several versions of Apache Log4j2 (Log4Shell). Attackers can exploit vulnerable servers by connecting over any protocol, such as HTTPS, and sending a specially crafted string.",
                    "summary": "Vulnerability CVE-2021-44228 allows remote code execution without authentication for several versions of Apache Log4j2 (Log4Shell). Attackers can exploit vulnerable servers by connecting over any protocol, such as HTTPS, and sending a specially crafted string.",
                    "url": "https://github.com/demining/Log4j-Vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · pierpaolosestito-dev/Log4Shell-CVE-2021-44228-PoC",
                    "author": "pierpaolosestito-dev",
                    "first_seen": "2023-02-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.",
                    "summary": "CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.",
                    "url": "https://github.com/pierpaolosestito-dev/Log4Shell-CVE-2021-44228-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · Sumitpathania03/LOG4J-CVE-2021-44228",
                    "author": "Sumitpathania03",
                    "first_seen": "2023-02-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/Sumitpathania03/LOG4J-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · Sma-Das/Log4j-PoC",
                    "author": "Sma-Das",
                    "first_seen": "2023-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "An educational Proof of Concept for the Log4j Vulnerability (CVE-2021-44228) in Minecraft",
                    "summary": "An educational Proof of Concept for the Log4j Vulnerability (CVE-2021-44228) in Minecraft",
                    "url": "https://github.com/Sma-Das/Log4j-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · 53buahapel/log4shell-vulnweb",
                    "author": "53buahapel",
                    "first_seen": "2023-03-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "this web is vulnerable against CVE-2021-44228",
                    "summary": "this web is vulnerable against CVE-2021-44228",
                    "url": "https://github.com/53buahapel/log4shell-vulnweb"
                },
                {
                    "repository": "PoC-in-GitHub · demonrvm/Log4ShellRemediation",
                    "author": "demonrvm",
                    "first_seen": "2023-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A vulnerable Spring Boot application that uses log4j and is vulnerable to CVE-2021-44228, CVE-2021-44832, CVE-2021-45046 and CVE-2021-45105",
                    "summary": "A vulnerable Spring Boot application that uses log4j and is vulnerable to CVE-2021-44228, CVE-2021-44832, CVE-2021-45046 and CVE-2021-45105",
                    "url": "https://github.com/demonrvm/Log4ShellRemediation"
                },
                {
                    "repository": "PoC-in-GitHub · funcid/log4j-exploit-fork-bomb",
                    "author": "funcid",
                    "first_seen": "2023-04-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "💣💥💀 Proof of Concept: пример запуска fork-бомбы на удаленном сервере благодаря уязвимости CVE-2021-44228",
                    "summary": "💣💥💀 Proof of Concept: пример запуска fork-бомбы на удаленном сервере благодаря уязвимости CVE-2021-44228",
                    "url": "https://github.com/funcid/log4j-exploit-fork-bomb"
                },
                {
                    "repository": "PoC-in-GitHub · MrHarshvardhan/PY-Log4j-RCE-Scanner",
                    "author": "MrHarshvardhan",
                    "first_seen": "2023-06-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.",
                    "summary": "Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.",
                    "url": "https://github.com/MrHarshvardhan/PY-Log4j-RCE-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · Muhammad-Ali007/Log4j_CVE-2021-44228",
                    "author": "Muhammad-Ali007",
                    "first_seen": "2023-07-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/Muhammad-Ali007/Log4j_CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · Tai-e/CVE-2021-44228",
                    "author": "Tai-e",
                    "first_seen": "2023-10-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability",
                    "summary": "Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability",
                    "url": "https://github.com/Tai-e/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · roshanshibu/Odysseus",
                    "author": "roshanshibu",
                    "first_seen": "2023-10-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A demo of the Log4Shell (CVE-2021-44228) vulnerability.",
                    "summary": "A demo of the Log4Shell (CVE-2021-44228) vulnerability.",
                    "url": "https://github.com/roshanshibu/Odysseus"
                },
                {
                    "repository": "PoC-in-GitHub · LucasPDiniz/CVE-2021-44228",
                    "author": "LucasPDiniz",
                    "first_seen": "2023-11-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4j Vulnerability RCE - CVE-2021-44228",
                    "summary": "Log4j Vulnerability RCE - CVE-2021-44228",
                    "url": "https://github.com/LucasPDiniz/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · felixslama/log4shell-minecraft-demo",
                    "author": "felixslama",
                    "first_seen": "2023-11-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell (CVE-2021-44228) minecraft demo. Used for education fairs",
                    "summary": "Log4Shell (CVE-2021-44228) minecraft demo. Used for education fairs",
                    "url": "https://github.com/felixslama/log4shell-minecraft-demo"
                },
                {
                    "repository": "PoC-in-GitHub · ShlomiRex/log4shell_lab",
                    "author": "ShlomiRex",
                    "first_seen": "2023-11-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228",
                    "summary": "CVE-2021-44228",
                    "url": "https://github.com/ShlomiRex/log4shell_lab"
                },
                {
                    "repository": "PoC-in-GitHub · dcm2406/CVE-Lab",
                    "author": "dcm2406",
                    "first_seen": "2023-12-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Instructions for exploiting vulnerabilities CVE-2021-44228 and CVE-2023-46604",
                    "summary": "Instructions for exploiting vulnerabilities CVE-2021-44228 and CVE-2023-46604",
                    "url": "https://github.com/dcm2406/CVE-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · scabench/l4j-tp1",
                    "author": "scabench",
                    "first_seen": "2023-12-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "jee web project with log4shell (CVE-2021-44228) vulnerability",
                    "summary": "jee web project with log4shell (CVE-2021-44228) vulnerability",
                    "url": "https://github.com/scabench/l4j-tp1"
                },
                {
                    "repository": "PoC-in-GitHub · scabench/l4j-fp1",
                    "author": "scabench",
                    "first_seen": "2023-12-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "jee web project with sanitised log4shell (CVE-2021-44228) vulnerability",
                    "summary": "jee web project with sanitised log4shell (CVE-2021-44228) vulnerability",
                    "url": "https://github.com/scabench/l4j-fp1"
                },
                {
                    "repository": "PoC-in-GitHub · KtokKawu/l4s-vulnapp",
                    "author": "KtokKawu",
                    "first_seen": "2024-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is a potentially vulnerable Java web application containing Log4j affected by log4shell(CVE-2021-44228).",
                    "summary": "This is a potentially vulnerable Java web application containing Log4j affected by log4shell(CVE-2021-44228).",
                    "url": "https://github.com/KtokKawu/l4s-vulnapp"
                },
                {
                    "repository": "PoC-in-GitHub · sec13b/CVE-2021-44228-POC",
                    "author": "sec13b",
                    "first_seen": "2024-03-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "exploit CVE-2021-44228",
                    "summary": "exploit CVE-2021-44228",
                    "url": "https://github.com/sec13b/CVE-2021-44228-POC"
                },
                {
                    "repository": "PoC-in-GitHub · KirkDJohnson/Wireshark",
                    "author": "KirkDJohnson",
                    "first_seen": "2024-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using the Log4J vulnerability (CVE-2021-44228). I examined teh amount of endpoints communicating with the server and knowing jnidi as a common in the vulnerbilty found it in clear text",
                    "summary": "Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using the Log4J vulnerability (CVE-2021-44228). I examined teh amount of endpoints communicating with the server and knowing jnidi as a common in the vulnerbilty found it in clear text",
                    "url": "https://github.com/KirkDJohnson/Wireshark"
                },
                {
                    "repository": "PoC-in-GitHub · YangHyperData/LOGJ4_PocShell_CVE-2021-44228",
                    "author": "YangHyperData",
                    "first_seen": "2024-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/YangHyperData/LOGJ4_PocShell_CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · Hoanle396/CVE-2021-44228-demo",
                    "author": "Hoanle396",
                    "first_seen": "2024-05-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/Hoanle396/CVE-2021-44228-demo"
                },
                {
                    "repository": "PoC-in-GitHub · NikitaPark/Log4Shell-PoC-Application",
                    "author": "NikitaPark",
                    "first_seen": "2024-05-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell (CVE-2021-44228) PoC Application",
                    "summary": "Log4Shell (CVE-2021-44228) PoC Application",
                    "url": "https://github.com/NikitaPark/Log4Shell-PoC-Application"
                },
                {
                    "repository": "PoC-in-GitHub · tadash10/Exploiting-CVE-2021-44228-Log4Shell-in-a-Banking-Environment",
                    "author": "tadash10",
                    "first_seen": "2024-06-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.",
                    "summary": "Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.",
                    "url": "https://github.com/tadash10/Exploiting-CVE-2021-44228-Log4Shell-in-a-Banking-Environment"
                },
                {
                    "repository": "PoC-in-GitHub · asd58584388/CVE-2021-44228",
                    "author": "asd58584388",
                    "first_seen": "2024-07-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 vulnerability study",
                    "summary": "CVE-2021-44228 vulnerability study",
                    "url": "https://github.com/asd58584388/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · OtisSymbos/CVE-2021-44228-Log4Shell-",
                    "author": "OtisSymbos",
                    "first_seen": "2024-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/OtisSymbos/CVE-2021-44228-Log4Shell-"
                },
                {
                    "repository": "PoC-in-GitHub · safeer-accuknox/log4j-shell-poc",
                    "author": "safeer-accuknox",
                    "first_seen": "2024-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4J exploit CVE-2021-44228",
                    "summary": "Log4J exploit CVE-2021-44228",
                    "url": "https://github.com/safeer-accuknox/log4j-shell-poc"
                },
                {
                    "repository": "PoC-in-GitHub · Carlos-Mesquita/TPASLog4ShellPoC",
                    "author": "Carlos-Mesquita",
                    "first_seen": "2024-10-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's degree in Information Security at FCUP.",
                    "summary": "Proof of Concept for the Log4Shell vulnerability (CVE-2021-44228), developed as part of the coursework for the curricular unit TPAS in the Master's degree in Information Security at FCUP.",
                    "url": "https://github.com/Carlos-Mesquita/TPASLog4ShellPoC"
                },
                {
                    "repository": "PoC-in-GitHub · AhmedMansour93/-Unveiling-the-Lessons-from-Log4Shell-A-Wake-Up-Call-for-Cybersecurity-",
                    "author": "AhmedMansour93",
                    "first_seen": "2024-11-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "In December 2021, the world of cybersecurity was shaken by the discovery of the Log4Shell vulnerability (CVE-2021-44228), embedded within the widely-used Apache Log4j library. With a CVSS score of 10",
                    "summary": "In December 2021, the world of cybersecurity was shaken by the discovery of the Log4Shell vulnerability (CVE-2021-44228), embedded within the widely-used Apache Log4j library. With a CVSS score of 10",
                    "url": "https://github.com/AhmedMansour93/-Unveiling-the-Lessons-from-Log4Shell-A-Wake-Up-Call-for-Cybersecurity-"
                },
                {
                    "repository": "PoC-in-GitHub · Super-Binary/cve-2021-44228",
                    "author": "Super-Binary",
                    "first_seen": "2024-11-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "这是安徽大学 “漏洞分析实验”（大三秋冬）期中作业归档。完整文档位于https://testgames.me/2024/11/10/cve-2021-44228/",
                    "summary": "这是安徽大学 “漏洞分析实验”（大三秋冬）期中作业归档。完整文档位于https://testgames.me/2024/11/10/cve-2021-44228/",
                    "url": "https://github.com/Super-Binary/cve-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · ZacharyZcR/CVE-2021-44228",
                    "author": "ZacharyZcR",
                    "first_seen": "2025-01-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "调试环境",
                    "summary": "调试环境",
                    "url": "https://github.com/ZacharyZcR/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · qw3rtyou/CVE-2021-44228_dockernize",
                    "author": "qw3rtyou",
                    "first_seen": "2025-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/qw3rtyou/CVE-2021-44228_dockernize"
                },
                {
                    "repository": "PoC-in-GitHub · yadavmukesh/Log4Shell-vulnerability-CVE-2021-44228-",
                    "author": "yadavmukesh",
                    "first_seen": "2025-02-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository provides an in-depth analysis of the Log4Shell vulnerability (CVE-2021-44228) and implements a machine learning-based approach to detect exploitation attempts in log data.",
                    "summary": "This repository provides an in-depth analysis of the Log4Shell vulnerability (CVE-2021-44228) and implements a machine learning-based approach to detect exploitation attempts in log data.",
                    "url": "https://github.com/yadavmukesh/Log4Shell-vulnerability-CVE-2021-44228-"
                },
                {
                    "repository": "PoC-in-GitHub · tpdlshdmlrkfmcla/Log4shell",
                    "author": "tpdlshdmlrkfmcla",
                    "first_seen": "2025-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228",
                    "summary": "CVE-2021-44228",
                    "url": "https://github.com/tpdlshdmlrkfmcla/Log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · timothyjxhn/DeliberatelyVulnerableWebApp",
                    "author": "timothyjxhn",
                    "first_seen": "2025-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.",
                    "summary": "A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.",
                    "url": "https://github.com/timothyjxhn/DeliberatelyVulnerableWebApp"
                },
                {
                    "repository": "PoC-in-GitHub · khaidtraivch/CVE-2021-44228-Log4Shell-",
                    "author": "khaidtraivch",
                    "first_seen": "2025-04-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Kiểm thử xâm nhập",
                    "summary": "Kiểm thử xâm nhập",
                    "url": "https://github.com/khaidtraivch/CVE-2021-44228-Log4Shell-"
                },
                {
                    "repository": "PoC-in-GitHub · Fauzan-Aldi/Log4j-_Vulnerability",
                    "author": "Fauzan-Aldi",
                    "first_seen": "2025-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "The Web Is Vulnerable to CVE-2021-44228",
                    "summary": "The Web Is Vulnerable to CVE-2021-44228",
                    "url": "https://github.com/Fauzan-Aldi/Log4j-_Vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · SerpilRivas/log4shell-homework9",
                    "author": "SerpilRivas",
                    "first_seen": "2025-05-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell (CVE-2021-44228) exploit demo for SEAS 8405. Includes a vulnerable Spring Boot app, fake LDAP server, Docker setup, MITRE mapping, incident response, and a full screen recording.",
                    "summary": "Log4Shell (CVE-2021-44228) exploit demo for SEAS 8405. Includes a vulnerable Spring Boot app, fake LDAP server, Docker setup, MITRE mapping, incident response, and a full screen recording.",
                    "url": "https://github.com/SerpilRivas/log4shell-homework9"
                },
                {
                    "repository": "PoC-in-GitHub · x1ongsec/CVE-2021-44228-Log4j-JNDI",
                    "author": "x1ongsec",
                    "first_seen": "2025-06-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 Vulnerability Reproduction Environment CVE-2021-44228 漏洞复现环境",
                    "summary": "CVE-2021-44228 Vulnerability Reproduction Environment CVE-2021-44228 漏洞复现环境",
                    "url": "https://github.com/x1ongsec/CVE-2021-44228-Log4j-JNDI"
                },
                {
                    "repository": "PoC-in-GitHub · fabioeletto/hka-seminar-log4shell",
                    "author": "fabioeletto",
                    "first_seen": "2025-07-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Praktische Demonstration der Log4Shell-Sicherheitslücke (CVE-2021-44228)",
                    "summary": "Praktische Demonstration der Log4Shell-Sicherheitslücke (CVE-2021-44228)",
                    "url": "https://github.com/fabioeletto/hka-seminar-log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · cuijiung/log4j-CVE-2021-44228",
                    "author": "cuijiung",
                    "first_seen": "2025-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/cuijiung/log4j-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · Sorrence/CVE-2021-44228",
                    "author": "Sorrence",
                    "first_seen": "2025-08-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A simple Log4j PoC written in Go",
                    "summary": "A simple Log4j PoC written in Go",
                    "url": "https://github.com/Sorrence/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · moften/Log4Shell",
                    "author": "moften",
                    "first_seen": "2025-09-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell CVE-2021-44228 PoC",
                    "summary": "Log4Shell CVE-2021-44228 PoC",
                    "url": "https://github.com/moften/Log4Shell"
                },
                {
                    "repository": "PoC-in-GitHub · KamalideenAK/Microsoft-Defender-for-Endpoint-Deployment-on-Windows-10-11-device",
                    "author": "KamalideenAK",
                    "first_seen": "2025-09-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling device discovery, configuring Log4j2 detection (CVE-2021-44228), and validating incident response workflows.",
                    "summary": "This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling device discovery, configuring Log4j2 detection (CVE-2021-44228), and validating incident response workflows.",
                    "url": "https://github.com/KamalideenAK/Microsoft-Defender-for-Endpoint-Deployment-on-Windows-10-11-device"
                },
                {
                    "repository": "PoC-in-GitHub · arabindadora/log4shell",
                    "author": "arabindadora",
                    "first_seen": "2025-09-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell (CVE-2021-44228) PoC",
                    "summary": "Log4Shell (CVE-2021-44228) PoC",
                    "url": "https://github.com/arabindadora/log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · Mintimate/log4j2-bugmaker",
                    "author": "Mintimate",
                    "first_seen": "2025-10-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Demo of CVE-2021-44228 Log4Shell.",
                    "summary": "Demo of CVE-2021-44228 Log4Shell.",
                    "url": "https://github.com/Mintimate/log4j2-bugmaker"
                },
                {
                    "repository": "PoC-in-GitHub · mgueye3/Log4Shell",
                    "author": "mgueye3",
                    "first_seen": "2025-11-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository contains my work for a cybersecurity assignment where I exploited the real-world Log4Shell (CVE-2021-44228) vulnerability inside a safe, controlled virtual machine. The project followed a Capture-the-Flag format with multiple exploitation tasks to retrieve hidden flags.",
                    "summary": "This repository contains my work for a cybersecurity assignment where I exploited the real-world Log4Shell (CVE-2021-44228) vulnerability inside a safe, controlled virtual machine. The project followed a Capture-the-Flag format with multiple exploitation tasks to retrieve hidden flags.",
                    "url": "https://github.com/mgueye3/Log4Shell"
                },
                {
                    "repository": "PoC-in-GitHub · PCMKUIT/CVE-2021-44228---Log4Shell-Analysis",
                    "author": "PCMKUIT",
                    "first_seen": "2025-11-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Technical deep dive into Apache Log4j2 JNDI injection vulnerability. Features static code analysis, patch comparison, attack vectors (LDAP/RMI/DNS), and enterprise mitigation guidance.",
                    "summary": "Technical deep dive into Apache Log4j2 JNDI injection vulnerability. Features static code analysis, patch comparison, attack vectors (LDAP/RMI/DNS), and enterprise mitigation guidance.",
                    "url": "https://github.com/PCMKUIT/CVE-2021-44228---Log4Shell-Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · DrHaitham/Log4Shell-CVE-2021-44228",
                    "author": "DrHaitham",
                    "first_seen": "2025-12-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and defensive training in controlled lab environments only.",
                    "summary": "Hands-on lab for exploiting and understanding Log4Shell (CVE-2021-44228) using Docker, Kali Linux, Burp Suite and log4j-shell-poc. For teaching and defensive training in controlled lab environments only.",
                    "url": "https://github.com/DrHaitham/Log4Shell-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · Loliverte/Log4j-Vulnerability",
                    "author": "Loliverte",
                    "first_seen": "2025-12-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Étude technique et mise en œuvre d'un environnement de test pour la faille Apache Log4j (CVE-2021-44228). Contient un Proof of Concept (PoC) Dockerisé et une proposition de mise à jour de PSSI. Pour un objectif de TP",
                    "summary": "Étude technique et mise en œuvre d'un environnement de test pour la faille Apache Log4j (CVE-2021-44228). Contient un Proof of Concept (PoC) Dockerisé et une proposition de mise à jour de PSSI. Pour un objectif de TP",
                    "url": "https://github.com/Loliverte/Log4j-Vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · JoseMariaMicoli/Log4Shell-PoC",
                    "author": "JoseMariaMicoli",
                    "first_seen": "2026-01-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized sandbox to demonstrate JNDI injection, LDAP/RMI referral redirection, and remote code execution (RCE) via the Log4j 2 library.",
                    "summary": "**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized sandbox to demonstrate JNDI injection, LDAP/RMI referral redirection, and remote code execution (RCE) via the Log4j 2 library.",
                    "url": "https://github.com/JoseMariaMicoli/Log4Shell-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · agylabs/log4shell-remediation",
                    "author": "agylabs",
                    "first_seen": "2026-02-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell (CVE-2021-44228) security remediation demo - Showcasing Antigravity's ability to identify and fix critical security vulnerabilities in Java applications",
                    "summary": "Log4Shell (CVE-2021-44228) security remediation demo - Showcasing Antigravity's ability to identify and fix critical security vulnerabilities in Java applications",
                    "url": "https://github.com/agylabs/log4shell-remediation"
                },
                {
                    "repository": "PoC-in-GitHub · 0xBlackash/CVE-2021-44228",
                    "author": "0xBlackash",
                    "first_seen": "2026-02-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228",
                    "summary": "CVE-2021-44228",
                    "url": "https://github.com/0xBlackash/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · Codepumpking/log4shell-poc",
                    "author": "Codepumpking",
                    "first_seen": "2026-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "POC for log4shll Vulnerablity (CVE-2021-44228)",
                    "summary": "POC for log4shll Vulnerablity (CVE-2021-44228)",
                    "url": "https://github.com/Codepumpking/log4shell-poc"
                },
                {
                    "repository": "PoC-in-GitHub · wmohamed2033/wmohamed2033.github.io",
                    "author": "wmohamed2033",
                    "first_seen": "2026-03-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 Log4Shell — Penetration Test Writeup",
                    "summary": "CVE-2021-44228 Log4Shell — Penetration Test Writeup",
                    "url": "https://github.com/wmohamed2033/wmohamed2033.github.io"
                },
                {
                    "repository": "PoC-in-GitHub · Saru1718/THM---Solar-exploiting-Log-4j",
                    "author": "Saru1718",
                    "first_seen": "2026-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables attackers to execute a remote code via injection of the malicious payloads into the log messages.",
                    "summary": "This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables attackers to execute a remote code via injection of the malicious payloads into the log messages.",
                    "url": "https://github.com/Saru1718/THM---Solar-exploiting-Log-4j"
                },
                {
                    "repository": "PoC-in-GitHub · lathika-3006/Solar-exploiting-log-4j",
                    "author": "lathika-3006",
                    "first_seen": "2026-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "This repository presents a comprehensive walkthrough of the Solar Exploiting Log4j room on TryHackMe, with a focus on understanding and exploiting the critical Log4Shell vulnerability (CVE-2021-44228).The process of triggering the exploit and gaining a reverse shell is explained in a practical and easy-to-follow manner.",
                    "summary": "This repository presents a comprehensive walkthrough of the Solar Exploiting Log4j room on TryHackMe, with a focus on understanding and exploiting the critical Log4Shell vulnerability (CVE-2021-44228).The process of triggering the exploit and gaining a reverse shell is explained in a practical and easy-to-follow manner.",
                    "url": "https://github.com/lathika-3006/Solar-exploiting-log-4j"
                },
                {
                    "repository": "PoC-in-GitHub · Lavanya2085/solar-exploiting-log4j",
                    "author": "Lavanya2085",
                    "first_seen": "2026-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell vulnerability (CVE-2021-44228). The project demonstrates how attackers can leverage insecure logging mechanisms in Java applications to achieve remote code execution.",
                    "summary": "This repository provides a detailed walkthrough of the *Solar Exploiting Log4j room* on TryHackMe, focusing on exploiting the critical Log4Shell vulnerability (CVE-2021-44228). The project demonstrates how attackers can leverage insecure logging mechanisms in Java applications to achieve remote code execution.",
                    "url": "https://github.com/Lavanya2085/solar-exploiting-log4j"
                },
                {
                    "repository": "PoC-in-GitHub · danieljosmariyan7254/TryHackMe-Solar-exploiting-log4j-",
                    "author": "danieljosmariyan7254",
                    "first_seen": "2026-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Explore CVE-2021-44228, a vulnerability in log4j affecting almost all software under the sun.",
                    "summary": "Explore CVE-2021-44228, a vulnerability in log4j affecting almost all software under the sun.",
                    "url": "https://github.com/danieljosmariyan7254/TryHackMe-Solar-exploiting-log4j-"
                },
                {
                    "repository": "PoC-in-GitHub · jdormannn/SecureOps-Lab",
                    "author": "jdormannn",
                    "first_seen": "2026-04-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Performed a live cybersecurity assessment on a university Linux server. During analysis, active attack activity was identified, including brute-force authentication attempts and exploitation attempts targeting Log4Shell (CVE-2021-44228).",
                    "summary": "Performed a live cybersecurity assessment on a university Linux server. During analysis, active attack activity was identified, including brute-force authentication attempts and exploitation attempts targeting Log4Shell (CVE-2021-44228).",
                    "url": "https://github.com/jdormannn/SecureOps-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · joaovicdev/EXPLOIT-CVE-2021-44228",
                    "author": "joaovicdev",
                    "first_seen": "2026-04-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC of CVE-2021-44228",
                    "summary": "PoC of CVE-2021-44228",
                    "url": "https://github.com/joaovicdev/EXPLOIT-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · pinaraltinok/Log4Shell-Attack",
                    "author": "pinaraltinok",
                    "first_seen": "2026-04-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Multi-Stage Attack Modeling and Detection of Log4Shell for CVE-2021-44228",
                    "summary": "Multi-Stage Attack Modeling and Detection of Log4Shell for CVE-2021-44228",
                    "url": "https://github.com/pinaraltinok/Log4Shell-Attack"
                },
                {
                    "repository": "PoC-in-GitHub · kaleth4/CVE-2021-44228",
                    "author": "kaleth4",
                    "first_seen": "2026-04-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/kaleth4/CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · tieupham267/log4shell-coraza",
                    "author": "tieupham267",
                    "first_seen": "2026-04-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.",
                    "summary": "Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.",
                    "url": "https://github.com/tieupham267/log4shell-coraza"
                },
                {
                    "repository": "PoC-in-GitHub · sajanapamuditha/Cyber-Attack-Simulation-",
                    "author": "sajanapamuditha",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell (CVE-2021-44228)",
                    "summary": "Log4Shell (CVE-2021-44228)",
                    "url": "https://github.com/sajanapamuditha/Cyber-Attack-Simulation-"
                },
                {
                    "repository": "PoC-in-GitHub · neilc1964techned/craready-test-java-vulns",
                    "author": "neilc1964techned",
                    "first_seen": "2026-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CRAReady SBOM test fixture — Java/Maven app with Log4Shell (CVE-2021-44228), Spring4Shell, Text4Shell, and other critical CVEs",
                    "summary": "CRAReady SBOM test fixture — Java/Maven app with Log4Shell (CVE-2021-44228), Spring4Shell, Text4Shell, and other critical CVEs",
                    "url": "https://github.com/neilc1964techned/craready-test-java-vulns"
                },
                {
                    "repository": "PoC-in-GitHub · FacundoMfernandez/pentesting-obioba",
                    "author": "FacundoMfernandez",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Pentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico",
                    "summary": "Pentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico",
                    "url": "https://github.com/FacundoMfernandez/pentesting-obioba"
                },
                {
                    "repository": "PoC-in-GitHub · vutiendat323/CVE-2021-44228_Log4Shell",
                    "author": "vutiendat323",
                    "first_seen": "2026-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/vutiendat323/CVE-2021-44228_Log4Shell"
                },
                {
                    "repository": "PoC-in-GitHub · aaronm-sysdig/log4j-vuln-demo",
                    "author": "aaronm-sysdig",
                    "first_seen": "2026-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Intentionally vulnerable Log4j 2.14.1 demo for Sysdig CNAPP scanning (CVE-2021-44228)",
                    "summary": "Intentionally vulnerable Log4j 2.14.1 demo for Sysdig CNAPP scanning (CVE-2021-44228)",
                    "url": "https://github.com/aaronm-sysdig/log4j-vuln-demo"
                },
                {
                    "repository": "PoC-in-GitHub · MAFO-sec/mi-laboratorio-log4shell",
                    "author": "MAFO-sec",
                    "first_seen": "2026-05-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Laboratorio automatizado Plug & Play en Docker para auditar y estudiar la vulnerabilidad Log4Shell (CVE-2021-44228)",
                    "summary": "Laboratorio automatizado Plug & Play en Docker para auditar y estudiar la vulnerabilidad Log4Shell (CVE-2021-44228)",
                    "url": "https://github.com/MAFO-sec/mi-laboratorio-log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · felisha-elmer/Sandbox-Challenge-Log4Shell-CVE-2021-44228-",
                    "author": "felisha-elmer",
                    "first_seen": "2026-05-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/felisha-elmer/Sandbox-Challenge-Log4Shell-CVE-2021-44228-"
                },
                {
                    "repository": "PoC-in-GitHub · jomjosh17/Log4Shell-CVE-2021-44228-",
                    "author": "jomjosh17",
                    "first_seen": "2026-05-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/jomjosh17/Log4Shell-CVE-2021-44228-"
                },
                {
                    "repository": "PoC-in-GitHub · C00LN3T/Log4ShellAuditor",
                    "author": "C00LN3T",
                    "first_seen": "2026-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and compliance reporting for CVE-2021-44228 (Log4Shell).",
                    "summary": "An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and compliance reporting for CVE-2021-44228 (Log4Shell).",
                    "url": "https://github.com/C00LN3T/Log4ShellAuditor"
                },
                {
                    "repository": "PoC-in-GitHub · bhimsekhar/vulnerable-java-app",
                    "author": "bhimsekhar",
                    "first_seen": "2026-06-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Spring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target",
                    "summary": "Spring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target",
                    "url": "https://github.com/bhimsekhar/vulnerable-java-app"
                },
                {
                    "repository": "PoC-in-GitHub · horrister/log4shell-cve-2021-44228",
                    "author": "horrister",
                    "first_seen": "2026-06-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/horrister/log4shell-cve-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · hmxh123/Log4Shell-Vulnerability-Replication",
                    "author": "hmxh123",
                    "first_seen": "2026-06-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 漏洞复现完整记录（含环境搭建、触发验证）",
                    "summary": "CVE-2021-44228 漏洞复现完整记录（含环境搭建、触发验证）",
                    "url": "https://github.com/hmxh123/Log4Shell-Vulnerability-Replication"
                },
                {
                    "repository": "PoC-in-GitHub · limxuan/ehir-vuln-enterprise-login",
                    "author": "limxuan",
                    "first_seen": "2026-06-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "webapp vulnerable to CVE-2021-44228",
                    "summary": "webapp vulnerable to CVE-2021-44228",
                    "url": "https://github.com/limxuan/ehir-vuln-enterprise-login"
                },
                {
                    "repository": "PoC-in-GitHub · DAADAISMYLIFE/log4shell-lab",
                    "author": "DAADAISMYLIFE",
                    "first_seen": "2026-06-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell (CVE-2021-44228) 보안 실습 환경 - Log4j 2.14.1 취약 로그 수집 서버",
                    "summary": "Log4Shell (CVE-2021-44228) 보안 실습 환경 - Log4j 2.14.1 취약 로그 수집 서버",
                    "url": "https://github.com/DAADAISMYLIFE/log4shell-lab"
                },
                {
                    "repository": "PoC-in-GitHub · probablysecure/Triage-CVE-2021-44228-Log4Shell-Log4j-",
                    "author": "probablysecure",
                    "first_seen": "2026-06-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Goal is to triage well known attack and learn how security teams quickly respond.",
                    "summary": "Goal is to triage well known attack and learn how security teams quickly respond.",
                    "url": "https://github.com/probablysecure/Triage-CVE-2021-44228-Log4Shell-Log4j-"
                },
                {
                    "repository": "PoC-in-GitHub · Ricardo354/homelab-CVE-2021-44228",
                    "author": "Ricardo354",
                    "first_seen": "2026-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4j Vulnerability homelab",
                    "summary": "Log4j Vulnerability homelab",
                    "url": "https://github.com/Ricardo354/homelab-CVE-2021-44228"
                },
                {
                    "repository": "PoC-in-GitHub · AstralJays/TraditionalJay",
                    "author": "AstralJays",
                    "first_seen": "2026-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Intentionally vulnerable VM-hosted Java shop — Log4Shell (CVE-2021-44228) workshop lab (EC2 / Azure VM / GCE)",
                    "summary": "Intentionally vulnerable VM-hosted Java shop — Log4Shell (CVE-2021-44228) workshop lab (EC2 / Azure VM / GCE)",
                    "url": "https://github.com/AstralJays/TraditionalJay"
                },
                {
                    "repository": "PoC-in-GitHub · prmawyer/log4shell-vulnerable-app",
                    "author": "prmawyer",
                    "first_seen": "2026-07-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).",
                    "summary": "Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).",
                    "url": "https://github.com/prmawyer/log4shell-vulnerable-app"
                },
                {
                    "repository": "PoC-in-GitHub · arpitgupta369/log4shell-scanner",
                    "author": "arpitgupta369",
                    "first_seen": "2026-07-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Lightweight scanner that detects vulnerable Log4j versions and Log4Shell (CVE-2021-44228) indicators in a filesystem tree.",
                    "summary": "Lightweight scanner that detects vulnerable Log4j versions and Log4Shell (CVE-2021-44228) indicators in a filesystem tree.",
                    "url": "https://github.com/arpitgupta369/log4shell-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · razureink/cve-2021-44228-log4shell_rce_reproduction",
                    "author": "razureink",
                    "first_seen": "2026-07-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-44228 Log4Shell - Apache Log4j2 JNDI Injection RCE",
                    "summary": "CVE-2021-44228 Log4Shell - Apache Log4j2 JNDI Injection RCE",
                    "url": "https://github.com/razureink/cve-2021-44228-log4shell_rce_reproduction"
                },
                {
                    "repository": "PoC-in-GitHub · sfr0435122531-ui/-log4shell-lab",
                    "author": "sfr0435122531-ui",
                    "first_seen": "2026-07-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Docker-based isolated proof-of-concept lab for analysing CVE-2021-44228 (Log4Shell) for the COMP6441 Security Engineering project.",
                    "summary": "Docker-based isolated proof-of-concept lab for analysing CVE-2021-44228 (Log4Shell) for the COMP6441 Security Engineering project.",
                    "url": "https://github.com/sfr0435122531-ui/-log4shell-lab"
                },
                {
                    "repository": "PoC-in-GitHub · yili-soc/vm-homelab-log4shell-assessment",
                    "author": "yili-soc",
                    "first_seen": "2026-08-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Full-lifecycle vulnerability management on a live Log4Shell (CVE-2021-44228) target — scan, manual exploitation, network detection, and remediation verification. Nessus, Suricata, Wireshark, Docker.",
                    "summary": "Full-lifecycle vulnerability management on a live Log4Shell (CVE-2021-44228) target — scan, manual exploitation, network detection, and remediation verification. Nessus, Suricata, Wireshark, Docker.",
                    "url": "https://github.com/yili-soc/vm-homelab-log4shell-assessment"
                },
                {
                    "repository": "PoC-in-GitHub · sanasimran1403-jpg/log4shell",
                    "author": "sanasimran1403-jpg",
                    "first_seen": "2026-08-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell (CVE-2021-44228) research report — technical breakdown, root cause analysis, and end-to-end lab-reproduced exploit chain with evidence screenshots.",
                    "summary": "Log4Shell (CVE-2021-44228) research report — technical breakdown, root cause analysis, and end-to-end lab-reproduced exploit chain with evidence screenshots.",
                    "url": "https://github.com/sanasimran1403-jpg/log4shell"
                },
                {
                    "repository": "PoC-in-GitHub · AhndreWalters/ProjectSecurity-Homelab",
                    "author": "AhndreWalters",
                    "first_seen": "2026-08-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Hands-on homelab simulating the Log4Shell (CVE-2021-44228) vulnerability. Deploy Docker containers to build a vulnerable target and attacker machine, execute the exploit, and implement security mitigations. Perfect for learning offensive security and application hardening.",
                    "summary": "Hands-on homelab simulating the Log4Shell (CVE-2021-44228) vulnerability. Deploy Docker containers to build a vulnerable target and attacker machine, execute the exploit, and implement security mitigations. Perfect for learning offensive security and application hardening.",
                    "url": "https://github.com/AhndreWalters/ProjectSecurity-Homelab"
                },
                {
                    "repository": "PoC-in-GitHub · Jiahong-Guan/log4j-shell-poc",
                    "author": "Jiahong-Guan",
                    "first_seen": "2026-08-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A Proof-Of-Concept for the CVE-2021-44228 vulnerability.",
                    "summary": "A Proof-Of-Concept for the CVE-2021-44228 vulnerability.",
                    "url": "https://github.com/Jiahong-Guan/log4j-shell-poc"
                },
                {
                    "repository": "PoC-in-GitHub · Vaibhav91one/log4shell-cve-lab",
                    "author": "Vaibhav91one",
                    "first_seen": "2026-08-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell CVE-2021-44228 vulnerable lab",
                    "summary": "Log4Shell CVE-2021-44228 vulnerable lab",
                    "url": "https://github.com/Vaibhav91one/log4shell-cve-lab"
                },
                {
                    "repository": "PoC-in-GitHub · 14free/log4j2-vuln-lab",
                    "author": "14free",
                    "first_seen": "2026-09-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证",
                    "summary": "CVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证",
                    "url": "https://github.com/14free/log4j2-vuln-lab"
                },
                {
                    "repository": "PoC-in-GitHub · Wafeeq-Fareed/log4shell-exploitation-lab",
                    "author": "Wafeeq-Fareed",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 Log4Shell reproduced end to end: exploitation through remediation",
                    "summary": "CVE-2021-44228 Log4Shell reproduced end to end: exploitation through remediation",
                    "url": "https://github.com/Wafeeq-Fareed/log4shell-exploitation-lab"
                },
                {
                    "repository": "PoC-in-GitHub · KalidouLabghaly/log4shell-exploitation-detection",
                    "author": "KalidouLabghaly",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Log4Shell (CVE-2021-44228) exploitation from a Kali VM against a vulnerable containerized app, with Splunk-based detection engineering and validated remediation. Covers the full attack lifecycle: exploitation, JNDI and host-level auditd detection, and before/after remediation proof.",
                    "summary": "Log4Shell (CVE-2021-44228) exploitation from a Kali VM against a vulnerable containerized app, with Splunk-based detection engineering and validated remediation. Covers the full attack lifecycle: exploitation, JNDI and host-level auditd detection, and before/after remediation proof.",
                    "url": "https://github.com/KalidouLabghaly/log4shell-exploitation-detection"
                },
                {
                    "repository": "PoC-in-GitHub · rh-rahulshetty/log4shell-CVE-2021-44228",
                    "author": "rh-rahulshetty",
                    "first_seen": "2026-09-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-44228 repository",
                    "summary": "",
                    "url": "https://github.com/rh-rahulshetty/log4shell-CVE-2021-44228"
                },
                {
                    "title": "Exploit for CVE-2021-44228-log4jVulnScanner-metasploit",
                    "summary": "Metasploit auxiliary module for scanning Log4Shell CVE-2021-44228 RCE vulnerability.",
                    "what_happened": "Metasploit auxiliary module for scanning Log4Shell CVE-2021-44228 RCE vulnerability.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TAROBALLZCHEN-CVE-2021-44228-LOG4JVULNSCANNER-METASPLOIT",
                        "https://kitploit.com/ru/tools/github/taroballzchen/cve-2021-44228-log4jvulnscanner-metasploit/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T14:53:10",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TAROBALLZCHEN-CVE-2021-44228-LOG4JVULNSCANNER-METASPLOIT"
                },
                {
                    "title": "Exploit for CVE-2021-44228-log4jVulnScanner-metasploit",
                    "summary": "Metasploit auxiliary module for scanning Log4Shell CVE-2021-44228 RCE vulnerability.",
                    "what_happened": "Metasploit auxiliary module for scanning Log4Shell CVE-2021-44228 RCE vulnerability.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TAROBALLZCHEN-CVE-2021-44228-LOG4JVULNSCANNER-METASPLOIT",
                        "https://kitploit.com/ru/tools/github/taroballzchen/cve-2021-44228-log4jvulnscanner-metasploit/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T14:53:10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/taroballzchen/cve-2021-44228-log4jvulnscanner-metasploit/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/51183",
                "https://www.exploit-db.com/exploits/50592",
                "https://www.exploit-db.com/exploits/50590",
                "https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j-Rce",
                "https://github.com/Glease/Healer",
                "https://github.com/jacobtread/L4J-Vuln-Patch",
                "https://github.com/jas502n/Log4j2-CVE-2021-44228",
                "https://github.com/HyCraftHD/Log4J-RCE-Proof-Of-Concept",
                "https://github.com/boundaryx/cloudrasp-log4j2",
                "https://github.com/dbgee/CVE-2021-44228",
                "https://github.com/CreeperHost/Log4jPatcher",
                "https://github.com/DragonSurvivalEU/RCE",
                "https://github.com/simonis/Log4jPatch",
                "https://github.com/zlepper/CVE-2021-44228-Test-Server",
                "https://github.com/christophetd/log4shell-vulnerable-app",
                "https://github.com/NorthwaveSecurity/log4jcheck",
                "https://github.com/nkoneko/VictimApp",
                "https://github.com/lhotari/pulsar-docker-images-patch-CVE-2021-44228",
                "https://github.com/1in9e/Apache-Log4j2-RCE",
                "https://github.com/KosmX/CVE-2021-44228-example",
                "https://github.com/greymd/CVE-2021-44228",
                "https://github.com/mubix/CVE-2021-44228-Log4Shell-Hashes",
                "https://github.com/OopsieWoopsie/mc-log4j-patcher",
                "https://github.com/wheezysec/CVE-2021-44228-kusto",
                "https://github.com/izzyacademy/log4shell-mitigation",
                "https://github.com/Kadantte/CVE-2021-44228-poc",
                "https://github.com/takito1812/log4j-detect",
                "https://github.com/winnpixie/log4noshell",
                "https://github.com/Azeemering/CVE-2021-44228-DFIR-Notes",
                "https://github.com/Puliczek/CVE-2021-44228-PoC-log4j-bypass-words",
                "https://github.com/kozmer/log4j-shell-poc",
                "https://github.com/alexandreroman/cve-2021-44228-workaround-buildpack",
                "https://github.com/Adikso/minecraft-log4j-honeypot",
                "https://github.com/racoon-rac/CVE-2021-44228",
                "https://github.com/TheArqsz/CVE-2021-44228-PoC",
                "https://github.com/1lann/log4shelldetect",
                "https://github.com/binganao/Log4j2-RCE",
                "https://github.com/phoswald/sample-ldap-exploit",
                "https://github.com/rakutentech/jndi-ldap-test-server",
                "https://github.com/uint0/cve-2021-44228--spring-hibernate",
                "https://github.com/saharNooby/log4j-vulnerability-patcher-agent",
                "https://github.com/f0ng/log4j2burpscanner",
                "https://github.com/M1ngGod/CVE-2021-44228-Log4j-lookup-Rce",
                "https://github.com/byteboycn/CVE-2021-44228-Apache-Log4j-Rce",
                "https://github.com/lhotari/log4shell-mitigation-tester",
                "https://github.com/toramanemre/log4j-rce-detect-waf-bypass",
                "https://github.com/logpresso/CVE-2021-44228-Scanner",
                "https://github.com/vorburger/Log4j_CVE-2021-44228",
                "https://github.com/gauthamg/log4j2021_vul_test",
                "https://github.com/b-abderrahmane/CVE-2021-44228-playground",
                "https://github.com/leetxyz/CVE-2021-44228-Advisories",
                "https://github.com/cado-security/log4shell",
                "https://github.com/WYSIIWYG/Log4J_0day_RCE",
                "https://github.com/mkhazamipour/log4j-vulnerable-app-cve-2021-44228-terraform",
                "https://github.com/Sh0ckFR/log4j-CVE-2021-44228-Public-IoCs",
                "https://github.com/zzzz0317/log4j2-vulnerable-spring-app",
                "https://github.com/datadavev/test-44228",
                "https://github.com/LemonCraftRu/JndiRemover",
                "https://github.com/zhangxvx/Log4j-Rec-CVE-2021-44228",
                "https://github.com/darkarnium/Log4j-CVE-Detect",
                "https://github.com/chilliwebs/CVE-2021-44228_Example",
                "https://github.com/irgoncalves/f5-waf-enforce-sig-CVE-2021-44228",
                "https://github.com/jeffbryner/log4j-docker-vaccine",
                "https://github.com/mergebase/log4j-detector",
                "https://github.com/unlimitedsola/log4j2-rce-poc",
                "https://github.com/Jeromeyoung/log4j2burpscanner",
                "https://github.com/corretto/hotpatch-for-apache-log4j2",
                "https://github.com/alexandre-lavoie/python-log4rce",
                "https://github.com/RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs",
                "https://github.com/mzlogin/CVE-2021-44228-Demo",
                "https://github.com/blake-fm/vcenter-log4j",
                "https://github.com/uint0/cve-2021-44228-helpers",
                "https://github.com/sud0x00/log4j-CVE-2021-44228",
                "https://github.com/DiCanio/CVE-2021-44228-docker-example",
                "https://github.com/mrlnstk/cve-2021-44228-minecraft-poc",
                "https://github.com/RrUZi/Awesome-CVE-2021-44228",
                "https://github.com/future-client/CVE-2021-44228",
                "https://github.com/CodeShield-Security/Log4JShell-Bytecode-Detector",
                "https://github.com/Crane-Mocker/log4j-poc",
                "https://github.com/dtact/divd-2021-00038--log4j-scanner",
                "https://github.com/kali-dass/CVE-2021-44228-log4Shell",
                "https://github.com/pravin-pp/log4j2-CVE-2021-44228",
                "https://github.com/Malwar3Ninja/Exploitation-of-Log4j2-CVE-2021-44228",
                "https://github.com/urholaukkarinen/docker-log4shell",
                "https://github.com/ssl/scan4log4j",
                "https://github.com/infiniroot/nginx-mitigate-log4shell",
                "https://github.com/lohanichaten/log4j-cve-2021-44228",
                "https://github.com/authomize/log4j-log4shell-affected",
                "https://github.com/guardicode/CVE-2021-44228_IoCs",
                "https://github.com/fireflyingup/log4j-poc",
                "https://github.com/qingtengyun/cve-2021-44228-qingteng-patch",
                "https://github.com/nccgroup/log4j-jndi-be-gone",
                "https://github.com/qingtengyun/cve-2021-44228-qingteng-online-patch",
                "https://github.com/tasooshi/horrors-log4shell",
                "https://github.com/Hydragyrum/evil-rmi-server",
                "https://github.com/twseptian/spring-boot-log4j-cve-2021-44228-docker-lab",
                "https://github.com/OlafHaalstra/log4jcheck",
                "https://github.com/Panyaprach/Prove-CVE-2021-44228",
                "https://github.com/momos1337/Log4j-RCE",
                "https://github.com/cyberxml/log4j-poc",
                "https://github.com/corneacristian/Log4J-CVE-2021-44228-RCE",
                "https://github.com/Diverto/nse-log4shell",
                "https://github.com/dotPY-hax/log4py",
                "https://github.com/sunnyvale-it/CVE-2021-44228-PoC",
                "https://github.com/maxant/log4j2-CVE-2021-44228",
                "https://github.com/atnetws/fail2ban-log4j",
                "https://github.com/kimobu/cve-2021-44228",
                "https://github.com/ph0lk3r/anti-jndi",
                "https://github.com/bigsizeme/Log4j-check",
                "https://github.com/pedrohavay/exploit-CVE-2021-44228",
                "https://github.com/fireeye/CVE-2021-44228",
                "https://github.com/fullhunt/log4j-scan",
                "https://github.com/rubo77/log4j_checker_beta",
                "https://github.com/thecyberneh/Log4j-RCE-Exploiter",
                "https://github.com/halibobor/log4j2",
                "https://github.com/sourcegraph/log4j-cve-code-search-resources",
                "https://github.com/thedevappsecguy/Log4J-Mitigation-CVE-2021-44228--CVE-2021-45046--CVE-2021-45105--CVE-2021-44832",
                "https://github.com/helsecert/CVE-2021-44228",
                "https://github.com/markuman/aws-log4j-mitigations",
                "https://github.com/tuyenee/Log4shell",
                "https://github.com/JiuBanSec/Log4j-CVE-2021-44228",
                "https://github.com/ycdxsb/Log4Shell-CVE-2021-44228-ENV",
                "https://github.com/avwolferen/Sitecore.Solr-log4j-mitigation",
                "https://github.com/george-petrakis/log4j-scanner-CVE-2021-44228",
                "https://github.com/Camphul/log4shell-spring-framework-research",
                "https://github.com/lov3r/cve-2021-44228-log4j-exploits",
                "https://github.com/sinakeshmiri/log4jScan",
                "https://github.com/0xDexter0us/Log4J-Scanner",
                "https://github.com/LutziGoz/Log4J_Exploitation-Vulnerabiliy__CVE-2021-44228",
                "https://github.com/0xsyr0/Log4Shell",
                "https://github.com/1hakusai1/log4j-rce-CVE-2021-44228",
                "https://github.com/jeffli1024/log4j-rce-test",
                "https://github.com/zsolt-halo/Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service",
                "https://github.com/manuel-alvarez-alvarez/log4j-cve-2021-44228",
                "https://github.com/VNYui/CVE-2021-44228",
                "https://github.com/justakazh/Log4j-CVE-2021-44228",
                "https://github.com/irgoncalves/f5-waf-quick-patch-cve-2021-44228",
                "https://github.com/madCdan/JndiLookup",
                "https://github.com/Koupah/MC-Log4j-Patcher",
                "https://github.com/AlexandreHeroux/Fix-CVE-2021-44228",
                "https://github.com/kossatzd/log4j-CVE-2021-44228-test",
                "https://github.com/tobiasoed/log4j-CVE-2021-44228",
                "https://github.com/hackinghippo/log4shell_ioc_ips",
                "https://github.com/p3dr16k/log4j-1.2.15-mod",
                "https://github.com/claranet/ansible-role-log4shell",
                "https://github.com/taurusxin/CVE-2021-44228",
                "https://github.com/corelight/cve-2021-44228",
                "https://github.com/rodfer0x80/log4j2-prosecutor",
                "https://github.com/yanghaoi/CVE-2021-44228_Log4Shell",
                "https://github.com/lfama/log4j_checker",
                "https://github.com/threatmonit/Log4j-IOCs",
                "https://github.com/ben-smash/l4j-info",
                "https://github.com/strawhatasif/log4j-test",
                "https://github.com/giterlizzi/nmap-log4shell",
                "https://github.com/tica506/Siem-queries-for-CVE-2021-44228",
                "https://github.com/chilit-nl/log4shell-example",
                "https://github.com/Occamsec/log4j-checker",
                "https://github.com/snatalius/log4j2-CVE-2021-44228-poc-local",
                "https://github.com/Contrast-Security-OSS/CVE-2021-44228",
                "https://github.com/back2root/log4shell-rex",
                "https://github.com/alexbakker/log4shell-tools",
                "https://github.com/perryflynn/find-log4j",
                "https://github.com/alpacamybags118/log4j-cve-2021-44228-sample",
                "https://github.com/sandarenu/log4j2-issue-check",
                "https://github.com/roticagas/CVE-2021-44228-Demo",
                "https://github.com/Woahd/log4j-urlscanner",
                "https://github.com/faisalfs10x/Log4j2-CVE-2021-44228-revshell",
                "https://github.com/gcmurphy/chk_log4j",
                "https://github.com/0xInfection/LogMePwn",
                "https://github.com/toramanemre/apache-solr-log4j-CVE-2021-44228",
                "https://github.com/codiobert/log4j-scanner",
                "https://github.com/cbuschka/log4j2-rce-recap",
                "https://github.com/andrii-kovalenko-celonis/log4j-vulnerability-demo",
                "https://github.com/dark-ninja10/Log4j-CVE-2021-44228",
                "https://github.com/fox-it/log4j-finder",
                "https://github.com/34zY/JNDI-Exploit-1.2-log4shell",
                "https://github.com/didoatanasov/cve-2021-44228",
                "https://github.com/ShaneKingBlog/org.shaneking.demo.cve.y2021.s44228",
                "https://github.com/wortell/log4j",
                "https://github.com/municipalparkingservices/CVE-2021-44228-Scanner",
                "https://github.com/BinaryDefense/log4j-honeypot-flask",
                "https://github.com/MalwareTech/Log4jTools",
                "https://github.com/mufeedvh/log4jail",
                "https://github.com/guerzon/log4shellpoc",
                "https://github.com/ab0x90/CVE-2021-44228_PoC",
                "https://github.com/stripe/log4j-remediation-tools",
                "https://github.com/xsultan/log4jshield",
                "https://github.com/HynekPetrak/log4shell-finder",
                "https://github.com/0xThiebaut/CVE-2021-44228",
                "https://github.com/CERTCC/CVE-2021-44228_scanner",
                "https://github.com/CrackerCat/CVE-2021-44228-Log4j-Payloads",
                "https://github.com/dbzoo/log4j_scanner",
                "https://github.com/jeremyrsellars/CVE-2021-44228_scanner",
                "https://github.com/VinniMarcon/Log4j-Updater",
                "https://github.com/bhprin/log4j-vul",
                "https://github.com/rgl/log4j-log4shell-playground",
                "https://github.com/anuvindhs/how-to-check-patch-secure-log4j-CVE-2021-44228",
                "https://github.com/KeysAU/Get-log4j-Windows.ps1",
                "https://github.com/kubearmor/log4j-CVE-2021-44228",
                "https://github.com/redhuntlabs/Log4JHunt",
                "https://github.com/mss/log4shell-hotfix-side-effect",
                "https://github.com/MeterianHQ/log4j-vuln-coverage-check",
                "https://github.com/mitiga/log4shell-cloud-scanner",
                "https://github.com/isuruwa/Log4j",
                "https://github.com/honeynet/log4shell-data",
                "https://github.com/inettgmbh/checkmk-log4j-scanner",
                "https://github.com/b1tm0n3r/CVE-2021-44228",
                "https://github.com/VerveIndustrialProtection/CVE-2021-44228-Log4j",
                "https://github.com/alenazi90/log4j",
                "https://github.com/pmontesd/log4j-cve-2021-44228",
                "https://github.com/LiveOverflow/log4shell",
                "https://github.com/aws-samples/kubernetes-log4j-cve-2021-44228-node-agent",
                "https://github.com/michaelsanford/Log4Shell-Honeypot",
                "https://github.com/thomaspatzke/Log4Pot",
                "https://github.com/ubitech/cve-2021-44228-rce-poc",
                "https://github.com/rv4l3r3/log4v-vuln-check",
                "https://github.com/dpomnean/log4j_scanner_wrapper",
                "https://github.com/roxas-tan/CVE-2021-44228",
                "https://github.com/shamo0/CVE-2021-44228",
                "https://github.com/snow0715/log4j-Scan-Burpsuite",
                "https://github.com/Joefreedy/Log4j-Windows-Scanner",
                "https://github.com/Nanitor/log4fix",
                "https://github.com/korteke/log4shell-demo",
                "https://github.com/recanavar/vuln_spring_log4j2",
                "https://github.com/DXC-StrikeForce/Burp-Log4j-HammerTime",
                "https://github.com/andalik/log4j-filescan",
                "https://github.com/lonecloud/CVE-2021-44228-Apache-Log4j",
                "https://github.com/gyaansastra/CVE-2021-44228",
                "https://github.com/axisops/CVE-2021-44228",
                "https://github.com/kal1gh0st/MyLog4Shell",
                "https://github.com/hozyx/log4shell",
                "https://github.com/andypitcher/Log4J_checker",
                "https://github.com/Vulnmachines/log4j-cve-2021-44228",
                "https://github.com/kannthu/CVE-2021-44228-Apache-Log4j-Rce",
                "https://github.com/Kr0ff/CVE-2021-44228",
                "https://github.com/suuhm/log4shell4shell",
                "https://github.com/wajda/log4shell-test-exploit",
                "https://github.com/obscuritylabs/log4shell-poc-lab",
                "https://github.com/Fazmin/vCenter-Server-Workaround-Script-CVE-2021-44228",
                "https://github.com/Grupo-Kapa-7/CVE-2021-44228-Log4j-PoC-RCE",
                "https://github.com/sysadmin0815/Fix-Log4j-PowershellScript",
                "https://github.com/RenYuH/log4j-lookups-vulnerability",
                "https://github.com/scheibling/py-log4shellscanner",
                "https://github.com/zaneef/CVE-2021-44228",
                "https://github.com/metodidavidovic/log4j-quick-scan",
                "https://github.com/WatchGuard-Threat-Lab/log4shell-iocs",
                "https://github.com/Aschen/log4j-patched",
                "https://github.com/nikolas-charalambidis/cve-2021-44228",
                "https://github.com/m0rath/detect-log4j-exploitable",
                "https://github.com/nu11secur1ty/CVE-2021-44228-VULN-APP",
                "https://github.com/ankur-katiyar/log4j-docker",
                "https://github.com/immunityinc/Log4j-JNDIServer",
                "https://github.com/DANSI/PowerShell-Log4J-Scanner",
                "https://github.com/suniastar/scan-log4shell",
                "https://github.com/shivakumarjayaraman/log4jvulnerability-CVE-2021-44228",
                "https://github.com/j3kz/CVE-2021-44228-PoC",
                "https://github.com/Apipia/log4j-pcap-activity",
                "https://github.com/axelcurmi/log4shell-docker-lab",
                "https://github.com/otaviokr/log4j-2021-vulnerability-study",
                "https://github.com/kkyehit/log4j_CVE-2021-44228",
                "https://github.com/trickyearlobe/inspec-log4j",
                "https://github.com/TheInterception/Log4J-Simulation-Tool",
                "https://github.com/KeysAU/Get-log4j-Windows-local",
                "https://github.com/mschmnet/Log4Shell-demo",
                "https://github.com/Rk-000/Log4j_scan_Advance",
                "https://github.com/puzzlepeaches/Log4jCenter",
                "https://github.com/Labout/log4shell-rmi-poc",
                "https://github.com/TotallyNotAHaxxer/f-for-java",
                "https://github.com/spasam/log4j2-exploit",
                "https://github.com/bumheehan/cve-2021-44228-log4j-test",
                "https://github.com/Y0-kan/Log4jShell-Scan",
                "https://github.com/julian911015/Log4j-Scanner-Exploit",
                "https://github.com/intel-xeon/CVE-2021-44228---detection-with-PowerShell",
                "https://github.com/chandru-gunasekaran/log4j-fix-CVE-2021-44228",
                "https://github.com/snapattack/damn-vulnerable-log4j-app",
                "https://github.com/r00thunter/Log4Shell-Scanner",
                "https://github.com/mn-io/log4j-spring-vuln-poc",
                "https://github.com/rejupillai/log4j2-hack-springboot",
                "https://github.com/lucab85/log4j-cve-2021-44228",
                "https://github.com/BabooPan/Log4Shell-CVE-2021-44228-Demo",
                "https://github.com/ossie-git/log4shell_sentinel",
                "https://github.com/r00thunter/Log4Shell",
                "https://github.com/ssl-user-en/Log4j-Scanner-Exploit",
                "https://github.com/BJLIYANLIANG/log4j-scanner",
                "https://github.com/badb33f/Apache-Log4j-POC",
                "https://github.com/TaroballzChen/CVE-2021-44228-log4jVulnScanner-metasploit",
                "https://github.com/lucab85/ansible-role-log4shell",
                "https://github.com/grimch/log4j-CVE-2021-44228-workaround",
                "https://github.com/cybersecurityworks553/log4j-shell-csw",
                "https://github.com/Toolsec/log4j-scan",
                "https://github.com/puzzlepeaches/Log4jUnifi",
                "https://github.com/many-fac3d-g0d/apache-tomcat-log4j",
                "https://github.com/marcourbano/CVE-2021-44228",
                "https://github.com/bsigouin/log4shell-vulnerable-app",
                "https://github.com/ToxicEnvelope/XSYS-Log4J2Shell-Ex",
                "https://github.com/felipe8398/ModSec-log4j2",
                "https://github.com/c3-h2/Log4j_Attacker_IPList",
                "https://github.com/mazhar-hassan/log4j-vulnerability",
                "https://github.com/s-retlaw/l4s_poc",
                "https://github.com/Ravid-CheckMarx/CVE-2021-44228-Apache-Log4j-Rce-main",
                "https://github.com/yesspider-hacker/log4j-payload-generator",
                "https://github.com/LinkMJB/log4shell_scanner",
                "https://github.com/NS-Sp4ce/Vm4J",
                "https://github.com/PoneyClairDeLune/LogJackFix",
                "https://github.com/MarceloLeite2604/log4j-vulnerability",
                "https://github.com/romanutti/log4shell-vulnerable-app",
                "https://github.com/marklindsey11/-CVE-2021-44228_scanner-Applications-that-are-vulnerable-to-the-log4j-CVE-2021-44228-https-nvd.",
                "https://github.com/Timborin0/log4j-dork-scanner",
                "https://github.com/marklindsey11/gh-repo-clone-marklindsey11--CVE-2021-44228_scanner-Applications-that-are-vulnerable-to-the-log4j-CV",
                "https://github.com/mklinkj/log4j2-test",
                "https://github.com/4jfinder/4jfinder.github.io",
                "https://github.com/alexpena5635/CVE-2021-44228_scanner-main-Modified-",
                "https://github.com/kanitan/log4j2-web-vulnerable",
                "https://github.com/mr-r3b00t/CVE-2021-44228",
                "https://github.com/ChandanShastri/Log4j_Vulnerability_Demo",
                "https://github.com/puzzlepeaches/Log4jHorizon",
                "https://github.com/Vulnmachines/log4jshell_CVE-2021-44228",
                "https://github.com/mr-vill4in/log4j-fuzzer",
                "https://github.com/nix-xin/vuln4japi",
                "https://github.com/maximofernandezriera/CVE-2021-44228",
                "https://github.com/mebibite/log4jhound",
                "https://github.com/3pplus/loguccino",
                "https://github.com/jxerome/log4shell",
                "https://github.com/solitarysp/Log4j-CVE-2021-44228",
                "https://github.com/atlassion/log4j-exploit-builder",
                "https://github.com/atlassion/RS4LOGJ-CVE-2021-44228",
                "https://github.com/sdogancesur/log4j_github_repository",
                "https://github.com/jrocia/Search-log4Jvuln-AppScanSTD",
                "https://github.com/aajuvonen/log4stdin",
                "https://github.com/arnaudluti/PS-CVE-2021-44228",
                "https://github.com/ColdFusionX/CVE-2021-44228-Log4Shell-POC",
                "https://github.com/robrankin/cve-2021-44228-waf-tests",
                "https://github.com/0xalwayslucky/log4j-polkit-poc",
                "https://github.com/y-security/yLog4j",
                "https://github.com/IAmNewbieZ/CVE-2021-44228",
                "https://github.com/FeryaelJustice/Log4Shell",
                "https://github.com/hotpotcookie/CVE-2021-44228-white-box",
                "https://github.com/s-retlaw/l4srs",
                "https://github.com/Ananya-0306/Log-4j-scanner",
                "https://github.com/paulvkitor/log4shellwithlog4j2_13_3",
                "https://github.com/MiguelM001/vulescanjndilookup",
                "https://github.com/Jun-5heng/CVE-2021-44228",
                "https://github.com/vulnerable-apps/log4shell-honeypot",
                "https://github.com/manishkanyal/log4j-scanner",
                "https://github.com/TPower2112/Writing-Sample-1",
                "https://github.com/Willian-2-0-0-1/Log4j-Exploit-CVE-2021-44228",
                "https://github.com/r3kind1e/Log4Shell-obfuscated-payloads-generator",
                "https://github.com/Phineas09/CVE-2021-44228",
                "https://github.com/hassaanahmad813/log4j",
                "https://github.com/yuuki1967/CVE-2021-44228-Apache-Log4j-Rce",
                "https://github.com/moshuum/tf-log4j-aws-poc",
                "https://github.com/jaehnri/CVE-2021-44228",
                "https://github.com/ra890927/Log4Shell-CVE-2021-44228-Demo",
                "https://github.com/vino-theva/CVE-2021-44228",
                "https://github.com/tharindudh/tharindudh-Log4j-Vulnerability-in-Ghidra-tool-CVE-2021-44228",
                "https://github.com/eurogig/jankybank",
                "https://github.com/digital-dev/Log4j-CVE-2021-44228-Remediation",
                "https://github.com/ocastel/log4j-shell-poc",
                "https://github.com/bcdunbar/CVE-2021-44228-poc",
                "https://github.com/srcporter/CVE-2021-44228",
                "https://github.com/sqsec/log4j2_CVE-2021-44228",
                "https://github.com/demining/Log4j-Vulnerability",
                "https://github.com/pierpaolosestito-dev/Log4Shell-CVE-2021-44228-PoC",
                "https://github.com/Sumitpathania03/LOG4J-CVE-2021-44228",
                "https://github.com/Sma-Das/Log4j-PoC",
                "https://github.com/53buahapel/log4shell-vulnweb",
                "https://github.com/demonrvm/Log4ShellRemediation",
                "https://github.com/funcid/log4j-exploit-fork-bomb",
                "https://github.com/MrHarshvardhan/PY-Log4j-RCE-Scanner",
                "https://github.com/Muhammad-Ali007/Log4j_CVE-2021-44228",
                "https://github.com/Tai-e/CVE-2021-44228",
                "https://github.com/roshanshibu/Odysseus",
                "https://github.com/LucasPDiniz/CVE-2021-44228",
                "https://github.com/felixslama/log4shell-minecraft-demo",
                "https://github.com/ShlomiRex/log4shell_lab",
                "https://github.com/dcm2406/CVE-Lab",
                "https://github.com/scabench/l4j-tp1",
                "https://github.com/scabench/l4j-fp1",
                "https://github.com/KtokKawu/l4s-vulnapp",
                "https://github.com/sec13b/CVE-2021-44228-POC",
                "https://github.com/KirkDJohnson/Wireshark",
                "https://github.com/YangHyperData/LOGJ4_PocShell_CVE-2021-44228",
                "https://github.com/Hoanle396/CVE-2021-44228-demo",
                "https://github.com/NikitaPark/Log4Shell-PoC-Application",
                "https://github.com/tadash10/Exploiting-CVE-2021-44228-Log4Shell-in-a-Banking-Environment",
                "https://github.com/asd58584388/CVE-2021-44228",
                "https://github.com/OtisSymbos/CVE-2021-44228-Log4Shell-",
                "https://github.com/safeer-accuknox/log4j-shell-poc",
                "https://github.com/Carlos-Mesquita/TPASLog4ShellPoC",
                "https://github.com/AhmedMansour93/-Unveiling-the-Lessons-from-Log4Shell-A-Wake-Up-Call-for-Cybersecurity-",
                "https://github.com/Super-Binary/cve-2021-44228",
                "https://github.com/ZacharyZcR/CVE-2021-44228",
                "https://github.com/qw3rtyou/CVE-2021-44228_dockernize",
                "https://github.com/yadavmukesh/Log4Shell-vulnerability-CVE-2021-44228-",
                "https://github.com/tpdlshdmlrkfmcla/Log4shell",
                "https://github.com/timothyjxhn/DeliberatelyVulnerableWebApp",
                "https://github.com/khaidtraivch/CVE-2021-44228-Log4Shell-",
                "https://github.com/Fauzan-Aldi/Log4j-_Vulnerability",
                "https://github.com/SerpilRivas/log4shell-homework9",
                "https://github.com/x1ongsec/CVE-2021-44228-Log4j-JNDI",
                "https://github.com/fabioeletto/hka-seminar-log4shell",
                "https://github.com/cuijiung/log4j-CVE-2021-44228",
                "https://github.com/Sorrence/CVE-2021-44228",
                "https://github.com/moften/Log4Shell",
                "https://github.com/KamalideenAK/Microsoft-Defender-for-Endpoint-Deployment-on-Windows-10-11-device",
                "https://github.com/arabindadora/log4shell",
                "https://github.com/Mintimate/log4j2-bugmaker",
                "https://github.com/mgueye3/Log4Shell",
                "https://github.com/PCMKUIT/CVE-2021-44228---Log4Shell-Analysis",
                "https://github.com/DrHaitham/Log4Shell-CVE-2021-44228",
                "https://github.com/Loliverte/Log4j-Vulnerability",
                "https://github.com/JoseMariaMicoli/Log4Shell-PoC",
                "https://github.com/agylabs/log4shell-remediation",
                "https://github.com/0xBlackash/CVE-2021-44228",
                "https://github.com/Codepumpking/log4shell-poc",
                "https://github.com/wmohamed2033/wmohamed2033.github.io",
                "https://github.com/Saru1718/THM---Solar-exploiting-Log-4j",
                "https://github.com/lathika-3006/Solar-exploiting-log-4j",
                "https://github.com/Lavanya2085/solar-exploiting-log4j",
                "https://github.com/danieljosmariyan7254/TryHackMe-Solar-exploiting-log4j-",
                "https://github.com/jdormannn/SecureOps-Lab",
                "https://github.com/joaovicdev/EXPLOIT-CVE-2021-44228",
                "https://github.com/pinaraltinok/Log4Shell-Attack",
                "https://github.com/kaleth4/CVE-2021-44228",
                "https://github.com/tieupham267/log4shell-coraza",
                "https://github.com/sajanapamuditha/Cyber-Attack-Simulation-",
                "https://github.com/neilc1964techned/craready-test-java-vulns",
                "https://github.com/FacundoMfernandez/pentesting-obioba",
                "https://github.com/vutiendat323/CVE-2021-44228_Log4Shell",
                "https://github.com/aaronm-sysdig/log4j-vuln-demo",
                "https://github.com/MAFO-sec/mi-laboratorio-log4shell",
                "https://github.com/felisha-elmer/Sandbox-Challenge-Log4Shell-CVE-2021-44228-",
                "https://github.com/jomjosh17/Log4Shell-CVE-2021-44228-",
                "https://github.com/C00LN3T/Log4ShellAuditor",
                "https://github.com/bhimsekhar/vulnerable-java-app",
                "https://github.com/horrister/log4shell-cve-2021-44228",
                "https://github.com/hmxh123/Log4Shell-Vulnerability-Replication",
                "https://github.com/limxuan/ehir-vuln-enterprise-login",
                "https://github.com/DAADAISMYLIFE/log4shell-lab",
                "https://github.com/probablysecure/Triage-CVE-2021-44228-Log4Shell-Log4j-",
                "https://github.com/Ricardo354/homelab-CVE-2021-44228",
                "https://github.com/AstralJays/TraditionalJay",
                "https://github.com/prmawyer/log4shell-vulnerable-app",
                "https://github.com/arpitgupta369/log4shell-scanner",
                "https://github.com/razureink/cve-2021-44228-log4shell_rce_reproduction",
                "https://github.com/sfr0435122531-ui/-log4shell-lab",
                "https://github.com/yili-soc/vm-homelab-log4shell-assessment",
                "https://github.com/sanasimran1403-jpg/log4shell",
                "https://github.com/AhndreWalters/ProjectSecurity-Homelab",
                "https://github.com/Jiahong-Guan/log4j-shell-poc",
                "https://github.com/Vaibhav91one/log4shell-cve-lab",
                "https://github.com/14free/log4j2-vuln-lab",
                "https://github.com/Wafeeq-Fareed/log4shell-exploitation-lab",
                "https://github.com/KalidouLabghaly/log4shell-exploitation-detection",
                "https://github.com/rh-rahulshetty/log4shell-CVE-2021-44228",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TAROBALLZCHEN-CVE-2021-44228-LOG4JVULNSCANNER-METASPLOIT",
                "https://kitploit.com/ru/tools/github/taroballzchen/cve-2021-44228-log4jvulnscanner-metasploit/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T18:31:54Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-43858",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2021-43858-MinIO exploit",
            "summary": "Exploit for CVE-2021-43858. CVSS 8.8.",
            "updated_at": "2026-09-13T18:37:19Z",
            "published_at": "2026-09-13T18:37:19Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 27,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "User privilege escalation vulnerability in MinIO.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2021-43858-MinIO",
                    "summary": "User privilege escalation vulnerability in MinIO.",
                    "what_happened": "User privilege escalation vulnerability in MinIO.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KHUNTOR-CVE-2021-43858-MINIO",
                        "https://kitploit.com/ru/tools/github/khuntor/cve-2021-43858-minio/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-11T17:33:41",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KHUNTOR-CVE-2021-43858-MINIO"
                },
                {
                    "title": "Exploit for CVE-2021-43858-MinIO",
                    "summary": "User privilege escalation vulnerability in MinIO.",
                    "what_happened": "User privilege escalation vulnerability in MinIO.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KHUNTOR-CVE-2021-43858-MINIO",
                        "https://kitploit.com/ru/tools/github/khuntor/cve-2021-43858-minio/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-11T17:33:41",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/khuntor/cve-2021-43858-minio/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KHUNTOR-CVE-2021-43858-MINIO",
                "https://kitploit.com/ru/tools/github/khuntor/cve-2021-43858-minio/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:37:19Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KHUNTOR-CVE-2021-43858-MINIO"
                }
            ]
        },
        {
            "id": "CVE-2021-43798",
            "vendor": "Grafana Labs",
            "product": "Grafana",
            "title": "Grafana Path Traversal Vulnerability",
            "summary": "Grafana contains a path traversal vulnerability that could allow access to local files.",
            "updated_at": "2026-09-08T14:31:01Z",
            "published_at": "2026-09-08T14:31:01Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 153,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Grafana contains a path traversal vulnerability that could allow access to local files.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50581",
                    "author": "s1gh",
                    "first_seen": "2021-12-09",
                    "confidence": "High",
                    "title": "Grafana 8.3.0 - Directory Traversal and Arbitrary File Read",
                    "summary": "Grafana 8.3.0 - Directory Traversal and Arbitrary File Read",
                    "url": "https://www.exploit-db.com/exploits/50581",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for Grafana-CVE-2021-43798",
                    "summary": "Unauthorized arbitrary file read in Grafana before 8.3.1 allows reading sensitive database files.",
                    "what_happened": "Unauthorized arbitrary file read in Grafana before 8.3.1 allows reading sensitive database files.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-GRAFANA-CVE-2021-43798",
                        "https://kitploit.com/ru/tools/github/jas502n/grafana-cve-2021-43798/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T20:51:47",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-GRAFANA-CVE-2021-43798"
                },
                {
                    "title": "Exploit for Grafana-CVE-2021-43798",
                    "summary": "Unauthorized arbitrary file read in Grafana before 8.3.1 allows reading sensitive database files.",
                    "what_happened": "Unauthorized arbitrary file read in Grafana before 8.3.1 allows reading sensitive database files.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-GRAFANA-CVE-2021-43798",
                        "https://kitploit.com/ru/tools/github/jas502n/grafana-cve-2021-43798/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-03T20:51:47",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/jas502n/grafana-cve-2021-43798/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/50581",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-GRAFANA-CVE-2021-43798",
                "https://kitploit.com/ru/tools/github/jas502n/grafana-cve-2021-43798/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T14:31:01Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-09",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-42913",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2006-3392 exploit",
            "summary": "Exploit for CVE-2006-3392 and CVE-2021-42913. CVSS 7.5.",
            "updated_at": "2026-09-13T18:36:41Z",
            "published_at": "2026-09-13T18:36:41Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:36:41+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2006-3392 exploit",
                    "summary": "Exploit for CVE-2006-3392 and CVE-2021-42913. CVSS 7.5.",
                    "cvss": 7.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KERNEL-CYBER-CVE-2006-3392"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KERNEL-CYBER-CVE-2006-3392"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:36:41Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KERNEL-CYBER-CVE-2006-3392"
                }
            ]
        },
        {
            "id": "CVE-2021-42756",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2021-42756 exploit",
            "summary": "Exploit for CVE-2021-42756. CVSS 9.8.",
            "updated_at": "2026-09-05T12:44:57Z",
            "published_at": "2026-09-05T12:44:57Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 89,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-121",
            "what_happened": "Stack overflow in FortiWeb proxy daemon MitB protection enables unauthenticated code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2021-42756",
                    "summary": "Stack overflow in FortiWeb proxy daemon MitB protection enables unauthenticated code execution.",
                    "what_happened": "Stack overflow in FortiWeb proxy daemon MitB protection enables unauthenticated code execution.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-121",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-3NDORPH1N-CVE-2021-42756",
                        "https://kitploit.com/ru/tools/github/3ndorph1n/cve-2021-42756/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T12:44:57",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-3NDORPH1N-CVE-2021-42756"
                },
                {
                    "title": "Exploit for CVE-2021-42756",
                    "summary": "Stack overflow in FortiWeb proxy daemon MitB protection enables unauthenticated code execution.",
                    "what_happened": "Stack overflow in FortiWeb proxy daemon MitB protection enables unauthenticated code execution.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-121",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-3NDORPH1N-CVE-2021-42756",
                        "https://kitploit.com/ru/tools/github/3ndorph1n/cve-2021-42756/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T12:44:57",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/3ndorph1n/cve-2021-42756/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-3NDORPH1N-CVE-2021-42756",
                "https://kitploit.com/ru/tools/github/3ndorph1n/cve-2021-42756/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:44:57Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-3NDORPH1N-CVE-2021-42756"
                }
            ]
        },
        {
            "id": "CVE-2021-42165",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Mitrastar GPT-2541GNAC-N1 - Privilege escalation",
            "summary": "Mitrastar GPT-2541GNAC-N1 - Privilege escalation",
            "updated_at": "2026-09-02T19:01:22Z",
            "published_at": "2026-09-02T19:01:22Z",
            "cvss": 9,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 144,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Unknown",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Command injection in MitraStar GPT-2541GNAC-N1 deviceinfo command grants root shell.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50351",
                    "author": "Leonardo Nicolas Servalli",
                    "first_seen": "2021-09-29",
                    "confidence": "High",
                    "title": "Mitrastar GPT-2541GNAC-N1 - Privilege escalation",
                    "summary": "Mitrastar GPT-2541GNAC-N1 - Privilege escalation",
                    "url": "https://www.exploit-db.com/exploits/50351",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for Privilege-escalation-MitraStar CVE-2021-42165",
                    "summary": "Command injection in MitraStar GPT-2541GNAC-N1 deviceinfo command grants root shell.",
                    "what_happened": "Command injection in MitraStar GPT-2541GNAC-N1 deviceinfo command grants root shell.",
                    "cvss": 9,
                    "cvss_vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LEOSERVALLI-PRIVILEGE-ESCALATION-MITRASTAR",
                        "https://kitploit.com/ru/tools/github/leoservalli/privilege-escalation-mitrastar/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-02T21:01:22",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LEOSERVALLI-PRIVILEGE-ESCALATION-MITRASTAR"
                },
                {
                    "title": "Exploit for Privilege-escalation-MitraStar CVE-2021-42165",
                    "summary": "Command injection in MitraStar GPT-2541GNAC-N1 deviceinfo command grants root shell.",
                    "what_happened": "Command injection in MitraStar GPT-2541GNAC-N1 deviceinfo command grants root shell.",
                    "cvss": 9,
                    "cvss_vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LEOSERVALLI-PRIVILEGE-ESCALATION-MITRASTAR",
                        "https://kitploit.com/ru/tools/github/leoservalli/privilege-escalation-mitrastar/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-02T21:01:22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/leoservalli/privilege-escalation-mitrastar/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/50351",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LEOSERVALLI-PRIVILEGE-ESCALATION-MITRASTAR",
                "https://kitploit.com/ru/tools/github/leoservalli/privilege-escalation-mitrastar/"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T19:01:22Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/50351"
                }
            ],
            "cvss_vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        },
        {
            "id": "CVE-2021-42013",
            "vendor": "Apache",
            "product": "HTTP Server",
            "title": "Apache HTTP Server Path Traversal Vulnerability",
            "summary": "Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.",
            "updated_at": "2026-09-15T08:30:56Z",
            "published_at": "2026-09-15T08:30:56Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 46,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default require all denied or if CGI scripts are enabled. This CVE ID resolves an incomplete patch for CVE-2021-41773.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50406",
                    "author": "Lucas Souza",
                    "first_seen": "2021-10-13",
                    "confidence": "High",
                    "title": "Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)",
                    "summary": "Apache HTTP Server 2.4.50 - Path Traversal & Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/50406",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 50446",
                    "author": "ThelastVvV",
                    "first_seen": "2021-10-25",
                    "confidence": "High",
                    "title": "Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2)",
                    "summary": "Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (2)",
                    "url": "https://www.exploit-db.com/exploits/50446",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 50512",
                    "author": "Valentin Lobstein",
                    "first_seen": "2021-11-11",
                    "confidence": "High",
                    "title": "Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)",
                    "summary": "Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)",
                    "url": "https://www.exploit-db.com/exploits/50512",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-15T08:30:56+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "cve-2021-42013-httpd exploit",
                    "summary": "Exploit for CVE-2021-42013. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CYBFAR-CVE-2021-42013-HTTPD"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/50406",
                "https://www.exploit-db.com/exploits/50446",
                "https://www.exploit-db.com/exploits/50512",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CYBFAR-CVE-2021-42013-HTTPD"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:30:56Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-41773",
            "vendor": "Apache",
            "product": "HTTP Server",
            "title": "Apache HTTP Server Path Traversal Vulnerability",
            "summary": "Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.",
            "updated_at": "2026-09-08T01:14:42Z",
            "published_at": "2026-09-08T01:14:42Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 222,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution if files outside directories configured by Alias-like directives are not under default �require all denied� or if CGI scripts are enabled. The original patch issued under this CVE ID is insufficient, please review remediation information under CVE-2021-42013.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50383",
                    "author": "Lucas Souza",
                    "first_seen": "2021-10-06",
                    "confidence": "High",
                    "title": "Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE)",
                    "summary": "Apache HTTP Server 2.4.49 - Path Traversal & Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/50383",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 50512",
                    "author": "Valentin Lobstein",
                    "first_seen": "2021-11-11",
                    "confidence": "High",
                    "title": "Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)",
                    "summary": "Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)",
                    "url": "https://www.exploit-db.com/exploits/50512",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2021-41773-Apache_2.4.49-Path-traversal-to-RCE",
                    "summary": "Unauthenticated path traversal to RCE in Apache 2.4.49 via %2e normalization when CGI enabled.",
                    "what_happened": "Unauthenticated path traversal to RCE in Apache 2.4.49 via %2e normalization when CGI enabled.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CYBERQUESTOR-INFOSEC-CVE-2021-41773-APACHE_2.4.49-PATH-TRAVERSAL-TO-RCE",
                        "https://kitploit.com/ja/tools/github/cyberquestor-infosec/cve-2021-41773-apache_2.4.49-path-traversal-to-rce/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T05:58:19",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CYBERQUESTOR-INFOSEC-CVE-2021-41773-APACHE_2.4.49-PATH-TRAVERSAL-TO-RCE"
                },
                {
                    "title": "Exploit for CVE-2021-41773-Apache_2.4.49-Path-traversal-to-RCE",
                    "summary": "Unauthenticated path traversal to RCE in Apache 2.4.49 via %2e normalization when CGI enabled.",
                    "what_happened": "Unauthenticated path traversal to RCE in Apache 2.4.49 via %2e normalization when CGI enabled.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CYBERQUESTOR-INFOSEC-CVE-2021-41773-APACHE_2.4.49-PATH-TRAVERSAL-TO-RCE",
                        "https://kitploit.com/ja/tools/github/cyberquestor-infosec/cve-2021-41773-apache_2.4.49-path-traversal-to-rce/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-04T05:58:19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/cyberquestor-infosec/cve-2021-41773-apache_2.4.49-path-traversal-to-rce/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/50383",
                "https://www.exploit-db.com/exploits/50512",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CYBERQUESTOR-INFOSEC-CVE-2021-41773-APACHE_2.4.49-PATH-TRAVERSAL-TO-RCE",
                "https://kitploit.com/ja/tools/github/cyberquestor-infosec/cve-2021-41773-apache_2.4.49-path-traversal-to-rce/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:14:42Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-40906",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2021-40906",
            "summary": "Reflected XSS in CheckMK Management Web Console 1.5.0 to 1.5.0p25 in unauthenticated zone.",
            "updated_at": "2026-09-04T06:29:50Z",
            "published_at": "2026-09-04T06:29:50Z",
            "cvss": 6.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 159,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Reflected XSS in CheckMK Management Web Console 1.5.0 to 1.5.0p25 in unauthenticated zone.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2021-40906",
                    "summary": "Reflected XSS in CheckMK Management Web Console 1.5.0 to 1.5.0p25 in unauthenticated zone.",
                    "what_happened": "Reflected XSS in CheckMK Management Web Console 1.5.0 to 1.5.0p25 in unauthenticated zone.",
                    "cvss": 6.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EDGARLOYOLA-CVE-2021-40906",
                        "https://kitploit.com/ru/tools/github/edgarloyola/cve-2021-40906/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T08:29:50",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EDGARLOYOLA-CVE-2021-40906"
                },
                {
                    "title": "Exploit for CVE-2021-40906",
                    "summary": "Reflected XSS in CheckMK Management Web Console 1.5.0 to 1.5.0p25 in unauthenticated zone.",
                    "what_happened": "Reflected XSS in CheckMK Management Web Console 1.5.0 to 1.5.0p25 in unauthenticated zone.",
                    "cvss": 6.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EDGARLOYOLA-CVE-2021-40906",
                        "https://kitploit.com/ru/tools/github/edgarloyola/cve-2021-40906/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T08:29:50",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/edgarloyola/cve-2021-40906/"
                },
                {
                    "repository": "Edgarloyola/CVE-2021-40906",
                    "author": "Edgarloyola",
                    "first_seen": "2021-10-12",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": "CVE-2021-40906 repository",
                    "summary": "",
                    "url": "https://github.com/Edgarloyola/CVE-2021-40906"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EDGARLOYOLA-CVE-2021-40906",
                "https://kitploit.com/ru/tools/github/edgarloyola/cve-2021-40906/",
                "https://github.com/Edgarloyola/CVE-2021-40906"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T06:29:50Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EDGARLOYOLA-CVE-2021-40906"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
        },
        {
            "id": "CVE-2021-39793",
            "vendor": "Google",
            "product": "Pixel",
            "title": "Google Pixel Out-of-Bounds Write Vulnerability",
            "summary": "Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.",
            "updated_at": "2026-08-24T10:00:02Z",
            "published_at": "2026-08-24T10:00:02Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 97,
            "kev": true,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Google Pixel contains a possible out-of-bounds write due to a logic error in the code that could lead to local escalation of privilege.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2022-22706-poc CVE-2021-39793 CVE-2022-22706",
                    "summary": "Page-cache write in Arm Mali GPU driver r35p0 via writable mapping of read-only file page cache.",
                    "what_happened": "Page-cache write in Arm Mali GPU driver r35p0 via writable mapping of read-only file page cache.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BYT3QUESTER-CVE-2022-22706-POC",
                        "https://kitploit.com/ru/tools/github/byt3quester/cve-2022-22706-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-24T12:00:02",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BYT3QUESTER-CVE-2022-22706-POC"
                },
                {
                    "title": "Exploit for CVE-2022-22706-poc CVE-2021-39793 CVE-2022-22706",
                    "summary": "Page-cache write in Arm Mali GPU driver r35p0 via writable mapping of read-only file page cache.",
                    "what_happened": "Page-cache write in Arm Mali GPU driver r35p0 via writable mapping of read-only file page cache.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BYT3QUESTER-CVE-2022-22706-POC",
                        "https://kitploit.com/ru/tools/github/byt3quester/cve-2022-22706-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-24T12:00:02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/byt3quester/cve-2022-22706-poc/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BYT3QUESTER-CVE-2022-22706-POC",
                "https://kitploit.com/ru/tools/github/byt3quester/cve-2022-22706-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-08-24T10:00:02Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-11",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2021-39115",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2019-11581",
            "summary": "Template injection in Atlassian JIRA enabling remote code execution via i18n class.",
            "updated_at": "2026-09-04T15:00:55Z",
            "published_at": "2026-09-04T15:00:55Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 61,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Template injection in Atlassian JIRA enabling remote code execution via i18n class.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2019-11581",
                    "summary": "Template injection in Atlassian JIRA enabling remote code execution via i18n class.",
                    "what_happened": "Template injection in Atlassian JIRA enabling remote code execution via i18n class.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2019-11581",
                        "https://kitploit.com/ja/tools/github/jas502n/cve-2019-11581/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T17:00:55",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2019-11581"
                },
                {
                    "title": "Exploit for CVE-2019-11581",
                    "summary": "Template injection in Atlassian JIRA enabling remote code execution via i18n class.",
                    "what_happened": "Template injection in Atlassian JIRA enabling remote code execution via i18n class.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2019-11581",
                        "https://kitploit.com/ja/tools/github/jas502n/cve-2019-11581/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-04T17:00:55",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/jas502n/cve-2019-11581/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2019-11581",
                "https://kitploit.com/ja/tools/github/jas502n/cve-2019-11581/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T15:00:55Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2019-11581"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2021-38817",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2021-38817-Remote-OS-Command-Injection exploit",
            "summary": "Exploit for CVE-2021-38817.",
            "updated_at": "2026-09-06T08:36:19Z",
            "published_at": "2026-09-06T08:36:19Z",
            "cvss": 5.4,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 87,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Authenticated OS command injection in TastyIgniter v3.0.7 via unsanitized Sendmail Path parameter.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2021-38817-Remote-OS-Command-Injection",
                    "summary": "Authenticated OS command injection in TastyIgniter v3.0.7 via unsanitized Sendmail Path parameter.",
                    "what_happened": "Authenticated OS command injection in TastyIgniter v3.0.7 via unsanitized Sendmail Path parameter.",
                    "cvss": 5.9,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HUSKYHACKS-CVE-2021-38817-REMOTE-OS-COMMAND-INJECTION",
                        "https://kitploit.com/ru/tools/github/huskyhacks/cve-2021-38817-remote-os-command-injection/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T08:36:19",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HUSKYHACKS-CVE-2021-38817-REMOTE-OS-COMMAND-INJECTION"
                },
                {
                    "title": "Exploit for CVE-2021-38817-Remote-OS-Command-Injection",
                    "summary": "Authenticated OS command injection in TastyIgniter v3.0.7 via unsanitized Sendmail Path parameter.",
                    "what_happened": "Authenticated OS command injection in TastyIgniter v3.0.7 via unsanitized Sendmail Path parameter.",
                    "cvss": 5.9,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HUSKYHACKS-CVE-2021-38817-REMOTE-OS-COMMAND-INJECTION",
                        "https://kitploit.com/ru/tools/github/huskyhacks/cve-2021-38817-remote-os-command-injection/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-06T08:36:19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/huskyhacks/cve-2021-38817-remote-os-command-injection/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HUSKYHACKS-CVE-2021-38817-REMOTE-OS-COMMAND-INJECTION",
                "https://kitploit.com/ru/tools/github/huskyhacks/cve-2021-38817-remote-os-command-injection/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:36:19Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HUSKYHACKS-CVE-2021-38817-REMOTE-OS-COMMAND-INJECTION"
                }
            ],
            "enrichment_checked_at": "2026-09-06T10:05:23Z",
            "cvss_vector": "NONE"
        },
        {
            "id": "CVE-2021-38085",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for concealed_position CVE-2019-19363 CVE-2020-1300 CVE-2021-34481 CVE-2021-35449 CVE-2021-38085",
            "summary": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
            "updated_at": "2026-09-04T19:28:37Z",
            "published_at": "2026-09-04T19:28:37Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 59,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for concealed_position CVE-2019-19363 CVE-2020-1300 CVE-2021-34481 CVE-2021-35449 CVE-2021-38085",
                    "summary": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                        "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T21:28:37",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION"
                },
                {
                    "title": "Exploit for concealed_position CVE-2019-19363 CVE-2020-1300 CVE-2021-34481 CVE-2021-35449 CVE-2021-38085",
                    "summary": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                        "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-04T21:28:37",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T19:28:37Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2021-36934",
            "vendor": "Microsoft",
            "product": "Windows",
            "title": "Microsoft Windows SAM Local Privilege Escalation Vulnerability",
            "summary": "If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.",
            "updated_at": "2026-09-11T18:33:09Z",
            "published_at": "2026-09-11T18:33:09Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 39,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "If a Volume Shadow Copy (VSS) shadow copy of the system drive is available, users can read the SAM file which would allow any user to escalate privileges to SYSTEM level.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-11T18:33:09+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "VSSCopy exploit",
                    "summary": "Exploit for CVE-2021-36934. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-VSSCOPY"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-VSSCOPY"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T18:33:09Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-36081",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.",
            "updated_at": "2026-09-14T14:14:21.223",
            "published_at": "2021-07-01T03:15:08.620",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 14,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-416",
            "what_happened": "Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "bugs.chromium.org",
                    "author": "NVD reference",
                    "first_seen": "2021-07-01",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=29698"
                }
            ],
            "references": [
                "https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=29698",
                "https://github.com/google/oss-fuzz-vulns/blob/main/vulns/tesseract-ocr/OSV-2021-211.yaml",
                "https://github.com/tesseract-ocr/tesseract/commit/e6f15621c2ab2ecbfabf656942d8ef66f03b2d55"
            ],
            "timeline": [
                {
                    "at": "2021-07-01T03:15:08.620",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-36081"
                }
            ]
        },
        {
            "id": "CVE-2021-35449",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for concealed_position CVE-2019-19363 CVE-2020-1300 CVE-2021-34481 CVE-2021-35449 CVE-2021-38085",
            "summary": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
            "updated_at": "2026-09-04T19:28:37Z",
            "published_at": "2026-09-04T19:28:37Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 59,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for concealed_position CVE-2019-19363 CVE-2020-1300 CVE-2021-34481 CVE-2021-35449 CVE-2021-38085",
                    "summary": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                        "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T21:28:37",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION"
                },
                {
                    "title": "Exploit for concealed_position CVE-2019-19363 CVE-2020-1300 CVE-2021-34481 CVE-2021-35449 CVE-2021-38085",
                    "summary": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                        "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-04T21:28:37",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T19:28:37Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2021-34646",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "WordPress Plugin WooCommerce Booster Plugin 5.4.3 - Authentication Bypass",
            "summary": "WordPress Plugin WooCommerce Booster Plugin 5.4.3 - Authentication Bypass",
            "updated_at": "2026-09-13T18:39:10Z",
            "published_at": "2026-09-13T18:39:10Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 50,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Authentication bypass in Booster for WooCommerce 5.4.3 via weak token allows admin login.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50299",
                    "author": "0xB455",
                    "first_seen": "2021-09-17",
                    "confidence": "High",
                    "title": "WordPress Plugin WooCommerce Booster Plugin 5.4.3 - Authentication Bypass",
                    "summary": "WordPress Plugin WooCommerce Booster Plugin 5.4.3 - Authentication Bypass",
                    "url": "https://www.exploit-db.com/exploits/50299",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2021-34646",
                    "summary": "Authentication bypass in Booster for WooCommerce 5.4.3 via weak token allows admin login.",
                    "what_happened": "Authentication bypass in Booster for WooCommerce 5.4.3 via weak token allows admin login.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MOTIKAN2010-CVE-2021-34646",
                        "https://kitploit.com/hi/tools/github/motikan2010/cve-2021-34646/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T18:39:01",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MOTIKAN2010-CVE-2021-34646"
                },
                {
                    "title": "Exploit for CVE-2021-34646",
                    "summary": "Authentication bypass in Booster for WooCommerce 5.4.3 via weak token allows admin login.",
                    "what_happened": "Authentication bypass in Booster for WooCommerce 5.4.3 via weak token allows admin login.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MOTIKAN2010-CVE-2021-34646",
                        "https://kitploit.com/hi/tools/github/motikan2010/cve-2021-34646/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T18:39:01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/motikan2010/cve-2021-34646/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/50299",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MOTIKAN2010-CVE-2021-34646",
                "https://kitploit.com/hi/tools/github/motikan2010/cve-2021-34646/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:39:10Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/50299"
                }
            ]
        },
        {
            "id": "CVE-2021-34481",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for concealed_position CVE-2019-19363 CVE-2020-1300 CVE-2021-34481 CVE-2021-35449 CVE-2021-38085",
            "summary": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
            "updated_at": "2026-09-04T19:28:37Z",
            "published_at": "2026-09-04T19:28:37Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 59,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for concealed_position CVE-2019-19363 CVE-2020-1300 CVE-2021-34481 CVE-2021-35449 CVE-2021-38085",
                    "summary": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                        "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T21:28:37",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION"
                },
                {
                    "title": "Exploit for concealed_position CVE-2019-19363 CVE-2020-1300 CVE-2021-34481 CVE-2021-35449 CVE-2021-38085",
                    "summary": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                        "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-04T21:28:37",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T19:28:37Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2021-33879",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "cve-2021-33879 exploit",
            "summary": "Exploit for CVE-2021-33879. CVSS 8.1.",
            "updated_at": "2026-09-12T15:06:23Z",
            "published_at": "2026-09-12T15:06:23Z",
            "cvss": 8.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 39,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-494",
            "what_happened": "Code execution in GameLoop before 4.1.21.90 via MITM spoofing of update packages over HTTP.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for cve-2021-33879 CVE-2021-33879",
                    "summary": "Code execution in GameLoop before 4.1.21.90 via MITM spoofing of update packages over HTTP.",
                    "what_happened": "Code execution in GameLoop before 4.1.21.90 via MITM spoofing of update packages over HTTP.",
                    "cvss": 8.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "High",
                    "cwe": "CWE-494",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MMISZCZYK-CVE-2021-33879",
                        "https://kitploit.com/ru/tools/github/mmiszczyk/cve-2021-33879/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T18:16:45",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MMISZCZYK-CVE-2021-33879"
                },
                {
                    "title": "Exploit for cve-2021-33879 CVE-2021-33879",
                    "summary": "Code execution in GameLoop before 4.1.21.90 via MITM spoofing of update packages over HTTP.",
                    "what_happened": "Code execution in GameLoop before 4.1.21.90 via MITM spoofing of update packages over HTTP.",
                    "cvss": 8.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "High",
                    "cwe": "CWE-494",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MMISZCZYK-CVE-2021-33879",
                        "https://kitploit.com/ru/tools/github/mmiszczyk/cve-2021-33879/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T18:16:45",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/mmiszczyk/cve-2021-33879/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MMISZCZYK-CVE-2021-33879",
                "https://kitploit.com/ru/tools/github/mmiszczyk/cve-2021-33879/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T15:06:23Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MMISZCZYK-CVE-2021-33879"
                }
            ]
        },
        {
            "id": "CVE-2021-31762",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Webmin 1.973 - 'save_user.cgi' Cross-Site Request Forgery (CSRF)",
            "summary": "Webmin 1.973 - 'save_user.cgi' Cross-Site Request Forgery (CSRF)",
            "updated_at": "2026-09-06T08:34:26Z",
            "published_at": "2026-09-06T08:34:26Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 164,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "CSRF in Webmin 1.973 enables remote command execution via user creation and process features.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50126",
                    "author": "Mesh3l_911",
                    "first_seen": "2021-07-14",
                    "confidence": "High",
                    "title": "Webmin 1.973 - 'save_user.cgi' Cross-Site Request Forgery (CSRF)",
                    "summary": "Webmin 1.973 - 'save_user.cgi' Cross-Site Request Forgery (CSRF)",
                    "url": "https://www.exploit-db.com/exploits/50126",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2021-31762",
                    "summary": "CSRF in Webmin 1.973 enables remote command execution via user creation and process features.",
                    "what_happened": "CSRF in Webmin 1.973 enables remote command execution via user creation and process features.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ELECTRONICBOTS-CVE-2021-31762",
                        "https://kitploit.com/ru/tools/github/electronicbots/cve-2021-31762/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T10:03:53",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ELECTRONICBOTS-CVE-2021-31762"
                },
                {
                    "title": "Exploit for CVE-2021-31762",
                    "summary": "CSRF in Webmin 1.973 enables remote command execution via user creation and process features.",
                    "what_happened": "CSRF in Webmin 1.973 enables remote command execution via user creation and process features.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ELECTRONICBOTS-CVE-2021-31762",
                        "https://kitploit.com/ru/tools/github/electronicbots/cve-2021-31762/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T10:03:53",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/electronicbots/cve-2021-31762/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/50126",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ELECTRONICBOTS-CVE-2021-31762",
                "https://kitploit.com/ru/tools/github/electronicbots/cve-2021-31762/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:34:26Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/50126"
                }
            ]
        },
        {
            "id": "CVE-2021-31166",
            "vendor": "Microsoft",
            "product": "HTTP Protocol Stack",
            "title": "Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability",
            "summary": "Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.",
            "updated_at": "2026-09-09T15:29:32Z",
            "published_at": "2026-09-09T15:29:32Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 72,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Microsoft HTTP Protocol Stack contains a vulnerability in http.sys that allows for remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T15:07:06+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2021-31166 exploit",
                    "summary": "Exploit for CVE-2021-31166. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MAURICELAMBERT-CVE-2021-31166"
                },
                {
                    "title": "Exploit for CVE-2021-31166",
                    "summary": "DoS in IIS Web Server via malformed Accept-Encoding header with double commas causing BSOD.",
                    "what_happened": "DoS in IIS Web Server via malformed Accept-Encoding header with double commas causing BSOD.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MAURICELAMBERT-CVE-2021-31166",
                        "https://kitploit.com/en/tools/github/mauricelambert/cve-2021-31166/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-09T17:29:32",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/mauricelambert/cve-2021-31166/"
                },
                {
                    "repository": "PoC-in-GitHub · 0vercl0k/CVE-2021-31166",
                    "author": "0vercl0k",
                    "first_seen": "2021-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 826,
                    "title": "Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.",
                    "summary": "Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.",
                    "url": "https://github.com/0vercl0k/CVE-2021-31166"
                },
                {
                    "repository": "PoC-in-GitHub · zha0gongz1/CVE-2021-31166",
                    "author": "zha0gongz1",
                    "first_seen": "2021-05-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "PoC for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. Although it was defined as remote command execution, it can only cause the system to crash.",
                    "summary": "PoC for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely. Although it was defined as remote command execution, it can only cause the system to crash.",
                    "url": "https://github.com/zha0gongz1/CVE-2021-31166"
                },
                {
                    "repository": "PoC-in-GitHub · mvlnetdev/CVE-2021-31166-detection-rules",
                    "author": "mvlnetdev",
                    "first_seen": "2021-05-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Different rules to detect if CVE-2021-31166 is being exploited",
                    "summary": "Different rules to detect if CVE-2021-31166 is being exploited",
                    "url": "https://github.com/mvlnetdev/CVE-2021-31166-detection-rules"
                },
                {
                    "repository": "PoC-in-GitHub · corelight/CVE-2021-31166",
                    "author": "corelight",
                    "first_seen": "2021-05-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "HTTP Protocol Stack CVE-2021-31166",
                    "summary": "HTTP Protocol Stack CVE-2021-31166",
                    "url": "https://github.com/corelight/CVE-2021-31166"
                },
                {
                    "repository": "PoC-in-GitHub · zecopro/CVE-2021-31166",
                    "author": "zecopro",
                    "first_seen": "2021-05-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "simple bash script for exploit CVE-2021-31166",
                    "summary": "simple bash script for exploit CVE-2021-31166",
                    "url": "https://github.com/zecopro/CVE-2021-31166"
                },
                {
                    "repository": "PoC-in-GitHub · bgsilvait/WIn-CVE-2021-31166",
                    "author": "bgsilvait",
                    "first_seen": "2021-05-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-31166 repository",
                    "summary": "",
                    "url": "https://github.com/bgsilvait/WIn-CVE-2021-31166"
                },
                {
                    "repository": "PoC-in-GitHub · y0g3sh-99/CVE-2021-31166-Exploit",
                    "author": "y0g3sh-99",
                    "first_seen": "2021-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Exploit for MS Http Protocol Stack RCE vulnerability (CVE-2021-31166)",
                    "summary": "Exploit for MS Http Protocol Stack RCE vulnerability (CVE-2021-31166)",
                    "url": "https://github.com/y0g3sh-99/CVE-2021-31166-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · ZZ-SOCMAP/CVE-2021-31166",
                    "author": "ZZ-SOCMAP",
                    "first_seen": "2021-09-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": "Windows HTTP协议栈远程代码执行漏洞 CVE-2021-31166",
                    "summary": "Windows HTTP协议栈远程代码执行漏洞 CVE-2021-31166",
                    "url": "https://github.com/ZZ-SOCMAP/CVE-2021-31166"
                },
                {
                    "repository": "PoC-in-GitHub · iranzai/CVE-2021-31166-exploit",
                    "author": "iranzai",
                    "first_seen": "2021-10-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Just a simple CVE-2021-31166 exploit tool",
                    "summary": "Just a simple CVE-2021-31166 exploit tool",
                    "url": "https://github.com/iranzai/CVE-2021-31166-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · mauricelambert/CVE-2021-31166",
                    "author": "mauricelambert",
                    "first_seen": "2022-03-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.",
                    "summary": "CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.",
                    "url": "https://github.com/mauricelambert/CVE-2021-31166"
                },
                {
                    "repository": "PoC-in-GitHub · 0xmaximus/Home-Demolisher",
                    "author": "0xmaximus",
                    "first_seen": "2022-11-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "PoC for CVE-2021-31166 and CVE-2022-21907",
                    "summary": "PoC for CVE-2021-31166 and CVE-2022-21907",
                    "url": "https://github.com/0xmaximus/Home-Demolisher"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MAURICELAMBERT-CVE-2021-31166",
                "https://kitploit.com/en/tools/github/mauricelambert/cve-2021-31166/",
                "https://github.com/0vercl0k/CVE-2021-31166",
                "https://github.com/zha0gongz1/CVE-2021-31166",
                "https://github.com/mvlnetdev/CVE-2021-31166-detection-rules",
                "https://github.com/corelight/CVE-2021-31166",
                "https://github.com/zecopro/CVE-2021-31166",
                "https://github.com/bgsilvait/WIn-CVE-2021-31166",
                "https://github.com/y0g3sh-99/CVE-2021-31166-Exploit",
                "https://github.com/ZZ-SOCMAP/CVE-2021-31166",
                "https://github.com/iranzai/CVE-2021-31166-exploit",
                "https://github.com/mauricelambert/CVE-2021-31166",
                "https://github.com/0xmaximus/Home-Demolisher"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T15:29:32Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2021-30327",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Let's hijack our bootchain - CVE-2021-30327",
            "summary": "Let's hijack our bootchain - CVE-2021-30327",
            "updated_at": "2026-08-23T22:00:00Z",
            "published_at": "2026-08-23T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 75,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · Daniel224455/katana",
                    "author": "Daniel224455",
                    "first_seen": "2026-06-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": "Let's hijack our bootchain - CVE-2021-30327",
                    "summary": "Let's hijack our bootchain - CVE-2021-30327",
                    "url": "https://github.com/Daniel224455/katana"
                },
                {
                    "repository": "PoC-in-GitHub · Daniel224455/echidna",
                    "author": "Daniel224455",
                    "first_seen": "2026-08-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Unlock the bootloader of any exploitable device vulnerable to CVE-2021-30327",
                    "summary": "Unlock the bootloader of any exploitable device vulnerable to CVE-2021-30327",
                    "url": "https://github.com/Daniel224455/echidna"
                }
            ],
            "references": [
                "https://github.com/Daniel224455/katana",
                "https://github.com/Daniel224455/echidna"
            ],
            "timeline": [
                {
                    "at": "2026-08-23T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/Daniel224455/katana"
                }
            ]
        },
        {
            "id": "CVE-2021-28664",
            "vendor": "Arm",
            "product": "Mali Graphics Processing Unit (GPU)",
            "title": "Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability",
            "summary": "Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes.",
            "updated_at": "2026-09-11T22:00:00Z",
            "published_at": "2026-09-11T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 38,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · woaphone/CVE-2021-28664-PoC",
                    "author": "woaphone",
                    "first_seen": "2026-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A POC of CVE-2021-28664",
                    "summary": "A POC of CVE-2021-28664",
                    "url": "https://github.com/woaphone/CVE-2021-28664-PoC"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/woaphone/CVE-2021-28664-PoC"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-27137",
            "vendor": "DD-WRT",
            "product": "DD-WRT",
            "title": "DD-WRT Stack-Based Buffer Overflow Vulnerability",
            "summary": "DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.",
            "updated_at": "2026-07-20T22:00:00Z",
            "published_at": "2026-07-20T22:00:00Z",
            "cvss": 0,
            "confidence": 65,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-07-20T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-07-21",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-27101",
            "vendor": "Accellion",
            "product": "FTA",
            "title": "Accellion FTA SQL Injection Vulnerability",
            "summary": "Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.",
            "updated_at": "2026-09-07T17:47:48Z",
            "published_at": "2026-09-07T17:47:48Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 101,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "Unknown",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for misfortune-cookie CVE-2014-9222",
                    "summary": "Stack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.",
                    "what_happened": "Stack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=FC88F5FE-B4FC-50D7-BADB-82E69F300083",
                        "https://github.com/luel-4013/misfortune-cookie"
                    ],
                    "repository": "Sploitus",
                    "author": "luel-4013",
                    "first_seen": "2026-09-07T19:47:48",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=FC88F5FE-B4FC-50D7-BADB-82E69F300083"
                },
                {
                    "repository": "PoC-in-GitHub · luel-4013/misfortune-cookie",
                    "author": "luel-4013",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This interactive suite targets CVE-2014-9222 (Misfortune Cookie) in legacy RomPager web servers, alongside modular testing for CVE-2017-17215 (Huawei HG532 RCE), CVE-2018-14847 (MikroTik WinBox credential leak), and the CVE-2021-27101 / CVE-2021-27102 exploit chain (Accellion FTA).",
                    "summary": "This interactive suite targets CVE-2014-9222 (Misfortune Cookie) in legacy RomPager web servers, alongside modular testing for CVE-2017-17215 (Huawei HG532 RCE), CVE-2018-14847 (MikroTik WinBox credential leak), and the CVE-2021-27101 / CVE-2021-27102 exploit chain (Accellion FTA).",
                    "url": "https://github.com/luel-4013/misfortune-cookie"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=FC88F5FE-B4FC-50D7-BADB-82E69F300083",
                "https://github.com/luel-4013/misfortune-cookie"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T17:47:48Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
            "id": "CVE-2021-26910",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "firejail exploit",
            "summary": "Exploit for CVE-2021-26910. CVSS 7.8.",
            "updated_at": "2026-09-13T18:05:55Z",
            "published_at": "2026-09-13T18:05:55Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:05:55+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "firejail exploit",
                    "summary": "Exploit for CVE-2021-26910. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NETBLUE30-FIREJAIL"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NETBLUE30-FIREJAIL"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:05:55Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NETBLUE30-FIREJAIL"
                }
            ]
        },
        {
            "id": "CVE-2021-25837",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Ethermint-CVE-2021-25837",
            "summary": "Ethermint CVE-2021-25837 vulnerability in tools.",
            "updated_at": "2026-08-29T05:54:17Z",
            "published_at": "2026-08-29T05:54:17Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 37,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Ethermint CVE-2021-25837 vulnerability in tools.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Ethermint-CVE-2021-25837",
                    "summary": "Ethermint CVE-2021-25837 vulnerability in tools.",
                    "what_happened": "Ethermint CVE-2021-25837 vulnerability in tools.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ICZC-ETHERMINT-CVE-2021-25837",
                        "https://kitploit.com/it/tools/github/iczc/ethermint-cve-2021-25837/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-29T07:54:17",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ICZC-ETHERMINT-CVE-2021-25837"
                },
                {
                    "title": "Exploit for Ethermint-CVE-2021-25837",
                    "summary": "Ethermint CVE-2021-25837 vulnerability in tools.",
                    "what_happened": "Ethermint CVE-2021-25837 vulnerability in tools.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ICZC-ETHERMINT-CVE-2021-25837",
                        "https://kitploit.com/it/tools/github/iczc/ethermint-cve-2021-25837/"
                    ],
                    "repository": "kitploit.com",
                    "author": "it",
                    "first_seen": "2026-08-29T07:54:17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/it/tools/github/iczc/ethermint-cve-2021-25837/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ICZC-ETHERMINT-CVE-2021-25837",
                "https://kitploit.com/it/tools/github/iczc/ethermint-cve-2021-25837/"
            ],
            "timeline": [
                {
                    "at": "2026-08-29T05:54:17Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ICZC-ETHERMINT-CVE-2021-25837"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
        },
        {
            "id": "CVE-2021-25646",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2021-25646",
            "summary": "RCE in Apache Druid via javascript filter in sampler endpoint executing arbitrary commands.",
            "updated_at": "2026-08-25T23:29:54Z",
            "published_at": "2026-08-25T23:29:54Z",
            "cvss": 9,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 65,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Unknown",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "RCE in Apache Druid via javascript filter in sampler endpoint executing arbitrary commands.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2021-25646",
                    "summary": "RCE in Apache Druid via javascript filter in sampler endpoint executing arbitrary commands.",
                    "what_happened": "RCE in Apache Druid via javascript filter in sampler endpoint executing arbitrary commands.",
                    "cvss": 9,
                    "cvss_vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LP008-CVE-2021-25646",
                        "https://kitploit.com/pt/tools/github/lp008/cve-2021-25646/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-26T01:29:54",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LP008-CVE-2021-25646"
                },
                {
                    "title": "Exploit for CVE-2021-25646",
                    "summary": "RCE in Apache Druid via javascript filter in sampler endpoint executing arbitrary commands.",
                    "what_happened": "RCE in Apache Druid via javascript filter in sampler endpoint executing arbitrary commands.",
                    "cvss": 9,
                    "cvss_vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LP008-CVE-2021-25646",
                        "https://kitploit.com/pt/tools/github/lp008/cve-2021-25646/"
                    ],
                    "repository": "kitploit.com",
                    "author": "pt",
                    "first_seen": "2026-08-26T01:29:54",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/pt/tools/github/lp008/cve-2021-25646/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LP008-CVE-2021-25646",
                "https://kitploit.com/pt/tools/github/lp008/cve-2021-25646/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T23:29:54Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LP008-CVE-2021-25646"
                }
            ],
            "cvss_vector": "AV:N/AC:L/Au:S/C:C/I:C/A:C"
        },
        {
            "id": "CVE-2021-23758",
            "vendor": "Ajax.NET Professional",
            "product": "Ajax.NET Professional",
            "title": "Ajax.NET Professional Deserialization of Untrusted Data Vulnerability",
            "summary": "Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
            "updated_at": "2026-08-25T22:00:00Z",
            "published_at": "2026-08-25T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 63,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · numanturle/CVE-2021-23758-POC",
                    "author": "numanturle",
                    "first_seen": "2021-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 18,
                    "title": "CVE-2021-23758 repository",
                    "summary": "",
                    "url": "https://github.com/numanturle/CVE-2021-23758-POC"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/numanturle/CVE-2021-23758-POC"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-22941",
            "vendor": "Citrix",
            "product": "ShareFile",
            "title": "Citrix ShareFile Improper Access Control Vulnerability",
            "summary": "Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.",
            "updated_at": "2026-09-05T16:44:43Z",
            "published_at": "2026-09-05T16:44:43Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 46,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "Unknown",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2021-22941",
                    "summary": "RCE in Citrix ShareFile via Python exploit accepting a target URL and shell URL parameter.",
                    "what_happened": "RCE in Citrix ShareFile via Python exploit accepting a target URL and shell URL parameter.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HOAV18-CVE-2021-22941",
                        "https://kitploit.com/ru/tools/github/hoav18/cve-2021-22941/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T18:44:43",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HOAV18-CVE-2021-22941"
                },
                {
                    "title": "Exploit for CVE-2021-22941",
                    "summary": "RCE in Citrix ShareFile via Python exploit accepting a target URL and shell URL parameter.",
                    "what_happened": "RCE in Citrix ShareFile via Python exploit accepting a target URL and shell URL parameter.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HOAV18-CVE-2021-22941",
                        "https://kitploit.com/ru/tools/github/hoav18/cve-2021-22941/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T18:44:43",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/hoav18/cve-2021-22941/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HOAV18-CVE-2021-22941",
                "https://kitploit.com/ru/tools/github/hoav18/cve-2021-22941/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T16:44:43Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
            "id": "CVE-2021-22555",
            "vendor": "Linux",
            "product": "Kernel",
            "title": "Linux Kernel Heap Out-of-Bounds Write Vulnerability",
            "summary": "Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.",
            "updated_at": "2026-09-08T01:15:09Z",
            "published_at": "2026-09-08T01:15:09Z",
            "cvss": 8.3,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 159,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50135",
                    "author": "TheFloW",
                    "first_seen": "2021-07-15",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.19 < 5.9 - 'Netfilter Local Privilege Escalation",
                    "summary": "Linux Kernel 2.6.19 < 5.9 - 'Netfilter Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/50135",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2021-22555",
                    "summary": "Vulnerability in tools component identified as CVE-2021-22555.",
                    "what_happened": "Vulnerability in tools component identified as CVE-2021-22555.",
                    "cvss": 8.3,
                    "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "None",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WHATSWRONGANDWHY-CVE-2021-22555",
                        "https://kitploit.com/es/tools/github/whatswrongandwhy/cve-2021-22555/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T05:06:30",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WHATSWRONGANDWHY-CVE-2021-22555"
                },
                {
                    "title": "Exploit for CVE-2021-22555",
                    "summary": "Vulnerability in tools component identified as CVE-2021-22555.",
                    "what_happened": "Vulnerability in tools component identified as CVE-2021-22555.",
                    "cvss": 8.3,
                    "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Adjacent",
                    "authentication": "None",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WHATSWRONGANDWHY-CVE-2021-22555",
                        "https://kitploit.com/es/tools/github/whatswrongandwhy/cve-2021-22555/"
                    ],
                    "repository": "kitploit.com",
                    "author": "es",
                    "first_seen": "2026-09-03T05:06:30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/es/tools/github/whatswrongandwhy/cve-2021-22555/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/50135",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WHATSWRONGANDWHY-CVE-2021-22555",
                "https://kitploit.com/es/tools/github/whatswrongandwhy/cve-2021-22555/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:15:09Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-10-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-21973",
            "vendor": "VMware",
            "product": "vCenter Server and Cloud Foundation",
            "title": "VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability",
            "summary": "VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.",
            "updated_at": "2026-09-05T12:42:33Z",
            "published_at": "2026-09-05T12:42:33Z",
            "cvss": 5.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 126,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2021-21973-Automateme",
                    "summary": "Security vulnerability in Automate Me tools component.",
                    "what_happened": "Security vulnerability in Automate Me tools component.",
                    "cvss": 5.3,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREAKANONYMOUS-CVE-2021-21973-AUTOMATEME",
                        "https://kitploit.com/ru/tools/github/freakanonymous/cve-2021-21973-automateme/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T12:42:33",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREAKANONYMOUS-CVE-2021-21973-AUTOMATEME"
                },
                {
                    "title": "Exploit for CVE-2021-21973-Automateme",
                    "summary": "Security vulnerability in Automate Me tools component.",
                    "what_happened": "Security vulnerability in Automate Me tools component.",
                    "cvss": 5.3,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREAKANONYMOUS-CVE-2021-21973-AUTOMATEME",
                        "https://kitploit.com/ru/tools/github/freakanonymous/cve-2021-21973-automateme/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T12:42:33",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/freakanonymous/cve-2021-21973-automateme/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREAKANONYMOUS-CVE-2021-21973-AUTOMATEME",
                "https://kitploit.com/ru/tools/github/freakanonymous/cve-2021-21973-automateme/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:42:33Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-21809",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2021-21809 exploit",
            "summary": "Exploit for CVE-2021-21809. CVSS 9.1.",
            "updated_at": "2026-09-06T08:32:48Z",
            "published_at": "2026-09-06T08:32:48Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 83,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Command execution in Moodle 3.10 legacy spellchecker plugin via aspell path requires admin.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2021-21809",
                    "summary": "Command execution in Moodle 3.10 legacy spellchecker plugin via aspell path requires admin.",
                    "what_happened": "Command execution in Moodle 3.10 legacy spellchecker plugin via aspell path requires admin.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANLDORI-CVE-2021-21809",
                        "https://kitploit.com/ru/tools/github/anldori/cve-2021-21809/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T06:37:15",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANLDORI-CVE-2021-21809"
                },
                {
                    "title": "Exploit for CVE-2021-21809",
                    "summary": "Command execution in Moodle 3.10 legacy spellchecker plugin via aspell path requires admin.",
                    "what_happened": "Command execution in Moodle 3.10 legacy spellchecker plugin via aspell path requires admin.",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANLDORI-CVE-2021-21809",
                        "https://kitploit.com/ru/tools/github/anldori/cve-2021-21809/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T06:37:15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/anldori/cve-2021-21809/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANLDORI-CVE-2021-21809",
                "https://kitploit.com/ru/tools/github/anldori/cve-2021-21809/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:32:48Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANLDORI-CVE-2021-21809"
                }
            ]
        },
        {
            "id": "CVE-2021-21423",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Authorized security-research lab reproducing CVE-2021-21423 (GHSA-gg2g-m5wc-vccq): projen rebuild-bot pwn request via issue_comment",
            "summary": "Authorized security-research lab reproducing CVE-2021-21423 (GHSA-gg2g-m5wc-vccq): projen rebuild-bot pwn request via issue_comment",
            "updated_at": "2026-08-30T22:00:00Z",
            "published_at": "2026-08-30T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 36,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · pvharmo2/gha-lab-b9842b12c0",
                    "author": "pvharmo2",
                    "first_seen": "2026-08-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Authorized security-research lab reproducing CVE-2021-21423 (GHSA-gg2g-m5wc-vccq): projen rebuild-bot pwn request via issue_comment",
                    "summary": "Authorized security-research lab reproducing CVE-2021-21423 (GHSA-gg2g-m5wc-vccq): projen rebuild-bot pwn request via issue_comment",
                    "url": "https://github.com/pvharmo2/gha-lab-b9842b12c0"
                }
            ],
            "references": [
                "https://github.com/pvharmo2/gha-lab-b9842b12c0"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/pvharmo2/gha-lab-b9842b12c0"
                }
            ]
        },
        {
            "id": "CVE-2021-4281",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in .github/workflows/combine-prs.yml (snapshot of BraveUX/for-the-badge @ 409c1fda). Do not use; authorized reproduction only.",
            "summary": "Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in .github/workflows/combine-prs.yml (snapshot of BraveUX/for-the-badge @ 409c1fda). Do not use; authorized reproduction only.",
            "updated_at": "2026-08-30T22:00:00Z",
            "published_at": "2026-08-30T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 36,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · pvharmo2/gha-lab-232af4821f",
                    "author": "pvharmo2",
                    "first_seen": "2026-08-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in .github/workflows/combine-prs.yml (snapshot of BraveUX/for-the-badge @ 409c1fda). Do not use; authorized reproduction only.",
                    "summary": "Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in .github/workflows/combine-prs.yml (snapshot of BraveUX/for-the-badge @ 409c1fda). Do not use; authorized reproduction only.",
                    "url": "https://github.com/pvharmo2/gha-lab-232af4821f"
                }
            ],
            "references": [
                "https://github.com/pvharmo2/gha-lab-232af4821f"
            ],
            "timeline": [
                {
                    "at": "2026-08-30T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/pvharmo2/gha-lab-232af4821f"
                }
            ]
        },
        {
            "id": "CVE-2021-4034",
            "vendor": "Red Hat",
            "product": "Polkit",
            "title": "Red Hat Polkit Out-of-Bounds Read and Write Vulnerability",
            "summary": "The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.",
            "updated_at": "2026-09-13T22:00:00Z",
            "published_at": "2026-09-13T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1854,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50689",
                    "author": "Lance Biggerstaff",
                    "first_seen": "2022-01-27",
                    "confidence": "High",
                    "title": "PolicyKit-1 0.105-31 - Privilege Escalation",
                    "summary": "PolicyKit-1 0.105-31 - Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/50689",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · ryaagard/CVE-2021-4034",
                    "author": "ryaagard",
                    "first_seen": "2022-01-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 74,
                    "title": "Local Privilege Escalation in polkit's pkexec",
                    "summary": "Local Privilege Escalation in polkit's pkexec",
                    "url": "https://github.com/ryaagard/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · berdav/CVE-2021-4034",
                    "author": "berdav",
                    "first_seen": "2022-01-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2047,
                    "title": "CVE-2021-4034 1day",
                    "summary": "CVE-2021-4034 1day",
                    "url": "https://github.com/berdav/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · clubby789/CVE-2021-4034",
                    "author": "clubby789",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/clubby789/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · gbrsh/CVE-2021-4034",
                    "author": "gbrsh",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/gbrsh/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · arthepsy/CVE-2021-4034",
                    "author": "arthepsy",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1162,
                    "title": "PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)",
                    "summary": "PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)",
                    "url": "https://github.com/arthepsy/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Audiobahn/CVE-2021-4034",
                    "author": "Audiobahn",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "CVE-2021-4034 🎧",
                    "summary": "CVE-2021-4034 🎧",
                    "url": "https://github.com/Audiobahn/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · dzonerzy/poc-cve-2021-4034",
                    "author": "dzonerzy",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 114,
                    "title": "PoC for CVE-2021-4034 dubbed pwnkit",
                    "summary": "PoC for CVE-2021-4034 dubbed pwnkit",
                    "url": "https://github.com/dzonerzy/poc-cve-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · nikaiw/CVE-2021-4034",
                    "author": "nikaiw",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 59,
                    "title": "PoC for CVE-2021-4034",
                    "summary": "PoC for CVE-2021-4034",
                    "url": "https://github.com/nikaiw/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · mebeim/CVE-2021-4034",
                    "author": "mebeim",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 36,
                    "title": "CVE-2021-4034: Local Privilege Escalation in polkit's pkexec proof of concept",
                    "summary": "CVE-2021-4034: Local Privilege Escalation in polkit's pkexec proof of concept",
                    "url": "https://github.com/mebeim/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Ayrx/CVE-2021-4034",
                    "author": "Ayrx",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 90,
                    "title": "Exploit for CVE-2021-4034",
                    "summary": "Exploit for CVE-2021-4034",
                    "url": "https://github.com/Ayrx/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Y3A/CVE-2021-4034",
                    "author": "Y3A",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/Y3A/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · An00bRektn/CVE-2021-4034",
                    "author": "An00bRektn",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "A Golang implementation of clubby789's implementation of CVE-2021-4034",
                    "summary": "A Golang implementation of clubby789's implementation of CVE-2021-4034",
                    "url": "https://github.com/An00bRektn/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · ayypril/CVE-2021-4034",
                    "author": "ayypril",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/ayypril/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · wongwaituck/CVE-2021-4034",
                    "author": "wongwaituck",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/wongwaituck/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · 0x05a/my-cve-2021-4034-poc",
                    "author": "0x05a",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "my PoC",
                    "summary": "my PoC",
                    "url": "https://github.com/0x05a/my-cve-2021-4034-poc"
                },
                {
                    "repository": "PoC-in-GitHub · silocityit/cve-2021-4034-playground",
                    "author": "silocityit",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "impromptu pwn chal",
                    "summary": "impromptu pwn chal",
                    "url": "https://github.com/silocityit/cve-2021-4034-playground"
                },
                {
                    "repository": "PoC-in-GitHub · zhzyker/CVE-2021-4034",
                    "author": "zhzyker",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 45,
                    "title": "polkit pkexec Local Privilege Vulnerability to Add custom commands",
                    "summary": "polkit pkexec Local Privilege Vulnerability to Add custom commands",
                    "url": "https://github.com/zhzyker/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Immersive-Labs-Sec/CVE-2021-4034",
                    "author": "Immersive-Labs-Sec",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Proof of Concept for CVE-2021-4034 Polkit Privilege Escalation",
                    "summary": "Proof of Concept for CVE-2021-4034 Polkit Privilege Escalation",
                    "url": "https://github.com/Immersive-Labs-Sec/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · kimusan/pkwner",
                    "author": "kimusan",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 23,
                    "title": "A python3 and bash PoC for CVE-2021-4034 by Kim Schulz",
                    "summary": "A python3 and bash PoC for CVE-2021-4034 by Kim Schulz",
                    "url": "https://github.com/kimusan/pkwner"
                },
                {
                    "repository": "PoC-in-GitHub · N1et/CVE-2021-4034",
                    "author": "N1et",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Just a sh script file to CVE-2021-4034",
                    "summary": "Just a sh script file to CVE-2021-4034",
                    "url": "https://github.com/N1et/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Nero22k/CVE-2021-4034",
                    "author": "Nero22k",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Dirty PoC for CVE-2021-4034 (Pwnkit)",
                    "summary": "Dirty PoC for CVE-2021-4034 (Pwnkit)",
                    "url": "https://github.com/Nero22k/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · LukeGix/CVE-2021-4034",
                    "author": "LukeGix",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A stupid poc for CVE-2021-4034",
                    "summary": "A stupid poc for CVE-2021-4034",
                    "url": "https://github.com/LukeGix/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · aus-mate/CVE-2021-4034-POC",
                    "author": "aus-mate",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/aus-mate/CVE-2021-4034-POC"
                },
                {
                    "repository": "PoC-in-GitHub · chenaotian/CVE-2021-4034",
                    "author": "chenaotian",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "CVE-2021-4034 POC and Docker and Analysis write up",
                    "summary": "CVE-2021-4034 POC and Docker and Analysis write up",
                    "url": "https://github.com/chenaotian/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · moldabekov/CVE-2021-4034",
                    "author": "moldabekov",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Pseudopatch for CVE-2021-4034",
                    "summary": "Pseudopatch for CVE-2021-4034",
                    "url": "https://github.com/moldabekov/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · jostmart/-CVE-2021-4034",
                    "author": "jostmart",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/jostmart/-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · c3l3si4n/pwnkit",
                    "author": "c3l3si4n",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 24,
                    "title": "PoC for the CVE-2021-4034 vulnerability, affecting polkit < 0.120.",
                    "summary": "PoC for the CVE-2021-4034 vulnerability, affecting polkit < 0.120.",
                    "url": "https://github.com/c3l3si4n/pwnkit"
                },
                {
                    "repository": "PoC-in-GitHub · h3x0v3rl0rd/CVE-2021-4034",
                    "author": "h3x0v3rl0rd",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/h3x0v3rl0rd/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · ly4k/PwnKit",
                    "author": "ly4k",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1329,
                    "title": "Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation",
                    "summary": "Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation",
                    "url": "https://github.com/ly4k/PwnKit"
                },
                {
                    "repository": "PoC-in-GitHub · san3ncrypt3d/CVE-2021-4034-POC",
                    "author": "san3ncrypt3d",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/san3ncrypt3d/CVE-2021-4034-POC"
                },
                {
                    "repository": "PoC-in-GitHub · fdellwing/CVE-2021-4034",
                    "author": "fdellwing",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/fdellwing/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · xcanwin/CVE-2021-4034-UniontechOS",
                    "author": "xcanwin",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "统信UOS 桌面操作系统，存在CVE-2021-4034漏洞（Linux Polkit本地权限提升漏洞）。",
                    "summary": "统信UOS 桌面操作系统，存在CVE-2021-4034漏洞（Linux Polkit本地权限提升漏洞）。",
                    "url": "https://github.com/xcanwin/CVE-2021-4034-UniontechOS"
                },
                {
                    "repository": "PoC-in-GitHub · azminawwar/CVE-2021-4034",
                    "author": "azminawwar",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 in Bash Script",
                    "summary": "CVE-2021-4034 in Bash Script",
                    "url": "https://github.com/azminawwar/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · PeterGottesman/pwnkit-exploit",
                    "author": "PeterGottesman",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 38,
                    "title": "CVE-2021-4034 POC exploit",
                    "summary": "CVE-2021-4034 POC exploit",
                    "url": "https://github.com/PeterGottesman/pwnkit-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · sunny0day/CVE-2021-4034",
                    "author": "sunny0day",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/sunny0day/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · artemis-mike/cve-2021-4034",
                    "author": "artemis-mike",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "PoC for cve-2021-4034",
                    "summary": "PoC for cve-2021-4034",
                    "url": "https://github.com/artemis-mike/cve-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · whokilleddb/CVE-2021-4034",
                    "author": "whokilleddb",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "An exploit for CVE-2021-4034 aka Pwnkit: Local Privilege Escalation in polkit's pkexec",
                    "summary": "An exploit for CVE-2021-4034 aka Pwnkit: Local Privilege Escalation in polkit's pkexec",
                    "url": "https://github.com/whokilleddb/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · dadvlingd/CVE-2021-4034",
                    "author": "dadvlingd",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 20,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/dadvlingd/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · zcrosman/cve-2021-4034",
                    "author": "zcrosman",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/zcrosman/cve-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · robemmerson/CVE-2021-4034",
                    "author": "robemmerson",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/robemmerson/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · joeammond/CVE-2021-4034",
                    "author": "joeammond",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 180,
                    "title": "Python exploit code for CVE-2021-4034 (pwnkit)",
                    "summary": "Python exploit code for CVE-2021-4034 (pwnkit)",
                    "url": "https://github.com/joeammond/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · luijait/PwnKit-Exploit",
                    "author": "luijait",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 98,
                    "title": "Proof of Concept (PoC) CVE-2021-4034",
                    "summary": "Proof of Concept (PoC) CVE-2021-4034",
                    "url": "https://github.com/luijait/PwnKit-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Anonymous-Family/CVE-2021-4034",
                    "author": "Anonymous-Family",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Linux system service bug gives root on all major distros, exploit published A vulnerability in the pkexec component of Polkit identified as CVE-2021-4034 PwnKit is present in the default configuration of all major Linux distributions and can be exploited to gain privileges over the compj researchers.",
                    "summary": "Linux system service bug gives root on all major distros, exploit published A vulnerability in the pkexec component of Polkit identified as CVE-2021-4034 PwnKit is present in the default configuration of all major Linux distributions and can be exploited to gain privileges over the compj researchers.",
                    "url": "https://github.com/Anonymous-Family/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · phvilasboas/CVE-2021-4034",
                    "author": "phvilasboas",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/phvilasboas/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · vilasboasph/CVE-2021-4034",
                    "author": "vilasboasph",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/vilasboasph/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · callrbx/pkexec-lpe-poc",
                    "author": "callrbx",
                    "first_seen": "2022-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "POC for CVE-2021-4034",
                    "summary": "POC for CVE-2021-4034",
                    "url": "https://github.com/callrbx/pkexec-lpe-poc"
                },
                {
                    "repository": "PoC-in-GitHub · cd80-ctf/CVE-2021-4034",
                    "author": "cd80-ctf",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A simple proof-of-concept for CVE-2021-4034 (pkexec local privilege escalation)",
                    "summary": "A simple proof-of-concept for CVE-2021-4034 (pkexec local privilege escalation)",
                    "url": "https://github.com/cd80-ctf/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Al1ex/CVE-2021-4034",
                    "author": "Al1ex",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)",
                    "summary": "Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)",
                    "url": "https://github.com/Al1ex/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · ashutoshrohilla/CVE-2021-4034",
                    "author": "ashutoshrohilla",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository contains the exploit for vulnerability CVE-2021-4034 .",
                    "summary": "This repository contains the exploit for vulnerability CVE-2021-4034 .",
                    "url": "https://github.com/ashutoshrohilla/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · nikip72/CVE-2021-4034",
                    "author": "nikip72",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/nikip72/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · NiS3x/CVE-2021-4034",
                    "author": "NiS3x",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC CVE 2021-4034 PwnKit: Local Privilege Escalation Vulnerability Discovered in polkit’s pkexec",
                    "summary": "PoC CVE 2021-4034 PwnKit: Local Privilege Escalation Vulnerability Discovered in polkit’s pkexec",
                    "url": "https://github.com/NiS3x/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · thatstraw/CVE-2021-4034",
                    "author": "thatstraw",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/thatstraw/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · luckythandel/CVE-2021-4034",
                    "author": "luckythandel",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is a POC for the vulnerability found in polkit's pkexec binary which is used to run programs as another users.",
                    "summary": "This is a POC for the vulnerability found in polkit's pkexec binary which is used to run programs as another users.",
                    "url": "https://github.com/luckythandel/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Plethore/CVE-2021-4034",
                    "author": "Plethore",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Python exploit for CVE-2021-4034",
                    "summary": "Python exploit for CVE-2021-4034",
                    "url": "https://github.com/Plethore/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · evdenis/lsm_bpf_check_argc0",
                    "author": "evdenis",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 21,
                    "title": "LSM BPF module to block pwnkit (CVE-2021-4034) like exploits",
                    "summary": "LSM BPF module to block pwnkit (CVE-2021-4034) like exploits",
                    "url": "https://github.com/evdenis/lsm_bpf_check_argc0"
                },
                {
                    "repository": "PoC-in-GitHub · tahaafarooq/poppy",
                    "author": "tahaafarooq",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2021-4034 PoC , polkit < 0.131",
                    "summary": "CVE-2021-4034 PoC , polkit < 0.131",
                    "url": "https://github.com/tahaafarooq/poppy"
                },
                {
                    "repository": "PoC-in-GitHub · DosAmp/pkwned",
                    "author": "DosAmp",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Proof of Concept for CVE-2021-4034 (with experimental traceless exploitation)",
                    "summary": "Proof of Concept for CVE-2021-4034 (with experimental traceless exploitation)",
                    "url": "https://github.com/DosAmp/pkwned"
                },
                {
                    "repository": "PoC-in-GitHub · PwnFunction/CVE-2021-4034",
                    "author": "PwnFunction",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 352,
                    "title": "Proof of concept for pwnkit vulnerability",
                    "summary": "Proof of concept for pwnkit vulnerability",
                    "url": "https://github.com/PwnFunction/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · NULL0B/CVE-2021-4034",
                    "author": "NULL0B",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/NULL0B/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · locksec/CVE-2021-4034",
                    "author": "locksec",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Exploit PoC for the polkit pkexec (PWNKIT) vulnerability",
                    "summary": "Exploit PoC for the polkit pkexec (PWNKIT) vulnerability",
                    "url": "https://github.com/locksec/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · deoxykev/CVE-2021-4034-Rust",
                    "author": "deoxykev",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Linux LPE using polkit-1 written in Rust.",
                    "summary": "Linux LPE using polkit-1 written in Rust.",
                    "url": "https://github.com/deoxykev/CVE-2021-4034-Rust"
                },
                {
                    "repository": "PoC-in-GitHub · c3c/CVE-2021-4034",
                    "author": "c3c",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 28,
                    "title": "Pre-compiled builds for CVE-2021-4034",
                    "summary": "Pre-compiled builds for CVE-2021-4034",
                    "url": "https://github.com/c3c/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Fato07/Pwnkit-exploit",
                    "author": "Fato07",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit for pkexec (CVE-2021-4034)",
                    "summary": "Exploit for pkexec (CVE-2021-4034)",
                    "url": "https://github.com/Fato07/Pwnkit-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · EstamelGG/CVE-2021-4034-NoGCC",
                    "author": "EstamelGG",
                    "first_seen": "2022-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 78,
                    "title": "CVE-2021-4034简单优化，以应对没有安装gcc和make的目标环境",
                    "summary": "CVE-2021-4034简单优化，以应对没有安装gcc和make的目标环境",
                    "url": "https://github.com/EstamelGG/CVE-2021-4034-NoGCC"
                },
                {
                    "repository": "PoC-in-GitHub · pengalaman-1t/CVE-2021-4034",
                    "author": "pengalaman-1t",
                    "first_seen": "2022-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/pengalaman-1t/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · jpmcb/pwnkit-go",
                    "author": "jpmcb",
                    "first_seen": "2022-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Exploit for the PwnKit vulnerability, CVE-2021-4034, written in Go",
                    "summary": "Exploit for the PwnKit vulnerability, CVE-2021-4034, written in Go",
                    "url": "https://github.com/jpmcb/pwnkit-go"
                },
                {
                    "repository": "PoC-in-GitHub · JoyGhoshs/CVE-2021-4034",
                    "author": "JoyGhoshs",
                    "first_seen": "2022-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Exploit for Local Privilege Escalation Vulnerability in polkit’s pkexec",
                    "summary": "Exploit for Local Privilege Escalation Vulnerability in polkit’s pkexec",
                    "url": "https://github.com/JoyGhoshs/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · galoget/PwnKit-CVE-2021-4034",
                    "author": "galoget",
                    "first_seen": "2022-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/galoget/PwnKit-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Yakumwamba/POC-CVE-2021-4034",
                    "author": "Yakumwamba",
                    "first_seen": "2022-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/Yakumwamba/POC-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · ayoub-elbouzi/CVE-2021-4034-Pwnkit",
                    "author": "ayoub-elbouzi",
                    "first_seen": "2022-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)",
                    "summary": "PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)",
                    "url": "https://github.com/ayoub-elbouzi/CVE-2021-4034-Pwnkit"
                },
                {
                    "repository": "PoC-in-GitHub · oreosec/pwnkit",
                    "author": "oreosec",
                    "first_seen": "2022-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-4034",
                    "summary": "CVE-2021-4034",
                    "url": "https://github.com/oreosec/pwnkit"
                },
                {
                    "repository": "PoC-in-GitHub · CYB3RK1D/CVE-2021-4034-POC",
                    "author": "CYB3RK1D",
                    "first_seen": "2022-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "pwnkit",
                    "summary": "pwnkit",
                    "url": "https://github.com/CYB3RK1D/CVE-2021-4034-POC"
                },
                {
                    "repository": "PoC-in-GitHub · Rvn0xsy/CVE-2021-4034",
                    "author": "Rvn0xsy",
                    "first_seen": "2022-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 96,
                    "title": "CVE-2021-4034 Add Root User - Pkexec Local Privilege Escalation",
                    "summary": "CVE-2021-4034 Add Root User - Pkexec Local Privilege Escalation",
                    "url": "https://github.com/Rvn0xsy/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Kirill89/CVE-2021-4034",
                    "author": "Kirill89",
                    "first_seen": "2022-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "pkexec (Polkit) exploit of Privilege Escalation vulnerability CVE-2021-4034",
                    "summary": "pkexec (Polkit) exploit of Privilege Escalation vulnerability CVE-2021-4034",
                    "url": "https://github.com/Kirill89/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · NeonWhiteRabbit/CVE-2021-4034",
                    "author": "NeonWhiteRabbit",
                    "first_seen": "2022-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "Pwnkit Exploit (CVE-2021-4034), no download capabilty? Copy and paste it!",
                    "summary": "Pwnkit Exploit (CVE-2021-4034), no download capabilty? Copy and paste it!",
                    "url": "https://github.com/NeonWhiteRabbit/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · sofire/polkit-0.96-CVE-2021-4034",
                    "author": "sofire",
                    "first_seen": "2022-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "centos 6.10 rpm for fix polkit CVE-2021-4034;   centos 6.10的rpm包，修复CVE-2021-4034 漏洞",
                    "summary": "centos 6.10 rpm for fix polkit CVE-2021-4034;   centos 6.10的rpm包，修复CVE-2021-4034 漏洞",
                    "url": "https://github.com/sofire/polkit-0.96-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · codiobert/pwnkit-scanner",
                    "author": "codiobert",
                    "first_seen": "2022-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Check CVE-2021-4034 vulnerability",
                    "summary": "Check CVE-2021-4034 vulnerability",
                    "url": "https://github.com/codiobert/pwnkit-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · v-rzh/CVE-2021-4034",
                    "author": "v-rzh",
                    "first_seen": "2022-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Exploit for the PwnKit Vulnerability",
                    "summary": "Exploit for the PwnKit Vulnerability",
                    "url": "https://github.com/v-rzh/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · TW-D/PwnKit-Vulnerability_CVE-2021-4034",
                    "author": "TW-D",
                    "first_seen": "2022-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PwnKit - Local Privilege Escalation Vulnerability Discovered in polkit’s pkexec (CVE-2021-4034)",
                    "summary": "PwnKit - Local Privilege Escalation Vulnerability Discovered in polkit’s pkexec (CVE-2021-4034)",
                    "url": "https://github.com/TW-D/PwnKit-Vulnerability_CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · OXDBXKXO/ez-pwnkit",
                    "author": "OXDBXKXO",
                    "first_seen": "2022-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "Go implementation of the PwnKit Linux Local Privilege Escalation exploit (CVE-2021-4034)",
                    "summary": "Go implementation of the PwnKit Linux Local Privilege Escalation exploit (CVE-2021-4034)",
                    "url": "https://github.com/OXDBXKXO/ez-pwnkit"
                },
                {
                    "repository": "PoC-in-GitHub · milot/dissecting-pkexec-cve-2021-4034",
                    "author": "milot",
                    "first_seen": "2022-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/milot/dissecting-pkexec-cve-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · 0x01-sec/CVE-2021-4034-",
                    "author": "0x01-sec",
                    "first_seen": "2022-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)",
                    "summary": "PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)",
                    "url": "https://github.com/0x01-sec/CVE-2021-4034-"
                },
                {
                    "repository": "PoC-in-GitHub · navisec/CVE-2021-4034-PwnKit",
                    "author": "navisec",
                    "first_seen": "2022-01-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "PwnKit PoC for Polkit pkexec CVE-2021-4034",
                    "summary": "PwnKit PoC for Polkit pkexec CVE-2021-4034",
                    "url": "https://github.com/navisec/CVE-2021-4034-PwnKit"
                },
                {
                    "repository": "PoC-in-GitHub · Almorabea/pkexec-exploit",
                    "author": "Almorabea",
                    "first_seen": "2022-01-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 26,
                    "title": "pwnkit: Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)",
                    "summary": "pwnkit: Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)",
                    "url": "https://github.com/Almorabea/pkexec-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · teelrabbit/Polkit-pkexec-exploit-for-Linux",
                    "author": "teelrabbit",
                    "first_seen": "2022-01-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034",
                    "summary": "CVE-2021-4034",
                    "url": "https://github.com/teelrabbit/Polkit-pkexec-exploit-for-Linux"
                },
                {
                    "repository": "PoC-in-GitHub · scent2d/PoC-CVE-2021-4034",
                    "author": "scent2d",
                    "first_seen": "2022-02-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Pwnkit CVE-2021-4034",
                    "summary": "Pwnkit CVE-2021-4034",
                    "url": "https://github.com/scent2d/PoC-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · HrishitJoshi/CVE-2021-4034",
                    "author": "HrishitJoshi",
                    "first_seen": "2022-02-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PWNKIT - Local Privilege Escalation Vulnerability on Linux (Polkit)",
                    "summary": "PWNKIT - Local Privilege Escalation Vulnerability on Linux (Polkit)",
                    "url": "https://github.com/HrishitJoshi/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Ankit-Ojha16/CVE-2021-4034",
                    "author": "Ankit-Ojha16",
                    "first_seen": "2022-02-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/Ankit-Ojha16/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · G01d3nW01f/CVE-2021-4034",
                    "author": "G01d3nW01f",
                    "first_seen": "2022-02-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PwnKit auto generate and Serve",
                    "summary": "PwnKit auto generate and Serve",
                    "url": "https://github.com/G01d3nW01f/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · drapl0n/pwnKit",
                    "author": "drapl0n",
                    "first_seen": "2022-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "pwnKit: Privilege Escalation USB-Rubber-Ducky payload, which exploits CVE-2021-4034 in less than 10sec's and spawns root shell for you.",
                    "summary": "pwnKit: Privilege Escalation USB-Rubber-Ducky payload, which exploits CVE-2021-4034 in less than 10sec's and spawns root shell for you.",
                    "url": "https://github.com/drapl0n/pwnKit"
                },
                {
                    "repository": "PoC-in-GitHub · rvzsec/CVE-2021-4034",
                    "author": "rvzsec",
                    "first_seen": "2022-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec in Python",
                    "summary": "PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec in Python",
                    "url": "https://github.com/rvzsec/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Joffr3y/Polkit-CVE-2021-4034-HLP",
                    "author": "Joffr3y",
                    "first_seen": "2022-02-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Polkit CVE-2021-4034 exploitation in High-Level Programming Language",
                    "summary": "Polkit CVE-2021-4034 exploitation in High-Level Programming Language",
                    "url": "https://github.com/Joffr3y/Polkit-CVE-2021-4034-HLP"
                },
                {
                    "repository": "PoC-in-GitHub · ziadsaleemi/polkit_CVE-2021-4034",
                    "author": "ziadsaleemi",
                    "first_seen": "2022-02-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Ansible role to patch  RHSB-2022-001 Polkit Privilege Escalation - (CVE-2021-4034)",
                    "summary": "Ansible role to patch  RHSB-2022-001 Polkit Privilege Escalation - (CVE-2021-4034)",
                    "url": "https://github.com/ziadsaleemi/polkit_CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · FDlucifer/Pwnkit-go",
                    "author": "FDlucifer",
                    "first_seen": "2022-02-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A golang based exp for CVE-2021-4034 dubbed pwnkit (more features added......)",
                    "summary": "A golang based exp for CVE-2021-4034 dubbed pwnkit (more features added......)",
                    "url": "https://github.com/FDlucifer/Pwnkit-go"
                },
                {
                    "repository": "PoC-in-GitHub · pombredanne/CVE-2021-4034",
                    "author": "pombredanne",
                    "first_seen": "2022-02-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Polkit pkexec CVE-2021-4034 Proof Of Concept and Patching",
                    "summary": "Polkit pkexec CVE-2021-4034 Proof Of Concept and Patching",
                    "url": "https://github.com/pombredanne/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · cspshivam/cve-2021-4034",
                    "author": "cspshivam",
                    "first_seen": "2022-02-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "pwnkit exploit",
                    "summary": "pwnkit exploit",
                    "url": "https://github.com/cspshivam/cve-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · an0n7os/CVE-2021-4034",
                    "author": "an0n7os",
                    "first_seen": "2022-02-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/an0n7os/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · DanaEpp/pwncat_pwnkit",
                    "author": "DanaEpp",
                    "first_seen": "2022-02-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 32,
                    "title": "pwncat module that automatically exploits CVE-2021-4034 (pwnkit)",
                    "summary": "pwncat module that automatically exploits CVE-2021-4034 (pwnkit)",
                    "url": "https://github.com/DanaEpp/pwncat_pwnkit"
                },
                {
                    "repository": "PoC-in-GitHub · x04000/CVE-2021-4034",
                    "author": "x04000",
                    "first_seen": "2022-02-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A simple PWNKIT file to convert you to root",
                    "summary": "A simple PWNKIT file to convert you to root",
                    "url": "https://github.com/x04000/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · x04000/AutoPwnkit",
                    "author": "x04000",
                    "first_seen": "2022-02-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A tool to automate the exploit PWNKIT (CVE-2021-4034)",
                    "summary": "A tool to automate the exploit PWNKIT (CVE-2021-4034)",
                    "url": "https://github.com/x04000/AutoPwnkit"
                },
                {
                    "repository": "PoC-in-GitHub · hohn/codeql-sample-polkit",
                    "author": "hohn",
                    "first_seen": "2022-02-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "All stages of exploring the polkit CVE-2021-4034 using codeql",
                    "summary": "All stages of exploring the polkit CVE-2021-4034 using codeql",
                    "url": "https://github.com/hohn/codeql-sample-polkit"
                },
                {
                    "repository": "PoC-in-GitHub · ck00004/CVE-2021-4034",
                    "author": "ck00004",
                    "first_seen": "2022-02-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 28,
                    "title": "CVE-2021-4034 centos8可用版本",
                    "summary": "CVE-2021-4034 centos8可用版本",
                    "url": "https://github.com/ck00004/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · LJP-TW/CVE-2021-4034",
                    "author": "LJP-TW",
                    "first_seen": "2022-02-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "pkexec EoP exploit",
                    "summary": "pkexec EoP exploit",
                    "url": "https://github.com/LJP-TW/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · fnknda/CVE-2021-4034_POC",
                    "author": "fnknda",
                    "first_seen": "2022-02-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Proof Of Concept for the 2021's pkexec vulnerability CVE-2021-4034",
                    "summary": "Proof Of Concept for the 2021's pkexec vulnerability CVE-2021-4034",
                    "url": "https://github.com/fnknda/CVE-2021-4034_POC"
                },
                {
                    "repository": "PoC-in-GitHub · Tanmay-N/CVE-2021-4034",
                    "author": "Tanmay-N",
                    "first_seen": "2022-02-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/Tanmay-N/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · hahaleyile/CVE-2021-4034",
                    "author": "hahaleyile",
                    "first_seen": "2022-02-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/hahaleyile/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · movvamrocks/PwnKit-CVE-2021-4034",
                    "author": "movvamrocks",
                    "first_seen": "2022-02-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/movvamrocks/PwnKit-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Squirre17/CVE-2021-4034",
                    "author": "Squirre17",
                    "first_seen": "2022-03-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "polkit-pkexec local privilege escalation vulnerability",
                    "summary": "polkit-pkexec local privilege escalation vulnerability",
                    "url": "https://github.com/Squirre17/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Jesrat/make_me_root",
                    "author": "Jesrat",
                    "first_seen": "2022-03-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034",
                    "summary": "CVE-2021-4034",
                    "url": "https://github.com/Jesrat/make_me_root"
                },
                {
                    "repository": "PoC-in-GitHub · defhacks/cve-2021-4034",
                    "author": "defhacks",
                    "first_seen": "2022-03-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "port of CVE-2021-4034 exploit to Rust/cargo for my own edification",
                    "summary": "port of CVE-2021-4034 exploit to Rust/cargo for my own edification",
                    "url": "https://github.com/defhacks/cve-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · ITMarcin2211/Polkit-s-Pkexec-CVE-2021-4034",
                    "author": "ITMarcin2211",
                    "first_seen": "2022-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Polkit's Pkexec CVE-2021-4034 Proof Of Concept and Patching",
                    "summary": "Polkit's Pkexec CVE-2021-4034 Proof Of Concept and Patching",
                    "url": "https://github.com/ITMarcin2211/Polkit-s-Pkexec-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · edsonjt81/CVE-2021-4034-Linux",
                    "author": "edsonjt81",
                    "first_seen": "2022-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/edsonjt81/CVE-2021-4034-Linux"
                },
                {
                    "repository": "PoC-in-GitHub · nel0x/pwnkit-vulnerability",
                    "author": "nel0x",
                    "first_seen": "2022-03-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 (PWNKIT).",
                    "summary": "CVE-2021-4034 (PWNKIT).",
                    "url": "https://github.com/nel0x/pwnkit-vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · TomSgn/CVE-2021-4034",
                    "author": "TomSgn",
                    "first_seen": "2022-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "pkexec --> privilege escalation",
                    "summary": "pkexec --> privilege escalation",
                    "url": "https://github.com/TomSgn/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · TheJoyOfHacking/berdav-CVE-2021-4034",
                    "author": "TheJoyOfHacking",
                    "first_seen": "2022-03-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/TheJoyOfHacking/berdav-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · tzwlhack/CVE-2021-4034",
                    "author": "tzwlhack",
                    "first_seen": "2022-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/tzwlhack/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · jcatala/f_poc_cve-2021-4034",
                    "author": "jcatala",
                    "first_seen": "2022-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/jcatala/f_poc_cve-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Nosferatuvjr/PwnKit",
                    "author": "Nosferatuvjr",
                    "first_seen": "2022-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Prova de conceito para a vulnerabilidade Polkit Pkexec: CVE-2021-4034(Pkexec Local Privilege Escalation)",
                    "summary": "Prova de conceito para a vulnerabilidade Polkit Pkexec: CVE-2021-4034(Pkexec Local Privilege Escalation)",
                    "url": "https://github.com/Nosferatuvjr/PwnKit"
                },
                {
                    "repository": "PoC-in-GitHub · TotallyNotAHaxxer/CVE-2021-4034",
                    "author": "TotallyNotAHaxxer",
                    "first_seen": "2022-04-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "POC for the priv esc exploit in PKEXEC [ CVE -2021-4034 ] ( needs fixing, not the best) Converted into go",
                    "summary": "POC for the priv esc exploit in PKEXEC [ CVE -2021-4034 ] ( needs fixing, not the best) Converted into go",
                    "url": "https://github.com/TotallyNotAHaxxer/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · 0x4ndy/CVE-2021-4034-PoC",
                    "author": "0x4ndy",
                    "first_seen": "2022-04-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 PoC",
                    "summary": "CVE-2021-4034 PoC",
                    "url": "https://github.com/0x4ndy/CVE-2021-4034-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · antoinenguyen-09/CVE-2021-4034",
                    "author": "antoinenguyen-09",
                    "first_seen": "2022-04-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "My research about  CVE-2021-4034",
                    "summary": "My research about  CVE-2021-4034",
                    "url": "https://github.com/antoinenguyen-09/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · wudicainiao/cve-2021-4034",
                    "author": "wudicainiao",
                    "first_seen": "2022-05-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "CVE-2021-4034 for single commcand",
                    "summary": "CVE-2021-4034 for single commcand",
                    "url": "https://github.com/wudicainiao/cve-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · TanmoyG1800/CVE-2021-4034",
                    "author": "TanmoyG1800",
                    "first_seen": "2022-06-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/TanmoyG1800/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · CronoX1/CVE-2021-4034",
                    "author": "CronoX1",
                    "first_seen": "2022-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit modificado para el tito Eu",
                    "summary": "Exploit modificado para el tito Eu",
                    "url": "https://github.com/CronoX1/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · supportingmx/cve-2021-4034",
                    "author": "supportingmx",
                    "first_seen": "2022-07-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/supportingmx/cve-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · A1vinSmith/CVE-2021-4034",
                    "author": "A1vinSmith",
                    "first_seen": "2022-08-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Script en python sobre la vulnerabilidad CVE-2021-4034",
                    "summary": "Script en python sobre la vulnerabilidad CVE-2021-4034",
                    "url": "https://github.com/A1vinSmith/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · HellGateCorp/pwnkit",
                    "author": "HellGateCorp",
                    "first_seen": "2022-08-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC for CVE-2021-4034.",
                    "summary": "PoC for CVE-2021-4034.",
                    "url": "https://github.com/HellGateCorp/pwnkit"
                },
                {
                    "repository": "PoC-in-GitHub · Silencecyber/cve-2021-4034",
                    "author": "Silencecyber",
                    "first_seen": "2022-08-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/Silencecyber/cve-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Geni0r/cve-2021-4034-poc",
                    "author": "Geni0r",
                    "first_seen": "2022-08-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/Geni0r/cve-2021-4034-poc"
                },
                {
                    "repository": "PoC-in-GitHub · RakhithJK/CVE-2021-4034-new",
                    "author": "RakhithJK",
                    "first_seen": "2022-08-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/RakhithJK/CVE-2021-4034-new"
                },
                {
                    "repository": "PoC-in-GitHub · Pixailz/CVE-2021-4034",
                    "author": "Pixailz",
                    "first_seen": "2022-10-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "polkit priv esc: pkexec out of boundary exploit",
                    "summary": "polkit priv esc: pkexec out of boundary exploit",
                    "url": "https://github.com/Pixailz/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · toecesws/CVE-2021-4034",
                    "author": "toecesws",
                    "first_seen": "2022-10-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Vulnerability to CVE-2021-4034 Pwnkit",
                    "summary": "Vulnerability to CVE-2021-4034 Pwnkit",
                    "url": "https://github.com/toecesws/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · tachote/CVE-2021-4034",
                    "author": "tachote",
                    "first_seen": "2022-11-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-4034, exploit para escalado de privilegios en SO Linux  a root",
                    "summary": "CVE-2021-4034, exploit para escalado de privilegios en SO Linux  a root",
                    "url": "https://github.com/tachote/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · fei9747/CVE-2021-4034",
                    "author": "fei9747",
                    "first_seen": "2022-11-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/fei9747/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · pyhrr0/pwnkit",
                    "author": "pyhrr0",
                    "first_seen": "2023-01-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 PoC",
                    "summary": "CVE-2021-4034 PoC",
                    "url": "https://github.com/pyhrr0/pwnkit"
                },
                {
                    "repository": "PoC-in-GitHub · mutur4/CVE-2021-4034",
                    "author": "mutur4",
                    "first_seen": "2023-01-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A pwnkit N-Day exploit",
                    "summary": "A pwnkit N-Day exploit",
                    "url": "https://github.com/mutur4/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · h3x0v3rl0rd/CVE-2021-4034_Python3",
                    "author": "h3x0v3rl0rd",
                    "first_seen": "2023-02-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/h3x0v3rl0rd/CVE-2021-4034_Python3"
                },
                {
                    "repository": "PoC-in-GitHub · ps-interactive/lab_cve-2021-4034-polkit-emulation-and-detection",
                    "author": "ps-interactive",
                    "first_seen": "2023-06-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/ps-interactive/lab_cve-2021-4034-polkit-emulation-and-detection"
                },
                {
                    "repository": "PoC-in-GitHub · asepsaepdin/CVE-2021-4034",
                    "author": "asepsaepdin",
                    "first_seen": "2023-07-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/asepsaepdin/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · JohnGilbert57/CVE-2021-4034-Capture-the-flag",
                    "author": "JohnGilbert57",
                    "first_seen": "2023-07-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/JohnGilbert57/CVE-2021-4034-Capture-the-flag"
                },
                {
                    "repository": "PoC-in-GitHub · Part01-Pai/Polkit-Permission-promotion-compiled",
                    "author": "Part01-Pai",
                    "first_seen": "2023-11-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Polkit提权包 CVE-2021-4034 （供需要的人方便使用",
                    "summary": "Polkit提权包 CVE-2021-4034 （供需要的人方便使用",
                    "url": "https://github.com/Part01-Pai/Polkit-Permission-promotion-compiled"
                },
                {
                    "repository": "PoC-in-GitHub · cdxiaodong/CVE-2021-4034-touch",
                    "author": "cdxiaodong",
                    "first_seen": "2024-01-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "touch 生成文件",
                    "summary": "touch 生成文件",
                    "url": "https://github.com/cdxiaodong/CVE-2021-4034-touch"
                },
                {
                    "repository": "PoC-in-GitHub · LucasPDiniz/CVE-2021-4034",
                    "author": "LucasPDiniz",
                    "first_seen": "2024-01-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Local Privilege Escalation (LPE) vulnerability in Polkit - Pwnkit",
                    "summary": "Local Privilege Escalation (LPE) vulnerability in Polkit - Pwnkit",
                    "url": "https://github.com/LucasPDiniz/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Pol-Ruiz/CVE-2021-4034",
                    "author": "Pol-Ruiz",
                    "first_seen": "2024-01-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/Pol-Ruiz/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · cerodah/CVE-2021-4034",
                    "author": "cerodah",
                    "first_seen": "2024-01-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC de Polkit",
                    "summary": "PoC de Polkit",
                    "url": "https://github.com/cerodah/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · FancySauce/PwnKit-CVE-2021-4034",
                    "author": "FancySauce",
                    "first_seen": "2024-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/FancySauce/PwnKit-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · wechicken456/CVE-2021-4034-CTF-writeup",
                    "author": "wechicken456",
                    "first_seen": "2024-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/wechicken456/CVE-2021-4034-CTF-writeup"
                },
                {
                    "repository": "PoC-in-GitHub · ASG-CASTLE/CVE-2021-4034",
                    "author": "ASG-CASTLE",
                    "first_seen": "2024-04-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/ASG-CASTLE/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · X-Projetion/Exploiting-PwnKit-CVE-2021-4034-",
                    "author": "X-Projetion",
                    "first_seen": "2024-05-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/X-Projetion/Exploiting-PwnKit-CVE-2021-4034-"
                },
                {
                    "repository": "PoC-in-GitHub · evkl1d/CVE-2021-4034",
                    "author": "evkl1d",
                    "first_seen": "2024-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "polkit",
                    "summary": "polkit",
                    "url": "https://github.com/evkl1d/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · zxybfq/CVE-2021-4034",
                    "author": "zxybfq",
                    "first_seen": "2024-08-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/zxybfq/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · EuJin03/CVE-2021-4034-PoC",
                    "author": "EuJin03",
                    "first_seen": "2024-10-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/EuJin03/CVE-2021-4034-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · dh4r4/PwnKit-CVE-2021-4034-",
                    "author": "dh4r4",
                    "first_seen": "2025-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A rewrite of the Polkit vulnerability.",
                    "summary": "A rewrite of the Polkit vulnerability.",
                    "url": "https://github.com/dh4r4/PwnKit-CVE-2021-4034-"
                },
                {
                    "repository": "PoC-in-GitHub · 12bijaya/CVE-2021-4034-PwnKit-",
                    "author": "12bijaya",
                    "first_seen": "2025-02-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Code to exploit CVE-2021-4034",
                    "summary": "Code to exploit CVE-2021-4034",
                    "url": "https://github.com/12bijaya/CVE-2021-4034-PwnKit-"
                },
                {
                    "repository": "PoC-in-GitHub · nagorealbisu/CVE-2021-4034",
                    "author": "nagorealbisu",
                    "first_seen": "2025-04-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/nagorealbisu/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · igonzalez357/CVE-2021-4034-PwnKit-",
                    "author": "igonzalez357",
                    "first_seen": "2025-04-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Este repositorio muestra cómo explotar la vulnerabilidad CVE-2021-4034.",
                    "summary": "Este repositorio muestra cómo explotar la vulnerabilidad CVE-2021-4034.",
                    "url": "https://github.com/igonzalez357/CVE-2021-4034-PwnKit-"
                },
                {
                    "repository": "PoC-in-GitHub · marcosChoucino/CVE-2021-4034",
                    "author": "marcosChoucino",
                    "first_seen": "2025-04-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit de la vulneravilidad CVE-2021-4034",
                    "summary": "Exploit de la vulneravilidad CVE-2021-4034",
                    "url": "https://github.com/marcosChoucino/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · ikerSandoval003/CVE-2021-4034",
                    "author": "ikerSandoval003",
                    "first_seen": "2025-04-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/ikerSandoval003/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · AsierEgana/cve-2021-4034",
                    "author": "AsierEgana",
                    "first_seen": "2025-04-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/AsierEgana/cve-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Z3R0space/CVE-2021-4034",
                    "author": "Z3R0space",
                    "first_seen": "2025-05-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This contains single-file exploit for cve-2021-4034 which is a Polkit Local Privilege Escalation. Use it wisely!",
                    "summary": "This contains single-file exploit for cve-2021-4034 which is a Polkit Local Privilege Escalation. Use it wisely!",
                    "url": "https://github.com/Z3R0space/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Milad-Rafie/PwnKit-Local-Privilege-Escalation-Vulnerability-Discovered-in-polkit-s-pkexec-CVE-2021-4034",
                    "author": "Milad-Rafie",
                    "first_seen": "2025-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Software Vulnerabilities and mitigation university course, to show exploitation and remediation caused by this vulnerability",
                    "summary": "Software Vulnerabilities and mitigation university course, to show exploitation and remediation caused by this vulnerability",
                    "url": "https://github.com/Milad-Rafie/PwnKit-Local-Privilege-Escalation-Vulnerability-Discovered-in-polkit-s-pkexec-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · kali-guru/Pwnkit-CVE-2021-4034",
                    "author": "kali-guru",
                    "first_seen": "2025-05-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Automation Exploit",
                    "summary": "Automation Exploit",
                    "url": "https://github.com/kali-guru/Pwnkit-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · jscamposx/hack",
                    "author": "jscamposx",
                    "first_seen": "2025-06-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Repositorio de investigación de seguridad que contiene una Prueba de Concepto (PoC) para la vulnerabilidad CVE-2021-4034 (PwnKit) y utilidades de scripting para la demostración de escalada de privilegios y ejecución remota en entornos Linux.",
                    "summary": "Repositorio de investigación de seguridad que contiene una Prueba de Concepto (PoC) para la vulnerabilidad CVE-2021-4034 (PwnKit) y utilidades de scripting para la demostración de escalada de privilegios y ejecución remota en entornos Linux.",
                    "url": "https://github.com/jscamposx/hack"
                },
                {
                    "repository": "PoC-in-GitHub · BugVex/Poison-HTB-Report",
                    "author": "BugVex",
                    "first_seen": "2025-06-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Privilege Escalation on HTB \"Poison\" using PwnKit (CVE-2021-4034)",
                    "summary": "Privilege Escalation on HTB \"Poison\" using PwnKit (CVE-2021-4034)",
                    "url": "https://github.com/BugVex/Poison-HTB-Report"
                },
                {
                    "repository": "PoC-in-GitHub · dr4xp/pwnkit-helper",
                    "author": "dr4xp",
                    "first_seen": "2025-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "For CTF's and Safe Environments.... CVE-2021-4034 Local PrivEsc.",
                    "summary": "For CTF's and Safe Environments.... CVE-2021-4034 Local PrivEsc.",
                    "url": "https://github.com/dr4xp/pwnkit-helper"
                },
                {
                    "repository": "PoC-in-GitHub · boro03/CVE-2021-4034",
                    "author": "boro03",
                    "first_seen": "2025-12-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/boro03/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · ramahmdr/PwnKit",
                    "author": "ramahmdr",
                    "first_seen": "2026-01-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation",
                    "summary": "Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation",
                    "url": "https://github.com/ramahmdr/PwnKit"
                },
                {
                    "repository": "PoC-in-GitHub · Abbykito/KERNELexploits",
                    "author": "Abbykito",
                    "first_seen": "2026-03-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation",
                    "summary": "Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation",
                    "url": "https://github.com/Abbykito/KERNELexploits"
                },
                {
                    "repository": "PoC-in-GitHub · Allu-mette/cve-2021-4034",
                    "author": "Allu-mette",
                    "first_seen": "2026-03-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC of CVE-2021-4034 (PwnKit) for personal training purposes.",
                    "summary": "PoC of CVE-2021-4034 (PwnKit) for personal training purposes.",
                    "url": "https://github.com/Allu-mette/cve-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · devianntsec/CVE-2021-4034",
                    "author": "devianntsec",
                    "first_seen": "2026-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Advanced Linux Privilege Escalation research on CVE-2021-4034 (PwnKit). Features an optimized exploit with 7 polymorphic payload modes (Interactive Shell, Backdoor, User Creation, Reverse Shell, etc). Portfolio piece focused on memory corruption logic, environment variable manipulation, and anti-forensic techniques.",
                    "summary": "Advanced Linux Privilege Escalation research on CVE-2021-4034 (PwnKit). Features an optimized exploit with 7 polymorphic payload modes (Interactive Shell, Backdoor, User Creation, Reverse Shell, etc). Portfolio piece focused on memory corruption logic, environment variable manipulation, and anti-forensic techniques.",
                    "url": "https://github.com/devianntsec/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · vaibhavkrishna12004/ubuntu-privesc-lab",
                    "author": "vaibhavkrishna12004",
                    "first_seen": "2026-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)",
                    "summary": "Full penetration testing workflow: credential brute force, SSH access and privilege escalation (CVE-2021-4034)",
                    "url": "https://github.com/vaibhavkrishna12004/ubuntu-privesc-lab"
                },
                {
                    "repository": "PoC-in-GitHub · Murguii/DEV-CVE-2021-4034",
                    "author": "Murguii",
                    "first_seen": "2026-04-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Repositorio para la práctica de DEV sobre la vulnerabilidad CVE-2021-4034. Realizada únicamente con fines académicos.",
                    "summary": "Repositorio para la práctica de DEV sobre la vulnerabilidad CVE-2021-4034. Realizada únicamente con fines académicos.",
                    "url": "https://github.com/Murguii/DEV-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · B1gN0Se/PwnKit_CVE-2021-4034",
                    "author": "B1gN0Se",
                    "first_seen": "2026-04-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/B1gN0Se/PwnKit_CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · usmansec/-CVE-2021-4034",
                    "author": "usmansec",
                    "first_seen": "2026-05-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/usmansec/-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · vorkampfer/pwnkit_safety_check",
                    "author": "vorkampfer",
                    "first_seen": "2026-05-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PwnKit (CVE-2021-4034) Safe Checker This tool performs read-only checks and does not attempt exploitation.",
                    "summary": "PwnKit (CVE-2021-4034) Safe Checker This tool performs read-only checks and does not attempt exploitation.",
                    "url": "https://github.com/vorkampfer/pwnkit_safety_check"
                },
                {
                    "repository": "PoC-in-GitHub · rusakalimantan/PwnKit-CVE-2021-4034",
                    "author": "rusakalimantan",
                    "first_seen": "2026-05-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC for PwnKit-CVE-2021-4034 - Pkexec Local Privilege Escalation",
                    "summary": "PoC for PwnKit-CVE-2021-4034 - Pkexec Local Privilege Escalation",
                    "url": "https://github.com/rusakalimantan/PwnKit-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · jayhutajulu1/PwnKit-CVE-2021-4034",
                    "author": "jayhutajulu1",
                    "first_seen": "2026-05-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "PoC for PwnKit / CVE-2021-4034 - Pkexec Local Privilege Escalation",
                    "summary": "PoC for PwnKit / CVE-2021-4034 - Pkexec Local Privilege Escalation",
                    "url": "https://github.com/jayhutajulu1/PwnKit-CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · Leemyunglyul/cve-2021-4034-mock",
                    "author": "Leemyunglyul",
                    "first_seen": "2026-05-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/Leemyunglyul/cve-2021-4034-mock"
                },
                {
                    "repository": "PoC-in-GitHub · mac3d0/CVE-2021-4034-pwnkit",
                    "author": "mac3d0",
                    "first_seen": "2026-06-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC educacional do CVE-2021-4034, o PwnKit, LPE via pkexec do polkit. Uso autorizado apenas.",
                    "summary": "PoC educacional do CVE-2021-4034, o PwnKit, LPE via pkexec do polkit. Uso autorizado apenas.",
                    "url": "https://github.com/mac3d0/CVE-2021-4034-pwnkit"
                },
                {
                    "repository": "PoC-in-GitHub · krleejihyeong/WHS4_CVE-2021-4034",
                    "author": "krleejihyeong",
                    "first_seen": "2026-07-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Whitehat School 4기 CVE-2021-4034 분석 및 POC 작성",
                    "summary": "Whitehat School 4기 CVE-2021-4034 분석 및 POC 작성",
                    "url": "https://github.com/krleejihyeong/WHS4_CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · nicoibarburu/CVE-2021-4034",
                    "author": "nicoibarburu",
                    "first_seen": "2026-08-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is my simple implementation of an exploit for the PwnKit vulnerability.",
                    "summary": "This is my simple implementation of an exploit for the PwnKit vulnerability.",
                    "url": "https://github.com/nicoibarburu/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · iurhfiu6/CVE-2021-4034",
                    "author": "iurhfiu6",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-4034 repository",
                    "summary": "",
                    "url": "https://github.com/iurhfiu6/CVE-2021-4034"
                },
                {
                    "repository": "PoC-in-GitHub · r00t-byte/Pwnkit-CVE-2021-4034-LPE",
                    "author": "r00t-byte",
                    "first_seen": "2026-09-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PwnKit - polkit pkexec Local Privilege Escalation <= 0.105-31",
                    "summary": "PwnKit - polkit pkexec Local Privilege Escalation <= 0.105-31",
                    "url": "https://github.com/r00t-byte/Pwnkit-CVE-2021-4034-LPE"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/50689",
                "https://github.com/ryaagard/CVE-2021-4034",
                "https://github.com/berdav/CVE-2021-4034",
                "https://github.com/clubby789/CVE-2021-4034",
                "https://github.com/gbrsh/CVE-2021-4034",
                "https://github.com/arthepsy/CVE-2021-4034",
                "https://github.com/Audiobahn/CVE-2021-4034",
                "https://github.com/dzonerzy/poc-cve-2021-4034",
                "https://github.com/nikaiw/CVE-2021-4034",
                "https://github.com/mebeim/CVE-2021-4034",
                "https://github.com/Ayrx/CVE-2021-4034",
                "https://github.com/Y3A/CVE-2021-4034",
                "https://github.com/An00bRektn/CVE-2021-4034",
                "https://github.com/ayypril/CVE-2021-4034",
                "https://github.com/wongwaituck/CVE-2021-4034",
                "https://github.com/0x05a/my-cve-2021-4034-poc",
                "https://github.com/silocityit/cve-2021-4034-playground",
                "https://github.com/zhzyker/CVE-2021-4034",
                "https://github.com/Immersive-Labs-Sec/CVE-2021-4034",
                "https://github.com/kimusan/pkwner",
                "https://github.com/N1et/CVE-2021-4034",
                "https://github.com/Nero22k/CVE-2021-4034",
                "https://github.com/LukeGix/CVE-2021-4034",
                "https://github.com/aus-mate/CVE-2021-4034-POC",
                "https://github.com/chenaotian/CVE-2021-4034",
                "https://github.com/moldabekov/CVE-2021-4034",
                "https://github.com/jostmart/-CVE-2021-4034",
                "https://github.com/c3l3si4n/pwnkit",
                "https://github.com/h3x0v3rl0rd/CVE-2021-4034",
                "https://github.com/ly4k/PwnKit",
                "https://github.com/san3ncrypt3d/CVE-2021-4034-POC",
                "https://github.com/fdellwing/CVE-2021-4034",
                "https://github.com/xcanwin/CVE-2021-4034-UniontechOS",
                "https://github.com/azminawwar/CVE-2021-4034",
                "https://github.com/PeterGottesman/pwnkit-exploit",
                "https://github.com/sunny0day/CVE-2021-4034",
                "https://github.com/artemis-mike/cve-2021-4034",
                "https://github.com/whokilleddb/CVE-2021-4034",
                "https://github.com/dadvlingd/CVE-2021-4034",
                "https://github.com/zcrosman/cve-2021-4034",
                "https://github.com/robemmerson/CVE-2021-4034",
                "https://github.com/joeammond/CVE-2021-4034",
                "https://github.com/luijait/PwnKit-Exploit",
                "https://github.com/Anonymous-Family/CVE-2021-4034",
                "https://github.com/phvilasboas/CVE-2021-4034",
                "https://github.com/vilasboasph/CVE-2021-4034",
                "https://github.com/callrbx/pkexec-lpe-poc",
                "https://github.com/cd80-ctf/CVE-2021-4034",
                "https://github.com/Al1ex/CVE-2021-4034",
                "https://github.com/ashutoshrohilla/CVE-2021-4034",
                "https://github.com/nikip72/CVE-2021-4034",
                "https://github.com/NiS3x/CVE-2021-4034",
                "https://github.com/thatstraw/CVE-2021-4034",
                "https://github.com/luckythandel/CVE-2021-4034",
                "https://github.com/Plethore/CVE-2021-4034",
                "https://github.com/evdenis/lsm_bpf_check_argc0",
                "https://github.com/tahaafarooq/poppy",
                "https://github.com/DosAmp/pkwned",
                "https://github.com/PwnFunction/CVE-2021-4034",
                "https://github.com/NULL0B/CVE-2021-4034",
                "https://github.com/locksec/CVE-2021-4034",
                "https://github.com/deoxykev/CVE-2021-4034-Rust",
                "https://github.com/c3c/CVE-2021-4034",
                "https://github.com/Fato07/Pwnkit-exploit",
                "https://github.com/EstamelGG/CVE-2021-4034-NoGCC",
                "https://github.com/pengalaman-1t/CVE-2021-4034",
                "https://github.com/jpmcb/pwnkit-go",
                "https://github.com/JoyGhoshs/CVE-2021-4034",
                "https://github.com/galoget/PwnKit-CVE-2021-4034",
                "https://github.com/Yakumwamba/POC-CVE-2021-4034",
                "https://github.com/ayoub-elbouzi/CVE-2021-4034-Pwnkit",
                "https://github.com/oreosec/pwnkit",
                "https://github.com/CYB3RK1D/CVE-2021-4034-POC",
                "https://github.com/Rvn0xsy/CVE-2021-4034",
                "https://github.com/Kirill89/CVE-2021-4034",
                "https://github.com/NeonWhiteRabbit/CVE-2021-4034",
                "https://github.com/sofire/polkit-0.96-CVE-2021-4034",
                "https://github.com/codiobert/pwnkit-scanner",
                "https://github.com/v-rzh/CVE-2021-4034",
                "https://github.com/TW-D/PwnKit-Vulnerability_CVE-2021-4034",
                "https://github.com/OXDBXKXO/ez-pwnkit",
                "https://github.com/milot/dissecting-pkexec-cve-2021-4034",
                "https://github.com/0x01-sec/CVE-2021-4034-",
                "https://github.com/navisec/CVE-2021-4034-PwnKit",
                "https://github.com/Almorabea/pkexec-exploit",
                "https://github.com/teelrabbit/Polkit-pkexec-exploit-for-Linux",
                "https://github.com/scent2d/PoC-CVE-2021-4034",
                "https://github.com/HrishitJoshi/CVE-2021-4034",
                "https://github.com/Ankit-Ojha16/CVE-2021-4034",
                "https://github.com/G01d3nW01f/CVE-2021-4034",
                "https://github.com/drapl0n/pwnKit",
                "https://github.com/rvzsec/CVE-2021-4034",
                "https://github.com/Joffr3y/Polkit-CVE-2021-4034-HLP",
                "https://github.com/ziadsaleemi/polkit_CVE-2021-4034",
                "https://github.com/FDlucifer/Pwnkit-go",
                "https://github.com/pombredanne/CVE-2021-4034",
                "https://github.com/cspshivam/cve-2021-4034",
                "https://github.com/an0n7os/CVE-2021-4034",
                "https://github.com/DanaEpp/pwncat_pwnkit",
                "https://github.com/x04000/CVE-2021-4034",
                "https://github.com/x04000/AutoPwnkit",
                "https://github.com/hohn/codeql-sample-polkit",
                "https://github.com/ck00004/CVE-2021-4034",
                "https://github.com/LJP-TW/CVE-2021-4034",
                "https://github.com/fnknda/CVE-2021-4034_POC",
                "https://github.com/Tanmay-N/CVE-2021-4034",
                "https://github.com/hahaleyile/CVE-2021-4034",
                "https://github.com/movvamrocks/PwnKit-CVE-2021-4034",
                "https://github.com/Squirre17/CVE-2021-4034",
                "https://github.com/Jesrat/make_me_root",
                "https://github.com/defhacks/cve-2021-4034",
                "https://github.com/ITMarcin2211/Polkit-s-Pkexec-CVE-2021-4034",
                "https://github.com/edsonjt81/CVE-2021-4034-Linux",
                "https://github.com/nel0x/pwnkit-vulnerability",
                "https://github.com/TomSgn/CVE-2021-4034",
                "https://github.com/TheJoyOfHacking/berdav-CVE-2021-4034",
                "https://github.com/tzwlhack/CVE-2021-4034",
                "https://github.com/jcatala/f_poc_cve-2021-4034",
                "https://github.com/Nosferatuvjr/PwnKit",
                "https://github.com/TotallyNotAHaxxer/CVE-2021-4034",
                "https://github.com/0x4ndy/CVE-2021-4034-PoC",
                "https://github.com/antoinenguyen-09/CVE-2021-4034",
                "https://github.com/wudicainiao/cve-2021-4034",
                "https://github.com/TanmoyG1800/CVE-2021-4034",
                "https://github.com/CronoX1/CVE-2021-4034",
                "https://github.com/supportingmx/cve-2021-4034",
                "https://github.com/A1vinSmith/CVE-2021-4034",
                "https://github.com/HellGateCorp/pwnkit",
                "https://github.com/Silencecyber/cve-2021-4034",
                "https://github.com/Geni0r/cve-2021-4034-poc",
                "https://github.com/RakhithJK/CVE-2021-4034-new",
                "https://github.com/Pixailz/CVE-2021-4034",
                "https://github.com/toecesws/CVE-2021-4034",
                "https://github.com/tachote/CVE-2021-4034",
                "https://github.com/fei9747/CVE-2021-4034",
                "https://github.com/pyhrr0/pwnkit",
                "https://github.com/mutur4/CVE-2021-4034",
                "https://github.com/h3x0v3rl0rd/CVE-2021-4034_Python3",
                "https://github.com/ps-interactive/lab_cve-2021-4034-polkit-emulation-and-detection",
                "https://github.com/asepsaepdin/CVE-2021-4034",
                "https://github.com/JohnGilbert57/CVE-2021-4034-Capture-the-flag",
                "https://github.com/Part01-Pai/Polkit-Permission-promotion-compiled",
                "https://github.com/cdxiaodong/CVE-2021-4034-touch",
                "https://github.com/LucasPDiniz/CVE-2021-4034",
                "https://github.com/Pol-Ruiz/CVE-2021-4034",
                "https://github.com/cerodah/CVE-2021-4034",
                "https://github.com/FancySauce/PwnKit-CVE-2021-4034",
                "https://github.com/wechicken456/CVE-2021-4034-CTF-writeup",
                "https://github.com/ASG-CASTLE/CVE-2021-4034",
                "https://github.com/X-Projetion/Exploiting-PwnKit-CVE-2021-4034-",
                "https://github.com/evkl1d/CVE-2021-4034",
                "https://github.com/zxybfq/CVE-2021-4034",
                "https://github.com/EuJin03/CVE-2021-4034-PoC",
                "https://github.com/dh4r4/PwnKit-CVE-2021-4034-",
                "https://github.com/12bijaya/CVE-2021-4034-PwnKit-",
                "https://github.com/nagorealbisu/CVE-2021-4034",
                "https://github.com/igonzalez357/CVE-2021-4034-PwnKit-",
                "https://github.com/marcosChoucino/CVE-2021-4034",
                "https://github.com/ikerSandoval003/CVE-2021-4034",
                "https://github.com/AsierEgana/cve-2021-4034",
                "https://github.com/Z3R0space/CVE-2021-4034",
                "https://github.com/Milad-Rafie/PwnKit-Local-Privilege-Escalation-Vulnerability-Discovered-in-polkit-s-pkexec-CVE-2021-4034",
                "https://github.com/kali-guru/Pwnkit-CVE-2021-4034",
                "https://github.com/jscamposx/hack",
                "https://github.com/BugVex/Poison-HTB-Report",
                "https://github.com/dr4xp/pwnkit-helper",
                "https://github.com/boro03/CVE-2021-4034",
                "https://github.com/ramahmdr/PwnKit",
                "https://github.com/Abbykito/KERNELexploits",
                "https://github.com/Allu-mette/cve-2021-4034",
                "https://github.com/devianntsec/CVE-2021-4034",
                "https://github.com/vaibhavkrishna12004/ubuntu-privesc-lab",
                "https://github.com/Murguii/DEV-CVE-2021-4034",
                "https://github.com/B1gN0Se/PwnKit_CVE-2021-4034",
                "https://github.com/usmansec/-CVE-2021-4034",
                "https://github.com/vorkampfer/pwnkit_safety_check",
                "https://github.com/rusakalimantan/PwnKit-CVE-2021-4034",
                "https://github.com/jayhutajulu1/PwnKit-CVE-2021-4034",
                "https://github.com/Leemyunglyul/cve-2021-4034-mock",
                "https://github.com/mac3d0/CVE-2021-4034-pwnkit",
                "https://github.com/krleejihyeong/WHS4_CVE-2021-4034",
                "https://github.com/nicoibarburu/CVE-2021-4034",
                "https://github.com/iurhfiu6/CVE-2021-4034",
                "https://github.com/r00t-byte/Pwnkit-CVE-2021-4034-LPE"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-27",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-3560",
            "vendor": "Red Hat",
            "product": "Polkit",
            "title": "Red Hat Polkit Incorrect Authorization Vulnerability",
            "summary": "Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation.",
            "updated_at": "2026-09-02T19:29:33Z",
            "published_at": "2026-09-02T19:29:33Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 125,
            "kev": true,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50011",
                    "author": "J Smith",
                    "first_seen": "2021-06-15",
                    "confidence": "High",
                    "title": "Polkit 0.105-26 0.117-2 - Local Privilege Escalation",
                    "summary": "Polkit 0.105-26 0.117-2 - Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/50011",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for traitor CVE-2021-3560 CVE-2021-4034 CVE-2022-0847",
                    "summary": "Automatic Linux privilege escalation tool exploiting misconfigurations and GTFOBins vulnerabilities to gain root shel",
                    "what_happened": "Automatic Linux privilege escalation tool exploiting misconfigurations and GTFOBins vulnerabilities to gain root shel",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A2038172355644588718",
                        "https://kitploit.com/en/tools/github/liamg/traitor/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-02T21:29:33",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A2038172355644588718"
                },
                {
                    "title": "Exploit for traitor CVE-2021-3560 CVE-2021-4034 CVE-2022-0847",
                    "summary": "Automatic Linux privilege escalation tool exploiting misconfigurations and GTFOBins vulnerabilities to gain root shel",
                    "what_happened": "Automatic Linux privilege escalation tool exploiting misconfigurations and GTFOBins vulnerabilities to gain root shel",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A2038172355644588718",
                        "https://kitploit.com/en/tools/github/liamg/traitor/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-02T21:29:33",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/liamg/traitor/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/50011",
                "https://sploitus.com/exploit?id=KITPLOIT%3A2038172355644588718",
                "https://kitploit.com/en/tools/github/liamg/traitor/"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T19:29:33Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-05-12",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2021-3493",
            "vendor": "Linux",
            "product": "Kernel",
            "title": "Linux Kernel Privilege Escalation Vulnerability",
            "summary": "The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.",
            "updated_at": "2026-08-31T22:00:00Z",
            "published_at": "2026-08-31T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 631,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "The overlayfs stacking file system in Linux kernel does not properly validate the application of file capabilities against user namespaces, which could lead to privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · briskets/CVE-2021-3493",
                    "author": "briskets",
                    "first_seen": "2021-04-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 443,
                    "title": "Ubuntu OverlayFS Local Privesc",
                    "summary": "Ubuntu OverlayFS Local Privesc",
                    "url": "https://github.com/briskets/CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · oneoy/CVE-2021-3493",
                    "author": "oneoy",
                    "first_seen": "2021-04-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2021-3493 repository",
                    "summary": "",
                    "url": "https://github.com/oneoy/CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · Abdennour-py/CVE-2021-3493",
                    "author": "Abdennour-py",
                    "first_seen": "2021-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3493 repository",
                    "summary": "",
                    "url": "https://github.com/Abdennour-py/CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · inspiringz/CVE-2021-3493",
                    "author": "inspiringz",
                    "first_seen": "2021-07-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 42,
                    "title": "CVE-2021-3493 Ubuntu OverlayFS Local Privesc (Interactive Bash Shell & Execute Command Entered)",
                    "summary": "CVE-2021-3493 Ubuntu OverlayFS Local Privesc (Interactive Bash Shell & Execute Command Entered)",
                    "url": "https://github.com/inspiringz/CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · derek-turing/CVE-2021-3493",
                    "author": "derek-turing",
                    "first_seen": "2021-07-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3493 Ubuntu漏洞",
                    "summary": "CVE-2021-3493 Ubuntu漏洞",
                    "url": "https://github.com/derek-turing/CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · cerodah/overlayFS-CVE-2021-3493",
                    "author": "cerodah",
                    "first_seen": "2021-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "2021 kernel vulnerability in Ubuntu.",
                    "summary": "2021 kernel vulnerability in Ubuntu.",
                    "url": "https://github.com/cerodah/overlayFS-CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · puckiestyle/CVE-2021-3493",
                    "author": "puckiestyle",
                    "first_seen": "2021-10-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2021-3493 repository",
                    "summary": "",
                    "url": "https://github.com/puckiestyle/CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · fei9747/CVE-2021-3493",
                    "author": "fei9747",
                    "first_seen": "2022-11-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-3493 repository",
                    "summary": "",
                    "url": "https://github.com/fei9747/CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · pmihsan/OverlayFS-CVE-2021-3493",
                    "author": "pmihsan",
                    "first_seen": "2023-01-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit For OverlayFS",
                    "summary": "Exploit For OverlayFS",
                    "url": "https://github.com/pmihsan/OverlayFS-CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · ptkhai15/OverlayFS---CVE-2021-3493",
                    "author": "ptkhai15",
                    "first_seen": "2023-08-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3493 repository",
                    "summary": "",
                    "url": "https://github.com/ptkhai15/OverlayFS---CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · iamz24/CVE-2021-3493_CVE-2022-3357",
                    "author": "iamz24",
                    "first_seen": "2024-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3493 repository",
                    "summary": "",
                    "url": "https://github.com/iamz24/CVE-2021-3493_CVE-2022-3357"
                },
                {
                    "repository": "PoC-in-GitHub · fathallah17/OverlayFS-CVE-2021-3493",
                    "author": "fathallah17",
                    "first_seen": "2024-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit a 2021 Kernel vulnerability in Ubuntu to become root almost instantly!",
                    "summary": "Exploit a 2021 Kernel vulnerability in Ubuntu to become root almost instantly!",
                    "url": "https://github.com/fathallah17/OverlayFS-CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · Sornphut/OverlayFS---CVE-2021-3493",
                    "author": "Sornphut",
                    "first_seen": "2025-03-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3493 repository",
                    "summary": "",
                    "url": "https://github.com/Sornphut/OverlayFS---CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · cyberx-1/OverlayFS-CVE-2021-3493",
                    "author": "cyberx-1",
                    "first_seen": "2025-10-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "root Privileges",
                    "summary": "root Privileges",
                    "url": "https://github.com/cyberx-1/OverlayFS-CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · George-Yanni/DeepRoot",
                    "author": "George-Yanni",
                    "first_seen": "2025-12-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3493 OverlayFS privilege escalation exploit framework with advanced red team features. Includes persistence mechanisms, post-exploitation modules, stealth capabilities, and comprehensive documentation. For authorized testing only.",
                    "summary": "CVE-2021-3493 OverlayFS privilege escalation exploit framework with advanced red team features. Includes persistence mechanisms, post-exploitation modules, stealth capabilities, and comprehensive documentation. For authorized testing only.",
                    "url": "https://github.com/George-Yanni/DeepRoot"
                },
                {
                    "repository": "PoC-in-GitHub · iqbalhussainas/OverlayFS-LPE-Exploit",
                    "author": "iqbalhussainas",
                    "first_seen": "2026-04-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Type Local Privilege Escalation exploit for CVE-2021-3493(Ubuntu Kernel vulnerability) documrnted during TryHackme Lab",
                    "summary": "Type Local Privilege Escalation exploit for CVE-2021-3493(Ubuntu Kernel vulnerability) documrnted during TryHackme Lab",
                    "url": "https://github.com/iqbalhussainas/OverlayFS-LPE-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Ayham-Megdadi/Zero-Day-Legacy",
                    "author": "Ayham-Megdadi",
                    "first_seen": "2026-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS, Session Hijacking, SSH access, password cracking, privilege escalation via CVE-2021-3493, and full root compromise. Developed as a graduation project at Ajloun National University (ANU), awarded 97%.",
                    "summary": "A vulnerable Boot-to-Root CTF lab machine simulating a hospital environment. Features a realistic 17-step attack chain including SQL Injection, XSS, Session Hijacking, SSH access, password cracking, privilege escalation via CVE-2021-3493, and full root compromise. Developed as a graduation project at Ajloun National University (ANU), awarded 97%.",
                    "url": "https://github.com/Ayham-Megdadi/Zero-Day-Legacy"
                },
                {
                    "repository": "PoC-in-GitHub · WhatsWrongAndWhy/CVE-2021-3493",
                    "author": "WhatsWrongAndWhy",
                    "first_seen": "2026-07-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3493 repository",
                    "summary": "",
                    "url": "https://github.com/WhatsWrongAndWhy/CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · 0xlane/CVE-2021-3493",
                    "author": "0xlane",
                    "first_seen": "2026-07-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3493 repository",
                    "summary": "",
                    "url": "https://github.com/0xlane/CVE-2021-3493"
                },
                {
                    "repository": "PoC-in-GitHub · r3dw4n48m3d/CVE-2021-3493-Exploit",
                    "author": "r3dw4n48m3d",
                    "first_seen": "2026-09-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "It's a CVE-2021-3493 Exploit written in C",
                    "summary": "It's a CVE-2021-3493 Exploit written in C",
                    "url": "https://github.com/r3dw4n48m3d/CVE-2021-3493-Exploit"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/briskets/CVE-2021-3493",
                "https://github.com/oneoy/CVE-2021-3493",
                "https://github.com/Abdennour-py/CVE-2021-3493",
                "https://github.com/inspiringz/CVE-2021-3493",
                "https://github.com/derek-turing/CVE-2021-3493",
                "https://github.com/cerodah/overlayFS-CVE-2021-3493",
                "https://github.com/puckiestyle/CVE-2021-3493",
                "https://github.com/fei9747/CVE-2021-3493",
                "https://github.com/pmihsan/OverlayFS-CVE-2021-3493",
                "https://github.com/ptkhai15/OverlayFS---CVE-2021-3493",
                "https://github.com/iamz24/CVE-2021-3493_CVE-2022-3357",
                "https://github.com/fathallah17/OverlayFS-CVE-2021-3493",
                "https://github.com/Sornphut/OverlayFS---CVE-2021-3493",
                "https://github.com/cyberx-1/OverlayFS-CVE-2021-3493",
                "https://github.com/George-Yanni/DeepRoot",
                "https://github.com/iqbalhussainas/OverlayFS-LPE-Exploit",
                "https://github.com/Ayham-Megdadi/Zero-Day-Legacy",
                "https://github.com/WhatsWrongAndWhy/CVE-2021-3493",
                "https://github.com/0xlane/CVE-2021-3493",
                "https://github.com/r3dw4n48m3d/CVE-2021-3493-Exploit"
            ],
            "timeline": [
                {
                    "at": "2026-08-31T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-10-20",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-3157",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2021-3156",
            "summary": "sudo heap overflow enabling local privilege escalation, exploit written in Go.",
            "updated_at": "2026-09-03T08:32:56Z",
            "published_at": "2026-09-03T08:32:56Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 59,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "sudo heap overflow enabling local privilege escalation, exploit written in Go.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2021-3156",
                    "summary": "sudo heap overflow enabling local privilege escalation, exploit written in Go.",
                    "what_happened": "sudo heap overflow enabling local privilege escalation, exploit written in Go.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JM33-M0-CVE-2021-3156",
                        "https://kitploit.com/ja/tools/github/jm33-m0/cve-2021-3156/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T10:32:56",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JM33-M0-CVE-2021-3156"
                },
                {
                    "title": "Exploit for CVE-2021-3156",
                    "summary": "sudo heap overflow enabling local privilege escalation, exploit written in Go.",
                    "what_happened": "sudo heap overflow enabling local privilege escalation, exploit written in Go.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JM33-M0-CVE-2021-3156",
                        "https://kitploit.com/ja/tools/github/jm33-m0/cve-2021-3156/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-03T10:32:56",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/jm33-m0/cve-2021-3156/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JM33-M0-CVE-2021-3156",
                "https://kitploit.com/ja/tools/github/jm33-m0/cve-2021-3156/"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T08:32:56Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JM33-M0-CVE-2021-3156"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2021-3156",
            "vendor": "Sudo",
            "product": "Sudo",
            "title": "Sudo Heap-Based Buffer Overflow Vulnerability",
            "summary": "Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.",
            "updated_at": "2026-09-14T18:32:55Z",
            "published_at": "2026-09-14T18:32:55Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 664,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Sudo contains an off-by-one error that can result in a heap-based buffer overflow, which allows for privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 49521",
                    "author": "West Shepherd",
                    "first_seen": "2021-02-03",
                    "confidence": "High",
                    "title": "Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (1)",
                    "summary": "Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (1)",
                    "url": "https://www.exploit-db.com/exploits/49521",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 49522",
                    "author": "nu11secur1ty",
                    "first_seen": "2021-02-03",
                    "confidence": "High",
                    "title": "Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (2)",
                    "summary": "Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (2)",
                    "url": "https://www.exploit-db.com/exploits/49522",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2021-3156",
                    "summary": "Heap overflow in Sudo 1.8.27 on Debian 10 with an available exploit.",
                    "what_happened": "Heap overflow in Sudo 1.8.27 on Debian 10 with an available exploit.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XDEVIL-CVE-2021-3156",
                        "https://kitploit.com/ar/tools/github/0xdevil/cve-2021-3156/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-31T18:32:07",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XDEVIL-CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · mr-r3b00t/CVE-2021-3156",
                    "author": "mr-r3b00t",
                    "first_seen": "2021-01-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 35,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/mr-r3b00t/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · nexcess/sudo_cve-2021-3156",
                    "author": "nexcess",
                    "first_seen": "2021-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/nexcess/sudo_cve-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · reverse-ex/CVE-2021-3156",
                    "author": "reverse-ex",
                    "first_seen": "2021-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 112,
                    "title": "CVE-2021-3156",
                    "summary": "CVE-2021-3156",
                    "url": "https://github.com/reverse-ex/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · unauth401/CVE-2021-3156",
                    "author": "unauth401",
                    "first_seen": "2021-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/unauth401/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · ymrsmns/CVE-2021-3156",
                    "author": "ymrsmns",
                    "first_seen": "2021-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156",
                    "summary": "CVE-2021-3156",
                    "url": "https://github.com/ymrsmns/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · elbee-cyber/CVE-2021-3156-PATCHER",
                    "author": "elbee-cyber",
                    "first_seen": "2021-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "This simple bash script will patch the recently discovered sudo heap overflow vulnerability.",
                    "summary": "This simple bash script will patch the recently discovered sudo heap overflow vulnerability.",
                    "url": "https://github.com/elbee-cyber/CVE-2021-3156-PATCHER"
                },
                {
                    "repository": "PoC-in-GitHub · kernelzeroday/CVE-2021-3156-Baron-Samedit",
                    "author": "kernelzeroday",
                    "first_seen": "2021-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 18,
                    "title": "1day research effort",
                    "summary": "1day research effort",
                    "url": "https://github.com/kernelzeroday/CVE-2021-3156-Baron-Samedit"
                },
                {
                    "repository": "PoC-in-GitHub · yaunsky/cve-2021-3156",
                    "author": "yaunsky",
                    "first_seen": "2021-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "cve-2021-3156;sudo堆溢出漏洞；漏洞检测",
                    "summary": "cve-2021-3156;sudo堆溢出漏洞；漏洞检测",
                    "url": "https://github.com/yaunsky/cve-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · baka9moe/CVE-2021-3156-Exp",
                    "author": "baka9moe",
                    "first_seen": "2021-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/baka9moe/CVE-2021-3156-Exp"
                },
                {
                    "repository": "PoC-in-GitHub · ph4ntonn/CVE-2021-3156",
                    "author": "ph4ntonn",
                    "first_seen": "2021-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2021-3156",
                    "summary": "CVE-2021-3156",
                    "url": "https://github.com/ph4ntonn/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · binw2018/CVE-2021-3156-SCRIPT",
                    "author": "binw2018",
                    "first_seen": "2021-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/binw2018/CVE-2021-3156-SCRIPT"
                },
                {
                    "repository": "PoC-in-GitHub · freeFV/CVE-2021-3156",
                    "author": "freeFV",
                    "first_seen": "2021-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/freeFV/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · mbcrump/CVE-2021-3156",
                    "author": "mbcrump",
                    "first_seen": "2021-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 39,
                    "title": "Notes regarding CVE-2021-3156: Heap-Based Buffer Overflow in Sudo",
                    "summary": "Notes regarding CVE-2021-3156: Heap-Based Buffer Overflow in Sudo",
                    "url": "https://github.com/mbcrump/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · stong/CVE-2021-3156",
                    "author": "stong",
                    "first_seen": "2021-01-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 429,
                    "title": "PoC for CVE-2021-3156 (sudo heap overflow)",
                    "summary": "PoC for CVE-2021-3156 (sudo heap overflow)",
                    "url": "https://github.com/stong/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · nobodyatall648/CVE-2021-3156",
                    "author": "nobodyatall648",
                    "first_seen": "2021-01-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "checking CVE-2021-3156 vulnerability & patch script",
                    "summary": "checking CVE-2021-3156 vulnerability & patch script",
                    "url": "https://github.com/nobodyatall648/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · blasty/CVE-2021-3156",
                    "author": "blasty",
                    "first_seen": "2021-01-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1024,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/blasty/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · teamtopkarl/CVE-2021-3156",
                    "author": "teamtopkarl",
                    "first_seen": "2021-01-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/teamtopkarl/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · Q4n/CVE-2021-3156",
                    "author": "Q4n",
                    "first_seen": "2021-01-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "复现别人家的CVEs系列",
                    "summary": "复现别人家的CVEs系列",
                    "url": "https://github.com/Q4n/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · kal1gh0st/CVE-2021-3156",
                    "author": "kal1gh0st",
                    "first_seen": "2021-01-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Description Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via \"sudoedit -s\" and a command-line argument that ends with a single backslash character.",
                    "summary": "Description Sudo before 1.9.5p2 has a Heap-based Buffer Overflow, allowing privilege escalation to root via \"sudoedit -s\" and a command-line argument that ends with a single backslash character.",
                    "url": "https://github.com/kal1gh0st/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · apogiatzis/docker-CVE-2021-3156",
                    "author": "apogiatzis",
                    "first_seen": "2021-01-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "A docker environment to research CVE-2021-3156",
                    "summary": "A docker environment to research CVE-2021-3156",
                    "url": "https://github.com/apogiatzis/docker-CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · Ashish-dawani/CVE-2021-3156-Patch",
                    "author": "Ashish-dawani",
                    "first_seen": "2021-02-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Patch Script for CVE-2021-3156 Heap Overflow",
                    "summary": "Patch Script for CVE-2021-3156 Heap Overflow",
                    "url": "https://github.com/Ashish-dawani/CVE-2021-3156-Patch"
                },
                {
                    "repository": "PoC-in-GitHub · SantiagoSerrao/ScannerCVE-2021-3156",
                    "author": "SantiagoSerrao",
                    "first_seen": "2021-02-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/SantiagoSerrao/ScannerCVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · DanielAzulayy/CTF-2021",
                    "author": "DanielAzulayy",
                    "first_seen": "2021-02-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CTF for HDE 64 students at See Security College. Exploit a JWT (web part) & CVE-2021-3156 (LPE part).",
                    "summary": "CTF for HDE 64 students at See Security College. Exploit a JWT (web part) & CVE-2021-3156 (LPE part).",
                    "url": "https://github.com/DanielAzulayy/CTF-2021"
                },
                {
                    "repository": "PoC-in-GitHub · dinhbaouit/CVE-2021-3156",
                    "author": "dinhbaouit",
                    "first_seen": "2021-02-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2021-3156 Vagrant Lab",
                    "summary": "CVE-2021-3156 Vagrant Lab",
                    "url": "https://github.com/dinhbaouit/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · CptGibbon/CVE-2021-3156",
                    "author": "CptGibbon",
                    "first_seen": "2021-02-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 158,
                    "title": "Root shell PoC for CVE-2021-3156",
                    "summary": "Root shell PoC for CVE-2021-3156",
                    "url": "https://github.com/CptGibbon/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · perlun/sudo-1.8.3p1-patched",
                    "author": "perlun",
                    "first_seen": "2021-02-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Custom version of sudo 1.8.3p1 with CVE-2021-3156 patches applied",
                    "summary": "Custom version of sudo 1.8.3p1 with CVE-2021-3156 patches applied",
                    "url": "https://github.com/perlun/sudo-1.8.3p1-patched"
                },
                {
                    "repository": "PoC-in-GitHub · 1N53C/CVE-2021-3156-PoC",
                    "author": "1N53C",
                    "first_seen": "2021-02-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/1N53C/CVE-2021-3156-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · 0xdevil/CVE-2021-3156",
                    "author": "0xdevil",
                    "first_seen": "2021-02-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 51,
                    "title": "CVE-2021-3156: Sudo heap overflow exploit for Debian 10",
                    "summary": "CVE-2021-3156: Sudo heap overflow exploit for Debian 10",
                    "url": "https://github.com/0xdevil/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · gmldbd94/cve-2021-3156",
                    "author": "gmldbd94",
                    "first_seen": "2021-02-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "보안취약점 확인",
                    "summary": "보안취약점 확인",
                    "url": "https://github.com/gmldbd94/cve-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · jm33-m0/CVE-2021-3156",
                    "author": "jm33-m0",
                    "first_seen": "2021-02-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 16,
                    "title": "sudo heap overflow to LPE, in Go",
                    "summary": "sudo heap overflow to LPE, in Go",
                    "url": "https://github.com/jm33-m0/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · Rvn0xsy/CVE-2021-3156-plus",
                    "author": "Rvn0xsy",
                    "first_seen": "2021-02-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 204,
                    "title": "CVE-2021-3156非交互式执行命令",
                    "summary": "CVE-2021-3156非交互式执行命令",
                    "url": "https://github.com/Rvn0xsy/CVE-2021-3156-plus"
                },
                {
                    "repository": "PoC-in-GitHub · oneoy/CVE-2021-3156",
                    "author": "oneoy",
                    "first_seen": "2021-02-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/oneoy/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · worawit/CVE-2021-3156",
                    "author": "worawit",
                    "first_seen": "2021-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 803,
                    "title": "Sudo Baron Samedit Exploit",
                    "summary": "Sudo Baron Samedit Exploit",
                    "url": "https://github.com/worawit/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · lmol/CVE-2021-3156",
                    "author": "lmol",
                    "first_seen": "2021-03-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Exploit generator for sudo CVE-2021-3156",
                    "summary": "Exploit generator for sudo CVE-2021-3156",
                    "url": "https://github.com/lmol/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · BearCat4/CVE-2021-3156",
                    "author": "BearCat4",
                    "first_seen": "2021-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-3156漏洞修复Shell",
                    "summary": "CVE-2021-3156漏洞修复Shell",
                    "url": "https://github.com/BearCat4/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · capturingcats/CVE-2021-3156",
                    "author": "capturingcats",
                    "first_seen": "2021-04-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/capturingcats/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · LiveOverflow/pwnedit",
                    "author": "LiveOverflow",
                    "first_seen": "2021-04-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 225,
                    "title": "CVE-2021-3156 - Sudo Baron Samedit",
                    "summary": "CVE-2021-3156 - Sudo Baron Samedit",
                    "url": "https://github.com/LiveOverflow/pwnedit"
                },
                {
                    "repository": "PoC-in-GitHub · ajtech-hue/CVE-2021-3156-Mitigation-ShellScript-Build",
                    "author": "ajtech-hue",
                    "first_seen": "2021-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/ajtech-hue/CVE-2021-3156-Mitigation-ShellScript-Build"
                },
                {
                    "repository": "PoC-in-GitHub · donghyunlee00/CVE-2021-3156",
                    "author": "donghyunlee00",
                    "first_seen": "2021-06-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/donghyunlee00/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · TheFlash2k/CVE-2021-3156",
                    "author": "TheFlash2k",
                    "first_seen": "2021-06-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/TheFlash2k/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · Exodusro/CVE-2021-3156",
                    "author": "Exodusro",
                    "first_seen": "2021-07-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/Exodusro/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · 0x7183/CVE-2021-3156",
                    "author": "0x7183",
                    "first_seen": "2021-08-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Sudo Heap Overflow Baron Samedit",
                    "summary": "Sudo Heap Overflow Baron Samedit",
                    "url": "https://github.com/0x7183/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · sbladiamond/CVE-2021-3156",
                    "author": "sbladiamond",
                    "first_seen": "2021-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/sbladiamond/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · redhawkeye/sudo-exploit",
                    "author": "redhawkeye",
                    "first_seen": "2021-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "CVE-2021-3156 - sudo exploit for ubuntu 18.04 & 20.04",
                    "summary": "CVE-2021-3156 - sudo exploit for ubuntu 18.04 & 20.04",
                    "url": "https://github.com/redhawkeye/sudo-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · d3c3ptic0n/CVE-2021-3156",
                    "author": "d3c3ptic0n",
                    "first_seen": "2021-09-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Sudo heap-based buffer overflow privilege escalation commands and mitigations.",
                    "summary": "Sudo heap-based buffer overflow privilege escalation commands and mitigations.",
                    "url": "https://github.com/d3c3ptic0n/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · musergi/CVE-2021-3156",
                    "author": "musergi",
                    "first_seen": "2021-10-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/musergi/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · halissha/CVE-2021-3156",
                    "author": "halissha",
                    "first_seen": "2021-10-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 exploit",
                    "summary": "CVE-2021-3156 exploit",
                    "url": "https://github.com/halissha/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · sharkmoos/Baron-Samedit",
                    "author": "sharkmoos",
                    "first_seen": "2021-11-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit and Demo system for CVE-2021-3156",
                    "summary": "Exploit and Demo system for CVE-2021-3156",
                    "url": "https://github.com/sharkmoos/Baron-Samedit"
                },
                {
                    "repository": "PoC-in-GitHub · chenaotian/CVE-2021-3156",
                    "author": "chenaotian",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "CVE-2021-3156 POC and Docker and Analysis write up",
                    "summary": "CVE-2021-3156 POC and Docker and Analysis write up",
                    "url": "https://github.com/chenaotian/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · ret2basic/SudoScience",
                    "author": "ret2basic",
                    "first_seen": "2022-02-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 deep dive.",
                    "summary": "CVE-2021-3156 deep dive.",
                    "url": "https://github.com/ret2basic/SudoScience"
                },
                {
                    "repository": "PoC-in-GitHub · puckiestyle/CVE-2021-3156",
                    "author": "puckiestyle",
                    "first_seen": "2022-03-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/puckiestyle/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · barebackbandit/CVE-2021-3156",
                    "author": "barebackbandit",
                    "first_seen": "2022-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit for CVE-2021-3156",
                    "summary": "Exploit for CVE-2021-3156",
                    "url": "https://github.com/barebackbandit/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · RodricBr/CVE-2021-3156",
                    "author": "RodricBr",
                    "first_seen": "2022-03-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-3156",
                    "summary": "CVE-2021-3156",
                    "url": "https://github.com/RodricBr/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · ypl6/heaplens",
                    "author": "ypl6",
                    "first_seen": "2022-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CMPT733 Cybersecurity Lab II Project: GDB plugin for heap exploits inspired by CVE-2021-3156",
                    "summary": "CMPT733 Cybersecurity Lab II Project: GDB plugin for heap exploits inspired by CVE-2021-3156",
                    "url": "https://github.com/ypl6/heaplens"
                },
                {
                    "repository": "PoC-in-GitHub · wangqian06/CVE-2021-3156",
                    "author": "wangqian06",
                    "first_seen": "2022-05-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "sudo提权漏洞CVE-2021-3156复现代码",
                    "summary": "sudo提权漏洞CVE-2021-3156复现代码",
                    "url": "https://github.com/wangqian06/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · arvindshima/CVE-2021-3156",
                    "author": "arvindshima",
                    "first_seen": "2022-06-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit)",
                    "summary": "CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit)",
                    "url": "https://github.com/arvindshima/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · Mhackiori/CVE-2021-3156",
                    "author": "Mhackiori",
                    "first_seen": "2022-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Visualization, Fuzzing, Exploit and Patch of Baron Samedit Vulnerability",
                    "summary": "Visualization, Fuzzing, Exploit and Patch of Baron Samedit Vulnerability",
                    "url": "https://github.com/Mhackiori/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · PhuketIsland/CVE-2021-3156-centos7",
                    "author": "PhuketIsland",
                    "first_seen": "2022-11-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 30,
                    "title": "利用sudo提权，只针对cnetos7",
                    "summary": "利用sudo提权，只针对cnetos7",
                    "url": "https://github.com/PhuketIsland/CVE-2021-3156-centos7"
                },
                {
                    "repository": "PoC-in-GitHub · 0x4ndy/clif",
                    "author": "0x4ndy",
                    "first_seen": "2022-11-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 100,
                    "title": "clif is a command-line interface (CLI) application fuzzer, pretty much what wfuzz or ffuf are for web. It was inspired by sudo vulnerability CVE-2021-3156 and the fact that for some reasons, Google's afl-fuzz doesn't allow for unlimited argument or option specification.",
                    "summary": "clif is a command-line interface (CLI) application fuzzer, pretty much what wfuzz or ffuf are for web. It was inspired by sudo vulnerability CVE-2021-3156 and the fact that for some reasons, Google's afl-fuzz doesn't allow for unlimited argument or option specification.",
                    "url": "https://github.com/0x4ndy/clif"
                },
                {
                    "repository": "PoC-in-GitHub · hycheng15/CVE-2021-3156",
                    "author": "hycheng15",
                    "first_seen": "2022-12-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/hycheng15/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · mutur4/CVE-2021-3156",
                    "author": "mutur4",
                    "first_seen": "2023-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Baron SameEdit Heap Overflow LPE 1-Day Exploit",
                    "summary": "Baron SameEdit Heap Overflow LPE 1-Day Exploit",
                    "url": "https://github.com/mutur4/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · PurpleOzone/PE_CVE-CVE-2021-3156",
                    "author": "PurpleOzone",
                    "first_seen": "2023-05-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Exploit for Ubuntu 20.04 using CVE-2021-3156 enhanced with post-exploitation scripts",
                    "summary": "Exploit for Ubuntu 20.04 using CVE-2021-3156 enhanced with post-exploitation scripts",
                    "url": "https://github.com/PurpleOzone/PE_CVE-CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · asepsaepdin/CVE-2021-3156",
                    "author": "asepsaepdin",
                    "first_seen": "2023-09-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/asepsaepdin/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · DDayLuong/CVE-2021-3156",
                    "author": "DDayLuong",
                    "first_seen": "2023-12-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/DDayLuong/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · DASICS-ICT/DASICS-CVE-2021-3156",
                    "author": "DASICS-ICT",
                    "first_seen": "2023-12-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/DASICS-ICT/DASICS-CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · wurwur/CVE-2021-3156",
                    "author": "wurwur",
                    "first_seen": "2024-01-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Different files for computer security coursework",
                    "summary": "Different files for computer security coursework",
                    "url": "https://github.com/wurwur/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · lypd0/CVE-2021-3156-checker",
                    "author": "lypd0",
                    "first_seen": "2024-05-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Checker for CVE-2021-3156 with static version check",
                    "summary": "Checker for CVE-2021-3156 with static version check",
                    "url": "https://github.com/lypd0/CVE-2021-3156-checker"
                },
                {
                    "repository": "PoC-in-GitHub · Bad3r/CVE-2021-3156-without-ip-command",
                    "author": "Bad3r",
                    "first_seen": "2024-11-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "fork of worawit/CVE-2021-3156 exploit_nss.py modified to work with ifconfig instead of the ip command",
                    "summary": "fork of worawit/CVE-2021-3156 exploit_nss.py modified to work with ifconfig instead of the ip command",
                    "url": "https://github.com/Bad3r/CVE-2021-3156-without-ip-command"
                },
                {
                    "repository": "PoC-in-GitHub · Sebastianbedoya25/CVE-2021-3156",
                    "author": "Sebastianbedoya25",
                    "first_seen": "2024-12-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/Sebastianbedoya25/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · czeti/baron-samedit",
                    "author": "czeti",
                    "first_seen": "2025-02-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege escalation on Ubuntu 20.04 with sudo version 1.8.31 and glibc version 2.31. It includes an assembly-based exploit, a shared object payload, and a Makefile for automated compilation.",
                    "summary": "This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege escalation on Ubuntu 20.04 with sudo version 1.8.31 and glibc version 2.31. It includes an assembly-based exploit, a shared object payload, and a Makefile for automated compilation.",
                    "url": "https://github.com/czeti/baron-samedit"
                },
                {
                    "repository": "PoC-in-GitHub · Sornphut/CVE-2021-3156-Heap-Based-Buffer-Overflow-in-Sudo-Baron-Samedit-",
                    "author": "Sornphut",
                    "first_seen": "2025-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/Sornphut/CVE-2021-3156-Heap-Based-Buffer-Overflow-in-Sudo-Baron-Samedit-"
                },
                {
                    "repository": "PoC-in-GitHub · shishirpandey18/CVE-2021-3156",
                    "author": "shishirpandey18",
                    "first_seen": "2025-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/shishirpandey18/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · Shuhaib88/Baron-Samedit-Heap-Buffer-Overflow-CVE-2021-3156",
                    "author": "Shuhaib88",
                    "first_seen": "2025-05-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/Shuhaib88/Baron-Samedit-Heap-Buffer-Overflow-CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · gmh5225/cve-2021-3156-",
                    "author": "gmh5225",
                    "first_seen": "2025-06-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/gmh5225/cve-2021-3156-"
                },
                {
                    "repository": "PoC-in-GitHub · TopskiyPavelQwertyGang/Review.CVE-2021-3156",
                    "author": "TopskiyPavelQwertyGang",
                    "first_seen": "2025-06-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156-Exploit-Demo",
                    "summary": "CVE-2021-3156-Exploit-Demo",
                    "url": "https://github.com/TopskiyPavelQwertyGang/Review.CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · Maalfer/Sudo-CVE-2021-3156",
                    "author": "Maalfer",
                    "first_seen": "2025-07-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "Exploit para explotar la vulnerabilidad CVE-2025-32463",
                    "summary": "Exploit para explotar la vulnerabilidad CVE-2025-32463",
                    "url": "https://github.com/Maalfer/Sudo-CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · HuzaifaTariqAfzalKhan/CVE-Exploit-Research-Development-ITSOLERA",
                    "author": "HuzaifaTariqAfzalKhan",
                    "first_seen": "2025-08-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A research regarding the exisiting CVE exploit : CVE-2021-3156(Sudo BufferOverflow)",
                    "summary": "A research regarding the exisiting CVE exploit : CVE-2021-3156(Sudo BufferOverflow)",
                    "url": "https://github.com/HuzaifaTariqAfzalKhan/CVE-Exploit-Research-Development-ITSOLERA"
                },
                {
                    "repository": "PoC-in-GitHub · VilmarTuminskii/cve-2021-3156-sudo-lab",
                    "author": "VilmarTuminskii",
                    "first_seen": "2026-01-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Projeto educacional desenvolvido em Python com foco na análise da vulnerabilidade CVE-2021-3156 (Baron Samedit), uma falha crítica no sudo que permitia elevação de privilégio local em sistemas Linux.",
                    "summary": "Projeto educacional desenvolvido em Python com foco na análise da vulnerabilidade CVE-2021-3156 (Baron Samedit), uma falha crítica no sudo que permitia elevação de privilégio local em sistemas Linux.",
                    "url": "https://github.com/VilmarTuminskii/cve-2021-3156-sudo-lab"
                },
                {
                    "repository": "PoC-in-GitHub · DakerQirszh/cve-2021-3156",
                    "author": "DakerQirszh",
                    "first_seen": "2026-01-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "fixed version",
                    "summary": "fixed version",
                    "url": "https://github.com/DakerQirszh/cve-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · TheLeopard65/CVE-2021-3156-Baron-Samedit",
                    "author": "TheLeopard65",
                    "first_seen": "2026-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A simple Docker lab and Exploit setup for CVE-2021-3156 - \"Baron Samedit\".",
                    "summary": "A simple Docker lab and Exploit setup for CVE-2021-3156 - \"Baron Samedit\".",
                    "url": "https://github.com/TheLeopard65/CVE-2021-3156-Baron-Samedit"
                },
                {
                    "repository": "PoC-in-GitHub · Rana-Ali93/CVE-2021-3156-Sudo-Buffer-Overflow-Linux",
                    "author": "Rana-Ali93",
                    "first_seen": "2026-03-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Red Team exploitation of CVE-2021-3156 (Baron Samedit) – Heap Buffer Overflow in Sudo leading to Local Privilege Escalation on Ubuntu 20.04",
                    "summary": "Red Team exploitation of CVE-2021-3156 (Baron Samedit) – Heap Buffer Overflow in Sudo leading to Local Privilege Escalation on Ubuntu 20.04",
                    "url": "https://github.com/Rana-Ali93/CVE-2021-3156-Sudo-Buffer-Overflow-Linux"
                },
                {
                    "repository": "PoC-in-GitHub · ngtuonghung/CVE-2021-3156",
                    "author": "ngtuonghung",
                    "first_seen": "2026-03-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "POC for CVE-2021-3156 - Heap-based buffer overflow in sudo",
                    "summary": "POC for CVE-2021-3156 - Heap-based buffer overflow in sudo",
                    "url": "https://github.com/ngtuonghung/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · Robblackcatchai/porfolio-Baron-Samedit",
                    "author": "Robblackcatchai",
                    "first_seen": "2026-05-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "this is a study about CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit)",
                    "summary": "this is a study about CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit)",
                    "url": "https://github.com/Robblackcatchai/porfolio-Baron-Samedit"
                },
                {
                    "repository": "PoC-in-GitHub · calonnuotcabe/CVE-2021-3156",
                    "author": "calonnuotcabe",
                    "first_seen": "2026-05-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Exploiting heap-based buffer overflow in sudo for privilege escalation",
                    "summary": "Exploiting heap-based buffer overflow in sudo for privilege escalation",
                    "url": "https://github.com/calonnuotcabe/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · Kranti08/CVE-2021-3156-Baron-Samedit",
                    "author": "Kranti08",
                    "first_seen": "2026-06-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploitation and mitigation analysis of CVE-2021-3156 heap-based buffer overflow in sudo",
                    "summary": "Exploitation and mitigation analysis of CVE-2021-3156 heap-based buffer overflow in sudo",
                    "url": "https://github.com/Kranti08/CVE-2021-3156-Baron-Samedit"
                },
                {
                    "repository": "PoC-in-GitHub · IJBaig/CVE-2021-3156",
                    "author": "IJBaig",
                    "first_seen": "2026-07-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 (Baron Samedit) Report and Research",
                    "summary": "CVE-2021-3156 (Baron Samedit) Report and Research",
                    "url": "https://github.com/IJBaig/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · WhatsWrongAndWhy/CVE-2021-3156",
                    "author": "WhatsWrongAndWhy",
                    "first_seen": "2026-07-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/WhatsWrongAndWhy/CVE-2021-3156"
                },
                {
                    "repository": "PoC-in-GitHub · Shams-Ul-Mehmood/CVE-2021-3156-Project",
                    "author": "Shams-Ul-Mehmood",
                    "first_seen": "2026-08-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2021-3156 repository",
                    "summary": "",
                    "url": "https://github.com/Shams-Ul-Mehmood/CVE-2021-3156-Project"
                },
                {
                    "title": "Exploit for CVE-2021-3156",
                    "summary": "Heap overflow in Sudo 1.8.27 on Debian 10 with an available exploit.",
                    "what_happened": "Heap overflow in Sudo 1.8.27 on Debian 10 with an available exploit.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XDEVIL-CVE-2021-3156",
                        "https://kitploit.com/ar/tools/github/0xdevil/cve-2021-3156/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-08-31T18:32:07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/0xdevil/cve-2021-3156/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/49521",
                "https://www.exploit-db.com/exploits/49522",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XDEVIL-CVE-2021-3156",
                "https://kitploit.com/ar/tools/github/0xdevil/cve-2021-3156/",
                "https://github.com/mr-r3b00t/CVE-2021-3156",
                "https://github.com/nexcess/sudo_cve-2021-3156",
                "https://github.com/reverse-ex/CVE-2021-3156",
                "https://github.com/unauth401/CVE-2021-3156",
                "https://github.com/ymrsmns/CVE-2021-3156",
                "https://github.com/elbee-cyber/CVE-2021-3156-PATCHER",
                "https://github.com/kernelzeroday/CVE-2021-3156-Baron-Samedit",
                "https://github.com/yaunsky/cve-2021-3156",
                "https://github.com/baka9moe/CVE-2021-3156-Exp",
                "https://github.com/ph4ntonn/CVE-2021-3156",
                "https://github.com/binw2018/CVE-2021-3156-SCRIPT",
                "https://github.com/freeFV/CVE-2021-3156",
                "https://github.com/mbcrump/CVE-2021-3156",
                "https://github.com/stong/CVE-2021-3156",
                "https://github.com/nobodyatall648/CVE-2021-3156",
                "https://github.com/blasty/CVE-2021-3156",
                "https://github.com/teamtopkarl/CVE-2021-3156",
                "https://github.com/Q4n/CVE-2021-3156",
                "https://github.com/kal1gh0st/CVE-2021-3156",
                "https://github.com/apogiatzis/docker-CVE-2021-3156",
                "https://github.com/Ashish-dawani/CVE-2021-3156-Patch",
                "https://github.com/SantiagoSerrao/ScannerCVE-2021-3156",
                "https://github.com/DanielAzulayy/CTF-2021",
                "https://github.com/dinhbaouit/CVE-2021-3156",
                "https://github.com/CptGibbon/CVE-2021-3156",
                "https://github.com/perlun/sudo-1.8.3p1-patched",
                "https://github.com/1N53C/CVE-2021-3156-PoC",
                "https://github.com/0xdevil/CVE-2021-3156",
                "https://github.com/gmldbd94/cve-2021-3156",
                "https://github.com/jm33-m0/CVE-2021-3156",
                "https://github.com/Rvn0xsy/CVE-2021-3156-plus",
                "https://github.com/oneoy/CVE-2021-3156",
                "https://github.com/worawit/CVE-2021-3156",
                "https://github.com/lmol/CVE-2021-3156",
                "https://github.com/BearCat4/CVE-2021-3156",
                "https://github.com/capturingcats/CVE-2021-3156",
                "https://github.com/LiveOverflow/pwnedit",
                "https://github.com/ajtech-hue/CVE-2021-3156-Mitigation-ShellScript-Build",
                "https://github.com/donghyunlee00/CVE-2021-3156",
                "https://github.com/TheFlash2k/CVE-2021-3156",
                "https://github.com/Exodusro/CVE-2021-3156",
                "https://github.com/0x7183/CVE-2021-3156",
                "https://github.com/sbladiamond/CVE-2021-3156",
                "https://github.com/redhawkeye/sudo-exploit",
                "https://github.com/d3c3ptic0n/CVE-2021-3156",
                "https://github.com/musergi/CVE-2021-3156",
                "https://github.com/halissha/CVE-2021-3156",
                "https://github.com/sharkmoos/Baron-Samedit",
                "https://github.com/chenaotian/CVE-2021-3156",
                "https://github.com/ret2basic/SudoScience",
                "https://github.com/puckiestyle/CVE-2021-3156",
                "https://github.com/barebackbandit/CVE-2021-3156",
                "https://github.com/RodricBr/CVE-2021-3156",
                "https://github.com/ypl6/heaplens",
                "https://github.com/wangqian06/CVE-2021-3156",
                "https://github.com/arvindshima/CVE-2021-3156",
                "https://github.com/Mhackiori/CVE-2021-3156",
                "https://github.com/PhuketIsland/CVE-2021-3156-centos7",
                "https://github.com/0x4ndy/clif",
                "https://github.com/hycheng15/CVE-2021-3156",
                "https://github.com/mutur4/CVE-2021-3156",
                "https://github.com/PurpleOzone/PE_CVE-CVE-2021-3156",
                "https://github.com/asepsaepdin/CVE-2021-3156",
                "https://github.com/DDayLuong/CVE-2021-3156",
                "https://github.com/DASICS-ICT/DASICS-CVE-2021-3156",
                "https://github.com/wurwur/CVE-2021-3156",
                "https://github.com/lypd0/CVE-2021-3156-checker",
                "https://github.com/Bad3r/CVE-2021-3156-without-ip-command",
                "https://github.com/Sebastianbedoya25/CVE-2021-3156",
                "https://github.com/czeti/baron-samedit",
                "https://github.com/Sornphut/CVE-2021-3156-Heap-Based-Buffer-Overflow-in-Sudo-Baron-Samedit-",
                "https://github.com/shishirpandey18/CVE-2021-3156",
                "https://github.com/Shuhaib88/Baron-Samedit-Heap-Buffer-Overflow-CVE-2021-3156",
                "https://github.com/gmh5225/cve-2021-3156-",
                "https://github.com/TopskiyPavelQwertyGang/Review.CVE-2021-3156",
                "https://github.com/Maalfer/Sudo-CVE-2021-3156",
                "https://github.com/HuzaifaTariqAfzalKhan/CVE-Exploit-Research-Development-ITSOLERA",
                "https://github.com/VilmarTuminskii/cve-2021-3156-sudo-lab",
                "https://github.com/DakerQirszh/cve-2021-3156",
                "https://github.com/TheLeopard65/CVE-2021-3156-Baron-Samedit",
                "https://github.com/Rana-Ali93/CVE-2021-3156-Sudo-Buffer-Overflow-Linux",
                "https://github.com/ngtuonghung/CVE-2021-3156",
                "https://github.com/Robblackcatchai/porfolio-Baron-Samedit",
                "https://github.com/calonnuotcabe/CVE-2021-3156",
                "https://github.com/Kranti08/CVE-2021-3156-Baron-Samedit",
                "https://github.com/IJBaig/CVE-2021-3156",
                "https://github.com/WhatsWrongAndWhy/CVE-2021-3156",
                "https://github.com/Shams-Ul-Mehmood/CVE-2021-3156-Project"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T18:32:55Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-06",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-3130",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2021-3129",
            "summary": "CVE-2021-3129 affects the tools component of a repository with no README.",
            "updated_at": "2026-09-14T00:12:56Z",
            "published_at": "2026-09-14T00:12:56Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "CVE-2021-3129 affects the tools component of a repository with no README.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2021-3129",
                    "summary": "CVE-2021-3129 affects the tools component of a repository with no README.",
                    "what_happened": "CVE-2021-3129 affects the tools component of a repository with no README.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZOO1SONDV-CVE-2021-3129",
                        "https://kitploit.com/ja/tools/github/zoo1sondv/cve-2021-3129/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-14T02:12:56",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZOO1SONDV-CVE-2021-3129"
                },
                {
                    "title": "Exploit for CVE-2021-3129",
                    "summary": "CVE-2021-3129 affects the tools component of a repository with no README.",
                    "what_happened": "CVE-2021-3129 affects the tools component of a repository with no README.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZOO1SONDV-CVE-2021-3129",
                        "https://kitploit.com/ja/tools/github/zoo1sondv/cve-2021-3129/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-14T02:12:56",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/zoo1sondv/cve-2021-3129/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZOO1SONDV-CVE-2021-3129",
                "https://kitploit.com/ja/tools/github/zoo1sondv/cve-2021-3129/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T00:12:56Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZOO1SONDV-CVE-2021-3129"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2021-3129",
            "vendor": "Laravel",
            "product": "Ignition",
            "title": "Laravel Ignition File Upload Vulnerability",
            "summary": "Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().",
            "updated_at": "2026-09-14T00:12:56Z",
            "published_at": "2026-09-14T00:12:56Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 30,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Laravel Ignition contains a file upload vulnerability that allows unauthenticated remote attackers to execute malicious code due to insecure usage of file_get_contents() and file_put_contents().",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 49424",
                    "author": "SunCSR Team",
                    "first_seen": "2021-01-14",
                    "confidence": "High",
                    "title": "Laravel 8.4.2 debug mode - Remote code execution",
                    "summary": "Laravel 8.4.2 debug mode - Remote code execution",
                    "url": "https://www.exploit-db.com/exploits/49424",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2021-3129",
                    "summary": "CVE-2021-3129 affects the tools component of a repository with no README.",
                    "what_happened": "CVE-2021-3129 affects the tools component of a repository with no README.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZOO1SONDV-CVE-2021-3129",
                        "https://kitploit.com/ja/tools/github/zoo1sondv/cve-2021-3129/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-14T02:12:56",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZOO1SONDV-CVE-2021-3129"
                },
                {
                    "title": "Exploit for CVE-2021-3129",
                    "summary": "CVE-2021-3129 affects the tools component of a repository with no README.",
                    "what_happened": "CVE-2021-3129 affects the tools component of a repository with no README.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZOO1SONDV-CVE-2021-3129",
                        "https://kitploit.com/ja/tools/github/zoo1sondv/cve-2021-3129/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-14T02:12:56",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/zoo1sondv/cve-2021-3129/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/49424",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZOO1SONDV-CVE-2021-3129",
                "https://kitploit.com/ja/tools/github/zoo1sondv/cve-2021-3129/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T00:12:56Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2023-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2021-3030",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Advisory: Cute Editor 6.4 reflected XSS via 'Theme' parameter in colorpicker_more.aspx",
            "summary": "Advisory: Cute Editor 6.4 reflected XSS via 'Theme' parameter in colorpicker_more.aspx",
            "updated_at": "2026-09-05T22:00:00Z",
            "published_at": "2026-09-05T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 41,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · athosgonzaga/CVE-2021-3030",
                    "author": "athosgonzaga",
                    "first_seen": "2026-09-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Advisory: Cute Editor 6.4 reflected XSS via 'Theme' parameter in colorpicker_more.aspx",
                    "summary": "Advisory: Cute Editor 6.4 reflected XSS via 'Theme' parameter in colorpicker_more.aspx",
                    "url": "https://github.com/athosgonzaga/CVE-2021-3030"
                }
            ],
            "references": [
                "https://github.com/athosgonzaga/CVE-2021-3030"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T22:00:00Z",
                    "label": "Discovered through PoC-in-GitHub",
                    "url": "https://github.com/athosgonzaga/CVE-2021-3030"
                }
            ],
            "enrichment_checked_at": "2026-09-06T04:05:17Z"
        },
        {
            "id": "CVE-2021-1732",
            "vendor": "Microsoft",
            "product": "Win32k",
            "title": "Microsoft Win32k Privilege Escalation Vulnerability",
            "summary": "Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.",
            "updated_at": "2026-09-05T12:41:50Z",
            "published_at": "2026-09-05T12:41:50Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 85,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-05T12:41:50+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2021-1732 exploit",
                    "summary": "Exploit for CVE-2021-1732. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FLYINBEDXYZ-CVE-2021-1732"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FLYINBEDXYZ-CVE-2021-1732"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:41:50Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2021-0688",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "frameworks_base_AOSP10_r33_CVE-2021-0688 exploit",
            "summary": "Exploit for CVE-2021-0688. CVSS 7.",
            "updated_at": "2026-09-07T19:21:14Z",
            "published_at": "2026-09-07T19:21:14Z",
            "cvss": 7,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 67,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "CVE-2021-0688 in AOSP 10 r33 frameworks_base component.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for frameworks_base_AOSP10_r33_CVE-2021-0688",
                    "summary": "CVE-2021-0688 in AOSP 10 r33 frameworks_base component.",
                    "what_happened": "CVE-2021-0688 in AOSP 10 r33 frameworks_base component.",
                    "cvss": 7,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SATHEESH575555-FRAMEWORKS_BASE_AOSP10_R33_CVE-2021-0688",
                        "https://kitploit.com/ar/tools/github/satheesh575555/frameworks_base_aosp10_r33_cve-2021-0688/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T17:47:59",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SATHEESH575555-FRAMEWORKS_BASE_AOSP10_R33_CVE-2021-0688"
                },
                {
                    "title": "Exploit for frameworks_base_AOSP10_r33_CVE-2021-0688",
                    "summary": "CVE-2021-0688 in AOSP 10 r33 frameworks_base component.",
                    "what_happened": "CVE-2021-0688 in AOSP 10 r33 frameworks_base component.",
                    "cvss": 7,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SATHEESH575555-FRAMEWORKS_BASE_AOSP10_R33_CVE-2021-0688",
                        "https://kitploit.com/ar/tools/github/satheesh575555/frameworks_base_aosp10_r33_cve-2021-0688/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-04T17:47:59",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/satheesh575555/frameworks_base_aosp10_r33_cve-2021-0688/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SATHEESH575555-FRAMEWORKS_BASE_AOSP10_R33_CVE-2021-0688",
                "https://kitploit.com/ar/tools/github/satheesh575555/frameworks_base_aosp10_r33_cve-2021-0688/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:21:14Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SATHEESH575555-FRAMEWORKS_BASE_AOSP10_R33_CVE-2021-0688"
                }
            ]
        },
        {
            "id": "CVE-2021-0326",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "wpa_supplicant_8_CVE-2021-0326. exploit",
            "summary": "Exploit for CVE-2021-0326. CVSS 7.9.",
            "updated_at": "2026-09-12T15:06:21Z",
            "published_at": "2026-09-12T15:06:21Z",
            "cvss": 7.9,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 39,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "wpa_supplicant_8 and hostapd affected by CVE-2021-0326.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for wpa_supplicant_8_CVE-2021-0326.",
                    "summary": "wpa_supplicant_8 and hostapd affected by CVE-2021-0326.",
                    "what_happened": "wpa_supplicant_8 and hostapd affected by CVE-2021-0326.",
                    "cvss": 7.9,
                    "cvss_vector": "AV:A/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Adjacent",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NANOPATHI-WPA_SUPPLICANT_8_CVE-2021-0326.",
                        "https://kitploit.com/ru/tools/github/nanopathi/wpa_supplicant_8_cve-2021-0326./"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T19:45:58",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NANOPATHI-WPA_SUPPLICANT_8_CVE-2021-0326."
                },
                {
                    "title": "Exploit for wpa_supplicant_8_CVE-2021-0326.",
                    "summary": "wpa_supplicant_8 and hostapd affected by CVE-2021-0326.",
                    "what_happened": "wpa_supplicant_8 and hostapd affected by CVE-2021-0326.",
                    "cvss": 7.9,
                    "cvss_vector": "AV:A/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Adjacent",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NANOPATHI-WPA_SUPPLICANT_8_CVE-2021-0326.",
                        "https://kitploit.com/ru/tools/github/nanopathi/wpa_supplicant_8_cve-2021-0326./"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-03T19:45:58",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/nanopathi/wpa_supplicant_8_cve-2021-0326./"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NANOPATHI-WPA_SUPPLICANT_8_CVE-2021-0326.",
                "https://kitploit.com/ru/tools/github/nanopathi/wpa_supplicant_8_cve-2021-0326./"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T15:06:21Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NANOPATHI-WPA_SUPPLICANT_8_CVE-2021-0326."
                }
            ]
        },
        {
            "id": "CVE-2020-37277",
            "vendor": "pmmp",
            "product": "PocketMine-MP",
            "title": "PocketMine-MP vulnerability",
            "summary": "PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server.",
            "updated_at": "2026-09-06T13:17:09.050",
            "published_at": "2026-09-06T12:17:13.547",
            "cvss": 7.1,
            "cvss_vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 3.15.4 (semver)",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-400",
            "what_happened": "PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://github.com/pmmp/PocketMine-MP/commit/c368ebb5e74632bc622534b37cd1447b97281e20",
                "https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-8jq6-w5cg-wm45",
                "https://www.vulncheck.com/advisories/pocketmine-mp-before-3.15.4-denial-of-service-via-inventorytransaction"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:17:13.547",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-37277"
                }
            ]
        },
        {
            "id": "CVE-2020-28637",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2018-0114 CVE-2019-20933 CVE-2020-28042 CVE-2020-28637 C",
            "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
            "updated_at": "2026-09-09T04:48:12Z",
            "published_at": "2026-09-09T04:48:12Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 65,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2020-28042 CVE-2020-28637 CVE-2022-21449",
                    "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                        "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-10T07:59:46",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299"
                },
                {
                    "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2020-28042 CVE-2020-28637 CVE-2022-21449",
                    "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                        "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-10T07:59:46",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T04:48:12Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2020-28042",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2018-0114 CVE-2019-20933 CVE-2020-28042 CVE-2020-28637 C",
            "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
            "updated_at": "2026-09-09T04:48:12Z",
            "published_at": "2026-09-09T04:48:12Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 70,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2020-28042 CVE-2020-28637 CVE-2022-21449",
                    "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                        "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-10T07:59:46",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299"
                },
                {
                    "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2020-28042 CVE-2020-28637 CVE-2022-21449",
                    "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                        "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-10T07:59:46",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                },
                {
                    "repository": "PoC-in-GitHub · z-bool/Venom-JWT",
                    "author": "z-bool",
                    "first_seen": "2025-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 288,
                    "title": "针对JWT渗透开发的漏洞验证/密钥爆破工具，针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ，也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)",
                    "summary": "针对JWT渗透开发的漏洞验证/密钥爆破工具，针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ，也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)",
                    "url": "https://github.com/z-bool/Venom-JWT"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/",
                "https://github.com/z-bool/Venom-JWT"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T04:48:12Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2020-25749",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2020-25749 exploit",
            "summary": "Exploit for CVE-2020-25749. CVSS 10.",
            "updated_at": "2026-09-12T15:06:26Z",
            "published_at": "2026-09-12T15:06:26Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 39,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "CWE-798",
            "what_happened": "Static Telnet password in Rubetek RV-3406/RV-3409/RV-3411 allows remote full device control.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2020-25749",
                    "summary": "Static Telnet password in Rubetek RV-3406/RV-3409/RV-3411 allows remote full device control.",
                    "what_happened": "Static Telnet password in Rubetek RV-3406/RV-3409/RV-3411 allows remote full device control.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "CWE-798",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JET-PENTEST-CVE-2020-25749",
                        "https://kitploit.com/ru/tools/github/jet-pentest/cve-2020-25749/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T10:17:41",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JET-PENTEST-CVE-2020-25749"
                },
                {
                    "title": "Exploit for CVE-2020-25749",
                    "summary": "Static Telnet password in Rubetek RV-3406/RV-3409/RV-3411 allows remote full device control.",
                    "what_happened": "Static Telnet password in Rubetek RV-3406/RV-3409/RV-3411 allows remote full device control.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "CWE-798",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JET-PENTEST-CVE-2020-25749",
                        "https://kitploit.com/ru/tools/github/jet-pentest/cve-2020-25749/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T10:17:41",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/jet-pentest/cve-2020-25749/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JET-PENTEST-CVE-2020-25749",
                "https://kitploit.com/ru/tools/github/jet-pentest/cve-2020-25749/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T15:06:26Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JET-PENTEST-CVE-2020-25749"
                }
            ]
        },
        {
            "id": "CVE-2020-25068",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2020-25068 exploit",
            "summary": "Exploit for CVE-2020-25068. CVSS 7.5.",
            "updated_at": "2026-09-15T08:29:16Z",
            "published_at": "2026-09-15T08:29:16Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-15T08:29:16+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2020-25068 exploit",
                    "summary": "Exploit for CVE-2020-25068. CVSS 7.5.",
                    "cvss": 7.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BRYANROMA-CVE-2020-25068"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BRYANROMA-CVE-2020-25068"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:29:16Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BRYANROMA-CVE-2020-25068"
                }
            ]
        },
        {
            "id": "CVE-2020-20212",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "Mikrotik RouterOs 6.44.5 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).",
            "updated_at": "2026-09-16T21:17:05.777",
            "published_at": "2021-07-07T14:15:09.353",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-476",
            "what_happened": "Mikrotik RouterOs 6.44.5 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "seclists.org",
                    "author": "NVD reference",
                    "first_seen": "2021-07-07",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://seclists.org/fulldisclosure/2021/May/0"
                }
            ],
            "references": [
                "http://seclists.org/fulldisclosure/2021/May/0",
                "https://mikrotik.com/",
                "https://seclists.org/fulldisclosure/2020/Apr/7",
                "https://seclists.org/fulldisclosure/2020/Jan/12"
            ],
            "timeline": [
                {
                    "at": "2021-07-07T14:15:09.353",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-20212"
                }
            ]
        },
        {
            "id": "CVE-2020-20211",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.",
            "updated_at": "2026-09-16T21:17:05.603",
            "published_at": "2021-07-07T14:15:09.303",
            "cvss": 6.5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 7,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-617",
            "what_happened": "Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "seclists.org",
                    "author": "NVD reference",
                    "first_seen": "2021-07-07",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://seclists.org/fulldisclosure/2021/May/0"
                }
            ],
            "references": [
                "http://seclists.org/fulldisclosure/2021/May/0",
                "https://mikrotik.com/",
                "https://seclists.org/fulldisclosure/2020/Apr/7",
                "https://seclists.org/fulldisclosure/2020/Jan/12"
            ],
            "timeline": [
                {
                    "at": "2021-07-07T14:15:09.303",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-20211"
                }
            ]
        },
        {
            "id": "CVE-2020-17518",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2020-17518 exploit",
            "summary": "Exploit for CVE-2020-17518. CVSS 7.5.",
            "updated_at": "2026-09-13T18:25:51Z",
            "published_at": "2026-09-13T18:25:51Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:25:51+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2020-17518 exploit",
                    "summary": "Exploit for CVE-2020-17518. CVSS 7.5.",
                    "cvss": 7.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MURATAYDEMIR-CVE-2020-17518"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MURATAYDEMIR-CVE-2020-17518"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:25:51Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MURATAYDEMIR-CVE-2020-17518"
                }
            ]
        },
        {
            "id": "CVE-2020-17103",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for miniplasma-advisory CVE-2020-17103",
            "summary": "MiniPlasma variant of CVE-2020-17103 affecting Windows cldflt.sys mini-filter driver.",
            "updated_at": "2026-08-26T22:40:39Z",
            "published_at": "2026-08-26T22:40:39Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 275,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "MiniPlasma variant of CVE-2020-17103 affecting Windows cldflt.sys mini-filter driver.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for miniplasma-advisory CVE-2020-17103",
                    "summary": "MiniPlasma variant of CVE-2020-17103 affecting Windows cldflt.sys mini-filter driver.",
                    "what_happened": "MiniPlasma variant of CVE-2020-17103 affecting Windows cldflt.sys mini-filter driver.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RFRANCA777-MINIPLASMA-ADVISORY",
                        "https://kitploit.com/ru/tools/github/rfranca777/miniplasma-advisory/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-27T00:40:39",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RFRANCA777-MINIPLASMA-ADVISORY"
                },
                {
                    "title": "Exploit for miniplasma-advisory CVE-2020-17103",
                    "summary": "MiniPlasma variant of CVE-2020-17103 affecting Windows cldflt.sys mini-filter driver.",
                    "what_happened": "MiniPlasma variant of CVE-2020-17103 affecting Windows cldflt.sys mini-filter driver.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RFRANCA777-MINIPLASMA-ADVISORY",
                        "https://kitploit.com/ru/tools/github/rfranca777/miniplasma-advisory/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-27T00:40:39",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/rfranca777/miniplasma-advisory/"
                },
                {
                    "repository": "PoC-in-GitHub · CaptainChicky/MiniPlasma",
                    "author": "CaptainChicky",
                    "first_seen": "2026-05-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2020-17103 was apparently not patched or the patch was reversed, regardless this the PoC for an LPE in cldflt.sys",
                    "summary": "CVE-2020-17103 was apparently not patched or the patch was reversed, regardless this the PoC for an LPE in cldflt.sys",
                    "url": "https://github.com/CaptainChicky/MiniPlasma"
                },
                {
                    "repository": "PoC-in-GitHub · arch1m3d/MiniPlasma-Detection",
                    "author": "arch1m3d",
                    "first_seen": "2026-05-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Sigma detection rule for MiniPlasma (CVE-2020-17103)",
                    "summary": "Sigma detection rule for MiniPlasma (CVE-2020-17103)",
                    "url": "https://github.com/arch1m3d/MiniPlasma-Detection"
                },
                {
                    "repository": "PoC-in-GitHub · AlexLinov/MiniPlasma-Runner",
                    "author": "AlexLinov",
                    "first_seen": "2026-05-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 47,
                    "title": "CVE-2020-17103 adapted for C2 with split-binary SYSTEM callback",
                    "summary": "CVE-2020-17103 adapted for C2 with split-binary SYSTEM callback",
                    "url": "https://github.com/AlexLinov/MiniPlasma-Runner"
                },
                {
                    "repository": "PoC-in-GitHub · mohammadzarnian1357/MiniPlasma",
                    "author": "mohammadzarnian1357",
                    "first_seen": "2026-05-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2020-17103",
                    "summary": "CVE-2020-17103",
                    "url": "https://github.com/mohammadzarnian1357/MiniPlasma"
                },
                {
                    "repository": "PoC-in-GitHub · rfranca777/miniplasma-advisory",
                    "author": "rfranca777",
                    "first_seen": "2026-06-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "MiniPlasma CVE-2020-17103 mitigation advisory",
                    "summary": "MiniPlasma CVE-2020-17103 mitigation advisory",
                    "url": "https://github.com/rfranca777/miniplasma-advisory"
                },
                {
                    "repository": "PoC-in-GitHub · 0xBlackash/CVE-2020-17103",
                    "author": "0xBlackash",
                    "first_seen": "2026-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-17103",
                    "summary": "CVE-2020-17103",
                    "url": "https://github.com/0xBlackash/CVE-2020-17103"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RFRANCA777-MINIPLASMA-ADVISORY",
                "https://kitploit.com/ru/tools/github/rfranca777/miniplasma-advisory/",
                "https://github.com/CaptainChicky/MiniPlasma",
                "https://github.com/arch1m3d/MiniPlasma-Detection",
                "https://github.com/AlexLinov/MiniPlasma-Runner",
                "https://github.com/mohammadzarnian1357/MiniPlasma",
                "https://github.com/rfranca777/miniplasma-advisory",
                "https://github.com/0xBlackash/CVE-2020-17103"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T22:40:39Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RFRANCA777-MINIPLASMA-ADVISORY"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2020-15875",
            "vendor": "LibreNMS",
            "product": "LibreNMS",
            "title": "LibreNMS vulnerability",
            "summary": "An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endpoint. This affects as-selection.inc.php, edit-ports.inc.php, alertlog-stats.inc.php, alerts.inc.php, eventlog.inc.php, inventory.inc.php, ix-list.inc.php, ix-peers.inc.php, mempool-edit.inc.php, mempool.inc.php, poll-log.inc.php, processor-edit.inc.php, processor.inc.php, routing-edit.inc.php, sensors-common.inc.php, storage-edit.inc.php, storage.inc.php, and toner.inc.php (in includes/html/table). NOTE: some sources refer to this as CVE-2020-15876, but CVE-2020-15875 is the only correct CVE ID.",
            "updated_at": "2026-09-13T19:16:51.627",
            "published_at": "2026-09-13T19:16:51.627",
            "cvss": 5,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 1.65.1 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "CWE-89",
            "what_happened": "An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endpoint. This affects as-selection.inc.php, edit-ports.inc.php, alertlog-stats.inc.php, alerts.inc.php, eventlog.inc.php, inventory.inc.php, ix-list.inc.php, ix-peers.inc.php, mempool-edit.inc.php, mempool.inc.php, poll-log.inc.php, processor-edit.inc.php, processor.inc.php, routing-edit.inc.php, sensors-common.inc.php, storage-edit.inc.php, storage.inc.php, and toner.inc.php (in includes/html/table). NOTE: some sources refer to this as CVE-2020-15876, but CVE-2020-15875 is the only correct CVE ID.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://community.librenms.org/c/announcements",
                "https://github.com/librenms/librenms/commit/32f72bc1ab7e980e4070e826a89d0d36a5ba62dd",
                "https://github.com/librenms/librenms/compare/1.65...1.65.1",
                "https://github.com/librenms/librenms/releases/tag/1.65.1",
                "https://shielder.it/blog",
                "https://www.shielder.com/advisories/librenms-searchphrase-authenticated-sql-injection/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T19:16:51.627",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-15875"
                }
            ]
        },
        {
            "id": "CVE-2020-15367",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2020-15367 exploit",
            "summary": "Exploit for CVE-2020-15367. CVSS 9.8.",
            "updated_at": "2026-09-07T19:20:06Z",
            "published_at": "2026-09-07T19:20:06Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 34,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-07T19:20:06+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2020-15367 exploit",
                    "summary": "Exploit for CVE-2020-15367. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-INFLIXIM4BE-CVE-2020-15367"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-INFLIXIM4BE-CVE-2020-15367"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:20:06Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-INFLIXIM4BE-CVE-2020-15367"
                }
            ]
        },
        {
            "id": "CVE-2020-14882",
            "vendor": "Oracle",
            "product": "WebLogic Server",
            "title": "Oracle WebLogic Server Remote Code Execution Vulnerability",
            "summary": "Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.",
            "updated_at": "2026-08-26T22:00:00Z",
            "published_at": "2026-08-26T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1350,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 49479",
                    "author": "CHackA0101",
                    "first_seen": "2021-01-26",
                    "confidence": "High",
                    "title": "Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated)",
                    "summary": "Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated)",
                    "url": "https://www.exploit-db.com/exploits/49479",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · zhzyker/exphub",
                    "author": "zhzyker",
                    "first_seen": "2020-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4292,
                    "title": "Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本，最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340",
                    "summary": "Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本，最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-2019-17558、CVE-2019-6340",
                    "url": "https://github.com/zhzyker/exphub"
                },
                {
                    "repository": "PoC-in-GitHub · jas502n/CVE-2020-14882",
                    "author": "jas502n",
                    "first_seen": "2020-10-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 287,
                    "title": "CVE-2020–14882、CVE-2020–14883",
                    "summary": "CVE-2020–14882、CVE-2020–14883",
                    "url": "https://github.com/jas502n/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · s1kr10s/CVE-2020-14882",
                    "author": "s1kr10s",
                    "first_seen": "2020-10-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 29,
                    "title": "CVE-2020–14882 by Jang",
                    "summary": "CVE-2020–14882 by Jang",
                    "url": "https://github.com/s1kr10s/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · XTeam-Wing/CVE-2020-14882",
                    "author": "XTeam-Wing",
                    "first_seen": "2020-10-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "CVE-2020-14882 Weblogic-Exp",
                    "summary": "CVE-2020-14882 Weblogic-Exp",
                    "url": "https://github.com/XTeam-Wing/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · 0thm4n3/cve-2020-14882",
                    "author": "0thm4n3",
                    "first_seen": "2020-10-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Bash script to exploit the Oracle's Weblogic Unauthenticated Remote Command Execution - CVE-2020-14882",
                    "summary": "Bash script to exploit the Oracle's Weblogic Unauthenticated Remote Command Execution - CVE-2020-14882",
                    "url": "https://github.com/0thm4n3/cve-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · wsfengfan/cve-2020-14882",
                    "author": "wsfengfan",
                    "first_seen": "2020-10-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2020-14882 EXP 回显",
                    "summary": "CVE-2020-14882 EXP 回显",
                    "url": "https://github.com/wsfengfan/cve-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · alexfrancow/CVE-2020-14882",
                    "author": "alexfrancow",
                    "first_seen": "2020-10-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-14882 repository",
                    "summary": "",
                    "url": "https://github.com/alexfrancow/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · GGyao/CVE-2020-14882_POC",
                    "author": "GGyao",
                    "first_seen": "2020-10-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "CVE-2020-14882批量验证工具。",
                    "summary": "CVE-2020-14882批量验证工具。",
                    "url": "https://github.com/GGyao/CVE-2020-14882_POC"
                },
                {
                    "repository": "PoC-in-GitHub · ludy-dev/Weblogic_Unauthorized-bypass-RCE",
                    "author": "ludy-dev",
                    "first_seen": "2020-11-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "(CVE-2020-14882) Oracle Weblogic Unauthorized bypass RCE test script",
                    "summary": "(CVE-2020-14882) Oracle Weblogic Unauthorized bypass RCE test script",
                    "url": "https://github.com/ludy-dev/Weblogic_Unauthorized-bypass-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · GGyao/CVE-2020-14882_ALL",
                    "author": "GGyao",
                    "first_seen": "2020-11-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 144,
                    "title": "CVE-2020-14882_ALL综合利用工具，支持命令回显检测、批量命令回显、外置xml无回显命令执行等功能。",
                    "summary": "CVE-2020-14882_ALL综合利用工具，支持命令回显检测、批量命令回显、外置xml无回显命令执行等功能。",
                    "url": "https://github.com/GGyao/CVE-2020-14882_ALL"
                },
                {
                    "repository": "PoC-in-GitHub · ovProphet/CVE-2020-14882-checker",
                    "author": "ovProphet",
                    "first_seen": "2020-11-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-14882 detection script",
                    "summary": "CVE-2020-14882 detection script",
                    "url": "https://github.com/ovProphet/CVE-2020-14882-checker"
                },
                {
                    "repository": "PoC-in-GitHub · NS-Sp4ce/CVE-2020-14882",
                    "author": "NS-Sp4ce",
                    "first_seen": "2020-11-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": "CVE-2020-14882/14883/14750",
                    "summary": "CVE-2020-14882/14883/14750",
                    "url": "https://github.com/NS-Sp4ce/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · mmioimm/cve-2020-14882",
                    "author": "mmioimm",
                    "first_seen": "2020-11-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2020-14882 repository",
                    "summary": "",
                    "url": "https://github.com/mmioimm/cve-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · QmF0c3UK/CVE-2020-14882",
                    "author": "QmF0c3UK",
                    "first_seen": "2020-11-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2020-14882 repository",
                    "summary": "",
                    "url": "https://github.com/QmF0c3UK/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · murataydemir/CVE-2020-14882",
                    "author": "murataydemir",
                    "first_seen": "2020-11-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "[CVE-2020-14882] Oracle WebLogic Server Authentication Bypass",
                    "summary": "[CVE-2020-14882] Oracle WebLogic Server Authentication Bypass",
                    "url": "https://github.com/murataydemir/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · Ormicron/CVE-2020-14882-GUI-Test",
                    "author": "Ormicron",
                    "first_seen": "2020-11-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "基于qt的图形化CVE-2020-14882漏洞回显测试工具.",
                    "summary": "基于qt的图形化CVE-2020-14882漏洞回显测试工具.",
                    "url": "https://github.com/Ormicron/CVE-2020-14882-GUI-Test"
                },
                {
                    "repository": "PoC-in-GitHub · corelight/CVE-2020-14882-weblogicRCE",
                    "author": "corelight",
                    "first_seen": "2020-11-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750",
                    "summary": "Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750",
                    "url": "https://github.com/corelight/CVE-2020-14882-weblogicRCE"
                },
                {
                    "repository": "PoC-in-GitHub · xfiftyone/CVE-2020-14882",
                    "author": "xfiftyone",
                    "first_seen": "2020-11-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2020-14882 repository",
                    "summary": "",
                    "url": "https://github.com/xfiftyone/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · adm1in/CodeTest",
                    "author": "adm1in",
                    "first_seen": "2020-12-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "CodeTest信息收集和漏洞利用工具，可在进行渗透测试之时方便利用相关信息收集脚本进行信息的获取和验证工作，漏洞利用模块可选择需要测试的漏洞模块，或者选择所有模块测试，包含CVE-2020-14882, CVE-2020-2555等，可自己收集脚本后按照模板进行修改。",
                    "summary": "CodeTest信息收集和漏洞利用工具，可在进行渗透测试之时方便利用相关信息收集脚本进行信息的获取和验证工作，漏洞利用模块可选择需要测试的漏洞模块，或者选择所有模块测试，包含CVE-2020-14882, CVE-2020-2555等，可自己收集脚本后按照模板进行修改。",
                    "url": "https://github.com/adm1in/CodeTest"
                },
                {
                    "repository": "PoC-in-GitHub · pwn3z/CVE-2020-14882-WebLogic",
                    "author": "pwn3z",
                    "first_seen": "2021-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-14882 repository",
                    "summary": "",
                    "url": "https://github.com/pwn3z/CVE-2020-14882-WebLogic"
                },
                {
                    "repository": "PoC-in-GitHub · milo2012/CVE-2020-14882",
                    "author": "milo2012",
                    "first_seen": "2021-02-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "CVE-2020-14882",
                    "summary": "CVE-2020-14882",
                    "url": "https://github.com/milo2012/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · kk98kk0/CVE-2020-14882",
                    "author": "kk98kk0",
                    "first_seen": "2021-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2020-14882部署冰蝎内存马",
                    "summary": "CVE-2020-14882部署冰蝎内存马",
                    "url": "https://github.com/kk98kk0/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · exploitblizzard/CVE-2020-14882-WebLogic",
                    "author": "exploitblizzard",
                    "first_seen": "2021-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Check YouTube - https://youtu.be/O0ZnLXRY5Wo",
                    "summary": "Check YouTube - https://youtu.be/O0ZnLXRY5Wo",
                    "url": "https://github.com/exploitblizzard/CVE-2020-14882-WebLogic"
                },
                {
                    "repository": "PoC-in-GitHub · qianniaoge/CVE-2020-14882_Exploit_Gui",
                    "author": "qianniaoge",
                    "first_seen": "2021-05-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-14882 repository",
                    "summary": "",
                    "url": "https://github.com/qianniaoge/CVE-2020-14882_Exploit_Gui"
                },
                {
                    "repository": "PoC-in-GitHub · N0Coriander/CVE-2020-14882-14883",
                    "author": "N0Coriander",
                    "first_seen": "2021-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "结合14882的未授权访问漏洞，通过14883可远程执行任意代码",
                    "summary": "结合14882的未授权访问漏洞，通过14883可远程执行任意代码",
                    "url": "https://github.com/N0Coriander/CVE-2020-14882-14883"
                },
                {
                    "repository": "PoC-in-GitHub · nik0nz7/CVE-2020-14882",
                    "author": "nik0nz7",
                    "first_seen": "2023-04-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-14882 repository",
                    "summary": "",
                    "url": "https://github.com/nik0nz7/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · Root-Shells/CVE-2020-14882",
                    "author": "Root-Shells",
                    "first_seen": "2023-04-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-14882 rewritten in PowerShell",
                    "summary": "CVE-2020-14882 rewritten in PowerShell",
                    "url": "https://github.com/Root-Shells/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · Danny-LLi/CVE-2020-14882",
                    "author": "Danny-LLi",
                    "first_seen": "2023-07-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "This script allows for remote code execution (RCE) on Oracle WebLogic Server",
                    "summary": "This script allows for remote code execution (RCE) on Oracle WebLogic Server",
                    "url": "https://github.com/Danny-LLi/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · LucasPDiniz/CVE-2020-14882",
                    "author": "LucasPDiniz",
                    "first_seen": "2023-11-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Takeover of Oracle WebLogic Server",
                    "summary": "Takeover of Oracle WebLogic Server",
                    "url": "https://github.com/LucasPDiniz/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · xMr110/CVE-2020-14882",
                    "author": "xMr110",
                    "first_seen": "2024-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-14882 repository",
                    "summary": "",
                    "url": "https://github.com/xMr110/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · zesnd/CVE-2020-14882-POC",
                    "author": "zesnd",
                    "first_seen": "2024-12-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-14882 repository",
                    "summary": "",
                    "url": "https://github.com/zesnd/CVE-2020-14882-POC"
                },
                {
                    "repository": "PoC-in-GitHub · AleksaZatezalo/CVE-2020-14882",
                    "author": "AleksaZatezalo",
                    "first_seen": "2024-12-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-14882 repository",
                    "summary": "",
                    "url": "https://github.com/AleksaZatezalo/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · KKC73/weblogic-cve-2020-14882",
                    "author": "KKC73",
                    "first_seen": "2025-01-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is a repository that aims to provide research material on CVE-2020-14882 as part of a project in partial fullfilment of ACS EDU Program.",
                    "summary": "This is a repository that aims to provide research material on CVE-2020-14882 as part of a project in partial fullfilment of ACS EDU Program.",
                    "url": "https://github.com/KKC73/weblogic-cve-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · b1g-b33f/CVE-2020-14882",
                    "author": "b1g-b33f",
                    "first_seen": "2025-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC for testing if a target is vulnerable to RCE",
                    "summary": "PoC for testing if a target is vulnerable to RCE",
                    "url": "https://github.com/b1g-b33f/CVE-2020-14882"
                },
                {
                    "repository": "PoC-in-GitHub · VelesSecurity/CVE-2020-14882-WebLogic-Analysis",
                    "author": "VelesSecurity",
                    "first_seen": "2026-08-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.",
                    "summary": "Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.",
                    "url": "https://github.com/VelesSecurity/CVE-2020-14882-WebLogic-Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · hyderpwn/weblogic",
                    "author": "hyderpwn",
                    "first_seen": "2026-08-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)",
                    "summary": "Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)",
                    "url": "https://github.com/hyderpwn/weblogic"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/49479",
                "https://github.com/zhzyker/exphub",
                "https://github.com/jas502n/CVE-2020-14882",
                "https://github.com/s1kr10s/CVE-2020-14882",
                "https://github.com/XTeam-Wing/CVE-2020-14882",
                "https://github.com/0thm4n3/cve-2020-14882",
                "https://github.com/wsfengfan/cve-2020-14882",
                "https://github.com/alexfrancow/CVE-2020-14882",
                "https://github.com/GGyao/CVE-2020-14882_POC",
                "https://github.com/ludy-dev/Weblogic_Unauthorized-bypass-RCE",
                "https://github.com/GGyao/CVE-2020-14882_ALL",
                "https://github.com/ovProphet/CVE-2020-14882-checker",
                "https://github.com/NS-Sp4ce/CVE-2020-14882",
                "https://github.com/mmioimm/cve-2020-14882",
                "https://github.com/QmF0c3UK/CVE-2020-14882",
                "https://github.com/murataydemir/CVE-2020-14882",
                "https://github.com/Ormicron/CVE-2020-14882-GUI-Test",
                "https://github.com/corelight/CVE-2020-14882-weblogicRCE",
                "https://github.com/xfiftyone/CVE-2020-14882",
                "https://github.com/adm1in/CodeTest",
                "https://github.com/pwn3z/CVE-2020-14882-WebLogic",
                "https://github.com/milo2012/CVE-2020-14882",
                "https://github.com/kk98kk0/CVE-2020-14882",
                "https://github.com/exploitblizzard/CVE-2020-14882-WebLogic",
                "https://github.com/qianniaoge/CVE-2020-14882_Exploit_Gui",
                "https://github.com/N0Coriander/CVE-2020-14882-14883",
                "https://github.com/nik0nz7/CVE-2020-14882",
                "https://github.com/Root-Shells/CVE-2020-14882",
                "https://github.com/Danny-LLi/CVE-2020-14882",
                "https://github.com/LucasPDiniz/CVE-2020-14882",
                "https://github.com/xMr110/CVE-2020-14882",
                "https://github.com/zesnd/CVE-2020-14882-POC",
                "https://github.com/AleksaZatezalo/CVE-2020-14882",
                "https://github.com/KKC73/weblogic-cve-2020-14882",
                "https://github.com/b1g-b33f/CVE-2020-14882",
                "https://github.com/VelesSecurity/CVE-2020-14882-WebLogic-Analysis",
                "https://github.com/hyderpwn/weblogic"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2020-14645",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2020-14645 exploit",
            "summary": "Exploit for CVE-2020-14645. CVSS 9.8.",
            "updated_at": "2026-09-06T08:33:53Z",
            "published_at": "2026-09-06T08:33:53Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 79,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "JNDI injection in WebLogic 12.2.1.4.0 UniversalExtractor via getDatabaseMetaData enabling RCE.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2020-14645",
                    "summary": "JNDI injection in WebLogic 12.2.1.4.0 UniversalExtractor via getDatabaseMetaData enabling RCE.",
                    "what_happened": "JNDI injection in WebLogic 12.2.1.4.0 UniversalExtractor via getDatabaseMetaData enabling RCE.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-Y4ER-CVE-2020-14645",
                        "https://kitploit.com/ru/tools/github/y4er/cve-2020-14645/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T07:08:53",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-Y4ER-CVE-2020-14645"
                },
                {
                    "title": "Exploit for CVE-2020-14645",
                    "summary": "JNDI injection in WebLogic 12.2.1.4.0 UniversalExtractor via getDatabaseMetaData enabling RCE.",
                    "what_happened": "JNDI injection in WebLogic 12.2.1.4.0 UniversalExtractor via getDatabaseMetaData enabling RCE.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-Y4ER-CVE-2020-14645",
                        "https://kitploit.com/ru/tools/github/y4er/cve-2020-14645/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T07:08:53",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/y4er/cve-2020-14645/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-Y4ER-CVE-2020-14645",
                "https://kitploit.com/ru/tools/github/y4er/cve-2020-14645/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:33:53Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-Y4ER-CVE-2020-14645"
                }
            ]
        },
        {
            "id": "CVE-2020-14644",
            "vendor": "Oracle",
            "product": "WebLogic Server",
            "title": "Oracle WebLogic Server Remote Code Execution Vulnerability",
            "summary": "Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.",
            "updated_at": "2026-09-04T05:08:53Z",
            "published_at": "2026-09-04T05:08:53Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 115,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2020-14645",
                    "summary": "JNDI injection in WebLogic 12.2.1.4.0 UniversalExtractor via getDatabaseMetaData enabling RCE.",
                    "what_happened": "JNDI injection in WebLogic 12.2.1.4.0 UniversalExtractor via getDatabaseMetaData enabling RCE.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-Y4ER-CVE-2020-14645",
                        "https://kitploit.com/ru/tools/github/y4er/cve-2020-14645/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T07:08:53",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-Y4ER-CVE-2020-14645"
                },
                {
                    "title": "Exploit for CVE-2020-14645",
                    "summary": "JNDI injection in WebLogic 12.2.1.4.0 UniversalExtractor via getDatabaseMetaData enabling RCE.",
                    "what_happened": "JNDI injection in WebLogic 12.2.1.4.0 UniversalExtractor via getDatabaseMetaData enabling RCE.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-Y4ER-CVE-2020-14645",
                        "https://kitploit.com/ru/tools/github/y4er/cve-2020-14645/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T07:08:53",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/y4er/cve-2020-14645/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-Y4ER-CVE-2020-14645",
                "https://kitploit.com/ru/tools/github/y4er/cve-2020-14645/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T05:08:53Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2020-14498",
            "vendor": "HMS Industrial Networks AB",
            "product": "eCatcher",
            "title": "eCatcher vulnerability",
            "summary": "HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.",
            "updated_at": "2026-09-10T18:17:53.100",
            "published_at": "2020-08-26T14:15:10.540",
            "cvss": 9.6,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "before 6.5.5 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-121",
            "what_happened": "HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/news-events/ics-advisories/icsa-20-210-03",
                "https://www.hms-networks.com/cybersecurity/security-advisories",
                "https://us-cert.cisa.gov/ics/advisories/icsa-20-210-03"
            ],
            "timeline": [
                {
                    "at": "2020-08-26T14:15:10.540",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-14498"
                }
            ]
        },
        {
            "id": "CVE-2020-13671",
            "vendor": "Drupal",
            "product": "Drupal core",
            "title": "Drupal core Un-restricted Upload of File",
            "summary": "Improper sanitization in the extension file names is present in Drupal core.",
            "updated_at": "2026-09-09T22:00:00Z",
            "published_at": "2026-09-09T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 101,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Improper sanitization in the extension file names is present in Drupal core.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · Dungsocool/CVE-2020-13671-old",
                    "author": "Dungsocool",
                    "first_seen": "2026-08-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-13671 - Drupal RCE via File Upload Vulnerability Analysis and PoC",
                    "summary": "CVE-2020-13671 - Drupal RCE via File Upload Vulnerability Analysis and PoC",
                    "url": "https://github.com/Dungsocool/CVE-2020-13671-old"
                },
                {
                    "repository": "PoC-in-GitHub · Dungsocool/CVE-2020-13671",
                    "author": "Dungsocool",
                    "first_seen": "2026-08-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-13671 - Drupal RCE via File Upload Vulnerability Analysis and PoC",
                    "summary": "CVE-2020-13671 - Drupal RCE via File Upload Vulnerability Analysis and PoC",
                    "url": "https://github.com/Dungsocool/CVE-2020-13671"
                },
                {
                    "repository": "PoC-in-GitHub · ivanesk315/CVE-2020-13671",
                    "author": "ivanesk315",
                    "first_seen": "2026-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-13671 repository",
                    "summary": "",
                    "url": "https://github.com/ivanesk315/CVE-2020-13671"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/Dungsocool/CVE-2020-13671-old",
                "https://github.com/Dungsocool/CVE-2020-13671",
                "https://github.com/ivanesk315/CVE-2020-13671"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2020-13640",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2020-13640 exploit",
            "summary": "Exploit for CVE-2020-13640. CVSS 9.8.",
            "updated_at": "2026-09-07T19:20:04Z",
            "published_at": "2026-09-07T19:20:04Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 34,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-07T19:20:04+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2020-13640 exploit",
                    "summary": "Exploit for CVE-2020-13640. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ASTERITE3-CVE-2020-13640"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ASTERITE3-CVE-2020-13640"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:20:04Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ASTERITE3-CVE-2020-13640"
                }
            ]
        },
        {
            "id": "CVE-2020-12753",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2020-12753-PoC",
            "summary": "SBL1/aboot vulnerability enabling Secure EL3 arbitrary code execution on LG Stylo 4.",
            "updated_at": "2026-08-25T02:25:55Z",
            "published_at": "2026-08-25T02:25:55Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 19,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "SBL1/aboot vulnerability enabling Secure EL3 arbitrary code execution on LG Stylo 4.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2020-12753-PoC",
                    "summary": "SBL1/aboot vulnerability enabling Secure EL3 arbitrary code execution on LG Stylo 4.",
                    "what_happened": "SBL1/aboot vulnerability enabling Secure EL3 arbitrary code execution on LG Stylo 4.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHINYQUAGSIRE23-CVE-2020-12753-POC",
                        "https://kitploit.com/ru/tools/github/shinyquagsire23/cve-2020-12753-poc/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T04:25:55",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHINYQUAGSIRE23-CVE-2020-12753-POC"
                },
                {
                    "title": "Exploit for CVE-2020-12753-PoC",
                    "summary": "SBL1/aboot vulnerability enabling Secure EL3 arbitrary code execution on LG Stylo 4.",
                    "what_happened": "SBL1/aboot vulnerability enabling Secure EL3 arbitrary code execution on LG Stylo 4.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHINYQUAGSIRE23-CVE-2020-12753-POC",
                        "https://kitploit.com/ru/tools/github/shinyquagsire23/cve-2020-12753-poc/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-25T04:25:55",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/shinyquagsire23/cve-2020-12753-poc/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHINYQUAGSIRE23-CVE-2020-12753-POC",
                "https://kitploit.com/ru/tools/github/shinyquagsire23/cve-2020-12753-poc/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T02:25:55Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHINYQUAGSIRE23-CVE-2020-12753-POC"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2020-12446",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Windows-11-24h2-Kernel-Exploit CVE-2020-12446",
            "summary": "LPE kernel exploit for Windows 11 24H2 via CVE-2020-12446 in eneio64.sys.",
            "updated_at": "2026-09-12T05:45:41Z",
            "published_at": "2026-09-12T05:45:41Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 29,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "LPE kernel exploit for Windows 11 24H2 via CVE-2020-12446 in eneio64.sys.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Windows-11-24h2-Kernel-Exploit CVE-2020-12446",
                    "summary": "LPE kernel exploit for Windows 11 24H2 via CVE-2020-12446 in eneio64.sys.",
                    "what_happened": "LPE kernel exploit for Windows 11 24H2 via CVE-2020-12446 in eneio64.sys.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ENESSAKIRCOLAK-WINDOWS-11-24H2-KERNEL-EXPLOIT",
                        "https://kitploit.com/ru/tools/github/enessakircolak/windows-11-24h2-kernel-exploit/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-12T07:45:41",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ENESSAKIRCOLAK-WINDOWS-11-24H2-KERNEL-EXPLOIT"
                },
                {
                    "title": "Windows-11-24h2-Kernel-Exploit CVE-2020-12446",
                    "summary": "LPE kernel exploit for Windows 11 24H2 via CVE-2020-12446 in eneio64.sys.",
                    "what_happened": "LPE kernel exploit for Windows 11 24H2 via CVE-2020-12446 in eneio64.sys.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ENESSAKIRCOLAK-WINDOWS-11-24H2-KERNEL-EXPLOIT",
                        "https://kitploit.com/ru/tools/github/enessakircolak/windows-11-24h2-kernel-exploit/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-12T07:45:41",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/enessakircolak/windows-11-24h2-kernel-exploit/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ENESSAKIRCOLAK-WINDOWS-11-24H2-KERNEL-EXPLOIT",
                "https://kitploit.com/ru/tools/github/enessakircolak/windows-11-24h2-kernel-exploit/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T05:45:41Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ENESSAKIRCOLAK-WINDOWS-11-24H2-KERNEL-EXPLOIT"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2020-11990",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2020-11990-Cordova exploit",
            "summary": "Exploit for CVE-2020-11990. CVSS 3.3.",
            "updated_at": "2026-09-08T14:29:30Z",
            "published_at": "2026-09-08T14:29:30Z",
            "cvss": 3.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 31,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-08T14:29:30+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2020-11990-Cordova exploit",
                    "summary": "Exploit for CVE-2020-11990. CVSS 3.3.",
                    "cvss": 3.3,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FORSE01-CVE-2020-11990-CORDOVA"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FORSE01-CVE-2020-11990-CORDOVA"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T14:29:30Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FORSE01-CVE-2020-11990-CORDOVA"
                }
            ]
        },
        {
            "id": "CVE-2020-10915",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Modified-CVE-2020-10915-MsfModule exploit",
            "summary": "Exploit for CVE-2020-10915. CVSS 9.8.",
            "updated_at": "2026-09-08T14:31:53Z",
            "published_at": "2026-09-08T14:31:53Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 73,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Metasploit module for CVE-2020-10915 Veeam One Agent deserialization vulnerability on Windows.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Modified-CVE-2020-10915-MsfModule",
                    "summary": "Metasploit module for CVE-2020-10915 Veeam One Agent deserialization vulnerability on Windows.",
                    "what_happened": "Metasploit module for CVE-2020-10915 Veeam One Agent deserialization vulnerability on Windows.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CINNAMON1212-MODIFIED-CVE-2020-10915-MSFMODULE",
                        "https://kitploit.com/ru/tools/github/cinnamon1212/modified-cve-2020-10915-msfmodule/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T15:06:59",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CINNAMON1212-MODIFIED-CVE-2020-10915-MSFMODULE"
                },
                {
                    "title": "Exploit for Modified-CVE-2020-10915-MsfModule",
                    "summary": "Metasploit module for CVE-2020-10915 Veeam One Agent deserialization vulnerability on Windows.",
                    "what_happened": "Metasploit module for CVE-2020-10915 Veeam One Agent deserialization vulnerability on Windows.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CINNAMON1212-MODIFIED-CVE-2020-10915-MSFMODULE",
                        "https://kitploit.com/ru/tools/github/cinnamon1212/modified-cve-2020-10915-msfmodule/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T15:06:59",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/cinnamon1212/modified-cve-2020-10915-msfmodule/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CINNAMON1212-MODIFIED-CVE-2020-10915-MSFMODULE",
                "https://kitploit.com/ru/tools/github/cinnamon1212/modified-cve-2020-10915-msfmodule/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T14:31:53Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CINNAMON1212-MODIFIED-CVE-2020-10915-MSFMODULE"
                }
            ]
        },
        {
            "id": "CVE-2020-10770",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)",
            "summary": "Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)",
            "updated_at": "2026-09-04T22:00:00Z",
            "published_at": "2026-09-04T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 162,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50405",
                    "author": "Mayank Deshmukh",
                    "first_seen": "2021-10-13",
                    "confidence": "High",
                    "title": "Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)",
                    "summary": "Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)",
                    "url": "https://www.exploit-db.com/exploits/50405",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · ColdFusionX/Keycloak-12.0.1-CVE-2020-10770",
                    "author": "ColdFusionX",
                    "first_seen": "2021-10-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)",
                    "summary": "Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)",
                    "url": "https://github.com/ColdFusionX/Keycloak-12.0.1-CVE-2020-10770"
                },
                {
                    "repository": "PoC-in-GitHub · 0xlyvio/CVE-2020-10770-keycloak-exploit-poc",
                    "author": "0xlyvio",
                    "first_seen": "2026-09-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Keycloak Blind SSRF POC",
                    "summary": "Keycloak Blind SSRF POC",
                    "url": "https://github.com/0xlyvio/CVE-2020-10770-keycloak-exploit-poc"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/50405",
                "https://github.com/ColdFusionX/Keycloak-12.0.1-CVE-2020-10770",
                "https://github.com/0xlyvio/CVE-2020-10770-keycloak-exploit-poc"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/50405"
                }
            ]
        },
        {
            "id": "CVE-2020-9380",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2020-9380 exploit",
            "summary": "Exploit for CVE-2020-9380. CVSS 9.8.",
            "updated_at": "2026-09-13T18:30:30Z",
            "published_at": "2026-09-13T18:30:30Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:30:30+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2020-9380 exploit",
                    "summary": "Exploit for CVE-2020-9380. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MIGUELTARGA-CVE-2020-9380"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MIGUELTARGA-CVE-2020-9380"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:30:30Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-MIGUELTARGA-CVE-2020-9380"
                }
            ]
        },
        {
            "id": "CVE-2020-9289",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for cve-2019-6693 CVE-2019-6693",
            "summary": "FortiGate standard key allows decryption of user passwords, private keys, and HA passwords.",
            "updated_at": "2026-09-04T05:46:31Z",
            "published_at": "2026-09-04T05:46:31Z",
            "cvss": 6.5,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 147,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "FortiGate standard key allows decryption of user passwords, private keys, and HA passwords.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for cve-2019-6693 CVE-2019-6693",
                    "summary": "FortiGate standard key allows decryption of user passwords, private keys, and HA passwords.",
                    "what_happened": "FortiGate standard key allows decryption of user passwords, private keys, and HA passwords.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SALADANDONIONRINGS-CVE-2019-6693",
                        "https://kitploit.com/ru/tools/github/saladandonionrings/cve-2019-6693/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T07:46:31",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SALADANDONIONRINGS-CVE-2019-6693"
                },
                {
                    "title": "Exploit for cve-2019-6693 CVE-2019-6693",
                    "summary": "FortiGate standard key allows decryption of user passwords, private keys, and HA passwords.",
                    "what_happened": "FortiGate standard key allows decryption of user passwords, private keys, and HA passwords.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SALADANDONIONRINGS-CVE-2019-6693",
                        "https://kitploit.com/ru/tools/github/saladandonionrings/cve-2019-6693/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T07:46:31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/saladandonionrings/cve-2019-6693/"
                },
                {
                    "repository": "synacktiv/CVE-2020-9289",
                    "author": "synacktiv",
                    "first_seen": "2023-06-30",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 11,
                    "title": "Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with CVE-2019-6693 is the encryption routine).",
                    "summary": "Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with CVE-2019-6693 is the encryption routine).",
                    "url": "https://github.com/synacktiv/CVE-2020-9289"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SALADANDONIONRINGS-CVE-2019-6693",
                "https://kitploit.com/ru/tools/github/saladandonionrings/cve-2019-6693/",
                "https://github.com/synacktiv/CVE-2020-9289"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T05:46:31Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SALADANDONIONRINGS-CVE-2019-6693"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2020-8840",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for jackson-CVE-2020-8840",
            "summary": "Remote code execution vulnerability in FasterXML jackson-databind (CVE-2020-8840).",
            "updated_at": "2026-09-11T01:33:49Z",
            "published_at": "2026-09-11T01:33:49Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 38,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Remote code execution vulnerability in FasterXML jackson-databind (CVE-2020-8840).",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T06:32:19+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "jackson-CVE-2020-8840 exploit",
                    "summary": "Exploit for CVE-2020-8840. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-JACKSON-CVE-2020-8840"
                },
                {
                    "title": "Exploit for jackson-CVE-2020-8840",
                    "summary": "Remote code execution vulnerability in FasterXML jackson-databind (CVE-2020-8840).",
                    "what_happened": "Remote code execution vulnerability in FasterXML jackson-databind (CVE-2020-8840).",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-JACKSON-CVE-2020-8840",
                        "https://kitploit.com/zh/tools/github/jas502n/jackson-cve-2020-8840/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-11T03:33:49",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/jas502n/jackson-cve-2020-8840/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-JACKSON-CVE-2020-8840",
                "https://kitploit.com/zh/tools/github/jas502n/jackson-cve-2020-8840/"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T01:33:49Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-JACKSON-CVE-2020-8840"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2020-8825",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting",
            "summary": "Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting",
            "updated_at": "2026-09-06T12:05:52Z",
            "published_at": "2026-09-06T12:05:52Z",
            "cvss": 5.4,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 120,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Stored XSS in PHP VanillaForum 2.6.3 via branding settings endpoint allows script injection.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 48042",
                    "author": "Sayak Naskar",
                    "first_seen": "2020-02-11",
                    "confidence": "High",
                    "title": "Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting",
                    "summary": "Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting",
                    "url": "https://www.exploit-db.com/exploits/48042",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2020-8825",
                    "summary": "Stored XSS in PHP VanillaForum 2.6.3 via branding settings endpoint allows script injection.",
                    "what_happened": "Stored XSS in PHP VanillaForum 2.6.3 via branding settings endpoint allows script injection.",
                    "cvss": 5.4,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HACKY1997-CVE-2020-8825",
                        "https://kitploit.com/ru/tools/github/hacky1997/cve-2020-8825/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T14:05:52",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HACKY1997-CVE-2020-8825"
                },
                {
                    "title": "Exploit for CVE-2020-8825",
                    "summary": "Stored XSS in PHP VanillaForum 2.6.3 via branding settings endpoint allows script injection.",
                    "what_happened": "Stored XSS in PHP VanillaForum 2.6.3 via branding settings endpoint allows script injection.",
                    "cvss": 5.4,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HACKY1997-CVE-2020-8825",
                        "https://kitploit.com/ru/tools/github/hacky1997/cve-2020-8825/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-06T14:05:52",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/hacky1997/cve-2020-8825/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/48042",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HACKY1997-CVE-2020-8825",
                "https://kitploit.com/ru/tools/github/hacky1997/cve-2020-8825/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T12:05:52Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/48042"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
        },
        {
            "id": "CVE-2020-6418",
            "vendor": "Google",
            "product": "Chromium V8",
            "title": "Google Chromium V8 Type Confusion Vulnerability",
            "summary": "Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.",
            "updated_at": "2026-09-05T22:19:31Z",
            "published_at": "2026-09-05T22:19:31Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 214,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 48186",
                    "author": "Metasploit",
                    "first_seen": "2020-03-09",
                    "confidence": "High",
                    "title": "Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit)",
                    "summary": "Google Chrome 80 - JSCreate Side-effect Type Confusion (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/48186",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2020-6418",
                    "summary": "CVE-2020-6418 affects the tools repository with no README describing the issue.",
                    "what_happened": "CVE-2020-6418 affects the tools repository with no README describing the issue.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ASKYEYE-CVE-2020-6418",
                        "https://kitploit.com/ar/tools/github/askyeye/cve-2020-6418/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T00:19:31",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ASKYEYE-CVE-2020-6418"
                },
                {
                    "title": "Exploit for CVE-2020-6418",
                    "summary": "CVE-2020-6418 affects the tools repository with no README describing the issue.",
                    "what_happened": "CVE-2020-6418 affects the tools repository with no README describing the issue.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ASKYEYE-CVE-2020-6418",
                        "https://kitploit.com/ar/tools/github/askyeye/cve-2020-6418/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-06T00:19:31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/askyeye/cve-2020-6418/"
                },
                {
                    "repository": "PoC-in-GitHub · ASkyeye/CVE-2020-6418",
                    "author": "ASkyeye",
                    "first_seen": "2020-03-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC of CVE",
                    "summary": "PoC of CVE",
                    "url": "https://github.com/ASkyeye/CVE-2020-6418"
                },
                {
                    "repository": "PoC-in-GitHub · Goyotan/CVE-2020-6418-PoC",
                    "author": "Goyotan",
                    "first_seen": "2020-06-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "for 供養",
                    "summary": "for 供養",
                    "url": "https://github.com/Goyotan/CVE-2020-6418-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · ulexec/ChromeSHELFLoader",
                    "author": "ulexec",
                    "first_seen": "2022-02-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "An exploit for CVE-2020-6418 implementing a SHELF Loader. Published as part of Tmp.0ut volume 2",
                    "summary": "An exploit for CVE-2020-6418 implementing a SHELF Loader. Published as part of Tmp.0ut volume 2",
                    "url": "https://github.com/ulexec/ChromeSHELFLoader"
                },
                {
                    "repository": "PoC-in-GitHub · SivaPriyaRanganatha/CVE-2020-6418",
                    "author": "SivaPriyaRanganatha",
                    "first_seen": "2022-03-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-6418 repository",
                    "summary": "",
                    "url": "https://github.com/SivaPriyaRanganatha/CVE-2020-6418"
                },
                {
                    "repository": "PoC-in-GitHub · a-mansilla/CVE-2020-6418",
                    "author": "a-mansilla",
                    "first_seen": "2026-08-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-6418 repository",
                    "summary": "",
                    "url": "https://github.com/a-mansilla/CVE-2020-6418"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/48186",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ASKYEYE-CVE-2020-6418",
                "https://kitploit.com/ar/tools/github/askyeye/cve-2020-6418/",
                "https://github.com/ASkyeye/CVE-2020-6418",
                "https://github.com/Goyotan/CVE-2020-6418-PoC",
                "https://github.com/ulexec/ChromeSHELFLoader",
                "https://github.com/SivaPriyaRanganatha/CVE-2020-6418",
                "https://github.com/a-mansilla/CVE-2020-6418"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T22:19:31Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2020-5902",
            "vendor": "F5",
            "product": "BIG-IP",
            "title": "F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability",
            "summary": "F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.",
            "updated_at": "2026-09-08T01:14:47Z",
            "published_at": "2026-09-08T01:14:47Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 285,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 48711",
                    "author": "Carlos E. Vieira",
                    "first_seen": "2020-07-26",
                    "confidence": "High",
                    "title": "F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion",
                    "summary": "F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion",
                    "url": "https://www.exploit-db.com/exploits/48711",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 48642",
                    "author": "Critical Start",
                    "first_seen": "2020-07-06",
                    "confidence": "High",
                    "title": "BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6.5.1 - Traffic Management User Interface 'TMUI'  Remote Code Execution",
                    "summary": "BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6.5.1 - Traffic Management User Interface 'TMUI'  Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/48642",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 48643",
                    "author": "Budi Khoirudin",
                    "first_seen": "2020-07-05",
                    "confidence": "High",
                    "title": "BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6.5.1 - Traffic Management User Interface 'TMUI'  Remote Code Execution (PoC)",
                    "summary": "BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6.5.1 - Traffic Management User Interface 'TMUI'  Remote Code Execution (PoC)",
                    "url": "https://www.exploit-db.com/exploits/48643",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for f5_scanner CVE-2020-5902",
                    "summary": "F5 mass scanner with 30 hardcoded threads checking CVE-2020-5902 across IPs or CIDR ranges.",
                    "what_happened": "F5 mass scanner with 30 hardcoded threads checking CVE-2020-5902 across IPs or CIDR ranges.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CRISTIANO-CORRADO-F5_SCANNER",
                        "https://kitploit.com/ru/tools/github/cristiano-corrado/f5_scanner/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T05:07:36",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CRISTIANO-CORRADO-F5_SCANNER"
                },
                {
                    "title": "Exploit for f5_scanner CVE-2020-5902",
                    "summary": "F5 mass scanner with 30 hardcoded threads checking CVE-2020-5902 across IPs or CIDR ranges.",
                    "what_happened": "F5 mass scanner with 30 hardcoded threads checking CVE-2020-5902 across IPs or CIDR ranges.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CRISTIANO-CORRADO-F5_SCANNER",
                        "https://kitploit.com/ru/tools/github/cristiano-corrado/f5_scanner/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-25T05:07:36",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/cristiano-corrado/f5_scanner/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/48711",
                "https://www.exploit-db.com/exploits/48642",
                "https://www.exploit-db.com/exploits/48643",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CRISTIANO-CORRADO-F5_SCANNER",
                "https://kitploit.com/ru/tools/github/cristiano-corrado/f5_scanner/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:14:47Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2020-5142",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2020-5142-POC-MB exploit",
            "summary": "Exploit for CVE-2020-5142. CVSS 6.1.",
            "updated_at": "2026-09-08T01:14:45Z",
            "published_at": "2026-09-08T01:14:45Z",
            "cvss": 6.1,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 64,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Reflected XSS in multiple locations on SonicOS 7.0 on Sonicwall NSA devices.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2020-5142-POC-MB",
                    "summary": "Reflected XSS in multiple locations on SonicOS 7.0 on Sonicwall NSA devices.",
                    "what_happened": "Reflected XSS in multiple locations on SonicOS 7.0 on Sonicwall NSA devices.",
                    "cvss": 6.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HACKERLAWYER-CVE-2020-5142-POC-MB",
                        "https://kitploit.com/ru/tools/github/hackerlawyer/cve-2020-5142-poc-mb/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T20:34:37",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HACKERLAWYER-CVE-2020-5142-POC-MB"
                },
                {
                    "title": "Exploit for CVE-2020-5142-POC-MB",
                    "summary": "Reflected XSS in multiple locations on SonicOS 7.0 on Sonicwall NSA devices.",
                    "what_happened": "Reflected XSS in multiple locations on SonicOS 7.0 on Sonicwall NSA devices.",
                    "cvss": 6.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HACKERLAWYER-CVE-2020-5142-POC-MB",
                        "https://kitploit.com/ru/tools/github/hackerlawyer/cve-2020-5142-poc-mb/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T20:34:37",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/hackerlawyer/cve-2020-5142-poc-mb/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HACKERLAWYER-CVE-2020-5142-POC-MB",
                "https://kitploit.com/ru/tools/github/hackerlawyer/cve-2020-5142-poc-mb/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:14:45Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HACKERLAWYER-CVE-2020-5142-POC-MB"
                }
            ]
        },
        {
            "id": "CVE-2020-3766",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2020-3766_APSB20-12 exploit",
            "summary": "Exploit for CVE-2020-3766. CVSS 7.8.",
            "updated_at": "2026-09-06T08:31:28Z",
            "published_at": "2026-09-06T08:31:28Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 40,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-06T08:31:28+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2020-3766_APSB20-12 exploit",
                    "summary": "Exploit for CVE-2020-3766. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HESSANDREW-CVE-2020-3766_APSB20-12"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HESSANDREW-CVE-2020-3766_APSB20-12"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T08:31:28Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HESSANDREW-CVE-2020-3766_APSB20-12"
                }
            ]
        },
        {
            "id": "CVE-2020-2021",
            "vendor": "Palo Alto Networks",
            "product": "PAN-OS",
            "title": "Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
            "summary": "Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.",
            "updated_at": "2026-09-04T22:00:00Z",
            "published_at": "2026-09-04T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 81,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "PoC-in-GitHub · mngunibanda1-prog/Jozini-network-scanner",
                    "author": "mngunibanda1-prog",
                    "first_seen": "2026-09-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "# Jozini Network Scanner Built in Termux at KwaQondile Library, Jozini KZN  Tools: - scanner.py: Port scanner with banner grabbing (20 ports + report saving) - cve_check.py: Maps RouterOS version to known CVEs  Finding: MikroTik RouterOS 6.46.8 vulnerable to CVE-2020-2021 (Critical) Author: [Your Name] - Aspiring Pentester",
                    "summary": "# Jozini Network Scanner Built in Termux at KwaQondile Library, Jozini KZN  Tools: - scanner.py: Port scanner with banner grabbing (20 ports + report saving) - cve_check.py: Maps RouterOS version to known CVEs  Finding: MikroTik RouterOS 6.46.8 vulnerable to CVE-2020-2021 (Critical) Author: [Your Name] - Aspiring Pentester",
                    "url": "https://github.com/mngunibanda1-prog/Jozini-network-scanner"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://github.com/mngunibanda1-prog/Jozini-network-scanner"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2020-1967",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2020-1967 exploit",
            "summary": "Exploit for CVE-2020-1967. CVSS 7.5.",
            "updated_at": "2026-09-13T18:19:40Z",
            "published_at": "2026-09-13T18:19:40Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:19:40+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2020-1967 exploit",
                    "summary": "Exploit for CVE-2020-1967. CVSS 7.5.",
                    "cvss": 7.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IRSL-CVE-2020-1967"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IRSL-CVE-2020-1967"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:19:40Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IRSL-CVE-2020-1967"
                }
            ]
        },
        {
            "id": "CVE-2020-1938",
            "vendor": "Apache",
            "product": "Tomcat",
            "title": "Apache Tomcat Improper Privilege Management Vulnerability",
            "summary": "Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.",
            "updated_at": "2026-09-03T22:00:00Z",
            "published_at": "2026-09-03T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1221,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 48143",
                    "author": "YDHCUI",
                    "first_seen": "2020-02-20",
                    "confidence": "High",
                    "title": "Apache Tomcat - AJP 'Ghostcat File Read/Inclusion",
                    "summary": "Apache Tomcat - AJP 'Ghostcat File Read/Inclusion",
                    "url": "https://www.exploit-db.com/exploits/48143",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 49039",
                    "author": "SunCSR",
                    "first_seen": "2020-11-13",
                    "confidence": "High",
                    "title": "Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)",
                    "summary": "Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/49039",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · xindongzhuaizhuai/CVE-2020-1938",
                    "author": "xindongzhuaizhuai",
                    "first_seen": "2020-02-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 45,
                    "title": "CVE-2020-1938 repository",
                    "summary": "",
                    "url": "https://github.com/xindongzhuaizhuai/CVE-2020-1938"
                },
                {
                    "repository": "PoC-in-GitHub · sgdream/CVE-2020-1938",
                    "author": "sgdream",
                    "first_seen": "2020-02-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2020-1938",
                    "summary": "CVE-2020-1938",
                    "url": "https://github.com/sgdream/CVE-2020-1938"
                },
                {
                    "repository": "PoC-in-GitHub · bkfish/CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner",
                    "author": "bkfish",
                    "first_seen": "2020-02-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 294,
                    "title": "Cnvd-2020-10487 / cve-2020-1938, scanner tool",
                    "summary": "Cnvd-2020-10487 / cve-2020-1938, scanner tool",
                    "url": "https://github.com/bkfish/CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · laolisafe/CVE-2020-1938",
                    "author": "laolisafe",
                    "first_seen": "2020-02-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 38,
                    "title": "CVE-2020-1938漏洞复现",
                    "summary": "CVE-2020-1938漏洞复现",
                    "url": "https://github.com/laolisafe/CVE-2020-1938"
                },
                {
                    "repository": "PoC-in-GitHub · h7hac9/CVE-2020-1938",
                    "author": "h7hac9",
                    "first_seen": "2020-02-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2020-1938 repository",
                    "summary": "",
                    "url": "https://github.com/h7hac9/CVE-2020-1938"
                },
                {
                    "repository": "PoC-in-GitHub · sv3nbeast/CVE-2020-1938-Tomact-file_include-file_read",
                    "author": "sv3nbeast",
                    "first_seen": "2020-02-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 57,
                    "title": "Tomcat的文件包含及文件读取漏洞利用POC",
                    "summary": "Tomcat的文件包含及文件读取漏洞利用POC",
                    "url": "https://github.com/sv3nbeast/CVE-2020-1938-Tomact-file_include-file_read"
                },
                {
                    "repository": "PoC-in-GitHub · fairyming/CVE-2020-1938",
                    "author": "fairyming",
                    "first_seen": "2020-02-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "在一定条件下可执行命令",
                    "summary": "在一定条件下可执行命令",
                    "url": "https://github.com/fairyming/CVE-2020-1938"
                },
                {
                    "repository": "PoC-in-GitHub · dacade/CVE-2020-1938",
                    "author": "dacade",
                    "first_seen": "2020-02-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2020-1938 repository",
                    "summary": "",
                    "url": "https://github.com/dacade/CVE-2020-1938"
                },
                {
                    "repository": "PoC-in-GitHub · woaiqiukui/CVE-2020-1938TomcatAjpScanner",
                    "author": "woaiqiukui",
                    "first_seen": "2020-02-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 15,
                    "title": "批量扫描TomcatAJP漏洞",
                    "summary": "批量扫描TomcatAJP漏洞",
                    "url": "https://github.com/woaiqiukui/CVE-2020-1938TomcatAjpScanner"
                },
                {
                    "repository": "PoC-in-GitHub · fatal0/tomcat-cve-2020-1938-check",
                    "author": "fatal0",
                    "first_seen": "2020-02-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2020-1938 repository",
                    "summary": "",
                    "url": "https://github.com/fatal0/tomcat-cve-2020-1938-check"
                },
                {
                    "repository": "PoC-in-GitHub · delsadan/CNVD-2020-10487-Bulk-verification",
                    "author": "delsadan",
                    "first_seen": "2020-02-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CNVD-2020-10487 OR CVE-2020-1938 批量验证脚本，批量验证，并自动截图，方便提交及复核",
                    "summary": "CNVD-2020-10487 OR CVE-2020-1938 批量验证脚本，批量验证，并自动截图，方便提交及复核",
                    "url": "https://github.com/delsadan/CNVD-2020-10487-Bulk-verification"
                },
                {
                    "repository": "PoC-in-GitHub · 00theway/Ghostcat-CNVD-2020-10487",
                    "author": "00theway",
                    "first_seen": "2020-02-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 423,
                    "title": "Ghostcat read file/code execute,CNVD-2020-10487(CVE-2020-1938)",
                    "summary": "Ghostcat read file/code execute,CNVD-2020-10487(CVE-2020-1938)",
                    "url": "https://github.com/00theway/Ghostcat-CNVD-2020-10487"
                },
                {
                    "repository": "PoC-in-GitHub · shaunmclernon/ghostcat-verification",
                    "author": "shaunmclernon",
                    "first_seen": "2020-02-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Learnings on how to verify if vulnerable to Ghostcat (aka CVE-2020-1938)",
                    "summary": "Learnings on how to verify if vulnerable to Ghostcat (aka CVE-2020-1938)",
                    "url": "https://github.com/shaunmclernon/ghostcat-verification"
                },
                {
                    "repository": "PoC-in-GitHub · w4fz5uck5/CVE-2020-1938-Clean-Version",
                    "author": "w4fz5uck5",
                    "first_seen": "2020-03-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2020-1938(GhostCat) clean and readable code version",
                    "summary": "CVE-2020-1938(GhostCat) clean and readable code version",
                    "url": "https://github.com/w4fz5uck5/CVE-2020-1938-Clean-Version"
                },
                {
                    "repository": "PoC-in-GitHub · whatboxapp/GhostCat-LFI-exp",
                    "author": "whatboxapp",
                    "first_seen": "2020-03-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1938",
                    "summary": "CVE-2020-1938",
                    "url": "https://github.com/whatboxapp/GhostCat-LFI-exp"
                },
                {
                    "repository": "PoC-in-GitHub · Just1ceP4rtn3r/CVE-2020-1938-Tool",
                    "author": "Just1ceP4rtn3r",
                    "first_seen": "2020-03-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "批量检测幽灵猫漏洞",
                    "summary": "批量检测幽灵猫漏洞",
                    "url": "https://github.com/Just1ceP4rtn3r/CVE-2020-1938-Tool"
                },
                {
                    "repository": "PoC-in-GitHub · doggycheng/CNVD-2020-10487",
                    "author": "doggycheng",
                    "first_seen": "2020-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "CVE-2020-1938 / CNVD-2020-1048 Detection Tools",
                    "summary": "CVE-2020-1938 / CNVD-2020-1048 Detection Tools",
                    "url": "https://github.com/doggycheng/CNVD-2020-10487"
                },
                {
                    "repository": "PoC-in-GitHub · I-Runtime-Error/CVE-2020-1938",
                    "author": "I-Runtime-Error",
                    "first_seen": "2020-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is about CVE-2020-1938",
                    "summary": "This is about CVE-2020-1938",
                    "url": "https://github.com/I-Runtime-Error/CVE-2020-1938"
                },
                {
                    "repository": "PoC-in-GitHub · Umesh2807/Ghostcat",
                    "author": "Umesh2807",
                    "first_seen": "2020-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1938 exploit",
                    "summary": "CVE-2020-1938 exploit",
                    "url": "https://github.com/Umesh2807/Ghostcat"
                },
                {
                    "repository": "PoC-in-GitHub · MateoSec/ghostcatch",
                    "author": "MateoSec",
                    "first_seen": "2020-07-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Disables AJP connectors to remediate CVE-2020-1938!",
                    "summary": "Disables AJP connectors to remediate CVE-2020-1938!",
                    "url": "https://github.com/MateoSec/ghostcatch"
                },
                {
                    "repository": "PoC-in-GitHub · acodervic/CVE-2020-1938-MSF-MODULE",
                    "author": "acodervic",
                    "first_seen": "2021-02-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Modified version of auxiliary/admin/http/tomcat_ghostcat, it can  Read any file",
                    "summary": "Modified version of auxiliary/admin/http/tomcat_ghostcat, it can  Read any file",
                    "url": "https://github.com/acodervic/CVE-2020-1938-MSF-MODULE"
                },
                {
                    "repository": "PoC-in-GitHub · Hancheng-Lei/Hacking-Vulnerability-CVE-2020-1938-Ghostcat",
                    "author": "Hancheng-Lei",
                    "first_seen": "2021-03-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 22,
                    "title": "CVE-2020-1938 repository",
                    "summary": "",
                    "url": "https://github.com/Hancheng-Lei/Hacking-Vulnerability-CVE-2020-1938-Ghostcat"
                },
                {
                    "repository": "PoC-in-GitHub · streghstreek/CVE-2020-1938",
                    "author": "streghstreek",
                    "first_seen": "2021-04-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-1938 repository",
                    "summary": "",
                    "url": "https://github.com/streghstreek/CVE-2020-1938"
                },
                {
                    "repository": "PoC-in-GitHub · Neko-chanQwQ/CVE-2020-1938",
                    "author": "Neko-chanQwQ",
                    "first_seen": "2021-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Scanner for CVE-2020-1938",
                    "summary": "Scanner for CVE-2020-1938",
                    "url": "https://github.com/Neko-chanQwQ/CVE-2020-1938"
                },
                {
                    "repository": "PoC-in-GitHub · jptr218/ghostcat",
                    "author": "jptr218",
                    "first_seen": "2021-08-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "An implementation of CVE-2020-1938",
                    "summary": "An implementation of CVE-2020-1938",
                    "url": "https://github.com/jptr218/ghostcat"
                },
                {
                    "repository": "PoC-in-GitHub · YounesTasra-R4z3rSw0rd/CVE-2020-1938",
                    "author": "YounesTasra-R4z3rSw0rd",
                    "first_seen": "2022-08-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "This is a modified version of the original GhostCat Exploit",
                    "summary": "This is a modified version of the original GhostCat Exploit",
                    "url": "https://github.com/YounesTasra-R4z3rSw0rd/CVE-2020-1938"
                },
                {
                    "repository": "PoC-in-GitHub · tpt11fb/AttackTomcat",
                    "author": "tpt11fb",
                    "first_seen": "2022-11-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 258,
                    "title": "Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含",
                    "summary": "Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含",
                    "url": "https://github.com/tpt11fb/AttackTomcat"
                },
                {
                    "repository": "PoC-in-GitHub · Warelock/cve-2020-1938",
                    "author": "Warelock",
                    "first_seen": "2024-04-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "cve-2020-1938 Tomcat-Ajp-lfi.git脚本",
                    "summary": "cve-2020-1938 Tomcat-Ajp-lfi.git脚本",
                    "url": "https://github.com/Warelock/cve-2020-1938"
                },
                {
                    "repository": "PoC-in-GitHub · RedTeam-Rediron/CVE-2020-1938",
                    "author": "RedTeam-Rediron",
                    "first_seen": "2024-08-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1938 repository",
                    "summary": "",
                    "url": "https://github.com/RedTeam-Rediron/CVE-2020-1938"
                },
                {
                    "repository": "PoC-in-GitHub · lizhianyuguangming/TomcatScanPro",
                    "author": "lizhianyuguangming",
                    "first_seen": "2024-08-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 296,
                    "title": "tomcat自动化漏洞扫描利用工具，支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含",
                    "summary": "tomcat自动化漏洞扫描利用工具，支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含",
                    "url": "https://github.com/lizhianyuguangming/TomcatScanPro"
                },
                {
                    "repository": "PoC-in-GitHub · hopsypopsy8/CVE-2020-1938-Exploitation",
                    "author": "hopsypopsy8",
                    "first_seen": "2025-02-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1938 repository",
                    "summary": "",
                    "url": "https://github.com/hopsypopsy8/CVE-2020-1938-Exploitation"
                },
                {
                    "repository": "PoC-in-GitHub · abrewer251/CVE-2020-1938_Ghostcat-PoC",
                    "author": "abrewer251",
                    "first_seen": "2025-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection capabilities",
                    "summary": "Apache Tomcat AJP Ghostcat (CVE-2020-1938) exploit tool for file disclosure with multi-target scanning, custom wordlists, and upload point detection capabilities",
                    "url": "https://github.com/abrewer251/CVE-2020-1938_Ghostcat-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · With-fate/CVE-2020-1938",
                    "author": "With-fate",
                    "first_seen": "2026-04-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Apache Tomcat(CVE-2020-1938)漏洞验证脚本",
                    "summary": "Apache Tomcat(CVE-2020-1938)漏洞验证脚本",
                    "url": "https://github.com/With-fate/CVE-2020-1938"
                },
                {
                    "repository": "PoC-in-GitHub · sangrok-jeon/CVE-2020-1938-Tomcat-AJP-Ghostcat--Analysis",
                    "author": "sangrok-jeon",
                    "first_seen": "2026-04-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1938-Tomcat-AJP(Ghostcat)-Analysis",
                    "summary": "CVE-2020-1938-Tomcat-AJP(Ghostcat)-Analysis",
                    "url": "https://github.com/sangrok-jeon/CVE-2020-1938-Tomcat-AJP-Ghostcat--Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · aidilzlkfli/Scanning",
                    "author": "aidilzlkfli",
                    "first_seen": "2026-05-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Analysis of network scan results, service vulnerabilities, OS fingerprinting, and critical Nessus findings including Ghostcat (CVE-2020-1938).",
                    "summary": "Analysis of network scan results, service vulnerabilities, OS fingerprinting, and critical Nessus findings including Ghostcat (CVE-2020-1938).",
                    "url": "https://github.com/aidilzlkfli/Scanning"
                },
                {
                    "repository": "PoC-in-GitHub · si1ence90/Ghostcat-Tomcat-AJP-Exploit-Py3",
                    "author": "si1ence90",
                    "first_seen": "2026-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A fully refactored, Python 3 compatible exploit script for Tomcat Ghostcat (CVE-2020-1938 / CNVD-2020-10487) AJP Local File Inclusion",
                    "summary": "A fully refactored, Python 3 compatible exploit script for Tomcat Ghostcat (CVE-2020-1938 / CNVD-2020-10487) AJP Local File Inclusion",
                    "url": "https://github.com/si1ence90/Ghostcat-Tomcat-AJP-Exploit-Py3"
                },
                {
                    "repository": "PoC-in-GitHub · cyberguardsec101-sketch/ghostcat",
                    "author": "cyberguardsec101-sketch",
                    "first_seen": "2026-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1938 Exploit",
                    "summary": "CVE-2020-1938 Exploit",
                    "url": "https://github.com/cyberguardsec101-sketch/ghostcat"
                },
                {
                    "repository": "PoC-in-GitHub · duckpigdog/Tomcat-AJP-CVE-2020-1938",
                    "author": "duckpigdog",
                    "first_seen": "2026-05-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Tomcat AJP文件读取/包含漏洞",
                    "summary": "Tomcat AJP文件读取/包含漏洞",
                    "url": "https://github.com/duckpigdog/Tomcat-AJP-CVE-2020-1938"
                },
                {
                    "repository": "PoC-in-GitHub · lem0n817/tomcatfileread",
                    "author": "lem0n817",
                    "first_seen": "2026-09-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1938 (Ghostcat) Tomcat AJP file read/file include PoC with python3 port",
                    "summary": "CVE-2020-1938 (Ghostcat) Tomcat AJP file read/file include PoC with python3 port",
                    "url": "https://github.com/lem0n817/tomcatfileread"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/48143",
                "https://www.exploit-db.com/exploits/49039",
                "https://github.com/xindongzhuaizhuai/CVE-2020-1938",
                "https://github.com/sgdream/CVE-2020-1938",
                "https://github.com/bkfish/CNVD-2020-10487-Tomcat-Ajp-lfi-Scanner",
                "https://github.com/laolisafe/CVE-2020-1938",
                "https://github.com/h7hac9/CVE-2020-1938",
                "https://github.com/sv3nbeast/CVE-2020-1938-Tomact-file_include-file_read",
                "https://github.com/fairyming/CVE-2020-1938",
                "https://github.com/dacade/CVE-2020-1938",
                "https://github.com/woaiqiukui/CVE-2020-1938TomcatAjpScanner",
                "https://github.com/fatal0/tomcat-cve-2020-1938-check",
                "https://github.com/delsadan/CNVD-2020-10487-Bulk-verification",
                "https://github.com/00theway/Ghostcat-CNVD-2020-10487",
                "https://github.com/shaunmclernon/ghostcat-verification",
                "https://github.com/w4fz5uck5/CVE-2020-1938-Clean-Version",
                "https://github.com/whatboxapp/GhostCat-LFI-exp",
                "https://github.com/Just1ceP4rtn3r/CVE-2020-1938-Tool",
                "https://github.com/doggycheng/CNVD-2020-10487",
                "https://github.com/I-Runtime-Error/CVE-2020-1938",
                "https://github.com/Umesh2807/Ghostcat",
                "https://github.com/MateoSec/ghostcatch",
                "https://github.com/acodervic/CVE-2020-1938-MSF-MODULE",
                "https://github.com/Hancheng-Lei/Hacking-Vulnerability-CVE-2020-1938-Ghostcat",
                "https://github.com/streghstreek/CVE-2020-1938",
                "https://github.com/Neko-chanQwQ/CVE-2020-1938",
                "https://github.com/jptr218/ghostcat",
                "https://github.com/YounesTasra-R4z3rSw0rd/CVE-2020-1938",
                "https://github.com/tpt11fb/AttackTomcat",
                "https://github.com/Warelock/cve-2020-1938",
                "https://github.com/RedTeam-Rediron/CVE-2020-1938",
                "https://github.com/lizhianyuguangming/TomcatScanPro",
                "https://github.com/hopsypopsy8/CVE-2020-1938-Exploitation",
                "https://github.com/abrewer251/CVE-2020-1938_Ghostcat-PoC",
                "https://github.com/With-fate/CVE-2020-1938",
                "https://github.com/sangrok-jeon/CVE-2020-1938-Tomcat-AJP-Ghostcat--Analysis",
                "https://github.com/aidilzlkfli/Scanning",
                "https://github.com/si1ence90/Ghostcat-Tomcat-AJP-Exploit-Py3",
                "https://github.com/cyberguardsec101-sketch/ghostcat",
                "https://github.com/duckpigdog/Tomcat-AJP-CVE-2020-1938",
                "https://github.com/lem0n817/tomcatfileread"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2020-1472",
            "vendor": "Microsoft",
            "product": "Netlogon",
            "title": "Microsoft Netlogon Privilege Escalation Vulnerability",
            "summary": "Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.",
            "updated_at": "2026-08-24T22:00:00Z",
            "published_at": "2026-08-24T22:00:00Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 3862,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 49071",
                    "author": "West Shepherd",
                    "first_seen": "2020-11-18",
                    "confidence": "High",
                    "title": "ZeroLogon - Netlogon Elevation of Privilege",
                    "summary": "ZeroLogon - Netlogon Elevation of Privilege",
                    "url": "https://www.exploit-db.com/exploits/49071",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · Tobey123/CVE-2020-1472-visualizer",
                    "author": "Tobey123",
                    "first_seen": "2020-08-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/Tobey123/CVE-2020-1472-visualizer"
                },
                {
                    "repository": "PoC-in-GitHub · bvcyber/CVE-2020-1472",
                    "author": "bvcyber",
                    "first_seen": "2020-09-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1834,
                    "title": "Test tool for CVE-2020-1472",
                    "summary": "Test tool for CVE-2020-1472",
                    "url": "https://github.com/bvcyber/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · cube0x0/CVE-2020-1472",
                    "author": "cube0x0",
                    "first_seen": "2020-09-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 38,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/cube0x0/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · dirkjanm/CVE-2020-1472",
                    "author": "dirkjanm",
                    "first_seen": "2020-09-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1324,
                    "title": "PoC for Zerologon - all research credits go to Tom Tervoort of Secura",
                    "summary": "PoC for Zerologon - all research credits go to Tom Tervoort of Secura",
                    "url": "https://github.com/dirkjanm/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · VoidSec/CVE-2020-1472",
                    "author": "VoidSec",
                    "first_seen": "2020-09-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 397,
                    "title": "Exploit Code for CVE-2020-1472 aka Zerologon",
                    "summary": "Exploit Code for CVE-2020-1472 aka Zerologon",
                    "url": "https://github.com/VoidSec/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · risksense/zerologon",
                    "author": "risksense",
                    "first_seen": "2020-09-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 709,
                    "title": "Exploit for zerologon cve-2020-1472",
                    "summary": "Exploit for zerologon cve-2020-1472",
                    "url": "https://github.com/risksense/zerologon"
                },
                {
                    "repository": "PoC-in-GitHub · bb00/zer0dump",
                    "author": "bb00",
                    "first_seen": "2020-09-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 179,
                    "title": "Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.",
                    "summary": "Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.",
                    "url": "https://github.com/bb00/zer0dump"
                },
                {
                    "repository": "PoC-in-GitHub · 0xkami/CVE-2020-1472",
                    "author": "0xkami",
                    "first_seen": "2020-09-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2020-1472漏洞复现过程",
                    "summary": "CVE-2020-1472漏洞复现过程",
                    "url": "https://github.com/0xkami/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · NAXG/CVE-2020-1472",
                    "author": "NAXG",
                    "first_seen": "2020-09-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2020-1472复现流程",
                    "summary": "CVE-2020-1472复现流程",
                    "url": "https://github.com/NAXG/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · thatonesecguy/zerologon-CVE-2020-1472",
                    "author": "thatonesecguy",
                    "first_seen": "2020-09-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "PoC for Zerologon (CVE-2020-1472) - Exploit",
                    "summary": "PoC for Zerologon (CVE-2020-1472) - Exploit",
                    "url": "https://github.com/thatonesecguy/zerologon-CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · k8gege/CVE-2020-1472-EXP",
                    "author": "k8gege",
                    "first_seen": "2020-09-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 58,
                    "title": "Ladon Moudle CVE-2020-1472 Exploit 域控提权神器",
                    "summary": "Ladon Moudle CVE-2020-1472 Exploit 域控提权神器",
                    "url": "https://github.com/k8gege/CVE-2020-1472-EXP"
                },
                {
                    "repository": "PoC-in-GitHub · jiushill/CVE-2020-1472",
                    "author": "jiushill",
                    "first_seen": "2020-09-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-1472",
                    "summary": "CVE-2020-1472",
                    "url": "https://github.com/jiushill/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · McKinnonIT/zabbix-template-CVE-2020-1472",
                    "author": "McKinnonIT",
                    "first_seen": "2020-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Zabbix Template to monitor for Windows Event Viewer event's related to Netlogon Elevation of Privilege Vulnerability - CVE-2020-1472. Monitors event ID's 5827, 5828 & 5829. See: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472",
                    "summary": "Zabbix Template to monitor for Windows Event Viewer event's related to Netlogon Elevation of Privilege Vulnerability - CVE-2020-1472. Monitors event ID's 5827, 5828 & 5829. See: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472",
                    "url": "https://github.com/McKinnonIT/zabbix-template-CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · mstxq17/cve-2020-1472",
                    "author": "mstxq17",
                    "first_seen": "2020-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 111,
                    "title": "cve-2020-1472  复现利用及其exp",
                    "summary": "cve-2020-1472  复现利用及其exp",
                    "url": "https://github.com/mstxq17/cve-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · Fa1c0n35/CVE-2020-1472",
                    "author": "Fa1c0n35",
                    "first_seen": "2020-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/Fa1c0n35/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · Fa1c0n35/SecuraBV-CVE-2020-1472",
                    "author": "Fa1c0n35",
                    "first_seen": "2020-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/Fa1c0n35/SecuraBV-CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · CanciuCostin/CVE-2020-1472",
                    "author": "CanciuCostin",
                    "first_seen": "2020-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2020-1472 - Zero Logon vulnerability Python implementation",
                    "summary": "CVE-2020-1472 - Zero Logon vulnerability Python implementation",
                    "url": "https://github.com/CanciuCostin/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · 0xcccc666/cve-2020-1472_Tool-collection",
                    "author": "0xcccc666",
                    "first_seen": "2020-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "cve-2020-1472_Tool collection",
                    "summary": "cve-2020-1472_Tool collection",
                    "url": "https://github.com/0xcccc666/cve-2020-1472_Tool-collection"
                },
                {
                    "repository": "PoC-in-GitHub · murataydemir/CVE-2020-1472",
                    "author": "murataydemir",
                    "first_seen": "2020-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "[CVE-2020-1472] Netlogon Remote Protocol Call (MS-NRPC) Privilege Escalation (Zerologon)",
                    "summary": "[CVE-2020-1472] Netlogon Remote Protocol Call (MS-NRPC) Privilege Escalation (Zerologon)",
                    "url": "https://github.com/murataydemir/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · npocmak/CVE-2020-1472",
                    "author": "npocmak",
                    "first_seen": "2020-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "https://github.com/dirkjanm/CVE-2020-1472",
                    "summary": "https://github.com/dirkjanm/CVE-2020-1472",
                    "url": "https://github.com/npocmak/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · FaFcFF41/CVE-2020-1472",
                    "author": "FaFcFF41",
                    "first_seen": "2020-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/FaFcFF41/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · zeronetworks/zerologon",
                    "author": "zeronetworks",
                    "first_seen": "2020-09-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 61,
                    "title": "Test script for CVE-2020-1472 for both RPC/TCP and RPC/SMB",
                    "summary": "Test script for CVE-2020-1472 for both RPC/TCP and RPC/SMB",
                    "url": "https://github.com/zeronetworks/zerologon"
                },
                {
                    "repository": "PoC-in-GitHub · sv3nbeast/CVE-2020-1472",
                    "author": "sv3nbeast",
                    "first_seen": "2020-09-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "CVE-2020-1472复现时使用的py文件整理打包",
                    "summary": "CVE-2020-1472复现时使用的py文件整理打包",
                    "url": "https://github.com/sv3nbeast/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · midpipps/CVE-2020-1472-Easy",
                    "author": "midpipps",
                    "first_seen": "2020-09-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A simple implementation/code smash of a bunch of other repos",
                    "summary": "A simple implementation/code smash of a bunch of other repos",
                    "url": "https://github.com/midpipps/CVE-2020-1472-Easy"
                },
                {
                    "repository": "PoC-in-GitHub · hectorgie/CVE-2020-1472",
                    "author": "hectorgie",
                    "first_seen": "2020-09-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/hectorgie/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · johnpathe/zerologon-cve-2020-1472-notes",
                    "author": "johnpathe",
                    "first_seen": "2020-09-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/johnpathe/zerologon-cve-2020-1472-notes"
                },
                {
                    "repository": "PoC-in-GitHub · t31m0/CVE-2020-1472",
                    "author": "t31m0",
                    "first_seen": "2020-09-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/t31m0/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · grupooruss/CVE-2020-1472",
                    "author": "grupooruss",
                    "first_seen": "2020-09-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE 2020-1472 Script de validación",
                    "summary": "CVE 2020-1472 Script de validación",
                    "url": "https://github.com/grupooruss/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · striveben/CVE-2020-1472",
                    "author": "striveben",
                    "first_seen": "2020-09-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/striveben/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · Fa1c0n35/CVE-2020-1472-02-",
                    "author": "Fa1c0n35",
                    "first_seen": "2020-09-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/Fa1c0n35/CVE-2020-1472-02-"
                },
                {
                    "repository": "PoC-in-GitHub · Whippet0/CVE-2020-1472",
                    "author": "Whippet0",
                    "first_seen": "2020-09-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472",
                    "summary": "CVE-2020-1472",
                    "url": "https://github.com/Whippet0/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · WiIs0n/Zerologon_CVE-2020-1472",
                    "author": "WiIs0n",
                    "first_seen": "2020-09-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "POC for checking multiple hosts for Zerologon vulnerability",
                    "summary": "POC for checking multiple hosts for Zerologon vulnerability",
                    "url": "https://github.com/WiIs0n/Zerologon_CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · Privia-Security/ADZero",
                    "author": "Privia-Security",
                    "first_seen": "2020-09-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 22,
                    "title": "Zerologon AutoExploit Tool | CVE-2020-1472",
                    "summary": "Zerologon AutoExploit Tool | CVE-2020-1472",
                    "url": "https://github.com/Privia-Security/ADZero"
                },
                {
                    "repository": "PoC-in-GitHub · Ken-Abruzzi/cve-2020-1472",
                    "author": "Ken-Abruzzi",
                    "first_seen": "2020-09-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/Ken-Abruzzi/cve-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · rhymeswithmogul/Set-ZerologonMitigation",
                    "author": "rhymeswithmogul",
                    "first_seen": "2020-09-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Protect your domain controllers against Zerologon (CVE-2020-1472).",
                    "summary": "Protect your domain controllers against Zerologon (CVE-2020-1472).",
                    "url": "https://github.com/rhymeswithmogul/Set-ZerologonMitigation"
                },
                {
                    "repository": "PoC-in-GitHub · shanfenglan/cve-2020-1472",
                    "author": "shanfenglan",
                    "first_seen": "2020-10-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/shanfenglan/cve-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · maikelnight/zerologon",
                    "author": "maikelnight",
                    "first_seen": "2020-10-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Check for events that indicate non compatible devices -> CVE-2020-1472",
                    "summary": "Check for events that indicate non compatible devices -> CVE-2020-1472",
                    "url": "https://github.com/maikelnight/zerologon"
                },
                {
                    "repository": "PoC-in-GitHub · CPO-EH/CVE-2020-1472_ZeroLogonChecker",
                    "author": "CPO-EH",
                    "first_seen": "2020-10-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "C# Vulnerability Checker for CVE-2020-1472 Aka Zerologon",
                    "summary": "C# Vulnerability Checker for CVE-2020-1472 Aka Zerologon",
                    "url": "https://github.com/CPO-EH/CVE-2020-1472_ZeroLogonChecker"
                },
                {
                    "repository": "PoC-in-GitHub · puckiestyle/CVE-2020-1472",
                    "author": "puckiestyle",
                    "first_seen": "2020-10-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/puckiestyle/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · mingchen-script/CVE-2020-1472-visualizer",
                    "author": "mingchen-script",
                    "first_seen": "2020-11-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/mingchen-script/CVE-2020-1472-visualizer"
                },
                {
                    "repository": "PoC-in-GitHub · JayP232/The_big_Zero",
                    "author": "JayP232",
                    "first_seen": "2020-11-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "The following is the outcome of playing with CVE-2020-1472 and attempting to automate the process of gaining a shell on the DC",
                    "summary": "The following is the outcome of playing with CVE-2020-1472 and attempting to automate the process of gaining a shell on the DC",
                    "url": "https://github.com/JayP232/The_big_Zero"
                },
                {
                    "repository": "PoC-in-GitHub · b1ack0wl/CVE-2020-1472",
                    "author": "b1ack0wl",
                    "first_seen": "2020-11-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/b1ack0wl/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · SaharAttackit/CVE-2020-1472",
                    "author": "SaharAttackit",
                    "first_seen": "2020-12-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/SaharAttackit/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · wrathfulDiety/zerologon",
                    "author": "wrathfulDiety",
                    "first_seen": "2021-01-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "zerologon script to exploit CVE-2020-1472 CVSS 10/10",
                    "summary": "zerologon script to exploit CVE-2020-1472 CVSS 10/10",
                    "url": "https://github.com/wrathfulDiety/zerologon"
                },
                {
                    "repository": "PoC-in-GitHub · YossiSassi/ZeroLogon-Exploitation-Check",
                    "author": "YossiSassi",
                    "first_seen": "2021-01-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual exploitation of CVE-2020-1472. requires admin access to the DCs",
                    "summary": "quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual exploitation of CVE-2020-1472. requires admin access to the DCs",
                    "url": "https://github.com/YossiSassi/ZeroLogon-Exploitation-Check"
                },
                {
                    "repository": "PoC-in-GitHub · sho-luv/zerologon",
                    "author": "sho-luv",
                    "first_seen": "2021-01-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 18,
                    "title": "Zerologon Check and Exploit - Discovered by Tom Tervoort of Secura and expanded on @Dirkjanm's cve-2020-1472 coded example. This tool will check, exploit and restore password to original state",
                    "summary": "Zerologon Check and Exploit - Discovered by Tom Tervoort of Secura and expanded on @Dirkjanm's cve-2020-1472 coded example. This tool will check, exploit and restore password to original state",
                    "url": "https://github.com/sho-luv/zerologon"
                },
                {
                    "repository": "PoC-in-GitHub · hell-moon/ZeroLogon-Exploit",
                    "author": "hell-moon",
                    "first_seen": "2021-03-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Modified the test PoC from Secura, CVE-2020-1472, to change the machine password to null",
                    "summary": "Modified the test PoC from Secura, CVE-2020-1472, to change the machine password to null",
                    "url": "https://github.com/hell-moon/ZeroLogon-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Udyz/Zerologon",
                    "author": "Udyz",
                    "first_seen": "2021-04-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Exploit Code for CVE-2020-1472 aka Zerologon",
                    "summary": "Exploit Code for CVE-2020-1472 aka Zerologon",
                    "url": "https://github.com/Udyz/Zerologon"
                },
                {
                    "repository": "PoC-in-GitHub · itssmikefm/CVE-2020-1472",
                    "author": "itssmikefm",
                    "first_seen": "2021-04-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/itssmikefm/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · B34MR/zeroscan",
                    "author": "B34MR",
                    "first_seen": "2021-06-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "Zeroscan is a Domain Controller vulnerability scanner, that currently includes checks for Zerologon (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.",
                    "summary": "Zeroscan is a Domain Controller vulnerability scanner, that currently includes checks for Zerologon (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.",
                    "url": "https://github.com/B34MR/zeroscan"
                },
                {
                    "repository": "PoC-in-GitHub · TheJoyOfHacking/SecuraBV-CVE-2020-1472",
                    "author": "TheJoyOfHacking",
                    "first_seen": "2022-02-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/TheJoyOfHacking/SecuraBV-CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · TheJoyOfHacking/dirkjanm-CVE-2020-1472",
                    "author": "TheJoyOfHacking",
                    "first_seen": "2022-02-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/TheJoyOfHacking/dirkjanm-CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · Anonymous-Family/Zero-day-scanning",
                    "author": "Anonymous-Family",
                    "first_seen": "2022-03-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Zero-day-scanning is a Domain Controller vulnerability scanner, that currently includes checks for Zero-day-scanning (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.",
                    "summary": "Zero-day-scanning is a Domain Controller vulnerability scanner, that currently includes checks for Zero-day-scanning (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.",
                    "url": "https://github.com/Anonymous-Family/Zero-day-scanning"
                },
                {
                    "repository": "PoC-in-GitHub · Anonymous-Family/CVE-2020-1472",
                    "author": "Anonymous-Family",
                    "first_seen": "2022-03-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Test tool for CVE-2020-1472",
                    "summary": "Test tool for CVE-2020-1472",
                    "url": "https://github.com/Anonymous-Family/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · carlos55ml/zerologon",
                    "author": "carlos55ml",
                    "first_seen": "2022-03-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Set of scripts, to test and exploit the zerologon vulnerability (CVE-2020-1472).",
                    "summary": "Set of scripts, to test and exploit the zerologon vulnerability (CVE-2020-1472).",
                    "url": "https://github.com/carlos55ml/zerologon"
                },
                {
                    "repository": "PoC-in-GitHub · Rvn0xsy/ZeroLogon",
                    "author": "Rvn0xsy",
                    "first_seen": "2022-08-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 83,
                    "title": "CVE-2020-1472 C++",
                    "summary": "CVE-2020-1472 C++",
                    "url": "https://github.com/Rvn0xsy/ZeroLogon"
                },
                {
                    "repository": "PoC-in-GitHub · guglia001/MassZeroLogon",
                    "author": "guglia001",
                    "first_seen": "2022-09-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Tool for mass testing ZeroLogon vulnerability CVE-2020-1472",
                    "summary": "Tool for mass testing ZeroLogon vulnerability CVE-2020-1472",
                    "url": "https://github.com/guglia001/MassZeroLogon"
                },
                {
                    "repository": "PoC-in-GitHub · likeww/MassZeroLogon",
                    "author": "likeww",
                    "first_seen": "2022-09-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Tool for mass testing ZeroLogon vulnerability CVE-2020-1472",
                    "summary": "Tool for mass testing ZeroLogon vulnerability CVE-2020-1472",
                    "url": "https://github.com/likeww/MassZeroLogon"
                },
                {
                    "repository": "PoC-in-GitHub · dr4g0n23/CVE-2020-1472",
                    "author": "dr4g0n23",
                    "first_seen": "2022-11-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/dr4g0n23/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · Akash7350/CVE-2020-1472",
                    "author": "Akash7350",
                    "first_seen": "2023-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/Akash7350/CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · c3rrberu5/ZeroLogon-to-Shell",
                    "author": "c3rrberu5",
                    "first_seen": "2023-08-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is a combination of the zerologon_tester.py code (https://raw.githubusercontent.com/SecuraBV/CVE-2020-1472/master/zerologon_tester.py) and the tool evil-winrm to get a shell.",
                    "summary": "This is a combination of the zerologon_tester.py code (https://raw.githubusercontent.com/SecuraBV/CVE-2020-1472/master/zerologon_tester.py) and the tool evil-winrm to get a shell.",
                    "url": "https://github.com/c3rrberu5/ZeroLogon-to-Shell"
                },
                {
                    "repository": "PoC-in-GitHub · logg-1/0logon",
                    "author": "logg-1",
                    "first_seen": "2024-01-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "MS-NRPC (Microsoft NetLogon Remote Protocol)/CVE-2020-1472",
                    "summary": "MS-NRPC (Microsoft NetLogon Remote Protocol)/CVE-2020-1472",
                    "url": "https://github.com/logg-1/0logon"
                },
                {
                    "repository": "PoC-in-GitHub · whoami-chmod777/Zerologon-Attack-CVE-2020-1472-POC",
                    "author": "whoami-chmod777",
                    "first_seen": "2024-01-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/whoami-chmod777/Zerologon-Attack-CVE-2020-1472-POC"
                },
                {
                    "repository": "PoC-in-GitHub · metehangelgi/CVE-2020-1472-LAB",
                    "author": "metehangelgi",
                    "first_seen": "2024-02-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Lab introduction to ZeroLogon",
                    "summary": "Lab introduction to ZeroLogon",
                    "url": "https://github.com/metehangelgi/CVE-2020-1472-LAB"
                },
                {
                    "repository": "PoC-in-GitHub · JolynNgSC/Zerologon_CVE-2020-1472",
                    "author": "JolynNgSC",
                    "first_seen": "2024-03-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/JolynNgSC/Zerologon_CVE-2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · blackh00d/zerologon-poc",
                    "author": "blackh00d",
                    "first_seen": "2024-06-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A script to exploit CVE-2020-1472 (Zerologon)",
                    "summary": "A script to exploit CVE-2020-1472 (Zerologon)",
                    "url": "https://github.com/blackh00d/zerologon-poc"
                },
                {
                    "repository": "PoC-in-GitHub · TuanCui22/ZerologonWithImpacket-CVE2020-1472",
                    "author": "TuanCui22",
                    "first_seen": "2024-12-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A practical proof-of-concept for CVE-2020-1472 (Zerologon) using the Impacket library to exploit Netlogon vulnerability and perform unauthorized domain controller access.",
                    "summary": "A practical proof-of-concept for CVE-2020-1472 (Zerologon) using the Impacket library to exploit Netlogon vulnerability and perform unauthorized domain controller access.",
                    "url": "https://github.com/TuanCui22/ZerologonWithImpacket-CVE2020-1472"
                },
                {
                    "repository": "PoC-in-GitHub · PakwanSK/Simulating-and-preventing-Zerologon-CVE-2020-1472-vulnerability-attacks.",
                    "author": "PakwanSK",
                    "first_seen": "2025-03-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Simulation of the Zerologon (CVE-2020-1472) vulnerability attack in Active Directory on Windows Server 2016 and the use of the Trend Micro Deep Security solution to prevent such attacks.",
                    "summary": "Simulation of the Zerologon (CVE-2020-1472) vulnerability attack in Active Directory on Windows Server 2016 and the use of the Trend Micro Deep Security solution to prevent such attacks.",
                    "url": "https://github.com/PakwanSK/Simulating-and-preventing-Zerologon-CVE-2020-1472-vulnerability-attacks."
                },
                {
                    "repository": "PoC-in-GitHub · tdevworks/CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation",
                    "author": "tdevworks",
                    "first_seen": "2025-05-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472 repository",
                    "summary": "",
                    "url": "https://github.com/tdevworks/CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation"
                },
                {
                    "repository": "PoC-in-GitHub · 100HnoMeuNome/ZeroLogon-CVE-2020-1472-lab",
                    "author": "100HnoMeuNome",
                    "first_seen": "2025-10-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Explicação e demonstração da vulnerabilidade ZeroLogon (CVE-2020-1472)",
                    "summary": "Explicação e demonstração da vulnerabilidade ZeroLogon (CVE-2020-1472)",
                    "url": "https://github.com/100HnoMeuNome/ZeroLogon-CVE-2020-1472-lab"
                },
                {
                    "repository": "PoC-in-GitHub · nyambiblaise/Domain-Controller-DC-Exploitation-with-Metasploit-Impacket",
                    "author": "nyambiblaise",
                    "first_seen": "2025-10-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "End-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-1472), extracted NTLM hashes, gained SYSTEM shell, and established a Meterpreter session.",
                    "summary": "End-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-1472), extracted NTLM hashes, gained SYSTEM shell, and established a Meterpreter session.",
                    "url": "https://github.com/nyambiblaise/Domain-Controller-DC-Exploitation-with-Metasploit-Impacket"
                },
                {
                    "repository": "PoC-in-GitHub · mods20hh/ZeroLogon-PoC-DC-Pwn",
                    "author": "mods20hh",
                    "first_seen": "2025-12-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Zerologon (CVE-2020-1472) Proof-of-Concept application - Critical Active Directory vulnerability exploitation tool.",
                    "summary": "Zerologon (CVE-2020-1472) Proof-of-Concept application - Critical Active Directory vulnerability exploitation tool.",
                    "url": "https://github.com/mods20hh/ZeroLogon-PoC-DC-Pwn"
                },
                {
                    "repository": "PoC-in-GitHub · commit2main/zerologon-lab",
                    "author": "commit2main",
                    "first_seen": "2025-12-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Scripts for a lab environment demonstrating the Zerologon (CVE-2020-1472) vulnerability.",
                    "summary": "Scripts for a lab environment demonstrating the Zerologon (CVE-2020-1472) vulnerability.",
                    "url": "https://github.com/commit2main/zerologon-lab"
                },
                {
                    "repository": "PoC-in-GitHub · abdullah50i/internal-penetration-testing-project-using-Metasploit",
                    "author": "abdullah50i",
                    "first_seen": "2026-07-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB & LDAP scanners. Exploited DC10 via ZeroLogon (CVE-2020-1472), dumped AD NTLM hashes with Impacket, performed Pass-the-Hash, then gained a Meterpreter reverse shell.",
                    "summary": "Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB & LDAP scanners. Exploited DC10 via ZeroLogon (CVE-2020-1472), dumped AD NTLM hashes with Impacket, performed Pass-the-Hash, then gained a Meterpreter reverse shell.",
                    "url": "https://github.com/abdullah50i/internal-penetration-testing-project-using-Metasploit"
                },
                {
                    "repository": "PoC-in-GitHub · ckq7703/CVE-2020-1472",
                    "author": "ckq7703",
                    "first_seen": "2026-08-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-1472",
                    "summary": "CVE-2020-1472",
                    "url": "https://github.com/ckq7703/CVE-2020-1472"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-07T08:07:54+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Zerologon exploit",
                    "summary": "Exploit for CVE-2020-1472. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-UDYZ-ZEROLOGON"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:05:29+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2020-1472 exploit",
                    "summary": "Exploit for CVE-2020-1472. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NAXG-CVE-2020-1472"
                },
                {
                    "title": "Exploit for cve-2020-1472_Tool-collection CVE-2020-1472",
                    "summary": "Zerologon tool collection for CVE-2020-1472 Active Directory DC hash extraction and password reset.",
                    "what_happened": "Zerologon tool collection for CVE-2020-1472 Active Directory DC hash extraction and password reset.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XCCCC666-CVE-2020-1472_TOOL-COLLECTION",
                        "https://kitploit.com/hi/tools/github/0xcccc666/cve-2020-1472_tool-collection/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-31T16:51:32",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XCCCC666-CVE-2020-1472_TOOL-COLLECTION"
                },
                {
                    "title": "Exploit for cve-2020-1472_Tool-collection CVE-2020-1472",
                    "summary": "Zerologon tool collection for CVE-2020-1472 Active Directory DC hash extraction and password reset.",
                    "what_happened": "Zerologon tool collection for CVE-2020-1472 Active Directory DC hash extraction and password reset.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XCCCC666-CVE-2020-1472_TOOL-COLLECTION",
                        "https://kitploit.com/hi/tools/github/0xcccc666/cve-2020-1472_tool-collection/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-08-31T16:51:32",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/0xcccc666/cve-2020-1472_tool-collection/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/49071",
                "https://github.com/Tobey123/CVE-2020-1472-visualizer",
                "https://github.com/bvcyber/CVE-2020-1472",
                "https://github.com/cube0x0/CVE-2020-1472",
                "https://github.com/dirkjanm/CVE-2020-1472",
                "https://github.com/VoidSec/CVE-2020-1472",
                "https://github.com/risksense/zerologon",
                "https://github.com/bb00/zer0dump",
                "https://github.com/0xkami/CVE-2020-1472",
                "https://github.com/NAXG/CVE-2020-1472",
                "https://github.com/thatonesecguy/zerologon-CVE-2020-1472",
                "https://github.com/k8gege/CVE-2020-1472-EXP",
                "https://github.com/jiushill/CVE-2020-1472",
                "https://github.com/McKinnonIT/zabbix-template-CVE-2020-1472",
                "https://github.com/mstxq17/cve-2020-1472",
                "https://github.com/Fa1c0n35/CVE-2020-1472",
                "https://github.com/Fa1c0n35/SecuraBV-CVE-2020-1472",
                "https://github.com/CanciuCostin/CVE-2020-1472",
                "https://github.com/0xcccc666/cve-2020-1472_Tool-collection",
                "https://github.com/murataydemir/CVE-2020-1472",
                "https://github.com/npocmak/CVE-2020-1472",
                "https://github.com/FaFcFF41/CVE-2020-1472",
                "https://github.com/zeronetworks/zerologon",
                "https://github.com/sv3nbeast/CVE-2020-1472",
                "https://github.com/midpipps/CVE-2020-1472-Easy",
                "https://github.com/hectorgie/CVE-2020-1472",
                "https://github.com/johnpathe/zerologon-cve-2020-1472-notes",
                "https://github.com/t31m0/CVE-2020-1472",
                "https://github.com/grupooruss/CVE-2020-1472",
                "https://github.com/striveben/CVE-2020-1472",
                "https://github.com/Fa1c0n35/CVE-2020-1472-02-",
                "https://github.com/Whippet0/CVE-2020-1472",
                "https://github.com/WiIs0n/Zerologon_CVE-2020-1472",
                "https://github.com/Privia-Security/ADZero",
                "https://github.com/Ken-Abruzzi/cve-2020-1472",
                "https://github.com/rhymeswithmogul/Set-ZerologonMitigation",
                "https://github.com/shanfenglan/cve-2020-1472",
                "https://github.com/maikelnight/zerologon",
                "https://github.com/CPO-EH/CVE-2020-1472_ZeroLogonChecker",
                "https://github.com/puckiestyle/CVE-2020-1472",
                "https://github.com/mingchen-script/CVE-2020-1472-visualizer",
                "https://github.com/JayP232/The_big_Zero",
                "https://github.com/b1ack0wl/CVE-2020-1472",
                "https://github.com/SaharAttackit/CVE-2020-1472",
                "https://github.com/wrathfulDiety/zerologon",
                "https://github.com/YossiSassi/ZeroLogon-Exploitation-Check",
                "https://github.com/sho-luv/zerologon",
                "https://github.com/hell-moon/ZeroLogon-Exploit",
                "https://github.com/Udyz/Zerologon",
                "https://github.com/itssmikefm/CVE-2020-1472",
                "https://github.com/B34MR/zeroscan",
                "https://github.com/TheJoyOfHacking/SecuraBV-CVE-2020-1472",
                "https://github.com/TheJoyOfHacking/dirkjanm-CVE-2020-1472",
                "https://github.com/Anonymous-Family/Zero-day-scanning",
                "https://github.com/Anonymous-Family/CVE-2020-1472",
                "https://github.com/carlos55ml/zerologon",
                "https://github.com/Rvn0xsy/ZeroLogon",
                "https://github.com/guglia001/MassZeroLogon",
                "https://github.com/likeww/MassZeroLogon",
                "https://github.com/dr4g0n23/CVE-2020-1472",
                "https://github.com/Akash7350/CVE-2020-1472",
                "https://github.com/c3rrberu5/ZeroLogon-to-Shell",
                "https://github.com/logg-1/0logon",
                "https://github.com/whoami-chmod777/Zerologon-Attack-CVE-2020-1472-POC",
                "https://github.com/metehangelgi/CVE-2020-1472-LAB",
                "https://github.com/JolynNgSC/Zerologon_CVE-2020-1472",
                "https://github.com/blackh00d/zerologon-poc",
                "https://github.com/TuanCui22/ZerologonWithImpacket-CVE2020-1472",
                "https://github.com/PakwanSK/Simulating-and-preventing-Zerologon-CVE-2020-1472-vulnerability-attacks.",
                "https://github.com/tdevworks/CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation",
                "https://github.com/100HnoMeuNome/ZeroLogon-CVE-2020-1472-lab",
                "https://github.com/nyambiblaise/Domain-Controller-DC-Exploitation-with-Metasploit-Impacket",
                "https://github.com/mods20hh/ZeroLogon-PoC-DC-Pwn",
                "https://github.com/commit2main/zerologon-lab",
                "https://github.com/abdullah50i/internal-penetration-testing-project-using-Metasploit",
                "https://github.com/ckq7703/CVE-2020-1472",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-UDYZ-ZEROLOGON",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-NAXG-CVE-2020-1472",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-0XCCCC666-CVE-2020-1472_TOOL-COLLECTION",
                "https://kitploit.com/hi/tools/github/0xcccc666/cve-2020-1472_tool-collection/"
            ],
            "timeline": [
                {
                    "at": "2026-08-24T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2020-1300",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for concealed_position CVE-2019-19363 CVE-2020-1300 CVE-2021-34481 CVE-2021-35449 CVE-2021-38085",
            "summary": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
            "updated_at": "2026-09-04T19:28:37Z",
            "published_at": "2026-09-04T19:28:37Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 59,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for concealed_position CVE-2019-19363 CVE-2020-1300 CVE-2021-34481 CVE-2021-35449 CVE-2021-38085",
                    "summary": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                        "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T21:28:37",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION"
                },
                {
                    "title": "Exploit for concealed_position CVE-2019-19363 CVE-2020-1300 CVE-2021-34481 CVE-2021-35449 CVE-2021-38085",
                    "summary": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                        "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-04T21:28:37",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T19:28:37Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2020-1206",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for SMBGhost-WorkaroundApplier CVE-2020-0796",
            "summary": "SMBv3 unauthenticated RCE (CVE-2020-0796) workaround applier tool for unpatched systems.",
            "updated_at": "2026-08-24T14:34:43Z",
            "published_at": "2026-08-24T14:34:43Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 124,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "SMBv3 unauthenticated RCE (CVE-2020-0796) workaround applier tool for unpatched systems.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for SMBGhost-WorkaroundApplier CVE-2020-0796",
                    "summary": "SMBv3 unauthenticated RCE (CVE-2020-0796) workaround applier tool for unpatched systems.",
                    "what_happened": "SMBv3 unauthenticated RCE (CVE-2020-0796) workaround applier tool for unpatched systems.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALMORABEA-SMBGHOST-WORKAROUNDAPPLIER",
                        "https://kitploit.com/ru/tools/github/almorabea/smbghost-workaroundapplier/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-24T16:34:43",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALMORABEA-SMBGHOST-WORKAROUNDAPPLIER"
                },
                {
                    "title": "Exploit for SMBGhost-WorkaroundApplier CVE-2020-0796",
                    "summary": "SMBv3 unauthenticated RCE (CVE-2020-0796) workaround applier tool for unpatched systems.",
                    "what_happened": "SMBv3 unauthenticated RCE (CVE-2020-0796) workaround applier tool for unpatched systems.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALMORABEA-SMBGHOST-WORKAROUNDAPPLIER",
                        "https://kitploit.com/ru/tools/github/almorabea/smbghost-workaroundapplier/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-24T16:34:43",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/almorabea/smbghost-workaroundapplier/"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-06T08:25:49+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2020-1206 exploit",
                    "summary": "Exploit for CVE-2020-0796 and CVE-2020-1206. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DATNTSEC-CVE-2020-1206"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALMORABEA-SMBGHOST-WORKAROUNDAPPLIER",
                "https://kitploit.com/ru/tools/github/almorabea/smbghost-workaroundapplier/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DATNTSEC-CVE-2020-1206"
            ],
            "timeline": [
                {
                    "at": "2026-08-24T14:34:43Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALMORABEA-SMBGHOST-WORKAROUNDAPPLIER"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2020-0796",
            "vendor": "Microsoft",
            "product": "SMBv3",
            "title": "Microsoft SMBv3 Remote Code Execution Vulnerability",
            "summary": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.",
            "updated_at": "2026-08-24T14:34:43Z",
            "published_at": "2026-08-24T14:34:43Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 4213,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 48216",
                    "author": "eerykitty",
                    "first_seen": "2020-03-14",
                    "confidence": "High",
                    "title": "Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)",
                    "summary": "Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Buffer Overflow (PoC)",
                    "url": "https://www.exploit-db.com/exploits/48216",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 48267",
                    "author": "Daniel García Gutiérrez",
                    "first_seen": "2020-03-30",
                    "confidence": "High",
                    "title": "Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege Escalation",
                    "summary": "Microsoft Windows 10 (1903/1909) - 'SMBGhost' SMB3.1.1 'SMB2_COMPRESSION_CAPABILITIES' Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/48267",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 48537",
                    "author": "chompie1337",
                    "first_seen": "2020-06-02",
                    "confidence": "High",
                    "title": "Microsoft Windows - 'SMBGhost' Remote Code Execution",
                    "summary": "Microsoft Windows - 'SMBGhost' Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/48537",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for SMBGhost-WorkaroundApplier CVE-2020-0796",
                    "summary": "SMBv3 unauthenticated RCE (CVE-2020-0796) workaround applier tool for unpatched systems.",
                    "what_happened": "SMBv3 unauthenticated RCE (CVE-2020-0796) workaround applier tool for unpatched systems.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALMORABEA-SMBGHOST-WORKAROUNDAPPLIER",
                        "https://kitploit.com/ru/tools/github/almorabea/smbghost-workaroundapplier/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-24T16:34:43",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALMORABEA-SMBGHOST-WORKAROUNDAPPLIER"
                },
                {
                    "title": "Exploit for SMBGhost-WorkaroundApplier CVE-2020-0796",
                    "summary": "SMBv3 unauthenticated RCE (CVE-2020-0796) workaround applier tool for unpatched systems.",
                    "what_happened": "SMBv3 unauthenticated RCE (CVE-2020-0796) workaround applier tool for unpatched systems.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALMORABEA-SMBGHOST-WORKAROUNDAPPLIER",
                        "https://kitploit.com/ru/tools/github/almorabea/smbghost-workaroundapplier/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-24T16:34:43",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/almorabea/smbghost-workaroundapplier/"
                },
                {
                    "repository": "PoC-in-GitHub · k8gege/PyLadon",
                    "author": "k8gege",
                    "first_seen": "2019-11-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 52,
                    "title": "Ladon Scanner For Python, Large Network Penetration Scanner & Cobalt Strike, vulnerability / exploit / detection / MS17010/SmbGhost/CVE-2020-0796/CVE-2018-2894",
                    "summary": "Ladon Scanner For Python, Large Network Penetration Scanner & Cobalt Strike, vulnerability / exploit / detection / MS17010/SmbGhost/CVE-2020-0796/CVE-2018-2894",
                    "url": "https://github.com/k8gege/PyLadon"
                },
                {
                    "repository": "PoC-in-GitHub · 0x25bit/CVE-2020-0796-PoC",
                    "author": "0x25bit",
                    "first_seen": "2020-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 18,
                    "title": "Weaponized PoC for SMBv3 TCP codec/compression vulnerability",
                    "summary": "Weaponized PoC for SMBv3 TCP codec/compression vulnerability",
                    "url": "https://github.com/0x25bit/CVE-2020-0796-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · technion/DisableSMBCompression",
                    "author": "technion",
                    "first_seen": "2020-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2020-0796 Flaw Mitigation - Active Directory Administrative Templates",
                    "summary": "CVE-2020-0796 Flaw Mitigation - Active Directory Administrative Templates",
                    "url": "https://github.com/technion/DisableSMBCompression"
                },
                {
                    "repository": "PoC-in-GitHub · T13nn3s/CVE-2020-0796",
                    "author": "T13nn3s",
                    "first_seen": "2020-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 28,
                    "title": "Powershell SMBv3 Compression checker",
                    "summary": "Powershell SMBv3 Compression checker",
                    "url": "https://github.com/T13nn3s/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · ly4k/SMBGhost",
                    "author": "ly4k",
                    "first_seen": "2020-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 722,
                    "title": "Scanner for CVE-2020-0796 - SMBv3 RCE",
                    "summary": "Scanner for CVE-2020-0796 - SMBv3 RCE",
                    "url": "https://github.com/ly4k/SMBGhost"
                },
                {
                    "repository": "PoC-in-GitHub · joaozietolie/CVE-2020-0796-Checker",
                    "author": "joaozietolie",
                    "first_seen": "2020-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "Script that checks if the system is vulnerable to CVE-2020-0796 (SMB v3.1.1)",
                    "summary": "Script that checks if the system is vulnerable to CVE-2020-0796 (SMB v3.1.1)",
                    "url": "https://github.com/joaozietolie/CVE-2020-0796-Checker"
                },
                {
                    "repository": "PoC-in-GitHub · ButrintKomoni/cve-2020-0796",
                    "author": "ButrintKomoni",
                    "first_seen": "2020-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "Identifying and Mitigating the CVE-2020–0796 flaw in the fly",
                    "summary": "Identifying and Mitigating the CVE-2020–0796 flaw in the fly",
                    "url": "https://github.com/ButrintKomoni/cve-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · dickens88/cve-2020-0796-scanner",
                    "author": "dickens88",
                    "first_seen": "2020-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "This project is used for scanning cve-2020-0796 SMB vulnerability",
                    "summary": "This project is used for scanning cve-2020-0796 SMB vulnerability",
                    "url": "https://github.com/dickens88/cve-2020-0796-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · kn6869610/CVE-2020-0796",
                    "author": "kn6869610",
                    "first_seen": "2020-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/kn6869610/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · awareseven/eternalghosttest",
                    "author": "awareseven",
                    "first_seen": "2020-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This repository contains a test case for CVE-2020-0796",
                    "summary": "This repository contains a test case for CVE-2020-0796",
                    "url": "https://github.com/awareseven/eternalghosttest"
                },
                {
                    "repository": "PoC-in-GitHub · xax007/CVE-2020-0796-Scanner",
                    "author": "xax007",
                    "first_seen": "2020-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 SMBv3.1.1 Compression Capability Vulnerability Scanner",
                    "summary": "CVE-2020-0796 SMBv3.1.1 Compression Capability Vulnerability Scanner",
                    "url": "https://github.com/xax007/CVE-2020-0796-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · Dhoomralochana/Scanners-for-CVE-2020-0796-Testing",
                    "author": "Dhoomralochana",
                    "first_seen": "2020-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Scanners List - Microsoft Windows SMBv3 Remote Code Execution Vulnerability (CVE-2020-0796)",
                    "summary": "Scanners List - Microsoft Windows SMBv3 Remote Code Execution Vulnerability (CVE-2020-0796)",
                    "url": "https://github.com/Dhoomralochana/Scanners-for-CVE-2020-0796-Testing"
                },
                {
                    "repository": "PoC-in-GitHub · UraSecTeam/smbee",
                    "author": "UraSecTeam",
                    "first_seen": "2020-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Check system is vulnerable CVE-2020-0796 (SMB v3)",
                    "summary": "Check system is vulnerable CVE-2020-0796 (SMB v3)",
                    "url": "https://github.com/UraSecTeam/smbee"
                },
                {
                    "repository": "PoC-in-GitHub · netscylla/SMBGhost",
                    "author": "netscylla",
                    "first_seen": "2020-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "SMBGhost (CVE-2020-0796) threaded scanner",
                    "summary": "SMBGhost (CVE-2020-0796) threaded scanner",
                    "url": "https://github.com/netscylla/SMBGhost"
                },
                {
                    "repository": "PoC-in-GitHub · eerykitty/CVE-2020-0796-PoC",
                    "author": "eerykitty",
                    "first_seen": "2020-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 331,
                    "title": "PoC for triggering buffer overflow via CVE-2020-0796",
                    "summary": "PoC for triggering buffer overflow via CVE-2020-0796",
                    "url": "https://github.com/eerykitty/CVE-2020-0796-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · wneessen/SMBCompScan",
                    "author": "wneessen",
                    "first_seen": "2020-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Scanner script to identify hosts vulnerable to CVE-2020-0796",
                    "summary": "Scanner script to identify hosts vulnerable to CVE-2020-0796",
                    "url": "https://github.com/wneessen/SMBCompScan"
                },
                {
                    "repository": "PoC-in-GitHub · ioncodes/SMBGhost",
                    "author": "ioncodes",
                    "first_seen": "2020-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 57,
                    "title": "Scanner for CVE-2020-0796 - A SMBv3.1.1 + SMB compression RCE",
                    "summary": "Scanner for CVE-2020-0796 - A SMBv3.1.1 + SMB compression RCE",
                    "url": "https://github.com/ioncodes/SMBGhost"
                },
                {
                    "repository": "PoC-in-GitHub · laolisafe/CVE-2020-0796",
                    "author": "laolisafe",
                    "first_seen": "2020-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "SMBv3 RCE vulnerability in SMBv3",
                    "summary": "SMBv3 RCE vulnerability in SMBv3",
                    "url": "https://github.com/laolisafe/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · gabimarti/SMBScanner",
                    "author": "gabimarti",
                    "first_seen": "2020-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": "Multithread SMB scanner to check CVE-2020-0796 for SMB v3.11",
                    "summary": "Multithread SMB scanner to check CVE-2020-0796 for SMB v3.11",
                    "url": "https://github.com/gabimarti/SMBScanner"
                },
                {
                    "repository": "PoC-in-GitHub · Almorabea/SMBGhost-WorkaroundApplier",
                    "author": "Almorabea",
                    "first_seen": "2020-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This script will apply the workaround for the vulnerability CVE-2020-0796 for the SMBv3 unauthenticated RCE",
                    "summary": "This script will apply the workaround for the vulnerability CVE-2020-0796 for the SMBv3 unauthenticated RCE",
                    "url": "https://github.com/Almorabea/SMBGhost-WorkaroundApplier"
                },
                {
                    "repository": "PoC-in-GitHub · vysecurity/CVE-2020-0796",
                    "author": "vysecurity",
                    "first_seen": "2020-03-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2020-0796 - Working PoC - 20200313",
                    "summary": "CVE-2020-0796 - Working PoC - 20200313",
                    "url": "https://github.com/vysecurity/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · BinaryShadow94/SMBv3.1.1-scan---CVE-2020-0796",
                    "author": "BinaryShadow94",
                    "first_seen": "2020-03-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Little scanner to know if a machine is runnig SMBv3 (possible vulnerability CVE-2020-0796)",
                    "summary": "Little scanner to know if a machine is runnig SMBv3 (possible vulnerability CVE-2020-0796)",
                    "url": "https://github.com/BinaryShadow94/SMBv3.1.1-scan---CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · w1ld3r/SMBGhost_Scanner",
                    "author": "w1ld3r",
                    "first_seen": "2020-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "Advanced scanner for CVE-2020-0796 - SMBv3 RCE",
                    "summary": "Advanced scanner for CVE-2020-0796 - SMBv3 RCE",
                    "url": "https://github.com/w1ld3r/SMBGhost_Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · wsfengfan/CVE-2020-0796",
                    "author": "wsfengfan",
                    "first_seen": "2020-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 Python POC buffer overflow",
                    "summary": "CVE-2020-0796 Python POC buffer overflow",
                    "url": "https://github.com/wsfengfan/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · GuoKerS/aioScan_CVE-2020-0796",
                    "author": "GuoKerS",
                    "first_seen": "2020-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 15,
                    "title": "基于asyncio（协程）的CVE-2020-0796 速度还是十分可观的，方便运维师傅们对内网做下快速检测。",
                    "summary": "基于asyncio（协程）的CVE-2020-0796 速度还是十分可观的，方便运维师傅们对内网做下快速检测。",
                    "url": "https://github.com/GuoKerS/aioScan_CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · jiansiting/CVE-2020-0796-Scanner",
                    "author": "jiansiting",
                    "first_seen": "2020-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2020-0796-Scanner",
                    "summary": "CVE-2020-0796-Scanner",
                    "url": "https://github.com/jiansiting/CVE-2020-0796-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · maxpl0it/Unauthenticated-CVE-2020-0796-PoC",
                    "author": "maxpl0it",
                    "first_seen": "2020-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 22,
                    "title": "An unauthenticated PoC for CVE-2020-0796",
                    "summary": "An unauthenticated PoC for CVE-2020-0796",
                    "url": "https://github.com/maxpl0it/Unauthenticated-CVE-2020-0796-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · ran-sama/CVE-2020-0796",
                    "author": "ran-sama",
                    "first_seen": "2020-03-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Lightweight PoC and Scanner for CVE-2020-0796 without authentication.",
                    "summary": "Lightweight PoC and Scanner for CVE-2020-0796 without authentication.",
                    "url": "https://github.com/ran-sama/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · sujitawake/smbghost",
                    "author": "sujitawake",
                    "first_seen": "2020-03-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2020-0796_CoronaBlue_SMBGhost",
                    "summary": "CVE-2020-0796_CoronaBlue_SMBGhost",
                    "url": "https://github.com/sujitawake/smbghost"
                },
                {
                    "repository": "PoC-in-GitHub · julixsalas/CVE-2020-0796",
                    "author": "julixsalas",
                    "first_seen": "2020-03-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Scanner for CVE-2020-0796",
                    "summary": "Scanner for CVE-2020-0796",
                    "url": "https://github.com/julixsalas/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · cory-zajicek/CVE-2020-0796-DoS",
                    "author": "cory-zajicek",
                    "first_seen": "2020-03-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "DoS PoC for CVE-2020-0796 (SMBGhost)",
                    "summary": "DoS PoC for CVE-2020-0796 (SMBGhost)",
                    "url": "https://github.com/cory-zajicek/CVE-2020-0796-DoS"
                },
                {
                    "repository": "PoC-in-GitHub · tripledd/cve-2020-0796-vuln",
                    "author": "tripledd",
                    "first_seen": "2020-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/tripledd/cve-2020-0796-vuln"
                },
                {
                    "repository": "PoC-in-GitHub · danigargu/CVE-2020-0796",
                    "author": "danigargu",
                    "first_seen": "2020-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1359,
                    "title": "CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost",
                    "summary": "CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost",
                    "url": "https://github.com/danigargu/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · jamf/CVE-2020-0796-LPE-POC",
                    "author": "jamf",
                    "first_seen": "2020-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 244,
                    "title": "CVE-2020-0796 Local Privilege Escalation POC",
                    "summary": "CVE-2020-0796 Local Privilege Escalation POC",
                    "url": "https://github.com/jamf/CVE-2020-0796-LPE-POC"
                },
                {
                    "repository": "PoC-in-GitHub · TinToSer/CVE-2020-0796-LPE",
                    "author": "TinToSer",
                    "first_seen": "2020-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "SMBGHOST local privilege escalation",
                    "summary": "SMBGHOST local privilege escalation",
                    "url": "https://github.com/TinToSer/CVE-2020-0796-LPE"
                },
                {
                    "repository": "PoC-in-GitHub · f1tz/CVE-2020-0796-LPE-EXP",
                    "author": "f1tz",
                    "first_seen": "2020-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "Windows SMBv3 LPE exploit 已编译版",
                    "summary": "Windows SMBv3 LPE exploit 已编译版",
                    "url": "https://github.com/f1tz/CVE-2020-0796-LPE-EXP"
                },
                {
                    "repository": "PoC-in-GitHub · tango-j/CVE-2020-0796",
                    "author": "tango-j",
                    "first_seen": "2020-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Coronablue exploit",
                    "summary": "Coronablue exploit",
                    "url": "https://github.com/tango-j/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · jiansiting/CVE-2020-0796",
                    "author": "jiansiting",
                    "first_seen": "2020-04-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 65,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/jiansiting/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · eastmountyxz/CVE-2020-0796-SMB",
                    "author": "eastmountyxz",
                    "first_seen": "2020-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 33,
                    "title": "该资源为CVE-2020-0796漏洞复现，包括Python版本和C++版本。主要是集合了github大神们的资源，希望您喜欢~",
                    "summary": "该资源为CVE-2020-0796漏洞复现，包括Python版本和C++版本。主要是集合了github大神们的资源，希望您喜欢~",
                    "url": "https://github.com/eastmountyxz/CVE-2020-0796-SMB"
                },
                {
                    "repository": "PoC-in-GitHub · LabDookhtegan/CVE-2020-0796-EXP",
                    "author": "LabDookhtegan",
                    "first_seen": "2020-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-0796-EXP",
                    "summary": "CVE-2020-0796-EXP",
                    "url": "https://github.com/LabDookhtegan/CVE-2020-0796-EXP"
                },
                {
                    "repository": "PoC-in-GitHub · Rvn0xsy/CVE_2020_0796_CNA",
                    "author": "Rvn0xsy",
                    "first_seen": "2020-04-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 74,
                    "title": "Cobalt Strike AggressorScripts CVE-2020-0796",
                    "summary": "Cobalt Strike AggressorScripts CVE-2020-0796",
                    "url": "https://github.com/Rvn0xsy/CVE_2020_0796_CNA"
                },
                {
                    "repository": "PoC-in-GitHub · 0xeb-bp/cve-2020-0796",
                    "author": "0xeb-bp",
                    "first_seen": "2020-04-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "CVE-2020-0796 (SMBGhost) LPE",
                    "summary": "CVE-2020-0796 (SMBGhost) LPE",
                    "url": "https://github.com/0xeb-bp/cve-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · intelliroot-tech/cve-2020-0796-Scanner",
                    "author": "intelliroot-tech",
                    "first_seen": "2020-04-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This tool helps scan large subnets for cve-2020-0796 vulnerable systems",
                    "summary": "This tool helps scan large subnets for cve-2020-0796 vulnerable systems",
                    "url": "https://github.com/intelliroot-tech/cve-2020-0796-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · jamf/CVE-2020-0796-RCE-POC",
                    "author": "jamf",
                    "first_seen": "2020-04-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 571,
                    "title": "CVE-2020-0796 Remote Code Execution POC",
                    "summary": "CVE-2020-0796 Remote Code Execution POC",
                    "url": "https://github.com/jamf/CVE-2020-0796-RCE-POC"
                },
                {
                    "repository": "PoC-in-GitHub · thelostworldFree/CVE-2020-0796",
                    "author": "thelostworldFree",
                    "first_seen": "2020-04-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "PoC RCE Reverse Shell for CVE-2020-0796 (SMBGhost)",
                    "summary": "PoC RCE Reverse Shell for CVE-2020-0796 (SMBGhost)",
                    "url": "https://github.com/thelostworldFree/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · bacth0san96/SMBGhostScanner",
                    "author": "bacth0san96",
                    "first_seen": "2020-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "SMBGhost CVE-2020-0796",
                    "summary": "SMBGhost CVE-2020-0796",
                    "url": "https://github.com/bacth0san96/SMBGhostScanner"
                },
                {
                    "repository": "PoC-in-GitHub · halsten/CVE-2020-0796",
                    "author": "halsten",
                    "first_seen": "2020-05-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/halsten/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · ysyyrps123/CVE-2020-0796-exp",
                    "author": "ysyyrps123",
                    "first_seen": "2020-06-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796-exp",
                    "summary": "CVE-2020-0796-exp",
                    "url": "https://github.com/ysyyrps123/CVE-2020-0796-exp"
                },
                {
                    "repository": "PoC-in-GitHub · exp-sky/CVE-2020-0796",
                    "author": "exp-sky",
                    "first_seen": "2020-06-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "SMBv3 Ghost (CVE-2020-0796) Vulnerability",
                    "summary": "SMBv3 Ghost (CVE-2020-0796) Vulnerability",
                    "url": "https://github.com/exp-sky/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · Barriuso/SMBGhost_AutomateExploitation",
                    "author": "Barriuso",
                    "first_seen": "2020-06-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 358,
                    "title": "SMBGhost (CVE-2020-0796) Automate Exploitation and Detection",
                    "summary": "SMBGhost (CVE-2020-0796) Automate Exploitation and Detection",
                    "url": "https://github.com/Barriuso/SMBGhost_AutomateExploitation"
                },
                {
                    "repository": "PoC-in-GitHub · 1060275195/SMBGhost",
                    "author": "1060275195",
                    "first_seen": "2020-06-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "批量测试CVE-2020-0796 - SMBv3 RCE",
                    "summary": "批量测试CVE-2020-0796 - SMBv3 RCE",
                    "url": "https://github.com/1060275195/SMBGhost"
                },
                {
                    "repository": "PoC-in-GitHub · Almorabea/SMBGhost-LPE-Metasploit-Module",
                    "author": "Almorabea",
                    "first_seen": "2020-06-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 20,
                    "title": "This is an implementation of the CVE-2020-0796 aka SMBGhost vulnerability, compatible with the Metasploit Framework",
                    "summary": "This is an implementation of the CVE-2020-0796 aka SMBGhost vulnerability, compatible with the Metasploit Framework",
                    "url": "https://github.com/Almorabea/SMBGhost-LPE-Metasploit-Module"
                },
                {
                    "repository": "PoC-in-GitHub · jamf/SMBGhost-SMBleed-scanner",
                    "author": "jamf",
                    "first_seen": "2020-07-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 44,
                    "title": "SMBGhost (CVE-2020-0796) and SMBleed (CVE-2020-1206) Scanner",
                    "summary": "SMBGhost (CVE-2020-0796) and SMBleed (CVE-2020-1206) Scanner",
                    "url": "https://github.com/jamf/SMBGhost-SMBleed-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · rsmudge/CVE-2020-0796-BOF",
                    "author": "rsmudge",
                    "first_seen": "2020-09-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 70,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/rsmudge/CVE-2020-0796-BOF"
                },
                {
                    "repository": "PoC-in-GitHub · codewithpradhan/SMBGhost-CVE-2020-0796-",
                    "author": "codewithpradhan",
                    "first_seen": "2020-09-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "To crash Windows-10 easily",
                    "summary": "To crash Windows-10 easily",
                    "url": "https://github.com/codewithpradhan/SMBGhost-CVE-2020-0796-"
                },
                {
                    "repository": "PoC-in-GitHub · AaronCaiii/CVE-2020-0796-POC",
                    "author": "AaronCaiii",
                    "first_seen": "2020-11-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796-POC",
                    "summary": "CVE-2020-0796-POC",
                    "url": "https://github.com/AaronCaiii/CVE-2020-0796-POC"
                },
                {
                    "repository": "PoC-in-GitHub · datntsec/CVE-2020-0796",
                    "author": "datntsec",
                    "first_seen": "2020-11-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/datntsec/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · MasterSploit/LPE---CVE-2020-0796",
                    "author": "MasterSploit",
                    "first_seen": "2020-11-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/MasterSploit/LPE---CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · 1stPeak/CVE-2020-0796-Scanner",
                    "author": "1stPeak",
                    "first_seen": "2021-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/1stPeak/CVE-2020-0796-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · Anonimo501/SMBGhost_CVE-2020-0796_checker",
                    "author": "Anonimo501",
                    "first_seen": "2021-09-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/Anonimo501/SMBGhost_CVE-2020-0796_checker"
                },
                {
                    "repository": "PoC-in-GitHub · Opensitoo/cve-2020-0796",
                    "author": "Opensitoo",
                    "first_seen": "2021-10-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/Opensitoo/cve-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · orangmuda/CVE-2020-0796",
                    "author": "orangmuda",
                    "first_seen": "2021-10-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Remote Code Execution POC for CVE-2020-0796",
                    "summary": "Remote Code Execution POC for CVE-2020-0796",
                    "url": "https://github.com/orangmuda/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · Murasame-nc/CVE-2020-0796-LPE-POC",
                    "author": "Murasame-nc",
                    "first_seen": "2021-10-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/Murasame-nc/CVE-2020-0796-LPE-POC"
                },
                {
                    "repository": "PoC-in-GitHub · F6JO/CVE-2020-0796-Batch-scanning",
                    "author": "F6JO",
                    "first_seen": "2021-10-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "批量扫描CVE-2020-0796",
                    "summary": "批量扫描CVE-2020-0796",
                    "url": "https://github.com/F6JO/CVE-2020-0796-Batch-scanning"
                },
                {
                    "repository": "PoC-in-GitHub · lisinan988/CVE-2020-0796-exp",
                    "author": "lisinan988",
                    "first_seen": "2021-11-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/lisinan988/CVE-2020-0796-exp"
                },
                {
                    "repository": "PoC-in-GitHub · vsai94/ECE9069_SMBGhost_Exploit_CVE-2020-0796-",
                    "author": "vsai94",
                    "first_seen": "2022-03-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Description of Exploit SMBGhost CVE-2020-0796",
                    "summary": "Description of Exploit SMBGhost CVE-2020-0796",
                    "url": "https://github.com/vsai94/ECE9069_SMBGhost_Exploit_CVE-2020-0796-"
                },
                {
                    "repository": "PoC-in-GitHub · arzuozkan/CVE-2020-0796",
                    "author": "arzuozkan",
                    "first_seen": "2022-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-0796 explanation and researching vulnerability for term porject CENG325",
                    "summary": "CVE-2020-0796 explanation and researching vulnerability for term porject CENG325",
                    "url": "https://github.com/arzuozkan/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · SEHandler/CVE-2020-0796",
                    "author": "SEHandler",
                    "first_seen": "2022-11-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-0796",
                    "summary": "CVE-2020-0796",
                    "url": "https://github.com/SEHandler/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · krizzz07/CVE-2020-0796",
                    "author": "krizzz07",
                    "first_seen": "2023-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "windows 10 SMB vulnerability",
                    "summary": "windows 10 SMB vulnerability",
                    "url": "https://github.com/krizzz07/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · OldDream666/cve-2020-0796",
                    "author": "OldDream666",
                    "first_seen": "2023-02-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "cve-2020-0796利用工具集",
                    "summary": "cve-2020-0796利用工具集",
                    "url": "https://github.com/OldDream666/cve-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · dungnm24/CVE-2020-0796",
                    "author": "dungnm24",
                    "first_seen": "2023-05-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "WindowsProtocolTestSuites is to trigger BSoD, and full exploit poc.",
                    "summary": "WindowsProtocolTestSuites is to trigger BSoD, and full exploit poc.",
                    "url": "https://github.com/dungnm24/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · hungdnvp/POC-CVE-2020-0796",
                    "author": "hungdnvp",
                    "first_seen": "2024-02-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/hungdnvp/POC-CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · AdamSonov/smbGhostCVE-2020-0796",
                    "author": "AdamSonov",
                    "first_seen": "2024-03-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This script will help you to scan for smbGhost vulnerability(CVE-2020-0796)",
                    "summary": "This script will help you to scan for smbGhost vulnerability(CVE-2020-0796)",
                    "url": "https://github.com/AdamSonov/smbGhostCVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · z3ena/Exploiting-and-Mitigating-CVE-2020-0796-SMBGhost-and-Print-Spooler-Vulnerabilities",
                    "author": "z3ena",
                    "first_seen": "2024-08-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository contains detailed documentation and code related to the exploitation, detection, and mitigation of two significant vulnerabilities: CVE-2020-0796 (SMBGhost) and Print Spooler.",
                    "summary": "This repository contains detailed documentation and code related to the exploitation, detection, and mitigation of two significant vulnerabilities: CVE-2020-0796 (SMBGhost) and Print Spooler.",
                    "url": "https://github.com/z3ena/Exploiting-and-Mitigating-CVE-2020-0796-SMBGhost-and-Print-Spooler-Vulnerabilities"
                },
                {
                    "repository": "PoC-in-GitHub · bsec404/CVE-2020-0796",
                    "author": "bsec404",
                    "first_seen": "2025-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/bsec404/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · monjheta/CVE-2020-0796",
                    "author": "monjheta",
                    "first_seen": "2025-02-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/monjheta/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · cybermads/CVE-2020-0796",
                    "author": "cybermads",
                    "first_seen": "2025-04-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/cybermads/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · DannyRavi/nmap-scripts",
                    "author": "DannyRavi",
                    "first_seen": "2025-04-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "nmap scripts for vuln cve-2020-0796 & cve-2019-7238 & cve2019-11580 & cve2017-6327",
                    "summary": "nmap scripts for vuln cve-2020-0796 & cve-2019-7238 & cve2019-11580 & cve2017-6327",
                    "url": "https://github.com/DannyRavi/nmap-scripts"
                },
                {
                    "repository": "PoC-in-GitHub · tdevworks/CVE-2020-0796-SMBGhost-Exploit-Demo",
                    "author": "tdevworks",
                    "first_seen": "2025-05-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/tdevworks/CVE-2020-0796-SMBGhost-Exploit-Demo"
                },
                {
                    "repository": "PoC-in-GitHub · maqeel-git/CVE-2020-0796",
                    "author": "maqeel-git",
                    "first_seen": "2025-06-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/maqeel-git/CVE-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · esmwaSpyware/DoS-PoC-for-CVE-2020-0796-SMBGhost-",
                    "author": "esmwaSpyware",
                    "first_seen": "2025-08-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/esmwaSpyware/DoS-PoC-for-CVE-2020-0796-SMBGhost-"
                },
                {
                    "repository": "PoC-in-GitHub · Jagadeesh7532/-CVE-2020-0796-SMBGhost-Windows-10-SMBv3-Remote-Code-Execution-Vulnerability",
                    "author": "Jagadeesh7532",
                    "first_seen": "2025-09-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2020-0796 (SMBGhost) is a critical RCE vulnerability in Windows 10 SMBv3 protocol. It allows attackers to execute code remotely via crafted SMB packets, making it wormable. Affects Windows 10 v1903/v1909 and Server 2019. Exploit targets srv2.sys via buffer overflow",
                    "summary": "CVE-2020-0796 (SMBGhost) is a critical RCE vulnerability in Windows 10 SMBv3 protocol. It allows attackers to execute code remotely via crafted SMB packets, making it wormable. Affects Windows 10 v1903/v1909 and Server 2019. Exploit targets srv2.sys via buffer overflow",
                    "url": "https://github.com/Jagadeesh7532/-CVE-2020-0796-SMBGhost-Windows-10-SMBv3-Remote-Code-Execution-Vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · nyambiblaise/Microsoft-Windows-SMBGhost-Vulnerability-Checker---CVE-2020-0796---SMBv3-RCE",
                    "author": "nyambiblaise",
                    "first_seen": "2025-12-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/nyambiblaise/Microsoft-Windows-SMBGhost-Vulnerability-Checker---CVE-2020-0796---SMBv3-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · thai1012/cve-2020-0796",
                    "author": "thai1012",
                    "first_seen": "2026-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2020-0796 repository",
                    "summary": "",
                    "url": "https://github.com/thai1012/cve-2020-0796"
                },
                {
                    "repository": "PoC-in-GitHub · Justjeff211/conti-ransomware-writeup",
                    "author": "Justjeff211",
                    "first_seen": "2026-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows Security, Sysmon, and IIS log sources to reconstruct the complete attack chain. Identified three exploited CVEs (CVE-2020-0796, CVE-2018-13374, CVE-2018-13379), located a trojanised cmd.exe",
                    "summary": "Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows Security, Sysmon, and IIS log sources to reconstruct the complete attack chain. Identified three exploited CVEs (CVE-2020-0796, CVE-2018-13374, CVE-2018-13379), located a trojanised cmd.exe",
                    "url": "https://github.com/Justjeff211/conti-ransomware-writeup"
                },
                {
                    "repository": "PoC-in-GitHub · p4ncontomat3/smbghost",
                    "author": "p4ncontomat3",
                    "first_seen": "2026-06-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "scanner for CVE-2020-0796",
                    "summary": "scanner for CVE-2020-0796",
                    "url": "https://github.com/p4ncontomat3/smbghost"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-06T08:25:49+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2020-1206 exploit",
                    "summary": "Exploit for CVE-2020-0796 and CVE-2020-1206. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DATNTSEC-CVE-2020-1206"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T06:34:23+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2020-0796 exploit",
                    "summary": "Exploit for CVE-2020-0796. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WSFENGFAN-CVE-2020-0796"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/48216",
                "https://www.exploit-db.com/exploits/48267",
                "https://www.exploit-db.com/exploits/48537",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALMORABEA-SMBGHOST-WORKAROUNDAPPLIER",
                "https://kitploit.com/ru/tools/github/almorabea/smbghost-workaroundapplier/",
                "https://github.com/k8gege/PyLadon",
                "https://github.com/0x25bit/CVE-2020-0796-PoC",
                "https://github.com/technion/DisableSMBCompression",
                "https://github.com/T13nn3s/CVE-2020-0796",
                "https://github.com/ly4k/SMBGhost",
                "https://github.com/joaozietolie/CVE-2020-0796-Checker",
                "https://github.com/ButrintKomoni/cve-2020-0796",
                "https://github.com/dickens88/cve-2020-0796-scanner",
                "https://github.com/kn6869610/CVE-2020-0796",
                "https://github.com/awareseven/eternalghosttest",
                "https://github.com/xax007/CVE-2020-0796-Scanner",
                "https://github.com/Dhoomralochana/Scanners-for-CVE-2020-0796-Testing",
                "https://github.com/UraSecTeam/smbee",
                "https://github.com/netscylla/SMBGhost",
                "https://github.com/eerykitty/CVE-2020-0796-PoC",
                "https://github.com/wneessen/SMBCompScan",
                "https://github.com/ioncodes/SMBGhost",
                "https://github.com/laolisafe/CVE-2020-0796",
                "https://github.com/gabimarti/SMBScanner",
                "https://github.com/Almorabea/SMBGhost-WorkaroundApplier",
                "https://github.com/vysecurity/CVE-2020-0796",
                "https://github.com/BinaryShadow94/SMBv3.1.1-scan---CVE-2020-0796",
                "https://github.com/w1ld3r/SMBGhost_Scanner",
                "https://github.com/wsfengfan/CVE-2020-0796",
                "https://github.com/GuoKerS/aioScan_CVE-2020-0796",
                "https://github.com/jiansiting/CVE-2020-0796-Scanner",
                "https://github.com/maxpl0it/Unauthenticated-CVE-2020-0796-PoC",
                "https://github.com/ran-sama/CVE-2020-0796",
                "https://github.com/sujitawake/smbghost",
                "https://github.com/julixsalas/CVE-2020-0796",
                "https://github.com/cory-zajicek/CVE-2020-0796-DoS",
                "https://github.com/tripledd/cve-2020-0796-vuln",
                "https://github.com/danigargu/CVE-2020-0796",
                "https://github.com/jamf/CVE-2020-0796-LPE-POC",
                "https://github.com/TinToSer/CVE-2020-0796-LPE",
                "https://github.com/f1tz/CVE-2020-0796-LPE-EXP",
                "https://github.com/tango-j/CVE-2020-0796",
                "https://github.com/jiansiting/CVE-2020-0796",
                "https://github.com/eastmountyxz/CVE-2020-0796-SMB",
                "https://github.com/LabDookhtegan/CVE-2020-0796-EXP",
                "https://github.com/Rvn0xsy/CVE_2020_0796_CNA",
                "https://github.com/0xeb-bp/cve-2020-0796",
                "https://github.com/intelliroot-tech/cve-2020-0796-Scanner",
                "https://github.com/jamf/CVE-2020-0796-RCE-POC",
                "https://github.com/thelostworldFree/CVE-2020-0796",
                "https://github.com/bacth0san96/SMBGhostScanner",
                "https://github.com/halsten/CVE-2020-0796",
                "https://github.com/ysyyrps123/CVE-2020-0796-exp",
                "https://github.com/exp-sky/CVE-2020-0796",
                "https://github.com/Barriuso/SMBGhost_AutomateExploitation",
                "https://github.com/1060275195/SMBGhost",
                "https://github.com/Almorabea/SMBGhost-LPE-Metasploit-Module",
                "https://github.com/jamf/SMBGhost-SMBleed-scanner",
                "https://github.com/rsmudge/CVE-2020-0796-BOF",
                "https://github.com/codewithpradhan/SMBGhost-CVE-2020-0796-",
                "https://github.com/AaronCaiii/CVE-2020-0796-POC",
                "https://github.com/datntsec/CVE-2020-0796",
                "https://github.com/MasterSploit/LPE---CVE-2020-0796",
                "https://github.com/1stPeak/CVE-2020-0796-Scanner",
                "https://github.com/Anonimo501/SMBGhost_CVE-2020-0796_checker",
                "https://github.com/Opensitoo/cve-2020-0796",
                "https://github.com/orangmuda/CVE-2020-0796",
                "https://github.com/Murasame-nc/CVE-2020-0796-LPE-POC",
                "https://github.com/F6JO/CVE-2020-0796-Batch-scanning",
                "https://github.com/lisinan988/CVE-2020-0796-exp",
                "https://github.com/vsai94/ECE9069_SMBGhost_Exploit_CVE-2020-0796-",
                "https://github.com/arzuozkan/CVE-2020-0796",
                "https://github.com/SEHandler/CVE-2020-0796",
                "https://github.com/krizzz07/CVE-2020-0796",
                "https://github.com/OldDream666/cve-2020-0796",
                "https://github.com/dungnm24/CVE-2020-0796",
                "https://github.com/hungdnvp/POC-CVE-2020-0796",
                "https://github.com/AdamSonov/smbGhostCVE-2020-0796",
                "https://github.com/z3ena/Exploiting-and-Mitigating-CVE-2020-0796-SMBGhost-and-Print-Spooler-Vulnerabilities",
                "https://github.com/bsec404/CVE-2020-0796",
                "https://github.com/monjheta/CVE-2020-0796",
                "https://github.com/cybermads/CVE-2020-0796",
                "https://github.com/DannyRavi/nmap-scripts",
                "https://github.com/tdevworks/CVE-2020-0796-SMBGhost-Exploit-Demo",
                "https://github.com/maqeel-git/CVE-2020-0796",
                "https://github.com/esmwaSpyware/DoS-PoC-for-CVE-2020-0796-SMBGhost-",
                "https://github.com/Jagadeesh7532/-CVE-2020-0796-SMBGhost-Windows-10-SMBv3-Remote-Code-Execution-Vulnerability",
                "https://github.com/nyambiblaise/Microsoft-Windows-SMBGhost-Vulnerability-Checker---CVE-2020-0796---SMBv3-RCE",
                "https://github.com/thai1012/cve-2020-0796",
                "https://github.com/Justjeff211/conti-ransomware-writeup",
                "https://github.com/p4ncontomat3/smbghost",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DATNTSEC-CVE-2020-1206",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WSFENGFAN-CVE-2020-0796"
            ],
            "timeline": [
                {
                    "at": "2026-08-24T14:34:43Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2020-0668",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2023-29343 CVE-2020-0668 CVE-2023-28222 CVE-2023-29343",
            "summary": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
            "updated_at": "2026-08-25T18:44:18Z",
            "published_at": "2026-08-25T18:44:18Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 67,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2023-29343 CVE-2020-0668 CVE-2023-28222 CVE-2023-29343",
                    "summary": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
                    "what_happened": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343",
                        "https://kitploit.com/ar/tools/github/wh04m1001/cve-2023-29343/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T20:44:18",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343"
                },
                {
                    "title": "Exploit for CVE-2023-29343 CVE-2020-0668 CVE-2023-28222 CVE-2023-29343",
                    "summary": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
                    "what_happened": "Arbitrary file write in Sysmon 14.14 via Windows service tracing and RasMan abuse.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343",
                        "https://kitploit.com/ar/tools/github/wh04m1001/cve-2023-29343/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-08-25T20:44:18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/wh04m1001/cve-2023-29343/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343",
                "https://kitploit.com/ar/tools/github/wh04m1001/cve-2023-29343/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T18:44:18Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WH04M1001-CVE-2023-29343"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2020-0618",
            "vendor": "Microsoft",
            "product": "SQL Server",
            "title": "Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability",
            "summary": "Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.",
            "updated_at": "2026-09-11T18:32:59Z",
            "published_at": "2026-09-11T18:32:59Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 76,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 48816",
                    "author": "West Shepherd",
                    "first_seen": "2020-09-17",
                    "confidence": "High",
                    "title": "Microsoft SQL Server Reporting Services 2016 - Remote Code Execution",
                    "summary": "Microsoft SQL Server Reporting Services 2016 - Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/48816",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-11T18:32:59+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2020-0618 exploit",
                    "summary": "Exploit for CVE-2020-0618. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EUPHRAT1CA-CVE-2020-0618"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/48816",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EUPHRAT1CA-CVE-2020-0618"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T18:32:59Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-09-18",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2020-0609",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)",
            "summary": "Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)",
            "updated_at": "2026-09-06T22:00:00Z",
            "published_at": "2026-09-06T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 329,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 47963",
                    "author": "ollypwn",
                    "first_seen": "2020-01-23",
                    "confidence": "High",
                    "title": "Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)",
                    "summary": "Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)",
                    "url": "https://www.exploit-db.com/exploits/47963",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 47964",
                    "author": "ollypwn",
                    "first_seen": "2020-01-23",
                    "confidence": "High",
                    "title": "Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)",
                    "summary": "Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC)",
                    "url": "https://www.exploit-db.com/exploits/47964",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · ruppde/rdg_scanner_cve-2020-0609",
                    "author": "ruppde",
                    "first_seen": "2020-01-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 39,
                    "title": "Scanning for Remote Desktop Gateways (Potentially unpatched CVE-2020-0609 and CVE-2020-0610)",
                    "summary": "Scanning for Remote Desktop Gateways (Potentially unpatched CVE-2020-0609 and CVE-2020-0610)",
                    "url": "https://github.com/ruppde/rdg_scanner_cve-2020-0609"
                },
                {
                    "repository": "PoC-in-GitHub · ly4k/BlueGate",
                    "author": "ly4k",
                    "first_seen": "2020-01-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 249,
                    "title": "PoC (DoS + scanner) for CVE-2020-0609 & CVE-2020-0610 - RD Gateway RCE",
                    "summary": "PoC (DoS + scanner) for CVE-2020-0609 & CVE-2020-0610 - RD Gateway RCE",
                    "url": "https://github.com/ly4k/BlueGate"
                },
                {
                    "repository": "PoC-in-GitHub · MalwareTech/RDGScanner",
                    "author": "MalwareTech",
                    "first_seen": "2020-01-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 68,
                    "title": "A proof-of-concept scanner to check an RDG Gateway Server for vulnerabilities CVE-2020-0609 & CVE-2020-0610.",
                    "summary": "A proof-of-concept scanner to check an RDG Gateway Server for vulnerabilities CVE-2020-0609 & CVE-2020-0610.",
                    "url": "https://github.com/MalwareTech/RDGScanner"
                },
                {
                    "repository": "PoC-in-GitHub · Archi73ct/CVE-2020-0609",
                    "author": "Archi73ct",
                    "first_seen": "2020-01-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2020-0609 repository",
                    "summary": "",
                    "url": "https://github.com/Archi73ct/CVE-2020-0609"
                },
                {
                    "repository": "PoC-in-GitHub · ioncodes/BlueGate",
                    "author": "ioncodes",
                    "first_seen": "2020-01-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 78,
                    "title": "PoC for the Remote Desktop Gateway vulnerability - CVE-2020-0609 & CVE-2020-0610",
                    "summary": "PoC for the Remote Desktop Gateway vulnerability - CVE-2020-0609 & CVE-2020-0610",
                    "url": "https://github.com/ioncodes/BlueGate"
                },
                {
                    "repository": "PoC-in-GitHub · Bhanunamikaze/BlueGate-CVE-2020-0609",
                    "author": "Bhanunamikaze",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "BlueGate Exploit validator - RD Gateway validator for CVE-2020-0609 and CVE-2020-0610 (BlueGate) using OpenSSL DTLS over UDP/3391.",
                    "summary": "BlueGate Exploit validator - RD Gateway validator for CVE-2020-0609 and CVE-2020-0610 (BlueGate) using OpenSSL DTLS over UDP/3391.",
                    "url": "https://github.com/Bhanunamikaze/BlueGate-CVE-2020-0609"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/47963",
                "https://www.exploit-db.com/exploits/47964",
                "https://github.com/ruppde/rdg_scanner_cve-2020-0609",
                "https://github.com/ly4k/BlueGate",
                "https://github.com/MalwareTech/RDGScanner",
                "https://github.com/Archi73ct/CVE-2020-0609",
                "https://github.com/ioncodes/BlueGate",
                "https://github.com/Bhanunamikaze/BlueGate-CVE-2020-0609"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/47963"
                }
            ]
        },
        {
            "id": "CVE-2020-0416",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "packages_apps_settings_AOSP10_r33_CVE-2020-0416 exploit",
            "summary": "Exploit for CVE-2020-0416. CVSS 9.3.",
            "updated_at": "2026-09-05T12:43:05Z",
            "published_at": "2026-09-05T12:43:05Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 87,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "CVE-2020-0416 in AOSP 10 Settings app (packages_apps_settings), revision r33.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for packages_apps_settings_AOSP10_r33_CVE-2020-0416",
                    "summary": "CVE-2020-0416 in AOSP 10 Settings app (packages_apps_settings), revision r33.",
                    "what_happened": "CVE-2020-0416 in AOSP 10 Settings app (packages_apps_settings), revision r33.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAIKUSAF-PACKAGES_APPS_SETTINGS_AOSP10_R33_CVE-2020-0416",
                        "https://kitploit.com/hi/tools/github/shaikusaf/packages_apps_settings_aosp10_r33_cve-2020-0416/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T12:17:18",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAIKUSAF-PACKAGES_APPS_SETTINGS_AOSP10_R33_CVE-2020-0416"
                },
                {
                    "title": "Exploit for packages_apps_settings_AOSP10_r33_CVE-2020-0416",
                    "summary": "CVE-2020-0416 in AOSP 10 Settings app (packages_apps_settings), revision r33.",
                    "what_happened": "CVE-2020-0416 in AOSP 10 Settings app (packages_apps_settings), revision r33.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAIKUSAF-PACKAGES_APPS_SETTINGS_AOSP10_R33_CVE-2020-0416",
                        "https://kitploit.com/hi/tools/github/shaikusaf/packages_apps_settings_aosp10_r33_cve-2020-0416/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-03T12:17:18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/shaikusaf/packages_apps_settings_aosp10_r33_cve-2020-0416/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAIKUSAF-PACKAGES_APPS_SETTINGS_AOSP10_R33_CVE-2020-0416",
                "https://kitploit.com/hi/tools/github/shaikusaf/packages_apps_settings_aosp10_r33_cve-2020-0416/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:43:05Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAIKUSAF-PACKAGES_APPS_SETTINGS_AOSP10_R33_CVE-2020-0416"
                }
            ]
        },
        {
            "id": "CVE-2020-0394",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "packages_apps_settings_AOSP10_r33_CVE-2020-0394 exploit",
            "summary": "Exploit for CVE-2020-0394. CVSS 7.8.",
            "updated_at": "2026-09-05T12:44:54Z",
            "published_at": "2026-09-05T12:44:54Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 89,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "CVE-2020-0394 in Android 10 Settings (AOSP10) packages_apps_settings.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for packages_apps_settings_AOSP10_r33_CVE-2020-0394",
                    "summary": "CVE-2020-0394 in Android 10 Settings (AOSP10) packages_apps_settings.",
                    "what_happened": "CVE-2020-0394 in Android 10 Settings (AOSP10) packages_apps_settings.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAIKUSAF-PACKAGES_APPS_SETTINGS_AOSP10_R33_CVE-2020-0394",
                        "https://kitploit.com/ar/tools/github/shaikusaf/packages_apps_settings_aosp10_r33_cve-2020-0394/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T16:23:03",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAIKUSAF-PACKAGES_APPS_SETTINGS_AOSP10_R33_CVE-2020-0394"
                },
                {
                    "title": "Exploit for packages_apps_settings_AOSP10_r33_CVE-2020-0394",
                    "summary": "CVE-2020-0394 in Android 10 Settings (AOSP10) packages_apps_settings.",
                    "what_happened": "CVE-2020-0394 in Android 10 Settings (AOSP10) packages_apps_settings.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAIKUSAF-PACKAGES_APPS_SETTINGS_AOSP10_R33_CVE-2020-0394",
                        "https://kitploit.com/ar/tools/github/shaikusaf/packages_apps_settings_aosp10_r33_cve-2020-0394/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-03T16:23:03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/shaikusaf/packages_apps_settings_aosp10_r33_cve-2020-0394/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAIKUSAF-PACKAGES_APPS_SETTINGS_AOSP10_R33_CVE-2020-0394",
                "https://kitploit.com/ar/tools/github/shaikusaf/packages_apps_settings_aosp10_r33_cve-2020-0394/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:44:54Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SHAIKUSAF-PACKAGES_APPS_SETTINGS_AOSP10_R33_CVE-2020-0394"
                }
            ]
        },
        {
            "id": "CVE-2020-0069",
            "vendor": "MediaTek",
            "product": "Multiple Chipsets",
            "title": "Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability",
            "summary": "Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain \"AbstractEmu.\"",
            "updated_at": "2026-09-11T19:05:23Z",
            "published_at": "2026-09-11T19:05:23Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 55,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain \"AbstractEmu.\"",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Use After Free in Arm Bifrost_Gpu_Kernel_Driver CVE-2022-38181 CVE-2026-43499",
                    "summary": "Use After Free in Arm Bifrost kbase JIT driver (CVE-2022-38181) enabling kernel root exploit.",
                    "what_happened": "Use After Free in Arm Bifrost kbase JIT driver (CVE-2022-38181) enabling kernel root exploit.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=B7F4C122-DCF4-5F88-B125-FCF4479408A9",
                        "https://github.com/artur9010/amazon-mustang-hack"
                    ],
                    "repository": "Sploitus",
                    "author": "artur9010",
                    "first_seen": "2026-09-11T21:05:23",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=B7F4C122-DCF4-5F88-B125-FCF4479408A9"
                },
                {
                    "title": "Exploit for Use After Free in Arm Bifrost_Gpu_Kernel_Driver CVE-2022-38181 CVE-2026-43499",
                    "summary": "Use After Free in Arm Bifrost kbase JIT driver (CVE-2022-38181) enabling kernel root exploit.",
                    "what_happened": "Use After Free in Arm Bifrost kbase JIT driver (CVE-2022-38181) enabling kernel root exploit.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=B7F4C122-DCF4-5F88-B125-FCF4479408A9",
                        "https://github.com/artur9010/amazon-mustang-hack"
                    ],
                    "repository": "artur9010/amazon-mustang-hack",
                    "author": "artur9010",
                    "first_seen": "2026-09-11T21:05:23",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/artur9010/amazon-mustang-hack"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=B7F4C122-DCF4-5F88-B125-FCF4479408A9",
                "https://github.com/artur9010/amazon-mustang-hack"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T19:05:23Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2019-20933",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2018-0114 CVE-2019-20933 CVE-2020-28042 CVE-2020-28637 C",
            "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
            "updated_at": "2026-09-09T04:48:12Z",
            "published_at": "2026-09-09T04:48:12Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 65,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2020-28042 CVE-2020-28637 CVE-2022-21449",
                    "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                        "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-10T07:59:46",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299"
                },
                {
                    "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2020-28042 CVE-2020-28637 CVE-2022-21449",
                    "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                        "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-10T07:59:46",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T04:48:12Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2019-19871",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for ioc-scanner-CVE-2019-19781",
            "summary": "IoC scanner for detecting Citrix ADC compromises related to CVE-2019-19781.",
            "updated_at": "2026-08-26T22:53:08Z",
            "published_at": "2026-08-26T22:53:08Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 65,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "IoC scanner for detecting Citrix ADC compromises related to CVE-2019-19781.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for ioc-scanner-CVE-2019-19781",
                    "summary": "IoC scanner for detecting Citrix ADC compromises related to CVE-2019-19781.",
                    "what_happened": "IoC scanner for detecting Citrix ADC compromises related to CVE-2019-19781.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CITRIX-IOC-SCANNER-CVE-2019-19781",
                        "https://kitploit.com/ru/tools/github/citrix/ioc-scanner-cve-2019-19781/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-27T00:53:08",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CITRIX-IOC-SCANNER-CVE-2019-19781"
                },
                {
                    "title": "Exploit for ioc-scanner-CVE-2019-19781",
                    "summary": "IoC scanner for detecting Citrix ADC compromises related to CVE-2019-19781.",
                    "what_happened": "IoC scanner for detecting Citrix ADC compromises related to CVE-2019-19781.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CITRIX-IOC-SCANNER-CVE-2019-19781",
                        "https://kitploit.com/ru/tools/github/citrix/ioc-scanner-cve-2019-19781/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-27T00:53:08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/citrix/ioc-scanner-cve-2019-19781/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CITRIX-IOC-SCANNER-CVE-2019-19781",
                "https://kitploit.com/ru/tools/github/citrix/ioc-scanner-cve-2019-19781/"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T22:53:08Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CITRIX-IOC-SCANNER-CVE-2019-19781"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2019-19781",
            "vendor": "Citrix",
            "product": "Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance",
            "title": "Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability",
            "summary": "Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.",
            "updated_at": "2026-08-26T22:53:08Z",
            "published_at": "2026-08-26T22:53:08Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 286,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 47930",
                    "author": "Dhiraj Mishra",
                    "first_seen": "2020-01-16",
                    "confidence": "High",
                    "title": "Citrix Application Delivery Controller (ADC) and Gateway 13.0 - Path Traversal",
                    "summary": "Citrix Application Delivery Controller (ADC) and Gateway 13.0 - Path Traversal",
                    "url": "https://www.exploit-db.com/exploits/47930",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 47901",
                    "author": "Project Zero India",
                    "first_seen": "2020-01-11",
                    "confidence": "High",
                    "title": "Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution (PoC)",
                    "summary": "Citrix Application Delivery Controller and Citrix Gateway - Remote Code Execution (PoC)",
                    "url": "https://www.exploit-db.com/exploits/47901",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 47913",
                    "author": "mekhalleh",
                    "first_seen": "2020-01-13",
                    "confidence": "High",
                    "title": "Citrix Application Delivery Controller and Gateway 10.5 - Remote Code Execution (Metasploit)",
                    "summary": "Citrix Application Delivery Controller and Gateway 10.5 - Remote Code Execution (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/47913",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for ioc-scanner-CVE-2019-19781",
                    "summary": "IoC scanner for detecting Citrix ADC compromises related to CVE-2019-19781.",
                    "what_happened": "IoC scanner for detecting Citrix ADC compromises related to CVE-2019-19781.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CITRIX-IOC-SCANNER-CVE-2019-19781",
                        "https://kitploit.com/ru/tools/github/citrix/ioc-scanner-cve-2019-19781/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-27T00:53:08",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CITRIX-IOC-SCANNER-CVE-2019-19781"
                },
                {
                    "title": "Exploit for ioc-scanner-CVE-2019-19781",
                    "summary": "IoC scanner for detecting Citrix ADC compromises related to CVE-2019-19781.",
                    "what_happened": "IoC scanner for detecting Citrix ADC compromises related to CVE-2019-19781.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CITRIX-IOC-SCANNER-CVE-2019-19781",
                        "https://kitploit.com/ru/tools/github/citrix/ioc-scanner-cve-2019-19781/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-27T00:53:08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/citrix/ioc-scanner-cve-2019-19781/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/47930",
                "https://www.exploit-db.com/exploits/47901",
                "https://www.exploit-db.com/exploits/47913",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CITRIX-IOC-SCANNER-CVE-2019-19781",
                "https://kitploit.com/ru/tools/github/citrix/ioc-scanner-cve-2019-19781/"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T22:53:08Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2019-19363",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Ricoh Driver - Privilege Escalation (Metasploit)",
            "summary": "Ricoh Driver - Privilege Escalation (Metasploit)",
            "updated_at": "2026-09-04T19:28:37Z",
            "published_at": "2026-09-04T19:28:37Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 173,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 48036",
                    "author": "Metasploit",
                    "first_seen": "2020-02-10",
                    "confidence": "High",
                    "title": "Ricoh Driver - Privilege Escalation (Metasploit)",
                    "summary": "Ricoh Driver - Privilege Escalation (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/48036",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 47962",
                    "author": "pentagrid",
                    "first_seen": "2020-01-22",
                    "confidence": "High",
                    "title": "Ricoh Printer Drivers - Local Privilege Escalation",
                    "summary": "Ricoh Printer Drivers - Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/47962",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for concealed_position CVE-2019-19363 CVE-2020-1300 CVE-2021-34481 CVE-2021-35449 CVE-2021-38085",
                    "summary": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                        "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T21:28:37",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION"
                },
                {
                    "title": "Exploit for concealed_position CVE-2019-19363 CVE-2020-1300 CVE-2021-34481 CVE-2021-35449 CVE-2021-38085",
                    "summary": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "what_happened": "Concealed Position: local privilege escalation on Windows via vulnerable printer drivers to SYSTEM.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                        "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-04T21:28:37",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/48036",
                "https://www.exploit-db.com/exploits/47962",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JACOB-BAINES-CONCEALED_POSITION",
                "https://kitploit.com/ar/tools/github/jacob-baines/concealed_position/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T19:28:37Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/48036"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2019-18935",
            "vendor": "Progress",
            "product": "Telerik UI for ASP.NET AJAX",
            "title": "Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
            "summary": "Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.",
            "updated_at": "2026-09-14T18:32:43Z",
            "published_at": "2026-09-14T18:32:43Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 35,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 47793",
                    "author": "Bishop Fox",
                    "first_seen": "2019-12-18",
                    "confidence": "High",
                    "title": "Telerik UI - Remote Code Execution via Insecure Deserialization",
                    "summary": "Telerik UI - Remote Code Execution via Insecure Deserialization",
                    "url": "https://www.exploit-db.com/exploits/47793",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for Telerik_CVE-2019-18935",
                    "summary": "CVE-2019-18935 RCE in Telerik UI via insecure deserialization in RadAsyncUpload.",
                    "what_happened": "CVE-2019-18935 RCE in Telerik UI via insecure deserialization in RadAsyncUpload.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BECREVEX-TELERIK_CVE-2019-18935",
                        "https://kitploit.com/ru/tools/github/becrevex/telerik_cve-2019-18935/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T00:35:28",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BECREVEX-TELERIK_CVE-2019-18935"
                },
                {
                    "title": "Exploit for Telerik_CVE-2019-18935",
                    "summary": "CVE-2019-18935 RCE in Telerik UI via insecure deserialization in RadAsyncUpload.",
                    "what_happened": "CVE-2019-18935 RCE in Telerik UI via insecure deserialization in RadAsyncUpload.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BECREVEX-TELERIK_CVE-2019-18935",
                        "https://kitploit.com/ru/tools/github/becrevex/telerik_cve-2019-18935/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-03T00:35:28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/becrevex/telerik_cve-2019-18935/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/47793",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BECREVEX-TELERIK_CVE-2019-18935",
                "https://kitploit.com/ru/tools/github/becrevex/telerik_cve-2019-18935/"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T18:32:43Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2019-17638",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2019-17638-Jetty exploit",
            "summary": "Exploit for CVE-2019-17638. CVSS 9.4.",
            "updated_at": "2026-09-05T12:43:03Z",
            "published_at": "2026-09-05T12:43:03Z",
            "cvss": 9.4,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 84,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Vulnerability in Jetty, a Java HTTP server and servlet container from Eclipse Foundation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2019-17638-Jetty",
                    "summary": "Vulnerability in Jetty, a Java HTTP server and servlet container from Eclipse Foundation.",
                    "what_happened": "Vulnerability in Jetty, a Java HTTP server and servlet container from Eclipse Foundation.",
                    "cvss": 9.4,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FORSE01-CVE-2019-17638-JETTY",
                        "https://kitploit.com/hi/tools/github/forse01/cve-2019-17638-jetty/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T07:38:48",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FORSE01-CVE-2019-17638-JETTY"
                },
                {
                    "title": "Exploit for CVE-2019-17638-Jetty",
                    "summary": "Vulnerability in Jetty, a Java HTTP server and servlet container from Eclipse Foundation.",
                    "what_happened": "Vulnerability in Jetty, a Java HTTP server and servlet container from Eclipse Foundation.",
                    "cvss": 9.4,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FORSE01-CVE-2019-17638-JETTY",
                        "https://kitploit.com/hi/tools/github/forse01/cve-2019-17638-jetty/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-03T07:38:48",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/forse01/cve-2019-17638-jetty/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FORSE01-CVE-2019-17638-JETTY",
                "https://kitploit.com/hi/tools/github/forse01/cve-2019-17638-jetty/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:43:03Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FORSE01-CVE-2019-17638-JETTY"
                }
            ]
        },
        {
            "id": "CVE-2019-16097",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2019-16097 exploit",
            "summary": "Exploit for CVE-2019-16097. CVSS 6.5.",
            "updated_at": "2026-09-07T19:19:35Z",
            "published_at": "2026-09-07T19:19:35Z",
            "cvss": 6.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 34,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-07T19:19:35+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2019-16097 exploit",
                    "summary": "Exploit for CVE-2019-16097. CVSS 6.5.",
                    "cvss": 6.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IANXTIANXT-CVE-2019-16097"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IANXTIANXT-CVE-2019-16097"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:19:35Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IANXTIANXT-CVE-2019-16097"
                }
            ]
        },
        {
            "id": "CVE-2019-13292",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "WebERP 4.15 - SQL injection",
            "summary": "WebERP 4.15 - SQL injection",
            "updated_at": "2026-09-15T08:34:40Z",
            "published_at": "2026-09-15T08:34:40Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 18,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 47013",
                    "author": "Semen Alexandrovich Lyhin",
                    "first_seen": "2019-06-20",
                    "confidence": "High",
                    "title": "WebERP 4.15 - SQL injection",
                    "summary": "WebERP 4.15 - SQL injection",
                    "url": "https://www.exploit-db.com/exploits/47013",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-15T08:34:40+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2019-13292-WebERP_4.15 exploit",
                    "summary": "Exploit for CVE-2019-13292. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEALELUYAH-CVE-2019-13292-WEBERP_4.15"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/47013",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEALELUYAH-CVE-2019-13292-WEBERP_4.15"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:34:40Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/47013"
                }
            ]
        },
        {
            "id": "CVE-2019-13272",
            "vendor": "Linux",
            "product": "Kernel",
            "title": "Linux Kernel Improper Privilege Management Vulnerability",
            "summary": "Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.",
            "updated_at": "2026-09-06T20:33:20Z",
            "published_at": "2026-09-06T20:33:20Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 410,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 47133",
                    "author": "Google Security Research",
                    "first_seen": "2019-07-17",
                    "confidence": "High",
                    "title": "Linux - Broken Permission and Object Lifetime Handling for PTRACE_TRACEME",
                    "summary": "Linux - Broken Permission and Object Lifetime Handling for PTRACE_TRACEME",
                    "url": "https://www.exploit-db.com/exploits/47133",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 47163",
                    "author": "bcoles",
                    "first_seen": "2019-07-24",
                    "confidence": "High",
                    "title": "Linux Kernel 4.10 < 5.1.17 - 'PTRACE_TRACEME' pkexec Local Privilege Escalation",
                    "summary": "Linux Kernel 4.10 < 5.1.17 - 'PTRACE_TRACEME' pkexec Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/47163",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 50541",
                    "author": "Ujas Dhami",
                    "first_seen": "2021-11-23",
                    "confidence": "High",
                    "title": "Linux Kernel 5.1.x - 'PTRACE_TRACEME' pkexec Local Privilege Escalation (2)",
                    "summary": "Linux Kernel 5.1.x - 'PTRACE_TRACEME' pkexec Local Privilege Escalation (2)",
                    "url": "https://www.exploit-db.com/exploits/50541",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 47543",
                    "author": "Metasploit",
                    "first_seen": "2019-10-24",
                    "confidence": "High",
                    "title": "Linux Polkit - pkexec helper PTRACE_TRACEME local root (Metasploit)",
                    "summary": "Linux Polkit - pkexec helper PTRACE_TRACEME local root (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/47543",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2019-13272-Local-Privilege-Escalation",
                    "summary": "Local privilege escalation exploit tool for CVE-2019-13272.",
                    "what_happened": "Local privilege escalation exploit tool for CVE-2019-13272.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JANA30116-CVE-2019-13272-LOCAL-PRIVILEGE-ESCALATION",
                        "https://kitploit.com/ja/tools/github/jana30116/cve-2019-13272-local-privilege-escalation/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-02T21:43:04",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JANA30116-CVE-2019-13272-LOCAL-PRIVILEGE-ESCALATION"
                },
                {
                    "title": "Exploit for CVE-2019-13272-Local-Privilege-Escalation",
                    "summary": "Local privilege escalation exploit tool for CVE-2019-13272.",
                    "what_happened": "Local privilege escalation exploit tool for CVE-2019-13272.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JANA30116-CVE-2019-13272-LOCAL-PRIVILEGE-ESCALATION",
                        "https://kitploit.com/ja/tools/github/jana30116/cve-2019-13272-local-privilege-escalation/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-02T21:43:04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/jana30116/cve-2019-13272-local-privilege-escalation/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/47133",
                "https://www.exploit-db.com/exploits/47163",
                "https://www.exploit-db.com/exploits/50541",
                "https://www.exploit-db.com/exploits/47543",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JANA30116-CVE-2019-13272-LOCAL-PRIVILEGE-ESCALATION",
                "https://kitploit.com/ja/tools/github/jana30116/cve-2019-13272-local-privilege-escalation/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T20:33:20Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2019-11581",
            "vendor": "Atlassian",
            "product": "Jira Server and Data Center",
            "title": "Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
            "summary": "Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.",
            "updated_at": "2026-09-08T14:43:51Z",
            "published_at": "2026-09-08T14:43:51Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 109,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2019-11581",
                    "summary": "Template injection in Atlassian JIRA enabling remote code execution via i18n class.",
                    "what_happened": "Template injection in Atlassian JIRA enabling remote code execution via i18n class.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2019-11581",
                        "https://kitploit.com/ja/tools/github/jas502n/cve-2019-11581/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T17:00:55",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2019-11581"
                },
                {
                    "title": "Exploit for CVE-2019-11581",
                    "summary": "Template injection in Atlassian JIRA enabling remote code execution via i18n class.",
                    "what_happened": "Template injection in Atlassian JIRA enabling remote code execution via i18n class.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2019-11581",
                        "https://kitploit.com/ja/tools/github/jas502n/cve-2019-11581/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-04T17:00:55",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/jas502n/cve-2019-11581/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2019-11581",
                "https://kitploit.com/ja/tools/github/jas502n/cve-2019-11581/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T14:43:51Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-07",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2019-11510",
            "vendor": "Ivanti",
            "product": "Pulse Connect Secure",
            "title": "Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability",
            "summary": "Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.",
            "updated_at": "2026-09-15T10:57:14Z",
            "published_at": "2026-09-15T10:57:14Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 31,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 47297",
                    "author": "Alyssa Herrera",
                    "first_seen": "2019-08-21",
                    "confidence": "High",
                    "title": "Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure (Metasploit)",
                    "summary": "Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/47297",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2019-11510",
                    "summary": "Missing README file in the tools repository.",
                    "what_happened": "Missing README file in the tools repository.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JASON3E7-CVE-2019-11510",
                        "https://kitploit.com/ru/tools/github/jason3e7/cve-2019-11510/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T22:11:31",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JASON3E7-CVE-2019-11510"
                },
                {
                    "title": "Exploit for CVE-2019-11510",
                    "summary": "Missing README file in the tools repository.",
                    "what_happened": "Missing README file in the tools repository.",
                    "cvss": 10,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JASON3E7-CVE-2019-11510",
                        "https://kitploit.com/ru/tools/github/jason3e7/cve-2019-11510/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-25T22:11:31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/jason3e7/cve-2019-11510/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/47297",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JASON3E7-CVE-2019-11510",
                "https://kitploit.com/ru/tools/github/jason3e7/cve-2019-11510/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T10:57:14Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2019-11043",
            "vendor": "PHP",
            "product": "FastCGI Process Manager (FPM)",
            "title": "PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability",
            "summary": "In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.",
            "updated_at": "2026-09-08T14:40:45Z",
            "published_at": "2026-09-08T14:40:45Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 981,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 48182",
                    "author": "Metasploit",
                    "first_seen": "2020-03-09",
                    "confidence": "High",
                    "title": "PHP-FPM - Underflow Remote Code Execution (Metasploit)",
                    "summary": "PHP-FPM - Underflow Remote Code Execution (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/48182",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 47553",
                    "author": "Emil Lerner",
                    "first_seen": "2019-10-28",
                    "confidence": "High",
                    "title": "PHP-FPM + Nginx - Remote Code Execution",
                    "summary": "PHP-FPM + Nginx - Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/47553",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2019-11043",
                    "summary": "RCE in Nginx + php-fpm when fastcgi_split_path_info with %0a causes empty PATH_INFO.",
                    "what_happened": "RCE in Nginx + php-fpm when fastcgi_split_path_info with %0a causes empty PATH_INFO.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IANXTIANXT-CVE-2019-11043",
                        "https://kitploit.com/ru/tools/github/ianxtianxt/cve-2019-11043/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T15:51:06",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IANXTIANXT-CVE-2019-11043"
                },
                {
                    "title": "Exploit for CVE-2019-11043",
                    "summary": "RCE in Nginx + php-fpm when fastcgi_split_path_info with %0a causes empty PATH_INFO.",
                    "what_happened": "RCE in Nginx + php-fpm when fastcgi_split_path_info with %0a causes empty PATH_INFO.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IANXTIANXT-CVE-2019-11043",
                        "https://kitploit.com/ru/tools/github/ianxtianxt/cve-2019-11043/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T15:51:06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/ianxtianxt/cve-2019-11043/"
                },
                {
                    "repository": "PoC-in-GitHub · neex/phuip-fpizdam",
                    "author": "neex",
                    "first_seen": "2019-09-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1833,
                    "title": "Exploit for CVE-2019-11043",
                    "summary": "Exploit for CVE-2019-11043",
                    "url": "https://github.com/neex/phuip-fpizdam"
                },
                {
                    "repository": "PoC-in-GitHub · B1gd0g/CVE-2019-11043",
                    "author": "B1gd0g",
                    "first_seen": "2019-10-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-11043",
                    "summary": "CVE-2019-11043",
                    "url": "https://github.com/B1gd0g/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · tinker-li/CVE-2019-11043",
                    "author": "tinker-li",
                    "first_seen": "2019-10-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-11043 repository",
                    "summary": "",
                    "url": "https://github.com/tinker-li/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · jas502n/CVE-2019-11043",
                    "author": "jas502n",
                    "first_seen": "2019-10-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 105,
                    "title": "php-fpm+Nginx RCE",
                    "summary": "php-fpm+Nginx RCE",
                    "url": "https://github.com/jas502n/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · AleWong/PHP-FPM-Remote-Code-Execution-Vulnerability-CVE-2019-11043-",
                    "author": "AleWong",
                    "first_seen": "2019-10-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "PHP-FPM Remote Code Execution Vulnerability (CVE-2019-11043) POC in Python",
                    "summary": "PHP-FPM Remote Code Execution Vulnerability (CVE-2019-11043) POC in Python",
                    "url": "https://github.com/AleWong/PHP-FPM-Remote-Code-Execution-Vulnerability-CVE-2019-11043-"
                },
                {
                    "repository": "PoC-in-GitHub · ianxtianxt/CVE-2019-11043",
                    "author": "ianxtianxt",
                    "first_seen": "2019-10-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-11043 repository",
                    "summary": "",
                    "url": "https://github.com/ianxtianxt/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · fairyming/CVE-2019-11043",
                    "author": "fairyming",
                    "first_seen": "2019-10-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-11043 repository",
                    "summary": "",
                    "url": "https://github.com/fairyming/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · akamajoris/CVE-2019-11043-Docker",
                    "author": "akamajoris",
                    "first_seen": "2019-10-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 27,
                    "title": "CVE-2019-11043 repository",
                    "summary": "",
                    "url": "https://github.com/akamajoris/CVE-2019-11043-Docker"
                },
                {
                    "repository": "PoC-in-GitHub · theMiddleBlue/CVE-2019-11043",
                    "author": "theMiddleBlue",
                    "first_seen": "2019-10-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 147,
                    "title": "(PoC) Python version of CVE-2019-11043 exploit by neex",
                    "summary": "(PoC) Python version of CVE-2019-11043 exploit by neex",
                    "url": "https://github.com/theMiddleBlue/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · shadow-horse/cve-2019-11043",
                    "author": "shadow-horse",
                    "first_seen": "2019-10-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-11043 PHP远程代码执行",
                    "summary": "CVE-2019-11043 PHP远程代码执行",
                    "url": "https://github.com/shadow-horse/cve-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · huowen/CVE-2019-11043",
                    "author": "huowen",
                    "first_seen": "2019-10-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Python exp for CVE-2019-11043",
                    "summary": "Python exp for CVE-2019-11043",
                    "url": "https://github.com/huowen/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · ypereirareis/docker-CVE-2019-11043",
                    "author": "ypereirareis",
                    "first_seen": "2019-10-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "Docker image and commands to check CVE-2019-11043 vulnerability on nginx/php-fpm applications.",
                    "summary": "Docker image and commands to check CVE-2019-11043 vulnerability on nginx/php-fpm applications.",
                    "url": "https://github.com/ypereirareis/docker-CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · MRdoulestar/CVE-2019-11043",
                    "author": "MRdoulestar",
                    "first_seen": "2019-11-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2019-11043  &&  PHP7.x  &&  RCE  EXP",
                    "summary": "CVE-2019-11043  &&  PHP7.x  &&  RCE  EXP",
                    "url": "https://github.com/MRdoulestar/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · 0th3rs-Security-Team/CVE-2019-11043",
                    "author": "0th3rs-Security-Team",
                    "first_seen": "2019-11-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "CVE-2019-11043  PHP7.x  RCE",
                    "summary": "CVE-2019-11043  PHP7.x  RCE",
                    "url": "https://github.com/0th3rs-Security-Team/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · k8gege/CVE-2019-11043",
                    "author": "k8gege",
                    "first_seen": "2019-11-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 16,
                    "title": "Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)",
                    "summary": "Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)",
                    "url": "https://github.com/k8gege/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · moniik/CVE-2019-11043_env",
                    "author": "moniik",
                    "first_seen": "2019-11-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "remote debug environment for CLion",
                    "summary": "remote debug environment for CLion",
                    "url": "https://github.com/moniik/CVE-2019-11043_env"
                },
                {
                    "repository": "PoC-in-GitHub · kriskhub/CVE-2019-11043",
                    "author": "kriskhub",
                    "first_seen": "2020-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "This repository provides a dockerized infrastructure and a python implementation of the CVE-2019-11043 exploit.",
                    "summary": "This repository provides a dockerized infrastructure and a python implementation of the CVE-2019-11043 exploit.",
                    "url": "https://github.com/kriskhub/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · alokaranasinghe/cve-2019-11043",
                    "author": "alokaranasinghe",
                    "first_seen": "2020-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-11043 repository",
                    "summary": "",
                    "url": "https://github.com/alokaranasinghe/cve-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · corifeo/CVE-2019-11043",
                    "author": "corifeo",
                    "first_seen": "2020-07-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "quick and dirty PHP RCE proof of concept",
                    "summary": "quick and dirty PHP RCE proof of concept",
                    "url": "https://github.com/corifeo/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · lindemer/CVE-2019-11043",
                    "author": "lindemer",
                    "first_seen": "2020-11-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "PHP-FPM Remote Command Execution Exploit",
                    "summary": "PHP-FPM Remote Command Execution Exploit",
                    "url": "https://github.com/lindemer/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · jptr218/php_hack",
                    "author": "jptr218",
                    "first_seen": "2021-08-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2019-11043",
                    "summary": "CVE-2019-11043",
                    "url": "https://github.com/jptr218/php_hack"
                },
                {
                    "repository": "PoC-in-GitHub · jas9reet/CVE-2019-11043",
                    "author": "jas9reet",
                    "first_seen": "2022-03-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-11043 LAB",
                    "summary": "CVE-2019-11043 LAB",
                    "url": "https://github.com/jas9reet/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · bayazid-bit/CVE-2019-11043",
                    "author": "bayazid-bit",
                    "first_seen": "2025-06-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019–11043: PHP-FPM Nginx Remote Code Execution Vulnerability",
                    "summary": "CVE-2019–11043: PHP-FPM Nginx Remote Code Execution Vulnerability",
                    "url": "https://github.com/bayazid-bit/CVE-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · a1ex-var1amov/ctf-cve-2019-11043",
                    "author": "a1ex-var1amov",
                    "first_seen": "2025-08-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-11043 repository",
                    "summary": "",
                    "url": "https://github.com/a1ex-var1amov/ctf-cve-2019-11043"
                },
                {
                    "repository": "PoC-in-GitHub · CodeHex083/phuip-fpizdam",
                    "author": "CodeHex083",
                    "first_seen": "2025-10-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Exploit for CVE-2019-11043",
                    "summary": "Exploit for CVE-2019-11043",
                    "url": "https://github.com/CodeHex083/phuip-fpizdam"
                },
                {
                    "repository": "PoC-in-GitHub · MagentaBear/CVE-2019-11043-Vulnerability",
                    "author": "MagentaBear",
                    "first_seen": "2025-11-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-11043 repository",
                    "summary": "",
                    "url": "https://github.com/MagentaBear/CVE-2019-11043-Vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · gon905332-jpg/cve-2019-11043.py",
                    "author": "gon905332-jpg",
                    "first_seen": "2025-12-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Python port of an ExploitDB proof-of-concept.",
                    "summary": "Python port of an ExploitDB proof-of-concept.",
                    "url": "https://github.com/gon905332-jpg/cve-2019-11043.py"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/48182",
                "https://www.exploit-db.com/exploits/47553",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IANXTIANXT-CVE-2019-11043",
                "https://kitploit.com/ru/tools/github/ianxtianxt/cve-2019-11043/",
                "https://github.com/neex/phuip-fpizdam",
                "https://github.com/B1gd0g/CVE-2019-11043",
                "https://github.com/tinker-li/CVE-2019-11043",
                "https://github.com/jas502n/CVE-2019-11043",
                "https://github.com/AleWong/PHP-FPM-Remote-Code-Execution-Vulnerability-CVE-2019-11043-",
                "https://github.com/ianxtianxt/CVE-2019-11043",
                "https://github.com/fairyming/CVE-2019-11043",
                "https://github.com/akamajoris/CVE-2019-11043-Docker",
                "https://github.com/theMiddleBlue/CVE-2019-11043",
                "https://github.com/shadow-horse/cve-2019-11043",
                "https://github.com/huowen/CVE-2019-11043",
                "https://github.com/ypereirareis/docker-CVE-2019-11043",
                "https://github.com/MRdoulestar/CVE-2019-11043",
                "https://github.com/0th3rs-Security-Team/CVE-2019-11043",
                "https://github.com/k8gege/CVE-2019-11043",
                "https://github.com/moniik/CVE-2019-11043_env",
                "https://github.com/kriskhub/CVE-2019-11043",
                "https://github.com/alokaranasinghe/cve-2019-11043",
                "https://github.com/corifeo/CVE-2019-11043",
                "https://github.com/lindemer/CVE-2019-11043",
                "https://github.com/jptr218/php_hack",
                "https://github.com/jas9reet/CVE-2019-11043",
                "https://github.com/bayazid-bit/CVE-2019-11043",
                "https://github.com/a1ex-var1amov/ctf-cve-2019-11043",
                "https://github.com/CodeHex083/phuip-fpizdam",
                "https://github.com/MagentaBear/CVE-2019-11043-Vulnerability",
                "https://github.com/gon905332-jpg/cve-2019-11043.py"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T14:40:45Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2019-9670",
            "vendor": "Synacor",
            "product": "Zimbra Collaboration Suite (ZCS)",
            "title": "Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference",
            "summary": "Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.",
            "updated_at": "2026-09-12T06:33:00Z",
            "published_at": "2026-09-12T06:33:00Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 85,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 46693",
                    "author": "Metasploit",
                    "first_seen": "2019-04-12",
                    "confidence": "High",
                    "title": "Zimbra Collaboration - Autodiscover Servlet XXE and ProxyServlet SSRF (Metasploit)",
                    "summary": "Zimbra Collaboration - Autodiscover Servlet XXE and ProxyServlet SSRF (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/46693",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for Zimbra-RCE CVE-2019-9670",
                    "summary": "RCE in Zimbra via CVE-2019-9670 using DTD-based attack with uploaded payload.",
                    "what_happened": "RCE in Zimbra via CVE-2019-9670 using DTD-based attack with uploaded payload.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ATTACKGITHUB-ZIMBRA-RCE",
                        "https://kitploit.com/hi/tools/github/attackgithub/zimbra-rce/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T10:31:12",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ATTACKGITHUB-ZIMBRA-RCE"
                },
                {
                    "title": "Exploit for Zimbra-RCE CVE-2019-9670",
                    "summary": "RCE in Zimbra via CVE-2019-9670 using DTD-based attack with uploaded payload.",
                    "what_happened": "RCE in Zimbra via CVE-2019-9670 using DTD-based attack with uploaded payload.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ATTACKGITHUB-ZIMBRA-RCE",
                        "https://kitploit.com/hi/tools/github/attackgithub/zimbra-rce/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T10:31:12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/attackgithub/zimbra-rce/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/46693",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ATTACKGITHUB-ZIMBRA-RCE",
                "https://kitploit.com/hi/tools/github/attackgithub/zimbra-rce/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:33:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2019-9465",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2019-9465",
            "summary": "Android demo application demonstrating the CVE-2019-9465 vulnerability.",
            "updated_at": "2026-09-06T05:24:26Z",
            "published_at": "2026-09-06T05:24:26Z",
            "cvss": 5.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Android demo application demonstrating the CVE-2019-9465 vulnerability.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2019-9465",
                    "summary": "Android demo application demonstrating the CVE-2019-9465 vulnerability.",
                    "what_happened": "Android demo application demonstrating the CVE-2019-9465 vulnerability.",
                    "cvss": 5.5,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXBAKKER-CVE-2019-9465",
                        "https://kitploit.com/hi/tools/github/alexbakker/cve-2019-9465/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T07:24:26",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXBAKKER-CVE-2019-9465"
                },
                {
                    "title": "Exploit for CVE-2019-9465",
                    "summary": "Android demo application demonstrating the CVE-2019-9465 vulnerability.",
                    "what_happened": "Android demo application demonstrating the CVE-2019-9465 vulnerability.",
                    "cvss": 5.5,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXBAKKER-CVE-2019-9465",
                        "https://kitploit.com/hi/tools/github/alexbakker/cve-2019-9465/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T07:24:26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/alexbakker/cve-2019-9465/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXBAKKER-CVE-2019-9465",
                "https://kitploit.com/hi/tools/github/alexbakker/cve-2019-9465/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T05:24:26Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXBAKKER-CVE-2019-9465"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2019-9053",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CMS Made Simple < 2.2.10 - SQL Injection",
            "summary": "CMS Made Simple < 2.2.10 - SQL Injection",
            "updated_at": "2026-08-21T22:00:00Z",
            "published_at": "2026-08-21T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 564,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 46635",
                    "author": "Daniele Scanu",
                    "first_seen": "2019-04-02",
                    "confidence": "High",
                    "title": "CMS Made Simple < 2.2.10 - SQL Injection",
                    "summary": "CMS Made Simple < 2.2.10 - SQL Injection",
                    "url": "https://www.exploit-db.com/exploits/46635",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · d3athcod3/46635.py_CVE-2019-9053",
                    "author": "d3athcod3",
                    "first_seen": "2021-05-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This is modified code of 46635 exploit from python2 to python3.",
                    "summary": "This is modified code of 46635 exploit from python2 to python3.",
                    "url": "https://github.com/d3athcod3/46635.py_CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · h3x0v3rl0rd/CVE-2019-9053",
                    "author": "h3x0v3rl0rd",
                    "first_seen": "2021-07-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2019-9053 repository",
                    "summary": "",
                    "url": "https://github.com/h3x0v3rl0rd/CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · maraspiras/46635.py",
                    "author": "maraspiras",
                    "first_seen": "2021-12-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "update to Daniele Scanu's SQL Injection Exploit - CVE-2019-9053",
                    "summary": "update to Daniele Scanu's SQL Injection Exploit - CVE-2019-9053",
                    "url": "https://github.com/maraspiras/46635.py"
                },
                {
                    "repository": "PoC-in-GitHub · e-renna/CVE-2019-9053",
                    "author": "e-renna",
                    "first_seen": "2021-12-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "CVE-2019-9053 Exploit for Python 3",
                    "summary": "CVE-2019-9053 Exploit for Python 3",
                    "url": "https://github.com/e-renna/CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · zmiddle/Simple_CMS_SQLi",
                    "author": "zmiddle",
                    "first_seen": "2022-10-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is a exploit for CVE-2019-9053",
                    "summary": "This is a exploit for CVE-2019-9053",
                    "url": "https://github.com/zmiddle/Simple_CMS_SQLi"
                },
                {
                    "repository": "PoC-in-GitHub · ELIZEUOPAIN/CVE-2019-9053-CMS-Made-Simple-2.2.10---SQL-Injection-Exploit",
                    "author": "ELIZEUOPAIN",
                    "first_seen": "2022-10-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2019-9053 repository",
                    "summary": "",
                    "url": "https://github.com/ELIZEUOPAIN/CVE-2019-9053-CMS-Made-Simple-2.2.10---SQL-Injection-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Mahamedm/CVE-2019-9053-Exploit-Python-3",
                    "author": "Mahamedm",
                    "first_seen": "2023-05-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.",
                    "summary": "The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.",
                    "url": "https://github.com/Mahamedm/CVE-2019-9053-Exploit-Python-3"
                },
                {
                    "repository": "PoC-in-GitHub · im-suman-roy/CVE-2019-9053",
                    "author": "im-suman-roy",
                    "first_seen": "2023-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is the Updated Python3 exploit for CVE-2019-9053",
                    "summary": "This is the Updated Python3 exploit for CVE-2019-9053",
                    "url": "https://github.com/im-suman-roy/CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · kahluri/CVE-2019-9053",
                    "author": "kahluri",
                    "first_seen": "2023-08-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Original Exploit Source: https://www.exploit-db.com/exploits/46635",
                    "summary": "Original Exploit Source: https://www.exploit-db.com/exploits/46635",
                    "url": "https://github.com/kahluri/CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · fernandobortotti/CVE-2019-9053",
                    "author": "fernandobortotti",
                    "first_seen": "2023-10-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This repository has the sole purpose of rewriting the CVE-2019-9053 script, which in the original publication is written in Python 2.7. I will be using Python 3.",
                    "summary": "This repository has the sole purpose of rewriting the CVE-2019-9053 script, which in the original publication is written in Python 2.7. I will be using Python 3.",
                    "url": "https://github.com/fernandobortotti/CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · byrek/CVE-2019-9053",
                    "author": "byrek",
                    "first_seen": "2023-11-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Improved code of Daniele Scanu SQL Injection exploit",
                    "summary": "Improved code of Daniele Scanu SQL Injection exploit",
                    "url": "https://github.com/byrek/CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · davcwikla/CVE-2019-9053-exploit",
                    "author": "davcwikla",
                    "first_seen": "2023-11-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "working exploit for CVE-2019-9053",
                    "summary": "working exploit for CVE-2019-9053",
                    "url": "https://github.com/davcwikla/CVE-2019-9053-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · BjarneVerschorre/CVE-2019-9053",
                    "author": "BjarneVerschorre",
                    "first_seen": "2023-11-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-9053 repository",
                    "summary": "",
                    "url": "https://github.com/BjarneVerschorre/CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · Jason-Siu/CVE-2019-9053-Exploit-in-Python-3",
                    "author": "Jason-Siu",
                    "first_seen": "2024-02-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-9053 repository",
                    "summary": "",
                    "url": "https://github.com/Jason-Siu/CVE-2019-9053-Exploit-in-Python-3"
                },
                {
                    "repository": "PoC-in-GitHub · 0xftorres/CVE-2019-9053-Fixed",
                    "author": "0xftorres",
                    "first_seen": "2024-05-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-9054 exploit added support for python3 + bug fixes",
                    "summary": "CVE-2019-9054 exploit added support for python3 + bug fixes",
                    "url": "https://github.com/0xftorres/CVE-2019-9053-Fixed"
                },
                {
                    "repository": "PoC-in-GitHub · Dh4nuJ4/SimpleCTF-UpdatedExploit",
                    "author": "Dh4nuJ4",
                    "first_seen": "2024-06-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.10 (CVE-2019-9053).",
                    "summary": "This script is a modified version of the original exploit by Daniele Scanu which exploits an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.10 (CVE-2019-9053).",
                    "url": "https://github.com/Dh4nuJ4/SimpleCTF-UpdatedExploit"
                },
                {
                    "repository": "PoC-in-GitHub · TeymurNovruzov/CVE-2019-9053-python3-remastered",
                    "author": "TeymurNovruzov",
                    "first_seen": "2024-06-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "The script has been remastered by Teymur Novruzov to ensure compatibility with Python 3. This tool is intended for educational purposes only. Unauthorized use of this tool on any system or network without permission is illegal. The author is not responsible for any misuse of this tool.",
                    "summary": "The script has been remastered by Teymur Novruzov to ensure compatibility with Python 3. This tool is intended for educational purposes only. Unauthorized use of this tool on any system or network without permission is illegal. The author is not responsible for any misuse of this tool.",
                    "url": "https://github.com/TeymurNovruzov/CVE-2019-9053-python3-remastered"
                },
                {
                    "repository": "PoC-in-GitHub · jtoalu/CTF-CVE-2019-9053-GTFOBins",
                    "author": "jtoalu",
                    "first_seen": "2024-08-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-9053 repository",
                    "summary": "",
                    "url": "https://github.com/jtoalu/CTF-CVE-2019-9053-GTFOBins"
                },
                {
                    "repository": "PoC-in-GitHub · Azrenom/CMS-Made-Simple-2.2.9-CVE-2019-9053",
                    "author": "Azrenom",
                    "first_seen": "2024-09-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2019-9053 repository",
                    "summary": "",
                    "url": "https://github.com/Azrenom/CMS-Made-Simple-2.2.9-CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · Ap0cryph1c/CVE-2019-9053",
                    "author": "Ap0cryph1c",
                    "first_seen": "2024-10-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-9053 rewritten in python3 to fix broken syntax. Affects CMS made simple <2.2.10",
                    "summary": "CVE-2019-9053 rewritten in python3 to fix broken syntax. Affects CMS made simple <2.2.10",
                    "url": "https://github.com/Ap0cryph1c/CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · Yzhacker/CVE-2019-9053-CMS46635-python3",
                    "author": "Yzhacker",
                    "first_seen": "2025-02-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CMS Made Simple < 2.2.10 - SQL Injection python3",
                    "summary": "CMS Made Simple < 2.2.10 - SQL Injection python3",
                    "url": "https://github.com/Yzhacker/CVE-2019-9053-CMS46635-python3"
                },
                {
                    "repository": "PoC-in-GitHub · hf3cyber/CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053-",
                    "author": "hf3cyber",
                    "first_seen": "2025-03-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This exploit targets an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.9 (CVE-2019-9053). It uses a time-based blind SQL injection to extract the username, email, and password hash from the database. Additionally, it supports password cracking using a wordlist.",
                    "summary": "This exploit targets an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.9 (CVE-2019-9053). It uses a time-based blind SQL injection to extract the username, email, and password hash from the database. Additionally, it supports password cracking using a wordlist.",
                    "url": "https://github.com/hf3cyber/CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053-"
                },
                {
                    "repository": "PoC-in-GitHub · del0x3/CVE-2019-9053-port-py3",
                    "author": "del0x3",
                    "first_seen": "2025-04-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-9053.",
                    "summary": "CVE-2019-9053.",
                    "url": "https://github.com/del0x3/CVE-2019-9053-port-py3"
                },
                {
                    "repository": "PoC-in-GitHub · kaizoku73/CVE-2019-9053",
                    "author": "kaizoku73",
                    "first_seen": "2025-04-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CMS Made Simple ≤ 2.2.9 SQL Injection Vulnerability CVE-2019-9053 is a vulnerability found in CMS Made Simple (CMSMS) versions up to 2.2.9, where the application is vulnerable to a blind time-based SQL injection",
                    "summary": "CMS Made Simple ≤ 2.2.9 SQL Injection Vulnerability CVE-2019-9053 is a vulnerability found in CMS Made Simple (CMSMS) versions up to 2.2.9, where the application is vulnerable to a blind time-based SQL injection",
                    "url": "https://github.com/kaizoku73/CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · Hackheart-tech/-exploit-lab",
                    "author": "Hackheart-tech",
                    "first_seen": "2025-04-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploits Python cve-2019-9053– by HackHeart",
                    "summary": "Exploits Python cve-2019-9053– by HackHeart",
                    "url": "https://github.com/Hackheart-tech/-exploit-lab"
                },
                {
                    "repository": "PoC-in-GitHub · Kalidas-7/CVE-2019-9053",
                    "author": "Kalidas-7",
                    "first_seen": "2025-07-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-9053 repository",
                    "summary": "",
                    "url": "https://github.com/Kalidas-7/CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · Boon-Rekcah/CMS-Made-Simple-2.2.9-CVE-2019-9053",
                    "author": "Boon-Rekcah",
                    "first_seen": "2025-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-9053 repository",
                    "summary": "",
                    "url": "https://github.com/Boon-Rekcah/CMS-Made-Simple-2.2.9-CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · Slayerma/-CVE-2019-9053",
                    "author": "Slayerma",
                    "first_seen": "2025-09-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository contains the corrected code for  CVE: 2019-9053",
                    "summary": "This repository contains the corrected code for  CVE: 2019-9053",
                    "url": "https://github.com/Slayerma/-CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · CaelumIsMe/CVE-2019-9053-POC",
                    "author": "CaelumIsMe",
                    "first_seen": "2025-10-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-9053 repository",
                    "summary": "",
                    "url": "https://github.com/CaelumIsMe/CVE-2019-9053-POC"
                },
                {
                    "repository": "PoC-in-GitHub · JagdeepSinghCeh/cms-made-simple-python3",
                    "author": "JagdeepSinghCeh",
                    "first_seen": "2025-11-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original PoC, improved Python3 version, usage instructions, and lab testing reference.",
                    "summary": "Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original PoC, improved Python3 version, usage instructions, and lab testing reference.",
                    "url": "https://github.com/JagdeepSinghCeh/cms-made-simple-python3"
                },
                {
                    "repository": "PoC-in-GitHub · Perseus99999/CVE-2019-9053-working-",
                    "author": "Perseus99999",
                    "first_seen": "2025-11-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CMS Made Simple < 2.2.10 - SQL Injection . Actual working version",
                    "summary": "CMS Made Simple < 2.2.10 - SQL Injection . Actual working version",
                    "url": "https://github.com/Perseus99999/CVE-2019-9053-working-"
                },
                {
                    "repository": "PoC-in-GitHub · tim-karov/cmsms-sqli",
                    "author": "tim-karov",
                    "first_seen": "2026-01-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.",
                    "summary": "Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.",
                    "url": "https://github.com/tim-karov/cmsms-sqli"
                },
                {
                    "repository": "PoC-in-GitHub · pasan2002/CVE-2019-9053---CMS-Made-Simple-SQL-Injection-Exploit-Modified-",
                    "author": "pasan2002",
                    "first_seen": "2026-02-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is a modified version of the time-based SQL injection exploit for CMS Made Simple <= 2.2.9. The exploit was originally created by Daniele Scanu and has been updated for better compatibility and modern Python practices.",
                    "summary": "This is a modified version of the time-based SQL injection exploit for CMS Made Simple <= 2.2.9. The exploit was originally created by Daniele Scanu and has been updated for better compatibility and modern Python practices.",
                    "url": "https://github.com/pasan2002/CVE-2019-9053---CMS-Made-Simple-SQL-Injection-Exploit-Modified-"
                },
                {
                    "repository": "PoC-in-GitHub · iTzR1g/CVE-2019-9053",
                    "author": "iTzR1g",
                    "first_seen": "2026-04-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Fixed CVE-2019-9053",
                    "summary": "Fixed CVE-2019-9053",
                    "url": "https://github.com/iTzR1g/CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · coolkiee/CVE-2019-9053",
                    "author": "coolkiee",
                    "first_seen": "2026-04-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-9053 repository",
                    "summary": "",
                    "url": "https://github.com/coolkiee/CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · killukeren/-CVE-2019-9053",
                    "author": "killukeren",
                    "first_seen": "2026-04-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CMS Simple CVE Recode Script Python 3",
                    "summary": "CMS Simple CVE Recode Script Python 3",
                    "url": "https://github.com/killukeren/-CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · paulameg/SimpleCTF-THM-Walkthrough",
                    "author": "paulameg",
                    "first_seen": "2026-05-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "First CTF successfully completed! This repo documents my walkthrough of TryHackMe's Simple CTF. It covers network reconnaissance (Nmap), web exploitation (CVE-2019-9053), and credential cracking. As a dev, it was great to pivot from SQLi to a Root shell by leveraging Sudo misconfigurations. Educational purposes only.",
                    "summary": "First CTF successfully completed! This repo documents my walkthrough of TryHackMe's Simple CTF. It covers network reconnaissance (Nmap), web exploitation (CVE-2019-9053), and credential cracking. As a dev, it was great to pivot from SQLi to a Root shell by leveraging Sudo misconfigurations. Educational purposes only.",
                    "url": "https://github.com/paulameg/SimpleCTF-THM-Walkthrough"
                },
                {
                    "repository": "PoC-in-GitHub · jyothsna-Git007/CMS-Made-Simple-2.2.10---SQL-Injection",
                    "author": "jyothsna-Git007",
                    "first_seen": "2026-05-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Google Dorks for detecting CMS Made Simple < 2.2.10 SQL Injection (CVE-2019-9053). Built for security auditing and patch verification.",
                    "summary": "Google Dorks for detecting CMS Made Simple < 2.2.10 SQL Injection (CVE-2019-9053). Built for security auditing and patch verification.",
                    "url": "https://github.com/jyothsna-Git007/CMS-Made-Simple-2.2.10---SQL-Injection"
                },
                {
                    "repository": "PoC-in-GitHub · v4rr10r/CVE-2019-9053",
                    "author": "v4rr10r",
                    "first_seen": "2026-05-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CMS Made Simple CVE-2019-9053 Exploit (Python 3)",
                    "summary": "CMS Made Simple CVE-2019-9053 Exploit (Python 3)",
                    "url": "https://github.com/v4rr10r/CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · ImperialX1104/Simple-CTF-Writeup",
                    "author": "ImperialX1104",
                    "first_seen": "2026-05-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Professional TryHackMe Simple CTF walkthrough covering enumeration, CMS Made Simple SQL Injection (CVE-2019-9053), credential recovery, SSH access, privilege escalation via Vim, and root compromise.",
                    "summary": "Professional TryHackMe Simple CTF walkthrough covering enumeration, CMS Made Simple SQL Injection (CVE-2019-9053), credential recovery, SSH access, privilege escalation via Vim, and root compromise.",
                    "url": "https://github.com/ImperialX1104/Simple-CTF-Writeup"
                },
                {
                    "repository": "PoC-in-GitHub · Jeanback1/CVE-2019-9053-exploit",
                    "author": "Jeanback1",
                    "first_seen": "2026-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-9053 repository",
                    "summary": "",
                    "url": "https://github.com/Jeanback1/CVE-2019-9053-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · rideckszz/poc-CVE-2019-9053",
                    "author": "rideckszz",
                    "first_seen": "2026-06-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC didático em Python 3 para a CVE-2019-9053, uma SQL Injection time-based blind no CMS Made Simple <= 2.2.9. Esta versão foi adaptada para uso em CTF/laboratório, com prefixos pré-configurados para reduzir o tempo de extração e mensagens explicativas em português.",
                    "summary": "PoC didático em Python 3 para a CVE-2019-9053, uma SQL Injection time-based blind no CMS Made Simple <= 2.2.9. Esta versão foi adaptada para uso em CTF/laboratório, com prefixos pré-configurados para reduzir o tempo de extração e mensagens explicativas em português.",
                    "url": "https://github.com/rideckszz/poc-CVE-2019-9053"
                },
                {
                    "repository": "PoC-in-GitHub · rgkue/mysqli",
                    "author": "rgkue",
                    "first_seen": "2026-06-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Time-Based Blind SQL Injection tool for MySQL - CVE-2019-9053",
                    "summary": "Time-Based Blind SQL Injection tool for MySQL - CVE-2019-9053",
                    "url": "https://github.com/rgkue/mysqli"
                },
                {
                    "repository": "PoC-in-GitHub · Vedantrana73/cve-2019-9053-py3",
                    "author": "Vedantrana73",
                    "first_seen": "2026-06-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Unauthenticated time-based blind SQL injection exploit for CMS Made Simple ≤ 2.2.9 (CVE-2019-9053), ported to Python 3.",
                    "summary": "Unauthenticated time-based blind SQL injection exploit for CMS Made Simple ≤ 2.2.9 (CVE-2019-9053), ported to Python 3.",
                    "url": "https://github.com/Vedantrana73/cve-2019-9053-py3"
                },
                {
                    "repository": "PoC-in-GitHub · quliyevresul7777/CVE-2019-9053",
                    "author": "quliyevresul7777",
                    "first_seen": "2026-08-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Exploit Title: Unauthenticated SQL Injection on CMS Made Simple <= 2.2.9",
                    "summary": "Exploit Title: Unauthenticated SQL Injection on CMS Made Simple <= 2.2.9",
                    "url": "https://github.com/quliyevresul7777/CVE-2019-9053"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/46635",
                "https://github.com/d3athcod3/46635.py_CVE-2019-9053",
                "https://github.com/h3x0v3rl0rd/CVE-2019-9053",
                "https://github.com/maraspiras/46635.py",
                "https://github.com/e-renna/CVE-2019-9053",
                "https://github.com/zmiddle/Simple_CMS_SQLi",
                "https://github.com/ELIZEUOPAIN/CVE-2019-9053-CMS-Made-Simple-2.2.10---SQL-Injection-Exploit",
                "https://github.com/Mahamedm/CVE-2019-9053-Exploit-Python-3",
                "https://github.com/im-suman-roy/CVE-2019-9053",
                "https://github.com/kahluri/CVE-2019-9053",
                "https://github.com/fernandobortotti/CVE-2019-9053",
                "https://github.com/byrek/CVE-2019-9053",
                "https://github.com/davcwikla/CVE-2019-9053-exploit",
                "https://github.com/BjarneVerschorre/CVE-2019-9053",
                "https://github.com/Jason-Siu/CVE-2019-9053-Exploit-in-Python-3",
                "https://github.com/0xftorres/CVE-2019-9053-Fixed",
                "https://github.com/Dh4nuJ4/SimpleCTF-UpdatedExploit",
                "https://github.com/TeymurNovruzov/CVE-2019-9053-python3-remastered",
                "https://github.com/jtoalu/CTF-CVE-2019-9053-GTFOBins",
                "https://github.com/Azrenom/CMS-Made-Simple-2.2.9-CVE-2019-9053",
                "https://github.com/Ap0cryph1c/CVE-2019-9053",
                "https://github.com/Yzhacker/CVE-2019-9053-CMS46635-python3",
                "https://github.com/hf3cyber/CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053-",
                "https://github.com/del0x3/CVE-2019-9053-port-py3",
                "https://github.com/kaizoku73/CVE-2019-9053",
                "https://github.com/Hackheart-tech/-exploit-lab",
                "https://github.com/Kalidas-7/CVE-2019-9053",
                "https://github.com/Boon-Rekcah/CMS-Made-Simple-2.2.9-CVE-2019-9053",
                "https://github.com/Slayerma/-CVE-2019-9053",
                "https://github.com/CaelumIsMe/CVE-2019-9053-POC",
                "https://github.com/JagdeepSinghCeh/cms-made-simple-python3",
                "https://github.com/Perseus99999/CVE-2019-9053-working-",
                "https://github.com/tim-karov/cmsms-sqli",
                "https://github.com/pasan2002/CVE-2019-9053---CMS-Made-Simple-SQL-Injection-Exploit-Modified-",
                "https://github.com/iTzR1g/CVE-2019-9053",
                "https://github.com/coolkiee/CVE-2019-9053",
                "https://github.com/killukeren/-CVE-2019-9053",
                "https://github.com/paulameg/SimpleCTF-THM-Walkthrough",
                "https://github.com/jyothsna-Git007/CMS-Made-Simple-2.2.10---SQL-Injection",
                "https://github.com/v4rr10r/CVE-2019-9053",
                "https://github.com/ImperialX1104/Simple-CTF-Writeup",
                "https://github.com/Jeanback1/CVE-2019-9053-exploit",
                "https://github.com/rideckszz/poc-CVE-2019-9053",
                "https://github.com/rgkue/mysqli",
                "https://github.com/Vedantrana73/cve-2019-9053-py3",
                "https://github.com/quliyevresul7777/CVE-2019-9053"
            ],
            "timeline": [
                {
                    "at": "2026-08-21T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/46635"
                }
            ]
        },
        {
            "id": "CVE-2019-7106",
            "vendor": "Adobe",
            "product": "Adobe XD",
            "title": "Adobe XD vulnerability",
            "summary": "Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.",
            "updated_at": "2026-09-15T15:33:05.933",
            "published_at": "2019-05-23T16:29:08.917",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16.0 and earlier versions",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://helpx.adobe.com/security/products/xd/apsb19-22.html"
            ],
            "timeline": [
                {
                    "at": "2019-05-23T16:29:08.917",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-7106"
                }
            ]
        },
        {
            "id": "CVE-2019-7105",
            "vendor": "Adobe",
            "product": "Adobe XD",
            "title": "Adobe XD vulnerability",
            "summary": "Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.",
            "updated_at": "2026-09-15T15:33:14.803",
            "published_at": "2019-05-23T16:29:08.887",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "16.0 and earlier versions",
            "fixed": "See vendor advisory",
            "source_count": 2,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-22",
            "what_happened": "Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary code execution.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://helpx.adobe.com/security/products/xd/apsb19-22.html"
            ],
            "timeline": [
                {
                    "at": "2019-05-23T16:29:08.887",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-7105"
                }
            ]
        },
        {
            "id": "CVE-2019-6693",
            "vendor": "Fortinet",
            "product": "FortiOS",
            "title": "Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability",
            "summary": "Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.",
            "updated_at": "2026-09-04T05:46:31Z",
            "published_at": "2026-09-04T05:46:31Z",
            "cvss": 6.5,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 346,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-05T08:15:22+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "cve-2019-6693 exploit",
                    "summary": "Exploit for CVE-2019-6693. CVSS 6.5.",
                    "cvss": 6.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SALADANDONIONRINGS-CVE-2019-6693"
                },
                {
                    "title": "Exploit for cve-2019-6693 CVE-2019-6693",
                    "summary": "FortiGate standard key allows decryption of user passwords, private keys, and HA passwords.",
                    "what_happened": "FortiGate standard key allows decryption of user passwords, private keys, and HA passwords.",
                    "cvss": 6.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SALADANDONIONRINGS-CVE-2019-6693",
                        "https://kitploit.com/ru/tools/github/saladandonionrings/cve-2019-6693/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T07:46:31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/saladandonionrings/cve-2019-6693/"
                },
                {
                    "repository": "Real4XoR/CVE-2019-6693",
                    "author": "Real4XoR",
                    "first_seen": "2025-08-26",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 1,
                    "title": "CVE-2019-6693 repository",
                    "summary": "",
                    "url": "https://github.com/Real4XoR/CVE-2019-6693"
                },
                {
                    "repository": "saladandonionrings/cve-2019-6693",
                    "author": "saladandonionrings",
                    "first_seen": "2023-12-08",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 28,
                    "title": "An authorized remote user with access or knowledge of the standard encryption key can gain access and decrypt the FortiOS backup files and all non-administator passwords, private keys and High Availability passwords.",
                    "summary": "An authorized remote user with access or knowledge of the standard encryption key can gain access and decrypt the FortiOS backup files and all non-administator passwords, private keys and High Availability passwords.",
                    "url": "https://github.com/saladandonionrings/cve-2019-6693"
                },
                {
                    "repository": "synacktiv/CVE-2020-9289",
                    "author": "synacktiv",
                    "first_seen": "2023-06-30",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 11,
                    "title": "Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with CVE-2019-6693 is the encryption routine).",
                    "summary": "Decrypt reversible secrets encrypted using the default hardcoded key related to CVE-2020-9289 on FortiAnalyzer/FortiManager (the only difference with CVE-2019-6693 is the encryption routine).",
                    "url": "https://github.com/synacktiv/CVE-2020-9289"
                },
                {
                    "repository": "gquere/CVE-2019-6693",
                    "author": "gquere",
                    "first_seen": "2021-12-21",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 8,
                    "title": "Decrypt FortiGate configuration secrets",
                    "summary": "Decrypt FortiGate configuration secrets",
                    "url": "https://github.com/gquere/CVE-2019-6693"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SALADANDONIONRINGS-CVE-2019-6693",
                "https://kitploit.com/ru/tools/github/saladandonionrings/cve-2019-6693/",
                "https://github.com/Real4XoR/CVE-2019-6693",
                "https://github.com/saladandonionrings/cve-2019-6693",
                "https://github.com/synacktiv/CVE-2020-9289",
                "https://github.com/gquere/CVE-2019-6693"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T05:46:31Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-06-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2019-6453",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "mIRC < 7.55 - 'Custom URI Protocol Handlers' Remote Command Execution",
            "summary": "mIRC < 7.55 - 'Custom URI Protocol Handlers' Remote Command Execution",
            "updated_at": "2026-09-15T08:29:48Z",
            "published_at": "2026-09-15T08:29:48Z",
            "cvss": 8.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 18,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 46392",
                    "author": "ProofOfCalc",
                    "first_seen": "2019-02-18",
                    "confidence": "High",
                    "title": "mIRC < 7.55 - 'Custom URI Protocol Handlers' Remote Command Execution",
                    "summary": "mIRC < 7.55 - 'Custom URI Protocol Handlers' Remote Command Execution",
                    "url": "https://www.exploit-db.com/exploits/46392",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-15T08:29:48+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "mIRC-CVE-2019-6453 exploit",
                    "summary": "Exploit for CVE-2019-6453. CVSS 8.1.",
                    "cvss": 8.1,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANDRIPWN-MIRC-CVE-2019-6453"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/46392",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANDRIPWN-MIRC-CVE-2019-6453"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:29:48Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/46392"
                }
            ]
        },
        {
            "id": "CVE-2019-6340",
            "vendor": "Drupal",
            "product": "Core",
            "title": "Drupal Core Remote Code Execution Vulnerability",
            "summary": "In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.",
            "updated_at": "2026-09-13T18:33:17Z",
            "published_at": "2026-09-13T18:33:17Z",
            "cvss": 8.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 94,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "In Drupal Core, some field types do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 46510",
                    "author": "Metasploit",
                    "first_seen": "2019-03-07",
                    "confidence": "High",
                    "title": "Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Execution (Metasploit)",
                    "summary": "Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Execution (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/46510",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 46452",
                    "author": "Charles Fol",
                    "first_seen": "2019-02-23",
                    "confidence": "High",
                    "title": "Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code Execution",
                    "summary": "Drupal < 8.6.10 / < 8.5.11 - REST Module Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/46452",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 46459",
                    "author": "leonjza",
                    "first_seen": "2019-02-25",
                    "confidence": "High",
                    "title": "Drupal < 8.6.9 - REST Module Remote Code Execution",
                    "summary": "Drupal < 8.6.9 - REST Module Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/46459",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:33:17+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2019-6340 exploit",
                    "summary": "Exploit for CVE-2019-6340. CVSS 8.1.",
                    "cvss": 8.1,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2019-6340"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/46510",
                "https://www.exploit-db.com/exploits/46452",
                "https://www.exploit-db.com/exploits/46459",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2019-6340"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:33:17Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2019-5736",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "runc < 1.0-rc6 (Docker < 18.09.2) - Container Breakout (1)",
            "summary": "runc < 1.0-rc6 (Docker < 18.09.2) - Container Breakout (1)",
            "updated_at": "2026-09-07T19:20:40Z",
            "published_at": "2026-09-07T19:20:40Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 164,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 46359",
                    "author": "feexd",
                    "first_seen": "2019-02-12",
                    "confidence": "High",
                    "title": "runc < 1.0-rc6 (Docker < 18.09.2) - Container Breakout (1)",
                    "summary": "runc < 1.0-rc6 (Docker < 18.09.2) - Container Breakout (1)",
                    "url": "https://www.exploit-db.com/exploits/46359",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 46369",
                    "author": "embargo",
                    "first_seen": "2019-02-13",
                    "confidence": "High",
                    "title": "runc < 1.0-rc6 (Docker < 18.09.2) - Container Breakout (2)",
                    "summary": "runc < 1.0-rc6 (Docker < 18.09.2) - Container Breakout (2)",
                    "url": "https://www.exploit-db.com/exploits/46369",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-07T19:20:40+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "cve_2019-5736-PoC exploit",
                    "summary": "Exploit for CVE-2019-5736. CVSS 9.3.",
                    "cvss": 9.3,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-PERIMORA-CVE_2019-5736-POC"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/46359",
                "https://www.exploit-db.com/exploits/46369",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-PERIMORA-CVE_2019-5736-POC"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T19:20:40Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/46359"
                }
            ]
        },
        {
            "id": "CVE-2019-2890",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for weblogic_cve-2019-2890 CVE-2019-2890",
            "summary": "XXE in Oracle WebLogic CVE-2019-2890 via serialized data injection with XXER tool.",
            "updated_at": "2026-09-04T16:29:15Z",
            "published_at": "2026-09-04T16:29:15Z",
            "cvss": 7.2,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 41,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "XXE in Oracle WebLogic CVE-2019-2890 via serialized data injection with XXER tool.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for weblogic_cve-2019-2890 CVE-2019-2890",
                    "summary": "XXE in Oracle WebLogic CVE-2019-2890 via serialized data injection with XXER tool.",
                    "what_happened": "XXE in Oracle WebLogic CVE-2019-2890 via serialized data injection with XXER tool.",
                    "cvss": 7.2,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREEIDE-WEBLOGIC_CVE-2019-2890",
                        "https://kitploit.com/ru/tools/github/freeide/weblogic_cve-2019-2890/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T18:29:15",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREEIDE-WEBLOGIC_CVE-2019-2890"
                },
                {
                    "title": "Exploit for weblogic_cve-2019-2890 CVE-2019-2890",
                    "summary": "XXE in Oracle WebLogic CVE-2019-2890 via serialized data injection with XXER tool.",
                    "what_happened": "XXE in Oracle WebLogic CVE-2019-2890 via serialized data injection with XXER tool.",
                    "cvss": 7.2,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREEIDE-WEBLOGIC_CVE-2019-2890",
                        "https://kitploit.com/ru/tools/github/freeide/weblogic_cve-2019-2890/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T18:29:15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/freeide/weblogic_cve-2019-2890/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREEIDE-WEBLOGIC_CVE-2019-2890",
                "https://kitploit.com/ru/tools/github/freeide/weblogic_cve-2019-2890/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:29:15Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREEIDE-WEBLOGIC_CVE-2019-2890"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2019-2888",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for weblogic_cve-2019-2890 CVE-2019-2890",
            "summary": "XXE in Oracle WebLogic CVE-2019-2890 via serialized data injection with XXER tool.",
            "updated_at": "2026-09-04T16:29:15Z",
            "published_at": "2026-09-04T16:29:15Z",
            "cvss": 7.2,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 41,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "High",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "XXE in Oracle WebLogic CVE-2019-2890 via serialized data injection with XXER tool.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for weblogic_cve-2019-2890 CVE-2019-2890",
                    "summary": "XXE in Oracle WebLogic CVE-2019-2890 via serialized data injection with XXER tool.",
                    "what_happened": "XXE in Oracle WebLogic CVE-2019-2890 via serialized data injection with XXER tool.",
                    "cvss": 7.2,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREEIDE-WEBLOGIC_CVE-2019-2890",
                        "https://kitploit.com/ru/tools/github/freeide/weblogic_cve-2019-2890/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T18:29:15",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREEIDE-WEBLOGIC_CVE-2019-2890"
                },
                {
                    "title": "Exploit for weblogic_cve-2019-2890 CVE-2019-2890",
                    "summary": "XXE in Oracle WebLogic CVE-2019-2890 via serialized data injection with XXER tool.",
                    "what_happened": "XXE in Oracle WebLogic CVE-2019-2890 via serialized data injection with XXER tool.",
                    "cvss": 7.2,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "High",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREEIDE-WEBLOGIC_CVE-2019-2890",
                        "https://kitploit.com/ru/tools/github/freeide/weblogic_cve-2019-2890/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T18:29:15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/freeide/weblogic_cve-2019-2890/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREEIDE-WEBLOGIC_CVE-2019-2890",
                "https://kitploit.com/ru/tools/github/freeide/weblogic_cve-2019-2890/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T16:29:15Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREEIDE-WEBLOGIC_CVE-2019-2890"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2019-2215",
            "vendor": "Android",
            "product": "Android Kernel",
            "title": "Android Kernel Use-After-Free Vulnerability",
            "summary": "Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain \"AbstractEmu.\"",
            "updated_at": "2026-08-18T22:00:00Z",
            "published_at": "2026-08-18T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1291,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain \"AbstractEmu.\"",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 47463",
                    "author": "Google Security Research",
                    "first_seen": "2019-10-04",
                    "confidence": "High",
                    "title": "Android - Binder Driver Use-After-Free",
                    "summary": "Android - Binder Driver Use-After-Free",
                    "url": "https://www.exploit-db.com/exploits/47463",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 48129",
                    "author": "Metasploit",
                    "first_seen": "2020-02-24",
                    "confidence": "High",
                    "title": "Android Binder - Use-After-Free (Metasploit)",
                    "summary": "Android Binder - Use-After-Free (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/48129",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · timwr/CVE-2019-2215",
                    "author": "timwr",
                    "first_seen": "2019-10-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 79,
                    "title": "CVE-2019-2215 repository",
                    "summary": "",
                    "url": "https://github.com/timwr/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · kangtastic/cve-2019-2215",
                    "author": "kangtastic",
                    "first_seen": "2019-10-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 137,
                    "title": "Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215",
                    "summary": "Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215",
                    "url": "https://github.com/kangtastic/cve-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · ATorNinja/CVE-2019-2215",
                    "author": "ATorNinja",
                    "first_seen": "2019-10-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE 2019-2215 Android Binder Use After Free",
                    "summary": "CVE 2019-2215 Android Binder Use After Free",
                    "url": "https://github.com/ATorNinja/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · LIznzn/CVE-2019-2215",
                    "author": "LIznzn",
                    "first_seen": "2020-01-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 26,
                    "title": "Temproot for Bravia TV via CVE-2019-2215.",
                    "summary": "Temproot for Bravia TV via CVE-2019-2215.",
                    "url": "https://github.com/LIznzn/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · DimitriFourny/cve-2019-2215",
                    "author": "DimitriFourny",
                    "first_seen": "2020-02-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 41,
                    "title": "Android privilege escalation via an use-after-free in binder.c",
                    "summary": "Android privilege escalation via an use-after-free in binder.c",
                    "url": "https://github.com/DimitriFourny/cve-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · codecat007/CVE-2019-2215",
                    "author": "codecat007",
                    "first_seen": "2020-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-2215 repository",
                    "summary": "",
                    "url": "https://github.com/codecat007/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · qre0ct/android-kernel-exploitation-ashfaq-CVE-2019-2215",
                    "author": "qre0ct",
                    "first_seen": "2020-04-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "android-kernel-exploitation-ashfaq-CVE-2019-2215 docker setup for mac users",
                    "summary": "android-kernel-exploitation-ashfaq-CVE-2019-2215 docker setup for mac users",
                    "url": "https://github.com/qre0ct/android-kernel-exploitation-ashfaq-CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · sharif-dev/AndroidKernelVulnerability",
                    "author": "sharif-dev",
                    "first_seen": "2020-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 73,
                    "title": "Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215",
                    "summary": "Triggering and Analyzing Android Kernel Vulnerability CVE-2019-2215",
                    "url": "https://github.com/sharif-dev/AndroidKernelVulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · c3r34lk1ll3r/CVE-2019-2215",
                    "author": "c3r34lk1ll3r",
                    "first_seen": "2020-10-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "PoC for old Binder vulnerability (based on P0 exploit)",
                    "summary": "PoC for old Binder vulnerability (based on P0 exploit)",
                    "url": "https://github.com/c3r34lk1ll3r/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · Byte-Master-101/CVE-2019-2215",
                    "author": "Byte-Master-101",
                    "first_seen": "2021-02-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215",
                    "summary": "Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215",
                    "url": "https://github.com/Byte-Master-101/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · mufidmb38/CVE-2019-2215",
                    "author": "mufidmb38",
                    "first_seen": "2021-05-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2019-2215",
                    "summary": "CVE-2019-2215",
                    "url": "https://github.com/mufidmb38/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · nicchongwb/Rootsmart-v2.0",
                    "author": "nicchongwb",
                    "first_seen": "2022-02-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration",
                    "summary": "Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration",
                    "url": "https://github.com/nicchongwb/Rootsmart-v2.0"
                },
                {
                    "repository": "PoC-in-GitHub · CrackerCat/Rootsmart-v2.0",
                    "author": "CrackerCat",
                    "first_seen": "2022-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration",
                    "summary": "Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration",
                    "url": "https://github.com/CrackerCat/Rootsmart-v2.0"
                },
                {
                    "repository": "PoC-in-GitHub · Enceka/cve-2019-2215-3.18",
                    "author": "Enceka",
                    "first_seen": "2022-04-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "for kernel 3.18.x",
                    "summary": "for kernel 3.18.x",
                    "url": "https://github.com/Enceka/cve-2019-2215-3.18"
                },
                {
                    "repository": "PoC-in-GitHub · elbiazo/CVE-2019-2215",
                    "author": "elbiazo",
                    "first_seen": "2023-05-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Exploit for Bad Binder",
                    "summary": "Exploit for Bad Binder",
                    "url": "https://github.com/elbiazo/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · stevejubx/CVE-2019-2215",
                    "author": "stevejubx",
                    "first_seen": "2023-11-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "Android Kernel Vulnerability (CVE-2019-2215) temporary root PoC",
                    "summary": "Android Kernel Vulnerability (CVE-2019-2215) temporary root PoC",
                    "url": "https://github.com/stevejubx/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · willboka/CVE-2019-2215-HuaweiP20Lite",
                    "author": "willboka",
                    "first_seen": "2024-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Exploit for CVE-2019-2215 (bad binder) for Huawei P20 Lite",
                    "summary": "Exploit for CVE-2019-2215 (bad binder) for Huawei P20 Lite",
                    "url": "https://github.com/willboka/CVE-2019-2215-HuaweiP20Lite"
                },
                {
                    "repository": "PoC-in-GitHub · mutur4/CVE-2019-2215",
                    "author": "mutur4",
                    "first_seen": "2024-04-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "This is a critical UAF vulnerability exploit that affected the android binder IPC system used in the wild and discovered by P0",
                    "summary": "This is a critical UAF vulnerability exploit that affected the android binder IPC system used in the wild and discovered by P0",
                    "url": "https://github.com/mutur4/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · R0rt1z2/huawei-unlock",
                    "author": "R0rt1z2",
                    "first_seen": "2024-05-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "Unlock your Huawei device with ADB (CVE-2019-2215)",
                    "summary": "Unlock your Huawei device with ADB (CVE-2019-2215)",
                    "url": "https://github.com/R0rt1z2/huawei-unlock"
                },
                {
                    "repository": "PoC-in-GitHub · raymontag/CVE-2019-2215",
                    "author": "raymontag",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-2215 repository",
                    "summary": "",
                    "url": "https://github.com/raymontag/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · XiaozaYa/CVE-2019-2215",
                    "author": "XiaozaYa",
                    "first_seen": "2024-11-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Andriod binder bug record",
                    "summary": "Andriod binder bug record",
                    "url": "https://github.com/XiaozaYa/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · llccd/TempRoot-Huawei",
                    "author": "llccd",
                    "first_seen": "2025-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2019-2215 poc for Huawei hardened kernel",
                    "summary": "CVE-2019-2215 poc for Huawei hardened kernel",
                    "url": "https://github.com/llccd/TempRoot-Huawei"
                },
                {
                    "repository": "PoC-in-GitHub · 0xbinder/android-kernel-exploitation-lab",
                    "author": "0xbinder",
                    "first_seen": "2025-03-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 45,
                    "title": "This lab guides you through setting up an environment to explore CVE-2019-2215, a critical Android kernel vulnerability in the binder subsystem.",
                    "summary": "This lab guides you through setting up an environment to explore CVE-2019-2215, a critical Android kernel vulnerability in the binder subsystem.",
                    "url": "https://github.com/0xbinder/android-kernel-exploitation-lab"
                },
                {
                    "repository": "PoC-in-GitHub · mouseos/cve-2019-2215_SH-M08",
                    "author": "mouseos",
                    "first_seen": "2025-04-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2019-2215 repository",
                    "summary": "",
                    "url": "https://github.com/mouseos/cve-2019-2215_SH-M08"
                },
                {
                    "repository": "PoC-in-GitHub · i-redbyte/android-badbinder-demo",
                    "author": "i-redbyte",
                    "first_seen": "2025-11-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "demo CVE-2019-2215 (Bad Binder) for Android Q",
                    "summary": "demo CVE-2019-2215 (Bad Binder) for Android Q",
                    "url": "https://github.com/i-redbyte/android-badbinder-demo"
                },
                {
                    "repository": "PoC-in-GitHub · wired0ut/CVE-2019-2215",
                    "author": "wired0ut",
                    "first_seen": "2026-04-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Full exploit for the Android vulnerability Bad Binder found in early Google Pixel phones.",
                    "summary": "Full exploit for the Android vulnerability Bad Binder found in early Google Pixel phones.",
                    "url": "https://github.com/wired0ut/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · mythicaltree/CVE-2019-2215",
                    "author": "mythicaltree",
                    "first_seen": "2026-06-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-2215 repository",
                    "summary": "",
                    "url": "https://github.com/mythicaltree/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · flipphoneguy/root-sonim-xp3800",
                    "author": "flipphoneguy",
                    "first_seen": "2026-06-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "app that ports CVE-2019-2215 to arm32 and mounts a su binary to /sbin with denylist + root app installer. firehose/Magisk guide included",
                    "summary": "app that ports CVE-2019-2215 to arm32 and mounts a su binary to /sbin with denylist + root app installer. firehose/Magisk guide included",
                    "url": "https://github.com/flipphoneguy/root-sonim-xp3800"
                },
                {
                    "repository": "PoC-in-GitHub · NESTle19/CVE-2019-2215",
                    "author": "NESTle19",
                    "first_seen": "2026-07-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-2215 repository",
                    "summary": "",
                    "url": "https://github.com/NESTle19/CVE-2019-2215"
                },
                {
                    "repository": "PoC-in-GitHub · 0xbinder/CVE_2019_2215",
                    "author": "0xbinder",
                    "first_seen": "2026-08-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A rewritten Proof-of-Concept / Local Privilege Escalation (LPE) exploit targeting CVE-2019-2215, a Use-After-Free vulnerability in the Android Binder driver.",
                    "summary": "A rewritten Proof-of-Concept / Local Privilege Escalation (LPE) exploit targeting CVE-2019-2215, a Use-After-Free vulnerability in the Android Binder driver.",
                    "url": "https://github.com/0xbinder/CVE_2019_2215"
                },
                {
                    "repository": "PoC-in-GitHub · Begitdj/cve-2019-2215-markw",
                    "author": "Begitdj",
                    "first_seen": "2026-08-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-2215 repository",
                    "summary": "",
                    "url": "https://github.com/Begitdj/cve-2019-2215-markw"
                },
                {
                    "repository": "PoC-in-GitHub · saaedimam/sony-bravia-root-toolkit",
                    "author": "saaedimam",
                    "first_seen": "2026-09-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-2215 & DirtyCOW exploit automation + post-root debloat + Magisk modules for Sony BRAVIA KDL-43W800C",
                    "summary": "CVE-2019-2215 & DirtyCOW exploit automation + post-root debloat + Magisk modules for Sony BRAVIA KDL-43W800C",
                    "url": "https://github.com/saaedimam/sony-bravia-root-toolkit"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/47463",
                "https://www.exploit-db.com/exploits/48129",
                "https://github.com/timwr/CVE-2019-2215",
                "https://github.com/kangtastic/cve-2019-2215",
                "https://github.com/ATorNinja/CVE-2019-2215",
                "https://github.com/LIznzn/CVE-2019-2215",
                "https://github.com/DimitriFourny/cve-2019-2215",
                "https://github.com/codecat007/CVE-2019-2215",
                "https://github.com/qre0ct/android-kernel-exploitation-ashfaq-CVE-2019-2215",
                "https://github.com/sharif-dev/AndroidKernelVulnerability",
                "https://github.com/c3r34lk1ll3r/CVE-2019-2215",
                "https://github.com/Byte-Master-101/CVE-2019-2215",
                "https://github.com/mufidmb38/CVE-2019-2215",
                "https://github.com/nicchongwb/Rootsmart-v2.0",
                "https://github.com/CrackerCat/Rootsmart-v2.0",
                "https://github.com/Enceka/cve-2019-2215-3.18",
                "https://github.com/elbiazo/CVE-2019-2215",
                "https://github.com/stevejubx/CVE-2019-2215",
                "https://github.com/willboka/CVE-2019-2215-HuaweiP20Lite",
                "https://github.com/mutur4/CVE-2019-2215",
                "https://github.com/R0rt1z2/huawei-unlock",
                "https://github.com/raymontag/CVE-2019-2215",
                "https://github.com/XiaozaYa/CVE-2019-2215",
                "https://github.com/llccd/TempRoot-Huawei",
                "https://github.com/0xbinder/android-kernel-exploitation-lab",
                "https://github.com/mouseos/cve-2019-2215_SH-M08",
                "https://github.com/i-redbyte/android-badbinder-demo",
                "https://github.com/wired0ut/CVE-2019-2215",
                "https://github.com/mythicaltree/CVE-2019-2215",
                "https://github.com/flipphoneguy/root-sonim-xp3800",
                "https://github.com/NESTle19/CVE-2019-2215",
                "https://github.com/0xbinder/CVE_2019_2215",
                "https://github.com/Begitdj/cve-2019-2215-markw",
                "https://github.com/saaedimam/sony-bravia-root-toolkit"
            ],
            "timeline": [
                {
                    "at": "2026-08-18T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2019-1215",
            "vendor": "Microsoft",
            "product": "Windows",
            "title": "Microsoft Windows Privilege Escalation Vulnerability",
            "summary": "Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges.",
            "updated_at": "2026-09-08T14:29:51Z",
            "published_at": "2026-09-08T14:29:51Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 147,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 47935",
                    "author": "bluefrostsec",
                    "first_seen": "2020-01-07",
                    "confidence": "High",
                    "title": "Microsoft Windows 10 (19H1 1901 x64) - 'ws2ifsl.sys' Use After Free Local Privilege Escalation (kASLR kCFG SMEP)",
                    "summary": "Microsoft Windows 10 (19H1 1901 x64) - 'ws2ifsl.sys' Use After Free Local Privilege Escalation (kASLR kCFG SMEP)",
                    "url": "https://www.exploit-db.com/exploits/47935",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2019-1215",
                    "summary": "Use-after-free in ws2ifsl.sys on Windows 10 19H1 x64 exploited for local privilege escalation.",
                    "what_happened": "Use-after-free in ws2ifsl.sys on Windows 10 19H1 x64 exploited for local privilege escalation.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BLUEFROSTSECURITY-CVE-2019-1215",
                        "https://kitploit.com/ru/tools/github/bluefrostsecurity/cve-2019-1215/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T19:03:27",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BLUEFROSTSECURITY-CVE-2019-1215"
                },
                {
                    "title": "Exploit for CVE-2019-1215",
                    "summary": "Use-after-free in ws2ifsl.sys on Windows 10 19H1 x64 exploited for local privilege escalation.",
                    "what_happened": "Use-after-free in ws2ifsl.sys on Windows 10 19H1 x64 exploited for local privilege escalation.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BLUEFROSTSECURITY-CVE-2019-1215",
                        "https://kitploit.com/ru/tools/github/bluefrostsecurity/cve-2019-1215/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T19:03:27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/bluefrostsecurity/cve-2019-1215/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/47935",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BLUEFROSTSECURITY-CVE-2019-1215",
                "https://kitploit.com/ru/tools/github/bluefrostsecurity/cve-2019-1215/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T14:29:51Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2019-1068",
            "vendor": "Microsoft",
            "product": "SQL Server",
            "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
            "summary": "Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.",
            "updated_at": "2026-08-25T22:00:00Z",
            "published_at": "2026-08-25T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "observed",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 48,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2019-0708",
            "vendor": "Microsoft",
            "product": "Remote Desktop Services",
            "title": "Microsoft Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.",
            "updated_at": "2026-08-23T22:00:00Z",
            "published_at": "2026-08-23T22:00:00Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 6124,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 46946",
                    "author": "n1xbyte",
                    "first_seen": "2019-05-30",
                    "confidence": "High",
                    "title": "Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service",
                    "summary": "Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service",
                    "url": "https://www.exploit-db.com/exploits/46946",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 47120",
                    "author": "RAMELLA Sebastien",
                    "first_seen": "2019-07-15",
                    "confidence": "High",
                    "title": "Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service (Metasploit)",
                    "summary": "Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/47120",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 47416",
                    "author": "Metasploit",
                    "first_seen": "2019-09-24",
                    "confidence": "High",
                    "title": "Microsoft Windows - BlueKeep RDP Remote Windows Kernel Use After Free (Metasploit)",
                    "summary": "Microsoft Windows - BlueKeep RDP Remote Windows Kernel Use After Free (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/47416",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 47683",
                    "author": "0xeb-bp",
                    "first_seen": "2019-11-19",
                    "confidence": "High",
                    "title": "Microsoft Windows 7 (x86) - 'BlueKeep' Remote Desktop Protocol (RDP) Remote Windows Kernel Use After Free",
                    "summary": "Microsoft Windows 7 (x86) - 'BlueKeep' Remote Desktop Protocol (RDP) Remote Windows Kernel Use After Free",
                    "url": "https://www.exploit-db.com/exploits/47683",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · hook-s3c/CVE-2019-0708-poc",
                    "author": "hook-s3c",
                    "first_seen": "2019-05-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 47,
                    "title": "proof of concept exploit for Microsoft Windows 7 and Server 2008 RDP vulnerability",
                    "summary": "proof of concept exploit for Microsoft Windows 7 and Server 2008 RDP vulnerability",
                    "url": "https://github.com/hook-s3c/CVE-2019-0708-poc"
                },
                {
                    "repository": "PoC-in-GitHub · SherlockSec/CVE-2019-0708",
                    "author": "SherlockSec",
                    "first_seen": "2019-05-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "A Win7 RDP exploit",
                    "summary": "A Win7 RDP exploit",
                    "url": "https://github.com/SherlockSec/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · yetiddbb/CVE-2019-0708-PoC",
                    "author": "yetiddbb",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708",
                    "summary": "CVE-2019-0708",
                    "url": "https://github.com/yetiddbb/CVE-2019-0708-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · p0p0p0/CVE-2019-0708-exploit",
                    "author": "p0p0p0",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 121,
                    "title": "CVE-2019-0708-exploit",
                    "summary": "CVE-2019-0708-exploit",
                    "url": "https://github.com/p0p0p0/CVE-2019-0708-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · rockmelodies/CVE-2019-0708-Exploit",
                    "author": "rockmelodies",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 31,
                    "title": "Using CVE-2019-0708 to Locally Promote Privileges in Windows 10 System",
                    "summary": "Using CVE-2019-0708 to Locally Promote Privileges in Windows 10 System",
                    "url": "https://github.com/rockmelodies/CVE-2019-0708-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · anquanscan/CVE-2019-0708",
                    "author": "anquanscan",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2019-0708   exp",
                    "summary": "CVE-2019-0708   exp",
                    "url": "https://github.com/anquanscan/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · temp-user-2014/CVE-2019-0708",
                    "author": "temp-user-2014",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708",
                    "summary": "CVE-2019-0708",
                    "url": "https://github.com/temp-user-2014/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · areusecure/CVE-2019-0708",
                    "author": "areusecure",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Proof of concept exploit for CVE-2019-0708",
                    "summary": "Proof of concept exploit for CVE-2019-0708",
                    "url": "https://github.com/areusecure/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · pry0cc/cve-2019-0708-2",
                    "author": "pry0cc",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Testing my new bot out",
                    "summary": "Testing my new bot out",
                    "url": "https://github.com/pry0cc/cve-2019-0708-2"
                },
                {
                    "repository": "PoC-in-GitHub · sbkcbig/CVE-2019-0708-EXPloit",
                    "author": "sbkcbig",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "POCexp:https://pan.baidu.com/s/184gN1tJVIOYqOjaezM_VsA 提取码:e2k8",
                    "summary": "POCexp:https://pan.baidu.com/s/184gN1tJVIOYqOjaezM_VsA 提取码:e2k8",
                    "url": "https://github.com/sbkcbig/CVE-2019-0708-EXPloit"
                },
                {
                    "repository": "PoC-in-GitHub · sbkcbig/CVE-2019-0708-EXPloit-3389",
                    "author": "sbkcbig",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "EXPloit-poc: https://pan.baidu.com/s/184gN1tJVIOYqOjaezM_VsA 提取码:e2k8",
                    "summary": "EXPloit-poc: https://pan.baidu.com/s/184gN1tJVIOYqOjaezM_VsA 提取码:e2k8",
                    "url": "https://github.com/sbkcbig/CVE-2019-0708-EXPloit-3389"
                },
                {
                    "repository": "PoC-in-GitHub · YSheldon/MS_T120",
                    "author": "YSheldon",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708",
                    "summary": "CVE-2019-0708",
                    "url": "https://github.com/YSheldon/MS_T120"
                },
                {
                    "repository": "PoC-in-GitHub · k8gege/CVE-2019-0708",
                    "author": "k8gege",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 388,
                    "title": "3389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check)",
                    "summary": "3389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check)",
                    "url": "https://github.com/k8gege/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · hotdog777714/RDS_CVE-2019-0708",
                    "author": "hotdog777714",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "exploit CVE-2019-0708  RDS",
                    "summary": "exploit CVE-2019-0708  RDS",
                    "url": "https://github.com/hotdog777714/RDS_CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · jiansiting/CVE-2019-0708",
                    "author": "jiansiting",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": "RDP POC",
                    "summary": "RDP POC",
                    "url": "https://github.com/jiansiting/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · NullByteSuiteDevs/CVE-2019-0708",
                    "author": "NullByteSuiteDevs",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "PoC exploit for BlueKeep (CVE-2019-0708)",
                    "summary": "PoC exploit for BlueKeep (CVE-2019-0708)",
                    "url": "https://github.com/NullByteSuiteDevs/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · thugcrowd/CVE-2019-0708",
                    "author": "thugcrowd",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "sup pry0cc :3",
                    "summary": "sup pry0cc :3",
                    "url": "https://github.com/thugcrowd/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · blacksunwen/CVE-2019-0708",
                    "author": "blacksunwen",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": "CVE-2019-0708",
                    "summary": "CVE-2019-0708",
                    "url": "https://github.com/blacksunwen/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · infenet/CVE-2019-0708",
                    "author": "infenet",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/infenet/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · n0auth/CVE-2019-0708",
                    "author": "n0auth",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "Totally legitimate",
                    "summary": "Totally legitimate",
                    "url": "https://github.com/n0auth/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · gildaaa/CVE-2019-0708",
                    "author": "gildaaa",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/gildaaa/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · HackerJ0e/CVE-2019-0708",
                    "author": "HackerJ0e",
                    "first_seen": "2019-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/HackerJ0e/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · syriusbughunt/CVE-2019-0708",
                    "author": "syriusbughunt",
                    "first_seen": "2019-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 39,
                    "title": "PoC about CVE-2019-0708 (RDP; Windows 7, Windows Server 2003, Windows Server 2008)",
                    "summary": "PoC about CVE-2019-0708 (RDP; Windows 7, Windows Server 2003, Windows Server 2008)",
                    "url": "https://github.com/syriusbughunt/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · Barry-McCockiner/CVE-2019-0708",
                    "author": "Barry-McCockiner",
                    "first_seen": "2019-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.",
                    "summary": "A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.",
                    "url": "https://github.com/Barry-McCockiner/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · ShadowBrokers-ExploitLeak/CVE-2019-0708",
                    "author": "ShadowBrokers-ExploitLeak",
                    "first_seen": "2019-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.",
                    "summary": "A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.",
                    "url": "https://github.com/ShadowBrokers-ExploitLeak/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · safly/CVE-2019-0708",
                    "author": "safly",
                    "first_seen": "2019-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708 demo",
                    "summary": "CVE-2019-0708 demo",
                    "url": "https://github.com/safly/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · Jaky5155/cve-2019-0708-exp",
                    "author": "Jaky5155",
                    "first_seen": "2019-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 30,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/Jaky5155/cve-2019-0708-exp"
                },
                {
                    "repository": "PoC-in-GitHub · fourtwizzy/CVE-2019-0708-Check-Device-Patch-Status",
                    "author": "fourtwizzy",
                    "first_seen": "2019-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 18,
                    "title": "Powershell script to run and determine if a specific device has been patched for CVE-2019-0708.  This checks to see if the termdd.sys file has been updated appropriate and is at a version level at or greater than the versions released in the 5/14/19 patches.",
                    "summary": "Powershell script to run and determine if a specific device has been patched for CVE-2019-0708.  This checks to see if the termdd.sys file has been updated appropriate and is at a version level at or greater than the versions released in the 5/14/19 patches.",
                    "url": "https://github.com/fourtwizzy/CVE-2019-0708-Check-Device-Patch-Status"
                },
                {
                    "repository": "PoC-in-GitHub · 303sec/CVE-2019-0708",
                    "author": "303sec",
                    "first_seen": "2019-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "POC for CVE-2019-0708",
                    "summary": "POC for CVE-2019-0708",
                    "url": "https://github.com/303sec/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · f8al/CVE-2019-0708-POC",
                    "author": "f8al",
                    "first_seen": "2019-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC for CVE-2019-0708",
                    "summary": "PoC for CVE-2019-0708",
                    "url": "https://github.com/f8al/CVE-2019-0708-POC"
                },
                {
                    "repository": "PoC-in-GitHub · blockchainguard/CVE-2019-0708",
                    "author": "blockchainguard",
                    "first_seen": "2019-05-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2019-0708漏洞MSF批量巡检插件",
                    "summary": "CVE-2019-0708漏洞MSF批量巡检插件",
                    "url": "https://github.com/blockchainguard/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · yushiro/CVE-2019-0708",
                    "author": "yushiro",
                    "first_seen": "2019-05-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "LOL",
                    "summary": "LOL",
                    "url": "https://github.com/yushiro/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · skyshell20082008/CVE-2019-0708-PoC-Hitting-Path",
                    "author": "skyshell20082008",
                    "first_seen": "2019-05-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "It's only hitting vulnerable path in termdd.sys!!! NOT DOS",
                    "summary": "It's only hitting vulnerable path in termdd.sys!!! NOT DOS",
                    "url": "https://github.com/skyshell20082008/CVE-2019-0708-PoC-Hitting-Path"
                },
                {
                    "repository": "PoC-in-GitHub · ttsite/CVE-2019-0708-",
                    "author": "ttsite",
                    "first_seen": "2019-05-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Announces fraud",
                    "summary": "Announces fraud",
                    "url": "https://github.com/ttsite/CVE-2019-0708-"
                },
                {
                    "repository": "PoC-in-GitHub · ttsite/CVE-2019-0708",
                    "author": "ttsite",
                    "first_seen": "2019-05-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Report fraud",
                    "summary": "Report fraud",
                    "url": "https://github.com/ttsite/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · biggerwing/CVE-2019-0708-poc",
                    "author": "biggerwing",
                    "first_seen": "2019-05-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 82,
                    "title": "CVE-2019-0708 远程代码执行漏洞批量检测",
                    "summary": "CVE-2019-0708 远程代码执行漏洞批量检测",
                    "url": "https://github.com/biggerwing/CVE-2019-0708-poc"
                },
                {
                    "repository": "PoC-in-GitHub · n1xbyte/CVE-2019-0708",
                    "author": "n1xbyte",
                    "first_seen": "2019-05-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 495,
                    "title": "dump",
                    "summary": "dump",
                    "url": "https://github.com/n1xbyte/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · freeide/CVE-2019-0708",
                    "author": "freeide",
                    "first_seen": "2019-05-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "High level exploit",
                    "summary": "High level exploit",
                    "url": "https://github.com/freeide/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · edvacco/CVE-2019-0708-POC",
                    "author": "edvacco",
                    "first_seen": "2019-05-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "根据360的程序，整的CVE-2019-0708批量检测",
                    "summary": "根据360的程序，整的CVE-2019-0708批量检测",
                    "url": "https://github.com/edvacco/CVE-2019-0708-POC"
                },
                {
                    "repository": "PoC-in-GitHub · pry0cc/BlueKeepTracker",
                    "author": "pry0cc",
                    "first_seen": "2019-05-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "My bot (badly written) to search and monitor cve-2019-0708 repositories",
                    "summary": "My bot (badly written) to search and monitor cve-2019-0708 repositories",
                    "url": "https://github.com/pry0cc/BlueKeepTracker"
                },
                {
                    "repository": "PoC-in-GitHub · zjw88282740/CVE-2019-0708-win7",
                    "author": "zjw88282740",
                    "first_seen": "2019-05-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/zjw88282740/CVE-2019-0708-win7"
                },
                {
                    "repository": "PoC-in-GitHub · victor0013/CVE-2019-0708",
                    "author": "victor0013",
                    "first_seen": "2019-05-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Scanner PoC for CVE-2019-0708 RDP RCE vuln",
                    "summary": "Scanner PoC for CVE-2019-0708 RDP RCE vuln",
                    "url": "https://github.com/victor0013/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · herhe/CVE-2019-0708poc",
                    "author": "herhe",
                    "first_seen": "2019-05-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "根据360Vulcan Team开发的CVE-2019-0708单个IP检测工具构造了个批量检测脚本而已",
                    "summary": "根据360Vulcan Team开发的CVE-2019-0708单个IP检测工具构造了个批量检测脚本而已",
                    "url": "https://github.com/herhe/CVE-2019-0708poc"
                },
                {
                    "repository": "PoC-in-GitHub · major203/cve-2019-0708-scan",
                    "author": "major203",
                    "first_seen": "2019-05-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/major203/cve-2019-0708-scan"
                },
                {
                    "repository": "PoC-in-GitHub · SugiB3o/Check-vuln-CVE-2019-0708",
                    "author": "SugiB3o",
                    "first_seen": "2019-05-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Check vuln CVE 2019-0708",
                    "summary": "Check vuln CVE 2019-0708",
                    "url": "https://github.com/SugiB3o/Check-vuln-CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · gobysec/CVE-2019-0708",
                    "author": "gobysec",
                    "first_seen": "2019-05-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "Goby support CVE-2019-0708 \"BlueKeep\" vulnerability check",
                    "summary": "Goby support CVE-2019-0708 \"BlueKeep\" vulnerability check",
                    "url": "https://github.com/gobysec/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · smallFunction/CVE-2019-0708-POC",
                    "author": "smallFunction",
                    "first_seen": "2019-05-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Working proof of concept for CVE-2019-0708, spawns remote shell.",
                    "summary": "Working proof of concept for CVE-2019-0708, spawns remote shell.",
                    "url": "https://github.com/smallFunction/CVE-2019-0708-POC"
                },
                {
                    "repository": "PoC-in-GitHub · freeide/CVE-2019-0708-PoC-Exploit",
                    "author": "freeide",
                    "first_seen": "2019-05-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708 PoC Exploit",
                    "summary": "CVE-2019-0708 PoC Exploit",
                    "url": "https://github.com/freeide/CVE-2019-0708-PoC-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · robertdavidgraham/rdpscan",
                    "author": "robertdavidgraham",
                    "first_seen": "2019-05-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 921,
                    "title": "A quick scanner for the CVE-2019-0708 \"BlueKeep\" vulnerability.",
                    "summary": "A quick scanner for the CVE-2019-0708 \"BlueKeep\" vulnerability.",
                    "url": "https://github.com/robertdavidgraham/rdpscan"
                },
                {
                    "repository": "PoC-in-GitHub · closethe/CVE-2019-0708-POC",
                    "author": "closethe",
                    "first_seen": "2019-05-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "cve-2019-0708 poc .",
                    "summary": "cve-2019-0708 poc .",
                    "url": "https://github.com/closethe/CVE-2019-0708-POC"
                },
                {
                    "repository": "PoC-in-GitHub · SQLDebugger/CVE-2019-0708-Tool",
                    "author": "SQLDebugger",
                    "first_seen": "2019-05-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "50 first stargazers will get get the tool via email",
                    "summary": "50 first stargazers will get get the tool via email",
                    "url": "https://github.com/SQLDebugger/CVE-2019-0708-Tool"
                },
                {
                    "repository": "PoC-in-GitHub · Leoid/CVE-2019-0708",
                    "author": "Leoid",
                    "first_seen": "2019-05-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 126,
                    "title": "Only Hitting PoC [Tested on Windows Server 2008 r2]",
                    "summary": "Only Hitting PoC [Tested on Windows Server 2008 r2]",
                    "url": "https://github.com/Leoid/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · ht0Ruial/CVE-2019-0708Poc-BatchScanning",
                    "author": "ht0Ruial",
                    "first_seen": "2019-05-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "基于360公开的无损检测工具的可直接在windows上运行的批量检测程序",
                    "summary": "基于360公开的无损检测工具的可直接在windows上运行的批量检测程序",
                    "url": "https://github.com/ht0Ruial/CVE-2019-0708Poc-BatchScanning"
                },
                {
                    "repository": "PoC-in-GitHub · oneoy/BlueKeep",
                    "author": "oneoy",
                    "first_seen": "2019-05-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708 bluekeep 漏洞检测",
                    "summary": "CVE-2019-0708 bluekeep 漏洞检测",
                    "url": "https://github.com/oneoy/BlueKeep"
                },
                {
                    "repository": "PoC-in-GitHub · infiniti-team/CVE-2019-0708",
                    "author": "infiniti-team",
                    "first_seen": "2019-05-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/infiniti-team/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · haishanzheng/CVE-2019-0708-generate-hosts",
                    "author": "haishanzheng",
                    "first_seen": "2019-05-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/haishanzheng/CVE-2019-0708-generate-hosts"
                },
                {
                    "repository": "PoC-in-GitHub · Ekultek/BlueKeep",
                    "author": "Ekultek",
                    "first_seen": "2019-05-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1182,
                    "title": "Proof of concept for CVE-2019-0708",
                    "summary": "Proof of concept for CVE-2019-0708",
                    "url": "https://github.com/Ekultek/BlueKeep"
                },
                {
                    "repository": "PoC-in-GitHub · UraSecTeam/CVE-2019-0708",
                    "author": "UraSecTeam",
                    "first_seen": "2019-05-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708",
                    "summary": "CVE-2019-0708",
                    "url": "https://github.com/UraSecTeam/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · Gh0st0ne/rdpscan-BlueKeep",
                    "author": "Gh0st0ne",
                    "first_seen": "2019-05-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A quick scanner for the CVE-2019-0708 \"BlueKeep\" vulnerability.",
                    "summary": "A quick scanner for the CVE-2019-0708 \"BlueKeep\" vulnerability.",
                    "url": "https://github.com/Gh0st0ne/rdpscan-BlueKeep"
                },
                {
                    "repository": "PoC-in-GitHub · algo7/bluekeep_CVE-2019-0708_poc_to_exploit",
                    "author": "algo7",
                    "first_seen": "2019-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 342,
                    "title": "An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits",
                    "summary": "An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits",
                    "url": "https://github.com/algo7/bluekeep_CVE-2019-0708_poc_to_exploit"
                },
                {
                    "repository": "PoC-in-GitHub · JasonLOU/CVE-2019-0708",
                    "author": "JasonLOU",
                    "first_seen": "2019-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/JasonLOU/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · AdministratorGithub/CVE-2019-0708",
                    "author": "AdministratorGithub",
                    "first_seen": "2019-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708批量蓝屏恶搞",
                    "summary": "CVE-2019-0708批量蓝屏恶搞",
                    "url": "https://github.com/AdministratorGithub/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · umarfarook882/CVE-2019-0708",
                    "author": "umarfarook882",
                    "first_seen": "2019-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 40,
                    "title": "CVE-2019-0708 - BlueKeep (RDP)",
                    "summary": "CVE-2019-0708 - BlueKeep (RDP)",
                    "url": "https://github.com/umarfarook882/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · HynekPetrak/detect_bluekeep.py",
                    "author": "HynekPetrak",
                    "first_seen": "2019-06-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 27,
                    "title": "Python script to detect bluekeep vulnerability (CVE-2019-0708) with TLS/SSL and x509 support",
                    "summary": "Python script to detect bluekeep vulnerability (CVE-2019-0708) with TLS/SSL and x509 support",
                    "url": "https://github.com/HynekPetrak/detect_bluekeep.py"
                },
                {
                    "repository": "PoC-in-GitHub · Pa55w0rd/CVE-2019-0708",
                    "author": "Pa55w0rd",
                    "first_seen": "2019-06-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "CVE-2019-0708批量检测",
                    "summary": "CVE-2019-0708批量检测",
                    "url": "https://github.com/Pa55w0rd/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · zoujialan/CVE-2019-0708-RCE",
                    "author": "zoujialan",
                    "first_seen": "2019-06-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708-RCE",
                    "summary": "CVE-2019-0708-RCE",
                    "url": "https://github.com/zoujialan/CVE-2019-0708-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · cream-sec/CVE-2019-0708-Msf--",
                    "author": "cream-sec",
                    "first_seen": "2019-06-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708-Msf-验证",
                    "summary": "CVE-2019-0708-Msf-验证",
                    "url": "https://github.com/cream-sec/CVE-2019-0708-Msf--"
                },
                {
                    "repository": "PoC-in-GitHub · ZhaoYukai/CVE-2019-0708",
                    "author": "ZhaoYukai",
                    "first_seen": "2019-06-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "蓝屏poc",
                    "summary": "蓝屏poc",
                    "url": "https://github.com/ZhaoYukai/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · ZhaoYukai/CVE-2019-0708-Batch-Blue-Screen",
                    "author": "ZhaoYukai",
                    "first_seen": "2019-06-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "改写某大佬写的0708蓝屏脚本 改为网段批量蓝屏",
                    "summary": "改写某大佬写的0708蓝屏脚本 改为网段批量蓝屏",
                    "url": "https://github.com/ZhaoYukai/CVE-2019-0708-Batch-Blue-Screen"
                },
                {
                    "repository": "PoC-in-GitHub · wdfcc/CVE-2019-0708",
                    "author": "wdfcc",
                    "first_seen": "2019-06-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/wdfcc/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · cvencoder/cve-2019-0708",
                    "author": "cvencoder",
                    "first_seen": "2019-06-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "POC CVE-2019-0708 with python script!",
                    "summary": "POC CVE-2019-0708 with python script!",
                    "url": "https://github.com/cvencoder/cve-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · ze0r/CVE-2019-0708-exp",
                    "author": "ze0r",
                    "first_seen": "2019-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/ze0r/CVE-2019-0708-exp"
                },
                {
                    "repository": "PoC-in-GitHub · mekhalleh/cve-2019-0708",
                    "author": "mekhalleh",
                    "first_seen": "2019-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 23,
                    "title": "Metasploit module for massive Denial of Service using #Bluekeep vector.",
                    "summary": "Metasploit module for massive Denial of Service using #Bluekeep vector.",
                    "url": "https://github.com/mekhalleh/cve-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · cve-2019-0708-poc/cve-2019-0708",
                    "author": "cve-2019-0708-poc",
                    "first_seen": "2019-07-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 18,
                    "title": "CVE-2019-0708 Exploit Tool",
                    "summary": "CVE-2019-0708 Exploit Tool",
                    "url": "https://github.com/cve-2019-0708-poc/cve-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · benhe119/bluekeepscan",
                    "author": "benhe119",
                    "first_seen": "2019-07-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708",
                    "summary": "CVE-2019-0708",
                    "url": "https://github.com/benhe119/bluekeepscan"
                },
                {
                    "repository": "PoC-in-GitHub · andripwn/CVE-2019-0708",
                    "author": "andripwn",
                    "first_seen": "2019-07-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Scanner PoC for CVE-2019-0708 RDP RCE vuln",
                    "summary": "Scanner PoC for CVE-2019-0708 RDP RCE vuln",
                    "url": "https://github.com/andripwn/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · 0xeb-bp/bluekeep",
                    "author": "0xeb-bp",
                    "first_seen": "2019-07-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 293,
                    "title": "Public work for CVE-2019-0708",
                    "summary": "Public work for CVE-2019-0708",
                    "url": "https://github.com/0xeb-bp/bluekeep"
                },
                {
                    "repository": "PoC-in-GitHub · ntkernel0/CVE-2019-0708",
                    "author": "ntkernel0",
                    "first_seen": "2019-07-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "收集网上CVE-2018-0708的poc和exp(目前没有找到exp)",
                    "summary": "收集网上CVE-2018-0708的poc和exp(目前没有找到exp)",
                    "url": "https://github.com/ntkernel0/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · dorkerdevil/Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708-",
                    "author": "dorkerdevil",
                    "first_seen": "2019-08-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 123,
                    "title": "rce exploit , made to work with pocsuite3",
                    "summary": "rce exploit , made to work with pocsuite3",
                    "url": "https://github.com/dorkerdevil/Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708-"
                },
                {
                    "repository": "PoC-in-GitHub · turingcompl33t/bluekeep",
                    "author": "turingcompl33t",
                    "first_seen": "2019-08-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Research Regarding CVE-2019-0708.",
                    "summary": "Research Regarding CVE-2019-0708.",
                    "url": "https://github.com/turingcompl33t/bluekeep"
                },
                {
                    "repository": "PoC-in-GitHub · skommando/CVE-2019-0708",
                    "author": "skommando",
                    "first_seen": "2019-09-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2019-0708 BlueKeep漏洞批量扫描工具和POC，暂时只有蓝屏。",
                    "summary": "CVE-2019-0708 BlueKeep漏洞批量扫描工具和POC，暂时只有蓝屏。",
                    "url": "https://github.com/skommando/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · RickGeex/msf-module-CVE-2019-0708",
                    "author": "RickGeex",
                    "first_seen": "2019-09-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "Metasploit module for CVE-2019-0708 (BlueKeep) - https://github.com/rapid7/metasploit-framework/tree/5a0119b04309c8e61b44763ac08811cd3ecbbf8d/modules/exploits/windows/rdp",
                    "summary": "Metasploit module for CVE-2019-0708 (BlueKeep) - https://github.com/rapid7/metasploit-framework/tree/5a0119b04309c8e61b44763ac08811cd3ecbbf8d/modules/exploits/windows/rdp",
                    "url": "https://github.com/RickGeex/msf-module-CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · wqsemc/CVE-2019-0708",
                    "author": "wqsemc",
                    "first_seen": "2019-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "initial exploit for CVE-2019-0708, BlueKeep CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free  The RDP termdd.sys driver improperly handles binds to internal-only channel MS_T120, allowing a malformed Disconnect Provider Indication message to cause use-after-free. With a controllable data/size remote nonpaged pool spray, an indirect call gadget of the freed channel is used to achieve arbitrary code execution.",
                    "summary": "initial exploit for CVE-2019-0708, BlueKeep CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free  The RDP termdd.sys driver improperly handles binds to internal-only channel MS_T120, allowing a malformed Disconnect Provider Indication message to cause use-after-free. With a controllable data/size remote nonpaged pool spray, an indirect call gadget of the freed channel is used to achieve arbitrary code execution.",
                    "url": "https://github.com/wqsemc/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · FrostsaberX/CVE-2019-0708",
                    "author": "FrostsaberX",
                    "first_seen": "2019-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2019-0708 With Metasploit-Framework Exploit",
                    "summary": "CVE-2019-0708 With Metasploit-Framework Exploit",
                    "url": "https://github.com/FrostsaberX/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · 0x6b7966/CVE-2019-0708-RCE",
                    "author": "0x6b7966",
                    "first_seen": "2019-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708 RCE远程代码执行getshell教程",
                    "summary": "CVE-2019-0708 RCE远程代码执行getshell教程",
                    "url": "https://github.com/0x6b7966/CVE-2019-0708-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · qing-root/CVE-2019-0708-EXP-MSF-",
                    "author": "qing-root",
                    "first_seen": "2019-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "CVE-2019-0708-EXP(MSF)  Vulnerability exploit program for cve-2019-0708",
                    "summary": "CVE-2019-0708-EXP(MSF)  Vulnerability exploit program for cve-2019-0708",
                    "url": "https://github.com/qing-root/CVE-2019-0708-EXP-MSF-"
                },
                {
                    "repository": "PoC-in-GitHub · distance-vector/CVE-2019-0708",
                    "author": "distance-vector",
                    "first_seen": "2019-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/distance-vector/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · 0xFlag/CVE-2019-0708-test",
                    "author": "0xFlag",
                    "first_seen": "2019-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708 C#验证漏洞",
                    "summary": "CVE-2019-0708 C#验证漏洞",
                    "url": "https://github.com/0xFlag/CVE-2019-0708-test"
                },
                {
                    "repository": "PoC-in-GitHub · 1aa87148377/CVE-2019-0708",
                    "author": "1aa87148377",
                    "first_seen": "2019-09-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/1aa87148377/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · coolboy4me/cve-2019-0708_bluekeep_rce",
                    "author": "coolboy4me",
                    "first_seen": "2019-09-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 75,
                    "title": "it works on xp (all version sp2 sp3)",
                    "summary": "it works on xp (all version sp2 sp3)",
                    "url": "https://github.com/coolboy4me/cve-2019-0708_bluekeep_rce"
                },
                {
                    "repository": "PoC-in-GitHub · Cyb0r9/ispy",
                    "author": "Cyb0r9",
                    "first_seen": "2019-09-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 245,
                    "title": "ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )",
                    "summary": "ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )",
                    "url": "https://github.com/Cyb0r9/ispy"
                },
                {
                    "repository": "PoC-in-GitHub · ulisesrc/-2-CVE-2019-0708",
                    "author": "ulisesrc",
                    "first_seen": "2019-11-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/ulisesrc/-2-CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · worawit/CVE-2019-0708",
                    "author": "worawit",
                    "first_seen": "2019-12-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 109,
                    "title": "CVE-2019-0708 (BlueKeep)",
                    "summary": "CVE-2019-0708 (BlueKeep)",
                    "url": "https://github.com/worawit/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · Ameg-yag/Wincrash",
                    "author": "Ameg-yag",
                    "first_seen": "2019-12-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Mass exploit for CVE-2019-0708",
                    "summary": "Mass exploit for CVE-2019-0708",
                    "url": "https://github.com/Ameg-yag/Wincrash"
                },
                {
                    "repository": "PoC-in-GitHub · cbwang505/CVE-2019-0708-EXP-Windows",
                    "author": "cbwang505",
                    "first_seen": "2020-01-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 317,
                    "title": "CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell",
                    "summary": "CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell",
                    "url": "https://github.com/cbwang505/CVE-2019-0708-EXP-Windows"
                },
                {
                    "repository": "PoC-in-GitHub · eastmountyxz/CVE-2019-0708-Windows",
                    "author": "eastmountyxz",
                    "first_seen": "2020-02-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "这篇文章将分享Windows远程桌面服务漏洞（CVE-2019-0708），并详细讲解该漏洞及防御措施。作者作为网络安全的小白，分享一些自学基础教程给大家，主要是关于安全工具和实践操作的在线笔记，希望您们喜欢。同时，更希望您能与我一起操作和进步，后续将深入学习网络安全和系统安全知识并分享相关实验。总之，希望该系列文章对博友有所帮助，写文不易，大神们不喜勿喷，谢谢！",
                    "summary": "这篇文章将分享Windows远程桌面服务漏洞（CVE-2019-0708），并详细讲解该漏洞及防御措施。作者作为网络安全的小白，分享一些自学基础教程给大家，主要是关于安全工具和实践操作的在线笔记，希望您们喜欢。同时，更希望您能与我一起操作和进步，后续将深入学习网络安全和系统安全知识并分享相关实验。总之，希望该系列文章对博友有所帮助，写文不易，大神们不喜勿喷，谢谢！",
                    "url": "https://github.com/eastmountyxz/CVE-2019-0708-Windows"
                },
                {
                    "repository": "PoC-in-GitHub · RICSecLab/CVE-2019-0708",
                    "author": "RICSecLab",
                    "first_seen": "2020-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 149,
                    "title": "CVE-2019-0708 (BlueKeep) proof of concept allowing pre-auth RCE on Windows7",
                    "summary": "CVE-2019-0708 (BlueKeep) proof of concept allowing pre-auth RCE on Windows7",
                    "url": "https://github.com/RICSecLab/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · JSec1337/Scanner-CVE-2019-0708",
                    "author": "JSec1337",
                    "first_seen": "2020-03-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Scanner CVE-2019-0708",
                    "summary": "Scanner CVE-2019-0708",
                    "url": "https://github.com/JSec1337/Scanner-CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · nochemax/bLuEkEeP-GUI",
                    "author": "nochemax",
                    "first_seen": "2020-05-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "vulnerabilidad CVE-2019-0708 testing y explotacion",
                    "summary": "vulnerabilidad CVE-2019-0708 testing y explotacion",
                    "url": "https://github.com/nochemax/bLuEkEeP-GUI"
                },
                {
                    "repository": "PoC-in-GitHub · AaronCaiii/CVE-2019-0708-POC",
                    "author": "AaronCaiii",
                    "first_seen": "2020-11-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/AaronCaiii/CVE-2019-0708-POC"
                },
                {
                    "repository": "PoC-in-GitHub · DeathStroke-source/Mass-scanner-for-CVE-2019-0708-RDP-RCE-Exploit",
                    "author": "DeathStroke-source",
                    "first_seen": "2020-12-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Scan through given ip list",
                    "summary": "Scan through given ip list",
                    "url": "https://github.com/DeathStroke-source/Mass-scanner-for-CVE-2019-0708-RDP-RCE-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · ryan-ally/rdp0708scanner",
                    "author": "ryan-ally",
                    "first_seen": "2020-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "cve-2019-0708 vulnerablility scanner",
                    "summary": "cve-2019-0708 vulnerablility scanner",
                    "url": "https://github.com/ryan-ally/rdp0708scanner"
                },
                {
                    "repository": "PoC-in-GitHub · sezayi1972/CVE-2019-0708",
                    "author": "sezayi1972",
                    "first_seen": "2021-04-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708 Exploit",
                    "summary": "CVE-2019-0708 Exploit",
                    "url": "https://github.com/sezayi1972/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · CircuitSoul/CVE-2019-0708",
                    "author": "CircuitSoul",
                    "first_seen": "2021-06-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "POC-CVE-2019-0708",
                    "summary": "POC-CVE-2019-0708",
                    "url": "https://github.com/CircuitSoul/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · pywc/CVE-2019-0708",
                    "author": "pywc",
                    "first_seen": "2021-06-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/pywc/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · bibo318/kali-CVE-2019-0708-lab",
                    "author": "bibo318",
                    "first_seen": "2021-10-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/bibo318/kali-CVE-2019-0708-lab"
                },
                {
                    "repository": "PoC-in-GitHub · lisinan988/CVE-2019-0708-scan",
                    "author": "lisinan988",
                    "first_seen": "2021-11-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/lisinan988/CVE-2019-0708-scan"
                },
                {
                    "repository": "PoC-in-GitHub · offensity/CVE-2019-0708",
                    "author": "offensity",
                    "first_seen": "2021-12-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/offensity/CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · Ravaan21/Bluekeep-Hunter",
                    "author": "Ravaan21",
                    "first_seen": "2022-09-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2019-0708, A tool which mass hunts for bluekeep vulnerability for exploitation.",
                    "summary": "CVE-2019-0708, A tool which mass hunts for bluekeep vulnerability for exploitation.",
                    "url": "https://github.com/Ravaan21/Bluekeep-Hunter"
                },
                {
                    "repository": "PoC-in-GitHub · davidfortytwo/bluekeep",
                    "author": "davidfortytwo",
                    "first_seen": "2023-03-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Checker and exploit for Bluekeep CVE-2019-0708 vulnerability",
                    "summary": "Checker and exploit for Bluekeep CVE-2019-0708 vulnerability",
                    "url": "https://github.com/davidfortytwo/bluekeep"
                },
                {
                    "repository": "PoC-in-GitHub · tranqtruong/Detect-BlueKeep",
                    "author": "tranqtruong",
                    "first_seen": "2023-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)",
                    "summary": "a simple tool to detect the exploitation of BlueKeep vulnerability (CVE-2019-0708)",
                    "url": "https://github.com/tranqtruong/Detect-BlueKeep"
                },
                {
                    "repository": "PoC-in-GitHub · rasan2001/Microsoft-Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708",
                    "author": "rasan2001",
                    "first_seen": "2024-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/rasan2001/Microsoft-Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708"
                },
                {
                    "repository": "PoC-in-GitHub · adyanamul/Remote-Code-Execution-RCE-Exploit-BlueKeep-CVE-2019-0708-PoC",
                    "author": "adyanamul",
                    "first_seen": "2024-06-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/adyanamul/Remote-Code-Execution-RCE-Exploit-BlueKeep-CVE-2019-0708-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · denuwanjayasekara/CVE-Exploitation-Reports",
                    "author": "denuwanjayasekara",
                    "first_seen": "2024-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708",
                    "summary": "CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708",
                    "url": "https://github.com/denuwanjayasekara/CVE-Exploitation-Reports"
                },
                {
                    "repository": "PoC-in-GitHub · hualy13/CVE-2019-0708-Check",
                    "author": "hualy13",
                    "first_seen": "2024-10-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/hualy13/CVE-2019-0708-Check"
                },
                {
                    "repository": "PoC-in-GitHub · isabelacostaz/CVE-2019-0708-POC",
                    "author": "isabelacostaz",
                    "first_seen": "2025-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/isabelacostaz/CVE-2019-0708-POC"
                },
                {
                    "repository": "PoC-in-GitHub · GopeshKachhadiya/Windows-2",
                    "author": "GopeshKachhadiya",
                    "first_seen": "2026-01-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A hands-on Windows 7 lab designed to demonstrate the real-world impact of the BlueKeep (CVE-2019-0708) vulnerability through practical exploitation and security analysis.",
                    "summary": "A hands-on Windows 7 lab designed to demonstrate the real-world impact of the BlueKeep (CVE-2019-0708) vulnerability through practical exploitation and security analysis.",
                    "url": "https://github.com/GopeshKachhadiya/Windows-2"
                },
                {
                    "repository": "PoC-in-GitHub · emmadej1234/bluekeep-metasploit-lab-project",
                    "author": "emmadej1234",
                    "first_seen": "2026-04-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploiting BlueKeep (CVE-2019-0708) on Windows 7 using Metasploit",
                    "summary": "Exploiting BlueKeep (CVE-2019-0708) on Windows 7 using Metasploit",
                    "url": "https://github.com/emmadej1234/bluekeep-metasploit-lab-project"
                },
                {
                    "repository": "PoC-in-GitHub · Ayomide-29/bluekeep_metasploit_practice",
                    "author": "Ayomide-29",
                    "first_seen": "2026-04-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploiting bluekeep (CVE-2019-0708) on windows 7 using metasplotable",
                    "summary": "Exploiting bluekeep (CVE-2019-0708) on windows 7 using metasplotable",
                    "url": "https://github.com/Ayomide-29/bluekeep_metasploit_practice"
                },
                {
                    "repository": "PoC-in-GitHub · Nweks/Bluekeep-Metasploit-Lab-Project",
                    "author": "Nweks",
                    "first_seen": "2026-04-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploiting Bluekeep (CVE-2019-0708) on windows 7 using metasploit (Esucational lab)",
                    "summary": "Exploiting Bluekeep (CVE-2019-0708) on windows 7 using metasploit (Esucational lab)",
                    "url": "https://github.com/Nweks/Bluekeep-Metasploit-Lab-Project"
                },
                {
                    "repository": "PoC-in-GitHub · Mohaimenul370/Perform-an-RDP-exploitation-using-the-BlueKeep-vulnerability-CVE-2019-0708-on-Windows",
                    "author": "Mohaimenul370",
                    "first_seen": "2026-08-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2019-0708 repository",
                    "summary": "",
                    "url": "https://github.com/Mohaimenul370/Perform-an-RDP-exploitation-using-the-BlueKeep-vulnerability-CVE-2019-0708-on-Windows"
                },
                {
                    "repository": "PoC-in-GitHub · SebasPV27/Explotacion-RCE-Pentesting-BlueKeep-CVE-2019-0708-",
                    "author": "SebasPV27",
                    "first_seen": "2026-08-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Demostración práctica y bitácora técnica de explotación de BlueKeep (CVE-2019-0708) en RDP usando Nmap y Metasploit, documentando la resolución de errores en el entorno virtual.",
                    "summary": "Demostración práctica y bitácora técnica de explotación de BlueKeep (CVE-2019-0708) en RDP usando Nmap y Metasploit, documentando la resolución de errores en el entorno virtual.",
                    "url": "https://github.com/SebasPV27/Explotacion-RCE-Pentesting-BlueKeep-CVE-2019-0708-"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-11T18:30:42+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2019-0708 exploit",
                    "summary": "Exploit for CVE-2019-0708. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-PA55W0RD-CVE-2019-0708"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-14T18:32:06+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2019-0708 exploit",
                    "summary": "Exploit for CVE-2019-0708. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREEIDE-CVE-2019-0708"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-15T08:29:18+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2019-0708 exploit",
                    "summary": "Exploit for CVE-2019-0708. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZHAOYUKAI-CVE-2019-0708"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/46946",
                "https://www.exploit-db.com/exploits/47120",
                "https://www.exploit-db.com/exploits/47416",
                "https://www.exploit-db.com/exploits/47683",
                "https://github.com/hook-s3c/CVE-2019-0708-poc",
                "https://github.com/SherlockSec/CVE-2019-0708",
                "https://github.com/yetiddbb/CVE-2019-0708-PoC",
                "https://github.com/p0p0p0/CVE-2019-0708-exploit",
                "https://github.com/rockmelodies/CVE-2019-0708-Exploit",
                "https://github.com/anquanscan/CVE-2019-0708",
                "https://github.com/temp-user-2014/CVE-2019-0708",
                "https://github.com/areusecure/CVE-2019-0708",
                "https://github.com/pry0cc/cve-2019-0708-2",
                "https://github.com/sbkcbig/CVE-2019-0708-EXPloit",
                "https://github.com/sbkcbig/CVE-2019-0708-EXPloit-3389",
                "https://github.com/YSheldon/MS_T120",
                "https://github.com/k8gege/CVE-2019-0708",
                "https://github.com/hotdog777714/RDS_CVE-2019-0708",
                "https://github.com/jiansiting/CVE-2019-0708",
                "https://github.com/NullByteSuiteDevs/CVE-2019-0708",
                "https://github.com/thugcrowd/CVE-2019-0708",
                "https://github.com/blacksunwen/CVE-2019-0708",
                "https://github.com/infenet/CVE-2019-0708",
                "https://github.com/n0auth/CVE-2019-0708",
                "https://github.com/gildaaa/CVE-2019-0708",
                "https://github.com/HackerJ0e/CVE-2019-0708",
                "https://github.com/syriusbughunt/CVE-2019-0708",
                "https://github.com/Barry-McCockiner/CVE-2019-0708",
                "https://github.com/ShadowBrokers-ExploitLeak/CVE-2019-0708",
                "https://github.com/safly/CVE-2019-0708",
                "https://github.com/Jaky5155/cve-2019-0708-exp",
                "https://github.com/fourtwizzy/CVE-2019-0708-Check-Device-Patch-Status",
                "https://github.com/303sec/CVE-2019-0708",
                "https://github.com/f8al/CVE-2019-0708-POC",
                "https://github.com/blockchainguard/CVE-2019-0708",
                "https://github.com/yushiro/CVE-2019-0708",
                "https://github.com/skyshell20082008/CVE-2019-0708-PoC-Hitting-Path",
                "https://github.com/ttsite/CVE-2019-0708-",
                "https://github.com/ttsite/CVE-2019-0708",
                "https://github.com/biggerwing/CVE-2019-0708-poc",
                "https://github.com/n1xbyte/CVE-2019-0708",
                "https://github.com/freeide/CVE-2019-0708",
                "https://github.com/edvacco/CVE-2019-0708-POC",
                "https://github.com/pry0cc/BlueKeepTracker",
                "https://github.com/zjw88282740/CVE-2019-0708-win7",
                "https://github.com/victor0013/CVE-2019-0708",
                "https://github.com/herhe/CVE-2019-0708poc",
                "https://github.com/major203/cve-2019-0708-scan",
                "https://github.com/SugiB3o/Check-vuln-CVE-2019-0708",
                "https://github.com/gobysec/CVE-2019-0708",
                "https://github.com/smallFunction/CVE-2019-0708-POC",
                "https://github.com/freeide/CVE-2019-0708-PoC-Exploit",
                "https://github.com/robertdavidgraham/rdpscan",
                "https://github.com/closethe/CVE-2019-0708-POC",
                "https://github.com/SQLDebugger/CVE-2019-0708-Tool",
                "https://github.com/Leoid/CVE-2019-0708",
                "https://github.com/ht0Ruial/CVE-2019-0708Poc-BatchScanning",
                "https://github.com/oneoy/BlueKeep",
                "https://github.com/infiniti-team/CVE-2019-0708",
                "https://github.com/haishanzheng/CVE-2019-0708-generate-hosts",
                "https://github.com/Ekultek/BlueKeep",
                "https://github.com/UraSecTeam/CVE-2019-0708",
                "https://github.com/Gh0st0ne/rdpscan-BlueKeep",
                "https://github.com/algo7/bluekeep_CVE-2019-0708_poc_to_exploit",
                "https://github.com/JasonLOU/CVE-2019-0708",
                "https://github.com/AdministratorGithub/CVE-2019-0708",
                "https://github.com/umarfarook882/CVE-2019-0708",
                "https://github.com/HynekPetrak/detect_bluekeep.py",
                "https://github.com/Pa55w0rd/CVE-2019-0708",
                "https://github.com/zoujialan/CVE-2019-0708-RCE",
                "https://github.com/cream-sec/CVE-2019-0708-Msf--",
                "https://github.com/ZhaoYukai/CVE-2019-0708",
                "https://github.com/ZhaoYukai/CVE-2019-0708-Batch-Blue-Screen",
                "https://github.com/wdfcc/CVE-2019-0708",
                "https://github.com/cvencoder/cve-2019-0708",
                "https://github.com/ze0r/CVE-2019-0708-exp",
                "https://github.com/mekhalleh/cve-2019-0708",
                "https://github.com/cve-2019-0708-poc/cve-2019-0708",
                "https://github.com/benhe119/bluekeepscan",
                "https://github.com/andripwn/CVE-2019-0708",
                "https://github.com/0xeb-bp/bluekeep",
                "https://github.com/ntkernel0/CVE-2019-0708",
                "https://github.com/dorkerdevil/Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708-",
                "https://github.com/turingcompl33t/bluekeep",
                "https://github.com/skommando/CVE-2019-0708",
                "https://github.com/RickGeex/msf-module-CVE-2019-0708",
                "https://github.com/wqsemc/CVE-2019-0708",
                "https://github.com/FrostsaberX/CVE-2019-0708",
                "https://github.com/0x6b7966/CVE-2019-0708-RCE",
                "https://github.com/qing-root/CVE-2019-0708-EXP-MSF-",
                "https://github.com/distance-vector/CVE-2019-0708",
                "https://github.com/0xFlag/CVE-2019-0708-test",
                "https://github.com/1aa87148377/CVE-2019-0708",
                "https://github.com/coolboy4me/cve-2019-0708_bluekeep_rce",
                "https://github.com/Cyb0r9/ispy",
                "https://github.com/ulisesrc/-2-CVE-2019-0708",
                "https://github.com/worawit/CVE-2019-0708",
                "https://github.com/Ameg-yag/Wincrash",
                "https://github.com/cbwang505/CVE-2019-0708-EXP-Windows",
                "https://github.com/eastmountyxz/CVE-2019-0708-Windows",
                "https://github.com/RICSecLab/CVE-2019-0708",
                "https://github.com/JSec1337/Scanner-CVE-2019-0708",
                "https://github.com/nochemax/bLuEkEeP-GUI",
                "https://github.com/AaronCaiii/CVE-2019-0708-POC",
                "https://github.com/DeathStroke-source/Mass-scanner-for-CVE-2019-0708-RDP-RCE-Exploit",
                "https://github.com/ryan-ally/rdp0708scanner",
                "https://github.com/sezayi1972/CVE-2019-0708",
                "https://github.com/CircuitSoul/CVE-2019-0708",
                "https://github.com/pywc/CVE-2019-0708",
                "https://github.com/bibo318/kali-CVE-2019-0708-lab",
                "https://github.com/lisinan988/CVE-2019-0708-scan",
                "https://github.com/offensity/CVE-2019-0708",
                "https://github.com/Ravaan21/Bluekeep-Hunter",
                "https://github.com/davidfortytwo/bluekeep",
                "https://github.com/tranqtruong/Detect-BlueKeep",
                "https://github.com/rasan2001/Microsoft-Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708",
                "https://github.com/adyanamul/Remote-Code-Execution-RCE-Exploit-BlueKeep-CVE-2019-0708-PoC",
                "https://github.com/denuwanjayasekara/CVE-Exploitation-Reports",
                "https://github.com/hualy13/CVE-2019-0708-Check",
                "https://github.com/isabelacostaz/CVE-2019-0708-POC",
                "https://github.com/GopeshKachhadiya/Windows-2",
                "https://github.com/emmadej1234/bluekeep-metasploit-lab-project",
                "https://github.com/Ayomide-29/bluekeep_metasploit_practice",
                "https://github.com/Nweks/Bluekeep-Metasploit-Lab-Project",
                "https://github.com/Mohaimenul370/Perform-an-RDP-exploitation-using-the-BlueKeep-vulnerability-CVE-2019-0708-on-Windows",
                "https://github.com/SebasPV27/Explotacion-RCE-Pentesting-BlueKeep-CVE-2019-0708-",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-PA55W0RD-CVE-2019-0708",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FREEIDE-CVE-2019-0708",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ZHAOYUKAI-CVE-2019-0708"
            ],
            "timeline": [
                {
                    "at": "2026-08-23T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2018-1000035",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
            "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
            "updated_at": "2026-09-04T19:43:05Z",
            "published_at": "2026-09-04T19:43:05Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 47,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
                    "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                        "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T21:43:05",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK"
                },
                {
                    "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
                    "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                        "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T21:43:05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T19:43:05Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2018-20062",
            "vendor": "ThinkPHP",
            "product": "noneCms",
            "title": "ThinkPHP \"noneCms\" Remote Code Execution Vulnerability",
            "summary": "ThinkPHP \"noneCms\" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.",
            "updated_at": "2026-09-09T22:00:00Z",
            "published_at": "2026-09-09T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 182,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "ThinkPHP \"noneCms\" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 48333",
                    "author": "Metasploit",
                    "first_seen": "2020-04-16",
                    "confidence": "High",
                    "title": "ThinkPHP - Multiple PHP Injection RCEs (Metasploit)",
                    "summary": "ThinkPHP - Multiple PHP Injection RCEs (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/48333",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · NS-Sp4ce/thinkphp5.XRce",
                    "author": "NS-Sp4ce",
                    "first_seen": "2019-03-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "thinkphp5.*Rce CVE-2018-20062",
                    "summary": "thinkphp5.*Rce CVE-2018-20062",
                    "url": "https://github.com/NS-Sp4ce/thinkphp5.XRce"
                },
                {
                    "repository": "PoC-in-GitHub · yilin1203/CVE-2018-20062",
                    "author": "yilin1203",
                    "first_seen": "2022-11-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2018-20062 repository",
                    "summary": "",
                    "url": "https://github.com/yilin1203/CVE-2018-20062"
                },
                {
                    "repository": "PoC-in-GitHub · shenhui35/RedArrow",
                    "author": "shenhui35",
                    "first_seen": "2025-09-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "RedArrow3.2 是一款用于渗透测试ThinkPHP 5.0.23 远程命令执行漏洞(CVE-2018-20062)的图形化工具。",
                    "summary": "RedArrow3.2 是一款用于渗透测试ThinkPHP 5.0.23 远程命令执行漏洞(CVE-2018-20062)的图形化工具。",
                    "url": "https://github.com/shenhui35/RedArrow"
                },
                {
                    "repository": "PoC-in-GitHub · Jasper2018/CVE-2018-20062",
                    "author": "Jasper2018",
                    "first_seen": "2026-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-20062 repository",
                    "summary": "",
                    "url": "https://github.com/Jasper2018/CVE-2018-20062"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/48333",
                "https://github.com/NS-Sp4ce/thinkphp5.XRce",
                "https://github.com/yilin1203/CVE-2018-20062",
                "https://github.com/shenhui35/RedArrow",
                "https://github.com/Jasper2018/CVE-2018-20062"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2018-19052",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for cve-2018-19052 CVE-2018-19052 CVE-2022-19052",
            "summary": "Path traversal in mod_alias enabling directory listing one level above the alias destination.",
            "updated_at": "2026-09-04T07:09:19Z",
            "published_at": "2026-09-04T07:09:19Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 55,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Path traversal in mod_alias enabling directory listing one level above the alias destination.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for cve-2018-19052 CVE-2018-19052 CVE-2022-19052",
                    "summary": "Path traversal in mod_alias enabling directory listing one level above the alias destination.",
                    "what_happened": "Path traversal in mod_alias enabling directory listing one level above the alias destination.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IVERESK-CVE-2018-19052",
                        "https://kitploit.com/ru/tools/github/iveresk/cve-2018-19052/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T09:09:19",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IVERESK-CVE-2018-19052"
                },
                {
                    "title": "Exploit for cve-2018-19052 CVE-2018-19052 CVE-2022-19052",
                    "summary": "Path traversal in mod_alias enabling directory listing one level above the alias destination.",
                    "what_happened": "Path traversal in mod_alias enabling directory listing one level above the alias destination.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IVERESK-CVE-2018-19052",
                        "https://kitploit.com/ru/tools/github/iveresk/cve-2018-19052/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T09:09:19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/iveresk/cve-2018-19052/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IVERESK-CVE-2018-19052",
                "https://kitploit.com/ru/tools/github/iveresk/cve-2018-19052/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T07:09:19Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IVERESK-CVE-2018-19052"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2018-16987",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2018-16987 exploit",
            "summary": "Exploit for CVE-2018-16987. CVSS 7.2.",
            "updated_at": "2026-09-13T18:35:02Z",
            "published_at": "2026-09-13T18:35:02Z",
            "cvss": 7.2,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:35:02+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2018-16987 exploit",
                    "summary": "Exploit for CVE-2018-16987. CVSS 7.2.",
                    "cvss": 7.2,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GQUERE-CVE-2018-16987"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GQUERE-CVE-2018-16987"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:35:02Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-GQUERE-CVE-2018-16987"
                }
            ]
        },
        {
            "id": "CVE-2018-16763",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "fuel CMS 1.4.1 - Remote Code Execution (1)",
            "summary": "fuel CMS 1.4.1 - Remote Code Execution (1)",
            "updated_at": "2026-09-05T12:38:51Z",
            "published_at": "2026-09-05T12:38:51Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 460,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 47138",
                    "author": "0xd0ff9",
                    "first_seen": "2019-07-19",
                    "confidence": "High",
                    "title": "fuel CMS 1.4.1 - Remote Code Execution (1)",
                    "summary": "fuel CMS 1.4.1 - Remote Code Execution (1)",
                    "url": "https://www.exploit-db.com/exploits/47138",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 49487",
                    "author": "Alexandre ZANNI",
                    "first_seen": "2021-01-28",
                    "confidence": "High",
                    "title": "Fuel CMS 1.4.1 - Remote Code Execution (2)",
                    "summary": "Fuel CMS 1.4.1 - Remote Code Execution (2)",
                    "url": "https://www.exploit-db.com/exploits/49487",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 50477",
                    "author": "Padsala Trushal",
                    "first_seen": "2021-11-03",
                    "confidence": "High",
                    "title": "Fuel CMS 1.4.1 - Remote Code Execution (3)",
                    "summary": "Fuel CMS 1.4.1 - Remote Code Execution (3)",
                    "url": "https://www.exploit-db.com/exploits/50477",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-05T12:38:51+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2018-16763 exploit",
                    "summary": "Exploit for CVE-2018-16763. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANTISECC-CVE-2018-16763"
                },
                {
                    "repository": "PoC-in-GitHub · dinhbaouit/CVE-2018-16763",
                    "author": "dinhbaouit",
                    "first_seen": "2020-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE 2018-16763",
                    "summary": "CVE 2018-16763",
                    "url": "https://github.com/dinhbaouit/CVE-2018-16763"
                },
                {
                    "repository": "PoC-in-GitHub · hikarihacks/CVE-2018-16763-exploit",
                    "author": "hikarihacks",
                    "first_seen": "2020-09-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "This is an updated version of the CVE-2018-16763 for fuelCMS 1.4.1",
                    "summary": "This is an updated version of the CVE-2018-16763 for fuelCMS 1.4.1",
                    "url": "https://github.com/hikarihacks/CVE-2018-16763-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · n3m1sys/CVE-2018-16763-Exploit-Python3",
                    "author": "n3m1sys",
                    "first_seen": "2020-10-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2018-16763 repository",
                    "summary": "",
                    "url": "https://github.com/n3m1sys/CVE-2018-16763-Exploit-Python3"
                },
                {
                    "repository": "PoC-in-GitHub · uwueviee/Fu3l-F1lt3r",
                    "author": "uwueviee",
                    "first_seen": "2021-01-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Rust implementation of CVE-2018-16763 with some extra features.",
                    "summary": "Rust implementation of CVE-2018-16763 with some extra features.",
                    "url": "https://github.com/uwueviee/Fu3l-F1lt3r"
                },
                {
                    "repository": "PoC-in-GitHub · shoamshilo/Fuel-CMS-Remote-Code-Execution-1.4--RCE--",
                    "author": "shoamshilo",
                    "first_seen": "2021-03-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "A working PoC to CVE-2018-16763",
                    "summary": "A working PoC to CVE-2018-16763",
                    "url": "https://github.com/shoamshilo/Fuel-CMS-Remote-Code-Execution-1.4--RCE--"
                },
                {
                    "repository": "PoC-in-GitHub · kxisxr/Bash-Script-CVE-2018-16763",
                    "author": "kxisxr",
                    "first_seen": "2021-09-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.",
                    "summary": "FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.",
                    "url": "https://github.com/kxisxr/Bash-Script-CVE-2018-16763"
                },
                {
                    "repository": "PoC-in-GitHub · padsalatushal/CVE-2018-16763",
                    "author": "padsalatushal",
                    "first_seen": "2021-11-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Fuel CMS 1.4.1 - Remote Code Execution",
                    "summary": "Fuel CMS 1.4.1 - Remote Code Execution",
                    "url": "https://github.com/padsalatushal/CVE-2018-16763"
                },
                {
                    "repository": "PoC-in-GitHub · wizardy0ga/THM-Vulnerability_Capstone-CVE-2018-16763",
                    "author": "wizardy0ga",
                    "first_seen": "2021-11-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A write up on the THM room Vulnerability Capstone & Exploit script for CVE-2018-16763.",
                    "summary": "A write up on the THM room Vulnerability Capstone & Exploit script for CVE-2018-16763.",
                    "url": "https://github.com/wizardy0ga/THM-Vulnerability_Capstone-CVE-2018-16763"
                },
                {
                    "repository": "PoC-in-GitHub · h3x0v3rl0rd/CVE-2018-16763",
                    "author": "h3x0v3rl0rd",
                    "first_seen": "2022-01-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2018-16763 repository",
                    "summary": "",
                    "url": "https://github.com/h3x0v3rl0rd/CVE-2018-16763"
                },
                {
                    "repository": "PoC-in-GitHub · BrunoPincho/cve-2018-16763-rust",
                    "author": "BrunoPincho",
                    "first_seen": "2022-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-16763 repository",
                    "summary": "",
                    "url": "https://github.com/BrunoPincho/cve-2018-16763-rust"
                },
                {
                    "repository": "PoC-in-GitHub · p0dalirius/CVE-2018-16763-FuelCMS-1.4.1-RCE",
                    "author": "p0dalirius",
                    "first_seen": "2022-05-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "Exploit to trigger RCE for CVE-2018-16763 on FuelCMS <= 1.4.1 and interactive shell.",
                    "summary": "Exploit to trigger RCE for CVE-2018-16763 on FuelCMS <= 1.4.1 and interactive shell.",
                    "url": "https://github.com/p0dalirius/CVE-2018-16763-FuelCMS-1.4.1-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · not1cyyy/CVE-2018-16763",
                    "author": "not1cyyy",
                    "first_seen": "2023-01-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2018-16763 FuelCMS 1.4 Remote Code Execution, this version of FuelCMS is still vulnerable until now",
                    "summary": "CVE-2018-16763 FuelCMS 1.4 Remote Code Execution, this version of FuelCMS is still vulnerable until now",
                    "url": "https://github.com/not1cyyy/CVE-2018-16763"
                },
                {
                    "repository": "PoC-in-GitHub · antisecc/CVE-2018-16763",
                    "author": "antisecc",
                    "first_seen": "2023-06-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-16763 repository",
                    "summary": "",
                    "url": "https://github.com/antisecc/CVE-2018-16763"
                },
                {
                    "repository": "PoC-in-GitHub · VitoBonetti/CVE-2018-16763",
                    "author": "VitoBonetti",
                    "first_seen": "2023-07-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Fuel CMS 1.4.1 - Remote Code Execution - Python 3.x",
                    "summary": "Fuel CMS 1.4.1 - Remote Code Execution - Python 3.x",
                    "url": "https://github.com/VitoBonetti/CVE-2018-16763"
                },
                {
                    "repository": "PoC-in-GitHub · kaxm23/exploit_cms_fuel",
                    "author": "kaxm23",
                    "first_seen": "2023-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Python3 exploit for Fuel CMS 1.4.1 Remote Code Execution (CVE-2018-16763) with Reverse Shell.",
                    "summary": "Python3 exploit for Fuel CMS 1.4.1 Remote Code Execution (CVE-2018-16763) with Reverse Shell.",
                    "url": "https://github.com/kaxm23/exploit_cms_fuel"
                },
                {
                    "repository": "PoC-in-GitHub · saccles/CVE_2018_16763_Proof_of_Concept",
                    "author": "saccles",
                    "first_seen": "2024-12-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A Proof-of-Concept (PoC) exploit for CVE-2018-16763 (Fuel CMS - Preauthenticated Remote Code Execution).",
                    "summary": "A Proof-of-Concept (PoC) exploit for CVE-2018-16763 (Fuel CMS - Preauthenticated Remote Code Execution).",
                    "url": "https://github.com/saccles/CVE_2018_16763_Proof_of_Concept"
                },
                {
                    "repository": "PoC-in-GitHub · altsun/CVE-2018-16763-FuelCMS-1.4.1-RCE",
                    "author": "altsun",
                    "first_seen": "2025-01-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Fuel CMS 1.4.1 - Remote Code Execution",
                    "summary": "Fuel CMS 1.4.1 - Remote Code Execution",
                    "url": "https://github.com/altsun/CVE-2018-16763-FuelCMS-1.4.1-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · ArtemCyberLab/Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763-",
                    "author": "ArtemCyberLab",
                    "first_seen": "2025-04-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "The goal of this project was to conduct a security audit of a blog recently launched by Ackme Support Incorporated, identifying any critical vulnerabilities before the site goes public. The task involved finding a way to remotely execute code and gain access to the target system.",
                    "summary": "The goal of this project was to conduct a security audit of a blog recently launched by Ackme Support Incorporated, identifying any critical vulnerabilities before the site goes public. The task involved finding a way to remotely execute code and gain access to the target system.",
                    "url": "https://github.com/ArtemCyberLab/Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763-"
                },
                {
                    "repository": "PoC-in-GitHub · bad-c0de/CVE-2018-16763_FuelCMS-1.4.1_RCE",
                    "author": "bad-c0de",
                    "first_seen": "2025-09-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "FuelCMS 1.4.1 Command Injection/Remote Code Execution.",
                    "summary": "FuelCMS 1.4.1 Command Injection/Remote Code Execution.",
                    "url": "https://github.com/bad-c0de/CVE-2018-16763_FuelCMS-1.4.1_RCE"
                },
                {
                    "repository": "PoC-in-GitHub · Cyberuser-hash/CVE-2018-16763",
                    "author": "Cyberuser-hash",
                    "first_seen": "2025-10-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "exploit for CVE-2018-16763",
                    "summary": "exploit for CVE-2018-16763",
                    "url": "https://github.com/Cyberuser-hash/CVE-2018-16763"
                },
                {
                    "repository": "PoC-in-GitHub · estebanzarate/CVE-2018-16763-Fuel-CMS-1.4.1-Remote-Code-Execution-PoC",
                    "author": "estebanzarate",
                    "first_seen": "2026-04-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Unauthenticated RCE vulnerability in Fuel CMS 1.4.1.",
                    "summary": "Unauthenticated RCE vulnerability in Fuel CMS 1.4.1.",
                    "url": "https://github.com/estebanzarate/CVE-2018-16763-Fuel-CMS-1.4.1-Remote-Code-Execution-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · SOME-1HING/CVE-2018-16763",
                    "author": "SOME-1HING",
                    "first_seen": "2026-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Python tool for analyzing CVE-2018-16763 in FUEL CMS with cleaner response parsing and interactive vulnerability checking.",
                    "summary": "Python tool for analyzing CVE-2018-16763 in FUEL CMS with cleaner response parsing and interactive vulnerability checking.",
                    "url": "https://github.com/SOME-1HING/CVE-2018-16763"
                },
                {
                    "repository": "PoC-in-GitHub · ShadowR-Root/fuel-cms-cve-2018-16763-python3-port",
                    "author": "ShadowR-Root",
                    "first_seen": "2026-08-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Maintained Python 3 port of the original FUEL CMS CVE-2018-16763 proof-of-concept.",
                    "summary": "Maintained Python 3 port of the original FUEL CMS CVE-2018-16763 proof-of-concept.",
                    "url": "https://github.com/ShadowR-Root/fuel-cms-cve-2018-16763-python3-port"
                },
                {
                    "repository": "PoC-in-GitHub · gh0stuncle/CVE-2018-16763_fuel_cms_exploit",
                    "author": "gh0stuncle",
                    "first_seen": "2026-08-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.",
                    "summary": "A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.",
                    "url": "https://github.com/gh0stuncle/CVE-2018-16763_fuel_cms_exploit"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/47138",
                "https://www.exploit-db.com/exploits/49487",
                "https://www.exploit-db.com/exploits/50477",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ANTISECC-CVE-2018-16763",
                "https://github.com/dinhbaouit/CVE-2018-16763",
                "https://github.com/hikarihacks/CVE-2018-16763-exploit",
                "https://github.com/n3m1sys/CVE-2018-16763-Exploit-Python3",
                "https://github.com/uwueviee/Fu3l-F1lt3r",
                "https://github.com/shoamshilo/Fuel-CMS-Remote-Code-Execution-1.4--RCE--",
                "https://github.com/kxisxr/Bash-Script-CVE-2018-16763",
                "https://github.com/padsalatushal/CVE-2018-16763",
                "https://github.com/wizardy0ga/THM-Vulnerability_Capstone-CVE-2018-16763",
                "https://github.com/h3x0v3rl0rd/CVE-2018-16763",
                "https://github.com/BrunoPincho/cve-2018-16763-rust",
                "https://github.com/p0dalirius/CVE-2018-16763-FuelCMS-1.4.1-RCE",
                "https://github.com/not1cyyy/CVE-2018-16763",
                "https://github.com/antisecc/CVE-2018-16763",
                "https://github.com/VitoBonetti/CVE-2018-16763",
                "https://github.com/kaxm23/exploit_cms_fuel",
                "https://github.com/saccles/CVE_2018_16763_Proof_of_Concept",
                "https://github.com/altsun/CVE-2018-16763-FuelCMS-1.4.1-RCE",
                "https://github.com/ArtemCyberLab/Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763-",
                "https://github.com/bad-c0de/CVE-2018-16763_FuelCMS-1.4.1_RCE",
                "https://github.com/Cyberuser-hash/CVE-2018-16763",
                "https://github.com/estebanzarate/CVE-2018-16763-Fuel-CMS-1.4.1-Remote-Code-Execution-PoC",
                "https://github.com/SOME-1HING/CVE-2018-16763",
                "https://github.com/ShadowR-Root/fuel-cms-cve-2018-16763-python3-port",
                "https://github.com/gh0stuncle/CVE-2018-16763_fuel_cms_exploit"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:38:51Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/47138"
                }
            ]
        },
        {
            "id": "CVE-2018-15982",
            "vendor": "Adobe",
            "product": "Flash Player",
            "title": "Adobe Flash Player Use-After-Free Vulnerability",
            "summary": "Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability",
            "updated_at": "2026-09-12T15:06:16Z",
            "published_at": "2026-09-12T15:06:16Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 80,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 46051",
                    "author": "smgorelik",
                    "first_seen": "2018-12-24",
                    "confidence": "High",
                    "title": "Adobe Flash ActiveX Plugin 28.0.0.137 - Remote Code Execution (PoC)",
                    "summary": "Adobe Flash ActiveX Plugin 28.0.0.137 - Remote Code Execution (PoC)",
                    "url": "https://www.exploit-db.com/exploits/46051",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2018-15982_EXP",
                    "summary": "CVE-2018-15982 exploit tool generating SWF and HTML with msfvenom Windows payloads.",
                    "what_happened": "CVE-2018-15982 exploit tool generating SWF and HTML with msfvenom Windows payloads.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RIDTER-CVE-2018-15982_EXP",
                        "https://kitploit.com/ja/tools/github/ridter/cve-2018-15982_exp/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-11T15:22:58",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RIDTER-CVE-2018-15982_EXP"
                },
                {
                    "title": "Exploit for CVE-2018-15982_EXP",
                    "summary": "CVE-2018-15982 exploit tool generating SWF and HTML with msfvenom Windows payloads.",
                    "what_happened": "CVE-2018-15982 exploit tool generating SWF and HTML with msfvenom Windows payloads.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RIDTER-CVE-2018-15982_EXP",
                        "https://kitploit.com/ja/tools/github/ridter/cve-2018-15982_exp/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-11T15:22:58",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/ridter/cve-2018-15982_exp/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/46051",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-RIDTER-CVE-2018-15982_EXP",
                "https://kitploit.com/ja/tools/github/ridter/cve-2018-15982_exp/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T15:06:16Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-15",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2018-15473",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "OpenSSH 2.3 < 7.7 - Username Enumeration",
            "summary": "OpenSSH 2.3 < 7.7 - Username Enumeration",
            "updated_at": "2026-09-08T14:29:33Z",
            "published_at": "2026-09-08T14:29:33Z",
            "cvss": 5.9,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 334,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 45233",
                    "author": "Justin Gardner",
                    "first_seen": "2018-08-21",
                    "confidence": "High",
                    "title": "OpenSSH 2.3 < 7.7 - Username Enumeration",
                    "summary": "OpenSSH 2.3 < 7.7 - Username Enumeration",
                    "url": "https://www.exploit-db.com/exploits/45233",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 45210",
                    "author": "Matthew Daley",
                    "first_seen": "2018-08-16",
                    "confidence": "High",
                    "title": "OpenSSH 2.3 < 7.7 - Username Enumeration (PoC)",
                    "summary": "OpenSSH 2.3 < 7.7 - Username Enumeration (PoC)",
                    "url": "https://www.exploit-db.com/exploits/45210",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 45939",
                    "author": "Leap Security",
                    "first_seen": "2018-12-04",
                    "confidence": "High",
                    "title": "OpenSSH < 7.7 - User Enumeration (2)",
                    "summary": "OpenSSH < 7.7 - User Enumeration (2)",
                    "url": "https://www.exploit-db.com/exploits/45939",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-08T14:29:33+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2018-15473_OpenSSH_7.7 exploit",
                    "summary": "Exploit for CVE-2018-15473. CVSS 5.9.",
                    "cvss": 5.9,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WILDFOOTW-CVE-2018-15473_OPENSSH_7.7"
                },
                {
                    "repository": "PoC-in-GitHub · trimstray/massh-enum",
                    "author": "trimstray",
                    "first_seen": "2018-08-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 159,
                    "title": "OpenSSH 2.3 up to 7.4 Mass Username Enumeration (CVE-2018-15473).",
                    "summary": "OpenSSH 2.3 up to 7.4 Mass Username Enumeration (CVE-2018-15473).",
                    "url": "https://github.com/trimstray/massh-enum"
                },
                {
                    "repository": "PoC-in-GitHub · gbonacini/opensshenum",
                    "author": "gbonacini",
                    "first_seen": "2018-08-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2018-15473 - Opensshenum is an user enumerator exploiting an OpenSsh bug",
                    "summary": "CVE-2018-15473 - Opensshenum is an user enumerator exploiting an OpenSsh bug",
                    "url": "https://github.com/gbonacini/opensshenum"
                },
                {
                    "repository": "PoC-in-GitHub · Rhynorater/CVE-2018-15473-Exploit",
                    "author": "Rhynorater",
                    "first_seen": "2018-08-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 534,
                    "title": "Exploit written in Python for CVE-2018-15473 with threading and export formats",
                    "summary": "Exploit written in Python for CVE-2018-15473 with threading and export formats",
                    "url": "https://github.com/Rhynorater/CVE-2018-15473-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · epi052/cve-2018-15473",
                    "author": "epi052",
                    "first_seen": "2018-10-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 116,
                    "title": "Multi-threaded, IPv6 aware, wordlists/single-user username enumeration via CVE-2018-15473",
                    "summary": "Multi-threaded, IPv6 aware, wordlists/single-user username enumeration via CVE-2018-15473",
                    "url": "https://github.com/epi052/cve-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · pyperanger/CVE-2018-15473_exploit",
                    "author": "pyperanger",
                    "first_seen": "2018-10-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "OpenSSH  < 7.7 User Enumeration CVE-2018-15473 Exploit",
                    "summary": "OpenSSH  < 7.7 User Enumeration CVE-2018-15473 Exploit",
                    "url": "https://github.com/pyperanger/CVE-2018-15473_exploit"
                },
                {
                    "repository": "PoC-in-GitHub · r3dxpl0it/CVE-2018-15473",
                    "author": "r3dxpl0it",
                    "first_seen": "2018-10-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 17,
                    "title": "OpenSSH 7.7 - Username Enumeration",
                    "summary": "OpenSSH 7.7 - Username Enumeration",
                    "url": "https://github.com/r3dxpl0it/CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · JoeBlackSecurity/SSHUsernameBruter-SSHUB",
                    "author": "JoeBlackSecurity",
                    "first_seen": "2018-10-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473",
                    "summary": "Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473",
                    "url": "https://github.com/JoeBlackSecurity/SSHUsernameBruter-SSHUB"
                },
                {
                    "repository": "PoC-in-GitHub · cved-sources/cve-2018-15473",
                    "author": "cved-sources",
                    "first_seen": "2019-01-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "cve-2018-15473",
                    "summary": "cve-2018-15473",
                    "url": "https://github.com/cved-sources/cve-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · LINYIKAI/CVE-2018-15473-exp",
                    "author": "LINYIKAI",
                    "first_seen": "2019-01-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This is a exp of CVE-2018-15473",
                    "summary": "This is a exp of CVE-2018-15473",
                    "url": "https://github.com/LINYIKAI/CVE-2018-15473-exp"
                },
                {
                    "repository": "PoC-in-GitHub · trickster1103/-",
                    "author": "trickster1103",
                    "first_seen": "2019-06-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "OpenSSH 用户名枚举漏洞（CVE-2018-15473）",
                    "summary": "OpenSSH 用户名枚举漏洞（CVE-2018-15473）",
                    "url": "https://github.com/trickster1103/-"
                },
                {
                    "repository": "PoC-in-GitHub · NHPT/SSH-account-enumeration-verification-script",
                    "author": "NHPT",
                    "first_seen": "2019-08-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "SSH account enumeration verification script(CVE-2018-15473)",
                    "summary": "SSH account enumeration verification script(CVE-2018-15473)",
                    "url": "https://github.com/NHPT/SSH-account-enumeration-verification-script"
                },
                {
                    "repository": "PoC-in-GitHub · CaioCGH/EP4-redes",
                    "author": "CaioCGH",
                    "first_seen": "2019-11-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-15473-Exploit",
                    "summary": "CVE-2018-15473-Exploit",
                    "url": "https://github.com/CaioCGH/EP4-redes"
                },
                {
                    "repository": "PoC-in-GitHub · Moon1705/easy_security",
                    "author": "Moon1705",
                    "first_seen": "2020-05-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Project with sublist3r, massan, CVE-2018-15473, ssh bruteforce, ftp bruteforce and nikto.",
                    "summary": "Project with sublist3r, massan, CVE-2018-15473, ssh bruteforce, ftp bruteforce and nikto.",
                    "url": "https://github.com/Moon1705/easy_security"
                },
                {
                    "repository": "PoC-in-GitHub · An0nYm0u5101/enumpossible",
                    "author": "An0nYm0u5101",
                    "first_seen": "2020-08-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Checks a list of SSH servers for password-based auth availability and for the existence of SSH user enumeration vulnerability (CVE-2018-15473) in those identified.",
                    "summary": "Checks a list of SSH servers for password-based auth availability and for the existence of SSH user enumeration vulnerability (CVE-2018-15473) in those identified.",
                    "url": "https://github.com/An0nYm0u5101/enumpossible"
                },
                {
                    "repository": "PoC-in-GitHub · Wh1t3Fox/cve-2018-15473",
                    "author": "Wh1t3Fox",
                    "first_seen": "2020-09-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-15473 repository",
                    "summary": "",
                    "url": "https://github.com/Wh1t3Fox/cve-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · 1stPeak/CVE-2018-15473",
                    "author": "1stPeak",
                    "first_seen": "2020-11-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-15473 repository",
                    "summary": "",
                    "url": "https://github.com/1stPeak/CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · coollce/CVE-2018-15473_burte",
                    "author": "coollce",
                    "first_seen": "2020-11-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "openssh<7.7 用户名枚举",
                    "summary": "openssh<7.7 用户名枚举",
                    "url": "https://github.com/coollce/CVE-2018-15473_burte"
                },
                {
                    "repository": "PoC-in-GitHub · Dirty-Racoon/CVE-2018-15473-py3",
                    "author": "Dirty-Racoon",
                    "first_seen": "2020-11-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-15473 repository",
                    "summary": "",
                    "url": "https://github.com/Dirty-Racoon/CVE-2018-15473-py3"
                },
                {
                    "repository": "PoC-in-GitHub · Sait-Nuri/CVE-2018-15473",
                    "author": "Sait-Nuri",
                    "first_seen": "2020-11-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 42,
                    "title": "OpenSSH 2.3 < 7.7 - Username Enumeration",
                    "summary": "OpenSSH 2.3 < 7.7 - Username Enumeration",
                    "url": "https://github.com/Sait-Nuri/CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · WildfootW/CVE-2018-15473_OpenSSH_7.7",
                    "author": "WildfootW",
                    "first_seen": "2020-12-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-15473 repository",
                    "summary": "",
                    "url": "https://github.com/WildfootW/CVE-2018-15473_OpenSSH_7.7"
                },
                {
                    "repository": "PoC-in-GitHub · MrDottt/CVE-2018-15473",
                    "author": "MrDottt",
                    "first_seen": "2021-09-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2018-15473 Exploit",
                    "summary": "CVE-2018-15473 Exploit",
                    "url": "https://github.com/MrDottt/CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · 66quentin/shodan-CVE-2018-15473",
                    "author": "66quentin",
                    "first_seen": "2021-12-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Test CVE-2018-15473 exploit on Shodan IP",
                    "summary": "Test CVE-2018-15473 exploit on Shodan IP",
                    "url": "https://github.com/66quentin/shodan-CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · 0xrobiul/CVE-2018-15473",
                    "author": "0xrobiul",
                    "first_seen": "2022-09-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2018-15473 repository",
                    "summary": "",
                    "url": "https://github.com/0xrobiul/CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · philippedixon/CVE-2018-15473",
                    "author": "philippedixon",
                    "first_seen": "2023-01-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-15473 repository",
                    "summary": "",
                    "url": "https://github.com/philippedixon/CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · sergiovks/SSH-User-Enum-Python3-CVE-2018-15473",
                    "author": "sergiovks",
                    "first_seen": "2023-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "SSH User Enumerator in Python3, CVE-2018-15473, I updated the code of this exploit (https://www.exploit-db.com/exploits/45939) to work with python3 instead of python2.",
                    "summary": "SSH User Enumerator in Python3, CVE-2018-15473, I updated the code of this exploit (https://www.exploit-db.com/exploits/45939) to work with python3 instead of python2.",
                    "url": "https://github.com/sergiovks/SSH-User-Enum-Python3-CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · Anonimo501/ssh_enum_users_CVE-2018-15473",
                    "author": "Anonimo501",
                    "first_seen": "2023-04-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-15473 repository",
                    "summary": "",
                    "url": "https://github.com/Anonimo501/ssh_enum_users_CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · mclbn/docker-cve-2018-15473",
                    "author": "mclbn",
                    "first_seen": "2023-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2018-15473 repository",
                    "summary": "",
                    "url": "https://github.com/mclbn/docker-cve-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · GaboLC98/userenum-CVE-2018-15473",
                    "author": "GaboLC98",
                    "first_seen": "2023-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "User enumeration for CVE-2018-15473",
                    "summary": "User enumeration for CVE-2018-15473",
                    "url": "https://github.com/GaboLC98/userenum-CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · NestyF/SSH_Enum_CVE-2018-15473",
                    "author": "NestyF",
                    "first_seen": "2023-11-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-15473 repository",
                    "summary": "",
                    "url": "https://github.com/NestyF/SSH_Enum_CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · yZee00/CVE-2018-15473",
                    "author": "yZee00",
                    "first_seen": "2024-06-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Fix for CVE-2018-15473",
                    "summary": "Fix for CVE-2018-15473",
                    "url": "https://github.com/yZee00/CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · SUDORM0X/PoC-CVE-2018-15473",
                    "author": "SUDORM0X",
                    "first_seen": "2024-11-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "FAFAF",
                    "summary": "FAFAF",
                    "url": "https://github.com/SUDORM0X/PoC-CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · OmarV4066/SSHEnumKL",
                    "author": "OmarV4066",
                    "first_seen": "2025-02-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "SSHEnum es una herramienta de enumeración de usuarios SSH basada en CVE-2018-15473. Permite detectar usuarios válidos aprovechando respuestas diferenciadas del servidor. Es rápida, compatible con Python 3.12 y soporta wordlists. Uso exclusivo para auditoría y pruebas de seguridad autorizadas.",
                    "summary": "SSHEnum es una herramienta de enumeración de usuarios SSH basada en CVE-2018-15473. Permite detectar usuarios válidos aprovechando respuestas diferenciadas del servidor. Es rápida, compatible con Python 3.12 y soporta wordlists. Uso exclusivo para auditoría y pruebas de seguridad autorizadas.",
                    "url": "https://github.com/OmarV4066/SSHEnumKL"
                },
                {
                    "repository": "PoC-in-GitHub · 0xNehru/ssh_Enum_vaild",
                    "author": "0xNehru",
                    "first_seen": "2025-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A Bash script to enumerate valid SSH usernames using the CVE-2018-15473 vulnerability. It checks for valid usernames on an OpenSSH OpenSSH 7.2p2 server by analyzing authentication responses.",
                    "summary": "A Bash script to enumerate valid SSH usernames using the CVE-2018-15473 vulnerability. It checks for valid usernames on an OpenSSH OpenSSH 7.2p2 server by analyzing authentication responses.",
                    "url": "https://github.com/0xNehru/ssh_Enum_vaild"
                },
                {
                    "repository": "PoC-in-GitHub · moften/cve-2018-15473-poc",
                    "author": "moften",
                    "first_seen": "2025-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Check if a username is valid on the SSH server by attempting an authentication.     The server response will indicate whether the username exists.",
                    "summary": "Check if a username is valid on the SSH server by attempting an authentication.     The server response will indicate whether the username exists.",
                    "url": "https://github.com/moften/cve-2018-15473-poc"
                },
                {
                    "repository": "PoC-in-GitHub · makmour/open-ssh-user-enumeration",
                    "author": "makmour",
                    "first_seen": "2025-05-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This script checks for the OpenSSH 7.7 (and prior) username enumeration vulnerability (CVE-2018-15473). It sends a malformed authentication packet and interprets the SSH server’s response to identify valid usernames.",
                    "summary": "This script checks for the OpenSSH 7.7 (and prior) username enumeration vulnerability (CVE-2018-15473). It sends a malformed authentication packet and interprets the SSH server’s response to identify valid usernames.",
                    "url": "https://github.com/makmour/open-ssh-user-enumeration"
                },
                {
                    "repository": "PoC-in-GitHub · Alph4Sec/ssh_enum_py",
                    "author": "Alph4Sec",
                    "first_seen": "2025-09-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "script de enumeración de usuarios SSH basado en diferencias de timing y respuestas de autenticación. Explota el mismo vector que CVE-2018-15473 en versiones vulnerables de OpenSSH (≤ 7.7), aunque también puede revelar patrones en configuraciones modernas.",
                    "summary": "script de enumeración de usuarios SSH basado en diferencias de timing y respuestas de autenticación. Explota el mismo vector que CVE-2018-15473 en versiones vulnerables de OpenSSH (≤ 7.7), aunque también puede revelar patrones en configuraciones modernas.",
                    "url": "https://github.com/Alph4Sec/ssh_enum_py"
                },
                {
                    "repository": "PoC-in-GitHub · anonymous121029034720384234234/py-network-scanner",
                    "author": "anonymous121029034720384234234",
                    "first_seen": "2025-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Advanced network penetration testing toolkit with SSH vulnerability assessment, CVE-2018-15473 exploitation, stealth brute force capabilities, and fail2ban evasion techniques. Professional-grade security testing framework for authorized penetration testing engagements.",
                    "summary": "Advanced network penetration testing toolkit with SSH vulnerability assessment, CVE-2018-15473 exploitation, stealth brute force capabilities, and fail2ban evasion techniques. Professional-grade security testing framework for authorized penetration testing engagements.",
                    "url": "https://github.com/anonymous121029034720384234234/py-network-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · K3rn3l-32/Threaded-CVE-2018-15473",
                    "author": "K3rn3l-32",
                    "first_seen": "2026-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A Python 3 reimplementation of the classic CVE-2018-15473 OpenSSH user enumeration exploit, extended with multi-threading, wordlist support, automatic vulnerability detection, and thread-safe exploit patching.",
                    "summary": "A Python 3 reimplementation of the classic CVE-2018-15473 OpenSSH user enumeration exploit, extended with multi-threading, wordlist support, automatic vulnerability detection, and thread-safe exploit patching.",
                    "url": "https://github.com/K3rn3l-32/Threaded-CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · wtbacon/cve-2018-15473",
                    "author": "wtbacon",
                    "first_seen": "2026-03-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-15473 repository",
                    "summary": "",
                    "url": "https://github.com/wtbacon/cve-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · kikechans/-SSH-Enum-CVE-2018-15473",
                    "author": "kikechans",
                    "first_seen": "2026-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "🛡️ SSH User Enumeration (CVE-2018-15473). Python 3, multihilo y calibración anti-falsos positivos. 🧵",
                    "summary": "🛡️ SSH User Enumeration (CVE-2018-15473). Python 3, multihilo y calibración anti-falsos positivos. 🧵",
                    "url": "https://github.com/kikechans/-SSH-Enum-CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · kaktus5454/CVE-2018-15473",
                    "author": "kaktus5454",
                    "first_seen": "2026-04-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "python code for CVE-2018-15473, using paramiko",
                    "summary": "python code for CVE-2018-15473, using paramiko",
                    "url": "https://github.com/kaktus5454/CVE-2018-15473"
                },
                {
                    "repository": "PoC-in-GitHub · bdalrhmnhamdalalm-jpg/CVE-2018-15473-User-Enumeration-",
                    "author": "bdalrhmnhamdalalm-jpg",
                    "first_seen": "2026-08-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "python code use to check for user in ssh",
                    "summary": "python code use to check for user in ssh",
                    "url": "https://github.com/bdalrhmnhamdalalm-jpg/CVE-2018-15473-User-Enumeration-"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/45233",
                "https://www.exploit-db.com/exploits/45210",
                "https://www.exploit-db.com/exploits/45939",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-WILDFOOTW-CVE-2018-15473_OPENSSH_7.7",
                "https://github.com/trimstray/massh-enum",
                "https://github.com/gbonacini/opensshenum",
                "https://github.com/Rhynorater/CVE-2018-15473-Exploit",
                "https://github.com/epi052/cve-2018-15473",
                "https://github.com/pyperanger/CVE-2018-15473_exploit",
                "https://github.com/r3dxpl0it/CVE-2018-15473",
                "https://github.com/JoeBlackSecurity/SSHUsernameBruter-SSHUB",
                "https://github.com/cved-sources/cve-2018-15473",
                "https://github.com/LINYIKAI/CVE-2018-15473-exp",
                "https://github.com/trickster1103/-",
                "https://github.com/NHPT/SSH-account-enumeration-verification-script",
                "https://github.com/CaioCGH/EP4-redes",
                "https://github.com/Moon1705/easy_security",
                "https://github.com/An0nYm0u5101/enumpossible",
                "https://github.com/Wh1t3Fox/cve-2018-15473",
                "https://github.com/1stPeak/CVE-2018-15473",
                "https://github.com/coollce/CVE-2018-15473_burte",
                "https://github.com/Dirty-Racoon/CVE-2018-15473-py3",
                "https://github.com/Sait-Nuri/CVE-2018-15473",
                "https://github.com/WildfootW/CVE-2018-15473_OpenSSH_7.7",
                "https://github.com/MrDottt/CVE-2018-15473",
                "https://github.com/66quentin/shodan-CVE-2018-15473",
                "https://github.com/0xrobiul/CVE-2018-15473",
                "https://github.com/philippedixon/CVE-2018-15473",
                "https://github.com/sergiovks/SSH-User-Enum-Python3-CVE-2018-15473",
                "https://github.com/Anonimo501/ssh_enum_users_CVE-2018-15473",
                "https://github.com/mclbn/docker-cve-2018-15473",
                "https://github.com/GaboLC98/userenum-CVE-2018-15473",
                "https://github.com/NestyF/SSH_Enum_CVE-2018-15473",
                "https://github.com/yZee00/CVE-2018-15473",
                "https://github.com/SUDORM0X/PoC-CVE-2018-15473",
                "https://github.com/OmarV4066/SSHEnumKL",
                "https://github.com/0xNehru/ssh_Enum_vaild",
                "https://github.com/moften/cve-2018-15473-poc",
                "https://github.com/makmour/open-ssh-user-enumeration",
                "https://github.com/Alph4Sec/ssh_enum_py",
                "https://github.com/anonymous121029034720384234234/py-network-scanner",
                "https://github.com/K3rn3l-32/Threaded-CVE-2018-15473",
                "https://github.com/wtbacon/cve-2018-15473",
                "https://github.com/kikechans/-SSH-Enum-CVE-2018-15473",
                "https://github.com/kaktus5454/CVE-2018-15473",
                "https://github.com/bdalrhmnhamdalalm-jpg/CVE-2018-15473-User-Enumeration-"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T14:29:33Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/45233"
                }
            ]
        },
        {
            "id": "CVE-2018-14847",
            "vendor": "MikroTik",
            "product": "RouterOS",
            "title": "MikroTik Router OS Directory Traversal Vulnerability",
            "summary": "MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.",
            "updated_at": "2026-09-06T22:00:00Z",
            "published_at": "2026-09-06T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 576,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 45578",
                    "author": "Jacob Baines",
                    "first_seen": "2018-10-10",
                    "confidence": "High",
                    "title": "MicroTik RouterOS < 6.43rc3 - Remote Root",
                    "summary": "MicroTik RouterOS < 6.43rc3 - Remote Root",
                    "url": "https://www.exploit-db.com/exploits/45578",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · BasuCert/WinboxPoC",
                    "author": "BasuCert",
                    "first_seen": "2018-06-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 520,
                    "title": "Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)",
                    "summary": "Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)",
                    "url": "https://github.com/BasuCert/WinboxPoC"
                },
                {
                    "repository": "PoC-in-GitHub · msterusky/WinboxExploit",
                    "author": "msterusky",
                    "first_seen": "2018-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "C# implementation of BasuCert/WinboxPoC [Winbox Critical Vulnerability (CVE-2018-14847)]",
                    "summary": "C# implementation of BasuCert/WinboxPoC [Winbox Critical Vulnerability (CVE-2018-14847)]",
                    "url": "https://github.com/msterusky/WinboxExploit"
                },
                {
                    "repository": "PoC-in-GitHub · syrex1013/MikroRoot",
                    "author": "syrex1013",
                    "first_seen": "2018-10-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 15,
                    "title": "Automated version of CVE-2018-14847 (MikroTik Exploit)",
                    "summary": "Automated version of CVE-2018-14847 (MikroTik Exploit)",
                    "url": "https://github.com/syrex1013/MikroRoot"
                },
                {
                    "repository": "PoC-in-GitHub · jas502n/CVE-2018-14847",
                    "author": "jas502n",
                    "first_seen": "2018-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 30,
                    "title": "MikroTik RouterOS Winbox未经身份验证的任意文件读/写漏洞",
                    "summary": "MikroTik RouterOS Winbox未经身份验证的任意文件读/写漏洞",
                    "url": "https://github.com/jas502n/CVE-2018-14847"
                },
                {
                    "repository": "PoC-in-GitHub · mahmoodsabir/mikrotik-beast",
                    "author": "mahmoodsabir",
                    "first_seen": "2019-05-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Mass MikroTik WinBox Exploitation tool, CVE-2018-14847",
                    "summary": "Mass MikroTik WinBox Exploitation tool, CVE-2018-14847",
                    "url": "https://github.com/mahmoodsabir/mikrotik-beast"
                },
                {
                    "repository": "PoC-in-GitHub · Tr33-He11/winboxPOC",
                    "author": "Tr33-He11",
                    "first_seen": "2019-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)",
                    "summary": "Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)",
                    "url": "https://github.com/Tr33-He11/winboxPOC"
                },
                {
                    "repository": "PoC-in-GitHub · sinichi449/Python-MikrotikLoginExploit",
                    "author": "sinichi449",
                    "first_seen": "2019-09-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 21,
                    "title": "PoC of CVE-2018-14847 Mikrotik Vulnerability using simple script",
                    "summary": "PoC of CVE-2018-14847 Mikrotik Vulnerability using simple script",
                    "url": "https://github.com/sinichi449/Python-MikrotikLoginExploit"
                },
                {
                    "repository": "PoC-in-GitHub · yukar1z0e/CVE-2018-14847",
                    "author": "yukar1z0e",
                    "first_seen": "2020-04-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2018-14847 repository",
                    "summary": "",
                    "url": "https://github.com/yukar1z0e/CVE-2018-14847"
                },
                {
                    "repository": "PoC-in-GitHub · hacker30468/Mikrotik-router-hack",
                    "author": "hacker30468",
                    "first_seen": "2021-04-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 55,
                    "title": "This is a proof of concept of the critical WinBox vulnerability (CVE-2018-14847) which allows for arbitrary file read of plain text passwords.  The vulnerability has long since been fixed, so this project has ended and will not be supported or updated anymore. You can fork it and update it yourself instead.",
                    "summary": "This is a proof of concept of the critical WinBox vulnerability (CVE-2018-14847) which allows for arbitrary file read of plain text passwords.  The vulnerability has long since been fixed, so this project has ended and will not be supported or updated anymore. You can fork it and update it yourself instead.",
                    "url": "https://github.com/hacker30468/Mikrotik-router-hack"
                },
                {
                    "repository": "PoC-in-GitHub · babyshen/routeros-CVE-2018-14847-bytheway",
                    "author": "babyshen",
                    "first_seen": "2022-10-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "By the Way is an exploit that enables a root shell on Mikrotik devices running RouterOS versions:",
                    "summary": "By the Way is an exploit that enables a root shell on Mikrotik devices running RouterOS versions:",
                    "url": "https://github.com/babyshen/routeros-CVE-2018-14847-bytheway"
                },
                {
                    "repository": "PoC-in-GitHub · K3ysTr0K3R/CVE-2018-14847-EXPLOIT",
                    "author": "K3ysTr0K3R",
                    "first_seen": "2024-04-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "A PoC exploit for CVE-2018-14847 - MikroTik WinBox File Read",
                    "summary": "A PoC exploit for CVE-2018-14847 - MikroTik WinBox File Read",
                    "url": "https://github.com/K3ysTr0K3R/CVE-2018-14847-EXPLOIT"
                },
                {
                    "repository": "PoC-in-GitHub · tausifzaman/CVE-2018-14847",
                    "author": "tausifzaman",
                    "first_seen": "2025-04-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This is a proof of concept of the critical WinBox vulnerability (CVE-2018-14847) which allows for arbitrary file read of plain text passwords.  The vulnerability has long since been fixed, so this project has ended and will not be supported or updated anymore. You can fork it and update it yourself instead.",
                    "summary": "This is a proof of concept of the critical WinBox vulnerability (CVE-2018-14847) which allows for arbitrary file read of plain text passwords.  The vulnerability has long since been fixed, so this project has ended and will not be supported or updated anymore. You can fork it and update it yourself instead.",
                    "url": "https://github.com/tausifzaman/CVE-2018-14847"
                },
                {
                    "repository": "PoC-in-GitHub · TheMalwareGuardian/CVE-2018-14847",
                    "author": "TheMalwareGuardian",
                    "first_seen": "2026-04-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Analysis and PoC for CVE-2018-14847, MikroTik RouterOS Winbox information disclosure vulnerability allowing unauthenticated read access to the credential database.",
                    "summary": "Analysis and PoC for CVE-2018-14847, MikroTik RouterOS Winbox information disclosure vulnerability allowing unauthenticated read access to the credential database.",
                    "url": "https://github.com/TheMalwareGuardian/CVE-2018-14847"
                },
                {
                    "repository": "PoC-in-GitHub · mourafuseti/VULNERAVEL-CVE-2018-14847---CREDENCIAIS-EXTRAIDAS",
                    "author": "mourafuseti",
                    "first_seen": "2026-05-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "VULNERAVEL CVE-2018-14847 - CREDENCIAIS EXTRAIDAS MIKROTIK EM PYTHON",
                    "summary": "VULNERAVEL CVE-2018-14847 - CREDENCIAIS EXTRAIDAS MIKROTIK EM PYTHON",
                    "url": "https://github.com/mourafuseti/VULNERAVEL-CVE-2018-14847---CREDENCIAIS-EXTRAIDAS"
                },
                {
                    "repository": "PoC-in-GitHub · luel-4013/misfortune-cookie",
                    "author": "luel-4013",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This interactive suite targets CVE-2014-9222 (Misfortune Cookie) in legacy RomPager web servers, alongside modular testing for CVE-2017-17215 (Huawei HG532 RCE), CVE-2018-14847 (MikroTik WinBox credential leak), and the CVE-2021-27101 / CVE-2021-27102 exploit chain (Accellion FTA).",
                    "summary": "This interactive suite targets CVE-2014-9222 (Misfortune Cookie) in legacy RomPager web servers, alongside modular testing for CVE-2017-17215 (Huawei HG532 RCE), CVE-2018-14847 (MikroTik WinBox credential leak), and the CVE-2021-27101 / CVE-2021-27102 exploit chain (Accellion FTA).",
                    "url": "https://github.com/luel-4013/misfortune-cookie"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/45578",
                "https://github.com/BasuCert/WinboxPoC",
                "https://github.com/msterusky/WinboxExploit",
                "https://github.com/syrex1013/MikroRoot",
                "https://github.com/jas502n/CVE-2018-14847",
                "https://github.com/mahmoodsabir/mikrotik-beast",
                "https://github.com/Tr33-He11/winboxPOC",
                "https://github.com/sinichi449/Python-MikrotikLoginExploit",
                "https://github.com/yukar1z0e/CVE-2018-14847",
                "https://github.com/hacker30468/Mikrotik-router-hack",
                "https://github.com/babyshen/routeros-CVE-2018-14847-bytheway",
                "https://github.com/K3ysTr0K3R/CVE-2018-14847-EXPLOIT",
                "https://github.com/tausifzaman/CVE-2018-14847",
                "https://github.com/TheMalwareGuardian/CVE-2018-14847",
                "https://github.com/mourafuseti/VULNERAVEL-CVE-2018-14847---CREDENCIAIS-EXTRAIDAS",
                "https://github.com/luel-4013/misfortune-cookie"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-12-01",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2018-11761",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2018-11761 exploit",
            "summary": "Exploit for CVE-2018-11761. CVSS 7.5.",
            "updated_at": "2026-09-15T08:37:04Z",
            "published_at": "2026-09-15T08:37:04Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "XML parser DoS in Apache Tika 1.18 via ElasticSearch 6.3.1 ingest attachment plugin.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2018-11761",
                    "summary": "XML parser DoS in Apache Tika 1.18 via ElasticSearch 6.3.1 ingest attachment plugin.",
                    "what_happened": "XML parser DoS in Apache Tika 1.18 via ElasticSearch 6.3.1 ingest attachment plugin.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BRIANWRF-CVE-2018-11761",
                        "https://kitploit.com/zh/tools/github/brianwrf/cve-2018-11761/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T17:48:55",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BRIANWRF-CVE-2018-11761"
                },
                {
                    "title": "Exploit for CVE-2018-11761",
                    "summary": "XML parser DoS in Apache Tika 1.18 via ElasticSearch 6.3.1 ingest attachment plugin.",
                    "what_happened": "XML parser DoS in Apache Tika 1.18 via ElasticSearch 6.3.1 ingest attachment plugin.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BRIANWRF-CVE-2018-11761",
                        "https://kitploit.com/zh/tools/github/brianwrf/cve-2018-11761/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-05T17:48:55",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/brianwrf/cve-2018-11761/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BRIANWRF-CVE-2018-11761",
                "https://kitploit.com/zh/tools/github/brianwrf/cve-2018-11761/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:37:04Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BRIANWRF-CVE-2018-11761"
                }
            ]
        },
        {
            "id": "CVE-2018-10933",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "libSSH - Authentication Bypass",
            "summary": "libSSH - Authentication Bypass",
            "updated_at": "2026-09-13T18:17:15Z",
            "published_at": "2026-09-13T18:17:15Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 54,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 45638",
                    "author": "Dayanç Soyadlı",
                    "first_seen": "2018-10-18",
                    "confidence": "High",
                    "title": "libSSH - Authentication Bypass",
                    "summary": "libSSH - Authentication Bypass",
                    "url": "https://www.exploit-db.com/exploits/45638",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 46307",
                    "author": "jas502n",
                    "first_seen": "2018-10-20",
                    "confidence": "High",
                    "title": "LibSSH 0.7.6 / 0.8.4 - Unauthorized Access",
                    "summary": "LibSSH 0.7.6 / 0.8.4 - Unauthorized Access",
                    "url": "https://www.exploit-db.com/exploits/46307",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:17:15+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "libssh-scanner exploit",
                    "summary": "Exploit for CVE-2018-10933. CVSS 9.1.",
                    "cvss": 9.1,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IVANACOSTARUBIO-LIBSSH-SCANNER"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/45638",
                "https://www.exploit-db.com/exploits/46307",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IVANACOSTARUBIO-LIBSSH-SCANNER"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:17:15Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/45638"
                }
            ]
        },
        {
            "id": "CVE-2018-10624",
            "vendor": "Johnson Controls",
            "product": "Metasys System",
            "title": "Metasys System vulnerability",
            "summary": "In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.",
            "updated_at": "2026-09-10T17:17:00.227",
            "published_at": "2018-08-01T21:29:00.217",
            "cvss": 4.3,
            "cvss_vector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "0 through 8.0 (custom); before 3.0.2 (custom)",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Adjacent Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-209",
            "what_happened": "In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "http://www.securityfocus.com/bid/104937",
                "https://www.cisa.gov/news-events/ics-advisories/icsa-18-212-02",
                "https://ics-cert.us-cert.gov/advisories/ICSA-18-212-02"
            ],
            "timeline": [
                {
                    "at": "2018-08-01T21:29:00.217",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-10624"
                }
            ]
        },
        {
            "id": "CVE-2018-7602",
            "vendor": "Drupal",
            "product": "Core",
            "title": "Drupal Core Remote Code Execution Vulnerability",
            "summary": "A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.",
            "updated_at": "2026-09-15T10:56:42Z",
            "published_at": "2026-09-15T10:56:42Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 41,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 44557",
                    "author": "SixP4ck3r",
                    "first_seen": "2018-04-30",
                    "confidence": "High",
                    "title": "Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit)",
                    "summary": "Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/44557",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 44542",
                    "author": "Blaklis",
                    "first_seen": "2018-04-25",
                    "confidence": "High",
                    "title": "Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC)",
                    "summary": "Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC)",
                    "url": "https://www.exploit-db.com/exploits/44542",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2018-7602",
                    "summary": "Vulnerability CVE-2018-7602 in the tools component.",
                    "what_happened": "Vulnerability CVE-2018-7602 in the tools component.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-132231G-CVE-2018-7602",
                        "https://kitploit.com/ja/tools/github/132231g/cve-2018-7602/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-15T10:56:42",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-132231G-CVE-2018-7602"
                },
                {
                    "title": "Exploit for CVE-2018-7602",
                    "summary": "Vulnerability CVE-2018-7602 in the tools component.",
                    "what_happened": "Vulnerability CVE-2018-7602 in the tools component.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-132231G-CVE-2018-7602",
                        "https://kitploit.com/ar/tools/github/132231g/cve-2018-7602/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-05T22:38:52",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/132231g/cve-2018-7602/"
                },
                {
                    "title": "Exploit for CVE-2018-7602",
                    "summary": "Vulnerability CVE-2018-7602 in the tools component.",
                    "what_happened": "Vulnerability CVE-2018-7602 in the tools component.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-132231G-CVE-2018-7602",
                        "https://kitploit.com/ja/tools/github/132231g/cve-2018-7602/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ja",
                    "first_seen": "2026-09-15T10:56:42",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ja/tools/github/132231g/cve-2018-7602/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/44557",
                "https://www.exploit-db.com/exploits/44542",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-132231G-CVE-2018-7602",
                "https://kitploit.com/ar/tools/github/132231g/cve-2018-7602/",
                "https://kitploit.com/ja/tools/github/132231g/cve-2018-7602/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T10:56:42Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-04-13",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2018-7600",
            "vendor": "Drupal",
            "product": "Drupal Core",
            "title": "Drupal Core Remote Code Execution Vulnerability",
            "summary": "Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.",
            "updated_at": "2026-08-29T22:00:00Z",
            "published_at": "2026-08-29T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 298,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 44482",
                    "author": "José Ignacio Rojo",
                    "first_seen": "2018-04-17",
                    "confidence": "High",
                    "title": "Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit)",
                    "summary": "Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/44482",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 44449",
                    "author": "Hans Topo & g0tmi1k",
                    "first_seen": "2018-04-13",
                    "confidence": "High",
                    "title": "Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution",
                    "summary": "Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/44449",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 44448",
                    "author": "Vitalii Rudnykh",
                    "first_seen": "2018-04-13",
                    "confidence": "High",
                    "title": "Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC)",
                    "summary": "Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC)",
                    "url": "https://www.exploit-db.com/exploits/44448",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · g0rx/CVE-2018-7600-Drupal-RCE",
                    "author": "g0rx",
                    "first_seen": "2018-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 114,
                    "title": "CVE-2018-7600 Drupal RCE",
                    "summary": "CVE-2018-7600 Drupal RCE",
                    "url": "https://github.com/g0rx/CVE-2018-7600-Drupal-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · a2u/CVE-2018-7600",
                    "author": "a2u",
                    "first_seen": "2018-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 354,
                    "title": "💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002",
                    "summary": "💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002",
                    "url": "https://github.com/a2u/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · dreadlocked/Drupalgeddon2",
                    "author": "dreadlocked",
                    "first_seen": "2018-04-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 604,
                    "title": "Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)",
                    "summary": "Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)",
                    "url": "https://github.com/dreadlocked/Drupalgeddon2"
                },
                {
                    "repository": "PoC-in-GitHub · knqyf263/CVE-2018-7600",
                    "author": "knqyf263",
                    "first_seen": "2018-04-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2018-7600 (Drupal)",
                    "summary": "CVE-2018-7600 (Drupal)",
                    "url": "https://github.com/knqyf263/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · dr-iman/CVE-2018-7600-Drupal-0day-RCE",
                    "author": "dr-iman",
                    "first_seen": "2018-04-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Drupal 0day Remote PHP Code Execution (Perl)",
                    "summary": "Drupal 0day Remote PHP Code Execution (Perl)",
                    "url": "https://github.com/dr-iman/CVE-2018-7600-Drupal-0day-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · jirojo2/drupalgeddon2",
                    "author": "jirojo2",
                    "first_seen": "2018-04-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "MSF exploit module for Drupalgeddon 2 (CVE-2018-7600 / SA-CORE-2018-002)",
                    "summary": "MSF exploit module for Drupalgeddon 2 (CVE-2018-7600 / SA-CORE-2018-002)",
                    "url": "https://github.com/jirojo2/drupalgeddon2"
                },
                {
                    "repository": "PoC-in-GitHub · dwisiswant0/CVE-2018-7600",
                    "author": "dwisiswant0",
                    "first_seen": "2018-04-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "PoC for CVE-2018-7600 Drupal SA-CORE-2018-002 (Drupalgeddon 2).",
                    "summary": "PoC for CVE-2018-7600 Drupal SA-CORE-2018-002 (Drupalgeddon 2).",
                    "url": "https://github.com/dwisiswant0/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · thehappydinoa/CVE-2018-7600",
                    "author": "thehappydinoa",
                    "first_seen": "2018-04-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Proof-of-Concept for Drupal CVE-2018-7600 / SA-CORE-2018-002",
                    "summary": "Proof-of-Concept for Drupal CVE-2018-7600 / SA-CORE-2018-002",
                    "url": "https://github.com/thehappydinoa/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · sl4cky/CVE-2018-7600",
                    "author": "sl4cky",
                    "first_seen": "2018-04-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600)",
                    "summary": "Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600)",
                    "url": "https://github.com/sl4cky/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · sl4cky/CVE-2018-7600-Masschecker",
                    "author": "sl4cky",
                    "first_seen": "2018-04-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Tool to check for CVE-2018-7600 vulnerability on several URLS",
                    "summary": "Tool to check for CVE-2018-7600 vulnerability on several URLS",
                    "url": "https://github.com/sl4cky/CVE-2018-7600-Masschecker"
                },
                {
                    "repository": "PoC-in-GitHub · firefart/CVE-2018-7600",
                    "author": "firefart",
                    "first_seen": "2018-04-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 71,
                    "title": "CVE-2018-7600 - Drupal 7.x RCE",
                    "summary": "CVE-2018-7600 - Drupal 7.x RCE",
                    "url": "https://github.com/firefart/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · pimps/CVE-2018-7600",
                    "author": "pimps",
                    "first_seen": "2018-04-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 140,
                    "title": "Exploit for Drupal 7 <= 7.57 CVE-2018-7600",
                    "summary": "Exploit for Drupal 7 <= 7.57 CVE-2018-7600",
                    "url": "https://github.com/pimps/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · lorddemon/drupalgeddon2",
                    "author": "lorddemon",
                    "first_seen": "2018-04-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "Exploit for CVE-2018-7600.. called drupalgeddon2,",
                    "summary": "Exploit for CVE-2018-7600.. called drupalgeddon2,",
                    "url": "https://github.com/lorddemon/drupalgeddon2"
                },
                {
                    "repository": "PoC-in-GitHub · Hestat/drupal-check",
                    "author": "Hestat",
                    "first_seen": "2018-04-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600",
                    "summary": "Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600",
                    "url": "https://github.com/Hestat/drupal-check"
                },
                {
                    "repository": "PoC-in-GitHub · Damian972/drupalgeddon-2",
                    "author": "Damian972",
                    "first_seen": "2018-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Vuln checker for Drupal v7.x + v8.x (CVE-2018-7600 / SA-CORE-2018-002)",
                    "summary": "Vuln checker for Drupal v7.x + v8.x (CVE-2018-7600 / SA-CORE-2018-002)",
                    "url": "https://github.com/Damian972/drupalgeddon-2"
                },
                {
                    "repository": "PoC-in-GitHub · soch4n/CVE-2018-7600",
                    "author": "soch4n",
                    "first_seen": "2018-05-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-7600 repository",
                    "summary": "",
                    "url": "https://github.com/soch4n/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · happynote3966/CVE-2018-7600",
                    "author": "happynote3966",
                    "first_seen": "2018-07-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-7600 repository",
                    "summary": "",
                    "url": "https://github.com/happynote3966/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · shellord/CVE-2018-7600-Drupal-RCE",
                    "author": "shellord",
                    "first_seen": "2018-10-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "MASS Exploiter",
                    "summary": "MASS Exploiter",
                    "url": "https://github.com/shellord/CVE-2018-7600-Drupal-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · r3dxpl0it/CVE-2018-7600",
                    "author": "r3dxpl0it",
                    "first_seen": "2018-10-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "CVE-2018-7600 POC (Drupal RCE)",
                    "summary": "CVE-2018-7600 POC (Drupal RCE)",
                    "url": "https://github.com/r3dxpl0it/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · cved-sources/cve-2018-7600",
                    "author": "cved-sources",
                    "first_seen": "2019-01-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "cve-2018-7600",
                    "summary": "cve-2018-7600",
                    "url": "https://github.com/cved-sources/cve-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · madneal/codeql-scanner",
                    "author": "madneal",
                    "first_seen": "2019-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "The exploit python script for CVE-2018-7600",
                    "summary": "The exploit python script for CVE-2018-7600",
                    "url": "https://github.com/madneal/codeql-scanner"
                },
                {
                    "repository": "PoC-in-GitHub · drugeddon/drupal-exploit",
                    "author": "drugeddon",
                    "first_seen": "2019-03-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2018-7600",
                    "summary": "CVE-2018-7600",
                    "url": "https://github.com/drugeddon/drupal-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · shellord/Drupalgeddon-Mass-Exploiter",
                    "author": "shellord",
                    "first_seen": "2019-10-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2018-7600 and CVE-2018-7602 Mass Exploiter",
                    "summary": "CVE-2018-7600 and CVE-2018-7602 Mass Exploiter",
                    "url": "https://github.com/shellord/Drupalgeddon-Mass-Exploiter"
                },
                {
                    "repository": "PoC-in-GitHub · zhzyker/CVE-2018-7600-Drupal-POC-EXP",
                    "author": "zhzyker",
                    "first_seen": "2020-04-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本",
                    "summary": "CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本",
                    "url": "https://github.com/zhzyker/CVE-2018-7600-Drupal-POC-EXP"
                },
                {
                    "repository": "PoC-in-GitHub · rabbitmask/CVE-2018-7600-Drupal7",
                    "author": "rabbitmask",
                    "first_seen": "2020-04-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "CVE-2018-7600【Drupal7】批量扫描工具。",
                    "summary": "CVE-2018-7600【Drupal7】批量扫描工具。",
                    "url": "https://github.com/rabbitmask/CVE-2018-7600-Drupal7"
                },
                {
                    "repository": "PoC-in-GitHub · ynsmroztas/drupalhunter",
                    "author": "ynsmroztas",
                    "first_seen": "2020-06-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-7600 0-Day Exploit (cyber-warrior.org)",
                    "summary": "CVE-2018-7600 0-Day Exploit (cyber-warrior.org)",
                    "url": "https://github.com/ynsmroztas/drupalhunter"
                },
                {
                    "repository": "PoC-in-GitHub · ruthvikvegunta/Drupalgeddon2",
                    "author": "ruthvikvegunta",
                    "first_seen": "2020-08-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-7600 | Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' RCE",
                    "summary": "CVE-2018-7600 | Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' RCE",
                    "url": "https://github.com/ruthvikvegunta/Drupalgeddon2"
                },
                {
                    "repository": "PoC-in-GitHub · ludy-dev/drupal8-REST-RCE",
                    "author": "ludy-dev",
                    "first_seen": "2020-08-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "(CVE-2019-6340, CVE-2018-7600) drupal8-REST-RCE",
                    "summary": "(CVE-2019-6340, CVE-2018-7600) drupal8-REST-RCE",
                    "url": "https://github.com/ludy-dev/drupal8-REST-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · 0xAJ2K/CVE-2018-7600",
                    "author": "0xAJ2K",
                    "first_seen": "2021-06-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Drupal 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.",
                    "summary": "Drupal 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.",
                    "url": "https://github.com/0xAJ2K/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · RB4C/drupalgeddon2-CVE-2018-7600",
                    "author": "RB4C",
                    "first_seen": "2021-10-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-7600 repository",
                    "summary": "",
                    "url": "https://github.com/RB4C/drupalgeddon2-CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · vphnguyen/ANM_CVE-2018-7600",
                    "author": "vphnguyen",
                    "first_seen": "2021-11-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Detect with python and tracking IP",
                    "summary": "Detect with python and tracking IP",
                    "url": "https://github.com/vphnguyen/ANM_CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · anldori/CVE-2018-7600",
                    "author": "anldori",
                    "first_seen": "2022-04-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-7600 repository",
                    "summary": "",
                    "url": "https://github.com/anldori/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · r0lh/CVE-2018-7600",
                    "author": "r0lh",
                    "first_seen": "2022-12-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Drupal CVE-2018-7600 RCE Pseudo-Shell PoC",
                    "summary": "Drupal CVE-2018-7600 RCE Pseudo-Shell PoC",
                    "url": "https://github.com/r0lh/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · raytran54/CVE-2018-7600",
                    "author": "raytran54",
                    "first_seen": "2024-06-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-7600 repository",
                    "summary": "",
                    "url": "https://github.com/raytran54/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · tpdlshdmlrkfmcla/CVE-2018-7600.",
                    "author": "tpdlshdmlrkfmcla",
                    "first_seen": "2025-03-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-7600.",
                    "summary": "CVE-2018-7600.",
                    "url": "https://github.com/tpdlshdmlrkfmcla/CVE-2018-7600."
                },
                {
                    "repository": "PoC-in-GitHub · Dowonkwon/drupal-cve-2018-7600-poc",
                    "author": "Dowonkwon",
                    "first_seen": "2025-04-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-7600 repository",
                    "summary": "",
                    "url": "https://github.com/Dowonkwon/drupal-cve-2018-7600-poc"
                },
                {
                    "repository": "PoC-in-GitHub · M-Abid34/CVE-2018-7600",
                    "author": "M-Abid34",
                    "first_seen": "2025-08-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "For Home Lab and Educational Purpose only not intended for any Harmful intenstions purely for educational purpose",
                    "summary": "For Home Lab and Educational Purpose only not intended for any Harmful intenstions purely for educational purpose",
                    "url": "https://github.com/M-Abid34/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · rajaabdullahnasir/CVE-2018-7600-Remote-Code-Execution",
                    "author": "rajaabdullahnasir",
                    "first_seen": "2025-08-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository contains a completely original and self-developed Proof-of-Concept (PoC) for CVE-2018-7600, also known as Drupalgeddon 2 — a critical remote code execution vulnerability affecting Drupal 7 and 8 core versions.",
                    "summary": "This repository contains a completely original and self-developed Proof-of-Concept (PoC) for CVE-2018-7600, also known as Drupalgeddon 2 — a critical remote code execution vulnerability affecting Drupal 7 and 8 core versions.",
                    "url": "https://github.com/rajaabdullahnasir/CVE-2018-7600-Remote-Code-Execution"
                },
                {
                    "repository": "PoC-in-GitHub · xxxTectationxxx/CVE-2018-7600",
                    "author": "xxxTectationxxx",
                    "first_seen": "2025-08-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Program python untuk melakukan RCE pada drupal versi 7.56",
                    "summary": "Program python untuk melakukan RCE pada drupal versi 7.56",
                    "url": "https://github.com/xxxTectationxxx/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · muhammedkayag/CVE-2018-7600",
                    "author": "muhammedkayag",
                    "first_seen": "2025-08-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC of CVE-2018-7600",
                    "summary": "PoC of CVE-2018-7600",
                    "url": "https://github.com/muhammedkayag/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · SyedGhufranRaza/CVE-2018-7600-Remote-Code-Execution",
                    "author": "SyedGhufranRaza",
                    "first_seen": "2025-08-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository showcases a fully self-developed Proof-of-Concept (PoC) for CVE-2018-7600, widely known as Drupalgeddon 2. This critical vulnerability in Drupal 7 and 8 core enables remote code execution (RCE), and the PoC demonstrates its exploitation in a clear and educational manner.",
                    "summary": "This repository showcases a fully self-developed Proof-of-Concept (PoC) for CVE-2018-7600, widely known as Drupalgeddon 2. This critical vulnerability in Drupal 7 and 8 core enables remote code execution (RCE), and the PoC demonstrates its exploitation in a clear and educational manner.",
                    "url": "https://github.com/SyedGhufranRaza/CVE-2018-7600-Remote-Code-Execution"
                },
                {
                    "repository": "PoC-in-GitHub · nika0x38/CVE-2018-7600",
                    "author": "nika0x38",
                    "first_seen": "2025-09-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A Rust implementation of the CVE-2018-7600 exploit targeting vulnerable Drupal 7 installations (<= 7.57)",
                    "summary": "A Rust implementation of the CVE-2018-7600 exploit targeting vulnerable Drupal 7 installations (<= 7.57)",
                    "url": "https://github.com/nika0x38/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · tea-celikik/Drupal-Exploit-Lab",
                    "author": "tea-celikik",
                    "first_seen": "2025-09-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Demonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall)",
                    "summary": "Demonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall)",
                    "url": "https://github.com/tea-celikik/Drupal-Exploit-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · 4l13n-DN/POC-CVE-2018-7600",
                    "author": "4l13n-DN",
                    "first_seen": "2025-12-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Drupal vulnerable a CVE-2018-7600",
                    "summary": "Drupal vulnerable a CVE-2018-7600",
                    "url": "https://github.com/4l13n-DN/POC-CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · bixiPRO/Drupalgeddon2-CVE-2018-7600",
                    "author": "bixiPRO",
                    "first_seen": "2026-02-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-7600 repository",
                    "summary": "",
                    "url": "https://github.com/bixiPRO/Drupalgeddon2-CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · Meraj1312/cve-2018-7600-drupalgeddon2-lab",
                    "author": "Meraj1312",
                    "first_seen": "2026-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Educational lab demonstrating CVE-2018-7600 (Drupalgeddon2) Remote Code Execution using a Docker-based vulnerable Drupal 7.56 environment.",
                    "summary": "Educational lab demonstrating CVE-2018-7600 (Drupalgeddon2) Remote Code Execution using a Docker-based vulnerable Drupal 7.56 environment.",
                    "url": "https://github.com/Meraj1312/cve-2018-7600-drupalgeddon2-lab"
                },
                {
                    "repository": "PoC-in-GitHub · erman-bolukbasi/web-penetration-drupal",
                    "author": "erman-bolukbasi",
                    "first_seen": "2026-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Penetration test of a Drupal web app — CVE-2018-7600 (Drupalgeddon 2) exploited using Nmap, Burp Suite & Metasploit | Internship @ BB CyberSec",
                    "summary": "Penetration test of a Drupal web app — CVE-2018-7600 (Drupalgeddon 2) exploited using Nmap, Burp Suite & Metasploit | Internship @ BB CyberSec",
                    "url": "https://github.com/erman-bolukbasi/web-penetration-drupal"
                },
                {
                    "repository": "PoC-in-GitHub · Dungsocool/CVE-2018-7600",
                    "author": "Dungsocool",
                    "first_seen": "2026-05-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-7600 repository",
                    "summary": "",
                    "url": "https://github.com/Dungsocool/CVE-2018-7600"
                },
                {
                    "repository": "PoC-in-GitHub · nayem-m/drupalgeddon2-cli",
                    "author": "nayem-m",
                    "first_seen": "2026-06-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CLI rewrite of the Drupalgeddon2 (CVE-2018-7600) PoC — for authorised testing/education",
                    "summary": "CLI rewrite of the Drupalgeddon2 (CVE-2018-7600) PoC — for authorised testing/education",
                    "url": "https://github.com/nayem-m/drupalgeddon2-cli"
                },
                {
                    "repository": "PoC-in-GitHub · Prapul1/VulnHub-DC1-Writeup",
                    "author": "Prapul1",
                    "first_seen": "2026-06-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password hash, and escalating to root via SUID find.",
                    "summary": "VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password hash, and escalating to root via SUID find.",
                    "url": "https://github.com/Prapul1/VulnHub-DC1-Writeup"
                },
                {
                    "repository": "PoC-in-GitHub · Shams-Ul-Mehmood/CVE-2018-7600-Drupalgeddon2-RCE",
                    "author": "Shams-Ul-Mehmood",
                    "first_seen": "2026-08-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-7600 repository",
                    "summary": "",
                    "url": "https://github.com/Shams-Ul-Mehmood/CVE-2018-7600-Drupalgeddon2-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · elkhaoudari/CVE-2018-7600-PoC",
                    "author": "elkhaoudari",
                    "first_seen": "2026-08-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2018-7600 repository",
                    "summary": "",
                    "url": "https://github.com/elkhaoudari/CVE-2018-7600-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · Vaibhav91one/drupalgeddon2-cve-lab",
                    "author": "Vaibhav91one",
                    "first_seen": "2026-08-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Drupalgeddon2 CVE-2018-7600 vulnerable Drupal 7 lab",
                    "summary": "Drupalgeddon2 CVE-2018-7600 vulnerable Drupal 7 lab",
                    "url": "https://github.com/Vaibhav91one/drupalgeddon2-cve-lab"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/44482",
                "https://www.exploit-db.com/exploits/44449",
                "https://www.exploit-db.com/exploits/44448",
                "https://github.com/g0rx/CVE-2018-7600-Drupal-RCE",
                "https://github.com/a2u/CVE-2018-7600",
                "https://github.com/dreadlocked/Drupalgeddon2",
                "https://github.com/knqyf263/CVE-2018-7600",
                "https://github.com/dr-iman/CVE-2018-7600-Drupal-0day-RCE",
                "https://github.com/jirojo2/drupalgeddon2",
                "https://github.com/dwisiswant0/CVE-2018-7600",
                "https://github.com/thehappydinoa/CVE-2018-7600",
                "https://github.com/sl4cky/CVE-2018-7600",
                "https://github.com/sl4cky/CVE-2018-7600-Masschecker",
                "https://github.com/firefart/CVE-2018-7600",
                "https://github.com/pimps/CVE-2018-7600",
                "https://github.com/lorddemon/drupalgeddon2",
                "https://github.com/Hestat/drupal-check",
                "https://github.com/Damian972/drupalgeddon-2",
                "https://github.com/soch4n/CVE-2018-7600",
                "https://github.com/happynote3966/CVE-2018-7600",
                "https://github.com/shellord/CVE-2018-7600-Drupal-RCE",
                "https://github.com/r3dxpl0it/CVE-2018-7600",
                "https://github.com/cved-sources/cve-2018-7600",
                "https://github.com/madneal/codeql-scanner",
                "https://github.com/drugeddon/drupal-exploit",
                "https://github.com/shellord/Drupalgeddon-Mass-Exploiter",
                "https://github.com/zhzyker/CVE-2018-7600-Drupal-POC-EXP",
                "https://github.com/rabbitmask/CVE-2018-7600-Drupal7",
                "https://github.com/ynsmroztas/drupalhunter",
                "https://github.com/ruthvikvegunta/Drupalgeddon2",
                "https://github.com/ludy-dev/drupal8-REST-RCE",
                "https://github.com/0xAJ2K/CVE-2018-7600",
                "https://github.com/RB4C/drupalgeddon2-CVE-2018-7600",
                "https://github.com/vphnguyen/ANM_CVE-2018-7600",
                "https://github.com/anldori/CVE-2018-7600",
                "https://github.com/r0lh/CVE-2018-7600",
                "https://github.com/raytran54/CVE-2018-7600",
                "https://github.com/tpdlshdmlrkfmcla/CVE-2018-7600.",
                "https://github.com/Dowonkwon/drupal-cve-2018-7600-poc",
                "https://github.com/M-Abid34/CVE-2018-7600",
                "https://github.com/rajaabdullahnasir/CVE-2018-7600-Remote-Code-Execution",
                "https://github.com/xxxTectationxxx/CVE-2018-7600",
                "https://github.com/muhammedkayag/CVE-2018-7600",
                "https://github.com/SyedGhufranRaza/CVE-2018-7600-Remote-Code-Execution",
                "https://github.com/nika0x38/CVE-2018-7600",
                "https://github.com/tea-celikik/Drupal-Exploit-Lab",
                "https://github.com/4l13n-DN/POC-CVE-2018-7600",
                "https://github.com/bixiPRO/Drupalgeddon2-CVE-2018-7600",
                "https://github.com/Meraj1312/cve-2018-7600-drupalgeddon2-lab",
                "https://github.com/erman-bolukbasi/web-penetration-drupal",
                "https://github.com/Dungsocool/CVE-2018-7600",
                "https://github.com/nayem-m/drupalgeddon2-cli",
                "https://github.com/Prapul1/VulnHub-DC1-Writeup",
                "https://github.com/Shams-Ul-Mehmood/CVE-2018-7600-Drupalgeddon2-RCE",
                "https://github.com/elkhaoudari/CVE-2018-7600-PoC",
                "https://github.com/Vaibhav91one/drupalgeddon2-cve-lab"
            ],
            "timeline": [
                {
                    "at": "2026-08-29T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2018-6961",
            "vendor": "VMware",
            "product": "SD-WAN Edge",
            "title": "VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability",
            "summary": "VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.",
            "updated_at": "2026-09-15T08:27:34Z",
            "published_at": "2026-09-15T08:27:34Z",
            "cvss": 8.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 24,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 44959",
                    "author": "ParagonSec",
                    "first_seen": "2018-07-02",
                    "confidence": "High",
                    "title": "VMware NSX SD-WAN Edge < 3.1.2 - Command Injection",
                    "summary": "VMware NSX SD-WAN Edge < 3.1.2 - Command Injection",
                    "url": "https://www.exploit-db.com/exploits/44959",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-15T08:27:34+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2018-6961 exploit",
                    "summary": "Exploit for CVE-2018-6961. CVSS 8.1.",
                    "cvss": 8.1,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BOKANRB-CVE-2018-6961"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/44959",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BOKANRB-CVE-2018-6961"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:27:34Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-25",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2018-4993",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Bad-Pdf CVE-2018-4993",
            "summary": "Bad-PDF tool creates malicious PDF files to steal NTLM hashes from Windows via CVE-2018-4993.",
            "updated_at": "2026-09-05T05:55:01Z",
            "published_at": "2026-09-05T05:55:01Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 59,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Bad-PDF tool creates malicious PDF files to steal NTLM hashes from Windows via CVE-2018-4993.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Bad-Pdf CVE-2018-4993",
                    "summary": "Bad-PDF tool creates malicious PDF files to steal NTLM hashes from Windows via CVE-2018-4993.",
                    "what_happened": "Bad-PDF tool creates malicious PDF files to steal NTLM hashes from Windows via CVE-2018-4993.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DEEPZEC-BAD-PDF",
                        "https://kitploit.com/ru/tools/github/deepzec/bad-pdf/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T07:55:01",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DEEPZEC-BAD-PDF"
                },
                {
                    "title": "Exploit for Bad-Pdf CVE-2018-4993",
                    "summary": "Bad-PDF tool creates malicious PDF files to steal NTLM hashes from Windows via CVE-2018-4993.",
                    "what_happened": "Bad-PDF tool creates malicious PDF files to steal NTLM hashes from Windows via CVE-2018-4993.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DEEPZEC-BAD-PDF",
                        "https://kitploit.com/ru/tools/github/deepzec/bad-pdf/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T07:55:01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/deepzec/bad-pdf/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DEEPZEC-BAD-PDF",
                "https://kitploit.com/ru/tools/github/deepzec/bad-pdf/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T05:55:01Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DEEPZEC-BAD-PDF"
                }
            ],
            "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
        },
        {
            "id": "CVE-2018-4407",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for AppleDOS CVE-2018-4407",
            "summary": "Heap overflow in Apple XNU ICMP error handling via crafted TCP packets crashes iOS 11 and macOS.",
            "updated_at": "2026-09-04T08:07:12Z",
            "published_at": "2026-09-04T08:07:12Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 21,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Low",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Heap overflow in Apple XNU ICMP error handling via crafted TCP packets crashes iOS 11 and macOS.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for AppleDOS CVE-2018-4407",
                    "summary": "Heap overflow in Apple XNU ICMP error handling via crafted TCP packets crashes iOS 11 and macOS.",
                    "what_happened": "Heap overflow in Apple XNU ICMP error handling via crafted TCP packets crashes iOS 11 and macOS.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FARISV-APPLEDOS",
                        "https://kitploit.com/ru/tools/github/farisv/appledos/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T10:07:12",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FARISV-APPLEDOS"
                },
                {
                    "title": "Exploit for AppleDOS CVE-2018-4407",
                    "summary": "Heap overflow in Apple XNU ICMP error handling via crafted TCP packets crashes iOS 11 and macOS.",
                    "what_happened": "Heap overflow in Apple XNU ICMP error handling via crafted TCP packets crashes iOS 11 and macOS.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FARISV-APPLEDOS",
                        "https://kitploit.com/ru/tools/github/farisv/appledos/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T10:07:12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/farisv/appledos/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FARISV-APPLEDOS",
                "https://kitploit.com/ru/tools/github/farisv/appledos/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T08:07:12Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FARISV-APPLEDOS"
                }
            ],
            "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2018-3810",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection",
            "summary": "WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection",
            "updated_at": "2026-09-13T18:06:08Z",
            "published_at": "2026-09-13T18:06:08Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 33,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 43420",
                    "author": "Benjamin Lim",
                    "first_seen": "2018-01-03",
                    "confidence": "High",
                    "title": "WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection",
                    "summary": "WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection",
                    "url": "https://www.exploit-db.com/exploits/43420",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:06:08+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "cve-2018-3810 exploit",
                    "summary": "Exploit for CVE-2018-3810. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CVED-SOURCES-CVE-2018-3810"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/43420",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CVED-SOURCES-CVE-2018-3810"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:06:08Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/43420"
                }
            ]
        },
        {
            "id": "CVE-2018-3004",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for odat",
            "summary": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
            "updated_at": "2026-09-03T19:22:31Z",
            "published_at": "2026-09-03T19:22:31Z",
            "cvss": 8.7,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 19,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for odat",
                    "summary": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
                    "what_happened": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
                    "cvss": 8.7,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A425673185408838890",
                        "https://kitploit.com/en/tools/github/quentinhardy/odat/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T21:22:31",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A425673185408838890"
                },
                {
                    "title": "Exploit for odat",
                    "summary": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
                    "what_happened": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
                    "cvss": 8.7,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A425673185408838890",
                        "https://kitploit.com/en/tools/github/quentinhardy/odat/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-03T21:22:31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/quentinhardy/odat/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3A425673185408838890",
                "https://kitploit.com/en/tools/github/quentinhardy/odat/"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T19:22:31Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A425673185408838890"
                }
            ],
            "cvss_vector": "NONE"
        },
        {
            "id": "CVE-2018-2894",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2018-2894 exploit",
            "summary": "Exploit for CVE-2018-2894. CVSS 9.8.",
            "updated_at": "2026-09-07T08:10:56Z",
            "published_at": "2026-09-07T08:10:56Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 73,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Vulnerability CVE-2018-2894 in tools repository.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2018-2894",
                    "summary": "Vulnerability CVE-2018-2894 in tools repository.",
                    "what_happened": "Vulnerability CVE-2018-2894 in tools repository.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2018-2894",
                        "https://kitploit.com/hi/tools/github/jas502n/cve-2018-2894/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T06:26:26",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2018-2894"
                },
                {
                    "title": "Exploit for CVE-2018-2894",
                    "summary": "Vulnerability CVE-2018-2894 in tools repository.",
                    "what_happened": "Vulnerability CVE-2018-2894 in tools repository.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2018-2894",
                        "https://kitploit.com/hi/tools/github/jas502n/cve-2018-2894/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T06:26:26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/jas502n/cve-2018-2894/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2018-2894",
                "https://kitploit.com/hi/tools/github/jas502n/cve-2018-2894/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:10:56Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JAS502N-CVE-2018-2894"
                }
            ]
        },
        {
            "id": "CVE-2018-1207",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Dell EMC iDRAC7/iDRAC8 2.52.52.52 -  Remote Code Execution (RCE)",
            "summary": "Dell EMC iDRAC7/iDRAC8 2.52.52.52 -  Remote Code Execution (RCE)",
            "updated_at": "2026-09-12T15:05:51Z",
            "published_at": "2026-09-12T15:05:51Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 48,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 52246",
                    "author": "Photubias",
                    "first_seen": "2025-04-16",
                    "confidence": "High",
                    "title": "Dell EMC iDRAC7/iDRAC8 2.52.52.52 -  Remote Code Execution (RCE)",
                    "summary": "Dell EMC iDRAC7/iDRAC8 2.52.52.52 -  Remote Code Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/52246",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T15:05:51+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2018-1207-better exploit",
                    "summary": "Exploit for CVE-2018-1207. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HIRONULL-CVE-2018-1207-BETTER"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/52246",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HIRONULL-CVE-2018-1207-BETTER"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T15:05:51Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/52246"
                }
            ]
        },
        {
            "id": "CVE-2018-0824",
            "vendor": "Microsoft",
            "product": "Windows",
            "title": "Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
            "summary": "Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.",
            "updated_at": "2026-09-05T21:37:33Z",
            "published_at": "2026-09-05T21:37:33Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 30,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 44906",
                    "author": "Code White",
                    "first_seen": "2018-06-18",
                    "confidence": "High",
                    "title": "Microsoft COM for Windows - Privilege Escalation",
                    "summary": "Microsoft COM for Windows - Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/44906",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for UnmarshalPwn CVE-2018-0624 CVE-2018-0824",
                    "summary": "UnmarshalPwn is a POC for CVE-2018-0824 demonstrating an unmarshal vulnerability.",
                    "what_happened": "UnmarshalPwn is a POC for CVE-2018-0824 demonstrating an unmarshal vulnerability.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CODEWHITESEC-UNMARSHALPWN",
                        "https://kitploit.com/hi/tools/github/codewhitesec/unmarshalpwn/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T23:37:33",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CODEWHITESEC-UNMARSHALPWN"
                },
                {
                    "title": "Exploit for UnmarshalPwn CVE-2018-0624 CVE-2018-0824",
                    "summary": "UnmarshalPwn is a POC for CVE-2018-0824 demonstrating an unmarshal vulnerability.",
                    "what_happened": "UnmarshalPwn is a POC for CVE-2018-0824 demonstrating an unmarshal vulnerability.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CODEWHITESEC-UNMARSHALPWN",
                        "https://kitploit.com/hi/tools/github/codewhitesec/unmarshalpwn/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-05T23:37:33",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/codewhitesec/unmarshalpwn/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/44906",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CODEWHITESEC-UNMARSHALPWN",
                "https://kitploit.com/hi/tools/github/codewhitesec/unmarshalpwn/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T21:37:33Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2024-08-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2018-0624",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for UnmarshalPwn CVE-2018-0624 CVE-2018-0824",
            "summary": "UnmarshalPwn is a POC for CVE-2018-0824 demonstrating an unmarshal vulnerability.",
            "updated_at": "2026-09-05T21:37:33Z",
            "published_at": "2026-09-05T21:37:33Z",
            "cvss": 8.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 13,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "UnmarshalPwn is a POC for CVE-2018-0824 demonstrating an unmarshal vulnerability.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for UnmarshalPwn CVE-2018-0624 CVE-2018-0824",
                    "summary": "UnmarshalPwn is a POC for CVE-2018-0824 demonstrating an unmarshal vulnerability.",
                    "what_happened": "UnmarshalPwn is a POC for CVE-2018-0824 demonstrating an unmarshal vulnerability.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CODEWHITESEC-UNMARSHALPWN",
                        "https://kitploit.com/hi/tools/github/codewhitesec/unmarshalpwn/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T23:37:33",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CODEWHITESEC-UNMARSHALPWN"
                },
                {
                    "title": "Exploit for UnmarshalPwn CVE-2018-0624 CVE-2018-0824",
                    "summary": "UnmarshalPwn is a POC for CVE-2018-0824 demonstrating an unmarshal vulnerability.",
                    "what_happened": "UnmarshalPwn is a POC for CVE-2018-0824 demonstrating an unmarshal vulnerability.",
                    "cvss": 8.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CODEWHITESEC-UNMARSHALPWN",
                        "https://kitploit.com/hi/tools/github/codewhitesec/unmarshalpwn/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-05T23:37:33",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/codewhitesec/unmarshalpwn/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CODEWHITESEC-UNMARSHALPWN",
                "https://kitploit.com/hi/tools/github/codewhitesec/unmarshalpwn/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T21:37:33Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CODEWHITESEC-UNMARSHALPWN"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2018-0114",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Cisco node-jos < 0.11.0 - Re-sign Tokens",
            "summary": "Cisco node-jos < 0.11.0 - Re-sign Tokens",
            "updated_at": "2026-09-09T04:48:12Z",
            "published_at": "2026-09-09T04:48:12Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 186,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 44324",
                    "author": "zioBlack",
                    "first_seen": "2018-03-20",
                    "confidence": "High",
                    "title": "Cisco node-jos < 0.11.0 - Re-sign Tokens",
                    "summary": "Cisco node-jos < 0.11.0 - Re-sign Tokens",
                    "url": "https://www.exploit-db.com/exploits/44324",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2020-28042 CVE-2020-28637 CVE-2022-21449",
                    "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                        "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-10T07:59:46",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299"
                },
                {
                    "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2020-28042 CVE-2020-28637 CVE-2022-21449",
                    "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                        "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-10T07:59:46",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                },
                {
                    "repository": "PoC-in-GitHub · zi0Black/POC-CVE-2018-0114",
                    "author": "zi0Black",
                    "first_seen": "2018-03-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 26,
                    "title": "This repository contains the POC of an exploit for node-jose < 0.11.0",
                    "summary": "This repository contains the POC of an exploit for node-jose < 0.11.0",
                    "url": "https://github.com/zi0Black/POC-CVE-2018-0114"
                },
                {
                    "repository": "PoC-in-GitHub · Logeirs/CVE-2018-0114",
                    "author": "Logeirs",
                    "first_seen": "2020-08-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-0114 repository",
                    "summary": "",
                    "url": "https://github.com/Logeirs/CVE-2018-0114"
                },
                {
                    "repository": "PoC-in-GitHub · adityathebe/POC-CVE-2018-0114",
                    "author": "adityathebe",
                    "first_seen": "2020-12-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "POC for CVE-2018-0114 written in Go",
                    "summary": "POC for CVE-2018-0114 written in Go",
                    "url": "https://github.com/adityathebe/POC-CVE-2018-0114"
                },
                {
                    "repository": "PoC-in-GitHub · Eremiel/CVE-2018-0114",
                    "author": "Eremiel",
                    "first_seen": "2021-01-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "python2.7 script for JWT generation",
                    "summary": "python2.7 script for JWT generation",
                    "url": "https://github.com/Eremiel/CVE-2018-0114"
                },
                {
                    "repository": "PoC-in-GitHub · Starry-lord/CVE-2018-0114",
                    "author": "Starry-lord",
                    "first_seen": "2021-01-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-0114 repository",
                    "summary": "",
                    "url": "https://github.com/Starry-lord/CVE-2018-0114"
                },
                {
                    "repository": "PoC-in-GitHub · scumdestroy/CVE-2018-0114",
                    "author": "scumdestroy",
                    "first_seen": "2021-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Exploit  for Node-jose < 0.11.0 written in Ruby",
                    "summary": "Exploit  for Node-jose < 0.11.0 written in Ruby",
                    "url": "https://github.com/scumdestroy/CVE-2018-0114"
                },
                {
                    "repository": "PoC-in-GitHub · j4k0m/CVE-2018-0114",
                    "author": "j4k0m",
                    "first_seen": "2021-09-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT.",
                    "summary": "Exploitation of a vulnerability in Cisco's node-jose, a JavaScript library created to manage JWT.",
                    "url": "https://github.com/j4k0m/CVE-2018-0114"
                },
                {
                    "repository": "PoC-in-GitHub · mmeza-developer/CVE-2018-0114",
                    "author": "mmeza-developer",
                    "first_seen": "2021-11-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "JWT Exploit",
                    "summary": "JWT Exploit",
                    "url": "https://github.com/mmeza-developer/CVE-2018-0114"
                },
                {
                    "repository": "PoC-in-GitHub · Pandora-research/CVE-2018-0114-Exploit",
                    "author": "Pandora-research",
                    "first_seen": "2022-09-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-0114 repository",
                    "summary": "",
                    "url": "https://github.com/Pandora-research/CVE-2018-0114-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · amr9k8/jwt-spoof-tool",
                    "author": "amr9k8",
                    "first_seen": "2023-03-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Automate JWT Exploit  (CVE-2018-0114)",
                    "summary": "Automate JWT Exploit  (CVE-2018-0114)",
                    "url": "https://github.com/amr9k8/jwt-spoof-tool"
                },
                {
                    "repository": "PoC-in-GitHub · z-bool/Venom-JWT",
                    "author": "z-bool",
                    "first_seen": "2025-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 288,
                    "title": "针对JWT渗透开发的漏洞验证/密钥爆破工具，针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ，也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)",
                    "summary": "针对JWT渗透开发的漏洞验证/密钥爆破工具，针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ，也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)",
                    "url": "https://github.com/z-bool/Venom-JWT"
                },
                {
                    "repository": "PoC-in-GitHub · sealldeveloper/CVE-2018-0114-PoC",
                    "author": "sealldeveloper",
                    "first_seen": "2025-04-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A PoC of CVE-2018-0114 I made for PentesterLab",
                    "summary": "A PoC of CVE-2018-0114 I made for PentesterLab",
                    "url": "https://github.com/sealldeveloper/CVE-2018-0114-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · n0m-d/CVE-2018-0114-Go",
                    "author": "n0m-d",
                    "first_seen": "2025-08-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2018-0114 repository",
                    "summary": "",
                    "url": "https://github.com/n0m-d/CVE-2018-0114-Go"
                },
                {
                    "repository": "PoC-in-GitHub · fevra-dev/ClaimJumper",
                    "author": "fevra-dev",
                    "first_seen": "2026-01-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist, and CVE-specific attacks (CVE-2022-21449, CVE-2018-0114).",
                    "summary": "Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist, and CVE-specific attacks (CVE-2022-21449, CVE-2018-0114).",
                    "url": "https://github.com/fevra-dev/ClaimJumper"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/44324",
                "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/",
                "https://github.com/zi0Black/POC-CVE-2018-0114",
                "https://github.com/Logeirs/CVE-2018-0114",
                "https://github.com/adityathebe/POC-CVE-2018-0114",
                "https://github.com/Eremiel/CVE-2018-0114",
                "https://github.com/Starry-lord/CVE-2018-0114",
                "https://github.com/scumdestroy/CVE-2018-0114",
                "https://github.com/j4k0m/CVE-2018-0114",
                "https://github.com/mmeza-developer/CVE-2018-0114",
                "https://github.com/Pandora-research/CVE-2018-0114-Exploit",
                "https://github.com/amr9k8/jwt-spoof-tool",
                "https://github.com/z-bool/Venom-JWT",
                "https://github.com/sealldeveloper/CVE-2018-0114-PoC",
                "https://github.com/n0m-d/CVE-2018-0114-Go",
                "https://github.com/fevra-dev/ClaimJumper"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T04:48:12Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/44324"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2017-17537",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "MikroTik RouterBOARD v6.39.2 and v6.40.5 allows an unauthenticated remote attacker to cause a denial of service by connecting to TCP port 53 and sending data that begins with many '\\0' characters, possibly related to DNS.",
            "updated_at": "2026-09-16T21:17:04.613",
            "published_at": "2017-12-13T16:29:00.363",
            "cvss": 7.5,
            "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 3,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-20",
            "what_happened": "MikroTik RouterBOARD v6.39.2 and v6.40.5 allows an unauthenticated remote attacker to cause a denial of service by connecting to TCP port 53 and sending data that begins with many '\\0' characters, possibly related to DNS.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "https://packetstorm.news/files/id/145382",
                "https://www.exploit-db.com/exploits/43200/"
            ],
            "timeline": [
                {
                    "at": "2017-12-13T16:29:00.363",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-17537"
                }
            ]
        },
        {
            "id": "CVE-2017-17215",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Huawei Router HG532 - Arbitrary Command Execution",
            "summary": "Huawei Router HG532 - Arbitrary Command Execution",
            "updated_at": "2026-09-07T17:47:48Z",
            "published_at": "2026-09-07T17:47:48Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 229,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Unknown",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Stack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 43414",
                    "author": "anonymous",
                    "first_seen": "2017-12-25",
                    "confidence": "High",
                    "title": "Huawei Router HG532 - Arbitrary Command Execution",
                    "summary": "Huawei Router HG532 - Arbitrary Command Execution",
                    "url": "https://www.exploit-db.com/exploits/43414",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for misfortune-cookie CVE-2014-9222",
                    "summary": "Stack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.",
                    "what_happened": "Stack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=FC88F5FE-B4FC-50D7-BADB-82E69F300083",
                        "https://github.com/luel-4013/misfortune-cookie"
                    ],
                    "repository": "Sploitus",
                    "author": "luel-4013",
                    "first_seen": "2026-09-07T19:47:48",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=FC88F5FE-B4FC-50D7-BADB-82E69F300083"
                },
                {
                    "repository": "PoC-in-GitHub · luel-4013/misfortune-cookie",
                    "author": "luel-4013",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This interactive suite targets CVE-2014-9222 (Misfortune Cookie) in legacy RomPager web servers, alongside modular testing for CVE-2017-17215 (Huawei HG532 RCE), CVE-2018-14847 (MikroTik WinBox credential leak), and the CVE-2021-27101 / CVE-2021-27102 exploit chain (Accellion FTA).",
                    "summary": "This interactive suite targets CVE-2014-9222 (Misfortune Cookie) in legacy RomPager web servers, alongside modular testing for CVE-2017-17215 (Huawei HG532 RCE), CVE-2018-14847 (MikroTik WinBox credential leak), and the CVE-2021-27101 / CVE-2021-27102 exploit chain (Accellion FTA).",
                    "url": "https://github.com/luel-4013/misfortune-cookie"
                },
                {
                    "repository": "PoC-in-GitHub · 1337g/CVE-2017-17215",
                    "author": "1337g",
                    "first_seen": "2017-12-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 26,
                    "title": "CVE-2017-17215 HuaWei Router RCE (NOT TESTED)",
                    "summary": "CVE-2017-17215 HuaWei Router RCE (NOT TESTED)",
                    "url": "https://github.com/1337g/CVE-2017-17215"
                },
                {
                    "repository": "PoC-in-GitHub · wilfred-wulbou/HG532d-RCE-Exploit",
                    "author": "wilfred-wulbou",
                    "first_seen": "2020-11-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "A Remote Code Execution (RCE) exploit for Huawei HG532d based on CVE-2017-17215 vulnerability. Modded from original PoC code from exploit-db.com",
                    "summary": "A Remote Code Execution (RCE) exploit for Huawei HG532d based on CVE-2017-17215 vulnerability. Modded from original PoC code from exploit-db.com",
                    "url": "https://github.com/wilfred-wulbou/HG532d-RCE-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · ltfafei/HuaWei_Route_HG532_RCE_CVE-2017-17215",
                    "author": "ltfafei",
                    "first_seen": "2022-11-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "POCsuite与goland实现华为HG532路由器命令注入CVE-2017-17215 POC",
                    "summary": "POCsuite与goland实现华为HG532路由器命令注入CVE-2017-17215 POC",
                    "url": "https://github.com/ltfafei/HuaWei_Route_HG532_RCE_CVE-2017-17215"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/43414",
                "https://sploitus.com/exploit?id=FC88F5FE-B4FC-50D7-BADB-82E69F300083",
                "https://github.com/luel-4013/misfortune-cookie",
                "https://github.com/1337g/CVE-2017-17215",
                "https://github.com/wilfred-wulbou/HG532d-RCE-Exploit",
                "https://github.com/ltfafei/HuaWei_Route_HG532_RCE_CVE-2017-17215"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T17:47:48Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/43414"
                }
            ],
            "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
            "id": "CVE-2017-11882",
            "vendor": "Microsoft",
            "product": "Office",
            "title": "Microsoft Office Memory Corruption Vulnerability",
            "summary": "Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.",
            "updated_at": "2026-08-25T02:15:14Z",
            "published_at": "2026-08-25T02:15:14Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 333,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 43163",
                    "author": "embedi",
                    "first_seen": "2017-11-20",
                    "confidence": "High",
                    "title": "Microsoft Office - OLE Remote Code Execution",
                    "summary": "Microsoft Office - OLE Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/43163",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2017-11882",
                    "summary": "CVE-2017-11882 in the tools repository component.",
                    "what_happened": "CVE-2017-11882 in the tools repository component.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ACTOREXPOSE-CVE-2017-11882",
                        "https://kitploit.com/ar/tools/github/actorexpose/cve-2017-11882/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T04:15:14",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ACTOREXPOSE-CVE-2017-11882"
                },
                {
                    "title": "Exploit for CVE-2017-11882",
                    "summary": "CVE-2017-11882 in the tools repository component.",
                    "what_happened": "CVE-2017-11882 in the tools repository component.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ACTOREXPOSE-CVE-2017-11882",
                        "https://kitploit.com/ar/tools/github/actorexpose/cve-2017-11882/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-08-25T04:15:14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/actorexpose/cve-2017-11882/"
                },
                {
                    "repository": "PoC-in-GitHub · zhouat/cve-2017-11882",
                    "author": "zhouat",
                    "first_seen": "2017-11-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2017-11882 repository",
                    "summary": "",
                    "url": "https://github.com/zhouat/cve-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · embedi/CVE-2017-11882",
                    "author": "embedi",
                    "first_seen": "2017-11-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 495,
                    "title": "Proof-of-Concept exploits for CVE-2017-11882",
                    "summary": "Proof-of-Concept exploits for CVE-2017-11882",
                    "url": "https://github.com/embedi/CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · Ridter/CVE-2017-11882",
                    "author": "Ridter",
                    "first_seen": "2017-11-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 535,
                    "title": "CVE-2017-11882 from https://github.com/embedi/CVE-2017-11882",
                    "summary": "CVE-2017-11882 from https://github.com/embedi/CVE-2017-11882",
                    "url": "https://github.com/Ridter/CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · BlackMathIT/2017-11882_Generator",
                    "author": "BlackMathIT",
                    "first_seen": "2017-11-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 34,
                    "title": "CVE-2017-11882 File Generator PoC",
                    "summary": "CVE-2017-11882 File Generator PoC",
                    "url": "https://github.com/BlackMathIT/2017-11882_Generator"
                },
                {
                    "repository": "PoC-in-GitHub · rip1s/CVE-2017-11882",
                    "author": "rip1s",
                    "first_seen": "2017-11-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 331,
                    "title": "CVE-2017-11882 Exploit accepts over 17k bytes long command/code in maximum.",
                    "summary": "CVE-2017-11882 Exploit accepts over 17k bytes long command/code in maximum.",
                    "url": "https://github.com/rip1s/CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · 0x09AL/CVE-2017-11882-metasploit",
                    "author": "0x09AL",
                    "first_seen": "2017-11-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 98,
                    "title": "This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about.",
                    "summary": "This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about.",
                    "url": "https://github.com/0x09AL/CVE-2017-11882-metasploit"
                },
                {
                    "repository": "PoC-in-GitHub · HZachev/ABC",
                    "author": "HZachev",
                    "first_seen": "2017-11-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-11882",
                    "summary": "CVE-2017-11882",
                    "url": "https://github.com/HZachev/ABC"
                },
                {
                    "repository": "PoC-in-GitHub · starnightcyber/CVE-2017-11882",
                    "author": "starnightcyber",
                    "first_seen": "2017-11-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 44,
                    "title": "CVE-2017-11882 exploitation",
                    "summary": "CVE-2017-11882 exploitation",
                    "url": "https://github.com/starnightcyber/CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · Grey-Li/CVE-2017-11882",
                    "author": "Grey-Li",
                    "first_seen": "2017-11-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-11882 repository",
                    "summary": "",
                    "url": "https://github.com/Grey-Li/CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · CSC-pentest/cve-2017-11882",
                    "author": "CSC-pentest",
                    "first_seen": "2017-11-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-11882 repository",
                    "summary": "",
                    "url": "https://github.com/CSC-pentest/cve-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · Shadowshusky/CVE-2017-11882-",
                    "author": "Shadowshusky",
                    "first_seen": "2017-11-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2017-11882 repository",
                    "summary": "",
                    "url": "https://github.com/Shadowshusky/CVE-2017-11882-"
                },
                {
                    "repository": "PoC-in-GitHub · rxwx/CVE-2018-0802",
                    "author": "rxwx",
                    "first_seen": "2018-01-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 270,
                    "title": "PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)",
                    "summary": "PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)",
                    "url": "https://github.com/rxwx/CVE-2018-0802"
                },
                {
                    "repository": "PoC-in-GitHub · Ridter/RTF_11882_0802",
                    "author": "Ridter",
                    "first_seen": "2018-01-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 166,
                    "title": "PoC for CVE-2018-0802 And CVE-2017-11882",
                    "summary": "PoC for CVE-2018-0802 And CVE-2017-11882",
                    "url": "https://github.com/Ridter/RTF_11882_0802"
                },
                {
                    "repository": "PoC-in-GitHub · likekabin/CVE-2017-11882",
                    "author": "likekabin",
                    "first_seen": "2018-01-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-11882 repository",
                    "summary": "",
                    "url": "https://github.com/likekabin/CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · likekabin/CVE-2018-0802_CVE-2017-11882",
                    "author": "likekabin",
                    "first_seen": "2018-01-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "CVE-2017-11882 repository",
                    "summary": "",
                    "url": "https://github.com/likekabin/CVE-2018-0802_CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · herbiezimmerman/CVE-2017-11882-Possible-Remcos-Malspam",
                    "author": "herbiezimmerman",
                    "first_seen": "2018-04-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-11882 repository",
                    "summary": "",
                    "url": "https://github.com/herbiezimmerman/CVE-2017-11882-Possible-Remcos-Malspam"
                },
                {
                    "repository": "PoC-in-GitHub · ChaitanyaHaritash/CVE-2017-11882",
                    "author": "ChaitanyaHaritash",
                    "first_seen": "2018-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Empire Port of CVE-2017-11882",
                    "summary": "Empire Port of CVE-2017-11882",
                    "url": "https://github.com/ChaitanyaHaritash/CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · j0lama/CVE-2017-11882",
                    "author": "j0lama",
                    "first_seen": "2018-10-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-11882 repository",
                    "summary": "",
                    "url": "https://github.com/j0lama/CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · chanbin/CVE-2017-11882",
                    "author": "chanbin",
                    "first_seen": "2018-12-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Microsoft Equation 3.0/Convert python2 to python3",
                    "summary": "Microsoft Equation 3.0/Convert python2 to python3",
                    "url": "https://github.com/chanbin/CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · littlebin404/CVE-2017-11882",
                    "author": "littlebin404",
                    "first_seen": "2019-08-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "CVE-2017-11882（通杀Office 2003到2016）",
                    "summary": "CVE-2017-11882（通杀Office 2003到2016）",
                    "url": "https://github.com/littlebin404/CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · ekgg/Overflow-Demo-CVE-2017-11882",
                    "author": "ekgg",
                    "first_seen": "2020-01-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Simple Overflow demo, like CVE-2017-11882 exp",
                    "summary": "Simple Overflow demo, like CVE-2017-11882 exp",
                    "url": "https://github.com/ekgg/Overflow-Demo-CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · HaoJame/CVE-2017-11882",
                    "author": "HaoJame",
                    "first_seen": "2020-11-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-11882 repository",
                    "summary": "",
                    "url": "https://github.com/HaoJame/CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · ActorExpose/CVE-2017-11882",
                    "author": "ActorExpose",
                    "first_seen": "2020-12-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-11882 repository",
                    "summary": "",
                    "url": "https://github.com/ActorExpose/CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · Retr0-code/SignHere",
                    "author": "Retr0-code",
                    "first_seen": "2021-01-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.",
                    "summary": "SignHere is implementation of CVE-2017-11882. SignHere is builder of malicious rtf document and VBScript payloads.",
                    "url": "https://github.com/Retr0-code/SignHere"
                },
                {
                    "repository": "PoC-in-GitHub · lisinan988/CVE-2017-11882-exp",
                    "author": "lisinan988",
                    "first_seen": "2021-11-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-11882 repository",
                    "summary": "",
                    "url": "https://github.com/lisinan988/CVE-2017-11882-exp"
                },
                {
                    "repository": "PoC-in-GitHub · tzwlhack/CVE-2017-11882",
                    "author": "tzwlhack",
                    "first_seen": "2022-03-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2017-11882 repository",
                    "summary": "",
                    "url": "https://github.com/tzwlhack/CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · Sunqiz/CVE-2017-11882-reproduction",
                    "author": "Sunqiz",
                    "first_seen": "2022-08-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2017-11882复现",
                    "summary": "CVE-2017-11882复现",
                    "url": "https://github.com/Sunqiz/CVE-2017-11882-reproduction"
                },
                {
                    "repository": "PoC-in-GitHub · Abdibimantara/Maldoc-Analysis",
                    "author": "Abdibimantara",
                    "first_seen": "2023-03-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Pada bulan maret 2023, terdapat sample baru yang terindentifikasi sebagai malware. Malware tersebut berasal dari file berekstensi.xls dan .doc dan dikenal dengan nama “Bank Slip.xls”. Aktivitas malware tersebut memiliki hubungan dengan kerentanan yang dikenal dengan id CVE-2017-11882 dan CVE-2018-0802.",
                    "summary": "Pada bulan maret 2023, terdapat sample baru yang terindentifikasi sebagai malware. Malware tersebut berasal dari file berekstensi.xls dan .doc dan dikenal dengan nama “Bank Slip.xls”. Aktivitas malware tersebut memiliki hubungan dengan kerentanan yang dikenal dengan id CVE-2017-11882 dan CVE-2018-0802.",
                    "url": "https://github.com/Abdibimantara/Maldoc-Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · jadeapar/Dragonfish-s-Malware-Cyber-Analysis",
                    "author": "jadeapar",
                    "first_seen": "2024-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Examining the phases of an attack using “Dragonfish's Elise Malware”, specifically, exploring the exploitation of vulnerability CVE-2017-11882.",
                    "summary": "Examining the phases of an attack using “Dragonfish's Elise Malware”, specifically, exploring the exploitation of vulnerability CVE-2017-11882.",
                    "url": "https://github.com/jadeapar/Dragonfish-s-Malware-Cyber-Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · pixelofapicture/001-Malware-Analysis-CVE-2017-11882",
                    "author": "pixelofapicture",
                    "first_seen": "2024-12-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Malware Analysis CVE-2017-11882",
                    "summary": "Malware Analysis CVE-2017-11882",
                    "url": "https://github.com/pixelofapicture/001-Malware-Analysis-CVE-2017-11882"
                },
                {
                    "repository": "PoC-in-GitHub · xdrake1010/CVE-2017-11882-Preventer",
                    "author": "xdrake1010",
                    "first_seen": "2025-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-11882 Preventer for .docx files",
                    "summary": "CVE-2017-11882 Preventer for .docx files",
                    "url": "https://github.com/xdrake1010/CVE-2017-11882-Preventer"
                },
                {
                    "repository": "PoC-in-GitHub · DONKEY0xSHOT/CVE-2017-11882-Blocker",
                    "author": "DONKEY0xSHOT",
                    "first_seen": "2026-04-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-11882 repository",
                    "summary": "",
                    "url": "https://github.com/DONKEY0xSHOT/CVE-2017-11882-Blocker"
                },
                {
                    "repository": "PoC-in-GitHub · Mo200909/Office-Malware-Forensics-Lab-REMnux-Static-Analysis",
                    "author": "Mo200909",
                    "first_seen": "2026-06-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Static analysis of 2 malicious Office documents on REMnux using oletools; identified CVE-2017-11882 and obfuscated macros.",
                    "summary": "Static analysis of 2 malicious Office documents on REMnux using oletools; identified CVE-2017-11882 and obfuscated macros.",
                    "url": "https://github.com/Mo200909/Office-Malware-Forensics-Lab-REMnux-Static-Analysis"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/43163",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ACTOREXPOSE-CVE-2017-11882",
                "https://kitploit.com/ar/tools/github/actorexpose/cve-2017-11882/",
                "https://github.com/zhouat/cve-2017-11882",
                "https://github.com/embedi/CVE-2017-11882",
                "https://github.com/Ridter/CVE-2017-11882",
                "https://github.com/BlackMathIT/2017-11882_Generator",
                "https://github.com/rip1s/CVE-2017-11882",
                "https://github.com/0x09AL/CVE-2017-11882-metasploit",
                "https://github.com/HZachev/ABC",
                "https://github.com/starnightcyber/CVE-2017-11882",
                "https://github.com/Grey-Li/CVE-2017-11882",
                "https://github.com/CSC-pentest/cve-2017-11882",
                "https://github.com/Shadowshusky/CVE-2017-11882-",
                "https://github.com/rxwx/CVE-2018-0802",
                "https://github.com/Ridter/RTF_11882_0802",
                "https://github.com/likekabin/CVE-2017-11882",
                "https://github.com/likekabin/CVE-2018-0802_CVE-2017-11882",
                "https://github.com/herbiezimmerman/CVE-2017-11882-Possible-Remcos-Malspam",
                "https://github.com/ChaitanyaHaritash/CVE-2017-11882",
                "https://github.com/j0lama/CVE-2017-11882",
                "https://github.com/chanbin/CVE-2017-11882",
                "https://github.com/littlebin404/CVE-2017-11882",
                "https://github.com/ekgg/Overflow-Demo-CVE-2017-11882",
                "https://github.com/HaoJame/CVE-2017-11882",
                "https://github.com/ActorExpose/CVE-2017-11882",
                "https://github.com/Retr0-code/SignHere",
                "https://github.com/lisinan988/CVE-2017-11882-exp",
                "https://github.com/tzwlhack/CVE-2017-11882",
                "https://github.com/Sunqiz/CVE-2017-11882-reproduction",
                "https://github.com/Abdibimantara/Maldoc-Analysis",
                "https://github.com/jadeapar/Dragonfish-s-Malware-Cyber-Analysis",
                "https://github.com/pixelofapicture/001-Malware-Analysis-CVE-2017-11882",
                "https://github.com/xdrake1010/CVE-2017-11882-Preventer",
                "https://github.com/DONKEY0xSHOT/CVE-2017-11882-Blocker",
                "https://github.com/Mo200909/Office-Malware-Forensics-Lab-REMnux-Static-Analysis"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T02:15:14Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C"
        },
        {
            "id": "CVE-2017-11176",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Linux Kernel < 4.11.8 - 'mq_notify: double sock_put()' Local Privilege Escalation",
            "summary": "Linux Kernel < 4.11.8 - 'mq_notify: double sock_put()' Local Privilege Escalation",
            "updated_at": "2026-09-15T10:57:17Z",
            "published_at": "2026-09-15T10:57:17Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 26,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "CVE-2017-11176 affects the tools repository.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 45553",
                    "author": "Lexfo",
                    "first_seen": "2018-10-02",
                    "confidence": "High",
                    "title": "Linux Kernel < 4.11.8 - 'mq_notify: double sock_put()' Local Privilege Escalation",
                    "summary": "Linux Kernel < 4.11.8 - 'mq_notify: double sock_put()' Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/45553",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2017-11176",
                    "summary": "CVE-2017-11176 affects the tools repository.",
                    "what_happened": "CVE-2017-11176 affects the tools repository.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YANORO-CVE-2017-11176",
                        "https://kitploit.com/hi/tools/github/yanoro/cve-2017-11176/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T04:17:28",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YANORO-CVE-2017-11176"
                },
                {
                    "title": "Exploit for CVE-2017-11176",
                    "summary": "CVE-2017-11176 affects the tools repository.",
                    "what_happened": "CVE-2017-11176 affects the tools repository.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YANORO-CVE-2017-11176",
                        "https://kitploit.com/hi/tools/github/yanoro/cve-2017-11176/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-08-25T04:17:28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/yanoro/cve-2017-11176/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/45553",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YANORO-CVE-2017-11176",
                "https://kitploit.com/hi/tools/github/yanoro/cve-2017-11176/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T10:57:17Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/45553"
                }
            ]
        },
        {
            "id": "CVE-2017-9791",
            "vendor": "Apache",
            "product": "Struts 1",
            "title": "Apache Struts 1 Improper Input Validation Vulnerability",
            "summary": "The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.",
            "updated_at": "2026-09-15T08:36:57Z",
            "published_at": "2026-09-15T08:36:57Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 41,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 44643",
                    "author": "Metasploit",
                    "first_seen": "2018-05-17",
                    "confidence": "High",
                    "title": "Apache Struts 2 - Struts 1 Plugin Showcase OGNL Code Execution (Metasploit)",
                    "summary": "Apache Struts 2 - Struts 1 Plugin Showcase OGNL Code Execution (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/44643",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 42324",
                    "author": "Vex Woo",
                    "first_seen": "2017-07-07",
                    "confidence": "High",
                    "title": "Apache Struts 2.3.x Showcase - Remote Code Execution",
                    "summary": "Apache Struts 2.3.x Showcase - Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/42324",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for Struts2-048 CVE-2017-9791",
                    "summary": "Struts2-048 (CVE-2017-9791) PoC tool targeting Struts2 .action endpoints.",
                    "what_happened": "Struts2-048 (CVE-2017-9791) PoC tool targeting Struts2 .action endpoints.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRAGONEEG-STRUTS2-048",
                        "https://kitploit.com/ar/tools/github/dragoneeg/struts2-048/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T02:27:13",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRAGONEEG-STRUTS2-048"
                },
                {
                    "title": "Exploit for Struts2-048 CVE-2017-9791",
                    "summary": "Struts2-048 (CVE-2017-9791) PoC tool targeting Struts2 .action endpoints.",
                    "what_happened": "Struts2-048 (CVE-2017-9791) PoC tool targeting Struts2 .action endpoints.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRAGONEEG-STRUTS2-048",
                        "https://kitploit.com/ar/tools/github/dragoneeg/struts2-048/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-04T02:27:13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/dragoneeg/struts2-048/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/44643",
                "https://www.exploit-db.com/exploits/42324",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRAGONEEG-STRUTS2-048",
                "https://kitploit.com/ar/tools/github/dragoneeg/struts2-048/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:36:57Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2017-8779",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "RPCBind / libtirpc - Denial of Service",
            "summary": "RPCBind / libtirpc - Denial of Service",
            "updated_at": "2026-09-12T06:32:27Z",
            "published_at": "2026-09-12T06:32:27Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 68,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "rpcbomb: DoS in rpcbind, LIBTIRPC, and NTIRPC via crafted UDP packet to port 111.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 41974",
                    "author": "Guido Vranken",
                    "first_seen": "2017-05-08",
                    "confidence": "High",
                    "title": "RPCBind / libtirpc - Denial of Service",
                    "summary": "RPCBind / libtirpc - Denial of Service",
                    "url": "https://www.exploit-db.com/exploits/41974",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for GO-RPCBOMB CVE-2017-8779",
                    "summary": "rpcbomb: DoS in rpcbind, LIBTIRPC, and NTIRPC via crafted UDP packet to port 111.",
                    "what_happened": "rpcbomb: DoS in rpcbind, LIBTIRPC, and NTIRPC via crafted UDP packet to port 111.",
                    "cvss": 7.8,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRBOTHEN-GO-RPCBOMB",
                        "https://kitploit.com/ru/tools/github/drbothen/go-rpcbomb/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T07:41:38",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRBOTHEN-GO-RPCBOMB"
                },
                {
                    "title": "Exploit for GO-RPCBOMB CVE-2017-8779",
                    "summary": "rpcbomb: DoS in rpcbind, LIBTIRPC, and NTIRPC via crafted UDP packet to port 111.",
                    "what_happened": "rpcbomb: DoS in rpcbind, LIBTIRPC, and NTIRPC via crafted UDP packet to port 111.",
                    "cvss": 7.8,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRBOTHEN-GO-RPCBOMB",
                        "https://kitploit.com/ru/tools/github/drbothen/go-rpcbomb/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-06T07:41:38",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/drbothen/go-rpcbomb/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/41974",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DRBOTHEN-GO-RPCBOMB",
                "https://kitploit.com/ru/tools/github/drbothen/go-rpcbomb/"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T06:32:27Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/41974"
                }
            ]
        },
        {
            "id": "CVE-2017-8056",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2017-8056 exploit",
            "summary": "Exploit for CVE-2017-8056. CVSS 5.3.",
            "updated_at": "2026-09-12T15:05:53Z",
            "published_at": "2026-09-12T15:05:53Z",
            "cvss": 5.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 17,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T15:05:53+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2017-8056 exploit",
                    "summary": "Exploit for CVE-2017-8056. CVSS 5.3.",
                    "cvss": 5.3,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ITZEXPLOIT-CVE-2017-8056"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ITZEXPLOIT-CVE-2017-8056"
            ],
            "timeline": [
                {
                    "at": "2026-09-12T15:05:53Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ITZEXPLOIT-CVE-2017-8056"
                }
            ]
        },
        {
            "id": "CVE-2017-8039",
            "vendor": "n/a",
            "product": "Spring Web Flow Spring Web Flow 2.4.0 to 2.4.5 and Older unsupported versions are also affected",
            "title": "Spring Web Flow Spring Web Flow 2.4.0 to 2.4.5 and Older unsupported versions are also affected vulnerability",
            "summary": "An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings. NOTE: this issue exists because of an incomplete fix for CVE-2017-4971.",
            "updated_at": "2026-09-08T17:13:05.477",
            "published_at": "2017-11-27T10:29:00.847",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Spring Web Flow Spring Web Flow 2.4.0 to 2.4.5 and Older unsupported versions are also affected",
            "fixed": "See vendor advisory",
            "source_count": 4,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-1188",
            "what_happened": "An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings. NOTE: this issue exists because of an incomplete fix for CVE-2017-4971.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "http://www.securityfocus.com/bid/100849",
                "https://pivotal.io/security/cve-2017-8039"
            ],
            "timeline": [
                {
                    "at": "2017-11-27T10:29:00.847",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-8039"
                }
            ]
        },
        {
            "id": "CVE-2017-7921",
            "vendor": "Hikvision",
            "product": "Multiple Products",
            "title": "Hikvision Multiple Products Improper Authentication Vulnerability",
            "summary": "Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.",
            "updated_at": "2026-08-24T06:32:47Z",
            "published_at": "2026-08-24T06:32:47Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 904,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for INtrack CVE-2017-7921",
                    "summary": "Multi-threaded security scanner and crawler for network reconnaissance and vulnerability detection.",
                    "what_happened": "Multi-threaded security scanner and crawler for network reconnaissance and vulnerability detection.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-K3YSTR0K3R-INTRACK",
                        "https://kitploit.com/hi/tools/github/k3ystr0k3r/intrack/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-24T08:32:47",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-K3YSTR0K3R-INTRACK"
                },
                {
                    "title": "Exploit for INtrack CVE-2017-7921",
                    "summary": "Multi-threaded security scanner and crawler for network reconnaissance and vulnerability detection.",
                    "what_happened": "Multi-threaded security scanner and crawler for network reconnaissance and vulnerability detection.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-K3YSTR0K3R-INTRACK",
                        "https://kitploit.com/hi/tools/github/k3ystr0k3r/intrack/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-08-24T08:32:47",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/k3ystr0k3r/intrack/"
                },
                {
                    "repository": "PoC-in-GitHub · JrDw0/CVE-2017-7921-EXP",
                    "author": "JrDw0",
                    "first_seen": "2020-04-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 102,
                    "title": "Hikvision camera CVE-2017-7921-EXP",
                    "summary": "Hikvision camera CVE-2017-7921-EXP",
                    "url": "https://github.com/JrDw0/CVE-2017-7921-EXP"
                },
                {
                    "repository": "PoC-in-GitHub · BurnyMcDull/CVE-2017-7921",
                    "author": "BurnyMcDull",
                    "first_seen": "2020-11-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 35,
                    "title": "海康威视未授权访问检测poc及口令爆破",
                    "summary": "海康威视未授权访问检测poc及口令爆破",
                    "url": "https://github.com/BurnyMcDull/CVE-2017-7921"
                },
                {
                    "repository": "PoC-in-GitHub · MisakaMikato/cve-2017-7921-golang",
                    "author": "MisakaMikato",
                    "first_seen": "2020-11-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "Hikvision IP camera access bypass exploit, developed by golang.",
                    "summary": "Hikvision IP camera access bypass exploit, developed by golang.",
                    "url": "https://github.com/MisakaMikato/cve-2017-7921-golang"
                },
                {
                    "repository": "PoC-in-GitHub · chrisjd20/hikvision_CVE-2017-7921_auth_bypass_config_decryptor",
                    "author": "chrisjd20",
                    "first_seen": "2021-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 117,
                    "title": "This python file will decrypt the configurationFile used by hikvision cameras vulnerable to CVE-2017-7921.",
                    "summary": "This python file will decrypt the configurationFile used by hikvision cameras vulnerable to CVE-2017-7921.",
                    "url": "https://github.com/chrisjd20/hikvision_CVE-2017-7921_auth_bypass_config_decryptor"
                },
                {
                    "repository": "PoC-in-GitHub · p4tq/hikvision_CVE-2017-7921_auth_bypass_config_decryptor",
                    "author": "p4tq",
                    "first_seen": "2022-06-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-7921 repository",
                    "summary": "",
                    "url": "https://github.com/p4tq/hikvision_CVE-2017-7921_auth_bypass_config_decryptor"
                },
                {
                    "repository": "PoC-in-GitHub · alkaid176/CVE-2017-7921",
                    "author": "alkaid176",
                    "first_seen": "2022-07-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2017-7921-EXP Hikvision camera",
                    "summary": "CVE-2017-7921-EXP Hikvision camera",
                    "url": "https://github.com/alkaid176/CVE-2017-7921"
                },
                {
                    "repository": "PoC-in-GitHub · inj3ction/CVE-2017-7921-EXP",
                    "author": "inj3ction",
                    "first_seen": "2022-10-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-7921 repository",
                    "summary": "",
                    "url": "https://github.com/inj3ction/CVE-2017-7921-EXP"
                },
                {
                    "repository": "PoC-in-GitHub · krypton612/hikivision",
                    "author": "krypton612",
                    "first_seen": "2023-07-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2017-7921 EXPLOIT",
                    "summary": "CVE-2017-7921 EXPLOIT",
                    "url": "https://github.com/krypton612/hikivision"
                },
                {
                    "repository": "PoC-in-GitHub · K3ysTr0K3R/CVE-2017-7921-EXPLOIT",
                    "author": "K3ysTr0K3R",
                    "first_seen": "2023-07-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 52,
                    "title": "A PoC exploit for CVE-2017-7921 - Hikvision Camera Series Improper Authentication Vulnerability.",
                    "summary": "A PoC exploit for CVE-2017-7921 - Hikvision Camera Series Improper Authentication Vulnerability.",
                    "url": "https://github.com/K3ysTr0K3R/CVE-2017-7921-EXPLOIT"
                },
                {
                    "repository": "PoC-in-GitHub · blacksheepstudio/CVE-2017-7921-EXP",
                    "author": "blacksheepstudio",
                    "first_seen": "2023-08-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Hikvision camera CVE-2017-7921-EXP",
                    "summary": "Hikvision camera CVE-2017-7921-EXP",
                    "url": "https://github.com/blacksheepstudio/CVE-2017-7921-EXP"
                },
                {
                    "repository": "PoC-in-GitHub · AnonkiGroup/AnonHik",
                    "author": "AnonkiGroup",
                    "first_seen": "2023-10-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Python script get image from Hikvision camera with CVE-2017-7921 vulnerability",
                    "summary": "Python script get image from Hikvision camera with CVE-2017-7921 vulnerability",
                    "url": "https://github.com/AnonkiGroup/AnonHik"
                },
                {
                    "repository": "PoC-in-GitHub · b3pwn3d/CVE-2017-7921",
                    "author": "b3pwn3d",
                    "first_seen": "2023-11-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-7921 repository",
                    "summary": "",
                    "url": "https://github.com/b3pwn3d/CVE-2017-7921"
                },
                {
                    "repository": "PoC-in-GitHub · kooroshsanaei/HikVision-CVE-2017-7921",
                    "author": "kooroshsanaei",
                    "first_seen": "2024-07-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Test For CVE-2017–7921;",
                    "summary": "Test For CVE-2017–7921;",
                    "url": "https://github.com/kooroshsanaei/HikVision-CVE-2017-7921"
                },
                {
                    "repository": "PoC-in-GitHub · aengussong/hikvision_probe",
                    "author": "aengussong",
                    "first_seen": "2024-11-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Identify hikvision ip and probe for cve-s (CVE-2017-7921,  CVE-2022-28171, CVE-2021-36260)",
                    "summary": "Identify hikvision ip and probe for cve-s (CVE-2017-7921,  CVE-2022-28171, CVE-2021-36260)",
                    "url": "https://github.com/aengussong/hikvision_probe"
                },
                {
                    "repository": "PoC-in-GitHub · GabrielAvls/CVE-2017-7921",
                    "author": "GabrielAvls",
                    "first_seen": "2025-01-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-7921 exploit. Allows admin password retrieval and automatic snapshot download.",
                    "summary": "CVE-2017-7921 exploit. Allows admin password retrieval and automatic snapshot download.",
                    "url": "https://github.com/GabrielAvls/CVE-2017-7921"
                },
                {
                    "repository": "PoC-in-GitHub · lastvocher/Hikvision-CVE-2017-7921-decryptor",
                    "author": "lastvocher",
                    "first_seen": "2025-10-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-7921 repository",
                    "summary": "",
                    "url": "https://github.com/lastvocher/Hikvision-CVE-2017-7921-decryptor"
                },
                {
                    "repository": "PoC-in-GitHub · voidsshadows/Hikvision-City-Hunter",
                    "author": "voidsshadows",
                    "first_seen": "2025-11-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": "This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading for speed, and honeypot filtering (skips devices with >12 open ports). It's built for red teamers, bug bounty hunters, and security researchers to identify",
                    "summary": "This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading for speed, and honeypot filtering (skips devices with >12 open ports). It's built for red teamers, bug bounty hunters, and security researchers to identify",
                    "url": "https://github.com/voidsshadows/Hikvision-City-Hunter"
                },
                {
                    "repository": "PoC-in-GitHub · 0xf3d0rq/CVE-2017-7921",
                    "author": "0xf3d0rq",
                    "first_seen": "2025-11-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2017-7921 is a critical vulnerability (CVSS score: 9.8) affecting multiple Hikvision IP camera and DVR models, first disclosed in 2017. It stems from an improper authentication flaw that allows unauthenticated remote attackers to bypass login mechanisms and gain unauthorized access to sensitive system information",
                    "summary": "CVE-2017-7921 is a critical vulnerability (CVSS score: 9.8) affecting multiple Hikvision IP camera and DVR models, first disclosed in 2017. It stems from an improper authentication flaw that allows unauthenticated remote attackers to bypass login mechanisms and gain unauthorized access to sensitive system information",
                    "url": "https://github.com/0xf3d0rq/CVE-2017-7921"
                },
                {
                    "repository": "PoC-in-GitHub · saaydmr/hikvision-exploiter",
                    "author": "saaydmr",
                    "first_seen": "2026-01-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2017-7921, CVE-2021-36260 updated 21/01/2026",
                    "summary": "CVE-2017-7921, CVE-2021-36260 updated 21/01/2026",
                    "url": "https://github.com/saaydmr/hikvision-exploiter"
                },
                {
                    "repository": "PoC-in-GitHub · Wyl-cmd/CVE-2017-7921-Research-Toolkit",
                    "author": "Wyl-cmd",
                    "first_seen": "2026-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "用于借助FOFA快速测试海康威视的CVE-2017-7921漏洞，并且给出登陆账号和密码，并输出json文件。",
                    "summary": "用于借助FOFA快速测试海康威视的CVE-2017-7921漏洞，并且给出登陆账号和密码，并输出json文件。",
                    "url": "https://github.com/Wyl-cmd/CVE-2017-7921-Research-Toolkit"
                },
                {
                    "repository": "PoC-in-GitHub · mverschu/CVE-2017-7921",
                    "author": "mverschu",
                    "first_seen": "2026-02-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.",
                    "summary": "HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.",
                    "url": "https://github.com/mverschu/CVE-2017-7921"
                },
                {
                    "repository": "PoC-in-GitHub · KelvinWin10/CVE-2017-7921-rewrite",
                    "author": "KelvinWin10",
                    "first_seen": "2026-02-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "simple CVE-2017-7921 rewrite in python by me. for educational purposes only!",
                    "summary": "simple CVE-2017-7921 rewrite in python by me. for educational purposes only!",
                    "url": "https://github.com/KelvinWin10/CVE-2017-7921-rewrite"
                },
                {
                    "repository": "PoC-in-GitHub · MK-ULTRA-project-monarch/CVE-2017-7921-Writeup-2026",
                    "author": "MK-ULTRA-project-monarch",
                    "first_seen": "2026-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Vulnerability research write-up on CVE-2017-7921 — a critical unauthenticated auth bypass in Hikvision IP cameras/DVRs/NVRs, covering root cause, exploitation path, detection, and remediation.",
                    "summary": "Vulnerability research write-up on CVE-2017-7921 — a critical unauthenticated auth bypass in Hikvision IP cameras/DVRs/NVRs, covering root cause, exploitation path, detection, and remediation.",
                    "url": "https://github.com/MK-ULTRA-project-monarch/CVE-2017-7921-Writeup-2026"
                },
                {
                    "repository": "PoC-in-GitHub · xjghnxhlh/hikihack",
                    "author": "xjghnxhlh",
                    "first_seen": "2026-08-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Hikvision CVE-2017-7921 hack",
                    "summary": "Hikvision CVE-2017-7921 hack",
                    "url": "https://github.com/xjghnxhlh/hikihack"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-K3YSTR0K3R-INTRACK",
                "https://kitploit.com/hi/tools/github/k3ystr0k3r/intrack/",
                "https://github.com/JrDw0/CVE-2017-7921-EXP",
                "https://github.com/BurnyMcDull/CVE-2017-7921",
                "https://github.com/MisakaMikato/cve-2017-7921-golang",
                "https://github.com/chrisjd20/hikvision_CVE-2017-7921_auth_bypass_config_decryptor",
                "https://github.com/p4tq/hikvision_CVE-2017-7921_auth_bypass_config_decryptor",
                "https://github.com/alkaid176/CVE-2017-7921",
                "https://github.com/inj3ction/CVE-2017-7921-EXP",
                "https://github.com/krypton612/hikivision",
                "https://github.com/K3ysTr0K3R/CVE-2017-7921-EXPLOIT",
                "https://github.com/blacksheepstudio/CVE-2017-7921-EXP",
                "https://github.com/AnonkiGroup/AnonHik",
                "https://github.com/b3pwn3d/CVE-2017-7921",
                "https://github.com/kooroshsanaei/HikVision-CVE-2017-7921",
                "https://github.com/aengussong/hikvision_probe",
                "https://github.com/GabrielAvls/CVE-2017-7921",
                "https://github.com/lastvocher/Hikvision-CVE-2017-7921-decryptor",
                "https://github.com/voidsshadows/Hikvision-City-Hunter",
                "https://github.com/0xf3d0rq/CVE-2017-7921",
                "https://github.com/saaydmr/hikvision-exploiter",
                "https://github.com/Wyl-cmd/CVE-2017-7921-Research-Toolkit",
                "https://github.com/mverschu/CVE-2017-7921",
                "https://github.com/KelvinWin10/CVE-2017-7921-rewrite",
                "https://github.com/MK-ULTRA-project-monarch/CVE-2017-7921-Writeup-2026",
                "https://github.com/xjghnxhlh/hikihack"
            ],
            "timeline": [
                {
                    "at": "2026-08-24T06:32:47Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-03-05",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2017-7269",
            "vendor": "Microsoft",
            "product": "Internet Information Services (IIS)",
            "title": "Microsoft Windows Server Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with \"If: <http://\" in a PROPFIND request.",
            "updated_at": "2026-08-25T11:52:51Z",
            "published_at": "2026-08-25T11:52:51Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 41,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "Unknown",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with \"If: <http://\" in a PROPFIND request.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 41992",
                    "author": "Metasploit",
                    "first_seen": "2017-05-11",
                    "confidence": "High",
                    "title": "Microsoft IIS - WebDav 'ScStoragePathFromUrl' Remote Overflow (Metasploit)",
                    "summary": "Microsoft IIS - WebDav 'ScStoragePathFromUrl' Remote Overflow (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/41992",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 41738",
                    "author": "Zhiniang Peng & Chen Wu",
                    "first_seen": "2017-03-27",
                    "confidence": "High",
                    "title": "Microsoft IIS 6.0 - WebDAV 'ScStoragePathFromUrl' Remote Buffer Overflow",
                    "summary": "Microsoft IIS 6.0 - WebDAV 'ScStoragePathFromUrl' Remote Buffer Overflow",
                    "url": "https://www.exploit-db.com/exploits/41738",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2017-7269",
                    "summary": "CVE-2017-7269 affects the tools repository, which lacks a README file.",
                    "what_happened": "CVE-2017-7269 affects the tools repository, which lacks a README file.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DENCHIEF1-CVE-2017-7269",
                        "https://kitploit.com/ko/tools/github/denchief1/cve-2017-7269/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-25T13:52:51",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DENCHIEF1-CVE-2017-7269"
                },
                {
                    "title": "Exploit for CVE-2017-7269",
                    "summary": "CVE-2017-7269 affects the tools repository, which lacks a README file.",
                    "what_happened": "CVE-2017-7269 affects the tools repository, which lacks a README file.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DENCHIEF1-CVE-2017-7269",
                        "https://kitploit.com/ko/tools/github/denchief1/cve-2017-7269/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ko",
                    "first_seen": "2026-08-25T13:52:51",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ko/tools/github/denchief1/cve-2017-7269/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/41992",
                "https://www.exploit-db.com/exploits/41738",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DENCHIEF1-CVE-2017-7269",
                "https://kitploit.com/ko/tools/github/denchief1/cve-2017-7269/"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T11:52:51Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
            "id": "CVE-2017-7089",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Webkit (Safari) - Universal Cross-site Scripting",
            "summary": "Webkit (Safari) - Universal Cross-site Scripting",
            "updated_at": "2026-09-15T08:35:51Z",
            "published_at": "2026-09-15T08:35:51Z",
            "cvss": 6.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 24,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Exploit for CVE-2017-7089 affecting Safari on Mac.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 45866",
                    "author": "Anton Lopanitsyn",
                    "first_seen": "2017-10-03",
                    "confidence": "High",
                    "title": "Webkit (Safari) - Universal Cross-site Scripting",
                    "summary": "Webkit (Safari) - Universal Cross-site Scripting",
                    "url": "https://www.exploit-db.com/exploits/45866",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for Safari_Mac CVE-2017-7089",
                    "summary": "Exploit for CVE-2017-7089 affecting Safari on Mac.",
                    "what_happened": "Exploit for CVE-2017-7089 affecting Safari on Mac.",
                    "cvss": 6.1,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AYMANKHALFATNI-SAFARI_MAC",
                        "https://kitploit.com/hi/tools/github/aymankhalfatni/safari_mac/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T03:59:26",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AYMANKHALFATNI-SAFARI_MAC"
                },
                {
                    "title": "Exploit for Safari_Mac CVE-2017-7089",
                    "summary": "Exploit for CVE-2017-7089 affecting Safari on Mac.",
                    "what_happened": "Exploit for CVE-2017-7089 affecting Safari on Mac.",
                    "cvss": 6.1,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AYMANKHALFATNI-SAFARI_MAC",
                        "https://kitploit.com/hi/tools/github/aymankhalfatni/safari_mac/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T03:59:26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/aymankhalfatni/safari_mac/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/45866",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AYMANKHALFATNI-SAFARI_MAC",
                "https://kitploit.com/hi/tools/github/aymankhalfatni/safari_mac/"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:35:51Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/45866"
                }
            ]
        },
        {
            "id": "CVE-2017-6297",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret.",
            "updated_at": "2026-09-16T21:17:05.393",
            "published_at": "2017-02-27T07:59:00.347",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "confidence": 80,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 5,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-311",
            "what_happened": "The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "blog.milne.it",
                    "author": "NVD reference",
                    "first_seen": "2017-02-27",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://blog.milne.it/2017/02/24/mikrotik-routeros-security-vulnerability-l2tp-tunnel-unencrypted-cve-2017-6297/"
                }
            ],
            "references": [
                "http://www.securityfocus.com/bid/96447",
                "https://blog.milne.it/2017/02/24/mikrotik-routeros-security-vulnerability-l2tp-tunnel-unencrypted-cve-2017-6297/"
            ],
            "timeline": [
                {
                    "at": "2017-02-27T07:59:00.347",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-6297"
                }
            ]
        },
        {
            "id": "CVE-2017-5689",
            "vendor": "Intel",
            "product": "Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability",
            "title": "Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability",
            "summary": "Intel products contain a vulnerability which can allow attackers to perform privilege escalation.",
            "updated_at": "2026-09-08T01:13:29Z",
            "published_at": "2026-09-08T01:13:29Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 128,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Intel products contain a vulnerability which can allow attackers to perform privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 43385",
                    "author": "nixawk",
                    "first_seen": "2017-05-10",
                    "confidence": "High",
                    "title": "Intel Active Management Technology - System Privileges",
                    "summary": "Intel Active Management Technology - System Privileges",
                    "url": "https://www.exploit-db.com/exploits/43385",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-08T01:13:29+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "amt_auth_bypass_poc exploit",
                    "summary": "Exploit for CVE-2017-5689. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EMBEDI-AMT_AUTH_BYPASS_POC"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/43385",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-EMBEDI-AMT_AUTH_BYPASS_POC"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T01:13:29Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2017-5638",
            "vendor": "Apache",
            "product": "Struts",
            "title": "Apache Struts Remote Code Execution Vulnerability",
            "summary": "Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.",
            "updated_at": "2026-09-02T22:00:00Z",
            "published_at": "2026-09-02T22:00:00Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2157,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 41570",
                    "author": "Vex Woo",
                    "first_seen": "2017-03-07",
                    "confidence": "High",
                    "title": "Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution",
                    "summary": "Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/41570",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 41614",
                    "author": "Metasploit",
                    "first_seen": "2017-03-15",
                    "confidence": "High",
                    "title": "Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - 'Jakarta' Multipart Parser OGNL Injection (Metasploit)",
                    "summary": "Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - 'Jakarta' Multipart Parser OGNL Injection (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/41614",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · PolarisLab/S2-045",
                    "author": "PolarisLab",
                    "first_seen": "2017-03-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 23,
                    "title": "Struts2 S2-045（CVE-2017-5638）Vulnerability environment - http://www.mottoin.com/97954.html",
                    "summary": "Struts2 S2-045（CVE-2017-5638）Vulnerability environment - http://www.mottoin.com/97954.html",
                    "url": "https://github.com/PolarisLab/S2-045"
                },
                {
                    "repository": "PoC-in-GitHub · Flyteas/Struts2-045-Exp",
                    "author": "Flyteas",
                    "first_seen": "2017-03-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 61,
                    "title": "Struts2 S2-045（CVE-2017-5638）Exp with GUI",
                    "summary": "Struts2 S2-045（CVE-2017-5638）Exp with GUI",
                    "url": "https://github.com/Flyteas/Struts2-045-Exp"
                },
                {
                    "repository": "PoC-in-GitHub · bongbongco/cve-2017-5638",
                    "author": "bongbongco",
                    "first_seen": "2017-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/bongbongco/cve-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · jas502n/S2-045-EXP-POC-TOOLS",
                    "author": "jas502n",
                    "first_seen": "2017-03-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 25,
                    "title": "S2-045 漏洞 POC-TOOLS   CVE-2017-5638",
                    "summary": "S2-045 漏洞 POC-TOOLS   CVE-2017-5638",
                    "url": "https://github.com/jas502n/S2-045-EXP-POC-TOOLS"
                },
                {
                    "repository": "PoC-in-GitHub · btamburi/strutszeiro",
                    "author": "btamburi",
                    "first_seen": "2017-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Telegram Bot to manage botnets created with struts vulnerability(CVE-2017-5638)",
                    "summary": "Telegram Bot to manage botnets created with struts vulnerability(CVE-2017-5638)",
                    "url": "https://github.com/btamburi/strutszeiro"
                },
                {
                    "repository": "PoC-in-GitHub · xsscx/cve-2017-5638",
                    "author": "xsscx",
                    "first_seen": "2017-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 22,
                    "title": "Example PoC Code for CVE-2017-5638 | Apache Struts Exploit",
                    "summary": "Example PoC Code for CVE-2017-5638 | Apache Struts Exploit",
                    "url": "https://github.com/xsscx/cve-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · immunio/apache-struts2-CVE-2017-5638",
                    "author": "immunio",
                    "first_seen": "2017-03-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 35,
                    "title": "Demo Application and Exploit",
                    "summary": "Demo Application and Exploit",
                    "url": "https://github.com/immunio/apache-struts2-CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · Masahiro-Yamada/OgnlContentTypeRejectorValve",
                    "author": "Masahiro-Yamada",
                    "first_seen": "2017-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This is Valve for Tomcat7 to block  Struts 2 Remote Code Execution vulnerability (CVE-2017-5638)",
                    "summary": "This is Valve for Tomcat7 to block  Struts 2 Remote Code Execution vulnerability (CVE-2017-5638)",
                    "url": "https://github.com/Masahiro-Yamada/OgnlContentTypeRejectorValve"
                },
                {
                    "repository": "PoC-in-GitHub · aljazceru/CVE-2017-5638-Apache-Struts2",
                    "author": "aljazceru",
                    "first_seen": "2017-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Tweaking original PoC (https://github.com/rapid7/metasploit-framework/issues/8064) to work on self-signed certificates",
                    "summary": "Tweaking original PoC (https://github.com/rapid7/metasploit-framework/issues/8064) to work on self-signed certificates",
                    "url": "https://github.com/aljazceru/CVE-2017-5638-Apache-Struts2"
                },
                {
                    "repository": "PoC-in-GitHub · sjitech/test_struts2_vulnerability_CVE-2017-5638",
                    "author": "sjitech",
                    "first_seen": "2017-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "test struts2 vulnerability CVE-2017-5638 in Mac OS X",
                    "summary": "test struts2 vulnerability CVE-2017-5638 in Mac OS X",
                    "url": "https://github.com/sjitech/test_struts2_vulnerability_CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · jrrombaldo/CVE-2017-5638",
                    "author": "jrrombaldo",
                    "first_seen": "2017-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/jrrombaldo/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · random-robbie/CVE-2017-5638",
                    "author": "random-robbie",
                    "first_seen": "2017-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE: 2017-5638 in different formats",
                    "summary": "CVE: 2017-5638 in different formats",
                    "url": "https://github.com/random-robbie/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · initconf/CVE-2017-5638_struts",
                    "author": "initconf",
                    "first_seen": "2017-03-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "detection for Apache Struts recon and compromise",
                    "summary": "detection for Apache Struts recon and compromise",
                    "url": "https://github.com/initconf/CVE-2017-5638_struts"
                },
                {
                    "repository": "PoC-in-GitHub · mazen160/struts-pwn",
                    "author": "mazen160",
                    "first_seen": "2017-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 442,
                    "title": "An exploit for Apache Struts CVE-2017-5638",
                    "summary": "An exploit for Apache Struts CVE-2017-5638",
                    "url": "https://github.com/mazen160/struts-pwn"
                },
                {
                    "repository": "PoC-in-GitHub · ret2jazzy/Struts-Apache-ExploitPack",
                    "author": "ret2jazzy",
                    "first_seen": "2017-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 16,
                    "title": "These are just some script which you can use to detect and exploit the Apache Struts Vulnerability (CVE-2017-5638)",
                    "summary": "These are just some script which you can use to detect and exploit the Apache Struts Vulnerability (CVE-2017-5638)",
                    "url": "https://github.com/ret2jazzy/Struts-Apache-ExploitPack"
                },
                {
                    "repository": "PoC-in-GitHub · lolwaleet/ExpStruts",
                    "author": "lolwaleet",
                    "first_seen": "2017-03-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A php based exploiter for CVE-2017-5638.",
                    "summary": "A php based exploiter for CVE-2017-5638.",
                    "url": "https://github.com/lolwaleet/ExpStruts"
                },
                {
                    "repository": "PoC-in-GitHub · oktavianto/CVE-2017-5638-Apache-Struts2",
                    "author": "oktavianto",
                    "first_seen": "2017-03-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Example PHP Exploiter for CVE-2017-5638",
                    "summary": "Example PHP Exploiter for CVE-2017-5638",
                    "url": "https://github.com/oktavianto/CVE-2017-5638-Apache-Struts2"
                },
                {
                    "repository": "PoC-in-GitHub · jrrdev/cve-2017-5638",
                    "author": "jrrdev",
                    "first_seen": "2017-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 14,
                    "title": "cve-2017-5638 Vulnerable site sample",
                    "summary": "cve-2017-5638 Vulnerable site sample",
                    "url": "https://github.com/jrrdev/cve-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · opt9/Strutshock",
                    "author": "opt9",
                    "first_seen": "2017-03-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Struts2 RCE CVE-2017-5638 non-intrusive check shell script",
                    "summary": "Struts2 RCE CVE-2017-5638 non-intrusive check shell script",
                    "url": "https://github.com/opt9/Strutshock"
                },
                {
                    "repository": "PoC-in-GitHub · falcon-lnhg/StrutsShell",
                    "author": "falcon-lnhg",
                    "first_seen": "2017-03-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Apache Struts (CVE-2017-5638) Shell",
                    "summary": "Apache Struts (CVE-2017-5638) Shell",
                    "url": "https://github.com/falcon-lnhg/StrutsShell"
                },
                {
                    "repository": "PoC-in-GitHub · jas502n/st2-046-poc",
                    "author": "jas502n",
                    "first_seen": "2017-03-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 21,
                    "title": "st2-046-poc  CVE-2017-5638",
                    "summary": "st2-046-poc  CVE-2017-5638",
                    "url": "https://github.com/jas502n/st2-046-poc"
                },
                {
                    "repository": "PoC-in-GitHub · KarzsGHR/S2-046_S2-045_POC",
                    "author": "KarzsGHR",
                    "first_seen": "2017-03-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "S2-046|S2-045: Struts 2 Remote Code Execution vulnerability（CVE-2017-5638）",
                    "summary": "S2-046|S2-045: Struts 2 Remote Code Execution vulnerability（CVE-2017-5638）",
                    "url": "https://github.com/KarzsGHR/S2-046_S2-045_POC"
                },
                {
                    "repository": "PoC-in-GitHub · gsfish/S2-Reaper",
                    "author": "gsfish",
                    "first_seen": "2017-03-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638",
                    "summary": "CVE-2017-5638",
                    "url": "https://github.com/gsfish/S2-Reaper"
                },
                {
                    "repository": "PoC-in-GitHub · mcassano/cve-2017-5638",
                    "author": "mcassano",
                    "first_seen": "2017-03-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/mcassano/cve-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · opt9/Strutscli",
                    "author": "opt9",
                    "first_seen": "2017-03-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Struts2 RCE CVE-2017-5638 CLI shell",
                    "summary": "Struts2 RCE CVE-2017-5638 CLI shell",
                    "url": "https://github.com/opt9/Strutscli"
                },
                {
                    "repository": "PoC-in-GitHub · tahmed11/strutsy",
                    "author": "tahmed11",
                    "first_seen": "2017-04-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "Strutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability",
                    "summary": "Strutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability",
                    "url": "https://github.com/tahmed11/strutsy"
                },
                {
                    "repository": "PoC-in-GitHub · payatu/CVE-2017-5638",
                    "author": "payatu",
                    "first_seen": "2017-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 8,
                    "title": "Apache Struts 2.0 RCE vulnerability - Allows an attacker to inject OS commands into a web application through the content-type header",
                    "summary": "Apache Struts 2.0 RCE vulnerability - Allows an attacker to inject OS commands into a web application through the content-type header",
                    "url": "https://github.com/payatu/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · Aasron/Struts2-045-Exp",
                    "author": "Aasron",
                    "first_seen": "2017-05-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638",
                    "summary": "CVE-2017-5638",
                    "url": "https://github.com/Aasron/Struts2-045-Exp"
                },
                {
                    "repository": "PoC-in-GitHub · SpiderMate/Stutsfi",
                    "author": "SpiderMate",
                    "first_seen": "2017-05-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "An exploit for CVE-2017-5638 Remote Code Execution (RCE) Vulnerability in Apache Struts 2",
                    "summary": "An exploit for CVE-2017-5638 Remote Code Execution (RCE) Vulnerability in Apache Struts 2",
                    "url": "https://github.com/SpiderMate/Stutsfi"
                },
                {
                    "repository": "PoC-in-GitHub · jpacora/Struts2Shell",
                    "author": "jpacora",
                    "first_seen": "2017-05-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "An exploit (and library) for CVE-2017-5638 - Apache Struts2 S2-045 bug.",
                    "summary": "An exploit (and library) for CVE-2017-5638 - Apache Struts2 S2-045 bug.",
                    "url": "https://github.com/jpacora/Struts2Shell"
                },
                {
                    "repository": "PoC-in-GitHub · smancke/CVE-2017-5638",
                    "author": "smancke",
                    "first_seen": "2017-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/smancke/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · riyazwalikar/struts-rce-cve-2017-5638",
                    "author": "riyazwalikar",
                    "first_seen": "2017-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Struts-RCE CVE-2017-5638",
                    "summary": "Struts-RCE CVE-2017-5638",
                    "url": "https://github.com/riyazwalikar/struts-rce-cve-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · homjxi0e/CVE-2017-5638",
                    "author": "homjxi0e",
                    "first_seen": "2017-06-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/homjxi0e/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · eeehit/CVE-2017-5638",
                    "author": "eeehit",
                    "first_seen": "2017-06-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 Test environment",
                    "summary": "CVE-2017-5638 Test environment",
                    "url": "https://github.com/eeehit/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · sUbc0ol/Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner",
                    "author": "sUbc0ol",
                    "first_seen": "2017-06-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/sUbc0ol/Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · sUbc0ol/Apache-Struts2-RCE-Exploit-v2-CVE-2017-5638",
                    "author": "sUbc0ol",
                    "first_seen": "2017-06-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/sUbc0ol/Apache-Struts2-RCE-Exploit-v2-CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · R4v3nBl4ck/Apache-Struts-2-CVE-2017-5638-Exploit-",
                    "author": "R4v3nBl4ck",
                    "first_seen": "2017-07-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Exploit created by: R4v3nBl4ck end Pacman",
                    "summary": "Exploit created by: R4v3nBl4ck end Pacman",
                    "url": "https://github.com/R4v3nBl4ck/Apache-Struts-2-CVE-2017-5638-Exploit-"
                },
                {
                    "repository": "PoC-in-GitHub · Xhendos/CVE-2017-5638",
                    "author": "Xhendos",
                    "first_seen": "2017-08-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/Xhendos/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · invisiblethreat/strutser",
                    "author": "invisiblethreat",
                    "first_seen": "2017-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Check for Struts Vulnerability CVE-2017-5638",
                    "summary": "Check for Struts Vulnerability CVE-2017-5638",
                    "url": "https://github.com/invisiblethreat/strutser"
                },
                {
                    "repository": "PoC-in-GitHub · c002/Apache-Struts",
                    "author": "c002",
                    "first_seen": "2017-10-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "An exploit for Apache Struts CVE-2017-5638",
                    "summary": "An exploit for Apache Struts CVE-2017-5638",
                    "url": "https://github.com/c002/Apache-Struts"
                },
                {
                    "repository": "PoC-in-GitHub · donaldashdown/Common-Vulnerability-and-Exploit",
                    "author": "donaldashdown",
                    "first_seen": "2017-10-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is the Apache Struts CVE-2017-5638 struts 2 vulnerability.  The same CVE that resulted in the equifax database breach.",
                    "summary": "This is the Apache Struts CVE-2017-5638 struts 2 vulnerability.  The same CVE that resulted in the equifax database breach.",
                    "url": "https://github.com/donaldashdown/Common-Vulnerability-and-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · sighup1/cybersecurity-struts2",
                    "author": "sighup1",
                    "first_seen": "2018-01-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart parser.",
                    "summary": "Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart parser.",
                    "url": "https://github.com/sighup1/cybersecurity-struts2"
                },
                {
                    "repository": "PoC-in-GitHub · cafnet/apache-struts-v2-CVE-2017-5638",
                    "author": "cafnet",
                    "first_seen": "2018-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Working POC for CVE 2017-5638",
                    "summary": "Working POC for CVE 2017-5638",
                    "url": "https://github.com/cafnet/apache-struts-v2-CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · 0x00-0x00/CVE-2017-5638",
                    "author": "0x00-0x00",
                    "first_seen": "2018-02-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Struts02 s2-045 exploit program",
                    "summary": "Struts02 s2-045 exploit program",
                    "url": "https://github.com/0x00-0x00/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · m3ssap0/struts2_cve-2017-5638",
                    "author": "m3ssap0",
                    "first_seen": "2018-02-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This is a sort of Java porting of the Python exploit at: https://www.exploit-db.com/exploits/41570/.",
                    "summary": "This is a sort of Java porting of the Python exploit at: https://www.exploit-db.com/exploits/41570/.",
                    "url": "https://github.com/m3ssap0/struts2_cve-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · Greynad/struts2-jakarta-inject",
                    "author": "Greynad",
                    "first_seen": "2018-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Golang exploit for CVE-2017-5638",
                    "summary": "Golang exploit for CVE-2017-5638",
                    "url": "https://github.com/Greynad/struts2-jakarta-inject"
                },
                {
                    "repository": "PoC-in-GitHub · ggolawski/struts-rce",
                    "author": "ggolawski",
                    "first_seen": "2018-03-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Apache Struts CVE-2017-5638 RCE exploitation",
                    "summary": "Apache Struts CVE-2017-5638 RCE exploitation",
                    "url": "https://github.com/ggolawski/struts-rce"
                },
                {
                    "repository": "PoC-in-GitHub · win3zz/CVE-2017-5638",
                    "author": "win3zz",
                    "first_seen": "2018-05-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 16,
                    "title": "Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution - Shell Script",
                    "summary": "Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution - Shell Script",
                    "url": "https://github.com/win3zz/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · leandrocamposcardoso/CVE-2017-5638-Mass-Exploit",
                    "author": "leandrocamposcardoso",
                    "first_seen": "2018-06-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/leandrocamposcardoso/CVE-2017-5638-Mass-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Iletee/struts2-rce",
                    "author": "Iletee",
                    "first_seen": "2018-06-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "Exploitable target to CVE-2017-5638",
                    "summary": "Exploitable target to CVE-2017-5638",
                    "url": "https://github.com/Iletee/struts2-rce"
                },
                {
                    "repository": "PoC-in-GitHub · andypitcher/check_struts",
                    "author": "andypitcher",
                    "first_seen": "2018-09-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Apache Struts version analyzer (Ansible) based on CVE-2017-5638",
                    "summary": "Apache Struts version analyzer (Ansible) based on CVE-2017-5638",
                    "url": "https://github.com/andypitcher/check_struts"
                },
                {
                    "repository": "PoC-in-GitHub · un4ckn0wl3z/CVE-2017-5638",
                    "author": "un4ckn0wl3z",
                    "first_seen": "2018-11-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/un4ckn0wl3z/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · colorblindpentester/CVE-2017-5638",
                    "author": "colorblindpentester",
                    "first_seen": "2019-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 (PoC Exploits)",
                    "summary": "CVE-2017-5638 (PoC Exploits)",
                    "url": "https://github.com/colorblindpentester/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · injcristianrojas/cve-2017-5638",
                    "author": "injcristianrojas",
                    "first_seen": "2019-08-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Demo app of THAT data broker's security breach",
                    "summary": "Demo app of THAT data broker's security breach",
                    "url": "https://github.com/injcristianrojas/cve-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · ludy-dev/XworkStruts-RCE",
                    "author": "ludy-dev",
                    "first_seen": "2020-08-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "(CVE-2017-5638) XworkStruts RCE Vuln test script",
                    "summary": "(CVE-2017-5638) XworkStruts RCE Vuln test script",
                    "url": "https://github.com/ludy-dev/XworkStruts-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · sonatype-workshops/struts2-rce",
                    "author": "sonatype-workshops",
                    "first_seen": "2020-10-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploitable target to CVE-2017-5638",
                    "summary": "Exploitable target to CVE-2017-5638",
                    "url": "https://github.com/sonatype-workshops/struts2-rce"
                },
                {
                    "repository": "PoC-in-GitHub · jongmartinez/CVE-2017-5638",
                    "author": "jongmartinez",
                    "first_seen": "2020-12-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "PoC for CVE: 2017-5638 - Apache Struts2 S2-045",
                    "summary": "PoC for CVE: 2017-5638 - Apache Struts2 S2-045",
                    "url": "https://github.com/jongmartinez/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · Badbird3/CVE-2017-5638",
                    "author": "Badbird3",
                    "first_seen": "2021-06-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/Badbird3/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · jptr218/struts_hack",
                    "author": "jptr218",
                    "first_seen": "2021-08-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "An implementation of CVE-2017-5638",
                    "summary": "An implementation of CVE-2017-5638",
                    "url": "https://github.com/jptr218/struts_hack"
                },
                {
                    "repository": "PoC-in-GitHub · testpilot031/vulnerability_struts-2.3.31",
                    "author": "testpilot031",
                    "first_seen": "2022-02-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Build the struts-2.3.31 (CVE-2017-5638) environment",
                    "summary": "Build the struts-2.3.31 (CVE-2017-5638) environment",
                    "url": "https://github.com/testpilot031/vulnerability_struts-2.3.31"
                },
                {
                    "repository": "PoC-in-GitHub · readloud/CVE-2017-5638",
                    "author": "readloud",
                    "first_seen": "2022-02-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This script is intended to validate Apache Struts 2 vulnerability (CVE-2017-5638), AKA Struts-Shock.",
                    "summary": "This script is intended to validate Apache Struts 2 vulnerability (CVE-2017-5638), AKA Struts-Shock.",
                    "url": "https://github.com/readloud/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · Tankirat/CVE-2017-5638",
                    "author": "Tankirat",
                    "first_seen": "2022-03-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/Tankirat/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · mfdev-solution/Exploit-CVE-2017-5638",
                    "author": "mfdev-solution",
                    "first_seen": "2022-12-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "this exemple of application permet to test the vunerability CVE_2017-5638",
                    "summary": "this exemple of application permet to test the vunerability CVE_2017-5638",
                    "url": "https://github.com/mfdev-solution/Exploit-CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · mritunjay-k/CVE-2017-5638",
                    "author": "mritunjay-k",
                    "first_seen": "2023-03-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "An exploit for CVE-2017-5638",
                    "summary": "An exploit for CVE-2017-5638",
                    "url": "https://github.com/mritunjay-k/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · FredBrave/CVE-2017-5638-ApacheStruts2.3.5",
                    "author": "FredBrave",
                    "first_seen": "2023-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A exploit for CVE-2017-5638. This exploit works on versions 2.3.5-2.3.31 and 2.5 – 2.5.10",
                    "summary": "A exploit for CVE-2017-5638. This exploit works on versions 2.3.5-2.3.31 and 2.5 – 2.5.10",
                    "url": "https://github.com/FredBrave/CVE-2017-5638-ApacheStruts2.3.5"
                },
                {
                    "repository": "PoC-in-GitHub · Nithylesh/web-application-firewall-",
                    "author": "Nithylesh",
                    "first_seen": "2024-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware blocks HTTP requests containing specific patterns, and the vulnerability checker tests for and exploits the Apache Struts 2 vulnerability (CVE-2017-5638).",
                    "summary": "This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware blocks HTTP requests containing specific patterns, and the vulnerability checker tests for and exploits the Apache Struts 2 vulnerability (CVE-2017-5638).",
                    "url": "https://github.com/Nithylesh/web-application-firewall-"
                },
                {
                    "repository": "PoC-in-GitHub · kloutkake/CVE-2017-5638-PoC",
                    "author": "kloutkake",
                    "first_seen": "2024-09-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "This repository provides a PoC for CVE-2017-5638, a remote code execution vulnerability in Apache Struts 2, exploitable via a crafted Content-Type HTTP header.",
                    "summary": "This repository provides a PoC for CVE-2017-5638, a remote code execution vulnerability in Apache Struts 2, exploitable via a crafted Content-Type HTTP header.",
                    "url": "https://github.com/kloutkake/CVE-2017-5638-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · Xernary/CVE-2017-5638-POC",
                    "author": "Xernary",
                    "first_seen": "2024-12-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Proof of concept of CVE-2017-5638 including the whole setup of the Apache vulnerable server",
                    "summary": "Proof of concept of CVE-2017-5638 including the whole setup of the Apache vulnerable server",
                    "url": "https://github.com/Xernary/CVE-2017-5638-POC"
                },
                {
                    "repository": "PoC-in-GitHub · timothyjxhn/DeliberatelyVulnerableWebApp",
                    "author": "timothyjxhn",
                    "first_seen": "2025-03-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.",
                    "summary": "A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10 Web Application Security Risks: A06:2021-Vulnerable and Outdated Components.",
                    "url": "https://github.com/timothyjxhn/DeliberatelyVulnerableWebApp"
                },
                {
                    "repository": "PoC-in-GitHub · toothbrushsoapflannelbiscuits/cve-2017-5638",
                    "author": "toothbrushsoapflannelbiscuits",
                    "first_seen": "2025-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/toothbrushsoapflannelbiscuits/cve-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · haxerr9/CVE-2017-5638",
                    "author": "haxerr9",
                    "first_seen": "2025-06-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2017-5638 Exploit Rewritten In Python By haxerr9",
                    "summary": "CVE-2017-5638 Exploit Rewritten In Python By haxerr9",
                    "url": "https://github.com/haxerr9/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · QHxDr-dz/CVE-2017-5638",
                    "author": "QHxDr-dz",
                    "first_seen": "2025-07-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/QHxDr-dz/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · joidiego/Detection-struts-cve-2017-5638-detector",
                    "author": "joidiego",
                    "first_seen": "2025-07-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Real-time anomaly detection system for Apache Struts CVE-2017-5638 exploit using streaming analytics, 3-gram byte analysis, and Count-Min Sketch. Detects RCE attacks without signatures, with <5ms latency and <0.1% false positives.",
                    "summary": "Real-time anomaly detection system for Apache Struts CVE-2017-5638 exploit using streaming analytics, 3-gram byte analysis, and Count-Min Sketch. Detects RCE attacks without signatures, with <5ms latency and <0.1% false positives.",
                    "url": "https://github.com/joidiego/Detection-struts-cve-2017-5638-detector"
                },
                {
                    "repository": "PoC-in-GitHub · iampetru/PoC-CVE-2017-5638",
                    "author": "iampetru",
                    "first_seen": "2025-08-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Apache Struts2 CVE-2017-5638 (Safe Educational Demo)",
                    "summary": "Apache Struts2 CVE-2017-5638 (Safe Educational Demo)",
                    "url": "https://github.com/iampetru/PoC-CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · MuhammadAbdullah192/CVE-2017-5638-Remote-Code-Execution-Apache-Struts2-EXPLOITATION",
                    "author": "MuhammadAbdullah192",
                    "first_seen": "2025-09-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/MuhammadAbdullah192/CVE-2017-5638-Remote-Code-Execution-Apache-Struts2-EXPLOITATION"
                },
                {
                    "repository": "PoC-in-GitHub · kaylertee/Computer-Security-Equifax-2017",
                    "author": "kaylertee",
                    "first_seen": "2025-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A hands-on simulation of CVE-2017-5638 (Apache Struts2 RCE), showcasing exploit reproduction, OS-level command execution, and mitigations such as input sanitization and endpoint monitoring. Built in Python/Flask with Jupyter notebook demos",
                    "summary": "A hands-on simulation of CVE-2017-5638 (Apache Struts2 RCE), showcasing exploit reproduction, OS-level command execution, and mitigations such as input sanitization and endpoint monitoring. Built in Python/Flask with Jupyter notebook demos",
                    "url": "https://github.com/kaylertee/Computer-Security-Equifax-2017"
                },
                {
                    "repository": "PoC-in-GitHub · ACharaf06/CVE-2017-5638-Attack-and-Defense",
                    "author": "ACharaf06",
                    "first_seen": "2025-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/ACharaf06/CVE-2017-5638-Attack-and-Defense"
                },
                {
                    "repository": "PoC-in-GitHub · soufiane-benchahyd/vulhub-struts2",
                    "author": "soufiane-benchahyd",
                    "first_seen": "2026-02-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A practical lab demonstrating the exploitation of a critical Remote Code Execution (RCE) vulnerability in Apache Struts2 (CVE-2017-5638) using Vulhub Docker environments. Includes setup instructions and commands to run the vulnerable container.",
                    "summary": "A practical lab demonstrating the exploitation of a critical Remote Code Execution (RCE) vulnerability in Apache Struts2 (CVE-2017-5638) using Vulhub Docker environments. Includes setup instructions and commands to run the vulnerable container.",
                    "url": "https://github.com/soufiane-benchahyd/vulhub-struts2"
                },
                {
                    "repository": "PoC-in-GitHub · AIPEACS/SC3010-Computer-Security",
                    "author": "AIPEACS",
                    "first_seen": "2026-04-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.",
                    "summary": "Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.",
                    "url": "https://github.com/AIPEACS/SC3010-Computer-Security"
                },
                {
                    "repository": "PoC-in-GitHub · Kouf320/docker-lab-cve-2017-5638-cve-2021-41773",
                    "author": "Kouf320",
                    "first_seen": "2026-04-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/Kouf320/docker-lab-cve-2017-5638-cve-2021-41773"
                },
                {
                    "repository": "PoC-in-GitHub · Majaktech/apache-struts-cve-2017-5638-project",
                    "author": "Majaktech",
                    "first_seen": "2026-05-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Attack and Defense course project focused on CVE-2017-5638 analysis, exploitation, and mitigation.",
                    "summary": "Attack and Defense course project focused on CVE-2017-5638 analysis, exploitation, and mitigation.",
                    "url": "https://github.com/Majaktech/apache-struts-cve-2017-5638-project"
                },
                {
                    "repository": "PoC-in-GitHub · Dungsocool/CVE-2017-5638",
                    "author": "Dungsocool",
                    "first_seen": "2026-05-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-5638 repository",
                    "summary": "",
                    "url": "https://github.com/Dungsocool/CVE-2017-5638"
                },
                {
                    "repository": "PoC-in-GitHub · GU-007/struts2-tool",
                    "author": "GU-007",
                    "first_seen": "2026-09-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool",
                    "summary": "Struts2 S2-045/S2-046 CVE-2017-5638 detection & exploitation tool",
                    "url": "https://github.com/GU-007/struts2-tool"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-11T18:30:14+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Struts2Shell exploit",
                    "summary": "Exploit for CVE-2017-5638. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JPACORA-STRUTS2SHELL"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T06:34:29+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "Common-Vulnerability-and-Exploit",
                    "summary": "Exploit for CVE-2017-5638. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DONALDASHDOWN-COMMON-VULNERABILITY-AND-EXPLOIT"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:37:48+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "cve-2017-5638 exploit",
                    "summary": "Exploit for CVE-2017-5638. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JRRDEV-CVE-2017-5638"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/41570",
                "https://www.exploit-db.com/exploits/41614",
                "https://github.com/PolarisLab/S2-045",
                "https://github.com/Flyteas/Struts2-045-Exp",
                "https://github.com/bongbongco/cve-2017-5638",
                "https://github.com/jas502n/S2-045-EXP-POC-TOOLS",
                "https://github.com/btamburi/strutszeiro",
                "https://github.com/xsscx/cve-2017-5638",
                "https://github.com/immunio/apache-struts2-CVE-2017-5638",
                "https://github.com/Masahiro-Yamada/OgnlContentTypeRejectorValve",
                "https://github.com/aljazceru/CVE-2017-5638-Apache-Struts2",
                "https://github.com/sjitech/test_struts2_vulnerability_CVE-2017-5638",
                "https://github.com/jrrombaldo/CVE-2017-5638",
                "https://github.com/random-robbie/CVE-2017-5638",
                "https://github.com/initconf/CVE-2017-5638_struts",
                "https://github.com/mazen160/struts-pwn",
                "https://github.com/ret2jazzy/Struts-Apache-ExploitPack",
                "https://github.com/lolwaleet/ExpStruts",
                "https://github.com/oktavianto/CVE-2017-5638-Apache-Struts2",
                "https://github.com/jrrdev/cve-2017-5638",
                "https://github.com/opt9/Strutshock",
                "https://github.com/falcon-lnhg/StrutsShell",
                "https://github.com/jas502n/st2-046-poc",
                "https://github.com/KarzsGHR/S2-046_S2-045_POC",
                "https://github.com/gsfish/S2-Reaper",
                "https://github.com/mcassano/cve-2017-5638",
                "https://github.com/opt9/Strutscli",
                "https://github.com/tahmed11/strutsy",
                "https://github.com/payatu/CVE-2017-5638",
                "https://github.com/Aasron/Struts2-045-Exp",
                "https://github.com/SpiderMate/Stutsfi",
                "https://github.com/jpacora/Struts2Shell",
                "https://github.com/smancke/CVE-2017-5638",
                "https://github.com/riyazwalikar/struts-rce-cve-2017-5638",
                "https://github.com/homjxi0e/CVE-2017-5638",
                "https://github.com/eeehit/CVE-2017-5638",
                "https://github.com/sUbc0ol/Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner",
                "https://github.com/sUbc0ol/Apache-Struts2-RCE-Exploit-v2-CVE-2017-5638",
                "https://github.com/R4v3nBl4ck/Apache-Struts-2-CVE-2017-5638-Exploit-",
                "https://github.com/Xhendos/CVE-2017-5638",
                "https://github.com/invisiblethreat/strutser",
                "https://github.com/c002/Apache-Struts",
                "https://github.com/donaldashdown/Common-Vulnerability-and-Exploit",
                "https://github.com/sighup1/cybersecurity-struts2",
                "https://github.com/cafnet/apache-struts-v2-CVE-2017-5638",
                "https://github.com/0x00-0x00/CVE-2017-5638",
                "https://github.com/m3ssap0/struts2_cve-2017-5638",
                "https://github.com/Greynad/struts2-jakarta-inject",
                "https://github.com/ggolawski/struts-rce",
                "https://github.com/win3zz/CVE-2017-5638",
                "https://github.com/leandrocamposcardoso/CVE-2017-5638-Mass-Exploit",
                "https://github.com/Iletee/struts2-rce",
                "https://github.com/andypitcher/check_struts",
                "https://github.com/un4ckn0wl3z/CVE-2017-5638",
                "https://github.com/colorblindpentester/CVE-2017-5638",
                "https://github.com/injcristianrojas/cve-2017-5638",
                "https://github.com/ludy-dev/XworkStruts-RCE",
                "https://github.com/sonatype-workshops/struts2-rce",
                "https://github.com/jongmartinez/CVE-2017-5638",
                "https://github.com/Badbird3/CVE-2017-5638",
                "https://github.com/jptr218/struts_hack",
                "https://github.com/testpilot031/vulnerability_struts-2.3.31",
                "https://github.com/readloud/CVE-2017-5638",
                "https://github.com/Tankirat/CVE-2017-5638",
                "https://github.com/mfdev-solution/Exploit-CVE-2017-5638",
                "https://github.com/mritunjay-k/CVE-2017-5638",
                "https://github.com/FredBrave/CVE-2017-5638-ApacheStruts2.3.5",
                "https://github.com/Nithylesh/web-application-firewall-",
                "https://github.com/kloutkake/CVE-2017-5638-PoC",
                "https://github.com/Xernary/CVE-2017-5638-POC",
                "https://github.com/timothyjxhn/DeliberatelyVulnerableWebApp",
                "https://github.com/toothbrushsoapflannelbiscuits/cve-2017-5638",
                "https://github.com/haxerr9/CVE-2017-5638",
                "https://github.com/QHxDr-dz/CVE-2017-5638",
                "https://github.com/joidiego/Detection-struts-cve-2017-5638-detector",
                "https://github.com/iampetru/PoC-CVE-2017-5638",
                "https://github.com/MuhammadAbdullah192/CVE-2017-5638-Remote-Code-Execution-Apache-Struts2-EXPLOITATION",
                "https://github.com/kaylertee/Computer-Security-Equifax-2017",
                "https://github.com/ACharaf06/CVE-2017-5638-Attack-and-Defense",
                "https://github.com/soufiane-benchahyd/vulhub-struts2",
                "https://github.com/AIPEACS/SC3010-Computer-Security",
                "https://github.com/Kouf320/docker-lab-cve-2017-5638-cve-2021-41773",
                "https://github.com/Majaktech/apache-struts-cve-2017-5638-project",
                "https://github.com/Dungsocool/CVE-2017-5638",
                "https://github.com/GU-007/struts2-tool",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JPACORA-STRUTS2SHELL",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-DONALDASHDOWN-COMMON-VULNERABILITY-AND-EXPLOIT",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-JRRDEV-CVE-2017-5638"
            ],
            "timeline": [
                {
                    "at": "2026-09-02T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2017-4971",
            "vendor": "n/a",
            "product": "Spring Web Flow",
            "title": "Spring Web Flow vulnerability",
            "summary": "An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings.",
            "updated_at": "2026-09-08T17:13:05.477",
            "published_at": "2017-06-13T06:29:00.597",
            "cvss": 5.9,
            "cvss_vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 35,
            "confidence_label": "observed",
            "affected": "Spring Web Flow",
            "fixed": "See vendor advisory",
            "source_count": 6,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "High",
            "cwe": "CWE-1188",
            "what_happened": "An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [],
            "references": [
                "http://www.securityfocus.com/bid/98785",
                "https://jira.spring.io/browse/SWF-1700",
                "https://pivotal.io/security/cve-2017-4971"
            ],
            "timeline": [
                {
                    "at": "2017-06-13T06:29:00.597",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-4971"
                }
            ]
        },
        {
            "id": "CVE-2017-3066",
            "vendor": "Adobe",
            "product": "ColdFusion",
            "title": "Adobe ColdFusion Deserialization Vulnerability",
            "summary": "Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.",
            "updated_at": "2026-09-05T12:46:01Z",
            "published_at": "2026-09-05T12:46:01Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 214,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 43993",
                    "author": "Faisal Tameesh",
                    "first_seen": "2018-02-07",
                    "confidence": "High",
                    "title": "Adobe Coldfusion 11.0.03.292866 - BlazeDS Java Object Deserialization Remote Code Execution",
                    "summary": "Adobe Coldfusion 11.0.03.292866 - BlazeDS Java Object Deserialization Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/43993",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2017-3066",
                    "summary": "Java deserialization in Adobe ColdFusion BlazeDS allows remote code execution via untrusted objects.",
                    "what_happened": "Java deserialization in Adobe ColdFusion BlazeDS allows remote code execution via untrusted objects.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CUCADILI-CVE-2017-3066",
                        "https://kitploit.com/ru/tools/github/cucadili/cve-2017-3066/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T12:46:01",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CUCADILI-CVE-2017-3066"
                },
                {
                    "title": "Exploit for CVE-2017-3066",
                    "summary": "Java deserialization in Adobe ColdFusion BlazeDS allows remote code execution via untrusted objects.",
                    "what_happened": "Java deserialization in Adobe ColdFusion BlazeDS allows remote code execution via untrusted objects.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CUCADILI-CVE-2017-3066",
                        "https://kitploit.com/ru/tools/github/cucadili/cve-2017-3066/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-05T12:46:01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/cucadili/cve-2017-3066/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/43993",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CUCADILI-CVE-2017-3066",
                "https://kitploit.com/ru/tools/github/cucadili/cve-2017-3066/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:46:01Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2025-02-24",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2017-2729",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for BootStomp CVE-2017-2729",
            "summary": "BootStomp finds memory corruption and state storage bugs in ARM boot-loaders using angr.",
            "updated_at": "2026-09-04T19:20:26Z",
            "published_at": "2026-09-04T19:20:26Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 47,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "BootStomp finds memory corruption and state storage bugs in ARM boot-loaders using angr.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for BootStomp CVE-2017-2729",
                    "summary": "BootStomp finds memory corruption and state storage bugs in ARM boot-loaders using angr.",
                    "what_happened": "BootStomp finds memory corruption and state storage bugs in ARM boot-loaders using angr.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-UCSB-SECLAB-BOOTSTOMP",
                        "https://kitploit.com/ru/tools/github/ucsb-seclab/bootstomp/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T21:20:26",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-UCSB-SECLAB-BOOTSTOMP"
                },
                {
                    "title": "Exploit for BootStomp CVE-2017-2729",
                    "summary": "BootStomp finds memory corruption and state storage bugs in ARM boot-loaders using angr.",
                    "what_happened": "BootStomp finds memory corruption and state storage bugs in ARM boot-loaders using angr.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-UCSB-SECLAB-BOOTSTOMP",
                        "https://kitploit.com/ru/tools/github/ucsb-seclab/bootstomp/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T21:20:26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/ucsb-seclab/bootstomp/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-UCSB-SECLAB-BOOTSTOMP",
                "https://kitploit.com/ru/tools/github/ucsb-seclab/bootstomp/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T19:20:26Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-UCSB-SECLAB-BOOTSTOMP"
                }
            ],
            "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C"
        },
        {
            "id": "CVE-2017-2636",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for cve-2017-2636-el CVE-2017-2636",
            "summary": "n_hdlc module blacklist role mitigates CVE-2017-2636 in RHEL 6 and 7 kernel.",
            "updated_at": "2026-08-26T04:09:44Z",
            "published_at": "2026-08-26T04:09:44Z",
            "cvss": 7,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 65,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "Unknown",
            "what_happened": "n_hdlc module blacklist role mitigates CVE-2017-2636 in RHEL 6 and 7 kernel.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for cve-2017-2636-el CVE-2017-2636",
                    "summary": "n_hdlc module blacklist role mitigates CVE-2017-2636 in RHEL 6 and 7 kernel.",
                    "what_happened": "n_hdlc module blacklist role mitigates CVE-2017-2636 in RHEL 6 and 7 kernel.",
                    "cvss": 7,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXZORIN-CVE-2017-2636-EL",
                        "https://kitploit.com/hi/tools/github/alexzorin/cve-2017-2636-el/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-26T06:09:44",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXZORIN-CVE-2017-2636-EL"
                },
                {
                    "title": "Exploit for cve-2017-2636-el CVE-2017-2636",
                    "summary": "n_hdlc module blacklist role mitigates CVE-2017-2636 in RHEL 6 and 7 kernel.",
                    "what_happened": "n_hdlc module blacklist role mitigates CVE-2017-2636 in RHEL 6 and 7 kernel.",
                    "cvss": 7,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXZORIN-CVE-2017-2636-EL",
                        "https://kitploit.com/hi/tools/github/alexzorin/cve-2017-2636-el/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-08-26T06:09:44",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/alexzorin/cve-2017-2636-el/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXZORIN-CVE-2017-2636-EL",
                "https://kitploit.com/hi/tools/github/alexzorin/cve-2017-2636-el/"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T04:09:44Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXZORIN-CVE-2017-2636-EL"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2017-0541",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2017-0541",
            "summary": "POC and vulnerability analysis for CVE-2017-0541 in tools.",
            "updated_at": "2026-09-01T14:07:58Z",
            "published_at": "2026-09-01T14:07:58Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 37,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "POC and vulnerability analysis for CVE-2017-0541 in tools.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2017-0541",
                    "summary": "POC and vulnerability analysis for CVE-2017-0541 in tools.",
                    "what_happened": "POC and vulnerability analysis for CVE-2017-0541 in tools.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LIKEKABIN-CVE-2017-0541",
                        "https://kitploit.com/ar/tools/github/likekabin/cve-2017-0541/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-01T16:07:58",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LIKEKABIN-CVE-2017-0541"
                },
                {
                    "title": "Exploit for CVE-2017-0541",
                    "summary": "POC and vulnerability analysis for CVE-2017-0541 in tools.",
                    "what_happened": "POC and vulnerability analysis for CVE-2017-0541 in tools.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LIKEKABIN-CVE-2017-0541",
                        "https://kitploit.com/ar/tools/github/likekabin/cve-2017-0541/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-01T16:07:58",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/likekabin/cve-2017-0541/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LIKEKABIN-CVE-2017-0541",
                "https://kitploit.com/ar/tools/github/likekabin/cve-2017-0541/"
            ],
            "timeline": [
                {
                    "at": "2026-09-01T14:07:58Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LIKEKABIN-CVE-2017-0541"
                }
            ],
            "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C"
        },
        {
            "id": "CVE-2017-0199",
            "vendor": "Microsoft",
            "product": "Office and WordPad",
            "title": "Microsoft Office and WordPad Remote Code Execution Vulnerability",
            "summary": "Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.",
            "updated_at": "2026-09-11T18:30:49Z",
            "published_at": "2026-09-11T18:30:49Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 189,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 42995",
                    "author": "Eduardo Braun Prado",
                    "first_seen": "2017-09-30",
                    "confidence": "High",
                    "title": "Microsoft Excel - OLE Arbitrary Code Execution",
                    "summary": "Microsoft Excel - OLE Arbitrary Code Execution",
                    "url": "https://www.exploit-db.com/exploits/42995",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 41934",
                    "author": "Metasploit",
                    "first_seen": "2017-04-25",
                    "confidence": "High",
                    "title": "Microsoft Office Word - '.RTF' Malicious HTA Execution (Metasploit)",
                    "summary": "Microsoft Office Word - '.RTF' Malicious HTA Execution (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/41934",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 41894",
                    "author": "Bhadresh Patel",
                    "first_seen": "2017-04-18",
                    "confidence": "High",
                    "title": "Microsoft Word - '.RTF' Remote Code Execution",
                    "summary": "Microsoft Word - '.RTF' Remote Code Execution",
                    "url": "https://www.exploit-db.com/exploits/41894",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2017-0199",
                    "summary": "Exploit toolkit for CVE-2017-0199 generating malicious RTF/PPSX files for Microsoft Office RCE.",
                    "what_happened": "Exploit toolkit for CVE-2017-0199 generating malicious RTF/PPSX files for Microsoft Office RCE.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LIKEKABIN-CVE-2017-0199",
                        "https://kitploit.com/ar/tools/github/likekabin/cve-2017-0199/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-05T21:11:04",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LIKEKABIN-CVE-2017-0199"
                },
                {
                    "title": "Exploit for CVE-2017-0199",
                    "summary": "Exploit toolkit for CVE-2017-0199 generating malicious RTF/PPSX files for Microsoft Office RCE.",
                    "what_happened": "Exploit toolkit for CVE-2017-0199 generating malicious RTF/PPSX files for Microsoft Office RCE.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LIKEKABIN-CVE-2017-0199",
                        "https://kitploit.com/ar/tools/github/likekabin/cve-2017-0199/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-05T21:11:04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/likekabin/cve-2017-0199/"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:06:03+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2017-0199-master exploit",
                    "summary": "Exploit for CVE-2017-0199. CVSS 9.3.",
                    "cvss": 9.3,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HAIBARA3839-CVE-2017-0199-MASTER"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/42995",
                "https://www.exploit-db.com/exploits/41934",
                "https://www.exploit-db.com/exploits/41894",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-LIKEKABIN-CVE-2017-0199",
                "https://kitploit.com/ar/tools/github/likekabin/cve-2017-0199/",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HAIBARA3839-CVE-2017-0199-MASTER"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T18:30:49Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2017-0144",
            "vendor": "Microsoft",
            "product": "SMBv1",
            "title": "Microsoft SMBv1 Remote Code Execution Vulnerability",
            "summary": "The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.",
            "updated_at": "2026-09-09T22:00:00Z",
            "published_at": "2026-09-09T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1073,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 41891",
                    "author": "Sean Dillon",
                    "first_seen": "2017-04-17",
                    "confidence": "High",
                    "title": "Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)",
                    "summary": "Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/41891",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 47456",
                    "author": "Metasploit",
                    "first_seen": "2019-10-02",
                    "confidence": "High",
                    "title": "DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)",
                    "summary": "DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/47456",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 42031",
                    "author": "sleepya",
                    "first_seen": "2017-05-17",
                    "confidence": "High",
                    "title": "Microsoft Windows 7/2008 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)",
                    "summary": "Microsoft Windows 7/2008 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)",
                    "url": "https://www.exploit-db.com/exploits/42031",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 42315",
                    "author": "sleepya",
                    "first_seen": "2017-07-11",
                    "confidence": "High",
                    "title": "Microsoft Windows 7/8.1/2008 R2/2012 R2/2016 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)",
                    "summary": "Microsoft Windows 7/8.1/2008 R2/2012 R2/2016 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)",
                    "url": "https://www.exploit-db.com/exploits/42315",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 42030",
                    "author": "sleepya",
                    "first_seen": "2017-05-17",
                    "confidence": "High",
                    "title": "Microsoft Windows 8/8.1/2012 R2 (x64) - 'EternalBlue' SMB Remote Code Execution (MS17-010)",
                    "summary": "Microsoft Windows 8/8.1/2012 R2 (x64) - 'EternalBlue' SMB Remote Code Execution (MS17-010)",
                    "url": "https://www.exploit-db.com/exploits/42030",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 41987",
                    "author": "Juan Sacco",
                    "first_seen": "2017-05-10",
                    "confidence": "High",
                    "title": "Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)",
                    "summary": "Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)",
                    "url": "https://www.exploit-db.com/exploits/41987",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · peterpt/eternal_scanner",
                    "author": "peterpt",
                    "first_seen": "2017-07-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 339,
                    "title": "An internet scanner for exploit CVE-2017-0144 (Eternal Blue) & CVE-2017-0145 (Eternal Romance)",
                    "summary": "An internet scanner for exploit CVE-2017-0144 (Eternal Blue) & CVE-2017-0145 (Eternal Romance)",
                    "url": "https://github.com/peterpt/eternal_scanner"
                },
                {
                    "repository": "PoC-in-GitHub · kimocoder/eternalblue",
                    "author": "kimocoder",
                    "first_seen": "2019-06-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2017-0144",
                    "summary": "CVE-2017-0144",
                    "url": "https://github.com/kimocoder/eternalblue"
                },
                {
                    "repository": "PoC-in-GitHub · EEsshq/CVE-2017-0144---EtneralBlue-MS17-010-Remote-Code-Execution",
                    "author": "EEsshq",
                    "first_seen": "2021-03-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 18,
                    "title": "CVE-2017-0144 repository",
                    "summary": "",
                    "url": "https://github.com/EEsshq/CVE-2017-0144---EtneralBlue-MS17-010-Remote-Code-Execution"
                },
                {
                    "repository": "PoC-in-GitHub · quynhold/Detect-CVE-2017-0144-attack",
                    "author": "quynhold",
                    "first_seen": "2022-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Chương trình theo dõi, giám sát lưu lượng mạng được viết bằng Python, nó sẽ đưa ra cảnh báo khi phát hiện tấn công CVE-2017-0144",
                    "summary": "Chương trình theo dõi, giám sát lưu lượng mạng được viết bằng Python, nó sẽ đưa ra cảnh báo khi phát hiện tấn công CVE-2017-0144",
                    "url": "https://github.com/quynhold/Detect-CVE-2017-0144-attack"
                },
                {
                    "repository": "PoC-in-GitHub · ducanh2oo3/Vulnerability-Research-CVE-2017-0144",
                    "author": "ducanh2oo3",
                    "first_seen": "2024-04-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "LAB: TẤN CÔNG HỆ ĐIỀU HÀNH WINDOWS DỰA VÀO LỖ HỔNG GIAO THỨC SMB.",
                    "summary": "LAB: TẤN CÔNG HỆ ĐIỀU HÀNH WINDOWS DỰA VÀO LỖ HỔNG GIAO THỨC SMB.",
                    "url": "https://github.com/ducanh2oo3/Vulnerability-Research-CVE-2017-0144"
                },
                {
                    "repository": "PoC-in-GitHub · AnugiArrawwala/CVE-Research",
                    "author": "AnugiArrawwala",
                    "first_seen": "2024-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-0144 (Eternal Blue) | CVE-2023-3881 | CVE-2011-2523",
                    "summary": "CVE-2017-0144 (Eternal Blue) | CVE-2023-3881 | CVE-2011-2523",
                    "url": "https://github.com/AnugiArrawwala/CVE-Research"
                },
                {
                    "repository": "PoC-in-GitHub · denuwanjayasekara/CVE-Exploitation-Reports",
                    "author": "denuwanjayasekara",
                    "first_seen": "2024-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708",
                    "summary": "CVE Exploitation Reports: CVE-2007-3280, CVE-2017-0144, CVE-2019-0708",
                    "url": "https://github.com/denuwanjayasekara/CVE-Exploitation-Reports"
                },
                {
                    "repository": "PoC-in-GitHub · sethwhy/BlueDoor",
                    "author": "sethwhy",
                    "first_seen": "2024-12-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative privileges and locate the flag stored behind the windows security",
                    "summary": "Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative privileges and locate the flag stored behind the windows security",
                    "url": "https://github.com/sethwhy/BlueDoor"
                },
                {
                    "repository": "PoC-in-GitHub · AtithKhawas/autoblue",
                    "author": "AtithKhawas",
                    "first_seen": "2024-12-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration testing, and CTF challenges. Strictly for authorized and educational use only!",
                    "summary": "AutoBlue - Automated EternalBlue (CVE-2017-0144 / MS17-010) exploitation tool leveraging Nmap and Metasploit for ethical hacking, penetration testing, and CTF challenges. Strictly for authorized and educational use only!",
                    "url": "https://github.com/AtithKhawas/autoblue"
                },
                {
                    "repository": "PoC-in-GitHub · MedX267/EternalBlue-Vulnerability-Scanner",
                    "author": "MedX267",
                    "first_seen": "2025-02-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This script checks for devices vulnerable to the EternalBlue exploit (CVE-2017-0144) in a network using SMB.",
                    "summary": "This script checks for devices vulnerable to the EternalBlue exploit (CVE-2017-0144) in a network using SMB.",
                    "url": "https://github.com/MedX267/EternalBlue-Vulnerability-Scanner"
                },
                {
                    "repository": "PoC-in-GitHub · pelagornisandersi/WIndows-7-automated-exploitation-using-metasploit-framework-",
                    "author": "pelagornisandersi",
                    "first_seen": "2025-05-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Automated bash script which scans an ip for potential vulnerability to eternalblue using nmap and then exploit using metasploit framework which uses the CVE-2017-0144 vulnerability[Code name: EternalBlue] in (windows 7,windows 2008 servers,etc.) to gain access to a windows 7 machine and establish a reverse meterpreter shell.",
                    "summary": "Automated bash script which scans an ip for potential vulnerability to eternalblue using nmap and then exploit using metasploit framework which uses the CVE-2017-0144 vulnerability[Code name: EternalBlue] in (windows 7,windows 2008 servers,etc.) to gain access to a windows 7 machine and establish a reverse meterpreter shell.",
                    "url": "https://github.com/pelagornisandersi/WIndows-7-automated-exploitation-using-metasploit-framework-"
                },
                {
                    "repository": "PoC-in-GitHub · luckyman2907/SMB-Protocol-Vulnerability_CVE-2017-0144",
                    "author": "luckyman2907",
                    "first_seen": "2025-06-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-0144 repository",
                    "summary": "",
                    "url": "https://github.com/luckyman2907/SMB-Protocol-Vulnerability_CVE-2017-0144"
                },
                {
                    "repository": "PoC-in-GitHub · AdityaBhatt3010/VAPT-Report-on-SMB-Exploitation-in-Windows-10-Finance-Endpoint",
                    "author": "AdityaBhatt3010",
                    "first_seen": "2025-07-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 15,
                    "title": "This report outlines a structured VAPT engagement focusing on PCI DSS compliance, SMB service enumeration, and exploitation of CVE-2017-0144 (EternalBlue) on a Windows 10 machine within a finance-oriented infrastructure.",
                    "summary": "This report outlines a structured VAPT engagement focusing on PCI DSS compliance, SMB service enumeration, and exploitation of CVE-2017-0144 (EternalBlue) on a Windows 10 machine within a finance-oriented infrastructure.",
                    "url": "https://github.com/AdityaBhatt3010/VAPT-Report-on-SMB-Exploitation-in-Windows-10-Finance-Endpoint"
                },
                {
                    "repository": "PoC-in-GitHub · FireTemple/Blackash-CVE-2017-0144",
                    "author": "FireTemple",
                    "first_seen": "2025-11-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2017-0144",
                    "summary": "CVE-2017-0144",
                    "url": "https://github.com/FireTemple/Blackash-CVE-2017-0144"
                },
                {
                    "repository": "PoC-in-GitHub · Mitsu-bis/Eternal-Blue-CVE-2017-0144-THM-Write-Up",
                    "author": "Mitsu-bis",
                    "first_seen": "2025-12-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka \"Windows SMB Remote Code Execution Vulnerability.\"",
                    "summary": "The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka \"Windows SMB Remote Code Execution Vulnerability.\"",
                    "url": "https://github.com/Mitsu-bis/Eternal-Blue-CVE-2017-0144-THM-Write-Up"
                },
                {
                    "repository": "PoC-in-GitHub · klairmanraj/Multi-VLAN-Enterprise-Network-Security-Infrastructure",
                    "author": "klairmanraj",
                    "first_seen": "2026-04-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Multi-VLAN virtual network across 10 VMs: GRE tunneling, nftables firewall, Active Directory, BIND9 DNS, Kea DHCP, Docker web services, SMB file sharing. Vulnerability assessment using OWASP ZAP (Stored XSS) and Nessus (CVE-2017-0144 EternalBlue). Validated with Wireshark.",
                    "summary": "Multi-VLAN virtual network across 10 VMs: GRE tunneling, nftables firewall, Active Directory, BIND9 DNS, Kea DHCP, Docker web services, SMB file sharing. Vulnerability assessment using OWASP ZAP (Stored XSS) and Nessus (CVE-2017-0144 EternalBlue). Validated with Wireshark.",
                    "url": "https://github.com/klairmanraj/Multi-VLAN-Enterprise-Network-Security-Infrastructure"
                },
                {
                    "repository": "PoC-in-GitHub · klairmanraj/Vulnerability-Risk-Assessment-TVRA-Enterprise-Network",
                    "author": "klairmanraj",
                    "first_seen": "2026-04-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Qualitative TVRA for a multi-VLAN enterprise lab: Stored XSS on WebGoat (HIGH, 16), Stored XSS on Magento (ABSENT, MEDIUM, 8), and CVE-2017-0144 EternalBlue on Metasploitable 3 (CRITICAL, 25). Scored via Likelihood × Impact using CVSS v3.0 and ZAP/Nessus/Wireshark evidence.",
                    "summary": "Qualitative TVRA for a multi-VLAN enterprise lab: Stored XSS on WebGoat (HIGH, 16), Stored XSS on Magento (ABSENT, MEDIUM, 8), and CVE-2017-0144 EternalBlue on Metasploitable 3 (CRITICAL, 25). Scored via Likelihood × Impact using CVSS v3.0 and ZAP/Nessus/Wireshark evidence.",
                    "url": "https://github.com/klairmanraj/Vulnerability-Risk-Assessment-TVRA-Enterprise-Network"
                },
                {
                    "repository": "PoC-in-GitHub · klairmanraj/Multi-VLAN-Enterprise-Network-Vulnerability-Assessment",
                    "author": "klairmanraj",
                    "first_seen": "2026-04-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Professional vulnerability assessment of a multi-VLAN enterprise network (student21.local). Confirmed Stored XSS on WebGoat (HIGH, 16) via OWASP ZAP fuzzer, absent XSS on Magento via server sanitization, and CVE-2017-0144 EternalBlue on Metasploitable 3 (CRITICAL, 25) via Nessus + Wireshark PCAP validation.",
                    "summary": "Professional vulnerability assessment of a multi-VLAN enterprise network (student21.local). Confirmed Stored XSS on WebGoat (HIGH, 16) via OWASP ZAP fuzzer, absent XSS on Magento via server sanitization, and CVE-2017-0144 EternalBlue on Metasploitable 3 (CRITICAL, 25) via Nessus + Wireshark PCAP validation.",
                    "url": "https://github.com/klairmanraj/Multi-VLAN-Enterprise-Network-Vulnerability-Assessment"
                },
                {
                    "repository": "PoC-in-GitHub · dannic145/EternalBlue-Exploit-Demonstration",
                    "author": "dannic145",
                    "first_seen": "2026-04-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Cybersecurity lab demonstrating exploitation of CVE-2017-0144 (EternalBlue) using Metasploit against a vulnerable Windows 7 VM, achieving SYSTEM-level access via Meterpreter. Includes full attack chain, post exploitation, and mitigation via MS17-010 patching, tested in an isolated ethical lab environment.",
                    "summary": "Cybersecurity lab demonstrating exploitation of CVE-2017-0144 (EternalBlue) using Metasploit against a vulnerable Windows 7 VM, achieving SYSTEM-level access via Meterpreter. Includes full attack chain, post exploitation, and mitigation via MS17-010 patching, tested in an isolated ethical lab environment.",
                    "url": "https://github.com/dannic145/EternalBlue-Exploit-Demonstration"
                },
                {
                    "repository": "PoC-in-GitHub · ichhyak22/EternalBlue-Exploit-Demonstration-MS17-010",
                    "author": "ichhyak22",
                    "first_seen": "2026-04-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Cybersecurity lab demonstrating exploitation of CVE-2017-0144 (EternalBlue) using Metasploit against a vulnerable Windows 7 VM, achieving SYSTEM-level access via Meterpreter. Includes full attack chain, post exploitation, and mitigation via MS17-010 patching, tested in an isolated ethical lab environment.",
                    "summary": "Cybersecurity lab demonstrating exploitation of CVE-2017-0144 (EternalBlue) using Metasploit against a vulnerable Windows 7 VM, achieving SYSTEM-level access via Meterpreter. Includes full attack chain, post exploitation, and mitigation via MS17-010 patching, tested in an isolated ethical lab environment.",
                    "url": "https://github.com/ichhyak22/EternalBlue-Exploit-Demonstration-MS17-010"
                },
                {
                    "repository": "PoC-in-GitHub · trinadh-dasari-cyber/eternalblue-ms17-010-research",
                    "author": "trinadh-dasari-cyber",
                    "first_seen": "2026-05-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Controlled reproduction of CVE-2017-0144 (EternalBlue) in an isolated AWS EC2 lab — exploit analysis, Wireshark traffic capture, and MITRE ATT&CK mapping",
                    "summary": "Controlled reproduction of CVE-2017-0144 (EternalBlue) in an isolated AWS EC2 lab — exploit analysis, Wireshark traffic capture, and MITRE ATT&CK mapping",
                    "url": "https://github.com/trinadh-dasari-cyber/eternalblue-ms17-010-research"
                },
                {
                    "repository": "PoC-in-GitHub · 0xBlackash/CVE-2017-0144",
                    "author": "0xBlackash",
                    "first_seen": "2026-06-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2017-0144",
                    "summary": "CVE-2017-0144",
                    "url": "https://github.com/0xBlackash/CVE-2017-0144"
                },
                {
                    "repository": "PoC-in-GitHub · probablysecure/Triage-CVE-2017-0144",
                    "author": "probablysecure",
                    "first_seen": "2026-06-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Goal is to triage well known attacks and learn how security teams quickly respond.",
                    "summary": "Goal is to triage well known attacks and learn how security teams quickly respond.",
                    "url": "https://github.com/probablysecure/Triage-CVE-2017-0144"
                },
                {
                    "repository": "PoC-in-GitHub · KitSkater/legacyshield-CVE-2017-0144",
                    "author": "KitSkater",
                    "first_seen": "2026-07-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Defensive Windows security application providing compensating controls for CVE-2017-0144 (EternalBlue/MS17-010) through SMB monitoring, attack detection, automated firewall response, configuration auditing, and security reporting for legacy and unsupported systems.",
                    "summary": "Defensive Windows security application providing compensating controls for CVE-2017-0144 (EternalBlue/MS17-010) through SMB monitoring, attack detection, automated firewall response, configuration auditing, and security reporting for legacy and unsupported systems.",
                    "url": "https://github.com/KitSkater/legacyshield-CVE-2017-0144"
                },
                {
                    "repository": "PoC-in-GitHub · quincyomoruyi6-lang/BLUE-WRITEUP-CVE-2017-0144",
                    "author": "quincyomoruyi6-lang",
                    "first_seen": "2026-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Conducted a complete security assessment of an unpatched Windows 7 target (\"Blue\") to demonstrate the impact of legacy service vulnerabilities in an enterprise environment",
                    "summary": "Conducted a complete security assessment of an unpatched Windows 7 target (\"Blue\") to demonstrate the impact of legacy service vulnerabilities in an enterprise environment",
                    "url": "https://github.com/quincyomoruyi6-lang/BLUE-WRITEUP-CVE-2017-0144"
                },
                {
                    "repository": "PoC-in-GitHub · porcumarcooo/TryHackMe-Blue-MS17-010",
                    "author": "porcumarcooo",
                    "first_seen": "2026-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Walkthrough, threat analysis, and remediation guide for CVE-2017-0144 (EternalBlue).",
                    "summary": "Walkthrough, threat analysis, and remediation guide for CVE-2017-0144 (EternalBlue).",
                    "url": "https://github.com/porcumarcooo/TryHackMe-Blue-MS17-010"
                },
                {
                    "repository": "PoC-in-GitHub · ronankongala/metasploit-pentest-report",
                    "author": "ronankongala",
                    "first_seen": "2026-08-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Authorized penetration test against Metasploitable2 and TryHackMe Blue. 3 CVEs exploited (CVE-2011-2523, CVE-2007-2447, CVE-2017-0144), 4 findings with CVSS scoring and MITRE ATT&CK mapping.",
                    "summary": "Authorized penetration test against Metasploitable2 and TryHackMe Blue. 3 CVEs exploited (CVE-2011-2523, CVE-2007-2447, CVE-2017-0144), 4 findings with CVSS scoring and MITRE ATT&CK mapping.",
                    "url": "https://github.com/ronankongala/metasploit-pentest-report"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/41891",
                "https://www.exploit-db.com/exploits/47456",
                "https://www.exploit-db.com/exploits/42031",
                "https://www.exploit-db.com/exploits/42315",
                "https://www.exploit-db.com/exploits/42030",
                "https://www.exploit-db.com/exploits/41987",
                "https://github.com/peterpt/eternal_scanner",
                "https://github.com/kimocoder/eternalblue",
                "https://github.com/EEsshq/CVE-2017-0144---EtneralBlue-MS17-010-Remote-Code-Execution",
                "https://github.com/quynhold/Detect-CVE-2017-0144-attack",
                "https://github.com/ducanh2oo3/Vulnerability-Research-CVE-2017-0144",
                "https://github.com/AnugiArrawwala/CVE-Research",
                "https://github.com/denuwanjayasekara/CVE-Exploitation-Reports",
                "https://github.com/sethwhy/BlueDoor",
                "https://github.com/AtithKhawas/autoblue",
                "https://github.com/MedX267/EternalBlue-Vulnerability-Scanner",
                "https://github.com/pelagornisandersi/WIndows-7-automated-exploitation-using-metasploit-framework-",
                "https://github.com/luckyman2907/SMB-Protocol-Vulnerability_CVE-2017-0144",
                "https://github.com/AdityaBhatt3010/VAPT-Report-on-SMB-Exploitation-in-Windows-10-Finance-Endpoint",
                "https://github.com/FireTemple/Blackash-CVE-2017-0144",
                "https://github.com/Mitsu-bis/Eternal-Blue-CVE-2017-0144-THM-Write-Up",
                "https://github.com/klairmanraj/Multi-VLAN-Enterprise-Network-Security-Infrastructure",
                "https://github.com/klairmanraj/Vulnerability-Risk-Assessment-TVRA-Enterprise-Network",
                "https://github.com/klairmanraj/Multi-VLAN-Enterprise-Network-Vulnerability-Assessment",
                "https://github.com/dannic145/EternalBlue-Exploit-Demonstration",
                "https://github.com/ichhyak22/EternalBlue-Exploit-Demonstration-MS17-010",
                "https://github.com/trinadh-dasari-cyber/eternalblue-ms17-010-research",
                "https://github.com/0xBlackash/CVE-2017-0144",
                "https://github.com/probablysecure/Triage-CVE-2017-0144",
                "https://github.com/KitSkater/legacyshield-CVE-2017-0144",
                "https://github.com/quincyomoruyi6-lang/BLUE-WRITEUP-CVE-2017-0144",
                "https://github.com/porcumarcooo/TryHackMe-Blue-MS17-010",
                "https://github.com/ronankongala/metasploit-pentest-report"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2016-1000027",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for Forced Browsing in Vmware Spring_Security CVE-2026-22732",
            "summary": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "updated_at": "2026-09-11T11:16:21Z",
            "published_at": "2026-09-11T11:16:21Z",
            "cvss": 9.1,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 45,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "CWE-425",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for Forced Browsing in Vmware Spring_Security CVE-2026-22732",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-425",
                    "references": [
                        "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE",
                        "https://github.com/dylan-chainguard/cve-2026-22732-poc"
                    ],
                    "repository": "Sploitus",
                    "author": "dylan-chainguard",
                    "first_seen": "2026-09-11T13:16:21",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE"
                },
                {
                    "title": "Exploit for Forced Browsing in Vmware Spring_Security CVE-2026-22732",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 9.1,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "CWE-425",
                    "references": [
                        "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE",
                        "https://github.com/dylan-chainguard/cve-2026-22732-poc"
                    ],
                    "repository": "dylan-chainguard/cve-2026-22732-poc",
                    "author": "dylan-chainguard",
                    "first_seen": "2026-09-11T13:16:21",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/dylan-chainguard/cve-2026-22732-poc"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE",
                "https://github.com/dylan-chainguard/cve-2026-22732-poc"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T11:16:21Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=EEC836DD-F307-57D4-9FD8-3DFE8C849ECE"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
        },
        {
            "id": "CVE-2016-10555",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2018-0114 CVE-2019-20933 CVE-2020-28042 CVE-2020-28637 C",
            "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
            "updated_at": "2026-09-09T04:48:12Z",
            "published_at": "2026-09-09T04:48:12Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 80,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2020-28042 CVE-2020-28637 CVE-2022-21449",
                    "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                        "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-10T07:59:46",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299"
                },
                {
                    "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2020-28042 CVE-2020-28637 CVE-2022-21449",
                    "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                        "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-10T07:59:46",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                },
                {
                    "repository": "PoC-in-GitHub · CircuitSoul/poc-cve-2016-10555",
                    "author": "CircuitSoul",
                    "first_seen": "2021-06-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Change the algorithm RS256(asymmetric) to HS256(symmetric) - POC (CVE-2016-10555)",
                    "summary": "Change the algorithm RS256(asymmetric) to HS256(symmetric) - POC (CVE-2016-10555)",
                    "url": "https://github.com/CircuitSoul/poc-cve-2016-10555"
                },
                {
                    "repository": "PoC-in-GitHub · scent2d/PoC-CVE-2016-10555",
                    "author": "scent2d",
                    "first_seen": "2022-01-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2016-10555 PoC code",
                    "summary": "CVE-2016-10555 PoC code",
                    "url": "https://github.com/scent2d/PoC-CVE-2016-10555"
                },
                {
                    "repository": "PoC-in-GitHub · z-bool/Venom-JWT",
                    "author": "z-bool",
                    "first_seen": "2025-01-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 288,
                    "title": "针对JWT渗透开发的漏洞验证/密钥爆破工具，针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ，也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)",
                    "summary": "针对JWT渗透开发的漏洞验证/密钥爆破工具，针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ，也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)",
                    "url": "https://github.com/z-bool/Venom-JWT"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/",
                "https://github.com/CircuitSoul/poc-cve-2016-10555",
                "https://github.com/scent2d/PoC-CVE-2016-10555",
                "https://github.com/z-bool/Venom-JWT"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T04:48:12Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2016-9066",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for foxpwn CVE-2016-9066",
            "summary": "Proof-of-concept exploit for CVE-2016-9066 known as Foxpwn.",
            "updated_at": "2026-08-31T16:32:42Z",
            "published_at": "2026-08-31T16:32:42Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 15,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Proof-of-concept exploit for CVE-2016-9066 known as Foxpwn.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for foxpwn CVE-2016-9066",
                    "summary": "Proof-of-concept exploit for CVE-2016-9066 known as Foxpwn.",
                    "what_happened": "Proof-of-concept exploit for CVE-2016-9066 known as Foxpwn.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SAELO-FOXPWN",
                        "https://kitploit.com/hi/tools/github/saelo/foxpwn/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-31T18:32:42",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SAELO-FOXPWN"
                },
                {
                    "title": "Exploit for foxpwn CVE-2016-9066",
                    "summary": "Proof-of-concept exploit for CVE-2016-9066 known as Foxpwn.",
                    "what_happened": "Proof-of-concept exploit for CVE-2016-9066 known as Foxpwn.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SAELO-FOXPWN",
                        "https://kitploit.com/hi/tools/github/saelo/foxpwn/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-08-31T18:32:42",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/saelo/foxpwn/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SAELO-FOXPWN",
                "https://kitploit.com/hi/tools/github/saelo/foxpwn/"
            ],
            "timeline": [
                {
                    "at": "2026-08-31T16:32:42Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SAELO-FOXPWN"
                }
            ],
            "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
            "id": "CVE-2016-7255",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability.\"",
            "updated_at": "2026-09-10T04:17:32.400",
            "published_at": "2016-11-10T07:00:09.460",
            "cvss": 7.8,
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 332,
            "kev": true,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka \"Win32k Elevation of Privilege Vulnerability.\"",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "packetstormsecurity.com",
                    "author": "NVD reference",
                    "first_seen": "2016-11-10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "http://packetstormsecurity.com/files/140468/Microsoft-Windows-Kernel-win32k.sys-NtSetWindowLongPtr-Privilege-Escalation.html"
                },
                {
                    "repository": "github.com",
                    "author": "NVD reference",
                    "first_seen": "2016-11-10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://github.com/mwrlabs/CVE-2016-7255"
                },
                {
                    "repository": "www.exploit-db.com",
                    "author": "NVD reference",
                    "first_seen": "2016-11-10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://www.exploit-db.com/exploits/40745/"
                },
                {
                    "repository": "www.exploit-db.com",
                    "author": "NVD reference",
                    "first_seen": "2016-11-10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://www.exploit-db.com/exploits/40823/"
                },
                {
                    "repository": "www.exploit-db.com",
                    "author": "NVD reference",
                    "first_seen": "2016-11-10",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://www.exploit-db.com/exploits/41015/"
                },
                {
                    "repository": "Exploit-DB 40745",
                    "author": "TinySec",
                    "first_seen": "2016-11-09",
                    "confidence": "High",
                    "title": "Microsoft Windows Kernel - 'win32k' Denial of Service (MS16-135)",
                    "summary": "Microsoft Windows Kernel - 'win32k' Denial of Service (MS16-135)",
                    "url": "https://www.exploit-db.com/exploits/40745",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 40823",
                    "author": "IOactive",
                    "first_seen": "2016-11-24",
                    "confidence": "High",
                    "title": "Microsoft Windows Kernel - 'win32k.sys NtSetWindowLongPtr' Local Privilege Escalation (MS16-135) (1)",
                    "summary": "Microsoft Windows Kernel - 'win32k.sys NtSetWindowLongPtr' Local Privilege Escalation (MS16-135) (1)",
                    "url": "https://www.exploit-db.com/exploits/40823",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 41015",
                    "author": "Rick Larabee",
                    "first_seen": "2017-01-08",
                    "confidence": "High",
                    "title": "Microsoft Windows Kernel - 'win32k.sys NtSetWindowLongPtr' Local Privilege Escalation (MS16-135) (2)",
                    "summary": "Microsoft Windows Kernel - 'win32k.sys NtSetWindowLongPtr' Local Privilege Escalation (MS16-135) (2)",
                    "url": "https://www.exploit-db.com/exploits/41015",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "http://blog.trendmicro.com/trendlabs-security-intelligence/one-bit-rule-system-analyzing-cve-2016-7255-exploit-wild/",
                "http://packetstormsecurity.com/files/140468/Microsoft-Windows-Kernel-win32k.sys-NtSetWindowLongPtr-Privilege-Escalation.html",
                "http://www.securityfocus.com/bid/94064",
                "http://www.securitytracker.com/id/1037251",
                "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-135",
                "https://github.com/mwrlabs/CVE-2016-7255",
                "https://securingtomorrow.mcafee.com/mcafee-labs/digging-windows-kernel-privilege-escalation-vulnerability-cve-2016-7255/",
                "https://security.googleblog.com/2016/10/disclosing-vulnerabilities-to-protect.html",
                "https://www.exploit-db.com/exploits/40745/",
                "https://www.exploit-db.com/exploits/40823/",
                "https://www.exploit-db.com/exploits/41015/",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-7255",
                "https://www.exploit-db.com/exploits/40745",
                "https://www.exploit-db.com/exploits/40823",
                "https://www.exploit-db.com/exploits/41015"
            ],
            "timeline": [
                {
                    "at": "2016-11-10T07:00:09.460",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-7255"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "enrichment_checked_at": "2026-09-10T10:05:28Z"
        },
        {
            "id": "CVE-2016-5195",
            "vendor": "Linux",
            "product": "Kernel",
            "title": "Linux Kernel Race Condition Vulnerability",
            "summary": "Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges.",
            "updated_at": "2026-08-25T22:00:00Z",
            "published_at": "2026-08-25T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 4182,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 40616",
                    "author": "Robin Verton",
                    "first_seen": "2016-10-21",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.22 < 3.9 (x86/x64) - 'Dirty COW /proc/self/mem' Race Condition Privilege Escalation (SUID Method)",
                    "summary": "Linux Kernel 2.6.22 < 3.9 (x86/x64) - 'Dirty COW /proc/self/mem' Race Condition Privilege Escalation (SUID Method)",
                    "url": "https://www.exploit-db.com/exploits/40616",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 40847",
                    "author": "Gabriele Bonacini",
                    "first_seen": "2016-11-27",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.22 < 3.9 - 'Dirty COW /proc/self/mem' Race Condition Privilege Escalation (/etc/passwd Method)",
                    "summary": "Linux Kernel 2.6.22 < 3.9 - 'Dirty COW /proc/self/mem' Race Condition Privilege Escalation (/etc/passwd Method)",
                    "url": "https://www.exploit-db.com/exploits/40847",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 40838",
                    "author": "Phil Oester",
                    "first_seen": "2016-10-26",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.22 < 3.9 - 'Dirty COW PTRACE_POKEDATA' Race Condition (Write Access Method)",
                    "summary": "Linux Kernel 2.6.22 < 3.9 - 'Dirty COW PTRACE_POKEDATA' Race Condition (Write Access Method)",
                    "url": "https://www.exploit-db.com/exploits/40838",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 40839",
                    "author": "FireFart",
                    "first_seen": "2016-11-28",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.22 < 3.9 - 'Dirty COW' 'PTRACE_POKEDATA' Race Condition Privilege Escalation (/etc/passwd Method)",
                    "summary": "Linux Kernel 2.6.22 < 3.9 - 'Dirty COW' 'PTRACE_POKEDATA' Race Condition Privilege Escalation (/etc/passwd Method)",
                    "url": "https://www.exploit-db.com/exploits/40839",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 40611",
                    "author": "Phil Oester",
                    "first_seen": "2016-10-19",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.22 < 3.9 - 'Dirty COW' /proc/self/mem Race Condition (Write Access Method)",
                    "summary": "Linux Kernel 2.6.22 < 3.9 - 'Dirty COW' /proc/self/mem Race Condition (Write Access Method)",
                    "url": "https://www.exploit-db.com/exploits/40611",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · ASRTeam/CVE-2016-5195",
                    "author": "ASRTeam",
                    "first_seen": "2016-10-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2016-5195 repository",
                    "summary": "",
                    "url": "https://github.com/ASRTeam/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · timwr/CVE-2016-5195",
                    "author": "timwr",
                    "first_seen": "2016-10-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1013,
                    "title": "CVE-2016-5195 (dirtycow/dirtyc0w) proof of concept for Android",
                    "summary": "CVE-2016-5195 (dirtycow/dirtyc0w) proof of concept for Android",
                    "url": "https://github.com/timwr/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · xlucas/dirtycow.cr",
                    "author": "xlucas",
                    "first_seen": "2016-10-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "CVE-2016-5195 exploit written in Crystal",
                    "summary": "CVE-2016-5195 exploit written in Crystal",
                    "url": "https://github.com/xlucas/dirtycow.cr"
                },
                {
                    "repository": "PoC-in-GitHub · istenrot/centos-dirty-cow-ansible",
                    "author": "istenrot",
                    "first_seen": "2016-10-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Ansible playbook to mitigate CVE-2016-5195 on CentOS",
                    "summary": "Ansible playbook to mitigate CVE-2016-5195 on CentOS",
                    "url": "https://github.com/istenrot/centos-dirty-cow-ansible"
                },
                {
                    "repository": "PoC-in-GitHub · pgporada/ansible-role-cve",
                    "author": "pgporada",
                    "first_seen": "2016-10-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "Mitigates CVE-2016-5195 aka DirtyCOW",
                    "summary": "Mitigates CVE-2016-5195 aka DirtyCOW",
                    "url": "https://github.com/pgporada/ansible-role-cve"
                },
                {
                    "repository": "PoC-in-GitHub · sideeffect42/DirtyCOWTester",
                    "author": "sideeffect42",
                    "first_seen": "2016-10-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Dirty COW (CVE-2016-5195) vulnerability testing utility for Linux-based systems.",
                    "summary": "Dirty COW (CVE-2016-5195) vulnerability testing utility for Linux-based systems.",
                    "url": "https://github.com/sideeffect42/DirtyCOWTester"
                },
                {
                    "repository": "PoC-in-GitHub · scumjr/dirtycow-vdso",
                    "author": "scumjr",
                    "first_seen": "2016-10-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 512,
                    "title": "PoC for Dirty COW (CVE-2016-5195)",
                    "summary": "PoC for Dirty COW (CVE-2016-5195)",
                    "url": "https://github.com/scumjr/dirtycow-vdso"
                },
                {
                    "repository": "PoC-in-GitHub · gbonacini/CVE-2016-5195",
                    "author": "gbonacini",
                    "first_seen": "2016-10-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 341,
                    "title": "A CVE-2016-5195 exploit example.",
                    "summary": "A CVE-2016-5195 exploit example.",
                    "url": "https://github.com/gbonacini/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · DavidBuchanan314/cowroot",
                    "author": "DavidBuchanan314",
                    "first_seen": "2016-10-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 32,
                    "title": "Universal Android root tool based on CVE-2016-5195. Watch this space.",
                    "summary": "Universal Android root tool based on CVE-2016-5195. Watch this space.",
                    "url": "https://github.com/DavidBuchanan314/cowroot"
                },
                {
                    "repository": "PoC-in-GitHub · aishee/scan-dirtycow",
                    "author": "aishee",
                    "first_seen": "2016-10-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 16,
                    "title": "Scan vuls kernel CVE-2016-5195 - DirtyCow",
                    "summary": "Scan vuls kernel CVE-2016-5195 - DirtyCow",
                    "url": "https://github.com/aishee/scan-dirtycow"
                },
                {
                    "repository": "PoC-in-GitHub · oleg-fiksel/ansible_CVE-2016-5195_check",
                    "author": "oleg-fiksel",
                    "first_seen": "2016-10-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "CVE-2016-5195 repository",
                    "summary": "",
                    "url": "https://github.com/oleg-fiksel/ansible_CVE-2016-5195_check"
                },
                {
                    "repository": "PoC-in-GitHub · ldenevi/CVE-2016-5195",
                    "author": "ldenevi",
                    "first_seen": "2016-11-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Recent Linux privilege escalation exploit",
                    "summary": "Recent Linux privilege escalation exploit",
                    "url": "https://github.com/ldenevi/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · whu-enjoy/CVE-2016-5195",
                    "author": "whu-enjoy",
                    "first_seen": "2016-11-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 10,
                    "title": "这里保留着部分脏牛漏洞的利用代码",
                    "summary": "这里保留着部分脏牛漏洞的利用代码",
                    "url": "https://github.com/whu-enjoy/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · firefart/dirtycow",
                    "author": "firefart",
                    "first_seen": "2016-11-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 934,
                    "title": "Dirty Cow exploit - CVE-2016-5195",
                    "summary": "Dirty Cow exploit - CVE-2016-5195",
                    "url": "https://github.com/firefart/dirtycow"
                },
                {
                    "repository": "PoC-in-GitHub · ndobson/inspec_CVE-2016-5195",
                    "author": "ndobson",
                    "first_seen": "2016-12-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Inspec profile for detecting CVE-2016-5195 aka Dirty COW",
                    "summary": "Inspec profile for detecting CVE-2016-5195 aka Dirty COW",
                    "url": "https://github.com/ndobson/inspec_CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · sribaba/android-CVE-2016-5195",
                    "author": "sribaba",
                    "first_seen": "2017-01-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2016-5195 repository",
                    "summary": "",
                    "url": "https://github.com/sribaba/android-CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · esc0rtd3w/org.cowpoop.moooooo",
                    "author": "esc0rtd3w",
                    "first_seen": "2017-01-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Android APK Based On Public Information Using DirtyCOW CVE-2016-5195 Exploit",
                    "summary": "Android APK Based On Public Information Using DirtyCOW CVE-2016-5195 Exploit",
                    "url": "https://github.com/esc0rtd3w/org.cowpoop.moooooo"
                },
                {
                    "repository": "PoC-in-GitHub · hyln9/VIKIROOT",
                    "author": "hyln9",
                    "first_seen": "2017-01-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 271,
                    "title": "CVE-2016-5195 (Dirty COW) PoC for Android 6.0.1 Marshmallow",
                    "summary": "CVE-2016-5195 (Dirty COW) PoC for Android 6.0.1 Marshmallow",
                    "url": "https://github.com/hyln9/VIKIROOT"
                },
                {
                    "repository": "PoC-in-GitHub · droidvoider/dirtycow-replacer",
                    "author": "droidvoider",
                    "first_seen": "2017-03-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2016-5195 dirtycow by timwr automated multi file patch tool",
                    "summary": "CVE-2016-5195 dirtycow by timwr automated multi file patch tool",
                    "url": "https://github.com/droidvoider/dirtycow-replacer"
                },
                {
                    "repository": "PoC-in-GitHub · FloridSleeves/os-experiment-4",
                    "author": "FloridSleeves",
                    "first_seen": "2017-06-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "os experiment 4 CVE-2016-5195",
                    "summary": "os experiment 4 CVE-2016-5195",
                    "url": "https://github.com/FloridSleeves/os-experiment-4"
                },
                {
                    "repository": "PoC-in-GitHub · arbll/dirtycow",
                    "author": "arbll",
                    "first_seen": "2017-10-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Ready to use, weaponized dirtycow (CVE-2016-5195)",
                    "summary": "Ready to use, weaponized dirtycow (CVE-2016-5195)",
                    "url": "https://github.com/arbll/dirtycow"
                },
                {
                    "repository": "PoC-in-GitHub · titanhp/Dirty-COW-CVE-2016-5195-Testing",
                    "author": "titanhp",
                    "first_seen": "2017-10-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Dirty COW (CVE-2016-5195) Testing",
                    "summary": "Dirty COW (CVE-2016-5195) Testing",
                    "url": "https://github.com/titanhp/Dirty-COW-CVE-2016-5195-Testing"
                },
                {
                    "repository": "PoC-in-GitHub · acidburnmi/CVE-2016-5195-master",
                    "author": "acidburnmi",
                    "first_seen": "2017-12-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2016-5195 repository",
                    "summary": "",
                    "url": "https://github.com/acidburnmi/CVE-2016-5195-master"
                },
                {
                    "repository": "PoC-in-GitHub · xpcmdshell/derpyc0w",
                    "author": "xpcmdshell",
                    "first_seen": "2018-04-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Example exploit for CVE-2016-5195",
                    "summary": "Example exploit for CVE-2016-5195",
                    "url": "https://github.com/xpcmdshell/derpyc0w"
                },
                {
                    "repository": "PoC-in-GitHub · Brucetg/DirtyCow-EXP",
                    "author": "Brucetg",
                    "first_seen": "2018-05-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 141,
                    "title": "编译好的脏牛漏洞（CVE-2016-5195）EXP",
                    "summary": "编译好的脏牛漏洞（CVE-2016-5195）EXP",
                    "url": "https://github.com/Brucetg/DirtyCow-EXP"
                },
                {
                    "repository": "PoC-in-GitHub · jas502n/CVE-2016-5195",
                    "author": "jas502n",
                    "first_seen": "2019-08-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Linux 本地提权漏洞",
                    "summary": "Linux 本地提权漏洞",
                    "url": "https://github.com/jas502n/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · imust6226/dirtcow",
                    "author": "imust6226",
                    "first_seen": "2019-10-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "脏牛Linux本地提权漏洞复现(CVE-2016-5195)",
                    "summary": "脏牛Linux本地提权漏洞复现(CVE-2016-5195)",
                    "url": "https://github.com/imust6226/dirtcow"
                },
                {
                    "repository": "PoC-in-GitHub · zakariamaaraki/Dirty-COW-CVE-2016-5195-",
                    "author": "zakariamaaraki",
                    "first_seen": "2019-11-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit the dirtycow vulnerability to login as root",
                    "summary": "Exploit the dirtycow vulnerability to login as root",
                    "url": "https://github.com/zakariamaaraki/Dirty-COW-CVE-2016-5195-"
                },
                {
                    "repository": "PoC-in-GitHub · shanuka-ashen/Dirty-Cow-Explanation-CVE-2016-5195-",
                    "author": "shanuka-ashen",
                    "first_seen": "2020-05-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2016-5195 repository",
                    "summary": "",
                    "url": "https://github.com/shanuka-ashen/Dirty-Cow-Explanation-CVE-2016-5195-"
                },
                {
                    "repository": "PoC-in-GitHub · dulanjaya23/Dirty-Cow-CVE-2016-5195-",
                    "author": "dulanjaya23",
                    "first_seen": "2020-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is a Dirty Cow (CVE-2016-5195) privilege escalation vulnerability exploit",
                    "summary": "This is a Dirty Cow (CVE-2016-5195) privilege escalation vulnerability exploit",
                    "url": "https://github.com/dulanjaya23/Dirty-Cow-CVE-2016-5195-"
                },
                {
                    "repository": "PoC-in-GitHub · KaviDk/dirtyCow",
                    "author": "KaviDk",
                    "first_seen": "2020-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Dirtycow also is known as CVE-2016-5195",
                    "summary": "Dirtycow also is known as CVE-2016-5195",
                    "url": "https://github.com/KaviDk/dirtyCow"
                },
                {
                    "repository": "PoC-in-GitHub · DanielEbert/CVE-2016-5195",
                    "author": "DanielEbert",
                    "first_seen": "2020-12-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "DirtyCOW Exploit for Android",
                    "summary": "DirtyCOW Exploit for Android",
                    "url": "https://github.com/DanielEbert/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · arttnba3/CVE-2016-5195",
                    "author": "arttnba3",
                    "first_seen": "2021-04-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "my personal POC of CVE-2016-5195(dirtyCOW)",
                    "summary": "my personal POC of CVE-2016-5195(dirtyCOW)",
                    "url": "https://github.com/arttnba3/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · talsim/root-dirtyc0w",
                    "author": "talsim",
                    "first_seen": "2021-10-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "DirtyCow root privilege escalation (CVE-2016-5195)",
                    "summary": "DirtyCow root privilege escalation (CVE-2016-5195)",
                    "url": "https://github.com/talsim/root-dirtyc0w"
                },
                {
                    "repository": "PoC-in-GitHub · KasunPriyashan/Y2S1-Project-Linux-Exploitaion-using-CVE-2016-5195-Vulnerability",
                    "author": "KasunPriyashan",
                    "first_seen": "2022-01-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2016-5195 repository",
                    "summary": "",
                    "url": "https://github.com/KasunPriyashan/Y2S1-Project-Linux-Exploitaion-using-CVE-2016-5195-Vulnerability"
                },
                {
                    "repository": "PoC-in-GitHub · th3-5had0w/DirtyCOW-PoC",
                    "author": "th3-5had0w",
                    "first_seen": "2022-02-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "An exploit script of CVE-2016-5195",
                    "summary": "An exploit script of CVE-2016-5195",
                    "url": "https://github.com/th3-5had0w/DirtyCOW-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · r1is/CVE-2022-0847",
                    "author": "r1is",
                    "first_seen": "2022-03-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 281,
                    "title": "CVE-2022-0847-DirtyPipe-Exploit   CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞，可覆盖重写任意可读文件中的数据，从而可将普通权限的用户提升到特权 root。    CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞（Dirty Cow），但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”",
                    "summary": "CVE-2022-0847-DirtyPipe-Exploit   CVE-2022-0847 是存在于 Linux内核 5.8 及之后版本中的本地提权漏洞。攻击者通过利用此漏洞，可覆盖重写任意可读文件中的数据，从而可将普通权限的用户提升到特权 root。    CVE-2022-0847 的漏洞原理类似于 CVE-2016-5195 脏牛漏洞（Dirty Cow），但它更容易被利用。漏洞作者将此漏洞命名为“Dirty Pipe”",
                    "url": "https://github.com/r1is/CVE-2022-0847"
                },
                {
                    "repository": "PoC-in-GitHub · TotallyNotAHaxxer/CVE-2016-5195",
                    "author": "TotallyNotAHaxxer",
                    "first_seen": "2022-04-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Ported golang version of dirtycow.c",
                    "summary": "Ported golang version of dirtycow.c",
                    "url": "https://github.com/TotallyNotAHaxxer/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · passionchenjianyegmail8/scumjrs",
                    "author": "passionchenjianyegmail8",
                    "first_seen": "2022-04-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC for Dirty COW (CVE-2016-5195)",
                    "summary": "PoC for Dirty COW (CVE-2016-5195)",
                    "url": "https://github.com/passionchenjianyegmail8/scumjrs"
                },
                {
                    "repository": "PoC-in-GitHub · malinthag62/The-exploitation-of-Dirty-Cow-CVE-2016-5195",
                    "author": "malinthag62",
                    "first_seen": "2022-05-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "The Repository contains documents that explains the explotation of CVE-2016-5195",
                    "summary": "The Repository contains documents that explains the explotation of CVE-2016-5195",
                    "url": "https://github.com/malinthag62/The-exploitation-of-Dirty-Cow-CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · fei9747/CVE-2016-5195",
                    "author": "fei9747",
                    "first_seen": "2022-11-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2016-5195 repository",
                    "summary": "",
                    "url": "https://github.com/fei9747/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · LinuxKernelContent/DirtyCow",
                    "author": "LinuxKernelContent",
                    "first_seen": "2023-02-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Below code takes advantage of a known vulnerability [Dirty COW (CVE-2016-5195)] 🔥",
                    "summary": "Below code takes advantage of a known vulnerability [Dirty COW (CVE-2016-5195)] 🔥",
                    "url": "https://github.com/LinuxKernelContent/DirtyCow"
                },
                {
                    "repository": "PoC-in-GitHub · h1n4mx0z/Research-CVE-2016-5195",
                    "author": "h1n4mx0z",
                    "first_seen": "2023-10-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2016-5195 repository",
                    "summary": "",
                    "url": "https://github.com/h1n4mx0z/Research-CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · EDLLT/CVE-2016-5195-master",
                    "author": "EDLLT",
                    "first_seen": "2023-11-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2016-5195 repository",
                    "summary": "",
                    "url": "https://github.com/EDLLT/CVE-2016-5195-master"
                },
                {
                    "repository": "PoC-in-GitHub · ZhiQiAnSecFork/DirtyCOW_CVE-2016-5195",
                    "author": "ZhiQiAnSecFork",
                    "first_seen": "2023-12-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2016-5195 repository",
                    "summary": "",
                    "url": "https://github.com/ZhiQiAnSecFork/DirtyCOW_CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · sakilahamed/Linux-Kernel-Exploit-LAB",
                    "author": "sakilahamed",
                    "first_seen": "2024-03-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "More specific : Dirty COW (CVE-2016-5195)",
                    "summary": "More specific : Dirty COW (CVE-2016-5195)",
                    "url": "https://github.com/sakilahamed/Linux-Kernel-Exploit-LAB"
                },
                {
                    "repository": "PoC-in-GitHub · ASUKA39/CVE-2016-5195",
                    "author": "ASUKA39",
                    "first_seen": "2024-04-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "DirtyCOW 笔记",
                    "summary": "DirtyCOW 笔记",
                    "url": "https://github.com/ASUKA39/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · LiEnby/PSSRoot",
                    "author": "LiEnby",
                    "first_seen": "2025-03-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "One-Click-Root program based on CVE-2016-5195, that works on the old 'PlayStation Certified' android devices",
                    "summary": "One-Click-Root program based on CVE-2016-5195, that works on the old 'PlayStation Certified' android devices",
                    "url": "https://github.com/LiEnby/PSSRoot"
                },
                {
                    "repository": "PoC-in-GitHub · 0x3n19m4/CVE-2016-5195",
                    "author": "0x3n19m4",
                    "first_seen": "2025-05-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2016-5195 linux kernel exploit",
                    "summary": "CVE-2016-5195 linux kernel exploit",
                    "url": "https://github.com/0x3n19m4/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · Samuel-G3/Escalamiento-de-Privilegios-usando-el-Kernel-Exploit-Dirty-Cow",
                    "author": "Samuel-G3",
                    "first_seen": "2025-06-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit para escalada de privilegios en Linux basado en la vulnerabilidad Dirty Cow (CVE-2016-5195). Incluye binario, código fuente e instrucciones para su uso en entornos controlados.",
                    "summary": "Exploit para escalada de privilegios en Linux basado en la vulnerabilidad Dirty Cow (CVE-2016-5195). Incluye binario, código fuente e instrucciones para su uso en entornos controlados.",
                    "url": "https://github.com/Samuel-G3/Escalamiento-de-Privilegios-usando-el-Kernel-Exploit-Dirty-Cow"
                },
                {
                    "repository": "PoC-in-GitHub · mohammadamin382/dirtycow-lab",
                    "author": "mohammadamin382",
                    "first_seen": "2025-07-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Educational PoC for Dirty COW (CVE-2016-5195) with logging, ptrace fallback, and binary payload support.",
                    "summary": "Educational PoC for Dirty COW (CVE-2016-5195) with logging, ptrace fallback, and binary payload support.",
                    "url": "https://github.com/mohammadamin382/dirtycow-lab"
                },
                {
                    "repository": "PoC-in-GitHub · MarioAlejos-Cs/dirtycow-lab",
                    "author": "MarioAlejos-Cs",
                    "first_seen": "2025-08-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Explotación vulnerabilidad Dirty COW (CVE-2016-5195) en Ubuntu 16.04.1.",
                    "summary": "Explotación vulnerabilidad Dirty COW (CVE-2016-5195) en Ubuntu 16.04.1.",
                    "url": "https://github.com/MarioAlejos-Cs/dirtycow-lab"
                },
                {
                    "repository": "PoC-in-GitHub · ramahmdr/dirtycow",
                    "author": "ramahmdr",
                    "first_seen": "2026-01-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Dirty Cow exploit - CVE-2016-5195",
                    "summary": "Dirty Cow exploit - CVE-2016-5195",
                    "url": "https://github.com/ramahmdr/dirtycow"
                },
                {
                    "repository": "PoC-in-GitHub · elhaddadalaa788-alt/kernel-exploit-dirtycow-project-subm",
                    "author": "elhaddadalaa788-alt",
                    "first_seen": "2026-02-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Dirty COW Privilege Escalation (CVE-2016-5195)",
                    "summary": "Dirty COW Privilege Escalation (CVE-2016-5195)",
                    "url": "https://github.com/elhaddadalaa788-alt/kernel-exploit-dirtycow-project-subm"
                },
                {
                    "repository": "PoC-in-GitHub · theo543/OSDS_Paper_CVE-2016-5195",
                    "author": "theo543",
                    "first_seen": "2026-02-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2016-5195 repository",
                    "summary": "",
                    "url": "https://github.com/theo543/OSDS_Paper_CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · maur0amaya/Escalamiento-de-Privilegios-usando-el-Kernel-Exploit-Dirty-Cow",
                    "author": "maur0amaya",
                    "first_seen": "2026-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Este proyecto tiene como objetivo demostrar de forma práctica el funcionamiento del exploit Dirty COW (CVE-2016-5195), una vulnerabilidad crítica del en el kernel de Linux. Se simula un escenario realista en el que un atacante con acceso local limitado a un sistema sin parchear logra escalar sus privilegios hasta obtener acceso completo como root.",
                    "summary": "Este proyecto tiene como objetivo demostrar de forma práctica el funcionamiento del exploit Dirty COW (CVE-2016-5195), una vulnerabilidad crítica del en el kernel de Linux. Se simula un escenario realista en el que un atacante con acceso local limitado a un sistema sin parchear logra escalar sus privilegios hasta obtener acceso completo como root.",
                    "url": "https://github.com/maur0amaya/Escalamiento-de-Privilegios-usando-el-Kernel-Exploit-Dirty-Cow"
                },
                {
                    "repository": "PoC-in-GitHub · rauljvc8/Exploit-Dirty-Cow",
                    "author": "rauljvc8",
                    "first_seen": "2026-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Privilege escalation lab reproducing the DirtyCow kernel exploit (CVE-2016-5195) in a controlled environment. Includes vulnerable setup, exploit execution, privilege escalation to root, and mitigation analysis.",
                    "summary": "Privilege escalation lab reproducing the DirtyCow kernel exploit (CVE-2016-5195) in a controlled environment. Includes vulnerable setup, exploit execution, privilege escalation to root, and mitigation analysis.",
                    "url": "https://github.com/rauljvc8/Exploit-Dirty-Cow"
                },
                {
                    "repository": "PoC-in-GitHub · GonzaBot/kernel-exploit-dirtycow",
                    "author": "GonzaBot",
                    "first_seen": "2026-06-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Lab — Privilege Escalation via Dirty Cow CVE-2016-5195 | 4Geeks Academy",
                    "summary": "Lab — Privilege Escalation via Dirty Cow CVE-2016-5195 | 4Geeks Academy",
                    "url": "https://github.com/GonzaBot/kernel-exploit-dirtycow"
                },
                {
                    "repository": "PoC-in-GitHub · gogooma125732/CVE-2016-5195",
                    "author": "gogooma125732",
                    "first_seen": "2026-06-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Defensive analysis and non-weaponized validation of CVE-2016-5195 (Dirty COW), including root-cause research, patch analysis, and reproducible evidence.",
                    "summary": "Defensive analysis and non-weaponized validation of CVE-2016-5195 (Dirty COW), including root-cause research, patch analysis, and reproducible evidence.",
                    "url": "https://github.com/gogooma125732/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · voidgguy/lenovo-a1000g-mt8317-A412_01_09_130907-kernel-3.4.0-root-cve-2016-5195",
                    "author": "voidgguy",
                    "first_seen": "2026-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)",
                    "summary": "[AI-assisted] Root method for Lenovo IdeaTab A1000G (MT8317, kernel 3.4.0, Android 4.1) via CVE-2016-5195 (Dirty COW)",
                    "url": "https://github.com/voidgguy/lenovo-a1000g-mt8317-A412_01_09_130907-kernel-3.4.0-root-cve-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · Minime794/CVE-2016-5195",
                    "author": "Minime794",
                    "first_seen": "2026-08-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Copy Fail CVE-2016-5195",
                    "summary": "Copy Fail CVE-2016-5195",
                    "url": "https://github.com/Minime794/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · KongQBin/CVE-2016-5195",
                    "author": "KongQBin",
                    "first_seen": "2026-08-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2016-5195 repository",
                    "summary": "",
                    "url": "https://github.com/KongQBin/CVE-2016-5195"
                },
                {
                    "repository": "PoC-in-GitHub · vudangducminh/CVE-2016-5195",
                    "author": "vudangducminh",
                    "first_seen": "2026-09-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2016-5195 repository",
                    "summary": "",
                    "url": "https://github.com/vudangducminh/CVE-2016-5195"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/40616",
                "https://www.exploit-db.com/exploits/40847",
                "https://www.exploit-db.com/exploits/40838",
                "https://www.exploit-db.com/exploits/40839",
                "https://www.exploit-db.com/exploits/40611",
                "https://github.com/ASRTeam/CVE-2016-5195",
                "https://github.com/timwr/CVE-2016-5195",
                "https://github.com/xlucas/dirtycow.cr",
                "https://github.com/istenrot/centos-dirty-cow-ansible",
                "https://github.com/pgporada/ansible-role-cve",
                "https://github.com/sideeffect42/DirtyCOWTester",
                "https://github.com/scumjr/dirtycow-vdso",
                "https://github.com/gbonacini/CVE-2016-5195",
                "https://github.com/DavidBuchanan314/cowroot",
                "https://github.com/aishee/scan-dirtycow",
                "https://github.com/oleg-fiksel/ansible_CVE-2016-5195_check",
                "https://github.com/ldenevi/CVE-2016-5195",
                "https://github.com/whu-enjoy/CVE-2016-5195",
                "https://github.com/firefart/dirtycow",
                "https://github.com/ndobson/inspec_CVE-2016-5195",
                "https://github.com/sribaba/android-CVE-2016-5195",
                "https://github.com/esc0rtd3w/org.cowpoop.moooooo",
                "https://github.com/hyln9/VIKIROOT",
                "https://github.com/droidvoider/dirtycow-replacer",
                "https://github.com/FloridSleeves/os-experiment-4",
                "https://github.com/arbll/dirtycow",
                "https://github.com/titanhp/Dirty-COW-CVE-2016-5195-Testing",
                "https://github.com/acidburnmi/CVE-2016-5195-master",
                "https://github.com/xpcmdshell/derpyc0w",
                "https://github.com/Brucetg/DirtyCow-EXP",
                "https://github.com/jas502n/CVE-2016-5195",
                "https://github.com/imust6226/dirtcow",
                "https://github.com/zakariamaaraki/Dirty-COW-CVE-2016-5195-",
                "https://github.com/shanuka-ashen/Dirty-Cow-Explanation-CVE-2016-5195-",
                "https://github.com/dulanjaya23/Dirty-Cow-CVE-2016-5195-",
                "https://github.com/KaviDk/dirtyCow",
                "https://github.com/DanielEbert/CVE-2016-5195",
                "https://github.com/arttnba3/CVE-2016-5195",
                "https://github.com/talsim/root-dirtyc0w",
                "https://github.com/KasunPriyashan/Y2S1-Project-Linux-Exploitaion-using-CVE-2016-5195-Vulnerability",
                "https://github.com/th3-5had0w/DirtyCOW-PoC",
                "https://github.com/r1is/CVE-2022-0847",
                "https://github.com/TotallyNotAHaxxer/CVE-2016-5195",
                "https://github.com/passionchenjianyegmail8/scumjrs",
                "https://github.com/malinthag62/The-exploitation-of-Dirty-Cow-CVE-2016-5195",
                "https://github.com/fei9747/CVE-2016-5195",
                "https://github.com/LinuxKernelContent/DirtyCow",
                "https://github.com/h1n4mx0z/Research-CVE-2016-5195",
                "https://github.com/EDLLT/CVE-2016-5195-master",
                "https://github.com/ZhiQiAnSecFork/DirtyCOW_CVE-2016-5195",
                "https://github.com/sakilahamed/Linux-Kernel-Exploit-LAB",
                "https://github.com/ASUKA39/CVE-2016-5195",
                "https://github.com/LiEnby/PSSRoot",
                "https://github.com/0x3n19m4/CVE-2016-5195",
                "https://github.com/Samuel-G3/Escalamiento-de-Privilegios-usando-el-Kernel-Exploit-Dirty-Cow",
                "https://github.com/mohammadamin382/dirtycow-lab",
                "https://github.com/MarioAlejos-Cs/dirtycow-lab",
                "https://github.com/ramahmdr/dirtycow",
                "https://github.com/elhaddadalaa788-alt/kernel-exploit-dirtycow-project-subm",
                "https://github.com/theo543/OSDS_Paper_CVE-2016-5195",
                "https://github.com/maur0amaya/Escalamiento-de-Privilegios-usando-el-Kernel-Exploit-Dirty-Cow",
                "https://github.com/rauljvc8/Exploit-Dirty-Cow",
                "https://github.com/GonzaBot/kernel-exploit-dirtycow",
                "https://github.com/gogooma125732/CVE-2016-5195",
                "https://github.com/voidgguy/lenovo-a1000g-mt8317-A412_01_09_130907-kernel-3.4.0-root-cve-2016-5195",
                "https://github.com/Minime794/CVE-2016-5195",
                "https://github.com/KongQBin/CVE-2016-5195",
                "https://github.com/vudangducminh/CVE-2016-5195"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2016-4463",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for CVE-2016-4463",
            "summary": "Xerces 3.1.3 and below exploit with Java OpenSAML potentially vulnerable.",
            "updated_at": "2026-09-06T13:45:52Z",
            "published_at": "2026-09-06T13:45:52Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 67,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Xerces 3.1.3 and below exploit with Java OpenSAML potentially vulnerable.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2016-4463",
                    "summary": "Xerces 3.1.3 and below exploit with Java OpenSAML potentially vulnerable.",
                    "what_happened": "Xerces 3.1.3 and below exploit with Java OpenSAML potentially vulnerable.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ARNTSONL-CVE-2016-4463",
                        "https://kitploit.com/hi/tools/github/arntsonl/cve-2016-4463/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T15:45:52",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ARNTSONL-CVE-2016-4463"
                },
                {
                    "title": "Exploit for CVE-2016-4463",
                    "summary": "Xerces 3.1.3 and below exploit with Java OpenSAML potentially vulnerable.",
                    "what_happened": "Xerces 3.1.3 and below exploit with Java OpenSAML potentially vulnerable.",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ARNTSONL-CVE-2016-4463",
                        "https://kitploit.com/hi/tools/github/arntsonl/cve-2016-4463/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-06T15:45:52",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/arntsonl/cve-2016-4463/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ARNTSONL-CVE-2016-4463",
                "https://kitploit.com/hi/tools/github/arntsonl/cve-2016-4463/"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T13:45:52Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ARNTSONL-CVE-2016-4463"
                }
            ],
            "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
        },
        {
            "id": "CVE-2016-4437",
            "vendor": "Apache",
            "product": "Shiro",
            "title": "Apache Shiro Code Execution Vulnerability",
            "summary": "Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the \"remember me\" feature.",
            "updated_at": "2026-09-13T18:39:14Z",
            "published_at": "2026-09-13T18:39:14Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 64,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been configured for the \"remember me\" feature.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 48410",
                    "author": "Metasploit",
                    "first_seen": "2020-05-01",
                    "confidence": "High",
                    "title": "Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)",
                    "summary": "Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/48410",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2016-4437",
                    "summary": "Deserialization in Apache Shiro due to hardcoded encryption key allows exploitation.",
                    "what_happened": "Deserialization in Apache Shiro due to hardcoded encryption key allows exploitation.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-PIZZA-POWER-CVE-2016-4437",
                        "https://kitploit.com/ru/tools/github/pizza-power/cve-2016-4437/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T18:39:05",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-PIZZA-POWER-CVE-2016-4437"
                },
                {
                    "title": "Exploit for CVE-2016-4437",
                    "summary": "Deserialization in Apache Shiro due to hardcoded encryption key allows exploitation.",
                    "what_happened": "Deserialization in Apache Shiro due to hardcoded encryption key allows exploitation.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-PIZZA-POWER-CVE-2016-4437",
                        "https://kitploit.com/ru/tools/github/pizza-power/cve-2016-4437/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-06T18:39:05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/pizza-power/cve-2016-4437/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/48410",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-PIZZA-POWER-CVE-2016-4437",
                "https://kitploit.com/ru/tools/github/pizza-power/cve-2016-4437/"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:39:14Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2021-11-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2016-4117",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.",
            "updated_at": "2026-09-10T04:17:30.760",
            "published_at": "2016-05-11T01:59:46.137",
            "cvss": 9.8,
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 190,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 46339",
                    "author": "Metasploit",
                    "first_seen": "2019-02-11",
                    "confidence": "High",
                    "title": "Adobe Flash Player - DeleteRangeTimelineOperation Type Confusion (Metasploit)",
                    "summary": "Adobe Flash Player - DeleteRangeTimelineOperation Type Confusion (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/46339",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2016-4117-Report",
                    "summary": "Vulnerability in tools identified as CVE-2016-4117.",
                    "what_happened": "Vulnerability in tools identified as CVE-2016-4117.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AMIT-RAUT-CVE-2016-4117-REPORT",
                        "https://kitploit.com/zh/tools/github/amit-raut/cve-2016-4117-report/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T08:28:06",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AMIT-RAUT-CVE-2016-4117-REPORT"
                },
                {
                    "repository": "www.exploit-db.com",
                    "author": "NVD reference",
                    "first_seen": "2016-05-11",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://www.exploit-db.com/exploits/46339/"
                },
                {
                    "title": "Exploit for CVE-2016-4117-Report",
                    "summary": "Vulnerability in tools identified as CVE-2016-4117.",
                    "what_happened": "Vulnerability in tools identified as CVE-2016-4117.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AMIT-RAUT-CVE-2016-4117-REPORT",
                        "https://kitploit.com/zh/tools/github/amit-raut/cve-2016-4117-report/"
                    ],
                    "repository": "kitploit.com",
                    "author": "zh",
                    "first_seen": "2026-09-06T08:28:06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/zh/tools/github/amit-raut/cve-2016-4117-report/"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/46339",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AMIT-RAUT-CVE-2016-4117-REPORT",
                "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00044.html",
                "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00045.html",
                "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00046.html",
                "http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00047.html",
                "http://rhn.redhat.com/errata/RHSA-2016-1079.html",
                "http://www.securityfocus.com/bid/90505",
                "http://www.securitytracker.com/id/1035826",
                "https://helpx.adobe.com/security/products/flash-player/apsa16-02.html",
                "https://helpx.adobe.com/security/products/flash-player/apsb16-15.html",
                "https://security.gentoo.org/glsa/201606-08",
                "https://www.exploit-db.com/exploits/46339/",
                "https://github.com/cisagov/vulnrichment/issues/196",
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-4117",
                "https://kitploit.com/zh/tools/github/amit-raut/cve-2016-4117-report/"
            ],
            "timeline": [
                {
                    "at": "2016-05-11T01:59:46.137",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-4117"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-03-03",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "enrichment_checked_at": "2026-09-10T10:05:28Z"
        },
        {
            "id": "CVE-2016-3223",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Microsoft Windows 7 (x86/x64) - Group Policy Privilege Escalation (MS16-072)",
            "summary": "Microsoft Windows 7 (x86/x64) - Group Policy Privilege Escalation (MS16-072)",
            "updated_at": "2026-09-09T22:00:00Z",
            "published_at": "2026-09-09T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 78,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 40219",
                    "author": "Nabeel Ahmed",
                    "first_seen": "2016-08-08",
                    "confidence": "High",
                    "title": "Microsoft Windows 7 (x86/x64) - Group Policy Privilege Escalation (MS16-072)",
                    "summary": "Microsoft Windows 7 (x86/x64) - Group Policy Privilege Escalation (MS16-072)",
                    "url": "https://www.exploit-db.com/exploits/40219",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · HORKimhab/CVE-2016-3223",
                    "author": "HORKimhab",
                    "first_seen": "2026-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2016-3223 - Draft or TODO",
                    "summary": "CVE-2016-3223 - Draft or TODO",
                    "url": "https://github.com/HORKimhab/CVE-2016-3223"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/40219",
                "https://github.com/HORKimhab/CVE-2016-3223"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/40219"
                }
            ]
        },
        {
            "id": "CVE-2016-3088",
            "vendor": "Apache",
            "product": "ActiveMQ",
            "title": "Apache ActiveMQ Improper Input Validation Vulnerability",
            "summary": "The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request",
            "updated_at": "2026-09-15T08:27:29Z",
            "published_at": "2026-09-15T08:27:29Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 35,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 42283",
                    "author": "Metasploit",
                    "first_seen": "2017-06-29",
                    "confidence": "High",
                    "title": "ActiveMQ < 5.14.0 - Web Shell Upload (Metasploit)",
                    "summary": "ActiveMQ < 5.14.0 - Web Shell Upload (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/42283",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 40857",
                    "author": "David Jorm",
                    "first_seen": "2015-08-17",
                    "confidence": "High",
                    "title": "Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution",
                    "summary": "Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution",
                    "url": "https://www.exploit-db.com/exploits/40857",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-15T08:27:29+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2016-3088 exploit",
                    "summary": "Exploit for CVE-2016-3088. CVSS 9.8.",
                    "cvss": 9.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CL4YM0RE-CVE-2016-3088"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/42283",
                "https://www.exploit-db.com/exploits/40857",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-CL4YM0RE-CVE-2016-3088"
            ],
            "timeline": [
                {
                    "at": "2026-09-15T08:27:29Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-02-10",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2015-7697",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
            "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
            "updated_at": "2026-09-04T19:43:05Z",
            "published_at": "2026-09-04T19:43:05Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 47,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
                    "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                        "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T21:43:05",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK"
                },
                {
                    "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
                    "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                        "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T21:43:05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T19:43:05Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2015-7696",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
            "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
            "updated_at": "2026-09-04T19:43:05Z",
            "published_at": "2026-09-04T19:43:05Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 47,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
                    "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                        "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T21:43:05",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK"
                },
                {
                    "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
                    "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                        "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T21:43:05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T19:43:05Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2015-5377",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2015-5377 exploit",
            "summary": "Exploit for CVE-2015-5377. CVSS 9.8.",
            "updated_at": "2026-09-05T08:14:08Z",
            "published_at": "2026-09-05T08:14:08Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 155,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "RCE in Elasticsearch 1.5.2 via insecure Java deserialization on transport port 9300.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for CVE-2015-5377",
                    "summary": "RCE in Elasticsearch 1.5.2 via insecure Java deserialization on transport port 9300.",
                    "what_happened": "RCE in Elasticsearch 1.5.2 via insecure Java deserialization on transport port 9300.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FI3RO-CVE-2015-5377",
                        "https://kitploit.com/hi/tools/github/fi3ro/cve-2015-5377/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T01:57:46",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FI3RO-CVE-2015-5377"
                },
                {
                    "repository": "fi3ro/CVE-2015-5377",
                    "author": "fi3ro",
                    "first_seen": "2020-12-28",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 3,
                    "title": "Java deserialization exploit for elasticsearch 1.5.2 CVE-2015-5377",
                    "summary": "Java deserialization exploit for elasticsearch 1.5.2 CVE-2015-5377",
                    "url": "https://github.com/fi3ro/CVE-2015-5377"
                },
                {
                    "title": "Exploit for CVE-2015-5377",
                    "summary": "RCE in Elasticsearch 1.5.2 via insecure Java deserialization on transport port 9300.",
                    "what_happened": "RCE in Elasticsearch 1.5.2 via insecure Java deserialization on transport port 9300.",
                    "cvss": 9.8,
                    "cvss_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FI3RO-CVE-2015-5377",
                        "https://kitploit.com/hi/tools/github/fi3ro/cve-2015-5377/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-09-03T01:57:46",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/fi3ro/cve-2015-5377/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FI3RO-CVE-2015-5377",
                "https://github.com/fi3ro/CVE-2015-5377",
                "https://kitploit.com/hi/tools/github/fi3ro/cve-2015-5377/"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:14:08Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-FI3RO-CVE-2015-5377"
                }
            ]
        },
        {
            "id": "CVE-2015-5287",
            "vendor": "Red Hat",
            "product": "Automatic Bug Reporting Tool",
            "title": "Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability",
            "summary": "Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
            "updated_at": "2026-08-25T22:00:00Z",
            "published_at": "2026-08-25T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 327,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 47421",
                    "author": "Metasploit",
                    "first_seen": "2019-09-25",
                    "confidence": "High",
                    "title": "ABRT - sosreport Privilege Escalation (Metasploit)",
                    "summary": "ABRT - sosreport Privilege Escalation (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/47421",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 38832",
                    "author": "rebel",
                    "first_seen": "2015-12-01",
                    "confidence": "High",
                    "title": "RHEL 7.0/7.1 - 'abrt/sosreport' Local Privilege Escalation",
                    "summary": "RHEL 7.0/7.1 - 'abrt/sosreport' Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/38832",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 38835",
                    "author": "rebel",
                    "first_seen": "2015-12-01",
                    "confidence": "High",
                    "title": "abrt (Centos 7.1 / Fedora 22) - Local Privilege Escalation",
                    "summary": "abrt (Centos 7.1 / Fedora 22) - Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/38835",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/47421",
                "https://www.exploit-db.com/exploits/38832",
                "https://www.exploit-db.com/exploits/38835"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2015-3306",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "ProFTPd 1.3.5 - 'mod_copy' Command Execution (Metasploit)",
            "summary": "ProFTPd 1.3.5 - 'mod_copy' Command Execution (Metasploit)",
            "updated_at": "2026-09-06T22:00:00Z",
            "published_at": "2026-09-06T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 829,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 37262",
                    "author": "Metasploit",
                    "first_seen": "2015-06-10",
                    "confidence": "High",
                    "title": "ProFTPd 1.3.5 - 'mod_copy' Command Execution (Metasploit)",
                    "summary": "ProFTPd 1.3.5 - 'mod_copy' Command Execution (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/37262",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 36803",
                    "author": "R-73eN",
                    "first_seen": "2015-04-21",
                    "confidence": "High",
                    "title": "ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution",
                    "summary": "ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution",
                    "url": "https://www.exploit-db.com/exploits/36803",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 49908",
                    "author": "Shellbr3ak",
                    "first_seen": "2021-05-26",
                    "confidence": "High",
                    "title": "ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution (2)",
                    "summary": "ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution (2)",
                    "url": "https://www.exploit-db.com/exploits/49908",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 36742",
                    "author": "anonymous",
                    "first_seen": "2015-04-13",
                    "confidence": "High",
                    "title": "ProFTPd 1.3.5 - File Copy",
                    "summary": "ProFTPd 1.3.5 - File Copy",
                    "url": "https://www.exploit-db.com/exploits/36742",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · xyk0x/cpx_proftpd",
                    "author": "xyk0x",
                    "first_seen": "2015-04-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Tool for exploit CVE-2015-3306",
                    "summary": "Tool for exploit CVE-2015-3306",
                    "url": "https://github.com/xyk0x/cpx_proftpd"
                },
                {
                    "repository": "PoC-in-GitHub · nootropics/propane",
                    "author": "nootropics",
                    "first_seen": "2015-04-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Exploits the arbitrary file write bug in proftpd (CVE-2015-3306) attempts code execution",
                    "summary": "Exploits the arbitrary file write bug in proftpd (CVE-2015-3306) attempts code execution",
                    "url": "https://github.com/nootropics/propane"
                },
                {
                    "repository": "PoC-in-GitHub · t0kx/exploit-CVE-2015-3306",
                    "author": "t0kx",
                    "first_seen": "2017-01-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 151,
                    "title": "ProFTPd 1.3.5 - (mod_copy) Remote Command Execution exploit and vulnerable container",
                    "summary": "ProFTPd 1.3.5 - (mod_copy) Remote Command Execution exploit and vulnerable container",
                    "url": "https://github.com/t0kx/exploit-CVE-2015-3306"
                },
                {
                    "repository": "PoC-in-GitHub · davidtavarez/CVE-2015-3306",
                    "author": "davidtavarez",
                    "first_seen": "2017-07-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "ProFTPd 1.3.5 - File Copy",
                    "summary": "ProFTPd 1.3.5 - File Copy",
                    "url": "https://github.com/davidtavarez/CVE-2015-3306"
                },
                {
                    "repository": "PoC-in-GitHub · cved-sources/cve-2015-3306",
                    "author": "cved-sources",
                    "first_seen": "2019-01-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "cve-2015-3306",
                    "summary": "cve-2015-3306",
                    "url": "https://github.com/cved-sources/cve-2015-3306"
                },
                {
                    "repository": "PoC-in-GitHub · hackarada/cve-2015-3306",
                    "author": "hackarada",
                    "first_seen": "2020-02-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "cve-2015-3306 docker image",
                    "summary": "cve-2015-3306 docker image",
                    "url": "https://github.com/hackarada/cve-2015-3306"
                },
                {
                    "repository": "PoC-in-GitHub · cdedmondson/Modified-CVE-2015-3306-Exploit",
                    "author": "cdedmondson",
                    "first_seen": "2020-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2015-3306 repository",
                    "summary": "",
                    "url": "https://github.com/cdedmondson/Modified-CVE-2015-3306-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · cd6629/CVE-2015-3306-Python-PoC",
                    "author": "cd6629",
                    "first_seen": "2020-10-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Converted with tweaks from a metasploit module as an exercise for OSCP studying and exploit development",
                    "summary": "Converted with tweaks from a metasploit module as an exercise for OSCP studying and exploit development",
                    "url": "https://github.com/cd6629/CVE-2015-3306-Python-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · 0xm4ud/ProFTPD_CVE-2015-3306",
                    "author": "0xm4ud",
                    "first_seen": "2021-05-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2015-3306 repository",
                    "summary": "",
                    "url": "https://github.com/0xm4ud/ProFTPD_CVE-2015-3306"
                },
                {
                    "repository": "PoC-in-GitHub · jptr218/proftpd_bypass",
                    "author": "jptr218",
                    "first_seen": "2021-08-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "An implementation of CVE-2015-3306",
                    "summary": "An implementation of CVE-2015-3306",
                    "url": "https://github.com/jptr218/proftpd_bypass"
                },
                {
                    "repository": "PoC-in-GitHub · JoseLRC97/ProFTPd-1.3.5-mod_copy-Remote-Command-Execution",
                    "author": "JoseLRC97",
                    "first_seen": "2024-04-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Script that exploits the vulnerability of the ProFTPd 1.3.5 service with CVE-2015-3306",
                    "summary": "Script that exploits the vulnerability of the ProFTPd 1.3.5 service with CVE-2015-3306",
                    "url": "https://github.com/JoseLRC97/ProFTPd-1.3.5-mod_copy-Remote-Command-Execution"
                },
                {
                    "repository": "PoC-in-GitHub · Z3R0space/CVE-2015-3306",
                    "author": "Z3R0space",
                    "first_seen": "2025-05-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This contains single-file exploit for ProFTPd 1.3.5 mod_copy (CVE-2015-3306) vulnerability, especially for TryHackMe Kenobi Lab.",
                    "summary": "This contains single-file exploit for ProFTPd 1.3.5 mod_copy (CVE-2015-3306) vulnerability, especially for TryHackMe Kenobi Lab.",
                    "url": "https://github.com/Z3R0space/CVE-2015-3306"
                },
                {
                    "repository": "PoC-in-GitHub · donmedfor/CVE-2015-3306",
                    "author": "donmedfor",
                    "first_seen": "2025-08-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2015-3306 repository",
                    "summary": "",
                    "url": "https://github.com/donmedfor/CVE-2015-3306"
                },
                {
                    "repository": "PoC-in-GitHub · cybersensei-EH/hackviser_labs_CVE-2015-3306",
                    "author": "cybersensei-EH",
                    "first_seen": "2025-11-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This is a customized script to help solve the lab on remote code execution under the CVE-2015-3306 lab.",
                    "summary": "This is a customized script to help solve the lab on remote code execution under the CVE-2015-3306 lab.",
                    "url": "https://github.com/cybersensei-EH/hackviser_labs_CVE-2015-3306"
                },
                {
                    "repository": "PoC-in-GitHub · netw0rk7/CVE-2015-3306-Home-Lab",
                    "author": "netw0rk7",
                    "first_seen": "2025-11-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2015-3306 - ProFTPD - RCE Home Lab setup (Docker) easy to use for Red Teaming or Penetration Testing",
                    "summary": "CVE-2015-3306 - ProFTPD - RCE Home Lab setup (Docker) easy to use for Red Teaming or Penetration Testing",
                    "url": "https://github.com/netw0rk7/CVE-2015-3306-Home-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · canpilayda/proftpd-mod_copy-cve-2015-3306",
                    "author": "canpilayda",
                    "first_seen": "2026-01-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploitation report for ProFTPD 1.3.5 mod_copy (CVE-2015-3306) lab.",
                    "summary": "Exploitation report for ProFTPD 1.3.5 mod_copy (CVE-2015-3306) lab.",
                    "url": "https://github.com/canpilayda/proftpd-mod_copy-cve-2015-3306"
                },
                {
                    "repository": "PoC-in-GitHub · bcononugbor-source/OpenVAS-Vulnerability-Analysis-Incident-Response-Report",
                    "author": "bcononugbor-source",
                    "first_seen": "2026-06-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Real-World Simulation: FTP Service Exploitation (ProFTPD CVE-2015-3306)",
                    "summary": "Real-World Simulation: FTP Service Exploitation (ProFTPD CVE-2015-3306)",
                    "url": "https://github.com/bcononugbor-source/OpenVAS-Vulnerability-Analysis-Incident-Response-Report"
                },
                {
                    "repository": "PoC-in-GitHub · diegslva/cve-2015-3306-lab",
                    "author": "diegslva",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Reproducible Docker lab + raw-socket exploit for CVE-2015-3306 (ProFTPD mod_copy pre-auth arbitrary file copy) — a patch-diffing learning exercise",
                    "summary": "Reproducible Docker lab + raw-socket exploit for CVE-2015-3306 (ProFTPD mod_copy pre-auth arbitrary file copy) — a patch-diffing learning exercise",
                    "url": "https://github.com/diegslva/cve-2015-3306-lab"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/37262",
                "https://www.exploit-db.com/exploits/36803",
                "https://www.exploit-db.com/exploits/49908",
                "https://www.exploit-db.com/exploits/36742",
                "https://github.com/xyk0x/cpx_proftpd",
                "https://github.com/nootropics/propane",
                "https://github.com/t0kx/exploit-CVE-2015-3306",
                "https://github.com/davidtavarez/CVE-2015-3306",
                "https://github.com/cved-sources/cve-2015-3306",
                "https://github.com/hackarada/cve-2015-3306",
                "https://github.com/cdedmondson/Modified-CVE-2015-3306-Exploit",
                "https://github.com/cd6629/CVE-2015-3306-Python-PoC",
                "https://github.com/0xm4ud/ProFTPD_CVE-2015-3306",
                "https://github.com/jptr218/proftpd_bypass",
                "https://github.com/JoseLRC97/ProFTPd-1.3.5-mod_copy-Remote-Command-Execution",
                "https://github.com/Z3R0space/CVE-2015-3306",
                "https://github.com/donmedfor/CVE-2015-3306",
                "https://github.com/cybersensei-EH/hackviser_labs_CVE-2015-3306",
                "https://github.com/netw0rk7/CVE-2015-3306-Home-Lab",
                "https://github.com/canpilayda/proftpd-mod_copy-cve-2015-3306",
                "https://github.com/bcononugbor-source/OpenVAS-Vulnerability-Analysis-Incident-Response-Report",
                "https://github.com/diegslva/cve-2015-3306-lab"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/37262"
                }
            ]
        },
        {
            "id": "CVE-2015-3246",
            "vendor": "Red Hat",
            "product": "Libuser",
            "title": "Red Hat Libuser Race Condition Vulnerability",
            "summary": "Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.",
            "updated_at": "2026-08-25T22:00:00Z",
            "published_at": "2026-08-25T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 234,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 37706",
                    "author": "Qualys Corporation",
                    "first_seen": "2015-07-27",
                    "confidence": "High",
                    "title": "Libuser Library - Multiple Vulnerabilities",
                    "summary": "Libuser Library - Multiple Vulnerabilities",
                    "url": "https://www.exploit-db.com/exploits/37706",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 44633",
                    "author": "Metasploit",
                    "first_seen": "2018-05-16",
                    "confidence": "High",
                    "title": "Libuser - 'roothelper' Local Privilege Escalation (Metasploit)",
                    "summary": "Libuser - 'roothelper' Local Privilege Escalation (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/44633",
                    "verification": "verified",
                    "verified": true
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/37706",
                "https://www.exploit-db.com/exploits/44633"
            ],
            "timeline": [
                {
                    "at": "2026-08-25T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2026-08-26",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2015-2951",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2018-0114 CVE-2019-20933 CVE-2020-28042 CVE-2020-28637 C",
            "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
            "updated_at": "2026-09-09T04:48:12Z",
            "published_at": "2026-09-09T04:48:12Z",
            "cvss": 9.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 65,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2020-28042 CVE-2020-28637 CVE-2022-21449",
                    "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                        "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-10T07:59:46",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299"
                },
                {
                    "title": "Exploit for jwt_tool CVE-2015-2951 CVE-2016-10555 CVE-2020-28042 CVE-2020-28637 CVE-2022-21449",
                    "summary": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "what_happened": "JWT Tool for Testing, Tweaking and Cracking JSON Web Tokens. Toolkit includes features such as validating token, testing for RS/HS256 key mismatch vulnerability, identifying weak keys, and forging new token header and payload values",
                    "cvss": 7.5,
                    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                    "attack_vector": "Network",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                        "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-10T07:59:46",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299",
                "https://kitploit.com/en/tools/github/ticarpi/jwt_tool/"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T04:48:12Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A5268517342174105299"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2015-1805",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for cve-2017-2636-el CVE-2017-2636",
            "summary": "n_hdlc module blacklist role mitigates CVE-2017-2636 in RHEL 6 and 7 kernel.",
            "updated_at": "2026-08-26T04:09:44Z",
            "published_at": "2026-08-26T04:09:44Z",
            "cvss": 7,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 65,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "Unknown",
            "what_happened": "n_hdlc module blacklist role mitigates CVE-2017-2636 in RHEL 6 and 7 kernel.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for cve-2017-2636-el CVE-2017-2636",
                    "summary": "n_hdlc module blacklist role mitigates CVE-2017-2636 in RHEL 6 and 7 kernel.",
                    "what_happened": "n_hdlc module blacklist role mitigates CVE-2017-2636 in RHEL 6 and 7 kernel.",
                    "cvss": 7,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXZORIN-CVE-2017-2636-EL",
                        "https://kitploit.com/hi/tools/github/alexzorin/cve-2017-2636-el/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-26T06:09:44",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXZORIN-CVE-2017-2636-EL"
                },
                {
                    "title": "Exploit for cve-2017-2636-el CVE-2017-2636",
                    "summary": "n_hdlc module blacklist role mitigates CVE-2017-2636 in RHEL 6 and 7 kernel.",
                    "what_happened": "n_hdlc module blacklist role mitigates CVE-2017-2636 in RHEL 6 and 7 kernel.",
                    "cvss": 7,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "Low",
                    "complexity": "High",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXZORIN-CVE-2017-2636-EL",
                        "https://kitploit.com/hi/tools/github/alexzorin/cve-2017-2636-el/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-08-26T06:09:44",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/alexzorin/cve-2017-2636-el/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXZORIN-CVE-2017-2636-EL",
                "https://kitploit.com/hi/tools/github/alexzorin/cve-2017-2636-el/"
            ],
            "timeline": [
                {
                    "at": "2026-08-26T04:09:44Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ALEXZORIN-CVE-2017-2636-EL"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2014-9222",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for misfortune-cookie CVE-2014-9222",
            "summary": "Stack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.",
            "updated_at": "2026-09-07T17:47:48Z",
            "published_at": "2026-09-07T17:47:48Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 132,
            "kev": false,
            "attack_vector": "Network",
            "authentication": "Unknown",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Stack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for misfortune-cookie CVE-2014-9222",
                    "summary": "Stack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.",
                    "what_happened": "Stack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=FC88F5FE-B4FC-50D7-BADB-82E69F300083",
                        "https://github.com/luel-4013/misfortune-cookie"
                    ],
                    "repository": "Sploitus",
                    "author": "luel-4013",
                    "first_seen": "2026-09-07T19:47:48",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=FC88F5FE-B4FC-50D7-BADB-82E69F300083"
                },
                {
                    "repository": "PoC-in-GitHub · luel-4013/misfortune-cookie",
                    "author": "luel-4013",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This interactive suite targets CVE-2014-9222 (Misfortune Cookie) in legacy RomPager web servers, alongside modular testing for CVE-2017-17215 (Huawei HG532 RCE), CVE-2018-14847 (MikroTik WinBox credential leak), and the CVE-2021-27101 / CVE-2021-27102 exploit chain (Accellion FTA).",
                    "summary": "This interactive suite targets CVE-2014-9222 (Misfortune Cookie) in legacy RomPager web servers, alongside modular testing for CVE-2017-17215 (Huawei HG532 RCE), CVE-2018-14847 (MikroTik WinBox credential leak), and the CVE-2021-27101 / CVE-2021-27102 exploit chain (Accellion FTA).",
                    "url": "https://github.com/luel-4013/misfortune-cookie"
                },
                {
                    "repository": "PoC-in-GitHub · donfanning/MIPS-CVE-2014-9222",
                    "author": "donfanning",
                    "first_seen": "2019-08-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Lets have fun by digging into a Zyxel router firmware and MIPS Arch",
                    "summary": "Lets have fun by digging into a Zyxel router firmware and MIPS Arch",
                    "url": "https://github.com/donfanning/MIPS-CVE-2014-9222"
                },
                {
                    "repository": "PoC-in-GitHub · mercul1ninna/MIPS-CVE-2014-9222",
                    "author": "mercul1ninna",
                    "first_seen": "2022-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Lets have fun by digging into a Zyxel router firmware and MIPS Arch",
                    "summary": "Lets have fun by digging into a Zyxel router firmware and MIPS Arch",
                    "url": "https://github.com/mercul1ninna/MIPS-CVE-2014-9222"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=FC88F5FE-B4FC-50D7-BADB-82E69F300083",
                "https://github.com/luel-4013/misfortune-cookie",
                "https://github.com/donfanning/MIPS-CVE-2014-9222",
                "https://github.com/mercul1ninna/MIPS-CVE-2014-9222"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T17:47:48Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=FC88F5FE-B4FC-50D7-BADB-82E69F300083"
                }
            ],
            "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
            "id": "CVE-2014-8141",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
            "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
            "updated_at": "2026-09-04T19:43:05Z",
            "published_at": "2026-09-04T19:43:05Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 47,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
                    "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                        "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T21:43:05",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK"
                },
                {
                    "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
                    "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                        "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T21:43:05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T19:43:05Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2014-8140",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
            "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
            "updated_at": "2026-09-04T19:43:05Z",
            "published_at": "2026-09-04T19:43:05Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 47,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
                    "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                        "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T21:43:05",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK"
                },
                {
                    "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
                    "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                        "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T21:43:05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T19:43:05Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2014-8139",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
            "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
            "updated_at": "2026-09-04T19:43:05Z",
            "published_at": "2026-09-04T19:43:05Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 47,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
                    "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                        "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T21:43:05",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK"
                },
                {
                    "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
                    "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                        "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T21:43:05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T19:43:05Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2014-6271",
            "vendor": "GNU",
            "product": "Bourne-Again Shell (Bash)",
            "title": "GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability",
            "summary": "GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.",
            "updated_at": "2026-08-31T05:37:25Z",
            "published_at": "2026-08-31T05:37:25Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 2490,
            "kev": true,
            "attack_vector": "Network",
            "authentication": "Unknown",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 38849",
                    "author": "Metasploit",
                    "first_seen": "2015-12-02",
                    "confidence": "High",
                    "title": "Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)",
                    "summary": "Advantech Switch - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/38849",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 34777",
                    "author": "Shaun Colley",
                    "first_seen": "2014-09-25",
                    "confidence": "High",
                    "title": "GNU Bash - Environment Variable Command Injection (Metasploit)",
                    "summary": "GNU Bash - Environment Variable Command Injection (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/34777",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 39918",
                    "author": "Metasploit",
                    "first_seen": "2016-06-10",
                    "confidence": "High",
                    "title": "IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)",
                    "summary": "IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/39918",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 34895",
                    "author": "Fady Mohammed Osman",
                    "first_seen": "2014-10-06",
                    "confidence": "High",
                    "title": "Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)",
                    "summary": "Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/34895",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 34839",
                    "author": "Claudio Viviani",
                    "first_seen": "2014-10-01",
                    "confidence": "High",
                    "title": "IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection",
                    "summary": "IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection",
                    "url": "https://www.exploit-db.com/exploits/34839",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 36503",
                    "author": "Patrick Pellegrino",
                    "first_seen": "2015-03-26",
                    "confidence": "High",
                    "title": "QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)",
                    "summary": "QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/36503",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 36504",
                    "author": "Patrick Pellegrino",
                    "first_seen": "2015-03-26",
                    "confidence": "High",
                    "title": "QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)",
                    "summary": "QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/36504",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 40619",
                    "author": "Hacker Fantastic",
                    "first_seen": "2016-10-21",
                    "confidence": "High",
                    "title": "TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command Injection",
                    "summary": "TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command Injection",
                    "url": "https://www.exploit-db.com/exploits/40619",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 40938",
                    "author": "Hacker Fantastic",
                    "first_seen": "2016-12-18",
                    "confidence": "High",
                    "title": "RedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command Injection",
                    "summary": "RedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command Injection",
                    "url": "https://www.exploit-db.com/exploits/40938",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 34900",
                    "author": "Federico Galatolo",
                    "first_seen": "2014-10-06",
                    "confidence": "High",
                    "title": "Apache mod_cgi - 'Shellshock' Remote Command Injection",
                    "summary": "Apache mod_cgi - 'Shellshock' Remote Command Injection",
                    "url": "https://www.exploit-db.com/exploits/34900",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 34766",
                    "author": "Prakhar Prasad & Subho Halder",
                    "first_seen": "2014-09-25",
                    "confidence": "High",
                    "title": "Bash - 'Shellshock' Environment Variables Command Injection",
                    "summary": "Bash - 'Shellshock' Environment Variables Command Injection",
                    "url": "https://www.exploit-db.com/exploits/34766",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 35115",
                    "author": "Metasploit",
                    "first_seen": "2014-10-29",
                    "confidence": "High",
                    "title": "CUPS Filter - Bash Environment Variable Code Injection (Metasploit)",
                    "summary": "CUPS Filter - Bash Environment Variable Code Injection (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/35115",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 34765",
                    "author": "Stephane Chazelas",
                    "first_seen": "2014-09-25",
                    "confidence": "High",
                    "title": "GNU Bash - 'Shellshock' Environment Variable Command Injection",
                    "summary": "GNU Bash - 'Shellshock' Environment Variable Command Injection",
                    "url": "https://www.exploit-db.com/exploits/34765",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 34860",
                    "author": "@0x00string",
                    "first_seen": "2014-10-02",
                    "confidence": "High",
                    "title": "GNU bash 4.3.11 - Environment Variable dhclient",
                    "summary": "GNU bash 4.3.11 - Environment Variable dhclient",
                    "url": "https://www.exploit-db.com/exploits/34860",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 34879",
                    "author": "hobbily plunt",
                    "first_seen": "2014-10-04",
                    "confidence": "High",
                    "title": "OpenVPN 2.2.29 - 'Shellshock' Remote Command Injection",
                    "summary": "OpenVPN 2.2.29 - 'Shellshock' Remote Command Injection",
                    "url": "https://www.exploit-db.com/exploits/34879",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 34896",
                    "author": "Phil Blank",
                    "first_seen": "2014-10-06",
                    "confidence": "High",
                    "title": "Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection",
                    "summary": "Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection",
                    "url": "https://www.exploit-db.com/exploits/34896",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 34862",
                    "author": "Metasploit",
                    "first_seen": "2014-10-02",
                    "confidence": "High",
                    "title": "Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)",
                    "summary": "Pure-FTPd - External Authentication Bash Environment Variable Code Injection (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/34862",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 42938",
                    "author": "Metasploit",
                    "first_seen": "2017-10-02",
                    "confidence": "High",
                    "title": "Qmail SMTP - Bash Environment Variable Injection (Metasploit)",
                    "summary": "Qmail SMTP - Bash Environment Variable Injection (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/42938",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 37816",
                    "author": "Bernhard Mueller",
                    "first_seen": "2015-08-18",
                    "confidence": "High",
                    "title": "Cisco Unified Communications Manager - Multiple Vulnerabilities",
                    "summary": "Cisco Unified Communications Manager - Multiple Vulnerabilities",
                    "url": "https://www.exploit-db.com/exploits/37816",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 36609",
                    "author": "Roberto Suggi Liverani",
                    "first_seen": "2015-04-02",
                    "confidence": "High",
                    "title": "Kemp Load Master 7.1.16 - Multiple Vulnerabilities",
                    "summary": "Kemp Load Master 7.1.16 - Multiple Vulnerabilities",
                    "url": "https://www.exploit-db.com/exploits/36609",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 35146",
                    "author": "Ryan King (Starfall)",
                    "first_seen": "2014-11-03",
                    "confidence": "High",
                    "title": "PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection",
                    "summary": "PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection",
                    "url": "https://www.exploit-db.com/exploits/35146",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for NetworkAlarm CVE-2014-6271",
                    "summary": "NetworkAlarm CLI tool monitors local network traffic for nmap, Nikto, Shellshock, and cleartext credential attacks.",
                    "what_happened": "NetworkAlarm CLI tool monitors local network traffic for nmap, Nikto, Shellshock, and cleartext credential attacks.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YOJIWATANABE-NETWORKALARM",
                        "https://kitploit.com/ru/tools/github/yojiwatanabe/networkalarm/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-08-31T07:37:25",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YOJIWATANABE-NETWORKALARM"
                },
                {
                    "title": "Exploit for NetworkAlarm CVE-2014-6271",
                    "summary": "NetworkAlarm CLI tool monitors local network traffic for nmap, Nikto, Shellshock, and cleartext credential attacks.",
                    "what_happened": "NetworkAlarm CLI tool monitors local network traffic for nmap, Nikto, Shellshock, and cleartext credential attacks.",
                    "cvss": 10,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YOJIWATANABE-NETWORKALARM",
                        "https://kitploit.com/ru/tools/github/yojiwatanabe/networkalarm/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-31T07:37:25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/yojiwatanabe/networkalarm/"
                },
                {
                    "repository": "PoC-in-GitHub · dlitz/bash-cve-2014-6271-fixes",
                    "author": "dlitz",
                    "first_seen": "2014-09-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Collected fixes for bash CVE-2014-6271",
                    "summary": "Collected fixes for bash CVE-2014-6271",
                    "url": "https://github.com/dlitz/bash-cve-2014-6271-fixes"
                },
                {
                    "repository": "PoC-in-GitHub · npm/ansible-bashpocalypse",
                    "author": "npm",
                    "first_seen": "2014-09-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "Patch for CVE-2014-6271",
                    "summary": "Patch for CVE-2014-6271",
                    "url": "https://github.com/npm/ansible-bashpocalypse"
                },
                {
                    "repository": "PoC-in-GitHub · ryancnelson/patched-bash-4.3",
                    "author": "ryancnelson",
                    "first_seen": "2014-09-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "patched-bash-4.3 for CVE-2014-6271",
                    "summary": "patched-bash-4.3 for CVE-2014-6271",
                    "url": "https://github.com/ryancnelson/patched-bash-4.3"
                },
                {
                    "repository": "PoC-in-GitHub · jblaine/cookbook-bash-CVE-2014-6271",
                    "author": "jblaine",
                    "first_seen": "2014-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Chef cookbook that will fail if bash vulnerability found per CVE-2014-6271",
                    "summary": "Chef cookbook that will fail if bash vulnerability found per CVE-2014-6271",
                    "url": "https://github.com/jblaine/cookbook-bash-CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · rrreeeyyy/cve-2014-6271-spec",
                    "author": "rrreeeyyy",
                    "first_seen": "2014-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/rrreeeyyy/cve-2014-6271-spec"
                },
                {
                    "repository": "PoC-in-GitHub · scottjpack/shellshock_scanner",
                    "author": "scottjpack",
                    "first_seen": "2014-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 46,
                    "title": "Python Scanner for \"ShellShock\" (CVE-2014-6271)",
                    "summary": "Python Scanner for \"ShellShock\" (CVE-2014-6271)",
                    "url": "https://github.com/scottjpack/shellshock_scanner"
                },
                {
                    "repository": "PoC-in-GitHub · Anklebiter87/Cgi-bin_bash_Reverse",
                    "author": "Anklebiter87",
                    "first_seen": "2014-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Written fro CVE-2014-6271",
                    "summary": "Written fro CVE-2014-6271",
                    "url": "https://github.com/Anklebiter87/Cgi-bin_bash_Reverse"
                },
                {
                    "repository": "PoC-in-GitHub · justzx2011/bash-up",
                    "author": "justzx2011",
                    "first_seen": "2014-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "a auto script to fix CVE-2014-6271 bash vulnerability",
                    "summary": "a auto script to fix CVE-2014-6271 bash vulnerability",
                    "url": "https://github.com/justzx2011/bash-up"
                },
                {
                    "repository": "PoC-in-GitHub · mattclegg/CVE-2014-6271",
                    "author": "mattclegg",
                    "first_seen": "2014-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/mattclegg/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · ilismal/Nessus_CVE-2014-6271_check",
                    "author": "ilismal",
                    "first_seen": "2014-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Quick and dirty nessus .audit file to check is bash is vulnerable to CVE-2014-6271",
                    "summary": "Quick and dirty nessus .audit file to check is bash is vulnerable to CVE-2014-6271",
                    "url": "https://github.com/ilismal/Nessus_CVE-2014-6271_check"
                },
                {
                    "repository": "PoC-in-GitHub · RainMak3r/Rainstorm",
                    "author": "RainMak3r",
                    "first_seen": "2014-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2014-6271 RCE tool",
                    "summary": "CVE-2014-6271 RCE tool",
                    "url": "https://github.com/RainMak3r/Rainstorm"
                },
                {
                    "repository": "PoC-in-GitHub · gabemarshall/shocknaww",
                    "author": "gabemarshall",
                    "first_seen": "2014-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Simple script to check for CVE-2014-6271",
                    "summary": "Simple script to check for CVE-2014-6271",
                    "url": "https://github.com/gabemarshall/shocknaww"
                },
                {
                    "repository": "PoC-in-GitHub · woltage/CVE-2014-6271",
                    "author": "woltage",
                    "first_seen": "2014-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/woltage/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · ariarijp/vagrant-shellshock",
                    "author": "ariarijp",
                    "first_seen": "2014-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271の検証用Vagrantfileです",
                    "summary": "CVE-2014-6271の検証用Vagrantfileです",
                    "url": "https://github.com/ariarijp/vagrant-shellshock"
                },
                {
                    "repository": "PoC-in-GitHub · themson/shellshock",
                    "author": "themson",
                    "first_seen": "2014-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "scripts associate with bourne shell EVN function parsing vulnerability CVE-2014-6271",
                    "summary": "scripts associate with bourne shell EVN function parsing vulnerability CVE-2014-6271",
                    "url": "https://github.com/themson/shellshock"
                },
                {
                    "repository": "PoC-in-GitHub · securusglobal/BadBash",
                    "author": "securusglobal",
                    "first_seen": "2014-09-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "CVE-2014-6271 (ShellShock) RCE PoC tool",
                    "summary": "CVE-2014-6271 (ShellShock) RCE PoC tool",
                    "url": "https://github.com/securusglobal/BadBash"
                },
                {
                    "repository": "PoC-in-GitHub · villadora/CVE-2014-6271",
                    "author": "villadora",
                    "first_seen": "2014-09-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "scaner for cve-2014-6271",
                    "summary": "scaner for cve-2014-6271",
                    "url": "https://github.com/villadora/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · APSL/salt-shellshock",
                    "author": "APSL",
                    "first_seen": "2014-09-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Salt recipe for  shellshock (CVE-2014-6271)",
                    "summary": "Salt recipe for  shellshock (CVE-2014-6271)",
                    "url": "https://github.com/APSL/salt-shellshock"
                },
                {
                    "repository": "PoC-in-GitHub · teedeedubya/bash-fix-exploit",
                    "author": "teedeedubya",
                    "first_seen": "2014-09-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Ansible role to check the CVE-2014-6271 vulnerability",
                    "summary": "Ansible role to check the CVE-2014-6271 vulnerability",
                    "url": "https://github.com/teedeedubya/bash-fix-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · internero/debian-lenny-bash_3.2.52-cve-2014-6271",
                    "author": "internero",
                    "first_seen": "2014-09-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Debian Lenny Bash packages with cve-2014-6271 patches (i386 and amd64)",
                    "summary": "Debian Lenny Bash packages with cve-2014-6271 patches (i386 and amd64)",
                    "url": "https://github.com/internero/debian-lenny-bash_3.2.52-cve-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · u20024804/bash-3.2-fixed-CVE-2014-6271",
                    "author": "u20024804",
                    "first_seen": "2014-09-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/u20024804/bash-3.2-fixed-CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · u20024804/bash-4.2-fixed-CVE-2014-6271",
                    "author": "u20024804",
                    "first_seen": "2014-09-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/u20024804/bash-4.2-fixed-CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · u20024804/bash-4.3-fixed-CVE-2014-6271",
                    "author": "u20024804",
                    "first_seen": "2014-09-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/u20024804/bash-4.3-fixed-CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · francisck/shellshock-cgi",
                    "author": "francisck",
                    "first_seen": "2014-09-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 12,
                    "title": "A python script to enumerate CGI scripts vulnerable to CVE-2014-6271 on one specific server",
                    "summary": "A python script to enumerate CGI scripts vulnerable to CVE-2014-6271 on one specific server",
                    "url": "https://github.com/francisck/shellshock-cgi"
                },
                {
                    "repository": "PoC-in-GitHub · proclnas/ShellShock-CGI-Scan",
                    "author": "proclnas",
                    "first_seen": "2014-09-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug)",
                    "summary": "A script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug)",
                    "url": "https://github.com/proclnas/ShellShock-CGI-Scan"
                },
                {
                    "repository": "PoC-in-GitHub · sch3m4/RIS",
                    "author": "sch3m4",
                    "first_seen": "2014-09-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2014-6271 Remote Interactive Shell - PoC Exploit",
                    "summary": "CVE-2014-6271 Remote Interactive Shell - PoC Exploit",
                    "url": "https://github.com/sch3m4/RIS"
                },
                {
                    "repository": "PoC-in-GitHub · ryeyao/CVE-2014-6271_Test",
                    "author": "ryeyao",
                    "first_seen": "2014-09-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/ryeyao/CVE-2014-6271_Test"
                },
                {
                    "repository": "PoC-in-GitHub · cj1324/CGIShell",
                    "author": "cj1324",
                    "first_seen": "2014-09-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 13,
                    "title": "shellshock CVE-2014-6271 CGI Exploit,  Use like Openssh via CGI",
                    "summary": "shellshock CVE-2014-6271 CGI Exploit,  Use like Openssh via CGI",
                    "url": "https://github.com/cj1324/CGIShell"
                },
                {
                    "repository": "PoC-in-GitHub · renanvicente/puppet-shellshock",
                    "author": "renanvicente",
                    "first_seen": "2014-09-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This module determine the vulnerability of a bash binary to the shellshock exploits (CVE-2014-6271 or CVE-2014-7169) and then patch that where possible",
                    "summary": "This module determine the vulnerability of a bash binary to the shellshock exploits (CVE-2014-6271 or CVE-2014-7169) and then patch that where possible",
                    "url": "https://github.com/renanvicente/puppet-shellshock"
                },
                {
                    "repository": "PoC-in-GitHub · indiandragon/Shellshock-Vulnerability-Scan",
                    "author": "indiandragon",
                    "first_seen": "2014-10-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 11,
                    "title": "Android app to scan for bash Vulnerability - CVE-2014-6271 also known as Shellshock",
                    "summary": "Android app to scan for bash Vulnerability - CVE-2014-6271 also known as Shellshock",
                    "url": "https://github.com/indiandragon/Shellshock-Vulnerability-Scan"
                },
                {
                    "repository": "PoC-in-GitHub · ramnes/pyshellshock",
                    "author": "ramnes",
                    "first_seen": "2014-11-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": ":scream: Python library and utility for CVE-2014-6271 (aka. \"shellshock\")",
                    "summary": ":scream: Python library and utility for CVE-2014-6271 (aka. \"shellshock\")",
                    "url": "https://github.com/ramnes/pyshellshock"
                },
                {
                    "repository": "PoC-in-GitHub · akiraaisha/shellshocker-python",
                    "author": "akiraaisha",
                    "first_seen": "2015-02-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "This is a Python Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271",
                    "summary": "This is a Python Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271",
                    "url": "https://github.com/akiraaisha/shellshocker-python"
                },
                {
                    "repository": "PoC-in-GitHub · 352926/shellshock_crawler",
                    "author": "352926",
                    "first_seen": "2015-03-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Using google to scan sites for \"ShellShock\" (CVE-2014-6271)",
                    "summary": "Using google to scan sites for \"ShellShock\" (CVE-2014-6271)",
                    "url": "https://github.com/352926/shellshock_crawler"
                },
                {
                    "repository": "PoC-in-GitHub · kelleykong/cve-2014-6271-mengjia-kong",
                    "author": "kelleykong",
                    "first_seen": "2015-06-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "system reading course",
                    "summary": "system reading course",
                    "url": "https://github.com/kelleykong/cve-2014-6271-mengjia-kong"
                },
                {
                    "repository": "PoC-in-GitHub · huanlu/cve-2014-6271-huan-lu",
                    "author": "huanlu",
                    "first_seen": "2015-06-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "reading course",
                    "summary": "reading course",
                    "url": "https://github.com/huanlu/cve-2014-6271-huan-lu"
                },
                {
                    "repository": "PoC-in-GitHub · sunnyjiang/shellshocker-android",
                    "author": "sunnyjiang",
                    "first_seen": "2015-06-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This is an Android Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271",
                    "summary": "This is an Android Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271",
                    "url": "https://github.com/sunnyjiang/shellshocker-android"
                },
                {
                    "repository": "PoC-in-GitHub · P0cL4bs/ShellShock-CGI-Scan",
                    "author": "P0cL4bs",
                    "first_seen": "2015-06-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 6,
                    "title": "A script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug).",
                    "summary": "A script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug).",
                    "url": "https://github.com/P0cL4bs/ShellShock-CGI-Scan"
                },
                {
                    "repository": "PoC-in-GitHub · hmlio/vaas-cve-2014-6271",
                    "author": "hmlio",
                    "first_seen": "2015-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 22,
                    "title": "Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock",
                    "summary": "Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock",
                    "url": "https://github.com/hmlio/vaas-cve-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · opsxcq/exploit-CVE-2014-6271",
                    "author": "opsxcq",
                    "first_seen": "2016-12-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 232,
                    "title": "Shellshock exploit + vulnerable environment",
                    "summary": "Shellshock exploit + vulnerable environment",
                    "url": "https://github.com/opsxcq/exploit-CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · Pilou-Pilou/docker_CVE-2014-6271.",
                    "author": "Pilou-Pilou",
                    "first_seen": "2017-01-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/Pilou-Pilou/docker_CVE-2014-6271."
                },
                {
                    "repository": "PoC-in-GitHub · zalalov/CVE-2014-6271",
                    "author": "zalalov",
                    "first_seen": "2017-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Shellshock POC | CVE-2014-6271 | cgi-bin reverse shell",
                    "summary": "Shellshock POC | CVE-2014-6271 | cgi-bin reverse shell",
                    "url": "https://github.com/zalalov/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · heikipikker/shellshock-shell",
                    "author": "heikipikker",
                    "first_seen": "2017-10-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A simple python shell-like exploit for the Shellschok CVE-2014-6271 bug.",
                    "summary": "A simple python shell-like exploit for the Shellschok CVE-2014-6271 bug.",
                    "url": "https://github.com/heikipikker/shellshock-shell"
                },
                {
                    "repository": "PoC-in-GitHub · 0x00-0x00/CVE-2014-6271",
                    "author": "0x00-0x00",
                    "first_seen": "2017-11-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Shellshock exploitation script that is able to upload and RCE using any vector due to its versatility.",
                    "summary": "Shellshock exploitation script that is able to upload and RCE using any vector due to its versatility.",
                    "url": "https://github.com/0x00-0x00/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · kowshik-sundararajan/CVE-2014-6271",
                    "author": "kowshik-sundararajan",
                    "first_seen": "2018-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CS4238 Computer Security Practices",
                    "summary": "CS4238 Computer Security Practices",
                    "url": "https://github.com/kowshik-sundararajan/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · w4fz5uck5/ShockZaum-CVE-2014-6271",
                    "author": "w4fz5uck5",
                    "first_seen": "2018-06-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Shellshock vulnerability attacker",
                    "summary": "Shellshock vulnerability attacker",
                    "url": "https://github.com/w4fz5uck5/ShockZaum-CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · Aruthw/CVE-2014-6271",
                    "author": "Aruthw",
                    "first_seen": "2018-06-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/Aruthw/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · cved-sources/cve-2014-6271",
                    "author": "cved-sources",
                    "first_seen": "2019-01-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "cve-2014-6271",
                    "summary": "cve-2014-6271",
                    "url": "https://github.com/cved-sources/cve-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · shawntns/exploit-CVE-2014-6271",
                    "author": "shawntns",
                    "first_seen": "2019-04-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/shawntns/exploit-CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · Sindadziy/cve-2014-6271",
                    "author": "Sindadziy",
                    "first_seen": "2019-11-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/Sindadziy/cve-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · wenyu1999/bash-shellshock",
                    "author": "wenyu1999",
                    "first_seen": "2019-11-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "cve-2014-6271",
                    "summary": "cve-2014-6271",
                    "url": "https://github.com/wenyu1999/bash-shellshock"
                },
                {
                    "repository": "PoC-in-GitHub · Sindayifu/CVE-2019-14287-CVE-2014-6271",
                    "author": "Sindayifu",
                    "first_seen": "2019-11-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/Sindayifu/CVE-2019-14287-CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · Any3ite/CVE-2014-6271",
                    "author": "Any3ite",
                    "first_seen": "2020-01-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/Any3ite/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · somhm-solutions/Shell-Shock",
                    "author": "somhm-solutions",
                    "first_seen": "2020-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "*CVE-2014-6271* Unix Arbitrary Code Execution Exploit commonly know as Shell Shock. Examples, Docs, Incident Response and Vulnerability/Risk Assessment, and Additional Resources may be dumped here. Enjoy :)  --- somhmxxghoul  ---",
                    "summary": "*CVE-2014-6271* Unix Arbitrary Code Execution Exploit commonly know as Shell Shock. Examples, Docs, Incident Response and Vulnerability/Risk Assessment, and Additional Resources may be dumped here. Enjoy :)  --- somhmxxghoul  ---",
                    "url": "https://github.com/somhm-solutions/Shell-Shock"
                },
                {
                    "repository": "PoC-in-GitHub · rashmikadileeshara/CVE-2014-6271-Shellshock-",
                    "author": "rashmikadileeshara",
                    "first_seen": "2020-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is an individual assignment for secure network programming",
                    "summary": "This is an individual assignment for secure network programming",
                    "url": "https://github.com/rashmikadileeshara/CVE-2014-6271-Shellshock-"
                },
                {
                    "repository": "PoC-in-GitHub · Dilith006/CVE-2014-6271",
                    "author": "Dilith006",
                    "first_seen": "2020-05-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/Dilith006/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · cyberharsh/Shellbash-CVE-2014-6271",
                    "author": "cyberharsh",
                    "first_seen": "2020-06-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/cyberharsh/Shellbash-CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · MuirlandOracle/CVE-2014-6271-IPFire",
                    "author": "MuirlandOracle",
                    "first_seen": "2020-11-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/MuirlandOracle/CVE-2014-6271-IPFire"
                },
                {
                    "repository": "PoC-in-GitHub · mochizuki875/CVE-2014-6271-Apache-Debian",
                    "author": "mochizuki875",
                    "first_seen": "2021-07-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "This Repo is PoC environment of CVE-2014-6271(https://nvd.nist.gov/vuln/detail/cve-2014-6271).",
                    "summary": "This Repo is PoC environment of CVE-2014-6271(https://nvd.nist.gov/vuln/detail/cve-2014-6271).",
                    "url": "https://github.com/mochizuki875/CVE-2014-6271-Apache-Debian"
                },
                {
                    "repository": "PoC-in-GitHub · b4keSn4ke/CVE-2014-6271",
                    "author": "b4keSn4ke",
                    "first_seen": "2021-07-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 15,
                    "title": "Shellshock exploit aka CVE-2014-6271",
                    "summary": "Shellshock exploit aka CVE-2014-6271",
                    "url": "https://github.com/b4keSn4ke/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · akr3ch/CVE-2014-6271",
                    "author": "akr3ch",
                    "first_seen": "2022-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "ShellShock interactive-shell exploit",
                    "summary": "ShellShock interactive-shell exploit",
                    "url": "https://github.com/akr3ch/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · Gurguii/cgi-bin-shellshock",
                    "author": "Gurguii",
                    "first_seen": "2022-06-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "[Python/Shell] - Tested in HackTheBox - Shocker (Easy) CVE-2014-6271",
                    "summary": "[Python/Shell] - Tested in HackTheBox - Shocker (Easy) CVE-2014-6271",
                    "url": "https://github.com/Gurguii/cgi-bin-shellshock"
                },
                {
                    "repository": "PoC-in-GitHub · anujbhan/shellshock-victim-host",
                    "author": "anujbhan",
                    "first_seen": "2022-06-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A docker container vulnerable to Shellshock - CVE-2014-6271",
                    "summary": "A docker container vulnerable to Shellshock - CVE-2014-6271",
                    "url": "https://github.com/anujbhan/shellshock-victim-host"
                },
                {
                    "repository": "PoC-in-GitHub · FilipStudeny/-CVE-2014-6271-Shellshock-Remote-Command-Injection-",
                    "author": "FilipStudeny",
                    "first_seen": "2022-09-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing",
                    "summary": "[CVE-2014-6271] Apache Shellshock Remote Command Injection tool for quick reverse shell and file browsing",
                    "url": "https://github.com/FilipStudeny/-CVE-2014-6271-Shellshock-Remote-Command-Injection-"
                },
                {
                    "repository": "PoC-in-GitHub · mritunjay-k/CVE-2014-6271",
                    "author": "mritunjay-k",
                    "first_seen": "2023-03-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/mritunjay-k/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · Brandaoo/CVE-2014-6271",
                    "author": "Brandaoo",
                    "first_seen": "2023-03-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/Brandaoo/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · J0hnTh3Kn1ght/CVE-2014-6271",
                    "author": "J0hnTh3Kn1ght",
                    "first_seen": "2023-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Exploitation of \"Shellshock\" Vulnerability. Remote code execution in Apache with mod_cgi",
                    "summary": "Exploitation of \"Shellshock\" Vulnerability. Remote code execution in Apache with mod_cgi",
                    "url": "https://github.com/J0hnTh3Kn1ght/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · hanmin0512/CVE-2014-6271_pwnable",
                    "author": "hanmin0512",
                    "first_seen": "2023-08-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/hanmin0512/CVE-2014-6271_pwnable"
                },
                {
                    "repository": "PoC-in-GitHub · 0xN7y/CVE-2014-6271",
                    "author": "0xN7y",
                    "first_seen": "2023-10-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "EXPLOIT FOR CVE-2014-6271",
                    "summary": "EXPLOIT FOR CVE-2014-6271",
                    "url": "https://github.com/0xN7y/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · AlissonFaoli/Shellshock",
                    "author": "AlissonFaoli",
                    "first_seen": "2024-02-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Shellshock exploit (CVE-2014-6271)",
                    "summary": "Shellshock exploit (CVE-2014-6271)",
                    "url": "https://github.com/AlissonFaoli/Shellshock"
                },
                {
                    "repository": "PoC-in-GitHub · ajansha/shellshock",
                    "author": "ajansha",
                    "first_seen": "2024-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Shelly is a lightweight and efficient vulnerability scanner designed to identify and mitigate Shellshock (CVE-2014-6271 & CVE-2014-7169) vulnerabilities in Bash environments.",
                    "summary": "Shelly is a lightweight and efficient vulnerability scanner designed to identify and mitigate Shellshock (CVE-2014-6271 & CVE-2014-7169) vulnerabilities in Bash environments.",
                    "url": "https://github.com/ajansha/shellshock"
                },
                {
                    "repository": "PoC-in-GitHub · K3ysTr0K3R/CVE-2014-6271-EXPLOIT",
                    "author": "K3ysTr0K3R",
                    "first_seen": "2024-05-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "A PoC exploit for CVE-2014-6271 - Shellshock",
                    "summary": "A PoC exploit for CVE-2014-6271 - Shellshock",
                    "url": "https://github.com/K3ysTr0K3R/CVE-2014-6271-EXPLOIT"
                },
                {
                    "repository": "PoC-in-GitHub · TheRealCiscoo/shellshock-poc",
                    "author": "TheRealCiscoo",
                    "first_seen": "2024-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Prueba de concepto para abusar de la vulnerabilidad Shellshock (CVE-2014-6271).",
                    "summary": "Prueba de concepto para abusar de la vulnerabilidad Shellshock (CVE-2014-6271).",
                    "url": "https://github.com/TheRealCiscoo/shellshock-poc"
                },
                {
                    "repository": "PoC-in-GitHub · RadYio/CVE-2014-6271",
                    "author": "RadYio",
                    "first_seen": "2024-11-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Projet de présentation d'une CVE (ShellShock) avec pdf, démonstration technique et reproductible",
                    "summary": "Projet de présentation d'une CVE (ShellShock) avec pdf, démonstration technique et reproductible",
                    "url": "https://github.com/RadYio/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · YunchoHang/CVE-2014-6271-SHELLSHOCK",
                    "author": "YunchoHang",
                    "first_seen": "2025-02-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Automation script to exploit the Shellshock vulnerability.",
                    "summary": "Automation script to exploit the Shellshock vulnerability.",
                    "url": "https://github.com/YunchoHang/CVE-2014-6271-SHELLSHOCK"
                },
                {
                    "repository": "PoC-in-GitHub · moften/CVE-2014-6271",
                    "author": "moften",
                    "first_seen": "2025-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Shellshock Vulnerability Scanner",
                    "summary": "Shellshock Vulnerability Scanner",
                    "url": "https://github.com/moften/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · knightc0de/Shellshock_vuln_Exploit",
                    "author": "knightc0de",
                    "first_seen": "2025-06-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271(RCE) poc Exploit",
                    "summary": "CVE-2014-6271(RCE) poc Exploit",
                    "url": "https://github.com/knightc0de/Shellshock_vuln_Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · rsherstnev/CVE-2014-6271",
                    "author": "rsherstnev",
                    "first_seen": "2025-07-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is my implementation of shellshock exploit",
                    "summary": "This is my implementation of shellshock exploit",
                    "url": "https://github.com/rsherstnev/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · RAJMadhusankha/Shellshock-CVE-2014-6271-Exploitation-and-Analysis",
                    "author": "RAJMadhusankha",
                    "first_seen": "2025-08-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/RAJMadhusankha/Shellshock-CVE-2014-6271-Exploitation-and-Analysis"
                },
                {
                    "repository": "PoC-in-GitHub · DrHaitham/CVE-2014-6271-Shellshock-",
                    "author": "DrHaitham",
                    "first_seen": "2025-12-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells, countermeasures, and full command cheat-sheet.",
                    "summary": "A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells, countermeasures, and full command cheat-sheet.",
                    "url": "https://github.com/DrHaitham/CVE-2014-6271-Shellshock-"
                },
                {
                    "repository": "PoC-in-GitHub · mtaha-sec/bash-apocalypse",
                    "author": "mtaha-sec",
                    "first_seen": "2025-12-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite methodology + Docker lab. Built for security research & education. Offensive security portfolio project.",
                    "summary": "Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite methodology + Docker lab. Built for security research & education. Offensive security portfolio project.",
                    "url": "https://github.com/mtaha-sec/bash-apocalypse"
                },
                {
                    "repository": "PoC-in-GitHub · andres101c/Shellshock-CVE-2014-6271",
                    "author": "andres101c",
                    "first_seen": "2026-02-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/andres101c/Shellshock-CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · Industri4l-H3ll-Xpl0it3rs/CVE-2014-6271-Shellshock",
                    "author": "Industri4l-H3ll-Xpl0it3rs",
                    "first_seen": "2026-02-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 Exploit | by infrar3d",
                    "summary": "CVE-2014-6271 Exploit | by infrar3d",
                    "url": "https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2014-6271-Shellshock"
                },
                {
                    "repository": "PoC-in-GitHub · 0xBlackash/CVE-2014-6271",
                    "author": "0xBlackash",
                    "first_seen": "2026-03-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271",
                    "summary": "CVE-2014-6271",
                    "url": "https://github.com/0xBlackash/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · ambjlou/it355-lab4-enterprise-lan-security",
                    "author": "ambjlou",
                    "first_seen": "2026-04-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository contains a comprehensive security assessment of an enterprise LAN environment. The core focus of this project was the identification, exploitation, and remediation of the **Shellshock (CVE-2014-6271)** vulnerability within a Linux-based web server.",
                    "summary": "This repository contains a comprehensive security assessment of an enterprise LAN environment. The core focus of this project was the identification, exploitation, and remediation of the **Shellshock (CVE-2014-6271)** vulnerability within a Linux-based web server.",
                    "url": "https://github.com/ambjlou/it355-lab4-enterprise-lan-security"
                },
                {
                    "repository": "PoC-in-GitHub · kaleth4/-CVE-2014-6271",
                    "author": "kaleth4",
                    "first_seen": "2026-04-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/kaleth4/-CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · kaleth4/CVE-2014-6271",
                    "author": "kaleth4",
                    "first_seen": "2026-04-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2014-6271 repository",
                    "summary": "",
                    "url": "https://github.com/kaleth4/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · V3nG4mxV1p3r/Mobile-Drop-Device-SOC-Detection",
                    "author": "V3nG4mxV1p3r",
                    "first_seen": "2026-04-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "End-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock (CVE-2014-6271).",
                    "summary": "End-to-end simulation of detecting a root-less Android Drop Device (Casper) using Wazuh SIEM to capture Layer 7 attacks like Shellshock (CVE-2014-6271).",
                    "url": "https://github.com/V3nG4mxV1p3r/Mobile-Drop-Device-SOC-Detection"
                },
                {
                    "repository": "PoC-in-GitHub · im2sinister/CVE-2014-6271",
                    "author": "im2sinister",
                    "first_seen": "2026-04-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "its simple Shellshock exploit",
                    "summary": "its simple Shellshock exploit",
                    "url": "https://github.com/im2sinister/CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · HevenTafese/Penetration-Testing-Walkthrough-Hacksudo-Thor",
                    "author": "HevenTafese",
                    "first_seen": "2026-04-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash eval injection for full privilege escalation. Includes custom CSRF-aware brute force tooling and Metasploit RPC automation.",
                    "summary": "Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash eval injection for full privilege escalation. Includes custom CSRF-aware brute force tooling and Metasploit RPC automation.",
                    "url": "https://github.com/HevenTafese/Penetration-Testing-Walkthrough-Hacksudo-Thor"
                },
                {
                    "repository": "PoC-in-GitHub · FacundoMfernandez/pentesting-obioba",
                    "author": "FacundoMfernandez",
                    "first_seen": "2026-05-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Pentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico",
                    "summary": "Pentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico",
                    "url": "https://github.com/FacundoMfernandez/pentesting-obioba"
                },
                {
                    "repository": "PoC-in-GitHub · R3fr4kt/Shocker-TJNULL-OSCP-",
                    "author": "R3fr4kt",
                    "first_seen": "2026-06-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "\"A professional walkthrough of HTB: Shocker. Demonstrates remote directory fuzzing to discover CGI scripts, manual exploitation of the Shellshock vulnerability (CVE-2014-6271), and privilege escalation via misconfigured Sudo Perl permissions using GTFOBins vectors.\"",
                    "summary": "\"A professional walkthrough of HTB: Shocker. Demonstrates remote directory fuzzing to discover CGI scripts, manual exploitation of the Shellshock vulnerability (CVE-2014-6271), and privilege escalation via misconfigured Sudo Perl permissions using GTFOBins vectors.\"",
                    "url": "https://github.com/R3fr4kt/Shocker-TJNULL-OSCP-"
                },
                {
                    "repository": "PoC-in-GitHub · cyberexpert111/Blind-SSRF-to-Remote-Code-Execution-Shellshock-Professional-Bug-Bounty-Report",
                    "author": "cyberexpert111",
                    "first_seen": "2026-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This repository contains a professional bug bounty report demonstrating the successful exploitation of a Blind SSRF vulnerability that reached an internal CGI endpoint vulnerable to Shellshock (CVE-2014-6271). Remote command execution was confirmed using an out-of-band (OAST) DNS callback, showcasing the complete attack chain, technical analysis.",
                    "summary": "This repository contains a professional bug bounty report demonstrating the successful exploitation of a Blind SSRF vulnerability that reached an internal CGI endpoint vulnerable to Shellshock (CVE-2014-6271). Remote command execution was confirmed using an out-of-band (OAST) DNS callback, showcasing the complete attack chain, technical analysis.",
                    "url": "https://github.com/cyberexpert111/Blind-SSRF-to-Remote-Code-Execution-Shellshock-Professional-Bug-Bounty-Report"
                },
                {
                    "repository": "PoC-in-GitHub · caverm/Shellshock_CVE-2014-6271",
                    "author": "caverm",
                    "first_seen": "2026-07-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Shellshock",
                    "summary": "Shellshock",
                    "url": "https://github.com/caverm/Shellshock_CVE-2014-6271"
                },
                {
                    "repository": "PoC-in-GitHub · FREEGUY-6/dmz-security-monitoring-hardening",
                    "author": "FREEGUY-6",
                    "first_seen": "2026-08-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271",
                    "summary": "CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271",
                    "url": "https://github.com/FREEGUY-6/dmz-security-monitoring-hardening"
                },
                {
                    "repository": "PoC-in-GitHub · Vaibhav91one/shellshock-cve-lab",
                    "author": "Vaibhav91one",
                    "first_seen": "2026-08-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Shellshock CVE-2014-6271 vulnerable CGI lab",
                    "summary": "Shellshock CVE-2014-6271 vulnerable CGI lab",
                    "url": "https://github.com/Vaibhav91one/shellshock-cve-lab"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/38849",
                "https://www.exploit-db.com/exploits/34777",
                "https://www.exploit-db.com/exploits/39918",
                "https://www.exploit-db.com/exploits/34895",
                "https://www.exploit-db.com/exploits/34839",
                "https://www.exploit-db.com/exploits/36503",
                "https://www.exploit-db.com/exploits/36504",
                "https://www.exploit-db.com/exploits/40619",
                "https://www.exploit-db.com/exploits/40938",
                "https://www.exploit-db.com/exploits/34900",
                "https://www.exploit-db.com/exploits/34766",
                "https://www.exploit-db.com/exploits/35115",
                "https://www.exploit-db.com/exploits/34765",
                "https://www.exploit-db.com/exploits/34860",
                "https://www.exploit-db.com/exploits/34879",
                "https://www.exploit-db.com/exploits/34896",
                "https://www.exploit-db.com/exploits/34862",
                "https://www.exploit-db.com/exploits/42938",
                "https://www.exploit-db.com/exploits/37816",
                "https://www.exploit-db.com/exploits/36609",
                "https://www.exploit-db.com/exploits/35146",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-YOJIWATANABE-NETWORKALARM",
                "https://kitploit.com/ru/tools/github/yojiwatanabe/networkalarm/",
                "https://github.com/dlitz/bash-cve-2014-6271-fixes",
                "https://github.com/npm/ansible-bashpocalypse",
                "https://github.com/ryancnelson/patched-bash-4.3",
                "https://github.com/jblaine/cookbook-bash-CVE-2014-6271",
                "https://github.com/rrreeeyyy/cve-2014-6271-spec",
                "https://github.com/scottjpack/shellshock_scanner",
                "https://github.com/Anklebiter87/Cgi-bin_bash_Reverse",
                "https://github.com/justzx2011/bash-up",
                "https://github.com/mattclegg/CVE-2014-6271",
                "https://github.com/ilismal/Nessus_CVE-2014-6271_check",
                "https://github.com/RainMak3r/Rainstorm",
                "https://github.com/gabemarshall/shocknaww",
                "https://github.com/woltage/CVE-2014-6271",
                "https://github.com/ariarijp/vagrant-shellshock",
                "https://github.com/themson/shellshock",
                "https://github.com/securusglobal/BadBash",
                "https://github.com/villadora/CVE-2014-6271",
                "https://github.com/APSL/salt-shellshock",
                "https://github.com/teedeedubya/bash-fix-exploit",
                "https://github.com/internero/debian-lenny-bash_3.2.52-cve-2014-6271",
                "https://github.com/u20024804/bash-3.2-fixed-CVE-2014-6271",
                "https://github.com/u20024804/bash-4.2-fixed-CVE-2014-6271",
                "https://github.com/u20024804/bash-4.3-fixed-CVE-2014-6271",
                "https://github.com/francisck/shellshock-cgi",
                "https://github.com/proclnas/ShellShock-CGI-Scan",
                "https://github.com/sch3m4/RIS",
                "https://github.com/ryeyao/CVE-2014-6271_Test",
                "https://github.com/cj1324/CGIShell",
                "https://github.com/renanvicente/puppet-shellshock",
                "https://github.com/indiandragon/Shellshock-Vulnerability-Scan",
                "https://github.com/ramnes/pyshellshock",
                "https://github.com/akiraaisha/shellshocker-python",
                "https://github.com/352926/shellshock_crawler",
                "https://github.com/kelleykong/cve-2014-6271-mengjia-kong",
                "https://github.com/huanlu/cve-2014-6271-huan-lu",
                "https://github.com/sunnyjiang/shellshocker-android",
                "https://github.com/P0cL4bs/ShellShock-CGI-Scan",
                "https://github.com/hmlio/vaas-cve-2014-6271",
                "https://github.com/opsxcq/exploit-CVE-2014-6271",
                "https://github.com/Pilou-Pilou/docker_CVE-2014-6271.",
                "https://github.com/zalalov/CVE-2014-6271",
                "https://github.com/heikipikker/shellshock-shell",
                "https://github.com/0x00-0x00/CVE-2014-6271",
                "https://github.com/kowshik-sundararajan/CVE-2014-6271",
                "https://github.com/w4fz5uck5/ShockZaum-CVE-2014-6271",
                "https://github.com/Aruthw/CVE-2014-6271",
                "https://github.com/cved-sources/cve-2014-6271",
                "https://github.com/shawntns/exploit-CVE-2014-6271",
                "https://github.com/Sindadziy/cve-2014-6271",
                "https://github.com/wenyu1999/bash-shellshock",
                "https://github.com/Sindayifu/CVE-2019-14287-CVE-2014-6271",
                "https://github.com/Any3ite/CVE-2014-6271",
                "https://github.com/somhm-solutions/Shell-Shock",
                "https://github.com/rashmikadileeshara/CVE-2014-6271-Shellshock-",
                "https://github.com/Dilith006/CVE-2014-6271",
                "https://github.com/cyberharsh/Shellbash-CVE-2014-6271",
                "https://github.com/MuirlandOracle/CVE-2014-6271-IPFire",
                "https://github.com/mochizuki875/CVE-2014-6271-Apache-Debian",
                "https://github.com/b4keSn4ke/CVE-2014-6271",
                "https://github.com/akr3ch/CVE-2014-6271",
                "https://github.com/Gurguii/cgi-bin-shellshock",
                "https://github.com/anujbhan/shellshock-victim-host",
                "https://github.com/FilipStudeny/-CVE-2014-6271-Shellshock-Remote-Command-Injection-",
                "https://github.com/mritunjay-k/CVE-2014-6271",
                "https://github.com/Brandaoo/CVE-2014-6271",
                "https://github.com/J0hnTh3Kn1ght/CVE-2014-6271",
                "https://github.com/hanmin0512/CVE-2014-6271_pwnable",
                "https://github.com/0xN7y/CVE-2014-6271",
                "https://github.com/AlissonFaoli/Shellshock",
                "https://github.com/ajansha/shellshock",
                "https://github.com/K3ysTr0K3R/CVE-2014-6271-EXPLOIT",
                "https://github.com/TheRealCiscoo/shellshock-poc",
                "https://github.com/RadYio/CVE-2014-6271",
                "https://github.com/YunchoHang/CVE-2014-6271-SHELLSHOCK",
                "https://github.com/moften/CVE-2014-6271",
                "https://github.com/knightc0de/Shellshock_vuln_Exploit",
                "https://github.com/rsherstnev/CVE-2014-6271",
                "https://github.com/RAJMadhusankha/Shellshock-CVE-2014-6271-Exploitation-and-Analysis",
                "https://github.com/DrHaitham/CVE-2014-6271-Shellshock-",
                "https://github.com/mtaha-sec/bash-apocalypse",
                "https://github.com/andres101c/Shellshock-CVE-2014-6271",
                "https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2014-6271-Shellshock",
                "https://github.com/0xBlackash/CVE-2014-6271",
                "https://github.com/ambjlou/it355-lab4-enterprise-lan-security",
                "https://github.com/kaleth4/-CVE-2014-6271",
                "https://github.com/kaleth4/CVE-2014-6271",
                "https://github.com/V3nG4mxV1p3r/Mobile-Drop-Device-SOC-Detection",
                "https://github.com/im2sinister/CVE-2014-6271",
                "https://github.com/HevenTafese/Penetration-Testing-Walkthrough-Hacksudo-Thor",
                "https://github.com/FacundoMfernandez/pentesting-obioba",
                "https://github.com/R3fr4kt/Shocker-TJNULL-OSCP-",
                "https://github.com/cyberexpert111/Blind-SSRF-to-Remote-Code-Execution-Shellshock-Professional-Bug-Bounty-Report",
                "https://github.com/caverm/Shellshock_CVE-2014-6271",
                "https://github.com/FREEGUY-6/dmz-security-monitoring-hardening",
                "https://github.com/Vaibhav91one/shellshock-cve-lab"
            ],
            "timeline": [
                {
                    "at": "2026-08-31T05:37:25Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-01-28",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ],
            "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
            "id": "CVE-2013-2028",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Nginx 1.3.9 < 1.4.0 - Denial of Service (PoC)",
            "summary": "Nginx 1.3.9 < 1.4.0 - Denial of Service (PoC)",
            "updated_at": "2026-09-11T22:00:00Z",
            "published_at": "2026-09-11T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 293,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 25499",
                    "author": "Mert SARICA",
                    "first_seen": "2013-05-17",
                    "confidence": "High",
                    "title": "Nginx 1.3.9 < 1.4.0 - Denial of Service (PoC)",
                    "summary": "Nginx 1.3.9 < 1.4.0 - Denial of Service (PoC)",
                    "url": "https://www.exploit-db.com/exploits/25499",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 25775",
                    "author": "Metasploit",
                    "first_seen": "2013-05-28",
                    "confidence": "High",
                    "title": "Nginx 1.3.9 < 1.4.0 - Chuncked Encoding Stack Buffer Overflow (Metasploit)",
                    "summary": "Nginx 1.3.9 < 1.4.0 - Chuncked Encoding Stack Buffer Overflow (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/25775",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 26737",
                    "author": "kingcope",
                    "first_seen": "2013-07-11",
                    "confidence": "High",
                    "title": "Nginx 1.3.9/1.4.0 (x86) - Brute Force",
                    "summary": "Nginx 1.3.9/1.4.0 (x86) - Brute Force",
                    "url": "https://www.exploit-db.com/exploits/26737",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 32277",
                    "author": "sorbo",
                    "first_seen": "2014-03-15",
                    "confidence": "High",
                    "title": "Nginx 1.4.0 (Generic Linux x64) - Remote Overflow",
                    "summary": "Nginx 1.4.0 (Generic Linux x64) - Remote Overflow",
                    "url": "https://www.exploit-db.com/exploits/32277",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · danghvu/nginx-1.4.0",
                    "author": "danghvu",
                    "first_seen": "2013-05-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 30,
                    "title": "For the analysis of CVE-2013-2028",
                    "summary": "For the analysis of CVE-2013-2028",
                    "url": "https://github.com/danghvu/nginx-1.4.0"
                },
                {
                    "repository": "PoC-in-GitHub · kitctf/nginxpwn",
                    "author": "kitctf",
                    "first_seen": "2016-03-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 55,
                    "title": "Exploitation Training -- CVE-2013-2028: Nginx Stack Based Buffer Overflow",
                    "summary": "Exploitation Training -- CVE-2013-2028: Nginx Stack Based Buffer Overflow",
                    "url": "https://github.com/kitctf/nginxpwn"
                },
                {
                    "repository": "PoC-in-GitHub · tachibana51/CVE-2013-2028-x64-bypass-ssp-and-pie-PoC",
                    "author": "tachibana51",
                    "first_seen": "2019-08-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "this is not stable",
                    "summary": "this is not stable",
                    "url": "https://github.com/tachibana51/CVE-2013-2028-x64-bypass-ssp-and-pie-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · m4drat/CVE-2013-2028-Exploit",
                    "author": "m4drat",
                    "first_seen": "2020-06-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 19,
                    "title": "CVE-2013-2028 python exploit",
                    "summary": "CVE-2013-2028 python exploit",
                    "url": "https://github.com/m4drat/CVE-2013-2028-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · jptr218/nginxhack",
                    "author": "jptr218",
                    "first_seen": "2021-07-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "A CVE-2013-2028 implementation",
                    "summary": "A CVE-2013-2028 implementation",
                    "url": "https://github.com/jptr218/nginxhack"
                },
                {
                    "repository": "PoC-in-GitHub · Sunqiz/CVE-2013-2028-reproduction",
                    "author": "Sunqiz",
                    "first_seen": "2022-08-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2013-2028复现",
                    "summary": "CVE-2013-2028复现",
                    "url": "https://github.com/Sunqiz/CVE-2013-2028-reproduction"
                },
                {
                    "repository": "PoC-in-GitHub · xiw1ll/CVE-2013-2028_Checker",
                    "author": "xiw1ll",
                    "first_seen": "2024-07-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Tool for checking Nginx CVE-2013-2028",
                    "summary": "Tool for checking Nginx CVE-2013-2028",
                    "url": "https://github.com/xiw1ll/CVE-2013-2028_Checker"
                },
                {
                    "repository": "PoC-in-GitHub · vanivamshi/CVE-2013-2028-Exploit",
                    "author": "vanivamshi",
                    "first_seen": "2026-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2013-2028 repository",
                    "summary": "",
                    "url": "https://github.com/vanivamshi/CVE-2013-2028-Exploit"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/25499",
                "https://www.exploit-db.com/exploits/25775",
                "https://www.exploit-db.com/exploits/26737",
                "https://www.exploit-db.com/exploits/32277",
                "https://github.com/danghvu/nginx-1.4.0",
                "https://github.com/kitctf/nginxpwn",
                "https://github.com/tachibana51/CVE-2013-2028-x64-bypass-ssp-and-pie-PoC",
                "https://github.com/m4drat/CVE-2013-2028-Exploit",
                "https://github.com/jptr218/nginxhack",
                "https://github.com/Sunqiz/CVE-2013-2028-reproduction",
                "https://github.com/xiw1ll/CVE-2013-2028_Checker",
                "https://github.com/vanivamshi/CVE-2013-2028-Exploit"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/25499"
                }
            ]
        },
        {
            "id": "CVE-2013-0333",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Ruby on Rails - JSON Processor YAML Deserialization Code Execution (Metasploit)",
            "summary": "Ruby on Rails - JSON Processor YAML Deserialization Code Execution (Metasploit)",
            "updated_at": "2026-09-08T14:30:33Z",
            "published_at": "2026-09-08T14:30:33Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 117,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Arbitrary code execution in Ruby on Rails 2.3 and 3.0 allowing attacker access to app data.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 24434",
                    "author": "Metasploit",
                    "first_seen": "2013-01-29",
                    "confidence": "High",
                    "title": "Ruby on Rails - JSON Processor YAML Deserialization Code Execution (Metasploit)",
                    "summary": "Ruby on Rails - JSON Processor YAML Deserialization Code Execution (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/24434",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for heroku-CVE-2013-0333",
                    "summary": "Arbitrary code execution in Ruby on Rails 2.3 and 3.0 allowing attacker access to app data.",
                    "what_happened": "Arbitrary code execution in Ruby on Rails 2.3 and 3.0 allowing attacker access to app data.",
                    "cvss": 7.5,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HEROKU-HEROKU-CVE-2013-0333",
                        "https://kitploit.com/ru/tools/github/heroku/heroku-cve-2013-0333/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T15:08:35",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HEROKU-HEROKU-CVE-2013-0333"
                },
                {
                    "title": "Exploit for heroku-CVE-2013-0333",
                    "summary": "Arbitrary code execution in Ruby on Rails 2.3 and 3.0 allowing attacker access to app data.",
                    "what_happened": "Arbitrary code execution in Ruby on Rails 2.3 and 3.0 allowing attacker access to app data.",
                    "cvss": 7.5,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HEROKU-HEROKU-CVE-2013-0333",
                        "https://kitploit.com/ru/tools/github/heroku/heroku-cve-2013-0333/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T15:08:35",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/heroku/heroku-cve-2013-0333/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/24434",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-HEROKU-HEROKU-CVE-2013-0333",
                "https://kitploit.com/ru/tools/github/heroku/heroku-cve-2013-0333/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T14:30:33Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/24434"
                }
            ]
        },
        {
            "id": "CVE-2012-4431",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "CVE-2012-4431 exploit",
            "summary": "Exploit for CVE-2012-4431. CVSS 4.3.",
            "updated_at": "2026-09-13T18:23:43Z",
            "published_at": "2026-09-13T18:23:43Z",
            "cvss": 4.3,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 12,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:23:43+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2012-4431 exploit",
                    "summary": "Exploit for CVE-2012-4431. CVSS 4.3.",
                    "cvss": 4.3,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IMJDL-CVE-2012-4431"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IMJDL-CVE-2012-4431"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:23:43Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-IMJDL-CVE-2012-4431"
                }
            ]
        },
        {
            "id": "CVE-2012-3137",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Oracle Database - Protocol Authentication Bypass",
            "summary": "Oracle Database - Protocol Authentication Bypass",
            "updated_at": "2026-09-03T19:22:31Z",
            "published_at": "2026-09-03T19:22:31Z",
            "cvss": 8.7,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 36,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 22069",
                    "author": "Esteban Martinez Fayo",
                    "first_seen": "2012-10-18",
                    "confidence": "High",
                    "title": "Oracle Database - Protocol Authentication Bypass",
                    "summary": "Oracle Database - Protocol Authentication Bypass",
                    "url": "https://www.exploit-db.com/exploits/22069",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for odat",
                    "summary": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
                    "what_happened": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
                    "cvss": 8.7,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A425673185408838890",
                        "https://kitploit.com/en/tools/github/quentinhardy/odat/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T21:22:31",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A425673185408838890"
                },
                {
                    "title": "Exploit for odat",
                    "summary": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
                    "what_happened": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
                    "cvss": 8.7,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A425673185408838890",
                        "https://kitploit.com/en/tools/github/quentinhardy/odat/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-03T21:22:31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/quentinhardy/odat/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/22069",
                "https://sploitus.com/exploit?id=KITPLOIT%3A425673185408838890",
                "https://kitploit.com/en/tools/github/quentinhardy/odat/"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T19:22:31Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/22069"
                }
            ],
            "cvss_vector": "NONE"
        },
        {
            "id": "CVE-2012-1675",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Exploit for odat",
            "summary": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
            "updated_at": "2026-09-03T19:22:31Z",
            "published_at": "2026-09-03T19:22:31Z",
            "cvss": 8.7,
            "confidence": 100,
            "confidence_label": "review",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 19,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "title": "Exploit for odat",
                    "summary": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
                    "what_happened": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
                    "cvss": 8.7,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A425673185408838890",
                        "https://kitploit.com/en/tools/github/quentinhardy/odat/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-03T21:22:31",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A425673185408838890"
                },
                {
                    "title": "Exploit for odat",
                    "summary": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
                    "what_happened": "ODAT is a tool for testing Oracle Database security remotely, including searching for valid SIDs and credentials, privilege escalation, executing OS commands, file management, HTTP requests, port scanning, and exploiting CVE-2012-313",
                    "cvss": 8.7,
                    "cvss_vector": "NONE",
                    "attack_vector": "Unknown",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3A425673185408838890",
                        "https://kitploit.com/en/tools/github/quentinhardy/odat/"
                    ],
                    "repository": "kitploit.com",
                    "author": "en",
                    "first_seen": "2026-09-03T21:22:31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/en/tools/github/quentinhardy/odat/"
                }
            ],
            "references": [
                "https://sploitus.com/exploit?id=KITPLOIT%3A425673185408838890",
                "https://kitploit.com/en/tools/github/quentinhardy/odat/"
            ],
            "timeline": [
                {
                    "at": "2026-09-03T19:22:31Z",
                    "label": "Discovered through Sploitus",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3A425673185408838890"
                }
            ],
            "cvss_vector": "NONE"
        },
        {
            "id": "CVE-2012-0754",
            "vendor": "Adobe",
            "product": "Flash Player",
            "title": "Adobe Flash Player Memory Corruption Vulnerability",
            "summary": "Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).",
            "updated_at": "2026-09-11T22:00:00Z",
            "published_at": "2026-09-11T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 60,
            "kev": true,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 18572",
                    "author": "Metasploit",
                    "first_seen": "2012-03-08",
                    "confidence": "High",
                    "title": "Adobe Flash Player - '.mp4 cprt' Remote Overflow (Metasploit)",
                    "summary": "Adobe Flash Player - '.mp4 cprt' Remote Overflow (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/18572",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · mbeweoo/flash-exploit-defense-system",
                    "author": "mbeweoo",
                    "first_seen": "2026-09-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Comprehensive multi-layer defense system against Adobe Flash CVE exploits (CVE-2012-0754, CVE-2015-xxxx, CVE-2016-xxxx, CVE-2018-xxxx) with browser, mobile, server, and system-level protection",
                    "summary": "Comprehensive multi-layer defense system against Adobe Flash CVE exploits (CVE-2012-0754, CVE-2015-xxxx, CVE-2016-xxxx, CVE-2018-xxxx) with browser, mobile, server, and system-level protection",
                    "url": "https://github.com/mbeweoo/flash-exploit-defense-system"
                }
            ],
            "references": [
                "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
                "https://www.exploit-db.com/exploits/18572",
                "https://github.com/mbeweoo/flash-exploit-defense-system"
            ],
            "timeline": [
                {
                    "at": "2026-09-11T22:00:00Z",
                    "label": "Discovered through CISA Known Exploited Vulnerabilities",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                },
                {
                    "at": "2022-06-08",
                    "label": "Added to CISA Known Exploited Vulnerabilities catalog",
                    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
                }
            ]
        },
        {
            "id": "CVE-2011-3192",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Apache - Denial of Service",
            "summary": "Apache - Denial of Service",
            "updated_at": "2026-09-05T08:11:19Z",
            "published_at": "2026-09-05T08:11:19Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 538,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Denial of service in Apache versions 1.3.x, 2.0.64 and 2.2.19 and below.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 18221",
                    "author": "Ramon de C Valle",
                    "first_seen": "2011-12-09",
                    "confidence": "High",
                    "title": "Apache - Denial of Service",
                    "summary": "Apache - Denial of Service",
                    "url": "https://www.exploit-db.com/exploits/18221",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 17696",
                    "author": "kingcope",
                    "first_seen": "2011-08-19",
                    "confidence": "High",
                    "title": "Apache - Remote Memory Exhaustion (Denial of Service)",
                    "summary": "Apache - Remote Memory Exhaustion (Denial of Service)",
                    "url": "https://www.exploit-db.com/exploits/17696",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-05T08:11:19+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2011-3192-apache-exploit",
                    "summary": "Exploit for CVE-2011-3192. CVSS 7.8.",
                    "cvss": 7.8,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BLUEDRAGONSECURITY-CVE-2011-3192-APACHE-EXPLOIT"
                },
                {
                    "title": "CVE-2011-3192-apache-exploit",
                    "summary": "Denial of service in Apache versions 1.3.x, 2.0.64 and 2.2.19 and below.",
                    "what_happened": "Denial of service in Apache versions 1.3.x, 2.0.64 and 2.2.19 and below.",
                    "cvss": 7.8,
                    "cvss_vector": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BLUEDRAGONSECURITY-CVE-2011-3192-APACHE-EXPLOIT",
                        "https://kitploit.com/ru/tools/github/bluedragonsecurity/cve-2011-3192-apache-exploit/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-08-25T03:46:08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/bluedragonsecurity/cve-2011-3192-apache-exploit/"
                },
                {
                    "repository": "bluedragonsecurity/CVE-2011-3192-apache-exploit",
                    "author": "bluedragonsecurity",
                    "first_seen": "2026-05-14",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 2,
                    "title": "CVE-2011-3192 - Remote Apache DOS for Apache versions 1.3.x, 2.0.64 and below and 2.2.19 and below. Developed in 2011 by Antonius (ev1lut10n / w1sdom)",
                    "summary": "CVE-2011-3192 - Remote Apache DOS for Apache versions 1.3.x, 2.0.64 and below and 2.2.19 and below. Developed in 2011 by Antonius (ev1lut10n / w1sdom)",
                    "url": "https://github.com/bluedragonsecurity/CVE-2011-3192-apache-exploit"
                },
                {
                    "repository": "Xinjis/Apache_ByteRange_DoS_cve_2011_3192",
                    "author": "Xinjis",
                    "first_seen": "2025-08-08",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 0,
                    "title": "Script en python para comprobar CVE",
                    "summary": "Script en python para comprobar CVE",
                    "url": "https://github.com/Xinjis/Apache_ByteRange_DoS_cve_2011_3192"
                },
                {
                    "repository": "futurezayka/CVE-2011-3192",
                    "author": "futurezayka",
                    "first_seen": "2023-09-16",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "stars": 0,
                    "title": "CVE-2011-3192 repository",
                    "summary": "",
                    "url": "https://github.com/futurezayka/CVE-2011-3192"
                },
                {
                    "repository": "stcmjp/cve-2011-3192",
                    "author": "stcmjp",
                    "first_seen": "2020-04-09",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 0,
                    "title": "This Repository use to test Apache Killer (cve-2011-3192).",
                    "summary": "This Repository use to test Apache Killer (cve-2011-3192).",
                    "url": "https://github.com/stcmjp/cve-2011-3192"
                },
                {
                    "repository": "tkisason/KillApachePy",
                    "author": "tkisason",
                    "first_seen": "2011-10-26",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 16,
                    "title": "Python Apache Killer (Range Header DoS CVE-2011-3192)",
                    "summary": "Python Apache Killer (Range Header DoS CVE-2011-3192)",
                    "url": "https://github.com/tkisason/KillApachePy"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/18221",
                "https://www.exploit-db.com/exploits/17696",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-BLUEDRAGONSECURITY-CVE-2011-3192-APACHE-EXPLOIT",
                "https://kitploit.com/ru/tools/github/bluedragonsecurity/cve-2011-3192-apache-exploit/",
                "https://github.com/bluedragonsecurity/CVE-2011-3192-apache-exploit",
                "https://github.com/Xinjis/Apache_ByteRange_DoS_cve_2011_3192",
                "https://github.com/futurezayka/CVE-2011-3192",
                "https://github.com/stcmjp/cve-2011-3192",
                "https://github.com/tkisason/KillApachePy"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:11:19Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/18221"
                }
            ]
        },
        {
            "id": "CVE-2011-2523",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "vsftpd 2.3.4 - Backdoor Command Execution",
            "summary": "vsftpd 2.3.4 - Backdoor Command Execution",
            "updated_at": "2026-09-07T22:00:00Z",
            "published_at": "2026-09-07T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 974,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 49757",
                    "author": "HerculesRD",
                    "first_seen": "2021-04-12",
                    "confidence": "High",
                    "title": "vsftpd 2.3.4 - Backdoor Command Execution",
                    "summary": "vsftpd 2.3.4 - Backdoor Command Execution",
                    "url": "https://www.exploit-db.com/exploits/49757",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 17491",
                    "author": "Metasploit",
                    "first_seen": "2011-07-05",
                    "confidence": "High",
                    "title": "vsftpd 2.3.4 - Backdoor Command Execution (Metasploit)",
                    "summary": "vsftpd 2.3.4 - Backdoor Command Execution (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/17491",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · HerculesRD/vsftpd2.3.4PyExploit",
                    "author": "HerculesRD",
                    "first_seen": "2021-04-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "An exploit to get root in vsftpd 2.3.4 (CVE-2011-2523) written in python",
                    "summary": "An exploit to get root in vsftpd 2.3.4 (CVE-2011-2523) written in python",
                    "url": "https://github.com/HerculesRD/vsftpd2.3.4PyExploit"
                },
                {
                    "repository": "PoC-in-GitHub · nobodyatall648/CVE-2011-2523",
                    "author": "nobodyatall648",
                    "first_seen": "2021-05-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "vsftpd 2.3.4 Backdoor Exploit",
                    "summary": "vsftpd 2.3.4 Backdoor Exploit",
                    "url": "https://github.com/nobodyatall648/CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · Gr4ykt/CVE-2011-2523",
                    "author": "Gr4ykt",
                    "first_seen": "2021-08-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "https://www.exploit-db.com/exploits/49757",
                    "summary": "https://www.exploit-db.com/exploits/49757",
                    "url": "https://github.com/Gr4ykt/CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · padsalatushal/CVE-2011-2523",
                    "author": "padsalatushal",
                    "first_seen": "2021-11-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 15,
                    "title": "Python exploit for vsftpd 2.3.4 - Backdoor Command Execution",
                    "summary": "Python exploit for vsftpd 2.3.4 - Backdoor Command Execution",
                    "url": "https://github.com/padsalatushal/CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · MFernstrom/OffensivePascal-CVE-2011-2523",
                    "author": "MFernstrom",
                    "first_seen": "2022-05-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "FreePascal implementation of the vsFTPD 2.3.4 CVE-2011-2523",
                    "summary": "FreePascal implementation of the vsFTPD 2.3.4 CVE-2011-2523",
                    "url": "https://github.com/MFernstrom/OffensivePascal-CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · 0xSojalSec/-CVE-2011-2523",
                    "author": "0xSojalSec",
                    "first_seen": "2022-06-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Python exploit for CVE-2011-2523 (VSFTPD 2.3.4 Backdoor Command Execution)",
                    "summary": "Python exploit for CVE-2011-2523 (VSFTPD 2.3.4 Backdoor Command Execution)",
                    "url": "https://github.com/0xSojalSec/-CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · 0xSojalSec/CVE-2011-2523",
                    "author": "0xSojalSec",
                    "first_seen": "2022-06-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Python exploit for CVE-2011-2523 (VSFTPD 2.3.4 Backdoor Command Execution)",
                    "summary": "Python exploit for CVE-2011-2523 (VSFTPD 2.3.4 Backdoor Command Execution)",
                    "url": "https://github.com/0xSojalSec/CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · XiangSi-Howard/CTF---CVE-2011-2523",
                    "author": "XiangSi-Howard",
                    "first_seen": "2022-12-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2011-2523 repository",
                    "summary": "",
                    "url": "https://github.com/XiangSi-Howard/CTF---CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · cowsecurity/CVE-2011-2523",
                    "author": "cowsecurity",
                    "first_seen": "2023-02-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2011-2523 exploit",
                    "summary": "CVE-2011-2523 exploit",
                    "url": "https://github.com/cowsecurity/CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · Lynk4/CVE-2011-2523",
                    "author": "Lynk4",
                    "first_seen": "2023-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Python exploit for vsftpd 2.3.4 - Backdoor Command Execution",
                    "summary": "Python exploit for vsftpd 2.3.4 - Backdoor Command Execution",
                    "url": "https://github.com/Lynk4/CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · vaishnavucv/CVE-2011-2523",
                    "author": "vaishnavucv",
                    "first_seen": "2023-10-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Python exploit for vsftpd 2.3.4 - Backdoor Command Execution",
                    "summary": "Python exploit for vsftpd 2.3.4 - Backdoor Command Execution",
                    "url": "https://github.com/vaishnavucv/CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · 4m3rr0r/CVE-2011-2523-poc",
                    "author": "4m3rr0r",
                    "first_seen": "2023-11-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Python exploit for CVE-2011-2523 (VSFTPD 2.3.4 Backdoor Command Execution)",
                    "summary": "Python exploit for CVE-2011-2523 (VSFTPD 2.3.4 Backdoor Command Execution)",
                    "url": "https://github.com/4m3rr0r/CVE-2011-2523-poc"
                },
                {
                    "repository": "PoC-in-GitHub · Shubham-2k1/Exploit-CVE-2011-2523",
                    "author": "Shubham-2k1",
                    "first_seen": "2024-03-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2011-2523 repository",
                    "summary": "",
                    "url": "https://github.com/Shubham-2k1/Exploit-CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · Tenor-Z/SmileySploit",
                    "author": "Tenor-Z",
                    "first_seen": "2024-04-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A basic script that exploits CVE-2011-2523",
                    "summary": "A basic script that exploits CVE-2011-2523",
                    "url": "https://github.com/Tenor-Z/SmileySploit"
                },
                {
                    "repository": "PoC-in-GitHub · 0xB0y426/CVE-2011-2523-PoC",
                    "author": "0xB0y426",
                    "first_seen": "2024-05-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "PoC CVE-2011-2523",
                    "summary": "PoC CVE-2011-2523",
                    "url": "https://github.com/0xB0y426/CVE-2011-2523-PoC"
                },
                {
                    "repository": "PoC-in-GitHub · AnugiArrawwala/CVE-Research",
                    "author": "AnugiArrawwala",
                    "first_seen": "2024-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2017-0144 (Eternal Blue) | CVE-2023-3881 | CVE-2011-2523",
                    "summary": "CVE-2017-0144 (Eternal Blue) | CVE-2023-3881 | CVE-2011-2523",
                    "url": "https://github.com/AnugiArrawwala/CVE-Research"
                },
                {
                    "repository": "PoC-in-GitHub · Gill-Singh-A/vsFTP-2.3.4-Remote-Root-Shell-Exploit",
                    "author": "Gill-Singh-A",
                    "first_seen": "2024-08-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "A Simple Python Program that uses gets a Remote Root Shell on the Target Device by exploiting a Vulnerability (CVE-2011-2523) present in vsFTP 2.3.4",
                    "summary": "A Simple Python Program that uses gets a Remote Root Shell on the Target Device by exploiting a Vulnerability (CVE-2011-2523) present in vsFTP 2.3.4",
                    "url": "https://github.com/Gill-Singh-A/vsFTP-2.3.4-Remote-Root-Shell-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Lychi3/vsftpd-backdoor",
                    "author": "Lychi3",
                    "first_seen": "2025-02-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit hecho en python para vsftpd 2.3.4 | CVE-2011-2523",
                    "summary": "Exploit hecho en python para vsftpd 2.3.4 | CVE-2011-2523",
                    "url": "https://github.com/Lychi3/vsftpd-backdoor"
                },
                {
                    "repository": "PoC-in-GitHub · vedpakhare/vsftpd-234-vuln-report",
                    "author": "vedpakhare",
                    "first_seen": "2025-04-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Vulnerability assessment and exploitation of vsftpd 2.3.4 (CVE-2011-2523) using Metasploit. Full report and proof of root access included.",
                    "summary": "Vulnerability assessment and exploitation of vsftpd 2.3.4 (CVE-2011-2523) using Metasploit. Full report and proof of root access included.",
                    "url": "https://github.com/vedpakhare/vsftpd-234-vuln-report"
                },
                {
                    "repository": "PoC-in-GitHub · cybermads/CVE-2011-2523",
                    "author": "cybermads",
                    "first_seen": "2025-04-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2011-2523 repository",
                    "summary": "",
                    "url": "https://github.com/cybermads/CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · sug4r-wr41th/CVE-2011-2523",
                    "author": "sug4r-wr41th",
                    "first_seen": "2025-04-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "vsFTPd 2.3.4 CVE-2011-2523 PoC",
                    "summary": "vsFTPd 2.3.4 CVE-2011-2523 PoC",
                    "url": "https://github.com/sug4r-wr41th/CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · JohanMV/explotacion-vsftpd-nmap_Laboratorio_1",
                    "author": "JohanMV",
                    "first_seen": "2025-04-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Laboratorio técnico de ciberseguridad donde se realiza reconocimiento de red con Nmap y explotación de la vulnerabilidad CVE-2011-2523 (vsftpd 2.3.4) mediante Metasploit Framework. Proyecto académico orientado a demostrar habilidades en análisis de vulnerabilidades, uso de herramientas de pentesting y reporte técnico.",
                    "summary": "Laboratorio técnico de ciberseguridad donde se realiza reconocimiento de red con Nmap y explotación de la vulnerabilidad CVE-2011-2523 (vsftpd 2.3.4) mediante Metasploit Framework. Proyecto académico orientado a demostrar habilidades en análisis de vulnerabilidades, uso de herramientas de pentesting y reporte técnico.",
                    "url": "https://github.com/JohanMV/explotacion-vsftpd-nmap_Laboratorio_1"
                },
                {
                    "repository": "PoC-in-GitHub · lghost256/vsftpd234-exploit",
                    "author": "lghost256",
                    "first_seen": "2025-06-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit for CVE-2011-2523.",
                    "summary": "Exploit for CVE-2011-2523.",
                    "url": "https://github.com/lghost256/vsftpd234-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · hklabCR/CVE-2011-2523",
                    "author": "hklabCR",
                    "first_seen": "2025-07-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2011-2523 repository",
                    "summary": "",
                    "url": "https://github.com/hklabCR/CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · krill-x7/CVE-2011-2523",
                    "author": "krill-x7",
                    "first_seen": "2025-07-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Python exploit for vsftpd 2.3.4 - Backdoor Command Execution",
                    "summary": "Python exploit for vsftpd 2.3.4 - Backdoor Command Execution",
                    "url": "https://github.com/krill-x7/CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · BolivarJ/CVE-2011-2523",
                    "author": "BolivarJ",
                    "first_seen": "2025-08-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "Python exploit for vsftpd 2.3.4 - Backdoor Command Execution",
                    "summary": "Python exploit for vsftpd 2.3.4 - Backdoor Command Execution",
                    "url": "https://github.com/BolivarJ/CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · KlyneZyro/Metasploitable2-VAPT-Report",
                    "author": "KlyneZyro",
                    "first_seen": "2025-12-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Comprehensive Penetration Testing report and exploit chain for Metasploitable 2 focusing on CVE-2011-2523.",
                    "summary": "Comprehensive Penetration Testing report and exploit chain for Metasploitable 2 focusing on CVE-2011-2523.",
                    "url": "https://github.com/KlyneZyro/Metasploitable2-VAPT-Report"
                },
                {
                    "repository": "PoC-in-GitHub · Mirza-22144/Vulnerability-Assessment-Exploitation-Lab",
                    "author": "Mirza-22144",
                    "first_seen": "2026-01-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Full-lifecycle penetration test of a legacy Linux environment (Metasploitable 2) emulated on Apple Silicon. Demonstrating network reconnaissance, RCE via service backdoors (CVE-2011-2523), and cryptographic credential recovery.",
                    "summary": "Full-lifecycle penetration test of a legacy Linux environment (Metasploitable 2) emulated on Apple Silicon. Demonstrating network reconnaissance, RCE via service backdoors (CVE-2011-2523), and cryptographic credential recovery.",
                    "url": "https://github.com/Mirza-22144/Vulnerability-Assessment-Exploitation-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · tshaq17/vsftpd-2.3.4---Backdoor-Command-Execution",
                    "author": "tshaq17",
                    "first_seen": "2026-01-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "vsftpd 2.3.4 (CVE-2011-2523) a critical vulnerability that leads to Reverse Root Shell. In this repo I will do a PoC how to exploit it step by step, Manually & Automatically (Python) for educational purposes.",
                    "summary": "vsftpd 2.3.4 (CVE-2011-2523) a critical vulnerability that leads to Reverse Root Shell. In this repo I will do a PoC how to exploit it step by step, Manually & Automatically (Python) for educational purposes.",
                    "url": "https://github.com/tshaq17/vsftpd-2.3.4---Backdoor-Command-Execution"
                },
                {
                    "repository": "PoC-in-GitHub · Efehamzaa/Metasploit-Red-Pentest-Lab",
                    "author": "Efehamzaa",
                    "first_seen": "2026-01-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Metasploitable 2 üzerinde vsftpd 2.3.4 (CVE-2011-2523) zafiyetinin istismarı ve sızma sonrası adımlarını içeren laboratuvar çalışması.",
                    "summary": "Metasploitable 2 üzerinde vsftpd 2.3.4 (CVE-2011-2523) zafiyetinin istismarı ve sızma sonrası adımlarını içeren laboratuvar çalışması.",
                    "url": "https://github.com/Efehamzaa/Metasploit-Red-Pentest-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · yagnikkrish/metasploitable-penetration-testing-lab",
                    "author": "yagnikkrish",
                    "first_seen": "2026-02-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Controlled penetration testing lab demonstrating CVE-2011-2523 exploitation and mitigation techniques.",
                    "summary": "Controlled penetration testing lab demonstrating CVE-2011-2523 exploitation and mitigation techniques.",
                    "url": "https://github.com/yagnikkrish/metasploitable-penetration-testing-lab"
                },
                {
                    "repository": "PoC-in-GitHub · brettsm/vsftpd2.3.4-backdoor-exploit",
                    "author": "brettsm",
                    "first_seen": "2026-03-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "vsftpd 2.3.4 Backdoor Exploit (CVE-2011-2523)",
                    "summary": "vsftpd 2.3.4 Backdoor Exploit (CVE-2011-2523)",
                    "url": "https://github.com/brettsm/vsftpd2.3.4-backdoor-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Tr00jan99/PwnTillDawn-Portal-Walkthrough",
                    "author": "Tr00jan99",
                    "first_seen": "2026-03-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A detailed penetration testing walkthrough and exploitation report for the 'Portal' machine, focusing on CVE-2011-2523 (vsFTPd 2.3.4 Backdoor) to achieve root access.",
                    "summary": "A detailed penetration testing walkthrough and exploitation report for the 'Portal' machine, focusing on CVE-2011-2523 (vsFTPd 2.3.4 Backdoor) to achieve root access.",
                    "url": "https://github.com/Tr00jan99/PwnTillDawn-Portal-Walkthrough"
                },
                {
                    "repository": "PoC-in-GitHub · Dahalsamir/CVE-2011-2523-exploit",
                    "author": "Dahalsamir",
                    "first_seen": "2026-04-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2011-2523 repository",
                    "summary": "",
                    "url": "https://github.com/Dahalsamir/CVE-2011-2523-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · RinAliyeva/metasploitable2-vsftpd-exploitation",
                    "author": "RinAliyeva",
                    "first_seen": "2026-04-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Project: vsFTPd 2.3.4 backdoor exploitation (CVE-2011-2523) on Metasploitable 2.",
                    "summary": "Project: vsFTPd 2.3.4 backdoor exploitation (CVE-2011-2523) on Metasploitable 2.",
                    "url": "https://github.com/RinAliyeva/metasploitable2-vsftpd-exploitation"
                },
                {
                    "repository": "PoC-in-GitHub · emilebarnard242/pentest-metasploitable2",
                    "author": "emilebarnard242",
                    "first_seen": "2026-04-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A documented penetration testing lab built on Kali Linux and Metasploitable2, walking through a full attack chain from network traffic analysis and service enumeration through to exploiting the vsftpd 2.3.4 backdoor (CVE-2011-2523) and achieving root access. Includes blue team detection notes and MITRE ATT&CK mapping throughout.",
                    "summary": "A documented penetration testing lab built on Kali Linux and Metasploitable2, walking through a full attack chain from network traffic analysis and service enumeration through to exploiting the vsftpd 2.3.4 backdoor (CVE-2011-2523) and achieving root access. Includes blue team detection notes and MITRE ATT&CK mapping throughout.",
                    "url": "https://github.com/emilebarnard242/pentest-metasploitable2"
                },
                {
                    "repository": "PoC-in-GitHub · Mithileshan/soc-investigation-lab",
                    "author": "Mithileshan",
                    "first_seen": "2026-04-24",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "End-to-end SOC investigation: CVE-2011-2523 kill chain, multi-source log correlation, incident report — MITRE ATT&CK T1190",
                    "summary": "End-to-end SOC investigation: CVE-2011-2523 kill chain, multi-source log correlation, incident report — MITRE ATT&CK T1190",
                    "url": "https://github.com/Mithileshan/soc-investigation-lab"
                },
                {
                    "repository": "PoC-in-GitHub · IvoAlbacete/Kali-Metasploitable",
                    "author": "IvoAlbacete",
                    "first_seen": "2026-04-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Escaneo de vulnerabilidades, análisis de tráfico con Wireshark y explotación controlada del CVE-2011-2523 (vsftpd 2.3.4) en entorno de red segura.",
                    "summary": "Escaneo de vulnerabilidades, análisis de tráfico con Wireshark y explotación controlada del CVE-2011-2523 (vsftpd 2.3.4) en entorno de red segura.",
                    "url": "https://github.com/IvoAlbacete/Kali-Metasploitable"
                },
                {
                    "repository": "PoC-in-GitHub · Amirmuhammadmarvi/network-security-lab",
                    "author": "Amirmuhammadmarvi",
                    "first_seen": "2026-05-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Controlled virtual attack & defense lab — CVE-2011-2523 exploitation, Nmap recon, Nikto scanning, UFW hardening on Metasploitable 2",
                    "summary": "Controlled virtual attack & defense lab — CVE-2011-2523 exploitation, Nmap recon, Nikto scanning, UFW hardening on Metasploitable 2",
                    "url": "https://github.com/Amirmuhammadmarvi/network-security-lab"
                },
                {
                    "repository": "PoC-in-GitHub · Prafullya-Shandilya/metasploitable-pentest-report",
                    "author": "Prafullya-Shandilya",
                    "first_seen": "2026-05-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Black-box penetration test on Metasploitable 2 — Identified 3 critical vulnerabilities including CVE-2011-2523. Conducted in isolated VMware lab. Tools: Nmap, Metasploit, Netcat.",
                    "summary": "Black-box penetration test on Metasploitable 2 — Identified 3 critical vulnerabilities including CVE-2011-2523. Conducted in isolated VMware lab. Tools: Nmap, Metasploit, Netcat.",
                    "url": "https://github.com/Prafullya-Shandilya/metasploitable-pentest-report"
                },
                {
                    "repository": "PoC-in-GitHub · Taisa456/network-security-snort",
                    "author": "Taisa456",
                    "first_seen": "2026-05-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd 2.3.4 backdoor (CVE-2011-2523).",
                    "summary": "Snort 3 IDS → IPS lab on Kali. Custom detection rules + iptables enforcement against ICMP recon, Nmap SYN scans, Hydra FTP brute force, and vsftpd 2.3.4 backdoor (CVE-2011-2523).",
                    "url": "https://github.com/Taisa456/network-security-snort"
                },
                {
                    "repository": "PoC-in-GitHub · ByteForgeFr/CVE-2011-2523",
                    "author": "ByteForgeFr",
                    "first_seen": "2026-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "VsFTPd 2.3.4 Backdoor Command Execution",
                    "summary": "VsFTPd 2.3.4 Backdoor Command Execution",
                    "url": "https://github.com/ByteForgeFr/CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · Jhatchi/NexaCorp-DFIR-INC-2026-001",
                    "author": "Jhatchi",
                    "first_seen": "2026-05-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "DFIR investigation + 7 Suricata rules on a simulated NexaCorp intrusion (vsftpd 2.3.4 CVE-2011-2523 + MITRE Caldera C2). 4-day solo engagement (BeCode Brussels Mission 01). 54-page report, 10 findings, 7/7 rules validated by PCAP replay.",
                    "summary": "DFIR investigation + 7 Suricata rules on a simulated NexaCorp intrusion (vsftpd 2.3.4 CVE-2011-2523 + MITRE Caldera C2). 4-day solo engagement (BeCode Brussels Mission 01). 54-page report, 10 findings, 7/7 rules validated by PCAP replay.",
                    "url": "https://github.com/Jhatchi/NexaCorp-DFIR-INC-2026-001"
                },
                {
                    "repository": "PoC-in-GitHub · Chathura123git/ethical-hacking-CVE-2011-2523",
                    "author": "Chathura123git",
                    "first_seen": "2026-05-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Ethical Hacking Assessment | Practical vulnerability testing of vsftpd 2.3.4 backdoor (CVE-2011-2523) on Metasploitable2 using Kali Linux & Metasploit",
                    "summary": "Ethical Hacking Assessment | Practical vulnerability testing of vsftpd 2.3.4 backdoor (CVE-2011-2523) on Metasploitable2 using Kali Linux & Metasploit",
                    "url": "https://github.com/Chathura123git/ethical-hacking-CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · NitinSukthe-G/OpenVAS-Vulnerability-Assessment-Incident-Response",
                    "author": "NitinSukthe-G",
                    "first_seen": "2026-06-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Performed a Full & Fast vulnerability assessment using OpenVAS against Metasploitable2, identified the critical vsftpd Backdoor vulnerability (CVE-2011-2523), and developed containment, remediation, and incident response documentation.",
                    "summary": "Performed a Full & Fast vulnerability assessment using OpenVAS against Metasploitable2, identified the critical vsftpd Backdoor vulnerability (CVE-2011-2523), and developed containment, remediation, and incident response documentation.",
                    "url": "https://github.com/NitinSukthe-G/OpenVAS-Vulnerability-Assessment-Incident-Response"
                },
                {
                    "repository": "PoC-in-GitHub · H4R335HR/vsftpd-234-backdoor",
                    "author": "H4R335HR",
                    "first_seen": "2026-06-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Dependency-free interactive Python exploit for the vsftpd 2.3.4 backdoor (CVE-2011-2523).",
                    "summary": "Dependency-free interactive Python exploit for the vsftpd 2.3.4 backdoor (CVE-2011-2523).",
                    "url": "https://github.com/H4R335HR/vsftpd-234-backdoor"
                },
                {
                    "repository": "PoC-in-GitHub · kn9annihilator/CVE-2011-2523-vsFTPd-2.3.4-Writeup",
                    "author": "kn9annihilator",
                    "first_seen": "2026-07-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2011-2523 repository",
                    "summary": "",
                    "url": "https://github.com/kn9annihilator/CVE-2011-2523-vsFTPd-2.3.4-Writeup"
                },
                {
                    "repository": "PoC-in-GitHub · Orevic21/wazuh-home-soc",
                    "author": "Orevic21",
                    "first_seen": "2026-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Wazuh + Suricata SOC lab detecting real exploits (CVE-2011-2523) and brute-force attacks, with custom detection rules for gaps in default IDS signatures.",
                    "summary": "Wazuh + Suricata SOC lab detecting real exploits (CVE-2011-2523) and brute-force attacks, with custom detection rules for gaps in default IDS signatures.",
                    "url": "https://github.com/Orevic21/wazuh-home-soc"
                },
                {
                    "repository": "PoC-in-GitHub · solomonhenry-afk/vsftpd-cve-2011-2523-detection-signature",
                    "author": "solomonhenry-afk",
                    "first_seen": "2026-07-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE research-to-detection-signature engineering project: fingerprinting the vsftpd 2.3.4 backdoor (CVE-2011-2523) externally, at scale, with validated false-positive/negative handling - built in Python",
                    "summary": "CVE research-to-detection-signature engineering project: fingerprinting the vsftpd 2.3.4 backdoor (CVE-2011-2523) externally, at scale, with validated false-positive/negative handling - built in Python",
                    "url": "https://github.com/solomonhenry-afk/vsftpd-cve-2011-2523-detection-signature"
                },
                {
                    "repository": "PoC-in-GitHub · IndiQuarks/vsftpd-cve-2011-2523-lab",
                    "author": "IndiQuarks",
                    "first_seen": "2026-07-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Pen Tesing Lab exploiting VSFTPD 2.3.4 backdoor via Metasploit Framework",
                    "summary": "Pen Tesing Lab exploiting VSFTPD 2.3.4 backdoor via Metasploit Framework",
                    "url": "https://github.com/IndiQuarks/vsftpd-cve-2011-2523-lab"
                },
                {
                    "repository": "PoC-in-GitHub · khalilu020/offensive-security-adversary-emulation",
                    "author": "khalilu020",
                    "first_seen": "2026-07-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing Wazuh/Suricata/Zeek SOC — uncovering and fixing 5 real monitoring pipeline bugs along the way.",
                    "summary": "Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing Wazuh/Suricata/Zeek SOC — uncovering and fixing 5 real monitoring pipeline bugs along the way.",
                    "url": "https://github.com/khalilu020/offensive-security-adversary-emulation"
                },
                {
                    "repository": "PoC-in-GitHub · IrsaAttiqueCyber/SystemVulnerabilityChecklist_Project4_Decodelabs",
                    "author": "IrsaAttiqueCyber",
                    "first_seen": "2026-08-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "System Vulnerability Checklist & Network Security Hardening project featuring reconnaissance, vsFTPd backdoor analysis (CVE-2011-2523), and active transport-layer mitigation using IPTables.",
                    "summary": "System Vulnerability Checklist & Network Security Hardening project featuring reconnaissance, vsFTPd backdoor analysis (CVE-2011-2523), and active transport-layer mitigation using IPTables.",
                    "url": "https://github.com/IrsaAttiqueCyber/SystemVulnerabilityChecklist_Project4_Decodelabs"
                },
                {
                    "repository": "PoC-in-GitHub · alexojocyber/cve-2011-2523-vsftpd-validation-lab",
                    "author": "alexojocyber",
                    "first_seen": "2026-08-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Authorized Kali–Metasploitable2 lab using Python and Nmap NSE to validate CVE-2011-2523 in vsFTPd 2.3.4.",
                    "summary": "Authorized Kali–Metasploitable2 lab using Python and Nmap NSE to validate CVE-2011-2523 in vsFTPd 2.3.4.",
                    "url": "https://github.com/alexojocyber/cve-2011-2523-vsftpd-validation-lab"
                },
                {
                    "repository": "PoC-in-GitHub · sonalisarkar-2003/FTP-vsFTPD-CVE-2011-2523-VAPT-Report",
                    "author": "sonalisarkar-2003",
                    "first_seen": "2026-08-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2011-2523 repository",
                    "summary": "",
                    "url": "https://github.com/sonalisarkar-2003/FTP-vsFTPD-CVE-2011-2523-VAPT-Report"
                },
                {
                    "repository": "PoC-in-GitHub · aish19siddiqua-commits/mtechweek_04",
                    "author": "aish19siddiqua-commits",
                    "first_seen": "2026-08-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.",
                    "summary": "Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.",
                    "url": "https://github.com/aish19siddiqua-commits/mtechweek_04"
                },
                {
                    "repository": "PoC-in-GitHub · rsakthikumar-cmd/metasploitable2-vsftpd-writeup",
                    "author": "rsakthikumar-cmd",
                    "first_seen": "2026-08-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploiting the vsftpd 2.3.4 backdoor (CVE-2011-2523) on Metasploitable2 — a hands-on pentesting lab writeup covering recon, exploitation, and remediation.",
                    "summary": "Exploiting the vsftpd 2.3.4 backdoor (CVE-2011-2523) on Metasploitable2 — a hands-on pentesting lab writeup covering recon, exploitation, and remediation.",
                    "url": "https://github.com/rsakthikumar-cmd/metasploitable2-vsftpd-writeup"
                },
                {
                    "repository": "PoC-in-GitHub · Gvln-S/CVE-2011-2523",
                    "author": "Gvln-S",
                    "first_seen": "2026-08-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2011-2523 repository",
                    "summary": "",
                    "url": "https://github.com/Gvln-S/CVE-2011-2523"
                },
                {
                    "repository": "PoC-in-GitHub · ronankongala/metasploit-pentest-report",
                    "author": "ronankongala",
                    "first_seen": "2026-08-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Authorized penetration test against Metasploitable2 and TryHackMe Blue. 3 CVEs exploited (CVE-2011-2523, CVE-2007-2447, CVE-2017-0144), 4 findings with CVSS scoring and MITRE ATT&CK mapping.",
                    "summary": "Authorized penetration test against Metasploitable2 and TryHackMe Blue. 3 CVEs exploited (CVE-2011-2523, CVE-2007-2447, CVE-2017-0144), 4 findings with CVSS scoring and MITRE ATT&CK mapping.",
                    "url": "https://github.com/ronankongala/metasploit-pentest-report"
                },
                {
                    "repository": "PoC-in-GitHub · aboubacar70/LAB1-metasploitable",
                    "author": "aboubacar70",
                    "first_seen": "2026-09-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploitation des vulnérabilités sur la version vsftpd 2.3.4 du service ftp (CVE-2011-2523)",
                    "summary": "Exploitation des vulnérabilités sur la version vsftpd 2.3.4 du service ftp (CVE-2011-2523)",
                    "url": "https://github.com/aboubacar70/LAB1-metasploitable"
                },
                {
                    "repository": "PoC-in-GitHub · JUN41DS2709/vsFTPd-2.3.4-Exploit",
                    "author": "JUN41DS2709",
                    "first_seen": "2026-09-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Python exploit for the vsFTPd 2.3.4 backdoor (CVE-2011-2523).",
                    "summary": "Python exploit for the vsFTPd 2.3.4 backdoor (CVE-2011-2523).",
                    "url": "https://github.com/JUN41DS2709/vsFTPd-2.3.4-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · samirchapagain/metasploit-lab-report",
                    "author": "samirchapagain",
                    "first_seen": "2026-09-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Educational penetration testing lab report demonstrating exploitation of  vsftpd 2.3.4 backdoor vulnerability (CVE-2011-2523) in Metasploitable 2  using Metasploit Framework. Includes detailed documentation of reconnaissance, vulnerability analysis, configuration, verification, and exploitation phases.",
                    "summary": "Educational penetration testing lab report demonstrating exploitation of  vsftpd 2.3.4 backdoor vulnerability (CVE-2011-2523) in Metasploitable 2  using Metasploit Framework. Includes detailed documentation of reconnaissance, vulnerability analysis, configuration, verification, and exploitation phases.",
                    "url": "https://github.com/samirchapagain/metasploit-lab-report"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/49757",
                "https://www.exploit-db.com/exploits/17491",
                "https://github.com/HerculesRD/vsftpd2.3.4PyExploit",
                "https://github.com/nobodyatall648/CVE-2011-2523",
                "https://github.com/Gr4ykt/CVE-2011-2523",
                "https://github.com/padsalatushal/CVE-2011-2523",
                "https://github.com/MFernstrom/OffensivePascal-CVE-2011-2523",
                "https://github.com/0xSojalSec/-CVE-2011-2523",
                "https://github.com/0xSojalSec/CVE-2011-2523",
                "https://github.com/XiangSi-Howard/CTF---CVE-2011-2523",
                "https://github.com/cowsecurity/CVE-2011-2523",
                "https://github.com/Lynk4/CVE-2011-2523",
                "https://github.com/vaishnavucv/CVE-2011-2523",
                "https://github.com/4m3rr0r/CVE-2011-2523-poc",
                "https://github.com/Shubham-2k1/Exploit-CVE-2011-2523",
                "https://github.com/Tenor-Z/SmileySploit",
                "https://github.com/0xB0y426/CVE-2011-2523-PoC",
                "https://github.com/AnugiArrawwala/CVE-Research",
                "https://github.com/Gill-Singh-A/vsFTP-2.3.4-Remote-Root-Shell-Exploit",
                "https://github.com/Lychi3/vsftpd-backdoor",
                "https://github.com/vedpakhare/vsftpd-234-vuln-report",
                "https://github.com/cybermads/CVE-2011-2523",
                "https://github.com/sug4r-wr41th/CVE-2011-2523",
                "https://github.com/JohanMV/explotacion-vsftpd-nmap_Laboratorio_1",
                "https://github.com/lghost256/vsftpd234-exploit",
                "https://github.com/hklabCR/CVE-2011-2523",
                "https://github.com/krill-x7/CVE-2011-2523",
                "https://github.com/BolivarJ/CVE-2011-2523",
                "https://github.com/KlyneZyro/Metasploitable2-VAPT-Report",
                "https://github.com/Mirza-22144/Vulnerability-Assessment-Exploitation-Lab",
                "https://github.com/tshaq17/vsftpd-2.3.4---Backdoor-Command-Execution",
                "https://github.com/Efehamzaa/Metasploit-Red-Pentest-Lab",
                "https://github.com/yagnikkrish/metasploitable-penetration-testing-lab",
                "https://github.com/brettsm/vsftpd2.3.4-backdoor-exploit",
                "https://github.com/Tr00jan99/PwnTillDawn-Portal-Walkthrough",
                "https://github.com/Dahalsamir/CVE-2011-2523-exploit",
                "https://github.com/RinAliyeva/metasploitable2-vsftpd-exploitation",
                "https://github.com/emilebarnard242/pentest-metasploitable2",
                "https://github.com/Mithileshan/soc-investigation-lab",
                "https://github.com/IvoAlbacete/Kali-Metasploitable",
                "https://github.com/Amirmuhammadmarvi/network-security-lab",
                "https://github.com/Prafullya-Shandilya/metasploitable-pentest-report",
                "https://github.com/Taisa456/network-security-snort",
                "https://github.com/ByteForgeFr/CVE-2011-2523",
                "https://github.com/Jhatchi/NexaCorp-DFIR-INC-2026-001",
                "https://github.com/Chathura123git/ethical-hacking-CVE-2011-2523",
                "https://github.com/NitinSukthe-G/OpenVAS-Vulnerability-Assessment-Incident-Response",
                "https://github.com/H4R335HR/vsftpd-234-backdoor",
                "https://github.com/kn9annihilator/CVE-2011-2523-vsFTPd-2.3.4-Writeup",
                "https://github.com/Orevic21/wazuh-home-soc",
                "https://github.com/solomonhenry-afk/vsftpd-cve-2011-2523-detection-signature",
                "https://github.com/IndiQuarks/vsftpd-cve-2011-2523-lab",
                "https://github.com/khalilu020/offensive-security-adversary-emulation",
                "https://github.com/IrsaAttiqueCyber/SystemVulnerabilityChecklist_Project4_Decodelabs",
                "https://github.com/alexojocyber/cve-2011-2523-vsftpd-validation-lab",
                "https://github.com/sonalisarkar-2003/FTP-vsFTPD-CVE-2011-2523-VAPT-Report",
                "https://github.com/aish19siddiqua-commits/mtechweek_04",
                "https://github.com/rsakthikumar-cmd/metasploitable2-vsftpd-writeup",
                "https://github.com/Gvln-S/CVE-2011-2523",
                "https://github.com/ronankongala/metasploit-pentest-report",
                "https://github.com/aboubacar70/LAB1-metasploitable",
                "https://github.com/JUN41DS2709/vsFTPd-2.3.4-Exploit",
                "https://github.com/samirchapagain/metasploit-lab-report"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/49757"
                }
            ]
        },
        {
            "id": "CVE-2011-1136",
            "vendor": "n/a",
            "product": "n/a",
            "title": "n/a vulnerability",
            "summary": "In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.",
            "updated_at": "2026-09-14T14:10:44.773",
            "published_at": "2019-11-14T01:15:10.727",
            "cvss": 4.7,
            "cvss_vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "n/a",
            "fixed": "See vendor advisory",
            "source_count": 22,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Low",
            "complexity": "High",
            "cwe": "CWE-59",
            "what_happened": "In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file.",
            "why_matters": "Review the vendor advisory and exposure of the affected product to determine operational impact.",
            "mitigations": [
                "Apply vendor-provided updates or mitigations.",
                "Review affected product exposure and access logs."
            ],
            "pocs": [
                {
                    "repository": "bugs.debian.org",
                    "author": "NVD reference",
                    "first_seen": "2019-11-14",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=612032"
                },
                {
                    "repository": "bugs.launchpad.net",
                    "author": "NVD reference",
                    "first_seen": "2019-11-14",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "url": "https://bugs.launchpad.net/ubuntu/+source/tesseract/+bug/607297"
                }
            ],
            "references": [
                "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=612032",
                "https://bugs.launchpad.net/ubuntu/+source/tesseract/+bug/607297",
                "https://security-tracker.debian.org/tracker/CVE-2011-1136"
            ],
            "timeline": [
                {
                    "at": "2019-11-14T01:15:10.727",
                    "label": "CVE record published by NVD",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-1136"
                }
            ]
        },
        {
            "id": "CVE-2011-0104",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Microsoft Excel - Remote Buffer Overflow",
            "summary": "Microsoft Excel - Remote Buffer Overflow",
            "updated_at": "2026-09-08T14:31:18Z",
            "published_at": "2026-09-08T14:31:18Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 123,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Reproduction of CVE-2011-0104 with tools in a repository without README.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 35573",
                    "author": "Rodrigo Rubira Branco",
                    "first_seen": "2011-04-12",
                    "confidence": "High",
                    "title": "Microsoft Excel - Remote Buffer Overflow",
                    "summary": "Microsoft Excel - Remote Buffer Overflow",
                    "url": "https://www.exploit-db.com/exploits/35573",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2011-0104-reproduction",
                    "summary": "Reproduction of CVE-2011-0104 with tools in a repository without README.",
                    "what_happened": "Reproduction of CVE-2011-0104 with tools in a repository without README.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SUNQIZ-CVE-2011-0104-REPRODUCTION",
                        "https://kitploit.com/ar/tools/github/sunqiz/cve-2011-0104-reproduction/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-06T11:52:09",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SUNQIZ-CVE-2011-0104-REPRODUCTION"
                },
                {
                    "title": "Exploit for CVE-2011-0104-reproduction",
                    "summary": "Reproduction of CVE-2011-0104 with tools in a repository without README.",
                    "what_happened": "Reproduction of CVE-2011-0104 with tools in a repository without README.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SUNQIZ-CVE-2011-0104-REPRODUCTION",
                        "https://kitploit.com/ar/tools/github/sunqiz/cve-2011-0104-reproduction/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ar",
                    "first_seen": "2026-09-06T11:52:09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ar/tools/github/sunqiz/cve-2011-0104-reproduction/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/35573",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SUNQIZ-CVE-2011-0104-REPRODUCTION",
                "https://kitploit.com/ar/tools/github/sunqiz/cve-2011-0104-reproduction/"
            ],
            "timeline": [
                {
                    "at": "2026-09-08T14:31:18Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/35573"
                }
            ]
        },
        {
            "id": "CVE-2010-4221",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "ProFTPd 1.3.2 rc3 < 1.3.3b (FreeBSD) - Telnet IAC Buffer Overflow (Metasploit)",
            "summary": "ProFTPd 1.3.2 rc3 < 1.3.3b (FreeBSD) - Telnet IAC Buffer Overflow (Metasploit)",
            "updated_at": "2026-09-07T22:00:00Z",
            "published_at": "2026-09-07T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 259,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 16878",
                    "author": "Metasploit",
                    "first_seen": "2010-12-02",
                    "confidence": "High",
                    "title": "ProFTPd 1.3.2 rc3 < 1.3.3b (FreeBSD) - Telnet IAC Buffer Overflow (Metasploit)",
                    "summary": "ProFTPd 1.3.2 rc3 < 1.3.3b (FreeBSD) - Telnet IAC Buffer Overflow (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/16878",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 16851",
                    "author": "Metasploit",
                    "first_seen": "2011-01-09",
                    "confidence": "High",
                    "title": "ProFTPd 1.3.2 rc3 < 1.3.3b (Linux) - Telnet IAC Buffer Overflow (Metasploit)",
                    "summary": "ProFTPd 1.3.2 rc3 < 1.3.3b (Linux) - Telnet IAC Buffer Overflow (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/16851",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 15449",
                    "author": "kingcope",
                    "first_seen": "2010-11-07",
                    "confidence": "High",
                    "title": "ProFTPd IAC 1.3.x - Remote Command Execution",
                    "summary": "ProFTPd IAC 1.3.x - Remote Command Execution",
                    "url": "https://www.exploit-db.com/exploits/15449",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · M41doror/cve-2010-4221",
                    "author": "M41doror",
                    "first_seen": "2017-10-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "This exploit was written to study some concepts, enjoy!",
                    "summary": "This exploit was written to study some concepts, enjoy!",
                    "url": "https://github.com/M41doror/cve-2010-4221"
                },
                {
                    "repository": "PoC-in-GitHub · Mafiosohack/Offensive-lab-2",
                    "author": "Mafiosohack",
                    "first_seen": "2025-12-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Penetration test walkthrough on a vulnerable Ubuntu VM. Exploited the ProFTPD 1.3.3c backdoor (CVE-2010-4221) to gain root access and capture the flag. Includes Nmap enumeration, Metasploit payload setup, and user hash cracking (John the Ripper).",
                    "summary": "Penetration test walkthrough on a vulnerable Ubuntu VM. Exploited the ProFTPD 1.3.3c backdoor (CVE-2010-4221) to gain root access and capture the flag. Includes Nmap enumeration, Metasploit payload setup, and user hash cracking (John the Ripper).",
                    "url": "https://github.com/Mafiosohack/Offensive-lab-2"
                },
                {
                    "repository": "PoC-in-GitHub · diegslva/cve-2010-4221-lab",
                    "author": "diegslva",
                    "first_seen": "2026-09-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "From patch to RCE: hand-built exploit for CVE-2010-4221 (ProFTPD TELNET IAC stack overflow), with the full failure-driven journey documented",
                    "summary": "From patch to RCE: hand-built exploit for CVE-2010-4221 (ProFTPD TELNET IAC stack overflow), with the full failure-driven journey documented",
                    "url": "https://github.com/diegslva/cve-2010-4221-lab"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/16878",
                "https://www.exploit-db.com/exploits/16851",
                "https://www.exploit-db.com/exploits/15449",
                "https://github.com/M41doror/cve-2010-4221",
                "https://github.com/Mafiosohack/Offensive-lab-2",
                "https://github.com/diegslva/cve-2010-4221-lab"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/16878"
                }
            ]
        },
        {
            "id": "CVE-2010-1240",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Adobe PDF - Embedded EXE Social Engineering (Metasploit)",
            "summary": "Adobe PDF - Embedded EXE Social Engineering (Metasploit)",
            "updated_at": "2026-09-07T08:10:22Z",
            "published_at": "2026-09-07T08:10:22Z",
            "cvss": 9.3,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 280,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Adobe Reader/Acrobat 9.x and 8.x Launch File dialog lets users execute arbitrary programs via PDF.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 16671",
                    "author": "Metasploit",
                    "first_seen": "2010-12-16",
                    "confidence": "High",
                    "title": "Adobe PDF - Embedded EXE Social Engineering (Metasploit)",
                    "summary": "Adobe PDF - Embedded EXE Social Engineering (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/16671",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 16682",
                    "author": "Metasploit",
                    "first_seen": "2010-12-16",
                    "confidence": "High",
                    "title": "Adobe PDF - Escape EXE Social Engineering (No JavaScript) (Metasploit)",
                    "summary": "Adobe PDF - Escape EXE Social Engineering (No JavaScript) (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/16682",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 11987",
                    "author": "Didier Stevens",
                    "first_seen": "2010-03-31",
                    "confidence": "High",
                    "title": "Adobe Reader - Escape From '.PDF' Execute Embedded Executable",
                    "summary": "Adobe Reader - Escape From '.PDF' Execute Embedded Executable",
                    "url": "https://www.exploit-db.com/exploits/11987",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2010-1240",
                    "summary": "Adobe Reader/Acrobat 9.x and 8.x Launch File dialog lets users execute arbitrary programs via PDF.",
                    "what_happened": "Adobe Reader/Acrobat 9.x and 8.x Launch File dialog lets users execute arbitrary programs via PDF.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ASEPSAEPDIN-CVE-2010-1240",
                        "https://kitploit.com/ru/tools/github/asepsaepdin/cve-2010-1240/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-02T11:39:21",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ASEPSAEPDIN-CVE-2010-1240"
                },
                {
                    "title": "Exploit for CVE-2010-1240",
                    "summary": "Adobe Reader/Acrobat 9.x and 8.x Launch File dialog lets users execute arbitrary programs via PDF.",
                    "what_happened": "Adobe Reader/Acrobat 9.x and 8.x Launch File dialog lets users execute arbitrary programs via PDF.",
                    "cvss": 9.3,
                    "cvss_vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ASEPSAEPDIN-CVE-2010-1240",
                        "https://kitploit.com/ru/tools/github/asepsaepdin/cve-2010-1240/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-02T11:39:21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/asepsaepdin/cve-2010-1240/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/16671",
                "https://www.exploit-db.com/exploits/16682",
                "https://www.exploit-db.com/exploits/11987",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-ASEPSAEPDIN-CVE-2010-1240",
                "https://kitploit.com/ru/tools/github/asepsaepdin/cve-2010-1240/"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T08:10:22Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/16671"
                }
            ]
        },
        {
            "id": "CVE-2009-3103",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Microsoft Windows - SMB2 Negotiate Protocol '0x72' Response Denial of Service",
            "summary": "Microsoft Windows - SMB2 Negotiate Protocol '0x72' Response Denial of Service",
            "updated_at": "2026-09-05T12:41:05Z",
            "published_at": "2026-09-05T12:41:05Z",
            "cvss": 10,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 541,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 12524",
                    "author": "Jelmer de Hen",
                    "first_seen": "2010-05-07",
                    "confidence": "High",
                    "title": "Microsoft Windows - SMB2 Negotiate Protocol '0x72' Response Denial of Service",
                    "summary": "Microsoft Windows - SMB2 Negotiate Protocol '0x72' Response Denial of Service",
                    "url": "https://www.exploit-db.com/exploits/12524",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 10005",
                    "author": "laurent gaffie",
                    "first_seen": "2009-11-11",
                    "confidence": "High",
                    "title": "Microsoft Windows 7/2008 R2 - Remote Kernel Crash",
                    "summary": "Microsoft Windows 7/2008 R2 - Remote Kernel Crash",
                    "url": "https://www.exploit-db.com/exploits/10005",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 9594",
                    "author": "laurent gaffie",
                    "first_seen": "2009-09-09",
                    "confidence": "High",
                    "title": "Microsoft Windows Vista/7 - SMB2.0 Negotiate Protocol Request Remote Blue Screen of Death (MS07-063)",
                    "summary": "Microsoft Windows Vista/7 - SMB2.0 Negotiate Protocol Request Remote Blue Screen of Death (MS07-063)",
                    "url": "https://www.exploit-db.com/exploits/9594",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 40280",
                    "author": "ohnozzy",
                    "first_seen": "2016-02-26",
                    "confidence": "High",
                    "title": "Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)",
                    "summary": "Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)",
                    "url": "https://www.exploit-db.com/exploits/40280",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 14674",
                    "author": "Piotr Bania",
                    "first_seen": "2010-08-17",
                    "confidence": "High",
                    "title": "Microsoft Windows - 'srv2.sys' SMB Negotiate ProcessID Function Table Dereference (MS09-050)",
                    "summary": "Microsoft Windows - 'srv2.sys' SMB Negotiate ProcessID Function Table Dereference (MS09-050)",
                    "url": "https://www.exploit-db.com/exploits/14674",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 16363",
                    "author": "Metasploit",
                    "first_seen": "2010-07-03",
                    "confidence": "High",
                    "title": "Microsoft Windows - 'srv2.sys' SMB Negotiate ProcessID Function Table Dereference (MS09-050) (Metasploit)",
                    "summary": "Microsoft Windows - 'srv2.sys' SMB Negotiate ProcessID Function Table Dereference (MS09-050) (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/16363",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-05T12:41:05+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "ms09-050_CVE-2009-3103 exploit",
                    "summary": "Exploit for CVE-2009-3103. CVSS 10.",
                    "cvss": 10,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SEC13B-MS09-050_CVE-2009-3103"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/12524",
                "https://www.exploit-db.com/exploits/10005",
                "https://www.exploit-db.com/exploits/9594",
                "https://www.exploit-db.com/exploits/40280",
                "https://www.exploit-db.com/exploits/14674",
                "https://www.exploit-db.com/exploits/16363",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-SEC13B-MS09-050_CVE-2009-3103"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T12:41:05Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/12524"
                }
            ]
        },
        {
            "id": "CVE-2009-2265",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Adobe ColdFusion 8 - Remote Command Execution (RCE)",
            "summary": "Adobe ColdFusion 8 - Remote Command Execution (RCE)",
            "updated_at": "2026-09-14T22:00:00Z",
            "published_at": "2026-09-14T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 43,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 50057",
                    "author": "Pergyz",
                    "first_seen": "2021-06-24",
                    "confidence": "High",
                    "title": "Adobe ColdFusion 8 - Remote Command Execution (RCE)",
                    "summary": "Adobe ColdFusion 8 - Remote Command Execution (RCE)",
                    "url": "https://www.exploit-db.com/exploits/50057",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 16788",
                    "author": "Metasploit",
                    "first_seen": "2010-11-24",
                    "confidence": "High",
                    "title": "ColdFusion 8.0.1 - Arbitrary File Upload / Execution (Metasploit)",
                    "summary": "ColdFusion 8.0.1 - Arbitrary File Upload / Execution (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/16788",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · zaphoxx/zaphoxx-coldfusion",
                    "author": "zaphoxx",
                    "first_seen": "2020-10-02",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "coldfusion exploit based on https://cvedetails.com/cve/CVE-2009-2265/",
                    "summary": "coldfusion exploit based on https://cvedetails.com/cve/CVE-2009-2265/",
                    "url": "https://github.com/zaphoxx/zaphoxx-coldfusion"
                },
                {
                    "repository": "PoC-in-GitHub · h3x0v3rl0rd/CVE-2009-2265",
                    "author": "h3x0v3rl0rd",
                    "first_seen": "2021-07-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2009-2265 repository",
                    "summary": "",
                    "url": "https://github.com/h3x0v3rl0rd/CVE-2009-2265"
                },
                {
                    "repository": "PoC-in-GitHub · p1ckzi/CVE-2009-2265",
                    "author": "p1ckzi",
                    "first_seen": "2022-01-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "cf8-upload.py | CVE-2009-2265",
                    "summary": "cf8-upload.py | CVE-2009-2265",
                    "url": "https://github.com/p1ckzi/CVE-2009-2265"
                },
                {
                    "repository": "PoC-in-GitHub · 0xDTC/Adobe-ColdFusion-8-RCE-CVE-2009-2265",
                    "author": "0xDTC",
                    "first_seen": "2024-12-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Adobe ColdFusion 8 - Remote Command Execution (RCE)",
                    "summary": "Adobe ColdFusion 8 - Remote Command Execution (RCE)",
                    "url": "https://github.com/0xDTC/Adobe-ColdFusion-8-RCE-CVE-2009-2265"
                },
                {
                    "repository": "PoC-in-GitHub · nika0x38/CVE-2009-2265",
                    "author": "nika0x38",
                    "first_seen": "2025-09-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A Rust implementation of the POC for the CVE-2009-2265 exploit, targeting Adobe ColdFusion 8.",
                    "summary": "A Rust implementation of the POC for the CVE-2009-2265 exploit, targeting Adobe ColdFusion 8.",
                    "url": "https://github.com/nika0x38/CVE-2009-2265"
                },
                {
                    "repository": "PoC-in-GitHub · matesz44/CVE-2009-2265",
                    "author": "matesz44",
                    "first_seen": "2026-01-12",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "posix sh poc for CVE-2009-2265 (deps: curl,msfvenom,uuidgen,tr)",
                    "summary": "posix sh poc for CVE-2009-2265 (deps: curl,msfvenom,uuidgen,tr)",
                    "url": "https://github.com/matesz44/CVE-2009-2265"
                },
                {
                    "repository": "PoC-in-GitHub · hd-exe/CVE-2009-2265-fix",
                    "author": "hd-exe",
                    "first_seen": "2026-09-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "fix for not working exploit script on exploitdb (50057.py)",
                    "summary": "fix for not working exploit script on exploitdb (50057.py)",
                    "url": "https://github.com/hd-exe/CVE-2009-2265-fix"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/50057",
                "https://www.exploit-db.com/exploits/16788",
                "https://github.com/zaphoxx/zaphoxx-coldfusion",
                "https://github.com/h3x0v3rl0rd/CVE-2009-2265",
                "https://github.com/p1ckzi/CVE-2009-2265",
                "https://github.com/0xDTC/Adobe-ColdFusion-8-RCE-CVE-2009-2265",
                "https://github.com/nika0x38/CVE-2009-2265",
                "https://github.com/matesz44/CVE-2009-2265",
                "https://github.com/hd-exe/CVE-2009-2265-fix"
            ],
            "timeline": [
                {
                    "at": "2026-09-14T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/50057"
                }
            ]
        },
        {
            "id": "CVE-2009-1185",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Linux Kernel 2.6 (Debian 4.0 / Ubuntu / Gentoo) UDEV < 1.4.1 - Local Privilege Escalation (1)",
            "summary": "Linux Kernel 2.6 (Debian 4.0 / Ubuntu / Gentoo) UDEV < 1.4.1 - Local Privilege Escalation (1)",
            "updated_at": "2026-09-06T22:00:00Z",
            "published_at": "2026-09-06T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 270,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 8478",
                    "author": "kingcope",
                    "first_seen": "2009-04-20",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6 (Debian 4.0 / Ubuntu / Gentoo) UDEV < 1.4.1 - Local Privilege Escalation (1)",
                    "summary": "Linux Kernel 2.6 (Debian 4.0 / Ubuntu / Gentoo) UDEV < 1.4.1 - Local Privilege Escalation (1)",
                    "url": "https://www.exploit-db.com/exploits/8478",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 8572",
                    "author": "Jon Oberheide",
                    "first_seen": "2009-04-30",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6 (Gentoo / Ubuntu 8.10/9.04) UDEV < 1.4.1 - Local Privilege Escalation (2)",
                    "summary": "Linux Kernel 2.6 (Gentoo / Ubuntu 8.10/9.04) UDEV < 1.4.1 - Local Privilege Escalation (2)",
                    "url": "https://www.exploit-db.com/exploits/8572",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 21848",
                    "author": "Metasploit",
                    "first_seen": "2012-10-10",
                    "confidence": "High",
                    "title": "Linux Kernel UDEV < 1.4.1 - 'Netlink' Local Privilege Escalation (Metasploit)",
                    "summary": "Linux Kernel UDEV < 1.4.1 - 'Netlink' Local Privilege Escalation (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/21848",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · aish19siddiqua-commits/mtechweek_04",
                    "author": "aish19siddiqua-commits",
                    "first_seen": "2026-08-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.",
                    "summary": "Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.",
                    "url": "https://github.com/aish19siddiqua-commits/mtechweek_04"
                },
                {
                    "repository": "PoC-in-GitHub · 0b0111100/2009",
                    "author": "0b0111100",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Linux Kernel Exploits -> CVE-2009-1185  + CVE-2009-1337 + CVE-2009-2692 + CVE-2009-2698 + CVE-2009-3547",
                    "summary": "Linux Kernel Exploits -> CVE-2009-1185  + CVE-2009-1337 + CVE-2009-2692 + CVE-2009-2698 + CVE-2009-3547",
                    "url": "https://github.com/0b0111100/2009"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/8478",
                "https://www.exploit-db.com/exploits/8572",
                "https://www.exploit-db.com/exploits/21848",
                "https://github.com/aish19siddiqua-commits/mtechweek_04",
                "https://github.com/0b0111100/2009"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/8478"
                }
            ]
        },
        {
            "id": "CVE-2009-0658",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Adobe Acrobat Reader - JBIG2 Local Buffer Overflow (PoC) (2)",
            "summary": "Adobe Acrobat Reader - JBIG2 Local Buffer Overflow (PoC) (2)",
            "updated_at": "2026-08-22T22:00:00Z",
            "published_at": "2026-08-22T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 153,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 8099",
                    "author": "Guido Landi",
                    "first_seen": "2009-02-23",
                    "confidence": "High",
                    "title": "Adobe Acrobat Reader - JBIG2 Local Buffer Overflow (PoC) (2)",
                    "summary": "Adobe Acrobat Reader - JBIG2 Local Buffer Overflow (PoC) (2)",
                    "url": "https://www.exploit-db.com/exploits/8099",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 16593",
                    "author": "Metasploit",
                    "first_seen": "2010-06-15",
                    "confidence": "High",
                    "title": "Adobe - JBIG2Decode Memory Corruption (Metasploit) (1)",
                    "summary": "Adobe - JBIG2Decode Memory Corruption (Metasploit) (1)",
                    "url": "https://www.exploit-db.com/exploits/16593",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 16672",
                    "author": "Metasploit",
                    "first_seen": "2010-09-25",
                    "confidence": "High",
                    "title": "Adobe - JBIG2Decode Memory Corruption (Metasploit) (2)",
                    "summary": "Adobe - JBIG2Decode Memory Corruption (Metasploit) (2)",
                    "url": "https://www.exploit-db.com/exploits/16672",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · kyaw-tun/blue-team-capstone",
                    "author": "kyaw-tun",
                    "first_seen": "2026-08-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVSS v3.1 assessment of CVE-2009-0658 (Adobe Acrobat Buffer Overflow), including Base, Temporal, and Environmental scoring and remediation recommendations.",
                    "summary": "CVSS v3.1 assessment of CVE-2009-0658 (Adobe Acrobat Buffer Overflow), including Base, Temporal, and Environmental scoring and remediation recommendations.",
                    "url": "https://github.com/kyaw-tun/blue-team-capstone"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/8099",
                "https://www.exploit-db.com/exploits/16593",
                "https://www.exploit-db.com/exploits/16672",
                "https://github.com/kyaw-tun/blue-team-capstone"
            ],
            "timeline": [
                {
                    "at": "2026-08-22T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/8099"
                }
            ]
        },
        {
            "id": "CVE-2008-0600",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Linux Kernel 2.6.17 < 2.6.24.1 - 'vmsplice' Local Privilege Escalation (2)",
            "summary": "Linux Kernel 2.6.17 < 2.6.24.1 - 'vmsplice' Local Privilege Escalation (2)",
            "updated_at": "2026-09-06T22:00:00Z",
            "published_at": "2026-09-06T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 169,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 5092",
                    "author": "qaaz",
                    "first_seen": "2008-02-09",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.17 < 2.6.24.1 - 'vmsplice' Local Privilege Escalation (2)",
                    "summary": "Linux Kernel 2.6.17 < 2.6.24.1 - 'vmsplice' Local Privilege Escalation (2)",
                    "url": "https://www.exploit-db.com/exploits/5092",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 5093",
                    "author": "qaaz",
                    "first_seen": "2008-02-09",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.23 < 2.6.24 - 'vmsplice' Local Privilege Escalation (1)",
                    "summary": "Linux Kernel 2.6.23 < 2.6.24 - 'vmsplice' Local Privilege Escalation (1)",
                    "url": "https://www.exploit-db.com/exploits/5093",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · 0b0111100/2008",
                    "author": "0b0111100",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Linux Kernel Exploits -> CVE-2008-0600 + CVE-2008-0900 + CVE-2008-4210",
                    "summary": "Linux Kernel Exploits -> CVE-2008-0600 + CVE-2008-0900 + CVE-2008-4210",
                    "url": "https://github.com/0b0111100/2008"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/5092",
                "https://www.exploit-db.com/exploits/5093",
                "https://github.com/0b0111100/2008"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/5092"
                }
            ]
        },
        {
            "id": "CVE-2008-0166",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH",
            "summary": "OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH",
            "updated_at": "2026-09-09T22:00:00Z",
            "published_at": "2026-09-09T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 341,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 5622",
                    "author": "Markus Mueller",
                    "first_seen": "2008-05-15",
                    "confidence": "High",
                    "title": "OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH",
                    "summary": "OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH",
                    "url": "https://www.exploit-db.com/exploits/5622",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 5720",
                    "author": "WarCat team",
                    "first_seen": "2008-06-01",
                    "confidence": "High",
                    "title": "OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH",
                    "summary": "OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH",
                    "url": "https://www.exploit-db.com/exploits/5720",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 5632",
                    "author": "L4teral",
                    "first_seen": "2008-05-16",
                    "confidence": "High",
                    "title": "OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH (Ruby)",
                    "summary": "OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH (Ruby)",
                    "url": "https://www.exploit-db.com/exploits/5632",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · g0tmi1k/debian-ssh",
                    "author": "g0tmi1k",
                    "first_seen": "2013-09-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 411,
                    "title": "Debian OpenSSL Predictable PRNG (CVE-2008-0166)",
                    "summary": "Debian OpenSSL Predictable PRNG (CVE-2008-0166)",
                    "url": "https://github.com/g0tmi1k/debian-ssh"
                },
                {
                    "repository": "PoC-in-GitHub · avarx/vulnkeys",
                    "author": "avarx",
                    "first_seen": "2018-12-31",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Debian OpenSSL Predictable PRNG (CVE-2008-0166)",
                    "summary": "Debian OpenSSL Predictable PRNG (CVE-2008-0166)",
                    "url": "https://github.com/avarx/vulnkeys"
                },
                {
                    "repository": "PoC-in-GitHub · badkeys/debianopenssl",
                    "author": "badkeys",
                    "first_seen": "2022-05-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 7,
                    "title": "Private keys vulnerable to Debian OpenSSL bug (CVE-2008-0166)",
                    "summary": "Private keys vulnerable to Debian OpenSSL bug (CVE-2008-0166)",
                    "url": "https://github.com/badkeys/debianopenssl"
                },
                {
                    "repository": "PoC-in-GitHub · demining/Vulnerable-to-Debian-OpenSSL-bug-CVE-2008-0166",
                    "author": "demining",
                    "first_seen": "2022-08-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 9,
                    "title": "Search for BTC coins on earlier versions of Bitcoin Core with critical vulnerability OpenSSL 0.9.8 CVE-2008-0166",
                    "summary": "Search for BTC coins on earlier versions of Bitcoin Core with critical vulnerability OpenSSL 0.9.8 CVE-2008-0166",
                    "url": "https://github.com/demining/Vulnerable-to-Debian-OpenSSL-bug-CVE-2008-0166"
                },
                {
                    "repository": "PoC-in-GitHub · AhegaoPsyops/sslWeakness",
                    "author": "AhegaoPsyops",
                    "first_seen": "2025-09-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Example script demonstrating a weak PRNG, CVE-2008-0166",
                    "summary": "Example script demonstrating a weak PRNG, CVE-2008-0166",
                    "url": "https://github.com/AhegaoPsyops/sslWeakness"
                },
                {
                    "repository": "PoC-in-GitHub · Faizan8232403/CVE-Exploit-Research-Development",
                    "author": "Faizan8232403",
                    "first_seen": "2026-03-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A professional Python tool designed for educational penetration testing, demonstrating SSH vulnerabilities (CVE-2008-0166 / CVE-2008-1657) with interactive shell access, command logging, and automated PDF/DOCX reporting.",
                    "summary": "A professional Python tool designed for educational penetration testing, demonstrating SSH vulnerabilities (CVE-2008-0166 / CVE-2008-1657) with interactive shell access, command logging, and automated PDF/DOCX reporting.",
                    "url": "https://github.com/Faizan8232403/CVE-Exploit-Research-Development"
                },
                {
                    "repository": "PoC-in-GitHub · QasimShahbaz21/CVE-Exploit-Research-Development",
                    "author": "QasimShahbaz21",
                    "first_seen": "2026-03-18",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "SSH Exploit Tool (Educational Use Only) 📌 Description This tool demonstrates exploitation of:  CVE-2008-0166 CVE-2008-1657 It connects to vulnerable SSH services and provides:  Persistent interactive shell Command execution logging Automatic PDF & DOCX report generation",
                    "summary": "SSH Exploit Tool (Educational Use Only) 📌 Description This tool demonstrates exploitation of:  CVE-2008-0166 CVE-2008-1657 It connects to vulnerable SSH services and provides:  Persistent interactive shell Command execution logging Automatic PDF & DOCX report generation",
                    "url": "https://github.com/QasimShahbaz21/CVE-Exploit-Research-Development"
                },
                {
                    "repository": "PoC-in-GitHub · ethicbrudhack/CVE-2008-0166-BTC-satoshi-mining-wallets",
                    "author": "ethicbrudhack",
                    "first_seen": "2026-09-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2008-0166 repository",
                    "summary": "",
                    "url": "https://github.com/ethicbrudhack/CVE-2008-0166-BTC-satoshi-mining-wallets"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/5622",
                "https://www.exploit-db.com/exploits/5720",
                "https://www.exploit-db.com/exploits/5632",
                "https://github.com/g0tmi1k/debian-ssh",
                "https://github.com/avarx/vulnkeys",
                "https://github.com/badkeys/debianopenssl",
                "https://github.com/demining/Vulnerable-to-Debian-OpenSSL-bug-CVE-2008-0166",
                "https://github.com/AhegaoPsyops/sslWeakness",
                "https://github.com/Faizan8232403/CVE-Exploit-Research-Development",
                "https://github.com/QasimShahbaz21/CVE-Exploit-Research-Development",
                "https://github.com/ethicbrudhack/CVE-2008-0166-BTC-satoshi-mining-wallets"
            ],
            "timeline": [
                {
                    "at": "2026-09-09T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/5622"
                }
            ]
        },
        {
            "id": "CVE-2007-2447",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Samba 3.0.20 < 3.0.25rc3 - 'Username' map script' Command Execution (Metasploit)",
            "summary": "Samba 3.0.20 < 3.0.25rc3 - 'Username' map script' Command Execution (Metasploit)",
            "updated_at": "2026-09-05T08:11:11Z",
            "published_at": "2026-09-05T08:11:11Z",
            "cvss": 6,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 1214,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "Samba usermap script vulnerability enables remote code execution.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 16320",
                    "author": "Metasploit",
                    "first_seen": "2010-08-18",
                    "confidence": "High",
                    "title": "Samba 3.0.20 < 3.0.25rc3 - 'Username' map script' Command Execution (Metasploit)",
                    "summary": "Samba 3.0.20 < 3.0.25rc3 - 'Username' map script' Command Execution (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/16320",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-05T08:11:11+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2007-2447 exploit",
                    "summary": "Exploit for CVE-2007-2447. CVSS 6.",
                    "cvss": 6,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AMRIUNIX-CVE-2007-2447"
                },
                {
                    "title": "Exploit for CVE-2007-2447",
                    "summary": "Samba usermap script vulnerability enables remote code execution.",
                    "what_happened": "Samba usermap script vulnerability enables remote code execution.",
                    "cvss": 6,
                    "cvss_vector": "AV:N/AC:M/Au:S/C:P/I:P/A:P",
                    "attack_vector": "Network",
                    "authentication": "Unknown",
                    "complexity": "Unknown",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AMRIUNIX-CVE-2007-2447",
                        "https://kitploit.com/hi/tools/github/amriunix/cve-2007-2447/"
                    ],
                    "repository": "kitploit.com",
                    "author": "hi",
                    "first_seen": "2026-08-26T06:09:53",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/hi/tools/github/amriunix/cve-2007-2447/"
                },
                {
                    "repository": "PoC-in-GitHub · harshiys/CVE-2007-2447-Exploitation-SIEM-Detection-Lab",
                    "author": "harshiys",
                    "first_seen": "2026-05-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)",
                    "summary": "Isolated AD/Linux attack lab: exploited CVE-2007-2447 via Metasploit, detected with Wazuh SIEM mapped to MITRE ATT&CK (T1190, T1059)",
                    "url": "https://github.com/harshiys/CVE-2007-2447-Exploitation-SIEM-Detection-Lab"
                },
                {
                    "repository": "PoC-in-GitHub · Mboatella25/metasploitable-pentest-lab",
                    "author": "Mboatella25",
                    "first_seen": "2026-07-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Pentest completo sobre Metasploitable: recon con nmap, explotación con Metasploit (CVE-2007-2447), extracción y cracking de credenciales, persistencia SSH",
                    "summary": "Pentest completo sobre Metasploitable: recon con nmap, explotación con Metasploit (CVE-2007-2447), extracción y cracking de credenciales, persistencia SSH",
                    "url": "https://github.com/Mboatella25/metasploitable-pentest-lab"
                },
                {
                    "repository": "PoC-in-GitHub · EthicalHackingLabs/metasploitable2-exploitation-metasploit",
                    "author": "EthicalHackingLabs",
                    "first_seen": "2026-06-26",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Full Metasploit exploitation walkthrough against Metasploitable2 — vsftpd backdoor, Samba CVE-2007-2447, UnrealIRCd backdoor, Netcat exfiltration, and credential cracking prep.",
                    "summary": "Full Metasploit exploitation walkthrough against Metasploitable2 — vsftpd backdoor, Samba CVE-2007-2447, UnrealIRCd backdoor, Netcat exfiltration, and credential cracking prep.",
                    "url": "https://github.com/EthicalHackingLabs/metasploitable2-exploitation-metasploit"
                },
                {
                    "repository": "PoC-in-GitHub · r3vpwnx/CVE-2007-2447",
                    "author": "r3vpwnx",
                    "first_seen": "2026-02-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Samba 3.0.20 CVE-2007-2447 Exploit",
                    "summary": "Samba 3.0.20 CVE-2007-2447 Exploit",
                    "url": "https://github.com/r3vpwnx/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · DesmondHinds94/S22_The_Verification_Protocol",
                    "author": "DesmondHinds94",
                    "first_seen": "2026-05-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "P1 W8 S22 - Metasploit Samba CVE-2007-2447 Exploitation",
                    "summary": "P1 W8 S22 - Metasploit Samba CVE-2007-2447 Exploitation",
                    "url": "https://github.com/DesmondHinds94/S22_The_Verification_Protocol"
                },
                {
                    "repository": "jaden-mas1010/Metasploitable2-Vulnerability-Assessment",
                    "author": "jaden-mas1010",
                    "first_seen": "2026-05-26",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 0,
                    "title": "End‑to‑end Metasploitable2 vulnerability assessment covering reconnaissance, exploitation (vsftpd backdoor, distcc RCE, Samba CVE‑2007‑2447), reverse‑shell handling, and Wireshark traffic analysis. Includes SOC‑style documentation, evidence, and mitigation recommendations.",
                    "summary": "End‑to‑end Metasploitable2 vulnerability assessment covering reconnaissance, exploitation (vsftpd backdoor, distcc RCE, Samba CVE‑2007‑2447), reverse‑shell handling, and Wireshark traffic analysis. Includes SOC‑style documentation, evidence, and mitigation recommendations.",
                    "url": "https://github.com/jaden-mas1010/Metasploitable2-Vulnerability-Assessment"
                },
                {
                    "repository": "PoC-in-GitHub · Youneskc/SMB-Penetration-Testing-NTLM-Relay-Version-2-",
                    "author": "Youneskc",
                    "first_seen": "2026-05-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "SMB Red Team Lab— NTLM Relay via LLMNR Poisoning, CVE-2007-2447, NTLMv2 Hash Cracking & NT AUTHORITY\\SYSTEM on Windows 10",
                    "summary": "SMB Red Team Lab— NTLM Relay via LLMNR Poisoning, CVE-2007-2447, NTLMv2 Hash Cracking & NT AUTHORITY\\SYSTEM on Windows 10",
                    "url": "https://github.com/Youneskc/SMB-Penetration-Testing-NTLM-Relay-Version-2-"
                },
                {
                    "repository": "PoC-in-GitHub · Daviddoctor/Samba-CVE-2007-2447-Exploit-Username-Map-Script",
                    "author": "Daviddoctor",
                    "first_seen": "2026-04-17",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Samba CVE-2007-2447 Exploit",
                    "summary": "Samba CVE-2007-2447 Exploit",
                    "url": "https://github.com/Daviddoctor/Samba-CVE-2007-2447-Exploit-Username-Map-Script"
                },
                {
                    "repository": "Nyabayo/flatiron-pentest-nmap-enum4linux-smb-ftp-samba-metasploitable2-kali-healthcare-report",
                    "author": "Nyabayo",
                    "first_seen": "2026-04-10",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "stars": 0,
                    "title": "flatiron cyberdefense penetration testing scanning enumeration nmap sV sS T4 enum4linux smb ftp vsftpd samba telnet vnc mysql nfs ssh metasploitable2 kali linux healthcare staging cve 2011 2523 cve 2007 2447 cve 2010 2075 vulnerability assessment lab",
                    "summary": "flatiron cyberdefense penetration testing scanning enumeration nmap sV sS T4 enum4linux smb ftp vsftpd samba telnet vnc mysql nfs ssh metasploitable2 kali linux healthcare staging cve 2011 2523 cve 2007 2447 cve 2010 2075 vulnerability assessment lab",
                    "url": "https://github.com/Nyabayo/flatiron-pentest-nmap-enum4linux-smb-ftp-samba-metasploitable2-kali-healthcare-report"
                },
                {
                    "repository": "PoC-in-GitHub · vig9610/Exploiting-Samba-on-Metasploitable-2",
                    "author": "vig9610",
                    "first_seen": "2026-01-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Utilize metasploit from a Kali Linux machine to exploit a well-known samba vulnerability (CVE-2007-2447). This is done in order to infiltrate a Metasploitable 2 machine with a reverse shell to access the root folder. Once this folder has been accessed, it should reveal the /etc/shadow folder which would give proof of compromise.",
                    "summary": "Utilize metasploit from a Kali Linux machine to exploit a well-known samba vulnerability (CVE-2007-2447). This is done in order to infiltrate a Metasploitable 2 machine with a reverse shell to access the root folder. Once this folder has been accessed, it should reveal the /etc/shadow folder which would give proof of compromise.",
                    "url": "https://github.com/vig9610/Exploiting-Samba-on-Metasploitable-2"
                },
                {
                    "repository": "PoC-in-GitHub · amriunix/CVE-2007-2447",
                    "author": "amriunix",
                    "first_seen": "2018-08-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 61,
                    "title": "CVE-2007-2447 - Samba usermap script",
                    "summary": "CVE-2007-2447 - Samba usermap script",
                    "url": "https://github.com/amriunix/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · Unix13/metasploitable2",
                    "author": "Unix13",
                    "first_seen": "2019-07-05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 4,
                    "title": "PHP-CGI-REMOTE_CVE-2012-1823, UnrealIRCd, MySQL, PostgreSQL and SSH bruteforce, VSFTPD2.3.4, samba CVE-2007-2447, JAVA RMI Server, distcc daemon, misconfigured NFS files, etc.",
                    "summary": "PHP-CGI-REMOTE_CVE-2012-1823, UnrealIRCd, MySQL, PostgreSQL and SSH bruteforce, VSFTPD2.3.4, samba CVE-2007-2447, JAVA RMI Server, distcc daemon, misconfigured NFS files, etc.",
                    "url": "https://github.com/Unix13/metasploitable2"
                },
                {
                    "repository": "PoC-in-GitHub · b1fair/smb_usermap",
                    "author": "b1fair",
                    "first_seen": "2019-09-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A simple exploit for CVE-2007-2447",
                    "summary": "A simple exploit for CVE-2007-2447",
                    "url": "https://github.com/b1fair/smb_usermap"
                },
                {
                    "repository": "PoC-in-GitHub · JoseBarrios/CVE-2007-2447",
                    "author": "JoseBarrios",
                    "first_seen": "2020-01-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Remote Command Injection Vulnerability (CVE-2007-2447), allows remote attackers to execute arbitrary commands by specifying a Samba username containing shell meta characters.",
                    "summary": "Remote Command Injection Vulnerability (CVE-2007-2447), allows remote attackers to execute arbitrary commands by specifying a Samba username containing shell meta characters.",
                    "url": "https://github.com/JoseBarrios/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · 3x1t1um/CVE-2007-2447",
                    "author": "3x1t1um",
                    "first_seen": "2020-04-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2007-2447 repository",
                    "summary": "",
                    "url": "https://github.com/3x1t1um/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · xlcc4096/exploit-CVE-2007-2447",
                    "author": "xlcc4096",
                    "first_seen": "2020-12-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit for the vulnerability CVE-2007-2447",
                    "summary": "Exploit for the vulnerability CVE-2007-2447",
                    "url": "https://github.com/xlcc4096/exploit-CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · WildfootW/CVE-2007-2447_Samba_3.0.25rc3",
                    "author": "WildfootW",
                    "first_seen": "2020-12-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2007-2447 repository",
                    "summary": "",
                    "url": "https://github.com/WildfootW/CVE-2007-2447_Samba_3.0.25rc3"
                },
                {
                    "repository": "PoC-in-GitHub · Ziemni/CVE-2007-2447-in-Python",
                    "author": "Ziemni",
                    "first_seen": "2021-02-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "Python implementation of 'Username' map script' RCE Exploit for Samba 3.0.20 < 3.0.25rc3 (CVE-2007-2447).",
                    "summary": "Python implementation of 'Username' map script' RCE Exploit for Samba 3.0.20 < 3.0.25rc3 (CVE-2007-2447).",
                    "url": "https://github.com/Ziemni/CVE-2007-2447-in-Python"
                },
                {
                    "repository": "PoC-in-GitHub · 0xKn/CVE-2007-2447",
                    "author": "0xKn",
                    "first_seen": "2021-03-06",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2007-2447 repository",
                    "summary": "",
                    "url": "https://github.com/0xKn/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · ozuma/CVE-2007-2447",
                    "author": "ozuma",
                    "first_seen": "2021-03-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Exploit Samba",
                    "summary": "Exploit Samba",
                    "url": "https://github.com/ozuma/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · G01d3nW01f/CVE-2007-2447",
                    "author": "G01d3nW01f",
                    "first_seen": "2021-04-16",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "cve-2007-2447 this script was rewrite the part of Metasploit modules to python3",
                    "summary": "cve-2007-2447 this script was rewrite the part of Metasploit modules to python3",
                    "url": "https://github.com/G01d3nW01f/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · Alien0ne/CVE-2007-2447",
                    "author": "Alien0ne",
                    "first_seen": "2021-06-30",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 3,
                    "title": "CVE-2007-2447 - Samba usermap script",
                    "summary": "CVE-2007-2447 - Samba usermap script",
                    "url": "https://github.com/Alien0ne/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · 3t4n/samba-3.0.24-CVE-2007-2447-vunerable-",
                    "author": "3t4n",
                    "first_seen": "2021-07-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2007-2447 repository",
                    "summary": "",
                    "url": "https://github.com/3t4n/samba-3.0.24-CVE-2007-2447-vunerable-"
                },
                {
                    "repository": "PoC-in-GitHub · xbufu/CVE-2007-2447",
                    "author": "xbufu",
                    "first_seen": "2021-10-03",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "Exploit code for CVE-2007-2447 written in Python3.",
                    "summary": "Exploit code for CVE-2007-2447 written in Python3.",
                    "url": "https://github.com/xbufu/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · Nosferatuvjr/Samba-Usermap-exploit",
                    "author": "Nosferatuvjr",
                    "first_seen": "2022-05-10",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2007-2447",
                    "summary": "CVE-2007-2447",
                    "url": "https://github.com/Nosferatuvjr/Samba-Usermap-exploit"
                },
                {
                    "repository": "PoC-in-GitHub · testaross4/CVE-2007-2447",
                    "author": "testaross4",
                    "first_seen": "2022-05-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2007-2447 repository",
                    "summary": "",
                    "url": "https://github.com/testaross4/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · b33m0x00/CVE-2007-2447",
                    "author": "b33m0x00",
                    "first_seen": "2022-07-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2007-2447 samba remote code execution",
                    "summary": "CVE-2007-2447 samba remote code execution",
                    "url": "https://github.com/b33m0x00/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · HerculesRD/PyUsernameMapScriptRCE",
                    "author": "HerculesRD",
                    "first_seen": "2022-08-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2007-2447 exploit written in python to get reverse shell",
                    "summary": "CVE-2007-2447 exploit written in python to get reverse shell",
                    "url": "https://github.com/HerculesRD/PyUsernameMapScriptRCE"
                },
                {
                    "repository": "PoC-in-GitHub · Aviksaikat/CVE-2007-2447",
                    "author": "Aviksaikat",
                    "first_seen": "2022-10-14",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "automated script for exploiting CVE-2007-2447",
                    "summary": "automated script for exploiting CVE-2007-2447",
                    "url": "https://github.com/Aviksaikat/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · h3x0v3rl0rd/CVE-2007-2447",
                    "author": "h3x0v3rl0rd",
                    "first_seen": "2022-10-25",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 5,
                    "title": "Exploit Samba smbd 3.0.20-Debian",
                    "summary": "Exploit Samba smbd 3.0.20-Debian",
                    "url": "https://github.com/h3x0v3rl0rd/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · bdunlap9/CVE-2007-2447_python",
                    "author": "bdunlap9",
                    "first_seen": "2022-12-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Exploit i used in HTB",
                    "summary": "Exploit i used in HTB",
                    "url": "https://github.com/bdunlap9/CVE-2007-2447_python"
                },
                {
                    "repository": "PoC-in-GitHub · MikeRega7/CVE-2007-2447-RCE",
                    "author": "MikeRega7",
                    "first_seen": "2023-06-15",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Samba 3.0.20",
                    "summary": "Samba 3.0.20",
                    "url": "https://github.com/MikeRega7/CVE-2007-2447-RCE"
                },
                {
                    "repository": "PoC-in-GitHub · ShivamDey/Samba-CVE-2007-2447-Exploit",
                    "author": "ShivamDey",
                    "first_seen": "2023-10-21",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2007-2447 repository",
                    "summary": "",
                    "url": "https://github.com/ShivamDey/Samba-CVE-2007-2447-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · Juantos/cve-2007-2447",
                    "author": "Juantos",
                    "first_seen": "2024-01-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Samba 3.0.0 - 3.0.25rc3",
                    "summary": "Samba 3.0.0 - 3.0.25rc3",
                    "url": "https://github.com/Juantos/cve-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · IamLucif3r/CVE-2007-2447-Exploit",
                    "author": "IamLucif3r",
                    "first_seen": "2024-07-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "This is a exploit for CVE-2007-2447; Vulnerable SMB",
                    "summary": "This is a exploit for CVE-2007-2447; Vulnerable SMB",
                    "url": "https://github.com/IamLucif3r/CVE-2007-2447-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · foudadev/CVE-2007-2447",
                    "author": "foudadev",
                    "first_seen": "2024-07-09",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2007-2447 repository",
                    "summary": "",
                    "url": "https://github.com/foudadev/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · elphon/CVE-2007-2447-Exploit",
                    "author": "elphon",
                    "first_seen": "2025-03-08",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2007-2447 repository",
                    "summary": "",
                    "url": "https://github.com/elphon/CVE-2007-2447-Exploit"
                },
                {
                    "repository": "PoC-in-GitHub · DevinLiggins14/SMB-PenTest-Exploiting-CVE-2007-2447-on-Metasploitable-2",
                    "author": "DevinLiggins14",
                    "first_seen": "2025-06-19",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2007-2447 repository",
                    "summary": "",
                    "url": "https://github.com/DevinLiggins14/SMB-PenTest-Exploiting-CVE-2007-2447-on-Metasploitable-2"
                },
                {
                    "repository": "PoC-in-GitHub · MrRoma577/exploit_cve-2007-2447_again",
                    "author": "MrRoma577",
                    "first_seen": "2025-07-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "just remeber how small mistake in santisize username could give yoy root access to the full machine",
                    "summary": "just remeber how small mistake in santisize username could give yoy root access to the full machine",
                    "url": "https://github.com/MrRoma577/exploit_cve-2007-2447_again"
                },
                {
                    "repository": "PoC-in-GitHub · nika0x38/CVE-2007-2447",
                    "author": "nika0x38",
                    "first_seen": "2025-08-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "A standalone Rust implementation of the CVE-2007-2447 exploit targeting Samba smbd 3.0.20-Debian.",
                    "summary": "A standalone Rust implementation of the CVE-2007-2447 exploit targeting Samba smbd 3.0.20-Debian.",
                    "url": "https://github.com/nika0x38/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · SeifEldienAhmad/Penetration-Testing-on-Metasploitable2",
                    "author": "SeifEldienAhmad",
                    "first_seen": "2025-09-13",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "Hands-on pentest project using Kali Linux vs Metasploitable2. Includes full workflow: Nmap scanning, enumeration, Metasploit exploitation (Samba CVE-2007-2447), post-exploitation validation, and mitigation steps. Repo contains commands, outputs, and report showing both offensive techniques and defensive recommendations.",
                    "summary": "Hands-on pentest project using Kali Linux vs Metasploitable2. Includes full workflow: Nmap scanning, enumeration, Metasploit exploitation (Samba CVE-2007-2447), post-exploitation validation, and mitigation steps. Repo contains commands, outputs, and report showing both offensive techniques and defensive recommendations.",
                    "url": "https://github.com/SeifEldienAhmad/Penetration-Testing-on-Metasploitable2"
                },
                {
                    "repository": "PoC-in-GitHub · nulltrace1336/Samba-Exploit-CVE-2007-2447",
                    "author": "nulltrace1336",
                    "first_seen": "2025-12-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2007-2447 repository",
                    "summary": "",
                    "url": "https://github.com/nulltrace1336/Samba-Exploit-CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · abdulsaabir/CVE-2007-2447",
                    "author": "abdulsaabir",
                    "first_seen": "2026-01-04",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2007-2447 repository",
                    "summary": "",
                    "url": "https://github.com/abdulsaabir/CVE-2007-2447"
                },
                {
                    "repository": "PoC-in-GitHub · ronankongala/metasploit-pentest-report",
                    "author": "ronankongala",
                    "first_seen": "2026-08-29",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Authorized penetration test against Metasploitable2 and TryHackMe Blue. 3 CVEs exploited (CVE-2011-2523, CVE-2007-2447, CVE-2017-0144), 4 findings with CVSS scoring and MITRE ATT&CK mapping.",
                    "summary": "Authorized penetration test against Metasploitable2 and TryHackMe Blue. 3 CVEs exploited (CVE-2011-2523, CVE-2007-2447, CVE-2017-0144), 4 findings with CVSS scoring and MITRE ATT&CK mapping.",
                    "url": "https://github.com/ronankongala/metasploit-pentest-report"
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-12T15:07:20+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2007-2447 exploit",
                    "summary": "Exploit for CVE-2007-2447. CVSS 6.",
                    "cvss": 6,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TESTAROSS4-CVE-2007-2447"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/16320",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-AMRIUNIX-CVE-2007-2447",
                "https://kitploit.com/hi/tools/github/amriunix/cve-2007-2447/",
                "https://github.com/harshiys/CVE-2007-2447-Exploitation-SIEM-Detection-Lab",
                "https://github.com/Mboatella25/metasploitable-pentest-lab",
                "https://github.com/EthicalHackingLabs/metasploitable2-exploitation-metasploit",
                "https://github.com/r3vpwnx/CVE-2007-2447",
                "https://github.com/DesmondHinds94/S22_The_Verification_Protocol",
                "https://github.com/jaden-mas1010/Metasploitable2-Vulnerability-Assessment",
                "https://github.com/Youneskc/SMB-Penetration-Testing-NTLM-Relay-Version-2-",
                "https://github.com/Daviddoctor/Samba-CVE-2007-2447-Exploit-Username-Map-Script",
                "https://github.com/Nyabayo/flatiron-pentest-nmap-enum4linux-smb-ftp-samba-metasploitable2-kali-healthcare-report",
                "https://github.com/vig9610/Exploiting-Samba-on-Metasploitable-2",
                "https://github.com/amriunix/CVE-2007-2447",
                "https://github.com/Unix13/metasploitable2",
                "https://github.com/b1fair/smb_usermap",
                "https://github.com/JoseBarrios/CVE-2007-2447",
                "https://github.com/3x1t1um/CVE-2007-2447",
                "https://github.com/xlcc4096/exploit-CVE-2007-2447",
                "https://github.com/WildfootW/CVE-2007-2447_Samba_3.0.25rc3",
                "https://github.com/Ziemni/CVE-2007-2447-in-Python",
                "https://github.com/0xKn/CVE-2007-2447",
                "https://github.com/ozuma/CVE-2007-2447",
                "https://github.com/G01d3nW01f/CVE-2007-2447",
                "https://github.com/Alien0ne/CVE-2007-2447",
                "https://github.com/3t4n/samba-3.0.24-CVE-2007-2447-vunerable-",
                "https://github.com/xbufu/CVE-2007-2447",
                "https://github.com/Nosferatuvjr/Samba-Usermap-exploit",
                "https://github.com/testaross4/CVE-2007-2447",
                "https://github.com/b33m0x00/CVE-2007-2447",
                "https://github.com/HerculesRD/PyUsernameMapScriptRCE",
                "https://github.com/Aviksaikat/CVE-2007-2447",
                "https://github.com/h3x0v3rl0rd/CVE-2007-2447",
                "https://github.com/bdunlap9/CVE-2007-2447_python",
                "https://github.com/MikeRega7/CVE-2007-2447-RCE",
                "https://github.com/ShivamDey/Samba-CVE-2007-2447-Exploit",
                "https://github.com/Juantos/cve-2007-2447",
                "https://github.com/IamLucif3r/CVE-2007-2447-Exploit",
                "https://github.com/foudadev/CVE-2007-2447",
                "https://github.com/elphon/CVE-2007-2447-Exploit",
                "https://github.com/DevinLiggins14/SMB-PenTest-Exploiting-CVE-2007-2447-on-Metasploitable-2",
                "https://github.com/MrRoma577/exploit_cve-2007-2447_again",
                "https://github.com/nika0x38/CVE-2007-2447",
                "https://github.com/SeifEldienAhmad/Penetration-Testing-on-Metasploitable2",
                "https://github.com/nulltrace1336/Samba-Exploit-CVE-2007-2447",
                "https://github.com/abdulsaabir/CVE-2007-2447",
                "https://github.com/ronankongala/metasploit-pentest-report",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-TESTAROSS4-CVE-2007-2447"
            ],
            "timeline": [
                {
                    "at": "2026-09-05T08:11:11Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/16320"
                }
            ]
        },
        {
            "id": "CVE-2006-3392",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure",
            "summary": "Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure",
            "updated_at": "2026-09-13T18:36:41Z",
            "published_at": "2026-09-13T18:36:41Z",
            "cvss": 7.5,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 60,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 1997",
                    "author": "joffer",
                    "first_seen": "2006-07-09",
                    "confidence": "High",
                    "title": "Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure",
                    "summary": "Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure",
                    "url": "https://www.exploit-db.com/exploits/1997",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 2017",
                    "author": "UmZ",
                    "first_seen": "2006-07-15",
                    "confidence": "High",
                    "title": "Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure",
                    "summary": "Webmin < 1.290 / Usermin < 1.220 - Arbitrary File Disclosure",
                    "url": "https://www.exploit-db.com/exploits/2017",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Sploitus",
                    "author": "Sploitus index",
                    "first_seen": "2026-09-13T18:36:41+00:00",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "title": "CVE-2006-3392 exploit",
                    "summary": "Exploit for CVE-2006-3392 and CVE-2021-42913. CVSS 7.5.",
                    "cvss": 7.5,
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KERNEL-CYBER-CVE-2006-3392"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/1997",
                "https://www.exploit-db.com/exploits/2017",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KERNEL-CYBER-CVE-2006-3392"
            ],
            "timeline": [
                {
                    "at": "2026-09-13T18:36:41Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/1997"
                }
            ]
        },
        {
            "id": "CVE-2006-2451",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Linux Kernel 2.6.13 < 2.6.17.4 - 'logrotate prctl()' Local Privilege Escalation",
            "summary": "Linux Kernel 2.6.13 < 2.6.17.4 - 'logrotate prctl()' Local Privilege Escalation",
            "updated_at": "2026-09-06T22:00:00Z",
            "published_at": "2026-09-06T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 370,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 2031",
                    "author": "Marco Ivaldi",
                    "first_seen": "2006-07-18",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.13 < 2.6.17.4 - 'logrotate prctl()' Local Privilege Escalation",
                    "summary": "Linux Kernel 2.6.13 < 2.6.17.4 - 'logrotate prctl()' Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/2031",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 2004",
                    "author": "dreyer & RoMaNSoFt",
                    "first_seen": "2006-07-11",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.13 < 2.6.17.4 - 'sys_prctl()' Local Privilege Escalation (1)",
                    "summary": "Linux Kernel 2.6.13 < 2.6.17.4 - 'sys_prctl()' Local Privilege Escalation (1)",
                    "url": "https://www.exploit-db.com/exploits/2004",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 2005",
                    "author": "Julien Tinnes",
                    "first_seen": "2006-07-12",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.13 < 2.6.17.4 - 'sys_prctl()' Local Privilege Escalation (2)",
                    "summary": "Linux Kernel 2.6.13 < 2.6.17.4 - 'sys_prctl()' Local Privilege Escalation (2)",
                    "url": "https://www.exploit-db.com/exploits/2005",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 2006",
                    "author": "Marco Ivaldi",
                    "first_seen": "2006-07-13",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.13 < 2.6.17.4 - 'sys_prctl()' Local Privilege Escalation (3)",
                    "summary": "Linux Kernel 2.6.13 < 2.6.17.4 - 'sys_prctl()' Local Privilege Escalation (3)",
                    "url": "https://www.exploit-db.com/exploits/2006",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 2011",
                    "author": "Sunay",
                    "first_seen": "2006-07-14",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.13 < 2.6.17.4 - 'sys_prctl()' Local Privilege Escalation (4)",
                    "summary": "Linux Kernel 2.6.13 < 2.6.17.4 - 'sys_prctl()' Local Privilege Escalation (4)",
                    "url": "https://www.exploit-db.com/exploits/2011",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · 0b0111100/2006",
                    "author": "0b0111100",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Linux Kernel Exploits -> CVE-2006-2451 + CVE-2006-3626",
                    "summary": "Linux Kernel Exploits -> CVE-2006-2451 + CVE-2006-3626",
                    "url": "https://github.com/0b0111100/2006"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/2031",
                "https://www.exploit-db.com/exploits/2004",
                "https://www.exploit-db.com/exploits/2005",
                "https://www.exploit-db.com/exploits/2006",
                "https://www.exploit-db.com/exploits/2011",
                "https://github.com/0b0111100/2006"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/2031"
                }
            ]
        },
        {
            "id": "CVE-2005-1263",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Linux Kernel 2.2.x/2.3.x/2.4.x/2.5.x/2.6.x - ELF Core Dump Local Buffer Overflow (PoC)",
            "summary": "Linux Kernel 2.2.x/2.3.x/2.4.x/2.5.x/2.6.x - ELF Core Dump Local Buffer Overflow (PoC)",
            "updated_at": "2026-09-07T06:51:43Z",
            "published_at": "2026-09-07T06:51:43Z",
            "cvss": 7.2,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 144,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Unknown",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 25647",
                    "author": "Paul Starzetz",
                    "first_seen": "2005-05-11",
                    "confidence": "High",
                    "title": "Linux Kernel 2.2.x/2.3.x/2.4.x/2.5.x/2.6.x - ELF Core Dump Local Buffer Overflow (PoC)",
                    "summary": "Linux Kernel 2.2.x/2.3.x/2.4.x/2.5.x/2.6.x - ELF Core Dump Local Buffer Overflow (PoC)",
                    "url": "https://www.exploit-db.com/exploits/25647",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2005-0736 CVE-2005-0736 CVE-2005-1263",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 7.2,
                    "cvss_vector": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Local",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=AE7EC20F-9007-5A4D-A45A-59188DA30067",
                        "https://github.com/0b0111100/2005"
                    ],
                    "repository": "Sploitus",
                    "author": "0b0111100",
                    "first_seen": "2026-09-07T08:51:43",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=AE7EC20F-9007-5A4D-A45A-59188DA30067"
                },
                {
                    "title": "Exploit for CVE-2005-0736 CVE-2005-0736 CVE-2005-1263",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 7.2,
                    "cvss_vector": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Local",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=AE7EC20F-9007-5A4D-A45A-59188DA30067",
                        "https://github.com/0b0111100/2005"
                    ],
                    "repository": "0b0111100/2005",
                    "author": "0b0111100",
                    "first_seen": "2026-09-07T08:51:43",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/0b0111100/2005"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/25647",
                "https://sploitus.com/exploit?id=AE7EC20F-9007-5A4D-A45A-59188DA30067",
                "https://github.com/0b0111100/2005"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T06:51:43Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/25647"
                }
            ],
            "cvss_vector": "AV:L/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
            "id": "CVE-2005-0736",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Linux Kernel 2.6.9 < 2.6.11 (RHEL 4) - 'SYS_EPoll_Wait' Local Integer Overflow / Local Privilege Escalation",
            "summary": "Linux Kernel 2.6.9 < 2.6.11 (RHEL 4) - 'SYS_EPoll_Wait' Local Integer Overflow / Local Privilege Escalation",
            "updated_at": "2026-09-07T06:51:43Z",
            "published_at": "2026-09-07T06:51:43Z",
            "cvss": 7.2,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 213,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "Unknown",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 1397",
                    "author": "alert7",
                    "first_seen": "2005-12-30",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.9 < 2.6.11 (RHEL 4) - 'SYS_EPoll_Wait' Local Integer Overflow / Local Privilege Escalation",
                    "summary": "Linux Kernel 2.6.9 < 2.6.11 (RHEL 4) - 'SYS_EPoll_Wait' Local Integer Overflow / Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/1397",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 25202",
                    "author": "sd",
                    "first_seen": "2005-03-09",
                    "confidence": "High",
                    "title": "Linux Kernel 2.6.x - 'SYS_EPoll_Wait' Local Integer Overflow / Local Privilege Escalation (1)",
                    "summary": "Linux Kernel 2.6.x - 'SYS_EPoll_Wait' Local Integer Overflow / Local Privilege Escalation (1)",
                    "url": "https://www.exploit-db.com/exploits/25202",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for CVE-2005-0736 CVE-2005-0736 CVE-2005-1263",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 7.2,
                    "cvss_vector": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Local",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=AE7EC20F-9007-5A4D-A45A-59188DA30067",
                        "https://github.com/0b0111100/2005"
                    ],
                    "repository": "Sploitus",
                    "author": "0b0111100",
                    "first_seen": "2026-09-07T08:51:43",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Sploitus reports working code with at least 90% confidence.",
                    "url": "https://sploitus.com/exploit?id=AE7EC20F-9007-5A4D-A45A-59188DA30067"
                },
                {
                    "title": "Exploit for CVE-2005-0736 CVE-2005-0736 CVE-2005-1263",
                    "summary": "",
                    "what_happened": "",
                    "cvss": 7.2,
                    "cvss_vector": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
                    "attack_vector": "Local",
                    "authentication": "Unknown",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=AE7EC20F-9007-5A4D-A45A-59188DA30067",
                        "https://github.com/0b0111100/2005"
                    ],
                    "repository": "0b0111100/2005",
                    "author": "0b0111100",
                    "first_seen": "2026-09-07T08:51:43",
                    "confidence": "High",
                    "verification": "verified",
                    "verified": true,
                    "verification_detail": "Linked by a Sploitus working-code assessment.",
                    "url": "https://github.com/0b0111100/2005"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/1397",
                "https://www.exploit-db.com/exploits/25202",
                "https://sploitus.com/exploit?id=AE7EC20F-9007-5A4D-A45A-59188DA30067",
                "https://github.com/0b0111100/2005"
            ],
            "timeline": [
                {
                    "at": "2026-09-07T06:51:43Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/1397"
                }
            ],
            "cvss_vector": "AV:L/AC:L/Au:N/C:C/I:C/A:C"
        },
        {
            "id": "CVE-2004-2687",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "DistCC Daemon - Command Execution (Metasploit)",
            "summary": "DistCC Daemon - Command Execution (Metasploit)",
            "updated_at": "2026-09-10T22:00:00Z",
            "published_at": "2026-09-10T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 180,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 9915",
                    "author": "H D Moore",
                    "first_seen": "2002-02-01",
                    "confidence": "High",
                    "title": "DistCC Daemon - Command Execution (Metasploit)",
                    "summary": "DistCC Daemon - Command Execution (Metasploit)",
                    "url": "https://www.exploit-db.com/exploits/9915",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · h3x0v3rl0rd/distccd_rce_CVE-2004-2687",
                    "author": "h3x0v3rl0rd",
                    "first_seen": "2021-07-01",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 2,
                    "title": "CVE-2004-2687 repository",
                    "summary": "",
                    "url": "https://github.com/h3x0v3rl0rd/distccd_rce_CVE-2004-2687"
                },
                {
                    "repository": "PoC-in-GitHub · k4miyo/CVE-2004-2687",
                    "author": "k4miyo",
                    "first_seen": "2021-08-28",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 1,
                    "title": "CVE-2004-2687 DistCC Daemon Command Execution",
                    "summary": "CVE-2004-2687 DistCC Daemon Command Execution",
                    "url": "https://github.com/k4miyo/CVE-2004-2687"
                },
                {
                    "repository": "PoC-in-GitHub · nulltrace1336/Metasploitable-2-Distcc-Exploit-via-Kali-Linux-CVE-2004-2687",
                    "author": "nulltrace1336",
                    "first_seen": "2025-12-23",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Ushbu videoda Metasploitable 2 tizimidagi distccd servisidagi zaiflikdan foydalanib, Kali Linux orqali remote shell olish ko‘rsatib beriladi.",
                    "summary": "Ushbu videoda Metasploitable 2 tizimidagi distccd servisidagi zaiflikdan foydalanib, Kali Linux orqali remote shell olish ko‘rsatib beriladi.",
                    "url": "https://github.com/nulltrace1336/Metasploitable-2-Distcc-Exploit-via-Kali-Linux-CVE-2004-2687"
                },
                {
                    "repository": "PoC-in-GitHub · micheaol/distccd_rce_CVE-2004-2687",
                    "author": "micheaol",
                    "first_seen": "2026-04-20",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2004-2687 repository",
                    "summary": "",
                    "url": "https://github.com/micheaol/distccd_rce_CVE-2004-2687"
                },
                {
                    "repository": "PoC-in-GitHub · aish19siddiqua-commits/mtechweek_04",
                    "author": "aish19siddiqua-commits",
                    "first_seen": "2026-08-22",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.",
                    "summary": "Metasploit-based penetration test on an isolated Metasploitable2 lab VM — remote exploitation via DistCC (CVE-2004-2687), privilege escalation via udev netlink (CVE-2009-1185), and vsftpd 2.3.4 backdoor analysis (CVE-2011-2523), with firewall mitigation validated end-to-end.",
                    "url": "https://github.com/aish19siddiqua-commits/mtechweek_04"
                },
                {
                    "repository": "PoC-in-GitHub · ocfagb/hacktivity-vulns-exploits-lab",
                    "author": "ocfagb",
                    "first_seen": "2026-08-27",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).",
                    "summary": "Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit, CVE-2010-1240, CVE-2004-2687).",
                    "url": "https://github.com/ocfagb/hacktivity-vulns-exploits-lab"
                },
                {
                    "repository": "PoC-in-GitHub · germarr93/CyberSecurity-Pentest-Lab",
                    "author": "germarr93",
                    "first_seen": "2026-09-11",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "CVE-2004-2687 (Distcc 3.2.1) exploitation, methodology & remediation — Metasploitable2 lab",
                    "summary": "CVE-2004-2687 (Distcc 3.2.1) exploitation, methodology & remediation — Metasploitable2 lab",
                    "url": "https://github.com/germarr93/CyberSecurity-Pentest-Lab"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/9915",
                "https://github.com/h3x0v3rl0rd/distccd_rce_CVE-2004-2687",
                "https://github.com/k4miyo/CVE-2004-2687",
                "https://github.com/nulltrace1336/Metasploitable-2-Distcc-Exploit-via-Kali-Linux-CVE-2004-2687",
                "https://github.com/micheaol/distccd_rce_CVE-2004-2687",
                "https://github.com/aish19siddiqua-commits/mtechweek_04",
                "https://github.com/ocfagb/hacktivity-vulns-exploits-lab",
                "https://github.com/germarr93/CyberSecurity-Pentest-Lab"
            ],
            "timeline": [
                {
                    "at": "2026-09-10T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/9915"
                }
            ]
        },
        {
            "id": "CVE-2004-0932",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Multiple AntiVirus - '.zip' Detection Bypass",
            "summary": "Multiple AntiVirus - '.zip' Detection Bypass",
            "updated_at": "2026-09-04T19:43:05Z",
            "published_at": "2026-09-04T19:43:05Z",
            "cvss": 7.8,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 92,
            "kev": false,
            "attack_vector": "Local",
            "authentication": "None",
            "complexity": "Low",
            "cwe": "Unknown",
            "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 629",
                    "author": "oc192",
                    "first_seen": "2004-11-14",
                    "confidence": "High",
                    "title": "Multiple AntiVirus - '.zip' Detection Bypass",
                    "summary": "Multiple AntiVirus - '.zip' Detection Bypass",
                    "url": "https://www.exploit-db.com/exploits/629",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
                    "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                        "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                    ],
                    "repository": "Sploitus",
                    "author": "KitPloit",
                    "first_seen": "2026-09-04T21:43:05",
                    "confidence": "Medium",
                    "verification": "candidate",
                    "verified": false,
                    "verification_detail": "Indexed source reference.",
                    "url": "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK"
                },
                {
                    "title": "Exploit for zipbrk CVE-2004-0932 CVE-2014-8139 CVE-2014-8140 CVE-2014-8141 CVE-2015-7696 CVE-2015-7697 CVE-201",
                    "summary": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "what_happened": "Cross-platform zip file dissection and modification tool addressing multiple zip parser CVEs.",
                    "cvss": 7.8,
                    "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                    "attack_vector": "Local",
                    "authentication": "None",
                    "complexity": "Low",
                    "cwe": "Unknown",
                    "references": [
                        "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                        "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                    ],
                    "repository": "kitploit.com",
                    "author": "ru",
                    "first_seen": "2026-09-04T21:43:05",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "verification_detail": "Linked from Sploitus structured metadata.",
                    "url": "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/629",
                "https://sploitus.com/exploit?id=KITPLOIT%3ATOOLS-GITHUB-KVESEL-ZIPBRK",
                "https://kitploit.com/ru/tools/github/kvesel/zipbrk/"
            ],
            "timeline": [
                {
                    "at": "2026-09-04T19:43:05Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/629"
                }
            ],
            "cvss_vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
        },
        {
            "id": "CVE-2004-0077",
            "vendor": "Unknown vendor",
            "product": "Unknown product",
            "title": "Linux Kernel 2.2.25/2.4.24/2.6.2 - 'mremap()' Local Privilege Escalation",
            "summary": "Linux Kernel 2.2.25/2.4.24/2.6.2 - 'mremap()' Local Privilege Escalation",
            "updated_at": "2026-09-06T22:00:00Z",
            "published_at": "2026-09-06T22:00:00Z",
            "cvss": 0,
            "confidence": 100,
            "confidence_label": "verified",
            "affected": "See original advisory",
            "fixed": "See vendor advisory",
            "source_count": 169,
            "kev": false,
            "attack_vector": "Unknown",
            "authentication": "Unknown",
            "complexity": "Unknown",
            "cwe": "Unknown",
            "what_happened": "A public source linked this CVE to an advisory or demonstration repository. Review the original reference before use.",
            "why_matters": "This source correlation may provide earlier visibility while structured CVE metadata is still being updated.",
            "mitigations": [
                "Review the original advisory and validate affected versions.",
                "Apply vendor-provided updates or mitigations when available."
            ],
            "pocs": [
                {
                    "repository": "Exploit-DB 160",
                    "author": "Paul Starzetz",
                    "first_seen": "2004-03-01",
                    "confidence": "High",
                    "title": "Linux Kernel 2.2.25/2.4.24/2.6.2 - 'mremap()' Local Privilege Escalation",
                    "summary": "Linux Kernel 2.2.25/2.4.24/2.6.2 - 'mremap()' Local Privilege Escalation",
                    "url": "https://www.exploit-db.com/exploits/160",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "Exploit-DB 154",
                    "author": "Christophe Devine",
                    "first_seen": "2004-02-18",
                    "confidence": "High",
                    "title": "Linux Kernel 2.2.25/2.4.24/2.6.2 - 'mremap()' Validator",
                    "summary": "Linux Kernel 2.2.25/2.4.24/2.6.2 - 'mremap()' Validator",
                    "url": "https://www.exploit-db.com/exploits/154",
                    "verification": "verified",
                    "verified": true
                },
                {
                    "repository": "PoC-in-GitHub · 0b0111100/2004",
                    "author": "0b0111100",
                    "first_seen": "2026-09-07",
                    "confidence": "Medium",
                    "verification": "correlated",
                    "verified": false,
                    "stars": 0,
                    "title": "Linux Kernel Exploits -> CVE-2004-0077 + CVE-2004-1235 + caps_to_root",
                    "summary": "Linux Kernel Exploits -> CVE-2004-0077 + CVE-2004-1235 + caps_to_root",
                    "url": "https://github.com/0b0111100/2004"
                }
            ],
            "references": [
                "https://www.exploit-db.com/exploits/160",
                "https://www.exploit-db.com/exploits/154",
                "https://github.com/0b0111100/2004"
            ],
            "timeline": [
                {
                    "at": "2026-09-06T22:00:00Z",
                    "label": "Discovered through Exploit-DB",
                    "url": "https://www.exploit-db.com/exploits/160"
                }
            ]
        }
    ]
}